From f1b4797f5fcbbb0797f4034152b765e0db7e306f Mon Sep 17 00:00:00 2001 From: "github-actions[bot]" Date: Fri, 11 Sep 2026 18:57:35 +0000 Subject: [PATCH] Merge pull request #582 from CyberDrain/dev Synced from CyberDrain/CIPP@ad6ed320abf3e882fa2420b8e1b477365a6304d4 --- package.json | 8 +- public/intune-definitions/03.json | 2 +- public/intune-definitions/05.json | 2 +- public/intune-definitions/07.json | 2 +- public/intune-definitions/08.json | 2 +- public/intune-definitions/0b.json | 2 +- public/intune-definitions/0e.json | 2 +- public/intune-definitions/0f.json | 2 +- public/intune-definitions/13.json | 2 +- public/intune-definitions/15.json | 2 +- public/intune-definitions/17.json | 2 +- public/intune-definitions/1a.json | 2 +- public/intune-definitions/1b.json | 2 +- public/intune-definitions/20.json | 2 +- public/intune-definitions/24.json | 2 +- public/intune-definitions/25.json | 2 +- public/intune-definitions/28.json | 2 +- public/intune-definitions/2c.json | 2 +- public/intune-definitions/30.json | 2 +- public/intune-definitions/31.json | 2 +- public/intune-definitions/33.json | 2 +- public/intune-definitions/34.json | 2 +- public/intune-definitions/38.json | 2 +- public/intune-definitions/3d.json | 2 +- public/intune-definitions/3e.json | 2 +- public/intune-definitions/41.json | 2 +- public/intune-definitions/42.json | 2 +- public/intune-definitions/46.json | 2 +- public/intune-definitions/49.json | 2 +- public/intune-definitions/4c.json | 2 +- public/intune-definitions/50.json | 2 +- public/intune-definitions/51.json | 2 +- public/intune-definitions/54.json | 2 +- public/intune-definitions/55.json | 2 +- public/intune-definitions/59.json | 2 +- public/intune-definitions/5a.json | 2 +- public/intune-definitions/5b.json | 2 +- public/intune-definitions/64.json | 2 +- public/intune-definitions/69.json | 2 +- public/intune-definitions/70.json | 2 +- public/intune-definitions/76.json | 2 +- public/intune-definitions/86.json | 2 +- public/intune-definitions/88.json | 2 +- public/intune-definitions/89.json | 2 +- public/intune-definitions/8e.json | 2 +- public/intune-definitions/8f.json | 2 +- public/intune-definitions/93.json | 2 +- public/intune-definitions/94.json | 2 +- public/intune-definitions/9a.json | 2 +- public/intune-definitions/9b.json | 2 +- public/intune-definitions/9c.json | 2 +- public/intune-definitions/9e.json | 2 +- public/intune-definitions/a1.json | 2 +- public/intune-definitions/a2.json | 2 +- public/intune-definitions/ac.json | 2 +- public/intune-definitions/ad.json | 2 +- public/intune-definitions/af.json | 2 +- public/intune-definitions/b2.json | 2 +- public/intune-definitions/b5.json | 2 +- public/intune-definitions/b7.json | 2 +- public/intune-definitions/ba.json | 2 +- public/intune-definitions/bb.json | 2 +- public/intune-definitions/be.json | 2 +- public/intune-definitions/bf.json | 2 +- public/intune-definitions/c4.json | 2 +- public/intune-definitions/c6.json | 2 +- public/intune-definitions/cb.json | 2 +- public/intune-definitions/cd.json | 2 +- public/intune-definitions/cf.json | 2 +- public/intune-definitions/d4.json | 2 +- public/intune-definitions/d6.json | 2 +- public/intune-definitions/d7.json | 2 +- public/intune-definitions/d8.json | 2 +- public/intune-definitions/da.json | 2 +- public/intune-definitions/e6.json | 2 +- public/intune-definitions/e7.json | 2 +- public/intune-definitions/e9.json | 2 +- public/intune-definitions/f0.json | 2 +- public/intune-definitions/f3.json | 2 +- public/intune-definitions/f8.json | 2 +- public/intune-definitions/f9.json | 2 +- public/intune-definitions/fb.json | 2 +- public/intune-definitions/fc.json | 2 +- public/intune-definitions/fd.json | 2 +- public/intune-definitions/fe.json | 2 +- public/intune-definitions/ff.json | 2 +- public/intuneCategories.json | 2 +- public/version.json | 2 +- .../CippComponents/CippAddUserDrawer.jsx | 22 +- .../CippComponents/CippAuthShell.jsx | 3 + .../CippComponents/CippBulkUserDrawer.jsx | 24 +- .../CippCAPolicyCoverageDrawer.jsx | 701 ++++++++++++++++++ .../CippDevicePolicySettingStates.jsx | 192 +++++ .../CippComponents/CippMfaVerifyForm.jsx | 6 +- .../CippComponents/CippPolicyDeployDrawer.jsx | 4 + .../CippComponents/CippTranslations.jsx | 8 + .../ForcedSsoMigrationDialog.jsx | 6 +- .../CippComponents/SsoMigrationDialog.jsx | 3 +- .../CippSettings/CippRoleAddEdit.jsx | 17 +- .../CippSettings/CippSSOSettings.jsx | 15 +- .../CippTable/CIPPTableToptoolbar.jsx | 5 +- .../CippTable/CippGraphExplorerFilter.jsx | 4 +- src/components/ReleaseNotesDialog.jsx | 13 +- src/data/ContainerLogPresets.json | 20 + src/data/standards.json | 22 +- .../container-management/diagnostics.jsx | 569 ++++++++++++++ .../container-management/tabOptions.json | 5 + src/pages/copilot/settings/index.jsx | 7 + .../endpoint/MEM/devices/device/index.jsx | 90 ++- .../identity/administration/roles/index.jsx | 13 + .../administration/roles/role/audit.jsx | 178 +++++ .../administration/roles/role/index.jsx | 315 ++++++++ .../administration/roles/role/pim.jsx | 541 ++++++++++++++ .../administration/roles/role/tabOptions.json | 17 + .../conditional/list-policies/index.jsx | 20 + src/theme/base/create-components.jsx | 21 +- src/utils/format-ca-coverage-reason.js | 339 +++++++++ src/utils/get-cipp-formatting.jsx | 76 +- src/utils/instance-diagnostics.js | 100 +++ src/utils/role-detail-shared.js | 32 + .../CippComponents/CippAddUserDrawer.test.jsx | 47 ++ .../CippBulkUserDrawer.test.jsx | 128 ++++ .../CippSettings/CippRoleAddEdit.test.jsx | 56 +- .../CippGraphExplorerFilter.test.jsx | 22 + tests/theme/mobile-gutters.test.js | 27 + tests/utils/instance-diagnostics.test.js | 123 +++ 126 files changed, 3819 insertions(+), 154 deletions(-) create mode 100644 src/components/CippComponents/CippCAPolicyCoverageDrawer.jsx create mode 100644 src/components/CippComponents/CippDevicePolicySettingStates.jsx create mode 100644 src/pages/cipp/advanced/container-management/diagnostics.jsx create mode 100644 src/pages/identity/administration/roles/role/audit.jsx create mode 100644 src/pages/identity/administration/roles/role/index.jsx create mode 100644 src/pages/identity/administration/roles/role/pim.jsx create mode 100644 src/pages/identity/administration/roles/role/tabOptions.json create mode 100644 src/utils/format-ca-coverage-reason.js create mode 100644 src/utils/instance-diagnostics.js create mode 100644 src/utils/role-detail-shared.js create mode 100644 tests/components/CippComponents/CippBulkUserDrawer.test.jsx create mode 100644 tests/utils/instance-diagnostics.test.js diff --git a/package.json b/package.json index 810e9acbc6ba..98a676fef060 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "cipp", - "version": "10.10.1", + "version": "10.10.2", "author": "CIPP Contributors", "homepage": "https://cipp.app/", "bugs": { @@ -8,7 +8,7 @@ }, "license": "AGPL-3.0", "engines": { - "node": "^22.22.0" + "node": "^22.22.2" }, "repository": { "type": "git", @@ -139,7 +139,7 @@ "eslint": "^9.39.4", "eslint-config-next": "^16.3.4", "eslint-config-prettier": "^10.1.8", - "jsdom": "29.0.1", + "jsdom": "30.0.1", "msw": "2.15.0", "msw-storybook-addon": "3.0.0", "playwright": "1.63.0", @@ -160,4 +160,4 @@ "sharp": "^0.35.0", "monaco-editor/dompurify": "^3.4.14" } -} +} \ No newline at end of file diff --git a/public/intune-definitions/03.json b/public/intune-definitions/03.json index 7d8ce2aef931..16b4e44162c3 100644 --- a/public/intune-definitions/03.json +++ b/public/intune-definitions/03.json @@ -1 +1 @@ -{"03aa7ce3ca5a117b":{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed","displayName":"Allow network escape hatch","description":"If 'True', allows users to turn on the network escape hatch feature. If a network connection can't be made at boot time, the escape hatch prompts the user to temporarily connect to a network in order to refresh the device policy. After applying policy, the temporary network will be forgotten and the device will continue booting. This prevents being unable to connect to a network if there is no suitable network in the last policy and the device boots into an app in lock task mode, or the user is otherwise unable to reach device settings. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from turning on the network escape hatch feature on the device. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed_false","displayName":"False","description":"false","helpText":null}]},"03f4054d5eea3004":{"id":"com.android.devicerestrictionpolicy.statusbarblocked","displayName":"Block access to status bar","description":"If 'True', prevents access to the status bar, including notifications and quick settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users access to the status bar. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.statusbarblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.statusbarblocked_false","displayName":"False","description":"false","helpText":null}]},"03697d0f972ded40":{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends","displayName":"Allow Adding Game Center Friends","description":"If false, prohibits adding friends to Game Center. As of iOS 13, requires a supervised device. Available in iOS 4.2.1 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends_true","displayName":"True","description":null,"helpText":null}]},"03ef3468a357e888":{"id":"com.apple.applicationaccess_allowcloudkeychainsync","displayName":"Allow Cloud Keychain Sync","description":"If false, disables iCloud keychain synchronization. Requires a supervised device. Available in iOS 7 and later and macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudkeychainsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudkeychainsync_true","displayName":"True","description":null,"helpText":null}]},"03b26e1a4a285b27":{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag","displayName":"AD Domain Admin Group List Flag","description":"If true, enables the AD Domain Admin Group List key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag_true","displayName":"True","description":null,"helpText":null}]},"03cb88cfcd060962":{"id":"com.apple.extensiblesso_urls","displayName":"URLs","description":"An array of URL prefixes of identity providers where the app extension performs SSO. Required for Redirect payloads. Ignored for Credential payloads. The URLs must begin with http:// or https://, the scheme and host name are matched case-insensitively, query parameters and URL fragments are not allowed, and the URLs of all installed Extensible SSO payloads must be unique.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"03bf66e455c8ac0b":{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy","displayName":"Automatically acknowledge data collection policy","description":"Suppress the Required Data Collection policy dialog from being shown to users.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/deployoffice/privacy/mac-privacy-preferences#preference-setting-for-the-required-data-notice-dialog-for-microsoft-autoupdate"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy_0","displayName":"Acknowledge - send required data","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy_1","displayName":"Acknowledge - send required and optional data (Deprecated)","description":null,"helpText":null}]},"03b95255e2ffd860":{"id":"com.apple.managedclient.preferences_efficiencymode","displayName":"Configure when efficiency mode should become active","description":"This policy setting lets you configure when efficiency mode becomes active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, efficiency mode is disabled by default and does not become active. Please note that Windows Energy Saver settings can influence when efficiency mode becomes active on all devices.\n\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nSet this policy to 'AlwaysActive' and efficiency mode is always active.\n\nSet this policy to 'NeverActive' and efficiency mode never becomes active.\n\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode becomes active when the device is unplugged.\n\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode becomes active when the device is unplugged and the battery is low.\n\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nIf the device does not have a battery, efficiency mode never becomes active in any mode other than 'AlwaysActive' unless the setting or \"EfficiencyModeEnabled\" policy is enabled.\n\nThis policy has no effect if the \"EfficiencyModeEnabled\" policy is disabled.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\n\nLearn more about energy saver: https://learn.microsoft.com/en-us/windows-hardware/design/component-guidelines/energy-saver\n\nPolicy options mapping:\n\n* AlwaysActive (0) = Efficiency mode is always active\n\n* NeverActive (1) = Efficiency mode is never active\n\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\n\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\n\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.","description":null,"helpText":null}]},"0377f6b4bd7286b6":{"id":"com.apple.managedclient.preferences_fileordirectorypickerwithoutgestureallowedfororigins","displayName":"Allow file or directory picker APIs to be called without prior user gesture","description":"For security reasons, the showOpenFilePicker(), showSaveFilePicker() and showDirectoryPicker() web APIs require a prior user gesture (\"transient activation\") to be called or will otherwise fail.\n\nIf you enable this policy, admins can specify origins on which these APIs can be called without prior user gesture.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\n\nIf you disable or don't configure this policy, all origins will require a prior user gesture to call these APIs.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#fileordirectorypickerwithoutgestureallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"036742162d019a51":{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\n\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\n\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\n\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pictureinpictureoverlayenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"03fe191cf3919934":{"id":"com.apple.servicemanagement_rules_item_comment","displayName":"Comment","description":"An optional description of the rule.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},"03131f22573558ad":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled","displayName":"Save and fill memberships","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"03a033d8278e23e0":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan","displayName":"Ignore bandwidth limits if the source and the destination are on the same subnet.","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan_1","displayName":"True","description":null,"helpText":null}]},"03820318661ec88d":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3_1","displayName":"True","description":null,"helpText":null}]},"03cc6e3d6fa6fed2":{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground","displayName":"Always use custom logon background","description":"This policy setting ignores Windows Logon Background.\r\n\r\nThis policy setting may be used to make Windows give preference to a custom logon background. \r\n\r\nIf you enable this policy setting, the logon screen always attempts to load a custom background instead of the Windows-branded logon background. \r\n\r\nIf you disable or do not configure this policy setting, Windows uses the default Windows logon background or custom background.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-useoembackground"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground_1","displayName":"Enabled","description":null,"helpText":null}]},"03bc67db9b606a58":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch","displayName":"Use DNS name resolution when a single-label domain name is used, by appending different registered DNS suffixes, if the AllowSingleLabelDnsDomain setting is not enabled.","description":"This policy setting specifies whether the computers to which this setting is applied attemps DNS name resolution of single-lablel domain names, by appending different registered DNS suffixes, and uses NetBIOS name resolution only if DNS name resolution fails. This policy, including the specified default behavior, is not used if the AllowSingleLabelDnsDomain policy setting is enabled.\r\n\r\nBy default, when no setting is specified for this policy, the behavior is the same as explicitly enabling this policy, unless the AllowSingleLabelDnsDomain policy setting is enabled.\r\n\r\nIf you enable this policy setting, when the AllowSingleLabelDnsDomain policy is not enabled, computers to which this policy is applied, will locate a domain controller hosting an Active Directory domain specified with a single-label name, by appending different registered DNS suffixes to perform DNS name resolution. The single-label name is not used without appending DNS suffixes unless the computer is joined to a domain that has a single-label DNS name in the Active Directory forest. NetBIOS name resolution is performed on the single-label name only, in the event that DNS resolution fails.\r\n\r\nIf you disable this policy setting, when the AllowSingleLabelDnsDomain policy is not enabled, computers to which this policy is applied, will only use NetBIOS name resolution to attempt to locate a domain controller hosting an Active Directory domain specified with a single-label name. The computers will not attempt DNS name resolution in this case, unless the computer is searching for a domain with a single label DNS name to which this computer is joined, in the Active Directory forest.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allowdnssuffixsearch"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch_1","displayName":"Enabled","description":null,"helpText":null}]},"03f52a8571c150e8":{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_outputdirectory","displayName":"Transcript output directory","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},"03e30a8b67159a37":{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"personalize\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},"03cb8093e08bc819":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2","displayName":"Allow .rdp files from unknown publishers","description":"This policy setting allows you to specify whether users can run unsigned Remote Desktop Protocol (.rdp) files and .rdp files from unknown publishers on the client computer.\r\n\r\nIf you enable or do not configure this policy setting, users can run unsigned .rdp files and .rdp files from unknown publishers on the client computer. Before a user starts an RDP session, the user receives a warning message and is asked to confirm whether they want to connect.\r\n\r\nIf you disable this policy setting, users cannot run unsigned .rdp files and .rdp files from unknown publishers on the client computer. If the user tries to start an RDP session, the user receives a message that the publisher has been blocked.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-allow-unsigned-files-2"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2_1","displayName":"Enabled","description":null,"helpText":null}]},"03efbdc2ce564ff9":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper","displayName":"Enforce Removal of Remote Desktop Wallpaper","description":"Specifies whether desktop wallpaper is displayed to remote clients connecting via Remote Desktop Services.\r\n\r\nYou can use this setting to enforce the removal of wallpaper during a Remote Desktop Services session. By default, Windows XP Professional displays wallpaper to remote clients connecting through Remote Desktop, depending on the client configuration (see the Experience tab in the Remote Desktop Connection options for more information). Servers running Windows Server 2003 do not display wallpaper by default to Remote Desktop Services sessions.\r\n\r\nIf the status is set to Enabled, wallpaper never appears in a Remote Desktop Services session.\r\n\r\nIf the status is set to Disabled, wallpaper might appear in a Remote Desktop Services session, depending on the client configuration.\r\n\r\nIf the status is set to Not Configured, the default behavior applies.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-disable-remote-desktop-wallpaper"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper_1","displayName":"Enabled","description":null,"helpText":null}]},"03d90f966f2b7492":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator","displayName":"Windows Calculator (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator_1","displayName":"True","description":null,"helpText":null}]},"03c79b9401651576":{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup","displayName":"Enable automatic cleanup of unused appv packages","description":"Enables automatic cleanup of appv packages that were added after Windows10 anniversary release.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpackagecleanup"],"categoryId":"f125d7cd-a333-4f24-a5f4-99fc289c6d22","categoryName":"Package Management","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup_1","displayName":"Enabled","description":null,"helpText":null}]},"030c69c203341d90":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting","description":"Setting the policy to BlockLocalFonts (value 2) automatically denies the local fonts permission to sites by default. This will limit the ability of sites to see information about local fonts.\r\n\r\nSetting the policy to AskLocalFonts (value 3) will prompt the user when the local fonts permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about local fonts.\r\n\r\nLeaving the policy unset means the default behavior applies which is to prompt the user, but users can change this setting","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"03540d4153c9c7f5":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs.","description":"Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the item to be valid, otherwise the item is ignored. Each item in the devices field must have a vendor_id and may have a product_id field. Omitting the product_id field will create a policy matching any device with the specified vendor ID. An item which has a product_id field without a vendor_id field is invalid and is ignored.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies.\r\n\r\nURLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebHidAllowDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://google.com\",\r\n \"https://chromium.org\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"03cc2bbe9b3da370":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},"0349876e01d37fc2":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},"03d63caea93e8e2e":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin","displayName":"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin_1","displayName":"Sign in and make domain account non-removable","description":null,"helpText":null}]},"039776c282c8b648":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_1","displayName":"All eligible navigations","description":null,"helpText":null}]},"03fba4e49924231f":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled","description":"This policy lets you configure support of CORS non-wildcard request headers.\r\n\r\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://go.microsoft.com/fwlink/?linkid=2180022 for more detail.\r\n\r\nIf you enable or don't configure the policy, Microsoft Edge will support the CORS non-wildcard request headers and behave as previously described.\r\n\r\nIf you disable this policy, Microsoft Edge will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\r\n\r\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's intended to be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport_1","displayName":"Enabled","description":null,"helpText":null}]},"031f802d4c2d3dec":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_forceallowtheseapps","displayName":"Let Apps Access Trusted Devices Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will have access to trusted devices. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstrusteddevices_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"0391a9a042a020b5":{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots","displayName":"Set Maximum Storage Duration For Recall Snapshots","description":"This policy setting allows you to control the maximum amount of time (in days) that Windows saves snapshots for Recall. The default value for this setting is '0' which doesn't set a time frame to delete snapshots. When the default is used, snapshots aren't deleted until the maximum storage allocation for Recall is reached and the oldest snapshots are deleted first. You can configure the maximum storage duration to be 30, 60, 90, or 180 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragedurationforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_0","displayName":"Let the OS define the maximum amount of time the snapshots will be saved","description":"Let the OS define the maximum amount of time the snapshots will be saved","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_30","displayName":"30 days","description":"30 days","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_60","displayName":"60 days","description":"60 days","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_90","displayName":"90 days","description":"90 days","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_180","displayName":"180 days","description":"180 days","helpText":null}]},"038f2983dc0d271b":{"id":"linux_mdatp_managed_antivirusengine_exclusions","displayName":"Scan exclusions","description":"Entities that have been excluded from the scan. Exclusions can be specified by full paths, extensions, or file names.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#scan-exclusions"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"03c8ce9ceb4a006c":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},"039a5aa7abcffb16":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders66","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders66_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders66_1","displayName":"True","description":null,"helpText":null}]},"034cc1a4b6ed7bae":{"id":"user_vendor_msft_policy_config_admx_startmenu_clearrecentprogfornewuserinstartmenu","displayName":"Clear the recent programs list for new users (User)","description":"If you enable this policy setting, the recent programs list in the start menu will be blank for each new user.\r\n\r\nIf you disable or do not configure this policy, the start menu recent programs list will be pre-populated with programs for each new user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-clearrecentprogfornewuserinstartmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_clearrecentprogfornewuserinstartmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_clearrecentprogfornewuserinstartmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"03b44a69b4ddeeef":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow insecure websites to make requests to more-private network endpoints (User)","description":"Controls whether insecure websites are allowed to make requests to more-private network endpoints.\r\n\r\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\r\n\r\nA network endpoint is more private than another if:\r\n1) Its IP address is localhost and the other is not.\r\n2) Its IP address is private and the other is public.\r\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\r\n\r\nA website is deemed secure if it meets the definition of a secure context in https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts. Otherwise, it will be treated as an insecure context.\r\n\r\nWhen this policy is either not set or set to false, the default behavior for requests from insecure contexts to more-private network endpoints will depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests feature, which may be set by a field trial or on the command line.\r\n\r\nWhen this policy is set to true, insecure websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"034cb615c41487c6":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments (User)","description":"This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete.\r\n\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled.\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"039f8198884d11bc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_2","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_3","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},"0315837b7ee7db56":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended","displayName":"Keep browsing data when creating enterprise profile by default (User)","description":"If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default.\r\n\r\nIf this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.\r\n\r\nRegardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile.\r\n\r\nThis policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"030af71b86f2992a":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls","displayName":"Allow Window Management permission on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which will automatically grant the window management permission. This will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nThis replaces the deprecated WindowPlacementAllowedForUrls policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0354b3af20829b5d":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview","displayName":"File tab | Options | Customize Ribbon | All Commands | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview_1","displayName":"True","description":null,"helpText":null}]},"03d92b7390ba057c":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402","displayName":"XAML Files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_1","displayName":"Prompt","description":null,"helpText":null}]},"03d993cc5f68f26c":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles","displayName":"Show security warning for potentially unsafe files (User)","description":"This policy setting controls whether or not the \"Open File - Security Warning\" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).\n\nIf you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.\n\nIf you disable this policy setting, these files do not open.\n\nIf you do not configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneshowsecuritywarningforpotentiallyunsafefiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"031875c9ba239e62":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"030315c173ec1e69":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowscriptlets"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"03c139d713cd5d92":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled","displayName":"Enable search suggestions (User)","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\r\n\r\nIf you enable this policy, web search suggestions are used.\r\n\r\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\r\n\r\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"03fa5d8d163fe07f":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed","displayName":"Allow single sign-on for Microsoft personal sites using this profile (User)","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\r\n\r\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\r\n\r\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"03d9be71513a48be":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},"038e8893f1677655":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage","displayName":"Web Query dialog box home page (User)","description":"Specifies the default location of the home page for Web queries.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"03f42ad20894b1fc":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording_l_bits","displayName":"Bits: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},"03e08372b7836280":{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier_l_empty16","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"039b56f65a35cf8b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend","displayName":"Configure Outlook object model prompt when sending mail (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to send e-mail programmatically using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to send e-mail programmatically using the Outlook object model: \r\n\r\n- Prompt user - The user will be prompted to approve every access attempt.\r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nImportant: This policy setting only applies if the ''Outlook Security Mode'' policy setting under ''Microsoft Outlook 2016\\Security\\Security Form Settings'' is configured to ''Use Outlook Security Group Policy.''\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to send mail programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_1","displayName":"Enabled","description":null,"helpText":null}]},"03d755b57b723276":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"03b1f0d437468d6f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},"03a07f31a8fbbaf5":{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat","displayName":"Turn Off Abbreviated Date Time Format (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#turnoffabbreviateddatetimeformat"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat_0","displayName":"Show abbreviated time and date format","description":"Show abbreviated time and date format","helpText":null},{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat_1","displayName":"Show classic time and date format","description":"Show classic time and date format","helpText":null}]},"03e697e27461d0eb":{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath","displayName":"Skip Opening Local Files with Long Paths (User)","description":"This policy controls whether Word should skip opening local files with very long paths.\n\nIf you enable this policy, Word will not open local files that have very long paths. Only enable if local files with long paths are causing issues in your environment.\n\nIf you disable or do not configure this policy, Word will open local files with long paths.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath_1","displayName":"Enabled","description":null,"helpText":null}]},"038e1e06527d1da5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers","displayName":"Disable features not supported by specified browsers (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"56e510be-ca39-46a2-9eb2-6f1af6d4b16a","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers_1","displayName":"Enabled","description":null,"helpText":null}]},"03b1fa3638101ee5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"03568c638195f45f":{"id":"vendor_msft_personalization_companyname","displayName":"Company Name","description":"The name of the company to be displayed on the sign-in screen. This setting is currently available for boot to cloud shared pc mode only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},"03694d88f6044316":{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe","displayName":"Require Network In OOBE (Device)","description":"true - Require network in OOBE, false - no network connection requirement in OOBE","helpText":null,"infoUrls":[],"categoryId":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","categoryName":"Tenant Lockdown","options":[{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe_true","displayName":"true","description":null,"helpText":null},{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe_false","displayName":"false","description":null,"helpText":null}]}} \ No newline at end of file +{"03aa7ce3ca5a117b":{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed","displayName":"Allow network escape hatch","description":"If 'True', allows users to turn on the network escape hatch feature. If a network connection can't be made at boot time, the escape hatch prompts the user to temporarily connect to a network in order to refresh the device policy. After applying policy, the temporary network will be forgotten and the device will continue booting. This prevents being unable to connect to a network if there is no suitable network in the last policy and the device boots into an app in lock task mode, or the user is otherwise unable to reach device settings. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from turning on the network escape hatch feature on the device. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.networkescapehatchallowed_false","displayName":"False","description":"false","helpText":null}]},"03f4054d5eea3004":{"id":"com.android.devicerestrictionpolicy.statusbarblocked","displayName":"Block access to status bar","description":"If 'True', prevents access to the status bar, including notifications and quick settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users access to the status bar. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.statusbarblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.statusbarblocked_false","displayName":"False","description":"false","helpText":null}]},"03697d0f972ded40":{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends","displayName":"Allow Adding Game Center Friends","description":"If false, prohibits adding friends to Game Center. As of iOS 13, requires a supervised device. Available in iOS 4.2.1 and later, and macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowaddinggamecenterfriends_true","displayName":"True","description":null,"helpText":null}]},"03ef3468a357e888":{"id":"com.apple.applicationaccess_allowcloudkeychainsync","displayName":"Allow Cloud Keychain Sync","description":"If false, disables iCloud keychain synchronization. Requires a supervised device. Available in iOS 7 and later and macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudkeychainsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudkeychainsync_true","displayName":"True","description":null,"helpText":null}]},"03b26e1a4a285b27":{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag","displayName":"AD Domain Admin Group List Flag","description":"If true, enables the AD Domain Admin Group List key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_addomainadmingrouplistflag_true","displayName":"True","description":null,"helpText":null}]},"03cb88cfcd060962":{"id":"com.apple.extensiblesso_urls","displayName":"URLs","description":"An array of URL prefixes of identity providers where the app extension performs SSO. Required for Redirect payloads. Ignored for Credential payloads. The URLs must begin with http:// or https://, the scheme and host name are matched case-insensitively, query parameters and URL fragments are not allowed, and the URLs of all installed Extensible SSO payloads must be unique.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"03bf66e455c8ac0b":{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy","displayName":"Automatically acknowledge data collection policy","description":"Suppress the Required Data Collection policy dialog from being shown to users.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/deployoffice/privacy/mac-privacy-preferences#preference-setting-for-the-required-data-notice-dialog-for-microsoft-autoupdate"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy_0","displayName":"Acknowledge - send required data","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_acknowledgeddatacollectionpolicy_1","displayName":"Acknowledge - send required and optional data (Deprecated)","description":null,"helpText":null}]},"03b95255e2ffd860":{"id":"com.apple.managedclient.preferences_efficiencymode","displayName":"Configure when efficiency mode should become active","description":"This policy setting lets you configure when efficiency mode becomes active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, efficiency mode is disabled by default and does not become active. Please note that Windows Energy Saver settings can influence when efficiency mode becomes active on all devices.\n\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nSet this policy to 'AlwaysActive' and efficiency mode is always active.\n\nSet this policy to 'NeverActive' and efficiency mode never becomes active.\n\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode becomes active when the device is unplugged.\n\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode becomes active when the device is unplugged and the battery is low.\n\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nIf the device does not have a battery, efficiency mode never becomes active in any mode other than 'AlwaysActive' unless the setting or \"EfficiencyModeEnabled\" policy is enabled.\n\nThis policy has no effect if the \"EfficiencyModeEnabled\" policy is disabled.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\n\nLearn more about energy saver: https://learn.microsoft.com/en-us/windows-hardware/design/component-guidelines/energy-saver\n\nPolicy options mapping:\n\n* AlwaysActive (0) = Efficiency mode is always active\n\n* NeverActive (1) = Efficiency mode is never active\n\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\n\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\n\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes extra steps to save battery.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes extra steps to save battery.","description":null,"helpText":null}]},"0377f6b4bd7286b6":{"id":"com.apple.managedclient.preferences_fileordirectorypickerwithoutgestureallowedfororigins","displayName":"Allow file or directory picker APIs to be called without prior user gesture","description":"For security reasons, the showOpenFilePicker(), showSaveFilePicker() and showDirectoryPicker() web APIs require a prior user gesture (\"transient activation\") to be called or will otherwise fail.\n\nIf you enable this policy, admins can specify origins on which these APIs can be called without prior user gesture.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\n\nIf you disable or don't configure this policy, all origins will require a prior user gesture to call these APIs.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#fileordirectorypickerwithoutgestureallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"036742162d019a51":{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\n\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\n\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\n\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pictureinpictureoverlayenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pictureinpictureoverlayenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"03fe191cf3919934":{"id":"com.apple.servicemanagement_rules_item_comment","displayName":"Comment","description":"An optional description of the rule.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},"03131f22573558ad":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled","displayName":"Save and fill memberships","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofillmembershipsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"036050eade43916e":{"id":"device_vendor_msft_maintenancewindows_startdate","displayName":"Start date","description":"Specify the start date for the maintenance window in YYYY-MM-DD format.","helpText":"Pick a date","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":null},"03a033d8278e23e0":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan","displayName":"Ignore bandwidth limits if the source and the destination are on the same subnet.","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_ignorelimitsonlan_1","displayName":"True","description":null,"helpText":null}]},"03820318661ec88d":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nobackground3_1","displayName":"True","description":null,"helpText":null}]},"03cc6e3d6fa6fed2":{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground","displayName":"Always use custom logon background","description":"This policy setting ignores Windows Logon Background.\r\n\r\nThis policy setting may be used to make Windows give preference to a custom logon background. \r\n\r\nIf you enable this policy setting, the logon screen always attempts to load a custom background instead of the Windows-branded logon background. \r\n\r\nIf you disable or do not configure this policy setting, Windows uses the default Windows logon background or custom background.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-useoembackground"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_useoembackground_1","displayName":"Enabled","description":null,"helpText":null}]},"03bc67db9b606a58":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch","displayName":"Use DNS name resolution when a single-label domain name is used, by appending different registered DNS suffixes, if the AllowSingleLabelDnsDomain setting is not enabled.","description":"This policy setting specifies whether the computers to which this setting is applied attemps DNS name resolution of single-lablel domain names, by appending different registered DNS suffixes, and uses NetBIOS name resolution only if DNS name resolution fails. This policy, including the specified default behavior, is not used if the AllowSingleLabelDnsDomain policy setting is enabled.\r\n\r\nBy default, when no setting is specified for this policy, the behavior is the same as explicitly enabling this policy, unless the AllowSingleLabelDnsDomain policy setting is enabled.\r\n\r\nIf you enable this policy setting, when the AllowSingleLabelDnsDomain policy is not enabled, computers to which this policy is applied, will locate a domain controller hosting an Active Directory domain specified with a single-label name, by appending different registered DNS suffixes to perform DNS name resolution. The single-label name is not used without appending DNS suffixes unless the computer is joined to a domain that has a single-label DNS name in the Active Directory forest. NetBIOS name resolution is performed on the single-label name only, in the event that DNS resolution fails.\r\n\r\nIf you disable this policy setting, when the AllowSingleLabelDnsDomain policy is not enabled, computers to which this policy is applied, will only use NetBIOS name resolution to attempt to locate a domain controller hosting an Active Directory domain specified with a single-label name. The computers will not attempt DNS name resolution in this case, unless the computer is searching for a domain with a single label DNS name to which this computer is joined, in the Active Directory forest.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allowdnssuffixsearch"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allowdnssuffixsearch_1","displayName":"Enabled","description":null,"helpText":null}]},"03f52a8571c150e8":{"id":"device_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_outputdirectory","displayName":"Transcript output directory","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},"03e30a8b67159a37":{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"personalize\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablepersonalizationsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},"03cb8093e08bc819":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2","displayName":"Allow .rdp files from unknown publishers","description":"This policy setting allows you to specify whether users can run unsigned Remote Desktop Protocol (.rdp) files and .rdp files from unknown publishers on the client computer.\r\n\r\nIf you enable or do not configure this policy setting, users can run unsigned .rdp files and .rdp files from unknown publishers on the client computer. Before a user starts an RDP session, the user receives a warning message and is asked to confirm whether they want to connect.\r\n\r\nIf you disable this policy setting, users cannot run unsigned .rdp files and .rdp files from unknown publishers on the client computer. If the user tries to start an RDP session, the user receives a message that the publisher has been blocked.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-allow-unsigned-files-2"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_2_1","displayName":"Enabled","description":null,"helpText":null}]},"03efbdc2ce564ff9":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper","displayName":"Enforce Removal of Remote Desktop Wallpaper","description":"Specifies whether desktop wallpaper is displayed to remote clients connecting via Remote Desktop Services.\r\n\r\nYou can use this setting to enforce the removal of wallpaper during a Remote Desktop Services session. By default, Windows XP Professional displays wallpaper to remote clients connecting through Remote Desktop, depending on the client configuration (see the Experience tab in the Remote Desktop Connection options for more information). Servers running Windows Server 2003 do not display wallpaper by default to Remote Desktop Services sessions.\r\n\r\nIf the status is set to Enabled, wallpaper never appears in a Remote Desktop Services session.\r\n\r\nIf the status is set to Disabled, wallpaper might appear in a Remote Desktop Services session, depending on the client configuration.\r\n\r\nIf the status is set to Not Configured, the default behavior applies.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-disable-remote-desktop-wallpaper"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_disable_remote_desktop_wallpaper_1","displayName":"Enabled","description":null,"helpText":null}]},"03d90f966f2b7492":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator","displayName":"Windows Calculator (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowscalculator_1","displayName":"True","description":null,"helpText":null}]},"03c79b9401651576":{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup","displayName":"Enable automatic cleanup of unused appv packages","description":"Enables automatic cleanup of appv packages that were added after Windows10 anniversary release.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpackagecleanup"],"categoryId":"f125d7cd-a333-4f24-a5f4-99fc289c6d22","categoryName":"Package Management","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagecleanup_1","displayName":"Enabled","description":null,"helpText":null}]},"030c69c203341d90":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting","description":"Setting the policy to BlockLocalFonts (value 2) automatically denies the local fonts permission to sites by default. This will limit the ability of sites to see information about local fonts.\r\n\r\nSetting the policy to AskLocalFonts (value 3) will prompt the user when the local fonts permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about local fonts.\r\n\r\nLeaving the policy unset means the default behavior applies which is to prompt the user, but users can change this setting","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"03540d4153c9c7f5":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs.","description":"Setting the policy lets you list the URLs that specify which sites are automatically granted permission to access a HID device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the item to be valid, otherwise the item is ignored. Each item in the devices field must have a vendor_id and may have a product_id field. Omitting the product_id field will create a policy matching any device with the specified vendor ID. An item which has a product_id field without a vendor_id field is invalid and is ignored.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies, if it's set. If not, the user's personal setting applies.\r\n\r\nURLs in this policy shouldn't conflict with those configured through WebHidBlockedForUrls. If they do, this policy takes precedence over WebHidBlockedForUrls.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebHidAllowDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://google.com\",\r\n \"https://chromium.org\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"03cc2bbe9b3da370":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},"0349876e01d37fc2":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},"03d63caea93e8e2e":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin","displayName":"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_configureonpremisesaccountautosignin_1","displayName":"Sign in and make domain account non-removable","description":null,"helpText":null}]},"039776c282c8b648":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_1","displayName":"All eligible navigations","description":null,"helpText":null}]},"03fba4e49924231f":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled","description":"This policy lets you configure support of CORS non-wildcard request headers.\r\n\r\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://go.microsoft.com/fwlink/?linkid=2180022 for more detail.\r\n\r\nIf you enable or don't configure the policy, Microsoft Edge will support the CORS non-wildcard request headers and behave as previously described.\r\n\r\nIf you disable this policy, Microsoft Edge will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\r\n\r\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's intended to be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_corsnonwildcardrequestheaderssupport_1","displayName":"Enabled","description":null,"helpText":null}]},"031f802d4c2d3dec":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_forceallowtheseapps","displayName":"Let Apps Access Trusted Devices Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will have access to trusted devices. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstrusteddevices_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"0391a9a042a020b5":{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots","displayName":"Set Maximum Storage Duration For Recall Snapshots","description":"This policy setting allows you to control the maximum amount of time (in days) that Windows saves snapshots for Recall. The default value for this setting is '0' which doesn't set a time frame to delete snapshots. When the default is used, snapshots aren't deleted until the maximum storage allocation for Recall is reached and the oldest snapshots are deleted first. You can configure the maximum storage duration to be 30, 60, 90, or 180 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragedurationforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_0","displayName":"Let the OS define the maximum amount of time the snapshots will be saved","description":"Let the OS define the maximum amount of time the snapshots will be saved","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_30","displayName":"30 days","description":"30 days","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_60","displayName":"60 days","description":"60 days","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_90","displayName":"90 days","description":"90 days","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_180","displayName":"180 days","description":"180 days","helpText":null}]},"038f2983dc0d271b":{"id":"linux_mdatp_managed_antivirusengine_exclusions","displayName":"Scan exclusions","description":"Entities that have been excluded from the scan. Exclusions can be specified by full paths, extensions, or file names.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#scan-exclusions"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"03c8ce9ceb4a006c":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifycngsaltlength","displayName":"Specify CNG salt length (User)","description":"This policy setting allows you to specific the number of bytes of salt that should be used.\r\n\r\nIf you enable this policy setting, the bytes specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default length or 16 will be used.","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifycngsaltlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifycngsaltlength_1","displayName":"Enabled","description":null,"helpText":null}]},"039a5aa7abcffb16":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders66","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders66_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_allowsubfolders66_1","displayName":"True","description":null,"helpText":null}]},"034cc1a4b6ed7bae":{"id":"user_vendor_msft_policy_config_admx_startmenu_clearrecentprogfornewuserinstartmenu","displayName":"Clear the recent programs list for new users (User)","description":"If you enable this policy setting, the recent programs list in the start menu will be blank for each new user.\r\n\r\nIf you disable or do not configure this policy, the start menu recent programs list will be pre-populated with programs for each new user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-clearrecentprogfornewuserinstartmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_clearrecentprogfornewuserinstartmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_clearrecentprogfornewuserinstartmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"03b44a69b4ddeeef":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow insecure websites to make requests to more-private network endpoints (User)","description":"Controls whether insecure websites are allowed to make requests to more-private network endpoints.\r\n\r\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\r\n\r\nA network endpoint is more private than another if:\r\n1) Its IP address is localhost and the other is not.\r\n2) Its IP address is private and the other is public.\r\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\r\n\r\nA website is deemed secure if it meets the definition of a secure context in https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts. Otherwise, it will be treated as an insecure context.\r\n\r\nWhen this policy is either not set or set to false, the default behavior for requests from insecure contexts to more-private network endpoints will depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests feature, which may be set by a field trial or on the command line.\r\n\r\nWhen this policy is set to true, insecure websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"034cb615c41487c6":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments (User)","description":"This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete.\r\n\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled.\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"039f8198884d11bc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_2","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_defaultwebusbguardsetting_3","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},"0315837b7ee7db56":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended","displayName":"Keep browsing data when creating enterprise profile by default (User)","description":"If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default.\r\n\r\nIf this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.\r\n\r\nRegardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile.\r\n\r\nThis policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_enterpriseprofilecreationkeepbrowsingdata_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"030af71b86f2992a":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls","displayName":"Allow Window Management permission on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which will automatically grant the window management permission. This will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nThis replaces the deprecated WindowPlacementAllowedForUrls policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0354b3af20829b5d":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview","displayName":"File tab | Options | Customize Ribbon | All Commands | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonxceloptionscustomizationcombinedpreviewwebpagepreview_1","displayName":"True","description":null,"helpText":null}]},"03d92b7390ba057c":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402","displayName":"XAML Files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_iz_partname2402_1","displayName":"Prompt","description":null,"helpText":null}]},"03d993cc5f68f26c":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles","displayName":"Show security warning for potentially unsafe files (User)","description":"This policy setting controls whether or not the \"Open File - Security Warning\" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).\n\nIf you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.\n\nIf you disable this policy setting, these files do not open.\n\nIf you do not configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneshowsecuritywarningforpotentiallyunsafefiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"031875c9ba239e62":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"030315c173ec1e69":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowscriptlets"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"03c139d713cd5d92":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled","displayName":"Enable search suggestions (User)","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\r\n\r\nIf you enable this policy, web search suggestions are used.\r\n\r\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\r\n\r\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_searchsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"03fa5d8d163fe07f":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed","displayName":"Allow single sign-on for Microsoft personal sites using this profile (User)","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\r\n\r\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\r\n\r\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_msawebsitessousingthisprofileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"03d9be71513a48be":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},"038e8893f1677655":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage","displayName":"Web Query dialog box home page (User)","description":"Specifies the default location of the home page for Web queries.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"03f42ad20894b1fc":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifynumberofbitstosamplewhenrecording_l_bits","displayName":"Bits: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},"03e08372b7836280":{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointbackgroundsyncintervalmultiplier_l_empty16","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"039b56f65a35cf8b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend","displayName":"Configure Outlook object model prompt when sending mail (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to send e-mail programmatically using the Outlook object model. \r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to send e-mail programmatically using the Outlook object model: \r\n\r\n- Prompt user - The user will be prompted to approve every access attempt.\r\n- Automatically approve - Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny - Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nImportant: This policy setting only applies if the ''Outlook Security Mode'' policy setting under ''Microsoft Outlook 2016\\Security\\Security Form Settings'' is configured to ''Use Outlook Security Group Policy.''\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to send mail programmatically, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsend_1","displayName":"Enabled","description":null,"helpText":null}]},"03d755b57b723276":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"03b1f0d437468d6f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16","displayName":"Trusted Location #16 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_1","displayName":"Enabled","description":null,"helpText":null}]},"03a07f31a8fbbaf5":{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat","displayName":"Turn Off Abbreviated Date Time Format (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#turnoffabbreviateddatetimeformat"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat_0","displayName":"Show abbreviated time and date format","description":"Show abbreviated time and date format","helpText":null},{"id":"user_vendor_msft_policy_config_start_turnoffabbreviateddatetimeformat_1","displayName":"Show classic time and date format","description":"Show classic time and date format","helpText":null}]},"03e697e27461d0eb":{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath","displayName":"Skip Opening Local Files with Long Paths (User)","description":"This policy controls whether Word should skip opening local files with very long paths.\n\nIf you enable this policy, Word will not open local files that have very long paths. Only enable if local files with long paths are causing issues in your environment.\n\nIf you disable or do not configure this policy, Word will open local files with long paths.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_skipopenduetolonglocalpath_1","displayName":"Enabled","description":null,"helpText":null}]},"038e1e06527d1da5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers","displayName":"Disable features not supported by specified browsers (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"56e510be-ca39-46a2-9eb2-6f1af6d4b16a","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_browser_l_disablefeaturesnotsupportedbyspecifiedbrowsers_1","displayName":"Enabled","description":null,"helpText":null}]},"03b1fa3638101ee5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_datecolon73","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"03568c638195f45f":{"id":"vendor_msft_personalization_companyname","displayName":"Company Name","description":"The name of the company to be displayed on the sign-in screen. This setting is currently available for boot to cloud shared pc mode only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Personalization-csp/"],"categoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","categoryName":"Personalization","options":null},"03694d88f6044316":{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe","displayName":"Require Network In OOBE (Device)","description":"true - Require network in OOBE, false - no network connection requirement in OOBE","helpText":null,"infoUrls":[],"categoryId":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","categoryName":"Tenant Lockdown","options":[{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe_true","displayName":"true","description":null,"helpText":null},{"id":"vendor_msft_tenantlockdown_requirenetworkinoobe_false","displayName":"false","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/05.json b/public/intune-definitions/05.json index b97a9f7c587a..c57e52dee631 100644 --- a/public/intune-definitions/05.json +++ b/public/intune-definitions/05.json @@ -1 +1 @@ -{"052962d1dc569b88":{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering","displayName":"Block tethering and access to hotspots","description":"If 'True', prevents tethering and access to portable hotspots. If 'False', Intune doesn't change or update this setting. By default, the OS might allow tethering and access to portable hotspots. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering_false","displayName":"False","description":"false","helpText":null}]},"05839256f6081425":{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked","displayName":"Block configuring mobile networks","description":"If 'True', the device is prevented from configuring mobile network settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow mobile network configuration. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked_true","displayName":"True","description":"True","helpText":null}]},"051cc026063eda9d":{"id":"com.apple.airplay_passwords_item_devicename","displayName":"Device Name","description":"The name of the AirPlay destination; used in iOS.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},"05d3359f28bd197d":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"0513b509f09a099b":{"id":"com.apple.finder_showremovablemediaondesktop","displayName":"Show Removable Media On Desktop","description":"If false, removable media can not appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showremovablemediaondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showremovablemediaondesktop_true","displayName":"True","description":null,"helpText":null}]},"0518dac68955816d":{"id":"com.apple.loginwindow_showotherusers_managed","displayName":"Show Other Users Managed","description":"If true, displays Other... when showing a list of users.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_showotherusers_managed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_showotherusers_managed_true","displayName":"True","description":null,"helpText":null}]},"05a74a325df5a8cc":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},"05fa9ebe8ba61d09":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_lcid","displayName":"Microsoft Remote Desktop LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"051dfd7175dd7035":{"id":"com.apple.mcx.filevault2_showrecoverykey","displayName":"Show Recovery Key","description":"If false, prevents display of the personal recovery key to the user after FileVault is enabled.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_showrecoverykey_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_showrecoverykey_true","displayName":"Enabled","description":null,"helpText":null}]},"05b8cad1facc0032":{"id":"com.apple.servicemanagement_rules_item_teamidentifier","displayName":"Team Identifier","description":"An additional constraint to limit the scope of the rule that is tested after matching the Rule Type and Rule Value.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},"057d5c61c8a805ef":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"0507c8001eafb8e9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on edge://extensions.\n\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\nIf the policy is set to Disallow (1), users can't turn on developer mode on the extensions page.\n\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\n\nPolicy options mapping:\n\n* Allow (0) = Allow the usage of developer mode on extensions page\n\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings_allow","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings_disallow","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},"0534be7d122e712a":{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2","displayName":"Do not throttle additional data","description":"This policy setting determines whether Windows Error Reporting (WER) sends additional, second-level report data even if a CAB file containing data about the same event types has already been uploaded to the server.\r\n\r\nIf you enable this policy setting, WER does not throttle data; that is, WER uploads additional CAB files that can contain data about the same event types as an earlier uploaded report.\r\n\r\nIf you disable or do not configure this policy setting, WER throttles data by default; that is, WER does not upload more than one CAB file for a report that contains data about the same event types.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassdatathrottling-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2_1","displayName":"Enabled","description":null,"helpText":null}]},"05194f4c4192db0e":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},"057581087fd71d90":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection","displayName":"Scan all downloaded files and attachments","description":"This policy setting allows you to configure scanning for all downloaded files and attachments.\r\n\r\n If you enable or do not configure this setting, scanning for all downloaded files and attachments will be enabled.\r\n\r\n If you disable this setting, scanning for all downloaded files and attachments will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disableioavprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection_1","displayName":"Enabled","description":null,"helpText":null}]},"05ec422f125eedc7":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection","displayName":"Microsoft Solitaire Collection","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection_1","displayName":"True","description":null,"helpText":null}]},"05ca241188f049d9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If set to Enabled, Google Chrome will\r\nallow Web Authentication requests on websites that have TLS certificates with\r\nerrors (i.e. websites considered not secure).\r\n\r\nIf the policy is set to Disabled or left unset, the default behavior of\r\nblocking such requests will apply.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts_1","displayName":"Enabled","description":null,"helpText":null}]},"056a9a37d31a38e9":{"id":"device_vendor_msft_policy_config_deliveryoptimization_domindisksizeallowedtopeer","displayName":"DO Min Disk Size Allowed To Peer","description":"Specifies the required minimum total disk size in GB for the device to use P2P.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#domindisksizeallowedtopeer"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"056e1dba713fe9d1":{"id":"device_vendor_msft_policy_config_deviceguard_enablevirtualizationbasedsecurity","displayName":"Enable Virtualization Based Security","description":"Turns On Virtualization Based Security(VBS)","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#enablevirtualizationbasedsecurity"],"categoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","categoryName":"Device Guard","options":[{"id":"device_vendor_msft_policy_config_deviceguard_enablevirtualizationbasedsecurity_0","displayName":"disable virtualization based security.","description":"disable virtualization based security.","helpText":null},{"id":"device_vendor_msft_policy_config_deviceguard_enablevirtualizationbasedsecurity_1","displayName":"enable virtualization based security.","description":"enable virtualization based security.","helpText":null}]},"054d2d1d1b910433":{"id":"device_vendor_msft_policy_config_devicelock_passwordcomplexity","displayName":"Password Complexity","description":"Password must meet complexity requirements This security setting determines whether passwords must meet complexity requirements. If this policy is enabled, passwords must meet the following minimum requirements: Not contain the user's account name or parts of the user's full name that exceed two consecutive characters Be at least six characters in length Contain characters from three of the following four categories: English uppercase characters (A through Z) English lowercase characters (a through z) Base 10 digits (0 through 9) Non-alphabetic characters (for example, !, $, #, %) Complexity requirements are enforced when passwords are changed or created.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeviceLock#passwordcomplexity"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":null},"058e87bda382e071":{"id":"device_vendor_msft_policy_config_experience_allowdevicediscovery","displayName":"Allow Device Discovery","description":"Allows users to turn on/off device discovery UX. When set to 0 , the projection pane is disabled. The Win+P and Win+K shortcut keys will not work on. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowdevicediscovery"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowdevicediscovery_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowdevicediscovery_1","displayName":"Allow","description":"Enabled.","helpText":null}]},"05e334d835870c54":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforregister","displayName":"Healthy Providers Required For Register","description":"This setting specifies the number of healthy CCD Locations required to allow a sign in. If using the default setting, users will always be allowed to sign in, even if no CCD Locations are available.\r\n\r\nIf a user signs in with no available CCD Locations, FSLogix assumes that one or more CCD Locations will become available prior to the user signing out. If a CCD Locations does not become available during the time of the user session, then the user is prevented from signing out (discussed in Healthy Provider Required For Unregister).\r\n\r\nIf it is desired to block a user from signing in and a minimum number of CCD Locations are not available, the Healthy Providers Required For Register may be set to the number of CCD Locations required for a sign in.\r\n\r\nIf the minimum number of CCD Locations required for registration aren't available, then the sign in will fail. When setting Healthy Providers Required For Register to anything other than 0, then Prevent Login With Failure and/or Preven tLogin With Temp Profile should be used in order to create the desired user experience.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\HealthyProvidersRequiredForRegister\r\nType: DWORD\r\nValues: Min = 0, Max = 4","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforregister_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforregister_1","displayName":"Enabled","description":null,"helpText":null}]},"05103f72f327070a":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessizeinmbs","displayName":"Size In MBs","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecify the size for auto-created VHD(x) files.\r\n\r\nNOTE: Default is 30,000 (30GB) which is the same as \"Not Configured\"\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\SizeInMBs\r\nType: DWORD\r\nValues: Min = 500, Max = 1000000","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessizeinmbs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessizeinmbs_1","displayName":"Enabled","description":null,"helpText":null}]},"057d63ac04c0653d":{"id":"device_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid","displayName":"Allow software to run or install even if the signature is invalid","description":"This policy setting allows you to manage whether software, such as ActiveX controls and file downloads, can be installed or run by the user even though the signature is invalid. An invalid signature might indicate that someone has tampered with the file.\n\nIf you enable this policy setting, users will be prompted to install or run files with an invalid signature.\n\nIf you disable this policy setting, users cannot run or install files with an invalid signature.\n\nIf you do not configure this policy, users can choose to run or install files with an invalid signature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsoftwarewhensignatureisinvalid"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_1","displayName":"Enabled","description":null,"helpText":null}]},"05ae980bb100879d":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowlessprivilegedsites"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"05e4c522f5b37aaa":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression","displayName":"Configure SIP compression mode","description":"\r\nDefines when to turn on SIP compression. Default: Based on adaptor speed.\r\n\r\nSetting this policy may cause an increase in sign-in time.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1","displayName":"Enabled","description":null,"helpText":null}]},"05b4d7a09424de0d":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar","description":"Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge the shortcut takes users to their Microsoft Office apps and docs.\r\n\r\nIf this policy is enabled or not configure, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\r\n\r\nIf the policy is disabled, the shortcut won't be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar_1","displayName":"Enabled","description":null,"helpText":null}]},"055a275e58e0df4c":{"id":"device_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token","description":"Microsoft Edge management service in Microsoft 365 Admin Center lets you set policy and manage users through a Microsoft Edge focused cloud-based management experience. This policy lets you specify an enrollment token that's used to register with Microsoft Edge management service and deploy the associated policies. The user must be signed into Microsoft Edge with a valid work or school account otherwise Microsoft Edge will not download the policy.\r\n\r\nIf you enable this policy, Microsoft Edge will attempt to use the specified enrollment token to register with the Microsoft Edge management service and download the published policy.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not attempt to connect to the Microsoft Edge management service.\r\n\r\nExample value: RgAAAACBbzoQDmUrRfq3WeKUoFeEBwBOqK2QPYsBT5V3lQFoKND-AAAAAAEVAAAOqK2QPYvBT5V4lQFoKMD-AAADTXvzAAAA0","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_1","displayName":"Enabled","description":null,"helpText":null}]},"054c09fb579cb0bd":{"id":"device_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be opened.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the 'EdgeSidebarAppUrlHostAllowList' (Allow specific apps to be opened in Microsoft Edge sidebar) policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"0572327d5786a1ba":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites","description":"Configure the list of URL patterns that are excluded from tracking prevention.\r\n\r\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\r\n\r\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"05acf139f27556af":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_defaultsearchproviderkeyword","displayName":"Default search provider keyword (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"058f1894fad20d59":{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseiprange","displayName":"Enterprise IP Range","description":"Sets the enterprise IP ranges that define the computers in the enterprise network. Data that comes from those computers will be considered part of the enterprise and protected. These locations will be considered a safe destination for enterprise data to be shared to. This is a comma-separated list of IPv4 and IPv6 ranges.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterpriseiprange"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":null},"05fbd8c1a3a0ecc4":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_grooveexe42","displayName":"groove.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_grooveexe42_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_grooveexe42_1","displayName":"True","description":null,"helpText":null}]},"05e6857efe4cb3f9":{"id":"device_vendor_msft_policy_config_printers_publishprinters","displayName":"Allow printers to be published","description":"Determines whether the computer's shared printers can be published in Active Directory.\n\n If you enable this setting or do not configure it, users can use the \"List in directory\" option in the Printer's Properties' Sharing tab to publish shared printers in Active Directory.\n\n If you disable this setting, this computer's shared printers cannot be published in Active Directory, and the \"List in directory\" option is not available.\n\n Note: This settings takes priority over the setting \"Automatically publish new printers in the Active Directory\".","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-publishprinters"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_publishprinters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_publishprinters_1","displayName":"Enabled","description":null,"helpText":null}]},"05686d85b9dbe7d5":{"id":"device_vendor_msft_policy_config_privacy_disableprivacyexperience","displayName":"Disable Privacy Experience","description":"Enabling this policy prevents the privacy experience from launching during user logon for new and upgraded users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#disableprivacyexperience"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_disableprivacyexperience_0","displayName":"Disabled","description":"Allow the 'choose privacy settings for your device' screen for a new user during their first logon or when an existing user logs in for the first time after an upgrade.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_disableprivacyexperience_1","displayName":"Enabled","description":"Do not allow the 'choose privacy settings for your device' screen when a new user logs in or an existing user logs in for the first time after an upgrade.","helpText":null}]},"057a844f7b10af78":{"id":"linux_platformupdatecontrols_schedule_endtime","displayName":"Platform Update Window End Time","description":"Specifies the end of the allowed time window for platform updates (24-hour clock). Select 'All Day' for no restriction. Use together with start time to define an update window.","helpText":null,"infoUrls":["https://learn.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#platform-update-preferences"],"categoryId":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","categoryName":"Platform Update","options":[{"id":"linux_platformupdatecontrols_schedule_endtime_every","displayName":"All Day","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_0","displayName":"00:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_1","displayName":"01:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_2","displayName":"02:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_3","displayName":"03:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_4","displayName":"04:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_5","displayName":"05:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_6","displayName":"06:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_7","displayName":"07:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_8","displayName":"08:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_9","displayName":"09:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_10","displayName":"10:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_11","displayName":"11:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_12","displayName":"12:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_13","displayName":"13:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_14","displayName":"14:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_15","displayName":"15:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_16","displayName":"16:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_17","displayName":"17:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_18","displayName":"18:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_19","displayName":"19:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_20","displayName":"20:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_21","displayName":"21:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_22","displayName":"22:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_23","displayName":"23:00","description":null,"helpText":null}]},"0517c089cf2a38b3":{"id":"settings_item_appanalytics","displayName":"App Analytics","description":"A dictionary that contains settings for sharing app analytics. This setting is available only for Shared iPad in iOS 9.3.2 and later.","helpText":null,"infoUrls":[],"categoryId":"5f71c40e-01aa-42d2-9c8c-7d560126cd4b","categoryName":"App Analytics","options":null},"052a4ff64581b6d2":{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_1","displayName":"Turn off AutoComplete integration with Input Panel (User)","description":"Turns off the integration of application auto complete lists with Tablet PC Input Panel in applications where this behavior is available.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, application auto complete lists will never appear next to Input Panel. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, application auto complete lists will appear next to Input Panel in applications where the functionality is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, application auto complete lists will appear next to Input Panel in applications where the functionality is available. Users will be able to configure this setting on the Text completion tab in Input Panel Options.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-autocomplete-1"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_1_1","displayName":"Enabled","description":null,"helpText":null}]},"055fcb4fb87fa576":{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_1","displayName":"Prevent Input Panel tab from appearing (User)","description":"Prevents Input Panel tab from appearing on the edge of the Tablet PC screen.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel tab will not appear on the edge of the Tablet PC screen. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel tab will appear on the edge of the Tablet PC screen. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel tab will appear on the edge of the Tablet PC screen. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-edgetarget-1"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_1_1","displayName":"Enabled","description":null,"helpText":null}]},"0532e455201ab8cc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename","displayName":"Enterprise web store name (deprecated) (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_1","displayName":"Enabled","description":null,"helpText":null}]},"0518e32bba6a44a7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of capture.\r\n\r\nNote that windowed Chrome Apps with the same origin as this site will still be allowed to be captured.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: TabCaptureAllowedByOrigins, WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"05864ea420a74189":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions","displayName":"Actions to run when the computer is idle (User)","description":"List of actions to run when the timeout from the IdleTimeout policy is reached.\r\n\r\nWarning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data.\r\n\r\nIf the IdleTimeout policy is unset, this policy has no effect.\r\n\r\nWhen the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\r\n\r\nIf this policy is empty or left unset, the IdleTimeout policy has no effect.\r\n\r\nSupported actions are:\r\n\r\n'close_browsers': close all browser windows and PWAs for this profile. Not supported on Android and iOS.\r\n\r\n'close_tabs': close all open tabs in open windows. Only supported on iOS.\r\n\r\n'show_profile_picker': show the Profile Picker window. Not supported on Android and iOS.\r\n\r\n'sign_out': Signs out the current signed in user. Only supported on iOS.\r\n\r\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings', 'clear_hosted_app_data': clear the corresponding browsing data. See the ClearBrowsingDataOnExitList policy for more details. The types supported on iOS are 'clear_browsing_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', and 'clear_autofill'\r\n\r\n'reload_pages': reload all webpages. For some pages, the user may be prompted for confirmation first. Not supported on iOS.\r\n\r\nThe user will stay signed into their Google account when deleting cookies using 'clear_cookies_and_other_site_data'.\r\n\r\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled.\r\n\r\nExample value:\r\n\r\nclose_browsers\r\nshow_profile_picker","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_1","displayName":"Enabled","description":null,"helpText":null}]},"058df7e9213ab7c9":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"0597be9beb73bb16":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls","displayName":"Allow pop-up windows on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can open pop-up windows.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"050cca3e71092a4b":{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (User)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\r\n\r\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"05f469d98fc17e31":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow_relaunchwindow","displayName":"Relaunch time window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"051bad967b503baf":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice","displayName":"Configure Writing Assistance installation and startup (User)","description":"This policy setting controls whether Writing Assistance is not installed, installed without launching automatically at startup and locked off, installed without launching automatically at startup but still user-controllable, installed and allowed to launch automatically at startup and locked on, or installed with startup on by default but still user-controllable.\n\nIf you enable this policy setting, choose one of the following options:\n- Not installed: Writing Assistance is removed and should not appear in Start.\n- Installed, don't launch at startup: Writing Assistance remains installed, but automatic startup launches are blocked and users cannot turn startup back on.\n- Installed, don't launch at startup by default (users can enable): Writing Assistance remains installed, automatic startup launches are off by default, and users can turn startup on later.\n- Installed, launch at startup: Writing Assistance remains installed, automatic startup launches are allowed, and users cannot turn startup off.\n- Installed, launch at startup by default (users can disable): Writing Assistance remains installed, automatic startup launches are on by default, and users can turn startup off later.\n\nIf you disable or don't configure this policy setting, Writing Assistance follows its default install and startup behavior, and users can control startup themselves.\n\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_1","displayName":"Enabled","description":null,"helpText":null}]},"05f58f545b92eb9b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink_l_onlycontainingalink357","displayName":"Only containing a link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},"051eb875808a6574":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowfriendly486","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"05c4e9d3218714f0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback","displayName":"Send Office Feedback (User)","description":"This policy setting manages the Office Feedback Tool (a.k.a. Send a Smile). The Office Feedback Tool allows users to provide Microsoft feedback regarding their positive and negative experiences when using Office.\r\n\r\nIf you enable this policy setting, the Office Feedback Tool will be turned on in all Office applications in which the tool is available. They can access the tool through the Smile button located in the top right corner of the Office application.\r\n\r\nIf you disable this policy setting, the Office Feedback Tool will be turned off. Users will not see the Smile button in any of the Office applications in which the tool is available.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback_1","displayName":"Enabled","description":null,"helpText":null}]},"05c4df4964a46bed":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_md5","displayName":"MD5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null}]},"05e5cdaae69f5c5e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_pathcolon01","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"058f3bdcefc788d4":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir","displayName":"Set the default location for the OneDrive folder (User)","description":"This setting lets you set a specific path as the default location of the OneDrive folder on users' computers. By default, the path is under %userprofile%.\r\n\r\nIf you enable this setting, the default location of the OneDrive - {organization name} folder will be the path that you specify in the OneDrive.admx file. To prevent users from changing the location you specify, enable the \"Prevent users from changing the location of their OneDrive folder\" setting.\r\n\r\nIf you disable or do not configure this setting, the default location of the OneDrive - {organization name} folder will be in %userprofile%.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_1","displayName":"Enabled","description":null,"helpText":null}]},"05b7b99a3c6ce23f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts","displayName":"Save calendar sync conflicts (User)","description":"This policy setting allows you to save calendar sync conflicts.\r\n\r\nIf you enable this policy setting, Outlook will save calendar sync conflicts.\r\n\r\nIf you disable or do not configure this policy setting, calendar sync conflicts are not saved by default.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},"051696b7c0d5fade":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2_l_removedextensions25","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},"056ebc607a1e98ca":{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported","displayName":"Maximum Groups Supported (User)","description":"This policy setting controls the maximum number of groups that are accessible through the Navigation Pane in Outlook for Windows.\r\n\r\nIf you enable this policy setting, only the number of groups set in the Groups Count will be shown in the Navigation Pane. \r\n\r\nIf you don’t enable this policy setting, the maximum number of groups displayed defaults to 1000.\r\n ","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_1","displayName":"Enabled","description":null,"helpText":null}]},"0521e0090e6e9222":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"050fc3344182677f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_l_mrutemplatelistlength39","displayName":"Most Recently Used Template List Length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},"0545f5ef18bc23b9":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_l_cachelocation37","displayName":"Local Project Cache Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":null},"05bf728a57595eca":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"05982befbc4e9615":{"id":"vendor_msft_firewall_mdmstore_privateprofile_logmaxfilesize","displayName":"Log Max File Size","description":"This value specifies the size, in kilobytes, of the log file where dropped packets and successful connections are logged. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file +{"052962d1dc569b88":{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering","displayName":"Block tethering and access to hotspots","description":"If 'True', prevents tethering and access to portable hotspots. If 'False', Intune doesn't change or update this setting. By default, the OS might allow tethering and access to portable hotspots. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.cellularblockwifitethering_false","displayName":"False","description":"false","helpText":null}]},"05839256f6081425":{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked","displayName":"Block configuring mobile networks","description":"If 'True', the device is prevented from configuring mobile network settings. If 'False', Intune doesn't change or update this setting. By default, the OS might allow mobile network configuration. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.mobilenetworksconfigblocked_true","displayName":"True","description":"True","helpText":null}]},"051cc026063eda9d":{"id":"com.apple.airplay_passwords_item_devicename","displayName":"Device Name","description":"The name of the AirPlay destination; used in iOS.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},"05d3359f28bd197d":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-curfew_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"0513b509f09a099b":{"id":"com.apple.finder_showremovablemediaondesktop","displayName":"Show Removable Media On Desktop","description":"If false, removable media can not appear on the desktop.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_showremovablemediaondesktop_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_showremovablemediaondesktop_true","displayName":"True","description":null,"helpText":null}]},"0518dac68955816d":{"id":"com.apple.loginwindow_showotherusers_managed","displayName":"Show Other Users Managed","description":"If true, displays Other... when showing a list of users.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_showotherusers_managed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_showotherusers_managed_true","displayName":"True","description":null,"helpText":null}]},"05a74a325df5a8cc":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver","displayName":"Update channel override","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_2","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_manifestserver_3","displayName":"Change Freeze","description":null,"helpText":null}]},"05fa9ebe8ba61d09":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_lcid","displayName":"Microsoft Remote Desktop LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"051dfd7175dd7035":{"id":"com.apple.mcx.filevault2_showrecoverykey","displayName":"Show Recovery Key","description":"If false, prevents display of the personal recovery key to the user after FileVault is enabled.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_showrecoverykey_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_showrecoverykey_true","displayName":"Enabled","description":null,"helpText":null}]},"05b8cad1facc0032":{"id":"com.apple.servicemanagement_rules_item_teamidentifier","displayName":"Team Identifier","description":"An additional constraint to limit the scope of the rule that is tested after matching the Rule Type and Rule Value.","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},"057d5c61c8a805ef":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"0507c8001eafb8e9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on edge://extensions.\n\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\nIf the policy is set to Disallow (1), users can't turn on developer mode on the extensions page.\n\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\n\nPolicy options mapping:\n\n* Allow (0) = Allow the usage of developer mode on extensions page\n\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings_allow","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensiondevelopermodesettings_disallow","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},"056b6fdcc31c7959":{"id":"contentcaching_keepawake","displayName":"Keep Awake","description":"If `true`, the system prevents the computer from sleeping as long as Content Caching is on (System Preferences > Sharing > Content Caching is on). Customers who want Content Caching to be as available as much as possible should turn this setting on.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_keepawake_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_keepawake_true","displayName":"Enabled","description":null,"helpText":null}]},"0534be7d122e712a":{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2","displayName":"Do not throttle additional data","description":"This policy setting determines whether Windows Error Reporting (WER) sends additional, second-level report data even if a CAB file containing data about the same event types has already been uploaded to the server.\r\n\r\nIf you enable this policy setting, WER does not throttle data; that is, WER uploads additional CAB files that can contain data about the same event types as an earlier uploaded report.\r\n\r\nIf you disable or do not configure this policy setting, WER throttles data by default; that is, WER does not upload more than one CAB file for a report that contains data about the same event types.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassdatathrottling-2"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_2_1","displayName":"Enabled","description":null,"helpText":null}]},"05194f4c4192db0e":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_5_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},"057581087fd71d90":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection","displayName":"Scan all downloaded files and attachments","description":"This policy setting allows you to configure scanning for all downloaded files and attachments.\r\n\r\n If you enable or do not configure this setting, scanning for all downloaded files and attachments will be enabled.\r\n\r\n If you disable this setting, scanning for all downloaded files and attachments will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disableioavprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disableioavprotection_1","displayName":"Enabled","description":null,"helpText":null}]},"05ec422f125eedc7":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection","displayName":"Microsoft Solitaire Collection","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftsolitairecollection_1","displayName":"True","description":null,"helpText":null}]},"05ca241188f049d9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If set to Enabled, Google Chrome will\r\nallow Web Authentication requests on websites that have TLS certificates with\r\nerrors (i.e. websites considered not secure).\r\n\r\nIf the policy is set to Disabled or left unset, the default behavior of\r\nblocking such requests will apply.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_allowwebauthnwithbrokentlscerts_1","displayName":"Enabled","description":null,"helpText":null}]},"056a9a37d31a38e9":{"id":"device_vendor_msft_policy_config_deliveryoptimization_domindisksizeallowedtopeer","displayName":"DO Min Disk Size Allowed To Peer","description":"Specifies the required minimum total disk size in GB for the device to use P2P.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#domindisksizeallowedtopeer"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"056e1dba713fe9d1":{"id":"device_vendor_msft_policy_config_deviceguard_enablevirtualizationbasedsecurity","displayName":"Enable Virtualization Based Security","description":"Turns On Virtualization Based Security(VBS)","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#enablevirtualizationbasedsecurity"],"categoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","categoryName":"Device Guard","options":[{"id":"device_vendor_msft_policy_config_deviceguard_enablevirtualizationbasedsecurity_0","displayName":"disable virtualization based security.","description":"disable virtualization based security.","helpText":null},{"id":"device_vendor_msft_policy_config_deviceguard_enablevirtualizationbasedsecurity_1","displayName":"enable virtualization based security.","description":"enable virtualization based security.","helpText":null}]},"054d2d1d1b910433":{"id":"device_vendor_msft_policy_config_devicelock_passwordcomplexity","displayName":"Password Complexity","description":"Password must meet complexity requirements This security setting determines whether passwords must meet complexity requirements. If this policy is enabled, passwords must meet the following minimum requirements: Not contain the user's account name or parts of the user's full name that exceed two consecutive characters Be at least six characters in length Contain characters from three of the following four categories: English uppercase characters (A through Z) English lowercase characters (a through z) Base 10 digits (0 through 9) Non-alphabetic characters (for example, !, $, #, %) Complexity requirements are enforced when passwords are changed or created.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeviceLock#passwordcomplexity"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":null},"058e87bda382e071":{"id":"device_vendor_msft_policy_config_experience_allowdevicediscovery","displayName":"Allow Device Discovery","description":"Allows users to turn on/off device discovery UX. When set to 0 , the projection pane is disabled. The Win+P and Win+K shortcut keys will not work on. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowdevicediscovery"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowdevicediscovery_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowdevicediscovery_1","displayName":"Allow","description":"Enabled.","helpText":null}]},"05e334d835870c54":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforregister","displayName":"Healthy Providers Required For Register","description":"This setting specifies the number of healthy CCD Locations required to allow a sign in. If using the default setting, users will always be allowed to sign in, even if no CCD Locations are available.\r\n\r\nIf a user signs in with no available CCD Locations, FSLogix assumes that one or more CCD Locations will become available prior to the user signing out. If a CCD Locations does not become available during the time of the user session, then the user is prevented from signing out (discussed in Healthy Provider Required For Unregister).\r\n\r\nIf it is desired to block a user from signing in and a minimum number of CCD Locations are not available, the Healthy Providers Required For Register may be set to the number of CCD Locations required for a sign in.\r\n\r\nIf the minimum number of CCD Locations required for registration aren't available, then the sign in will fail. When setting Healthy Providers Required For Register to anything other than 0, then Prevent Login With Failure and/or Preven tLogin With Temp Profile should be used in order to create the desired user experience.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\HealthyProvidersRequiredForRegister\r\nType: DWORD\r\nValues: Min = 0, Max = 4","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforregister_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforregister_1","displayName":"Enabled","description":null,"helpText":null}]},"05103f72f327070a":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessizeinmbs","displayName":"Size In MBs","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecify the size for auto-created VHD(x) files.\r\n\r\nNOTE: Default is 30,000 (30GB) which is the same as \"Not Configured\"\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\SizeInMBs\r\nType: DWORD\r\nValues: Min = 500, Max = 1000000","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessizeinmbs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessizeinmbs_1","displayName":"Enabled","description":null,"helpText":null}]},"057d63ac04c0653d":{"id":"device_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid","displayName":"Allow software to run or install even if the signature is invalid","description":"This policy setting allows you to manage whether software, such as ActiveX controls and file downloads, can be installed or run by the user even though the signature is invalid. An invalid signature might indicate that someone has tampered with the file.\n\nIf you enable this policy setting, users will be prompted to install or run files with an invalid signature.\n\nIf you disable this policy setting, users cannot run or install files with an invalid signature.\n\nIf you do not configure this policy, users can choose to run or install files with an invalid signature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsoftwarewhensignatureisinvalid"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_1","displayName":"Enabled","description":null,"helpText":null}]},"05ae980bb100879d":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowlessprivilegedsites"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"05e4c522f5b37aaa":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression","displayName":"Configure SIP compression mode","description":"\r\nDefines when to turn on SIP compression. Default: Based on adaptor speed.\r\n\r\nSetting this policy may cause an increase in sign-in time.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysipcompression_1","displayName":"Enabled","description":null,"helpText":null}]},"05b4d7a09424de0d":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar","description":"Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge the shortcut takes users to their Microsoft Office apps and docs.\r\n\r\nIf this policy is enabled or not configure, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\r\n\r\nIf the policy is disabled, the shortcut won't be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_showofficeshortcutinfavoritesbar_1","displayName":"Enabled","description":null,"helpText":null}]},"055a275e58e0df4c":{"id":"device_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token","description":"Microsoft Edge management service in Microsoft 365 Admin Center lets you set policy and manage users through a Microsoft Edge focused cloud-based management experience. This policy lets you specify an enrollment token that's used to register with Microsoft Edge management service and deploy the associated policies. The user must be signed into Microsoft Edge with a valid work or school account otherwise Microsoft Edge will not download the policy.\r\n\r\nIf you enable this policy, Microsoft Edge will attempt to use the specified enrollment token to register with the Microsoft Edge management service and download the published policy.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not attempt to connect to the Microsoft Edge management service.\r\n\r\nExample value: RgAAAACBbzoQDmUrRfq3WeKUoFeEBwBOqK2QPYsBT5V3lQFoKND-AAAAAAEVAAAOqK2QPYvBT5V4lQFoKMD-AAADTXvzAAAA0","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_1","displayName":"Enabled","description":null,"helpText":null}]},"054c09fb579cb0bd":{"id":"device_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be opened.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the 'EdgeSidebarAppUrlHostAllowList' (Allow specific apps to be opened in Microsoft Edge sidebar) policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"0572327d5786a1ba":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites","description":"Configure the list of URL patterns that are excluded from tracking prevention.\r\n\r\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\r\n\r\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"05acf139f27556af":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_defaultsearchproviderkeyword","displayName":"Default search provider keyword (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"058f1894fad20d59":{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseiprange","displayName":"Enterprise IP Range","description":"Sets the enterprise IP ranges that define the computers in the enterprise network. Data that comes from those computers will be considered part of the enterprise and protected. These locations will be considered a safe destination for enterprise data to be shared to. This is a comma-separated list of IPv4 and IPv6 ranges.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterpriseiprange"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":null},"05fbd8c1a3a0ecc4":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_grooveexe42","displayName":"groove.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_grooveexe42_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_grooveexe42_1","displayName":"True","description":null,"helpText":null}]},"05e6857efe4cb3f9":{"id":"device_vendor_msft_policy_config_printers_publishprinters","displayName":"Allow printers to be published","description":"Determines whether the computer's shared printers can be published in Active Directory.\n\n If you enable this setting or do not configure it, users can use the \"List in directory\" option in the Printer's Properties' Sharing tab to publish shared printers in Active Directory.\n\n If you disable this setting, this computer's shared printers cannot be published in Active Directory, and the \"List in directory\" option is not available.\n\n Note: This settings takes priority over the setting \"Automatically publish new printers in the Active Directory\".","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-publishprinters"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_publishprinters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_publishprinters_1","displayName":"Enabled","description":null,"helpText":null}]},"05686d85b9dbe7d5":{"id":"device_vendor_msft_policy_config_privacy_disableprivacyexperience","displayName":"Disable Privacy Experience","description":"Enabling this policy prevents the privacy experience from launching during user logon for new and upgraded users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#disableprivacyexperience"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_disableprivacyexperience_0","displayName":"Disabled","description":"Allow the 'choose privacy settings for your device' screen for a new user during their first logon or when an existing user logs in for the first time after an upgrade.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_disableprivacyexperience_1","displayName":"Enabled","description":"Do not allow the 'choose privacy settings for your device' screen when a new user logs in or an existing user logs in for the first time after an upgrade.","helpText":null}]},"057a844f7b10af78":{"id":"linux_platformupdatecontrols_schedule_endtime","displayName":"Platform Update Window End Time","description":"Specifies the end of the allowed time window for platform updates (24-hour clock). Select 'All Day' for no restriction. Use together with start time to define an update window.","helpText":null,"infoUrls":["https://learn.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#platform-update-preferences"],"categoryId":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","categoryName":"Platform Update","options":[{"id":"linux_platformupdatecontrols_schedule_endtime_every","displayName":"All Day","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_0","displayName":"00:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_1","displayName":"01:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_2","displayName":"02:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_3","displayName":"03:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_4","displayName":"04:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_5","displayName":"05:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_6","displayName":"06:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_7","displayName":"07:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_8","displayName":"08:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_9","displayName":"09:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_10","displayName":"10:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_11","displayName":"11:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_12","displayName":"12:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_13","displayName":"13:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_14","displayName":"14:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_15","displayName":"15:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_16","displayName":"16:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_17","displayName":"17:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_18","displayName":"18:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_19","displayName":"19:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_20","displayName":"20:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_21","displayName":"21:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_22","displayName":"22:00","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_endtime_23","displayName":"23:00","description":null,"helpText":null}]},"0517c089cf2a38b3":{"id":"settings_item_appanalytics","displayName":"App Analytics","description":"A dictionary that contains settings for sharing app analytics. This setting is available only for Shared iPad in iOS 9.3.2 and later.","helpText":null,"infoUrls":[],"categoryId":"5f71c40e-01aa-42d2-9c8c-7d560126cd4b","categoryName":"App Analytics","options":null},"052a4ff64581b6d2":{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_1","displayName":"Turn off AutoComplete integration with Input Panel (User)","description":"Turns off the integration of application auto complete lists with Tablet PC Input Panel in applications where this behavior is available.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, application auto complete lists will never appear next to Input Panel. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, application auto complete lists will appear next to Input Panel in applications where the functionality is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, application auto complete lists will appear next to Input Panel in applications where the functionality is available. Users will be able to configure this setting on the Text completion tab in Input Panel Options.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-autocomplete-1"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_autocomplete_1_1","displayName":"Enabled","description":null,"helpText":null}]},"055fcb4fb87fa576":{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_1","displayName":"Prevent Input Panel tab from appearing (User)","description":"Prevents Input Panel tab from appearing on the edge of the Tablet PC screen.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel tab will not appear on the edge of the Tablet PC screen. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel tab will appear on the edge of the Tablet PC screen. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel tab will appear on the edge of the Tablet PC screen. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-edgetarget-1"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_edgetarget_1_1","displayName":"Enabled","description":null,"helpText":null}]},"0532e455201ab8cc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename","displayName":"Enterprise web store name (deprecated) (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_1","displayName":"Enabled","description":null,"helpText":null}]},"0518e32bba6a44a7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this level of capture.\r\n\r\nNote that windowed Chrome Apps with the same origin as this site will still be allowed to be captured.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: TabCaptureAllowedByOrigins, WindowCaptureAllowedByOrigins, ScreenCaptureAllowedByOrigins, ScreenCaptureAllowed.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"05864ea420a74189":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions","displayName":"Actions to run when the computer is idle (User)","description":"List of actions to run when the timeout from the IdleTimeout policy is reached.\r\n\r\nWarning: Setting this policy can impact and permanently remove local personal data. It is recommended to test your settings before deploying to prevent accidental deletion of personal data.\r\n\r\nIf the IdleTimeout policy is unset, this policy has no effect.\r\n\r\nWhen the timeout from the IdleTimeout policy is reached, the browser runs the actions configured in this policy.\r\n\r\nIf this policy is empty or left unset, the IdleTimeout policy has no effect.\r\n\r\nSupported actions are:\r\n\r\n'close_browsers': close all browser windows and PWAs for this profile. Not supported on Android and iOS.\r\n\r\n'close_tabs': close all open tabs in open windows. Only supported on iOS.\r\n\r\n'show_profile_picker': show the Profile Picker window. Not supported on Android and iOS.\r\n\r\n'sign_out': Signs out the current signed in user. Only supported on iOS.\r\n\r\n'clear_browsing_history', 'clear_download_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', 'clear_autofill', 'clear_site_settings', 'clear_hosted_app_data': clear the corresponding browsing data. See the ClearBrowsingDataOnExitList policy for more details. The types supported on iOS are 'clear_browsing_history', 'clear_cookies_and_other_site_data', 'clear_cached_images_and_files', 'clear_password_signing', and 'clear_autofill'\r\n\r\n'reload_pages': reload all webpages. For some pages, the user may be prompted for confirmation first. Not supported on iOS.\r\n\r\nThe user will stay signed into their Google account when deleting cookies using 'clear_cookies_and_other_site_data'.\r\n\r\nSetting 'clear_browsing_history', 'clear_password_signing', 'clear_autofill', and 'clear_site_settings' will disable sync for the respective data types if neither `Chrome Sync` is disabled by setting the SyncDisabled policy nor BrowserSignin is disabled.\r\n\r\nExample value:\r\n\r\nclose_browsers\r\nshow_profile_picker","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeoutactions_1","displayName":"Enabled","description":null,"helpText":null}]},"058df7e9213ab7c9":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_l_excel9597workbooksandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"0597be9beb73bb16":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls","displayName":"Allow pop-up windows on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can open pop-up windows.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPopupsSetting' (Default pop-up window setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"050cca3e71092a4b":{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (User)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\r\n\r\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_recommended_newpdfreaderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"05f469d98fc17e31":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_relaunchwindow_relaunchwindow","displayName":"Relaunch time window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"051bad967b503baf":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice","displayName":"Configure Writing Assistance installation and startup (User)","description":"This policy setting controls whether Writing Assistance is not installed, installed without launching automatically at startup and locked off, installed without launching automatically at startup but still user-controllable, installed and allowed to launch automatically at startup and locked on, or installed with startup on by default but still user-controllable.\n\nIf you enable this policy setting, choose one of the following options:\n- Not installed: Writing Assistance is removed and should not appear in Start.\n- Installed, don't launch at startup: Writing Assistance remains installed, but automatic startup launches are blocked and users cannot turn startup back on.\n- Installed, don't launch at startup by default (users can enable): Writing Assistance remains installed, automatic startup launches are off by default, and users can turn startup on later.\n- Installed, launch at startup: Writing Assistance remains installed, automatic startup launches are allowed, and users cannot turn startup off.\n- Installed, launch at startup by default (users can disable): Writing Assistance remains installed, automatic startup launches are on by default, and users can turn startup off later.\n\nIf you disable or don't configure this policy setting, Writing Assistance follows its default install and startup behavior, and users can control startup themselves.\n\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for Enterprise.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantinstallandstartupadminchoice_1","displayName":"Enabled","description":null,"helpText":null}]},"05f58f545b92eb9b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontainingalink_l_onlycontainingalink357","displayName":"Only containing a link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},"051eb875808a6574":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowfriendly486","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"05c4e9d3218714f0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback","displayName":"Send Office Feedback (User)","description":"This policy setting manages the Office Feedback Tool (a.k.a. Send a Smile). The Office Feedback Tool allows users to provide Microsoft feedback regarding their positive and negative experiences when using Office.\r\n\r\nIf you enable this policy setting, the Office Feedback Tool will be turned on in all Office applications in which the tool is available. They can access the tool through the Smile button located in the top right corner of the Office application.\r\n\r\nIf you disable this policy setting, the Office Feedback Tool will be turned off. Users will not see the Smile button in any of the Office applications in which the tool is available.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendfeedback_1","displayName":"Enabled","description":null,"helpText":null}]},"05c4df4964a46bed":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_md5","displayName":"MD5","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null}]},"05e5cdaae69f5c5e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc01_l_pathcolon01","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"058f3bdcefc788d4":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir","displayName":"Set the default location for the OneDrive folder (User)","description":"This setting lets you set a specific path as the default location of the OneDrive folder on users' computers. By default, the path is under %userprofile%.\r\n\r\nIf you enable this setting, the default location of the OneDrive - {organization name} folder will be the path that you specify in the OneDrive.admx file. To prevent users from changing the location you specify, enable the \"Prevent users from changing the location of their OneDrive folder\" setting.\r\n\r\nIf you disable or do not configure this setting, the default location of the OneDrive - {organization name} folder will be in %userprofile%.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_1","displayName":"Enabled","description":null,"helpText":null}]},"05b7b99a3c6ce23f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts","displayName":"Save calendar sync conflicts (User)","description":"This policy setting allows you to save calendar sync conflicts.\r\n\r\nIf you enable this policy setting, Outlook will save calendar sync conflicts.\r\n\r\nIf you disable or do not configure this policy setting, calendar sync conflicts are not saved by default.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_savecalendarconflicts_1","displayName":"Enabled","description":null,"helpText":null}]},"051696b7c0d5fade":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2removefilepolicy_v2_l_removedextensions25","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},"056ebc607a1e98ca":{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported","displayName":"Maximum Groups Supported (User)","description":"This policy setting controls the maximum number of groups that are accessible through the Navigation Pane in Outlook for Windows.\r\n\r\nIf you enable this policy setting, only the number of groups set in the Groups Count will be shown in the Navigation Pane. \r\n\r\nIf you don’t enable this policy setting, the maximum number of groups displayed defaults to 1000.\r\n ","helpText":"","infoUrls":[],"categoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","categoryName":"Outlook Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_outlookoptions_l_specifymaxgroupssupported_1","displayName":"Enabled","description":null,"helpText":null}]},"0521e0090e6e9222":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon21","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"050fc3344182677f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_l_mrutemplatelistlength39","displayName":"Most Recently Used Template List Length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},"0545f5ef18bc23b9":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_l_cachelocation37","displayName":"Local Project Cache Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":null},"05bf728a57595eca":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"05982befbc4e9615":{"id":"vendor_msft_firewall_mdmstore_privateprofile_logmaxfilesize","displayName":"Log Max File Size","description":"This value specifies the size, in kilobytes, of the log file where dropped packets and successful connections are logged. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/07.json b/public/intune-definitions/07.json index 0a21ff78c2ed..a6d0bb8749c1 100644 --- a/public/intune-definitions/07.json +++ b/public/intune-definitions/07.json @@ -1 +1 @@ -{"072ff49a140aad82":{"id":"ade_setupassistant_multitasking","displayName":"Multitasking","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_multitasking_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_multitasking_1","displayName":"Show","description":null,"helpText":null}]},"07e89ad49db2b4c7":{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype","displayName":"Required password type","description":"Set the password’s complexity requirements. Additional password requirements will become available based on your selection. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level). For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-fx#device-password"],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},"07ace6de15d77e50":{"id":"com.apple.applicationaccess_allowcloudaddressbook","displayName":"Allow Cloud Address Book","description":"If false, disables iCloud Address Book services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudaddressbook_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudaddressbook_true","displayName":"True","description":null,"helpText":null}]},"07c44d7883fbc7e0":{"id":"com.apple.caldav.account_caldavusername","displayName":"Cal DAV Username","description":"The user name for logins.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},"0700fd37c3e8a9e6":{"id":"com.apple.managedclient.preferences_disabledonotforward","displayName":"Disable 'Do Not Forward' options","description":"Prevent users from applying the Do Not Forward option to emails when using Microsoft 365 Message Encryption.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-do-not-forward"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disabledonotforward_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disabledonotforward_true","displayName":"True","description":null,"helpText":null}]},"07e87ee50e1b1445":{"id":"com.apple.managedclient.preferences_personalizationreportingenabled","displayName":"Allow personalization of ads, search and news by sending browsing history to Microsoft","description":"This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history to be used for personalizing advertising, search, news and other Microsoft services.\n\nThis setting is only available for users with a Microsoft account. This setting is not available for child accounts or enterprise accounts.\n\nIf you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge will default to the user’s preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#personalizationreportingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_personalizationreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_personalizationreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"07e47e03eac1ca2e":{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring","displayName":"Wake On Modem Ring","description":"If true, enables \"Wake for modem ring.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring_1","displayName":"True","description":null,"helpText":null}]},"077311fcd2f31fd1":{"id":"com.apple.mcx.timemachine_backupsizemb","displayName":"Backup Size MB","description":"The backup size limit, in megabytes. Set to 0 for unlimited.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},"0733b07ab71007fe":{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_comment","displayName":"Comment","description":"Not used.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"0775a10e037209bd":{"id":"com.microsoft.edge.mamedgeappconfigsettings.urlallowlist","displayName":"Define a list of allowed URLs","description":"Setting the policy provides access to the listed URLs as exceptions to \"URLBlocklist\".\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can use this policy to open exceptions to restrictive blocklists. For example, you can include '*' in the blocklist to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\n\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the blocked list.\n\nThis policy is limited to 1000 entries; subsequent entries are ignored.\n\nThis policy also allows the browser to automatically invoke external applications registered as protocol handlers for protocols like \"tel:\" or \"ssh:\".\n\nIf you don't configure this policy, there are no exceptions to the blocklist in the \"URLBlocklist\" policy.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"072183d8715d5fb9":{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder_pol_sslciphersuiteorder","displayName":"SSL Cipher Suites","description":null,"helpText":"","infoUrls":[],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":null},"07fb836feab20136":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4_1","displayName":"True","description":null,"helpText":null}]},"07723ec2c8501094":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity","displayName":"Configure IP security policy processing","description":"This policy setting determines when IP security policies are updated.\r\n\r\nThis policy setting affects all policies that use the IP security component of Group Policy, such as policies in Computer Configuration\\Windows Settings\\Security Settings\\IP Security Policies on Local Machine.\r\n\r\nThis policy setting overrides customized settings that the program implementing the IP security policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-ipsecurity"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},"07369fdfd716346e":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet","displayName":"Allow operation while in public network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet_1","displayName":"True","description":null,"helpText":null}]},"0734d14df1fb30aa":{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy","displayName":"Automatic Maintenance Activation Boundary","description":"\r\n This policy setting allows you to configure Automatic Maintenance activation boundary.\r\n\r\n The maintenance activation boundary is the daily schduled time at which Automatic Maintenance starts\r\n\r\n If you enable this policy setting, this will override the default daily scheduled time as specified in Security and Maintenance/Automatic Maintenance Control Panel.\r\n\r\n If you disable or do not configure this policy setting, the daily scheduled time as specified in Security and Maintenance/Automatic Maintenance Control Panel will apply.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msched#admx-msched-activationboundarypolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"070012fbf87da21f":{"id":"device_vendor_msft_policy_config_admx_msi_msilogging_msilogging","displayName":"Logging","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":null},"07bdcb24c24caed1":{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth","displayName":"Turn on bandwidth optimization","description":"This policy setting allows you to improve performance in low bandwidth scenarios.\r\n\r\nThis setting is incrementally scaled from \"No optimization\" to \"Full optimization\". Each incremental setting includes the previous optimization setting.\r\n\r\nFor example:\r\n\r\n\"Turn off background\" will include the following optimizations:\r\n-No full window drag\r\n-Turn off background\r\n\r\n\"Full optimization\" will include the following optimizations:\r\n-Use 16-bit color (8-bit color in Windows Vista)\r\n-Turn off font smoothing (not supported in Windows Vista)\r\n-No full window drag\r\n-Turn off background\r\n\r\nIf you enable this policy setting, bandwidth optimization occurs at the level specified.\r\n\r\nIf you disable this policy setting, application-based settings are used.\r\n\r\nIf you do not configure this policy setting, application-based settings are used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-remoteassistance#admx-remoteassistance-ra-optimize-bandwidth"],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_1","displayName":"Enabled","description":null,"helpText":null}]},"07ad19570f307597":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext","displayName":"Idle session limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_432000000","displayName":"5 days","description":null,"helpText":null}]},"073d81c8e1200424":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup","displayName":"Publisher 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Publisher 2013.\r\nMicrosoft Publisher 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Publisher 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Publisher 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Publisher 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013publisherbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"07d13c696bbca14a":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"07dee3f1b23c6221":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for image URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it.\r\n\r\nLeaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"07a703072f57238b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl_browserswitcherexternalgreylisturl","displayName":"URL of an XML file that contains URLs that should never trigger a browser switch. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"07a2d6fa343c4226":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls_webusbaskforurlsdesc","displayName":"Allow WebUSB on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"077d6fb4f199f35b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"0726e7bb82198fa8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_cacertificatesdesc","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"071e6356615c837f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessAllowedForUrls, this policy takes precedence.\r\n\r\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0706a7c195807b65":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled","displayName":"Control Javascript setTimeout() function minimum timeout.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"07997e3914dbf7d9":{"id":"device_vendor_msft_policy_config_connectivity_allowphonepclinking","displayName":"Allow Phone PC Linking","description":"This policy allows IT admins to turn off the ability to Link a Phone with a PC to continue tasks, such as reading, email, and other tasks that require linking between Phone and PC. If you enable this policy setting, the Windows device will be able to enroll in Phone-PC linking functionality and participate in 'Continue on PC experiences'. If you disable this policy setting, the Windows device is not allowed to be linked to phones, will remove itself from the device list of any linked Phones, and cannot participate in 'Continue on PC experiences'. If you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-connectivity#allowphonepclinking"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"device_vendor_msft_policy_config_connectivity_allowphonepclinking_0","displayName":"Block","description":"Do not link.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowphonepclinking_1","displayName":"Allow","description":"Allow phone-PC linking.","helpText":null}]},"0747321cd94e3e8b":{"id":"device_vendor_msft_policy_config_connectivity_hardeneduncpaths_pol_hardenedpaths_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"643081a4-132d-463e-9d86-c8650cb2a011","categoryName":"Network Provider","options":null},"071550208a8f36da":{"id":"device_vendor_msft_policy_config_internetexplorer_disablehtmlapplication","displayName":"Disable HTML Application","description":"This policy setting specifies if running the HTML Application (HTA file) is blocked or allowed.\n\nIf you enable this policy setting, running the HTML Application (HTA file) will be blocked.\n\nIf you disable or do not configure this policy setting, running the HTML Application (HTA file) is allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablehtmlapplication"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablehtmlapplication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablehtmlapplication_1","displayName":"Enabled","description":null,"helpText":null}]},"07f5014d1acede75":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneinitializeandscriptactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"0704063b9663245b":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"077438add807ded3":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard use on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"07e58c0fa6d08078":{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled","displayName":"Enable Discover access to page contents for AAD profiles (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy has been obsoleted as of Edge 127. Two new Edge Policies have taken its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles), and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles).\r\n\r\nThis policy did not allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allowed force-disabling of Copilot page access.\r\n\r\nThis policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. In order to summarize pages and interact with text selections, it needs to be able to access the page contents. When enabled, page contents will be sent to Bing. This policy does not affect MSA profiles.\r\n\r\nIf you enable or don't configure this policy, Discover will have access to page contents.\r\n\r\nIf you disable this policy, Discover will not be able to access page contents.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"078f45c903fd6438":{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},"07eb04f051dee482":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors.","description":"This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\r\n\r\nIf you enable this policy or don't set it, Microsoft Edge will enable these security protections for all connections.\r\n\r\nIf you disable this policy, Microsoft Edge will disable these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\r\n\r\nThis policy may be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED. A later version of Microsoft Edge will enable this option by default.\r\n\r\nAfter it is enabled by default, administrators who need more time to upgrade affected proxies may use this policy to temporarily disable this security feature. This policy will be removed after version 85.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"071162136a8ff561":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault","displayName":"Configure Automatic HTTPS","description":"This policy lets you manage settings for 'AutomaticHttpsDefault' (Configure Automatic HTTPS), which switches connections from HTTP to HTTPS.\r\n\r\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\r\n\r\nNote: The 'UpgradeCapableDomains' configuration requires a component list, and will not upgrade these connections if 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) is set to 'Disabled'.\r\n\r\nIf you don't configure this policy, 'AutomaticHttpsDefault' will be enabled, and will only upgrade connections on domains likely to support HTTPS.\r\n\r\nPolicy options mapping:\r\n\r\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\r\n\r\n* UpgradeCapableDomains (1) = Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\r\n\r\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},"073fd4386c28d112":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices","description":"Setting the policy lets you list sites that are automatically granted permission to access USB serial devices with vendor and product IDs that match the vendor_id and product_id fields.\r\n\r\nOptionally you can omit the product_id field. This enables site access to all the vendor's devices. When you provide a product ID, then you give the site access to a specific device from the vendor but not all devices.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the 'WebUsbAllowDevicesForUrls' (Grant access to specific sites to connect to specific USB devices) policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://specific-device.example.com\"\r\n ]\r\n },\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://all-vendor-devices.example.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"07004461a108e58f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_outlookexe50","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_outlookexe50_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_outlookexe50_1","displayName":"True","description":null,"helpText":null}]},"07fcfb5e4c350558":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"0762baec7f50bb28":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_dehydratesyncedteamsites","displayName":"Convert synced team site files to online-only files","description":"This setting is used in conjunction with OneDrive Files On-Demand. When many users sync the same team sites, this setting lets you conserve bandwidth and free up space across devices by making synced team site files online-only files.\r\n\r\nIf you enable this setting, team site files that were syncing before OneDrive Files On-Demand was enabled, will be converted (as a one-time action) to online-only files.\r\n\r\nIf you disable or do not configure this setting, team site files will remain locally available unless users choose to make them online only.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_dehydratesyncedteamsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_dehydratesyncedteamsites_1","displayName":"Enabled","description":null,"helpText":null}]},"07893243e419821e":{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_nowarningnoelevationonupdate_enum","displayName":"When updating drivers for an existing connection:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_nowarningnoelevationonupdate_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_nowarningnoelevationonupdate_enum_1","displayName":"Show warning only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_nowarningnoelevationonupdate_enum_2","displayName":"Do not show warning or elevation prompt","description":null,"helpText":null}]},"07fbdf4ef2735a8f":{"id":"device_vendor_msft_policy_config_userrights_loadunloaddevicedrivers","displayName":"Load Unload Device Drivers","description":"This user right determines which users can dynamically load and unload device drivers or other code in to kernel mode. This user right does not apply to Plug and Play device drivers. It is recommended that you do not assign this privilege to other users. Caution: Assigning this user right can be a security risk. Do not assign this user right to any user, group, or process that you do not want to take over the system.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#loadunloaddevicedrivers"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"0749b2aec11ce1f8":{"id":"device_vendor_msft_scepcertificate_rootcertificate","displayName":"Root Certificate","description":"Choose a previously configured and assigned root CA certificate profile. The CA certificate must match the root certificate of the CA that is issuing the certificate for this profile (the one you are currently configuring).","helpText":"","infoUrls":[],"categoryId":"66c92e07-234b-4992-a081-9afe4c113ba3","categoryName":"SCEP certificate","options":null},"07b5f03fd6f53b0b":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon24","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"079251f1f09d81bf":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},"079b4731ed6dd334":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_1_lbl_reminderinittimeoutspin","displayName":"Seconds: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"07bac3e405406234":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmynetworkplaces","displayName":"Remove Network icon from Start Menu (User)","description":"This policy setting allows you to remove the Network icon from Start Menu.\r\n\r\nIf you enable this policy setting, the Network icon is no longer available from Start Menu.\r\n\r\nIf you disable or do not configure this policy setting, the Network icon is available from Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosmmynetworkplaces"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmynetworkplaces_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmynetworkplaces_1","displayName":"Enabled","description":null,"helpText":null}]},"07d8616ba03d973a":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote","displayName":"Microsoft OneNote 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft OneNote 2010.\r\nBy default, the user settings of Microsoft OneNote 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote_1","displayName":"Enabled","description":null,"helpText":null}]},"07ebf38e7ccff8d5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings","displayName":"Proxy settings (User)","description":"Setting the policy configures the proxy settings for Chrome and ARC-apps, which ignore all proxy-related options specified from the command line.\r\n\r\n Leaving the policy unset lets users choose their proxy settings.\r\n\r\n Setting the ProxySettings policy accepts the following fields:\r\n * ProxyMode, which lets you specify the proxy server Chrome uses and prevents users from changing proxy settings\r\n * ProxyPacUrl, a URL to a proxy .pac file\r\n * ProxyPacMandatory, which prevents the network stack from falling back to direct connections with invalid or unavailable PAC script\r\n * ProxyServer, a URL of the proxy server\r\n * ProxyBypassList, a list of hosts for which the proxy will be bypassed\r\n\r\n The ProxyServerMode field is deprecated in favor of the ProxyMode field.\r\n\r\n For ProxyMode, if you choose the value:\r\n * direct, a proxy is never used and all other fields are ignored.\r\n * system, the systems's proxy is used and all other fields are ignored.\r\n * auto_detect, all other fields are ignored.\r\n * fixed_servers, the ProxyServer and ProxyBypassList fields are used.\r\n * pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used.\r\n\r\nNote: For more detailed examples, visit The Chromium Projects ( https://www.chromium.org/developers/design-documents/network-settings#TOC-Command-line-options-for-proxy-sett ).\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ProxySettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"ProxyMode\": \"fixed_servers\",\r\n \"ProxyServer\": \"123.123.123.123:8080\",\r\n \"ProxyBypassList\": \"https://www.example1.com,https://www.example2.com,https://internalsite/\"\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_1","displayName":"Enabled","description":null,"helpText":null}]},"075b73615dd28bd9":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended_downloaddirectory","displayName":"Set download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":null},"0765ce7a53705f6e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled","displayName":"Enable spellcheck (User)","description":"Setting the policy to Enabled turns spellcheck on, and users can't turn it off. On Microsoft® Windows®, Google Chrome OS and Linux®, spellcheck languages can be switched on or off individually, so users can still turn spellcheck off by switching off every spellcheck language. To avoid that, use the SpellcheckLanguage to force-enable specific spellcheck languages.\r\n\r\nSetting the policy to Disabled turns off spellcheck from all sources, and users can't turn it on. The SpellCheckServiceEnabled, SpellcheckLanguage and SpellcheckLanguageBlocklist policies have no effect when this policy is set to False.\r\n\r\nLeaving the policy unset lets users turn spellcheck on or off in the language settings.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0798d6a19237735f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (User)","description":"Setting the policy to 3 lets websites ask for access to connected USB devices. Setting the policy to 2 denies access to connected USB devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"07d9d43f43a30d6c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls","displayName":"Allow popups on these sites (User)","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can open pop-ups.\r\n\r\nLeaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"070fee19f3bcbf8e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation_l_defaultfilelocation0","displayName":"Default file location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},"077d58c176159c8e":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1","displayName":"Enable using BITS to download Address Book Service files (User)","description":"This policy allows Microsoft Lync to use BITS (Background Intelligent Transfer Service) to download the Address Book Services files.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1_1","displayName":"Enabled","description":null,"helpText":null}]},"07fc50673f11abca":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled","displayName":"Default Profile Setting Enabled (User)","description":"Configuring this policy will let you set a default profile in Microsoft Edge to be used when opening the browser rather than the last profile used. This policy won't affect when \"--profile-directory\" parameter has been specified. Set the value to \"Default\" to refer to the default profile. The value is case sensitive.\r\nThe value of the policy is the name of the profile (case sensitive) and can be configured with string that is the name of a specific profile.\r\nThe value \"Edge Kids Mode\" and \"Guest Profile\" are considered not useful values because they not supposed to be a default profile.\r\nThis policy won't impact the following scenarios:\r\n 1) Settings specified in \"Profile preferences for sites\" in \"Profile preferences\"\r\n 2) Links opening from Outlook and Teams.\r\n\r\nThe following statements are under the condition of not specify the \"--profile-directory\" and configured value is not \"Edge Kids Mode\" or \"Guest Profile\":\r\nIf you enable this policy and configure it with a specific profile name and the specified profile can be found, Microsoft Edge will use the specified profile when launching and the setting of \"Default profile for external link\" is changed to the specified profile name and greyed out.\r\nIf you enable this policy and configure it with a specific profile name but it can't be found, the policy will behave like it's never been set before.\r\nIf you enable this policy, but don't configure or disable it, the policy will behave like it's never been set before.\r\n\r\nExample value: Default","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0796bb3f93fb829c":{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled","displayName":"Enable Gamer Mode (User)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\r\n\r\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\r\nIf you disable this policy, Gamer Mode will be disabled.","helpText":"","infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"07dc147f5a11d295":{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended","displayName":"Show Hubs Sidebar (User)","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"07b1b2ce0bd74b9f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath_1","displayName":"True","description":null,"helpText":null}]},"07b8fdce3a914f65":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto","displayName":"Pashto (User)","description":"Enables the editing language Pashto","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto_1","displayName":"Enabled","description":null,"helpText":null}]},"07d3e845667d5a8f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions","displayName":"Allow file extensions for OLE embedding (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365.\r\n\r\nThis policy setting allows you to specify which file extensions Office won’t block when they are embedded as an OLE package in an Office file by using the Object Packager control.\r\n\r\nBy default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759.\r\n\r\nImportant: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user.\r\n\r\nIf you enable this policy setting, enter the file extensions to allow, separated by semicolons. For example, exe;vbs;js.\r\n\r\nIf you disable or don’t configure this policy setting, the default set of file extensions will be blocked.\r\n\r\nIf you want to block additional file extensions, enable the \"Block additional file extensions for OLE embedding\" policy setting.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"07737555cf9dd336":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265_1","displayName":"True","description":null,"helpText":null}]},"0780eb3ec85ccc4a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect","displayName":"Exclude the HTTP redirect method (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect_1","displayName":"True","description":null,"helpText":null}]},"0732b844c7dd2eb2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode","displayName":"Disable Exchange Fast Access (User)","description":"This policy setting allows you to disable Exchange Fast Access, which forces user accounts to access data from a local cache.\r\n\r\nIf you enable this policy setting, Exchange Fast Access is not available to any Exchange Accounts on a computer.\r\n\r\nIf you disable or do not configure this policy setting, Exchange Fast Access is turned on by default for Exchange Accounts in Cached Exchange Mode.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode_1","displayName":"Enabled","description":null,"helpText":null}]},"07f02fbc5ebd9c3f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},"072f5d577a4ef60a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},"071fce7557c865ad":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},"0732ea1a41177c86":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items for Publisher.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for Publisher.","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"07ce00000905de2c":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"075faab2dd934669":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument","displayName":"File tab | Info | Protect Document (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument_1","displayName":"True","description":null,"helpText":null}]},"079409c4f7bf8946":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]}} \ No newline at end of file +{"072ff49a140aad82":{"id":"ade_setupassistant_multitasking","displayName":"Multitasking","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_multitasking_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_multitasking_1","displayName":"Show","description":null,"helpText":null}]},"07e89ad49db2b4c7":{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype","displayName":"Required password type","description":"Set the password’s complexity requirements. Additional password requirements will become available based on your selection. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level). For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-fx#device-password"],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequiredtype_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},"07ace6de15d77e50":{"id":"com.apple.applicationaccess_allowcloudaddressbook","displayName":"Allow Cloud Address Book","description":"If false, disables iCloud Address Book services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudaddressbook_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudaddressbook_true","displayName":"True","description":null,"helpText":null}]},"07c44d7883fbc7e0":{"id":"com.apple.caldav.account_caldavusername","displayName":"Cal DAV Username","description":"The user name for logins.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},"0700fd37c3e8a9e6":{"id":"com.apple.managedclient.preferences_disabledonotforward","displayName":"Disable 'Do Not Forward' options","description":"Prevent users from applying the Do Not Forward option to emails when using Microsoft 365 Message Encryption.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-do-not-forward"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disabledonotforward_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disabledonotforward_true","displayName":"True","description":null,"helpText":null}]},"07e87ee50e1b1445":{"id":"com.apple.managedclient.preferences_personalizationreportingenabled","displayName":"Allow personalization of ads, search and news by sending browsing history to Microsoft","description":"This policy prevents Microsoft from collecting a user's Microsoft Edge browsing history to be used for personalizing advertising, search, news and other Microsoft services.\n\nThis setting is only available for users with a Microsoft account. This setting is not available for child accounts or enterprise accounts.\n\nIf you disable this policy, users can't change or override the setting. If this policy is enabled or not configured, Microsoft Edge will default to the user’s preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#personalizationreportingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_personalizationreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_personalizationreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"07e47e03eac1ca2e":{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring","displayName":"Wake On Modem Ring","description":"If true, enables \"Wake for modem ring.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_wake on modem ring_1","displayName":"True","description":null,"helpText":null}]},"077311fcd2f31fd1":{"id":"com.apple.mcx.timemachine_backupsizemb","displayName":"Backup Size MB","description":"The backup size limit, in megabytes. Set to 0 for unlimited.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},"0733b07ab71007fe":{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_comment","displayName":"Comment","description":"Not used.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"0775a10e037209bd":{"id":"com.microsoft.edge.mamedgeappconfigsettings.urlallowlist","displayName":"Define a list of allowed URLs","description":"Setting the policy provides access to the listed URLs as exceptions to \"URLBlocklist\".\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can use this policy to open exceptions to restrictive blocklists. For example, you can include '*' in the blocklist to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\n\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the blocked list.\n\nThis policy is limited to 1000 entries; subsequent entries are ignored.\n\nThis policy also allows the browser to automatically invoke external applications registered as protocol handlers for protocols like \"tel:\" or \"ssh:\".\n\nIf you don't configure this policy, there are no exceptions to the blocklist in the \"URLBlocklist\" policy.\n\nThis policy doesn't work as expected with file://* wildcards.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"072183d8715d5fb9":{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslciphersuiteorder_pol_sslciphersuiteorder","displayName":"SSL Cipher Suites","description":null,"helpText":"","infoUrls":[],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":null},"07fb836feab20136":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_folderredirection_cse_slowlink4_1","displayName":"True","description":null,"helpText":null}]},"07723ec2c8501094":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity","displayName":"Configure IP security policy processing","description":"This policy setting determines when IP security policies are updated.\r\n\r\nThis policy setting affects all policies that use the IP security component of Group Policy, such as policies in Computer Configuration\\Windows Settings\\Security Settings\\IP Security Policies on Local Machine.\r\n\r\nThis policy setting overrides customized settings that the program implementing the IP security policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-ipsecurity"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},"07369fdfd716346e":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet","displayName":"Allow operation while in public network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowonpublicnet_1","displayName":"True","description":null,"helpText":null}]},"0734d14df1fb30aa":{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy","displayName":"Automatic Maintenance Activation Boundary","description":"\r\n This policy setting allows you to configure Automatic Maintenance activation boundary.\r\n\r\n The maintenance activation boundary is the daily schduled time at which Automatic Maintenance starts\r\n\r\n If you enable this policy setting, this will override the default daily scheduled time as specified in Security and Maintenance/Automatic Maintenance Control Panel.\r\n\r\n If you disable or do not configure this policy setting, the daily scheduled time as specified in Security and Maintenance/Automatic Maintenance Control Panel will apply.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msched#admx-msched-activationboundarypolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msched_activationboundarypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"070012fbf87da21f":{"id":"device_vendor_msft_policy_config_admx_msi_msilogging_msilogging","displayName":"Logging","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":null},"07bdcb24c24caed1":{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth","displayName":"Turn on bandwidth optimization","description":"This policy setting allows you to improve performance in low bandwidth scenarios.\r\n\r\nThis setting is incrementally scaled from \"No optimization\" to \"Full optimization\". Each incremental setting includes the previous optimization setting.\r\n\r\nFor example:\r\n\r\n\"Turn off background\" will include the following optimizations:\r\n-No full window drag\r\n-Turn off background\r\n\r\n\"Full optimization\" will include the following optimizations:\r\n-Use 16-bit color (8-bit color in Windows Vista)\r\n-Turn off font smoothing (not supported in Windows Vista)\r\n-No full window drag\r\n-Turn off background\r\n\r\nIf you enable this policy setting, bandwidth optimization occurs at the level specified.\r\n\r\nIf you disable this policy setting, application-based settings are used.\r\n\r\nIf you do not configure this policy setting, application-based settings are used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-remoteassistance#admx-remoteassistance-ra-optimize-bandwidth"],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_remoteassistance_ra_optimize_bandwidth_1","displayName":"Enabled","description":null,"helpText":null}]},"07ad19570f307597":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext","displayName":"Idle session limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sessions_idle_limit_2_ts_sessions_idlelimittext_432000000","displayName":"5 days","description":null,"helpText":null}]},"073d81c8e1200424":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup","displayName":"Publisher 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Publisher 2013.\r\nMicrosoft Publisher 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Publisher 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Publisher 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Publisher 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013publisherbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013publisherbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"07d13c696bbca14a":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_global_refresh_interval_prompt","displayName":"Global Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"07dee3f1b23c6221":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for image URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURLPostParams specifies the parameters during image search with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as {imageThumbnail}, real image thumbnail data replaces it.\r\n\r\nLeaving DefaultSearchProviderImageURLPostParams unset means image search request is sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"07a703072f57238b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalgreylisturl_browserswitcherexternalgreylisturl","displayName":"URL of an XML file that contains URLs that should never trigger a browser switch. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"07a2d6fa343c4226":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbaskforurls_webusbaskforurlsdesc","displayName":"Allow WebUSB on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"077d6fb4f199f35b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"0726e7bb82198fa8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_cacertificatesdesc","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"071e6356615c837f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessAllowedForUrls, this policy takes precedence.\r\n\r\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0706a7c195807b65":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled","displayName":"Control Javascript setTimeout() function minimum timeout.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_settimeoutwithout1msclampenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"07997e3914dbf7d9":{"id":"device_vendor_msft_policy_config_connectivity_allowphonepclinking","displayName":"Allow Phone PC Linking","description":"This policy allows IT admins to turn off the ability to Link a Phone with a PC to continue tasks, such as reading, email, and other tasks that require linking between Phone and PC. If you enable this policy setting, the Windows device will be able to enroll in Phone-PC linking functionality and participate in 'Continue on PC experiences'. If you disable this policy setting, the Windows device is not allowed to be linked to phones, will remove itself from the device list of any linked Phones, and cannot participate in 'Continue on PC experiences'. If you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-connectivity#allowphonepclinking"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"device_vendor_msft_policy_config_connectivity_allowphonepclinking_0","displayName":"Block","description":"Do not link.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowphonepclinking_1","displayName":"Allow","description":"Allow phone-PC linking.","helpText":null}]},"0747321cd94e3e8b":{"id":"device_vendor_msft_policy_config_connectivity_hardeneduncpaths_pol_hardenedpaths_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"643081a4-132d-463e-9d86-c8650cb2a011","categoryName":"Network Provider","options":null},"07bd90369b5e8e27":{"id":"device_vendor_msft_policy_config_experience_disableinlinecompose","displayName":"Disable Inline Compose","description":"This policy controls whether users can compose a message directly in the Share sheet after selecting Outlook. If the policy is enabled, Windows hides the message entry field and users must complete message composition within Outlook. If the policy is disabled or not configured, Windows may display a message entry field in the Share sheet.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#disableinlinecompose"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_disableinlinecompose_0","displayName":"Inline Compose on ShareSheet is Enabled.","description":"Inline Compose on ShareSheet is Enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_disableinlinecompose_1","displayName":"Inline Compose on ShareSheet is Disabled.","description":"Inline Compose on ShareSheet is Disabled.","helpText":null}]},"071550208a8f36da":{"id":"device_vendor_msft_policy_config_internetexplorer_disablehtmlapplication","displayName":"Disable HTML Application","description":"This policy setting specifies if running the HTML Application (HTA file) is blocked or allowed.\n\nIf you enable this policy setting, running the HTML Application (HTA file) will be blocked.\n\nIf you disable or do not configure this policy setting, running the HTML Application (HTA file) is allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablehtmlapplication"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablehtmlapplication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablehtmlapplication_1","displayName":"Enabled","description":null,"helpText":null}]},"07f5014d1acede75":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneinitializeandscriptactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"0704063b9663245b":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"077438add807ded3":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard use on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"07e58c0fa6d08078":{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled","displayName":"Enable Discover access to page contents for AAD profiles (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy has been obsoleted as of Edge 127. Two new Edge Policies have taken its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles), and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles).\r\n\r\nThis policy did not allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allowed force-disabling of Copilot page access.\r\n\r\nThis policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. In order to summarize pages and interact with text selections, it needs to be able to access the page contents. When enabled, page contents will be sent to Bing. This policy does not affect MSA profiles.\r\n\r\nIf you enable or don't configure this policy, Discover will have access to page contents.\r\n\r\nIf you disable this policy, Discover will not be able to access page contents.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_discoverpagecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"078f45c903fd6438":{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},"07eb04f051dee482":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors.","description":"This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\r\n\r\nIf you enable this policy or don't set it, Microsoft Edge will enable these security protections for all connections.\r\n\r\nIf you disable this policy, Microsoft Edge will disable these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\r\n\r\nThis policy may be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED. A later version of Microsoft Edge will enable this option by default.\r\n\r\nAfter it is enabled by default, administrators who need more time to upgrade affected proxies may use this policy to temporarily disable this security feature. This policy will be removed after version 85.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"071162136a8ff561":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault","displayName":"Configure Automatic HTTPS","description":"This policy lets you manage settings for 'AutomaticHttpsDefault' (Configure Automatic HTTPS), which switches connections from HTTP to HTTPS.\r\n\r\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\r\n\r\nNote: The 'UpgradeCapableDomains' configuration requires a component list, and will not upgrade these connections if 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) is set to 'Disabled'.\r\n\r\nIf you don't configure this policy, 'AutomaticHttpsDefault' will be enabled, and will only upgrade connections on domains likely to support HTTPS.\r\n\r\nPolicy options mapping:\r\n\r\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\r\n\r\n* UpgradeCapableDomains (1) = Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\r\n\r\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_automatichttpsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},"073fd4386c28d112":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices","description":"Setting the policy lets you list sites that are automatically granted permission to access USB serial devices with vendor and product IDs that match the vendor_id and product_id fields.\r\n\r\nOptionally you can omit the product_id field. This enables site access to all the vendor's devices. When you provide a product ID, then you give the site access to a specific device from the vendor but not all devices.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the 'WebUsbAllowDevicesForUrls' (Grant access to specific sites to connect to specific USB devices) policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://specific-device.example.com\"\r\n ]\r\n },\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://all-vendor-devices.example.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"07004461a108e58f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_outlookexe50","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_outlookexe50_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_outlookexe50_1","displayName":"True","description":null,"helpText":null}]},"07fcfb5e4c350558":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"0762baec7f50bb28":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_dehydratesyncedteamsites","displayName":"Convert synced team site files to online-only files","description":"This setting is used in conjunction with OneDrive Files On-Demand. When many users sync the same team sites, this setting lets you conserve bandwidth and free up space across devices by making synced team site files online-only files.\r\n\r\nIf you enable this setting, team site files that were syncing before OneDrive Files On-Demand was enabled, will be converted (as a one-time action) to online-only files.\r\n\r\nIf you disable or do not configure this setting, team site files will remain locally available unless users choose to make them online only.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_dehydratesyncedteamsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_dehydratesyncedteamsites_1","displayName":"Enabled","description":null,"helpText":null}]},"07893243e419821e":{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_nowarningnoelevationonupdate_enum","displayName":"When updating drivers for an existing connection:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_nowarningnoelevationonupdate_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_nowarningnoelevationonupdate_enum_1","displayName":"Show warning only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_nowarningnoelevationonupdate_enum_2","displayName":"Do not show warning or elevation prompt","description":null,"helpText":null}]},"07fbdf4ef2735a8f":{"id":"device_vendor_msft_policy_config_userrights_loadunloaddevicedrivers","displayName":"Load Unload Device Drivers","description":"This user right determines which users can dynamically load and unload device drivers or other code in to kernel mode. This user right does not apply to Plug and Play device drivers. It is recommended that you do not assign this privilege to other users. Caution: Assigning this user right can be a security risk. Do not assign this user right to any user, group, or process that you do not want to take over the system.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#loadunloaddevicedrivers"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"0749b2aec11ce1f8":{"id":"device_vendor_msft_scepcertificate_rootcertificate","displayName":"Root Certificate","description":"Choose a previously configured and assigned root CA certificate profile. The CA certificate must match the root certificate of the CA that is issuing the certificate for this profile (the one you are currently configuring).","helpText":"","infoUrls":[],"categoryId":"66c92e07-234b-4992-a081-9afe4c113ba3","categoryName":"SCEP certificate","options":null},"07b5f03fd6f53b0b":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon24","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"079251f1f09d81bf":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},"079b4731ed6dd334":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_1_lbl_reminderinittimeoutspin","displayName":"Seconds: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"07bac3e405406234":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmynetworkplaces","displayName":"Remove Network icon from Start Menu (User)","description":"This policy setting allows you to remove the Network icon from Start Menu.\r\n\r\nIf you enable this policy setting, the Network icon is no longer available from Start Menu.\r\n\r\nIf you disable or do not configure this policy setting, the Network icon is available from Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosmmynetworkplaces"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmynetworkplaces_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmynetworkplaces_1","displayName":"Enabled","description":null,"helpText":null}]},"07d8616ba03d973a":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote","displayName":"Microsoft OneNote 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft OneNote 2010.\r\nBy default, the user settings of Microsoft OneNote 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010onenote_1","displayName":"Enabled","description":null,"helpText":null}]},"07ebf38e7ccff8d5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings","displayName":"Proxy settings (User)","description":"Setting the policy configures the proxy settings for Chrome and ARC-apps, which ignore all proxy-related options specified from the command line.\r\n\r\n Leaving the policy unset lets users choose their proxy settings.\r\n\r\n Setting the ProxySettings policy accepts the following fields:\r\n * ProxyMode, which lets you specify the proxy server Chrome uses and prevents users from changing proxy settings\r\n * ProxyPacUrl, a URL to a proxy .pac file\r\n * ProxyPacMandatory, which prevents the network stack from falling back to direct connections with invalid or unavailable PAC script\r\n * ProxyServer, a URL of the proxy server\r\n * ProxyBypassList, a list of hosts for which the proxy will be bypassed\r\n\r\n The ProxyServerMode field is deprecated in favor of the ProxyMode field.\r\n\r\n For ProxyMode, if you choose the value:\r\n * direct, a proxy is never used and all other fields are ignored.\r\n * system, the systems's proxy is used and all other fields are ignored.\r\n * auto_detect, all other fields are ignored.\r\n * fixed_servers, the ProxyServer and ProxyBypassList fields are used.\r\n * pac_script, the ProxyPacUrl, ProxyPacMandatory and ProxyBypassList fields are used.\r\n\r\nNote: For more detailed examples, visit The Chromium Projects ( https://www.chromium.org/developers/design-documents/network-settings#TOC-Command-line-options-for-proxy-sett ).\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ProxySettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"ProxyMode\": \"fixed_servers\",\r\n \"ProxyServer\": \"123.123.123.123:8080\",\r\n \"ProxyBypassList\": \"https://www.example1.com,https://www.example2.com,https://internalsite/\"\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_proxysettings_1","displayName":"Enabled","description":null,"helpText":null}]},"075b73615dd28bd9":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloaddirectory_recommended_downloaddirectory","displayName":"Set download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":null},"0765ce7a53705f6e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled","displayName":"Enable spellcheck (User)","description":"Setting the policy to Enabled turns spellcheck on, and users can't turn it off. On Microsoft® Windows®, Google Chrome OS and Linux®, spellcheck languages can be switched on or off individually, so users can still turn spellcheck off by switching off every spellcheck language. To avoid that, use the SpellcheckLanguage to force-enable specific spellcheck languages.\r\n\r\nSetting the policy to Disabled turns off spellcheck from all sources, and users can't turn it on. The SpellCheckServiceEnabled, SpellcheckLanguage and SpellcheckLanguageBlocklist policies have no effect when this policy is set to False.\r\n\r\nLeaving the policy unset lets users turn spellcheck on or off in the language settings.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0798d6a19237735f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting","displayName":"Control use of the WebUSB API (User)","description":"Setting the policy to 3 lets websites ask for access to connected USB devices. Setting the policy to 2 denies access to connected USB devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebusbguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"07d9d43f43a30d6c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls","displayName":"Allow popups on these sites (User)","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can open pop-ups.\r\n\r\nLeaving the policy unset means DefaultPopupsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"070fee19f3bcbf8e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_defaultfilelocation_l_defaultfilelocation0","displayName":"Default file location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":null},"077d58c176159c8e":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1","displayName":"Enable using BITS to download Address Book Service files (User)","description":"This policy allows Microsoft Lync to use BITS (Background Intelligent Transfer Service) to download the Address Book Services files.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyenablebitsforgaldownload_1_1","displayName":"Enabled","description":null,"helpText":null}]},"07fc50673f11abca":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled","displayName":"Default Profile Setting Enabled (User)","description":"Configuring this policy will let you set a default profile in Microsoft Edge to be used when opening the browser rather than the last profile used. This policy won't affect when \"--profile-directory\" parameter has been specified. Set the value to \"Default\" to refer to the default profile. The value is case sensitive.\r\nThe value of the policy is the name of the profile (case sensitive) and can be configured with string that is the name of a specific profile.\r\nThe value \"Edge Kids Mode\" and \"Guest Profile\" are considered not useful values because they not supposed to be a default profile.\r\nThis policy won't impact the following scenarios:\r\n 1) Settings specified in \"Profile preferences for sites\" in \"Profile preferences\"\r\n 2) Links opening from Outlook and Teams.\r\n\r\nThe following statements are under the condition of not specify the \"--profile-directory\" and configured value is not \"Edge Kids Mode\" or \"Guest Profile\":\r\nIf you enable this policy and configure it with a specific profile name and the specified profile can be found, Microsoft Edge will use the specified profile when launching and the setting of \"Default profile for external link\" is changed to the specified profile name and greyed out.\r\nIf you enable this policy and configure it with a specific profile name but it can't be found, the policy will behave like it's never been set before.\r\nIf you enable this policy, but don't configure or disable it, the policy will behave like it's never been set before.\r\n\r\nExample value: Default","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0796bb3f93fb829c":{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled","displayName":"Enable Gamer Mode (User)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\r\n\r\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\r\nIf you disable this policy, Gamer Mode will be disabled.","helpText":"","infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge~edgegames_gamermodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"07dc147f5a11d295":{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended","displayName":"Show Hubs Sidebar (User)","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"07b1b2ce0bd74b9f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyinfopath_1","displayName":"True","description":null,"helpText":null}]},"07b8fdce3a914f65":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto","displayName":"Pashto (User)","description":"Enables the editing language Pashto","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_pashto_1","displayName":"Enabled","description":null,"helpText":null}]},"07d3e845667d5a8f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions","displayName":"Allow file extensions for OLE embedding (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365.\r\n\r\nThis policy setting allows you to specify which file extensions Office won’t block when they are embedded as an OLE package in an Office file by using the Object Packager control.\r\n\r\nBy default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759.\r\n\r\nImportant: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user.\r\n\r\nIf you enable this policy setting, enter the file extensions to allow, separated by semicolons. For example, exe;vbs;js.\r\n\r\nIf you disable or don’t configure this policy setting, the default set of file extensions will be blocked.\r\n\r\nIf you want to block additional file extensions, enable the \"Block additional file extensions for OLE embedding\" policy setting.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"07737555cf9dd336":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_allowsubfolders265_1","displayName":"True","description":null,"helpText":null}]},"0780eb3ec85ccc4a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect","displayName":"Exclude the HTTP redirect method (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_l_outlookdisableautodiscoverhttpredirect_1","displayName":"True","description":null,"helpText":null}]},"0732b844c7dd2eb2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode","displayName":"Disable Exchange Fast Access (User)","description":"This policy setting allows you to disable Exchange Fast Access, which forces user accounts to access data from a local cache.\r\n\r\nIf you enable this policy setting, Exchange Fast Access is not available to any Exchange Accounts on a computer.\r\n\r\nIf you disable or do not configure this policy setting, Exchange Fast Access is turned on by default for Exchange Accounts in Cached Exchange Mode.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_hybridmode_1","displayName":"Enabled","description":null,"helpText":null}]},"07f02fbc5ebd9c3f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},"072f5d577a4ef60a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},"071fce7557c865ad":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},"0732ea1a41177c86":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items for Publisher.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for Publisher.","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"07ce00000905de2c":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"075faab2dd934669":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument","displayName":"File tab | Info | Protect Document (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsprotectdocument_1","displayName":"True","description":null,"helpText":null}]},"079409c4f7bf8946":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/08.json b/public/intune-definitions/08.json index b01fa35aeeba..77e89d9ffcd0 100644 --- a/public/intune-definitions/08.json +++ b/public/intune-definitions/08.json @@ -1 +1 @@ -{"08c98b03c6c54e2f":{"id":"com.apple.airplay_passwords_item_deviceid","displayName":"Device ID","description":"The device ID of the AirPlay destination; used in macOS.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},"087c503869dac3e1":{"id":"com.apple.ldap.account_ldapaccounthostname","displayName":"LDAP Account Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},"082f3d79e4eeda3c":{"id":"com.apple.loginwindow_shutdowndisabled","displayName":"Shut Down Disabled","description":"If true, disables the Shut Down button.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_shutdowndisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_shutdowndisabled_true","displayName":"True","description":null,"helpText":null}]},"088f6d301d9a3d22":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"08089dbe8e99b469":{"id":"com.apple.managedclient.preferences_defaultclipboardsetting","displayName":"Default clipboard site permission","description":"This policy controls the default value for the clipboard site permission.\n\nSetting the policy to 2 blocks sites from using the clipboard site permission.\n\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\n\nThis policy can be overridden for specific URL patterns using the \"ClipboardAllowedForUrls\" and \"ClipboardBlockedForUrls\" policies.\n\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\n\nPolicy options mapping:\n\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\n\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultclipboardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultclipboardsetting_0","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultclipboardsetting_1","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},"08c35d1b352fde88":{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection","displayName":"Enforcement level","description":"Specifies if tamper protection is disabled, in audit mode, or enforced","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":[{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_0","displayName":"disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_1","displayName":"audit","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_2","displayName":"block","description":null,"helpText":null}]},"082fa2b27782e1d5":{"id":"com.apple.managedclient.preferences_updatecache","displayName":"Update cache server","description":"Specify the HTTP(S) URL of the server that you use for cached package updates (PKG files). You must include a trailing forward slash.","helpText":null,"infoUrls":["https://macadmins.software/docs/MAU_CachingServer.pdf"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"082fc533adba33e1":{"id":"com.apple.mcx_dontallowfdedisable","displayName":"Prevent FileVault From Being Disabled","description":"Set to true to prevent FileVault from being disabled.","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":[{"id":"com.apple.mcx_dontallowfdedisable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_dontallowfdedisable_true","displayName":"True","description":null,"helpText":null}]},"08b0d67e5be86afb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\n\nIf you disable or don't set this policy, the browser uses the default behavior of cross-site auth. This behavior is to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials need to be provided independently in the context of both sites. Cached proxy credentials are reused across sites.\n\nIf you enable this policy, HTTP auth credentials entered in the context of one site is automatically used in the context of another site.\n\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\n\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"08d12dbefd6ab9c2":{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepagelocation","displayName":"Configure the home page URL","description":"Configures the default home page URL in Microsoft Edge.\n\nThe home page is the page opened by the Home button. \"RestoreOnStartup\" policies control the pages that open on startup.\n\nYou can either set a URL here or set the home page to open the new tab page 'edge://newtab'. By default, the Home button opens the new tab page (as configured by the user or with the policy \"NewTabPageLocation\"), and the user is able to choose between the URL configured by this policy and the new tab page.\n\nIf you enable this policy, users can't change their home page URL, but they can choose the behavior for the Home button to open either the set URL or the new tab page. If you wish to enforce the usage of the set URL, you must also configure \"HomepageIsNewTabPage\"=Disabled.\n\nIf you disable or don't configure this policy, users can choose their own home page, as long as the \"HomepageIsNewTabPage\" policy isn't enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"08ec64333d2833cd":{"id":"com.microsoft.edge.mamedgeappconfigsettings.localfontsblockedforurls","displayName":"Block Local Fonts permission on these sites","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically denied. Sites in this list are prevented from accessing information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the \"DefaultLocalFontsSetting\" policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"08cc2c119dcc3c94":{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled","displayName":"Wallet Donation Enabled (Deprecated)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.\n\nThis policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"088f790c26e6ff19":{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype","displayName":"Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)","description":"This policy setting allows you to configure the algorithm and cipher strength used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption method has no effect if the drive is already encrypted, or if encryption is in progress.\n\nIf you enable this policy setting you will be able to configure an encryption algorithm and key cipher strength for fixed data drives, operating system drives, and removable data drives individually. For fixed and operating system drives, we recommend that you use the XTS-AES algorithm. For removable drives, you should use AES-CBC 128-bit or AES-CBC 256-bit if the drive will be used in other devices that are not running Windows 10 (Version 1511).\n\nIf you disable or do not configure this policy setting, BitLocker will use AES with the same bit strength (128-bit or 256-bit) as the \"Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7)\" and \"Choose drive encryption method and cipher strength\" policy settings (in that order), if they are set. If none of the policies are set, BitLocker will use the default encryption method of XTS-AES 128-bit or the encryption method specified by the setup script.”\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_1","displayName":"Enabled","description":null,"helpText":null}]},"086401ae018ef535":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime_bits_maxdownloadseconds","displayName":"Active Job Timeout in seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"087acde96e993941":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist_dns_searchlistlabel","displayName":"DNS Suffixes:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},"080ceec9a18dda89":{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp","displayName":"Restrict potentially unsafe HTML Help functions to specified folders","description":"This policy setting allows you to restrict certain HTML Help commands to function only in HTML Help (.chm) files within specified folders and their subfolders. Alternatively, you can disable these commands on the entire system. It is strongly recommended that only folders requiring administrative privileges be added to this policy setting.\r\n\r\n If you enable this policy setting, the commands function only for .chm files in the specified folders and their subfolders.\r\n\r\n To restrict the commands to one or more folders, enable the policy setting and enter the desired folders in the text box on the Settings tab of the Policy Properties dialog box. Use a semicolon to separate folders. For example, to restrict the commands to only .chm files in the %windir%\\help folder and D:\\somefolder, add the following string to the edit box: \"%windir%\\help;D:\\somefolder\".\r\n\r\n Note: An environment variable may be used, (for example, %windir%), as long as it is defined on the system. For example, %programfiles% is not defined on some early versions of Windows.\r\n\r\n The \"Shortcut\" command is used to add a link to a Help topic, and runs executables that are external to the Help file. The \"WinHelp\" command is used to add a link to a Help topic, and runs a WinHLP32.exe Help (.hlp) file.\r\n\r\n To disallow the \"Shortcut\" and \"WinHelp\" commands on the entire local system, enable the policy setting and leave the text box on the Settings tab of the Policy Properties dialog box blank.\r\n\r\n If you disable or do not configure this policy setting, these commands are fully functional for all Help files.\r\n\r\n Note: Only folders on the local computer can be specified in this policy setting. You cannot use this policy setting to enable the \"Shortcut\" and \"WinHelp\" commands for .chm files that are stored on mapped drives or accessed using UNC paths.\r\n\r\n For additional options, see the \"Restrict these programs from being launched from Help\" policy.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-helpqualifiedrootdir-comp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_1","displayName":"Enabled","description":null,"helpText":null}]},"086e51fac026a8a9":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather","displayName":"Weather","description":"This policy setting configures the synchronization of user settings for the Weather app.\r\nBy default, the user settings of Weather sync between computers. Use the policy setting to prevent the user settings of Weather from synchronizing between computers.\r\nIf you enable this policy setting, Weather user settings continue to sync.\r\nIf you disable this policy setting, Weather user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-weather"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather_1","displayName":"Enabled","description":null,"helpText":null}]},"08278a0a4882ba6d":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen","displayName":"Configure Windows Defender SmartScreen","description":"This policy allows you to turn Windows Defender SmartScreen on or off. SmartScreen helps protect PCs by warning users before running potentially malicious programs downloaded from the Internet. This warning is presented as an interstitial dialog shown before running an app that has been downloaded from the Internet and is unrecognized or known to be malicious. No dialog is shown for apps that do not appear to be suspicious.\r\n\r\nSome information is sent to Microsoft about files and programs run on PCs with this feature enabled.\r\n\r\nIf you enable this policy, SmartScreen will be turned on for all users. Its behavior can be controlled by the following options:\r\n\r\n• Warn and prevent bypass\r\n• Warn\r\n\r\nIf you enable this policy with the \"Warn and prevent bypass\" option, SmartScreen's dialogs will not present the user with the option to disregard the warning and run the app. SmartScreen will continue to show the warning on subsequent attempts to run the app.\r\n\r\nIf you enable this policy with the \"Warn\" option, SmartScreen's dialogs will warn the user that the app appears suspicious, but will permit the user to disregard the warning and run the app anyway. SmartScreen will not warn the user again for that app if the user tells SmartScreen to run the app.\r\n\r\nIf you disable this policy, SmartScreen will be turned off for all users. Users will not be warned if they try to run suspicious apps from the Internet.\r\n\r\nIf you do not configure this policy, SmartScreen will be enabled by default, but users may change their settings.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enablesmartscreen"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_1","displayName":"Enabled","description":null,"helpText":null}]},"081fbc77726e4b46":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos","displayName":"Microsoft Photos ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos_1","displayName":"True","description":null,"helpText":null}]},"0807080aed309add":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply","description":"Setting the policy specifies a list of origins (URLs) or hostname patterns (such as *.example.com) for which security restrictions on insecure origins won't apply. Organizations can specify origins for legacy applications that can't deploy TLS or set up a staging server for internal web development, so developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled \"Not Secure\" in the address bar.\r\n\r\nSetting a list of URLs in this policy amounts to setting the command-line flag --unsafely-treat-insecure-origin-as-secure to a comma-separated list of the same URLs. The policy overrides the command-line flag and UnsafelyTreatInsecureOriginAsSecure, if present.\r\n\r\nFor more information on secure contexts, see Secure Contexts ( https://www.w3.org/TR/secure-contexts ).\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_1","displayName":"Enabled","description":null,"helpText":null}]},"0816430102a019b3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_autoselectcertificateforurlsdesc","displayName":"Automatically select client certificates for these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"089ffd7f874a6716":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser_enterprisecustomlabelforbrowser","displayName":"Set a custom enterprise label for a managed browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"085e4c2e32125450":{"id":"device_vendor_msft_policy_config_internetexplorer_donotallowuserstoaddsites","displayName":"Security Zones: Do not allow users to add/delete sites","description":"Prevents users from adding or removing sites from security zones. A security zone is a group of Web sites with the same security level.\n\nIf you enable this policy, the site management settings for security zones are disabled. (To see the site management settings for security zones, in the Internet Options dialog box, click the Security tab, and then click the Sites button.)\n\nIf you disable this policy or do not configure it, users can add Web sites to or remove sites from the Trusted Sites and Restricted Sites zones, and alter settings for the Local Intranet zone.\n\nThis policy prevents users from changing site management settings for security zones established by the administrator.\n\nNote: The \"Disable the Security page\" policy (located in \\User Configuration\\Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel), which removes the Security tab from the interface, takes precedence over this policy. If it is enabled, this policy is ignored.\n\nAlso, see the \"Security zones: Use only machine settings\" policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-donotallowuserstoaddsites"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_donotallowuserstoaddsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_donotallowuserstoaddsites_1","displayName":"Enabled","description":null,"helpText":null}]},"083c160fb7505eac":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions","displayName":"Java permissions","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to Medium Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonejavapermissions"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},"088afe96b20cf281":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets","displayName":"Allow scriptlets","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowscriptlets"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"084cf3f4187337e6":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript","displayName":"Allow updates to status bar via script","description":"This policy setting allows you to manage whether script is allowed to update the status bar within the zone.\n\nIf you enable this policy setting, script is allowed to update the status bar.\n\nIf you disable or do not configure this policy setting, script is not allowed to update the status bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowupdatestostatusbarviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"0866d8aab4509699":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_recoveryconsole_allowfloppycopyandaccesstoalldrivesandallfolders","displayName":"Recovery Console Allow Floppy Copy And Access To All Drives And All Folders","description":"Recovery console: Allow floppy copy and access to all drives and all folders Enabling this security option makes the Recovery Console SET command available, which allows you to set the following Recovery Console environment variables: AllowWildCards: Enable wildcard support for some commands (such as the DEL command). AllowAllPaths: Allow access to all files and folders on the computer. AllowRemovableMedia: Allow files to be copied to removable media, such as a floppy disk. NoCopyPrompt: Do not prompt when overwriting an existing file. Default: This policy is not defined and the recover console SET command is not available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#recoveryconsole_allowfloppycopyandaccesstoalldrivesandallfolders"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"0809361075111405":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_applicationlocalevalue","displayName":"Application locale (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},"08a16ea53da5215a":{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\r\n\r\n * 'WebHidBlockedForUrls' (Block the WebHID API on these sites) (if there is a match),\r\n\r\n * 'DefaultWebHidGuardSetting' (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with 'WebHidBlockedForUrls'. Neither policy takes precedence if a URL matches both patterns.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"087bef07e4adc75a":{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning","description":"This policy controls whether third-party storage partitioning is allowed by default.\r\n\r\nIf this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means.\r\n\r\nIf this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts.\r\n\r\nUse ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowPartitioning (1) = Allow third-party storage partitioning by default.\r\n\r\n* BlockPartitioning (2) = Disable third-party storage partitioning.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"08a1d52972883274":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket","displayName":"Maximum number of concurrent connections to the proxy server for WebSocket requests","description":"Specifies the maximum number of simultaneous connections to a proxy server for WebSocket requests.\r\n\r\nTo configure limits for non-WebSocket requests, see the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server) policy.\r\n\r\nIf you don't configure this policy, the default value of 32 is used.\r\n\r\nSome web applications maintain multiple concurrent connections (for example, long-lived or hanging requests). Setting a value lower than the default may cause networking delays when many such applications are open.\r\n\r\nSome proxy servers cannot handle a high number of concurrent connections per client. In these cases, reducing the value of this policy may improve reliability.\r\n\r\nThe supported range is 6 to 256:\r\n- Values less than 6 are treated as 6.\r\n- Values greater than 256 are treated as 256.\r\n\r\nWe recommend modifying this value only if required by your proxy server configuration or network environment.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_1","displayName":"Enabled","description":null,"helpText":null}]},"083312513e86b8e8":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84. (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThe Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and have been disabled by default starting in M80. This policy allows these features to be selectively re-enabled until M84.\r\n\r\n If you set this policy is set to True, the Web Components v0 features will be enabled for all sites.\r\n\r\n If you set this policy to False or don't set this policy, the Web Components v0 features will be disabled by default, starting in M80.\r\n\r\n This policy will be removed after Microsoft Edge 84.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"08151b5e121f7e32":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_visioexe117","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_visioexe117_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_visioexe117_1","displayName":"True","description":null,"helpText":null}]},"0865a9a3667ea8e7":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature","displayName":"Mime Sniffing Safety Feature","description":"Mime Sniffing","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_1","displayName":"Enabled","description":null,"helpText":null}]},"08e865a554a7dee3":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_excelexe1","displayName":"excel.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_excelexe1_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_excelexe1_1","displayName":"True","description":null,"helpText":null}]},"08bc8c8516040176":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessbackgroundspatialperception_userincontroloftheseapps","displayName":"Let Apps Access Background Spatial Perception User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. The user is able to control the user movements privacy setting for the listed apps. This setting overrides the default LetAppsAccessBackgroundSpatialPerception policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessbackgroundspatialperception_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"08748f37a6cdd704":{"id":"device_vendor_msft_policy_config_remotedesktopservices_ts_server_remoteapp_use_shellappruntime","displayName":"Enable enhanced shell experience for RemoteApp","description":"This policy setting enables an enhanced shell experience for RemoteApp sessions, offering support for default file associations, Run/RunOnce registry keys, and more. This policy setting applies only to RemoteApp sessions and does not apply to Remote Desktop sessions.\n\nIf you enable or do not configure this policy setting, RemoteApp sessions on RD Session Host servers will have the enhanced shell experience.\n\nIf you disable this policy setting, RemoteApp sessions will not have the enhanced shell experience and will use the legacy shell behavior. This may be needed if compatibility issues arise in published RemoteApp programs.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-ts-server-remoteapp-use-shellappruntime"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_ts_server_remoteapp_use_shellappruntime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_ts_server_remoteapp_use_shellappruntime_1","displayName":"Enabled","description":null,"helpText":null}]},"08bd4d26dfe6ad11":{"id":"device_vendor_msft_policy_config_userrights_adjustmemoryquotasforprocess","displayName":"Adjust Memory Quotas For Process","description":"Adjust memory quotas for a process - This privilege determines who can change the maximum memory that can be consumed by a process. This privilege is useful for system tuning on a group or user basis.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#adjustmemoryquotasforprocess"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"0819760aac099db1":{"id":"linux_mdatp_managed_cloudservice_automaticsamplesubmissionconsent","displayName":"Enable automatic sample submissions","description":"Sends sample files to Microsoft to help protect device users and your organization from potential threats","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#enable--disable-automatic-sample-submissions"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"linux_mdatp_managed_cloudservice_automaticsamplesubmissionconsent_none","displayName":"None","description":null,"helpText":null},{"id":"linux_mdatp_managed_cloudservice_automaticsamplesubmissionconsent_safe","displayName":"Safe","description":null,"helpText":null},{"id":"linux_mdatp_managed_cloudservice_automaticsamplesubmissionconsent_all","displayName":"All","description":null,"helpText":null}]},"08e9aeab78edf4f6":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon47","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"08b0aa144580ebb1":{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_noaddfromnetwork","displayName":"Hide the \"Add programs from your network\" option (User)","description":"Prevents users from viewing or installing published programs.\r\n\r\nThis setting removes the \"Add programs from your network\" section from the Add New Programs page. The \"Add programs from your network\" section lists published programs and provides an easy way to install them.\r\n\r\nPublished programs are those programs that the system administrator has explicitly made available to the user with a tool such as Windows Installer. Typically, system administrators publish programs to notify users that the programs are available, to recommend their use, or to enable users to install them without having to search for installation files.\r\n\r\nIf you enable this setting, users cannot tell which programs have been published by the system administrator, and they cannot use Add or Remove Programs to install published programs. However, they can still install programs by using other methods, and they can view and install assigned (partially installed) programs that are offered on the desktop or on the Start menu.\r\n\r\nIf you disable this setting or do not configure it, \"Add programs from your network\" is available to all users.\r\n\r\nNote: If the \"Hide Add New Programs page\" setting is enabled, this setting is ignored.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-addremoveprograms#admx-addremoveprograms-noaddfromnetwork"],"categoryId":"023e0367-b563-4fae-8fb6-589c836ee223","categoryName":"Add or Remove Programs","options":[{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_noaddfromnetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_noaddfromnetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"08039a8cafefbfec":{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoaddremovetoolbar","displayName":"Prevent users from adding or removing toolbars (User)","description":"This policy setting allows you to prevent users from adding or removing toolbars.\r\n\r\nIf you enable this policy setting, the user is not allowed to add or remove any toolbars to the taskbar. Applications are not able to add toolbars either.\r\n\r\nIf you disable or do not configure this policy setting, the users and applications are able to add toolbars to the taskbar.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnoaddremovetoolbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoaddremovetoolbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoaddremovetoolbar_1","displayName":"Enabled","description":null,"helpText":null}]},"0869f2d16dcb83ef":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended","displayName":"Use System Default Printer as Default (User)","description":"Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"085e840c326aac4e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation","displayName":"Set the roaming profile directory (User)","description":"Configures the directory that Google Chrome will use for storing the roaming copy of the profiles.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory to store the roaming copy of the profiles if the RoamingProfileSupportEnabled policy has been enabled. If the RoamingProfileSupportEnabled policy is disabled or left unset the value stored in this policy is not used.\r\n\r\nSee https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.\r\n\r\nOn non-Windows platforms, this policy must be set for roaming profiles to work.\r\n\r\nOn Windows, if this policy is left unset, the default roaming profile path will be used.\r\n\r\nExample value: ${roaming_app_data}\\chrome-profile","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"0801810d6f714544":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_firstpartysetsoverrides","displayName":"Override First-Party Sets. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":null},"088d0394f7e566ef":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation","displayName":"Check for accessibility issues while editing (User)","description":"This policy setting controls whether accessibility issues are checked for automatically while the user is editing a workbook. By default, accessibility issues aren’t checked for automatically.\r\n\r\nIf you enable this policy setting, accessibility issues are checked for automatically and users won’t be able to turn it off. The status bar will indicate if accessibility recommendations are available to make the workbook more usable by people with disabilities.\r\n\r\nIf you disable or don’t configure this policy setting, accessibility issues won’t be checked for automatically while editing a workbook. Users can turn on automatic checking by going to File > Options > Ease of Access.\r\n","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_1","displayName":"Enabled","description":null,"helpText":null}]},"0829e289ca308afc":{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid","displayName":"Allow software to run or install even if the signature is invalid (User)","description":"This policy setting allows you to manage whether software, such as ActiveX controls and file downloads, can be installed or run by the user even though the signature is invalid. An invalid signature might indicate that someone has tampered with the file.\n\nIf you enable this policy setting, users will be prompted to install or run files with an invalid signature.\n\nIf you disable this policy setting, users cannot run or install files with an invalid signature.\n\nIf you do not configure this policy, users can choose to run or install files with an invalid signature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsoftwarewhensignatureisinvalid"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_1","displayName":"Enabled","description":null,"helpText":null}]},"08ad367393f3574b":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowaccesstodatasources"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"083a3dedacd70e84":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowuserdatapersistence"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"085a0f13b0f4f4db":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service (User)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\r\nThese assets can be config files or Machine Learning models that power the features that use this service.\r\n\r\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\r\n\r\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0844391b5c70f725":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_loopbacknetworkallowedforurlsdesc","displayName":"Allow sites to make network requests to the local device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"0836cdc1d49178b2":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_insecurecontentblockedforurlsdesc","displayName":"Block insecure content on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"08f446364e7b7fce":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"0857cbdca1927c86":{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice","displayName":"Use the Sensitivity feature in Office to apply sensitivity labels to PDFs (User)","description":"This policy setting controls whether sensitivity labels powered by Microsoft Purview Information Protection are applied to PDFs created in Word, Excel, and PowerPoint.​\r\n\r\nIf you enable this policy setting or don’t configure it, PDFs will inherit the sensitivity label and encryption from the source Word, Excel, and PowerPoint document.\r\n\r\nIf you disable this policy setting, PDFs created in Word, Excel, and PowerPoint do not inherit their source file’s sensitivity labels and encryption. When the source file is encrypted, users who do not have the rights to remove protection cannot export to PDF.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise. For more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2220953.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice_1","displayName":"Enabled","description":null,"helpText":null}]},"088f4451409ed23f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview","displayName":"Outlook: 'send for review' (User)","description":"\"Enable 'send for review\"': Enables the Send For Review feature. | \"Exclude author's e-mail in documents\": Enables the Send For Review feature, but the authors e-mail is not recorded on the sent document. | \"Disable 'send for review\"': Disables the Send For Review feature.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},"081399b5f73074ce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic","displayName":"Icelandic (User)","description":"Enables the editing language Icelandic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic_1","displayName":"Enabled","description":null,"helpText":null}]},"0873c96714c210ae":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5","displayName":"Block signing into Office (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_0","displayName":"Both IDs allowed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_1","displayName":"Microsoft Account only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_2","displayName":"Org ID only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_3","displayName":"None allowed","description":null,"helpText":null}]},"0837573e143ab890":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"08c1d514faf85572":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_pathcolon09","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"0822b2cc11f663c6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05","displayName":"Trusted Catalog Location #5 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_1","displayName":"Enabled","description":null,"helpText":null}]},"08e5f045c8c8f58a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday_l_empty428","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},"08cb9b804eea7607":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68_1","displayName":"True","description":null,"helpText":null}]},"08e944b0740b30b5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly","displayName":"Delete expired items (e-mail folders only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly_1","displayName":"True","description":null,"helpText":null}]},"08546659c786cfa6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch","displayName":"Turn off Hierarchical Address Book search (User)","description":"This policy setting controls entry points to search in the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, all entry points to search features in the HAB will be turned off. \r\n\r\nIf you disable or do not configure this policy setting, all entry points to search features in the HAB will be enabled.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch_1","displayName":"Enabled","description":null,"helpText":null}]},"0809c0cdbe567db5":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages","displayName":"Web Pages (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_1","displayName":"Enabled","description":null,"helpText":null}]},"08baf0903d474c43":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell","displayName":"Edit directly in cell (User)","description":"Allows editing directly in the selected cell.\r\n \r\nIf you enable this setting, users can directly edit a cell's value.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell_1","displayName":"Enabled","description":null,"helpText":null}]},"085a06e1f43daf73":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11","displayName":"Weeks (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_0","displayName":"w","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_1","displayName":"wk","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_2","displayName":"week","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_4","displayName":"\r\n ","description":null,"helpText":null}]},"08c06b744c09184d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34","displayName":"Project Guide Functionality and Layout page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34_1","displayName":"Use Microsoft Project's Default page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34_0","displayName":"Use a custom page","description":null,"helpText":null}]},"08b4b26dcbb49b9c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_1","displayName":"Enabled","description":null,"helpText":null}]},"08cb34573e734d0e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"08c98b03c6c54e2f":{"id":"com.apple.airplay_passwords_item_deviceid","displayName":"Device ID","description":"The device ID of the AirPlay destination; used in macOS.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},"087c503869dac3e1":{"id":"com.apple.ldap.account_ldapaccounthostname","displayName":"LDAP Account Host Name","description":"The server’s address.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},"082f3d79e4eeda3c":{"id":"com.apple.loginwindow_shutdowndisabled","displayName":"Shut Down Disabled","description":"If true, disables the Shut Down button.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_shutdowndisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_shutdowndisabled_true","displayName":"True","description":null,"helpText":null}]},"088f6d301d9a3d22":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"08089dbe8e99b469":{"id":"com.apple.managedclient.preferences_defaultclipboardsetting","displayName":"Default clipboard site permission","description":"This policy controls the default value for the clipboard site permission.\n\nSetting the policy to 2 blocks sites from using the clipboard site permission.\n\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\n\nThis policy can be overridden for specific URL patterns using the \"ClipboardAllowedForUrls\" and \"ClipboardBlockedForUrls\" policies.\n\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\n\nPolicy options mapping:\n\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\n\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultclipboardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultclipboardsetting_0","displayName":"Do not allow any site to use the clipboard site permission","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultclipboardsetting_1","displayName":"Allow sites to ask the user to grant the clipboard site permission","description":null,"helpText":null}]},"08c35d1b352fde88":{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection","displayName":"Enforcement level","description":"Specifies if tamper protection is disabled, in audit mode, or enforced","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":[{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_0","displayName":"disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_1","displayName":"audit","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enforcementlevel_tamperprotection_2","displayName":"block","description":null,"helpText":null}]},"082fa2b27782e1d5":{"id":"com.apple.managedclient.preferences_updatecache","displayName":"Update cache server","description":"Specify the HTTP(S) URL of the server that you use for cached package updates (PKG files). You must include a trailing forward slash.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/deployoffice/mac/mau-preferences#updatecache"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"082fc533adba33e1":{"id":"com.apple.mcx_dontallowfdedisable","displayName":"Prevent FileVault From Being Disabled","description":"Set to true to prevent FileVault from being disabled.","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":[{"id":"com.apple.mcx_dontallowfdedisable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_dontallowfdedisable_true","displayName":"True","description":null,"helpText":null}]},"08b0d67e5be86afb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\n\nIf you disable or don't set this policy, the browser uses the default behavior of cross-site auth. This behavior is to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials need to be provided independently in the context of both sites. Cached proxy credentials are reused across sites.\n\nIf you enable this policy, HTTP auth credentials entered in the context of one site is automatically used in the context of another site.\n\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\n\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.globallyscopehttpauthcacheenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"08d12dbefd6ab9c2":{"id":"com.microsoft.edge.mamedgeappconfigsettings.homepagelocation","displayName":"Configure the home page URL","description":"Configures the default home page URL in Microsoft Edge.\n\nThe home page is the page opened by the Home button. \"RestoreOnStartup\" policies control the pages that open on startup.\n\nYou can either set a URL here or set the home page to open the new tab page 'edge://newtab'. By default, the Home button opens the new tab page (as configured by the user or with the policy \"NewTabPageLocation\"), and the user is able to choose between the URL configured by this policy and the new tab page.\n\nIf you enable this policy, users can't change their home page URL, but they can choose the behavior for the Home button to open either the set URL or the new tab page. If you wish to enforce the usage of the set URL, you must also configure \"HomepageIsNewTabPage\"=Disabled.\n\nIf you disable or don't configure this policy, users can choose their own home page, as long as the \"HomepageIsNewTabPage\" policy isn't enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"08ec64333d2833cd":{"id":"com.microsoft.edge.mamedgeappconfigsettings.localfontsblockedforurls","displayName":"Block Local Fonts permission on these sites","description":"Specifies a list of site URL patterns for which the local fonts permission is automatically denied. Sites in this list are prevented from accessing information about local fonts.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are supported. This policy matches based on origin only; any path in the URL pattern is ignored.\n\nIf a site isn't included in this policy, the \"DefaultLocalFontsSetting\" policy applies if configured. Otherwise, the browser default behavior applies, and users can choose the permission on a per-site basis.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"08cc2c119dcc3c94":{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled","displayName":"Wallet Donation Enabled (Deprecated)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.\n\nThis policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"088f790c26e6ff19":{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype","displayName":"Choose drive encryption method and cipher strength (Windows 10 [Version 1511] and later)","description":"This policy setting allows you to configure the algorithm and cipher strength used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption method has no effect if the drive is already encrypted, or if encryption is in progress.\n\nIf you enable this policy setting you will be able to configure an encryption algorithm and key cipher strength for fixed data drives, operating system drives, and removable data drives individually. For fixed and operating system drives, we recommend that you use the XTS-AES algorithm. For removable drives, you should use AES-CBC 128-bit or AES-CBC 256-bit if the drive will be used in other devices that are not running Windows 10 (Version 1511).\n\nIf you disable or do not configure this policy setting, BitLocker will use AES with the same bit strength (128-bit or 256-bit) as the \"Choose drive encryption method and cipher strength (Windows Vista, Windows Server 2008, Windows 7)\" and \"Choose drive encryption method and cipher strength\" policy settings (in that order), if they are set. If none of the policies are set, BitLocker will use the default encryption method of XTS-AES 128-bit or the encryption method specified by the setup script.”\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_1","displayName":"Enabled","description":null,"helpText":null}]},"086401ae018ef535":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxdownloadtime_bits_maxdownloadseconds","displayName":"Active Job Timeout in seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"087acde96e993941":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_searchlist_dns_searchlistlabel","displayName":"DNS Suffixes:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},"080ceec9a18dda89":{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp","displayName":"Restrict potentially unsafe HTML Help functions to specified folders","description":"This policy setting allows you to restrict certain HTML Help commands to function only in HTML Help (.chm) files within specified folders and their subfolders. Alternatively, you can disable these commands on the entire system. It is strongly recommended that only folders requiring administrative privileges be added to this policy setting.\r\n\r\n If you enable this policy setting, the commands function only for .chm files in the specified folders and their subfolders.\r\n\r\n To restrict the commands to one or more folders, enable the policy setting and enter the desired folders in the text box on the Settings tab of the Policy Properties dialog box. Use a semicolon to separate folders. For example, to restrict the commands to only .chm files in the %windir%\\help folder and D:\\somefolder, add the following string to the edit box: \"%windir%\\help;D:\\somefolder\".\r\n\r\n Note: An environment variable may be used, (for example, %windir%), as long as it is defined on the system. For example, %programfiles% is not defined on some early versions of Windows.\r\n\r\n The \"Shortcut\" command is used to add a link to a Help topic, and runs executables that are external to the Help file. The \"WinHelp\" command is used to add a link to a Help topic, and runs a WinHLP32.exe Help (.hlp) file.\r\n\r\n To disallow the \"Shortcut\" and \"WinHelp\" commands on the entire local system, enable the policy setting and leave the text box on the Settings tab of the Policy Properties dialog box blank.\r\n\r\n If you disable or do not configure this policy setting, these commands are fully functional for all Help files.\r\n\r\n Note: Only folders on the local computer can be specified in this policy setting. You cannot use this policy setting to enable the \"Shortcut\" and \"WinHelp\" commands for .chm files that are stored on mapped drives or accessed using UNC paths.\r\n\r\n For additional options, see the \"Restrict these programs from being launched from Help\" policy.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-helpqualifiedrootdir-comp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_helpqualifiedrootdir_comp_1","displayName":"Enabled","description":null,"helpText":null}]},"086e51fac026a8a9":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather","displayName":"Weather","description":"This policy setting configures the synchronization of user settings for the Weather app.\r\nBy default, the user settings of Weather sync between computers. Use the policy setting to prevent the user settings of Weather from synchronizing between computers.\r\nIf you enable this policy setting, Weather user settings continue to sync.\r\nIf you disable this policy setting, Weather user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-weather"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_weather_1","displayName":"Enabled","description":null,"helpText":null}]},"08278a0a4882ba6d":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen","displayName":"Configure Windows Defender SmartScreen","description":"This policy allows you to turn Windows Defender SmartScreen on or off. SmartScreen helps protect PCs by warning users before running potentially malicious programs downloaded from the Internet. This warning is presented as an interstitial dialog shown before running an app that has been downloaded from the Internet and is unrecognized or known to be malicious. No dialog is shown for apps that do not appear to be suspicious.\r\n\r\nSome information is sent to Microsoft about files and programs run on PCs with this feature enabled.\r\n\r\nIf you enable this policy, SmartScreen will be turned on for all users. Its behavior can be controlled by the following options:\r\n\r\n• Warn and prevent bypass\r\n• Warn\r\n\r\nIf you enable this policy with the \"Warn and prevent bypass\" option, SmartScreen's dialogs will not present the user with the option to disregard the warning and run the app. SmartScreen will continue to show the warning on subsequent attempts to run the app.\r\n\r\nIf you enable this policy with the \"Warn\" option, SmartScreen's dialogs will warn the user that the app appears suspicious, but will permit the user to disregard the warning and run the app anyway. SmartScreen will not warn the user again for that app if the user tells SmartScreen to run the app.\r\n\r\nIf you disable this policy, SmartScreen will be turned off for all users. Users will not be warned if they try to run suspicious apps from the Internet.\r\n\r\nIf you do not configure this policy, SmartScreen will be enabled by default, but users may change their settings.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enablesmartscreen"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_1","displayName":"Enabled","description":null,"helpText":null}]},"081fbc77726e4b46":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos","displayName":"Microsoft Photos ** (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_photos_1","displayName":"True","description":null,"helpText":null}]},"0807080aed309add":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply","description":"Setting the policy specifies a list of origins (URLs) or hostname patterns (such as *.example.com) for which security restrictions on insecure origins won't apply. Organizations can specify origins for legacy applications that can't deploy TLS or set up a staging server for internal web development, so developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled \"Not Secure\" in the address bar.\r\n\r\nSetting a list of URLs in this policy amounts to setting the command-line flag --unsafely-treat-insecure-origin-as-secure to a comma-separated list of the same URLs. The policy overrides the command-line flag and UnsafelyTreatInsecureOriginAsSecure, if present.\r\n\r\nFor more information on secure contexts, see Secure Contexts ( https://www.w3.org/TR/secure-contexts ).\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_1","displayName":"Enabled","description":null,"helpText":null}]},"0816430102a019b3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_autoselectcertificateforurlsdesc","displayName":"Automatically select client certificates for these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"089ffd7f874a6716":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabelforbrowser_enterprisecustomlabelforbrowser","displayName":"Set a custom enterprise label for a managed browser (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"085e4c2e32125450":{"id":"device_vendor_msft_policy_config_internetexplorer_donotallowuserstoaddsites","displayName":"Security Zones: Do not allow users to add/delete sites","description":"Prevents users from adding or removing sites from security zones. A security zone is a group of Web sites with the same security level.\n\nIf you enable this policy, the site management settings for security zones are disabled. (To see the site management settings for security zones, in the Internet Options dialog box, click the Security tab, and then click the Sites button.)\n\nIf you disable this policy or do not configure it, users can add Web sites to or remove sites from the Trusted Sites and Restricted Sites zones, and alter settings for the Local Intranet zone.\n\nThis policy prevents users from changing site management settings for security zones established by the administrator.\n\nNote: The \"Disable the Security page\" policy (located in \\User Configuration\\Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel), which removes the Security tab from the interface, takes precedence over this policy. If it is enabled, this policy is ignored.\n\nAlso, see the \"Security zones: Use only machine settings\" policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-donotallowuserstoaddsites"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_donotallowuserstoaddsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_donotallowuserstoaddsites_1","displayName":"Enabled","description":null,"helpText":null}]},"083c160fb7505eac":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions","displayName":"Java permissions","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, the permission is set to Medium Safety.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonejavapermissions"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},"088afe96b20cf281":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets","displayName":"Allow scriptlets","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowscriptlets"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"084cf3f4187337e6":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript","displayName":"Allow updates to status bar via script","description":"This policy setting allows you to manage whether script is allowed to update the status bar within the zone.\n\nIf you enable this policy setting, script is allowed to update the status bar.\n\nIf you disable or do not configure this policy setting, script is not allowed to update the status bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowupdatestostatusbarviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"0866d8aab4509699":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_recoveryconsole_allowfloppycopyandaccesstoalldrivesandallfolders","displayName":"Recovery Console Allow Floppy Copy And Access To All Drives And All Folders","description":"Recovery console: Allow floppy copy and access to all drives and all folders Enabling this security option makes the Recovery Console SET command available, which allows you to set the following Recovery Console environment variables: AllowWildCards: Enable wildcard support for some commands (such as the DEL command). AllowAllPaths: Allow access to all files and folders on the computer. AllowRemovableMedia: Allow files to be copied to removable media, such as a floppy disk. NoCopyPrompt: Do not prompt when overwriting an existing file. Default: This policy is not defined and the recover console SET command is not available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#recoveryconsole_allowfloppycopyandaccesstoalldrivesandallfolders"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"0809361075111405":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_applicationlocalevalue","displayName":"Application locale (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},"08a16ea53da5215a":{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\r\n\r\n * 'WebHidBlockedForUrls' (Block the WebHID API on these sites) (if there is a match),\r\n\r\n * 'DefaultWebHidGuardSetting' (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with 'WebHidBlockedForUrls'. Neither policy takes precedence if a URL matches both patterns.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"087bef07e4adc75a":{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning","description":"This policy controls whether third-party storage partitioning is allowed by default.\r\n\r\nIf this policy is set to 1 - AllowPartitioning, or unset, third-party storage partitioning will be allowed by default. This default may be overridden for specific top-level origins by other means.\r\n\r\nIf this policy is set to 2 - BlockPartitioning, third-party storage partitioning will be disabled for all contexts.\r\n\r\nUse ThirdPartyStoragePartitioningBlockedForOrigins to disable third-party storage partitioning for specific top-level origins.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowPartitioning (1) = Allow third-party storage partitioning by default.\r\n\r\n* BlockPartitioning (2) = Disable third-party storage partitioning.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"08a1d52972883274":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket","displayName":"Maximum number of concurrent connections to the proxy server for WebSocket requests","description":"Specifies the maximum number of simultaneous connections to a proxy server for WebSocket requests.\r\n\r\nTo configure limits for non-WebSocket requests, see the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server) policy.\r\n\r\nIf you don't configure this policy, the default value of 32 is used.\r\n\r\nSome web applications maintain multiple concurrent connections (for example, long-lived or hanging requests). Setting a value lower than the default may cause networking delays when many such applications are open.\r\n\r\nSome proxy servers cannot handle a high number of concurrent connections per client. In these cases, reducing the value of this policy may improve reliability.\r\n\r\nThe supported range is 6 to 256:\r\n- Values less than 6 are treated as 6.\r\n- Values greater than 256 are treated as 256.\r\n\r\nWe recommend modifying this value only if required by your proxy server configuration or network environment.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_1","displayName":"Enabled","description":null,"helpText":null}]},"083312513e86b8e8":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84. (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThe Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and have been disabled by default starting in M80. This policy allows these features to be selectively re-enabled until M84.\r\n\r\n If you set this policy is set to True, the Web Components v0 features will be enabled for all sites.\r\n\r\n If you set this policy to False or don't set this policy, the Web Components v0 features will be disabled by default, starting in M80.\r\n\r\n This policy will be removed after Microsoft Edge 84.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"08151b5e121f7e32":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_visioexe117","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_visioexe117_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_visioexe117_1","displayName":"True","description":null,"helpText":null}]},"0865a9a3667ea8e7":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature","displayName":"Mime Sniffing Safety Feature","description":"Mime Sniffing","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_1","displayName":"Enabled","description":null,"helpText":null}]},"08e865a554a7dee3":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_excelexe1","displayName":"excel.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_excelexe1_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_excelexe1_1","displayName":"True","description":null,"helpText":null}]},"08bc8c8516040176":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessbackgroundspatialperception_userincontroloftheseapps","displayName":"Let Apps Access Background Spatial Perception User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. The user is able to control the user movements privacy setting for the listed apps. This setting overrides the default LetAppsAccessBackgroundSpatialPerception policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessbackgroundspatialperception_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"08748f37a6cdd704":{"id":"device_vendor_msft_policy_config_remotedesktopservices_ts_server_remoteapp_use_shellappruntime","displayName":"Enable enhanced shell experience for RemoteApp","description":"This policy setting enables an enhanced shell experience for RemoteApp sessions, offering support for default file associations, Run/RunOnce registry keys, and more. This policy setting applies only to RemoteApp sessions and does not apply to Remote Desktop sessions.\n\nIf you enable or do not configure this policy setting, RemoteApp sessions on RD Session Host servers will have the enhanced shell experience.\n\nIf you disable this policy setting, RemoteApp sessions will not have the enhanced shell experience and will use the legacy shell behavior. This may be needed if compatibility issues arise in published RemoteApp programs.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-ts-server-remoteapp-use-shellappruntime"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_ts_server_remoteapp_use_shellappruntime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_ts_server_remoteapp_use_shellappruntime_1","displayName":"Enabled","description":null,"helpText":null}]},"08bd4d26dfe6ad11":{"id":"device_vendor_msft_policy_config_userrights_adjustmemoryquotasforprocess","displayName":"Adjust Memory Quotas For Process","description":"Adjust memory quotas for a process - This privilege determines who can change the maximum memory that can be consumed by a process. This privilege is useful for system tuning on a group or user basis.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#adjustmemoryquotasforprocess"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"0819760aac099db1":{"id":"linux_mdatp_managed_cloudservice_automaticsamplesubmissionconsent","displayName":"Enable automatic sample submissions","description":"Sends sample files to Microsoft to help protect device users and your organization from potential threats","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#enable--disable-automatic-sample-submissions"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"linux_mdatp_managed_cloudservice_automaticsamplesubmissionconsent_none","displayName":"None","description":null,"helpText":null},{"id":"linux_mdatp_managed_cloudservice_automaticsamplesubmissionconsent_safe","displayName":"Safe","description":null,"helpText":null},{"id":"linux_mdatp_managed_cloudservice_automaticsamplesubmissionconsent_all","displayName":"All","description":null,"helpText":null}]},"085b868817c2e6de":{"id":"plugin_filter_browsers","displayName":"Browsers","description":"Settings that control the browser filter. If not present, the system doesn't use browser filtering.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"08a2ece20ba15f42":{"id":"plugin_filter_sockets_enabled","displayName":"Enabled","description":"If `true`, enables the filtering of socket traffic.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":[{"id":"plugin_filter_sockets_enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"plugin_filter_sockets_enabled_true","displayName":"Enabled","description":null,"helpText":null}]},"08e9aeab78edf4f6":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon47","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"08b0aa144580ebb1":{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_noaddfromnetwork","displayName":"Hide the \"Add programs from your network\" option (User)","description":"Prevents users from viewing or installing published programs.\r\n\r\nThis setting removes the \"Add programs from your network\" section from the Add New Programs page. The \"Add programs from your network\" section lists published programs and provides an easy way to install them.\r\n\r\nPublished programs are those programs that the system administrator has explicitly made available to the user with a tool such as Windows Installer. Typically, system administrators publish programs to notify users that the programs are available, to recommend their use, or to enable users to install them without having to search for installation files.\r\n\r\nIf you enable this setting, users cannot tell which programs have been published by the system administrator, and they cannot use Add or Remove Programs to install published programs. However, they can still install programs by using other methods, and they can view and install assigned (partially installed) programs that are offered on the desktop or on the Start menu.\r\n\r\nIf you disable this setting or do not configure it, \"Add programs from your network\" is available to all users.\r\n\r\nNote: If the \"Hide Add New Programs page\" setting is enabled, this setting is ignored.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-addremoveprograms#admx-addremoveprograms-noaddfromnetwork"],"categoryId":"023e0367-b563-4fae-8fb6-589c836ee223","categoryName":"Add or Remove Programs","options":[{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_noaddfromnetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_noaddfromnetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"08039a8cafefbfec":{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoaddremovetoolbar","displayName":"Prevent users from adding or removing toolbars (User)","description":"This policy setting allows you to prevent users from adding or removing toolbars.\r\n\r\nIf you enable this policy setting, the user is not allowed to add or remove any toolbars to the taskbar. Applications are not able to add toolbars either.\r\n\r\nIf you disable or do not configure this policy setting, the users and applications are able to add toolbars to the taskbar.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnoaddremovetoolbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoaddremovetoolbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoaddremovetoolbar_1","displayName":"Enabled","description":null,"helpText":null}]},"0869f2d16dcb83ef":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended","displayName":"Use System Default Printer as Default (User)","description":"Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpreviewusesystemdefaultprinter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"085e840c326aac4e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation","displayName":"Set the roaming profile directory (User)","description":"Configures the directory that Google Chrome will use for storing the roaming copy of the profiles.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory to store the roaming copy of the profiles if the RoamingProfileSupportEnabled policy has been enabled. If the RoamingProfileSupportEnabled policy is disabled or left unset the value stored in this policy is not used.\r\n\r\nSee https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.\r\n\r\nOn non-Windows platforms, this policy must be set for roaming profiles to work.\r\n\r\nOn Windows, if this policy is left unset, the default roaming profile path will be used.\r\n\r\nExample value: ${roaming_app_data}\\chrome-profile","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"0801810d6f714544":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_firstpartysetsoverrides","displayName":"Override First-Party Sets. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":null},"088d0394f7e566ef":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation","displayName":"Check for accessibility issues while editing (User)","description":"This policy setting controls whether accessibility issues are checked for automatically while the user is editing a workbook. By default, accessibility issues aren’t checked for automatically.\r\n\r\nIf you enable this policy setting, accessibility issues are checked for automatically and users won’t be able to turn it off. The status bar will indicate if accessibility recommendations are available to make the workbook more usable by people with disabilities.\r\n\r\nIf you disable or don’t configure this policy setting, accessibility issues won’t be checked for automatically while editing a workbook. Users can turn on automatic checking by going to File > Options > Ease of Access.\r\n","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_backgroundaccessibilitycheckerinformation_1","displayName":"Enabled","description":null,"helpText":null}]},"0829e289ca308afc":{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid","displayName":"Allow software to run or install even if the signature is invalid (User)","description":"This policy setting allows you to manage whether software, such as ActiveX controls and file downloads, can be installed or run by the user even though the signature is invalid. An invalid signature might indicate that someone has tampered with the file.\n\nIf you enable this policy setting, users will be prompted to install or run files with an invalid signature.\n\nIf you disable this policy setting, users cannot run or install files with an invalid signature.\n\nIf you do not configure this policy, users can choose to run or install files with an invalid signature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsoftwarewhensignatureisinvalid"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsoftwarewhensignatureisinvalid_1","displayName":"Enabled","description":null,"helpText":null}]},"08ad367393f3574b":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowaccesstodatasources"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"083a3dedacd70e84":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowuserdatapersistence"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"085a0f13b0f4f4db":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service (User)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\r\nThese assets can be config files or Machine Learning models that power the features that use this service.\r\n\r\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\r\n\r\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_edgeassetdeliveryserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0844391b5c70f725":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_loopbacknetworkallowedforurlsdesc","displayName":"Allow sites to make network requests to the local device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"0836cdc1d49178b2":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_insecurecontentblockedforurlsdesc","displayName":"Block insecure content on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"08f446364e7b7fce":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"0857cbdca1927c86":{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice","displayName":"Use the Sensitivity feature in Office to apply sensitivity labels to PDFs (User)","description":"This policy setting controls whether sensitivity labels powered by Microsoft Purview Information Protection are applied to PDFs created in Word, Excel, and PowerPoint.​\r\n\r\nIf you enable this policy setting or don’t configure it, PDFs will inherit the sensitivity label and encryption from the source Word, Excel, and PowerPoint document.\r\n\r\nIf you disable this policy setting, PDFs created in Word, Excel, and PowerPoint do not inherit their source file’s sensitivity labels and encryption. When the source file is encrypted, users who do not have the rights to remove protection cannot export to PDF.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise. For more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2220953.","helpText":"","infoUrls":[],"categoryId":"5b1be2c5-9939-4b2e-b29b-b22069455c90","categoryName":"Microsoft Save As PDF and XPS add-ins","options":[{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v13~policy~l_microsoftofficesystem~l_pdfandxps_l_pdfprotectionfromoffice_1","displayName":"Enabled","description":null,"helpText":null}]},"088f4451409ed23f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview","displayName":"Outlook: 'send for review' (User)","description":"\"Enable 'send for review\"': Enables the Send For Review feature. | \"Exclude author's e-mail in documents\": Enables the Send For Review feature, but the authors e-mail is not recorded on the sent document. | \"Disable 'send for review\"': Disables the Send For Review feature.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},"081399b5f73074ce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic","displayName":"Icelandic (User)","description":"Enables the editing language Icelandic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_icelandic_1","displayName":"Enabled","description":null,"helpText":null}]},"0873c96714c210ae":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5","displayName":"Block signing into Office (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_0","displayName":"Both IDs allowed","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_1","displayName":"Microsoft Account only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_2","displayName":"Org ID only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_signinoptions_l_signinoptions5_3","displayName":"None allowed","description":null,"helpText":null}]},"0837573e143ab890":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"08c1d514faf85572":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc09_l_pathcolon09","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"0822b2cc11f663c6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05","displayName":"Trusted Catalog Location #5 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog05_1","displayName":"Enabled","description":null,"helpText":null}]},"08e5f045c8c8f58a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofitemstoscanfromtoday_l_empty428","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},"08cb9b804eea7607":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage68_1","displayName":"True","description":null,"helpText":null}]},"08e944b0740b30b5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly","displayName":"Delete expired items (e-mail folders only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_deleteexpireditemsemailfoldersonly_1","displayName":"True","description":null,"helpText":null}]},"08546659c786cfa6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch","displayName":"Turn off Hierarchical Address Book search (User)","description":"This policy setting controls entry points to search in the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, all entry points to search features in the HAB will be turned off. \r\n\r\nIf you disable or do not configure this policy setting, all entry points to search features in the HAB will be enabled.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbooksearch_1","displayName":"Enabled","description":null,"helpText":null}]},"0809c0cdbe567db5":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages","displayName":"Web Pages (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_1","displayName":"Enabled","description":null,"helpText":null}]},"08baf0903d474c43":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell","displayName":"Edit directly in cell (User)","description":"Allows editing directly in the selected cell.\r\n \r\nIf you enable this setting, users can directly edit a cell's value.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"d33133b4-77df-429a-9580-ed70f7da676d","categoryName":"Edit options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjeditoptionsproj_l_pjeditdirectlycell_1","displayName":"Enabled","description":null,"helpText":null}]},"085a06e1f43daf73":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11","displayName":"Weeks (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_0","displayName":"w","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_1","displayName":"wk","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_2","displayName":"week","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjweeks_l_pjweeks11_4","displayName":"\r\n ","description":null,"helpText":null}]},"08c06b744c09184d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34","displayName":"Project Guide Functionality and Layout page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34_1","displayName":"Use Microsoft Project's Default page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_l_pjusedefaultstartpage34_0","displayName":"Use a custom page","description":null,"helpText":null}]},"08b4b26dcbb49b9c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_1","displayName":"Enabled","description":null,"helpText":null}]},"08cb34573e734d0e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/0b.json b/public/intune-definitions/0b.json index c75fbc6f6329..532e09cd6678 100644 --- a/public/intune-definitions/0b.json +++ b/public/intune-definitions/0b.json @@ -1 +1 @@ -{"0bac8a0cef114e71":{"id":"app_privacy_permissiondefaults_generickey_localnetwork","displayName":"Local Network","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the local network.\n* `Allow`: The app privacy permission default is set to allow use of the local network.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_localnetwork_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_localnetwork_1","displayName":"Allow","description":null,"helpText":null}]},"0b8b389cbde821a2":{"id":"com.apple.app.lock_app_identifier","displayName":"App Identifier","description":"The bundle identifier of the app.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},"0b4943a5fda5a3db":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance","displayName":"Weekend Allowance","description":"The weekend allowance settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"0b0ddea7f811d3e1":{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled","displayName":"Enable origin-keyed process isolation for improved security","description":"This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This may increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off.\n\nIf you enable this policy, most origins will be isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies.\n\nIf you disable this policy, origins will not be isolated from the rest of their site unless the origin explicitly requests isolation.\n\nIf you don’t configure this policy, the browser will decide which origins to isolate and when. By default, this feature is disabled. The default state may change in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#originkeyedprocessesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"0bb86211cc75dec5":{"id":"com.apple.notificationsettings_com.apple.notificationsettings","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},"0baccc59b11493c5":{"id":"com.apple.proxy.http.global_proxyserver","displayName":"Proxy Server","description":"The proxy server's network address.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},"0b87e4c098aaa88e":{"id":"com.apple.security.smartcard_com.apple.security.smartcard","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":null},"0b779321ee4c16ca":{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"0bf7284afb585eeb":{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"0b9e5d8054dd4983":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled (Deprecated)","description":"This policy is deprecated because the E-Tree feature has been removed from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"0b73bb910cf74362":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability","description":"Control if Manifest v2 extensions can be used by browser.\n\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about and the timeline of the migration hasn't been established.\n\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This follows the preceding timeline when it's established.\n\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\n\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\n\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by \"ExtensionInstallForcelist\" or \"ExtensionSettings\" with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\n\nExtensions availabilities are still controlled by other policies.\n\nPolicy options mapping:\n\n* Default (0) = Default browser behavior\n\n* Disable (1) = Manifest v2 is disabled\n\n* Enable (2) = Manifest v2 is enabled\n\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_default","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_disable","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_enable","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_enableforforcedextensions","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},"0bc68d8a2821dd4f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive","displayName":"Keep the active Microsoft Edge window with an Internet Explorer mode tab always in the foreground.","description":"This policy controls whether to always keep the active Microsoft Edge window with an Internet Explorer mode tab in the foreground.\n\nIf you enable this policy, the active Microsoft Edge window with an Internet Explorer mode tab remains in the foreground.\n\nIf you disable or don't configure this policy, the active Microsoft Edge window with an Internet Explorer mode tab isn't kept in the foreground.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive_true","displayName":"Enabled","description":null,"helpText":null}]},"0b90668debf5bf09":{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed","displayName":"Allow or deny screen capture","description":"If you enable this policy, or don't configure this policy, a webpage uses screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\nIf you disable this policy, calls to screen-share APIs fail. For example, if you're using a web-based online meeting, video or screen sharing won't work. However, this policy isn't considered.\n(and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies:\n\"ScreenCaptureAllowedByOrigins\",\n\"WindowCaptureAllowedByOrigins\",\n\"TabCaptureAllowedByOrigins\",\n\"SameOriginTabCaptureAllowedByOrigins\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"0b0b2a3d6087bcf5":{"id":"com.microsoft.edge.mamedgeappconfigsettings.windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites","description":"Lets you configure a list of site URL patterns that specify sites which can automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission follows the browser's defaults and lets users choose this permission per site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"0ba21904577962f5":{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock","displayName":"Allow users to select when a password is required when resuming from connected standby","description":"This policy setting allows you to control whether a user can change the time before a password is required when a Connected Standby device screen turns off.\r\n\r\nIf you enable this policy setting, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.\r\n\r\nIf you disable this policy setting, a user cannot change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.\r\n\r\nIf you don't configure this policy setting on a domain-joined device, a user cannot change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.\r\n\r\nIf you don't configure this policy setting on a workgroup device, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-allowdomaindelaylock"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock_1","displayName":"Enabled","description":null,"helpText":null}]},"0b945b841774da63":{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode","displayName":"Allow Distributed Link Tracking clients to use domain resources","description":"Specifies that Distributed Link Tracking clients in this domain may use the Distributed Link Tracking (DLT) server, which runs on domain controllers. The DLT client enables programs to track linked files that are moved within an NTFS volume, to another NTFS volume on the same computer, or to an NTFS volume on another computer. The DLT client can more reliably track links when allowed to use the DLT server. This policy should not be set unless the DLT server is running on all domain controllers in the domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-distributedlinktracking#admx-distributedlinktracking-dlt-allowdomainmode"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode_1","displayName":"Enabled","description":null,"helpText":null}]},"0b55dab3d1ff8bfb":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled","displayName":"Allow or Disallow use of the Offline Files feature","description":"This policy setting determines whether the Offline Files feature is enabled. Offline Files saves a copy of network files on the user's computer for use when the computer is not connected to the network.\r\n\r\nIf you enable this policy setting, Offline Files is enabled and users cannot disable it.\r\n\r\nIf you disable this policy setting, Offline Files is disabled and users cannot enable it.\r\n\r\nIf you do not configure this policy setting, Offline Files is enabled on Windows client computers, and disabled on computers running Windows Server, unless changed by the user.\r\n\r\nNote: Changes to this policy setting do not take effect until the affected computer is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-enabled"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0b128b99830eb4fe":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended","displayName":"Always Open PDF files externally","description":"Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application.\r\n\r\nSetting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"0ba2f208038ddd6f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended","displayName":"Show Full URLs","description":"This feature enables display of the full URL in the address bar.\r\nIf this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains.\r\nIf this policy is set to False, then the default URL display will apply.\r\nIf this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"0b52a249b76bfd88":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":null},"0bbe704ef2c8447f":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcremoveorphanedostfilesonlogoff","displayName":"Remove Orphaned OST Files On Logoff","description":"Removes duplicate OST files.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\RemoveOrphanedOSTFilesOnLogoff\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcremoveorphanedostfilesonlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcremoveorphanedostfilesonlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"0b8b241450227efe":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates","description":"Notify users that they need to restart Microsoft Edge to apply a pending update.\r\n\r\nIf you don't configure this policy, Microsoft Edge adds a recycle icon at the far right of the top menu bar to prompt users to restart the browser to apply the update.\r\n\r\nIf you enable this policy and set it to 'Recommended' (1), a recurring warning prompts users that a restart is recommended. Users can dismiss this warning and defer the restart.\r\n\r\nIf you set the policy to 'Required' (2), a recurring warning prompts users that the browser will be restarted automatically as soon as a notification period passes. The default period is seven days. You can configure this period with the 'RelaunchNotificationPeriod' (Set the time period for update notifications) policy.\r\n\r\nThe user's session is restored when the browser restarts.\r\n\r\n* 1 = Recommended - Show a recurring prompt to the user indicating that a restart is recommended\r\n\r\n* 2 = Required - Show a recurring prompt to the user indicating that a restart is required","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"0b78686b72a41eac":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled","displayName":"Enable the default search provider","description":"Enables the ability to use a default search provider.\r\n\r\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\r\n\r\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\r\n\r\nIf you disable this policy, the user can't search from the address bar.\r\n\r\nIf you enable or disable this policy, users can't change or override it.\r\n\r\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0b022a774b1c0d7a":{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_1","displayName":"Allow all websites to perform automatic downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_2","displayName":"Don't allow any website to perform automatic downloads","description":null,"helpText":null}]},"0bc59e29e20e6052":{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled","displayName":"Enables DALL-E themes generation","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the AI generated themes will be enabled.\r\n\r\nIf you disable this policy, the AI generated themes will be disabled for your organization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0b39bd455de22a9a":{"id":"device_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_localnetworkaccessipaddressspaceoverridesdesc","displayName":"Override IP address space mappings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"0bb3f2fdf3f97fda":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_screencaptureallowedbyoriginsdesc","displayName":"Allow Desktop, Window, and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"0bf1ea5a842df063":{"id":"device_vendor_msft_policy_config_mixedreality_skipcalibrationduringsetup","displayName":"Skip Calibration During Setup","description":"This policy configures whether the device will take the user through the eye tracking calibration process during device setup and first time user setup. If this policy is enabled, the device will not show the eye tracking calibration process during device setup and first time user setup. Note that until the user goes through the calibration process, eye tracking will not work on the device. If an app requires eye tracking and the user has not gone through the calibration process, the user will be prompted to do so.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#skipcalibrationduringsetup"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_skipcalibrationduringsetup_0","displayName":"Eye tracking calibration process will be shown during device setup and first time user setup.","description":"Eye tracking calibration process will be shown during device setup and first time user setup.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_skipcalibrationduringsetup_1","displayName":"Eye tracking calibration process will not be shown during device setup and first time user setup.","description":"Eye tracking calibration process will not be shown during device setup and first time user setup.","helpText":null}]},"0b4aca8163ca105e":{"id":"device_vendor_msft_policy_config_mssecurityguide_wdigestauthentication","displayName":"WDigest Authentication (disabling may require KB2871997)","description":"When WDigest authentication is enabled, Lsass.exe retains a copy of the user's plaintext password in memory, where it can be at risk of theft. Microsoft recommends disabling WDigest authentication unless it is needed.\n\nIf this setting is not configured, WDigest authentication is disabled in Windows 8.1 and in Windows Server 2012 R2; it is enabled by default in earlier versions of Windows and Windows Server.\n\nUpdate KB2871997 must first be installed to disable WDigest authentication using this setting in Windows 7, Windows 8, Windows Server 2008 R2 and Windows Server 2012.\n\nEnabled: Enables WDigest authentication.\n\nDisabled (recommended): Disables WDigest authentication. For this setting to work on Windows 7, Windows 8, Windows Server 2008 R2 or Windows Server 2012, KB2871997 must first be installed.\n\nFor more information, see http://support.microsoft.com/kb/2871997 and http://blogs.technet.com/b/srd/archive/2014/06/05/an-overview-of-kb2871997.aspx .\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-mssecurityguide#mssecurityguide-wdigestauthentication"],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_mssecurityguide_wdigestauthentication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_mssecurityguide_wdigestauthentication_1","displayName":"Enabled","description":null,"helpText":null}]},"0b5a09671610de4f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_miscellaneous_l_documentinspector_l_empty197","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","categoryName":"Miscellaneous","options":null},"0b88504be3946e63":{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_documents_checkbox","displayName":"Documents (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_documents_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_documents_checkbox_1","displayName":"True","description":null,"helpText":null}]},"0b98e0b8cc8c1f8f":{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutonbattery","displayName":"Specify the system hibernate timeout (on battery)","description":"This policy setting allows you to specify the period of inactivity before Windows transitions the system to hibernate.\n\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows transitions to hibernate.\n\nIf you disable or do not configure this policy setting, users control this setting.\n\nIf the user has configured a slide show to run on the lock screen when the machine is locked, this can prevent the sleep transition from occuring. The \"Prevent enabling lock screen slide show\" policy setting can be used to disable the slide show feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-hibernatetimeoutonbattery"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},"0bf18e3a4cdf29a8":{"id":"device_vendor_msft_policy_config_printers_configurerpcconnectionpolicy_rpcconnectionauthentication_enum","displayName":"Use authentication for outgoing RPC connections:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configurerpcconnectionpolicy_rpcconnectionauthentication_enum_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpcconnectionpolicy_rpcconnectionauthentication_enum_1","displayName":"Authentication enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpcconnectionpolicy_rpcconnectionauthentication_enum_2","displayName":"Authentication disabled","description":null,"helpText":null}]},"0be42c8a24b1eb03":{"id":"device_vendor_msft_policy_config_security_requireprovisioningpackagesignature","displayName":"Require Provisioning Package Signature","description":"Specifies whether provisioning packages must have a certificate signed by a device trusted authority.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Security#requireprovisioningpackagesignature"],"categoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_security_requireprovisioningpackagesignature_0","displayName":"Not required.","description":"Not required.","helpText":null},{"id":"device_vendor_msft_policy_config_security_requireprovisioningpackagesignature_1","displayName":"Required.","description":"Required.","helpText":null}]},"0bdd76376e126538":{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdocuments","displayName":"Allow Pinned Folder Documents","description":"This policy controls the visibility of the Documents shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#allowpinnedfolderdocuments"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdocuments_0","displayName":"The shortcut is hidden and disables the setting in the Settings app.","description":"The shortcut is hidden and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdocuments_1","displayName":"The shortcut is visible and disables the setting in the Settings app.","description":"The shortcut is visible and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdocuments_65535","displayName":"There is no enforced configuration and the setting can be changed by the user.","description":"There is no enforced configuration and the setting can be changed by the user.","helpText":null}]},"0b7e8183e50a434a":{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_filedescription","displayName":"File description","description":null,"helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":null},"0b5a3fcfd640e787":{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek","displayName":"Weekly Schedule scan day","description":"Specify the day of the week when the scheduled scan should run. Select Daily to run the scan every day, or choose a specific weekday. Sunday is represented by 1, Monday by 2, and so on.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#scheduled-scan"],"categoryId":"0e1122f8-2bbf-475b-bce0-9e43a2f5e475","categoryName":"Schedule Scan","options":[{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_0","displayName":"Never","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_1","displayName":"Sunday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_2","displayName":"Monday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_5","displayName":"Thursday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_6","displayName":"Friday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_7","displayName":"Saturday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_8","displayName":"Daily","description":null,"helpText":null}]},"0b23c7dc990f0ab4":{"id":"mathsettings_systembehavior_mathnotes","displayName":"Math Notes","description":"Controls whether Math Notes is allowed in other apps such as Notes.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":[{"id":"mathsettings_systembehavior_mathnotes_false","displayName":"False","description":null,"helpText":null},{"id":"mathsettings_systembehavior_mathnotes_true","displayName":"True","description":null,"helpText":null}]},"0b60fe588b460deb":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":null},"0b8e9a7e4cc8d58c":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders74","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders74_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders74_1","displayName":"True","description":null,"helpText":null}]},"0b17c7488ccedce9":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_1","displayName":"Send additional data when on battery power (User)","description":"This policy setting determines whether Windows Error Reporting (WER) checks if the computer is running on battery power. By default, when a computer is running on battery power, WER only checks for solutions, but does not upload additional report data until the computer is connected to a more permanent power source.\r\n\r\nIf you enable this policy setting, WER does not determine whether the computer is running on battery power, but checks for solutions and uploads report data normally.\r\n\r\nIf you disable or do not configure this policy setting, WER checks for solutions while a computer is running on battery power, but does not upload report data until the computer is connected to a more permanent power source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypasspowerthrottling-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_1_1","displayName":"Enabled","description":null,"helpText":null}]},"0b7f3d618808cdf5":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werconsentcustomize_1_werconsentcustomize","displayName":"Customize consent settings (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":null},"0b8ff670a30d24df":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsearches","displayName":"Searches (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsearches_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsearches_1","displayName":"True","description":null,"helpText":null}]},"0b72485511bb84ed":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_linkresolveignorelinkinfo","displayName":"Do not track Shell shortcuts during roaming (User)","description":"This policy setting determines whether Windows traces shortcuts back to their sources when it cannot find the target on the user's system.\r\n\r\nShortcut files typically include an absolute path to the original target file as well as the relative path to the current target file. When the system cannot find the file in the current target path, then, by default, it searches for the target in the original path. If the shortcut has been copied to a different computer, the original path might lead to a network computer, including external resources, such as an Internet server.\r\n\r\nIf you enable this policy setting, Windows only searches the current target path. It does not search for the original path even when it cannot find the target file in the current target path.\r\n\r\nIf you disable or do not configure this policy setting, Windows searches for the original path when it cannot find the target file in the current target path.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-linkresolveignorelinkinfo"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_linkresolveignorelinkinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_linkresolveignorelinkinfo_1","displayName":"Enabled","description":null,"helpText":null}]},"0b4dbc4c1d93e5ef":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},"0bc1cbd7d039b9e0":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection","displayName":"Move selection after Enter direction (User)","description":"Specifies the direction that the selection is moved after the Enter key is pressed.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_1","displayName":"Enabled","description":null,"helpText":null}]},"0b4fd8b5acb3be8b":{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\r\n\r\n * 'WebHidBlockedForUrls' (Block the WebHID API on these sites) (if there is a match),\r\n\r\n * 'DefaultWebHidGuardSetting' (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with 'WebHidBlockedForUrls'. Neither policy takes precedence if a URL matches both patterns.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0b0af3ec3bb8be57":{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (User)","description":"Control if Manifest v2 extensions can be used by browser.\r\n\r\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about, and the timeline of the migration has not been established.\r\n\r\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This will follow the preceding timeline when it's established.\r\n\r\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\r\n\r\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\r\n\r\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by 'ExtensionInstallForcelist' (Control which extensions are installed silently) or 'ExtensionSettings' (Configure extension management settings) with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\r\n\r\nExtensions availabilities are still controlled by other policies.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default browser behavior\r\n\r\n* Disable (1) = Manifest v2 is disabled\r\n\r\n* Enable (2) = Manifest v2 is enabled\r\n\r\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_1","displayName":"Enabled","description":null,"helpText":null}]},"0b9234e820acfe9c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar","displayName":"Remove Calendar Line (User)","description":"\r\nThis policy setting enables you to remove the Calendar line on the Contact Tab, which is on the Contact Card.\r\n\r\nIf you enable this policy setting, you can remove the Calendar line.\r\n\r\nIf you disable or do not configure this policy setting, the Calendar line appears on the Contact Tab.\r\n","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},"0b79c356236dea68":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_l_placesbarname221","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},"0b4d0503b4b3c2bc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter","displayName":"Hide file locations when opening or saving files (User)","description":"\r\nThis policy setting allows you to hide specific file locations when the user opens or saves a file. This helps prevent users from using either the local PC, SharePointServer, or Microsoft Office 365 cloud-based file locations such as OneDrive or SharePoint Online, to open, save, or share files.\r\n\r\nNote: This policy setting only applies to Word, PowerPoint, and Excel.\r\n\r\nIf you enable this policy setting, you can specify which file locations are hidden when the user opens or saves a file.\r\n\r\nIf you disable or don’t configure this policy setting, users can use the local PC, SharePoint Server or any configured Microsoft cloud-based file location to open, save, and share files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_1","displayName":"Enabled","description":null,"helpText":null}]},"0bc682cc1c0c4eeb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"0bf3afbff6e3b490":{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum","displayName":"Theme: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_0","displayName":"Colorful","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_3","displayName":"Dark Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_4","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_5","displayName":"White","description":null,"helpText":null}]},"0b101fc3cba59564":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders","displayName":"Synchronizing data in shared folders (User)","description":"This setting controls the number of days that elapses without a user accessing an Outlook folder before Outlook stops synchronizing the folder with Exchange. For example, say this option is set to 45. User A opens User B's calendar in Outlook, and then does not click on it again for 45 days. Outlook stops synchronizing the data with Exchange and the calendar is no longer up-to-date. The local copy of the data is removed from the OST file. If User A then clicks on the User B calendar 90 days later, Outlook synchronizes the calendar data and starts the clock again for 45 days.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"0b8214edd64f4131":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors","displayName":"Colors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_browsercolors","displayName":"Browser colors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_presentationschemetextcolor","displayName":"Presentation colors (text color)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_presentationschemeaccentcolor","displayName":"Presentation colors (accent color)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_whitetextonblack","displayName":"White text on black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_blacktextonwhite","displayName":"Black text on white","description":null,"helpText":null}]},"0b2b46aac90e56f8":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},"0b21929681d4f4a1":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation","description":null,"helpText":null}]},"0b4bc609ef94154a":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview","displayName":"Open files on local Intranet UNC in Protected View (User)","description":"This policy setting lets you determine if files on local Intranet UNC file shares open in Protected View.\r\n\r\nIf you enable this policy setting, files on local Intranet UNC file shares open in Protected View if their UNC paths appear to be within the Internet zone.\r\n\r\nIf you disable or do not configure this policy setting, files on Intranet UNC file shares do not open in Protected View if their UNC paths appear to be within the Internet zone.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},"0bec7cb93ace998b":{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_edit","displayName":"Enter fully qualified server names separated by semicolons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},"0b2d3adbbdc12e03":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints","displayName":"Tasks will always honor their constraint dates (User)","description":"Specifies that Project schedules tasks according to their constraint dates.\r\n\r\nIf you enable this setting, task constraints will always be honored when tasks are scheduled.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},"0bc5b3fe4b6a7f2f":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"0b08d55be935701f":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},"0b7ef93c5740c123":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics","displayName":"Use this color for diacritics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics_1","displayName":"Enabled","description":null,"helpText":null}]},"0ba2be7ba56590e2":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties","displayName":"Print document properties (User)","description":"This policy setting allows you to control the \"Print document properties\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will print an additional page with the printed document's properties, including the document's author, filename, creation date, etc., for every document that is printed.\r\n\r\nIf you disable or do not configure this policy setting, no additional page will be printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"0b770a8cd06d9f8d":{"id":"vendor_msft_defender_configuration_tamperprotection_options","displayName":"Controlled Configuration (Device)","description":"This setting can be used to turn on controlled configuration or tamper protection to help protect important security features from unwanted changes and interference.\r\n\r\nIf the setting is configured to Tamper Protection (On), this turns on tamper protection to enforce tamper protected settings to their secure defaults. This includes real-time protection, behavior monitoring, and more. Settings are configured with an MDM solution, such as Intune and is available in Windows 10 Enterprise E5 or equivalent subscriptions.\r\n\r\nIf the setting is configured to Controlled Configuration (On), this turns on controlled configuration, which enforces the configuration coming from Intune exclusively and any non-configured settings to their secure defaults. Controlled configuration is applicable to Antivirus and Endpoint detection and response settings.\r\n\r\nIf the setting is configured to OFF, this turns off Controlled Configuration and Tamper Protection.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"vendor_msft_defender_configuration_tamperprotection_options_1","displayName":"Off","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options_0","displayName":"Tamper Protection (On)","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options_2","displayName":"Controlled Configuration (On)","description":null,"helpText":null}]}} \ No newline at end of file +{"0bac8a0cef114e71":{"id":"app_privacy_permissiondefaults_generickey_localnetwork","displayName":"Local Network","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the local network.\n* `Allow`: The app privacy permission default is set to allow use of the local network.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_localnetwork_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_localnetwork_1","displayName":"Allow","description":null,"helpText":null}]},"0b8b389cbde821a2":{"id":"com.apple.app.lock_app_identifier","displayName":"App Identifier","description":"The bundle identifier of the app.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},"0b4943a5fda5a3db":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance","displayName":"Weekend Allowance","description":"The weekend allowance settings.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"0b0ddea7f811d3e1":{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled","displayName":"Enable origin-keyed process isolation for improved security","description":"This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This may increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off.\n\nIf you enable this policy, most origins will be isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies.\n\nIf you disable this policy, origins will not be isolated from the rest of their site unless the origin explicitly requests isolation.\n\nIf you don’t configure this policy, the browser will decide which origins to isolate and when. By default, this feature is disabled. The default state may change in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#originkeyedprocessesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_originkeyedprocessesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"0bb86211cc75dec5":{"id":"com.apple.notificationsettings_com.apple.notificationsettings","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},"0baccc59b11493c5":{"id":"com.apple.proxy.http.global_proxyserver","displayName":"Proxy Server","description":"The proxy server's network address.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},"0b87e4c098aaa88e":{"id":"com.apple.security.smartcard_com.apple.security.smartcard","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","categoryName":"Smart Card","options":null},"0b779321ee4c16ca":{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"0bf7284afb585eeb":{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"0b9e5d8054dd4983":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled (Deprecated)","description":"This policy is deprecated because the E-Tree feature has been removed from Microsoft Edge.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletetreeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"0b73bb910cf74362":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability","description":"Control if Manifest v2 extensions can be used by browser.\n\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about and the timeline of the migration hasn't been established.\n\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This follows the preceding timeline when it's established.\n\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\n\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\n\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by \"ExtensionInstallForcelist\" or \"ExtensionSettings\" with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\n\nExtensions availabilities are still controlled by other policies.\n\nPolicy options mapping:\n\n* Default (0) = Default browser behavior\n\n* Disable (1) = Manifest v2 is disabled\n\n* Enable (2) = Manifest v2 is enabled\n\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_default","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_disable","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_enable","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionmanifestv2availability_enableforforcedextensions","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},"0bc68d8a2821dd4f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive","displayName":"Keep the active Microsoft Edge window with an Internet Explorer mode tab always in the foreground.","description":"This policy controls whether to always keep the active Microsoft Edge window with an Internet Explorer mode tab in the foreground.\n\nIf you enable this policy, the active Microsoft Edge window with an Internet Explorer mode tab remains in the foreground.\n\nIf you disable or don't configure this policy, the active Microsoft Edge window with an Internet Explorer mode tab isn't kept in the foreground.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorersetforegroundwhenactive_true","displayName":"Enabled","description":null,"helpText":null}]},"0b90668debf5bf09":{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed","displayName":"Allow or deny screen capture","description":"If you enable this policy, or don't configure this policy, a webpage uses screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\nIf you disable this policy, calls to screen-share APIs fail. For example, if you're using a web-based online meeting, video or screen sharing won't work. However, this policy isn't considered.\n(and a site will be allowed to use screen-share APIs) if the site matches an origin pattern in any of the following policies:\n\"ScreenCaptureAllowedByOrigins\",\n\"WindowCaptureAllowedByOrigins\",\n\"TabCaptureAllowedByOrigins\",\n\"SameOriginTabCaptureAllowedByOrigins\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.screencaptureallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"0b0b2a3d6087bcf5":{"id":"com.microsoft.edge.mamedgeappconfigsettings.windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites","description":"Lets you configure a list of site URL patterns that specify sites which can automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission follows the browser's defaults and lets users choose this permission per site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"0ba21904577962f5":{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock","displayName":"Allow users to select when a password is required when resuming from connected standby","description":"This policy setting allows you to control whether a user can change the time before a password is required when a Connected Standby device screen turns off.\r\n\r\nIf you enable this policy setting, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.\r\n\r\nIf you disable this policy setting, a user cannot change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.\r\n\r\nIf you don't configure this policy setting on a domain-joined device, a user cannot change the amount of time after the device's screen turns off before a password is required when waking the device. Instead, a password is required immediately after the screen turns off.\r\n\r\nIf you don't configure this policy setting on a workgroup device, a user on a Connected Standby device can change the amount of time after the device's screen turns off before a password is required when waking the device. The time is limited by any EAS settings or Group Policies that affect the maximum idle time before a device locks. Additionally, if a password is required when a screensaver turns on, the screensaver timeout will limit the options the user may choose.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-allowdomaindelaylock"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_allowdomaindelaylock_1","displayName":"Enabled","description":null,"helpText":null}]},"0b945b841774da63":{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode","displayName":"Allow Distributed Link Tracking clients to use domain resources","description":"Specifies that Distributed Link Tracking clients in this domain may use the Distributed Link Tracking (DLT) server, which runs on domain controllers. The DLT client enables programs to track linked files that are moved within an NTFS volume, to another NTFS volume on the same computer, or to an NTFS volume on another computer. The DLT client can more reliably track links when allowed to use the DLT server. This policy should not be set unless the DLT server is running on all domain controllers in the domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-distributedlinktracking#admx-distributedlinktracking-dlt-allowdomainmode"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_distributedlinktracking_dlt_allowdomainmode_1","displayName":"Enabled","description":null,"helpText":null}]},"0b55dab3d1ff8bfb":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled","displayName":"Allow or Disallow use of the Offline Files feature","description":"This policy setting determines whether the Offline Files feature is enabled. Offline Files saves a copy of network files on the user's computer for use when the computer is not connected to the network.\r\n\r\nIf you enable this policy setting, Offline Files is enabled and users cannot disable it.\r\n\r\nIf you disable this policy setting, Offline Files is disabled and users cannot enable it.\r\n\r\nIf you do not configure this policy setting, Offline Files is enabled on Windows client computers, and disabled on computers running Windows Server, unless changed by the user.\r\n\r\nNote: Changes to this policy setting do not take effect until the affected computer is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-enabled"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0b128b99830eb4fe":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended","displayName":"Always Open PDF files externally","description":"Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application.\r\n\r\nSetting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alwaysopenpdfexternally_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"0ba2f208038ddd6f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended","displayName":"Show Full URLs","description":"This feature enables display of the full URL in the address bar.\r\nIf this policy is set to True, then the full URL will be shown in the address bar, including schemes and subdomains.\r\nIf this policy is set to False, then the default URL display will apply.\r\nIf this policy is left unset, then the default URL display will apply and the user will be able to toggle between default and full URL display with a context menu option.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_showfullurlsinaddressbar_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"0b52a249b76bfd88":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":null},"0bbe704ef2c8447f":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcremoveorphanedostfilesonlogoff","displayName":"Remove Orphaned OST Files On Logoff","description":"Removes duplicate OST files.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\RemoveOrphanedOSTFilesOnLogoff\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcremoveorphanedostfilesonlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcremoveorphanedostfilesonlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"0b8b241450227efe":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates","description":"Notify users that they need to restart Microsoft Edge to apply a pending update.\r\n\r\nIf you don't configure this policy, Microsoft Edge adds a recycle icon at the far right of the top menu bar to prompt users to restart the browser to apply the update.\r\n\r\nIf you enable this policy and set it to 'Recommended' (1), a recurring warning prompts users that a restart is recommended. Users can dismiss this warning and defer the restart.\r\n\r\nIf you set the policy to 'Required' (2), a recurring warning prompts users that the browser will be restarted automatically as soon as a notification period passes. The default period is seven days. You can configure this period with the 'RelaunchNotificationPeriod' (Set the time period for update notifications) policy.\r\n\r\nThe user's session is restored when the browser restarts.\r\n\r\n* 1 = Recommended - Show a recurring prompt to the user indicating that a restart is recommended\r\n\r\n* 2 = Required - Show a recurring prompt to the user indicating that a restart is required","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"0b78686b72a41eac":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled","displayName":"Enable the default search provider","description":"Enables the ability to use a default search provider.\r\n\r\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\r\n\r\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\r\n\r\nIf you disable this policy, the user can't search from the address bar.\r\n\r\nIf you enable or disable this policy, users can't change or override it.\r\n\r\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0b022a774b1c0d7a":{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_1","displayName":"Allow all websites to perform automatic downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_2","displayName":"Don't allow any website to perform automatic downloads","description":null,"helpText":null}]},"0bc59e29e20e6052":{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled","displayName":"Enables DALL-E themes generation","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the AI generated themes will be enabled.\r\n\r\nIf you disable this policy, the AI generated themes will be disabled for your organization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0b39bd455de22a9a":{"id":"device_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_localnetworkaccessipaddressspaceoverridesdesc","displayName":"Override IP address space mappings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"0bb3f2fdf3f97fda":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_screencaptureallowedbyoriginsdesc","displayName":"Allow Desktop, Window, and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"0bf1ea5a842df063":{"id":"device_vendor_msft_policy_config_mixedreality_skipcalibrationduringsetup","displayName":"Skip Calibration During Setup","description":"This policy configures whether the device will take the user through the eye tracking calibration process during device setup and first time user setup. If this policy is enabled, the device will not show the eye tracking calibration process during device setup and first time user setup. Note that until the user goes through the calibration process, eye tracking will not work on the device. If an app requires eye tracking and the user has not gone through the calibration process, the user will be prompted to do so.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#skipcalibrationduringsetup"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_skipcalibrationduringsetup_0","displayName":"Eye tracking calibration process will be shown during device setup and first time user setup.","description":"Eye tracking calibration process will be shown during device setup and first time user setup.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_skipcalibrationduringsetup_1","displayName":"Eye tracking calibration process will not be shown during device setup and first time user setup.","description":"Eye tracking calibration process will not be shown during device setup and first time user setup.","helpText":null}]},"0b4aca8163ca105e":{"id":"device_vendor_msft_policy_config_mssecurityguide_wdigestauthentication","displayName":"WDigest Authentication (disabling may require KB2871997)","description":"When WDigest authentication is enabled, Lsass.exe retains a copy of the user's plaintext password in memory, where it can be at risk of theft. Microsoft recommends disabling WDigest authentication unless it is needed.\n\nIf this setting is not configured, WDigest authentication is disabled in Windows 8.1 and in Windows Server 2012 R2; it is enabled by default in earlier versions of Windows and Windows Server.\n\nUpdate KB2871997 must first be installed to disable WDigest authentication using this setting in Windows 7, Windows 8, Windows Server 2008 R2 and Windows Server 2012.\n\nEnabled: Enables WDigest authentication.\n\nDisabled (recommended): Disables WDigest authentication. For this setting to work on Windows 7, Windows 8, Windows Server 2008 R2 or Windows Server 2012, KB2871997 must first be installed.\n\nFor more information, see http://support.microsoft.com/kb/2871997 and http://blogs.technet.com/b/srd/archive/2014/06/05/an-overview-of-kb2871997.aspx .\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-mssecurityguide#mssecurityguide-wdigestauthentication"],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_mssecurityguide_wdigestauthentication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_mssecurityguide_wdigestauthentication_1","displayName":"Enabled","description":null,"helpText":null}]},"0b5a09671610de4f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_miscellaneous_l_documentinspector_l_empty197","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","categoryName":"Miscellaneous","options":null},"0b88504be3946e63":{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_documents_checkbox","displayName":"Documents (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_documents_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_documents_checkbox_1","displayName":"True","description":null,"helpText":null}]},"0b98e0b8cc8c1f8f":{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutonbattery","displayName":"Specify the system hibernate timeout (on battery)","description":"This policy setting allows you to specify the period of inactivity before Windows transitions the system to hibernate.\n\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows transitions to hibernate.\n\nIf you disable or do not configure this policy setting, users control this setting.\n\nIf the user has configured a slide show to run on the lock screen when the machine is locked, this can prevent the sleep transition from occuring. The \"Prevent enabling lock screen slide show\" policy setting can be used to disable the slide show feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-hibernatetimeoutonbattery"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},"0bf18e3a4cdf29a8":{"id":"device_vendor_msft_policy_config_printers_configurerpcconnectionpolicy_rpcconnectionauthentication_enum","displayName":"Use authentication for outgoing RPC connections:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configurerpcconnectionpolicy_rpcconnectionauthentication_enum_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpcconnectionpolicy_rpcconnectionauthentication_enum_1","displayName":"Authentication enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpcconnectionpolicy_rpcconnectionauthentication_enum_2","displayName":"Authentication disabled","description":null,"helpText":null}]},"0be42c8a24b1eb03":{"id":"device_vendor_msft_policy_config_security_requireprovisioningpackagesignature","displayName":"Require Provisioning Package Signature","description":"Specifies whether provisioning packages must have a certificate signed by a device trusted authority.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Security#requireprovisioningpackagesignature"],"categoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_security_requireprovisioningpackagesignature_0","displayName":"Not required.","description":"Not required.","helpText":null},{"id":"device_vendor_msft_policy_config_security_requireprovisioningpackagesignature_1","displayName":"Required.","description":"Required.","helpText":null}]},"0bdd76376e126538":{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdocuments","displayName":"Allow Pinned Folder Documents","description":"This policy controls the visibility of the Documents shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#allowpinnedfolderdocuments"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdocuments_0","displayName":"The shortcut is hidden and disables the setting in the Settings app.","description":"The shortcut is hidden and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdocuments_1","displayName":"The shortcut is visible and disables the setting in the Settings app.","description":"The shortcut is visible and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdocuments_65535","displayName":"There is no enforced configuration and the setting can be changed by the user.","description":"There is no enforced configuration and the setting can be changed by the user.","helpText":null}]},"0b7e8183e50a434a":{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_filedescription","displayName":"File description","description":null,"helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":null},"0b5a3fcfd640e787":{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek","displayName":"Weekly Schedule scan day","description":"Specify the day of the week when the scheduled scan should run. Select Daily to run the scan every day, or choose a specific weekday. Sunday is represented by 1, Monday by 2, and so on.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#scheduled-scan"],"categoryId":"0e1122f8-2bbf-475b-bce0-9e43a2f5e475","categoryName":"Schedule Scan","options":[{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_0","displayName":"Never","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_1","displayName":"Sunday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_2","displayName":"Monday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_5","displayName":"Thursday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_6","displayName":"Friday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_7","displayName":"Saturday","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_dayofweek_8","displayName":"Daily","description":null,"helpText":null}]},"0b23c7dc990f0ab4":{"id":"mathsettings_systembehavior_mathnotes","displayName":"Math Notes","description":"Controls whether Math Notes is allowed in other apps such as Notes.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":[{"id":"mathsettings_systembehavior_mathnotes_false","displayName":"False","description":null,"helpText":null},{"id":"mathsettings_systembehavior_mathnotes_true","displayName":"True","description":null,"helpText":null}]},"0b60fe588b460deb":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":null},"0b8e9a7e4cc8d58c":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders74","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders74_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders74_1","displayName":"True","description":null,"helpText":null}]},"0b17c7488ccedce9":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_1","displayName":"Send additional data when on battery power (User)","description":"This policy setting determines whether Windows Error Reporting (WER) checks if the computer is running on battery power. By default, when a computer is running on battery power, WER only checks for solutions, but does not upload additional report data until the computer is connected to a more permanent power source.\r\n\r\nIf you enable this policy setting, WER does not determine whether the computer is running on battery power, but checks for solutions and uploads report data normally.\r\n\r\nIf you disable or do not configure this policy setting, WER checks for solutions while a computer is running on battery power, but does not upload report data until the computer is connected to a more permanent power source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypasspowerthrottling-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypasspowerthrottling_1_1","displayName":"Enabled","description":null,"helpText":null}]},"0b7f3d618808cdf5":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werconsentcustomize_1_werconsentcustomize","displayName":"Customize consent settings (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":null},"0b8ff670a30d24df":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsearches","displayName":"Searches (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsearches_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsearches_1","displayName":"True","description":null,"helpText":null}]},"0b72485511bb84ed":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_linkresolveignorelinkinfo","displayName":"Do not track Shell shortcuts during roaming (User)","description":"This policy setting determines whether Windows traces shortcuts back to their sources when it cannot find the target on the user's system.\r\n\r\nShortcut files typically include an absolute path to the original target file as well as the relative path to the current target file. When the system cannot find the file in the current target path, then, by default, it searches for the target in the original path. If the shortcut has been copied to a different computer, the original path might lead to a network computer, including external resources, such as an Internet server.\r\n\r\nIf you enable this policy setting, Windows only searches the current target path. It does not search for the original path even when it cannot find the target file in the current target path.\r\n\r\nIf you disable or do not configure this policy setting, Windows searches for the original path when it cannot find the target file in the current target path.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-linkresolveignorelinkinfo"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_linkresolveignorelinkinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_linkresolveignorelinkinfo_1","displayName":"Enabled","description":null,"helpText":null}]},"0b4dbc4c1d93e5ef":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins","displayName":"Disable third-party storage partitioning for specific top-level origins (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_thirdpartystoragepartitioningblockedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},"0bc1cbd7d039b9e0":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection","displayName":"Move selection after Enter direction (User)","description":"Specifies the direction that the selection is moved after the Enter key is pressed.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenterdirection_1","displayName":"Enabled","description":null,"helpText":null}]},"0b4fd8b5acb3be8b":{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns that don't match the policy, the following values are applied in order of precedence:\r\n\r\n * 'WebHidBlockedForUrls' (Block the WebHID API on these sites) (if there is a match),\r\n\r\n * 'DefaultWebHidGuardSetting' (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with 'WebHidBlockedForUrls'. Neither policy takes precedence if a URL matches both patterns.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://microsoft.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0b0af3ec3bb8be57":{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (User)","description":"Control if Manifest v2 extensions can be used by browser.\r\n\r\nManifest v2 extensions support will be deprecated and all extensions need to be migrated to v3 in the future. More information about, and the timeline of the migration has not been established.\r\n\r\nIf the policy is set to Default or not set, v2 extension loading is decided by browser. This will follow the preceding timeline when it's established.\r\n\r\nIf the policy is set to Disable, v2 extensions installation are blocked, and existing ones are disabled. This option is going to be treated the same as if the policy is unset after v2 support is turned off by default.\r\n\r\nIf the policy is set to Enable, v2 extensions are allowed. The option is going to be treated the same as if the policy isn't set before v2 support is turned off by default.\r\n\r\nIf the policy is set to EnableForForcedExtensions, force installed v2 extensions are allowed. This includes extensions that are listed by 'ExtensionInstallForcelist' (Control which extensions are installed silently) or 'ExtensionSettings' (Configure extension management settings) with installation_mode \"force_installed\" or \"normal_installed\". All other v2 extensions are disabled. The option is always available regardless of the manifest migration state.\r\n\r\nExtensions availabilities are still controlled by other policies.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default browser behavior\r\n\r\n* Disable (1) = Manifest v2 is disabled\r\n\r\n* Enable (2) = Manifest v2 is enabled\r\n\r\n* EnableForForcedExtensions (3) = Manifest v2 is enabled for forced extensions only\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensionmanifestv2availability_1","displayName":"Enabled","description":null,"helpText":null}]},"0b9234e820acfe9c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar","displayName":"Remove Calendar Line (User)","description":"\r\nThis policy setting enables you to remove the Calendar line on the Contact Tab, which is on the Contact Card.\r\n\r\nIf you enable this policy setting, you can remove the Calendar line.\r\n\r\nIf you disable or do not configure this policy setting, the Calendar line appears on the Contact Tab.\r\n","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoffcontacttabcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},"0b79c356236dea68":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_l_placesbarname221","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},"0b4d0503b4b3c2bc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter","displayName":"Hide file locations when opening or saving files (User)","description":"\r\nThis policy setting allows you to hide specific file locations when the user opens or saves a file. This helps prevent users from using either the local PC, SharePointServer, or Microsoft Office 365 cloud-based file locations such as OneDrive or SharePoint Online, to open, save, or share files.\r\n\r\nNote: This policy setting only applies to Word, PowerPoint, and Excel.\r\n\r\nIf you enable this policy setting, you can specify which file locations are hidden when the user opens or saves a file.\r\n\r\nIf you disable or don’t configure this policy setting, users can use the local PC, SharePoint Server or any configured Microsoft cloud-based file location to open, save, and share files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_1","displayName":"Enabled","description":null,"helpText":null}]},"0bc682cc1c0c4eeb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey10_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"0bf3afbff6e3b490":{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum","displayName":"Theme: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_0","displayName":"Colorful","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_3","displayName":"Dark Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_4","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_l_defaultuithemeenum_5","displayName":"White","description":null,"helpText":null}]},"0b101fc3cba59564":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders","displayName":"Synchronizing data in shared folders (User)","description":"This setting controls the number of days that elapses without a user accessing an Outlook folder before Outlook stops synchronizing the folder with Exchange. For example, say this option is set to 45. User A opens User B's calendar in Outlook, and then does not click on it again for 45 days. Outlook stops synchronizing the data with Exchange and the calendar is no longer up-to-date. The local copy of the data is removed from the OST file. If User A then clicks on the User B calendar 90 days later, Outlook synchronizes the calendar data and starts the clock again for 45 days.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_synchronizingdatainsharedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"0b8214edd64f4131":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors","displayName":"Colors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_browsercolors","displayName":"Browser colors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_presentationschemetextcolor","displayName":"Presentation colors (text color)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_presentationschemeaccentcolor","displayName":"Presentation colors (accent color)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_whitetextonblack","displayName":"White text on black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_colors_blacktextonwhite","displayName":"Black text on white","description":null,"helpText":null}]},"0b2b46aac90e56f8":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},"0b21929681d4f4a1":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation","description":null,"helpText":null}]},"0b4bc609ef94154a":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview","displayName":"Open files on local Intranet UNC in Protected View (User)","description":"This policy setting lets you determine if files on local Intranet UNC file shares open in Protected View.\r\n\r\nIf you enable this policy setting, files on local Intranet UNC file shares open in Protected View if their UNC paths appear to be within the Internet zone.\r\n\r\nIf you disable or do not configure this policy setting, files on Intranet UNC file shares do not open in Protected View if their UNC paths appear to be within the Internet zone.","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_openfilesonlocalintranetuncinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]},"0bec7cb93ace998b":{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_trustedservers_edit","displayName":"Enter fully qualified server names separated by semicolons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},"0b2d3adbbdc12e03":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints","displayName":"Tasks will always honor their constraint dates (User)","description":"Specifies that Project schedules tasks according to their constraint dates.\r\n\r\nIf you enable this setting, task constraints will always be honored when tasks are scheduled.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjtaskshonorconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},"0bc5b3fe4b6a7f2f":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_datecolon17","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"0b08d55be935701f":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2003files_l_visio2003filesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},"0b7ef93c5740c123":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics","displayName":"Use this color for diacritics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_differentcolorfordiacritics_1","displayName":"Enabled","description":null,"helpText":null}]},"0ba2be7ba56590e2":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties","displayName":"Print document properties (User)","description":"This policy setting allows you to control the \"Print document properties\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will print an additional page with the printed document's properties, including the document's author, filename, creation date, etc., for every document that is printed.\r\n\r\nIf you disable or do not configure this policy setting, no additional page will be printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_documentproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"0b770a8cd06d9f8d":{"id":"vendor_msft_defender_configuration_tamperprotection_options","displayName":"Configuration Protection (Device) (Preview)","description":"This setting can be used to turn on controlled configuration or tamper protection to help protect important security features from unwanted changes and interference.\r\n\r\nIf the setting is configured to Tamper Protection (On), this turns on tamper protection to enforce tamper protected settings to their secure defaults. This includes real-time protection, behavior monitoring, and more. Settings are configured with an MDM solution, such as Intune and is available in Windows 10 Enterprise E5 or equivalent subscriptions.\r\n\r\nIf the setting is configured to Controlled Configuration (On), this turns on controlled configuration, which enforces the configuration coming from Intune exclusively and any non-configured settings to their secure defaults. Controlled configuration is applicable to Antivirus and Endpoint detection and response settings.\r\n\r\nIf the setting is configured to OFF, this turns off Controlled Configuration and Tamper Protection.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"vendor_msft_defender_configuration_tamperprotection_options_1","displayName":"Off","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options_0","displayName":"Tamper Protection (On)","description":null,"helpText":null},{"id":"vendor_msft_defender_configuration_tamperprotection_options_2","displayName":"Configuration Protection (On)","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/0e.json b/public/intune-definitions/0e.json index c0bd52baf599..ac79eea67e89 100644 --- a/public/intune-definitions/0e.json +++ b/public/intune-definitions/0e.json @@ -1 +1 @@ -{"0e663db42981e020":{"id":"com.apple.app.lock_app_options_enableinvertcolors","displayName":"Enable Invert Colors","description":"If true, enables Invert Colors. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enableinvertcolors_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enableinvertcolors_true","displayName":"True","description":null,"helpText":null}]},"0e913b9167cda3ba":{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation","displayName":"Allow UI Configuration Profile Installation","description":"If false, prohibits the user from installing configuration profiles and certificates interactively. Requires a supervised device. Available in iOS 6 and later and macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation_true","displayName":"True","description":null,"helpText":null}]},"0e69de1de252f62e":{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry","displayName":"Force iTunes Store Password Entry (Deprecated)","description":"If true, forces the user to enter their iTunes password for each transaction. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry_true","displayName":"True","description":null,"helpText":null}]},"0e728b32c49d6aba":{"id":"com.apple.extensiblesso_realm","displayName":"Realm","description":"The realm name for Credential payloads. Use proper capitalization for this value. This key is ignored for Redirect payloads.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"0eca94af95168042":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"0e9861f526452e8e":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app","displayName":"Microsoft Edge Beta (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"0e4fe26282a62b97":{"id":"com.apple.managedclient.preferences_autoplayallowlist","displayName":"Allow media autoplay on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\n\nIf you don't configure this policy, the global default value from the \"AutoplayAllowed\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nNote: * is not an accepted value for this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoplayallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"0ecaa67be3a724ad":{"id":"com.apple.managedclient.preferences_importextensions","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **favorites** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importextensions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importextensions_true","displayName":"Enabled","description":null,"helpText":null}]},"0e56f3030d3cde5e":{"id":"com.apple.managedclient.preferences_startdaemononapplaunch","displayName":"Register app on launch","description":"Force Office apps to register with AutoUpdate on each launch.","helpText":null,"infoUrls":["https://macadmins.software/docs/MAU_38.pdf"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_startdaemononapplaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_startdaemononapplaunch_true","displayName":"True","description":null,"helpText":null}]},"0e4fb557e5e38f3f":{"id":"com.apple.universalaccess_mousedriverinitialdelay","displayName":"Mouse Driver Initial Delay","description":"The initial delay before moving the mouse with Mouse Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},"0ed756bf664a1501":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"0e7cebf1b3afe3de":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallallowlist","displayName":"Allow specific extensions to be installed","description":"Setting this policy specifies which extensions aren't subject to the blocklist.\n\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\n\nBy default, all extensions are allowed. However, if you prohibited extensions by policy, you can use the list of allowed extensions to change that policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"0ee9f928c1a0886e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewstickysettings_recommended","displayName":"Configure the sticky print preview settings (users can override)","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\n\nEach item of this policy expects a boolean:\n\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If you set this to True, the webpage layout uses the recent choice; otherwise, it sets to default value.\n\nSize specifies if the page size should be kept sticky or not in print preview settings. If you set this to True, the page size uses the recent choice; otherwise, it sets to default value.\n\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If you set this to True, the scale percentage and scale type both use the recent choice; otherwise, it will set to default value.\n\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If you set this to True, the page margins use the recent choice; otherwise, it sets to default value.\n\nIf you enable this policy, the selected values use the most recent choice in Print Preview.\n\nIf you disable or don't configure this policy, print preview settings aren't impacted.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"0e920e97737af246":{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name","displayName":"Allow users to apply BitLocker protection on removable data drives","description":"","helpText":"","infoUrls":[],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name_1","displayName":"True","description":null,"helpText":null}]},"0e17bc42fd63197f":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults","displayName":"Report operating system errors","description":"This policy setting controls whether errors in the operating system are included Windows Error Reporting is enabled.\r\n\r\nIf you enable this policy setting, Windows Error Reporting includes operating system errors.\r\n\r\nIf you disable this policy setting, operating system errors are not included in error reports.\r\n\r\nIf you do not configure this policy setting, users can change this setting in Control Panel. By default, Windows Error Reporting settings in Control Panel are set to upload operating system errors.\r\n\r\nSee also the Configure Error Reporting policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-reportoperatingsystemfaults"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults_1","displayName":"Enabled","description":null,"helpText":null}]},"0e03f2003ecfc964":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority","displayName":"Configure low CPU priority for scheduled scans","description":"\r\n This policy setting allows you to enable or disable low CPU priority for scheduled scans.\r\n\r\n If you enable this setting, low CPU priority will be used during scheduled scans.\r\n\r\n If you disable or do not configure this setting, not changes will be made to CPU priority for scheduled scans.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-lowcpupriority"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority_1","displayName":"Enabled","description":null,"helpText":null}]},"0e56466013a9f051":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_netlogon_dnsavoidregisterrecordslabel","displayName":"Mnemonics:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},"0e1139bdf315d474":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11","displayName":"Internet Explorer 11","description":"This policy setting configures the synchronization of user settings of Internet Explorer 11.\r\nBy default, the user settings of Internet Explorer 11 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 11 from synchronization between computers.\r\nIf you enable this policy setting, the Internet Explorer 11 user settings continue to synchronize.\r\nIf you disable this policy setting, Internet Explorer 11 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer11"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11_1","displayName":"Enabled","description":null,"helpText":null}]},"0e8830317ddf8bc5":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016","displayName":"Microsoft Office 365 PowerPoint 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016_1","displayName":"Enabled","description":null,"helpText":null}]},"0e2de9beeceb1f19":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam","displayName":"Object Access Audit SAM","description":"This policy setting allows you to audit events generated by attempts to access to Security Accounts Manager (SAM) objects. SAM objects include the following: SAM_ALIAS -- A local group. SAM_GROUP -- A group that is not a local group. SAM_USER – A user account. SAM_DOMAIN – A domain. SAM_SERVER – A computer account. If you configure this policy setting, an audit event is generated when an attempt to access a kernel object is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an attempt to access a kernel object is made. Note: Only the System Access Control List (SACL) for SAM_SERVER can be modified. Volume: High on domain controllers. For information about reducing the amount of events generated in this subcategory, see article 841001 in the Microsoft Knowledge Base (https://go.microsoft.com/fwlink/?LinkId=121698).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditsam"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"0efcb7b93e147134":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history","description":"Setting the policy to Enabled or leaving it unset means browser history and download history can be deleted in Chrome, and users can't change this setting.\r\n\r\nSetting the policy to Disabled means browser history and download history can't be deleted. Even with this policy off, the browsing and download history are not guaranteed to be retained. Users may be able to edit or delete the history database files directly, and the browser itself may expire or archive any or all history items at any time.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory_1","displayName":"Enabled","description":null,"helpText":null}]},"0e59d6601a04e556":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_legacysamesitecookiebehaviorenabledfordomainlistdesc","displayName":"Revert to legacy SameSite behavior for cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"0e59c69d5aca8558":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions","displayName":"URL pattern Exceptions to tab discarding","description":"This policy makes it so that any URL matching one or more of the patterns it specifies (using the URLBlocklist filter format) will never be discarded by the browser.\r\nThis applies to memory pressure and high efficiency mode discarding.\r\nA discarded page is unloaded and its resources fully reclaimed. The tab its associated with remains in the tabstrip, but making it visible will trigger a full reload.\r\n\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://*\r\n*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_1","displayName":"Enabled","description":null,"helpText":null}]},"0e5b45cbbc840b0f":{"id":"device_vendor_msft_policy_config_devicehealthmonitoring_configdevicehealthmonitoringuploaddestination_v2","displayName":"Config Device Health Monitoring Upload Destination","description":"If the device is not opted-in to the DeviceHealthMonitoring service via the AllowDeviceHealthMonitoring then this policy has no meaning. For devices which are opted in, the value of this policy modifies which destinations are in-scope for monitored events to be uploaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeviceHealthMonitoring#configdevicehealthmonitoringuploaddestination"],"categoryId":"55c888df-44ff-49d1-808e-ad9cb8429aff","categoryName":"Device Health Monitoring","options":null},"0e67ae70d5dd7297":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesdeletelocalprofilewhenvhdshouldapply","displayName":"Delete Local Profile When VHD Should Apply","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nWhen the FSLogix Profiles system determines that a user should have a FSLogix profile but a local profile exists, the local profile WILL BE REMOVED and the user logged on with the FSLogix profile\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\DeleteLocalProfileWhenVHDShouldApply\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesdeletelocalprofilewhenvhdshouldapply_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesdeletelocalprofilewhenvhdshouldapply_1","displayName":"Enabled","description":null,"helpText":null}]},"0e1bfa172889926e":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachinterval","displayName":"Reattach Interval","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nWhen a VHD(x) volume is detached unexpectedly, the FSLogix system will attempt to reattach the volume. This value specifies the number of seconds to wait between retries. The default value is 10 seconds which is the same as \"Not Configured\".\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ReAttachIntervalSeconds\r\nType: DWORD\r\nValues: Min = 1, Max = 60","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"0e95e9e305fb7834":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesremoveorphanedostfilesonlogoff","displayName":"Remove Orphaned OST Files On Logoff","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nRemoves duplicate OST files\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\RemoveOrphanedOSTFilesOnLogoff\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesremoveorphanedostfilesonlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesremoveorphanedostfilesonlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"0e3c97421f3c34e8":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads","displayName":"Allow font downloads","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowfontdownloads"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"0e6322dc9ea45752":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"0e97e25cd72c6a61":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowlessprivilegedsites"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"0e28fbc6f566d376":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809","displayName":"Use Pop-up Blocker","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809_3","displayName":"Disable","description":null,"helpText":null}]},"0e69732bc9320141":{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\r\n\r\nIf you disable this policy, post-quantum key agreement will not be offered for WebRTC.\r\n\r\nIf you don't configure this policy, post-quantum key agreement will not be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\r\n\r\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\r\n\r\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},"0e4b0b86d312d1d6":{"id":"device_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_scarewareblockerallowlistdomainsdesc","displayName":"Configure the list of domains where Microsoft Edge scareware blocker won't run (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},"0ed0b173648309df":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_idledetectionblockedforurlsdesc","displayName":"Blocked sites for idle detection (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"0edd2733ac2f902e":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended","displayName":"Enable startup boost","description":"Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.\r\n\r\nIf Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.\r\n\r\nIf you enable this policy, startup boost is turned on.\r\n\r\nIf you disable this policy, startup boost is turned off.\r\n\r\nIf you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"0e64530291649984":{"id":"device_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatiemachine","displayName":"Disable local training of the Adaptive Floatie feature for the computer.","description":"\r\nThis policy setting disables local training of the Adaptive Floatie feature for the computer.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\n- If this policy setting is enabled, local training of the Adaptive Floatie feature is disabled for the computer.\r\n- If this policy setting is disabled, local training of the Adaptive Floatie feature is enabled for the computer.\r\n- If this policy setting is not configured, local training of the Adaptive Floatie feature is determined by lower priority policy settings.\r\n- If this policy setting is not configured and lower priority policy settings are also not configured, local training of the Adaptive Floatie feature is enabled for the computer.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of the Adaptive Floatie feature for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of the Adaptive Floatie feature for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"device_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatiemachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatiemachine_1","displayName":"Enabled","description":null,"helpText":null}]},"0edb597fd5417405":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatedeadline_l_updatedeadlineid","displayName":"Deadline: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":null},"0ea2d6d8941388db":{"id":"device_vendor_msft_policy_config_power_allowstandbystateswhensleepingonbattery","displayName":"Allow standby states (S1-S3) when sleeping (on battery)","description":"This policy setting manages whether or not Windows is allowed to use standby states when putting the computer in a sleep state.\n\nIf you enable or do not configure this policy setting, Windows uses standby states to put the computer in a sleep state.\n\nIf you disable this policy setting, standby states (S1-S3) are not allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-allowstandbystateswhensleepingonbattery"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_allowstandbystateswhensleepingonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_allowstandbystateswhensleepingonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},"0eb10a47887aa3f1":{"id":"device_vendor_msft_policy_config_quiettime_mutenotificationsdaily","displayName":"Mute notifications daily","description":null,"helpText":null,"infoUrls":[],"categoryId":"3ccd987e-bfca-4838-98ea-576de34b3ebe","categoryName":"Certain Hours","options":{"id":"device_vendor_msft_policy_config_quiettime_mutenotificationsdaily_1","displayName":"Require","description":null,"helpText":null}},"0e23efb12ee69f77":{"id":"device_vendor_msft_policy_config_update_allowautoupdate","displayName":"Allow Auto Update","description":"Enables the IT admin to manage automatic update behavior to scan, download, and install updates. Supported operations are Get and Replace. Important. This option should be used only for systems under regulatory compliance, as you will not get security updates as well. If the policy is not configured, end-users get the default behavior (Auto install and restart).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#allowautoupdate"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_allowautoupdate_0","displayName":"Notify the user before downloading the update. This policy is used by the enterprise who wants to enable the end-users to manage data usage. With this option users are notified when there are updates that apply to the device and are ready for download. Users can download and install the updates from the Windows Update control panel.","description":"Notify the user before downloading the update. This policy is used by the enterprise who wants to enable the end-users to manage data usage. With this option users are notified when there are updates that apply to the device and are ready for download. Users can download and install the updates from the Windows Update control panel.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_1","displayName":"Auto install the update and then notify the user to schedule a device restart. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates immediately. If the installation requires a restart, the end-user is prompted to schedule the restart time. The end-user has up to seven days to schedule the restart and after that, a restart of the device is forced. Enabling the end-user to control the start time reduces the risk of accidental data loss caused by applications that do not shutdown properly on restart.","description":"Auto install the update and then notify the user to schedule a device restart. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates immediately. If the installation requires a restart, the end-user is prompted to schedule the restart time. The end-user has up to seven days to schedule the restart and after that, a restart of the device is forced. Enabling the end-user to control the start time reduces the risk of accidental data loss caused by applications that do not shutdown properly on restart.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_2","displayName":"Auto install and restart. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device is not actively being used. This is the default behavior for unmanaged devices. Devices are updated quickly, but it increases the risk of accidental data loss caused by an application that does not shutdown properly on restart.","description":"Auto install and restart. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device is not actively being used. This is the default behavior for unmanaged devices. Devices are updated quickly, but it increases the risk of accidental data loss caused by an application that does not shutdown properly on restart.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_3","displayName":"Auto install and restart at a specified time. The IT specifies the installation day and time. If no day and time are specified, the default is 3 AM daily. Automatic installation happens at this time and device restart happens after a 15-minute countdown. If the user is logged in when Windows is ready to restart, the user can interrupt the 15-minute countdown to delay the restart.","description":"Auto install and restart at a specified time. The IT specifies the installation day and time. If no day and time are specified, the default is 3 AM daily. Automatic installation happens at this time and device restart happens after a 15-minute countdown. If the user is logged in when Windows is ready to restart, the user can interrupt the 15-minute countdown to delay the restart.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_4","displayName":"Auto install and restart without end-user control. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device is not actively being used. This setting option also sets the end-user control panel to read-only.","description":"Auto install and restart without end-user control. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device is not actively being used. This setting option also sets the end-user control panel to read-only.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_5","displayName":"Turn off automatic updates.","description":"Turn off automatic updates.","helpText":null}]},"0e0cdbd24292fbe2":{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_preferences_pol_updatechecksuppressedperiod_part_updatechecksuppressedstartmin","displayName":"Minute (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"78497707-c3e4-400b-a6bc-1813c3689fdc","categoryName":"Preferences","options":null},"0e370d76f903ced6":{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_rollbacktotargetversionmicrosoftedgecanary","displayName":"Rollback to Target version","description":"Specifies that Microsoft Edge Update should rollback installations of Microsoft Edge to the version indicated in 'Target version override'.\r\n\r\nThis policy has no effect unless 'Target version override' is set and 'Update policy override' is set to one of the ON states (Always allow updates, Automatic silent updates only, Manual updates only).\r\n\r\nIf you disable this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is.\r\n\r\nIf you enable this policy, installs that have a current version higher than specified by the 'Target version override' will be downgraded to the target version.\r\n\r\nWe recommend that users install the latest version of the Microsoft Edge browser to ensure protection by the latest security updates. Rollback to an earlier version risks exposure to known security issues. This policy is meant to be used as a temporary fix to address issues in a Microsoft Edge browser update.\r\n\r\nBefore temporarily rolling back your browser version, we recommend that you turn on Sync (https://go.microsoft.com/fwlink/?linkid=2133032) for all users in your organization. If you don't turn on Sync, there is a risk of permanent browsing data loss. Use this policy at your own risk.\r\n\r\nNote: All versions available for rollback can be viewed here https://aka.ms/EdgeEnterprise.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.\r\n\r\nThis policy applies to Microsoft Edge version 86 or later.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2133918 for more information. This policy is meant to serve as temporary measure when Enterprise Administrators need to downgrade for business reasons. To ensure users are protected by the latest security updates, the most recent version should be used. When versions are downgraded to older versions, there could be incompatibilities.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_rollbacktotargetversionmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_rollbacktotargetversionmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},"0e3c37601dcfb702":{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_allowdiskmount","displayName":"Allow passthrough disk mount","description":"When set to disabled, this policy disables passthrough disk mounting in WSL2 (wsl.exe --mount). This policy only applies to Store WSL.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_allowdiskmount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_allowdiskmount_1","displayName":"Enabled","description":null,"helpText":null}]},"0e1a27f28ab0ae17":{"id":"enrollment_autopilot_dpp_allowedappids","displayName":"Allowed applications","description":"Select up to 25 managed apps you want to apply with this deployment. These apps should be assigned to the device security group you selected earlier. You can check the installation status for these apps in the Autopilot device preparation deployment report.","helpText":"","infoUrls":[],"categoryId":"9d952d62-89a8-46cd-8d2b-bb86ad1fac5e","categoryName":null,"options":null},"0efffe706d94dbfd":{"id":"linux_mdatp_managed_antivirusengine_threattypesettingsmergepolicy","displayName":"Threat type settings merge","description":"Specify the merge policy for threat type settings. This can be a combination of administrator-defined and user-defined settings (merge) or only administrator-defined settings (admin_only). This setting can be used to restrict local users from defining their own settings for different threat types.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#threat-type-settings-merge-policy"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_threattypesettingsmergepolicy_0","displayName":"merge","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_threattypesettingsmergepolicy_1","displayName":"admin_only","description":null,"helpText":null}]},"0e219f6769ec6bdc":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecurityencryptdecryptdatabase","displayName":"File tab | Access Options | Customize | All Commands | Encode/Decode Database (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecurityencryptdecryptdatabase_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecurityencryptdecryptdatabase_1","displayName":"True","description":null,"helpText":null}]},"0e50c0ef308fa183":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecuritysetdatabasepassword","displayName":"Database tools | Database tools | Encrypt with Password (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecuritysetdatabasepassword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecuritysetdatabasepassword_1","displayName":"True","description":null,"helpText":null}]},"0ed4e4dc549d249f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_sameorigintabcaptureallowedbyoriginsdesc","displayName":"Allow Same Origin Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},"0e681a5dc9945961":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls","displayName":"Block Window Management permission on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which will automatically deny the window management permission. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nThis replaces the deprecated WindowPlacementBlockedForUrls policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0e3b93b0a1d86072":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},"0e9628776d17901f":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneinitializeandscriptactivexcontrols"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"0ef3f3e418c2f2ab":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"0ec682ff4f1842cb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},"0e8e1efa3dea24b6":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates. (User)","description":"Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.\r\n\r\nPolicy options mapping:\r\n\r\n* All (0) = Allow users to manage all certificates\r\n\r\n* UserOnly (1) = Allow users to manage user certificates\r\n\r\n* None (2) = Disallow users from managing certificates\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"0e8850bb0c471d44":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall","displayName":"Prevent install of the BHO to redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether to block the install of the Browser Helper Object (BHO) that enables redirecting incompatible sites from Internet Explorer to Microsoft Edge for sites that require a modern browser.\r\n\r\nIf you enable this policy, the BHO will not be installed. If it is already installed it will be uninstalled on the next Microsoft Edge update.\r\n\r\nIf this policy is not configured or is disabled, the BHO will be installed.\r\n\r\nThe BHO is required for incompatible site redirection to occur, however whether redirection occurs or not is also controlled by 'RedirectSitesFromInternetExplorerRedirectMode' (Redirect incompatible sites from Internet Explorer to Microsoft Edge).\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},"0e3118308a3e3c44":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist_internetexplorerintegrationcloudsitelist","displayName":"Configure the Enterprise Mode Cloud Site List (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"0e129f63628a0b0b":{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice","displayName":"Choose which browser opens web links (User)","description":"This policy controls which browser will open web links from within supported Microsoft 365 apps. By default, web links will open in Microsoft Edge.\r\n\r\nNote: This policy doesn’t override any user settings or policies that specify that document links should open in the desktop apps instead of their web app counterparts.\r\n\r\nIf you enable this policy, you can choose either “System default browser” or a specific browser, such as “Microsoft Edge.” “System default browser” refers to the browser setting specified on the user’s Windows device.\r\n\r\nIf you disable or don’t configure this policy, web links will open in Microsoft Edge. The user can set their preferred browser from the settings for the specific Microsoft 365 app.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2224834.","helpText":"","infoUrls":[],"categoryId":"94ce8206-be22-496c-aa72-f3560e2a5c8d","categoryName":"Links","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_1","displayName":"Enabled","description":null,"helpText":null}]},"0eaec469ab8345b8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval","displayName":"Set errors cleanup interval (User)","description":"This policy setting allows you to specify the interval for how long failed operations and other error data will remain in the cache before they can be deleted. Synchronization can fail for any reason. The failed operations and related instances are marked as \"in error,\" and this data will eventually need to be removed from the cache. It is recommended that this interval be larger than the regular cleanup interval to give the user opportunities to troubleshoot errors.\r\n\r\nIf you enable this policy setting, you may specify the interval (in minutes) for the times the failed operations and error data in the cache are deleted. \r\n\r\nIf you disable or do not configure this policy setting, a default value of 10080 minutes (1 week) will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"0e15eb3300c79439":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext","displayName":"Default button text (User)","description":"Sets the custom button text that appears on the error dialog box.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_1","displayName":"Enabled","description":null,"helpText":null}]},"0e84ce575b7860ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution","displayName":"Trust Local Solution (User)","description":"Suppresses prompt that asks to load a locally installed full-trust solution of a Document Information Panel in the background. This is normally shown if a full-trust solution is deployed and there are bound properties in the document (e.g. lookups) that must load the Document Information Panel in the background to retrieve the contents of the property. \r\n\r\nEnter pairs corresponding to the Document Information Panel solution path and a value of 1 to disable. If the value is set, the user will not be prompted when loading the full-trust solution in the background. The solution will load normally (and any non-related warnings that exist).","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_1","displayName":"Enabled","description":null,"helpText":null}]},"0ecabbf300a8fe9f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw","displayName":"Disallow in SharePoint Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw_1","displayName":"True","description":null,"helpText":null}]},"0e42820b05ba9b39":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee","displayName":"Cherokee (User)","description":"Enables the editing language Cherokee","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee_1","displayName":"Enabled","description":null,"helpText":null}]},"0ecdc3d7c7a8e506":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins","displayName":"COM add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins_1","displayName":"True","description":null,"helpText":null}]},"0e9c677c41888e9e":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},"0e26146544d421f1":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65_1","displayName":"True","description":null,"helpText":null}]},"0ec439f59f849a36":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes","displayName":"Replace straight quotes with smart quotes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},"0e273bf9fa02aa20":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},"0ee82bdee966a609":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"0e5c5e0314bce89e":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},"0ebabd962e06babd":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker_l_delaybeforestartingbackgroundspellingchecker3","displayName":"Milliseconds (e.g. 5000 milliseconds = 5 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":null}} \ No newline at end of file +{"0e663db42981e020":{"id":"com.apple.app.lock_app_options_enableinvertcolors","displayName":"Enable Invert Colors","description":"If true, enables Invert Colors. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enableinvertcolors_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enableinvertcolors_true","displayName":"True","description":null,"helpText":null}]},"0e913b9167cda3ba":{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation","displayName":"Allow UI Configuration Profile Installation","description":"If false, prohibits the user from installing configuration profiles and certificates interactively. Requires a supervised device. Available in iOS 6 and later and macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowuiconfigurationprofileinstallation_true","displayName":"True","description":null,"helpText":null}]},"0e69de1de252f62e":{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry","displayName":"Force iTunes Store Password Entry (Deprecated)","description":"If true, forces the user to enter their iTunes password for each transaction. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceitunesstorepasswordentry_true","displayName":"True","description":null,"helpText":null}]},"0e728b32c49d6aba":{"id":"com.apple.extensiblesso_realm","displayName":"Realm","description":"The realm name for Credential payloads. Use proper capitalization for this value. This key is ignored for Redirect payloads.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"0eca94af95168042":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_secondsperday","displayName":"Seconds Per Day","description":"The allowance for that day, in seconds. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"0e9861f526452e8e":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge beta.app","displayName":"Microsoft Edge Beta (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"0e4fe26282a62b97":{"id":"com.apple.managedclient.preferences_autoplayallowlist","displayName":"Allow media autoplay on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\n\nIf you don't configure this policy, the global default value from the \"AutoplayAllowed\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nNote: * is not an accepted value for this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoplayallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"0ecaa67be3a724ad":{"id":"com.apple.managedclient.preferences_importextensions","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **favorites** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importextensions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importextensions_true","displayName":"Enabled","description":null,"helpText":null}]},"0e56f3030d3cde5e":{"id":"com.apple.managedclient.preferences_startdaemononapplaunch","displayName":"Register app on launch","description":"Force Office apps to register with AutoUpdate on each launch.","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_startdaemononapplaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_startdaemononapplaunch_true","displayName":"True","description":null,"helpText":null}]},"0e4fb557e5e38f3f":{"id":"com.apple.universalaccess_mousedriverinitialdelay","displayName":"Mouse Driver Initial Delay","description":"The initial delay before moving the mouse with Mouse Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},"0ed756bf664a1501":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"0e7cebf1b3afe3de":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallallowlist","displayName":"Allow specific extensions to be installed","description":"Setting this policy specifies which extensions aren't subject to the blocklist.\n\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\n\nBy default, all extensions are allowed. However, if you prohibited extensions by policy, you can use the list of allowed extensions to change that policy.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"0ee9f928c1a0886e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printpreviewstickysettings_recommended","displayName":"Configure the sticky print preview settings (users can override)","description":"Configuring this policy sets the print preview settings as the most recent choice in Print Preview instead of the default print preview settings.\n\nEach item of this policy expects a boolean:\n\nLayout specifies if the webpage layout should be kept sticky or not in print preview settings. If you set this to True, the webpage layout uses the recent choice; otherwise, it sets to default value.\n\nSize specifies if the page size should be kept sticky or not in print preview settings. If you set this to True, the page size uses the recent choice; otherwise, it sets to default value.\n\nScale Type specifies if the scaling percentage and scale type should be kept sticky or not in print preview settings. If you set this to True, the scale percentage and scale type both use the recent choice; otherwise, it will set to default value.\n\nMargins specifies if the page margin should be kept sticky or not in print preview settings. If you set this to True, the page margins use the recent choice; otherwise, it sets to default value.\n\nIf you enable this policy, the selected values use the most recent choice in Print Preview.\n\nIf you disable or don't configure this policy, print preview settings aren't impacted.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"0e920e97737af246":{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name","displayName":"Allow users to apply BitLocker protection on removable data drives","description":"","helpText":"","infoUrls":[],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesconfigurebde_rdvallowbde_name_1","displayName":"True","description":null,"helpText":null}]},"0e17bc42fd63197f":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults","displayName":"Report operating system errors","description":"This policy setting controls whether errors in the operating system are included Windows Error Reporting is enabled.\r\n\r\nIf you enable this policy setting, Windows Error Reporting includes operating system errors.\r\n\r\nIf you disable this policy setting, operating system errors are not included in error reports.\r\n\r\nIf you do not configure this policy setting, users can change this setting in Control Panel. By default, Windows Error Reporting settings in Control Panel are set to upload operating system errors.\r\n\r\nSee also the Configure Error Reporting policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-reportoperatingsystemfaults"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_reportoperatingsystemfaults_1","displayName":"Enabled","description":null,"helpText":null}]},"0e03f2003ecfc964":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority","displayName":"Configure low CPU priority for scheduled scans","description":"\r\n This policy setting allows you to enable or disable low CPU priority for scheduled scans.\r\n\r\n If you enable this setting, low CPU priority will be used during scheduled scans.\r\n\r\n If you disable or do not configure this setting, not changes will be made to CPU priority for scheduled scans.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-lowcpupriority"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_lowcpupriority_1","displayName":"Enabled","description":null,"helpText":null}]},"0e56466013a9f051":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_netlogon_dnsavoidregisterrecordslabel","displayName":"Mnemonics:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},"0e1139bdf315d474":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11","displayName":"Internet Explorer 11","description":"This policy setting configures the synchronization of user settings of Internet Explorer 11.\r\nBy default, the user settings of Internet Explorer 11 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 11 from synchronization between computers.\r\nIf you enable this policy setting, the Internet Explorer 11 user settings continue to synchronize.\r\nIf you disable this policy setting, Internet Explorer 11 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer11"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer11_1","displayName":"Enabled","description":null,"helpText":null}]},"0e8830317ddf8bc5":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016","displayName":"Microsoft Office 365 PowerPoint 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2016_1","displayName":"Enabled","description":null,"helpText":null}]},"0e2de9beeceb1f19":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam","displayName":"Object Access Audit SAM","description":"This policy setting allows you to audit events generated by attempts to access to Security Accounts Manager (SAM) objects. SAM objects include the following: SAM_ALIAS -- A local group. SAM_GROUP -- A group that is not a local group. SAM_USER – A user account. SAM_DOMAIN – A domain. SAM_SERVER – A computer account. If you configure this policy setting, an audit event is generated when an attempt to access a kernel object is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an attempt to access a kernel object is made. Note: Only the System Access Control List (SACL) for SAM_SERVER can be modified. Volume: High on domain controllers. For information about reducing the amount of events generated in this subcategory, see article 841001 in the Microsoft Knowledge Base (https://go.microsoft.com/fwlink/?LinkId=121698).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditsam"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditsam_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"0efcb7b93e147134":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory","displayName":"Enable deleting browser and download history","description":"Setting the policy to Enabled or leaving it unset means browser history and download history can be deleted in Chrome, and users can't change this setting.\r\n\r\nSetting the policy to Disabled means browser history and download history can't be deleted. Even with this policy off, the browsing and download history are not guaranteed to be retained. Users may be able to edit or delete the history database files directly, and the browser itself may expire or archive any or all history items at any time.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowdeletingbrowserhistory_1","displayName":"Enabled","description":null,"helpText":null}]},"0e59d6601a04e556":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_legacysamesitecookiebehaviorenabledfordomainlistdesc","displayName":"Revert to legacy SameSite behavior for cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"0e59c69d5aca8558":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions","displayName":"URL pattern Exceptions to tab discarding","description":"This policy makes it so that any URL matching one or more of the patterns it specifies (using the URLBlocklist filter format) will never be discarded by the browser.\r\nThis applies to memory pressure and high efficiency mode discarding.\r\nA discarded page is unloaded and its resources fully reclaimed. The tab its associated with remains in the tabstrip, but making it visible will trigger a full reload.\r\n\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://*\r\n*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_1","displayName":"Enabled","description":null,"helpText":null}]},"0e5b45cbbc840b0f":{"id":"device_vendor_msft_policy_config_devicehealthmonitoring_configdevicehealthmonitoringuploaddestination_v2","displayName":"Config Device Health Monitoring Upload Destination","description":"If the device is not opted-in to the DeviceHealthMonitoring service via the AllowDeviceHealthMonitoring then this policy has no meaning. For devices which are opted in, the value of this policy modifies which destinations are in-scope for monitored events to be uploaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeviceHealthMonitoring#configdevicehealthmonitoringuploaddestination"],"categoryId":"55c888df-44ff-49d1-808e-ad9cb8429aff","categoryName":"Device Health Monitoring","options":null},"0e67ae70d5dd7297":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesdeletelocalprofilewhenvhdshouldapply","displayName":"Delete Local Profile When VHD Should Apply","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nWhen the FSLogix Profiles system determines that a user should have a FSLogix profile but a local profile exists, the local profile WILL BE REMOVED and the user logged on with the FSLogix profile\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\DeleteLocalProfileWhenVHDShouldApply\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesdeletelocalprofilewhenvhdshouldapply_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesdeletelocalprofilewhenvhdshouldapply_1","displayName":"Enabled","description":null,"helpText":null}]},"0e1bfa172889926e":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachinterval","displayName":"Reattach Interval","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nWhen a VHD(x) volume is detached unexpectedly, the FSLogix system will attempt to reattach the volume. This value specifies the number of seconds to wait between retries. The default value is 10 seconds which is the same as \"Not Configured\".\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ReAttachIntervalSeconds\r\nType: DWORD\r\nValues: Min = 1, Max = 60","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"0e95e9e305fb7834":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesremoveorphanedostfilesonlogoff","displayName":"Remove Orphaned OST Files On Logoff","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nRemoves duplicate OST files\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\RemoveOrphanedOSTFilesOnLogoff\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesremoveorphanedostfilesonlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesremoveorphanedostfilesonlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"0e3c97421f3c34e8":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads","displayName":"Allow font downloads","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowfontdownloads"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"0e6322dc9ea45752":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"0e97e25cd72c6a61":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowlessprivilegedsites"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"0e28fbc6f566d376":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809","displayName":"Use Pop-up Blocker","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_iz_partname1809_3","displayName":"Disable","description":null,"helpText":null}]},"0e69732bc9320141":{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\r\n\r\nIf you disable this policy, post-quantum key agreement will not be offered for WebRTC.\r\n\r\nIf you don't configure this policy, post-quantum key agreement will not be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\r\n\r\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\r\n\r\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"08677354-6f67-455e-a430-4d8d2fbabe84","categoryName":"Web Rtc settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},"0e4b0b86d312d1d6":{"id":"device_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_scarewareblockerallowlistdomainsdesc","displayName":"Configure the list of domains where Microsoft Edge scareware blocker won't run (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},"0ed0b173648309df":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_idledetectionblockedforurlsdesc","displayName":"Blocked sites for idle detection (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"0edd2733ac2f902e":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended","displayName":"Enable startup boost","description":"Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.\r\n\r\nIf Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.\r\n\r\nIf you enable this policy, startup boost is turned on.\r\n\r\nIf you disable this policy, startup boost is turned off.\r\n\r\nIf you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~performance_recommended_startupboostenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"0e64530291649984":{"id":"device_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatiemachine","displayName":"Disable local training of the Adaptive Floatie feature for the computer.","description":"\r\nThis policy setting disables local training of the Adaptive Floatie feature for the computer.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\n- If this policy setting is enabled, local training of the Adaptive Floatie feature is disabled for the computer.\r\n- If this policy setting is disabled, local training of the Adaptive Floatie feature is enabled for the computer.\r\n- If this policy setting is not configured, local training of the Adaptive Floatie feature is determined by lower priority policy settings.\r\n- If this policy setting is not configured and lower priority policy settings are also not configured, local training of the Adaptive Floatie feature is enabled for the computer.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of the Adaptive Floatie feature for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of the Adaptive Floatie feature for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"device_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatiemachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatiemachine_1","displayName":"Enabled","description":null,"helpText":null}]},"0edb597fd5417405":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatedeadline_l_updatedeadlineid","displayName":"Deadline: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":null},"0ea2d6d8941388db":{"id":"device_vendor_msft_policy_config_power_allowstandbystateswhensleepingonbattery","displayName":"Allow standby states (S1-S3) when sleeping (on battery)","description":"This policy setting manages whether or not Windows is allowed to use standby states when putting the computer in a sleep state.\n\nIf you enable or do not configure this policy setting, Windows uses standby states to put the computer in a sleep state.\n\nIf you disable this policy setting, standby states (S1-S3) are not allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-allowstandbystateswhensleepingonbattery"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_allowstandbystateswhensleepingonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_allowstandbystateswhensleepingonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},"0eb10a47887aa3f1":{"id":"device_vendor_msft_policy_config_quiettime_mutenotificationsdaily","displayName":"Mute notifications daily","description":null,"helpText":null,"infoUrls":[],"categoryId":"3ccd987e-bfca-4838-98ea-576de34b3ebe","categoryName":"Certain Hours","options":{"id":"device_vendor_msft_policy_config_quiettime_mutenotificationsdaily_1","displayName":"Require","description":null,"helpText":null}},"0e23efb12ee69f77":{"id":"device_vendor_msft_policy_config_update_allowautoupdate","displayName":"Allow Auto Update","description":"Enables the IT admin to manage automatic update behavior to scan, download, and install updates. Supported operations are Get and Replace. Important. This option should be used only for systems under regulatory compliance, as you will not get security updates as well. If the policy is not configured, end-users get the default behavior (Auto install and restart).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#allowautoupdate"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_allowautoupdate_0","displayName":"Notify the user before downloading the update. This policy is used by the enterprise who wants to enable the end-users to manage data usage. With this option users are notified when there are updates that apply to the device and are ready for download. Users can download and install the updates from the Windows Update control panel.","description":"Notify the user before downloading the update. This policy is used by the enterprise who wants to enable the end-users to manage data usage. With this option users are notified when there are updates that apply to the device and are ready for download. Users can download and install the updates from the Windows Update control panel.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_1","displayName":"Auto install the update and then notify the user to schedule a device restart. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates immediately. If the installation requires a restart, the end-user is prompted to schedule the restart time. The end-user has up to seven days to schedule the restart and after that, a restart of the device is forced. Enabling the end-user to control the start time reduces the risk of accidental data loss caused by applications that do not shutdown properly on restart.","description":"Auto install the update and then notify the user to schedule a device restart. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates immediately. If the installation requires a restart, the end-user is prompted to schedule the restart time. The end-user has up to seven days to schedule the restart and after that, a restart of the device is forced. Enabling the end-user to control the start time reduces the risk of accidental data loss caused by applications that do not shutdown properly on restart.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_2","displayName":"Auto install and restart. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device is not actively being used. This is the default behavior for unmanaged devices. Devices are updated quickly, but it increases the risk of accidental data loss caused by an application that does not shutdown properly on restart.","description":"Auto install and restart. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device is not actively being used. This is the default behavior for unmanaged devices. Devices are updated quickly, but it increases the risk of accidental data loss caused by an application that does not shutdown properly on restart.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_3","displayName":"Auto install and restart at a specified time. The IT specifies the installation day and time. If no day and time are specified, the default is 3 AM daily. Automatic installation happens at this time and device restart happens after a 15-minute countdown. If the user is logged in when Windows is ready to restart, the user can interrupt the 15-minute countdown to delay the restart.","description":"Auto install and restart at a specified time. The IT specifies the installation day and time. If no day and time are specified, the default is 3 AM daily. Automatic installation happens at this time and device restart happens after a 15-minute countdown. If the user is logged in when Windows is ready to restart, the user can interrupt the 15-minute countdown to delay the restart.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_4","displayName":"Auto install and restart without end-user control. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device is not actively being used. This setting option also sets the end-user control panel to read-only.","description":"Auto install and restart without end-user control. Updates are downloaded automatically on non-metered networks and installed during \"Automatic Maintenance\" when the device is not in use and is not running on battery power. If automatic maintenance is unable to install updates for two days, Windows Update will install updates right away. If a restart is required, then the device is automatically restarted when the device is not actively being used. This setting option also sets the end-user control panel to read-only.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautoupdate_5","displayName":"Turn off automatic updates.","description":"Turn off automatic updates.","helpText":null}]},"0e0cdbd24292fbe2":{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_preferences_pol_updatechecksuppressedperiod_part_updatechecksuppressedstartmin","displayName":"Minute (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"78497707-c3e4-400b-a6bc-1813c3689fdc","categoryName":"Preferences","options":null},"0e370d76f903ced6":{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_rollbacktotargetversionmicrosoftedgecanary","displayName":"Rollback to Target version","description":"Specifies that Microsoft Edge Update should rollback installations of Microsoft Edge to the version indicated in 'Target version override'.\r\n\r\nThis policy has no effect unless 'Target version override' is set and 'Update policy override' is set to one of the ON states (Always allow updates, Automatic silent updates only, Manual updates only).\r\n\r\nIf you disable this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is.\r\n\r\nIf you enable this policy, installs that have a current version higher than specified by the 'Target version override' will be downgraded to the target version.\r\n\r\nWe recommend that users install the latest version of the Microsoft Edge browser to ensure protection by the latest security updates. Rollback to an earlier version risks exposure to known security issues. This policy is meant to be used as a temporary fix to address issues in a Microsoft Edge browser update.\r\n\r\nBefore temporarily rolling back your browser version, we recommend that you turn on Sync (https://go.microsoft.com/fwlink/?linkid=2133032) for all users in your organization. If you don't turn on Sync, there is a risk of permanent browsing data loss. Use this policy at your own risk.\r\n\r\nNote: All versions available for rollback can be viewed here https://aka.ms/EdgeEnterprise.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.\r\n\r\nThis policy applies to Microsoft Edge version 86 or later.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2133918 for more information. This policy is meant to serve as temporary measure when Enterprise Administrators need to downgrade for business reasons. To ensure users are protected by the latest security updates, the most recent version should be used. When versions are downgraded to older versions, there could be incompatibilities.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_rollbacktotargetversionmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_rollbacktotargetversionmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},"0e3c37601dcfb702":{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_allowdiskmount","displayName":"Allow passthrough disk mount","description":"When set to disabled, this policy disables passthrough disk mounting in WSL2 (wsl.exe --mount). This policy only applies to Store WSL.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_allowdiskmount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_allowdiskmount_1","displayName":"Enabled","description":null,"helpText":null}]},"0e1a27f28ab0ae17":{"id":"enrollment_autopilot_dpp_allowedappids","displayName":"Allowed applications","description":"Select up to 25 managed apps you want to apply with this deployment. These apps should be assigned to the device security group you selected earlier. You can check the installation status for these apps in the Autopilot device preparation deployment report.","helpText":"","infoUrls":[],"categoryId":"9d952d62-89a8-46cd-8d2b-bb86ad1fac5e","categoryName":null,"options":null},"0efffe706d94dbfd":{"id":"linux_mdatp_managed_antivirusengine_threattypesettingsmergepolicy","displayName":"Threat type settings merge","description":"Specify the merge policy for threat type settings. This can be a combination of administrator-defined and user-defined settings (merge) or only administrator-defined settings (admin_only). This setting can be used to restrict local users from defining their own settings for different threat types.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#threat-type-settings-merge-policy"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_threattypesettingsmergepolicy_0","displayName":"merge","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_threattypesettingsmergepolicy_1","displayName":"admin_only","description":null,"helpText":null}]},"0e219f6769ec6bdc":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecurityencryptdecryptdatabase","displayName":"File tab | Access Options | Customize | All Commands | Encode/Decode Database (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecurityencryptdecryptdatabase_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecurityencryptdecryptdatabase_1","displayName":"True","description":null,"helpText":null}]},"0e50c0ef308fa183":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecuritysetdatabasepassword","displayName":"Database tools | Database tools | Encrypt with Password (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecuritysetdatabasepassword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolssecuritysetdatabasepassword_1","displayName":"True","description":null,"helpText":null}]},"0ed4e4dc549d249f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_sameorigintabcaptureallowedbyorigins_sameorigintabcaptureallowedbyoriginsdesc","displayName":"Allow Same Origin Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},"0e681a5dc9945961":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls","displayName":"Block Window Management permission on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which will automatically deny the window management permission. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultWindowManagementSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nThis replaces the deprecated WindowPlacementBlockedForUrls policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0e3b93b0a1d86072":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},"0e9628776d17901f":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneinitializeandscriptactivexcontrols"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"0ef3f3e418c2f2ab":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"0ec682ff4f1842cb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},"0e8e1efa3dea24b6":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates. (User)","description":"Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.\r\n\r\nPolicy options mapping:\r\n\r\n* All (0) = Allow users to manage all certificates\r\n\r\n* UserOnly (1) = Allow users to manage user certificates\r\n\r\n* None (2) = Disallow users from managing certificates\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificatemanagementallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"0e8850bb0c471d44":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall","displayName":"Prevent install of the BHO to redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether to block the install of the Browser Helper Object (BHO) that enables redirecting incompatible sites from Internet Explorer to Microsoft Edge for sites that require a modern browser.\r\n\r\nIf you enable this policy, the BHO will not be installed. If it is already installed it will be uninstalled on the next Microsoft Edge update.\r\n\r\nIf this policy is not configured or is disabled, the BHO will be installed.\r\n\r\nThe BHO is required for incompatible site redirection to occur, however whether redirection occurs or not is also controlled by 'RedirectSitesFromInternetExplorerRedirectMode' (Redirect incompatible sites from Internet Explorer to Microsoft Edge).\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},"0e3118308a3e3c44":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationcloudsitelist_internetexplorerintegrationcloudsitelist","displayName":"Configure the Enterprise Mode Cloud Site List (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"0e129f63628a0b0b":{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice","displayName":"Choose which browser opens web links (User)","description":"This policy controls which browser will open web links from within supported Microsoft 365 apps. By default, web links will open in Microsoft Edge.\r\n\r\nNote: This policy doesn’t override any user settings or policies that specify that document links should open in the desktop apps instead of their web app counterparts.\r\n\r\nIf you enable this policy, you can choose either “System default browser” or a specific browser, such as “Microsoft Edge.” “System default browser” refers to the browser setting specified on the user’s Windows device.\r\n\r\nIf you disable or don’t configure this policy, web links will open in Microsoft Edge. The user can set their preferred browser from the settings for the specific Microsoft 365 app.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2224834.","helpText":"","infoUrls":[],"categoryId":"94ce8206-be22-496c-aa72-f3560e2a5c8d","categoryName":"Links","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_m365linkshandling_l_m365linksbrowserchoice_1","displayName":"Enabled","description":null,"helpText":null}]},"0eaec469ab8345b8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval","displayName":"Set errors cleanup interval (User)","description":"This policy setting allows you to specify the interval for how long failed operations and other error data will remain in the cache before they can be deleted. Synchronization can fail for any reason. The failed operations and related instances are marked as \"in error,\" and this data will eventually need to be removed from the cache. It is recommended that this interval be larger than the regular cleanup interval to give the user opportunities to troubleshoot errors.\r\n\r\nIf you enable this policy setting, you may specify the interval (in minutes) for the times the failed operations and error data in the cache are deleted. \r\n\r\nIf you disable or do not configure this policy setting, a default value of 10080 minutes (1 week) will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_errorscleanupinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"0e15eb3300c79439":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext","displayName":"Default button text (User)","description":"Sets the custom button text that appears on the error dialog box.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultbuttontext_1","displayName":"Enabled","description":null,"helpText":null}]},"0e84ce575b7860ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution","displayName":"Trust Local Solution (User)","description":"Suppresses prompt that asks to load a locally installed full-trust solution of a Document Information Panel in the background. This is normally shown if a full-trust solution is deployed and there are bound properties in the document (e.g. lookups) that must load the Document Information Panel in the background to retrieve the contents of the property. \r\n\r\nEnter pairs corresponding to the Document Information Panel solution path and a value of 1 to disable. If the value is set, the user will not be prompted when loading the full-trust solution in the background. The solution will load normally (and any non-related warnings that exist).","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_1","displayName":"Enabled","description":null,"helpText":null}]},"0ecabbf300a8fe9f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw","displayName":"Disallow in SharePoint Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspw_1","displayName":"True","description":null,"helpText":null}]},"0e42820b05ba9b39":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee","displayName":"Cherokee (User)","description":"Enables the editing language Cherokee","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_cherokee_1","displayName":"Enabled","description":null,"helpText":null}]},"0ecdc3d7c7a8e506":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins","displayName":"COM add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypescomaddins_1","displayName":"True","description":null,"helpText":null}]},"0e9c677c41888e9e":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},"0e26146544d421f1":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_sentitemsfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage65_1","displayName":"True","description":null,"helpText":null}]},"0ec439f59f849a36":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes","displayName":"Replace straight quotes with smart quotes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_replacestraightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},"0e273bf9fa02aa20":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]},"0ee82bdee966a609":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"0e5c5e0314bce89e":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},"0ebabd962e06babd":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingbackgroundspellingchecker_l_delaybeforestartingbackgroundspellingchecker3","displayName":"Milliseconds (e.g. 5000 milliseconds = 5 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/0f.json b/public/intune-definitions/0f.json index c7e8a7ff02d2..c7034b845af2 100644 --- a/public/intune-definitions/0f.json +++ b/public/intune-definitions/0f.json @@ -1 +1 @@ -{"0f7b78b3fd8f1eef":{"id":"ade_setupassistant_department","displayName":"Department","description":null,"helpText":"Appears to users on About Configuration screen","infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":null},"0f6d1177538b2d41":{"id":"com.apple.airplay_allowlist_item_deviceid","displayName":"Device ID (Deprecated)","description":"The device ID of the AirPlay destination in the format xx:xx:xx:xx:xx:xx. This field isn’t case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},"0ff8d5d0b700d3fb":{"id":"com.apple.applicationaccess_allowardremotemanagementmodification","displayName":"Allow ARD Remote Management Modification","description":"If 'false', prevents modifying the Remote Management Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowardremotemanagementmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowardremotemanagementmodification_true","displayName":"True","description":null,"helpText":null}]},"0faa38373a8946fc":{"id":"com.apple.managedclient.preferences_clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clipboardallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"0fdad7cb98427c62":{"id":"com.apple.managedclient.preferences_extensioninstallforcelist","displayName":"Control which extensions are installed silently","description":"Specifies extensions that are installed silently, without user interaction, and that the users can't uninstall or disable (\"force-installed\"). All permissions requested by the extensions are granted implicitly, without user interaction, including any additional permissions requested by future versions of the extension. Furthermore, permissions are granted for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These two APIs are only available to extensions that are force-installed.)\n\nThis policy takes precedence over a potentially conflicting \"ExtensionInstallBlocklist\" policy. When you take an extension off of the force-installed list it's automatically uninstalled by Microsoft Edge.\n\nFor Windows devices that aren't joined to a Microsoft Active Directory domain, forced installation is limited to extensions available in the Microsoft Store.\n\nNote that users can modify the source code of any extension by using Developer Tools, potentially rendering the extension dysfunctional. If this is a concern, set the \"DeveloperToolsAvailability\" policy.\n\nUse the following format to add an extension to the list:\n\n[extensionID];[updateURL]\n\n- extensionID - the 32-letter string found on edge://extensions when in developer mode.\n\n- updateURL (optional) is the address of the Update Manifest XML document for the app or extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043. If you don't set the updateURL, the Microsoft Store update URL is used (currently https://edge.microsoft.com/extensionwebstorebase/v1/crx). Note that the update URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL indicated in the extension's manifest.\n\nFor example, gggmmkjegpiggikcnhidnjjhmicpibll;https://edge.microsoft.com/extensionwebstorebase/v1/crx installs the Microsoft Online app from the Microsoft Store \"update\" URL. For more information about hosting extensions, see: https://go.microsoft.com/fwlink/?linkid=2095044.\n\nIf you don't configure this policy, no extensions are installed automatically, and users can uninstall any extension in Microsoft Edge.\n\nNote that this policy doesn't apply to InPrivate mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"0f2496048632e6b6":{"id":"com.apple.mcx_com.apple.mcx-accounts","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":null},"0f47ea385ba730c8":{"id":"com.apple.system-extension-policy_removablesystemextensions","displayName":"Removable System Extensions","description":"A dictionary of system extensions that are allowed to remove themselves from the machine. The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension. An application using the OSSystemExtensionDeactivationRequest API can deactivate the specified system extensions without requiring an administrator to authorize the operation. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"0f8fdd0215e661df":{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled","displayName":"Enables DALL-E themes generation","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\n\nIf you enable or don't configure this policy, the AI generated themes are enabled.\n\nIf you disable this policy, the AI generated themes are disabled for your organization.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"0fd1e5692ab90025":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended","displayName":"Allow importing of browsing history (users can override)","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the Browsing history check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can't import this data manually.\n\nIf you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"0f574f75906ee78a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards","displayName":"Show Microsoft Rewards experiences","description":"Show Microsoft Rewards experience and notifications.\nIf you enable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.\n\nIf you disable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets won't see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is disabled and toggled off.\n\nIf you don't configure this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_true","displayName":"Enabled","description":null,"helpText":null}]},"0fe321996de847ed":{"id":"ddm-latestsoftwareupdate_installtime","displayName":"Install Time","description":"Specify the local device time for when updates are enforced. This setting uses the 24-hour clock format where midnight is 00:00 and 11:59pm is 23:59. Ensure that you include the leading 0 on single digit hours. For example, 01:00, 02:00, 03:00.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},"0f0ee6021d51a74a":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution","displayName":"Turn off smart multi-homed name resolution","description":"Specifies that a multi-homed DNS client should optimize name resolution across networks. The setting improves performance by issuing parallel DNS, link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT) queries across all networks. In the event that multiple positive responses are received, the network binding order is used to determine which response to accept.\r\n\r\nIf you enable this policy setting, the DNS client will not perform any optimizations. DNS queries will be issued across all networks first. LLMNR queries will be issued if the DNS queries fail, followed by NetBT queries if LLMNR queries fail.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, name resolution will be optimized when issuing DNS, LLMNR and NetBT queries.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-smartmultihomednameresolution"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution_1","displayName":"Enabled","description":null,"helpText":null}]},"0f697eb1d5a13c5f":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist_lbl_extexclusionlistedit","displayName":"Extensions: ","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"0ff4f17581c46caf":{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_customactiveschemeoverrideenter","displayName":"Custom Active Power Plan (GUID):","description":null,"helpText":"","infoUrls":[],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":null},"0f99eb5e07cf3bc8":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},"0fa72827698e66bb":{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock","displayName":"Allow Integrated Unblock screen to be displayed at the time of logon","description":"This policy setting lets you determine whether the integrated unblock feature will be available in the logon User Interface (UI).\r\n\r\nIn order to use the integrated unblock feature your smart card must support this feature. Please check with your hardware manufacturer to see if your smart card supports this feature.\r\n\r\nIf you enable this policy setting, the integrated unblock feature will be available.\r\n\r\nIf you disable or do not configure this policy setting then the integrated unblock feature will not be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowintegratedunblock"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock_1","displayName":"Enabled","description":null,"helpText":null}]},"0fb12ccc0dd6cc9c":{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_routernameresolutionintervalbox","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},"0f64bd2b6eea671f":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_delay","displayName":"Notification delay (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},"0f24497d38eb513e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete.\r\n\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled.\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0fc7a9453e1beb1b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled","displayName":"Enable WPAD optimization","description":"Setting the policy to Enabled or leaving it unset turns on WPAD (Web Proxy Auto-Discovery) optimization in Google Chrome.\r\n\r\nSetting the policy to Disabled turns off WPAD optimization, causing Google Chrome to wait longer for DNS-based WPAD servers.\r\n\r\nWhether or not this policy is set, users can't change the WPAD optimization setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0f3e8e6923800766":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profileskeeplocaldirectoryafterlogoff","displayName":"Keep Local Directory (after logoff)","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nThe 'local_%username%' folder will be left on the system after logoff and will also be used again if the same user logs on again\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\KeepLocalDir\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profileskeeplocaldirectoryafterlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profileskeeplocaldirectoryafterlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"0f939b0a5a7cd154":{"id":"device_vendor_msft_policy_config_internetexplorer_disableadobeflash","displayName":"Turn off Adobe Flash in Internet Explorer and prevent applications from using Internet Explorer technology to instantiate Flash objects","description":"This policy setting turns off Adobe Flash in Internet Explorer and prevents applications from using Internet Explorer technology to instantiate Flash objects.\r\n\r\nIf you enable this policy setting, Flash is turned off for Internet Explorer, and applications cannot use Internet Explorer technology to instantiate Flash objects. In the Manage Add-ons dialog box, the Flash status will be 'Disabled', and users cannot enable Flash. If you enable this policy setting, Internet Explorer will ignore settings made for Adobe Flash through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings.\r\n\r\nIf you disable, or do not configure this policy setting, Flash is turned on for Internet Explorer, and applications can use Internet Explorer technology to instantiate Flash objects. Users can enable or disable Flash in the Manage Add-ons dialog box.\r\n\r\nNote that Adobe Flash can still be disabled through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings, even if this policy setting is disabled, or not configured. However, if Adobe Flash is disabled through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings and not through this policy setting, all applications that use Internet Explorer technology to instantiate Flash object can still do so. For more information, see \"Group Policy Settings in Internet Explorer 10\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-InternetExplorer#internetexplorer-disableadobeflash"],"categoryId":"89c0381d-3b9b-4be5-8077-ffb18d47e910","categoryName":"Add-on Management","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableadobeflash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableadobeflash_1","displayName":"Enabled","description":null,"helpText":null}]},"0f2f0649f4516b2e":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},"0f3f28adf8b1e58e":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles","displayName":"Show security warning for potentially unsafe files","description":"This policy setting controls whether or not the \"Open File - Security Warning\" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).\n\nIf you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.\n\nIf you disable this policy setting, these files do not open.\n\nIf you do not configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneshowsecuritywarningforpotentiallyunsafefiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"0f4f0e6975280ab3":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"0feb0a7b1e3f964a":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_domainmember_digitallyencryptorsignsecurechanneldataalways","displayName":"Domain Member Digitally Encrypt Or Sign Secure Channel Data Always","description":"Domain member: Digitally encrypt or sign secure channel data (always) This security setting determines whether all secure channel traffic initiated by the domain member must be signed or encrypted. When a computer joins a domain, a computer account is created. After that, when the system starts, it uses the computer account password to create a secure channel with a domain controller for its domain. This secure channel is used to perform operations such as NTLM pass through authentication, LSA SID/name Lookup etc. This setting determines whether or not all secure channel traffic initiated by the domain member meets minimum security requirements. Specifically it determines whether all secure channel traffic initiated by the domain member must be signed or encrypted. If this policy is enabled, then the secure channel will not be established unless either signing or encryption of all secure channel traffic is negotiated. If this policy is disabled, then encryption and signing of all secure channel traffic is negotiated with the Domain Controller in which case the level of signing and encryption depends on the version of the Domain Controller and the settings of the following two policies: Domain member: Digitally encrypt secure channel data (when possible) Domain member: Digitally sign secure channel data (when possible) Default: Enabled. Notes: If this policy is enabled, the policy Domain member: Digitally sign secure channel data (when possible) is assumed to be enabled regardless of its current setting. This ensures that the domain member attempts to negotiate at least signing of the secure channel traffic. Logon information transmitted over the secure channel is always encrypted regardless of whether encryption of ALL other secure channel traffic is negotiated or not.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#domainmember_digitallyencryptorsignsecurechanneldataalways"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"0fb09b2d2fbb5f58":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\r\n\r\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\r\n\r\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\r\n\r\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\r\n\r\n * 'default' = Allow all interfaces. This exposes the local IP address.\r\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\r\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\r\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_1","displayName":"Enabled","description":null,"helpText":null}]},"0f76d7cd11190c78":{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled","displayName":"Enable open in sidebar","description":"Allow/Disallow user open a website or an app to the sidebar.\r\n\r\nIf you enable or don't configure this policy, users will be able to access the feature.\r\nIf you disable this policy, users will not be able to access the feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0f48679c38a7e017":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"0f64dac05b502e2d":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_spellchecklanguageblocklistdesc","displayName":"Force disable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"0f082a8db1644ff1":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection","displayName":"Configure enhanced hang detection for Internet Explorer mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection_0","displayName":"Enhanced hang detection disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection_1","displayName":"Enhanced hang detection enabled","description":null,"helpText":null}]},"0fb3902e58aaa95f":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended","displayName":"Configure Edge Website Typo Protection","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\r\n\r\nIf you enable this policy, Edge Website Typo Protection is turned on.\r\n\r\nIf you disable this policy, Edge Website Typo Protection is turned off.\r\n\r\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":"","infoUrls":[],"categoryId":"1ccd3115-55e7-464f-9bb9-d38a92191306","categoryName":"Edge Website Typo Protection settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"0f559e92456ec0b4":{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseinternalproxyservers","displayName":"Enterprise Internal Proxy Servers","description":"This is the comma-separated list of internal proxy servers. For example 157.54.14.28, 157.54.11.118, 10.202.14.167, 157.53.14.163, 157.69.210.59. These proxies have been configured by the admin to connect to specific resources on the Internet. They are considered to be enterprise network locations. The proxies are only leveraged in configuring the EnterpriseCloudResources policy to force traffic to the matched cloud resources through these proxies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterpriseinternalproxyservers"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":null},"0fc73070b13d5823":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablevbaforofficeapplications","displayName":"Disable VBA for Office applications","description":"This setting will prevent Excel, SharePoint Designer, Outlook, PowerPoint, Publisher and Word from using Visual Basic for Applications (VBA), despite whether or not the VBA feature is installed. Changing this setting will not install or remove the VBA files from the omputer. See the Office Resource Kit for more important information about configuring security settings.","helpText":"","infoUrls":[],"categoryId":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","categoryName":"Security Settings","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablevbaforofficeapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablevbaforofficeapplications_1","displayName":"Enabled","description":null,"helpText":null}]},"0fabde7adcc8f379":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_spdesignexe191","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_spdesignexe191_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_spdesignexe191_1","displayName":"True","description":null,"helpText":null}]},"0f080b9b5188c28b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_visioexe131","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_visioexe131_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_visioexe131_1","displayName":"True","description":null,"helpText":null}]},"0f15036f85111690":{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_desktop_checkbox","displayName":"Desktop (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_desktop_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_desktop_checkbox_1","displayName":"True","description":null,"helpText":null}]},"0fd5e558ff70f501":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb_diskspacecheckthresholdmblist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"0f87381faba12202":{"id":"device_vendor_msft_policy_config_userrights_restorefilesanddirectories","displayName":"Restore Files And Directories","description":"This user right determines which users can bypass file, directory, registry, and other persistent objects permissions when restoring backed up files and directories, and determines which users can set any valid security principal as the owner of an object. Specifically, this user right is similar to granting the following permissions to the user or group in question on all files and folders on the system:Traverse Folder/Execute File, Write. Caution: Assigning this user right can be a security risk. Since users with this user right can overwrite registry settings, hide data, and gain ownership of system objects, only assign this user right to trusted users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#restorefilesanddirectories"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"0f2413c3952b47d2":{"id":"intelligencesettings_allowimageplayground","displayName":"Allow Image Playground","description":"If `false`, disables Image Playground.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_allowimageplayground_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_allowimageplayground_true","displayName":"True","description":null,"helpText":null}]},"0f9dde54883e44f8":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_international_l_generalalignment","displayName":"General Alignment (User)","description":"Specifies the default text alignment.","helpText":"","infoUrls":[],"categoryId":"33b9194b-4027-4c23-b662-52f25db7f839","categoryName":"International","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_international_l_generalalignment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_international_l_generalalignment_1","displayName":"Enabled","description":null,"helpText":null}]},"0f2adc6b33a42fde":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_descriptioncolon53","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"0f82001a71c678f1":{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_defaultcategory","displayName":"Specify default category for Add New Programs (User)","description":"Specifies the category of programs that appears when users open the \"Add New Programs\" page.\r\n\r\nIf you enable this setting, only the programs in the category you specify are displayed when the \"Add New Programs\" page opens. Users can use the Category box on the \"Add New Programs\" page to display programs in other categories.\r\n\r\nTo use this setting, type the name of a category in the Category box for this setting. You must enter a category that is already defined in Add or Remove Programs. To define a category, use Software Installation.\r\n\r\nIf you disable this setting or do not configure it, all programs (Category: All) are displayed when the \"Add New Programs\" page opens.\r\n\r\nYou can use this setting to direct users to the programs they are most likely to need.\r\n\r\nNote: This setting is ignored if either the \"Remove Add or Remove Programs\" setting or the \"Hide Add New Programs page\" setting is enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-addremoveprograms#admx-addremoveprograms-defaultcategory"],"categoryId":"023e0367-b563-4fae-8fb6-589c836ee223","categoryName":"Add or Remove Programs","options":[{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_defaultcategory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_defaultcategory_1","displayName":"Enabled","description":null,"helpText":null}]},"0fec8f6451a81c99":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_setscreensaver","displayName":"Force specific screen saver (User)","description":"Specifies the screen saver for the user's desktop.\r\n\r\nIf you enable this setting, the system displays the specified screen saver on the user's desktop. Also, this setting disables the drop-down list of screen savers in the Screen Saver dialog in the Personalization or Display Control Panel, which prevents users from changing the screen saver.\r\n\r\nIf you disable this setting or do not configure it, users can select any screen saver.\r\n\r\nIf you enable this setting, type the name of the file that contains the screen saver, including the .scr file name extension. If the screen saver file is not in the %Systemroot%\\System32 directory, type the fully qualified path to the file.\r\n\r\nIf the specified screen saver is not installed on a computer to which this setting applies, the setting is ignored.\r\n\r\nNote: This setting can be superseded by the \"Enable Screen Saver\" setting. If the \"Enable Screen Saver\" setting is disabled, this setting is ignored, and screen savers do not run.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-setscreensaver"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_setscreensaver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_setscreensaver_1","displayName":"Enabled","description":null,"helpText":null}]},"0fb54ee8e25f80d5":{"id":"user_vendor_msft_policy_config_admx_desktop_ad_hidedirectoryfolder","displayName":"Hide Active Directory folder (User)","description":"Hides the Active Directory folder in Network Locations.\r\n\r\nThe Active Directory folder displays Active Directory objects in a browse window.\r\n\r\nIf you enable this setting, the Active Directory folder does not appear in the Network Locations folder.\r\n\r\nIf you disable this setting or do not configure it, the Active Directory folder appears in the Network Locations folder.\r\n\r\nThis setting is designed to let users search Active Directory but not tempt them to casually browse Active Directory.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-ad-hidedirectoryfolder"],"categoryId":"99ba9e42-9872-4a03-a615-fc4a4cebc067","categoryName":"Active Directory","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_ad_hidedirectoryfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_ad_hidedirectoryfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"0f130d112386ae7c":{"id":"user_vendor_msft_policy_config_admx_msi_disablerollback_1","displayName":"Prohibit rollback (User)","description":"This policy setting prohibits Windows Installer from generating and saving the files it needs to reverse an interrupted or unsuccessful installation.\r\n\r\nIf you enable this policy setting, Windows Installer is prevented from recording the original state of the system and sequence of changes it makes during installation. It also prevents Windows Installer from retaining files it intends to delete later. As a result, Windows Installer cannot restore the computer to its original state if the installation does not complete.\r\n\r\nThis policy setting is designed to reduce the amount of temporary disk space required to install programs. Also, it prevents malicious users from interrupting an installation to gather data about the internal state of the computer or to search secure system files. However, because an incomplete installation can render the system or a program inoperable, do not use this policy setting unless it is essential.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If the policy setting is enabled in either folder, it is considered be enabled, even if it is explicitly disabled in the other folder.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablerollback-1"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"user_vendor_msft_policy_config_admx_msi_disablerollback_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_msi_disablerollback_1_1","displayName":"Enabled","description":null,"helpText":null}]},"0f2ff9cc27e04c7b":{"id":"user_vendor_msft_policy_config_admx_startmenu_locktaskbar","displayName":"Lock the Taskbar (User)","description":"This setting affects the taskbar, which is used to switch between running applications.\r\n\r\nThe taskbar includes the Start button, list of currently running tasks, and the notification area. By default, the taskbar is located at the bottom of the screen, but it can be dragged to any side of the screen. When it is locked, it cannot be moved or resized.\r\n\r\nIf you enable this setting, it prevents the user from moving or resizing the taskbar. While the taskbar is locked, auto-hide and other taskbar options are still available in Taskbar properties.\r\n\r\nIf you disable this setting or do not configure it, the user can configure the taskbar position.\r\n\r\nNote: Enabling this setting also locks the QuickLaunch bar and any other toolbars that the user has on their taskbar. The toolbar's position is locked, and the user cannot show and hide various toolbars using the taskbar context menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-locktaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_locktaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_locktaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"0f27d17cba4e5ec5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs","displayName":"Allow invocation of file selection dialogs (User)","description":"Setting the policy to Enabled or leaving it unset means Chrome can display, and users can open, file selection dialogs.\r\n\r\nSetting the policy to Disabled means that whenever users perform actions provoking a file selection dialog, such as importing bookmarks, uploading files, and saving links, a message appears instead. The user is assumed to have clicked Cancel on the file selection dialog.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"0f31de27db954e4c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank (User)","description":"Setting the policy to Disabled allows popups targeting _blank to access (via JavaScript) the page that requested to open the popup.\r\n\r\nSetting the policy to Enabled or leaving it unset causes the window.opener property to be set to null unless the anchor specifies rel=\"opener\".\r\n\r\nThis policy will be removed in Google Chrome version 95.\r\n\r\nSee https://chromestatus.com/feature/6140064063029248.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},"0fa919b3a44824cb":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_2","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_3","displayName":"Ask every time a site wants obtain the Local Fonts permission","description":null,"helpText":null}]},"0fad15db9d9a47af":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy, the following take precedence, in this order:\r\n\r\n * WebHidBlockedForUrls (if there is a match),\r\n\r\n * DefaultWebHidGuardSetting (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with WebHidBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0f6852d06911a58d":{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering","displayName":"Turn on ActiveX Filtering (User)","description":"This policy setting controls the ActiveX Filtering feature for websites that are running ActiveX controls. The user can choose to turn off ActiveX Filtering for specific websites so that ActiveX controls can run properly.\n\nIf you enable this policy setting, ActiveX Filtering is enabled by default for the user. The user cannot turn off ActiveX Filtering, although they may add per-site exceptions.\n\nIf you disable or do not configure this policy setting, ActiveX Filtering is not enabled by default for the user. The user can turn ActiveX Filtering on or off.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowactivexfiltering"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering_1","displayName":"Enabled","description":null,"helpText":null}]},"0fc309933979cbd7":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.\n\nIf you selected Enable in the drop-down box, VBScript can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.\n\nIf you selected Disable in the drop-down box, VBScript is prevented from running.\n\nIf you do not configure or disable this policy setting, VBScript is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowvbscripttorunininternetexplorer"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"0f1784696ff0c2eb":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows","displayName":"Enable dragging of content from different domains across windows (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when both the source and destination are in different windows. Users cannot change this setting.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy or do not configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_1","displayName":"Enabled","description":null,"helpText":null}]},"0f919e5d5570ac45":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites (User)","description":"Specify a list of sites, based on URL patterns, for which Microsoft Edge should automatically select a client certificate, if the site requests one.\r\n\r\nThe value must be an array of stringified JSON dictionaries. Each dictionary must have the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts from which client certificates the browser will automatically select. Independent of the filter, only certificates will be selected that match the server's certificate request. For example, if $FILTER has the form { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, additionally only client certificates are selected that are issued by a certificate with the CommonName $ISSUER_CN. If $FILTER contains an \"ISSUER\" and a \"SUBJECT\" section, a client certificate must satisfy both conditions to be selected. If $FILTER specifies an organization (\"O\"), a certificate must have at least one organization which matches the specified value to be selected. If $FILTER specifies an organization unit (\"OU\"), a certificate must have at least one organization unit which matches the specified value to be selected. If $FILTER is the empty dictionary {}, the selection of client certificates is not additionally restricted.\r\n\r\nIf you don't configure this policy, auto-selection isn't done for any site.\r\n\r\nExample value:\r\n\r\n{\"pattern\":\"https://www.contoso.com\",\"filter\":{\"ISSUER\":{\"CN\":\"certificate issuer name\", \"L\": \"certificate issuer location\", \"O\": \"certificate issuer org\", \"OU\": \"certificate issuer org unit\"}, \"SUBJECT\":{\"CN\":\"certificate subject name\", \"L\": \"certificate subject location\", \"O\": \"certificate subject org\", \"OU\": \"certificate subject org unit\"}}}","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0f29d5125ec8db87":{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"0f1dd66dcc3f78cf":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview","displayName":"Max number of documents being reviewed using 'send for review' (User)","description":"Sets the total number of documents that can be sent for review by a user before reusing registry entries from previous review cycles.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},"0fa7dc8282875620":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean","displayName":"French (Caribbean) (User)","description":"Enables the editing language French (Caribbean)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean_1","displayName":"Enabled","description":null,"helpText":null}]},"0ff7df2e0fe0c63e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa","displayName":"isiXhosa (User)","description":"Enables the editing language isiXhosa","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa_1","displayName":"Enabled","description":null,"helpText":null}]},"0f0b099be80c56b7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"0f553bec16e9aef6":{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback","displayName":"Restrict Apps from FPRPC Fallback (User)","description":"\r\n\t\t\tThis policy setting allows you to control the fallback behavior of Microsoft 365 apps when using FrontPage Server Extensions Remote Procedure Call Protocol (FPRPC).\r\n\r\n\t\t\tIf you enable this policy setting, Microsoft 365 apps will not use FPRPC.\r\n\r\n\t\t\tIf you disable this policy setting, Microsoft 365 apps will continue to use FPRPC.\r\n\r\n\t\t\tIf you don't configure this policy setting, Microsoft 365 apps will continue to use FPRPC.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback_1","displayName":"Enabled","description":null,"helpText":null}]},"0fe6aee7dd894cf7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36","displayName":"Override published sync interval (User)","description":"This policy setting allows you to prevent users from overriding the sync interval published by managed SharePoint lists.\r\n\r\nIf you enable this policy setting, the \"Update Limit\" checkbox found under File tab | Info | Account Settings | SharePoint List | Change… is disabled, and the user's connected SharePoint lists will only sync as defined by the list's administrator.\r\n\r\nIf you disable this policy setting, then individual users will be able to override the sync interval by unchecking the \"Update Limit\" checkbox in the SharePoint List's Options dialog. Defined sync intervals can range from 1 minute to 1440 minutes (a full day).\r\n\r\nIf you do not configure this policy setting, the user's profile will sync the SharePoint list at a default of 20 minutes or as specified by the administrator of the SharePoint list.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36_1","displayName":"Enabled","description":null,"helpText":null}]},"0fa7e3fabe15d9d7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_l_empty32_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":null},"0fef77f45ed5cdb6":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers","displayName":"Only show enterprise themes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers_1","displayName":"True","description":null,"helpText":null}]},"0fc7bcae91efac07":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins","displayName":"Developer tab | Add-Ins | COM Add-Ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins_1","displayName":"True","description":null,"helpText":null}]},"0ffa8156a4c86c37":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},"0f63dd5da8a37357":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon","displayName":"Match minus/dash/cho-on (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"0f7b78b3fd8f1eef":{"id":"ade_setupassistant_department","displayName":"Department","description":null,"helpText":"Appears to users on About Configuration screen","infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":null},"0f6d1177538b2d41":{"id":"com.apple.airplay_allowlist_item_deviceid","displayName":"Device ID (Deprecated)","description":"The device ID of the AirPlay destination in the format xx:xx:xx:xx:xx:xx. This field isn’t case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","categoryName":"AirPlay","options":null},"0ff8d5d0b700d3fb":{"id":"com.apple.applicationaccess_allowardremotemanagementmodification","displayName":"Allow ARD Remote Management Modification","description":"If 'false', prevents modifying the Remote Management Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowardremotemanagementmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowardremotemanagementmodification_true","displayName":"True","description":null,"helpText":null}]},"0faa38373a8946fc":{"id":"com.apple.managedclient.preferences_clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clipboardallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"0fdad7cb98427c62":{"id":"com.apple.managedclient.preferences_extensioninstallforcelist","displayName":"Control which extensions are installed silently","description":"Specifies extensions that are installed silently, without user interaction, and that the users can't uninstall or disable (\"force-installed\"). All permissions requested by the extensions are granted implicitly, without user interaction, including any additional permissions requested by future versions of the extension. Furthermore, permissions are granted for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These two APIs are only available to extensions that are force-installed.)\n\nThis policy takes precedence over a potentially conflicting \"ExtensionInstallBlocklist\" policy. When you take an extension off of the force-installed list it's automatically uninstalled by Microsoft Edge.\n\nFor Windows devices that aren't joined to a Microsoft Active Directory domain, forced installation is limited to extensions available in the Microsoft Store.\n\nNote that users can modify the source code of any extension by using Developer Tools, potentially rendering the extension dysfunctional. If this is a concern, set the \"DeveloperToolsAvailability\" policy.\n\nUse the following format to add an extension to the list:\n\n[extensionID];[updateURL]\n\n- extensionID - the 32-letter string found on edge://extensions when in developer mode.\n\n- updateURL (optional) is the address of the Update Manifest XML document for the app or extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043. If you don't set the updateURL, the Microsoft Store update URL is used (currently https://edge.microsoft.com/extensionwebstorebase/v1/crx). Note that the update URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL indicated in the extension's manifest.\n\nFor example, gggmmkjegpiggikcnhidnjjhmicpibll;https://edge.microsoft.com/extensionwebstorebase/v1/crx installs the Microsoft Online app from the Microsoft Store \"update\" URL. For more information about hosting extensions, see: https://go.microsoft.com/fwlink/?linkid=2095044.\n\nIf you don't configure this policy, no extensions are installed automatically, and users can uninstall any extension in Microsoft Edge.\n\nNote that this policy doesn't apply to InPrivate mode.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"0f2496048632e6b6":{"id":"com.apple.mcx_com.apple.mcx-accounts","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":null},"0f47ea385ba730c8":{"id":"com.apple.system-extension-policy_removablesystemextensions","displayName":"Removable System Extensions","description":"A dictionary of system extensions that are allowed to remove themselves from the machine. The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension. An application using the OSSystemExtensionDeactivationRequest API can deactivate the specified system extensions without requiring an administrator to authorize the operation. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"0f8fdd0215e661df":{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled","displayName":"Enables DALL-E themes generation","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\n\nIf you enable or don't configure this policy, the AI generated themes are enabled.\n\nIf you disable this policy, the AI generated themes are disabled for your organization.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.aigenthemesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"0fd1e5692ab90025":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended","displayName":"Allow importing of browsing history (users can override)","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the Browsing history check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can't import this data manually.\n\nIf you don't configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importhistory_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"0f574f75906ee78a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards","displayName":"Show Microsoft Rewards experiences","description":"Show Microsoft Rewards experience and notifications.\nIf you enable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.\n\nIf you disable this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets won't see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is disabled and toggled off.\n\nIf you don't configure this policy:\n - Microsoft account users (excludes Azure AD accounts) in search, new tab page, and earn markets see the Microsoft Rewards experience in their Microsoft Edge user profile.\n - The setting to enable Microsoft Rewards in Microsoft Edge settings is enabled and toggled on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showmicrosoftrewards_true","displayName":"Enabled","description":null,"helpText":null}]},"0fe321996de847ed":{"id":"ddm-latestsoftwareupdate_installtime","displayName":"Install Time","description":"Specify the local device time for when updates are enforced. This setting uses the 24-hour clock format where midnight is 00:00 and 11:59pm is 23:59. Ensure that you include the leading 0 on single digit hours. For example, 01:00, 02:00, 03:00.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},"0f0ee6021d51a74a":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution","displayName":"Turn off smart multi-homed name resolution","description":"Specifies that a multi-homed DNS client should optimize name resolution across networks. The setting improves performance by issuing parallel DNS, link local multicast name resolution (LLMNR) and NetBIOS over TCP/IP (NetBT) queries across all networks. In the event that multiple positive responses are received, the network binding order is used to determine which response to accept.\r\n\r\nIf you enable this policy setting, the DNS client will not perform any optimizations. DNS queries will be issued across all networks first. LLMNR queries will be issued if the DNS queries fail, followed by NetBT queries if LLMNR queries fail.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, name resolution will be optimized when issuing DNS, LLMNR and NetBT queries.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-smartmultihomednameresolution"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_smartmultihomednameresolution_1","displayName":"Enabled","description":null,"helpText":null}]},"0f697eb1d5a13c5f":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_extexclusionlist_lbl_extexclusionlistedit","displayName":"Extensions: ","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"0ff4f17581c46caf":{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_customactiveschemeoverrideenter","displayName":"Custom Active Power Plan (GUID):","description":null,"helpText":"","infoUrls":[],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":null},"0f99eb5e07cf3bc8":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},"0fa72827698e66bb":{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock","displayName":"Allow Integrated Unblock screen to be displayed at the time of logon","description":"This policy setting lets you determine whether the integrated unblock feature will be available in the logon User Interface (UI).\r\n\r\nIn order to use the integrated unblock feature your smart card must support this feature. Please check with your hardware manufacturer to see if your smart card supports this feature.\r\n\r\nIf you enable this policy setting, the integrated unblock feature will be available.\r\n\r\nIf you disable or do not configure this policy setting then the integrated unblock feature will not be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowintegratedunblock"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowintegratedunblock_1","displayName":"Enabled","description":null,"helpText":null}]},"0fb12ccc0dd6cc9c":{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_routernameresolutionintervalbox","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},"0f64bd2b6eea671f":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_delay","displayName":"Notification delay (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},"0f24497d38eb513e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature allows for hyperlinks and address bar URL navigations to target specific text within a web page, which will be scrolled to once the loading of the web page is complete.\r\n\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via URL will be enabled.\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0fc7a9453e1beb1b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled","displayName":"Enable WPAD optimization","description":"Setting the policy to Enabled or leaving it unset turns on WPAD (Web Proxy Auto-Discovery) optimization in Google Chrome.\r\n\r\nSetting the policy to Disabled turns off WPAD optimization, causing Google Chrome to wait longer for DNS-based WPAD servers.\r\n\r\nWhether or not this policy is set, users can't change the WPAD optimization setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_wpadquickcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0f3e8e6923800766":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profileskeeplocaldirectoryafterlogoff","displayName":"Keep Local Directory (after logoff)","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nThe 'local_%username%' folder will be left on the system after logoff and will also be used again if the same user logs on again\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\KeepLocalDir\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profileskeeplocaldirectoryafterlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profileskeeplocaldirectoryafterlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"0f939b0a5a7cd154":{"id":"device_vendor_msft_policy_config_internetexplorer_disableadobeflash","displayName":"Turn off Adobe Flash in Internet Explorer and prevent applications from using Internet Explorer technology to instantiate Flash objects","description":"This policy setting turns off Adobe Flash in Internet Explorer and prevents applications from using Internet Explorer technology to instantiate Flash objects.\r\n\r\nIf you enable this policy setting, Flash is turned off for Internet Explorer, and applications cannot use Internet Explorer technology to instantiate Flash objects. In the Manage Add-ons dialog box, the Flash status will be 'Disabled', and users cannot enable Flash. If you enable this policy setting, Internet Explorer will ignore settings made for Adobe Flash through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings.\r\n\r\nIf you disable, or do not configure this policy setting, Flash is turned on for Internet Explorer, and applications can use Internet Explorer technology to instantiate Flash objects. Users can enable or disable Flash in the Manage Add-ons dialog box.\r\n\r\nNote that Adobe Flash can still be disabled through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings, even if this policy setting is disabled, or not configured. However, if Adobe Flash is disabled through the \"Add-on List\" and \"Deny all add-ons unless specifically allowed in the Add-on List\" policy settings and not through this policy setting, all applications that use Internet Explorer technology to instantiate Flash object can still do so. For more information, see \"Group Policy Settings in Internet Explorer 10\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-InternetExplorer#internetexplorer-disableadobeflash"],"categoryId":"89c0381d-3b9b-4be5-8077-ffb18d47e910","categoryName":"Add-on Management","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableadobeflash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableadobeflash_1","displayName":"Enabled","description":null,"helpText":null}]},"0f2f0649f4516b2e":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},"0f3f28adf8b1e58e":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles","displayName":"Show security warning for potentially unsafe files","description":"This policy setting controls whether or not the \"Open File - Security Warning\" message appears when the user tries to open executable files or other potentially unsafe files (from an intranet file share by using File Explorer, for example).\n\nIf you enable this policy setting and set the drop-down box to Enable, these files open without a security warning. If you set the drop-down box to Prompt, a security warning appears before the files open.\n\nIf you disable this policy setting, these files do not open.\n\nIf you do not configure this policy setting, the user can configure how the computer handles these files. By default, these files are blocked in the Restricted zone, enabled in the Intranet and Local Computer zones, and set to prompt in the Internet and Trusted zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneshowsecuritywarningforpotentiallyunsafefiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"0f4f0e6975280ab3":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"0feb0a7b1e3f964a":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_domainmember_digitallyencryptorsignsecurechanneldataalways","displayName":"Domain Member Digitally Encrypt Or Sign Secure Channel Data Always","description":"Domain member: Digitally encrypt or sign secure channel data (always) This security setting determines whether all secure channel traffic initiated by the domain member must be signed or encrypted. When a computer joins a domain, a computer account is created. After that, when the system starts, it uses the computer account password to create a secure channel with a domain controller for its domain. This secure channel is used to perform operations such as NTLM pass through authentication, LSA SID/name Lookup etc. This setting determines whether or not all secure channel traffic initiated by the domain member meets minimum security requirements. Specifically it determines whether all secure channel traffic initiated by the domain member must be signed or encrypted. If this policy is enabled, then the secure channel will not be established unless either signing or encryption of all secure channel traffic is negotiated. If this policy is disabled, then encryption and signing of all secure channel traffic is negotiated with the Domain Controller in which case the level of signing and encryption depends on the version of the Domain Controller and the settings of the following two policies: Domain member: Digitally encrypt secure channel data (when possible) Domain member: Digitally sign secure channel data (when possible) Default: Enabled. Notes: If this policy is enabled, the policy Domain member: Digitally sign secure channel data (when possible) is assumed to be enabled regardless of its current setting. This ensures that the domain member attempts to negotiate at least signing of the secure channel traffic. Logon information transmitted over the secure channel is always encrypted regardless of whether encryption of ALL other secure channel traffic is negotiated or not.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#domainmember_digitallyencryptorsignsecurechanneldataalways"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"0fb09b2d2fbb5f58":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\r\n\r\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\r\n\r\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\r\n\r\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\r\n\r\n * 'default' = Allow all interfaces. This exposes the local IP address.\r\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\r\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\r\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_1","displayName":"Enabled","description":null,"helpText":null}]},"0f76d7cd11190c78":{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled","displayName":"Enable open in sidebar","description":"Allow/Disallow user open a website or an app to the sidebar.\r\n\r\nIf you enable or don't configure this policy, users will be able to access the feature.\r\nIf you disable this policy, users will not be able to access the feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_edgeopeninsidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"0f48679c38a7e017":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"0f64dac05b502e2d":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_spellchecklanguageblocklistdesc","displayName":"Force disable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"0f082a8db1644ff1":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection","displayName":"Configure enhanced hang detection for Internet Explorer mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection_0","displayName":"Enhanced hang detection disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_internetexplorerintegrationenhancedhangdetection_internetexplorerintegrationenhancedhangdetection_1","displayName":"Enhanced hang detection enabled","description":null,"helpText":null}]},"0fb3902e58aaa95f":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended","displayName":"Configure Edge Website Typo Protection","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\r\n\r\nIf you enable this policy, Edge Website Typo Protection is turned on.\r\n\r\nIf you disable this policy, Edge Website Typo Protection is turned off.\r\n\r\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":"","infoUrls":[],"categoryId":"1ccd3115-55e7-464f-9bb9-d38a92191306","categoryName":"Edge Website Typo Protection settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"0f559e92456ec0b4":{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseinternalproxyservers","displayName":"Enterprise Internal Proxy Servers","description":"This is the comma-separated list of internal proxy servers. For example 157.54.14.28, 157.54.11.118, 10.202.14.167, 157.53.14.163, 157.69.210.59. These proxies have been configured by the admin to connect to specific resources on the Internet. They are considered to be enterprise network locations. The proxies are only leveraged in configuring the EnterpriseCloudResources policy to force traffic to the matched cloud resources through these proxies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterpriseinternalproxyservers"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":null},"0fc73070b13d5823":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablevbaforofficeapplications","displayName":"Disable VBA for Office applications","description":"This setting will prevent Excel, SharePoint Designer, Outlook, PowerPoint, Publisher and Word from using Visual Basic for Applications (VBA), despite whether or not the VBA feature is installed. Changing this setting will not install or remove the VBA files from the omputer. See the Office Resource Kit for more important information about configuring security settings.","helpText":"","infoUrls":[],"categoryId":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","categoryName":"Security Settings","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablevbaforofficeapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablevbaforofficeapplications_1","displayName":"Enabled","description":null,"helpText":null}]},"0fabde7adcc8f379":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_spdesignexe191","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_spdesignexe191_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_spdesignexe191_1","displayName":"True","description":null,"helpText":null}]},"0f080b9b5188c28b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_visioexe131","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_visioexe131_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_visioexe131_1","displayName":"True","description":null,"helpText":null}]},"0f15036f85111690":{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_desktop_checkbox","displayName":"Desktop (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_desktop_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_desktop_checkbox_1","displayName":"True","description":null,"helpText":null}]},"0fd5e558ff70f501":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb_diskspacecheckthresholdmblist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"0f1bb59c255dc882":{"id":"device_vendor_msft_policy_config_update_maintenancewindowweeklytuesday","displayName":"Maintenance Window Weekly Tuesday","description":"If the maintenance window repeat schedule is set to weekly, configure whether Tuesday is included in the weekly schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowweeklytuesday"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"0f87381faba12202":{"id":"device_vendor_msft_policy_config_userrights_restorefilesanddirectories","displayName":"Restore Files And Directories","description":"This user right determines which users can bypass file, directory, registry, and other persistent objects permissions when restoring backed up files and directories, and determines which users can set any valid security principal as the owner of an object. Specifically, this user right is similar to granting the following permissions to the user or group in question on all files and folders on the system:Traverse Folder/Execute File, Write. Caution: Assigning this user right can be a security risk. Since users with this user right can overwrite registry settings, hide data, and gain ownership of system objects, only assign this user right to trusted users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#restorefilesanddirectories"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"0f2413c3952b47d2":{"id":"intelligencesettings_allowimageplayground","displayName":"Allow Image Playground","description":"If `false`, disables Image Playground.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_allowimageplayground_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_allowimageplayground_true","displayName":"True","description":null,"helpText":null}]},"0f9dde54883e44f8":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_international_l_generalalignment","displayName":"General Alignment (User)","description":"Specifies the default text alignment.","helpText":"","infoUrls":[],"categoryId":"33b9194b-4027-4c23-b662-52f25db7f839","categoryName":"International","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_international_l_generalalignment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_international_l_generalalignment_1","displayName":"Enabled","description":null,"helpText":null}]},"0f2adc6b33a42fde":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_descriptioncolon53","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"0f82001a71c678f1":{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_defaultcategory","displayName":"Specify default category for Add New Programs (User)","description":"Specifies the category of programs that appears when users open the \"Add New Programs\" page.\r\n\r\nIf you enable this setting, only the programs in the category you specify are displayed when the \"Add New Programs\" page opens. Users can use the Category box on the \"Add New Programs\" page to display programs in other categories.\r\n\r\nTo use this setting, type the name of a category in the Category box for this setting. You must enter a category that is already defined in Add or Remove Programs. To define a category, use Software Installation.\r\n\r\nIf you disable this setting or do not configure it, all programs (Category: All) are displayed when the \"Add New Programs\" page opens.\r\n\r\nYou can use this setting to direct users to the programs they are most likely to need.\r\n\r\nNote: This setting is ignored if either the \"Remove Add or Remove Programs\" setting or the \"Hide Add New Programs page\" setting is enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-addremoveprograms#admx-addremoveprograms-defaultcategory"],"categoryId":"023e0367-b563-4fae-8fb6-589c836ee223","categoryName":"Add or Remove Programs","options":[{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_defaultcategory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_addremoveprograms_defaultcategory_1","displayName":"Enabled","description":null,"helpText":null}]},"0fec8f6451a81c99":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_setscreensaver","displayName":"Force specific screen saver (User)","description":"Specifies the screen saver for the user's desktop.\r\n\r\nIf you enable this setting, the system displays the specified screen saver on the user's desktop. Also, this setting disables the drop-down list of screen savers in the Screen Saver dialog in the Personalization or Display Control Panel, which prevents users from changing the screen saver.\r\n\r\nIf you disable this setting or do not configure it, users can select any screen saver.\r\n\r\nIf you enable this setting, type the name of the file that contains the screen saver, including the .scr file name extension. If the screen saver file is not in the %Systemroot%\\System32 directory, type the fully qualified path to the file.\r\n\r\nIf the specified screen saver is not installed on a computer to which this setting applies, the setting is ignored.\r\n\r\nNote: This setting can be superseded by the \"Enable Screen Saver\" setting. If the \"Enable Screen Saver\" setting is disabled, this setting is ignored, and screen savers do not run.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-setscreensaver"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_setscreensaver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_setscreensaver_1","displayName":"Enabled","description":null,"helpText":null}]},"0fb54ee8e25f80d5":{"id":"user_vendor_msft_policy_config_admx_desktop_ad_hidedirectoryfolder","displayName":"Hide Active Directory folder (User)","description":"Hides the Active Directory folder in Network Locations.\r\n\r\nThe Active Directory folder displays Active Directory objects in a browse window.\r\n\r\nIf you enable this setting, the Active Directory folder does not appear in the Network Locations folder.\r\n\r\nIf you disable this setting or do not configure it, the Active Directory folder appears in the Network Locations folder.\r\n\r\nThis setting is designed to let users search Active Directory but not tempt them to casually browse Active Directory.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-ad-hidedirectoryfolder"],"categoryId":"99ba9e42-9872-4a03-a615-fc4a4cebc067","categoryName":"Active Directory","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_ad_hidedirectoryfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_ad_hidedirectoryfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"0f130d112386ae7c":{"id":"user_vendor_msft_policy_config_admx_msi_disablerollback_1","displayName":"Prohibit rollback (User)","description":"This policy setting prohibits Windows Installer from generating and saving the files it needs to reverse an interrupted or unsuccessful installation.\r\n\r\nIf you enable this policy setting, Windows Installer is prevented from recording the original state of the system and sequence of changes it makes during installation. It also prevents Windows Installer from retaining files it intends to delete later. As a result, Windows Installer cannot restore the computer to its original state if the installation does not complete.\r\n\r\nThis policy setting is designed to reduce the amount of temporary disk space required to install programs. Also, it prevents malicious users from interrupting an installation to gather data about the internal state of the computer or to search secure system files. However, because an incomplete installation can render the system or a program inoperable, do not use this policy setting unless it is essential.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If the policy setting is enabled in either folder, it is considered be enabled, even if it is explicitly disabled in the other folder.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablerollback-1"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"user_vendor_msft_policy_config_admx_msi_disablerollback_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_msi_disablerollback_1_1","displayName":"Enabled","description":null,"helpText":null}]},"0f2ff9cc27e04c7b":{"id":"user_vendor_msft_policy_config_admx_startmenu_locktaskbar","displayName":"Lock the Taskbar (User)","description":"This setting affects the taskbar, which is used to switch between running applications.\r\n\r\nThe taskbar includes the Start button, list of currently running tasks, and the notification area. By default, the taskbar is located at the bottom of the screen, but it can be dragged to any side of the screen. When it is locked, it cannot be moved or resized.\r\n\r\nIf you enable this setting, it prevents the user from moving or resizing the taskbar. While the taskbar is locked, auto-hide and other taskbar options are still available in Taskbar properties.\r\n\r\nIf you disable this setting or do not configure it, the user can configure the taskbar position.\r\n\r\nNote: Enabling this setting also locks the QuickLaunch bar and any other toolbars that the user has on their taskbar. The toolbar's position is locked, and the user cannot show and hide various toolbars using the taskbar context menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-locktaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_locktaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_locktaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"0f27d17cba4e5ec5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs","displayName":"Allow invocation of file selection dialogs (User)","description":"Setting the policy to Enabled or leaving it unset means Chrome can display, and users can open, file selection dialogs.\r\n\r\nSetting the policy to Disabled means that whenever users perform actions provoking a file selection dialog, such as importing bookmarks, uploading files, and saving links, a message appears instead. The user is assumed to have clicked Cancel on the file selection dialog.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowfileselectiondialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"0f31de27db954e4c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank (User)","description":"Setting the policy to Disabled allows popups targeting _blank to access (via JavaScript) the page that requested to open the popup.\r\n\r\nSetting the policy to Enabled or leaving it unset causes the window.opener property to be set to null unless the anchor specifies rel=\"opener\".\r\n\r\nThis policy will be removed in Google Chrome version 95.\r\n\r\nSee https://chromestatus.com/feature/6140064063029248.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},"0fa919b3a44824cb":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_2","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_3","displayName":"Ask every time a site wants obtain the Local Fonts permission","description":null,"helpText":null}]},"0fad15db9d9a47af":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy, the following take precedence, in this order:\r\n\r\n * WebHidBlockedForUrls (if there is a match),\r\n\r\n * DefaultWebHidGuardSetting (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with WebHidBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0f6852d06911a58d":{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering","displayName":"Turn on ActiveX Filtering (User)","description":"This policy setting controls the ActiveX Filtering feature for websites that are running ActiveX controls. The user can choose to turn off ActiveX Filtering for specific websites so that ActiveX controls can run properly.\n\nIf you enable this policy setting, ActiveX Filtering is enabled by default for the user. The user cannot turn off ActiveX Filtering, although they may add per-site exceptions.\n\nIf you disable or do not configure this policy setting, ActiveX Filtering is not enabled by default for the user. The user can turn ActiveX Filtering on or off.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowactivexfiltering"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowactivexfiltering_1","displayName":"Enabled","description":null,"helpText":null}]},"0fc309933979cbd7":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer","displayName":"Allow VBScript to run in Internet Explorer (User)","description":"This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.\n\nIf you selected Enable in the drop-down box, VBScript can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.\n\nIf you selected Disable in the drop-down box, VBScript is prevented from running.\n\nIf you do not configure or disable this policy setting, VBScript is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowvbscripttorunininternetexplorer"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"0f1784696ff0c2eb":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows","displayName":"Enable dragging of content from different domains across windows (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when both the source and destination are in different windows. Users cannot change this setting.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy or do not configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_1","displayName":"Enabled","description":null,"helpText":null}]},"0f919e5d5570ac45":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls","displayName":"Automatically select client certificates for these sites (User)","description":"Specify a list of sites, based on URL patterns, for which Microsoft Edge should automatically select a client certificate, if the site requests one.\r\n\r\nThe value must be an array of stringified JSON dictionaries. Each dictionary must have the form { \"pattern\": \"$URL_PATTERN\", \"filter\" : $FILTER }, where $URL_PATTERN is a content setting pattern. $FILTER restricts from which client certificates the browser will automatically select. Independent of the filter, only certificates will be selected that match the server's certificate request. For example, if $FILTER has the form { \"ISSUER\": { \"CN\": \"$ISSUER_CN\" } }, additionally only client certificates are selected that are issued by a certificate with the CommonName $ISSUER_CN. If $FILTER contains an \"ISSUER\" and a \"SUBJECT\" section, a client certificate must satisfy both conditions to be selected. If $FILTER specifies an organization (\"O\"), a certificate must have at least one organization which matches the specified value to be selected. If $FILTER specifies an organization unit (\"OU\"), a certificate must have at least one organization unit which matches the specified value to be selected. If $FILTER is the empty dictionary {}, the selection of client certificates is not additionally restricted.\r\n\r\nIf you don't configure this policy, auto-selection isn't done for any site.\r\n\r\nExample value:\r\n\r\n{\"pattern\":\"https://www.contoso.com\",\"filter\":{\"ISSUER\":{\"CN\":\"certificate issuer name\", \"L\": \"certificate issuer location\", \"O\": \"certificate issuer org\", \"OU\": \"certificate issuer org unit\"}, \"SUBJECT\":{\"CN\":\"certificate subject name\", \"L\": \"certificate subject location\", \"O\": \"certificate subject org\", \"OU\": \"certificate subject org unit\"}}}","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_autoselectcertificateforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"0f29d5125ec8db87":{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"0f1dd66dcc3f78cf":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview","displayName":"Max number of documents being reviewed using 'send for review' (User)","description":"Sets the total number of documents that can be sent for review by a user before reusing registry entries from previous review cycles.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingsendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},"0fa7dc8282875620":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean","displayName":"French (Caribbean) (User)","description":"Enables the editing language French (Caribbean)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcaribbean_1","displayName":"Enabled","description":null,"helpText":null}]},"0ff7df2e0fe0c63e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa","displayName":"isiXhosa (User)","description":"Enables the editing language isiXhosa","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_isixhosa_1","displayName":"Enabled","description":null,"helpText":null}]},"0f0b099be80c56b7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog02_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"0f553bec16e9aef6":{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback","displayName":"Restrict Apps from FPRPC Fallback (User)","description":"\r\n\t\t\tThis policy setting allows you to control the fallback behavior of Microsoft 365 apps when using FrontPage Server Extensions Remote Procedure Call Protocol (FPRPC).\r\n\r\n\t\t\tIf you enable this policy setting, Microsoft 365 apps will not use FPRPC.\r\n\r\n\t\t\tIf you disable this policy setting, Microsoft 365 apps will continue to use FPRPC.\r\n\r\n\t\t\tIf you don't configure this policy setting, Microsoft 365 apps will continue to use FPRPC.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockwecfallback_1","displayName":"Enabled","description":null,"helpText":null}]},"0fe6aee7dd894cf7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36","displayName":"Override published sync interval (User)","description":"This policy setting allows you to prevent users from overriding the sync interval published by managed SharePoint lists.\r\n\r\nIf you enable this policy setting, the \"Update Limit\" checkbox found under File tab | Info | Account Settings | SharePoint List | Change… is disabled, and the user's connected SharePoint lists will only sync as defined by the list's administrator.\r\n\r\nIf you disable this policy setting, then individual users will be able to override the sync interval by unchecking the \"Update Limit\" checkbox in the SharePoint List's Options dialog. Defined sync intervals can range from 1 minute to 1440 minutes (a full day).\r\n\r\nIf you do not configure this policy setting, the user's profile will sync the SharePoint list at a default of 20 minutes or as specified by the administrator of the SharePoint list.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_overridepublishedsyncinteral36_1","displayName":"Enabled","description":null,"helpText":null}]},"0fa7e3fabe15d9d7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_l_empty32_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":null},"0fef77f45ed5cdb6":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers","displayName":"Only show enterprise themes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesdontshowothers_1","displayName":"True","description":null,"helpText":null}]},"0fc7bcae91efac07":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins","displayName":"Developer tab | Add-Ins | COM Add-Ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsaddins_1","displayName":"True","description":null,"helpText":null}]},"0ffa8156a4c86c37":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve","displayName":"Set maximum number of trust records to preserve (User)","description":"This policy setting allows you to specify the maximum number of trust records to preserve when the purge task detects that this application has trusted more than the number of trusted documents set by the \"Set maximum number of trusted documents\" policy setting.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of trust records to preserve, with an upper limit of 20000. Due to performance reasons, it is not recommended to set it to the upper limit.\r\n\r\nIf you disable or you do not configure this policy setting, the default value for of 400 is used.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_1","displayName":"Enabled","description":null,"helpText":null}]},"0f63dd5da8a37357":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon","displayName":"Match minus/dash/cho-on (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchminusdashchoon_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/13.json b/public/intune-definitions/13.json index 7f5971463237..e8419d36177b 100644 --- a/public/intune-definitions/13.json +++ b/public/intune-definitions/13.json @@ -1 +1 @@ -{"13bb1818afcf4664":{"id":"com.apple.managedclient.preferences_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\n\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\n\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\n\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\n\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\n\nNote: Sites that use WebAssembly (WASM) are not supported on 32-bit systems when \"EnhanceSecurityMode\" is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\n\nStarting in Microsoft Edge 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It won't work in Microsoft Edge version 116.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895\n\nPolicy options mapping:\n\n* StandardMode (0) = Standard mode\n\n* BalancedMode (1) = Balanced mode\n\n* StrictMode (2) = Strict mode\n\n* BasicMode (3) = (Deprecated) Basic mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_3","displayName":"(Deprecated) Basic mode","description":null,"helpText":null}]},"13737ba2a60b051c":{"id":"com.apple.managedclient.preferences_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown","description":"Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown.\n\nIf you configure this policy, the browser will block completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy.\n\nIf you disable or don't configure this policy, the default value of 0 seconds is used and outstanding keepalive requests will be immediately cancelled during browser shutdown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#fetchkeepalivedurationsecondsonshutdown"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"13d04f5a7abf3a9b":{"id":"com.apple.mcx.filevault2_deferforceatuserloginmaxbypassattempts","displayName":"Defer Force At User Login Max Bypass Attempts","description":"The maximum number of times users can bypass enabling FileVault before being required to enable it to log in. If the value is 0, the user will be required to enabled FileVault the next time they attempt to log in. Setting this key to –1 disables the feature.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},"13c7f2dd60363715":{"id":"com.apple.mobiledevice.passwordpolicy_maxgraceperiod","displayName":"Max Grace Period","description":"The maximum grace period, in minutes, to unlock the phone without entering a passcode. The default is 0, which is no grace period and requires a passcode immediately. In macOS, this grace period value is translated to screen-saver settings.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"13937552cf6a9e13":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder","displayName":"System Policy Downloads Folder","description":"Allows the application to access files in the user's Downloads folder.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"13d57fe52078dbfa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech","displayName":"Configure Online Text To Speech","description":"Set whether the browser can apply Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts.\n\nIf you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.\n\nIf you disable this policy, the voice fonts aren't available.\n\nRead more about this feature here:\nSpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech_true","displayName":"Enabled","description":null,"helpText":null}]},"13281f5200916995":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallblocklist","displayName":"Control which extensions cannot be installed","description":"Lets you specify which extensions the users CANNOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. After a disabled extension is removed from the blocklist it will automatically get re-enabled.\n\nA blocklist value of '*' means all extensions are blocked unless they are explicitly listed in the allowlist.\n\nIf this policy isn't set, the user can install any extension in Microsoft Edge.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"13c4d2954bd6e1fe":{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing","displayName":"Disable Dns Over Tcp Parsing","description":"This setting disables DNS over TCP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing_1","displayName":"DNS over TCP parsing is disabled","description":"DNS over TCP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing_0","displayName":"DNS over TCP parsing is enabled","description":"DNS over TCP parsing is enabled","helpText":null}]},"132588287ab71df7":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_threats_threatiddefaultactionlist","displayName":"Specify threats upon which default action should not be taken when detected","description":null,"helpText":"","infoUrls":[],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":null},"13980096ac376f91":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize","displayName":"Limit disk space used by Offline Files","description":"This policy setting limits the amount of disk space that can be used to store offline files. This includes the space used by automatically cached files and files that are specifically made available offline. Files can be automatically cached if the user accesses a file on an automatic caching network share.\r\n\r\nThis setting also disables the ability to adjust, through the Offline Files control panel applet, the disk space limits on the Offline Files cache. This prevents users from trying to change the option while a policy setting controls it.\r\n\r\nIf you enable this policy setting, you can specify the disk space limit (in megabytes) for offline files and also specify how much of that disk space can be used by automatically cached files.\r\n\r\nIf you disable this policy setting, the system limits the space that offline files occupy to 25 percent of the total space on the drive where the Offline Files cache is located. The limit for automatically cached files is 100 percent of the total disk space limit.\r\n\r\nIf you do not configure this policy setting, the system limits the space that offline files occupy to 25 percent of the total space on the drive where the Offline Files cache is located. The limit for automatically cached files is 100 percent of the total disk space limit. However, the users can change these values using the Offline Files control applet.\r\n\r\nIf you enable this setting and specify a total size limit greater than the size of the drive hosting the Offline Files cache, and that drive is the system drive, the total size limit is automatically adjusted downward to 75 percent of the size of the drive. If the cache is located on a drive other than the system drive, the limit is automatically adjusted downward to 100 percent of the size of the drive.\r\n\r\nIf you enable this setting and specify a total size limit less than the amount of space currently used by the Offline Files cache, the total size limit is automatically adjusted upward to the amount of space currently used by offline files. The cache is then considered full.\r\n\r\nIf you enable this setting and specify an auto-cached space limit greater than the total size limit, the auto-cached limit is automatically adjusted downward to equal the total size limit.\r\n\r\nThis setting replaces the Default Cache Size setting used by pre-Windows Vista systems.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-cachesize"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"1331b8a353e137ca":{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2_accessrights_reboottime_seconds","displayName":"Time (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},"13a8e1228a5629c4":{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name","displayName":"Configure the system to use legacy Dictionary Attack Prevention Parameters setting for TPM 2.0.","description":"This policy setting configures the TPM to use the Dictionary Attack Prevention Parameters (lockout threshold and recovery time) to the values that were used for Windows 10 Version 1607 and below. Setting this policy will take effect only if a) the TPM was originally prepared using a version of Windows after Windows 10 Version 1607 and b) the System has a TPM 2.0. Note that enabling this policy will only take effect after the TPM maintenance task runs (which typically happens after a system restart). Once this policy has been enabled on a system and has taken effect (after a system restart), disabling it will have no impact and the system's TPM will remain configured using the legacy Dictionary Attack Prevention parameters, regardless of the value of this group policy. The only way for the disabled setting of this policy to take effect on a system where it was once enabled is to a) disable it from group policy and b)clear the TPM on the system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-uselegacydap-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name_1","displayName":"Enabled","description":null,"helpText":null}]},"132ee12a87b775ad":{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription","displayName":"Timeout for hung logon sessions during shutdown","description":"This policy setting configures the number of minutes the system waits for the hung logon sessions before proceeding with the system shutdown.\r\n\r\nIf you enable this policy setting, the system waits for the hung logon sessions for the number of minutes specified.\r\n\r\nIf you disable or do not configure this policy setting, the default timeout value is 3 minutes for workstations and 15 minutes for servers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wininit#admx-wininit-shutdowntimeouthungsessionsdescription"],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":[{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_1","displayName":"Enabled","description":null,"helpText":null}]},"13dfd0a2f92687ac":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller","displayName":"Trust apps from managed installer","description":"Turning Trust apps from managed installer on will not enforce the policy. We recommend first running the poliy with Trust apps from managed installer turned on prior to enforcement to determine the impacts of the policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller_enabled","displayName":"Enabled","description":null,"helpText":null}]},"130600e20d4ea8d7":{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_forceallowtheseapps","displayName":"Let Apps Access Cellular Data Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are allowed access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_forceallowtheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},"137cfc689341a952":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain_remoteaccesshostdomain","displayName":"Configure the required domain name for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"1369884368e0bb12":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist","displayName":"Configure extension installation allow list","description":"Setting the policy specifies which extensions are not subject to the blocklist.\r\n\r\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\r\n\r\nBy default, all extensions are allowed. But, if you prohibited extensions by policy, use the list of allowed extensions to change that policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"130e1636fae0a4ca":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters_additionallaunchparameters","displayName":"Additional command line parameters for Google Chrome (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"1342f7313804327c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting","displayName":"Default Flash setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_1","displayName":"Allow all sites to automatically run the Flash plugin","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_2","displayName":"Block the Flash plugin","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_3","displayName":"Click to play","description":null,"helpText":null}]},"139d31494ebbce54":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with\r\nthe \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome makes srcdoc iframes\r\nwith \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\r\n\r\nSetting the policy to Disabled leaves the srcdoc iframe not controlled by\r\nServiceWorker.\r\n\r\nThis policy is intended to be temporary and will be removed in 2026.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"13f181f631170399":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls","displayName":"Allow Local Fonts permission on these sites","description":"Sets a list of site url patterns that specify sites which will automatically grant the local fonts permission. This will extend the ability of sites to see information about local fonts.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"13bd8d05de5998af":{"id":"device_vendor_msft_policy_config_defender_disablecatchupfullscan","displayName":"Disable Catchup Full Scan","description":"This policy setting allows you to configure catch-up scans for scheduled full scans. A catch-up scan is a scan that is initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled time. If you disable or do not configure this setting, catch-up scans for scheduled full scans will be turned on. If a computer is offline for two consecutive scheduled scans, a catch-up scan is started the next time someone logs on to the computer. If there is no scheduled scan configured, there will be no catch-up scan run. If you enable this setting, catch-up scans for scheduled full scans will be disabled. Supported values:0 - Disabled1 - Enabled (default)OMA-URI Path: . /Vendor/MSFT/Policy/Config/Defender/DisableCatchupFullScan","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_disablecatchupfullscan_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_defender_disablecatchupfullscan_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"1393c5cf42d47692":{"id":"device_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist","displayName":"Site to Zone Assignment List","description":"This policy setting allows you to manage a list of sites that you want to associate with a particular security zone. These zone numbers have associated security settings that apply to all of the sites in the zone.\n\nInternet Explorer has 4 security zones, numbered 1-4, and these are used by this policy setting to associate sites to zones. They are: (1) Intranet zone, (2) Trusted Sites zone, (3) Internet zone, and (4) Restricted Sites zone. Security settings can be set for each of these zones through other policy settings, and their default settings are: Trusted Sites zone (Low template), Intranet zone (Medium-Low template), Internet zone (Medium template), and Restricted Sites zone (High template). (The Local Machine zone and its locked down equivalent have special security settings that protect your local computer.)\n\nIf you enable this policy setting, you can enter a list of sites and their related zone numbers. The association of a site with a zone will ensure that the security settings for the specified zone are applied to the site.  For each entry that you add to the list, enter the following information:\n\nValuename – A host for an intranet site, or a fully qualified domain name for other sites. The valuename may also include a specific protocol. For example, if you enter http://www.contoso.com as the valuename, other protocols are not affected. If you enter just www.contoso.com, then all protocols are affected for that site, including http, https, ftp, and so on. The site may also be expressed as an IP address (e.g., 127.0.0.1) or range (e.g., 127.0.0.1-10). To avoid creating conflicting policies, do not include additional characters after the domain such as trailing slashes or URL path. For example, policy settings for www.contoso.com and www.contoso.com/mail would be treated as the same policy setting by Internet Explorer, and would therefore be in conflict.\n\nValue - A number indicating the zone with which this site should be associated for security settings. The Internet Explorer zones described above are 1-4.\n\nIf you disable or do not configure this policy, users may choose their own site-to-zone assignments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsitetozoneassignmentlist"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_1","displayName":"Enabled","description":null,"helpText":null}]},"13a0c603f9b9363b":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfontdownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"134925405cbc57b1":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_accounts_enableguestaccountstatus","displayName":"Accounts Enable Guest Account Status","description":"This security setting determines if the Guest account is enabled or disabled. Default: Disabled. Note: If the Guest account is disabled and the security option Network Access: Sharing and Security Model for local accounts is set to Guest Only, network logons, such as those performed by the Microsoft Network Server (SMB Service), will fail.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#accounts_enableguestaccountstatus"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_accounts_enableguestaccountstatus_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_accounts_enableguestaccountstatus_0","displayName":"Disable","description":"Disable","helpText":null}]},"1323c7fb48650cd7":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_messagetitleforusersattemptingtologon","displayName":"Interactive Logon Message Title For Users Attempting To Log On","description":"Interactive logon: Message title for users attempting to log on This security setting allows the specification of a title to appear in the title bar of the window that contains the Interactive logon: Message text for users attempting to log on. Default: No message.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_messagetitleforusersattemptingtologon"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"1306b6ae68d45569":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled","displayName":"Enable component updates in Microsoft Edge","description":"If you enable or don't configure this policy, component updates are enabled in Microsoft Edge.\r\n\r\nIf you disable this policy or set it to false, component updates are disabled for all components in Microsoft Edge.\r\n\r\nHowever, some components are exempt from this policy. This includes any component that doesn't contain executable code, that doesn't significantly alter the behavior of the browser, or that's critical for security. That is, updates that are deemed \"critical for security\" are still applied even if you disable this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"13c6881e5686928f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled","displayName":"Disable synchronization of data using Microsoft sync services","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1337e1577904991a":{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess","displayName":"Force WebSQL to be enabled","description":"WebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.\r\nIf you enable this policy, WebSQL cannot be disabled.\r\nIf you disable or don't configure this policy, WebSQL can be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"13119f2d040c1275":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting","displayName":"Default clipboard site permission","description":"This policy controls the default value for the clipboard site permission.\r\n\r\nSetting the policy to 2 blocks sites from using the clipboard site permission.\r\n\r\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'ClipboardAllowedForUrls' (Allow clipboard use on specific sites) and 'ClipboardBlockedForUrls' (Block clipboard use on specific sites) policies.\r\n\r\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\r\n\r\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"1379c20474bb6639":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list","description":"Set this policy to control which profiles Microsoft Edge will use to open sites in. Switching configurations for sites listed in this policy take precedence over other heuristics Microsoft Edge uses for switching sites but note that sites not listed on this policy are still subject to switching by those heuristics. If this policy is not configured, Microsoft Edge will continue using its heuristics to automatically switch sites.\r\n\r\nThis policy maps a URL hostname to a profile that it should be opened in.\r\n\r\nThe 'site' field should take the form of a URL hostname.\r\n\r\nThe 'profile' field can take one of the following values:\r\n- 'Work': The most recently used Microsoft Entra signed-in profile will be used to open 'site'.\r\n- 'Personal': The most recently used MSA signed-in profile will be used to open 'site'.\r\n- 'No preference': The currently used profile will be used to open 'site'.\r\n- Wildcard email address: This takes the form of '*@contoso.com'. A profile whose username ends with the contents following the '*' will be used to open 'site'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"site\": \"work.com\",\r\n \"profile\": \"Work\"\r\n },\r\n {\r\n \"site\": \"personal.com\",\r\n \"profile\": \"Personal\"\r\n },\r\n {\r\n \"site\": \"nopreference.com\",\r\n \"profile\": \"No preference\"\r\n },\r\n {\r\n \"site\": \"contoso.com\",\r\n \"profile\": \"*@contoso.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},"13a192b9b82c5e58":{"id":"device_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader","description":"Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration is not available.\r\n\r\nWhen enabled, Microsoft Edge will use SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines.\r\n\r\nStarting in Microsoft Edge version 139, SwiftShader has been deprecated due to security concerns. As a result, WebGL context creation will fail in scenarios where SwiftShader would have been used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader.\r\n\r\nIf you disable or do not configure this policy, WebGL context creation may fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it does not handle context creation failures.\r\n\r\nNote: This is a temporary policy and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader_1","displayName":"Enabled","description":null,"helpText":null}]},"131d54f8cd3318b6":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls_serialaskforurlsdesc","displayName":"Allow the Serial API on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"139a8245097722c2":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes","displayName":"New tab page experience (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_1","displayName":"Disable daily background image type","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_2","displayName":"Disable custom background image type","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_3","displayName":"Disable all background image types","description":null,"helpText":null}]},"1341f972ca8dbf27":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf this policy is not set, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the 'InsecurePrivateNetworkRequestsAllowed' (Specifies whether to allow insecure websites to make requests to more-private network endpoints) policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://docs.microsoft.com/en-us/DeployEdge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"13658fef37c26092":{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutpluggedin","displayName":"Specify the system hibernate timeout (plugged in)","description":"This policy setting allows you to specify the period of inactivity before Windows transitions the system to hibernate.\n\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows transitions to hibernate.\n\nIf you disable or do not configure this policy setting, users control this setting.\n\nIf the user has configured a slide show to run on the lock screen when the machine is locked, this can prevent the sleep transition from occuring. The \"Prevent enabling lock screen slide show\" policy setting can be used to disable the slide show feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-hibernatetimeoutpluggedin"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutpluggedin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutpluggedin_1","displayName":"Enabled","description":null,"helpText":null}]},"13fb32a9cd54cb39":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_forcedenytheseapps","displayName":"Let Apps Access Trusted Devices Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will not have access to trusted devices. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstrusteddevices_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"13ed7b1473f93d66":{"id":"device_vendor_msft_policy_config_security_preventautomaticdeviceencryptionforazureadjoineddevices","displayName":"Prevent Automatic Device Encryption For Azure AD Joined Devices","description":"Specifies whether to allow automatic device encryption during OOBE when the device is Azure AD joined.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Security#preventautomaticdeviceencryptionforazureadjoineddevices"],"categoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_security_preventautomaticdeviceencryptionforazureadjoineddevices_0","displayName":"Encryption enabled.","description":"Encryption enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_security_preventautomaticdeviceencryptionforazureadjoineddevices_1","displayName":"Encryption disabled.","description":"Encryption disabled.","helpText":null}]},"13846d24a9fd50e3":{"id":"device_vendor_msft_policy_config_security_recoveryenvironmentauthentication","displayName":"Recovery Environment Authentication","description":"This policy controls the requirement of Admin Authentication in RecoveryEnvironment.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Security#recoveryenvironmentauthentication"],"categoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_security_recoveryenvironmentauthentication_0","displayName":"current) behavior","description":"current) behavior","helpText":null},{"id":"device_vendor_msft_policy_config_security_recoveryenvironmentauthentication_1","displayName":"RequireAuthentication: Admin Authentication is always required for components in RecoveryEnvironment","description":"RequireAuthentication: Admin Authentication is always required for components in RecoveryEnvironment","helpText":null},{"id":"device_vendor_msft_policy_config_security_recoveryenvironmentauthentication_2","displayName":"NoRequireAuthentication: Admin Authentication is not required for components in RecoveryEnvironment","description":"NoRequireAuthentication: Admin Authentication is not required for components in RecoveryEnvironment","helpText":null}]},"13280c74b0962fff":{"id":"device_vendor_msft_policy_config_start_hidecategoryview","displayName":"Hide Category View","description":"This policy setting allows you to hide the category view in the Start Menu. If you enable this policy setting, the Start Menu will no longer show the category view as an option and will default to grid view.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidecategoryview"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hidecategoryview_0","displayName":"Category view shown.","description":"Category view shown.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hidecategoryview_1","displayName":"Category view hidden.","description":"Category view hidden.","helpText":null}]},"134bec3c24bb790b":{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning_v2","displayName":"Schedule Imminent Restart Warning","description":"Allows the IT Admin to specify the period for auto-restart imminent warning notifications. The default value is 15 (minutes).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduleimminentrestartwarning"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning_15","displayName":"15 Minutes","description":"15 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning_30","displayName":"30 Minutes","description":"30 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning_60","displayName":"60 Minutes","description":"60 Minutes","helpText":null}]},"138da0555507aa3b":{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_signaturesource","displayName":"Signature source","description":"","helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":[{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_signaturesource_0","displayName":"Use a certificate file in reusable settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_signaturesource_1","displayName":"Upload a certificate file","description":null,"helpText":null}]},"13611de0fd65aa2a":{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_1","displayName":"Do not allow color changes (User)","description":"This policy setting controls the ability to change the color of window frames. \r\n\r\nIf you enable this policy setting, you prevent users from changing the default window frame color. \r\n\r\nIf you disable or do not configure this policy setting, you allow users to change the default window frame color. \r\n\r\nNote: This policy setting can be used in conjunction with the \"Specify a default color for window frames\" policy setting, to enforce a specific color for window frames that cannot be changed by users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdisallowcolorizationcolorchanges-1"],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":[{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_1_1","displayName":"Enabled","description":null,"helpText":null}]},"13b9fb1fb6cbb332":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_1_lbl_customgoofflineactionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"13039909b0d4cb5b":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_confirmfiledelete","displayName":"Display confirmation dialog when deleting files (User)","description":"Allows you to have File Explorer display a confirmation dialog whenever a file is deleted or moved to the Recycle Bin.\r\n\r\nIf you enable this setting, a confirmation dialog is displayed when a file is deleted or moved to the Recycle Bin by the user.\r\n\r\nIf you disable or do not configure this setting, the default behavior of not displaying a confirmation dialog occurs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-confirmfiledelete"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_confirmfiledelete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_confirmfiledelete_1","displayName":"Enabled","description":null,"helpText":null}]},"13a1c5ab64049392":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_proxyaddress","displayName":"Proxy address (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"13654fa61ce50113":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"13c8df1c2fcfeeeb":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_1","displayName":"Type42","description":null,"helpText":null}]},"13d0f1771ac80878":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled","displayName":"Default legacy SameSite cookie behavior setting (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"13249d27d42c35e1":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},"13d52d483c9d1289":{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings","displayName":"Allow Windows Spotlight On Settings (User)","description":"This policy allows IT admins to turn off Suggestions in Settings app. These suggestions from Microsoft may show after each OS clean install, upgrade or an on-going basis to help users discover apps/features on Windows or across devices, to make their experience productive. User setting is under Settings -> Privacy -> General -> Show me suggested content in Settings app. User Setting is changeable on a per user basis. If the Group policy is set to off, no suggestions will be shown to the user in Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightonsettings"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"13dd5695facf238b":{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange","displayName":"Disable changing secondary home page settings (User)","description":"Secondary home pages are the default Web pages that Internet Explorer loads in separate tabs from the home page whenever the browser is run. This policy setting allows you to set default secondary home pages.\n\nIf you enable this policy setting, you can specify which default home pages should load as secondary home pages. The user cannot set custom default secondary home pages.\n\nIf you disable or do not configure this policy setting, the user can add secondary home pages.\n\nNote: If the “Disable Changing Home Page Settings” policy is enabled, the user cannot add secondary home pages.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecondaryhomepagechange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_1","displayName":"Enabled","description":null,"helpText":null}]},"13b8b887ea89a42b":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},"1391f698dc8edd16":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},"13323259b5b9620b":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting","displayName":"Configure cookies (User)","description":"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites.\r\n\r\nSet the policy to 'SessionOnly' (4) to clear cookies when the session closes. If Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about configuring what happens when Microsoft Edge runs in background mode.\r\n\r\nIf you don't configure this policy, the default 'AllowCookies' (1) is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.)\r\n\r\n* 1 = Let all sites create cookies\r\n\r\n* 2 = Don't let any site create cookies\r\n\r\n* 4 = Keep cookies for the duration of the session","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_1","displayName":"Enabled","description":null,"helpText":null}]},"137381b59c3fdc5d":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled","displayName":"Allow the audio sandbox to run (User)","description":"This policy controls the audio process sandbox.\r\n\r\nIf you enable this policy, the audio process will run sandboxed.\r\n\r\nIf you disable this policy, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\n\r\nIf you don't configure this policy, the default configuration for the audio sandbox will be used, which might differ based on the platform.\r\n\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"135bc089bb542d05":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled","displayName":"Enable using roaming copies for Microsoft Edge profile data (User)","description":"Enable this policy to use roaming profiles on Windows. The settings stored in Microsoft Edge profiles (favorites and preferences) are also saved to a file stored in the Roaming user profile folder (or the location specified by the administrator through the 'RoamingProfileLocation' (Set the roaming profile directory) policy).\r\n\r\nIf you disable this policy or don't configure it, only the regular local profiles are used.\r\n\r\nThe 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) policy disables all data synchronization, overriding policy.\r\n\r\nSee https://docs.microsoft.com/windows-server/storage/folder-redirection/deploy-roaming-user-profiles for more information on using roaming user profiles.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"13c6dedb8ee19522":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_autoplayallowlistdesc","displayName":"Allow media autoplay on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"13fd73e258755586":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit_l_webservicedefaultsizelimitdecimal","displayName":"Web service default size limit (KB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},"136151604d6ede2b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2","displayName":"Replace AD - Work2 (User)","description":"This policy setting allows you to customize the 3rd value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work phone 2\" of line 3.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 3 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_1","displayName":"Enabled","description":null,"helpText":null}]},"138be2b89a9d52c8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite","displayName":"Change or delete link to the proofing tools download site (User)","description":"This policy setting affects the proofing tools link under the Editing language section.\r\n\r\nIf you enable this policy setting you, you may enter the URL to another location where proofing tools may be downloaded.\r\n\r\nIf you disable this policy setting the URL will be removed.\r\n\r\nIf you do not configure this policy setting, the URL will remain available and point to the proofing tools site on Office.com.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_1","displayName":"Enabled","description":null,"helpText":null}]},"136275190698d6f5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria","displayName":"Arabic (Algeria) (User)","description":"Enables the editing language Arabic (Algeria)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria_1","displayName":"Enabled","description":null,"helpText":null}]},"1349c743ae3d2bf3":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"135c9e9ac28b8a44":{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy","displayName":"Manage user setting for new Outlook automatic migration (User)","description":"\r\nThis policy allows you to manage the user setting for enabling or disabling automatic migration to the new Outlook app. Automatic migration could be admin-driven (enabled through 'Admin-Controlled migration to New Outlook' policy), or Microsoft-driven.\r\n\r\nWhen applied, this policy controls whether the user can be switched to the new Outlook app automatically or retains control over the setting.\r\n\r\nIf you set this policy to 1 (Set to 1), the user setting controlling automatic migration is enabled. Automatic migration to the new Outlook app is allowed, and the user cannot change this setting.\r\n\r\nIf you set this policy to 2 (Set to 2), the user setting controlling automatic migration is disabled. Automatic migration to the new Outlook app is not allowed, and the user cannot change this setting.\r\n\r\nIf you set this policy to 0 (Set to 0) or don't configure this policy (default), the user setting for automatic migration is not controlled by the policy, allowing the user to manage it themselves. This user setting for automatic migration is enabled by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"137edb0d915bf18b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishatthisurl","displayName":"Publish at this URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},"135b25e28d50cc2a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex","displayName":"Additional Contacts Index: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_2","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_7","displayName":"Cyrillic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_15","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_16","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_28","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_30","displayName":"Vietnamese","description":null,"helpText":null}]},"1396efe0c959fd12":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability","displayName":"Outlook Today availability (User)","description":"Checked: Displays the customizable Outlook Today page. | Unchecked: Displays a standard folder view in place of Outlook Today.","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"13453fe262d73337":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},"13aa0eed01bc34d5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval","displayName":"Specify alert interval for web extensions (User)","description":"This policy setting allows you to specify the alert interval Outlook uses before disabling a web extension during initialization. The alert interval controls how often Office checks on memory and CPU usage for a running web extension. \r\n\r\nIf you enable this policy setting, you can specify the alert interval for web extensions. If the web extension requires more than the specified memory alert threshold when the memory or CPU check occurs, Outlook disables the web extension. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default alert interval of 5 seconds. This alert interval overrides the WEF alert interval. The maximum alert interval is 600 seconds, and the minimum alert interval is 5 seconds.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"13652df4eff9246a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Project (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},"130ad76113c3f096":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"135053741e819997":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters","displayName":"Ignore whitespace characters (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters_1","displayName":"Enabled","description":null,"helpText":null}]},"134270cca73ebe91":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments","displayName":"Word 2003 and plain XML documents (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"13ff3ab555f1b150":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"13bb1818afcf4664":{"id":"com.apple.managedclient.preferences_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\n\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\n\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\n\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\n\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\n\nNote: Sites that use WebAssembly (WASM) are not supported on 32-bit systems when \"EnhanceSecurityMode\" is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\n\nStarting in Microsoft Edge 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It won't work in Microsoft Edge version 116.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895\n\nPolicy options mapping:\n\n* StandardMode (0) = Standard mode\n\n* BalancedMode (1) = Balanced mode\n\n* StrictMode (2) = Strict mode\n\n* BasicMode (3) = (Deprecated) Basic mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymode_3","displayName":"(Deprecated) Basic mode","description":null,"helpText":null}]},"13737ba2a60b051c":{"id":"com.apple.managedclient.preferences_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on shutdown","description":"Controls the duration (in seconds) that keepalive requests are allowed to prevent the browser from completing its shutdown.\n\nIf you configure this policy, the browser will block completing shutdown while it processes any outstanding keepalive requests (see https://fetch.spec.whatwg.org/#request-keepalive-flag) up to the maximum period of time specified by this policy.\n\nIf you disable or don't configure this policy, the default value of 0 seconds is used and outstanding keepalive requests will be immediately cancelled during browser shutdown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#fetchkeepalivedurationsecondsonshutdown"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"13d04f5a7abf3a9b":{"id":"com.apple.mcx.filevault2_deferforceatuserloginmaxbypassattempts","displayName":"Defer Force At User Login Max Bypass Attempts","description":"The maximum number of times users can bypass enabling FileVault before being required to enable it to log in. If the value is 0, the user will be required to enabled FileVault the next time they attempt to log in. Setting this key to –1 disables the feature.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},"13c7f2dd60363715":{"id":"com.apple.mobiledevice.passwordpolicy_maxgraceperiod","displayName":"Max Grace Period","description":"The maximum grace period, in minutes, to unlock the phone without entering a passcode. The default is 0, which is no grace period and requires a passcode immediately. In macOS, this grace period value is translated to screen-saver settings.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"13937552cf6a9e13":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydownloadsfolder","displayName":"System Policy Downloads Folder","description":"Allows the application to access files in the user's Downloads folder.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"13d57fe52078dbfa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech","displayName":"Configure Online Text To Speech","description":"Set whether the browser can apply Online Text to Speech voice fonts, part of Azure Cognitive Services. These voice fonts are higher quality than the pre-installed system voice fonts.\n\nIf you enable or don't configure this policy, web-based applications that use the SpeechSynthesis API can use Online Text to Speech voice fonts.\n\nIf you disable this policy, the voice fonts aren't available.\n\nRead more about this feature here:\nSpeechSynthesis API: https://go.microsoft.com/fwlink/?linkid=2110038\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2110141","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configureonlinetexttospeech_true","displayName":"Enabled","description":null,"helpText":null}]},"13281f5200916995":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallblocklist","displayName":"Control which extensions cannot be installed","description":"Lets you specify which extensions the users CANNOT install. Extensions already installed will be disabled if blocked, without a way for the user to enable them. After a disabled extension is removed from the blocklist it will automatically get re-enabled.\n\nA blocklist value of '*' means all extensions are blocked unless they are explicitly listed in the allowlist.\n\nIf this policy isn't set, the user can install any extension in Microsoft Edge.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"1399c646060aa493":{"id":"contentcaching_listenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"13c4d2954bd6e1fe":{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing","displayName":"Disable Dns Over Tcp Parsing","description":"This setting disables DNS over TCP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing_1","displayName":"DNS over TCP parsing is disabled","description":"DNS over TCP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablednsovertcpparsing_0","displayName":"DNS over TCP parsing is enabled","description":"DNS over TCP parsing is enabled","helpText":null}]},"132588287ab71df7":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_threats_threatiddefaultaction_threats_threatiddefaultactionlist","displayName":"Specify threats upon which default action should not be taken when detected","description":null,"helpText":"","infoUrls":[],"categoryId":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","categoryName":"Threats","options":null},"13980096ac376f91":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize","displayName":"Limit disk space used by Offline Files","description":"This policy setting limits the amount of disk space that can be used to store offline files. This includes the space used by automatically cached files and files that are specifically made available offline. Files can be automatically cached if the user accesses a file on an automatic caching network share.\r\n\r\nThis setting also disables the ability to adjust, through the Offline Files control panel applet, the disk space limits on the Offline Files cache. This prevents users from trying to change the option while a policy setting controls it.\r\n\r\nIf you enable this policy setting, you can specify the disk space limit (in megabytes) for offline files and also specify how much of that disk space can be used by automatically cached files.\r\n\r\nIf you disable this policy setting, the system limits the space that offline files occupy to 25 percent of the total space on the drive where the Offline Files cache is located. The limit for automatically cached files is 100 percent of the total disk space limit.\r\n\r\nIf you do not configure this policy setting, the system limits the space that offline files occupy to 25 percent of the total space on the drive where the Offline Files cache is located. The limit for automatically cached files is 100 percent of the total disk space limit. However, the users can change these values using the Offline Files control applet.\r\n\r\nIf you enable this setting and specify a total size limit greater than the size of the drive hosting the Offline Files cache, and that drive is the system drive, the total size limit is automatically adjusted downward to 75 percent of the size of the drive. If the cache is located on a drive other than the system drive, the limit is automatically adjusted downward to 100 percent of the size of the drive.\r\n\r\nIf you enable this setting and specify a total size limit less than the amount of space currently used by the Offline Files cache, the total size limit is automatically adjusted upward to the amount of space currently used by offline files. The cache is then considered full.\r\n\r\nIf you enable this setting and specify an auto-cached space limit greater than the total size limit, the auto-cached limit is automatically adjusted downward to equal the total size limit.\r\n\r\nThis setting replaces the Default Cache Size setting used by pre-Windows Vista systems.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-cachesize"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_cachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"1331b8a353e137ca":{"id":"device_vendor_msft_policy_config_admx_removablestorage_accessrights_reboottime_2_accessrights_reboottime_seconds","displayName":"Time (in seconds):","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},"13a8e1228a5629c4":{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name","displayName":"Configure the system to use legacy Dictionary Attack Prevention Parameters setting for TPM 2.0.","description":"This policy setting configures the TPM to use the Dictionary Attack Prevention Parameters (lockout threshold and recovery time) to the values that were used for Windows 10 Version 1607 and below. Setting this policy will take effect only if a) the TPM was originally prepared using a version of Windows after Windows 10 Version 1607 and b) the System has a TPM 2.0. Note that enabling this policy will only take effect after the TPM maintenance task runs (which typically happens after a system restart). Once this policy has been enabled on a system and has taken effect (after a system restart), disabling it will have no impact and the system's TPM will remain configured using the legacy Dictionary Attack Prevention parameters, regardless of the value of this group policy. The only way for the disabled setting of this policy to take effect on a system where it was once enabled is to a) disable it from group policy and b)clear the TPM on the system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-uselegacydap-name"],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_uselegacydap_name_1","displayName":"Enabled","description":null,"helpText":null}]},"132ee12a87b775ad":{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription","displayName":"Timeout for hung logon sessions during shutdown","description":"This policy setting configures the number of minutes the system waits for the hung logon sessions before proceeding with the system shutdown.\r\n\r\nIf you enable this policy setting, the system waits for the hung logon sessions for the number of minutes specified.\r\n\r\nIf you disable or do not configure this policy setting, the default timeout value is 3 minutes for workstations and 15 minutes for servers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wininit#admx-wininit-shutdowntimeouthungsessionsdescription"],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":[{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_1","displayName":"Enabled","description":null,"helpText":null}]},"13dfd0a2f92687ac":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller","displayName":"Trust apps from managed installer","description":"Turning Trust apps from managed installer on will not enforce the policy. We recommend first running the poliy with Trust apps from managed installer turned on prior to enforcement to determine the impacts of the policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_trustappsfrommanagedinstaller_enabled","displayName":"Enabled","description":null,"helpText":null}]},"130600e20d4ea8d7":{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_forceallowtheseapps","displayName":"Let Apps Access Cellular Data Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are allowed access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_forceallowtheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},"137cfc689341a952":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostdomain_remoteaccesshostdomain","displayName":"Configure the required domain name for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"1369884368e0bb12":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist","displayName":"Configure extension installation allow list","description":"Setting the policy specifies which extensions are not subject to the blocklist.\r\n\r\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\r\n\r\nBy default, all extensions are allowed. But, if you prohibited extensions by policy, use the list of allowed extensions to change that policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"130e1636fae0a4ca":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_additionallaunchparameters_additionallaunchparameters","displayName":"Additional command line parameters for Google Chrome (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"1342f7313804327c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting","displayName":"Default Flash setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_1","displayName":"Allow all sites to automatically run the Flash plugin","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_2","displayName":"Block the Flash plugin","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultpluginssetting_defaultpluginssetting_3","displayName":"Click to play","description":null,"helpText":null}]},"139d31494ebbce54":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with\r\nthe \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome makes srcdoc iframes\r\nwith \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\r\n\r\nSetting the policy to Disabled leaves the srcdoc iframe not controlled by\r\nServiceWorker.\r\n\r\nThis policy is intended to be temporary and will be removed in 2026.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"13f181f631170399":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls","displayName":"Allow Local Fonts permission on these sites","description":"Sets a list of site url patterns that specify sites which will automatically grant the local fonts permission. This will extend the ability of sites to see information about local fonts.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy is not set for a site then the policy from DefaultLocalFontsSetting applies to the site, if set, otherwise the permission will follow the browser's defaults and allow users to choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_localfontsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"13bd8d05de5998af":{"id":"device_vendor_msft_policy_config_defender_disablecatchupfullscan","displayName":"Disable Catchup Full Scan","description":"This policy setting allows you to configure catch-up scans for scheduled full scans. A catch-up scan is a scan that is initiated because a regularly scheduled scan was missed. Usually these scheduled scans are missed because the computer was turned off at the scheduled time. If you disable or do not configure this setting, catch-up scans for scheduled full scans will be turned on. If a computer is offline for two consecutive scheduled scans, a catch-up scan is started the next time someone logs on to the computer. If there is no scheduled scan configured, there will be no catch-up scan run. If you enable this setting, catch-up scans for scheduled full scans will be disabled. Supported values:0 - Disabled1 - Enabled (default)OMA-URI Path: . /Vendor/MSFT/Policy/Config/Defender/DisableCatchupFullScan","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_disablecatchupfullscan_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_defender_disablecatchupfullscan_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"1393c5cf42d47692":{"id":"device_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist","displayName":"Site to Zone Assignment List","description":"This policy setting allows you to manage a list of sites that you want to associate with a particular security zone. These zone numbers have associated security settings that apply to all of the sites in the zone.\n\nInternet Explorer has 4 security zones, numbered 1-4, and these are used by this policy setting to associate sites to zones. They are: (1) Intranet zone, (2) Trusted Sites zone, (3) Internet zone, and (4) Restricted Sites zone. Security settings can be set for each of these zones through other policy settings, and their default settings are: Trusted Sites zone (Low template), Intranet zone (Medium-Low template), Internet zone (Medium template), and Restricted Sites zone (High template). (The Local Machine zone and its locked down equivalent have special security settings that protect your local computer.)\n\nIf you enable this policy setting, you can enter a list of sites and their related zone numbers. The association of a site with a zone will ensure that the security settings for the specified zone are applied to the site.  For each entry that you add to the list, enter the following information:\n\nValuename – A host for an intranet site, or a fully qualified domain name for other sites. The valuename may also include a specific protocol. For example, if you enter http://www.contoso.com as the valuename, other protocols are not affected. If you enter just www.contoso.com, then all protocols are affected for that site, including http, https, ftp, and so on. The site may also be expressed as an IP address (e.g., 127.0.0.1) or range (e.g., 127.0.0.1-10). To avoid creating conflicting policies, do not include additional characters after the domain such as trailing slashes or URL path. For example, policy settings for www.contoso.com and www.contoso.com/mail would be treated as the same policy setting by Internet Explorer, and would therefore be in conflict.\n\nValue - A number indicating the zone with which this site should be associated for security settings. The Internet Explorer zones described above are 1-4.\n\nIf you disable or do not configure this policy, users may choose their own site-to-zone assignments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsitetozoneassignmentlist"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_1","displayName":"Enabled","description":null,"helpText":null}]},"13a0c603f9b9363b":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfontdownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"134925405cbc57b1":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_accounts_enableguestaccountstatus","displayName":"Accounts Enable Guest Account Status","description":"This security setting determines if the Guest account is enabled or disabled. Default: Disabled. Note: If the Guest account is disabled and the security option Network Access: Sharing and Security Model for local accounts is set to Guest Only, network logons, such as those performed by the Microsoft Network Server (SMB Service), will fail.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#accounts_enableguestaccountstatus"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_accounts_enableguestaccountstatus_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_accounts_enableguestaccountstatus_0","displayName":"Disable","description":"Disable","helpText":null}]},"1323c7fb48650cd7":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_messagetitleforusersattemptingtologon","displayName":"Interactive Logon Message Title For Users Attempting To Log On","description":"Interactive logon: Message title for users attempting to log on This security setting allows the specification of a title to appear in the title bar of the window that contains the Interactive logon: Message text for users attempting to log on. Default: No message.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_messagetitleforusersattemptingtologon"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"1306b6ae68d45569":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled","displayName":"Enable component updates in Microsoft Edge","description":"If you enable or don't configure this policy, component updates are enabled in Microsoft Edge.\r\n\r\nIf you disable this policy or set it to false, component updates are disabled for all components in Microsoft Edge.\r\n\r\nHowever, some components are exempt from this policy. This includes any component that doesn't contain executable code, that doesn't significantly alter the behavior of the browser, or that's critical for security. That is, updates that are deemed \"critical for security\" are still applied even if you disable this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_componentupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"13c6881e5686928f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled","displayName":"Disable synchronization of data using Microsoft sync services","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_syncdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1337e1577904991a":{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess","displayName":"Force WebSQL to be enabled","description":"WebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.\r\nIf you enable this policy, WebSQL cannot be disabled.\r\nIf you disable or don't configure this policy, WebSQL can be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"13119f2d040c1275":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting","displayName":"Default clipboard site permission","description":"This policy controls the default value for the clipboard site permission.\r\n\r\nSetting the policy to 2 blocks sites from using the clipboard site permission.\r\n\r\nSetting the policy to 3 or leaving it unset lets the user change the setting and decide if the clipboard APIs are available when a site wants to use an API.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'ClipboardAllowedForUrls' (Allow clipboard use on specific sites) and 'ClipboardBlockedForUrls' (Block clipboard use on specific sites) policies.\r\n\r\nThis policy only affects clipboard operations controlled by the clipboard site permission and doesn't affect sanitized clipboard writes or trusted copy and paste operations.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockClipboard (2) = Do not allow any site to use the clipboard site permission\r\n\r\n* AskClipboard (3) = Allow sites to ask the user to grant the clipboard site permission\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_defaultclipboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"1379c20474bb6639":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list","description":"Set this policy to control which profiles Microsoft Edge will use to open sites in. Switching configurations for sites listed in this policy take precedence over other heuristics Microsoft Edge uses for switching sites but note that sites not listed on this policy are still subject to switching by those heuristics. If this policy is not configured, Microsoft Edge will continue using its heuristics to automatically switch sites.\r\n\r\nThis policy maps a URL hostname to a profile that it should be opened in.\r\n\r\nThe 'site' field should take the form of a URL hostname.\r\n\r\nThe 'profile' field can take one of the following values:\r\n- 'Work': The most recently used Microsoft Entra signed-in profile will be used to open 'site'.\r\n- 'Personal': The most recently used MSA signed-in profile will be used to open 'site'.\r\n- 'No preference': The currently used profile will be used to open 'site'.\r\n- Wildcard email address: This takes the form of '*@contoso.com'. A profile whose username ends with the contents following the '*' will be used to open 'site'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"site\": \"work.com\",\r\n \"profile\": \"Work\"\r\n },\r\n {\r\n \"site\": \"personal.com\",\r\n \"profile\": \"Personal\"\r\n },\r\n {\r\n \"site\": \"nopreference.com\",\r\n \"profile\": \"No preference\"\r\n },\r\n {\r\n \"site\": \"contoso.com\",\r\n \"profile\": \"*@contoso.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},"13a192b9b82c5e58":{"id":"device_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader","description":"Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration is not available.\r\n\r\nWhen enabled, Microsoft Edge will use SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines.\r\n\r\nStarting in Microsoft Edge version 139, SwiftShader has been deprecated due to security concerns. As a result, WebGL context creation will fail in scenarios where SwiftShader would have been used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader.\r\n\r\nIf you disable or do not configure this policy, WebGL context creation may fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it does not handle context creation failures.\r\n\r\nNote: This is a temporary policy and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_enableunsafeswiftshader_1","displayName":"Enabled","description":null,"helpText":null}]},"131d54f8cd3318b6":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialaskforurls_serialaskforurlsdesc","displayName":"Allow the Serial API on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"139a8245097722c2":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes","displayName":"New tab page experience (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_1","displayName":"Disable daily background image type","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_2","displayName":"Disable custom background image type","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~startup_newtabpageallowedbackgroundtypes_newtabpageallowedbackgroundtypes_3","displayName":"Disable all background image types","description":null,"helpText":null}]},"1341f972ca8dbf27":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf this policy is not set, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the 'InsecurePrivateNetworkRequestsAllowed' (Specifies whether to allow insecure websites to make requests to more-private network endpoints) policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://docs.microsoft.com/en-us/DeployEdge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"13658fef37c26092":{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutpluggedin","displayName":"Specify the system hibernate timeout (plugged in)","description":"This policy setting allows you to specify the period of inactivity before Windows transitions the system to hibernate.\n\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows transitions to hibernate.\n\nIf you disable or do not configure this policy setting, users control this setting.\n\nIf the user has configured a slide show to run on the lock screen when the machine is locked, this can prevent the sleep transition from occuring. The \"Prevent enabling lock screen slide show\" policy setting can be used to disable the slide show feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-hibernatetimeoutpluggedin"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutpluggedin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutpluggedin_1","displayName":"Enabled","description":null,"helpText":null}]},"13fb32a9cd54cb39":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_forcedenytheseapps","displayName":"Let Apps Access Trusted Devices Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will not have access to trusted devices. This setting overrides the default LetAppsAccessTrustedDevices policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstrusteddevices_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"13ed7b1473f93d66":{"id":"device_vendor_msft_policy_config_security_preventautomaticdeviceencryptionforazureadjoineddevices","displayName":"Prevent Automatic Device Encryption For Azure AD Joined Devices","description":"Specifies whether to allow automatic device encryption during OOBE when the device is Azure AD joined.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Security#preventautomaticdeviceencryptionforazureadjoineddevices"],"categoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_security_preventautomaticdeviceencryptionforazureadjoineddevices_0","displayName":"Encryption enabled.","description":"Encryption enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_security_preventautomaticdeviceencryptionforazureadjoineddevices_1","displayName":"Encryption disabled.","description":"Encryption disabled.","helpText":null}]},"13846d24a9fd50e3":{"id":"device_vendor_msft_policy_config_security_recoveryenvironmentauthentication","displayName":"Recovery Environment Authentication","description":"This policy controls the requirement of Admin Authentication in RecoveryEnvironment.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Security#recoveryenvironmentauthentication"],"categoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_security_recoveryenvironmentauthentication_0","displayName":"current) behavior","description":"current) behavior","helpText":null},{"id":"device_vendor_msft_policy_config_security_recoveryenvironmentauthentication_1","displayName":"RequireAuthentication: Admin Authentication is always required for components in RecoveryEnvironment","description":"RequireAuthentication: Admin Authentication is always required for components in RecoveryEnvironment","helpText":null},{"id":"device_vendor_msft_policy_config_security_recoveryenvironmentauthentication_2","displayName":"NoRequireAuthentication: Admin Authentication is not required for components in RecoveryEnvironment","description":"NoRequireAuthentication: Admin Authentication is not required for components in RecoveryEnvironment","helpText":null}]},"13280c74b0962fff":{"id":"device_vendor_msft_policy_config_start_hidecategoryview","displayName":"Hide Category View","description":"This policy setting allows you to hide the category view in the Start Menu. If you enable this policy setting, the Start Menu will no longer show the category view as an option and will default to grid view.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidecategoryview"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hidecategoryview_0","displayName":"Category view shown.","description":"Category view shown.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hidecategoryview_1","displayName":"Category view hidden.","description":"Category view hidden.","helpText":null}]},"134bec3c24bb790b":{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning_v2","displayName":"Schedule Imminent Restart Warning","description":"Allows the IT Admin to specify the period for auto-restart imminent warning notifications. The default value is 15 (minutes).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduleimminentrestartwarning"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning_15","displayName":"15 Minutes","description":"15 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning_30","displayName":"30 Minutes","description":"30 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning_60","displayName":"60 Minutes","description":"60 Minutes","helpText":null}]},"138da0555507aa3b":{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_signaturesource","displayName":"Signature source","description":"","helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":[{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_signaturesource_0","displayName":"Use a certificate file in reusable settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_signaturesource_1","displayName":"Upload a certificate file","description":null,"helpText":null}]},"13611de0fd65aa2a":{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_1","displayName":"Do not allow color changes (User)","description":"This policy setting controls the ability to change the color of window frames. \r\n\r\nIf you enable this policy setting, you prevent users from changing the default window frame color. \r\n\r\nIf you disable or do not configure this policy setting, you allow users to change the default window frame color. \r\n\r\nNote: This policy setting can be used in conjunction with the \"Specify a default color for window frames\" policy setting, to enforce a specific color for window frames that cannot be changed by users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdisallowcolorizationcolorchanges-1"],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":[{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowcolorizationcolorchanges_1_1","displayName":"Enabled","description":null,"helpText":null}]},"13b9fb1fb6cbb332":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_1_lbl_customgoofflineactionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"13039909b0d4cb5b":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_confirmfiledelete","displayName":"Display confirmation dialog when deleting files (User)","description":"Allows you to have File Explorer display a confirmation dialog whenever a file is deleted or moved to the Recycle Bin.\r\n\r\nIf you enable this setting, a confirmation dialog is displayed when a file is deleted or moved to the Recycle Bin by the user.\r\n\r\nIf you disable or do not configure this setting, the default behavior of not displaying a confirmation dialog occurs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-confirmfiledelete"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_confirmfiledelete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_confirmfiledelete_1","displayName":"Enabled","description":null,"helpText":null}]},"13a1c5ab64049392":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_proxyaddress","displayName":"Proxy address (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"13654fa61ce50113":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurl_recommended_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"13c8df1c2fcfeeeb":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_1","displayName":"Type42","description":null,"helpText":null}]},"13d0f1771ac80878":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled","displayName":"Default legacy SameSite cookie behavior setting (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"13249d27d42c35e1":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},"13d52d483c9d1289":{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings","displayName":"Allow Windows Spotlight On Settings (User)","description":"This policy allows IT admins to turn off Suggestions in Settings app. These suggestions from Microsoft may show after each OS clean install, upgrade or an on-going basis to help users discover apps/features on Windows or across devices, to make their experience productive. User setting is under Settings -> Privacy -> General -> Show me suggested content in Settings app. User Setting is changeable on a per user basis. If the Group policy is set to off, no suggestions will be shown to the user in Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightonsettings"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonsettings_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"13dd5695facf238b":{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange","displayName":"Disable changing secondary home page settings (User)","description":"Secondary home pages are the default Web pages that Internet Explorer loads in separate tabs from the home page whenever the browser is run. This policy setting allows you to set default secondary home pages.\n\nIf you enable this policy setting, you can specify which default home pages should load as secondary home pages. The user cannot set custom default secondary home pages.\n\nIf you disable or do not configure this policy setting, the user can add secondary home pages.\n\nNote: If the “Disable Changing Home Page Settings” policy is enabled, the user cannot add secondary home pages.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecondaryhomepagechange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_1","displayName":"Enabled","description":null,"helpText":null}]},"13b8b887ea89a42b":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},"1391f698dc8edd16":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},"13323259b5b9620b":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting","displayName":"Configure cookies (User)","description":"Control whether websites can create cookies on the user's device. This policy is all or nothing - you can let all websites create cookies, or no websites create cookies. You can't use this policy to enable cookies from specific websites.\r\n\r\nSet the policy to 'SessionOnly' (4) to clear cookies when the session closes. If Microsoft Edge is running in background mode, the session might not close when the last window is closed, meaning the cookies won't be cleared when the window closes. See 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about configuring what happens when Microsoft Edge runs in background mode.\r\n\r\nIf you don't configure this policy, the default 'AllowCookies' (1) is used, and users can change this setting in Microsoft Edge Settings. (If you don't want users to be able to change this setting, set the policy.)\r\n\r\n* 1 = Let all sites create cookies\r\n\r\n* 2 = Don't let any site create cookies\r\n\r\n* 4 = Keep cookies for the duration of the session","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_1","displayName":"Enabled","description":null,"helpText":null}]},"137381b59c3fdc5d":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled","displayName":"Allow the audio sandbox to run (User)","description":"This policy controls the audio process sandbox.\r\n\r\nIf you enable this policy, the audio process will run sandboxed.\r\n\r\nIf you disable this policy, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\n\r\nIf you don't configure this policy, the default configuration for the audio sandbox will be used, which might differ based on the platform.\r\n\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"135bc089bb542d05":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled","displayName":"Enable using roaming copies for Microsoft Edge profile data (User)","description":"Enable this policy to use roaming profiles on Windows. The settings stored in Microsoft Edge profiles (favorites and preferences) are also saved to a file stored in the Roaming user profile folder (or the location specified by the administrator through the 'RoamingProfileLocation' (Set the roaming profile directory) policy).\r\n\r\nIf you disable this policy or don't configure it, only the regular local profiles are used.\r\n\r\nThe 'SyncDisabled' (Disable synchronization of data using Microsoft sync services) policy disables all data synchronization, overriding policy.\r\n\r\nSee https://docs.microsoft.com/windows-server/storage/folder-redirection/deploy-roaming-user-profiles for more information on using roaming user profiles.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilesupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"13c6dedb8ee19522":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_autoplayallowlistdesc","displayName":"Allow media autoplay on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"13fd73e258755586":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_webservice_l_webservicedefaultsizelimit_l_webservicedefaultsizelimitdecimal","displayName":"Web service default size limit (KB) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c72d9f00-d625-43ec-add4-514891035839","categoryName":"Web Service","options":null},"136151604d6ede2b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2","displayName":"Replace AD - Work2 (User)","description":"This policy setting allows you to customize the 3rd value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"work phone 2\" of line 3.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 3 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework2_1","displayName":"Enabled","description":null,"helpText":null}]},"138be2b89a9d52c8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite","displayName":"Change or delete link to the proofing tools download site (User)","description":"This policy setting affects the proofing tools link under the Editing language section.\r\n\r\nIf you enable this policy setting you, you may enter the URL to another location where proofing tools may be downloaded.\r\n\r\nIf you disable this policy setting the URL will be removed.\r\n\r\nIf you do not configure this policy setting, the URL will remain available and point to the proofing tools site on Office.com.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktoproofingtoolsdownloadsite_1","displayName":"Enabled","description":null,"helpText":null}]},"136275190698d6f5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria","displayName":"Arabic (Algeria) (User)","description":"Enables the editing language Arabic (Algeria)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicalgeria_1","displayName":"Enabled","description":null,"helpText":null}]},"1349c743ae3d2bf3":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"135c9e9ac28b8a44":{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy","displayName":"Manage user setting for new Outlook automatic migration (User)","description":"\r\nThis policy allows you to manage the user setting for enabling or disabling automatic migration to the new Outlook app. Automatic migration could be admin-driven (enabled through 'Admin-Controlled migration to New Outlook' policy), or Microsoft-driven.\r\n\r\nWhen applied, this policy controls whether the user can be switched to the new Outlook app automatically or retains control over the setting.\r\n\r\nIf you set this policy to 1 (Set to 1), the user setting controlling automatic migration is enabled. Automatic migration to the new Outlook app is allowed, and the user cannot change this setting.\r\n\r\nIf you set this policy to 2 (Set to 2), the user setting controlling automatic migration is disabled. Automatic migration to the new Outlook app is not allowed, and the user cannot change this setting.\r\n\r\nIf you set this policy to 0 (Set to 0) or don't configure this policy (default), the user setting for automatic migration is not controlled by the policy, allowing the user to manage it themselves. This user setting for automatic migration is enabled by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v16~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationusersettingpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"137edb0d915bf18b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_internetfreebusyoptions_l_publishatthisurl","displayName":"Publish at this URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},"135b25e28d50cc2a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex","displayName":"Additional Contacts Index: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_2","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_7","displayName":"Cyrillic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_15","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_16","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_28","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_additionalcontactsindex_30","displayName":"Vietnamese","description":null,"helpText":null}]},"1396efe0c959fd12":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability","displayName":"Outlook Today availability (User)","description":"Checked: Displays the customizable Outlook Today page. | Unchecked: Displays a standard folder view in place of Outlook Today.","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_outlooktodayavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"13453fe262d73337":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressbook_v2_l_oomaddressbook_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},"13aa0eed01bc34d5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval","displayName":"Specify alert interval for web extensions (User)","description":"This policy setting allows you to specify the alert interval Outlook uses before disabling a web extension during initialization. The alert interval controls how often Office checks on memory and CPU usage for a running web extension. \r\n\r\nIf you enable this policy setting, you can specify the alert interval for web extensions. If the web extension requires more than the specified memory alert threshold when the memory or CPU check occurs, Outlook disables the web extension. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default alert interval of 5 seconds. This alert interval overrides the WEF alert interval. The maximum alert interval is 600 seconds, and the minimum alert interval is 5 seconds.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookalertinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"13652df4eff9246a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Project (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},"130ad76113c3f096":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"135053741e819997":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters","displayName":"Ignore whitespace characters (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorewhitespacecharacters_1","displayName":"Enabled","description":null,"helpText":null}]},"134270cca73ebe91":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments","displayName":"Word 2003 and plain XML documents (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003andplainxmldocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"13ff3ab555f1b150":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/15.json b/public/intune-definitions/15.json index cedf4b612bc5..b2efb2e29818 100644 --- a/public/intune-definitions/15.json +++ b/public/intune-definitions/15.json @@ -1 +1 @@ -{"15932bd229919a97":{"id":"com.apple.managedclient.preferences_blocktruncatedcookies","displayName":"Block truncated cookies (Deprecated)","description":"This policy provides a temporary opt-out for changes to how Microsoft Edge handles cookies set via JavaScript that contain certain control characters (NULL, carriage return, and line feed).\nPreviously, the presence of any of these characters in a cookie string would cause it to be truncated but still set.\nNow, the presence of these characters will cause the whole cookie string to be ignored.\n\nIf you enable or don't configure this policy, the new behavior is enabled.\n\nIf you disable this policy, the old behavior is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blocktruncatedcookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blocktruncatedcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blocktruncatedcookies_true","displayName":"Enabled","description":null,"helpText":null}]},"150213d6604622d1":{"id":"com.apple.managedclient.preferences_extensioninstallsources","displayName":"Configure extension and user script install sources","description":"Define URLs that can install extensions and themes.\n\nBy default, users have to download a *.crx file for each extension or script they want to install, and then drag it onto the Microsoft Edge settings page. This policy lets specific URLs use install the extension or script for the user.\n\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns.\n\nThe \"ExtensionInstallBlocklist\" policy takes precedence over this policy. Any extensions that's on the block list won't be installed, even if it comes from a site on this list.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallsources"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"158708f209e91dc0":{"id":"com.apple.managedclient.preferences_showhistorythumbnails","displayName":"Show thumbnail images for browsing history","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past 7 days.\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showhistorythumbnails"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showhistorythumbnails_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showhistorythumbnails_true","displayName":"Enabled","description":null,"helpText":null}]},"153129147d1fd002":{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\n\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sslerroroverrideallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"15700837fac03525":{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet","displayName":"Hide the 'Get started with Outlook' control in the task pane","description":"Suppress the task pane control that advertises access to toolbar customization, notification preferences, theme, and adding secondary accounts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet_true","displayName":"True","description":null,"helpText":null}]},"15a43e42057a74c2":{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"15666dd1c08f639c":{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan","displayName":"Wake on LAN","description":"If true, enables \"Wake for network access.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan_1","displayName":"True","description":null,"helpText":null}]},"15b25d5b3be791bd":{"id":"com.apple.mcx.filevault2_com.apple.mcx.filevault2","displayName":"Top Level Setting Group Collection","description":"com.apple.MCX.FileVault2","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},"15ac19afaf78276b":{"id":"com.apple.softwareupdate_configdatainstall","displayName":"Config Data Install (Deprecated)","description":"If false, restricts the automatic installation of configuration data.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_configdatainstall_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_configdatainstall_true","displayName":"True","description":null,"helpText":null}]},"155d00f703c36a14":{"id":"com.apple.system.logging_system_enable-private-data","displayName":"Enable Private Data","description":"Setting this value to true enables private data logging for the entire system.","helpText":null,"infoUrls":[],"categoryId":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","categoryName":"System Logging","options":[{"id":"com.apple.system.logging_system_enable-private-data_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.system.logging_system_enable-private-data_true","displayName":"True","description":null,"helpText":null}]},"15009641f182613d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed","displayName":"Allow sites configured for Internet Explorer mode to open in Microsoft Edge","description":"This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list.\n\nUsers can configure this setting in the \"More tools\" menu by selecting 'Open sites in Microsoft Edge'.\n\nIf you enable this policy, the option to 'Open sites in Microsoft Edge' is visible under \"More tools\". Users use this option to test IE mode sites on a modern browser.\n\nIf you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the \"More tools\" menu. However, users can access this menu option with the --ie-mode-test flag.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"15eac552e359d2c0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site URL patterns that specify sites that are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\n\nFor detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com won't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set, otherwise Javascript JIT is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"15f97a2abb64910d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\n\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge doesn't send authentications requests to these services, and users need to manually sign-in.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1595616d21e6ae5c":{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop","displayName":"Use the following restricted mode:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_3","displayName":"Restrict Credential Delegation","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_2","displayName":"Require Remote Credential Guard","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_1","displayName":"Require Restricted Admin","description":null,"helpText":null}]},"15dfbf320d3bd095":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex","displayName":"List of applications to never report errors for","description":"This policy setting controls Windows Error Reporting behavior for errors in general applications when Windows Error Reporting is turned on.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are never included in error reports. To create a list of applications for which Windows Error Reporting never reports errors, click Show under the Exclude errors for applications on this list setting, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). File names must always include the .exe file name extension. Errors that are generated by applications in this list are not reported, even if the Default Application Reporting Settings policy setting is configured to report all application errors.\r\n\r\nIf this policy setting is enabled, the Exclude errors for applications on this list setting takes precedence. If an application is listed both in the List of applications to always report errors for policy setting, and in the exclusion list in this policy setting, the application is excluded from error reporting. You can also use the exclusion list in this policy setting to exclude specific Microsoft applications or parts of Windows if the check boxes for these categories are filled in the Default application reporting settings policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Default application reporting settings policy setting takes precedence.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornoneex"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_1","displayName":"Enabled","description":null,"helpText":null}]},"1518c761f1ec16ac":{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl","displayName":"Connect using SSL","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl_1","displayName":"True","description":null,"helpText":null}]},"15cda127e1c1ef06":{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_bluetoothprinters","displayName":"Number of Bluetooth printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"157c87f3aa198b41":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv","displayName":"Best effort service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_1","displayName":"Enabled","description":null,"helpText":null}]},"15ed4a6a9bd13e89":{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_transferrateop","displayName":"Connection speed (Kbps):","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},"1550558ad48b73d7":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_publishernamedetails","displayName":"Publisher","description":"The name of the application publisher","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},"15920ec84ad9e789":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies","displayName":"Enables experimental policies","description":"Allows Google Chrome to load experimental policies.\r\n\r\nWARNING: Experimental policies are unsupported and subject to change or be removed without notice in future version of the browser!\r\n\r\nAn experimental policy may not be finished or still have known or unknown defects. It may be changed or even removed without any notification. By enabling experimental policies, you could lose browser data or compromise your security or privacy.\r\n\r\nIf a policy is not in the list and it's not officially released, its value will be ignored on Beta and Stable channel.\r\n\r\nIf a policy is in the list and it's not officially released, its value will be applied.\r\n\r\nThis policy has no effect on already released policies.\r\n\r\nExample value:\r\n\r\nExtensionInstallAllowlist\r\nExtensionInstallBlocklist","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_1","displayName":"Enabled","description":null,"helpText":null}]},"1514d421a764d8a8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions","displayName":"Enable network prediction (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},"1588508a2e6b8eee":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_1","displayName":"Enabled","description":null,"helpText":null}]},"154024ed50ab53ad":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls_restoreonstartupurlsdesc","displayName":"URLs to open on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},"15d216fe4311a307":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"1508e11ebcfd5ca4":{"id":"device_vendor_msft_policy_config_connectivity_usecellularwhenwifipoor","displayName":"Use Cellular When Wi Fi Poor (Windows Insiders only)","description":"This policy allows the use of a cellular connection when Wi-Fi connectivity is limited.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Connectivity#usecellularwhenwifipoor"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"device_vendor_msft_policy_config_connectivity_usecellularwhenwifipoor_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_usecellularwhenwifipoor_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"156805513886c6ea":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcrefreshuserpolicy","displayName":"Refresh User Policy","description":"If a GPO is configured for an Office product that is included in the ODFC container, there may be a conflict with a previous user setting. Standard behavior is for the GPO to be applied, but when the ODFC container is read, the GPO will be over-written by the setting in the ODFC container. If the desire is for the GPO change to be universally applied, then enabling this setting should be done prior to the GPO update being applied. When this setting is enabled, the ODFC container will overwrite the previous user setting with the GPO setting.\r\n\r\nNOTE: There is a performance implication to enabling the RefreshUserPolicy. RefreshUserPolicy should only be enabled during a specific GPO and then should be set back to disabled.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\RefreshUserPolicy\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcrefreshuserpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcrefreshuserpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"15422f666f33193c":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"157f1bf9329febe0":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallownetframeworkreliantcomponents"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"15094c50190334f2":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\r\n\r\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"15399b49d31d2944":{"id":"device_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"15ae868bc4b13397":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting","displayName":"Idle detection (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_1","displayName":"Allow sites to detect idle state without asking the user","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_2","displayName":"Do not allow any site to detect the user's idle state","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_3","displayName":"Ask every time a site wants to detect the user's idle state","description":null,"helpText":null}]},"151e8667170efe91":{"id":"device_vendor_msft_policy_config_mixedreality_microphonedisabled","displayName":"Microphone Disabled","description":"This policy setting controls whether microphone on HoloLens 2 is disabled or not.","helpText":"","infoUrls":[],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_microphonedisabled_0","displayName":"Disabled","description":"Microphone can be used for voice.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_microphonedisabled_1","displayName":"Enabled","description":"Microphone cannot be used for voice.","helpText":null}]},"152b4304a2469461":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_spdesignexe149","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_spdesignexe149_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_spdesignexe149_1","displayName":"True","description":null,"helpText":null}]},"1526bbc56df8c76b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_powerpntexe73","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_powerpntexe73_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_powerpntexe73_1","displayName":"True","description":null,"helpText":null}]},"159b98e191f21b35":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_customsyncrootfoldername","displayName":"Set a custom name for the OneDrive folder","description":"This setting lets you customize the local OneDrive sync root folder name on users' computers. By default, the folder name is \"OneDrive - {organization name}.\" Shortening this name increases the available path length for nested folders and files. \nIf you enable this setting and provide a custom folder name, OneDrive will use that name when creating the sync root folder for new users. Users who are already syncing will need to unlink and relink their account for the change to take effect. To learn more, see https://learn.microsoft.com/en-us/sharepoint/use-group-policy. \n\nIf you disable this setting, the folder name will revert to \"OneDrive - {organization name}\". Users who were using a custom folder name will need to unlink and relink their account for the change to take effect. \n\nIf you do not configure this setting, the default folder name will be used. \n\nImportant:\n\nYou must provide at least one character for the custom folder name. \n\nThe custom folder name cannot be \"OneDrive\". \n\nThe full OneDrive sync root folder path (for example, C:\\Users\\{alias}\\OneDrive - {organization name}) cannot exceed 120 characters. \n\nCustom folder names cannot contain characters that are invalid for Windows folders. For a list of unsupported characters, see https://support.microsoft.com/office/restrictions-and-limitations-in-onedrive-and-sharepoint-64883a5d-228e-48f5-b3d2-eb39e07630fa#invalidcharacters. \n","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_customsyncrootfoldername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_customsyncrootfoldername_1","displayName":"Enabled","description":null,"helpText":null}]},"15daf7fe5f9f6b5e":{"id":"device_vendor_msft_policy_config_start_hidehibernate","displayName":"Hide Hibernate","description":"Enabling this policy hides \"Hibernate\" from appearing in the power button in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidehibernate"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hidehibernate_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hidehibernate_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"15759596afea8563":{"id":"device_vendor_msft_policy_config_userrights_increaseschedulingpriority","displayName":"Increase Scheduling Priority","description":"This user right determines which accounts can use a process with Write Property access to another process to increase the execution priority assigned to the other process. A user with this privilege can change the scheduling priority of a process through the Task Manager user interface.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#increaseschedulingpriority"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"15f2f6771538faf4":{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_email","displayName":"Email","description":"The email address that is displayed to users.  The default mail application is used to initiate email actions. If you disable or do not configure this setting, or do not have EnableCustomizedToasts or EnableInAppCustomization enabled, then devices will not display contact options. Value type is string. Supported operations are Add, Get, Replace and Delete.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsDefenderSecurityCenter#email"],"categoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","categoryName":"Windows Defender Security Center","options":null},"15d67572df10f2f3":{"id":"mathsettings_calculator_scientificmode","displayName":"Scientific Mode","description":"If present, configures the scientific mode of the calculator. If not present, scientific mode is enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":null},"150a30465f2194c5":{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_agentuser_userprofile","displayName":"Identity profile","description":"The Entra user profile (UPN or SID) to run the agent as.","helpText":"","infoUrls":[],"categoryId":"ea5fabb0-6eec-4c3e-8c6d-7523739207c3","categoryName":null,"options":null},"15aebaac194a7031":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_weboptions~l_general_l_underlinehyperlinks","displayName":"Underline hyperlinks (User)","description":"This policy setting controls whether hyperlinks in Access tables, queries, forms, and reports are underlined. \r\n \r\nIf you enable this policy setting, Access underlines all hyperlinks in tables, queries, forms, and reports when they are created, overriding any configuration changes on the users' computers. \r\n \r\nIf you disable this policy setting, Access does not underline hyperlinks in tables, queries, forms and reports. \r\n \r\nIf you do not configure this policy setting, Access underlines hyperlinks that appear in tables, queries, forms, and reports. \r\n \r\nEnabling this policy setting enforces the default configuration in Access, and is therefore unlikely to cause a significant usability issue for most users. If this configuration is changed, users might click on dangerous hyperlinks without realizing it, which could pose a security risk.","helpText":"","infoUrls":[],"categoryId":"cbb98485-6a36-47b8-b450-7821e08507ac","categoryName":"Web Options - General","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_weboptions~l_general_l_underlinehyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_weboptions~l_general_l_underlinehyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},"159d96582f2b6232":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_maps","displayName":"Maps (User)","description":"This policy setting configures the synchronization of user settings for the Maps app.\r\nBy default, the user settings of Maps sync between computers. Use the policy setting to prevent the user settings of Maps from synchronizing between computers.\r\nIf you enable this policy setting, Maps user settings continue to sync.\r\nIf you disable this policy setting, Maps user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-maps"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_maps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_maps_1","displayName":"Enabled","description":null,"helpText":null}]},"1587f5fc0b66ff29":{"id":"user_vendor_msft_policy_config_attachmentmanager_notifyantivirusprograms","displayName":"Notify antivirus programs when opening attachments (User)","description":"This policy setting allows you to manage the behavior for notifying registered antivirus programs. If multiple programs are registered, they will all be notified. If the registered antivirus program already performs on-access checks or scans files as they arrive on the computer's email server, additional calls would be redundant. \n\nIf you enable this policy setting, Windows tells the registered antivirus program to scan the file when a user opens a file attachment. If the antivirus program fails, the attachment is blocked from being opened.\n\nIf you disable this policy setting, Windows does not call the registered antivirus programs when file attachments are opened.\n\nIf you do not configure this policy setting, Windows does not call the registered antivirus programs when file attachments are opened.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-attachmentmanager#attachmentmanager-notifyantivirusprograms"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_attachmentmanager_notifyantivirusprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_attachmentmanager_notifyantivirusprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"156eaa818ba3a457":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_diskcachedir","displayName":"Set disk cache directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"15dcd1e414ce3312":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Controls the mode of DNS-over-HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"15d09f6da37509e6":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled","displayName":"Allow users to customize the background on the New Tab page (User)","description":"If the policy is set to false, the New Tab page won't allow users to customize the background. Any existing custom background will be permanently removed even if the policy is set to true later.\r\n\r\nIf the policy is set to true or unset, users can customize the background on the New Tab page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1504b5e363e96917":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"15250f7c6859dc86":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block popups on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"15c8c4aa2f782b2f":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Safe Browsing warnings.\r\n\r\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent file type extension-based download warnings on \"exe\" and \"jnlp\" extensions for *.example.com domains, and on \"swf\" extensions for all domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\r\n\r\n[\r\n{ \"file_extension\": \"jnlp\", \"domains\": [\"example.com\"] },\r\n{ \"file_extension\": \"exe\", \"domains\": [\"example.com\"] },\r\n{ \"file_extension\": \"swf\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nIf this policy is enabled alongside DownloadRestrictions, then the exemptions to file type extension-based warnings specified by this policy take precedence over a DownloadRestrictions setting that would block dangerous file types. The exemptions specified by this policy only apply to the \"block dangerous file types\" behavior specified by values 1 and 2 of DownloadRestrictions.\r\n\r\nFor example, if this policy specifies an exemption for \"exe\" downloads from \"website1.com\", and DownloadRestrictions is set to block malicious downloads and dangerous file types (value 1), then \"exe\" downloads from \"website1.com\" will be exempt from file type extension-based blocking but will still be blocked if they are malicious.\r\n\r\nMore information about DownloadRestrictions can be found at https://chromeenterprise.google/policies/?policy=DownloadRestrictions.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ExemptDomainFileTypePairsFromFileTypeDownloadWarnings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"domains\": [\r\n \"https://example.com\",\r\n \"example2.com\"\r\n ],\r\n \"file_extension\": \"jnlp\"\r\n },\r\n {\r\n \"domains\": [\r\n \"*\"\r\n ],\r\n \"file_extension\": \"swf\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},"15173b11f52f48b5":{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete","displayName":"Turn on the auto-complete feature for user names and passwords on forms (User)","description":"This AutoComplete feature can remember and suggest User names and passwords on Forms.\n\nIf you enable this setting, the user cannot change \"User name and passwords on forms\" or \"prompt me to save passwords\". The Auto Complete feature for User names and passwords on Forms will be turned on. You have to decide whether to select \"prompt me to save passwords\".\n\nIf you disable this setting the user cannot change \"User name and passwords on forms\" or \"prompt me to save passwords\". The Auto Complete feature for User names and passwords on Forms is turned off. The user also cannot opt to be prompted to save passwords.\n\nIf you do not configure this setting, the user has the freedom of turning on Auto complete for User name and passwords on forms and the option of prompting to save passwords. To display this option, the users open the Internet Options dialog box, click the Contents Tab and click the Settings button.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowautocomplete"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_1","displayName":"Enabled","description":null,"helpText":null}]},"1555f270e31ac1a9":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"1580967d5360ab2e":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1","displayName":"Additional server versions supported (User)","description":"\r\nSpecify a semicolon separated list of server version names, e.g. RTC/2.9;RTC/3.0;RTC/4.0, to which Microsoft Lync allows logon in addition to the server versions that are supported by default. Space character is treated as part of the version string.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_1","displayName":"Enabled","description":null,"helpText":null}]},"15a108bc68cdd60d":{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload","displayName":"Wait for Internet Explorer mode tabs to completely unload before ending the browser session (User)","description":"This policy causes Microsoft Edge to continue running until all Internet Explorer tabs have completely finished unloading. This allows Internet Explorer plugins like ActiveX controls to perform additional critical work even after the browser has been closed. However, this can cause stability and performance issues, and Microsoft Edge processes may remain active in the background with no visible windows if the webpage or plugin prevents Internet Explorer from unloading. This policy should only be used if your organization depends on a plugin that requires this behavior.\r\n\r\nIf you enable this policy, Microsoft Edge will always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload_1","displayName":"Enabled","description":null,"helpText":null}]},"15c4862aad28c475":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls","displayName":"Allow sites to make network requests to the local device. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions when accessing loopback addresses (127.0.0.1, ::1, localhost).\r\n\r\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are allowed and are not subject to Local Network Access restrictions.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\r\n\r\nIf this policy is disabled or not configured, no additional exemptions are granted beyond the user's existing configuration.\r\n\r\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nFor guidance on valid URL pattern syntax, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns .\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"158a77cd38e6b21a":{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist_smartactionsblocklistdesc","displayName":"Block smart actions for a list of services (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"154bc4042607c90f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceservercapabilities3","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"15529980ddbd7a23":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink_l_withawebdiscussionslink367","displayName":"With a Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},"15f19c2d6cc9e7ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject_1","displayName":"True","description":null,"helpText":null}]},"15949a4a5575d180":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador","displayName":"Quechua (Ecuador) (User)","description":"Enables the editing language Quechua (Ecuador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador_1","displayName":"Enabled","description":null,"helpText":null}]},"15346e489639dbb3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowcachename478","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"154b94f99651f8e3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257_1","displayName":"True","description":null,"helpText":null}]},"15f92464671415ac":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_descriptioncolon256","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"157ce3a7c57fcdb2":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_l_ageoutpolicyincludingfilespendinguploaddecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"1526990ca234a9aa":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"154c094e85d73e47":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7_1","displayName":"True","description":null,"helpText":null}]},"15ee4cc0b8ff9d50":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_1","displayName":"Low (enabled)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_2","displayName":"By UI (prompted)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_3","displayName":"High (disabled)","description":null,"helpText":null}]},"15554bea866f64f7":{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection","displayName":"Restrict clipboard transfer from client to server (User)","description":"This policy setting allows you to restrict clipboard data transfers from client to server.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from client to server.\r\n\r\n- Allow plain text copying from client to server.\r\n\r\n- Allow plain text and images copying from client to server.\r\n\r\n- Allow plain text, images and Rich Text Format copying from client to server.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from client to server.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from client to server if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitclienttoserverclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},"1571052c772923ac":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess","displayName":"Stop checking to ensure documents allow programmatic access (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that documents have not blocked programmatic access through DRM.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that documents have not blocked programmatic access through DRM.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for programmatic access and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"15a6acd697989dfc":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},"151decc104a13efc":{"id":"vendor_msft_controlledconfiguration_blob","displayName":"Controlled Configuration Blob","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null}} \ No newline at end of file +{"15932bd229919a97":{"id":"com.apple.managedclient.preferences_blocktruncatedcookies","displayName":"Block truncated cookies (Deprecated)","description":"This policy provides a temporary opt-out for changes to how Microsoft Edge handles cookies set via JavaScript that contain certain control characters (NULL, carriage return, and line feed).\nPreviously, the presence of any of these characters in a cookie string would cause it to be truncated but still set.\nNow, the presence of these characters will cause the whole cookie string to be ignored.\n\nIf you enable or don't configure this policy, the new behavior is enabled.\n\nIf you disable this policy, the old behavior is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blocktruncatedcookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blocktruncatedcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blocktruncatedcookies_true","displayName":"Enabled","description":null,"helpText":null}]},"150213d6604622d1":{"id":"com.apple.managedclient.preferences_extensioninstallsources","displayName":"Configure extension and user script install sources","description":"Define URLs that can install extensions and themes.\n\nBy default, users have to download a *.crx file for each extension or script they want to install, and then drag it onto the Microsoft Edge settings page. This policy lets specific URLs use install the extension or script for the user.\n\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns.\n\nThe \"ExtensionInstallBlocklist\" policy takes precedence over this policy. Any extensions that's on the block list won't be installed, even if it comes from a site on this list.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallsources"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"158708f209e91dc0":{"id":"com.apple.managedclient.preferences_showhistorythumbnails","displayName":"Show thumbnail images for browsing history","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past 7 days.\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showhistorythumbnails"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showhistorythumbnails_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showhistorythumbnails_true","displayName":"Enabled","description":null,"helpText":null}]},"153129147d1fd002":{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\n\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sslerroroverrideallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sslerroroverrideallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"15700837fac03525":{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet","displayName":"Hide the 'Get started with Outlook' control in the task pane","description":"Suppress the task pane control that advertises access to toolbar customization, notification preferences, theme, and adding secondary accounts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_userpreference_maxchecklistdisplaydurationmet_true","displayName":"True","description":null,"helpText":null}]},"15a43e42057a74c2":{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"15666dd1c08f639c":{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan","displayName":"Wake on LAN","description":"If true, enables \"Wake for network access.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_wake on lan_1","displayName":"True","description":null,"helpText":null}]},"15b25d5b3be791bd":{"id":"com.apple.mcx.filevault2_com.apple.mcx.filevault2","displayName":"Top Level Setting Group Collection","description":"com.apple.MCX.FileVault2","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},"15ac19afaf78276b":{"id":"com.apple.softwareupdate_configdatainstall","displayName":"Config Data Install (Deprecated)","description":"If false, restricts the automatic installation of configuration data.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_configdatainstall_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_configdatainstall_true","displayName":"True","description":null,"helpText":null}]},"155d00f703c36a14":{"id":"com.apple.system.logging_system_enable-private-data","displayName":"Enable Private Data","description":"Setting this value to true enables private data logging for the entire system.","helpText":null,"infoUrls":[],"categoryId":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","categoryName":"System Logging","options":[{"id":"com.apple.system.logging_system_enable-private-data_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.system.logging_system_enable-private-data_true","displayName":"True","description":null,"helpText":null}]},"15009641f182613d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed","displayName":"Allow sites configured for Internet Explorer mode to open in Microsoft Edge","description":"This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list.\n\nUsers can configure this setting in the \"More tools\" menu by selecting 'Open sites in Microsoft Edge'.\n\nIf you enable this policy, the option to 'Open sites in Microsoft Edge' is visible under \"More tools\". Users use this option to test IE mode sites on a modern browser.\n\nIf you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the \"More tools\" menu. However, users can access this menu option with the --ie-mode-test flag.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetabinedgemodeallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"15eac552e359d2c0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site URL patterns that specify sites that are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\n\nFor detailed information on valid site URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com won't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptJitSetting\", if set, or default to JavaScript JIT enabled.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptJitSetting\" applies to the site, if set, otherwise Javascript JIT is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"15f97a2abb64910d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\n\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge doesn't send authentications requests to these services, and users need to manually sign-in.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proactiveauthworkflowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1595616d21e6ae5c":{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop","displayName":"Use the following restricted mode:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_3","displayName":"Restrict Credential Delegation","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_2","displayName":"Require Remote Credential Guard","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_restrictedremoteadministrationdrop_1","displayName":"Require Restricted Admin","description":null,"helpText":null}]},"15dfbf320d3bd095":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex","displayName":"List of applications to never report errors for","description":"This policy setting controls Windows Error Reporting behavior for errors in general applications when Windows Error Reporting is turned on.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are never included in error reports. To create a list of applications for which Windows Error Reporting never reports errors, click Show under the Exclude errors for applications on this list setting, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). File names must always include the .exe file name extension. Errors that are generated by applications in this list are not reported, even if the Default Application Reporting Settings policy setting is configured to report all application errors.\r\n\r\nIf this policy setting is enabled, the Exclude errors for applications on this list setting takes precedence. If an application is listed both in the List of applications to always report errors for policy setting, and in the exclusion list in this policy setting, the application is excluded from error reporting. You can also use the exclusion list in this policy setting to exclude specific Microsoft applications or parts of Windows if the check boxes for these categories are filled in the Default application reporting settings policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Default application reporting settings policy setting takes precedence.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornoneex"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneex_1","displayName":"Enabled","description":null,"helpText":null}]},"1518c761f1ec16ac":{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl","displayName":"Connect using SSL","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerusessl_1","displayName":"True","description":null,"helpText":null}]},"15cda127e1c1ef06":{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_bluetoothprinters","displayName":"Number of Bluetooth printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"157c87f3aa198b41":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv","displayName":"Best effort service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_1","displayName":"Enabled","description":null,"helpText":null}]},"15ed4a6a9bd13e89":{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_transferrateop","displayName":"Connection speed (Kbps):","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},"1550558ad48b73d7":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisherdetails_publishernamedetails","displayName":"Publisher","description":"The name of the application publisher","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},"15920ec84ad9e789":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies","displayName":"Enables experimental policies","description":"Allows Google Chrome to load experimental policies.\r\n\r\nWARNING: Experimental policies are unsupported and subject to change or be removed without notice in future version of the browser!\r\n\r\nAn experimental policy may not be finished or still have known or unknown defects. It may be changed or even removed without any notification. By enabling experimental policies, you could lose browser data or compromise your security or privacy.\r\n\r\nIf a policy is not in the list and it's not officially released, its value will be ignored on Beta and Stable channel.\r\n\r\nIf a policy is in the list and it's not officially released, its value will be applied.\r\n\r\nThis policy has no effect on already released policies.\r\n\r\nExample value:\r\n\r\nExtensionInstallAllowlist\r\nExtensionInstallBlocklist","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_1","displayName":"Enabled","description":null,"helpText":null}]},"1514d421a764d8a8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions","displayName":"Enable network prediction (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},"1588508a2e6b8eee":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_1","displayName":"Enabled","description":null,"helpText":null}]},"154024ed50ab53ad":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartupurls_restoreonstartupurlsdesc","displayName":"URLs to open on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},"15d216fe4311a307":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"1508e11ebcfd5ca4":{"id":"device_vendor_msft_policy_config_connectivity_usecellularwhenwifipoor","displayName":"Use Cellular When Wi Fi Poor (Windows Insiders only)","description":"This policy allows the use of a cellular connection when Wi-Fi connectivity is limited.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Connectivity#usecellularwhenwifipoor"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"device_vendor_msft_policy_config_connectivity_usecellularwhenwifipoor_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_usecellularwhenwifipoor_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"156805513886c6ea":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcrefreshuserpolicy","displayName":"Refresh User Policy","description":"If a GPO is configured for an Office product that is included in the ODFC container, there may be a conflict with a previous user setting. Standard behavior is for the GPO to be applied, but when the ODFC container is read, the GPO will be over-written by the setting in the ODFC container. If the desire is for the GPO change to be universally applied, then enabling this setting should be done prior to the GPO update being applied. When this setting is enabled, the ODFC container will overwrite the previous user setting with the GPO setting.\r\n\r\nNOTE: There is a performance implication to enabling the RefreshUserPolicy. RefreshUserPolicy should only be enabled during a specific GPO and then should be set back to disabled.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\RefreshUserPolicy\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcrefreshuserpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcrefreshuserpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"15422f666f33193c":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"157f1bf9329febe0":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallownetframeworkreliantcomponents"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"15094c50190334f2":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\r\n\r\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"15399b49d31d2944":{"id":"device_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"15ae868bc4b13397":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting","displayName":"Idle detection (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_1","displayName":"Allow sites to detect idle state without asking the user","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_2","displayName":"Do not allow any site to detect the user's idle state","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_defaultidledetectionsetting_defaultidledetectionsetting_3","displayName":"Ask every time a site wants to detect the user's idle state","description":null,"helpText":null}]},"151e8667170efe91":{"id":"device_vendor_msft_policy_config_mixedreality_microphonedisabled","displayName":"Microphone Disabled","description":"This policy setting controls whether microphone on HoloLens 2 is disabled or not.","helpText":"","infoUrls":[],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_microphonedisabled_0","displayName":"Disabled","description":"Microphone can be used for voice.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_microphonedisabled_1","displayName":"Enabled","description":"Microphone cannot be used for voice.","helpText":null}]},"152b4304a2469461":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_spdesignexe149","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_spdesignexe149_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_spdesignexe149_1","displayName":"True","description":null,"helpText":null}]},"1526bbc56df8c76b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_powerpntexe73","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_powerpntexe73_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_powerpntexe73_1","displayName":"True","description":null,"helpText":null}]},"159b98e191f21b35":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_customsyncrootfoldername","displayName":"Set a custom name for the OneDrive folder","description":"This setting lets you customize the local OneDrive sync root folder name on users' computers. By default, the folder name is \"OneDrive - {organization name}.\" Shortening this name increases the available path length for nested folders and files. \nIf you enable this setting and provide a custom folder name, OneDrive will use that name when creating the sync root folder for new users. Users who are already syncing will need to unlink and relink their account for the change to take effect. To learn more, see https://learn.microsoft.com/en-us/sharepoint/use-group-policy. \n\nIf you disable this setting, the folder name will revert to \"OneDrive - {organization name}\". Users who were using a custom folder name will need to unlink and relink their account for the change to take effect. \n\nIf you do not configure this setting, the default folder name will be used. \n\nImportant:\n\nYou must provide at least one character for the custom folder name. \n\nThe custom folder name cannot be \"OneDrive\". \n\nThe full OneDrive sync root folder path (for example, C:\\Users\\{alias}\\OneDrive - {organization name}) cannot exceed 120 characters. \n\nCustom folder names cannot contain characters that are invalid for Windows folders. For a list of unsupported characters, see https://support.microsoft.com/office/restrictions-and-limitations-in-onedrive-and-sharepoint-64883a5d-228e-48f5-b3d2-eb39e07630fa#invalidcharacters. \n","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_customsyncrootfoldername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_customsyncrootfoldername_1","displayName":"Enabled","description":null,"helpText":null}]},"15daf7fe5f9f6b5e":{"id":"device_vendor_msft_policy_config_start_hidehibernate","displayName":"Hide Hibernate","description":"Enabling this policy hides \"Hibernate\" from appearing in the power button in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidehibernate"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hidehibernate_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hidehibernate_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"15b64ab221c20a65":{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlymonthbaseddayofmonth","displayName":"Maintenance Window Monthly Month Based Day Of Month","description":"If the maintenance window repeat schedule is set to monthly, and set to repeat on the same date each month, configure the day of the month to repeat maintenance window occurrence (for example, 2 = repeat on the 2nd day of the month). Maximum value is 28.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowmonthlymonthbaseddayofmonth"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"15759596afea8563":{"id":"device_vendor_msft_policy_config_userrights_increaseschedulingpriority","displayName":"Increase Scheduling Priority","description":"This user right determines which accounts can use a process with Write Property access to another process to increase the execution priority assigned to the other process. A user with this privilege can change the scheduling priority of a process through the Task Manager user interface.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#increaseschedulingpriority"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"15f2f6771538faf4":{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_email","displayName":"Email","description":"The email address that is displayed to users.  The default mail application is used to initiate email actions. If you disable or do not configure this setting, or do not have EnableCustomizedToasts or EnableInAppCustomization enabled, then devices will not display contact options. Value type is string. Supported operations are Add, Get, Replace and Delete.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsDefenderSecurityCenter#email"],"categoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","categoryName":"Windows Defender Security Center","options":null},"15d67572df10f2f3":{"id":"mathsettings_calculator_scientificmode","displayName":"Scientific Mode","description":"If present, configures the scientific mode of the calculator. If not present, scientific mode is enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":null},"150a30465f2194c5":{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_agentuser_userprofile","displayName":"Identity profile","description":"The Entra user profile (UPN or SID) to run the agent as.","helpText":"","infoUrls":[],"categoryId":"ea5fabb0-6eec-4c3e-8c6d-7523739207c3","categoryName":null,"options":null},"15aebaac194a7031":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_weboptions~l_general_l_underlinehyperlinks","displayName":"Underline hyperlinks (User)","description":"This policy setting controls whether hyperlinks in Access tables, queries, forms, and reports are underlined. \r\n \r\nIf you enable this policy setting, Access underlines all hyperlinks in tables, queries, forms, and reports when they are created, overriding any configuration changes on the users' computers. \r\n \r\nIf you disable this policy setting, Access does not underline hyperlinks in tables, queries, forms and reports. \r\n \r\nIf you do not configure this policy setting, Access underlines hyperlinks that appear in tables, queries, forms, and reports. \r\n \r\nEnabling this policy setting enforces the default configuration in Access, and is therefore unlikely to cause a significant usability issue for most users. If this configuration is changed, users might click on dangerous hyperlinks without realizing it, which could pose a security risk.","helpText":"","infoUrls":[],"categoryId":"cbb98485-6a36-47b8-b450-7821e08507ac","categoryName":"Web Options - General","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_weboptions~l_general_l_underlinehyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_weboptions~l_general_l_underlinehyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},"159d96582f2b6232":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_maps","displayName":"Maps (User)","description":"This policy setting configures the synchronization of user settings for the Maps app.\r\nBy default, the user settings of Maps sync between computers. Use the policy setting to prevent the user settings of Maps from synchronizing between computers.\r\nIf you enable this policy setting, Maps user settings continue to sync.\r\nIf you disable this policy setting, Maps user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-maps"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_maps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_maps_1","displayName":"Enabled","description":null,"helpText":null}]},"1587f5fc0b66ff29":{"id":"user_vendor_msft_policy_config_attachmentmanager_notifyantivirusprograms","displayName":"Notify antivirus programs when opening attachments (User)","description":"This policy setting allows you to manage the behavior for notifying registered antivirus programs. If multiple programs are registered, they will all be notified. If the registered antivirus program already performs on-access checks or scans files as they arrive on the computer's email server, additional calls would be redundant. \n\nIf you enable this policy setting, Windows tells the registered antivirus program to scan the file when a user opens a file attachment. If the antivirus program fails, the attachment is blocked from being opened.\n\nIf you disable this policy setting, Windows does not call the registered antivirus programs when file attachments are opened.\n\nIf you do not configure this policy setting, Windows does not call the registered antivirus programs when file attachments are opened.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-attachmentmanager#attachmentmanager-notifyantivirusprograms"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_attachmentmanager_notifyantivirusprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_attachmentmanager_notifyantivirusprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"156eaa818ba3a457":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_diskcachedir","displayName":"Set disk cache directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"15dcd1e414ce3312":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Controls the mode of DNS-over-HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"15d09f6da37509e6":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled","displayName":"Allow users to customize the background on the New Tab page (User)","description":"If the policy is set to false, the New Tab page won't allow users to customize the background. Any existing custom background will be permanently removed even if the policy is set to true later.\r\n\r\nIf the policy is set to true or unset, users can customize the background on the New Tab page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1504b5e363e96917":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"15250f7c6859dc86":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block popups on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"15c8c4aa2f782b2f":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\r\n\r\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Safe Browsing warnings.\r\n\r\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\r\n\r\nIf you enable this policy:\r\n\r\n* The URL pattern should be formatted according to https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\r\n\r\nExample:\r\n\r\nThe following example value would prevent file type extension-based download warnings on \"exe\" and \"jnlp\" extensions for *.example.com domains, and on \"swf\" extensions for all domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\r\n\r\n[\r\n{ \"file_extension\": \"jnlp\", \"domains\": [\"example.com\"] },\r\n{ \"file_extension\": \"exe\", \"domains\": [\"example.com\"] },\r\n{ \"file_extension\": \"swf\", \"domains\": [\"*\"] }\r\n]\r\n\r\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.\r\n\r\nIf this policy is enabled alongside DownloadRestrictions, then the exemptions to file type extension-based warnings specified by this policy take precedence over a DownloadRestrictions setting that would block dangerous file types. The exemptions specified by this policy only apply to the \"block dangerous file types\" behavior specified by values 1 and 2 of DownloadRestrictions.\r\n\r\nFor example, if this policy specifies an exemption for \"exe\" downloads from \"website1.com\", and DownloadRestrictions is set to block malicious downloads and dangerous file types (value 1), then \"exe\" downloads from \"website1.com\" will be exempt from file type extension-based blocking but will still be blocked if they are malicious.\r\n\r\nMore information about DownloadRestrictions can be found at https://chromeenterprise.google/policies/?policy=DownloadRestrictions.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ExemptDomainFileTypePairsFromFileTypeDownloadWarnings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"domains\": [\r\n \"https://example.com\",\r\n \"example2.com\"\r\n ],\r\n \"file_extension\": \"jnlp\"\r\n },\r\n {\r\n \"domains\": [\r\n \"*\"\r\n ],\r\n \"file_extension\": \"swf\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_exemptdomainfiletypepairsfromfiletypedownloadwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},"15173b11f52f48b5":{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete","displayName":"Turn on the auto-complete feature for user names and passwords on forms (User)","description":"This AutoComplete feature can remember and suggest User names and passwords on Forms.\n\nIf you enable this setting, the user cannot change \"User name and passwords on forms\" or \"prompt me to save passwords\". The Auto Complete feature for User names and passwords on Forms will be turned on. You have to decide whether to select \"prompt me to save passwords\".\n\nIf you disable this setting the user cannot change \"User name and passwords on forms\" or \"prompt me to save passwords\". The Auto Complete feature for User names and passwords on Forms is turned off. The user also cannot opt to be prompted to save passwords.\n\nIf you do not configure this setting, the user has the freedom of turning on Auto complete for User name and passwords on forms and the option of prompting to save passwords. To display this option, the users open the Internet Options dialog box, click the Contents Tab and click the Settings button.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowautocomplete"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowautocomplete_1","displayName":"Enabled","description":null,"helpText":null}]},"1555f270e31ac1a9":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"1580967d5360ab2e":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1","displayName":"Additional server versions supported (User)","description":"\r\nSpecify a semicolon separated list of server version names, e.g. RTC/2.9;RTC/3.0;RTC/4.0, to which Microsoft Lync allows logon in addition to the server versions that are supported by default. Space character is treated as part of the version string.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1_1","displayName":"Enabled","description":null,"helpText":null}]},"15a108bc68cdd60d":{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload","displayName":"Wait for Internet Explorer mode tabs to completely unload before ending the browser session (User)","description":"This policy causes Microsoft Edge to continue running until all Internet Explorer tabs have completely finished unloading. This allows Internet Explorer plugins like ActiveX controls to perform additional critical work even after the browser has been closed. However, this can cause stability and performance issues, and Microsoft Edge processes may remain active in the background with no visible windows if the webpage or plugin prevents Internet Explorer from unloading. This policy should only be used if your organization depends on a plugin that requires this behavior.\r\n\r\nIf you enable this policy, Microsoft Edge will always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not always wait for Internet Explorer mode tabs to fully unload before ending the browser session.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2174004","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_internetexplorerintegrationalwayswaitforunload_1","displayName":"Enabled","description":null,"helpText":null}]},"15c4862aad28c475":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls","displayName":"Allow sites to make network requests to the local device. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions when accessing loopback addresses (127.0.0.1, ::1, localhost).\r\n\r\nIf a requesting origin matches a URL pattern specified in this policy, requests to loopback addresses are allowed and are not subject to Local Network Access restrictions.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions apply.\r\n\r\nIf this policy is disabled or not configured, no additional exemptions are granted beyond the user's existing configuration.\r\n\r\nMultiple policies can specify origins that affect requests to the local device. If an origin matches more than one of the following policies, they are applied in the following order of precedence:\r\n- LoopbackNetworkBlockedForUrls\r\n- LoopbackNetworkAllowedForUrls\r\n- LocalNetworkAccessBlockedForUrls\r\n- LocalNetworkAccessAllowedForUrls\r\n\r\nFor guidance on valid URL pattern syntax, see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns .\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"158a77cd38e6b21a":{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_smartactionsblocklist_smartactionsblocklistdesc","displayName":"Block smart actions for a list of services (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"154bc4042607c90f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceservercapabilities3","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"15529980ddbd7a23":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withawebdiscussionslink_l_withawebdiscussionslink367","displayName":"With a Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},"15f19c2d6cc9e7ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyproject_1","displayName":"True","description":null,"helpText":null}]},"15949a4a5575d180":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador","displayName":"Quechua (Ecuador) (User)","description":"Enables the editing language Quechua (Ecuador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_quechuaecuador_1","displayName":"Enabled","description":null,"helpText":null}]},"15346e489639dbb3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowcachename478","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"154b94f99651f8e3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_allowsubfolders257_1","displayName":"True","description":null,"helpText":null}]},"15f92464671415ac":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_descriptioncolon256","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"157ce3a7c57fcdb2":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_l_ageoutpolicyincludingfilespendinguploaddecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"1526990ca234a9aa":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"154c094e85d73e47":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders7_1","displayName":"True","description":null,"helpText":null}]},"15ee4cc0b8ff9d50":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_1","displayName":"Low (enabled)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_2","displayName":"By UI (prompted)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_l_empty_3","displayName":"High (disabled)","description":null,"helpText":null}]},"15554bea866f64f7":{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection","displayName":"Restrict clipboard transfer from client to server (User)","description":"This policy setting allows you to restrict clipboard data transfers from client to server.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from client to server.\r\n\r\n- Allow plain text copying from client to server.\r\n\r\n- Allow plain text and images copying from client to server.\r\n\r\n- Allow plain text, images and Rich Text Format copying from client to server.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from client to server.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from client to server if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitclienttoserverclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},"1571052c772923ac":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess","displayName":"Stop checking to ensure documents allow programmatic access (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that documents have not blocked programmatic access through DRM.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that documents have not blocked programmatic access through DRM.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for programmatic access and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingdocumentsallowprogrammaticaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"15a6acd697989dfc":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},"151decc104a13efc":{"id":"vendor_msft_controlledconfiguration_blob","displayName":"Controlled Configuration Blob","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/defender-csp#:~:text=Configuration/TamperProtection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/17.json b/public/intune-definitions/17.json index ce01deaf085f..48af4c4cc1fa 100644 --- a/public/intune-definitions/17.json +++ b/public/intune-definitions/17.json @@ -1 +1 @@ -{"17f6685b8144970b":{"id":"com.apple.assetcache.managed_listenwithpeersandparents","displayName":"Listen With Peers And Parents","description":"If true, the content cache provides content to the clients in the union of the Listen Ranges, Peer Listen Ranges and Parents.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_listenwithpeersandparents_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_listenwithpeersandparents_true","displayName":"True","description":null,"helpText":null}]},"17eddcd97deb9595":{"id":"com.apple.dock_com.apple.dock","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},"17a768a805012967":{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos","displayName":"Start In Smart Card Mode","description":"If set to true, the user interface will start in SmartCard mode. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},"17b24de807ef0be1":{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer","description":"Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF).\nThis will be the new PDF viewer architecture going forward, as it is simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated.\n\nWhen this policy is set to Enabled or not set, Microsoft Edge will use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Microsoft Edge.\n\nWhen this policy is set to Disabled, Microsoft Edge will strictly use the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page.\n\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pdfvieweroutofprocessiframeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"17f3da0eebf6cd2d":{"id":"com.apple.managedclient.preferences_webcaptureenabled","displayName":"Enable web capture feature in Microsoft Edge","description":"Enables the web capture feature in Microsoft Edge that allows users to capture web content and annotate the capture using inking tools.\nIf you enable this policy or don't configure it, the Web capture option shows up in the context menu, Settings and more menu, and by using the keyboard shortcut, CTRL+SHIFT+S.\nIf you disable this policy, users can't access the web capture feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webcaptureenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webcaptureenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webcaptureenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1777e5640b3f6bc2":{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement","description":"This policy enables Data URL support for SVGUseElement, which is disabled\nby default starting in Microsoft Edge version 119.\nIf this policy is enabled, Data URLs keep working in SVGUseElement.\nIf this policy is disabled or not configured, Data URLs can't work in SVGUseElement.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"17f27bd6c5532384":{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailabilityblocklist","displayName":"List of URL patterns for which developer tools are blocked","description":"This policy specifies URL patterns where developer tools are blocked. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nURL patterns are evaluated against the URL of every frame on the page being inspected. If any frame matches a pattern in this policy, developer tools are blocked for the entire page.\n\nIf you configure this policy and do not configure the \"DeveloperToolsAvailabilityAllowlist\" policy, developer tools are blocked when any frame matches a pattern in this policy. If no frames match, availability is determined by the \"DeveloperToolsAvailability\" policy.\n\nIf you configure both this policy and the \"DeveloperToolsAvailabilityAllowlist\" policy, the allowlist takes precedence. URLs that match the allowlist are allowed, even if they also match this policy. URLs that match this policy (but not the allowlist) are blocked. If a URL matches neither, the \"DeveloperToolsAvailability\" policy determines availability.\n\nIf you disable or do not configure this policy, developer tools availability is determined by the \"DeveloperToolsAvailabilityAllowlist\" and \"DeveloperToolsAvailability\" policies.\n\nThis policy supports up to 1,000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"17c14f4407d1afde":{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled","displayName":"Allows users to translate videos to different languages.","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\nWith this feature, users can watch videos translated into their selected language in real time.\n\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\n\nThese components can be updated periodically to improve performance and translation quality.\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\nFor more information, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\n\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\nusers will see the Translate button when hovering over videos.\n\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button is not shown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"17ed79ce387d51ea":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled","displayName":"Allow quick links on the new tab page","description":"If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy doesn't force quick links to be visible - the user can continue to turn quick links on and off.\n\nIf you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout.\n\nThis policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal.\n\nRelated policies: \"NewTabPageAllowedBackgroundTypes\", \"NewTabPageContentEnabled\"","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"174af4b6a5d4b788":{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_storagecapacitystartdeletion","displayName":"Storage Capacity Start Deletion","description":"Start deleting profiles when available storage capacity falls below this threshold, given as percent of total storage available for profiles. Profiles that have been inactive the longest will be deleted first.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},"171bf36423981c59":{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits","displayName":"Units","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_1","displayName":"KB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_2","displayName":"MB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_3","displayName":"GB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_4","displayName":"TB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_5","displayName":"PB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_6","displayName":"EB","description":null,"helpText":null}]},"17705990de101b4b":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution","displayName":"Primary DNS suffix devolution","description":"Specifies if the DNS client performs primary DNS suffix devolution during the name resolution process.\r\n\r\nWith devolution, a DNS client creates queries by appending a single-label, unqualified domain name with the parent suffix of the primary DNS suffix name, and the parent of that suffix, and so on, stopping if the name is successfully resolved or at a level determined by devolution settings. Devolution can be used when a user or application submits a query for a single-label domain name.\r\n\r\nThe DNS client appends DNS suffixes to the single-label, unqualified domain name based on the state of the Append primary and connection specific DNS suffixes radio button and Append parent suffixes of the primary DNS suffix check box on the DNS tab in Advanced TCP/IP Settings for the Internet Protocol (TCP/IP) Properties dialog box.\r\n\r\nDevolution is not enabled if a global suffix search list is configured using Group Policy.\r\n\r\nIf a global suffix search list is not configured, and the Append primary and connection specific DNS suffixes radio button is selected, the DNS client appends the following names to a single-label name when it sends DNS queries:\r\n\r\nThe primary DNS suffix, as specified on the Computer Name tab of the System control panel.\r\n\r\nEach connection-specific DNS suffix, assigned either through DHCP or specified in the DNS suffix for this connection box on the DNS tab in the Advanced TCP/IP Settings dialog box for each connection.\r\n\r\nFor example, when a user submits a query for a single-label name such as \"example,\" the DNS client attaches a suffix such as \"microsoft.com\" resulting in the query \"example.microsoft.com,\" before sending the query to a DNS server.\r\n\r\nIf a DNS suffix search list is not specified, the DNS client attaches the primary DNS suffix to a single-label name. If this query fails, the connection-specific DNS suffix is attached for a new query. If none of these queries are resolved, the client devolves the primary DNS suffix of the computer (drops the leftmost label of the primary DNS suffix), attaches this devolved primary DNS suffix to the single-label name, and submits this new query to a DNS server.\r\n\r\nFor example, if the primary DNS suffix ooo.aaa.microsoft.com is attached to the non-dot-terminated single-label name \"example,\" and the DNS query for example.ooo.aaa.microsoft.com fails, the DNS client devolves the primary DNS suffix (drops the leftmost label) till the specified devolution level, and submits a query for example.aaa.microsoft.com. If this query fails, the primary DNS suffix is devolved further if it is under specified devolution level and the query example.microsoft.com is submitted. If this query fails, devolution continues if it is under specified devolution level and the query example.microsoft.com is submitted, corresponding to a devolution level of two. The primary DNS suffix cannot be devolved beyond a devolution level of two. The devolution level can be configured using the primary DNS suffix devolution level policy setting. The default devolution level is two.\r\n\r\nIf you enable this policy setting, or if you do not configure this policy setting, DNS clients attempt to resolve single-label names using concatenations of the single-label name to be resolved and the devolved primary DNS suffix.\r\n\r\nIf you disable this policy setting, DNS clients do not attempt to resolve names that are concatenations of the single-label name to be resolved and the devolved primary DNS suffix.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-usedomainnamedevolution"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution_1","displayName":"Enabled","description":null,"helpText":null}]},"17c0f715ea655271":{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize","displayName":"Control maximum size of baseline file cache","description":"\r\n This policy controls the percentage of disk space available to the Windows Installer baseline file cache.\r\n\r\n The Windows Installer uses the baseline file cache to save baseline files modified by binary delta difference updates. The cache is used to retrieve the baseline file for future updates. The cache eliminates user prompts for source media when new updates are applied.\r\n\r\n If you enable this policy setting you can modify the maximum size of the Windows Installer baseline file cache.\r\n\r\n If you set the baseline cache size to 0, the Windows Installer will stop populating the baseline cache for new updates. The existing cached files will remain on disk and will be deleted when the product is removed.\r\n\r\n If you set the baseline cache to 100, the Windows Installer will use available free space for the baseline file cache.\r\n\r\n If you disable or do not configure this policy setting, the Windows Installer will uses a default value of 10 percent for the baseline file cache maximum size.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-maxpatchcachesize"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"177a1de79b8ab515":{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Boot Performance Diagnostics.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Boot Performance problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Boot Performance problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Boot Performance problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows Boot Performance for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-1"],"categoryId":"18b972fd-74f2-4345-9449-087c80dd38a3","categoryName":"Windows Boot Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_1","displayName":"Enabled","description":null,"helpText":null}]},"17eff4ccb8355c6e":{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2","displayName":"Prevent flicks","description":"Makes pen flicks and all related features unavailable.\r\n\r\nIf you enable this policy, pen flicks and all related features are unavailable. This includes: pen flicks themselves, pen flicks training, pen flicks training triggers in Internet Explorer, the pen flicks notification and the pen flicks tray icon.\r\n\r\nIf you disable or do not configure this policy, pen flicks and related features are available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventflicks-2"],"categoryId":"b524d6e2-75bc-4409-ae3d-07605707d7ee","categoryName":"Pen UX Behaviors","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2_1","displayName":"Enabled","description":null,"helpText":null}]},"17bb99c043b3c7aa":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews","displayName":"Microsoft News (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews_1","displayName":"True","description":null,"helpText":null}]},"17d8113254fd1661":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub","displayName":"Feedback Hub (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub_1","displayName":"True","description":null,"helpText":null}]},"177dfef104e46a73":{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_data_cache_limit","displayName":"Data Cache Limit","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},"1715e98f6c294fac":{"id":"device_vendor_msft_policy_config_browser_provisionfavorites","displayName":"Provision Favorites","description":"This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites. If you enable this setting, you can set favorite URL's and favorite folders to appear on top of users' favorites list (either in the Hub or Favorites Bar). The user favorites will appear after these provisioned favorites. Important Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge. If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#provisionfavorites"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"171f5f104796df16":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol, so list \"skype\" instead of \"skype:\" or \"skype://\".\r\n\r\nIf this policy is set, a protocol will only be permitted to launch an external application without prompting by policy if the protocol is listed, and the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf this policy is not set, no protocols can launch without a prompt by default. Users may opt out of prompts on a per-protocol/per-site basis unless the ExternalProtocolDialogShowAlwaysOpenCheckbox policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' policy, which are documented at http://www.chromium.org/administrators/url-blocklist-filter-format.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=AutoLaunchProtocolsFromOrigins for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"spotify\",\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"teams\",\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"outlook\",\r\n \"allowed_origins\": [\r\n \"*\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"17082f2556ba5a9c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nExample value: https://search.my.company/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},"17471e7594dd8084":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist","displayName":"Configure native messaging blocklist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},"1769b255d6db1e94":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain_remoteaccesshostclientdomain","displayName":"Configure the required domain name for remote access clients (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"17dce53abe5d56fc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls","displayName":"Allow the Flash plugin on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"17b3bc5427f3bd35":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},"179ba7c2425bb8a2":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings","displayName":"Settings for the Lens Overlay feature (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings_0","displayName":"Allow","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings_1","displayName":"Do not allow","description":null,"helpText":null}]},"17d0abea051319b0":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled","displayName":"Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"17ecc4adc1b8169c":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"17d450f6c7317f67":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets","displayName":"Allow scriptlets","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptlets"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"170de20d7546d8a0":{"id":"device_vendor_msft_policy_config_lanmanworkstation_auditserverdoesnotsupportencryption","displayName":"Audit Server Does Not Support Encryption","description":"This policy controls whether the SMB client will enable the audit event when the SMB server doesn't support encryption. If you enable this policy setting, the SMB client will log the event when the SMB server doesn't support encryption. If you disable or do not configure this policy setting, the SMB client will not log the event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanWorkstation#auditserverdoesnotsupportencryption"],"categoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_lanmanworkstation_auditserverdoesnotsupportencryption_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_auditserverdoesnotsupportencryption_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"1789fcebe41b554c":{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect","displayName":"Min Smb2 Dialect","description":"This policy controls the minimum version of SMB protocol. Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanWorkstation#minsmb2dialect"],"categoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_514","displayName":"SMB 2.0.2","description":"SMB 2.0.2","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_528","displayName":"SMB 2.1.0","description":"SMB 2.1.0","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_768","displayName":"SMB 3.0.0","description":"SMB 3.0.0","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_770","displayName":"SMB 3.0.2","description":"SMB 3.0.2","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_785","displayName":"SMB 3.1.1","description":"SMB 3.1.1","helpText":null}]},"177fe57a5b83f895":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_domainmember_disablemachineaccountpasswordchanges","displayName":"Domain Member Disable Machine Account Password Changes","description":"Domain member: Disable machine account password changes Determines whether a domain member periodically changes its computer account password. If this setting is enabled, the domain member does not attempt to change its computer account password. If this setting is disabled, the domain member attempts to change its computer account password as specified by the setting for Domain Member: Maximum age for machine account password, which by default is every 30 days. Default: Disabled. Notes This security setting should not be enabled. Computer account passwords are used to establish secure channel communications between members and domain controllers and, within the domain, between the domain controllers themselves. Once it is established, the secure channel is used to transmit sensitive information that is necessary for making authentication and authorization decisions. This setting should not be used in an attempt to support dual-boot scenarios that use the same computer account. If you want to dual-boot two installations that are joined to the same domain, give the two installations different computer names.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#domainmember_disablemachineaccountpasswordchanges"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"17f252fee8072ace":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_diskcachesize","displayName":"Set disk cache size: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"179b1c7e0f122a52":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls","displayName":"Allow cookies on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nSee the 'CookiesBlockedForUrls' (Block cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- 'CookiesBlockedForUrls'\r\n\r\n- CookiesAllowedForUrls\r\n\r\n- 'CookiesSessionOnlyForUrls'\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"17cbf743b6f43337":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient","displayName":"Forces Microsoft Edge to use its built-in WNS push client to connect to the Windows Push Notification Service.","description":"In some environments, the Windows OS client can't connect to the Windows Push Notification Service (WNS). For these environments, you can use the Microsoft Edge built-in WNS push client, which may be able to connect successfully.\r\n\r\nIf enabled, Microsoft Edge will use its built-in WNS push client to connect to WNS.\r\n\r\nIf disabled or not configured, Microsoft Edge will use the Windows OS client to connect to the Windows Push Notification Service. This is the default setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient_1","displayName":"Enabled","description":null,"helpText":null}]},"1752c10145ceb393":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout","displayName":"Delay before running idle actions","description":"Triggers an action when the computer is idle.\r\n\r\nIf you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\r\n\r\nIf you not set this policy, no action will be ran.\r\n\r\nThe minimum threshold is 1 minute.\r\n\r\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"17bfdac79a3ef6ac":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessaccountinfo_forcedenytheseapps","displayName":"Let Apps Access Account Info Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to account information. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessaccountinfo_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"177c0dacf959e816":{"id":"device_vendor_msft_policy_config_update_configuredeadlinegraceperiod","displayName":"Configure Deadline Grace Period","description":"Also available in Windows 10, versions 1809, 1803, and 1709. Allows the IT admin (when used with Update/ConfigureDeadlineForFeatureUpdates or Update/ConfigureDeadlineForQualityUpdates) to specify a minimum number of days until restarts occur automatically. Setting the grace period may extend the effective deadline set by the deadline policies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlinegraceperiod"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"1739975bf90b17be":{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopcoverinfrastructure","displayName":"Allow Projection To PC Over Infrastructure","description":"This policy setting allows you to turn off projection to a PC over infrastructure. If you set it to 0, your PC cannot be discoverable and can't be projected to over infrastructure, though it may still be possible to project over WiFi Direct. If you set it to 1, your PC can be discoverable and can be projected to over infrastructure.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WirelessDisplay#allowprojectiontopcoverinfrastructure"],"categoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopcoverinfrastructure_0","displayName":"Your PC is not discoverable and other devices cannot project to it over infrastructure, although it is possible to project to it over WiFi Direct.","description":"Your PC is not discoverable and other devices cannot project to it over infrastructure, although it is possible to project to it over WiFi Direct.","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopcoverinfrastructure_1","displayName":"Your PC is discoverable and other devices can project to it over infrastructure.","description":"Your PC is discoverable and other devices can project to it over infrastructure.","helpText":null}]},"17d1b00de8b175e8":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon36","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"17be4189aa39604b":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablevisualstyle","displayName":"Prevent changing visual style for windows and buttons (User)","description":"Prevents users or applications from changing the visual style of the windows and buttons displayed on their screens.\r\n\r\nWhen enabled on Windows XP, this setting disables the \"Windows and buttons\" drop-down list on the Appearance tab in Display Properties.\r\n\r\nWhen enabled on Windows XP and later systems, this setting prevents users and applications from changing the visual style through the command line. Also, a user may not apply a different visual style when changing themes.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-disablevisualstyle"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablevisualstyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablevisualstyle_1","displayName":"Enabled","description":null,"helpText":null}]},"172512ad5eda3b37":{"id":"user_vendor_msft_policy_config_admx_programs_nogetprograms","displayName":"Hide \"Get Programs\" page (User)","description":"Prevents users from viewing or installing published programs from the network. \r\n\r\nThis setting prevents users from accessing the \"Get Programs\" page from the Programs Control Panel in Category View, Programs and Features in Classic View and the \"Install a program from the netowrk\" task. The \"Get Programs\" page lists published programs and provides an easy way to install them.\r\n\r\nPublished programs are those programs that the system administrator has explicitly made available to the user with a tool such as Windows Installer. Typically, system administrators publish programs to notify users of their availability, to recommend their use, or to enable users to install them without having to search for installation files.\r\n\r\nIf this setting is enabled, users cannot view the programs that have been published by the system administrator, and they cannot use the \"Get Programs\" page to install published programs. Enabling this feature does not prevent users from installing programs by using other methods. Users will still be able to view and installed assigned (partially installed) programs that are offered on the desktop or on the Start menu.\r\n\r\nIf this setting is disabled or is not configured, the \"Install a program from the network\" task to the \"Get Programs\" page will be available to all users.\r\n\r\nNote: If the \"Hide Programs Control Panel\" setting is enabled, this setting is ignored.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-programs#admx-programs-nogetprograms"],"categoryId":"dc16dbf0-aac8-4ff3-a546-1ddb55650f47","categoryName":"Programs","options":[{"id":"user_vendor_msft_policy_config_admx_programs_nogetprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_programs_nogetprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"17eb03d771938e94":{"id":"user_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart","displayName":"Prevent users from uninstalling applications from Start (User)","description":"If you enable this setting, users cannot uninstall apps from Start.\r\n\r\nIf you disable this setting or do not configure it, users can access the uninstall command from Start\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nouninstallfromstart"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_1","displayName":"Enabled","description":null,"helpText":null}]},"17a7a0e8ef21e5ec":{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoresize","displayName":"Prevent users from resizing the taskbar (User)","description":"This policy setting allows you to prevent users from resizing the taskbar.\r\n\r\nIf you enable this policy setting, users are not be able to resize their taskbar.\r\n\r\nIf you disable or do not configure this policy setting, users are able to resize their taskbar unless prevented by another setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnoresize"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoresize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoresize_1","displayName":"Enabled","description":null,"helpText":null}]},"17e1ebc46feb13fb":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup","displayName":"Outlook 2016 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Outlook 2016.\r\nMicrosoft Outlook 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Outlook 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Outlook 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Outlook 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016outlookbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"176b03ff3b15e819":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities (User)","description":"Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of Legacy Certificate Authorities (CA) for certificate chains with a specified subjectPublicKeyInfo hash. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the subjectPublicKeyInfo hash must appear in a CA certificate recognized as a Legacy CA. A Legacy CA is publicly trusted by one or more operating systems supported by Google Chrome, but not Android Open Source Project or Google Chrome OS.\r\n\r\nSpecify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored.\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_1","displayName":"Enabled","description":null,"helpText":null}]},"1715d18abad8be38":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},"177db65cf6523ce0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (User)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"17146b458c65c9b0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture salted hashes of passwords. (User)","description":"Setting the policy sets the list of enterprise login URLs (HTTP and HTTPS protocols only). Password protection service will capture salted hashes of passwords on these URLs and use them for password reuse detection. For Google Chrome to correctly capture password salted hashes, ensure your sign-in pages follow these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ).\r\n\r\nTurning this setting off or leaving it unset means the password protection service only captures the password salted hashes on https://accounts.google.com.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://mydomain.com/login.html\r\nhttps://login.mydomain.com","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_1","displayName":"Enabled","description":null,"helpText":null}]},"17a6b3d1cb41b47f":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints (User)","description":"A list of TLS certificates that should be trusted by Google Chrome for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.\r\nCertificates should be base64-encoded. At least one constraint must be specified for each certificate.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=CACertificatesWithConstraints for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"certificate\": \"MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X\",\r\n \"constraints\": {\r\n \"permitted_dns_names\": [\r\n \"example.org\"\r\n ],\r\n \"permitted_cidrs\": [\r\n \"10.1.1.0/24\"\r\n ]\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},"17987022587f8af7":{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage","displayName":"Specify default behavior for a new tab (User)","description":"This policy setting allows you to specify what is displayed when the user opens a new tab.\n\nIf you enable this policy setting, you can choose which page to display when the user opens a new tab: blank page (about:blank), the first home page, the new tab page or the new tab page with my news feed.\n\nIf you disable or do not configure this policy setting, the user can select his or her preference for this behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-newtabdefaultpage"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_1","displayName":"Enabled","description":null,"helpText":null}]},"17a087d7935b3dc9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"17e647174e7c12c7":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter","displayName":"Print headers and footers (User)","description":"Force 'headers and footers' to be on or off in the printing dialog.\r\n\r\nIf you don't configure this policy, users can decide whether to print headers and footers.\r\n\r\nIf you disable this policy, users can't print headers and footers.\r\n\r\nIf you enable this policy, users always print headers and footers.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},"17133bfd12e5ef3a":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage","displayName":"Set the new tab page as the home page (User)","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\r\n\r\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\r\n\r\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\r\n\r\nIf not configured users can choose whether the new tab page is their home page.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage_1","displayName":"Enabled","description":null,"helpText":null}]},"177a2190fe1108e7":{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile","displayName":"Switch intranet sites to a work profile (User)","description":"Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet.\r\n\r\nIf you enable or don't configure this policy, navigations to intranet URLs will switch to the most recently used work profile if one exists.\r\n\r\nIf you disable this policy, navigations to intranet URLs will remain in the current browser profile.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_1","displayName":"Enabled","description":null,"helpText":null}]},"17957cd1be5acbad":{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended","displayName":"Enable origin-keyed process isolation for improved security (User)","description":"This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This may increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off.\r\n\r\nIf you enable this policy, most origins will be isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies.\r\n\r\nIf you disable this policy, origins will not be isolated from the rest of their site unless the origin explicitly requests isolation.\r\n\r\nIf you don’t configure this policy, the browser will decide which origins to isolate and when. By default, this feature is disabled. The default state may change in the future.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"17d662a930c5bb63":{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\r\n\r\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\r\n\r\nDisabling this setting is the same as leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nPolicy options mapping:\r\n\r\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\r\n\r\n* RestoreOnStartupIsLastSession (1) = Restore the last session\r\n\r\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\r\n\r\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},"17c1bba1912e0be5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_datecolon275","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"17aa00a1cb44388a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder","displayName":"Organize supporting files in a folder (User)","description":"This will be forced on if 'Use long file names' is forced off.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder_1","displayName":"Enabled","description":null,"helpText":null}]},"1744ef58a9290d7c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist","displayName":"Use auto-change list (User)","description":"Checks/Unchecks the option \"Search misused word list\". This option is available only if you are using the Korean language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for Korean, and have enabled support for Korean through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist_1","displayName":"Enabled","description":null,"helpText":null}]},"1797d6ad25faeb79":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_defaultrootdirlist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"17e3ebeb016ea5fe":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions_l_empty12","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"176d3017b24297fb":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit_l_embeddedfilesizelimit","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"170edce6e6de4e96":{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_1","displayName":"Enabled","description":null,"helpText":null}]},"1753532944e7fbe5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail","displayName":"Prompt user to choose security settings if default settings fail (User)","description":"Check to prompt the user to choose security settings if default settings fail; uncheck to automatically select.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail_1","displayName":"Enabled","description":null,"helpText":null}]},"17f520f1d5c5d2bf":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover","displayName":"Disable AutoDiscover (User)","description":"This policy setting allows you to disable AutoDiscover.\r\n\r\nIf you enable this policy setting, you can select one or more of the following options to disable in the AutoDiscover feature.\r\n\r\n\"Exclude the last known good URL” – Outlook does not use the last known good Autodiscover URL.\r\n\r\n\"Exclude the SCP object lookup\" – Outlook does not perform Active Directory queries for Service Connection Point (SCP) objects with Autodiscover information.\r\n\r\n\"Exclude the root domain query based on your primary SMTP address\" - Outlook does not use the root domain of your primary SMTP address to locate the AutoDiscover service. For example, you select this optionOutlook does not use the following URL: https:///autodiscover/autodiscover.xml.\r\n\r\n\"Exclude the query for the AutoDiscover domain\" - Outlook does not use the Autodiscover domain to locate the Autodiscover service. For example, Outlook does not use the following URL: https://autodiscover./autodiscover/autodiscover.xml\r\n\r\n\"Exclude the HTTP redirect method\" - Outlook does not use the HTTP redirect method in the event it is unable to reach the AutoDiscover service via either of the HTTPS URLs: https:///autodiscover/autodiscover.xml or https://autodiscover./autodiscover/autodiscover.xml.\r\n\r\n\"Exclude the SRV record query in DNS\" - Outlook does not use an SRV record lookup in DNS to locate the AutoDiscover service.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_1","displayName":"Enabled","description":null,"helpText":null}]},"1783bc56284e85a4":{"id":"user_vendor_msft_policy_config_start_forcestartsize","displayName":"Force Start Size (User)","description":"Forces the start screen size. If there is policy configuration conflict, the latest configuration request is applied to the device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#forcestartsize"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_forcestartsize_0","displayName":"Do not force size of Start.","description":"Do not force size of Start.","helpText":null},{"id":"user_vendor_msft_policy_config_start_forcestartsize_1","displayName":"Force non-fullscreen size of Start.","description":"Force non-fullscreen size of Start.","helpText":null},{"id":"user_vendor_msft_policy_config_start_forcestartsize_2","displayName":"Force a fullscreen size of Start.","description":"Force a fullscreen size of Start.","helpText":null}]},"17572efdb4ae2ec7":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"17be10acda2de7e1":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks","displayName":"Stop checking for image watermarks (User)","description":"This policy setting prevents the Accessibility Checker from checking if a document has image watermarks.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking if a document has image watermarks.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for watermarks and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks_1","displayName":"Enabled","description":null,"helpText":null}]},"173e29541d846943":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks","displayName":"Match 'repeat character' marks (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks_1","displayName":"Enabled","description":null,"helpText":null}]},"17f4aa92e5e43f2c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"17f6685b8144970b":{"id":"com.apple.assetcache.managed_listenwithpeersandparents","displayName":"Listen With Peers And Parents","description":"If true, the content cache provides content to the clients in the union of the Listen Ranges, Peer Listen Ranges and Parents.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_listenwithpeersandparents_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_listenwithpeersandparents_true","displayName":"True","description":null,"helpText":null}]},"17eddcd97deb9595":{"id":"com.apple.dock_com.apple.dock","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},"17a768a805012967":{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos","displayName":"Start In Smart Card Mode","description":"If set to true, the user interface will start in SmartCard mode. (macOS only)","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_startinsmartcardmode_kerberos_true","displayName":"Enabled","description":null,"helpText":null}]},"17b24de807ef0be1":{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled","displayName":"Use out-of-process iframe PDF Viewer","description":"Determines whether the PDF viewer in Microsoft Edge uses an out-of-process iframe (OOPIF).\nThis will be the new PDF viewer architecture going forward, as it is simpler in design and makes adding new features easier. The current GuestView PDF viewer, which relies on an outdated and overly complex architecture, is being deprecated.\n\nWhen this policy is set to Enabled or not set, Microsoft Edge will use the OOPIF PDF viewer architecture. Once Enabled or not set, the default behavior will be decided by Microsoft Edge.\n\nWhen this policy is set to Disabled, Microsoft Edge will strictly use the existing GuestView PDF viewer. This approach embeds a web page with its own separate frame tree into another web page.\n\nThis policy will be removed in the future, after the OOPIF PDF viewer feature has fully rolled out.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pdfvieweroutofprocessiframeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_pdfvieweroutofprocessiframeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"17f3da0eebf6cd2d":{"id":"com.apple.managedclient.preferences_webcaptureenabled","displayName":"Enable web capture feature in Microsoft Edge","description":"Enables the web capture feature in Microsoft Edge that allows users to capture web content and annotate the capture using inking tools.\nIf you enable this policy or don't configure it, the Web capture option shows up in the context menu, Settings and more menu, and by using the keyboard shortcut, CTRL+SHIFT+S.\nIf you disable this policy, users can't access the web capture feature in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webcaptureenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webcaptureenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webcaptureenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1777e5640b3f6bc2":{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled","displayName":"Data URL support for SVGUseElement","description":"This policy enables Data URL support for SVGUseElement, which is disabled\nby default starting in Microsoft Edge version 119.\nIf this policy is enabled, Data URLs keep working in SVGUseElement.\nIf this policy is disabled or not configured, Data URLs can't work in SVGUseElement.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinsvguseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"17f27bd6c5532384":{"id":"com.microsoft.edge.mamedgeappconfigsettings.developertoolsavailabilityblocklist","displayName":"List of URL patterns for which developer tools are blocked","description":"This policy specifies URL patterns where developer tools are blocked. For information on the URL format, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nURL patterns are evaluated against the URL of every frame on the page being inspected. If any frame matches a pattern in this policy, developer tools are blocked for the entire page.\n\nIf you configure this policy and do not configure the \"DeveloperToolsAvailabilityAllowlist\" policy, developer tools are blocked when any frame matches a pattern in this policy. If no frames match, availability is determined by the \"DeveloperToolsAvailability\" policy.\n\nIf you configure both this policy and the \"DeveloperToolsAvailabilityAllowlist\" policy, the allowlist takes precedence. URLs that match the allowlist are allowed, even if they also match this policy. URLs that match this policy (but not the allowlist) are blocked. If a URL matches neither, the \"DeveloperToolsAvailability\" policy determines availability.\n\nIf you disable or do not configure this policy, developer tools availability is determined by the \"DeveloperToolsAvailabilityAllowlist\" and \"DeveloperToolsAvailability\" policies.\n\nThis policy supports up to 1,000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"17c14f4407d1afde":{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled","displayName":"Allows users to translate videos to different languages.","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\nWith this feature, users can watch videos translated into their selected language in real time.\n\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\n\nThese components can be updated periodically to improve performance and translation quality.\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\nFor more information, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\n\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\nusers will see the Translate button when hovering over videos.\n\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button is not shown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livevideotranslationenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"17ed79ce387d51ea":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled","displayName":"Allow quick links on the new tab page","description":"If you enable or don't configure this policy, Microsoft Edge displays quick links on the new tab page, and the user can interact with the control, turning quick links on and off. Enabling this policy doesn't force quick links to be visible - the user can continue to turn quick links on and off.\n\nIf you disable this policy, Microsoft Edge hides quick links on the new tab page and disables the quick links control in the NTP settings flyout.\n\nThis policy only applies for Microsoft Edge local user profiles, profiles signed in using a Microsoft Account, and profiles signed in using Active Directory. To configure the Enterprise new tab page for profiles signed in using Azure Active Directory, use the M365 admin portal.\n\nRelated policies: \"NewTabPageAllowedBackgroundTypes\", \"NewTabPageContentEnabled\"","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagequicklinksenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"17ecbbd4cd41f885":{"id":"contentcaching_peerlistenranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"174af4b6a5d4b788":{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_storagecapacitystartdeletion","displayName":"Storage Capacity Start Deletion","description":"Start deleting profiles when available storage capacity falls below this threshold, given as percent of total storage available for profiles. Profiles that have been inactive the longest will be deleted first.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},"171bf36423981c59":{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits","displayName":"Units","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":[{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_1","displayName":"KB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_2","displayName":"MB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_3","displayName":"GB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_4","displayName":"TB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_5","displayName":"PB","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitunits_6","displayName":"EB","description":null,"helpText":null}]},"17705990de101b4b":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution","displayName":"Primary DNS suffix devolution","description":"Specifies if the DNS client performs primary DNS suffix devolution during the name resolution process.\r\n\r\nWith devolution, a DNS client creates queries by appending a single-label, unqualified domain name with the parent suffix of the primary DNS suffix name, and the parent of that suffix, and so on, stopping if the name is successfully resolved or at a level determined by devolution settings. Devolution can be used when a user or application submits a query for a single-label domain name.\r\n\r\nThe DNS client appends DNS suffixes to the single-label, unqualified domain name based on the state of the Append primary and connection specific DNS suffixes radio button and Append parent suffixes of the primary DNS suffix check box on the DNS tab in Advanced TCP/IP Settings for the Internet Protocol (TCP/IP) Properties dialog box.\r\n\r\nDevolution is not enabled if a global suffix search list is configured using Group Policy.\r\n\r\nIf a global suffix search list is not configured, and the Append primary and connection specific DNS suffixes radio button is selected, the DNS client appends the following names to a single-label name when it sends DNS queries:\r\n\r\nThe primary DNS suffix, as specified on the Computer Name tab of the System control panel.\r\n\r\nEach connection-specific DNS suffix, assigned either through DHCP or specified in the DNS suffix for this connection box on the DNS tab in the Advanced TCP/IP Settings dialog box for each connection.\r\n\r\nFor example, when a user submits a query for a single-label name such as \"example,\" the DNS client attaches a suffix such as \"microsoft.com\" resulting in the query \"example.microsoft.com,\" before sending the query to a DNS server.\r\n\r\nIf a DNS suffix search list is not specified, the DNS client attaches the primary DNS suffix to a single-label name. If this query fails, the connection-specific DNS suffix is attached for a new query. If none of these queries are resolved, the client devolves the primary DNS suffix of the computer (drops the leftmost label of the primary DNS suffix), attaches this devolved primary DNS suffix to the single-label name, and submits this new query to a DNS server.\r\n\r\nFor example, if the primary DNS suffix ooo.aaa.microsoft.com is attached to the non-dot-terminated single-label name \"example,\" and the DNS query for example.ooo.aaa.microsoft.com fails, the DNS client devolves the primary DNS suffix (drops the leftmost label) till the specified devolution level, and submits a query for example.aaa.microsoft.com. If this query fails, the primary DNS suffix is devolved further if it is under specified devolution level and the query example.microsoft.com is submitted. If this query fails, devolution continues if it is under specified devolution level and the query example.microsoft.com is submitted, corresponding to a devolution level of two. The primary DNS suffix cannot be devolved beyond a devolution level of two. The devolution level can be configured using the primary DNS suffix devolution level policy setting. The default devolution level is two.\r\n\r\nIf you enable this policy setting, or if you do not configure this policy setting, DNS clients attempt to resolve single-label names using concatenations of the single-label name to be resolved and the devolved primary DNS suffix.\r\n\r\nIf you disable this policy setting, DNS clients do not attempt to resolve names that are concatenations of the single-label name to be resolved and the devolved primary DNS suffix.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-usedomainnamedevolution"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_usedomainnamedevolution_1","displayName":"Enabled","description":null,"helpText":null}]},"17c0f715ea655271":{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize","displayName":"Control maximum size of baseline file cache","description":"\r\n This policy controls the percentage of disk space available to the Windows Installer baseline file cache.\r\n\r\n The Windows Installer uses the baseline file cache to save baseline files modified by binary delta difference updates. The cache is used to retrieve the baseline file for future updates. The cache eliminates user prompts for source media when new updates are applied.\r\n\r\n If you enable this policy setting you can modify the maximum size of the Windows Installer baseline file cache.\r\n\r\n If you set the baseline cache size to 0, the Windows Installer will stop populating the baseline cache for new updates. The existing cached files will remain on disk and will be deleted when the product is removed.\r\n\r\n If you set the baseline cache to 100, the Windows Installer will use available free space for the baseline file cache.\r\n\r\n If you disable or do not configure this policy setting, the Windows Installer will uses a default value of 10 percent for the baseline file cache maximum size.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-maxpatchcachesize"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_maxpatchcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"177a1de79b8ab515":{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1","displayName":"Configure Scenario Execution Level","description":"Determines the execution level for Windows Boot Performance Diagnostics.\r\n\r\nIf you enable this policy setting, you must select an execution level from the dropdown menu. If you select problem detection and troubleshooting only, the Diagnostic Policy Service (DPS) will detect Windows Boot Performance problems and attempt to determine their root causes. These root causes will be logged to the event log when detected, but no corrective action will be taken. If you select detection, troubleshooting and resolution, the DPS will detect Windows Boot Performance problems and indicate to the user that assisted resolution is available.\r\n\r\nIf you disable this policy setting, Windows will not be able to detect, troubleshoot or resolve any Windows Boot Performance problems that are handled by the DPS.\r\n\r\nIf you do not configure this policy setting, the DPS will enable Windows Boot Performance for resolution by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo system restart or service restart is required for this policy to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-performancediagnostics#admx-performancediagnostics-wdiscenarioexecutionpolicy-1"],"categoryId":"18b972fd-74f2-4345-9449-087c80dd38a3","categoryName":"Windows Boot Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_1_1","displayName":"Enabled","description":null,"helpText":null}]},"17eff4ccb8355c6e":{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2","displayName":"Prevent flicks","description":"Makes pen flicks and all related features unavailable.\r\n\r\nIf you enable this policy, pen flicks and all related features are unavailable. This includes: pen flicks themselves, pen flicks training, pen flicks training triggers in Internet Explorer, the pen flicks notification and the pen flicks tray icon.\r\n\r\nIf you disable or do not configure this policy, pen flicks and related features are available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventflicks-2"],"categoryId":"b524d6e2-75bc-4409-ae3d-07605707d7ee","categoryName":"Pen UX Behaviors","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventflicks_2_1","displayName":"Enabled","description":null,"helpText":null}]},"17bb99c043b3c7aa":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews","displayName":"Microsoft News (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingnews_1","displayName":"True","description":null,"helpText":null}]},"17d8113254fd1661":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub","displayName":"Feedback Hub (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_windowsfeedbackhub_1","displayName":"True","description":null,"helpText":null}]},"177dfef104e46a73":{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_data_cache_limit","displayName":"Data Cache Limit","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},"1715e98f6c294fac":{"id":"device_vendor_msft_policy_config_browser_provisionfavorites","displayName":"Provision Favorites","description":"This policy setting allows you to configure a default set of favorites, which will appear for employees. Employees cannot modify, sort, move, export or delete these provisioned favorites. If you enable this setting, you can set favorite URL's and favorite folders to appear on top of users' favorites list (either in the Hub or Favorites Bar). The user favorites will appear after these provisioned favorites. Important Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge. If you disable or don't configure this setting, employees will see the favorites they set in the Hub and Favorites Bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#provisionfavorites"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"171f5f104796df16":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol, so list \"skype\" instead of \"skype:\" or \"skype://\".\r\n\r\nIf this policy is set, a protocol will only be permitted to launch an external application without prompting by policy if the protocol is listed, and the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list. If either condition is false the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf this policy is not set, no protocols can launch without a prompt by default. Users may opt out of prompts on a per-protocol/per-site basis unless the ExternalProtocolDialogShowAlwaysOpenCheckbox policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' policy, which are documented at http://www.chromium.org/administrators/url-blocklist-filter-format.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=AutoLaunchProtocolsFromOrigins for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"spotify\",\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"teams\",\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"outlook\",\r\n \"allowed_origins\": [\r\n \"*\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"17082f2556ba5a9c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nExample value: https://search.my.company/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},"17471e7594dd8084":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist","displayName":"Configure native messaging blocklist","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativemessagingblacklist_1","displayName":"Enabled","description":null,"helpText":null}]},"1769b255d6db1e94":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_remoteaccesshostclientdomain_remoteaccesshostclientdomain","displayName":"Configure the required domain name for remote access clients (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"17dce53abe5d56fc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls","displayName":"Allow the Flash plugin on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"17b3bc5427f3bd35":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionchangepasswordurl_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},"179ba7c2425bb8a2":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings","displayName":"Settings for the Lens Overlay feature (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings_0","displayName":"Allow","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_lensoverlaysettings_1","displayName":"Do not allow","description":null,"helpText":null}]},"17d0abea051319b0":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled","displayName":"Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_enforcelocalanchorconstraintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"17ecc4adc1b8169c":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"17d450f6c7317f67":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets","displayName":"Allow scriptlets","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptlets"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"170de20d7546d8a0":{"id":"device_vendor_msft_policy_config_lanmanworkstation_auditserverdoesnotsupportencryption","displayName":"Audit Server Does Not Support Encryption","description":"This policy controls whether the SMB client will enable the audit event when the SMB server doesn't support encryption. If you enable this policy setting, the SMB client will log the event when the SMB server doesn't support encryption. If you disable or do not configure this policy setting, the SMB client will not log the event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanWorkstation#auditserverdoesnotsupportencryption"],"categoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_lanmanworkstation_auditserverdoesnotsupportencryption_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_auditserverdoesnotsupportencryption_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"1789fcebe41b554c":{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect","displayName":"Min Smb2 Dialect","description":"This policy controls the minimum version of SMB protocol. Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanWorkstation#minsmb2dialect"],"categoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_514","displayName":"SMB 2.0.2","description":"SMB 2.0.2","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_528","displayName":"SMB 2.1.0","description":"SMB 2.1.0","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_768","displayName":"SMB 3.0.0","description":"SMB 3.0.0","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_770","displayName":"SMB 3.0.2","description":"SMB 3.0.2","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_minsmb2dialect_785","displayName":"SMB 3.1.1","description":"SMB 3.1.1","helpText":null}]},"177fe57a5b83f895":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_domainmember_disablemachineaccountpasswordchanges","displayName":"Domain Member Disable Machine Account Password Changes","description":"Domain member: Disable machine account password changes Determines whether a domain member periodically changes its computer account password. If this setting is enabled, the domain member does not attempt to change its computer account password. If this setting is disabled, the domain member attempts to change its computer account password as specified by the setting for Domain Member: Maximum age for machine account password, which by default is every 30 days. Default: Disabled. Notes This security setting should not be enabled. Computer account passwords are used to establish secure channel communications between members and domain controllers and, within the domain, between the domain controllers themselves. Once it is established, the secure channel is used to transmit sensitive information that is necessary for making authentication and authorization decisions. This setting should not be used in an attempt to support dual-boot scenarios that use the same computer account. If you want to dual-boot two installations that are joined to the same domain, give the two installations different computer names.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#domainmember_disablemachineaccountpasswordchanges"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"17f252fee8072ace":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_diskcachesize","displayName":"Set disk cache size: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"179b1c7e0f122a52":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls","displayName":"Allow cookies on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nSee the 'CookiesBlockedForUrls' (Block cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- 'CookiesBlockedForUrls'\r\n\r\n- CookiesAllowedForUrls\r\n\r\n- 'CookiesSessionOnlyForUrls'\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"17cbf743b6f43337":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient","displayName":"Forces Microsoft Edge to use its built-in WNS push client to connect to the Windows Push Notification Service.","description":"In some environments, the Windows OS client can't connect to the Windows Push Notification Service (WNS). For these environments, you can use the Microsoft Edge built-in WNS push client, which may be able to connect successfully.\r\n\r\nIf enabled, Microsoft Edge will use its built-in WNS push client to connect to WNS.\r\n\r\nIf disabled or not configured, Microsoft Edge will use the Windows OS client to connect to the Windows Push Notification Service. This is the default setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcebuiltinpushmessagingclient_1","displayName":"Enabled","description":null,"helpText":null}]},"1752c10145ceb393":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout","displayName":"Delay before running idle actions","description":"Triggers an action when the computer is idle.\r\n\r\nIf you set this policy, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\r\n\r\nIf you not set this policy, no action will be ran.\r\n\r\nThe minimum threshold is 1 minute.\r\n\r\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"17bfdac79a3ef6ac":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessaccountinfo_forcedenytheseapps","displayName":"Let Apps Access Account Info Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to account information. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessaccountinfo_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"177c0dacf959e816":{"id":"device_vendor_msft_policy_config_update_configuredeadlinegraceperiod","displayName":"Configure Deadline Grace Period","description":"Also available in Windows 10, versions 1809, 1803, and 1709. Allows the IT admin (when used with Update/ConfigureDeadlineForFeatureUpdates or Update/ConfigureDeadlineForQualityUpdates) to specify a minimum number of days until restarts occur automatically. Setting the grace period may extend the effective deadline set by the deadline policies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlinegraceperiod"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"1739975bf90b17be":{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopcoverinfrastructure","displayName":"Allow Projection To PC Over Infrastructure","description":"This policy setting allows you to turn off projection to a PC over infrastructure. If you set it to 0, your PC cannot be discoverable and can't be projected to over infrastructure, though it may still be possible to project over WiFi Direct. If you set it to 1, your PC can be discoverable and can be projected to over infrastructure.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WirelessDisplay#allowprojectiontopcoverinfrastructure"],"categoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopcoverinfrastructure_0","displayName":"Your PC is not discoverable and other devices cannot project to it over infrastructure, although it is possible to project to it over WiFi Direct.","description":"Your PC is not discoverable and other devices cannot project to it over infrastructure, although it is possible to project to it over WiFi Direct.","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopcoverinfrastructure_1","displayName":"Your PC is discoverable and other devices can project to it over infrastructure.","description":"Your PC is discoverable and other devices can project to it over infrastructure.","helpText":null}]},"17d1b00de8b175e8":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon36","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"17be4189aa39604b":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablevisualstyle","displayName":"Prevent changing visual style for windows and buttons (User)","description":"Prevents users or applications from changing the visual style of the windows and buttons displayed on their screens.\r\n\r\nWhen enabled on Windows XP, this setting disables the \"Windows and buttons\" drop-down list on the Appearance tab in Display Properties.\r\n\r\nWhen enabled on Windows XP and later systems, this setting prevents users and applications from changing the visual style through the command line. Also, a user may not apply a different visual style when changing themes.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-disablevisualstyle"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablevisualstyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablevisualstyle_1","displayName":"Enabled","description":null,"helpText":null}]},"172512ad5eda3b37":{"id":"user_vendor_msft_policy_config_admx_programs_nogetprograms","displayName":"Hide \"Get Programs\" page (User)","description":"Prevents users from viewing or installing published programs from the network. \r\n\r\nThis setting prevents users from accessing the \"Get Programs\" page from the Programs Control Panel in Category View, Programs and Features in Classic View and the \"Install a program from the netowrk\" task. The \"Get Programs\" page lists published programs and provides an easy way to install them.\r\n\r\nPublished programs are those programs that the system administrator has explicitly made available to the user with a tool such as Windows Installer. Typically, system administrators publish programs to notify users of their availability, to recommend their use, or to enable users to install them without having to search for installation files.\r\n\r\nIf this setting is enabled, users cannot view the programs that have been published by the system administrator, and they cannot use the \"Get Programs\" page to install published programs. Enabling this feature does not prevent users from installing programs by using other methods. Users will still be able to view and installed assigned (partially installed) programs that are offered on the desktop or on the Start menu.\r\n\r\nIf this setting is disabled or is not configured, the \"Install a program from the network\" task to the \"Get Programs\" page will be available to all users.\r\n\r\nNote: If the \"Hide Programs Control Panel\" setting is enabled, this setting is ignored.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-programs#admx-programs-nogetprograms"],"categoryId":"dc16dbf0-aac8-4ff3-a546-1ddb55650f47","categoryName":"Programs","options":[{"id":"user_vendor_msft_policy_config_admx_programs_nogetprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_programs_nogetprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"17eb03d771938e94":{"id":"user_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart","displayName":"Prevent users from uninstalling applications from Start (User)","description":"If you enable this setting, users cannot uninstall apps from Start.\r\n\r\nIf you disable this setting or do not configure it, users can access the uninstall command from Start\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nouninstallfromstart"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_1","displayName":"Enabled","description":null,"helpText":null}]},"17a7a0e8ef21e5ec":{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoresize","displayName":"Prevent users from resizing the taskbar (User)","description":"This policy setting allows you to prevent users from resizing the taskbar.\r\n\r\nIf you enable this policy setting, users are not be able to resize their taskbar.\r\n\r\nIf you disable or do not configure this policy setting, users are able to resize their taskbar unless prevented by another setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnoresize"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoresize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnoresize_1","displayName":"Enabled","description":null,"helpText":null}]},"17e1ebc46feb13fb":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup","displayName":"Outlook 2016 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Outlook 2016.\r\nMicrosoft Outlook 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Outlook 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Outlook 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Outlook 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016outlookbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"176b03ff3b15e819":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities (User)","description":"Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of Legacy Certificate Authorities (CA) for certificate chains with a specified subjectPublicKeyInfo hash. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the subjectPublicKeyInfo hash must appear in a CA certificate recognized as a Legacy CA. A Legacy CA is publicly trusted by one or more operating systems supported by Google Chrome, but not Android Open Source Project or Google Chrome OS.\r\n\r\nSpecify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored.\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_1","displayName":"Enabled","description":null,"helpText":null}]},"1715d18abad8be38":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},"177db65cf6523ce0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (User)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"17146b458c65c9b0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture salted hashes of passwords. (User)","description":"Setting the policy sets the list of enterprise login URLs (HTTP and HTTPS protocols only). Password protection service will capture salted hashes of passwords on these URLs and use them for password reuse detection. For Google Chrome to correctly capture password salted hashes, ensure your sign-in pages follow these guidelines ( https://www.chromium.org/developers/design-documents/create-amazing-password-forms ).\r\n\r\nTurning this setting off or leaving it unset means the password protection service only captures the password salted hashes on https://accounts.google.com.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://mydomain.com/login.html\r\nhttps://login.mydomain.com","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionloginurls_1","displayName":"Enabled","description":null,"helpText":null}]},"17a6b3d1cb41b47f":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints (User)","description":"A list of TLS certificates that should be trusted by Google Chrome for server authentication, with constraints added outside the certificate. If no constraint of a certain type is present, then any name of that type is allowed.\r\nCertificates should be base64-encoded. At least one constraint must be specified for each certificate.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=CACertificatesWithConstraints for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"certificate\": \"MIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X\",\r\n \"constraints\": {\r\n \"permitted_dns_names\": [\r\n \"example.org\"\r\n ],\r\n \"permitted_cidrs\": [\r\n \"10.1.1.0/24\"\r\n ]\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_1","displayName":"Enabled","description":null,"helpText":null}]},"17987022587f8af7":{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage","displayName":"Specify default behavior for a new tab (User)","description":"This policy setting allows you to specify what is displayed when the user opens a new tab.\n\nIf you enable this policy setting, you can choose which page to display when the user opens a new tab: blank page (about:blank), the first home page, the new tab page or the new tab page with my news feed.\n\nIf you disable or do not configure this policy setting, the user can select his or her preference for this behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-newtabdefaultpage"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_1","displayName":"Enabled","description":null,"helpText":null}]},"17a087d7935b3dc9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"17e647174e7c12c7":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter","displayName":"Print headers and footers (User)","description":"Force 'headers and footers' to be on or off in the printing dialog.\r\n\r\nIf you don't configure this policy, users can decide whether to print headers and footers.\r\n\r\nIf you disable this policy, users can't print headers and footers.\r\n\r\nIf you enable this policy, users always print headers and footers.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},"17133bfd12e5ef3a":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage","displayName":"Set the new tab page as the home page (User)","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\r\n\r\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\r\n\r\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\r\n\r\nIf not configured users can choose whether the new tab page is their home page.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepageisnewtabpage_1","displayName":"Enabled","description":null,"helpText":null}]},"177a2190fe1108e7":{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile","displayName":"Switch intranet sites to a work profile (User)","description":"Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet.\r\n\r\nIf you enable or don't configure this policy, navigations to intranet URLs will switch to the most recently used work profile if one exists.\r\n\r\nIf you disable this policy, navigations to intranet URLs will remain in the current browser profile.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_1","displayName":"Enabled","description":null,"helpText":null}]},"17957cd1be5acbad":{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended","displayName":"Enable origin-keyed process isolation for improved security (User)","description":"This policy enables origin-keyed process isolation for most pages, which improves security by separating content from different origins into distinct processes. This may increase the number of processes created. Users can override this setting by using command-line flags or edge://flags to turn the feature on or off.\r\n\r\nIf you enable this policy, most origins will be isolated, even from other origins within the same site. For related configuration, see the IsolateOrigins and SitePerProcess policies.\r\n\r\nIf you disable this policy, origins will not be isolated from the rest of their site unless the origin explicitly requests isolation.\r\n\r\nIf you don’t configure this policy, the browser will decide which origins to isolate and when. By default, this feature is disabled. The default state may change in the future.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_originkeyedprocessesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"17d662a930c5bb63":{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\r\n\r\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\r\n\r\nDisabling this setting is the same as leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nPolicy options mapping:\r\n\r\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\r\n\r\n* RestoreOnStartupIsLastSession (1) = Restore the last session\r\n\r\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\r\n\r\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},"17c1bba1912e0be5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_datecolon275","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"17aa00a1cb44388a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder","displayName":"Organize supporting files in a folder (User)","description":"This will be forced on if 'Use long file names' is forced off.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_organizesupportingfilesinafolder_1","displayName":"Enabled","description":null,"helpText":null}]},"1744ef58a9290d7c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist","displayName":"Use auto-change list (User)","description":"Checks/Unchecks the option \"Search misused word list\". This option is available only if you are using the Korean language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for Korean, and have enabled support for Korean through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_useautochangelist_1","displayName":"Enabled","description":null,"helpText":null}]},"1797d6ad25faeb79":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_defaultrootdir_defaultrootdirlist_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"17e3ebeb016ea5fe":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_embeddedfilesblockedextensions_l_empty12","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"176d3017b24297fb":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_specifyembeddedfilesizelimit_l_embeddedfilesizelimit","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"170edce6e6de4e96":{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v8~policy~l_microsoftofficeonenote~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys291_1","displayName":"Enabled","description":null,"helpText":null}]},"1753532944e7fbe5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail","displayName":"Prompt user to choose security settings if default settings fail (User)","description":"Check to prompt the user to choose security settings if default settings fail; uncheck to automatically select.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_promptusertochoosesecuritysettingsifdefaultsettingsfail_1","displayName":"Enabled","description":null,"helpText":null}]},"17f520f1d5c5d2bf":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover","displayName":"Disable AutoDiscover (User)","description":"This policy setting allows you to disable AutoDiscover.\r\n\r\nIf you enable this policy setting, you can select one or more of the following options to disable in the AutoDiscover feature.\r\n\r\n\"Exclude the last known good URL” – Outlook does not use the last known good Autodiscover URL.\r\n\r\n\"Exclude the SCP object lookup\" – Outlook does not perform Active Directory queries for Service Connection Point (SCP) objects with Autodiscover information.\r\n\r\n\"Exclude the root domain query based on your primary SMTP address\" - Outlook does not use the root domain of your primary SMTP address to locate the AutoDiscover service. For example, you select this optionOutlook does not use the following URL: https:///autodiscover/autodiscover.xml.\r\n\r\n\"Exclude the query for the AutoDiscover domain\" - Outlook does not use the Autodiscover domain to locate the Autodiscover service. For example, Outlook does not use the following URL: https://autodiscover./autodiscover/autodiscover.xml\r\n\r\n\"Exclude the HTTP redirect method\" - Outlook does not use the HTTP redirect method in the event it is unable to reach the AutoDiscover service via either of the HTTPS URLs: https:///autodiscover/autodiscover.xml or https://autodiscover./autodiscover/autodiscover.xml.\r\n\r\n\"Exclude the SRV record query in DNS\" - Outlook does not use an SRV record lookup in DNS to locate the AutoDiscover service.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_outlookdisableautodiscover_1","displayName":"Enabled","description":null,"helpText":null}]},"1783bc56284e85a4":{"id":"user_vendor_msft_policy_config_start_forcestartsize","displayName":"Force Start Size (User)","description":"Forces the start screen size. If there is policy configuration conflict, the latest configuration request is applied to the device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#forcestartsize"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_forcestartsize_0","displayName":"Do not force size of Start.","description":"Do not force size of Start.","helpText":null},{"id":"user_vendor_msft_policy_config_start_forcestartsize_1","displayName":"Force non-fullscreen size of Start.","description":"Force non-fullscreen size of Start.","helpText":null},{"id":"user_vendor_msft_policy_config_start_forcestartsize_2","displayName":"Force a fullscreen size of Start.","description":"Force a fullscreen size of Start.","helpText":null}]},"17572efdb4ae2ec7":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_descriptioncolon42","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"17be10acda2de7e1":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks","displayName":"Stop checking for image watermarks (User)","description":"This policy setting prevents the Accessibility Checker from checking if a document has image watermarks.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking if a document has image watermarks.\r\n\r\nIf you disable or do not configure this policy setting, documents will be checked for watermarks and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingforimagewatermarks_1","displayName":"Enabled","description":null,"helpText":null}]},"173e29541d846943":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks","displayName":"Match 'repeat character' marks (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchrepeatcharactermarks_1","displayName":"Enabled","description":null,"helpText":null}]},"17f4aa92e5e43f2c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/1a.json b/public/intune-definitions/1a.json index e565645e94d1..fe8a2084e122 100644 --- a/public/intune-definitions/1a.json +++ b/public/intune-definitions/1a.json @@ -1 +1 @@ -{"1a385ab21b7f10e6":{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos","displayName":"Is Default Realm","description":"This property specifies it is the default realm if there is more than one Kerberos extension configuration.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos_true","displayName":"True","description":null,"helpText":null}]},"1ad58171e1fddf3b":{"id":"com.apple.loginwindow_sleepdisabled","displayName":"Sleep Disabled","description":"If true, disables the Sleep button.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_sleepdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_sleepdisabled_true","displayName":"True","description":null,"helpText":null}]},"1a21c3066f55c325":{"id":"com.apple.managedclient.preferences_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled, even if it's turned off by default","description":"If you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge is not available by default.\n\nIf you set this policy to false, or don't set it, AppCache will follow Microsoft Edge's defaults.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#appcacheforceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_appcacheforceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_appcacheforceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1aea7724f22ae7e4":{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference","displayName":"Allow experiences and functionality that downloads user content","description":"Examples: Office document templates, online 3D models, online videos.","helpText":null,"infoUrls":["https://aka.ms/macoce"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference_true","displayName":"True","description":null,"helpText":null}]},"1a62cdf08591f5ff":{"id":"com.apple.managedclient.preferences_printingenabled","displayName":"Enable printing","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\n\nIf you enable this policy or don't configure it, users can print.\n\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1a9a784b91d78353":{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},"1af9d16d589b1998":{"id":"com.apple.security.firewall_blockallincoming","displayName":"Block All Incoming","description":"If true, enables blocking of all incoming connections. ","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_blockallincoming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_blockallincoming_true","displayName":"True","description":null,"helpText":null}]},"1a3fb1b7bfe49934":{"id":"com.apple.systemconfiguration_proxies_exceptionslist","displayName":"Exceptions List","description":"The list of hosts and domains that should bypass proxy settings.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},"1a64f86aa60e65c9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting","displayName":"Default pop-up window setting","description":"Set whether websites can show pop-up windows. You can allow them on all websites ('AllowPopups') or block them on all sites ('BlockPopups').\n\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\n\nPolicy options mapping:\n\n* AllowPopups (1) = Allow all sites to show pop-ups\n\n* BlockPopups (2) = Do not allow any site to show popups\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting_allowpopups","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting_blockpopups","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},"1a18914aba1aa707":{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site URL patterns that specify sites for which advanced JavaScript optimizations are enabled.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com doesn't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the \"JavaScriptOptimizerAllowedForSites\" policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript optimizations enabled, but fabrikam.com uses the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site, then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise Javascript optimization is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"1adaa4cdd80c74f3":{"id":"com.microsoft.edge.mamedgeappconfigsettings.pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nDefine a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. However, starting in M85, patterns with '*' and '[*.]' wildcards in the host are no longer supported for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"1a0f79f6b8546c8f":{"id":"device_vendor_msft_defender_configuration_excludedipaddresses","displayName":"Excluded Ip Addresses","description":"Allows an administrator to explicitly disable network packet inspection made by wdnisdrv on a particular set of IP addresses.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"1a1abb8cddd7c7af":{"id":"device_vendor_msft_defender_configuration_performancemodestatus","displayName":"Performance Mode Status","description":"This setting allows IT admins to configure performance mode in either enabled or disabled mode for managed devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_performancemodestatus_0","displayName":"Performance mode is enabled (default). A service restart is required after changing this value.","description":"Performance mode is enabled (default). A service restart is required after changing this value.","helpText":null},{"id":"device_vendor_msft_defender_configuration_performancemodestatus_1","displayName":"Performance mode is disabled. A service restart is required after changing this value.","description":"Performance mode is disabled. A service restart is required after changing this value.","helpText":null}]},"1a978487591deaa4":{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled","displayName":"Scan Only If Idle Enabled","description":"In Microsoft Defender Antivirus, this setting will run scheduled scans only if the system is idle.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled_1","displayName":"Runs scheduled scans only if the system is idle.","description":"Runs scheduled scans only if the system is idle.","helpText":null},{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled_0","displayName":"Runs scheduled scans regardless of whether the system is idle.","description":"Runs scheduled scans regardless of whether the system is idle.","helpText":null}]},"1a00b5d3ba00e0c5":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers_bits_maxbandwidthservedforpeerslist","displayName":"Maximum network bandwidth used for Peercaching (bps):","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"1a946e70d0119947":{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2","displayName":"Download missing COM components","description":"This policy setting directs the system to search Active Directory for missing Component Object Model (COM) components that a program requires.\r\n\r\nMany Windows programs, such as the MMC snap-ins, use the interfaces provided by the COM components. These programs cannot perform all their functions unless Windows has internally registered the required components.\r\n\r\nIf you enable this policy setting and a component registration is missing, the system searches for it in Active Directory and, if it is found, downloads it. The resulting searches might make some programs start or run slowly.\r\n\r\nIf you disable or do not configure this policy setting, the program continues without the registration. As a result, the program might not perform all its functions, or it might stop.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-com#admx-com-appmgmt-com-searchforclsid-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2_1","displayName":"Enabled","description":null,"helpText":null}]},"1a9601e704265ebc":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx","displayName":"Phone-PC linking on this device","description":"\r\nThis policy allows IT admins to turn off the ability to Link a Phone with a PC to continue reading, emailing and other tasks that requires linking between Phone and PC.\r\n\r\nIf you enable this policy setting, the Windows device will be able to enroll in Phone-PC linking functionality and participate in Continue on PC experiences.\r\n\r\nIf you disable this policy setting, the Windows device is not allowed to be linked to Phones, will remove itself from the device list of any linked Phones, and cannot participate in Continue on PC experiences.\r\n\r\nIf you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablemmx"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx_1","displayName":"Enabled","description":null,"helpText":null}]},"1afcedbdad4fd710":{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport","displayName":"Turn off Windows Error Reporting","description":"This policy setting controls whether or not errors are reported to Microsoft.\r\n\r\nError Reporting is used to report information about a system or application that has failed or has stopped responding and is used to improve the quality of the product.\r\n\r\nIf you enable this policy setting, users are not given the option to report errors.\r\n\r\nIf you disable or do not configure this policy setting, the errors may be reported to Microsoft via the Internet or to a corporate file share.\r\n\r\nThis policy setting overrides any user setting made from the Control Panel for error reporting.\r\n\r\nAlso see the \"Configure Error Reporting\", \"Display Error Notification\" and \"Disable Windows Error Reporting\" policy settings under Computer Configuration/Administrative Templates/Windows Components/Windows Error Reporting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-pch-donotreport"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport_1","displayName":"Enabled","description":null,"helpText":null}]},"1ac9f2ed5553f5f3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities","description":"Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of Legacy Certificate Authorities (CA) for certificate chains with a specified subjectPublicKeyInfo hash. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the subjectPublicKeyInfo hash must appear in a CA certificate recognized as a Legacy CA. A Legacy CA is publicly trusted by one or more operating systems supported by Google Chrome, but not Android Open Source Project or Google Chrome OS.\r\n\r\nSpecify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored.\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_1","displayName":"Enabled","description":null,"helpText":null}]},"1a7a0ae537059691":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended","displayName":"Import search engines from default browser on first run","description":"Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1a3c2c803ca1bcf8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled","displayName":"Enable Renderer Code Integrity","description":"Setting the policy to Enabled or leaving it unset turns Renderer Code Integrity on.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's renderer processes. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's renderer processes.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1a2a443bc8cda3b0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch","displayName":"Force SafeSearch","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},"1a6c5916b64f26bf":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_proxyserver","displayName":"Address or URL of proxy server (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"1a8f7afd79a527fb":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter","displayName":"Print Headers and Footers","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},"1ada1f5d476fb806":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS","description":"This policy configures whether Google Chrome will offer a post-quantum key agreement algorithm in TLS, using the ML-KEM NIST standard. Prior to Google Chrome 131, the algorithm was Kyber, an earlier draft iteration of the standard. This allows supporting servers to protect user traffic from being later decrypted by quantum computers.\r\n\r\nIf this policy is Enabled or not set, Google Chrome will offer a post-quantum key agreement in TLS connections. User traffic will then be protected from quantum computers when communicating with compatible servers.\r\n\r\nIf this policy is Disabled, Google Chrome will not offer a post-quantum key agreement in TLS connections. User traffic will then be unprotected from quantum computers.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement TLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or the resulting larger messages. Such devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed sometime after Google Chrome version 145. It may be Enabled to allow you to test for issues, and may be Disabled while issues are being resolved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1afef1de9db42ab0":{"id":"device_vendor_msft_policy_config_connectivity_hardeneduncpaths_pol_hardenedpaths_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"643081a4-132d-463e-9d86-c8650cb2a011","categoryName":"Network Provider","options":null},"1ade5e9af9989d25":{"id":"device_vendor_msft_policy_config_federatedauthentication_enablewebsigninforprimaryuser","displayName":"Enable Web Sign In For Primary User","description":"Specifies whether web-based sign-in is enabled with the Primary User experience","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FederatedAuthentication#enablewebsigninforprimaryuser"],"categoryId":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","categoryName":"Federated Authentication","options":[{"id":"device_vendor_msft_policy_config_federatedauthentication_enablewebsigninforprimaryuser_0","displayName":"Feature defaults as appropriate for edition and device capabilities. As of now, all editions/devices exhibit Disabled behavior by default. However, this may change for future editions/devices.","description":"Feature defaults as appropriate for edition and device capabilities. As of now, all editions/devices exhibit Disabled behavior by default. However, this may change for future editions/devices.","helpText":null},{"id":"device_vendor_msft_policy_config_federatedauthentication_enablewebsigninforprimaryuser_1","displayName":"Enabled. Web Sign-in Credential Provider will be enabled for device sign-in.","description":"Enabled. Web Sign-in Credential Provider will be enabled for device sign-in.","helpText":null},{"id":"device_vendor_msft_policy_config_federatedauthentication_enablewebsigninforprimaryuser_2","displayName":"Disabled. Web Sign-in Credential Provider will be not be enabled for device sign-in.","description":"Disabled. Web Sign-in Credential Provider will be not be enabled for device sign-in.","helpText":null}]},"1a932001ab734cd1":{"id":"device_vendor_msft_policy_config_fileexplorer_turnoffdataexecutionpreventionforexplorer","displayName":"Turn off Data Execution Prevention for Explorer","description":"Disabling data execution prevention can allow certain legacy plug-in applications to function without terminating Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-fileexplorer#fileexplorer-turnoffdataexecutionpreventionforexplorer"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_fileexplorer_turnoffdataexecutionpreventionforexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fileexplorer_turnoffdataexecutionpreventionforexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"1aae6949449f8803":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilessiddirectorynamepattern","displayName":"SID Directory Name Pattern","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies a string pattern used when creating a Profile or ODFC container folder. Use this setting to define how FSLogix will attempt to create a users Profile or ODFC container folder. FSLogix will use the VHDLocations or CCDLocations as the location where to create and this setting defines what to create.\r\n\r\nNOTE: When using this configuration setting, be sure the SIDDIRNameMatch value matches this setting.\r\n\r\n- This setting has NO EFFECT when FlipFlopProfileDirectoryName is enabled.\r\n- This setting has NO EFFECT when NoProfileContainingFolder is enabled.\r\n- NoProfileContainingFolder > FlipFlopProfileDirectoryName > SIDDirNamePattern (this setting)\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\SIDDirNamePattern\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilessiddirectorynamepattern_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilessiddirectorynamepattern_1","displayName":"Enabled","description":null,"helpText":null}]},"1a678f7b6a2a788e":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowaccesstodatasources"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"1a8b775d81017a71":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver","displayName":"Include local path when user is uploading files to a server","description":"This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.\n\nIf you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.\n\nIf you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.\n\nIf you do not configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},"1a038dbd755b7fea":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"1acada2d4631439d":{"id":"device_vendor_msft_policy_config_kerberos_requirekerberosarmoring","displayName":"Fail authentication requests when Kerberos armoring is not available","description":"This policy setting controls whether a computer requires that Kerberos message exchanges be armored when communicating with a domain controller.\r\n\r\nWarning: When a domain does not support Kerberos armoring by enabling \"Support Dynamic Access Control and Kerberos armoring\", then all authentication for all its users will fail from computers with this policy setting enabled.\r\n\r\nIf you enable this policy setting, the client computers in the domain enforce the use of Kerberos armoring in only authentication service (AS) and ticket-granting service (TGS) message exchanges with the domain controllers. \r\n\r\nNote: The Kerberos Group Policy \"Kerberos client support for claims, compound authentication and Kerberos armoring\" must also be enabled to support Kerberos armoring. \r\n\r\nIf you disable or do not configure this policy setting, the client computers in the domain enforce the use of Kerberos armoring when possible as supported by the target domain.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-kerberos#kerberos-requirekerberosarmoring"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_kerberos_requirekerberosarmoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_requirekerberosarmoring_1","displayName":"Enabled","description":null,"helpText":null}]},"1ac7c766f56fedde":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_devices_preventusersfrominstallingprinterdriverswhenconnectingtosharedprinters","displayName":"Devices Prevent Users From Installing Printer Drivers When Connecting To Shared Printers","description":"Devices: Prevent users from installing printer drivers when connecting to shared printers For a computer to print to a shared printer, the driver for that shared printer must be installed on the local computer. This security setting determines who is allowed to install a printer driver as part of connecting to a shared printer. If this setting is enabled, only Administrators can install a printer driver as part of connecting to a shared printer. If this setting is disabled, any user can install a printer driver as part of connecting to a shared printer. Default on servers: Enabled. Default on workstations: Disabled Notes This setting does not affect the ability to add a local printer. This setting does not affect Administrators.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#devices_preventusersfrominstallingprinterdriverswhenconnectingtosharedprinters"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_devices_preventusersfrominstallingprinterdriverswhenconnectingtosharedprinters_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_devices_preventusersfrominstallingprinterdriverswhenconnectingtosharedprinters_0","displayName":"Disable","description":"Disable","helpText":null}]},"1a04860ee17ab768":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"1a4f36d0fa1306cb":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls_pluginsallowedforurlsdesc","displayName":"Allow the Adobe Flash plug-in on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"1ab818f9a2e5b1b0":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode","displayName":"Configure proxy server settings","description":"Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.\r\n\r\nIf you choose to never use a proxy server and to always connect directly, all other options are ignored.\r\n\r\nIf you choose to use system proxy settings, all other options are ignored.\r\n\r\nIf you choose to auto detect the proxy server, all other options are ignored.\r\n\r\nIf you choose fixed server proxy mode, you can specify further options in 'ProxyServer' (Configure address or URL of proxy server) and 'Comma-separated list of proxy bypass rules'.\r\n\r\nIf you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.\r\n\r\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nIf you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.\r\n\r\nIf you don't configure this policy users can choose their own proxy settings.\r\n\r\n* \"direct\" = Never use a proxy\r\n\r\n* \"auto_detect\" = Auto detect proxy settings\r\n\r\n* \"pac_script\" = Use a .pac proxy script\r\n\r\n* \"fixed_servers\" = Use fixed proxy servers\r\n\r\n* \"system\" = Use system proxy settings\r\n\r\nExample value: direct","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_1","displayName":"Enabled","description":null,"helpText":null}]},"1a1c6ce4943a7eeb":{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":null},"1ad63c234b9031e1":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled","displayName":"Enable editing profile in settings","description":"This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page.\r\n\r\nIf you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page.\r\n\r\nIf you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1a35e23eaa04e4b2":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"1ac039b5e049d813":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\r\n\r\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\r\n\r\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1ac67782056a95f2":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1a13f39e16cecc4f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_mspubexe72","displayName":"mspub.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_mspubexe72_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_mspubexe72_1","displayName":"True","description":null,"helpText":null}]},"1a047a3a72b31b27":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc","displayName":"Enable OpenID Connect (OIDC) authentication for syncing content from an on-prem SharePoint Server using the OneDrive sync app","description":"When enabled, this setting allows the OneDrive sync app (OneDrive.exe) to authenticate requests to an on-premises SharePoint Server using OIDC authentication, if supported by the server. To use this setting, you must also enable \"Specify SharePoint Server URL and organization name\". This setting affects only OneDrive for Business sync functionality. It does not impact syncing team sites in SharePoint Online.\n\nIf you enable this setting, you can select one of two options:\n\nDisable OIDC Authentication: The Sync app will not attempt to use OIDC authentication for communicating with SharePoint Server, even if the server is configured to support it.\n\nEnable OIDC Authentication: The Sync app will attempt to use OIDC authentication for communicating with SharePoint Server if the server is configured to support it.\n\nIf you disable or do not configure this setting, the Sync app will attempt to use legacy network authentication schemes that the server supports.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_1","displayName":"Enabled","description":null,"helpText":null}]},"1a376a120fe31622":{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport","displayName":"Allow users to contact Microsoft for feedback and support","description":"\r\n This setting specifies whether users in your organization can communicate directly with Microsoft through user experiences in the sync app. Letting users share their thoughts helps us improve OneDrive.\r\n\r\n If you enable or do not configure this setting, users can use the experiences in the OneDrive sync app to contact Microsoft directly for feedback and support.\r\n\r\n If you disable this setting, users will be unable to contact Microsoft for support, feedback, or suggestions within the sync app. Users will still have access to help content and self-help tools.\r\n ","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_1","displayName":"Enabled","description":null,"helpText":null}]},"1af17802dc7dd0ff":{"id":"device_vendor_msft_policy_config_remotemanagement_allowcredsspauthenticationclient","displayName":"Allow CredSSP authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) client uses CredSSP authentication.\n\nIf you enable this policy setting, the WinRM client uses CredSSP authentication.\n\nIf you disable or do not configure this policy setting, the WinRM client does not use CredSSP authentication.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-allowcredsspauthenticationclient"],"categoryId":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","categoryName":"Win RM Client","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_allowcredsspauthenticationclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_allowcredsspauthenticationclient_1","displayName":"Enabled","description":null,"helpText":null}]},"1af187e23b23c5f2":{"id":"device_vendor_msft_policy_config_timelanguagesettings_machineuilanguageoverwrite","displayName":"Machine UI Language Overwrite","description":"This policy setting controls which UI language is used for computers with more than one UI language installed. If you enable this setting, the UI language of Windows menus and dialogs for systems with more than one language is restricted to the machine language.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TimeLanguageSettings#machineuilanguageoverwrite"],"categoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","categoryName":"Time Language Settings","options":[{"id":"device_vendor_msft_policy_config_timelanguagesettings_machineuilanguageoverwrite_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_timelanguagesettings_machineuilanguageoverwrite_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"1af675b80c26fe26":{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customsystemdistrousersettingconfigurable","displayName":"Allow custom system distribution configuration","description":"When set to disabled, this policy disables custom system distribution configuration via .wslconfig (wsl2.systemDistro). This policy only applies to Store WSL.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customsystemdistrousersettingconfigurable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customsystemdistrousersettingconfigurable_1","displayName":"Enabled","description":null,"helpText":null}]},"1a73f689cbe926c3":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},"1aabcb946623a865":{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_disablelockcomputer","displayName":"Remove Lock Computer (User)","description":"This policy setting prevents users from locking the system.\r\n\r\nWhile locked, the desktop is hidden and the system cannot be used. Only the user who locked the system or the system administrator can unlock it.\r\n\r\nIf you enable this policy setting, users cannot lock the computer from the keyboard using Ctrl+Alt+Del.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to lock the computer from the keyboard using Ctrl+Alt+Del.\r\n\r\nTip:To lock a computer without configuring a setting, press Ctrl+Alt+Delete, and then click Lock this computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ctrlaltdel#admx-ctrlaltdel-disablelockcomputer"],"categoryId":"5536b5f4-3d31-4290-acea-9bef323bb83d","categoryName":"Ctrl Alt Del Options","options":[{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_disablelockcomputer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_disablelockcomputer_1","displayName":"Enabled","description":null,"helpText":null}]},"1a3567d3ea308158":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_1","displayName":"Synchronize offline files before suspend (User)","description":"Determines whether offline files are synchonized before a computer is suspended.\r\n\r\nIf you enable this setting, offline files are synchronized whenever the computer is suspended. Setting the synchronization action to \"Quick\" ensures only that all files in the cache are complete. Setting the synchronization action to \"Full\" ensures that all cached files and folders are up-to-date with the most current version.\r\n\r\nIf you disable or do not configuring this setting, files are not synchronized when the computer is suspended.\r\n\r\nNote: If the computer is suspended by closing the display on a portable computer, files are not synchronized. If multiple users are logged on to the computer at the time the computer is suspended, a synchronization is not performed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatsuspend-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_1_1","displayName":"Enabled","description":null,"helpText":null}]},"1a85f71bba326ef6":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace","displayName":"Microsoft SharePoint Workspace 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Workspace 2010.\r\nBy default, the user settings of Microsoft SharePoint Workspace 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Workspace 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Workspace 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Workspace 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointworkspace"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_1","displayName":"Enabled","description":null,"helpText":null}]},"1a1b719e335dae93":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations","displayName":"Determine the availability of variations (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_0","displayName":"Enable all variations","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_1","displayName":"Enable variations concerning critical fixes only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_2","displayName":"Disable all variations","description":null,"helpText":null}]},"1af53a3de5b546e4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode","displayName":"Print Rasterization Mode (User)","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a non-PostScript printer on Microsoft® Windows®, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nWhen this policy is set to Full, Google Chrome will do full page rasterization if necessary.\r\n\r\nWhen this policy is set to Fast, Google Chrome will avoid rasterization if possible, reducing the amount of rasterization can help reduce print job sizes and increase printing speed.\r\n\r\nWhen this policy is not set, Google Chrome will be in Full mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},"1addd2a360d27846":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax","displayName":"Maximum SSL version enabled (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_1","displayName":"Enabled","description":null,"helpText":null}]},"1aff92896ac798fc":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled. (User)","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy. Currently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers. This enterprise policy can be used to opt out of this gradual deprecation by forcing the default to remain as enabled.\r\n\r\nPages may depend on unload event handlers to save data or signal the end of a user session to the server. This is not recommended as it is unreliable and impacts performance by blocking use of BackForwardCache. Recommended alternatives exist, however the unload event has been used for a long time. Some applications may still rely on them.\r\n\r\nIf this policy is set to false or not set, then unload events handlers will be gradually deprecated in-line with the deprecation rollout and sites which do not set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf this policy is set to true then unload event handlers will continue to work by default.\r\n\r\nNOTE: This policy had an incorrectly documented default of `true` in M117. The unload event did and will not change in M117, so this policy has no effect in that version.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1ae70aaa52b6780a":{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate","displayName":"Restricted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsrestrictedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"1ad7bc9c662a74e8":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open additional windows and frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow additional windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open other windows and frames from other domains or access applications from different domains.\n\nIf you do not configure this policy setting, users cannot open other windows and frames from different domains or access applications from different domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszonenavigatewindowsandframes"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"1a7d637bd8034c67":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"1ad66a368df43a10":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, a warning is issued to the user that potentially risky navigation is about to occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowlessprivilegedsites"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"1ad49d6d8da8bf3b":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"1a90097948650077":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_0","displayName":"Automatically imports all supported datatypes and settings from the default browser","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_1","displayName":"Automatically imports all supported datatypes and settings from Internet Explorer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_2","displayName":"Automatically imports all supported datatypes and settings from Google Chrome","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_3","displayName":"Automatically imports all supported datatypes and settings from Safari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_4","displayName":"Disables automatic import, and the import section of the first-run experience is skipped","description":null,"helpText":null}]},"1a35b352937fe3bb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed","displayName":"Allow QUIC protocol (User)","description":"Allows use of the QUIC protocol in Microsoft Edge.\r\n\r\nIf you enable this policy or don't configure it, the QUIC protocol is allowed.\r\n\r\nIf you disable this policy, the QUIC protocol is blocked.\r\n\r\nQUIC is a transport layer network protocol that can improve performance of web applications that currently use TCP.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"1a30331f2624fb44":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended","displayName":"Disable synchronization of data using Microsoft sync services (User)","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1aef2d320c2f7017":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas","displayName":"Allow Save page as in Internet Explorer mode (User)","description":"This policy enables 'Save page as' functionality in Internet Explorer mode.\r\nUsers can use this option to save the current page in the browser. When a user re-opens a saved page, it will be loaded in the default browser.\r\n\r\nIf you enable this policy, the \"Save page as\" option will be clickable in \"More tools\".\r\n\r\nIf you disable or don't configure this policy, users can't select the \"Save page as\" option in \"More tools\".\r\n\r\nNote: To make the \"Ctrl+S\" shortcut work, users must enable the Internet Explorer policy, 'Enable extended hot key in Internet Explorer mode'.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas_1","displayName":"Enabled","description":null,"helpText":null}]},"1af7cef33a8f5916":{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context (User)","description":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that can be used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\r\n\r\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\r\n\r\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\r\n\r\nMicrosoft Edge will require cross-origin isolation when using SharedArrayBuffers from Microsoft Edge 91 onward for Web Compatibility reasons.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"1aeccfec12550e16":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled. (User)","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\r\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\r\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\r\n\r\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\r\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\r\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\r\n\r\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1a6b06c159e0403a":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages (User)","description":"This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site.\r\n\r\nIf you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_1","displayName":"Enabled","description":null,"helpText":null}]},"1a9dd4d6e9fdfc04":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended","displayName":"Configure Edge Website Typo Protection (User)","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\r\n\r\nIf you enable this policy, Edge Website Typo Protection is turned on.\r\n\r\nIf you disable this policy, Edge Website Typo Protection is turned off.\r\n\r\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":"","infoUrls":[],"categoryId":"1ccd3115-55e7-464f-9bb9-d38a92191306","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1a0376e2410930fa":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_tabcaptureallowedbyoriginsdesc","displayName":"Allow Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"1a3cf865788b3dad":{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning_l_ageoutpolicylocalversioningdecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"1a0f2aa77d7b2ee8":{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser","displayName":"Disable local training of all features for the user. (User)","description":"\r\nThis policy setting disables local training of all features for the user.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\nIf a higher priority policy setting is not configured, then:\r\n- If this policy setting is enabled, local training of all features is disabled for the user.\r\n- If this policy setting is disabled, local training of all features is enabled for the user.\r\n- If this policy setting is not configured, local training of all features is enabled for the user.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of [a specific feature] for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of [a specific feature] for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser_1","displayName":"Enabled","description":null,"helpText":null}]},"1aaf639fb7712dcb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceservercapabilities8","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"1a82d3ec4f3e8493":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverterms8","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"1aec58ec298e1e1a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419","displayName":"Error Severity Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_0","displayName":"Errors only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_1","displayName":"Level 1 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_2","displayName":"Level 2 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_3","displayName":"Level 3 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_4","displayName":"All","description":null,"helpText":null}]},"1ab82225a3f1c091":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh","displayName":"Bangla (Bangladesh) (User)","description":"Enables the editing language Bangla (Bangladesh)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh_1","displayName":"Enabled","description":null,"helpText":null}]},"1a6783990919bd1c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips","displayName":"Show Screen Tips (User)","description":"This policy setting allows you to determine whether Office applications display screen tips when users hover on commands on the Office Ribbon, and whether the screen tips display feature names and descriptions, or just feature names. \r\n\r\nIf you enable this policy setting, you can select any of the following options:\r\n- Show feature descriptions: Both feature names and descriptions appear when users hover over commands on the Ribbon. \r\n- Don't show feature descriptions: Only feature names appear when users hover over commands on the Ribbon. \r\n- Don't show screen tips: Nothing appears when users hover over commands on the Ribbon.\r\n\r\nIf you disable this policy setting, nothing appears when users hover over commands on the Office Ribbon.\r\n\r\nIf you do not configure this policy setting, both feature names and descriptions appear when users hover over commands on the Office Ribbon.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},"1a04b52943be05ed":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"1afc7d81f98a6dfb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly","displayName":"End appointments and meetings early (User)","description":"\r\n This policy setting allows you to control whether the end time of appointments and meetings are reduced by a specified number of minutes when a user creates an appointment or meeting.\r\n\r\n If you enable this policy setting, the end time of appointments and meetings are reduced by a specified number of minutes when a user creates an appointment or meeting.\r\n\r\n To specify how many minutes to reduce appointments and meetings by, you can use the “Reduce the end time of short appointments and meetings by a specified number of minutes” and “Reduce the end time of long appointments and meetings by a specified number of minutes” policy settings.\r\n\r\n If you don’t enable those policy settings to specify a time in minutes, users will be able to specify a time, in minutes, by going to File > Options > Calendar. If the user hasn’t specified a time, default values of 5 minutes, for short meetings, and 10 minutes, for long meetings, will be used.\r\n\r\n If you disable this policy setting, appointments and meetings can’t be configured to end early and the option will be disabled under File > Options > Calendar and can’t be enabled by the user.\r\n\r\n If you don’t configure this policy setting, appointments and meetings aren’t configured to end early, but the user can enable appointments and meetings to end early by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly_1","displayName":"Enabled","description":null,"helpText":null}]},"1a0977484fde2a58":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2","displayName":"Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (User)","description":"This policy setting controls what happens when a user designs a custom form in Outlook and attempts to bind an Address Information field to a combination or formula custom field.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access address information using the UserProperties. Find method of the Outlook object model: \r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nIf you disable or do not configure this policy setting, when a user tries to bind an address information field to a combination or formula custom field in a custom form, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"1a1c9bc48a4a9319":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal","displayName":"Automatically download attachments (User)","description":"This policy setting controls whether Outlook downloads files attached to Internet Calendar appointments. \r\n\r\nIf you enable this policy setting, Outlook automatically downloads all Internet Calendar appointment attachments \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not download attachments when retrieving Internet Calendar appointments.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal_1","displayName":"Enabled","description":null,"helpText":null}]},"1a820852532495a7":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation","displayName":"Local Project Cache Location (User)","description":"Sets the location path of the local project cache on the user's computer.","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"1a9c5d68c3b9511d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},"1a6b8a69ee49f599":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},"1a180a6f1ed830e5":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands_l_emailmessageforsendtocommands101","displayName":"Email message for 'Send To' commands (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},"1ada60a11b9cb748":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},"1a9cf7ef14363fb2":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},"1a8c9ea03e9ca518":{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets","displayName":"Enable Log Dropped Packets","description":"This value is used as an on/off switch. If this value is on, the firewall logs all the dropped packets. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets_false","displayName":"Disable Logging Of Dropped Packets","description":"Disable Logging Of Dropped Packets","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets_true","displayName":"Enable Logging Of Dropped Packets","description":"Enable Logging Of Dropped Packets","helpText":null}]}} \ No newline at end of file +{"1a385ab21b7f10e6":{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos","displayName":"Is Default Realm","description":"This property specifies it is the default realm if there is more than one Kerberos extension configuration.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_isdefaultrealm_kerberos_true","displayName":"True","description":null,"helpText":null}]},"1ad58171e1fddf3b":{"id":"com.apple.loginwindow_sleepdisabled","displayName":"Sleep Disabled","description":"If true, disables the Sleep button.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_sleepdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_sleepdisabled_true","displayName":"True","description":null,"helpText":null}]},"1a21c3066f55c325":{"id":"com.apple.managedclient.preferences_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled, even if it's turned off by default","description":"If you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge is not available by default.\n\nIf you set this policy to false, or don't set it, AppCache will follow Microsoft Edge's defaults.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#appcacheforceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_appcacheforceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_appcacheforceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1aea7724f22ae7e4":{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference","displayName":"Allow experiences and functionality that downloads user content","description":"Examples: Office document templates, online 3D models, online videos.","helpText":null,"infoUrls":["https://aka.ms/macoce"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_officeexperiencesdownloadingcontentpreference_true","displayName":"True","description":null,"helpText":null}]},"1a62cdf08591f5ff":{"id":"com.apple.managedclient.preferences_printingenabled","displayName":"Enable printing","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\n\nIf you enable this policy or don't configure it, users can print.\n\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1a9a784b91d78353":{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},"1af9d16d589b1998":{"id":"com.apple.security.firewall_blockallincoming","displayName":"Block All Incoming","description":"If true, enables blocking of all incoming connections. ","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_blockallincoming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_blockallincoming_true","displayName":"True","description":null,"helpText":null}]},"1a3fb1b7bfe49934":{"id":"com.apple.systemconfiguration_proxies_exceptionslist","displayName":"Exceptions List","description":"The list of hosts and domains that should bypass proxy settings.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},"1a64f86aa60e65c9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting","displayName":"Default pop-up window setting","description":"Set whether websites can show pop-up windows. You can allow them on all websites ('AllowPopups') or block them on all sites ('BlockPopups').\n\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\n\nPolicy options mapping:\n\n* AllowPopups (1) = Allow all sites to show pop-ups\n\n* BlockPopups (2) = Do not allow any site to show popups\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting_allowpopups","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultpopupssetting_blockpopups","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},"1a18914aba1aa707":{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site URL patterns that specify sites for which advanced JavaScript optimizations are enabled.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com doesn't correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there's no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top-level origin URL alone; so, for example, if contoso.com is listed in the \"JavaScriptOptimizerAllowedForSites\" policy but contoso.com loads a frame containing fabrikam.com, then contoso.com has JavaScript optimizations enabled, but fabrikam.com uses the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site, then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise Javascript optimization is enabled for the site.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"1adaa4cdd80c74f3":{"id":"com.microsoft.edge.mamedgeappconfigsettings.pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nDefine a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. However, starting in M85, patterns with '*' and '[*.]' wildcards in the host are no longer supported for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"1a0f79f6b8546c8f":{"id":"device_vendor_msft_defender_configuration_excludedipaddresses","displayName":"Excluded Ip Addresses","description":"Allows an administrator to explicitly disable network packet inspection made by wdnisdrv on a particular set of IP addresses.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"1a1abb8cddd7c7af":{"id":"device_vendor_msft_defender_configuration_performancemodestatus","displayName":"Performance Mode Status","description":"This setting allows IT admins to configure performance mode in either enabled or disabled mode for managed devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_performancemodestatus_0","displayName":"Performance mode is enabled (default). A service restart is required after changing this value.","description":"Performance mode is enabled (default). A service restart is required after changing this value.","helpText":null},{"id":"device_vendor_msft_defender_configuration_performancemodestatus_1","displayName":"Performance mode is disabled. A service restart is required after changing this value.","description":"Performance mode is disabled. A service restart is required after changing this value.","helpText":null}]},"1a978487591deaa4":{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled","displayName":"Scan Only If Idle Enabled","description":"In Microsoft Defender Antivirus, this setting will run scheduled scans only if the system is idle.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled_1","displayName":"Runs scheduled scans only if the system is idle.","description":"Runs scheduled scans only if the system is idle.","helpText":null},{"id":"device_vendor_msft_defender_configuration_scanonlyifidleenabled_0","displayName":"Runs scheduled scans regardless of whether the system is idle.","description":"Runs scheduled scans regardless of whether the system is idle.","helpText":null}]},"1a00b5d3ba00e0c5":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthservedforpeers_bits_maxbandwidthservedforpeerslist","displayName":"Maximum network bandwidth used for Peercaching (bps):","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"1a946e70d0119947":{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2","displayName":"Download missing COM components","description":"This policy setting directs the system to search Active Directory for missing Component Object Model (COM) components that a program requires.\r\n\r\nMany Windows programs, such as the MMC snap-ins, use the interfaces provided by the COM components. These programs cannot perform all their functions unless Windows has internally registered the required components.\r\n\r\nIf you enable this policy setting and a component registration is missing, the system searches for it in Active Directory and, if it is found, downloads it. The resulting searches might make some programs start or run slowly.\r\n\r\nIf you disable or do not configure this policy setting, the program continues without the registration. As a result, the program might not perform all its functions, or it might stop.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-com#admx-com-appmgmt-com-searchforclsid-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_com_appmgmt_com_searchforclsid_2_1","displayName":"Enabled","description":null,"helpText":null}]},"1a9601e704265ebc":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx","displayName":"Phone-PC linking on this device","description":"\r\nThis policy allows IT admins to turn off the ability to Link a Phone with a PC to continue reading, emailing and other tasks that requires linking between Phone and PC.\r\n\r\nIf you enable this policy setting, the Windows device will be able to enroll in Phone-PC linking functionality and participate in Continue on PC experiences.\r\n\r\nIf you disable this policy setting, the Windows device is not allowed to be linked to Phones, will remove itself from the device list of any linked Phones, and cannot participate in Continue on PC experiences.\r\n\r\nIf you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablemmx"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablemmx_1","displayName":"Enabled","description":null,"helpText":null}]},"1afcedbdad4fd710":{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport","displayName":"Turn off Windows Error Reporting","description":"This policy setting controls whether or not errors are reported to Microsoft.\r\n\r\nError Reporting is used to report information about a system or application that has failed or has stopped responding and is used to improve the quality of the product.\r\n\r\nIf you enable this policy setting, users are not given the option to report errors.\r\n\r\nIf you disable or do not configure this policy setting, the errors may be reported to Microsoft via the Internet or to a corporate file share.\r\n\r\nThis policy setting overrides any user setting made from the Control Panel for error reporting.\r\n\r\nAlso see the \"Configure Error Reporting\", \"Display Error Notification\" and \"Disable Windows Error Reporting\" policy settings under Computer Configuration/Administrative Templates/Windows Components/Windows Error Reporting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-pch-donotreport"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_pch_donotreport_1","displayName":"Enabled","description":null,"helpText":null}]},"1ac9f2ed5553f5f3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities","description":"Setting the policy turns off enforcement of Certificate Transparency disclosure requirements for a list of Legacy Certificate Authorities (CA) for certificate chains with a specified subjectPublicKeyInfo hash. Enterprise hosts can keep using certificates that otherwise wouldn't be trusted (because they weren't properly publicly disclosed). To turn off enforcement, the subjectPublicKeyInfo hash must appear in a CA certificate recognized as a Legacy CA. A Legacy CA is publicly trusted by one or more operating systems supported by Google Chrome, but not Android Open Source Project or Google Chrome OS.\r\n\r\nSpecify a subjectPublicKeyInfo hash by linking the hash algorithm name, a slash and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. Base64 encoding format matches that of an SPKI Fingerprint. The only recognized hash algorithm is sha256; others are ignored.\r\n\r\nLeaving the policy unset means that if certificates requiring disclosure through Certificate Transparency aren't disclosed, then Google Chrome doesn't trust those certificates.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_1","displayName":"Enabled","description":null,"helpText":null}]},"1a7a0ae537059691":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended","displayName":"Import search engines from default browser on first run","description":"Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1a3c2c803ca1bcf8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled","displayName":"Enable Renderer Code Integrity","description":"Setting the policy to Enabled or leaving it unset turns Renderer Code Integrity on.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's renderer processes. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's renderer processes.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_renderercodeintegrityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1a2a443bc8cda3b0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch","displayName":"Force SafeSearch","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forcesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},"1a6c5916b64f26bf":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_proxyserver","displayName":"Address or URL of proxy server (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"1a8f7afd79a527fb":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter","displayName":"Print Headers and Footers","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},"1ada1f5d476fb806":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS","description":"This policy configures whether Google Chrome will offer a post-quantum key agreement algorithm in TLS, using the ML-KEM NIST standard. Prior to Google Chrome 131, the algorithm was Kyber, an earlier draft iteration of the standard. This allows supporting servers to protect user traffic from being later decrypted by quantum computers.\r\n\r\nIf this policy is Enabled or not set, Google Chrome will offer a post-quantum key agreement in TLS connections. User traffic will then be protected from quantum computers when communicating with compatible servers.\r\n\r\nIf this policy is Disabled, Google Chrome will not offer a post-quantum key agreement in TLS connections. User traffic will then be unprotected from quantum computers.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement TLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or the resulting larger messages. Such devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed sometime after Google Chrome version 145. It may be Enabled to allow you to test for issues, and may be Disabled while issues are being resolved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_postquantumkeyagreementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1afef1de9db42ab0":{"id":"device_vendor_msft_policy_config_connectivity_hardeneduncpaths_pol_hardenedpaths_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"643081a4-132d-463e-9d86-c8650cb2a011","categoryName":"Network Provider","options":null},"1ade5e9af9989d25":{"id":"device_vendor_msft_policy_config_federatedauthentication_enablewebsigninforprimaryuser","displayName":"Enable Web Sign In For Primary User","description":"Specifies whether web-based sign-in is enabled with the Primary User experience","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FederatedAuthentication#enablewebsigninforprimaryuser"],"categoryId":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","categoryName":"Federated Authentication","options":[{"id":"device_vendor_msft_policy_config_federatedauthentication_enablewebsigninforprimaryuser_0","displayName":"Feature defaults as appropriate for edition and device capabilities. As of now, all editions/devices exhibit Disabled behavior by default. However, this may change for future editions/devices.","description":"Feature defaults as appropriate for edition and device capabilities. As of now, all editions/devices exhibit Disabled behavior by default. However, this may change for future editions/devices.","helpText":null},{"id":"device_vendor_msft_policy_config_federatedauthentication_enablewebsigninforprimaryuser_1","displayName":"Enabled. Web Sign-in Credential Provider will be enabled for device sign-in.","description":"Enabled. Web Sign-in Credential Provider will be enabled for device sign-in.","helpText":null},{"id":"device_vendor_msft_policy_config_federatedauthentication_enablewebsigninforprimaryuser_2","displayName":"Disabled. Web Sign-in Credential Provider will be not be enabled for device sign-in.","description":"Disabled. Web Sign-in Credential Provider will be not be enabled for device sign-in.","helpText":null}]},"1a932001ab734cd1":{"id":"device_vendor_msft_policy_config_fileexplorer_turnoffdataexecutionpreventionforexplorer","displayName":"Turn off Data Execution Prevention for Explorer","description":"Disabling data execution prevention can allow certain legacy plug-in applications to function without terminating Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-fileexplorer#fileexplorer-turnoffdataexecutionpreventionforexplorer"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_fileexplorer_turnoffdataexecutionpreventionforexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fileexplorer_turnoffdataexecutionpreventionforexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"1aae6949449f8803":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilessiddirectorynamepattern","displayName":"SID Directory Name Pattern","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies a string pattern used when creating a Profile or ODFC container folder. Use this setting to define how FSLogix will attempt to create a users Profile or ODFC container folder. FSLogix will use the VHDLocations or CCDLocations as the location where to create and this setting defines what to create.\r\n\r\nNOTE: When using this configuration setting, be sure the SIDDIRNameMatch value matches this setting.\r\n\r\n- This setting has NO EFFECT when FlipFlopProfileDirectoryName is enabled.\r\n- This setting has NO EFFECT when NoProfileContainingFolder is enabled.\r\n- NoProfileContainingFolder > FlipFlopProfileDirectoryName > SIDDirNamePattern (this setting)\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\SIDDirNamePattern\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilessiddirectorynamepattern_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilessiddirectorynamepattern_1","displayName":"Enabled","description":null,"helpText":null}]},"1a678f7b6a2a788e":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowaccesstodatasources"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"1a8b775d81017a71":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver","displayName":"Include local path when user is uploading files to a server","description":"This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.\n\nIf you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.\n\nIf you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.\n\nIf you do not configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneincludelocalpathwhenuploadingfilestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},"1a038dbd755b7fea":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"1acada2d4631439d":{"id":"device_vendor_msft_policy_config_kerberos_requirekerberosarmoring","displayName":"Fail authentication requests when Kerberos armoring is not available","description":"This policy setting controls whether a computer requires that Kerberos message exchanges be armored when communicating with a domain controller.\r\n\r\nWarning: When a domain does not support Kerberos armoring by enabling \"Support Dynamic Access Control and Kerberos armoring\", then all authentication for all its users will fail from computers with this policy setting enabled.\r\n\r\nIf you enable this policy setting, the client computers in the domain enforce the use of Kerberos armoring in only authentication service (AS) and ticket-granting service (TGS) message exchanges with the domain controllers. \r\n\r\nNote: The Kerberos Group Policy \"Kerberos client support for claims, compound authentication and Kerberos armoring\" must also be enabled to support Kerberos armoring. \r\n\r\nIf you disable or do not configure this policy setting, the client computers in the domain enforce the use of Kerberos armoring when possible as supported by the target domain.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-kerberos#kerberos-requirekerberosarmoring"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_kerberos_requirekerberosarmoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_requirekerberosarmoring_1","displayName":"Enabled","description":null,"helpText":null}]},"1ac7c766f56fedde":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_devices_preventusersfrominstallingprinterdriverswhenconnectingtosharedprinters","displayName":"Devices Prevent Users From Installing Printer Drivers When Connecting To Shared Printers","description":"Devices: Prevent users from installing printer drivers when connecting to shared printers For a computer to print to a shared printer, the driver for that shared printer must be installed on the local computer. This security setting determines who is allowed to install a printer driver as part of connecting to a shared printer. If this setting is enabled, only Administrators can install a printer driver as part of connecting to a shared printer. If this setting is disabled, any user can install a printer driver as part of connecting to a shared printer. Default on servers: Enabled. Default on workstations: Disabled Notes This setting does not affect the ability to add a local printer. This setting does not affect Administrators.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#devices_preventusersfrominstallingprinterdriverswhenconnectingtosharedprinters"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_devices_preventusersfrominstallingprinterdriverswhenconnectingtosharedprinters_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_devices_preventusersfrominstallingprinterdriverswhenconnectingtosharedprinters_0","displayName":"Disable","description":"Disable","helpText":null}]},"1a04860ee17ab768":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"1a7888a6fa9b4048":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended","displayName":"Enable clipboard suggestions in the address bar","description":"This policy controls whether suggestions based on clipboard content are shown in the address bar suggestion dropdown.\n\nIf you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown.\n\nIf you disable this policy, Microsoft Edge doesn't show suggestions based on clipboard content in the address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1a4f36d0fa1306cb":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsallowedforurls_pluginsallowedforurlsdesc","displayName":"Allow the Adobe Flash plug-in on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"1ab818f9a2e5b1b0":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode","displayName":"Configure proxy server settings","description":"Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.\r\n\r\nIf you choose to never use a proxy server and to always connect directly, all other options are ignored.\r\n\r\nIf you choose to use system proxy settings, all other options are ignored.\r\n\r\nIf you choose to auto detect the proxy server, all other options are ignored.\r\n\r\nIf you choose fixed server proxy mode, you can specify further options in 'ProxyServer' (Configure address or URL of proxy server) and 'Comma-separated list of proxy bypass rules'.\r\n\r\nIf you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.\r\n\r\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\r\n\r\nIf you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.\r\n\r\nIf you don't configure this policy users can choose their own proxy settings.\r\n\r\n* \"direct\" = Never use a proxy\r\n\r\n* \"auto_detect\" = Auto detect proxy settings\r\n\r\n* \"pac_script\" = Use a .pac proxy script\r\n\r\n* \"fixed_servers\" = Use fixed proxy servers\r\n\r\n* \"system\" = Use system proxy settings\r\n\r\nExample value: direct","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxymode_1","displayName":"Enabled","description":null,"helpText":null}]},"1a1c6ce4943a7eeb":{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":null},"1ad63c234b9031e1":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled","displayName":"Enable editing profile in settings","description":"This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page.\r\n\r\nIf you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page.\r\n\r\nIf you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1a35e23eaa04e4b2":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderencodings_recommended_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"1ac039b5e049d813":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\r\n\r\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\r\n\r\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1ac67782056a95f2":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1a13f39e16cecc4f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_mspubexe72","displayName":"mspub.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_mspubexe72_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_mspubexe72_1","displayName":"True","description":null,"helpText":null}]},"1a047a3a72b31b27":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc","displayName":"Enable OpenID Connect (OIDC) authentication for syncing content from an on-prem SharePoint Server using the OneDrive sync app","description":"When enabled, this setting allows the OneDrive sync app (OneDrive.exe) to authenticate requests to an on-premises SharePoint Server using OIDC authentication, if supported by the server. To use this setting, you must also enable \"Specify SharePoint Server URL and organization name\". This setting affects only OneDrive for Business sync functionality. It does not impact syncing team sites in SharePoint Online.\n\nIf you enable this setting, you can select one of two options:\n\nDisable OIDC Authentication: The Sync app will not attempt to use OIDC authentication for communicating with SharePoint Server, even if the server is configured to support it.\n\nEnable OIDC Authentication: The Sync app will attempt to use OIDC authentication for communicating with SharePoint Server if the server is configured to support it.\n\nIf you disable or do not configure this setting, the Sync app will attempt to use legacy network authentication schemes that the server supports.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_1","displayName":"Enabled","description":null,"helpText":null}]},"1a376a120fe31622":{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport","displayName":"Allow users to contact Microsoft for feedback and support","description":"\r\n This setting specifies whether users in your organization can communicate directly with Microsoft through user experiences in the sync app. Letting users share their thoughts helps us improve OneDrive.\r\n\r\n If you enable or do not configure this setting, users can use the experiences in the OneDrive sync app to contact Microsoft directly for feedback and support.\r\n\r\n If you disable this setting, users will be unable to contact Microsoft for support, feedback, or suggestions within the sync app. Users will still have access to help content and self-help tools.\r\n ","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_1","displayName":"Enabled","description":null,"helpText":null}]},"1af17802dc7dd0ff":{"id":"device_vendor_msft_policy_config_remotemanagement_allowcredsspauthenticationclient","displayName":"Allow CredSSP authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) client uses CredSSP authentication.\n\nIf you enable this policy setting, the WinRM client uses CredSSP authentication.\n\nIf you disable or do not configure this policy setting, the WinRM client does not use CredSSP authentication.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-allowcredsspauthenticationclient"],"categoryId":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","categoryName":"Win RM Client","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_allowcredsspauthenticationclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_allowcredsspauthenticationclient_1","displayName":"Enabled","description":null,"helpText":null}]},"1af187e23b23c5f2":{"id":"device_vendor_msft_policy_config_timelanguagesettings_machineuilanguageoverwrite","displayName":"Machine UI Language Overwrite","description":"This policy setting controls which UI language is used for computers with more than one UI language installed. If you enable this setting, the UI language of Windows menus and dialogs for systems with more than one language is restricted to the machine language.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TimeLanguageSettings#machineuilanguageoverwrite"],"categoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","categoryName":"Time Language Settings","options":[{"id":"device_vendor_msft_policy_config_timelanguagesettings_machineuilanguageoverwrite_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_timelanguagesettings_machineuilanguageoverwrite_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"1af675b80c26fe26":{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customsystemdistrousersettingconfigurable","displayName":"Allow custom system distribution configuration","description":"When set to disabled, this policy disables custom system distribution configuration via .wslconfig (wsl2.systemDistro). This policy only applies to Store WSL.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customsystemdistrousersettingconfigurable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customsystemdistrousersettingconfigurable_1","displayName":"Enabled","description":null,"helpText":null}]},"1a73f689cbe926c3":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},"1aabcb946623a865":{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_disablelockcomputer","displayName":"Remove Lock Computer (User)","description":"This policy setting prevents users from locking the system.\r\n\r\nWhile locked, the desktop is hidden and the system cannot be used. Only the user who locked the system or the system administrator can unlock it.\r\n\r\nIf you enable this policy setting, users cannot lock the computer from the keyboard using Ctrl+Alt+Del.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to lock the computer from the keyboard using Ctrl+Alt+Del.\r\n\r\nTip:To lock a computer without configuring a setting, press Ctrl+Alt+Delete, and then click Lock this computer.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ctrlaltdel#admx-ctrlaltdel-disablelockcomputer"],"categoryId":"5536b5f4-3d31-4290-acea-9bef323bb83d","categoryName":"Ctrl Alt Del Options","options":[{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_disablelockcomputer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_disablelockcomputer_1","displayName":"Enabled","description":null,"helpText":null}]},"1a3567d3ea308158":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_1","displayName":"Synchronize offline files before suspend (User)","description":"Determines whether offline files are synchonized before a computer is suspended.\r\n\r\nIf you enable this setting, offline files are synchronized whenever the computer is suspended. Setting the synchronization action to \"Quick\" ensures only that all files in the cache are complete. Setting the synchronization action to \"Full\" ensures that all cached files and folders are up-to-date with the most current version.\r\n\r\nIf you disable or do not configuring this setting, files are not synchronized when the computer is suspended.\r\n\r\nNote: If the computer is suspended by closing the display on a portable computer, files are not synchronized. If multiple users are logged on to the computer at the time the computer is suspended, a synchronization is not performed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatsuspend-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_syncatsuspend_1_1","displayName":"Enabled","description":null,"helpText":null}]},"1a85f71bba326ef6":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace","displayName":"Microsoft SharePoint Workspace 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Workspace 2010.\r\nBy default, the user settings of Microsoft SharePoint Workspace 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Workspace 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Workspace 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Workspace 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointworkspace"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_1","displayName":"Enabled","description":null,"helpText":null}]},"1a1b719e335dae93":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations","displayName":"Determine the availability of variations (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_0","displayName":"Enable all variations","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_1","displayName":"Enable variations concerning critical fixes only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_2","displayName":"Disable all variations","description":null,"helpText":null}]},"1af53a3de5b546e4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode","displayName":"Print Rasterization Mode (User)","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a non-PostScript printer on Microsoft® Windows®, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nWhen this policy is set to Full, Google Chrome will do full page rasterization if necessary.\r\n\r\nWhen this policy is set to Fast, Google Chrome will avoid rasterization if possible, reducing the amount of rasterization can help reduce print job sizes and increase printing speed.\r\n\r\nWhen this policy is not set, Google Chrome will be in Full mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},"1addd2a360d27846":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax","displayName":"Maximum SSL version enabled (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionmax_1","displayName":"Enabled","description":null,"helpText":null}]},"1aff92896ac798fc":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled. (User)","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy. Currently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers. This enterprise policy can be used to opt out of this gradual deprecation by forcing the default to remain as enabled.\r\n\r\nPages may depend on unload event handlers to save data or signal the end of a user session to the server. This is not recommended as it is unreliable and impacts performance by blocking use of BackForwardCache. Recommended alternatives exist, however the unload event has been used for a long time. Some applications may still rely on them.\r\n\r\nIf this policy is set to false or not set, then unload events handlers will be gradually deprecated in-line with the deprecation rollout and sites which do not set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf this policy is set to true then unload event handlers will continue to work by default.\r\n\r\nNOTE: This policy had an incorrectly documented default of `true` in M117. The unload event did and will not change in M117, so this policy has no effect in that version.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1ae70aaa52b6780a":{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate","displayName":"Restricted Sites Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowsrestrictedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowsrestrictedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"1ad7bc9c662a74e8":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains (User)","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open additional windows and frames from other domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow additional windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open other windows and frames from other domains or access applications from different domains.\n\nIf you do not configure this policy setting, users cannot open other windows and frames from different domains or access applications from different domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszonenavigatewindowsandframes"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"1a7d637bd8034c67":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"1ad66a368df43a10":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, a warning is issued to the user that potentially risky navigation is about to occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowlessprivilegedsites"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"1ad49d6d8da8bf3b":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"1a90097948650077":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_0","displayName":"Automatically imports all supported datatypes and settings from the default browser","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_1","displayName":"Automatically imports all supported datatypes and settings from Internet Explorer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_2","displayName":"Automatically imports all supported datatypes and settings from Google Chrome","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_3","displayName":"Automatically imports all supported datatypes and settings from Safari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_autoimportatfirstrun_4","displayName":"Disables automatic import, and the import section of the first-run experience is skipped","description":null,"helpText":null}]},"1a35b352937fe3bb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed","displayName":"Allow QUIC protocol (User)","description":"Allows use of the QUIC protocol in Microsoft Edge.\r\n\r\nIf you enable this policy or don't configure it, the QUIC protocol is allowed.\r\n\r\nIf you disable this policy, the QUIC protocol is blocked.\r\n\r\nQUIC is a transport layer network protocol that can improve performance of web applications that currently use TCP.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"1a30331f2624fb44":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended","displayName":"Disable synchronization of data using Microsoft sync services (User)","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1aef2d320c2f7017":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas","displayName":"Allow Save page as in Internet Explorer mode (User)","description":"This policy enables 'Save page as' functionality in Internet Explorer mode.\r\nUsers can use this option to save the current page in the browser. When a user re-opens a saved page, it will be loaded in the default browser.\r\n\r\nIf you enable this policy, the \"Save page as\" option will be clickable in \"More tools\".\r\n\r\nIf you disable or don't configure this policy, users can't select the \"Save page as\" option in \"More tools\".\r\n\r\nNote: To make the \"Ctrl+S\" shortcut work, users must enable the Internet Explorer policy, 'Enable extended hot key in Internet Explorer mode'.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_internetexplorermodeenablesavepageas_1","displayName":"Enabled","description":null,"helpText":null}]},"1af7cef33a8f5916":{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context (User)","description":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that can be used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\r\n\r\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\r\n\r\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\r\n\r\nMicrosoft Edge will require cross-origin isolation when using SharedArrayBuffers from Microsoft Edge 91 onward for Web Compatibility reasons.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"1aeccfec12550e16":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled. (User)","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\r\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\r\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\r\n\r\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\r\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\r\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\r\n\r\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1a6b06c159e0403a":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages (User)","description":"This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site.\r\n\r\nIf you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_1","displayName":"Enabled","description":null,"helpText":null}]},"1a9dd4d6e9fdfc04":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended","displayName":"Configure Edge Website Typo Protection (User)","description":"This policy setting lets you configure whether to turn on Edge Website Typo Protection. Edge Website Typo Protection provides warning messages to help protect your users from potential typosquatting sites. By default, Edge Website Typo Protection is turned on.\r\n\r\nIf you enable this policy, Edge Website Typo Protection is turned on.\r\n\r\nIf you disable this policy, Edge Website Typo Protection is turned off.\r\n\r\nIf you don't configure this policy, Edge Website Typo Protection is turned on but users can choose whether to use Edge Website Typo Protection.","helpText":"","infoUrls":[],"categoryId":"1ccd3115-55e7-464f-9bb9-d38a92191306","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_recommended~typosquattingchecker_recommended_typosquattingcheckerenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1a0376e2410930fa":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_tabcaptureallowedbyoriginsdesc","displayName":"Allow Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"1a3cf865788b3dad":{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicylocalversioning_l_ageoutpolicylocalversioningdecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"1a0f2aa77d7b2ee8":{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser","displayName":"Disable local training of all features for the user. (User)","description":"\r\nThis policy setting disables local training of all features for the user.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\nIf a higher priority policy setting is not configured, then:\r\n- If this policy setting is enabled, local training of all features is disabled for the user.\r\n- If this policy setting is disabled, local training of all features is enabled for the user.\r\n- If this policy setting is not configured, local training of all features is enabled for the user.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of [a specific feature] for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of [a specific feature] for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletraininguser_1","displayName":"Enabled","description":null,"helpText":null}]},"1aaf639fb7712dcb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceservercapabilities8","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"1a82d3ec4f3e8493":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverterms8","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"1aec58ec298e1e1a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419","displayName":"Error Severity Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_0","displayName":"Errors only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_1","displayName":"Level 1 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_2","displayName":"Level 2 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_3","displayName":"Level 3 warnings and below","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_errorseveritylevel_l_errorseveritylevel419_4","displayName":"All","description":null,"helpText":null}]},"1ab82225a3f1c091":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh","displayName":"Bangla (Bangladesh) (User)","description":"Enables the editing language Bangla (Bangladesh)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_banglabangladesh_1","displayName":"Enabled","description":null,"helpText":null}]},"1a6783990919bd1c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips","displayName":"Show Screen Tips (User)","description":"This policy setting allows you to determine whether Office applications display screen tips when users hover on commands on the Office Ribbon, and whether the screen tips display feature names and descriptions, or just feature names. \r\n\r\nIf you enable this policy setting, you can select any of the following options:\r\n- Show feature descriptions: Both feature names and descriptions appear when users hover over commands on the Ribbon. \r\n- Don't show feature descriptions: Only feature names appear when users hover over commands on the Ribbon. \r\n- Don't show screen tips: Nothing appears when users hover over commands on the Ribbon.\r\n\r\nIf you disable this policy setting, nothing appears when users hover over commands on the Office Ribbon.\r\n\r\nIf you do not configure this policy setting, both feature names and descriptions appear when users hover over commands on the Office Ribbon.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},"1a04b52943be05ed":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog06_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"1afc7d81f98a6dfb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly","displayName":"End appointments and meetings early (User)","description":"\r\n This policy setting allows you to control whether the end time of appointments and meetings are reduced by a specified number of minutes when a user creates an appointment or meeting.\r\n\r\n If you enable this policy setting, the end time of appointments and meetings are reduced by a specified number of minutes when a user creates an appointment or meeting.\r\n\r\n To specify how many minutes to reduce appointments and meetings by, you can use the “Reduce the end time of short appointments and meetings by a specified number of minutes” and “Reduce the end time of long appointments and meetings by a specified number of minutes” policy settings.\r\n\r\n If you don’t enable those policy settings to specify a time in minutes, users will be able to specify a time, in minutes, by going to File > Options > Calendar. If the user hasn’t specified a time, default values of 5 minutes, for short meetings, and 10 minutes, for long meetings, will be used.\r\n\r\n If you disable this policy setting, appointments and meetings can’t be configured to end early and the option will be disabled under File > Options > Calendar and can’t be enabled by the user.\r\n\r\n If you don’t configure this policy setting, appointments and meetings aren’t configured to end early, but the user can enable appointments and meetings to end early by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enableendearly_1","displayName":"Enabled","description":null,"helpText":null}]},"1a0977484fde2a58":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2","displayName":"Configure Outlook object model prompt When accessing the Formula property of a UserProperty object (User)","description":"This policy setting controls what happens when a user designs a custom form in Outlook and attempts to bind an Address Information field to a combination or formula custom field.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access address information using the UserProperties. Find method of the Outlook object model: \r\n\r\n- Prompt user. The user will be prompted to approve every access attempt. \r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended. \r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program. \r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. \r\n\r\nIf you disable or do not configure this policy setting, when a user tries to bind an address information field to a combination or formula custom field in a custom form, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center. ","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomformula_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"1a1c9bc48a4a9319":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal","displayName":"Automatically download attachments (User)","description":"This policy setting controls whether Outlook downloads files attached to Internet Calendar appointments. \r\n\r\nIf you enable this policy setting, Outlook automatically downloads all Internet Calendar appointment attachments \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not download attachments when retrieving Internet Calendar appointments.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_automaticallydownloadenclosureswebcal_1","displayName":"Enabled","description":null,"helpText":null}]},"1a820852532495a7":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation","displayName":"Local Project Cache Location (User)","description":"Sets the location path of the local project cache on the user's computer.","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"1a9c5d68c3b9511d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_l_setcngcipheralgorithmid","displayName":"CNG cipher algorithm: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},"1a6b8a69ee49f599":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc16_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},"1a180a6f1ed830e5":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_emailmessageforsendtocommands_l_emailmessageforsendtocommands101","displayName":"Email message for 'Send To' commands (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},"1ada60a11b9cb748":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},"1a9cf7ef14363fb2":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},"1a8c9ea03e9ca518":{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets","displayName":"Enable Log Dropped Packets","description":"This value is used as an on/off switch. If this value is on, the firewall logs all the dropped packets. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets_false","displayName":"Disable Logging Of Dropped Packets","description":"Disable Logging Of Dropped Packets","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_enablelogdroppedpackets_true","displayName":"Enable Logging Of Dropped Packets","description":"Enable Logging Of Dropped Packets","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/1b.json b/public/intune-definitions/1b.json index 88acc63800e0..3ae4fde27bbb 100644 --- a/public/intune-definitions/1b.json +++ b/public/intune-definitions/1b.json @@ -1 +1 @@ -{"1b4968eea4b67a53":{"id":"com.apple.applicationaccess_allowhostpairing","displayName":"Allow Host Pairing","description":"If false, disables host pairing with the exception of the supervision host. If no supervision host certificate has been configured, all pairing is disabled. Host pairing lets the administrator control if an iOS device can pair with a host Mac or PC. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowhostpairing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowhostpairing_true","displayName":"True","description":null,"helpText":null}]},"1b39db3b46740e55":{"id":"com.apple.applicationaccess_allowrosettausageawareness","displayName":"Allow Rosetta Usage Awareness","description":"If `false`, disables Rosetta usage awareness. When Rosetta usage awareness is active, the device displays a pop-up dialog to the user when launching an app that uses Rosetta. The pop-up dialog indicates that Rosetta will be removed in a future version of the operating system so that the user can contact the app vendor regarding a replacement for the current app.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrosettausageawareness_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrosettausageawareness_true","displayName":"Enabled","description":null,"helpText":null}]},"1b1487b277a43038":{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope","displayName":"LDAP Search Setting Scope","description":"The type of recursion to use in the search. It is one of the following values:\r\n\r\nBase: Only the immediate node that the search base points to.\r\n\r\nOne Level: The node plus its immediate children.\r\n\r\nSubtree: The node plus all children, regardless of depth.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":[{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_0","displayName":"Base","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_1","displayName":"OneLevel","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_2","displayName":"Subtree","description":null,"helpText":null}]},"1b8c03ce83391d1a":{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own.\n\nIf fixing them is possible, it usually requires complex user actions.\n\nEnabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\n\nDisabling this policy means users will have their password manager data untouched, but will experience a broken password manager functionality.\n\nIf the policy is set, users can't override it in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#deletingundecryptablepasswordsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1bab94a4d894451b":{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled","displayName":"Badges Enabled","description":"If true, enables badges for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled_true","displayName":"True","description":null,"helpText":null}]},"1b920643dc53db92":{"id":"com.apple.screensaver_modulename","displayName":"Module Name","description":"The name of the screen saver module.","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},"1b6390eaddaa3c55":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing","description":"If you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories\n\n* AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting_blockfilesystemwrite","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting_askfilesystemwrite","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},"1b89016fe675b4aa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1b6f90af33fcb7cb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1b3584e800dcc880":{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging_encryptioncertificate","displayName":"Provide an encryption certificate to be used by Protected Event Logging. You may provide either:\n\n - The content of a base-64 encoded X.509 certificate\n - The thumbprint of a certificate that can be found in the Local Machine certificate store (usually deployed by PKI infrastructure)\n - The full path to a certificate (can be local, or a remote share)\n - The path to a directory containing a certificate or certificates (can be local, or a remote share)\n - The subject name of a certificate that can be found in the Local Machine certificate store (usually deployed by PKI infrastructure)\n\nThe resulting certificate must have 'Document Encryption' as an enhanced key usage (1.3.6.1.4.1.311.80.1), as well as either Data Encipherment or Key Encipherment key usages enabled.","description":null,"helpText":"","infoUrls":[],"categoryId":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","categoryName":"Event Logging","options":null},"1b858f617b4d3481":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10_1","displayName":"True","description":null,"helpText":null}]},"1b5db5ed482199c1":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_gprefreshrateoffset1","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"1b99c3e79cba649e":{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms","displayName":"Define interoperable Kerberos V5 realm settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"1bf0c9e588d39905":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime","displayName":"Configure local setting override for scheduled quick scan time","description":"This policy setting configures a local override for the configuration of scheduled quick scan time. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverrideschedulequickscantime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime_1","displayName":"Enabled","description":null,"helpText":null}]},"1b126fb5a743bed3":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth","displayName":"Configure server authentication for client","description":"This policy setting allows you to specify whether the client will establish a connection to the RD Session Host server when the client cannot authenticate the RD Session Host server.\r\n\r\nIf you enable this policy setting, you must specify one of the following settings:\r\n\r\nAlways connect, even if authentication fails: The client connects to the RD Session Host server even if the client cannot authenticate the RD Session Host server.\r\n\r\nWarn me if authentication fails: The client attempts to authenticate the RD Session Host server. If the RD Session Host server can be authenticated, the client establishes a connection to the RD Session Host server. If the RD Session Host server cannot be authenticated, the user is prompted to choose whether to connect to the RD Session Host server without authenticating the RD Session Host server.\r\n\r\nDo not connect if authentication fails: The client establishes a connection to the RD Session Host server only if the RD Session Host server can be authenticated.\r\n\r\nIf you disable or do not configure this policy setting, the authentication setting that is specified in Remote Desktop Connection or in the .rdp file determines whether the client establishes a connection to the RD Session Host server when the client cannot authenticate the RD Session Host server.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-auth"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_1","displayName":"Enabled","description":null,"helpText":null}]},"1b3408c0d7f89eb8":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot_package_source_root_prompt","displayName":"Package Source Root","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},"1b12a8cbc1cdd671":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},"1bf61b1dc8b164ec":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled","displayName":"Enable Google Cloud Print proxy","description":"Setting the policy to Enabled or leaving it unset lets Google Chrome act as a proxy between Google Cloud Print and legacy printers connected to the machine. Using their Google Account, users may turn on the cloud print proxy by authentication.\r\n\r\nSetting the policy to Disabled means users can't turn on the proxy, and the machine can't share its printers with Google Cloud Print.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1b5a5efcc8deedba":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_mediacachesize","displayName":"Set media disk cache size: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"1b55e75233644343":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode","displayName":"Extend Flash content setting to all content (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode_1","displayName":"Enabled","description":null,"helpText":null}]},"1bb4956982f78e9f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Local Network Access checks.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessBlockedForUrls, LocalNetworkAccessBlockedForUrls takes precedence.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"1be49e367cb5fb64":{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablewindowspackagemanagerconfiguration","displayName":"Enable Windows Package Manager Configuration","description":"This policy controls whether the Windows Package Manager configuration feature can be used by users.\n\nIf you enable or do not configure this setting, users will be able to use the Windows Package Manager configuration feature.\n\nIf you disable this setting, users will not be able to use the Windows Package Manager configuration feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-enablewindowspackagemanagerconfiguration"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablewindowspackagemanagerconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablewindowspackagemanagerconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},"1b3a3b3e6243cde1":{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdeviceids","displayName":"Allow installation of devices that match any of these device IDs","description":"This policy setting allows you to specify a list of Plug and Play hardware IDs and compatible IDs for devices that Windows is allowed to install. Use this policy setting only when the \"Prevent installation of devices not described by other policy settings\" policy setting is enabled. Other policy settings that prevent device installation take precedence over this one.\r\n\r\nIf you enable this policy setting, Windows is allowed to install or update any device whose Plug and Play hardware ID or compatible ID appears in the list you create, unless another policy setting specifically prevents that installation (for example, the \"Prevent installation of devices that match any of these device IDs\" policy setting, the \"Prevent installation of devices for these device classes\" policy setting, or the \"Prevent installation of removable devices\" policy setting). If you enable this policy setting on a remote desktop server, the policy setting affects redirection of the specified devices from a remote desktop client to the remote desktop server.\r\n\r\nIf you disable or do not configure this policy setting, and no other policy setting describes the device, the \"Prevent installation of devices not described by other policy settings\" policy setting determines whether the device can be installed.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdeviceids_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdeviceids_1","displayName":"Enabled","description":null,"helpText":null}]},"1bafb52d6f159020":{"id":"device_vendor_msft_policy_config_internetexplorer_disableproxychange","displayName":"Prevent changing proxy settings","description":"This policy setting specifies if a user can change proxy settings.\n\nIf you enable this policy setting, the user will not be able to configure proxy settings.\n\nIf you disable or do not configure this policy setting, the user can configure proxy settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableproxychange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableproxychange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableproxychange_1","displayName":"Enabled","description":null,"helpText":null}]},"1b2287d07710277d":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00","displayName":"Java permissions","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},"1bcbf41bbc84f835":{"id":"device_vendor_msft_policy_config_licensing_disallowkmsclientonlineavsvalidation","displayName":"Disallow KMS Client Online AVS Validation","description":"Enabling this setting prevents this computer from sending data to Microsoft regarding its activation state.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Licensing#disallowkmsclientonlineavsvalidation"],"categoryId":"c0204a51-a73c-46a6-8626-deeadcabe6ac","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_licensing_disallowkmsclientonlineavsvalidation_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_licensing_disallowkmsclientonlineavsvalidation_1","displayName":"Allow","description":"Enabled.","helpText":null}]},"1b600f193c12f00a":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions","displayName":"Allow download restrictions","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},"1be939eaba969c1f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions)","description":"Enables user-level installation of native messaging hosts.\r\n\r\nIf you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.\r\n\r\nBy default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},"1bd0506e9784d2fb":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_1","displayName":"Enabled","description":null,"helpText":null}]},"1bb26f2a0039ad39":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_exprwdexe10","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_exprwdexe10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_exprwdexe10_1","displayName":"True","description":null,"helpText":null}]},"1be7fd1a912940d7":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_pptviewexe4","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_pptviewexe4_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_pptviewexe4_1","displayName":"True","description":null,"helpText":null}]},"1b610d1844d778ea":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updateblockversion","displayName":"Prevent Office from being updated to a specific version","description":"\r\n This policy setting allows you to prevent Office from being updated to a specific version, and instead have Office be updated to a different version that you specify.\r\n\r\n If you enable this policy setting, you need to specify both the version to block and the version to update Office to. You list the version to block first and separate the two versions with a colon. You can specify more than one version to block by separating the entries with a vertical bar.\r\n\r\n For example, if you want to block versions 16.0.10326.10000 and 16.0.10326.20000 and have Office updated to version 16.0.10328.10000 instead, you would enter 16.0.10326.10000:16.0.10328.10000|16.0.10326.20000:16.0.10328.10000.\r\n\r\n If the blocked version is already installed, Office will be updated to the other version you've specified.\r\n\r\n Note: if you make a mistake entering the versions, the update won't be blocked. Also, be sure that the installation files for the version that you want to update Office to are available on the update location.\r\n\r\n If you disable or don't configure this policy setting, Office will be updated to whichever more current version is available in the location where Office is configured to get updates from, unless youve specified a version to block by using the Office Deployment Tool.\r\n\r\n Note: This policy setting only applies to Office products that are installed by using Click-to-Run. It doesn't apply to Office products that use Windows Installer (MSI).","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updateblockversion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updateblockversion_1","displayName":"Enabled","description":null,"helpText":null}]},"1b4cb971b8aa6a93":{"id":"device_vendor_msft_policy_config_storage_allowdiskhealthmodelupdates","displayName":"Allow Disk Health Model Updates","description":"Allows disk health model updates. Value type is integer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Storage#allowdiskhealthmodelupdates"],"categoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","categoryName":"Storage","options":[{"id":"device_vendor_msft_policy_config_storage_allowdiskhealthmodelupdates_0","displayName":"Do not allow","description":"Do not allow","helpText":null},{"id":"device_vendor_msft_policy_config_storage_allowdiskhealthmodelupdates_1","displayName":"Allow","description":"Allow","helpText":null}]},"1b7a634d9ba057cc":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_hideavailabletab","displayName":"Hide the Available tab shown in the Visual Studio Installer","description":"This policy determines whether the Available tab in the installer is visible or not. The Available tab contains suggested products that can be installed by the Visual Studio Installer.\r\n\r\nIf set to 1 (enabled), then users will be prevented from seeing the Available Tab, and thus will not have an ability to install new products from the Available Tab using the installer UI. Users will still be able to install products from the command line or directly through the bootstrapper.\r\n\r\nIf set to 0 (disabled) or missing entirely, users will be able to see the Available Tab and freely install new products that are advertised on the installer UI. Note: This is the default behavior.\r\n\r\nThis functionality requires the Visual Studio 2022 version 17.6 installer to be installed on the client machine.\r\n\r\nFor more information, see http://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_hideavailabletab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_hideavailabletab_1","displayName":"Enabled","description":null,"helpText":null}]},"1bc78377d150e04a":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~privacysettings_intellicoderemoteanalysisdisabled","displayName":"Disable IntelliCode custom model training","description":"This policy disables the ability to train custom IntelliCode models for IntelliSense completions.","helpText":"","infoUrls":[],"categoryId":"96277512-3d35-4876-ad74-2d849348799e","categoryName":"Privacy Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~privacysettings_intellicoderemoteanalysisdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~privacysettings_intellicoderemoteanalysisdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1b0c4bee2c063855":{"id":"linux_mdatp_managed_antivirusengine_threattypesettings_item_value","displayName":"Action to take","description":"Action to take when coming across a threat of the type specified in the preceding section.","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_threattypesettings_item_value_0","displayName":"audit","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_threattypesettings_item_value_1","displayName":"block","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_threattypesettings_item_value_2","displayName":"off","description":null,"helpText":null}]},"1b0f5668a9a2bafa":{"id":"settings_item_bluetooth_enabled","displayName":"Enabled","description":"If `true`, enable the Bluetooth setting. If `false`, disable the Bluetooth setting.","helpText":null,"infoUrls":[],"categoryId":"3c7f15ef-a539-411c-93f1-5f97b7bd5519","categoryName":"Bluetooth","options":[{"id":"settings_item_bluetooth_enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"settings_item_bluetooth_enabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1b204963c784fe1e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_pathcolon67","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"1bc0fcbbddf1810e":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_donotshowanchor","displayName":"Do Not Show Anchor (User)","description":"Prevents the anchor window from being displayed when Windows Media Player is in skin mode.\r\n\r\nThis policy hides the anchor window when the Player is in skin mode. In addition, the option on the Player tab in the Player that enables users to choose whether the anchor window displays is not available.\r\n\r\nWhen this policy is not configured or disabled, users can show or hide the anchor window when the Player is in skin mode by using the Player tab in the Player.\r\n\r\nWhen this policy is not configured and the Set and Lock Skin policy is enabled, some options in the anchor window are not available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-donotshowanchor"],"categoryId":"7f461268-0fb6-4247-b6db-52515d42a20e","categoryName":"User Interface","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_donotshowanchor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_donotshowanchor_1","displayName":"Enabled","description":null,"helpText":null}]},"1b1b55454a7ef8c4":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_networkbuffering_bufferingtime","displayName":"Buffering Time (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_networkbuffering_bufferingtime_1","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_networkbuffering_bufferingtime_2","displayName":"Custom","description":null,"helpText":null}]},"1b0a50e7becfc18f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended","displayName":"Import search engines from default browser on first run (User)","description":"Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1b07b3be014cc9cd":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_defaultsearchprovideralternateurlsdesc","displayName":"List of alternate URLs for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"1b934b78167bb658":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"1b6c8149319ddace":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings","displayName":"Tab Compare settings (User)","description":"Tab Compare is an AI-powered tool for comparing information across a user's tabs. As an example, the feature can be offered to the user when multiple tabs with products in a similar category are open.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"1b4c5e63065debc0":{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions","displayName":"Select your choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions_1","displayName":"Go directly to home page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions_2","displayName":"Go directly to \"Welcome To IE\" page","description":null,"helpText":null}]},"1b0467546228f901":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"1b1a9eae23e37102":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled","displayName":"Allows users to edit favorites (User)","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\r\n\r\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1b2ed6359a237c69":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed","displayName":"Allow local MHTML files to open automatically in Internet Explorer mode (User)","description":"This policy controls whether local mht or mhtml files launched from the command line can open automatically in Internet Explorer mode based on the file content without specifying the --ie-mode-file-url command line.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'\r\nand\r\n'InternetExplorerIntegrationLocalFileAllowed' (Allow launching of local files in Internet Explorer mode) is enabled or not configured.\r\n\r\nIf you enable or don't configure this policy, local mht or mhtml files can launch in Microsoft Edge or Internet Explorer mode to best view the file.\r\n\r\nIf you disable this policy, local mht or mhtml files will launch in Microsoft Edge.\r\n\r\nNote that if you use the --ie-mode-file-url command line argument for launching local mht or mhtml files, it takes precedence over how you configured this policy.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"1b52bc6875d5c85a":{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled","displayName":"Control whether TLS 1.3 Early Data is enabled in Microsoft Edge (User)","description":"This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge.\r\n\r\nTLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance.\r\n\r\nEnabled – Microsoft Edge enables TLS 1.3 Early Data.\r\n\r\nDisabled – Microsoft Edge disables TLS 1.3 Early Data.\r\n\r\nNot configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data.\r\n\r\nNOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution.\r\n\r\nThis policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1b52113a6d362d3f":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"1b54db3683e1dc18":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverinfo8","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"1bfa83ccc5225774":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowfriendly436","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"1b6dbdfa4c28b86d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467_1","displayName":"True","description":null,"helpText":null}]},"1b3fa7eadd6f58a3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_l_blockedextensionsole","displayName":"File extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},"1b9e9adbca57d913":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},"1b5aa23e09f0aea7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature","displayName":"Disable Internet Fax feature (User)","description":"This policy setting determines whether users can access the Internet Fax feature in Office 2016 applications. \r\n\r\nIf you enable this policy setting, Office 2016 users cannot send Internet faxes, and the Internet Fax menu item is removed from the Send sub-menu of the Microsoft Office menu. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 users can use the Internet Fax feature.","helpText":"","infoUrls":[],"categoryId":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","categoryName":"Fax","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature_1","displayName":"Enabled","description":null,"helpText":null}]},"1b859ced7d0d1753":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder","displayName":"AutoFit title text to placeholder (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder_1","displayName":"Enabled","description":null,"helpText":null}]},"1b5badd4ee84e067":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"1b9cee9eaa7472c2":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},"1b5e7cbe6c1a3bc1":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},"1b9a1cf7c6304002":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},"1b5a6161dce3ff92":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":null},"1b931be0bd4362bf":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters","displayName":"Ignore punctuation characters (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},"1bfbc84612cefea7":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},"1bd71381c1907352":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteaddressranges","displayName":"Remote Address Ranges","description":"List of remote addresses covered by the rule. Tokens are case insensitive. Valid tokens include:​​​\r\n\r\n\"*\" indicates any remote address. If present, this must be the only token included.\r\n\r\n\"Defaultgateway\"\r\n\"DHCP\"\r\n\"DNS\"\r\n\"WINS\"\r\n\"Intranet\" (supported on Windows versions 1809+)\r\n\"RmtIntranet\" (supported on Windows versions 1809+)\r\n\"Internet\" (supported on Windows versions 1809+)\r\n\"Ply2Renders\" ​(supported on Windows versions 1809+)\r\n\"LocalSubnet\" indicates any local address on the local subnet.\r\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask nor a network prefix is specified, the subnet mask defaults to 255.255.255.255.\r\nA valid IPv6 address.\r\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.\r\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.​\r\n\r\nIf not specified, the default is \"Any address.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},"1bf5ef8958e7ceda":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action","displayName":"Action","description":"Specifies the action the rule enforces:\n0 - Block\n1 - Allow","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action_0","displayName":"Block","description":"Block","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action_1","displayName":"Allow","description":"Allow","helpText":null}]}} \ No newline at end of file +{"1b4968eea4b67a53":{"id":"com.apple.applicationaccess_allowhostpairing","displayName":"Allow Host Pairing","description":"If false, disables host pairing with the exception of the supervision host. If no supervision host certificate has been configured, all pairing is disabled. Host pairing lets the administrator control if an iOS device can pair with a host Mac or PC. Requires a supervised device. Available in iOS 7 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowhostpairing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowhostpairing_true","displayName":"True","description":null,"helpText":null}]},"1b39db3b46740e55":{"id":"com.apple.applicationaccess_allowrosettausageawareness","displayName":"Allow Rosetta Usage Awareness","description":"If `false`, disables Rosetta usage awareness. When Rosetta usage awareness is active, the device displays a pop-up dialog to the user when launching an app that uses Rosetta. The pop-up dialog indicates that Rosetta will be removed in a future version of the operating system so that the user can contact the app vendor regarding a replacement for the current app.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrosettausageawareness_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrosettausageawareness_true","displayName":"Enabled","description":null,"helpText":null}]},"1b1487b277a43038":{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope","displayName":"LDAP Search Setting Scope","description":"The type of recursion to use in the search. It is one of the following values:\r\n\r\nBase: Only the immediate node that the search base points to.\r\n\r\nOne Level: The node plus its immediate children.\r\n\r\nSubtree: The node plus all children, regardless of depth.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":[{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_0","displayName":"Base","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_1","displayName":"OneLevel","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapsearchsettings_item_ldapsearchsettingscope_2","displayName":"Subtree","description":null,"helpText":null}]},"1b8c03ce83391d1a":{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own.\n\nIf fixing them is possible, it usually requires complex user actions.\n\nEnabling this policy or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\n\nDisabling this policy means users will have their password manager data untouched, but will experience a broken password manager functionality.\n\nIf the policy is set, users can't override it in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#deletingundecryptablepasswordsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_deletingundecryptablepasswordsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1bab94a4d894451b":{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled","displayName":"Badges Enabled","description":"If true, enables badges for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_badgesenabled_true","displayName":"True","description":null,"helpText":null}]},"1b920643dc53db92":{"id":"com.apple.screensaver_modulename","displayName":"Module Name","description":"The name of the screen saver module.","helpText":null,"infoUrls":[],"categoryId":"8cefd936-362e-4a24-bc76-e078b6fd13fa","categoryName":"Screensaver","options":null},"1b6390eaddaa3c55":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing","description":"If you set this policy to 3, websites can ask for write access to the host operating system's filesystem using the File System API. If you set this policy to 2, access is denied.\n\nIf you don't set this policy, websites can ask for access. Users can change this setting.\n\nPolicy options mapping:\n\n* BlockFileSystemWrite (2) = Don't allow any site to request write access to files and directories\n\n* AskFileSystemWrite (3) = Allow sites to ask the user to grant write access to files and directories\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting_blockfilesystemwrite","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultfilesystemwriteguardsetting_askfilesystemwrite","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},"1b89016fe675b4aa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.favoritesbarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1b6f90af33fcb7cb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.performancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1b2b96feec929c04":{"id":"contentcaching_parentselectionpolicy","displayName":"Parent Selection Policy","description":"The policy to implement when choosing among more than one configured parent content cache. With every policy, the system skips parent caches that are temporarily unavailable. Allowed values:\n\n- `first-available`: Always use the first available parent in the Parents list. Use this policy to designate permanent primary, secondary, and subsequent parents.\n- `url-path-hash`: Hash the path part of the requested URL so that the same parent is always used for the same URL. This is useful for maximizing the size of the combined caches of the parents.\n- `random`: Choose a parent at random. Use this policy for load balancing.\n- `round-robin`: Rotate through the parents in order. Use this policy for load balancing.\n- `sticky-available`: Use the first available parent in the Parents list until it becomes unavailable, then advance to the next one. Use this policy for designating floating primary, secondary, and subsequent parents.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_parentselectionpolicy_0","displayName":"first-available","description":null,"helpText":null},{"id":"contentcaching_parentselectionpolicy_1","displayName":"url-path-hash","description":null,"helpText":null},{"id":"contentcaching_parentselectionpolicy_2","displayName":"random","description":null,"helpText":null},{"id":"contentcaching_parentselectionpolicy_3","displayName":"round-robin","description":null,"helpText":null},{"id":"contentcaching_parentselectionpolicy_4","displayName":"sticky-available","description":null,"helpText":null}]},"1b3584e800dcc880":{"id":"device_vendor_msft_policy_config_admx_eventlogging_enableprotectedeventlogging_encryptioncertificate","displayName":"Provide an encryption certificate to be used by Protected Event Logging. You may provide either:\n\n - The content of a base-64 encoded X.509 certificate\n - The thumbprint of a certificate that can be found in the Local Machine certificate store (usually deployed by PKI infrastructure)\n - The full path to a certificate (can be local, or a remote share)\n - The path to a directory containing a certificate or certificates (can be local, or a remote share)\n - The subject name of a certificate that can be found in the Local Machine certificate store (usually deployed by PKI infrastructure)\n\nThe resulting certificate must have 'Document Encryption' as an enhanced key usage (1.3.6.1.4.1.311.80.1), as well as either Data Encipherment or Key Encipherment key usages enabled.","description":null,"helpText":"","infoUrls":[],"categoryId":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","categoryName":"Event Logging","options":null},"1b858f617b4d3481":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nobackground10_1","displayName":"True","description":null,"helpText":null}]},"1b5db5ed482199c1":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrate_gprefreshrateoffset1","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"1b99c3e79cba649e":{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms","displayName":"Define interoperable Kerberos V5 realm settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"1bf0c9e588d39905":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime","displayName":"Configure local setting override for scheduled quick scan time","description":"This policy setting configures a local override for the configuration of scheduled quick scan time. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverrideschedulequickscantime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverrideschedulequickscantime_1","displayName":"Enabled","description":null,"helpText":null}]},"1b126fb5a743bed3":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth","displayName":"Configure server authentication for client","description":"This policy setting allows you to specify whether the client will establish a connection to the RD Session Host server when the client cannot authenticate the RD Session Host server.\r\n\r\nIf you enable this policy setting, you must specify one of the following settings:\r\n\r\nAlways connect, even if authentication fails: The client connects to the RD Session Host server even if the client cannot authenticate the RD Session Host server.\r\n\r\nWarn me if authentication fails: The client attempts to authenticate the RD Session Host server. If the RD Session Host server can be authenticated, the client establishes a connection to the RD Session Host server. If the RD Session Host server cannot be authenticated, the user is prompted to choose whether to connect to the RD Session Host server without authenticating the RD Session Host server.\r\n\r\nDo not connect if authentication fails: The client establishes a connection to the RD Session Host server only if the RD Session Host server can be authenticated.\r\n\r\nIf you disable or do not configure this policy setting, the authentication setting that is specified in Remote Desktop Connection or in the .rdp file determines whether the client establishes a connection to the RD Session Host server when the client cannot authenticate the RD Session Host server.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-auth"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_auth_1","displayName":"Enabled","description":null,"helpText":null}]},"1b3408c0d7f89eb8":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackagesourceroot_package_source_root_prompt","displayName":"Package Source Root","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},"1b12a8cbc1cdd671":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},"1bf61b1dc8b164ec":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled","displayName":"Enable Google Cloud Print proxy","description":"Setting the policy to Enabled or leaving it unset lets Google Chrome act as a proxy between Google Cloud Print and legacy printers connected to the machine. Using their Google Account, users may turn on the cloud print proxy by authentication.\r\n\r\nSetting the policy to Disabled means users can't turn on the proxy, and the machine can't share its printers with Google Cloud Print.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1b5a5efcc8deedba":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_mediacachesize","displayName":"Set media disk cache size: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"1b55e75233644343":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode","displayName":"Extend Flash content setting to all content (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_runallflashinallowmode_1","displayName":"Enabled","description":null,"helpText":null}]},"1bb4956982f78e9f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Local Network Access checks.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessBlockedForUrls, LocalNetworkAccessBlockedForUrls takes precedence.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"1be49e367cb5fb64":{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablewindowspackagemanagerconfiguration","displayName":"Enable Windows Package Manager Configuration","description":"This policy controls whether the Windows Package Manager configuration feature can be used by users.\n\nIf you enable or do not configure this setting, users will be able to use the Windows Package Manager configuration feature.\n\nIf you disable this setting, users will not be able to use the Windows Package Manager configuration feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-enablewindowspackagemanagerconfiguration"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablewindowspackagemanagerconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablewindowspackagemanagerconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},"1b3a3b3e6243cde1":{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdeviceids","displayName":"Allow installation of devices that match any of these device IDs","description":"This policy setting allows you to specify a list of Plug and Play hardware IDs and compatible IDs for devices that Windows is allowed to install. Use this policy setting only when the \"Prevent installation of devices not described by other policy settings\" policy setting is enabled. Other policy settings that prevent device installation take precedence over this one.\r\n\r\nIf you enable this policy setting, Windows is allowed to install or update any device whose Plug and Play hardware ID or compatible ID appears in the list you create, unless another policy setting specifically prevents that installation (for example, the \"Prevent installation of devices that match any of these device IDs\" policy setting, the \"Prevent installation of devices for these device classes\" policy setting, or the \"Prevent installation of removable devices\" policy setting). If you enable this policy setting on a remote desktop server, the policy setting affects redirection of the specified devices from a remote desktop client to the remote desktop server.\r\n\r\nIf you disable or do not configure this policy setting, and no other policy setting describes the device, the \"Prevent installation of devices not described by other policy settings\" policy setting determines whether the device can be installed.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdeviceids_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdeviceids_1","displayName":"Enabled","description":null,"helpText":null}]},"1bafb52d6f159020":{"id":"device_vendor_msft_policy_config_internetexplorer_disableproxychange","displayName":"Prevent changing proxy settings","description":"This policy setting specifies if a user can change proxy settings.\n\nIf you enable this policy setting, the user will not be able to configure proxy settings.\n\nIf you disable or do not configure this policy setting, the user can configure proxy settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableproxychange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableproxychange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableproxychange_1","displayName":"Enabled","description":null,"helpText":null}]},"1b2287d07710277d":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00","displayName":"Java permissions","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},"1bcbf41bbc84f835":{"id":"device_vendor_msft_policy_config_licensing_disallowkmsclientonlineavsvalidation","displayName":"Disallow KMS Client Online AVS Validation","description":"Enabling this setting prevents this computer from sending data to Microsoft regarding its activation state.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Licensing#disallowkmsclientonlineavsvalidation"],"categoryId":"c0204a51-a73c-46a6-8626-deeadcabe6ac","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_licensing_disallowkmsclientonlineavsvalidation_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_licensing_disallowkmsclientonlineavsvalidation_1","displayName":"Allow","description":"Enabled.","helpText":null}]},"1b600f193c12f00a":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions","displayName":"Allow download restrictions","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},"1be939eaba969c1f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions)","description":"Enables user-level installation of native messaging hosts.\r\n\r\nIf you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.\r\n\r\nBy default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},"1bd0506e9784d2fb":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~printing_printingwebpagelayout_1","displayName":"Enabled","description":null,"helpText":null}]},"1bb26f2a0039ad39":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_exprwdexe10","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_exprwdexe10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_exprwdexe10_1","displayName":"True","description":null,"helpText":null}]},"1be7fd1a912940d7":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_pptviewexe4","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_pptviewexe4_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_pptviewexe4_1","displayName":"True","description":null,"helpText":null}]},"1b610d1844d778ea":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updateblockversion","displayName":"Prevent Office from being updated to a specific version","description":"\r\n This policy setting allows you to prevent Office from being updated to a specific version, and instead have Office be updated to a different version that you specify.\r\n\r\n If you enable this policy setting, you need to specify both the version to block and the version to update Office to. You list the version to block first and separate the two versions with a colon. You can specify more than one version to block by separating the entries with a vertical bar.\r\n\r\n For example, if you want to block versions 16.0.10326.10000 and 16.0.10326.20000 and have Office updated to version 16.0.10328.10000 instead, you would enter 16.0.10326.10000:16.0.10328.10000|16.0.10326.20000:16.0.10328.10000.\r\n\r\n If the blocked version is already installed, Office will be updated to the other version you've specified.\r\n\r\n Note: if you make a mistake entering the versions, the update won't be blocked. Also, be sure that the installation files for the version that you want to update Office to are available on the update location.\r\n\r\n If you disable or don't configure this policy setting, Office will be updated to whichever more current version is available in the location where Office is configured to get updates from, unless youve specified a version to block by using the Office Deployment Tool.\r\n\r\n Note: This policy setting only applies to Office products that are installed by using Click-to-Run. It doesn't apply to Office products that use Windows Installer (MSI).","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updateblockversion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updateblockversion_1","displayName":"Enabled","description":null,"helpText":null}]},"1b4cb971b8aa6a93":{"id":"device_vendor_msft_policy_config_storage_allowdiskhealthmodelupdates","displayName":"Allow Disk Health Model Updates","description":"Allows disk health model updates. Value type is integer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Storage#allowdiskhealthmodelupdates"],"categoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","categoryName":"Storage","options":[{"id":"device_vendor_msft_policy_config_storage_allowdiskhealthmodelupdates_0","displayName":"Do not allow","description":"Do not allow","helpText":null},{"id":"device_vendor_msft_policy_config_storage_allowdiskhealthmodelupdates_1","displayName":"Allow","description":"Allow","helpText":null}]},"1b7a634d9ba057cc":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_hideavailabletab","displayName":"Hide the Available tab shown in the Visual Studio Installer","description":"This policy determines whether the Available tab in the installer is visible or not. The Available tab contains suggested products that can be installed by the Visual Studio Installer.\r\n\r\nIf set to 1 (enabled), then users will be prevented from seeing the Available Tab, and thus will not have an ability to install new products from the Available Tab using the installer UI. Users will still be able to install products from the command line or directly through the bootstrapper.\r\n\r\nIf set to 0 (disabled) or missing entirely, users will be able to see the Available Tab and freely install new products that are advertised on the installer UI. Note: This is the default behavior.\r\n\r\nThis functionality requires the Visual Studio 2022 version 17.6 installer to be installed on the client machine.\r\n\r\nFor more information, see http://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_hideavailabletab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_hideavailabletab_1","displayName":"Enabled","description":null,"helpText":null}]},"1bc78377d150e04a":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~privacysettings_intellicoderemoteanalysisdisabled","displayName":"Disable IntelliCode custom model training","description":"This policy disables the ability to train custom IntelliCode models for IntelliSense completions.","helpText":"","infoUrls":[],"categoryId":"96277512-3d35-4876-ad74-2d849348799e","categoryName":"Privacy Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~privacysettings_intellicoderemoteanalysisdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~privacysettings_intellicoderemoteanalysisdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1b0c4bee2c063855":{"id":"linux_mdatp_managed_antivirusengine_threattypesettings_item_value","displayName":"Action to take","description":"Action to take when coming across a threat of the type specified in the preceding section.","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_threattypesettings_item_value_0","displayName":"audit","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_threattypesettings_item_value_1","displayName":"block","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_threattypesettings_item_value_2","displayName":"off","description":null,"helpText":null}]},"1b0f5668a9a2bafa":{"id":"settings_item_bluetooth_enabled","displayName":"Enabled","description":"If `true`, enable the Bluetooth setting. If `false`, disable the Bluetooth setting.","helpText":null,"infoUrls":[],"categoryId":"3c7f15ef-a539-411c-93f1-5f97b7bd5519","categoryName":"Bluetooth","options":[{"id":"settings_item_bluetooth_enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"settings_item_bluetooth_enabled_true","displayName":"Enabled","description":null,"helpText":null}]},"1b204963c784fe1e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_pathcolon67","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"1bc0fcbbddf1810e":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_donotshowanchor","displayName":"Do Not Show Anchor (User)","description":"Prevents the anchor window from being displayed when Windows Media Player is in skin mode.\r\n\r\nThis policy hides the anchor window when the Player is in skin mode. In addition, the option on the Player tab in the Player that enables users to choose whether the anchor window displays is not available.\r\n\r\nWhen this policy is not configured or disabled, users can show or hide the anchor window when the Player is in skin mode by using the Player tab in the Player.\r\n\r\nWhen this policy is not configured and the Set and Lock Skin policy is enabled, some options in the anchor window are not available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-donotshowanchor"],"categoryId":"7f461268-0fb6-4247-b6db-52515d42a20e","categoryName":"User Interface","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_donotshowanchor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_donotshowanchor_1","displayName":"Enabled","description":null,"helpText":null}]},"1b1b55454a7ef8c4":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_networkbuffering_bufferingtime","displayName":"Buffering Time (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_networkbuffering_bufferingtime_1","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_networkbuffering_bufferingtime_2","displayName":"Custom","description":null,"helpText":null}]},"1b0a50e7becfc18f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended","displayName":"Import search engines from default browser on first run (User)","description":"Setting the policy to Enabled imports the default search engine from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the default search engine isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the default search engine checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"1b07b3be014cc9cd":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_defaultsearchprovideralternateurlsdesc","displayName":"List of alternate URLs for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"1b934b78167bb658":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"1b6c8149319ddace":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings","displayName":"Tab Compare settings (User)","description":"Tab Compare is an AI-powered tool for comparing information across a user's tabs. As an example, the feature can be offered to the user when multiple tabs with products in a similar category are open.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_tabcomparesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"1b4c5e63065debc0":{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions","displayName":"Select your choice (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions_1","displayName":"Go directly to home page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_firstrunoptions_2","displayName":"Go directly to \"Welcome To IE\" page","description":null,"helpText":null}]},"1b0467546228f901":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"1b1a9eae23e37102":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled","displayName":"Allows users to edit favorites (User)","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\r\n\r\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1b2ed6359a237c69":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed","displayName":"Allow local MHTML files to open automatically in Internet Explorer mode (User)","description":"This policy controls whether local mht or mhtml files launched from the command line can open automatically in Internet Explorer mode based on the file content without specifying the --ie-mode-file-url command line.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'\r\nand\r\n'InternetExplorerIntegrationLocalFileAllowed' (Allow launching of local files in Internet Explorer mode) is enabled or not configured.\r\n\r\nIf you enable or don't configure this policy, local mht or mhtml files can launch in Microsoft Edge or Internet Explorer mode to best view the file.\r\n\r\nIf you disable this policy, local mht or mhtml files will launch in Microsoft Edge.\r\n\r\nNote that if you use the --ie-mode-file-url command line argument for launching local mht or mhtml files, it takes precedence over how you configured this policy.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_internetexplorerintegrationlocalmhtfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"1b52bc6875d5c85a":{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled","displayName":"Control whether TLS 1.3 Early Data is enabled in Microsoft Edge (User)","description":"This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge.\r\n\r\nTLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance.\r\n\r\nEnabled – Microsoft Edge enables TLS 1.3 Early Data.\r\n\r\nDisabled – Microsoft Edge disables TLS 1.3 Early Data.\r\n\r\nNot configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data.\r\n\r\nNOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution.\r\n\r\nThis policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge_tls13earlydataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"1b52113a6d362d3f":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"1b54db3683e1dc18":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceserverinfo8","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"1bfa83ccc5225774":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowfriendly436","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"1b6dbdfa4c28b86d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467","displayName":"Workflow requires the user to sign the document (Word/Excel only) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowsig467_1","displayName":"True","description":null,"helpText":null}]},"1b3fa7eadd6f58a3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_l_blockedextensionsole","displayName":"File extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},"1b9e9adbca57d913":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},"1b5aa23e09f0aea7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature","displayName":"Disable Internet Fax feature (User)","description":"This policy setting determines whether users can access the Internet Fax feature in Office 2016 applications. \r\n\r\nIf you enable this policy setting, Office 2016 users cannot send Internet faxes, and the Internet Fax menu item is removed from the Send sub-menu of the Microsoft Office menu. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 users can use the Internet Fax feature.","helpText":"","infoUrls":[],"categoryId":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","categoryName":"Fax","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_services~l_fax_l_disablefaxoverinternetfeature_1","displayName":"Enabled","description":null,"helpText":null}]},"1b859ced7d0d1753":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder","displayName":"AutoFit title text to placeholder (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b792508d-da03-4174-bcf1-666d128ee8ad","categoryName":"AutoFormat as you type","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing~l_autoformatasyoutype_l_autofittitletexttoplaceholder_1","displayName":"Enabled","description":null,"helpText":null}]},"1b5badd4ee84e067":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_powerpoint972003presentationsshowstemplatesandaddinfiles_l_powerpoint972003presentationsshowstemplatesandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"1b9cee9eaa7472c2":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_allowsubfolders23_1","displayName":"True","description":null,"helpText":null}]},"1b5e7cbe6c1a3bc1":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},"1b9a1cf7c6304002":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":null},"1b5a6161dce3ff92":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys100_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":null},"1b931be0bd4362bf":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters","displayName":"Ignore punctuation characters (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_ignorepunctuationcharacters_1","displayName":"Enabled","description":null,"helpText":null}]},"1bfbc84612cefea7":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},"1bd71381c1907352":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteaddressranges","displayName":"Remote Address Ranges","description":"List of remote addresses covered by the rule. Tokens are case insensitive. Valid tokens include:​​​\r\n\r\n\"*\" indicates any remote address. If present, this must be the only token included.\r\n\r\n\"Defaultgateway\"\r\n\"DHCP\"\r\n\"DNS\"\r\n\"WINS\"\r\n\"Intranet\" (supported on Windows versions 1809+)\r\n\"RmtIntranet\" (supported on Windows versions 1809+)\r\n\"Internet\" (supported on Windows versions 1809+)\r\n\"Ply2Renders\" ​(supported on Windows versions 1809+)\r\n\"LocalSubnet\" indicates any local address on the local subnet.\r\nA subnet can be specified using either the subnet mask or network prefix notation. If neither a subnet mask nor a network prefix is specified, the subnet mask defaults to 255.255.255.255.\r\nA valid IPv6 address.\r\nAn IPv4 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.\r\nAn IPv6 address range in the format of \"start address - end address\" with no spaces included, where the start address is less than the end address.​\r\n\r\nIf not specified, the default is \"Any address.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},"1bf5ef8958e7ceda":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action","displayName":"Action","description":"Specifies the action the rule enforces:\n0 - Block\n1 - Allow","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action_0","displayName":"Block","description":"Block","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_action_1","displayName":"Allow","description":"Allow","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/20.json b/public/intune-definitions/20.json index e6c7508ac719..d83c19aa236d 100644 --- a/public/intune-definitions/20.json +++ b/public/intune-definitions/20.json @@ -1 +1 @@ -{"20aaa0ad5797489b":{"id":"ade_setupassistant_tvhomescreensync","displayName":"TV Home Screen Sync","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tvhomescreensync_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tvhomescreensync_1","displayName":"Show","description":null,"helpText":null}]},"20a12f0bd2b0a56d":{"id":"app_allowed_deniedbinaries","displayName":"Denied Binaries","description":"If present, the device doesn't allow binaries that match the binary identifier properties to run. A binary only matches when all the binary identifiers match.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},"20c4e60373c0ce19":{"id":"com.apple.applicationaccess_allowtimemachinebackup","displayName":"Allow Time Machine Backup","description":"If 'false', prevents modification of Time Machine settings in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowtimemachinebackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowtimemachinebackup_true","displayName":"True","description":null,"helpText":null}]},"2007a54fd9a7bd1a":{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming","displayName":"Allowed Protocol Mask In Domestic Roaming","description":"The supported Internet Protocol versions while roaming domestically. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_2","displayName":"Both","description":null,"helpText":null}]},"209a95535f2dac73":{"id":"com.apple.extensiblesso_extensiondata_generickey_string","displayName":"Value","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"20ca742e214e7518":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_application id","displayName":"OneDrive Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"20976707bc592d9b":{"id":"com.apple.managedclient.preferences_extendedlogging","displayName":"Enable extended logging","description":"Write verbose logging events to /Library/Logs/Microsoft/autoupdate.log","helpText":null,"infoUrls":["https://macadmins.software/docs/MAU_38.pdf"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_extendedlogging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extendedlogging_true","displayName":"True","description":null,"helpText":null}]},"200446d200ea2d6c":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed","displayName":"Allowed","description":"If 'true', access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed_true","displayName":"Allowed","description":null,"helpText":null}]},"20ecaa63f2739dc8":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"20272e80bbb375af":{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled","description":"This policy lets you configure support for CORS non-wildcard request headers.\n\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header is explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. For more information, see https://go.microsoft.com/fwlink/?linkid=2180022.\n\nIf you enable or don't configure the policy, Microsoft Edge supports the CORS non-wildcard request headers and behaves as previously described.\n\nIf you disable this policy, Microsoft Edge allows the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\n\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's planned to be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport_true","displayName":"Enabled","description":null,"helpText":null}]},"20c48e78f87ee72a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled","displayName":"Enable preload of the new tab page for faster rendering","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"20318f66b30d72f6":{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended","displayName":"Enables Microsoft Edge mini menu (users can override)","description":"Enables the Microsoft Edge mini menu on websites and PDFs. The mini menu appears when users select text and provides basic actions like Copy and smart actions such as Definitions.\n\nIf you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu.\n\nIf you disable this policy, the mini menu doesn't appear when users select text on websites or PDFs.\n\nNote: Starting in Microsoft Edge for Mac version 143, this policy is obsolete because the mini menu feature is removed on Mac.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"20cdb3f3d9395b6b":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_23","displayName":"11 PM","description":null,"helpText":null}]},"201cf4d1096b9e1b":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighprioritylimit","displayName":"High Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"206616129f1adf03":{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen","displayName":"Force a specific default lock screen and logon image","description":"This setting allows you to force a specific default lock screen and logon image by entering the path (location) of the image file. The same image will be used for both the lock and logon screens.\r\n\r\nThis setting lets you specify the default lock screen and logon image shown when no user is signed in, and also sets the specified image as the default for all users (it replaces the inbox default image).\r\n\r\nTo use this setting, type the fully qualified path and name of the file that stores the default lock screen and logon image. You can type a local path, such as C:\\Windows\\Web\\Screen\\img104.jpg or a UNC path, such as \\\\Server\\Share\\Corp.jpg.\r\n\r\nThis can be used in conjunction with the \"Prevent changing lock screen and logon image\" setting to always force the specified lock screen and logon image to be shown.\r\n\r\nNote: This setting only applies to Enterprise, Education, and Server SKUs.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-forcedefaultlockscreen"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_1","displayName":"Enabled","description":null,"helpText":null}]},"20c11cb28d455182":{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy","displayName":"Disk Diagnostic: Configure execution level","description":"This policy setting determines the execution level for S.M.A.R.T.-based disk diagnostics. \r\n\r\nSelf-Monitoring And Reporting Technology (S.M.A.R.T.) is a standard mechanism for storage devices to report faults to Windows. A disk that reports a S.M.A.R.T. fault may need to be repaired or replaced. The Diagnostic Policy Service (DPS) detects and logs S.M.A.R.T. faults to the event log when they occur. \r\n\r\nIf you enable this policy setting, the DPS also warns users of S.M.A.R.T. faults and guides them through backup and recovery to minimize potential data loss. \r\n\r\nIf you disable this policy, S.M.A.R.T. faults are still detected and logged, but no corrective action is taken. \r\n\r\nIf you do not configure this policy setting, the DPS enables S.M.A.R.T. fault resolution by default. \r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured. \r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately. \r\n\r\nThis policy setting takes effect only when the DPS is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console. \r\n\r\nNote: For Windows Server systems, this policy setting applies only if the Desktop Experience optional component is installed and the Remote Desktop Services role is not installed. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskdiagnostic#admx-diskdiagnostic-wdiscenarioexecutionpolicy"],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":[{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"202542a6b459c021":{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality","displayName":"Enable / disable TXF deprecated features","description":"TXF deprecated features included savepoints, secondary RM, miniversion and roll forward. Please enable it if you want to use the APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-txfdeprecatedfunctionality"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality_1","displayName":"Enabled","description":null,"helpText":null}]},"207eaf94b764ce6c":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_exclusions_pathslist","displayName":"Path Exclusions","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},"204c995225d5c321":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation","displayName":"NtfsDisable8dot3NameCreation","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_0","displayName":"Enable 8Dot3 Creation on all Volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_1","displayName":"Disable 8Dot3 Creation on all Volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_2","displayName":"Set 8dot3 name creation per volume using FSUTIL","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_3","displayName":"Disable 8Dot3 name creation on all volumes except system volume","description":null,"helpText":null}]},"20b0b2d279a2fed6":{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2","displayName":"Low battery notification level","description":"This policy setting specifies the percentage of battery capacity remaining that triggers the low battery notification action.\r\n\r\nIf you enable this policy setting, you must enter a numeric value (percentage) to set the battery level that triggers the low notification.\r\n\r\nTo set the action that is triggered, see the \"Low Battery Notification Action\" policy setting.\r\n\r\nIf you disable this policy setting or do not configure it, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargelevel1-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_1","displayName":"Enabled","description":null,"helpText":null}]},"20b5d889362e9ffe":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv","displayName":"Guaranteed service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_1","displayName":"Enabled","description":null,"helpText":null}]},"20c9ba0663dcda87":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality","displayName":"Configure image quality for RemoteFX Adaptive Graphics","description":"This policy setting allows you to specify the visual quality for remote users when connecting to this computer by using Remote Desktop Connection. You can use this policy setting to balance the network bandwidth usage with the visual quality that is delivered.\r\n If you enable this policy setting and set quality to Low, RemoteFX Adaptive Graphics uses an encoding mechanism that results in low quality images. This mode consumes the lowest amount of network bandwidth of the quality modes.\r\n If you enable this policy setting and set quality to Medium, RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images. This mode provides better graphics quality than low quality and uses less bandwidth than high quality.\r\n If you enable this policy setting and set quality to High, RemoteFX Adaptive Graphics uses an encoding mechanism that results in high quality images and consumes moderate network bandwidth.\r\n If you enable this policy setting and set quality to Lossless, RemoteFX Adaptive Graphics uses lossless encoding. In this mode, the color integrity of the graphics data is not impacted. However, this setting results in a significant increase in network bandwidth consumption. We recommend that you set this for very specific cases only.\r\n If you disable or do not configure this policy setting, RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-image-quality"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_1","displayName":"Enabled","description":null,"helpText":null}]},"20ae54551f31dccb":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp","displayName":"Optimize visual experience for Remote Desktop Service Sessions","description":"This policy setting allows you to specify the visual experience that remote users receive in Remote Desktop Services sessions. Remote sessions on the remote computer are then optimized to support this visual experience.\r\n\r\nBy default, Remote Desktop Services sessions are optimized for rich multimedia, such as applications that use Silverlight or Windows Presentation Foundation.\r\n\r\nIf you enable this policy setting, you must select the visual experience for which you want to optimize Remote Desktop Services sessions. You can select either Rich multimedia or Text.\r\n\r\nIf you disable or do not configure this policy setting, Remote Desktop Services sessions are optimized for rich multimedia.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-visexp"],"categoryId":"b7bde490-eac6-4f57-8808-e0786b8191a1","categoryName":"Remote FX for Windows Server 2008 R2","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_1","displayName":"Enabled","description":null,"helpText":null}]},"2071f0523f3b7e1f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled","displayName":"Enable JavaScript","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"20daa97ce8cbbe9d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_1","displayName":"Enabled","description":null,"helpText":null}]},"2068d43d7a79de0e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy","displayName":"Use a default referrer policy of no-referrer-when-downgrade.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"20150992f78befcc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_safebrowsingallowlistdomainsdesc","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},"20a03a9b6334fa28":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"20ecedfafc5f8005":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdproxydirectory","displayName":"Proxy Directory","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies the location of the proxy disk location. This location must not be on a network path.\r\n\r\nRegistry Entry: HKLM\\SYSTEM\\CurrentControlSet\\Services\\frxccds\\Parameters\\ProxyDirectory\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"f2d139ed-a314-48b7-b700-4d11adfcc309","categoryName":"Cloud Cache Service","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdproxydirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdproxydirectory_1","displayName":"Enabled","description":null,"helpText":null}]},"2057f533535a54a9":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvolumewaittimemilliseconds","displayName":"Volume Wait Time (milliseconds)","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies the number of milliseconds to wait for the volume to be attached by the system. Default is 20,000 (20 seconds)\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\VolumeWaitTimeMS\r\nType: DWORD\r\nValues: Min = 1000, Max = 1000000","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvolumewaittimemilliseconds_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvolumewaittimemilliseconds_1","displayName":"Enabled","description":null,"helpText":null}]},"20160063940a0aa4":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallownetframeworkreliantcomponents"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"20e7d90cb22681ad":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets","displayName":"Allow scriptlets","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowscriptlets"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"20bd406d6f348807":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402","displayName":"XAML Files","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_1","displayName":"Prompt","description":null,"helpText":null}]},"20ca629e190ba38f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas_certificatetransparencyenforcementdisabledforlegacycasdesc","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"20ee578a3df5fff5":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled","displayName":"Seamless Web To Browser Sign-in Enabled","description":"This policy only takes effect when the 'WebToBrowserSignInEnabled' (Web To Browser Sign-in Enabled) is enabled.\r\nIf you enable this policy and set this policy to True, users cannot turn off Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\r\nIf you enable this policy and set this policy to False, users cannot turn on Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\r\nIf you enable this policy but not configured or disabled, users can turn on/off Seamless Web to Browser Sign-in feature from settings by themselves.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"20544122f5fb91c2":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"203c642eb1c16e85":{"id":"device_vendor_msft_policy_config_mixedreality_fallbackdiagnostics","displayName":"Fallback Diagnostics","description":"This policy setting controls, when and if diagnostic logs can be collected using specific button combination on HoloLens.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#fallbackdiagnostics"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_fallbackdiagnostics_0","displayName":"Not allowed. Diagnostic logs cannot be collected by pressing the button combination.","description":"Not allowed. Diagnostic logs cannot be collected by pressing the button combination.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_fallbackdiagnostics_1","displayName":"Allowed for device owners only. Diagnostics logs can be collected by pressing the button combination only if signed-in user is considered as device owner.","description":"Allowed for device owners only. Diagnostics logs can be collected by pressing the button combination only if signed-in user is considered as device owner.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_fallbackdiagnostics_2","displayName":"Allowed for all users. Diagnostic logs can be collected by pressing the button combination.","description":"Allowed for all users. Diagnostic logs can be collected by pressing the button combination.","helpText":null}]},"208673bcc3a055c1":{"id":"device_vendor_msft_policy_config_remotemanagement_allowremoteservermanagement_allowautoconfig_ipv4filter","displayName":"IPv4 filter:","description":"","helpText":"","infoUrls":[],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":null},"200a8548f3cf0533":{"id":"device_vendor_msft_policy_config_textinput_touchkeyboardhandwritingmodeavailability","displayName":"Touch Keyboard Handwriting Mode Availability","description":"Specifies whether the handwriting input panel is enabled or disabled. When this policy is set to disabled, the handwriting input panel is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#touchkeyboardhandwritingmodeavailability"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_touchkeyboardhandwritingmodeavailability_0","displayName":"The OS determines when it's most appropriate to be available.","description":"The OS determines when it's most appropriate to be available.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_touchkeyboardhandwritingmodeavailability_1","displayName":"Handwriting input panel is always available.","description":"Handwriting input panel is always available.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_touchkeyboardhandwritingmodeavailability_2","displayName":"Handwriting input panel is always disabled.","description":"Handwriting input panel is always disabled.","helpText":null}]},"204bd8a6e015205e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_pathcolon75","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"20dfff458dc7cd9d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys86","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"dba1a547-e288-45ac-8553-27a3b564699e","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys86_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys86_1","displayName":"Enabled","description":null,"helpText":null}]},"20e986e42c9acb90":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindacc","displayName":"Ctrl+F (Home | Find | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindacc_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindacc_1","displayName":"True","description":null,"helpText":null}]},"208ee019795dd58a":{"id":"user_vendor_msft_policy_config_admx_errorreporting_wernosecondleveldata_1","displayName":"Do not send additional data (User)","description":"This policy setting controls whether additional data in support of error reports can be sent to Microsoft automatically.\r\n\r\nIf you enable this policy setting, any additional data requests from Microsoft in response to a Windows Error Reporting report are automatically declined, without notification to the user.\r\n\r\nIf you disable or do not configure this policy setting, then consent policy settings in Computer Configuration/Administrative Templates/Windows Components/Windows Error Reporting/Consent take precedence.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-wernosecondleveldata-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_wernosecondleveldata_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_wernosecondleveldata_1_1","displayName":"Enabled","description":null,"helpText":null}]},"20a50fa213f8e471":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup","displayName":"Access 2016 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Access 2016.\r\nMicrosoft Access 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Access 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Access 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Access 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016accessbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"20491069490410b2":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-intranet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet_1","displayName":"Enabled","description":null,"helpText":null}]},"20f661df5755b90d":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nomycomputershareddocuments","displayName":"Remove Shared Documents from My Computer (User)","description":"This policy setting allows you to remove the Shared Documents folder from My Computer.\r\n\r\nWhen a Windows client is in a workgroup, a Shared Documents icon appears in the File Explorer Web view under \"Other Places\" and also under \"Files Stored on This Computer\" in My Computer. Using this policy setting, you can choose not to have these items displayed.\r\n\r\nIf you enable this policy setting, the Shared Documents folder is not displayed in the Web view or in My Computer.\r\n\r\nIf you disable or do not configure this policy setting, the Shared Documents folder is displayed in Web view and also in My Computer when the client is part of a workgroup.\r\n\r\nNote: The ability to remove the Shared Documents folder via Group Policy is only available on Windows XP Professional.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nomycomputershareddocuments"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nomycomputershareddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nomycomputershareddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"20a8772df0f10f9f":{"id":"user_vendor_msft_policy_config_admx_wpn_notoastnotification","displayName":"Turn off toast notifications (User)","description":"\r\n This policy setting turns off toast notifications for applications.\r\n\r\n If you enable this policy setting, applications will not be able to raise toast notifications.\r\n\r\n Note that this policy does not affect taskbar notification balloons.\r\n\r\n Note that Windows system features are not affected by this policy. You must enable/disable system features individually to stop their ability to raise toast notifications.\r\n\r\n If you disable or do not configure this policy setting, toast notifications are enabled and can be turned off by the administrator or user.\r\n\r\n No reboots or service restarts are required for this policy setting to take effect.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-notoastnotification"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_admx_wpn_notoastnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_wpn_notoastnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"203ffa8d475bf549":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage","displayName":"Import of homepage from default browser on first run (User)","description":"Setting the policy to Enabled imports the homepage from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the homepage isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the homepage checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"20eb73665803b0fb":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (User)","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' and 'InsecureContentBlockedForUrls' policies.\r\n\r\nIf this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"2030ef9314728f67":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist_nativemessagingallowlistdesc","displayName":"Names of the native messaging hosts to exempt from the blocklist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":null},"2090ad4a2b46699e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel","displayName":"Scan encrypted macros in Excel Open XML workbooks (User)","description":"This policy setting controls whether encrypted macros in Open XML workbooks be are required to be scanned with anti-virus software before being opened.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted workbook that contains macros.\r\n- Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load.\r\n- Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file.\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be similar to the \"Scan encrypted macros\" option.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_1","displayName":"Enabled","description":null,"helpText":null}]},"200d56abc2f1d315":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},"20ae5e867372e21d":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript","displayName":"Allow updates to status bar via script (User)","description":"This policy setting allows you to manage whether script is allowed to update the status bar within the zone.\n\nIf you enable this policy setting, script is allowed to update the status bar.\n\nIf you disable or do not configure this policy setting, script is not allowed to update the status bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowupdatestostatusbarviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"2020fb89e485b24a":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},"200993d5e30cbacb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies","displayName":"Block third party cookies (User)","description":"Block web page elements that aren't from the domain that's in the address bar from setting cookies.\r\n\r\nIf you enable this policy, web page elements that are not from the domain that is in the address bar can't set cookies\r\n\r\nIf you disable this policy, web page elements from domains other than in the address bar can set cookies.\r\n\r\nIf you don't configure this policy, third-party cookies are enabled but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_1","displayName":"Enabled","description":null,"helpText":null}]},"201901367d34c867":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer (User)","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\r\n\r\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\r\n\r\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter_1","displayName":"Enabled","description":null,"helpText":null}]},"2046b8de9032f8bb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled","displayName":"Configure Microsoft Defender SmartScreen (User)","description":"This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you enable this setting, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"200f7c5ded0e8120":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it is a temporary policy to support WebSQL in non-secure contexts. It won't work in Microsoft Edge as soon as version 110.\r\nIf you enable this policy, WebSQL in non-secure contexts will be enabled.\r\nIf you disable or don't configure this policy, WebSQL in non-secure contexts will follow the default settings of the broser.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"20cff146db6fabba":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerAllowedForSites' (Allow JavaScript optimization on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise Javascript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"2069f76525aa2469":{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_precisegeolocationallowedforurlsdesc","displayName":"Allow precise geolocation on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"20438793f59938ac":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist","displayName":"Browsing with Copilot Blocked URLs (User)","description":"Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list.\r\n\r\nUse this policy to define exceptions to broader allowlists. For example, you can set 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) to '*' to allow all sites, and then use this policy to block access to specific URLs.\r\n\r\nThis policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.\r\n\r\nIf you don't configure this policy, no exceptions are applied to 'BrowsingWithCopilotAllowList'.\r\n\r\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored.\r\n\r\nFor information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu\r\ncontoso.net\r\nlogin.contoso.us","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"206dc4f541b9c519":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended","displayName":"Allow importing of open tabs (User)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"20d60695d7d8fc8f":{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_smartactionsblocklistdesc","displayName":"Block smart actions for a list of services (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},"20cd0ea0d3fb6463":{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics","displayName":"Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation. (User)","description":"This policy setting allows you to enable or disable Get Diagnostics in Office applications and specifies the mode in which the feature operates.\r\n\r\nIf you enable this policy setting, you must choose one of the following options:\r\nDisabled\r\nEnable upload of diagnostics logs to Microsoft\r\nEnable the collection of diagnostic logs in an archive\r\n\r\nIf you select \"Disabled\", Office applications will not display a visible Get Diagnostics button in the Help Ribbon.\r\n\r\nIf you select \"Enable upload of diagnostics logs to Microsoft\", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will upload the application’s diagnostic logs to Microsoft for support purposes.\r\n\r\nIf you select \"Enable the collection of diagnostic logs in an archive\", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will capture the application’s diagnostic logs in a file archive on the device where the application is currently running. These logs will not be uploaded to Microsoft.\r\n\r\nPlease note that the option “Enable the collection of diagnostic logs in an archive” may not be applicable in certain Office applications. When the application does not support local log collection, setting the policy to this option will completely disable the feature, removing the \"Get Diagnostics\" button.\r\n\r\nIf you don’t set this policy, the feature will operate in the default mode, which is “Enable upload of diagnostics logs to Microsoft.”\r\n ","helpText":"","infoUrls":[],"categoryId":"e86f24d3-8531-4298-b064-692ea795b1d9","categoryName":"Diagnostics","options":[{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},"20ac422fe2a4861c":{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid","displayName":"Online Storage Filter Value: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"201356944ae07746":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicenotesdefaulturl4","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"20e27c9d23206508":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicenotesdefaulturl9","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"20369b6e35755cb4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout","displayName":"Set maximum database timeout limit (User)","description":"This policy setting allows you to specify the maximum timeout in milliseconds used by the database shim. This maximum value is enforced for applications including those that do not respect the default.\r\n\r\nIf you enable this policy setting, you may specify the maximum timeout in milliseconds used by the database shim.\r\n\r\nIf you disable or do not configure this policy setting, no maximum timeout value will be enforced.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"20ea5b1ca8ae62ec":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium","displayName":"French (Belgium) (User)","description":"Enables the editing language French (Belgium)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium_1","displayName":"Enabled","description":null,"helpText":null}]},"20efd9ce05799ee0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures","displayName":"Show LinkedIn features in Office applications (User)","description":"This policy setting will prevent LinkedIn features from appearing in the Office applications.\r\n\r\nIf you enable or do not configure this policy, users will be able to leverage LinkedIn data and resources from a variety of locations within the Office applications.\r\n\r\nIf you disable this policy setting, LinkedIn features will not be available.\r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI).\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},"20f0ff69709e9e79":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowdescrip440","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"20716c0314f96fcd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength","displayName":"Set minimum password length (User)","description":"This setting will define what the minimum length a password should be when the local policy is enforced.\r\n\r\nIf you enable this policy setting, you may specify the minimum password length. The valid range is between 0 and 255.\r\n\r\nIf you disable or do not configure this policy setting, the default minimum password length is 0 characters.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_1","displayName":"Enabled","description":null,"helpText":null}]},"20a7e0a20fcac2af":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16","displayName":"Unsafe Location #16 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_1","displayName":"Enabled","description":null,"helpText":null}]},"201a37b87cbf53b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_l_webquerydialoghomepage333","displayName":"Web Query dialog box home page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},"204315879001b6d1":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins","displayName":"List of allowed COM/VSTO add-ins registered in HKCU (User)","description":"This policy setting allows you to specify COM/VSTO add-ins registered in HKEY_CURRENT_USER (HKCU) that should be allowed to load, overriding the \"Block loading of COM/VSTO add-ins registered in HKCU\" policy.\r\n\r\nSome legitimate add-ins may be installed in HKCU even when deployed by administrators, due to how the independent software vendor (ISV) designed their installer. This policy provides an administrative override to allow specific add-ins to load despite being registered in HKCU.\r\n\r\nIf you enable this policy setting, you can specify a list of COM/VSTO add-ins that are allowed to load from HKCU. Enter each add-in using its ProgID as the name.\r\n\r\nIf you disable or don't configure this policy setting, the standard HKCU blocking behavior applies when that policy is enabled.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_1","displayName":"Enabled","description":null,"helpText":null}]},"20822d7b16e529ee":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_urladdressofassociatedwebpage55","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"203bb88b51f59530":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest","displayName":"Specify delay before sending people search request (User)","description":"This policy is used to set the delay for sending people search requests from the Find a Contact box in Outlook and the Related People section that appears in the Backstage view (Info tab) of Office applications.\r\n\r\nIf you enable this policy setting, you can specify the delay in milliseconds between when the user stops (or pauses) typing in the search box and when the application sends a search request.\r\n\r\nIf you disable or do not configure this policy setting, the default delay is 200 milliseconds (0.20 seconds).","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_1","displayName":"Enabled","description":null,"helpText":null}]},"20d7d4edf4801cd4":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours","displayName":"Working hours (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_1","displayName":"Enabled","description":null,"helpText":null}]},"20c5eb94082af85f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones","displayName":"Block Trusted Zones (User)","description":"This policy setting controls whether pictures from sites in the Trusted Sites security zone are automatically downloaded in Outlook e-mail messages and other items. \r\n\r\nIf you enable this policy setting, Outlook does not automatically download content from Web sites in the Trusted sites zone in Internet Explorer. Recipients can choose to download external content on a message-by-message basis. \r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically downloads content from Web sites in the Trusted sites zone in Internet Explorer.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones_1","displayName":"Enabled","description":null,"helpText":null}]},"2063490ac7c9be8e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads_l_allowxxincrementaloabdownloadsper13hrperiod","displayName":"Allow xx incremental OAB downloads per 13hr period (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":null},"2030fbf1ba029e72":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},"2071fac6df662efd":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},"2013ee62bf940043":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"202e616db015aa6d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart","displayName":"Color for tracking deletions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_2","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_3","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_4","displayName":"Turquoise","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_5","displayName":"Bright Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_6","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_7","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_8","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_9","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_10","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_11","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_12","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_13","displayName":"Violet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_14","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_15","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_16","displayName":"Gray 50%","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_17","displayName":"Gray 25%","description":null,"helpText":null}]}} \ No newline at end of file +{"20aaa0ad5797489b":{"id":"ade_setupassistant_tvhomescreensync","displayName":"TV Home Screen Sync","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_tvhomescreensync_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_tvhomescreensync_1","displayName":"Show","description":null,"helpText":null}]},"20a12f0bd2b0a56d":{"id":"app_allowed_deniedbinaries","displayName":"Denied Binaries","description":"If present, the device doesn't allow binaries that match the binary identifier properties to run. A binary only matches when all the binary identifiers match.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},"20c4e60373c0ce19":{"id":"com.apple.applicationaccess_allowtimemachinebackup","displayName":"Allow Time Machine Backup","description":"If 'false', prevents modification of Time Machine settings in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowtimemachinebackup_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowtimemachinebackup_true","displayName":"True","description":null,"helpText":null}]},"2007a54fd9a7bd1a":{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming","displayName":"Allowed Protocol Mask In Domestic Roaming","description":"The supported Internet Protocol versions while roaming domestically. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskindomesticroaming_2","displayName":"Both","description":null,"helpText":null}]},"209a95535f2dac73":{"id":"com.apple.extensiblesso_extensiondata_generickey_string","displayName":"Value","description":"Keys and values to pass to the app extension.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"20ca742e214e7518":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_application id","displayName":"OneDrive Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"20976707bc592d9b":{"id":"com.apple.managedclient.preferences_extendedlogging","displayName":"Enable extended logging","description":"Write verbose logging events to /Library/Logs/Microsoft/autoupdate.log","helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_extendedlogging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extendedlogging_true","displayName":"True","description":null,"helpText":null}]},"200446d200ea2d6c":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed","displayName":"Allowed","description":"If 'true', access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_allowed_true","displayName":"Allowed","description":null,"helpText":null}]},"20ecaa63f2739dc8":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"20272e80bbb375af":{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request header support enabled","description":"This policy lets you configure support for CORS non-wildcard request headers.\n\nMicrosoft Edge version 97 introduces support for CORS non-wildcard request headers. When a script makes a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header is explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. For more information, see https://go.microsoft.com/fwlink/?linkid=2180022.\n\nIf you enable or don't configure the policy, Microsoft Edge supports the CORS non-wildcard request headers and behaves as previously described.\n\nIf you disable this policy, Microsoft Edge allows the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\n\nThis policy is a temporary workaround for the new CORS non-wildcard request header feature. It's planned to be removed in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.corsnonwildcardrequestheaderssupport_true","displayName":"Enabled","description":null,"helpText":null}]},"20c48e78f87ee72a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled","displayName":"Enable preload of the new tab page for faster rendering","description":"If you configure this policy, preloading the New tab page is enabled, and users can't change this setting. If you don't configure this policy, preloading is enabled and a user can change this setting.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageprerenderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"20318f66b30d72f6":{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended","displayName":"Enables Microsoft Edge mini menu (users can override)","description":"Enables the Microsoft Edge mini menu on websites and PDFs. The mini menu appears when users select text and provides basic actions like Copy and smart actions such as Definitions.\n\nIf you enable or don't configure this policy, selecting text on websites or PDFs shows the mini menu.\n\nIf you disable this policy, the mini menu doesn't appear when users select text on websites or PDFs.\n\nNote: Starting in Microsoft Edge for Mac version 143, this policy is obsolete because the mini menu feature is removed on Mac.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.quicksearchshowminimenu_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"20cdb3f3d9395b6b":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursfrom_23","displayName":"11 PM","description":null,"helpText":null}]},"201cf4d1096b9e1b":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworkhighprioritylimit","displayName":"High Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"206616129f1adf03":{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen","displayName":"Force a specific default lock screen and logon image","description":"This setting allows you to force a specific default lock screen and logon image by entering the path (location) of the image file. The same image will be used for both the lock and logon screens.\r\n\r\nThis setting lets you specify the default lock screen and logon image shown when no user is signed in, and also sets the specified image as the default for all users (it replaces the inbox default image).\r\n\r\nTo use this setting, type the fully qualified path and name of the file that stores the default lock screen and logon image. You can type a local path, such as C:\\Windows\\Web\\Screen\\img104.jpg or a UNC path, such as \\\\Server\\Share\\Corp.jpg.\r\n\r\nThis can be used in conjunction with the \"Prevent changing lock screen and logon image\" setting to always force the specified lock screen and logon image to be shown.\r\n\r\nNote: This setting only applies to Enterprise, Education, and Server SKUs.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-forcedefaultlockscreen"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_forcedefaultlockscreen_1","displayName":"Enabled","description":null,"helpText":null}]},"20c11cb28d455182":{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy","displayName":"Disk Diagnostic: Configure execution level","description":"This policy setting determines the execution level for S.M.A.R.T.-based disk diagnostics. \r\n\r\nSelf-Monitoring And Reporting Technology (S.M.A.R.T.) is a standard mechanism for storage devices to report faults to Windows. A disk that reports a S.M.A.R.T. fault may need to be repaired or replaced. The Diagnostic Policy Service (DPS) detects and logs S.M.A.R.T. faults to the event log when they occur. \r\n\r\nIf you enable this policy setting, the DPS also warns users of S.M.A.R.T. faults and guides them through backup and recovery to minimize potential data loss. \r\n\r\nIf you disable this policy, S.M.A.R.T. faults are still detected and logged, but no corrective action is taken. \r\n\r\nIf you do not configure this policy setting, the DPS enables S.M.A.R.T. fault resolution by default. \r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured. \r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately. \r\n\r\nThis policy setting takes effect only when the DPS is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console. \r\n\r\nNote: For Windows Server systems, this policy setting applies only if the Desktop Experience optional component is installed and the Remote Desktop Services role is not installed. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskdiagnostic#admx-diskdiagnostic-wdiscenarioexecutionpolicy"],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":[{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"202542a6b459c021":{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality","displayName":"Enable / disable TXF deprecated features","description":"TXF deprecated features included savepoints, secondary RM, miniversion and roll forward. Please enable it if you want to use the APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-txfdeprecatedfunctionality"],"categoryId":"bb54b081-5004-4f05-a46c-f5b948f57b82","categoryName":"NTFS","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_txfdeprecatedfunctionality_1","displayName":"Enabled","description":null,"helpText":null}]},"207eaf94b764ce6c":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_exclusions_pathslist","displayName":"Path Exclusions","description":null,"helpText":"","infoUrls":[],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":null},"204c995225d5c321":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation","displayName":"NtfsDisable8dot3NameCreation","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_0","displayName":"Enable 8Dot3 Creation on all Volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_1","displayName":"Disable 8Dot3 Creation on all Volumes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_2","displayName":"Set 8dot3 name creation per volume using FSUTIL","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_ntfsdisable8dot3namecreation_ntfsdisable8dot3namecreation_3","displayName":"Disable 8Dot3 name creation on all volumes except system volume","description":null,"helpText":null}]},"20b0b2d279a2fed6":{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2","displayName":"Low battery notification level","description":"This policy setting specifies the percentage of battery capacity remaining that triggers the low battery notification action.\r\n\r\nIf you enable this policy setting, you must enter a numeric value (percentage) to set the battery level that triggers the low notification.\r\n\r\nTo set the action that is triggered, see the \"Low Battery Notification Action\" policy setting.\r\n\r\nIf you disable this policy setting or do not configure it, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargelevel1-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargelevel1_2_1","displayName":"Enabled","description":null,"helpText":null}]},"20b5d889362e9ffe":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv","displayName":"Guaranteed service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_1","displayName":"Enabled","description":null,"helpText":null}]},"20c9ba0663dcda87":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality","displayName":"Configure image quality for RemoteFX Adaptive Graphics","description":"This policy setting allows you to specify the visual quality for remote users when connecting to this computer by using Remote Desktop Connection. You can use this policy setting to balance the network bandwidth usage with the visual quality that is delivered.\r\n If you enable this policy setting and set quality to Low, RemoteFX Adaptive Graphics uses an encoding mechanism that results in low quality images. This mode consumes the lowest amount of network bandwidth of the quality modes.\r\n If you enable this policy setting and set quality to Medium, RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images. This mode provides better graphics quality than low quality and uses less bandwidth than high quality.\r\n If you enable this policy setting and set quality to High, RemoteFX Adaptive Graphics uses an encoding mechanism that results in high quality images and consumes moderate network bandwidth.\r\n If you enable this policy setting and set quality to Lossless, RemoteFX Adaptive Graphics uses lossless encoding. In this mode, the color integrity of the graphics data is not impacted. However, this setting results in a significant increase in network bandwidth consumption. We recommend that you set this for very specific cases only.\r\n If you disable or do not configure this policy setting, RemoteFX Adaptive Graphics uses an encoding mechanism that results in medium quality images.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-image-quality"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_image_quality_1","displayName":"Enabled","description":null,"helpText":null}]},"20ae54551f31dccb":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp","displayName":"Optimize visual experience for Remote Desktop Service Sessions","description":"This policy setting allows you to specify the visual experience that remote users receive in Remote Desktop Services sessions. Remote sessions on the remote computer are then optimized to support this visual experience.\r\n\r\nBy default, Remote Desktop Services sessions are optimized for rich multimedia, such as applications that use Silverlight or Windows Presentation Foundation.\r\n\r\nIf you enable this policy setting, you must select the visual experience for which you want to optimize Remote Desktop Services sessions. You can select either Rich multimedia or Text.\r\n\r\nIf you disable or do not configure this policy setting, Remote Desktop Services sessions are optimized for rich multimedia.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-visexp"],"categoryId":"b7bde490-eac6-4f57-8808-e0786b8191a1","categoryName":"Remote FX for Windows Server 2008 R2","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_visexp_1","displayName":"Enabled","description":null,"helpText":null}]},"2071f0523f3b7e1f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled","displayName":"Enable JavaScript","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_javascriptenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"20daa97ce8cbbe9d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_1","displayName":"Enabled","description":null,"helpText":null}]},"2068d43d7a79de0e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy","displayName":"Use a default referrer policy of no-referrer-when-downgrade.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_forcelegacydefaultreferrerpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"20150992f78befcc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_safebrowsingallowlistdomainsdesc","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":null},"20a03a9b6334fa28":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"20ecedfafc5f8005":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdproxydirectory","displayName":"Proxy Directory","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies the location of the proxy disk location. This location must not be on a network path.\r\n\r\nRegistry Entry: HKLM\\SYSTEM\\CurrentControlSet\\Services\\frxccds\\Parameters\\ProxyDirectory\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"f2d139ed-a314-48b7-b700-4d11adfcc309","categoryName":"Cloud Cache Service","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdproxydirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdproxydirectory_1","displayName":"Enabled","description":null,"helpText":null}]},"2057f533535a54a9":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvolumewaittimemilliseconds","displayName":"Volume Wait Time (milliseconds)","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies the number of milliseconds to wait for the volume to be attached by the system. Default is 20,000 (20 seconds)\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\VolumeWaitTimeMS\r\nType: DWORD\r\nValues: Min = 1000, Max = 1000000","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvolumewaittimemilliseconds_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvolumewaittimemilliseconds_1","displayName":"Enabled","description":null,"helpText":null}]},"20160063940a0aa4":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallownetframeworkreliantcomponents"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"20e7d90cb22681ad":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets","displayName":"Allow scriptlets","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowscriptlets"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"20bd406d6f348807":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402","displayName":"XAML Files","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_iz_partname2402_1","displayName":"Prompt","description":null,"helpText":null}]},"20ca629e190ba38f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforlegacycas_certificatetransparencyenforcementdisabledforlegacycasdesc","displayName":"Disable Certificate Transparency enforcement for a list of legacy certificate authorities (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"20ee578a3df5fff5":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled","displayName":"Seamless Web To Browser Sign-in Enabled","description":"This policy only takes effect when the 'WebToBrowserSignInEnabled' (Web To Browser Sign-in Enabled) is enabled.\r\nIf you enable this policy and set this policy to True, users cannot turn off Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\r\nIf you enable this policy and set this policy to False, users cannot turn on Seamless Web to Browser Sign-in feature from \"Automatic sign in on Microsoft Edge\" setting on Microsoft Edge profile settings page and that toggle will be greyed out.\r\nIf you enable this policy but not configured or disabled, users can turn on/off Seamless Web to Browser Sign-in feature from settings by themselves.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_seamlesswebtobrowsersigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"20544122f5fb91c2":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"203c642eb1c16e85":{"id":"device_vendor_msft_policy_config_mixedreality_fallbackdiagnostics","displayName":"Fallback Diagnostics","description":"This policy setting controls, when and if diagnostic logs can be collected using specific button combination on HoloLens.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#fallbackdiagnostics"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_fallbackdiagnostics_0","displayName":"Not allowed. Diagnostic logs cannot be collected by pressing the button combination.","description":"Not allowed. Diagnostic logs cannot be collected by pressing the button combination.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_fallbackdiagnostics_1","displayName":"Allowed for device owners only. Diagnostics logs can be collected by pressing the button combination only if signed-in user is considered as device owner.","description":"Allowed for device owners only. Diagnostics logs can be collected by pressing the button combination only if signed-in user is considered as device owner.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_fallbackdiagnostics_2","displayName":"Allowed for all users. Diagnostic logs can be collected by pressing the button combination.","description":"Allowed for all users. Diagnostic logs can be collected by pressing the button combination.","helpText":null}]},"208673bcc3a055c1":{"id":"device_vendor_msft_policy_config_remotemanagement_allowremoteservermanagement_allowautoconfig_ipv4filter","displayName":"IPv4 filter:","description":"","helpText":"","infoUrls":[],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":null},"200a8548f3cf0533":{"id":"device_vendor_msft_policy_config_textinput_touchkeyboardhandwritingmodeavailability","displayName":"Touch Keyboard Handwriting Mode Availability","description":"Specifies whether the handwriting input panel is enabled or disabled. When this policy is set to disabled, the handwriting input panel is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#touchkeyboardhandwritingmodeavailability"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_touchkeyboardhandwritingmodeavailability_0","displayName":"The OS determines when it's most appropriate to be available.","description":"The OS determines when it's most appropriate to be available.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_touchkeyboardhandwritingmodeavailability_1","displayName":"Handwriting input panel is always available.","description":"Handwriting input panel is always available.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_touchkeyboardhandwritingmodeavailability_2","displayName":"Handwriting input panel is always disabled.","description":"Handwriting input panel is always disabled.","helpText":null}]},"202dbbfa0fcc6a75":{"id":"device_vendor_msft_policy_config_update_maintenancewindowstartdate","displayName":"Maintenance Window Start Date","description":"Configure the start date for the maintenance window in the format of YYYY-MM-DD (for example, 2025-12-16). This field will only be honored for a non-repeating maintenance window. Repeating maintenance windows will start on the earliest date that meets the configured schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowstartdate"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"204bd8a6e015205e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_pathcolon75","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"20dfff458dc7cd9d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys86","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"dba1a547-e288-45ac-8553-27a3b564699e","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys86_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys86_1","displayName":"Enabled","description":null,"helpText":null}]},"20e986e42c9acb90":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindacc","displayName":"Ctrl+F (Home | Find | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindacc_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlffindacc_1","displayName":"True","description":null,"helpText":null}]},"208ee019795dd58a":{"id":"user_vendor_msft_policy_config_admx_errorreporting_wernosecondleveldata_1","displayName":"Do not send additional data (User)","description":"This policy setting controls whether additional data in support of error reports can be sent to Microsoft automatically.\r\n\r\nIf you enable this policy setting, any additional data requests from Microsoft in response to a Windows Error Reporting report are automatically declined, without notification to the user.\r\n\r\nIf you disable or do not configure this policy setting, then consent policy settings in Computer Configuration/Administrative Templates/Windows Components/Windows Error Reporting/Consent take precedence.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-wernosecondleveldata-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_wernosecondleveldata_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_wernosecondleveldata_1_1","displayName":"Enabled","description":null,"helpText":null}]},"20a50fa213f8e471":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup","displayName":"Access 2016 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Access 2016.\r\nMicrosoft Access 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Access 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Access 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Access 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016accessbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016accessbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"20491069490410b2":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-intranet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_intranet_1","displayName":"Enabled","description":null,"helpText":null}]},"20f661df5755b90d":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nomycomputershareddocuments","displayName":"Remove Shared Documents from My Computer (User)","description":"This policy setting allows you to remove the Shared Documents folder from My Computer.\r\n\r\nWhen a Windows client is in a workgroup, a Shared Documents icon appears in the File Explorer Web view under \"Other Places\" and also under \"Files Stored on This Computer\" in My Computer. Using this policy setting, you can choose not to have these items displayed.\r\n\r\nIf you enable this policy setting, the Shared Documents folder is not displayed in the Web view or in My Computer.\r\n\r\nIf you disable or do not configure this policy setting, the Shared Documents folder is displayed in Web view and also in My Computer when the client is part of a workgroup.\r\n\r\nNote: The ability to remove the Shared Documents folder via Group Policy is only available on Windows XP Professional.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nomycomputershareddocuments"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nomycomputershareddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nomycomputershareddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"20a8772df0f10f9f":{"id":"user_vendor_msft_policy_config_admx_wpn_notoastnotification","displayName":"Turn off toast notifications (User)","description":"\r\n This policy setting turns off toast notifications for applications.\r\n\r\n If you enable this policy setting, applications will not be able to raise toast notifications.\r\n\r\n Note that this policy does not affect taskbar notification balloons.\r\n\r\n Note that Windows system features are not affected by this policy. You must enable/disable system features individually to stop their ability to raise toast notifications.\r\n\r\n If you disable or do not configure this policy setting, toast notifications are enabled and can be turned off by the administrator or user.\r\n\r\n No reboots or service restarts are required for this policy setting to take effect.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-notoastnotification"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_admx_wpn_notoastnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_wpn_notoastnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"203ffa8d475bf549":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage","displayName":"Import of homepage from default browser on first run (User)","description":"Setting the policy to Enabled imports the homepage from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means the homepage isn't imported on first run.\r\n\r\nUsers can trigger an import dialog and the homepage checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"20eb73665803b0fb":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (User)","description":"Allows you to set whether users can add exceptions to allow mixed content for specific sites.\r\n\r\nThis policy can be overridden for specific URL patterns using the 'InsecureContentAllowedForUrls' and 'InsecureContentBlockedForUrls' policies.\r\n\r\nIf this policy is left not set, users will be allowed to add exceptions to allow blockable mixed content and disable autoupgrades for optionally blockable mixed content.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"2030ef9314728f67":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessagingallowlist_nativemessagingallowlistdesc","displayName":"Names of the native messaging hosts to exempt from the blocklist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":null},"2090ad4a2b46699e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel","displayName":"Scan encrypted macros in Excel Open XML workbooks (User)","description":"This policy setting controls whether encrypted macros in Open XML workbooks be are required to be scanned with anti-virus software before being opened.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- Scan encrypted macros: encrypted macros are disabled unless anti-virus software is installed. Encrypted macros are scanned by your anti-virus software when you attempt to open an encrypted workbook that contains macros.\r\n- Scan if anti-virus software available: if anti-virus software is installed, scan the encrypted macros first before allowing them to load. If anti-virus software is not available, allow encrypted macros to load.\r\n- Load macros without scanning: do not check for anti-virus software and allow macros to be loaded in an encrypted file.\r\n\r\nIf you disable or do not configure this policy setting, the behavior will be similar to the \"Scan encrypted macros\" option.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_1","displayName":"Enabled","description":null,"helpText":null}]},"200d56abc2f1d315":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},"20ae5e867372e21d":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript","displayName":"Allow updates to status bar via script (User)","description":"This policy setting allows you to manage whether script is allowed to update the status bar within the zone.\n\nIf you enable this policy setting, script is allowed to update the status bar.\n\nIf you disable or do not configure this policy setting, script is not allowed to update the status bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowupdatestostatusbarviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowupdatestostatusbarviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"2020fb89e485b24a":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},"200993d5e30cbacb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies","displayName":"Block third party cookies (User)","description":"Block web page elements that aren't from the domain that's in the address bar from setting cookies.\r\n\r\nIf you enable this policy, web page elements that are not from the domain that is in the address bar can't set cookies\r\n\r\nIf you disable this policy, web page elements from domains other than in the address bar can set cookies.\r\n\r\nIf you don't configure this policy, third-party cookies are enabled but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_1","displayName":"Enabled","description":null,"helpText":null}]},"201901367d34c867":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer (User)","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\r\n\r\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\r\n\r\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~printing_printpreviewusesystemdefaultprinter_1","displayName":"Enabled","description":null,"helpText":null}]},"2046b8de9032f8bb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled","displayName":"Configure Microsoft Defender SmartScreen (User)","description":"This policy setting lets you configure whether to turn on Microsoft Defender SmartScreen. Microsoft Defender SmartScreen provides warning messages to help protect your users from potential phishing scams and malicious software. By default, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you enable this setting, Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"200f7c5ded0e8120":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it is a temporary policy to support WebSQL in non-secure contexts. It won't work in Microsoft Edge as soon as version 110.\r\nIf you enable this policy, WebSQL in non-secure contexts will be enabled.\r\nIf you disable or don't configure this policy, WebSQL in non-secure contexts will follow the default settings of the broser.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"20cff146db6fabba":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerAllowedForSites' (Allow JavaScript optimization on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise Javascript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"2069f76525aa2469":{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_precisegeolocationallowedforurlsdesc","displayName":"Allow precise geolocation on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"20438793f59938ac":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist","displayName":"Browsing with Copilot Blocked URLs (User)","description":"Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list.\r\n\r\nUse this policy to define exceptions to broader allowlists. For example, you can set 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) to '*' to allow all sites, and then use this policy to block access to specific URLs.\r\n\r\nThis policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.\r\n\r\nIf you don't configure this policy, no exceptions are applied to 'BrowsingWithCopilotAllowList'.\r\n\r\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored.\r\n\r\nFor information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu\r\ncontoso.net\r\nlogin.contoso.us","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"206dc4f541b9c519":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended","displayName":"Allow importing of open tabs (User)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"20d60695d7d8fc8f":{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_smartactionsblocklistdesc","displayName":"Block smart actions for a list of services (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},"20cd0ea0d3fb6463":{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics","displayName":"Configure Get Diagnostics feature's visibility in the Help Ribbon in Office applications and control the feature's mode of operation. (User)","description":"This policy setting allows you to enable or disable Get Diagnostics in Office applications and specifies the mode in which the feature operates.\r\n\r\nIf you enable this policy setting, you must choose one of the following options:\r\nDisabled\r\nEnable upload of diagnostics logs to Microsoft\r\nEnable the collection of diagnostic logs in an archive\r\n\r\nIf you select \"Disabled\", Office applications will not display a visible Get Diagnostics button in the Help Ribbon.\r\n\r\nIf you select \"Enable upload of diagnostics logs to Microsoft\", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will upload the application’s diagnostic logs to Microsoft for support purposes.\r\n\r\nIf you select \"Enable the collection of diagnostic logs in an archive\", Office applications will have a visible Get Diagnostics button in the Help Ribbon. Clicking this button will capture the application’s diagnostic logs in a file archive on the device where the application is currently running. These logs will not be uploaded to Microsoft.\r\n\r\nPlease note that the option “Enable the collection of diagnostic logs in an archive” may not be applicable in certain Office applications. When the application does not support local log collection, setting the policy to this option will completely disable the feature, removing the \"Get Diagnostics\" button.\r\n\r\nIf you don’t set this policy, the feature will operate in the default mode, which is “Enable upload of diagnostics logs to Microsoft.”\r\n ","helpText":"","infoUrls":[],"categoryId":"e86f24d3-8531-4298-b064-692ea795b1d9","categoryName":"Diagnostics","options":[{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},"20ac422fe2a4861c":{"id":"user_vendor_msft_policy_config_office16v2.updates.2~policy~l_microsoftofficesystem~l_miscellaneous437_l_onlinestoragefilter_l_onlinestoragefilterid","displayName":"Online Storage Filter Value: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"201356944ae07746":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastservicenotesdefaulturl4","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"20e27c9d23206508":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicenotesdefaulturl9","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"20369b6e35755cb4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout","displayName":"Set maximum database timeout limit (User)","description":"This policy setting allows you to specify the maximum timeout in milliseconds used by the database shim. This maximum value is enforced for applications including those that do not respect the default.\r\n\r\nIf you enable this policy setting, you may specify the maximum timeout in milliseconds used by the database shim.\r\n\r\nIf you disable or do not configure this policy setting, no maximum timeout value will be enforced.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"20ea5b1ca8ae62ec":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium","displayName":"French (Belgium) (User)","description":"Enables the editing language French (Belgium)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchbelgium_1","displayName":"Enabled","description":null,"helpText":null}]},"20efd9ce05799ee0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures","displayName":"Show LinkedIn features in Office applications (User)","description":"This policy setting will prevent LinkedIn features from appearing in the Office applications.\r\n\r\nIf you enable or do not configure this policy, users will be able to leverage LinkedIn data and resources from a variety of locations within the Office applications.\r\n\r\nIf you disable this policy setting, LinkedIn features will not be available.\r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI).\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_allowlinkedinfeatures_1","displayName":"Enabled","description":null,"helpText":null}]},"20f0ff69709e9e79":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowdescrip440","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"20716c0314f96fcd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength","displayName":"Set minimum password length (User)","description":"This setting will define what the minimum length a password should be when the local policy is enforced.\r\n\r\nIf you enable this policy setting, you may specify the minimum password length. The valid range is between 0 and 255.\r\n\r\nIf you disable or do not configure this policy setting, the default minimum password length is 0 characters.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setminimumpasswordlength_1","displayName":"Enabled","description":null,"helpText":null}]},"20a7e0a20fcac2af":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16","displayName":"Unsafe Location #16 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_1","displayName":"Enabled","description":null,"helpText":null}]},"201a37b87cbf53b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_webquerydialoghomepage_l_webquerydialoghomepage333","displayName":"Web Query dialog box home page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},"204315879001b6d1":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins","displayName":"List of allowed COM/VSTO add-ins registered in HKCU (User)","description":"This policy setting allows you to specify COM/VSTO add-ins registered in HKEY_CURRENT_USER (HKCU) that should be allowed to load, overriding the \"Block loading of COM/VSTO add-ins registered in HKCU\" policy.\r\n\r\nSome legitimate add-ins may be installed in HKCU even when deployed by administrators, due to how the independent software vendor (ISV) designed their installer. This policy provides an administrative override to allow specific add-ins to load despite being registered in HKCU.\r\n\r\nIf you enable this policy setting, you can specify a list of COM/VSTO add-ins that are allowed to load from HKCU. Enter each add-in using its ProgID as the name.\r\n\r\nIf you disable or don't configure this policy setting, the standard HKCU blocking behavior applies when that policy is enabled.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_1","displayName":"Enabled","description":null,"helpText":null}]},"20822d7b16e529ee":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_journalfolderhomepage_l_urladdressofassociatedwebpage55","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"203bb88b51f59530":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest","displayName":"Specify delay before sending people search request (User)","description":"This policy is used to set the delay for sending people search requests from the Find a Contact box in Outlook and the Related People section that appears in the Backstage view (Info tab) of Office applications.\r\n\r\nIf you enable this policy setting, you can specify the delay in milliseconds between when the user stops (or pauses) typing in the search box and when the application sends a search request.\r\n\r\nIf you disable or do not configure this policy setting, the default delay is 200 milliseconds (0.20 seconds).","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifydelaybeforesendingpeoplesearchrequest_1","displayName":"Enabled","description":null,"helpText":null}]},"20d7d4edf4801cd4":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours","displayName":"Working hours (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_1","displayName":"Enabled","description":null,"helpText":null}]},"20c5eb94082af85f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones","displayName":"Block Trusted Zones (User)","description":"This policy setting controls whether pictures from sites in the Trusted Sites security zone are automatically downloaded in Outlook e-mail messages and other items. \r\n\r\nIf you enable this policy setting, Outlook does not automatically download content from Web sites in the Trusted sites zone in Internet Explorer. Recipients can choose to download external content on a message-by-message basis. \r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically downloads content from Web sites in the Trusted sites zone in Internet Explorer.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_blocktrustedzones_1","displayName":"Enabled","description":null,"helpText":null}]},"2063490ac7c9be8e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitnumberofincrementaloabdownloads_l_allowxxincrementaloabdownloadsper13hrperiod","displayName":"Allow xx incremental OAB downloads per 13hr period (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":null},"2030fbf1ba029e72":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},"2071fac6df662efd":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter~l_fileblocksettings_l_visio2000files_l_visio2000filesdropid_2","displayName":"Open/Save blocked","description":null,"helpText":null}]},"2013ee62bf940043":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon33","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"202e616db015aa6d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart","displayName":"Color for tracking deletions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_2","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_3","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_4","displayName":"Turquoise","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_5","displayName":"Bright Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_6","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_7","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_8","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_9","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_10","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_11","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_12","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_13","displayName":"Violet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_14","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_15","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_16","displayName":"Gray 50%","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_deletionscolor_l_deletionscolorpart_17","displayName":"Gray 25%","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/24.json b/public/intune-definitions/24.json index 647193e2fb11..581c60e3bcfc 100644 --- a/public/intune-definitions/24.json +++ b/public/intune-definitions/24.json @@ -1 +1 @@ -{"24e14ccf3d5fbd72":{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp","displayName":"Maximum minutes of inactivity until screen locks","description":"Enter the maximum length of time, from 1 minute to 1 hour, that devices can be idle before the screen is automatically locked. Users must enter their credentials to regain access. For example, enter 5 to lock the device after 5 minutes of inactivity. Ignored by device if new time is longer than what's currently set on device. If set to Immediately, devices will use the minimum possible value per device.","helpText":"","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_1minute","displayName":"1 Minute","description":"Screen Timeout after 1 Minute of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_5minutes","displayName":"5 Minutes","description":"Screen Timeout after 5 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_15minutes","displayName":"15 Minutes","description":"Screen Timeout after 15 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_30minutes","displayName":"30 Minutes","description":"Screen Timeout after 30 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_1hour","displayName":"1 Hour","description":"Screen Timeout after 1 Hour of Inactivity","helpText":null}]},"24543e8abc9f5f40":{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification","displayName":"Allow Bluetooth Sharing Modification","description":"If 'false', prevents modifying Bluetooth setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification_true","displayName":"True","description":null,"helpText":null}]},"2471da5bcb2b6516":{"id":"com.apple.applicationaccess_allowmailsmartreplies","displayName":"Allow Mail Smart Replies (Deprecated)","description":"If false, disables smart replies in Mail.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmailsmartreplies_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmailsmartreplies_true","displayName":"True","description":null,"helpText":null}]},"24205497ff1e5722":{"id":"com.apple.applicationaccess_ratingappsca","displayName":"Rating Apps - Canada","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsca_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_22","displayName":"All","description":null,"helpText":null}]},"241f416d6a8c5280":{"id":"com.apple.finder_warnonemptytrash","displayName":"Warn On Empty Trash","description":"If false, the warning before a user empties the Trash can be disabled.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_warnonemptytrash_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_warnonemptytrash_true","displayName":"True","description":null,"helpText":null}]},"24550bd951a2c487":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"2426582d51b875d8":{"id":"com.apple.managedclient.preferences_exclusions_item_teamid_tamperprotection","displayName":"Process's TeamIdentifier","description":"Code signature TeamIdentifier","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},"24628a3ddcfaca23":{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\n\nIf you disable or don’t set this policy, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\n\nIf you enable this policy HTTP auth credentials entered in the context of one site will automatically be used in the context of another site.\n\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\n\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#globallyscopehttpauthcacheenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"243f666674492a32":{"id":"com.apple.managedclient.preferences_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable \"HttpsUpgradesEnabled\".\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\n\nBlanket host wildcards (that is, \"*\" or \"[*]\") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\n\nNote: This policy doesn't apply to HSTS upgrades.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#httpallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"24e9f027f869b257":{"id":"com.apple.managedclient.preferences_tlsciphersuitedenylist","displayName":"Specify the TLS cipher suites to disable","description":"Configure the list of cipher suites that are disabled for TLS connections.\n\nIf you configure this policy, the list of configured cipher suites will not be used when establishing TLS connections.\n\nIf you don't configure this policy, the browser will choose which TLS cipher suites to use.\n\nCipher suite values to be disabled are specified as 16-bit hexadecimal values. The values are assigned by the Internet Assigned Numbers Authority (IANA) registry.\n\nThe TLS 1.3 cipher suite TLS_AES_128_GCM_SHA256 (0x1301) is required for TLS 1.3 and can't be disabled by this policy.\n\nThis policy does not affect QUIC-based connections. QUIC can be turned off via the \"QuicAllowed\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tlsciphersuitedenylist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"2413c96f00622578":{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout","displayName":"Defer Dont Ask At User Logout","description":"If true, prevents requests for enabling FileVault at user logout time.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout_true","displayName":"Enabled","description":null,"helpText":null}]},"24ed90b2a51f7e41":{"id":"com.apple.universalaccess_slowkeydelay","displayName":"Slow Key Delay","description":"The acceptance delay, in milliseconds, for Slow Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},"242b6019cb9e64cc":{"id":"device_vendor_msft_laps_policies_passwordcomplexity","displayName":"Password Complexity ","description":"Use this setting to configure password complexity of the managed local administrator account.\n\nThe allowable settings are:\n\n1=Large letters\n2=Large letters + small letters\n3=Large letters + small letters + numbers\n4=Large letters + small letters + numbers + special characters\n\nIf not specified, this setting will default to 4.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_passwordcomplexity_1","displayName":"Large letters","description":"Large letters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_2","displayName":"Large letters + small letters","description":"Large letters + small letters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_3","displayName":"Large letters + small letters + numbers","description":"Large letters + small letters + numbers","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_4","displayName":"Large letters + small letters + numbers + special characters","description":"Large letters + small letters + numbers + special characters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_5","displayName":"Large letters + small letters + numbers + special characters (improved readability)","description":"Large letters + small letters + numbers + special characters (improved readability)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_6","displayName":"Passphrase (long words)","description":"Passphrase (long words)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_7","displayName":"Passphrase (short words)","description":"Passphrase (short words)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_8","displayName":"Passphrase (short words with unique prefixes)","description":"Passphrase (short words with unique prefixes)","helpText":null}]},"24b2898c6b748181":{"id":"device_vendor_msft_passportforwork_deviceunlock_plugins","displayName":"Device Unlock Plugins","description":"List of plugins that the passive provider monitors to detect user presence","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"240d2e0adb80dcef":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore","displayName":"Prevent creation of a system restore point during device activity that would normally prompt creation of a restore point","description":"This policy setting allows you to prevent Windows from creating a system restore point during device activity that would normally prompt Windows to create a system restore point. Windows normally creates restore points for certain driver activity, such as the installation of an unsigned driver. A system restore point enables you to more easily restore your system to its state before the activity. \r\n\r\nIf you enable this policy setting, Windows does not create a system restore point when one would normally be created.\r\n\r\nIf you disable or do not configure this policy setting, Windows creates a system restore point as it normally would.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-systemrestore"],"categoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","categoryName":"Device Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore_1","displayName":"Enabled","description":null,"helpText":null}]},"244c103dd018d2f0":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_pch_allornoneinc_list","displayName":"Report errors for applications on this list:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"24915d0f43007079":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay","displayName":"Configure local setting override for the removal of items from Quarantine folder","description":"This policy setting configures a local override for the configuration of the number of days items should be kept in the Quarantine folder before being removed. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-quarantine-localsettingoverridepurgeitemsafterdelay"],"categoryId":"a004deb8-6f52-4411-8d94-41563a8203fc","categoryName":"Quarantine","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"245cbe111be6b408":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection","displayName":"Configure local setting override for monitoring file and program activity on your computer","description":"This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisableonaccessprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection_1","displayName":"Enabled","description":null,"helpText":null}]},"24abfea45189754d":{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading","displayName":"Configure Client BranchCache Version Support","description":"This policy setting specifies whether BranchCache-capable client computers operate in a downgraded mode in order to maintain compatibility with previous versions of BranchCache. If client computers do not use the same BranchCache version, cache efficiency might be reduced because client computers that are using different versions of BranchCache might store cache data in incompatible formats.\r\n\r\nIf you enable this policy setting, all clients use the version of BranchCache that you specify in \"Select from the following versions.\"\r\n\r\nIf you do not configure this setting, all clients will use the version of BranchCache that matches their operating system.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, this policy setting is not applied to client computers, and the clients run the version of BranchCache that is included with their operating system.\r\n\r\n- Enabled. With this selection, this policy setting is applied to client computers based on the value of the option setting \"Select from the following versions\" that you specify.\r\n\r\n- Disabled. With this selection, this policy setting is not applied to client computers, and the clients run the version of BranchCache that is included with their operating system.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\nSelect from the following versions\r\n\r\n- Windows Vista with BITS 4.0 installed, Windows 7, or Windows Server 2008 R2. If you select this version, later versions of Windows run the version of BranchCache that is included in these operating systems rather than later versions of BranchCache.\r\n\r\n- Windows 8. If you select this version, Windows 8 will run the version of BranchCache that is included in the operating system.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setdowngrading"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_1","displayName":"Enabled","description":null,"helpText":null}]},"2495069e44f6908f":{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist","displayName":"RPC Runtime state information to maintain:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_1","displayName":"Auto1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_2","displayName":"Auto2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_3","displayName":"Server","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_4","displayName":"Full","description":null,"helpText":null}]},"245543a60e738c22":{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy_maxgposcriptwait","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":null},"248ea5aac91ffbab":{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2","displayName":"Turn off pen feedback","description":"Disables visual pen action feedback, except for press and hold feedback.\r\n\r\nIf you enable this policy, all visual pen action feedback is disabled except for press and hold feedback. Additionally, the mouse cursors are shown instead of the pen cursors.\r\n\r\nIf you disable or do not configure this policy, visual feedback and pen cursors will be shown unless the user disables them in Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-turnofffeedback-2"],"categoryId":"9b894b32-3697-4a83-9731-3db2a35455ad","categoryName":"Cursors","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2_1","displayName":"Enabled","description":null,"helpText":null}]},"2470030822c3c083":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter","displayName":"Microsoft Office 2016 Upload Center","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 2016 Upload Center.\r\nBy default, the user settings of Microsoft Office 2016 Upload Center synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Office 2016 Upload Center from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Office 2016 Upload Center user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Office 2016 Upload Center user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016uploadcenter"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter_1","displayName":"Enabled","description":null,"helpText":null}]},"246f38f0f03e569b":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016","displayName":"Microsoft Office 365 OneNote 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 OneNote 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 OneNote 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 OneNote 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 OneNote 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 OneNote 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365onenote2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016_1","displayName":"Enabled","description":null,"helpText":null}]},"2423f1dbb6c391a1":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_publishing_server3_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"24e6b41443c3edec":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"24db2d5857c23cc1":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination","displayName":"Detailed Tracking Audit Process Termination","description":"This policy setting allows you to audit events generated when a process ends. If you configure this policy setting, an audit event is generated when a process ends. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a process ends.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditprocesstermination"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"24c025747b10f39e":{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent Smart Screen Prompt Override For Files","description":"Don't allow Windows Defender SmartScreen warning overrides for unverified files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventsmartscreenpromptoverrideforfiles"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles_0","displayName":"Disabled","description":"Allowed/turned off. Users can ignore the warning and continue to download the unverified file(s).","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},"2417714223d3eab7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended","displayName":"Parameters for search URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"24a71fcb1022dbe9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended","displayName":"Safe Browsing Protection Level","description":"Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in.\r\n\r\nIf this policy is set to 'NoProtection' (value 0), Safe Browsing is never active.\r\n\r\nIf this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode.\r\n\r\nIf this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google.\r\n\r\nIf you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome.\r\n\r\nIf this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.\r\n\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.","helpText":"","infoUrls":[],"categoryId":"af351b0c-3d9e-4b18-957b-8179e4eaba15","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"24dfb28bd1ea2b0d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation","displayName":"Set the roaming profile directory","description":"Configures the directory that Google Chrome will use for storing the roaming copy of the profiles.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory to store the roaming copy of the profiles if the RoamingProfileSupportEnabled policy has been enabled. If the RoamingProfileSupportEnabled policy is disabled or left unset the value stored in this policy is not used.\r\n\r\nSee https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.\r\n\r\nOn non-Windows platforms, this policy must be set for roaming profiles to work.\r\n\r\nOn Windows, if this policy is left unset, the default roaming profile path will be used.\r\n\r\nExample value: ${roaming_app_data}\\chrome-profile","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"247bf8d55a1d0862":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_cookiessessiononlyforurlsdesc","displayName":"Limit cookies from matching URLs to the current session (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"24debfc9709cf5a2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed","displayName":"Allow or deny screen capture","description":"If enabled or not configured (default), a Web page can use\r\nscreen-share APIs (e.g., getDisplayMedia() or the Desktop Capture extension API)\r\nto prompt the user to select a tab, window or desktop to capture.\r\n\r\nWhen this policy is disabled, any calls to screen-share APIs will fail\r\nwith an error; however this policy is not considered (and a site will be\r\nallowed to use screen-share APIs) if the site matches an origin pattern in\r\nany of the following policies:\r\nScreenCaptureAllowedByOrigins,\r\nWindowCaptureAllowedByOrigins,\r\nTabCaptureAllowedByOrigins,\r\nSameOriginTabCaptureAllowedByOrigins.\r\n","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"245954f32f8883a0":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled","displayName":"Re-enable the deprecated window.webkitStorageInfo API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"242a764470cae9cb":{"id":"device_vendor_msft_policy_config_deviceinstallation_preventinstallationofmatchingdeviceinstanceids_deviceinstall_instance_ids_deny_retroactive","displayName":"Also apply to matching devices that are already installed.","description":"","helpText":"","infoUrls":[],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_deviceinstallation_preventinstallationofmatchingdeviceinstanceids_deviceinstall_instance_ids_deny_retroactive_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deviceinstallation_preventinstallationofmatchingdeviceinstanceids_deviceinstall_instance_ids_deny_retroactive_1","displayName":"True","description":null,"helpText":null}]},"24f69e944571ead6":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingjavaruleeditor","displayName":"Java rule editor","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging fo the Java Rule Editor.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\JavaRuleEditor\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingjavaruleeditor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingjavaruleeditor_1","displayName":"Enabled","description":null,"helpText":null}]},"2484bc1de7d36f7b":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},"24b5bccbd19c4e8f":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata","displayName":"Trusted Domain List","description":"\r\nWhen Lync connects to an unknown domain, it needs explicit user consent. A dialog is shown asking the user for confirmation on whether it should continue.\r\n\r\nThis policy gives administrators the ability to provide trusted domain names. If a domain name is added to this list, Lync will trust that domain and will not show the dialog requesting permission. Multiple domain addresses as comma separated values can be provided.\r\n\r\nBy setting this policy, Lync will not explicitly trust the default domains specified below. It will exclusively trust the domain specified by the policy.\r\n\r\nSupported values:\r\n Not Configured (Default)/Disabled: By default the following domains will be trusted: \"lync.com, outlook.com, lync.glbdns.microsoft.com, and microsoftonline.com.\"\r\n Enabled: The list of domains to be trusted. For example: \"contoso.com, contoso.co.in\"\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1","displayName":"Enabled","description":null,"helpText":null}]},"2485e33a93c5e3ff":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting","displayName":"Default Adobe Flash setting","description":"Determines whether websites that aren't covered by 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites) or 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) can automatically run the Adobe Flash plug-in. You can select 'BlockPlugins' (2) to block Adobe Flash on all sites, or you can select 'ClickToPlay' (3) to let Adobe Flash run but require the user to click the placeholder to start it. In any case, the 'PluginsAllowedForUrls' and 'PluginsBlockedForUrls' policies take precedence over 'DefaultPluginsSetting'.\r\n\r\nAutomatic playback is only allowed for domains explicitly listed in the 'PluginsAllowedForUrls' policy. If you want to enable automatic playback for all sites, consider adding http://* and https://* to this list.\r\n\r\nIf you don't configure this policy, the user can change this setting manually.\r\n\r\n* 2 = Block the Adobe Flash plug-in\r\n\r\n* 3 = Click to play\r\n\r\nThe former '1' option set allow-all, but this functionality is now only handled by the 'PluginsAllowedForUrls' policy. Existing policies using '1' will operate in Click-to-play mode.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"24c7d2b5f12772b5":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled. Organizations can use this policy to maintain access to servers that do not support HTTPS, without needing to disable 'AutomaticHttpsDefault' (Configure Automatic HTTPS).\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"241e160d3f29999a":{"id":"device_vendor_msft_policy_config_remoteassistance_customizewarningmessages_ra_options_connect_message","displayName":"Display warning message before connecting:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":null},"241c875eb63ba95b":{"id":"device_vendor_msft_policy_config_update_disabledualscan","displayName":"Disable Dual Scan","description":"Do not allow update deferral policies to cause scans against Windows Update","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#disabledualscan"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_disabledualscan_0","displayName":"allow scan against Windows Update","description":"allow scan against Windows Update","helpText":null},{"id":"device_vendor_msft_policy_config_update_disabledualscan_1","displayName":"do not allow update deferral policies to cause scans against Windows Update","description":"do not allow update deferral policies to cause scans against Windows Update","helpText":null}]},"240b8f50cf462df0":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_cachepath","displayName":"Package manifest and payload cache path","description":"The directory where package manifests and, optionally, payloads are stored.\r\n\r\nThe Visual Studio Installer enforces a 50 character limit for the path.\r\n\r\nFor more information, see http://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_cachepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_cachepath_1","displayName":"Enabled","description":null,"helpText":null}]},"24828c4230afc490":{"id":"linux_mdatp_managed_edr_tags_item_value","displayName":"Value of tag","description":"Only one value per tag type can be set. Type of tags are unique, and should not be repeated in the same configuration profile.","helpText":null,"infoUrls":[],"categoryId":"22a2a407-0f28-481d-bdbe-1f9cb6d589c3","categoryName":" EDR preferences","options":null},"242c005ff258dbb3":{"id":"user_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_1","displayName":"Run logon scripts synchronously (User)","description":"This policy setting directs the system to wait for logon scripts to finish running before it starts the File Explorer interface program and creates the desktop.\r\n\r\nIf you enable this policy setting, File Explorer does not start until the logon scripts have finished running. This policy setting ensures that logon script processing is complete before the user starts working, but it can delay the appearance of the desktop.\r\n\r\nIf you disable or do not configure this policy setting, the logon scripts and File Explorer are not synchronized and can run simultaneously.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. The policy setting set in Computer Configuration takes precedence over the policy setting set in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-logon-script-sync-1"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"user_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_1_1","displayName":"Enabled","description":null,"helpText":null}]},"24b4ce10c6a64316":{"id":"user_vendor_msft_policy_config_admx_startmenu_forcestartmenulogoff","displayName":"Add Logoff to the Start Menu (User)","description":"This policy only applies to the classic version of the start menu and does not affect the new style start menu.\r\n\r\nAdds the \"Log Off \" item to the Start menu and prevents users from removing it.\r\n\r\nIf you enable this setting, the Log Off item appears in the Start menu. This setting also removes the Display Logoff item from Start Menu Options. As a result, users cannot remove the Log Off item from the Start Menu.\r\n\r\nIf you disable this setting or do not configure it, users can use the Display Logoff item to add and remove the Log Off item.\r\n\r\nThis setting affects the Start menu only. It does not affect the Log Off item on the Windows Security dialog box that appears when you press Ctrl+Alt+Del.\r\n\r\nNote: To add or remove the Log Off item on a computer, click Start, click Settings, click Taskbar and Start Menu, click the Start Menu Options tab, and then, in the Start Menu Settings box, click Display Logoff.\r\n\r\nAlso, see \"Remove Logoff\" in User Configuration\\Administrative Templates\\System\\Logon/Logoff.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-forcestartmenulogoff"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_forcestartmenulogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_forcestartmenulogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"2420b0e76893c0e6":{"id":"user_vendor_msft_policy_config_admx_startmenu_nostartmenuhomegroup","displayName":"Remove Homegroup link from Start Menu (User)","description":"If you enable this policy the Start menu will not show a link to Homegroup. It also removes the homegroup item from the Start Menu options. As a result, users cannot add the homegroup link to the Start Menu.\r\n\r\n If you disable or do not configure this policy, users can use the Start Menu options to add or remove the homegroup link from the Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nostartmenuhomegroup"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nostartmenuhomegroup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nostartmenuhomegroup_1","displayName":"Enabled","description":null,"helpText":null}]},"24c24fae5789cb22":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls","displayName":"Allow images on these sites (User)","description":"Setting the policy lets you set a list of URL patterns that specify sites that may display images.\r\n\r\nLeaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nNote that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"249ec975fc49d417":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nExample value: https://search.my.company/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},"2486185efd787291":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"2494093255ad1b96":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_passwordmanagerblocklistdesc","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":null},"2495d229078cb2ae":{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols","displayName":"Remove \"Run this time\" button for outdated ActiveX controls in Internet Explorer (User)","description":"This policy setting allows you to stop users from seeing the \"Run this time\" button and from running specific outdated ActiveX controls in Internet Explorer.\n\nIf you enable this policy setting, users won't see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control.\n\nIf you disable or don't configure this policy setting, users will see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control. Clicking this button lets the user run the outdated ActiveX control once.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-removerunthistimebuttonforoutdatedactivexcontrols"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"24d6a66c69947932":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins","displayName":"Run ActiveX controls and plugins (User)","description":"This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone.\n\nIf you enable this policy setting, controls and plug-ins can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow the controls or plug-in to run.\n\nIf you disable this policy setting, controls and plug-ins are prevented from running.\n\nIf you do not configure this policy setting, controls and plug-ins are prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonerunactivexcontrolsandplugins"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_1","displayName":"Enabled","description":null,"helpText":null}]},"24638e22839c2a86":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_videocaptureallowedurlsdesc","displayName":"Sites that can access video capture devices without requesting permission (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"242673cc9f4d06bc":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages (User)","description":"An \"in-page\" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous \"in-page\" navigation attempt. Conversely, a user can start a navigation that isn't \"in-page\" that's independent of the current page in several ways by using the browser controls. For example, using the address bar, the back button, or a favorite link.\r\n\r\nThis setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that are not configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\nIf you disable or don’t configure this policy, only sites configured to open in Internet Explorer mode will open in that mode. Any site not configured to open in Internet Explorer mode will be redirected back to Microsoft Edge.\r\n\r\nIf you set this policy to Default (value 0), only sites configured to open in Internet Explorer mode will open in that mode. Any site not configured to open in Internet Explorer mode will be redirected back to Microsoft Edge.\r\n\r\nIf you set this policy to AutomaticNavigationsOnly (value 1), you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites will be kept in Internet Explorer mode.\r\n\r\nIf you set this policy to AllInPageNavigations (value 2), all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended).\r\n\r\nIf you enable this policy, you can choose one of the following navigation options:\r\n\r\n* 0 = Default\r\n\r\n* 1 = Keep only automatic navigations in Internet Explorer mode\r\n\r\n* 2 = Keep all in-page navigations in Internet Explorer mode\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_1","displayName":"Enabled","description":null,"helpText":null}]},"24cd8d8505da62de":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceservername5","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"2452e72576c2af1e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework_l_workadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"2461d3f188207b1c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid","displayName":"Type of diagnostic data: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_3","displayName":"Neither","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_2","displayName":"Optional","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_1","displayName":"Required","description":null,"helpText":null}]},"242677b006ad8743":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},"24aadfbd7084f527":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313_1","displayName":"True","description":null,"helpText":null}]},"241401662334467f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_100","displayName":"100","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_450","displayName":"450","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_5000","displayName":"5000","description":null,"helpText":null}]},"24572c11b8a93a59":{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_l_newoutlookautomigrationretryintervalsid","displayName":"New Outlook Auto Migration Retry Interval: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},"2422d04d0626df99":{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade","displayName":"Disable web add-in installation on migration to new Outlook for Windows (User)","description":"This policy setting allows you to disable installation of web add-in equivalents of COM add-ins on the switch to new Outlook. The add-ins available for migration are listed in https://aka.ms/newoutlooksettings.\r\n\r\nLearn more about Outlook web add-ins at https://learn.microsoft.com/office/dev/add-ins/outlook/outlook-add-ins-overview.\r\n\r\nCOM add-ins do not work in new Outlook for Windows. By default, users in the organization will get the option to install available web add-ins, in place of COM add-ins, when they move from classic Outlook for Windows.\r\n\r\nIf you enable this policy setting, users will not get the option to install web add-ins in place of their COM add-ins. \r\n \r\nIf you disable or do not configure this policy setting, users will get an option to install web add-ins in place of their COM add-ins.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},"242184c1347a1681":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications","displayName":"Do not send meeting forward notifications (User)","description":"This policy setting prevents Outlook from sending meeting forward notifications. This does not affect whether or not Exchange sends meeting forward notifications. \r\n\r\nIf you enable this policy setting, Outlook will not send meeting forward notifications.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will send meeting forward notifications.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"24274f35799cbe66":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2","displayName":"Allow users to demote attachments to Level 2 (User)","description":"This policy setting controls whether Outlook users can demote attachments to Level 2 by using a registry key, which will allow them to save files to disk and open them from that location. Outlook uses two levels of security to restrict access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, users can create a list of Level 1 file types to demote to Level 2 by adding the file types to the following registry key: HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove. \r\n\r\nIf you disable or do not configure this policy setting, users cannot demote level 1 attachments to level 2, and the HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove registry key has no effect.\r\n","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"246fcaa481b63429":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview","displayName":"Turn off camera recording by default when recording a slide show (User)","description":"This policy setting allows you to set camera recording off by default when recording a slide show.\r\n\r\nBy default, camera recording is on the first time a user records a slide show. If the user turns off camera recording, then camera recording will be off the next time the slide show recording window is launched, even if PowerPoint is closed and reopened.\r\n\r\nIf you enable this policy setting, camera recording is turned off by default. A user can turn on camera recording when recording a slide show. But, the next time the slide show recording window is launched, camera recording will be off by default.\r\n\r\nIf you disable or don’t configure this policy setting, the default state of camera recording is determined by the user, unless the “Turn off microphone recording by default when recording a slide show” policy setting is enabled. Enabling that policy setting also turns off camera recording by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview_1","displayName":"Enabled","description":null,"helpText":null}]},"24a7cc9ff165051c":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits","displayName":"Show assignment units as (User)","description":"Shows resource assignments units as a decimal or percentage.\r\n\r\nIf you enable this setting, resource assignment units will be set to the option you choose from the list.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"304a579b-ff3b-4897-8bb8-5a1dda45356f","categoryName":"Schedule options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_1","displayName":"Enabled","description":null,"helpText":null}]},"241c72d7bb509f21":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the 2016 versions of the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the 2016 versions of the specified applications are ignored, including any trusted locations established by Office during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the 2016 versions of the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},"2493a848d76405a5":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},"24208afa8aa0205a":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana","displayName":"Match hiragana/katakana (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana_1","displayName":"Enabled","description":null,"helpText":null}]},"2485661843deba00":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"24e14ccf3d5fbd72":{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp","displayName":"Maximum minutes of inactivity until screen locks","description":"Enter the maximum length of time, from 1 minute to 1 hour, that devices can be idle before the screen is automatically locked. Users must enter their credentials to regain access. For example, enter 5 to lock the device after 5 minutes of inactivity. Ignored by device if new time is longer than what's currently set on device. If set to Immediately, devices will use the minimum possible value per device.","helpText":"","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_1minute","displayName":"1 Minute","description":"Screen Timeout after 1 Minute of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_5minutes","displayName":"5 Minutes","description":"Screen Timeout after 5 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_15minutes","displayName":"15 Minutes","description":"Screen Timeout after 15 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_30minutes","displayName":"30 Minutes","description":"Screen Timeout after 30 Minutes of Inactivity","helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordminutesofinactivitybeforescreentimeoutaosp_1hour","displayName":"1 Hour","description":"Screen Timeout after 1 Hour of Inactivity","helpText":null}]},"24543e8abc9f5f40":{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification","displayName":"Allow Bluetooth Sharing Modification","description":"If 'false', prevents modifying Bluetooth setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbluetoothsharingmodification_true","displayName":"True","description":null,"helpText":null}]},"2471da5bcb2b6516":{"id":"com.apple.applicationaccess_allowmailsmartreplies","displayName":"Allow Mail Smart Replies (Deprecated)","description":"If false, disables smart replies in Mail.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmailsmartreplies_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmailsmartreplies_true","displayName":"True","description":null,"helpText":null}]},"24205497ff1e5722":{"id":"com.apple.applicationaccess_ratingappsca","displayName":"Rating Apps - Canada","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsca_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsca_22","displayName":"All","description":null,"helpText":null}]},"241f416d6a8c5280":{"id":"com.apple.finder_warnonemptytrash","displayName":"Warn On Empty Trash","description":"If false, the warning before a user empties the Trash can be disabled.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_warnonemptytrash_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_warnonemptytrash_true","displayName":"True","description":null,"helpText":null}]},"24550bd951a2c487":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"2426582d51b875d8":{"id":"com.apple.managedclient.preferences_exclusions_item_teamid_tamperprotection","displayName":"Process's TeamIdentifier","description":"Code signature TeamIdentifier","helpText":null,"infoUrls":[],"categoryId":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","categoryName":"Tamper protection","options":null},"24628a3ddcfaca23":{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\n\nIf you disable or don’t set this policy, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\n\nIf you enable this policy HTTP auth credentials entered in the context of one site will automatically be used in the context of another site.\n\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\n\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#globallyscopehttpauthcacheenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_globallyscopehttpauthcacheenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"243f666674492a32":{"id":"com.apple.managedclient.preferences_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that won't be upgraded to HTTPS. Organizations can use this policy to maintain access to servers that don't support HTTPS, without needing to disable \"HttpsUpgradesEnabled\".\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\n\nBlanket host wildcards (that is, \"*\" or \"[*]\") aren't allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\n\nNote: This policy doesn't apply to HSTS upgrades.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#httpallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"24e9f027f869b257":{"id":"com.apple.managedclient.preferences_tlsciphersuitedenylist","displayName":"Specify the TLS cipher suites to disable","description":"Configure the list of cipher suites that are disabled for TLS connections.\n\nIf you configure this policy, the list of configured cipher suites will not be used when establishing TLS connections.\n\nIf you don't configure this policy, the browser will choose which TLS cipher suites to use.\n\nCipher suite values to be disabled are specified as 16-bit hexadecimal values. The values are assigned by the Internet Assigned Numbers Authority (IANA) registry.\n\nThe TLS 1.3 cipher suite TLS_AES_128_GCM_SHA256 (0x1301) is required for TLS 1.3 and can't be disabled by this policy.\n\nThis policy does not affect QUIC-based connections. QUIC can be turned off via the \"QuicAllowed\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tlsciphersuitedenylist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"2413c96f00622578":{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout","displayName":"Defer Dont Ask At User Logout","description":"If true, prevents requests for enabling FileVault at user logout time.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_deferdontaskatuserlogout_true","displayName":"Enabled","description":null,"helpText":null}]},"24ed90b2a51f7e41":{"id":"com.apple.universalaccess_slowkeydelay","displayName":"Slow Key Delay","description":"The acceptance delay, in milliseconds, for Slow Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},"242b6019cb9e64cc":{"id":"device_vendor_msft_laps_policies_passwordcomplexity","displayName":"Password Complexity ","description":"Use this setting to configure password complexity of the managed local administrator account.\n\nThe allowable settings are:\n\n1=Large letters\n2=Large letters + small letters\n3=Large letters + small letters + numbers\n4=Large letters + small letters + numbers + special characters\n\nIf not specified, this setting will default to 4.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_passwordcomplexity_1","displayName":"Large letters","description":"Large letters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_2","displayName":"Large letters + small letters","description":"Large letters + small letters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_3","displayName":"Large letters + small letters + numbers","description":"Large letters + small letters + numbers","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_4","displayName":"Large letters + small letters + numbers + special characters","description":"Large letters + small letters + numbers + special characters","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_5","displayName":"Large letters + small letters + numbers + special characters (improved readability)","description":"Large letters + small letters + numbers + special characters (improved readability)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_6","displayName":"Passphrase (long words)","description":"Passphrase (long words)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_7","displayName":"Passphrase (short words)","description":"Passphrase (short words)","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordcomplexity_8","displayName":"Passphrase (short words with unique prefixes)","description":"Passphrase (short words with unique prefixes)","helpText":null}]},"24b2898c6b748181":{"id":"device_vendor_msft_passportforwork_deviceunlock_plugins","displayName":"Device Unlock Plugins","description":"List of plugins that the passive provider monitors to detect user presence","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"240d2e0adb80dcef":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore","displayName":"Prevent creation of a system restore point during device activity that would normally prompt creation of a restore point","description":"This policy setting allows you to prevent Windows from creating a system restore point during device activity that would normally prompt Windows to create a system restore point. Windows normally creates restore points for certain driver activity, such as the installation of an unsigned driver. A system restore point enables you to more easily restore your system to its state before the activity. \r\n\r\nIf you enable this policy setting, Windows does not create a system restore point when one would normally be created.\r\n\r\nIf you disable or do not configure this policy setting, Windows creates a system restore point as it normally would.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-systemrestore"],"categoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","categoryName":"Device Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_systemrestore_1","displayName":"Enabled","description":null,"helpText":null}]},"244c103dd018d2f0":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_pch_allornoneinc_list","displayName":"Report errors for applications on this list:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"24915d0f43007079":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay","displayName":"Configure local setting override for the removal of items from Quarantine folder","description":"This policy setting configures a local override for the configuration of the number of days items should be kept in the Quarantine folder before being removed. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-quarantine-localsettingoverridepurgeitemsafterdelay"],"categoryId":"a004deb8-6f52-4411-8d94-41563a8203fc","categoryName":"Quarantine","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_quarantine_localsettingoverridepurgeitemsafterdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"245cbe111be6b408":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection","displayName":"Configure local setting override for monitoring file and program activity on your computer","description":"This policy setting configures a local override for the configuration of monitoring for file and program activity on your computer. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisableonaccessprotection"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisableonaccessprotection_1","displayName":"Enabled","description":null,"helpText":null}]},"24abfea45189754d":{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading","displayName":"Configure Client BranchCache Version Support","description":"This policy setting specifies whether BranchCache-capable client computers operate in a downgraded mode in order to maintain compatibility with previous versions of BranchCache. If client computers do not use the same BranchCache version, cache efficiency might be reduced because client computers that are using different versions of BranchCache might store cache data in incompatible formats.\r\n\r\nIf you enable this policy setting, all clients use the version of BranchCache that you specify in \"Select from the following versions.\"\r\n\r\nIf you do not configure this setting, all clients will use the version of BranchCache that matches their operating system.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, this policy setting is not applied to client computers, and the clients run the version of BranchCache that is included with their operating system.\r\n\r\n- Enabled. With this selection, this policy setting is applied to client computers based on the value of the option setting \"Select from the following versions\" that you specify.\r\n\r\n- Disabled. With this selection, this policy setting is not applied to client computers, and the clients run the version of BranchCache that is included with their operating system.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\nSelect from the following versions\r\n\r\n- Windows Vista with BITS 4.0 installed, Windows 7, or Windows Server 2008 R2. If you select this version, later versions of Windows run the version of BranchCache that is included in these operating systems rather than later versions of BranchCache.\r\n\r\n- Windows 8. If you select this version, Windows 8 will run the version of BranchCache that is included in the operating system.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setdowngrading"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdowngrading_1","displayName":"Enabled","description":null,"helpText":null}]},"2495069e44f6908f":{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist","displayName":"RPC Runtime state information to maintain:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_0","displayName":"None","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_1","displayName":"Auto1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_2","displayName":"Auto2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_3","displayName":"Server","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_rpcstateinformationlist_4","displayName":"Full","description":null,"helpText":null}]},"245543a60e738c22":{"id":"device_vendor_msft_policy_config_admx_scripts_maxgposcriptwaitpolicy_maxgposcriptwait","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":null},"248ea5aac91ffbab":{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2","displayName":"Turn off pen feedback","description":"Disables visual pen action feedback, except for press and hold feedback.\r\n\r\nIf you enable this policy, all visual pen action feedback is disabled except for press and hold feedback. Additionally, the mouse cursors are shown instead of the pen cursors.\r\n\r\nIf you disable or do not configure this policy, visual feedback and pen cursors will be shown unless the user disables them in Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-turnofffeedback-2"],"categoryId":"9b894b32-3697-4a83-9731-3db2a35455ad","categoryName":"Cursors","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnofffeedback_2_1","displayName":"Enabled","description":null,"helpText":null}]},"2470030822c3c083":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter","displayName":"Microsoft Office 2016 Upload Center","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 2016 Upload Center.\r\nBy default, the user settings of Microsoft Office 2016 Upload Center synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Office 2016 Upload Center from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Office 2016 Upload Center user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Office 2016 Upload Center user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016uploadcenter"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016uploadcenter_1","displayName":"Enabled","description":null,"helpText":null}]},"246f38f0f03e569b":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016","displayName":"Microsoft Office 365 OneNote 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 OneNote 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 OneNote 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 OneNote 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 OneNote 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 OneNote 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365onenote2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2016_1","displayName":"Enabled","description":null,"helpText":null}]},"2423f1dbb6c391a1":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_publishing_server3_name_prompt","displayName":"Publishing Server Display Name","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"24e6b41443c3edec":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"24db2d5857c23cc1":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination","displayName":"Detailed Tracking Audit Process Termination","description":"This policy setting allows you to audit events generated when a process ends. If you configure this policy setting, an audit event is generated when a process ends. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a process ends.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditprocesstermination"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesstermination_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"24c025747b10f39e":{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent Smart Screen Prompt Override For Files","description":"Don't allow Windows Defender SmartScreen warning overrides for unverified files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventsmartscreenpromptoverrideforfiles"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles_0","displayName":"Disabled","description":"Allowed/turned off. Users can ignore the warning and continue to download the unverified file(s).","helpText":null},{"id":"device_vendor_msft_policy_config_browser_preventsmartscreenpromptoverrideforfiles_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},"2417714223d3eab7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended","displayName":"Parameters for search URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersearchurlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"24a71fcb1022dbe9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended","displayName":"Safe Browsing Protection Level","description":"Allows you to control whether Google Chrome's Safe Browsing feature is enabled and the mode it operates in.\r\n\r\nIf this policy is set to 'NoProtection' (value 0), Safe Browsing is never active.\r\n\r\nIf this policy is set to 'StandardProtection' (value 1, which is the default), Safe Browsing is always active in the standard mode.\r\n\r\nIf this policy is set to 'EnhancedProtection' (value 2), Safe Browsing is always active in the enhanced mode, which provides better security, but requires sharing more browsing information with Google.\r\n\r\nIf you set this policy as mandatory, users cannot change or override the Safe Browsing setting in Google Chrome.\r\n\r\nIf this policy is left not set, Safe Browsing will operate in Standard Protection mode but users can change this setting.\r\n\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.","helpText":"","infoUrls":[],"categoryId":"af351b0c-3d9e-4b18-957b-8179e4eaba15","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~safebrowsing_recommended_safebrowsingprotectionlevel_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"24dfb28bd1ea2b0d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation","displayName":"Set the roaming profile directory","description":"Configures the directory that Google Chrome will use for storing the roaming copy of the profiles.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory to store the roaming copy of the profiles if the RoamingProfileSupportEnabled policy has been enabled. If the RoamingProfileSupportEnabled policy is disabled or left unset the value stored in this policy is not used.\r\n\r\nSee https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables for a list of variables that can be used.\r\n\r\nOn non-Windows platforms, this policy must be set for roaming profiles to work.\r\n\r\nOn Windows, if this policy is left unset, the default roaming profile path will be used.\r\n\r\nExample value: ${roaming_app_data}\\chrome-profile","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"247bf8d55a1d0862":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_cookiessessiononlyforurlsdesc","displayName":"Limit cookies from matching URLs to the current session (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"24debfc9709cf5a2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed","displayName":"Allow or deny screen capture","description":"If enabled or not configured (default), a Web page can use\r\nscreen-share APIs (e.g., getDisplayMedia() or the Desktop Capture extension API)\r\nto prompt the user to select a tab, window or desktop to capture.\r\n\r\nWhen this policy is disabled, any calls to screen-share APIs will fail\r\nwith an error; however this policy is not considered (and a site will be\r\nallowed to use screen-share APIs) if the site matches an origin pattern in\r\nany of the following policies:\r\nScreenCaptureAllowedByOrigins,\r\nWindowCaptureAllowedByOrigins,\r\nTabCaptureAllowedByOrigins,\r\nSameOriginTabCaptureAllowedByOrigins.\r\n","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_screencaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"245954f32f8883a0":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled","displayName":"Re-enable the deprecated window.webkitStorageInfo API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedstorageinfoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"242a764470cae9cb":{"id":"device_vendor_msft_policy_config_deviceinstallation_preventinstallationofmatchingdeviceinstanceids_deviceinstall_instance_ids_deny_retroactive","displayName":"Also apply to matching devices that are already installed.","description":"","helpText":"","infoUrls":[],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_deviceinstallation_preventinstallationofmatchingdeviceinstanceids_deviceinstall_instance_ids_deny_retroactive_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deviceinstallation_preventinstallationofmatchingdeviceinstanceids_deviceinstall_instance_ids_deny_retroactive_1","displayName":"True","description":null,"helpText":null}]},"24f69e944571ead6":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingjavaruleeditor","displayName":"Java rule editor","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging fo the Java Rule Editor.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\JavaRuleEditor\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingjavaruleeditor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingjavaruleeditor_1","displayName":"Enabled","description":null,"helpText":null}]},"2484bc1de7d36f7b":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},"24b5bccbd19c4e8f":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata","displayName":"Trusted Domain List","description":"\r\nWhen Lync connects to an unknown domain, it needs explicit user consent. A dialog is shown asking the user for confirmation on whether it should continue.\r\n\r\nThis policy gives administrators the ability to provide trusted domain names. If a domain name is added to this list, Lync will trust that domain and will not show the dialog requesting permission. Multiple domain addresses as comma separated values can be provided.\r\n\r\nBy setting this policy, Lync will not explicitly trust the default domains specified below. It will exclusively trust the domain specified by the policy.\r\n\r\nSupported values:\r\n Not Configured (Default)/Disabled: By default the following domains will be trusted: \"lync.com, outlook.com, lync.glbdns.microsoft.com, and microsoftonline.com.\"\r\n Enabled: The list of domains to be trusted. For example: \"contoso.com, contoso.co.in\"\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_1","displayName":"Enabled","description":null,"helpText":null}]},"24de3bcb452b9ef6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled","displayName":"Enable Process Isolation","description":"This policy controls Process Isolation in Microsoft Edge.\n\nWhen this policy is enabled, Microsoft Edge uses Process Isolation to help improve browser security by preventing authorized applications on the device from reading or modifying the contents of Microsoft Edge's running processes. This also helps prevent other applications from accessing encrypted data used by Microsoft Edge.\n\nEnabling Process Isolation may cause incompatibilities with third party applications that rely on being able to inject or tamper with Microsoft Edge's processes, such as antivirus, screen reader or window manager applications.\n\nSetting the policy to Enabled turns on process isolation in Microsoft Edge.\n\nSetting the policy to Disabled turns off process isolation in Microsoft Edge.\n\nIf this policy is unset, Microsoft Edge will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users.\n\nNote: This policy is applied when Microsoft Edge starts. If the policy is changed while Microsoft Edge is running, the new setting will take effect on the next restart.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2485e33a93c5e3ff":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting","displayName":"Default Adobe Flash setting","description":"Determines whether websites that aren't covered by 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites) or 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) can automatically run the Adobe Flash plug-in. You can select 'BlockPlugins' (2) to block Adobe Flash on all sites, or you can select 'ClickToPlay' (3) to let Adobe Flash run but require the user to click the placeholder to start it. In any case, the 'PluginsAllowedForUrls' and 'PluginsBlockedForUrls' policies take precedence over 'DefaultPluginsSetting'.\r\n\r\nAutomatic playback is only allowed for domains explicitly listed in the 'PluginsAllowedForUrls' policy. If you want to enable automatic playback for all sites, consider adding http://* and https://* to this list.\r\n\r\nIf you don't configure this policy, the user can change this setting manually.\r\n\r\n* 2 = Block the Adobe Flash plug-in\r\n\r\n* 3 = Click to play\r\n\r\nThe former '1' option set allow-all, but this functionality is now only handled by the 'PluginsAllowedForUrls' policy. Existing policies using '1' will operate in Click-to-play mode.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpluginssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"24c7d2b5f12772b5":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as '[*.]example.com') that will not be upgraded to HTTPS and will not show an error interstitial if HTTPS-First Mode is enabled. Organizations can use this policy to maintain access to servers that do not support HTTPS, without needing to disable 'AutomaticHttpsDefault' (Configure Automatic HTTPS).\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead, HTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their specific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"241e160d3f29999a":{"id":"device_vendor_msft_policy_config_remoteassistance_customizewarningmessages_ra_options_connect_message","displayName":"Display warning message before connecting:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":null},"241c875eb63ba95b":{"id":"device_vendor_msft_policy_config_update_disabledualscan","displayName":"Disable Dual Scan","description":"Do not allow update deferral policies to cause scans against Windows Update","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#disabledualscan"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_disabledualscan_0","displayName":"allow scan against Windows Update","description":"allow scan against Windows Update","helpText":null},{"id":"device_vendor_msft_policy_config_update_disabledualscan_1","displayName":"do not allow update deferral policies to cause scans against Windows Update","description":"do not allow update deferral policies to cause scans against Windows Update","helpText":null}]},"240b8f50cf462df0":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_cachepath","displayName":"Package manifest and payload cache path","description":"The directory where package manifests and, optionally, payloads are stored.\r\n\r\nThe Visual Studio Installer enforces a 50 character limit for the path.\r\n\r\nFor more information, see http://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_cachepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_cachepath_1","displayName":"Enabled","description":null,"helpText":null}]},"24828c4230afc490":{"id":"linux_mdatp_managed_edr_tags_item_value","displayName":"Value of tag","description":"Only one value per tag type can be set. Type of tags are unique, and should not be repeated in the same configuration profile.","helpText":null,"infoUrls":[],"categoryId":"22a2a407-0f28-481d-bdbe-1f9cb6d589c3","categoryName":" EDR preferences","options":null},"242c005ff258dbb3":{"id":"user_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_1","displayName":"Run logon scripts synchronously (User)","description":"This policy setting directs the system to wait for logon scripts to finish running before it starts the File Explorer interface program and creates the desktop.\r\n\r\nIf you enable this policy setting, File Explorer does not start until the logon scripts have finished running. This policy setting ensures that logon script processing is complete before the user starts working, but it can delay the appearance of the desktop.\r\n\r\nIf you disable or do not configure this policy setting, the logon scripts and File Explorer are not synchronized and can run simultaneously.\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. The policy setting set in Computer Configuration takes precedence over the policy setting set in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-run-logon-script-sync-1"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"user_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_scripts_run_logon_script_sync_1_1","displayName":"Enabled","description":null,"helpText":null}]},"24b4ce10c6a64316":{"id":"user_vendor_msft_policy_config_admx_startmenu_forcestartmenulogoff","displayName":"Add Logoff to the Start Menu (User)","description":"This policy only applies to the classic version of the start menu and does not affect the new style start menu.\r\n\r\nAdds the \"Log Off \" item to the Start menu and prevents users from removing it.\r\n\r\nIf you enable this setting, the Log Off item appears in the Start menu. This setting also removes the Display Logoff item from Start Menu Options. As a result, users cannot remove the Log Off item from the Start Menu.\r\n\r\nIf you disable this setting or do not configure it, users can use the Display Logoff item to add and remove the Log Off item.\r\n\r\nThis setting affects the Start menu only. It does not affect the Log Off item on the Windows Security dialog box that appears when you press Ctrl+Alt+Del.\r\n\r\nNote: To add or remove the Log Off item on a computer, click Start, click Settings, click Taskbar and Start Menu, click the Start Menu Options tab, and then, in the Start Menu Settings box, click Display Logoff.\r\n\r\nAlso, see \"Remove Logoff\" in User Configuration\\Administrative Templates\\System\\Logon/Logoff.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-forcestartmenulogoff"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_forcestartmenulogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_forcestartmenulogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"2420b0e76893c0e6":{"id":"user_vendor_msft_policy_config_admx_startmenu_nostartmenuhomegroup","displayName":"Remove Homegroup link from Start Menu (User)","description":"If you enable this policy the Start menu will not show a link to Homegroup. It also removes the homegroup item from the Start Menu options. As a result, users cannot add the homegroup link to the Start Menu.\r\n\r\n If you disable or do not configure this policy, users can use the Start Menu options to add or remove the homegroup link from the Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nostartmenuhomegroup"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nostartmenuhomegroup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nostartmenuhomegroup_1","displayName":"Enabled","description":null,"helpText":null}]},"24c24fae5789cb22":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls","displayName":"Allow images on these sites (User)","description":"Setting the policy lets you set a list of URL patterns that specify sites that may display images.\r\n\r\nLeaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nNote that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"249ec975fc49d417":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSuggestURL specifies the URL of the search engine to provide search suggestions. The URL should include the string '{searchTerms}', replaced in the query by the user's search terms.\r\n\r\nYou can specify Google's search URL as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nExample value: https://search.my.company/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},"2486185efd787291":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"2494093255ad1b96":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_passwordmanagerblocklistdesc","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":null},"2495d229078cb2ae":{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols","displayName":"Remove \"Run this time\" button for outdated ActiveX controls in Internet Explorer (User)","description":"This policy setting allows you to stop users from seeing the \"Run this time\" button and from running specific outdated ActiveX controls in Internet Explorer.\n\nIf you enable this policy setting, users won't see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control.\n\nIf you disable or don't configure this policy setting, users will see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control. Clicking this button lets the user run the outdated ActiveX control once.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-removerunthistimebuttonforoutdatedactivexcontrols"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"24d6a66c69947932":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins","displayName":"Run ActiveX controls and plugins (User)","description":"This policy setting allows you to manage whether ActiveX controls and plug-ins can be run on pages from the specified zone.\n\nIf you enable this policy setting, controls and plug-ins can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow the controls or plug-in to run.\n\nIf you disable this policy setting, controls and plug-ins are prevented from running.\n\nIf you do not configure this policy setting, controls and plug-ins are prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonerunactivexcontrolsandplugins"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_1","displayName":"Enabled","description":null,"helpText":null}]},"24638e22839c2a86":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_videocaptureallowedurlsdesc","displayName":"Sites that can access video capture devices without requesting permission (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"242673cc9f4d06bc":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages (User)","description":"An \"in-page\" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous \"in-page\" navigation attempt. Conversely, a user can start a navigation that isn't \"in-page\" that's independent of the current page in several ways by using the browser controls. For example, using the address bar, the back button, or a favorite link.\r\n\r\nThis setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that are not configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to \"Internet Explorer mode\" (1)\r\nand\r\n'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\nIf you disable or don’t configure this policy, only sites configured to open in Internet Explorer mode will open in that mode. Any site not configured to open in Internet Explorer mode will be redirected back to Microsoft Edge.\r\n\r\nIf you set this policy to Default (value 0), only sites configured to open in Internet Explorer mode will open in that mode. Any site not configured to open in Internet Explorer mode will be redirected back to Microsoft Edge.\r\n\r\nIf you set this policy to AutomaticNavigationsOnly (value 1), you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites will be kept in Internet Explorer mode.\r\n\r\nIf you set this policy to AllInPageNavigations (value 2), all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended).\r\n\r\nIf you enable this policy, you can choose one of the following navigation options:\r\n\r\n* 0 = Default\r\n\r\n* 1 = Keep only automatic navigations in Internet Explorer mode\r\n\r\n* 2 = Keep all in-page navigations in Internet Explorer mode\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_1","displayName":"Enabled","description":null,"helpText":null}]},"24cd8d8505da62de":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceservername5","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"2452e72576c2af1e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacework_l_workadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"2461d3f188207b1c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid","displayName":"Type of diagnostic data: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_3","displayName":"Neither","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_2","displayName":"Optional","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendtelemetry_l_sendtelemetrydropid_1","displayName":"Required","description":null,"helpText":null}]},"242677b006ad8743":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},"24aadfbd7084f527":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_allowsubfolders313_1","displayName":"True","description":null,"helpText":null}]},"241401662334467f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_100","displayName":"100","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_450","displayName":"450","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_maximumnumberofrows_l_empty433_5000","displayName":"5000","description":null,"helpText":null}]},"24572c11b8a93a59":{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_l_newoutlookautomigrationretryintervalsid","displayName":"New Outlook Auto Migration Retry Interval: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},"2422d04d0626df99":{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade","displayName":"Disable web add-in installation on migration to new Outlook for Windows (User)","description":"This policy setting allows you to disable installation of web add-in equivalents of COM add-ins on the switch to new Outlook. The add-ins available for migration are listed in https://aka.ms/newoutlooksettings.\r\n\r\nLearn more about Outlook web add-ins at https://learn.microsoft.com/office/dev/add-ins/outlook/outlook-add-ins-overview.\r\n\r\nCOM add-ins do not work in new Outlook for Windows. By default, users in the organization will get the option to install available web add-ins, in place of COM add-ins, when they move from classic Outlook for Windows.\r\n\r\nIf you enable this policy setting, users will not get the option to install web add-ins in place of their COM add-ins. \r\n \r\nIf you disable or do not configure this policy setting, users will get an option to install web add-ins in place of their COM add-ins.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablecomtowebaddinupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},"242184c1347a1681":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications","displayName":"Do not send meeting forward notifications (User)","description":"This policy setting prevents Outlook from sending meeting forward notifications. This does not affect whether or not Exchange sends meeting forward notifications. \r\n\r\nIf you enable this policy setting, Outlook will not send meeting forward notifications.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will send meeting forward notifications.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_donotsendmeetingforwardnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"24274f35799cbe66":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2","displayName":"Allow users to demote attachments to Level 2 (User)","description":"This policy setting controls whether Outlook users can demote attachments to Level 2 by using a registry key, which will allow them to save files to disk and open them from that location. Outlook uses two levels of security to restrict access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, users can create a list of Level 1 file types to demote to Level 2 by adding the file types to the following registry key: HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove. \r\n\r\nIf you disable or do not configure this policy setting, users cannot demote level 1 attachments to level 2, and the HKEY_CURRENT_USER\\Software\\Microsoft\\Office\\14.0\\Outlook\\Security\\Level1Remove registry key has no effect.\r\n","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_allowuserstolowerattachments_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"246fcaa481b63429":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview","displayName":"Turn off camera recording by default when recording a slide show (User)","description":"This policy setting allows you to set camera recording off by default when recording a slide show.\r\n\r\nBy default, camera recording is on the first time a user records a slide show. If the user turns off camera recording, then camera recording will be off the next time the slide show recording window is launched, even if PowerPoint is closed and reopened.\r\n\r\nIf you enable this policy setting, camera recording is turned off by default. A user can turn on camera recording when recording a slide show. But, the next time the slide show recording window is launched, camera recording will be off by default.\r\n\r\nIf you disable or don’t configure this policy setting, the default state of camera recording is determined by the user, unless the “Turn off microphone recording by default when recording a slide show” policy setting is enabled. Enabling that policy setting also turns off camera recording by default.\r\n ","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultvideooffinrecordingpresenterview_1","displayName":"Enabled","description":null,"helpText":null}]},"24a7cc9ff165051c":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits","displayName":"Show assignment units as (User)","description":"Shows resource assignments units as a decimal or percentage.\r\n\r\nIf you enable this setting, resource assignment units will be set to the option you choose from the list.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"304a579b-ff3b-4897-8bb8-5a1dda45356f","categoryName":"Schedule options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjschedproj_l_pjassignmentunits_1","displayName":"Enabled","description":null,"helpText":null}]},"241c72d7bb509f21":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the 2016 versions of the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the 2016 versions of the specified applications are ignored, including any trusted locations established by Office during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the 2016 versions of the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},"2493a848d76405a5":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},"24208afa8aa0205a":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana","displayName":"Match hiragana/katakana (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhiraganakatakana_1","displayName":"Enabled","description":null,"helpText":null}]},"2485661843deba00":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/25.json b/public/intune-definitions/25.json index 86cb2a48ae5c..0f741bfc052c 100644 --- a/public/intune-definitions/25.json +++ b/public/intune-definitions/25.json @@ -1 +1 @@ -{"256fbbd21c311e85":{"id":"ade_setupassistant_devicemigration","displayName":"Device to device migration","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_devicemigration_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_devicemigration_1","displayName":"Show","description":null,"helpText":null}]},"250f4fd7b2031b61":{"id":"com.apple.applicationaccess_allowautounlock","displayName":"Allow Auto Unlock","description":"If false, disallows auto unlock. Available in macOS 10.12 and later, and iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautounlock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautounlock_true","displayName":"True","description":null,"helpText":null}]},"25c546ee84d7d426":{"id":"com.apple.applicationaccess_allowlockscreennotificationsview","displayName":"Allow Lock Screen Notifications View","description":"If false, disables the Notifications history view on the lock screen, so users can’t view past notifications. However, they can still see notifications when they arrive. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreennotificationsview_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreennotificationsview_true","displayName":"True","description":null,"helpText":null}]},"257c0adf1cc3e800":{"id":"com.apple.applicationaccess_enforcedsoftwareupdatemajorosdeferredinstalldelay","displayName":"Enforced Software Update Major OS Deferred Install Delay (Deprecated)","description":"This restriction allows the admin to set how many days to delay a major software update on the device. When this restriction is in place the user sees a software update only after the specified delay after the release of the software update. This value controls the delay for Force Delayed Major Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},"2598fd5f2c6f85f3":{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos","displayName":"Sync Local Password","description":"If false, disables password sync. Note that this will not work if the user is logged in with a mobile account. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos_true","displayName":"True","description":null,"helpText":null}]},"2502354af7502b7e":{"id":"com.apple.fileproviderd_com.apple.fileproviderd","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},"25050b285d0a703f":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_application id","displayName":"Skype for Business Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"2599d9d207853aca":{"id":"com.apple.managedclient.preferences_insecurecontentblockedforurls","displayName":"Block insecure content on specified sites","description":"Create a list of URL patterns to specify sites that aren't allowed to display blockable (i.e. active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\n\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecurecontentblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"25c07894b071658e":{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\n\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\n\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printpreviewusesystemdefaultprinter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter_true","displayName":"Enabled","description":null,"helpText":null}]},"251810609ab0d5dc":{"id":"com.apple.mcx.timemachine_basepaths","displayName":"Base Paths","description":"The list of paths to back up besides the startup volume.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},"25a4877ec6c88c49":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"25a5a33159a3ab94":{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge.","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\n\nBrowsing with Copilot is available only on domains specified in the \"BrowsingWithCopilotAllowList\" policy and is blocked on domains specified in the \"BrowsingWithCopilotBlockList\" policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\n\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\n\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\n\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\n\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\n\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_true","displayName":"Enabled","description":null,"helpText":null}]},"251a45fd3be27b29":{"id":"com.microsoft.edge.mamedgeappconfigsettings.exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from file type extension-based download warnings. This exemption lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users can't see a warning when downloading \"jnlp\" files from \"website1.com\" but can see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy are still subject to nonfile type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value prevents file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It shows the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nWhile the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension isn't recommended due to security concerns. It's shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"25dea778e8013d79":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled","displayName":"Enable printing","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\n\nIf you enable this policy or don't configure it, users can print.\n\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"25f877efb9c1d29b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Disables saving browser history and prevents users from changing this setting.\n\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\n\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled_true","displayName":"Enabled","description":null,"helpText":null}]},"25966954dfafb58b":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_tcpmaxdataretransmissions","displayName":"TcpMaxDataRetransmissions","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":null},"259a840dae555bbd":{"id":"device_vendor_msft_policy_config_admx_nca_supportemail_supportemail_control","displayName":"Support Email","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},"257ab2ad278fb011":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename","displayName":"Specify site name","description":"This policy setting specifies the Active Directory site to which computers belong.\r\n\r\nAn Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication.\r\n\r\nTo specify the site name for this setting, click Enabled, and then enter the site name. When the site to which a computer belongs is not specified, the computer automatically discovers its site from Active Directory.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sitename"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_1","displayName":"Enabled","description":null,"helpText":null}]},"25b3cbfd14741af8":{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage_wbc_cache_maxage_dctxtbox","displayName":"Specify the age in days for which segments in the data cache are valid","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},"256e49defc0fbe8f":{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0","displayName":"Critical Battery Notification Action","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_0","displayName":"Take no action","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_1","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_2","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_3","displayName":"Shut down","description":null,"helpText":null}]},"259744f432746a9c":{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters","displayName":"Add Printer wizard - Network scan page (Managed network)","description":"If you enable this policy setting, it sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on a managed network (when the computer is able to reach a domain controller, e.g. a domain-joined laptop on a corporate network.)\r\n\r\n If this policy setting is disabled, the network scan page will not be displayed.\r\n\r\n If this policy setting is not configured, the Add Printer wizard will display the default number of printers of each type:\r\n Directory printers: 20\r\n TCP/IP printers: 0\r\n Web Services printers: 0\r\n Bluetooth printers: 10\r\n Shared printers: 0\r\n\r\n In order to view available Web Services printers on your network, ensure that network discovery is turned on. To turn on network discovery, click \"Start\", click \"Control Panel\", and then click \"Network and Internet\". On the \"Network and Internet\" page, click \"Network and Sharing Center\". On the Network and Sharing Center page, click \"Change advanced sharing settings\". On the Advanced sharing settings page, click the arrow next to \"Domain\" arrow, click \"turn on network discovery\", and then click \"Save changes\".\r\n\r\n If you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.\r\n\r\n In Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.\r\n \r\n In Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-domainprinters"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_1","displayName":"Enabled","description":null,"helpText":null}]},"255c336700ada620":{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2","displayName":"CD and DVD: Deny read access","description":"This policy setting denies read access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"2592fac00914d431":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath_settingsstoragepath","displayName":"Settings storage path","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},"250f009bd71d60e3":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather","displayName":"MSN Weather (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather_1","displayName":"True","description":null,"helpText":null}]},"2584089a95c44029":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"258044e2944d27c2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended","displayName":"URLs to open on startup","description":"If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open.\r\n\r\nIf not set, the New Tab page opens on start up.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://example.com\r\nhttps://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"25d5bb5875f3fb2d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed","displayName":"Allow user feedback","description":"Setting the policy to Enabled or leaving it unset lets users send feedback to Google through Menu > Help > Report an Issue or key combination.\r\n\r\nSetting the policy to Disabled means users can't send feedback to Google.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"25b7acb896f7f551":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings","displayName":"Settings for the Lens Overlay feature","description":"Lens Overlay lets users perform contextual Google searches either via a screenshot or by asking a question about the current page's contents. This feature requires the end user to opt-in.\r\n\r\nThis feature is available to all users with Google as their default search engine, unless it is disabled by this policy.\r\n\r\nWhen policy is set to 0 - Allow or not set, the feature will be available to users.\r\n\r\nWhen policy is set to 1 - Do not allow, the feature will not be available.\r\n\r\nStarting in Google Chrome 140, if the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_1","displayName":"Enabled","description":null,"helpText":null}]},"254a1a4b64e64fd8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt","displayName":"Prompt users to re-authenticate to the profile","description":"When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser.\r\n\r\nWhen set to PromptInTab, when the user's authentication expires, immediately open a new tab with the Google login page. This only happens if using Chrome Sync.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},"252124f6a883292b":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_windowplacementallowedforurlsdesc","displayName":"Allow Window Placement permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"257f82a28db98ac9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled","displayName":"Force persistent quota to be enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"251a9dc476de5175":{"id":"device_vendor_msft_policy_config_defender_schedulequickscantime","displayName":"Schedule Quick Scan Time","description":"Selects the time of day that the daily Windows Defender quick scan should run. For example, a value of 0=12:00AM, a value of 60=1:00AM, a value of 120=2:00, and so on, up to a value of 1380=11:00PM. The default value is 120","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#schedulequickscantime"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"2556b0ad759af72e":{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablelocalmanifestfiles","displayName":"Enable App Installer Local Manifest Files","description":"This policy controls whether users can install packages with local manifest files.\n\nIf you enable or do not configure this setting, users will be able to install packages with local manifests using the Windows Package Manager.\n\nIf you disable this setting, users will not be able to install packages with local manifests using the Windows Package Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-enablelocalmanifestfiles"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablelocalmanifestfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablelocalmanifestfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"2557871f4b1bf951":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesvhdnamematch_profilesvhdnamematch","displayName":"VHD Name Match (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":null},"25cfad17aaae1f17":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script can perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowcopypasteviascript"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"251ebc05d3cc1220":{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist_extensioninstalltypeblocklistdesc","displayName":"Blocklist for extension install types (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"25b101c8ca74ee73":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled","displayName":"Enable additional search box in browser","description":"A search box is an additional text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\r\n\r\nIf you enable or don't configure this policy, the search box will be visible and available for use.\r\nUsers can toggle the search box in Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\r\n\r\nIf you disable this policy, search box will not be visible, and users will have to use the address bar or navigate to a search engine to perform web searches.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"253d548625493ec5":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_powerpntexe115","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_powerpntexe115_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_powerpntexe115_1","displayName":"True","description":null,"helpText":null}]},"250d3b8598e1647d":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_forcedlocalmassdeletedetection","displayName":"Require users to confirm large delete operations","description":"This setting makes users confirm that they want to delete files in the cloud when they delete a large number of synced files.\r\n\r\nIf you enable this setting, a warning will always appear when users delete a large number of synced files. If a user does not confirm a delete operation within 7 days, the files will not be deleted.\r\n\r\nIf you disable or do not configure this setting, users can choose to hide the warning and always delete files in the cloud.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_forcedlocalmassdeletedetection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_forcedlocalmassdeletedetection_1","displayName":"Enabled","description":null,"helpText":null}]},"25d6f99333982360":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessnotifications_forceallowtheseapps","displayName":"Let Apps Access Notifications Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to notifications. This setting overrides the default LetAppsAccessNotifications policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessnotifications_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"2530aed14123450b":{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderhomegroup","displayName":"Allow Pinned Folder Home Group","description":"This policy controls the visibility of the HomeGroup shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#allowpinnedfolderhomegroup"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderhomegroup_0","displayName":"The shortcut is hidden and disables the setting in the Settings app.","description":"The shortcut is hidden and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderhomegroup_1","displayName":"The shortcut is visible and disables the setting in the Settings app.","description":"The shortcut is visible and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderhomegroup_65535","displayName":"There is no enforced configuration and the setting can be changed by the user.","description":"There is no enforced configuration and the setting can be changed by the user.","helpText":null}]},"255c0cb7112bc718":{"id":"device_vendor_msft_policy_config_windowsai_disablecocreator","displayName":"Disable Cocreator","description":"This policy setting allows you to control whether Cocreator functionality is disabled in the Windows Paint app. If this policy is enabled, Cocreator functionality will not be accessible in the Paint app. If this policy is disabled or not configured, users will be able to access Cocreator functionality.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disablecocreator"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_disablecocreator_0","displayName":"Cocreator is enabled.","description":"Cocreator is enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disablecocreator_1","displayName":"Cocreator is disabled.","description":"Cocreator is disabled.","helpText":null}]},"2575adc4fb6f4450":{"id":"diskmanagement_restrictions","displayName":"Restrictions","description":"Defines the restrictions for disks","helpText":null,"infoUrls":[],"categoryId":"83febe72-a64f-4051-9071-1efae1ea9a15","categoryName":"Disk Management","options":null},"25f633b96c5f6e21":{"id":"diskmanagement_restrictions_externalstorage","displayName":"External Storage","description":"Specifies the mount policy for external storage:\n* Allowed - external storage that is read-write or read-only will be mounted.\n* ReadOnly - only external storage that is read-only will be automatically mounted. Note that external storage that is read-write will not be mounted read-only.\n* Disallowed - no external storage will be mounted.","helpText":null,"infoUrls":[],"categoryId":"83febe72-a64f-4051-9071-1efae1ea9a15","categoryName":"Disk Management","options":[{"id":"diskmanagement_restrictions_externalstorage_0","displayName":"Allowed","description":null,"helpText":null},{"id":"diskmanagement_restrictions_externalstorage_1","displayName":"ReadOnly","description":null,"helpText":null},{"id":"diskmanagement_restrictions_externalstorage_2","displayName":"Disallowed","description":null,"helpText":null}]},"258bcaeac12d3a38":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters","displayName":"Uppercase Letters (User)","description":"Use this policy setting to configure the use of uppercase letters in the Windows Hello for Business PIN.\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one uppercase letter in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using uppercase letters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use uppercase letters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_0","displayName":"Allowed","description":"Allows the use of uppercase letters in PIN.","helpText":null},{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_1","displayName":"Required","description":"Requires the use of at least one uppercase letters in PIN.","helpText":null},{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_2","displayName":"Blocked","description":"Does not allow the use of uppercase letters in PIN.","helpText":null}]},"25b7ce5497819ffc":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":null},"25d398c2fce07586":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsavedgames","displayName":"Saved Games (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsavedgames_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsavedgames_1","displayName":"True","description":null,"helpText":null}]},"253217a7ffc5cc5e":{"id":"user_vendor_msft_policy_config_admx_printing_printerdirectorysearchscope_printerdirectorysearchscope_name","displayName":"Default Active Directory path (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},"25fccf958409d6e8":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmydocuments","displayName":"Remove Documents icon from Start Menu (User)","description":"This policy setting allows you to remove the Documents icon from the Start menu and its submenus.\r\n\r\nIf you enable this policy setting, the Documents icon is removed from the Start menu and its submenus. Enabling this policy setting only removes the icon. It does not prevent the user from using other methods to gain access to the contents of the Documents folder.\r\n\r\nNote: To make changes to this policy setting effective, you must log off and then log on.\r\n\r\nIf you disable or do not configure this policy setting, he Documents icon is available from the Start menu.\r\n\r\nAlso, see the \"Remove Documents icon on the desktop\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosmmydocuments"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmydocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmydocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"25ca6f51cdfd52f9":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access","displayName":"Microsoft Access 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Access 2016.\r\nBy default, the user settings of Microsoft Access 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Access 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access_1","displayName":"Enabled","description":null,"helpText":null}]},"25e807f6c1cab0a0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"Setting the policy turns on Chrome's restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains (to allow gmail or googlemail accounts, add consumer_accounts to the list of domains). This setting prevents users from signing in and adding a Secondary Account on a managed device that requires Google authentication, if that account doesn't belong to one of the explicitly allowed domains.\r\n\r\nLeaving this setting empty or unset means users can access Google Workspace with any account.\r\n\r\nUsers cannot change or override this setting.\r\n\r\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://support.google.com/a/answer/1668854.\r\n\r\nExample value: managedchrome.com,example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_1","displayName":"Enabled","description":null,"helpText":null}]},"25d55c3b89cfe5c4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled","displayName":"Enables managed extensions to use the Enterprise Hardware Platform API (User)","description":"Setting the policy to True lets extensions installed by enterprise policy use the Enterprise Hardware Platform API.\r\n\r\nSetting the policy to False or leaving it unset prevents extensions from using this API.\r\n\r\nNote: This policy also applies to component extensions, such as the Hangout Services extension.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2593947d1604b101":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch to ServiceWorker-controlled URLs (User)","description":"SpeculationRules prefetch can be issued to URLs that are controlled by\r\nServiceWorker. However, legacy code did not allow it and canceled the prefetch\r\nrequests. This policy enables to control the behavior.\r\n\r\nSetting this policy to Enabled or not set allows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is\r\nenabled). This is the current default behavior and is aligned with the\r\nspecifications.\r\n\r\nSetting this policy to Disabled disallows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs. This is the legacy behavior.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"257afcac36245302":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings","displayName":"Enable automated password change (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_0","displayName":"Allow feature use and improving AI models","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_1","displayName":"Allow feature use without improving AI models","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_2","displayName":"Do not allow feature","description":null,"helpText":null}]},"25d0d94f93326f35":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled","displayName":"Insecure Hashes in TLS Handshakes Enabled (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"25c18792491f20de":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled","displayName":"Control the URL parameter filter feature (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"25a69557178bc186":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"2596b4221dc864c5":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled","displayName":"Enable guest mode (User)","description":"Enable the option to allow the use of guest profiles in Microsoft Edge. In a guest profile, the browser doesn't import browsing data from existing profiles, and it deletes browsing data when all guest profiles are closed.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge lets users browse in guest profiles.\r\n\r\nIf you disable this policy, Microsoft Edge doesn't let users browse in guest profiles.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"251d66b75768da68":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets (User)","description":"This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites.\r\n\r\nIf this policy set to True or unset, the Related Website Sets feature is enabled.\r\n\r\nIf this policy is set to False, the Related Website Sets feature is disabled.","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"259b8464fc520179":{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled","displayName":"Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates (User)","description":"Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing.\r\n\r\nThis policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles.\r\n\r\nThis policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145.\r\n\r\nIf you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.\r\nIf you disable this policy, Microsoft Edge does not show the informational page to users.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"25551c9e2a70c84b":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides","displayName":"Override IP address space mappings (User)","description":"Specifies IP address space overrides for Local Network Access restrictions. This policy allows administrators to treat specific IP address ranges as public (exempt from Local Network Access restrictions) or as local (subject to Local Network Access restrictions).\r\n\r\nIP address space overrides can be specified using one of the following formats:\r\n\r\n• [cidr]=[public|local|loopback]\r\nwhere [cidr] is an IP address range in CIDR notation. CIDR overrides apply to all ports.\r\n\r\n• [ip-address]:[port]=[public|local|loopback]\r\n\r\nIPv6 addresses must be specified in URL-safe (bracketed) format.\r\n\r\nFor more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\n100.64.0.0/10=public\r\n[2001:db8::]/32=local\r\n192.168.0.1:8000=public\r\n[2001:DB8::8:800:200C:417A]:8080=local","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},"25363e391acc9a54":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\r\nIf you enable this policy or don't set it, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\r\nIf you disable this policy, warnings will not be shown for insecure forms, and autofill will work normally.\r\n\r\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"25b1cff807929049":{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled","displayName":"Ignore Application Guard site list configuration and browse Edge normally (User)","description":"Set whether Edge should ignore the Application Guard site list configuration for trusted and untrusted sites.\r\n\r\nIf you enable this policy, all navigations from Edge, including navigations to untrusted sites, will be accessed normally within Edge without redirecting to the Application Guard container. Note: this policy ONLY impacts Edge, so navigations from other browsers might get redirected to the Application Guard Container if you have the corresponding extensions enabled.\r\n\r\nIf you disable or don't configure this policy, Edge does not ignore the Application Guard site list. If users try to navigate to an untrusted site in the host, the site will open in the container.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2549f3fb55039ad4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval_l_sleepintervaldecimal","displayName":"Sleep interval upper limit (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},"2570563026db3b49":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany","displayName":"German (Germany) (User)","description":"Enables the editing language German (Germany)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany_1","displayName":"Enabled","description":null,"helpText":null}]},"25b64b82fd513b81":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite","displayName":"Enable Workflows on My Site (User)","description":"Allows workflows on My Site to be started from within the workflow enabled Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite_1","displayName":"Enabled","description":null,"helpText":null}]},"25de542d7ce6c041":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_0","displayName":"No minimum level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_1","displayName":"XAdES-BES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_2","displayName":"XAdES-T","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_3","displayName":"XAdES-C","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_4","displayName":"XAdES-X","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_5","displayName":"XAdES-X-L","description":null,"helpText":null}]},"25fd4f0feb186535":{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols","displayName":"Block Insecure Protocols (User)","description":"\r\n\t\t\tThis policy setting allows you to control which protocols can be used when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you enable this policy setting, non-HTTPS links will be blocked when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you disable this policy setting, all protocols and links will be allowed when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you don't configure this policy setting, all protocols and links will be allowed when opening documents in Microsoft 365 apps.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},"256f86f8b2850dd4":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44_1","displayName":"True","description":null,"helpText":null}]},"258ed2a2da63e103":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends","displayName":"Request a read receipt for all messages a user sends (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends_1","displayName":"True","description":null,"helpText":null}]},"2559f02e0449545a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms","displayName":"Allow Active X One Off Forms (User) (Deprecated)","description":"By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_1","displayName":"Enabled","description":null,"helpText":null}]},"257707a85154801c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs","displayName":"Do not provide Continue option on Encryption warning dialog boxes (User)","description":"This setting controls whether Outlook users are allowed to send e-mail messages after they see an encryption warning. \r\n\r\nIf you enable this policy setting, encryption warning dialog boxes do not contain a Continue button, which means that users must cancel the sending operation entirely. \r\n\r\nIf you disable or do not configure this policy setting, if Outlook users see an encryption-related dialog box when attempting to send a message, they can choose to dismiss the warning and send the message anyway.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"25a1f06f1a8ca45d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2","displayName":"Security setting for macros (User)","description":"This policy setting controls the security level for macros in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for handling macros in Outlook: \r\n\r\n- Always warn. This option corresponds to the \"Warnings for all macros\" option in the \"Macro Security\" section of the Outlook Trust Center. Outlook disables all macros that are not opened from a trusted location, even if the macros are signed by a trusted publisher. For each disabled macro, Outlook displays a security alert dialog box with information about the macro and its digital signature (if present), and allows users to enable the macro or leave it disabled. \r\n\r\n- Never warn, disable all. This option corresponds to the \"No warnings and disable all macros\" option in the Trust Center. Outlook disables all macros that are not opened from trusted locations, and does not notify users. \r\n\r\n- Warning for signed, disable unsigned. This option corresponds to the \"Warnings for signed macros; all unsigned macros are disabled\" option in the Trust Center. Outlook handles macros as follows: \r\n\r\n--If a macro is digitally signed by a trusted publisher, the macro can run if the user has already trusted the publisher. \r\n\r\n--If a macro has a valid signature from a publisher that the user has not trusted, the security alert dialog box for the macro lets the user choose whether to enable the macro for the current session, disable the macro for the current session, or to add the publisher to the Trusted Publishers list so that it will run without prompting the user in the future. \r\n\r\n--If a macro does not have a valid signature, Outlook disables it without prompting the user, unless it is opened from a trusted location. \r\n\r\nThis option is the default configuration in Outlook. \r\n\r\n- No security check. This option corresponds to the \"No security check for macros (Not recommended)\" option in the Trust Center. Outlook runs all macros without prompting users. This configuration makes users' computers vulnerable to potentially malicious code and is not recommended. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of Enabled -- Warning for signed, disable unsigned.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"25ad74bd1a49c2ca":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername_l_rpcproxyservernametextid","displayName":"Specify the proxy server name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},"252f8dfd1e17f225":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads","displayName":"Offline Address Book: Limit manual OAB downloads (User)","description":"This policy setting allows you to specify the number of manual downloads of the offline address book (OAB) allowed in a 13 hour period.\r\n\r\nIf you enable this policy setting, you may specify the number of manual downloads of the offline address book (OAB) allowed in a 13 hour period. If you set the value to 0, then no manual OAB downloads are allowed. If you set the value to the maximum of 65535, then that will allow an unlimited number of manual downloads of the OAB.\r\n\r\nIf you disable or do not configure this policy setting, an unlimited number of manual downloads of the OAB will be allowed.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"25ba5be771cac1c5":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_1","displayName":"Enabled","description":null,"helpText":null}]},"25077ed1f7873be6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd_1","displayName":"True","description":null,"helpText":null}]},"25fb665886c89189":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},"25b7bfe5eca095df":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"256fbbd21c311e85":{"id":"ade_setupassistant_devicemigration","displayName":"Device to device migration","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_devicemigration_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_devicemigration_1","displayName":"Show","description":null,"helpText":null}]},"250f4fd7b2031b61":{"id":"com.apple.applicationaccess_allowautounlock","displayName":"Allow Auto Unlock","description":"If false, disallows auto unlock. Available in macOS 10.12 and later, and iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautounlock_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautounlock_true","displayName":"True","description":null,"helpText":null}]},"25c546ee84d7d426":{"id":"com.apple.applicationaccess_allowlockscreennotificationsview","displayName":"Allow Lock Screen Notifications View","description":"If false, disables the Notifications history view on the lock screen, so users can’t view past notifications. However, they can still see notifications when they arrive. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreennotificationsview_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreennotificationsview_true","displayName":"True","description":null,"helpText":null}]},"257c0adf1cc3e800":{"id":"com.apple.applicationaccess_enforcedsoftwareupdatemajorosdeferredinstalldelay","displayName":"Enforced Software Update Major OS Deferred Install Delay (Deprecated)","description":"This restriction allows the admin to set how many days to delay a major software update on the device. When this restriction is in place the user sees a software update only after the specified delay after the release of the software update. This value controls the delay for Force Delayed Major Software Updates. Available in macOS 11.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},"2598fd5f2c6f85f3":{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos","displayName":"Sync Local Password","description":"If false, disables password sync. Note that this will not work if the user is logged in with a mobile account. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_synclocalpassword_kerberos_true","displayName":"True","description":null,"helpText":null}]},"2502354af7502b7e":{"id":"com.apple.fileproviderd_com.apple.fileproviderd","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},"25050b285d0a703f":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app_application id","displayName":"Skype for Business Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"2599d9d207853aca":{"id":"com.apple.managedclient.preferences_insecurecontentblockedforurls","displayName":"Block insecure content on specified sites","description":"Create a list of URL patterns to specify sites that aren't allowed to display blockable (i.e. active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\n\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecurecontentblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"25c07894b071658e":{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter","displayName":"Set the system default printer as the default printer","description":"Tells Microsoft Edge to use the system default printer as the default choice in Print Preview instead of the most recently used printer.\n\nIf you disable this policy or don't configure it, Print Preview uses the most recently used printer as the default destination choice.\n\nIf you enable this policy, Print Preview uses the OS system default printer as the default destination choice.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printpreviewusesystemdefaultprinter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printpreviewusesystemdefaultprinter_true","displayName":"Enabled","description":null,"helpText":null}]},"251810609ab0d5dc":{"id":"com.apple.mcx.timemachine_basepaths","displayName":"Base Paths","description":"The list of paths to back up besides the startup volume.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},"25a4877ec6c88c49":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"25a5a33159a3ab94":{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge.","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\n\nBrowsing with Copilot is available only on domains specified in the \"BrowsingWithCopilotAllowList\" policy and is blocked on domains specified in the \"BrowsingWithCopilotBlockList\" policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\n\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\n\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\n\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\n\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\n\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowbrowsingwithcopilot_true","displayName":"Enabled","description":null,"helpText":null}]},"251a45fd3be27b29":{"id":"com.microsoft.edge.mamedgeappconfigsettings.exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that are exempted from file type extension-based download warnings. This exemption lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users can't see a warning when downloading \"jnlp\" files from \"website1.com\" but can see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy are still subject to nonfile type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator shouldn't be included when listing the file type extension; so, list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value prevents file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It shows the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nWhile the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension isn't recommended due to security concerns. It's shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"25dea778e8013d79":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled","displayName":"Enable printing","description":"Enables printing in Microsoft Edge and prevents users from changing this setting.\n\nIf you enable this policy or don't configure it, users can print.\n\nIf you disable this policy, users can't print from Microsoft Edge. Printing is disabled in the wrench menu, extensions, JavaScript applications, and so on. Users can still print from plug-ins that bypass Microsoft Edge while printing. For example, certain Adobe Flash applications have the print option in their context menu, which isn't covered by this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"25f877efb9c1d29b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Disables saving browser history and prevents users from changing this setting.\n\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\n\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.savingbrowserhistorydisabled_true","displayName":"Enabled","description":null,"helpText":null}]},"25ad611c56fba7f4":{"id":"contentcaching_cachelimit","displayName":"Cache Limit","description":"The maximum number of bytes of disk space to use for the content cache. Set to `0` for unlimited disk space. Also serves as the upper bound to the `PersonalCacheLimit`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"25966954dfafb58b":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_tcpmaxdataretransmissions","displayName":"TcpMaxDataRetransmissions","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":null},"259a840dae555bbd":{"id":"device_vendor_msft_policy_config_admx_nca_supportemail_supportemail_control","displayName":"Support Email","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},"257ab2ad278fb011":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename","displayName":"Specify site name","description":"This policy setting specifies the Active Directory site to which computers belong.\r\n\r\nAn Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication.\r\n\r\nTo specify the site name for this setting, click Enabled, and then enter the site name. When the site to which a computer belongs is not specified, the computer automatically discovers its site from Active Directory.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sitename"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_1","displayName":"Enabled","description":null,"helpText":null}]},"25b3cbfd14741af8":{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setdatacacheentrymaxage_wbc_cache_maxage_dctxtbox","displayName":"Specify the age in days for which segments in the data cache are valid","description":null,"helpText":"","infoUrls":[],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":null},"256e49defc0fbe8f":{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0","displayName":"Critical Battery Notification Action","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_0","displayName":"Take no action","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_1","displayName":"Sleep","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_2","displayName":"Hibernate","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_selectdcbatterydischargeaction0_3","displayName":"Shut down","description":null,"helpText":null}]},"259744f432746a9c":{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters","displayName":"Add Printer wizard - Network scan page (Managed network)","description":"If you enable this policy setting, it sets the maximum number of printers (of each type) that the Add Printer wizard will display on a computer on a managed network (when the computer is able to reach a domain controller, e.g. a domain-joined laptop on a corporate network.)\r\n\r\n If this policy setting is disabled, the network scan page will not be displayed.\r\n\r\n If this policy setting is not configured, the Add Printer wizard will display the default number of printers of each type:\r\n Directory printers: 20\r\n TCP/IP printers: 0\r\n Web Services printers: 0\r\n Bluetooth printers: 10\r\n Shared printers: 0\r\n\r\n In order to view available Web Services printers on your network, ensure that network discovery is turned on. To turn on network discovery, click \"Start\", click \"Control Panel\", and then click \"Network and Internet\". On the \"Network and Internet\" page, click \"Network and Sharing Center\". On the Network and Sharing Center page, click \"Change advanced sharing settings\". On the Advanced sharing settings page, click the arrow next to \"Domain\" arrow, click \"turn on network discovery\", and then click \"Save changes\".\r\n\r\n If you would like to not display printers of a certain type, enable this policy and set the number of printers to display to 0.\r\n\r\n In Windows 10 and later, only TCP/IP printers can be shown in the wizard. If you enable this policy setting, only TCP/IP printer limits are applicable. On Windows 10 only, if you disable or do not configure this policy setting, the default limit is applied.\r\n \r\n In Windows 8 and later, Bluetooth printers are not shown so its limit does not apply to those versions of Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-domainprinters"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_1","displayName":"Enabled","description":null,"helpText":null}]},"255c336700ada620":{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2","displayName":"CD and DVD: Deny read access","description":"This policy setting denies read access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"2592fac00914d431":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingsstoragepath_settingsstoragepath","displayName":"Settings storage path","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},"250f009bd71d60e3":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather","displayName":"MSN Weather (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_bingweather_1","displayName":"True","description":null,"helpText":null}]},"2584089a95c44029":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"258044e2944d27c2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended","displayName":"URLs to open on startup","description":"If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open.\r\n\r\nIf not set, the New Tab page opens on start up.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://example.com\r\nhttps://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"25d5bb5875f3fb2d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed","displayName":"Allow user feedback","description":"Setting the policy to Enabled or leaving it unset lets users send feedback to Google through Menu > Help > Report an Issue or key combination.\r\n\r\nSetting the policy to Disabled means users can't send feedback to Google.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userfeedbackallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"25b7acb896f7f551":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings","displayName":"Settings for the Lens Overlay feature","description":"Lens Overlay lets users perform contextual Google searches either via a screenshot or by asking a question about the current page's contents. This feature requires the end user to opt-in.\r\n\r\nThis feature is available to all users with Google as their default search engine, unless it is disabled by this policy.\r\n\r\nWhen policy is set to 0 - Allow or not set, the feature will be available to users.\r\n\r\nWhen policy is set to 1 - Do not allow, the feature will not be available.\r\n\r\nStarting in Google Chrome 140, if the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_lensoverlaysettings_1","displayName":"Enabled","description":null,"helpText":null}]},"254a1a4b64e64fd8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt","displayName":"Prompt users to re-authenticate to the profile","description":"When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser.\r\n\r\nWhen set to PromptInTab, when the user's authentication expires, immediately open a new tab with the Google login page. This only happens if using Chrome Sync.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},"252124f6a883292b":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_windowplacementallowedforurlsdesc","displayName":"Allow Window Placement permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"257f82a28db98ac9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled","displayName":"Force persistent quota to be enabled","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_persistentquotaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"251a9dc476de5175":{"id":"device_vendor_msft_policy_config_defender_schedulequickscantime","displayName":"Schedule Quick Scan Time","description":"Selects the time of day that the daily Windows Defender quick scan should run. For example, a value of 0=12:00AM, a value of 60=1:00AM, a value of 120=2:00, and so on, up to a value of 1380=11:00PM. The default value is 120","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#schedulequickscantime"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"2556b0ad759af72e":{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablelocalmanifestfiles","displayName":"Enable App Installer Local Manifest Files","description":"This policy controls whether users can install packages with local manifest files.\n\nIf you enable or do not configure this setting, users will be able to install packages with local manifests using the Windows Package Manager.\n\nIf you disable this setting, users will not be able to install packages with local manifests using the Windows Package Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-enablelocalmanifestfiles"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablelocalmanifestfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablelocalmanifestfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"2557871f4b1bf951":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesvhdnamematch_profilesvhdnamematch","displayName":"VHD Name Match (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":null},"25cfad17aaae1f17":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script can perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowcopypasteviascript"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"251ebc05d3cc1220":{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~extensions_extensioninstalltypeblocklist_extensioninstalltypeblocklistdesc","displayName":"Blocklist for extension install types (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"25b101c8ca74ee73":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled","displayName":"Enable additional search box in browser","description":"A search box is an additional text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\r\n\r\nIf you enable or don't configure this policy, the search box will be visible and available for use.\r\nUsers can toggle the search box in Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\r\n\r\nIf you disable this policy, search box will not be visible, and users will have to use the address bar or navigate to a search engine to perform web searches.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"253d548625493ec5":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_powerpntexe115","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_powerpntexe115_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_powerpntexe115_1","displayName":"True","description":null,"helpText":null}]},"250d3b8598e1647d":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_forcedlocalmassdeletedetection","displayName":"Require users to confirm large delete operations","description":"This setting makes users confirm that they want to delete files in the cloud when they delete a large number of synced files.\r\n\r\nIf you enable this setting, a warning will always appear when users delete a large number of synced files. If a user does not confirm a delete operation within 7 days, the files will not be deleted.\r\n\r\nIf you disable or do not configure this setting, users can choose to hide the warning and always delete files in the cloud.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_forcedlocalmassdeletedetection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_forcedlocalmassdeletedetection_1","displayName":"Enabled","description":null,"helpText":null}]},"25d6f99333982360":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessnotifications_forceallowtheseapps","displayName":"Let Apps Access Notifications Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are allowed access to notifications. This setting overrides the default LetAppsAccessNotifications policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessnotifications_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"2530aed14123450b":{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderhomegroup","displayName":"Allow Pinned Folder Home Group","description":"This policy controls the visibility of the HomeGroup shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#allowpinnedfolderhomegroup"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderhomegroup_0","displayName":"The shortcut is hidden and disables the setting in the Settings app.","description":"The shortcut is hidden and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderhomegroup_1","displayName":"The shortcut is visible and disables the setting in the Settings app.","description":"The shortcut is visible and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderhomegroup_65535","displayName":"There is no enforced configuration and the setting can be changed by the user.","description":"There is no enforced configuration and the setting can be changed by the user.","helpText":null}]},"255c0cb7112bc718":{"id":"device_vendor_msft_policy_config_windowsai_disablecocreator","displayName":"Disable Cocreator","description":"This policy setting allows you to control whether Cocreator functionality is disabled in the Windows Paint app. If this policy is enabled, Cocreator functionality will not be accessible in the Paint app. If this policy is disabled or not configured, users will be able to access Cocreator functionality.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disablecocreator"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_disablecocreator_0","displayName":"Cocreator is enabled.","description":"Cocreator is enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disablecocreator_1","displayName":"Cocreator is disabled.","description":"Cocreator is disabled.","helpText":null}]},"2575adc4fb6f4450":{"id":"diskmanagement_restrictions","displayName":"Restrictions","description":"Defines the restrictions for disks","helpText":null,"infoUrls":[],"categoryId":"83febe72-a64f-4051-9071-1efae1ea9a15","categoryName":"Disk Management","options":null},"25f633b96c5f6e21":{"id":"diskmanagement_restrictions_externalstorage","displayName":"External Storage","description":"Specifies the mount policy for external storage:\n* Allowed - external storage that is read-write or read-only will be mounted.\n* ReadOnly - only external storage that is read-only will be automatically mounted. Note that external storage that is read-write will not be mounted read-only.\n* Disallowed - no external storage will be mounted.","helpText":null,"infoUrls":[],"categoryId":"83febe72-a64f-4051-9071-1efae1ea9a15","categoryName":"Disk Management","options":[{"id":"diskmanagement_restrictions_externalstorage_0","displayName":"Allowed","description":null,"helpText":null},{"id":"diskmanagement_restrictions_externalstorage_1","displayName":"ReadOnly","description":null,"helpText":null},{"id":"diskmanagement_restrictions_externalstorage_2","displayName":"Disallowed","description":null,"helpText":null}]},"258bcaeac12d3a38":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters","displayName":"Uppercase Letters (User)","description":"Use this policy setting to configure the use of uppercase letters in the Windows Hello for Business PIN.\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one uppercase letter in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using uppercase letters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use uppercase letters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_0","displayName":"Allowed","description":"Allows the use of uppercase letters in PIN.","helpText":null},{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_1","displayName":"Required","description":"Requires the use of at least one uppercase letters in PIN.","helpText":null},{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_uppercaseletters_2","displayName":"Blocked","description":"Does not allow the use of uppercase letters in PIN.","helpText":null}]},"25b7ce5497819ffc":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":null},"25d398c2fce07586":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsavedgames","displayName":"Saved Games (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsavedgames_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinsavedgames_1","displayName":"True","description":null,"helpText":null}]},"253217a7ffc5cc5e":{"id":"user_vendor_msft_policy_config_admx_printing_printerdirectorysearchscope_printerdirectorysearchscope_name","displayName":"Default Active Directory path (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},"25fccf958409d6e8":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmydocuments","displayName":"Remove Documents icon from Start Menu (User)","description":"This policy setting allows you to remove the Documents icon from the Start menu and its submenus.\r\n\r\nIf you enable this policy setting, the Documents icon is removed from the Start menu and its submenus. Enabling this policy setting only removes the icon. It does not prevent the user from using other methods to gain access to the contents of the Documents folder.\r\n\r\nNote: To make changes to this policy setting effective, you must log off and then log on.\r\n\r\nIf you disable or do not configure this policy setting, he Documents icon is available from the Start menu.\r\n\r\nAlso, see the \"Remove Documents icon on the desktop\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosmmydocuments"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmydocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmydocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"25ca6f51cdfd52f9":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access","displayName":"Microsoft Access 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Access 2016.\r\nBy default, the user settings of Microsoft Access 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Access 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016access_1","displayName":"Enabled","description":null,"helpText":null}]},"25e807f6c1cab0a0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"Setting the policy turns on Chrome's restricted sign-in feature in Google Workspace and prevents users from changing this setting. Users can only access Google tools using accounts from the specified domains (to allow gmail or googlemail accounts, add consumer_accounts to the list of domains). This setting prevents users from signing in and adding a Secondary Account on a managed device that requires Google authentication, if that account doesn't belong to one of the explicitly allowed domains.\r\n\r\nLeaving this setting empty or unset means users can access Google Workspace with any account.\r\n\r\nUsers cannot change or override this setting.\r\n\r\nNote: This policy causes the X-GoogApps-Allowed-Domains header to be appended to all HTTP and HTTPS requests to all google.com domains, as described in https://support.google.com/a/answer/1668854.\r\n\r\nExample value: managedchrome.com,example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_1","displayName":"Enabled","description":null,"helpText":null}]},"25d55c3b89cfe5c4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled","displayName":"Enables managed extensions to use the Enterprise Hardware Platform API (User)","description":"Setting the policy to True lets extensions installed by enterprise policy use the Enterprise Hardware Platform API.\r\n\r\nSetting the policy to False or leaving it unset prevents extensions from using this API.\r\n\r\nNote: This policy also applies to component extensions, such as the Hangout Services extension.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2593947d1604b101":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch to ServiceWorker-controlled URLs (User)","description":"SpeculationRules prefetch can be issued to URLs that are controlled by\r\nServiceWorker. However, legacy code did not allow it and canceled the prefetch\r\nrequests. This policy enables to control the behavior.\r\n\r\nSetting this policy to Enabled or not set allows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is\r\nenabled). This is the current default behavior and is aligned with the\r\nspecifications.\r\n\r\nSetting this policy to Disabled disallows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs. This is the legacy behavior.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"257afcac36245302":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings","displayName":"Enable automated password change (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_0","displayName":"Allow feature use and improving AI models","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_1","displayName":"Allow feature use without improving AI models","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_2","displayName":"Do not allow feature","description":null,"helpText":null}]},"25d0d94f93326f35":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled","displayName":"Insecure Hashes in TLS Handshakes Enabled (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_insecurehashesintlshandshakesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"25c18792491f20de":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled","displayName":"Control the URL parameter filter feature (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"25a69557178bc186":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"2596b4221dc864c5":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled","displayName":"Enable guest mode (User)","description":"Enable the option to allow the use of guest profiles in Microsoft Edge. In a guest profile, the browser doesn't import browsing data from existing profiles, and it deletes browsing data when all guest profiles are closed.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge lets users browse in guest profiles.\r\n\r\nIf you disable this policy, Microsoft Edge doesn't let users browse in guest profiles.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_browserguestmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"251d66b75768da68":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets (User)","description":"This policy lets you control the enablement of the Related Website Sets feature. Related Website Sets (RWS) is a way for an organisation to declare relationships among sites, so that Microsoft Edge allows limited third-party cookie access for specific purposes across those sites.\r\n\r\nIf this policy set to True or unset, the Related Website Sets feature is enabled.\r\n\r\nIf this policy is set to False, the Related Website Sets feature is disabled.","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"259b8464fc520179":{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled","displayName":"Control whether an informational webpage for Edge for Business is shown in the new tab after major browser updates (User)","description":"Starting in Microsoft Edge version 145, users with Microsoft Entra ID profiles will see an informational page about new Edge for Business features after major browser updates. This page highlights recent enhancements designed to promote secure and productive browsing.\r\n\r\nThis policy controls whether users with Microsoft Entra ID profiles see this informational page. This policy applies only to Microsoft Entra ID profiles and does not apply to Microsoft account (MSA) profiles.\r\n\r\nThis policy is available starting in Microsoft Edge version 144 to allow configuration ahead of the changes introduced in version 145.\r\n\r\nIf you enable this policy or do not configure it, Microsoft Edge shows the informational page by default.\r\nIf you disable this policy, Microsoft Edge does not show the informational page to users.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_whatsnewpageforentraprofilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"25551c9e2a70c84b":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides","displayName":"Override IP address space mappings (User)","description":"Specifies IP address space overrides for Local Network Access restrictions. This policy allows administrators to treat specific IP address ranges as public (exempt from Local Network Access restrictions) or as local (subject to Local Network Access restrictions).\r\n\r\nIP address space overrides can be specified using one of the following formats:\r\n\r\n• [cidr]=[public|local|loopback]\r\nwhere [cidr] is an IP address range in CIDR notation. CIDR overrides apply to all ports.\r\n\r\n• [ip-address]:[port]=[public|local|loopback]\r\n\r\nIPv6 addresses must be specified in URL-safe (bracketed) format.\r\n\r\nFor more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\n100.64.0.0/10=public\r\n[2001:db8::]/32=local\r\n192.168.0.1:8000=public\r\n[2001:DB8::8:800:200C:417A]:8080=local","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkaccessipaddressspaceoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},"25363e391acc9a54":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\r\nIf you enable this policy or don't set it, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\r\nIf you disable this policy, warnings will not be shown for insecure forms, and autofill will work normally.\r\n\r\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"25b1cff807929049":{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled","displayName":"Ignore Application Guard site list configuration and browse Edge normally (User)","description":"Set whether Edge should ignore the Application Guard site list configuration for trusted and untrusted sites.\r\n\r\nIf you enable this policy, all navigations from Edge, including navigations to untrusted sites, will be accessed normally within Edge without redirecting to the Application Guard container. Note: this policy ONLY impacts Edge, so navigations from other browsers might get redirected to the Application Guard Container if you have the corresponding extensions enabled.\r\n\r\nIf you disable or don't configure this policy, Edge does not ignore the Application Guard site list. If users try to navigate to an untrusted site in the host, the site will open in the container.","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge~applicationguard_applicationguardpassivemodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2549f3fb55039ad4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_sleepinterval_l_sleepintervaldecimal","displayName":"Sleep interval upper limit (minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},"2570563026db3b49":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany","displayName":"German (Germany) (User)","description":"Enables the editing language German (Germany)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germangermany_1","displayName":"Enabled","description":null,"helpText":null}]},"25b64b82fd513b81":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite","displayName":"Enable Workflows on My Site (User)","description":"Allows workflows on My Site to be started from within the workflow enabled Office applications.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_enableworkflowsonmysite_1","displayName":"Enabled","description":null,"helpText":null}]},"25de542d7ce6c041":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_0","displayName":"No minimum level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_1","displayName":"XAdES-BES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_2","displayName":"XAdES-T","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_3","displayName":"XAdES-C","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_4","displayName":"XAdES-X","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyminimumxadeslevelfordigitalsignaturegeneration_l_specifyminimumxadeslevelfordigitalsignaturegenerationdropid_5","displayName":"XAdES-X-L","description":null,"helpText":null}]},"25fd4f0feb186535":{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols","displayName":"Block Insecure Protocols (User)","description":"\r\n\t\t\tThis policy setting allows you to control which protocols can be used when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you enable this policy setting, non-HTTPS links will be blocked when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you disable this policy setting, all protocols and links will be allowed when opening documents in Microsoft 365 apps.\r\n\r\n\t\t\tIf you don't configure this policy setting, all protocols and links will be allowed when opening documents in Microsoft 365 apps.\r\n\t\t","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockinsecureprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},"256f86f8b2850dd4":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage44_1","displayName":"True","description":null,"helpText":null}]},"258ed2a2da63e103":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends","displayName":"Request a read receipt for all messages a user sends (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_requestareadreceiptforallmessagesausersends_1","displayName":"True","description":null,"helpText":null}]},"2559f02e0449545a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms","displayName":"Allow Active X One Off Forms (User) (Deprecated)","description":"By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_1","displayName":"Enabled","description":null,"helpText":null}]},"257707a85154801c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs","displayName":"Do not provide Continue option on Encryption warning dialog boxes (User)","description":"This setting controls whether Outlook users are allowed to send e-mail messages after they see an encryption warning. \r\n\r\nIf you enable this policy setting, encryption warning dialog boxes do not contain a Continue button, which means that users must cancel the sending operation entirely. \r\n\r\nIf you disable or do not configure this policy setting, if Outlook users see an encryption-related dialog box when attempting to send a message, they can choose to dismiss the warning and send the message anyway.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_disablecontinuebuttononallencryptionwarningdialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"25a1f06f1a8ca45d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2","displayName":"Security setting for macros (User)","description":"This policy setting controls the security level for macros in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for handling macros in Outlook: \r\n\r\n- Always warn. This option corresponds to the \"Warnings for all macros\" option in the \"Macro Security\" section of the Outlook Trust Center. Outlook disables all macros that are not opened from a trusted location, even if the macros are signed by a trusted publisher. For each disabled macro, Outlook displays a security alert dialog box with information about the macro and its digital signature (if present), and allows users to enable the macro or leave it disabled. \r\n\r\n- Never warn, disable all. This option corresponds to the \"No warnings and disable all macros\" option in the Trust Center. Outlook disables all macros that are not opened from trusted locations, and does not notify users. \r\n\r\n- Warning for signed, disable unsigned. This option corresponds to the \"Warnings for signed macros; all unsigned macros are disabled\" option in the Trust Center. Outlook handles macros as follows: \r\n\r\n--If a macro is digitally signed by a trusted publisher, the macro can run if the user has already trusted the publisher. \r\n\r\n--If a macro has a valid signature from a publisher that the user has not trusted, the security alert dialog box for the macro lets the user choose whether to enable the macro for the current session, disable the macro for the current session, or to add the publisher to the Trusted Publishers list so that it will run without prompting the user in the future. \r\n\r\n--If a macro does not have a valid signature, Outlook disables it without prompting the user, unless it is opened from a trusted location. \r\n\r\nThis option is the default configuration in Outlook. \r\n\r\n- No security check. This option corresponds to the \"No security check for macros (Not recommended)\" option in the Trust Center. Outlook runs all macros without prompting users. This configuration makes users' computers vulnerable to potentially malicious code and is not recommended. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of Enabled -- Warning for signed, disable unsigned.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"25ad74bd1a49c2ca":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_rpcproxyservername_l_rpcproxyservernametextid","displayName":"Specify the proxy server name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},"252f8dfd1e17f225":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads","displayName":"Offline Address Book: Limit manual OAB downloads (User)","description":"This policy setting allows you to specify the number of manual downloads of the offline address book (OAB) allowed in a 13 hour period.\r\n\r\nIf you enable this policy setting, you may specify the number of manual downloads of the offline address book (OAB) allowed in a 13 hour period. If you set the value to 0, then no manual OAB downloads are allowed. If you set the value to the maximum of 65535, then that will allow an unlimited number of manual downloads of the OAB.\r\n\r\nIf you disable or do not configure this policy setting, an unlimited number of manual downloads of the OAB will be allowed.","helpText":"","infoUrls":[],"categoryId":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","categoryName":"Offline Address Book","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_offlineaddressbook_l_offlineaddressbooklimitmanualoabdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"25ba5be771cac1c5":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems157_1","displayName":"Enabled","description":null,"helpText":null}]},"25077ed1f7873be6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkwd_1","displayName":"True","description":null,"helpText":null}]},"25fb665886c89189":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":null},"25b7bfe5eca095df":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/28.json b/public/intune-definitions/28.json index 178d2c178460..c43902623e5f 100644 --- a/public/intune-definitions/28.json +++ b/public/intune-definitions/28.json @@ -1 +1 @@ -{"280122f0d6faee06":{"id":"com.apple.applicationaccess_allowsatelliteconnection","displayName":"Allow Satellite Connection","description":"If `false`, the system prohibits the connection to and use of satellite services.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsatelliteconnection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsatelliteconnection_true","displayName":"True","description":null,"helpText":null}]},"28cf4836fd6dad7e":{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction","displayName":"Domain Action","description":"The DNS settings behavior for the specified domains. Allowed values:\n\n* 'NeverConnect': Don't use the DNS Settings for the specified domains.\n* 'ConnectIfNeeded': Allow using the DNS Settings for the specified domains.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction_0","displayName":"NeverConnect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction_1","displayName":"ConnectIfNeeded","description":null,"helpText":null}]},"2824cfada016fa54":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},"2856e8c931afc763":{"id":"com.apple.managedclient.preferences_askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\n\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\n\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#askbeforecloseenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_askbeforecloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_askbeforecloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"28a58f35c07f1a5f":{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates","description":"Lets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\n\nIf you enable this setting or the setting is unconfigured, the list of available templates will be downloaded in the background from a Microsoft service every 24 hours.\n\nIf you disable this setting the list of available templates will be downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#backgroundtemplatelistupdatesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"281f8f76df6e4fa8":{"id":"com.apple.managedclient.preferences_builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs.","description":"Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API.\n\nEnable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed.\n\nDisable this policy to block access to the APIs. The APIs will return an error when used.\n\nFor more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtinaiapisenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtinaiapisenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtinaiapisenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"2824d64df94539bc":{"id":"com.apple.managedclient.preferences_disableautoconfig","displayName":"Disable automatic sign in","description":"If you set this value to true the sync app is prevented from automatically signing in with an existing Azure AD credential that is made available to Microsoft applications.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disableautoconfig"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disableautoconfig_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableautoconfig_1","displayName":"True","description":null,"helpText":null}]},"28a91ddd516eb530":{"id":"com.apple.managedclient.preferences_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports","description":"There is a list of restricted ports built into Microsoft Edge. Connections to these ports will fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on.\n\nPorts are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for error code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (for example port 80 or 443).\n\nMalicious websites can easily detect that this policy is set, and for which ports, then use that information to target attacks.\n\nEach port listed in this policy is labeled with a date that it can be unblocked until. After that date the port will be restricted regardless of if it's specified by the value of this policy.\n\nLeaving the value empty or unset means that all restricted ports will be blocked. Invalid port values set through this policy will be ignored while valid ones will still be applied.\n\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\n\nPolicy options mapping:\n\n* 554 (554) = port 554 (can be unblocked until 2021/10/15)\n\n* 10080 (10080) = port 10080 (can be unblocked until 2022/04/01)\n\n* 6566 (6566) = port 6566 (can be unblocked until 2021/10/15)\n\n* 989 (989) = port 989 (can be unblocked until 2022/02/01)\n\n* 990 (990) = port 990 (can be unblocked until 2022/02/01)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#explicitlyallowednetworkports"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"28c0aa0312df1da7":{"id":"com.apple.managedclient.preferences_performanceprofiles","displayName":"Performance Profiles","description":"Performance profiles","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/performance-profiles"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_performanceprofiles_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_performanceprofiles_1","displayName":"disabled","description":null,"helpText":null}]},"28fbfefac3f93ba4":{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled","displayName":"Enable insecure download warnings","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\n\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\n\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showdownloadsinsecurewarningsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"28c8c4f1062bc3a4":{"id":"com.apple.mcx_timeserver","displayName":"Time Server","description":"The NTP server to connect to. Use commas to separate multiple time servers.","helpText":null,"infoUrls":[],"categoryId":"853f4181-42e8-411c-91cf-c06968c0a543","categoryName":"Time Server","options":null},"28a38f16b18fcdb3":{"id":"com.apple.screensaver.user_modulename","displayName":"Module Name","description":"The module name.","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},"282b5f510d4e3359":{"id":"com.apple.security.firewall_applications_item_allowed","displayName":"Allowed","description":"If true, allows connections for the app.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_applications_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_applications_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"283c503d9c04a7bd":{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"2889d10d822b2422":{"id":"ddm-latestsoftwareupdate_delayindays","displayName":"Delay In Days","description":"Specify the number of days that should pass before a deadline is enforced after a new update is released by Apple.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},"2878c23448f1fb44":{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins","displayName":"Hide Exclusions From Local Admins","description":"This policy setting controls whether or not exclusions are visible to local admins. To control local users exlcusions visibility use HideExclusionsFromLocalUsers. If HideExclusionsFromLocalAdmins is set then HideExclusionsFromLocalUsers will be implicitly set.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins_1","displayName":"If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","description":"If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","helpText":null},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins_0","displayName":"If you disable or do not configure this setting, local admins will be able to see exclusions in the Windows Security App and via PowerShell.","description":"If you disable or do not configure this setting, local admins will be able to see exclusions in the Windows Security App and via PowerShell.","helpText":null}]},"2896c237468961f0":{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin","displayName":"Use Security Key For Signin","description":"Use security key for signin. 0 is disabled. 1 is enable. If you do not configure this policy setting, the default is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin_0","displayName":"Disabled","description":"disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin_1","displayName":"Enabled","description":"enabled","helpText":null}]},"28edb92d29c4a541":{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials","displayName":"Allow delegating fresh credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials can be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of fresh credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of fresh credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating fresh credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com\r\nRemote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowfreshcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},"284d6284996612aa":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass","displayName":"Define addresses to bypass proxy server","description":"This policy, if defined, will prevent antimalware from using the configured proxy server when communicating with the specified IP addresses. The address value should be entered as a valid URL.\r\n\r\n If you enable this setting, the proxy server will be bypassed for the specified addresses.\r\n\r\n If you disable or do not configure this setting, the proxy server will not be bypassed for the specified addresses.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-proxybypass"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_1","displayName":"Enabled","description":null,"helpText":null}]},"2806da902fafb704":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot","displayName":"MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)","description":"MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoreboot"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot_1","displayName":"Enabled","description":null,"helpText":null}]},"28f8755f56cf991e":{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat","displayName":"Override print driver execution compatibility setting reported by print driver","description":"This policy setting determines whether the print spooler will override the Driver Isolation compatibility reported by the print driver. This enables executing print drivers in an isolated process, even if the driver does not report compatibility.\r\n\r\nIf you enable this policy setting, the print spooler isolates all print drivers that do not explicitly opt out of Driver Isolation.\r\n\r\nIf you disable or do not configure this policy setting, the print spooler uses the Driver Isolation compatibility flag value reported by the print driver.\r\n\r\nNotes:\r\n-Other system or driver policy settings may alter the process in which a print driver is executed.\r\n-This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.\r\n-This policy setting takes effect without restarting the print spooler service.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-printdriverisolationoverridecompat"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat_1","displayName":"Enabled","description":null,"helpText":null}]},"28379900af307ae1":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_default","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_client","displayName":"Client","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_enterprise client","displayName":"Enterprise Client","description":null,"helpText":null}]},"28c17ecb4b9ce9ff":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp","displayName":"Prompt for credentials on the client computer","description":"This policy setting determines whether a user will be prompted on the client computer to provide credentials for a remote connection to an RD Session Host server.\r\n\r\nIf you enable this policy setting, a user will be prompted on the client computer instead of on the RD Session Host server to provide credentials for a remote connection to an RD Session Host server. If saved credentials for the user are available on the client computer, the user will not be prompted to provide credentials.\r\n\r\nNote: If you enable this policy setting in releases of Windows Server 2008 R2 with SP1 or Windows Server 2008 R2, and a user is prompted on both the client computer and on the RD Session Host server to provide credentials, clear the Always prompt for password check box on the Log on Settings tab in Remote Desktop Session Host Configuration.\r\n\r\nIf you disable or do not configure this policy setting, the version of the operating system on the RD Session Host server will determine when a user is prompted to provide credentials for a remote connection to an RD Session Host server. For Windows Server 2003 and Windows 2000 Server a user will be prompted on the terminal server to provide credentials for a remote connection. For Windows Server 2008 and Windows Server 2008 R2, a user will be prompted on the client computer to provide credentials for a remote connection.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-promt-creds-client-comp"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp_1","displayName":"Enabled","description":null,"helpText":null}]},"28a735506b9081fc":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote","displayName":"Microsoft OneNote 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2013.\r\nBy default, the user settings of Microsoft OneNote 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote_1","displayName":"Enabled","description":null,"helpText":null}]},"28e6707d8bf35bf0":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries","displayName":"Reestablishment Retries","description":"Specifies the number of times to retry a dropped session.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowreestablishmentretries"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_1","displayName":"Enabled","description":null,"helpText":null}]},"2873fc888d98746c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed","displayName":"Allow QUIC protocol","description":"Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome.\r\n\r\nSetting the policy to Disabled disallows the use of QUIC protocol.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"28611d185a449661":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning","description":"Setting the policy to Enabled suppresses the warning that appears when Google Chrome is running on an unsupported computer or operating system.\r\n\r\nSetting the policy to Disabled or leaving it unset means the warnings appear on unsupported systems.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning_1","displayName":"Enabled","description":null,"helpText":null}]},"282e2d2868b3f152":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled","displayName":"Disable synchronization of data with Google","description":"Setting the policy to Enabled turns off data synchronization in Google Chrome using Google-hosted synchronization services.\r\nTo fully turn off Chrome Sync services, we recommend that you turn off the service in the Google Admin console.\r\n\r\nIf the policy is set to Disabled or not set, users are allowed to choose whether to use Chrome Sync.\r\n\r\nNote: Do not turn on this policy when RoamingProfileSupportEnabled is Enabled, because that feature shares the same client-side functionality. The Google-hosted synchronization is off completely in this case.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"28d2b214824d95a9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible","displayName":"Show the middle slot announcement on the New Tab Page","description":"This policy controls the visibility of the middle slot announcement on the New Tab Page.\r\n\r\nIf the policy is set to Enabled, the New Tab Page will show the middle slot announcement if it is available.\r\n\r\nIf the policy is set to Disabled, the New Tab Page will not show the middle slot announcement even if it is available.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible_1","displayName":"Enabled","description":null,"helpText":null}]},"28e429129c033dcb":{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdevicesetupclasses_deviceinstall_classes_allow_list","displayName":"Allowed classes","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},"281dd1b0284353a1":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.\r\n\r\nIf you disable this policy, AutoFill never suggests or fills in address information, nor does it save additional address information that the user might submit while browsing the web.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for addresses in the user interface.\r\n\r\nNote that if you disable this policy you also stop all activity for all web forms, except payment and password forms. No further entries are saved, and Microsoft Edge won't suggest or AutoFill any previous entries.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"28cca7e1de7c9e30":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod","displayName":"Set the time period for update notifications","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"28da9eda6d42cd8b":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting","displayName":"Default pop-up window setting","description":"Set whether websites can show pop-up windows. You can allow them on all websites (1) or block them on all sites (2).\r\n\r\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\r\n\r\n* 1 = Allow all sites to show pop-ups\r\n\r\n* 2 = Don't allow any site to show pop-up windows","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"284dfdcacfc44c44":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls","displayName":"Block WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nURL patterns in this policy can't conflict with those configured in the 'WebUsbAskForUrls' (Allow WebUSB on specific sites) policy. You can't both allow and block a URL.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"28ed1e8400fa593e":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Microsoft Edge may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise JavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"28e74454b3ff22a3":{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_allowed","displayName":"Do not restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_disallowed","displayName":"Do not allow users to enable any HTTPS-Only Mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},"28834a0f3ab66d8c":{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_inprivatemodeurlblocklistdesc","displayName":"Block access to a list of URLs in InPrivate mode. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"28089ac23df8156c":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings","displayName":"Allow importing of browser settings","description":"Allows users to import browser settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings_1","displayName":"Enabled","description":null,"helpText":null}]},"28f2a7f80f783e0d":{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype","displayName":"New tab page experience (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},"28f110bd3b148953":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended","displayName":"Manage Search Engines","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\r\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\r\n\r\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default. Starting in Microsoft Edge 84, you can set this policy as a recommended policy to allow search provider discovery. You do not need to add the allow_search_engine_discovery optional parameter.\r\n\r\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\r\n\r\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\r\n\r\nIf the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allow_search_engine_discovery\": true\r\n }, \r\n {\r\n \"is_default\": true, \r\n \"suggest_url\": \"https://www.example1.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example1.com/search?q={searchTerms}\", \r\n \"name\": \"Example1\", \r\n \"keyword\": \"example1.com\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example2.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example2.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example2\", \r\n \"keyword\": \"example2.com\", \r\n \"image_search_post_params\": \"content={imageThumbnail},url={imageURL},sbisrc={SearchSource}\", \r\n \"search_url\": \"https://www.example2.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example3.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example3.com/search?q={searchTerms}\", \r\n \"name\": \"Example3\", \r\n \"keyword\": \"example3.com\", \r\n \"encoding\": \"UTF-8\", \r\n \"image_search_url\": \"https://www.example3.com/images/detail/search?iss=sbiupload\"\r\n }, \r\n {\r\n \"search_url\": \"https://www.example4.com/search?q={searchTerms}\", \r\n \"name\": \"Example4\", \r\n \"keyword\": \"example4.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"28a4a3248c82c3bc":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"2856a26af82b26a5":{"id":"device_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_graphsettings_l_mapchartitadminoptin","displayName":"Allow Map Charts to send geographic data to Bing","description":"This policy setting controls whether Map Charts can send geographic data to Bing. For more information about Map Charts, see https://go.microsoft.com/fwlink/?linkid=2194000.\r\n\r\nIf you enable this policy setting, when a user adds geographic data to a new or existing map chart, that data will be sent to Bing and the map chart will be updated to include any new locations.\r\n\r\nIf you disable this policy setting, when a user adds geographic data to a new or existing map chart, the geographic data won’t be sent to Bing and the map chart won’t be updated to include any new locations. Also, the user will see a message letting them know that their map chart can’t be created.\r\n\r\nIf you don’t configure this policy setting, when a user adds geographic data to a new or existing map chart, that data will be sent to Bing and the map chart will be updated to include any new locations.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"device_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_graphsettings_l_mapchartitadminoptin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_graphsettings_l_mapchartitadminoptin_1","displayName":"Enabled","description":null,"helpText":null}]},"281dce87487532fc":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_powerpntexe31","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_powerpntexe31_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_powerpntexe31_1","displayName":"True","description":null,"helpText":null}]},"282ec251a0ea735d":{"id":"sirisettings_forceprofanityfilter","displayName":"Force Profanity Filter","description":"If `true`, forces Siri profanity filter.","helpText":null,"infoUrls":[],"categoryId":"b85d9c04-4923-4fdf-a425-424686d47859","categoryName":"Siri Settings","options":[{"id":"sirisettings_forceprofanityfilter_false","displayName":"False","description":null,"helpText":null},{"id":"sirisettings_forceprofanityfilter_true","displayName":"True","description":null,"helpText":null}]},"28a296f0dea058d1":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation format","description":null,"helpText":null}]},"287a9a1f8d049c53":{"id":"user_vendor_msft_policy_config_admx_desktop_ad_querylimit","displayName":"Maximum size of Active Directory searches (User)","description":"Specifies the maximum number of objects the system displays in response to a command to browse or search Active Directory. This setting affects all browse displays associated with Active Directory, such as those in Local Users and Groups, Active Directory Users and Computers, and dialog boxes used to set permissions for user or group objects in Active Directory.\r\n\r\nIf you enable this setting, you can use the \"Number of objects returned\" box to limit returns from an Active Directory search.\r\n\r\nIf you disable this setting or do not configure it, the system displays up to 10,000 objects. This consumes approximately 2 MB of memory or disk space.\r\n\r\nThis setting is designed to protect the network and the domain controller from the effect of expansive searches.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-ad-querylimit"],"categoryId":"99ba9e42-9872-4a03-a615-fc4a4cebc067","categoryName":"Active Directory","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_ad_querylimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_ad_querylimit_1","displayName":"Enabled","description":null,"helpText":null}]},"28a16dc4a2b06823":{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremotepage_1","displayName":"Hide previous versions list for remote files (User)","description":"This policy setting lets you hide the list of previous versions of files that are on file shares. The previous versions come from the on-disk restore points on the file share.\r\n\r\nIf you enable this policy setting, users cannot list or restore previous versions of files on file shares.\r\n\r\nIf you disable this policy setting, users can list and restore previous versions of files on file shares.\r\n\r\nIf you do not configure this policy setting, it is disabled by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disableremotepage-1"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremotepage_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremotepage_1_1","displayName":"Enabled","description":null,"helpText":null}]},"287edd3a21686977":{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailybeginminute_quiethoursdailybeginminutecontrol","displayName":"Minutes after midnight: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":null},"28cf356c2dda16e6":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled","displayName":"Enable dismissing compromised password alerts for entered credentials (User)","description":"Setting the policy to Enabled or leaving it unset gives the user the option to dismiss/restore compromised password alerts.\r\n\r\nIf you disable this setting, users will not be able to dismiss alerts about compromised passwords. If enabled, users will be able to dismiss alerts about compromised passwords.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"28a172b82b5e14e2":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings","displayName":"Settings for Tab Organizer (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_1","displayName":"Enabled","description":null,"helpText":null}]},"28229c6bbc1bf2e1":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop","displayName":"Enable fill handle and cell drag-and-drop (User)","description":"This policy setting sets the \"Enable fill handle and cell drag-and-drop\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will enable the fill handle and allow drag-and-drop. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will disable the fill handle and drag-and-drop will not be allowed.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop_1","displayName":"Enabled","description":null,"helpText":null}]},"28fa742401959b24":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40_1","displayName":"True","description":null,"helpText":null}]},"2816212a9aa22cd5":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},"28c95c02be2884d4":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowaccesstodatasources"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"28bb365cb682696b":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"283189ecfbcd2a6d":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001","displayName":"Download signed ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_1","displayName":"Prompt","description":null,"helpText":null}]},"284849254c05b0e5":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},"28531b434f880758":{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm for connection attempts (User)","description":"Controls whether Microsoft Edge uses the Happy Eyeballs V3 algorithm to optimize connection attempts. This algorithm improves reliability and performance in dual-stack (IPv4/IPv6) networks by racing connection attempts across IP versions and HTTP protocols (e.g., HTTP/3 vs. others). For more details, see https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3.\r\n\r\nEnabled or not configured: Uses the algorithm for connection attempts.\r\n\r\nDisabled: Disables the algorithm.\r\n\r\nNote: This policy supports dynamic refresh.\r\n\r\nImportant: This policy is temporary and will be removed in a future version.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"282ae368b21e86f9":{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_6","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},"28abc052ca483c98":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"2804ed09321984d7":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior","displayName":"Configure ShadowStack crash rollback behavior (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy is deprecated because it's intended to serve only as a short-term mechanism to give enterprises more time to update their environments and report issues if they are found to be incompatible with Hardware-enforced Stack Protection. It won't work in Microsoft Edge as soon as version 109.\r\n\r\nMicrosoft Edge includes a Hardware-enforced Stack Protection security feature. This feature may result in the browser crashing unexpectedly in cases that do not represent an attempt to compromise the browser's security.\r\n\r\nUsing this policy, you may control the behavior of the Hardware-enforced Stack Protection feature after a crash triggered by this feature is encountered.\r\n\r\nSet this policy to 'Disable' to disable the feature.\r\n\r\nSet this policy to 'DisableUntilUpdate' to disable the feature until Microsoft Edge updates next time.\r\n\r\nSet this policy to 'Enable' to keep the feature enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable Hardware-enforced Stack Protection\r\n\r\n* DisableUntilUpdate (1) = Disable Hardware-enforced Stack Protection until the next Microsoft Edge update\r\n\r\n* Enable (2) = Enable Hardware-enforced Stack Protection\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"28d5f087446d1a36":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit","displayName":"Set maximum database instances limit (User)","description":"This policy setting allows you to specify the maximum limit of how many instances per page the database shim can return. This policy setting enforces the allowed maximum for applications including those that do not respect the default.\r\n \r\nIf you enable this policy setting, you may specify the maximum limit of how many instances the database shim can return.\r\n\r\nIf you disable or do not configure this policy setting, there will be no limit of how many instances the database shim can return.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_1","displayName":"Enabled","description":null,"helpText":null}]},"281d8b8c5020808b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath_l_graphgallerypath354","displayName":"Graph gallery path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":null},"285a5d0391bf069d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada","displayName":"English (Canada) (User)","description":"Enables the editing language English (Canada)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada_1","displayName":"Enabled","description":null,"helpText":null}]},"2840fd271bd21312":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia","displayName":"Nepali (India) (User)","description":"Enables the editing language Nepali (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia_1","displayName":"Enabled","description":null,"helpText":null}]},"28b75f488cedb12b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish","displayName":"Polish (User)","description":"Enables the editing language Polish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish_1","displayName":"Enabled","description":null,"helpText":null}]},"28551a82cdac4d79":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria","displayName":"Tamazight (Latin, Algeria) (User)","description":"Enables the editing language \"Tamazight (Latin, Algeria)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria_1","displayName":"Enabled","description":null,"helpText":null}]},"2890fdb655fd957e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowdescrip480","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"28cedf2b1504236b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_l_listoftrustedaddins_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":null},"286447a281051761":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"289c540c21c640db":{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge","displayName":"Allow Local Ipsec Policy Merge","description":"This value is an on/off switch. If this value is false, connection security rules from the local store are ignored and not enforced, regardless of the schema version and connection security rule version. The merge law for this option is to always use the value of the GroupPolicyRSoPStore.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge_false","displayName":"False","description":"AllowLocalIpsecPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge_true","displayName":"True","description":"AllowLocalIpsecPolicyMerge On","helpText":null}]},"28d17d5b724b88e4":{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]}} \ No newline at end of file +{"280122f0d6faee06":{"id":"com.apple.applicationaccess_allowsatelliteconnection","displayName":"Allow Satellite Connection","description":"If `false`, the system prohibits the connection to and use of satellite services.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsatelliteconnection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsatelliteconnection_true","displayName":"True","description":null,"helpText":null}]},"28cf4836fd6dad7e":{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction","displayName":"Domain Action","description":"The DNS settings behavior for the specified domains. Allowed values:\n\n* 'NeverConnect': Don't use the DNS Settings for the specified domains.\n* 'ConnectIfNeeded': Allow using the DNS Settings for the specified domains.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction_0","displayName":"NeverConnect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_item_domainaction_1","displayName":"ConnectIfNeeded","description":null,"helpText":null}]},"2824cfada016fa54":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype","displayName":"Range Type","description":"The type of day range.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype_0","displayName":"Weekday","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_rangetype_1","displayName":"Weekend","description":null,"helpText":null}]},"2856e8c931afc763":{"id":"com.apple.managedclient.preferences_askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\n\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\n\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#askbeforecloseenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_askbeforecloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_askbeforecloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"28a58f35c07f1a5f":{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates","description":"Lets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\n\nIf you enable this setting or the setting is unconfigured, the list of available templates will be downloaded in the background from a Microsoft service every 24 hours.\n\nIf you disable this setting the list of available templates will be downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#backgroundtemplatelistupdatesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_backgroundtemplatelistupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"281f8f76df6e4fa8":{"id":"com.apple.managedclient.preferences_builtinaiapisenabled","displayName":"Allow pages to use the built-in AI APIs.","description":"Use this policy to control whether websites can access the built-in AI APIs, including the LanguageModel API, Summarization API, Writer API, and Rewriter API.\n\nEnable this policy to allow pages to use the APIs. If you don’t configure this policy, the APIs are still allowed.\n\nDisable this policy to block access to the APIs. The APIs will return an error when used.\n\nFor more information, see https://github.com/webmachinelearning/writing-assistance-apis/blob/main/README.md.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtinaiapisenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtinaiapisenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtinaiapisenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"2824d64df94539bc":{"id":"com.apple.managedclient.preferences_disableautoconfig","displayName":"Disable automatic sign in","description":"If you set this value to true the sync app is prevented from automatically signing in with an existing Azure AD credential that is made available to Microsoft applications.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disableautoconfig"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disableautoconfig_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableautoconfig_1","displayName":"True","description":null,"helpText":null}]},"28a91ddd516eb530":{"id":"com.apple.managedclient.preferences_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports","description":"There is a list of restricted ports built into Microsoft Edge. Connections to these ports will fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on.\n\nPorts are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for error code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (for example port 80 or 443).\n\nMalicious websites can easily detect that this policy is set, and for which ports, then use that information to target attacks.\n\nEach port listed in this policy is labeled with a date that it can be unblocked until. After that date the port will be restricted regardless of if it's specified by the value of this policy.\n\nLeaving the value empty or unset means that all restricted ports will be blocked. Invalid port values set through this policy will be ignored while valid ones will still be applied.\n\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\n\nPolicy options mapping:\n\n* 554 (554) = port 554 (can be unblocked until 2021/10/15)\n\n* 10080 (10080) = port 10080 (can be unblocked until 2022/04/01)\n\n* 6566 (6566) = port 6566 (can be unblocked until 2021/10/15)\n\n* 989 (989) = port 989 (can be unblocked until 2022/02/01)\n\n* 990 (990) = port 990 (can be unblocked until 2022/02/01)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#explicitlyallowednetworkports"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"28c0aa0312df1da7":{"id":"com.apple.managedclient.preferences_performanceprofiles","displayName":"Performance Profiles","description":"Performance profiles","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/performance-profiles"],"categoryId":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","categoryName":"Features","options":[{"id":"com.apple.managedclient.preferences_performanceprofiles_0","displayName":"enabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_performanceprofiles_1","displayName":"disabled","description":null,"helpText":null}]},"28fbfefac3f93ba4":{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled","displayName":"Enable insecure download warnings","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\n\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\n\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showdownloadsinsecurewarningsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdownloadsinsecurewarningsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"28c8c4f1062bc3a4":{"id":"com.apple.mcx_timeserver","displayName":"Time Server","description":"The NTP server to connect to. Use commas to separate multiple time servers.","helpText":null,"infoUrls":[],"categoryId":"853f4181-42e8-411c-91cf-c06968c0a543","categoryName":"Time Server","options":null},"28a38f16b18fcdb3":{"id":"com.apple.screensaver.user_modulename","displayName":"Module Name","description":"The module name.","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},"282b5f510d4e3359":{"id":"com.apple.security.firewall_applications_item_allowed","displayName":"Allowed","description":"If true, allows connections for the app.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_applications_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_applications_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"283c503d9c04a7bd":{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"2889d10d822b2422":{"id":"ddm-latestsoftwareupdate_delayindays","displayName":"Delay In Days","description":"Specify the number of days that should pass before a deadline is enforced after a new update is released by Apple.","helpText":null,"infoUrls":[],"categoryId":"15be55d8-7477-4274-9b09-b775bce68416","categoryName":"Software Update Enforce Latest","options":null},"2878c23448f1fb44":{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins","displayName":"Hide Exclusions From Local Admins","description":"This policy setting controls whether or not exclusions are visible to local admins. To control local users exlcusions visibility use HideExclusionsFromLocalUsers. If HideExclusionsFromLocalAdmins is set then HideExclusionsFromLocalUsers will be implicitly set.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins_1","displayName":"If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","description":"If you enable this setting, local admins will no longer be able to see the exclusion list in Windows Security App or via PowerShell.","helpText":null},{"id":"device_vendor_msft_defender_configuration_hideexclusionsfromlocaladmins_0","displayName":"If you disable or do not configure this setting, local admins will be able to see exclusions in the Windows Security App and via PowerShell.","description":"If you disable or do not configure this setting, local admins will be able to see exclusions in the Windows Security App and via PowerShell.","helpText":null}]},"2896c237468961f0":{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin","displayName":"Use Security Key For Signin","description":"Use security key for signin. 0 is disabled. 1 is enable. If you do not configure this policy setting, the default is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin_0","displayName":"Disabled","description":"disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_securitykey_usesecuritykeyforsignin_1","displayName":"Enabled","description":"enabled","helpText":null}]},"28edb92d29c4a541":{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials","displayName":"Allow delegating fresh credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials can be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of fresh credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of fresh credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating fresh credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com\r\nRemote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowfreshcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},"284d6284996612aa":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass","displayName":"Define addresses to bypass proxy server","description":"This policy, if defined, will prevent antimalware from using the configured proxy server when communicating with the specified IP addresses. The address value should be entered as a valid URL.\r\n\r\n If you enable this setting, the proxy server will be bypassed for the specified addresses.\r\n\r\n If you disable or do not configure this setting, the proxy server will not be bypassed for the specified addresses.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-proxybypass"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_1","displayName":"Enabled","description":null,"helpText":null}]},"2806da902fafb704":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot","displayName":"MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)","description":"MSS: (AutoReboot) Allow Windows to automatically restart after a system crash (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoreboot"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoreboot_1","displayName":"Enabled","description":null,"helpText":null}]},"28f8755f56cf991e":{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat","displayName":"Override print driver execution compatibility setting reported by print driver","description":"This policy setting determines whether the print spooler will override the Driver Isolation compatibility reported by the print driver. This enables executing print drivers in an isolated process, even if the driver does not report compatibility.\r\n\r\nIf you enable this policy setting, the print spooler isolates all print drivers that do not explicitly opt out of Driver Isolation.\r\n\r\nIf you disable or do not configure this policy setting, the print spooler uses the Driver Isolation compatibility flag value reported by the print driver.\r\n\r\nNotes:\r\n-Other system or driver policy settings may alter the process in which a print driver is executed.\r\n-This policy setting applies only to print drivers loaded by the print spooler. Print drivers loaded by applications are not affected.\r\n-This policy setting takes effect without restarting the print spooler service.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-printdriverisolationoverridecompat"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_printdriverisolationoverridecompat_1","displayName":"Enabled","description":null,"helpText":null}]},"28379900af307ae1":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect","displayName":"Select from the following states:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_default","displayName":"Default State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_disabled","displayName":"Disabled State","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_client","displayName":"Client","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_stateselect_enterprise client","displayName":"Enterprise Client","description":null,"helpText":null}]},"28c17ecb4b9ce9ff":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp","displayName":"Prompt for credentials on the client computer","description":"This policy setting determines whether a user will be prompted on the client computer to provide credentials for a remote connection to an RD Session Host server.\r\n\r\nIf you enable this policy setting, a user will be prompted on the client computer instead of on the RD Session Host server to provide credentials for a remote connection to an RD Session Host server. If saved credentials for the user are available on the client computer, the user will not be prompted to provide credentials.\r\n\r\nNote: If you enable this policy setting in releases of Windows Server 2008 R2 with SP1 or Windows Server 2008 R2, and a user is prompted on both the client computer and on the RD Session Host server to provide credentials, clear the Always prompt for password check box on the Log on Settings tab in Remote Desktop Session Host Configuration.\r\n\r\nIf you disable or do not configure this policy setting, the version of the operating system on the RD Session Host server will determine when a user is prompted to provide credentials for a remote connection to an RD Session Host server. For Windows Server 2003 and Windows 2000 Server a user will be prompted on the terminal server to provide credentials for a remote connection. For Windows Server 2008 and Windows Server 2008 R2, a user will be prompted on the client computer to provide credentials for a remote connection.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-promt-creds-client-comp"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_promt_creds_client_comp_1","displayName":"Enabled","description":null,"helpText":null}]},"28a735506b9081fc":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote","displayName":"Microsoft OneNote 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2013.\r\nBy default, the user settings of Microsoft OneNote 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013onenote_1","displayName":"Enabled","description":null,"helpText":null}]},"28e6707d8bf35bf0":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries","displayName":"Reestablishment Retries","description":"Specifies the number of times to retry a dropped session.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowreestablishmentretries"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowreestablishmentretries_1","displayName":"Enabled","description":null,"helpText":null}]},"2873fc888d98746c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed","displayName":"Allow QUIC protocol","description":"Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome.\r\n\r\nSetting the policy to Disabled disallows the use of QUIC protocol.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"28611d185a449661":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning","description":"Setting the policy to Enabled suppresses the warning that appears when Google Chrome is running on an unsupported computer or operating system.\r\n\r\nSetting the policy to Disabled or leaving it unset means the warnings appear on unsupported systems.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressunsupportedoswarning_1","displayName":"Enabled","description":null,"helpText":null}]},"282e2d2868b3f152":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled","displayName":"Disable synchronization of data with Google","description":"Setting the policy to Enabled turns off data synchronization in Google Chrome using Google-hosted synchronization services.\r\nTo fully turn off Chrome Sync services, we recommend that you turn off the service in the Google Admin console.\r\n\r\nIf the policy is set to Disabled or not set, users are allowed to choose whether to use Chrome Sync.\r\n\r\nNote: Do not turn on this policy when RoamingProfileSupportEnabled is Enabled, because that feature shares the same client-side functionality. The Google-hosted synchronization is off completely in this case.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_syncdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"28d2b214824d95a9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible","displayName":"Show the middle slot announcement on the New Tab Page","description":"This policy controls the visibility of the middle slot announcement on the New Tab Page.\r\n\r\nIf the policy is set to Enabled, the New Tab Page will show the middle slot announcement if it is available.\r\n\r\nIf the policy is set to Disabled, the New Tab Page will not show the middle slot announcement even if it is available.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpmiddleslotannouncementvisible_1","displayName":"Enabled","description":null,"helpText":null}]},"28e429129c033dcb":{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdevicesetupclasses_deviceinstall_classes_allow_list","displayName":"Allowed classes","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},"281dd1b0284353a1":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Enables the AutoFill feature and allows users to auto-complete address information in web forms using previously stored information.\r\n\r\nIf you disable this policy, AutoFill never suggests or fills in address information, nor does it save additional address information that the user might submit while browsing the web.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for addresses in the user interface.\r\n\r\nNote that if you disable this policy you also stop all activity for all web forms, except payment and password forms. No further entries are saved, and Microsoft Edge won't suggest or AutoFill any previous entries.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofilladdressenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"28cca7e1de7c9e30":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod","displayName":"Set the time period for update notifications","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"28da9eda6d42cd8b":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting","displayName":"Default pop-up window setting","description":"Set whether websites can show pop-up windows. You can allow them on all websites (1) or block them on all sites (2).\r\n\r\nIf you don't configure this policy, pop-up windows are blocked by default, and users can change this setting.\r\n\r\n* 1 = Allow all sites to show pop-ups\r\n\r\n* 2 = Don't allow any site to show pop-up windows","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"284dfdcacfc44c44":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls","displayName":"Block WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can't ask the user to grant them access to a USB device.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nURL patterns in this policy can't conflict with those configured in the 'WebUsbAskForUrls' (Allow WebUSB on specific sites) policy. You can't both allow and block a URL.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"28ed1e8400fa593e":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Microsoft Edge may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise JavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"28e74454b3ff22a3":{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_allowed","displayName":"Do not restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_disallowed","displayName":"Do not allow users to enable any HTTPS-Only Mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge_httpsonlymode_httpsonlymode_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},"28834a0f3ab66d8c":{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_inprivatemodeurlblocklistdesc","displayName":"Block access to a list of URLs in InPrivate mode. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"28089ac23df8156c":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings","displayName":"Allow importing of browser settings","description":"Allows users to import browser settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_importbrowsersettings_1","displayName":"Enabled","description":null,"helpText":null}]},"28f2a7f80f783e0d":{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype","displayName":"New tab page experience (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},"28f110bd3b148953":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended","displayName":"Manage Search Engines","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\r\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\r\n\r\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default. Starting in Microsoft Edge 84, you can set this policy as a recommended policy to allow search provider discovery. You do not need to add the allow_search_engine_discovery optional parameter.\r\n\r\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\r\n\r\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\r\n\r\nIf the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allow_search_engine_discovery\": true\r\n }, \r\n {\r\n \"is_default\": true, \r\n \"suggest_url\": \"https://www.example1.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example1.com/search?q={searchTerms}\", \r\n \"name\": \"Example1\", \r\n \"keyword\": \"example1.com\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example2.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example2.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example2\", \r\n \"keyword\": \"example2.com\", \r\n \"image_search_post_params\": \"content={imageThumbnail},url={imageURL},sbisrc={SearchSource}\", \r\n \"search_url\": \"https://www.example2.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example3.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example3.com/search?q={searchTerms}\", \r\n \"name\": \"Example3\", \r\n \"keyword\": \"example3.com\", \r\n \"encoding\": \"UTF-8\", \r\n \"image_search_url\": \"https://www.example3.com/images/detail/search?iss=sbiupload\"\r\n }, \r\n {\r\n \"search_url\": \"https://www.example4.com/search?q={searchTerms}\", \r\n \"name\": \"Example4\", \r\n \"keyword\": \"example4.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"28a4a3248c82c3bc":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"2856a26af82b26a5":{"id":"device_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_graphsettings_l_mapchartitadminoptin","displayName":"Allow Map Charts to send geographic data to Bing","description":"This policy setting controls whether Map Charts can send geographic data to Bing. For more information about Map Charts, see https://go.microsoft.com/fwlink/?linkid=2194000.\r\n\r\nIf you enable this policy setting, when a user adds geographic data to a new or existing map chart, that data will be sent to Bing and the map chart will be updated to include any new locations.\r\n\r\nIf you disable this policy setting, when a user adds geographic data to a new or existing map chart, the geographic data won’t be sent to Bing and the map chart won’t be updated to include any new locations. Also, the user will see a message letting them know that their map chart can’t be created.\r\n\r\nIf you don’t configure this policy setting, when a user adds geographic data to a new or existing map chart, that data will be sent to Bing and the map chart will be updated to include any new locations.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"device_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_graphsettings_l_mapchartitadminoptin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_graphsettings_l_mapchartitadminoptin_1","displayName":"Enabled","description":null,"helpText":null}]},"281dce87487532fc":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_powerpntexe31","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_powerpntexe31_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_powerpntexe31_1","displayName":"True","description":null,"helpText":null}]},"28ae0a9bc5c6cada":{"id":"device_vendor_msft_policy_config_update_maintenancewindowweeklywednesday","displayName":"Maintenance Window Weekly Wednesday","description":"If the maintenance window repeat schedule is set to weekly, configure whether Wednesday is included in the weekly schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowweeklywednesday"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"282ec251a0ea735d":{"id":"sirisettings_forceprofanityfilter","displayName":"Force Profanity Filter","description":"If `true`, forces Siri profanity filter.","helpText":null,"infoUrls":[],"categoryId":"b85d9c04-4923-4fdf-a425-424686d47859","categoryName":"Siri Settings","options":[{"id":"sirisettings_forceprofanityfilter_false","displayName":"False","description":null,"helpText":null},{"id":"sirisettings_forceprofanityfilter_true","displayName":"True","description":null,"helpText":null}]},"28a296f0dea058d1":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_0","displayName":"Use legacy format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_1","displayName":"Use next generation format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_specifyencryptioncompatibility_l_specifyencryptioncompatibilitydropid_2","displayName":"All files save with next generation format","description":null,"helpText":null}]},"287a9a1f8d049c53":{"id":"user_vendor_msft_policy_config_admx_desktop_ad_querylimit","displayName":"Maximum size of Active Directory searches (User)","description":"Specifies the maximum number of objects the system displays in response to a command to browse or search Active Directory. This setting affects all browse displays associated with Active Directory, such as those in Local Users and Groups, Active Directory Users and Computers, and dialog boxes used to set permissions for user or group objects in Active Directory.\r\n\r\nIf you enable this setting, you can use the \"Number of objects returned\" box to limit returns from an Active Directory search.\r\n\r\nIf you disable this setting or do not configure it, the system displays up to 10,000 objects. This consumes approximately 2 MB of memory or disk space.\r\n\r\nThis setting is designed to protect the network and the domain controller from the effect of expansive searches.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-ad-querylimit"],"categoryId":"99ba9e42-9872-4a03-a615-fc4a4cebc067","categoryName":"Active Directory","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_ad_querylimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_ad_querylimit_1","displayName":"Enabled","description":null,"helpText":null}]},"28a16dc4a2b06823":{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremotepage_1","displayName":"Hide previous versions list for remote files (User)","description":"This policy setting lets you hide the list of previous versions of files that are on file shares. The previous versions come from the on-disk restore points on the file share.\r\n\r\nIf you enable this policy setting, users cannot list or restore previous versions of files on file shares.\r\n\r\nIf you disable this policy setting, users can list and restore previous versions of files on file shares.\r\n\r\nIf you do not configure this policy setting, it is disabled by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disableremotepage-1"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremotepage_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremotepage_1_1","displayName":"Enabled","description":null,"helpText":null}]},"287edd3a21686977":{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailybeginminute_quiethoursdailybeginminutecontrol","displayName":"Minutes after midnight: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":null},"28cf356c2dda16e6":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled","displayName":"Enable dismissing compromised password alerts for entered credentials (User)","description":"Setting the policy to Enabled or leaving it unset gives the user the option to dismiss/restore compromised password alerts.\r\n\r\nIf you disable this setting, users will not be able to dismiss alerts about compromised passwords. If enabled, users will be able to dismiss alerts about compromised passwords.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passworddismisscompromisedalertenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"28a172b82b5e14e2":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings","displayName":"Settings for Tab Organizer (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_1","displayName":"Enabled","description":null,"helpText":null}]},"28229c6bbc1bf2e1":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop","displayName":"Enable fill handle and cell drag-and-drop (User)","description":"This policy setting sets the \"Enable fill handle and cell drag-and-drop\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will enable the fill handle and allow drag-and-drop. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will disable the fill handle and drag-and-drop will not be allowed.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_enablefillhandleandcelldraganddrop_1","displayName":"Enabled","description":null,"helpText":null}]},"28fa742401959b24":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders40_1","displayName":"True","description":null,"helpText":null}]},"2816212a9aa22cd5":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},"28c95c02be2884d4":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowaccesstodatasources"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"28bb365cb682696b":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"283189ecfbcd2a6d":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001","displayName":"Download signed ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_1","displayName":"Prompt","description":null,"helpText":null}]},"284849254c05b0e5":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},"28531b434f880758":{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm for connection attempts (User)","description":"Controls whether Microsoft Edge uses the Happy Eyeballs V3 algorithm to optimize connection attempts. This algorithm improves reliability and performance in dual-stack (IPv4/IPv6) networks by racing connection attempts across IP versions and HTTP protocols (e.g., HTTP/3 vs. others). For more details, see https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3.\r\n\r\nEnabled or not configured: Uses the algorithm for connection attempts.\r\n\r\nDisabled: Disables the algorithm.\r\n\r\nNote: This policy supports dynamic refresh.\r\n\r\nImportant: This policy is temporary and will be removed in a future version.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge~network_happyeyeballsv3enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"282ae368b21e86f9":{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_6","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},"28abc052ca483c98":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"2804ed09321984d7":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior","displayName":"Configure ShadowStack crash rollback behavior (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy is deprecated because it's intended to serve only as a short-term mechanism to give enterprises more time to update their environments and report issues if they are found to be incompatible with Hardware-enforced Stack Protection. It won't work in Microsoft Edge as soon as version 109.\r\n\r\nMicrosoft Edge includes a Hardware-enforced Stack Protection security feature. This feature may result in the browser crashing unexpectedly in cases that do not represent an attempt to compromise the browser's security.\r\n\r\nUsing this policy, you may control the behavior of the Hardware-enforced Stack Protection feature after a crash triggered by this feature is encountered.\r\n\r\nSet this policy to 'Disable' to disable the feature.\r\n\r\nSet this policy to 'DisableUntilUpdate' to disable the feature until Microsoft Edge updates next time.\r\n\r\nSet this policy to 'Enable' to keep the feature enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable Hardware-enforced Stack Protection\r\n\r\n* DisableUntilUpdate (1) = Disable Hardware-enforced Stack Protection until the next Microsoft Edge update\r\n\r\n* Enable (2) = Enable Hardware-enforced Stack Protection\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_shadowstackcrashrollbackbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"28d5f087446d1a36":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit","displayName":"Set maximum database instances limit (User)","description":"This policy setting allows you to specify the maximum limit of how many instances per page the database shim can return. This policy setting enforces the allowed maximum for applications including those that do not respect the default.\r\n \r\nIf you enable this policy setting, you may specify the maximum limit of how many instances the database shim can return.\r\n\r\nIf you disable or do not configure this policy setting, there will be no limit of how many instances the database shim can return.","helpText":"","infoUrls":[],"categoryId":"952f69c8-2644-48df-976b-01fd624cbb3a","categoryName":"Database","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_database_l_databasemaxinstanceslimit_1","displayName":"Enabled","description":null,"helpText":null}]},"281d8b8c5020808b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_graphgallerypath_l_graphgallerypath354","displayName":"Graph gallery path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":null},"285a5d0391bf069d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada","displayName":"English (Canada) (User)","description":"Enables the editing language English (Canada)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishcanada_1","displayName":"Enabled","description":null,"helpText":null}]},"2840fd271bd21312":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia","displayName":"Nepali (India) (User)","description":"Enables the editing language Nepali (India)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_nepaliindia_1","displayName":"Enabled","description":null,"helpText":null}]},"28b75f488cedb12b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish","displayName":"Polish (User)","description":"Enables the editing language Polish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_polish_1","displayName":"Enabled","description":null,"helpText":null}]},"28551a82cdac4d79":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria","displayName":"Tamazight (Latin, Algeria) (User)","description":"Enables the editing language \"Tamazight (Latin, Algeria)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightlatinalgeria_1","displayName":"Enabled","description":null,"helpText":null}]},"2890fdb655fd957e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache11_l_workflowdescrip480","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"28cedf2b1504236b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings~l_trustedaddins_l_settrustedaddins_l_listoftrustedaddins_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","categoryName":"Trusted Add-ins","options":null},"286447a281051761":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"289c540c21c640db":{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge","displayName":"Allow Local Ipsec Policy Merge","description":"This value is an on/off switch. If this value is false, connection security rules from the local store are ignored and not enforced, regardless of the schema version and connection security rule version. The merge law for this option is to always use the value of the GroupPolicyRSoPStore.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge_false","displayName":"False","description":"AllowLocalIpsecPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_allowlocalipsecpolicymerge_true","displayName":"True","description":"AllowLocalIpsecPolicyMerge On","helpText":null}]},"28d17d5b724b88e4":{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/2c.json b/public/intune-definitions/2c.json index 6a4f5f064ddf..168a49ee7ddd 100644 --- a/public/intune-definitions/2c.json +++ b/public/intune-definitions/2c.json @@ -1 +1 @@ -{"2c4200e09889dc18":{"id":"app_allowed_deniedbinaries_item_teamid","displayName":"Team ID","description":"The code signature team identifier of the binary. Use the value \"*APPLE*\" instead of an empty string for Apple binaries with an empty team identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},"2c9e24b1da864820":{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled","displayName":"Allow access to developer settings","description":"If 'True', allow users access developer settings on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from accessing developer settings on the device. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled_false","displayName":"False","description":"false","helpText":null}]},"2c4e4774b55d0d63":{"id":"com.apple.app.lock_app_options_disablevolumebuttons","displayName":"Disable Volume Buttons","description":"If true, disables the volume buttons.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disablevolumebuttons_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disablevolumebuttons_true","displayName":"True","description":null,"helpText":null}]},"2c1131865dc79a22":{"id":"com.apple.applicationaccess_enforcedfingerprinttimeout","displayName":"Enforced Fingerprint Timeout","description":"The value, in seconds, after which the fingerprint unlock will require a password to authenticate. The default value is 48 hours.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},"2cd5065e7d1a4082":{"id":"com.apple.directoryservice.managed_admapuidattributeflag","displayName":"AD Map UID Attribute Flag","description":"If true, enables the AD Map UID Attribute key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapuidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapuidattributeflag_true","displayName":"True","description":null,"helpText":null}]},"2c9171a339834d3b":{"id":"com.apple.managedclient.preferences_disableteamsmeeting","displayName":"Disable Microsoft Teams meeting support","description":"Prevent users from adding Teams to meeting invites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-teams-online-meetings"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableteamsmeeting_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableteamsmeeting_true","displayName":"True","description":null,"helpText":null}]},"2c5a46271bfd7198":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo_url","displayName":"URL","description":"The URL from which the image can be downloaded.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"2c0e1f465263572b":{"id":"com.apple.managedclient.preferences_printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printer types on the deny list won't be discovered or have their capabilities fetched.\n\nPlacing all printer types on the deny list effectively disables printing, because there's no print destination for documents.\n\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\n\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\n\nPolicy options mapping:\n\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\n\n* extension (extension) = Extension-based destinations\n\n* pdf (pdf) = The 'Save as PDF' destination\n\n* local (local) = Local printer destinations\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printertypedenylist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"2c4b638c54684513":{"id":"com.apple.managedclient.preferences_uploadbandwidthlimited","displayName":"Set maximum upload throughput","description":"Sets the maximum upload throughput rate in kilobytes (KB)/sec for computers running the OneDrive sync app. The minimum rate is 50 KB/sec and the maximum rate is 100,000 KB/sec.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#uploadbandwidthlimited"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},"2cd87f159db641bb":{"id":"com.apple.proxy.http.global_proxytype","displayName":"Proxy Type","description":"The proxy type. For a manual proxy type, the profile contains the proxy server address, including its port, and optionally a user name and password. For an auto proxy type, you can enter a PAC URL.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxytype_0","displayName":"Manual","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxytype_1","displayName":"Auto","description":null,"helpText":null}]},"2c330668e697a7f4":{"id":"com.apple.security.firewall_allowsigned","displayName":"Allow Signed","description":"If true, allows built-in software to receive incoming connections. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_allowsigned_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_allowsigned_true","displayName":"True","description":null,"helpText":null}]},"2cf092a2b62a93df":{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"2ca5c095141824d8":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended","displayName":"Set the default \"share additional operating system region\" setting (users can override)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting is shared with the web through the default JavaScript locale. If shared, websites can query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format is shared only if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format is always shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months are displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format is never shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Always\"; however, the OS Regional format isn't shared if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282.\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_limited","displayName":"Limited","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_always","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_never","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},"2c3b01f06a6113a1":{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch","displayName":"Enforce Google SafeSearch","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\n\nIf you enable this policy, SafeSearch in Google Search is always active.\n\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch_true","displayName":"Enabled","description":null,"helpText":null}]},"2c404929ef219dee":{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended","displayName":"Allow suggestions from local providers (users can override)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear.\n\nIf you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nSome features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"2caf9770c1882179":{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype","displayName":"Enforce drive encryption type on removable data drives","description":"This policy setting allows you to configure the encryption type used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption type has no effect if the drive is already encrypted or if encryption is in progress. Choose full encryption to require that the entire drive be encrypted when BitLocker is turned on. Choose used space only encryption to require that only the portion of the drive used to store data is encrypted when BitLocker is turned on.\r\n\r\nIf you enable this policy setting the encryption type that BitLocker will use to encrypt drives is defined by this policy and the encryption type option will not be presented in the BitLocker setup wizard.\r\n\r\nIf you disable or do not configure this policy setting, the BitLocker setup wizard will ask the user to select the encryption type before turning on BitLocker.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_1","displayName":"Enabled","description":null,"helpText":null}]},"2c6deb475d02d1d9":{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy","displayName":"Disk Diagnostic: Configure custom alert text","description":"This policy setting substitutes custom alert text in the disk diagnostic message shown to users when a disk reports a S.M.A.R.T. fault. \r\n\r\nIf you enable this policy setting, Windows displays custom alert text in the disk diagnostic message. The custom text may not exceed 512 characters. \r\n\r\nIf you disable or do not configure this policy setting, Windows displays the default alert text in the disk diagnostic message. \r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately. \r\n\r\nThis policy setting only takes effect if the Disk Diagnostic scenario policy setting is enabled or not configured and the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console. \r\n\r\nNote: For Windows Server systems, this policy setting applies only if the Desktop Experience optional component is installed and the Remote Desktop Services role is not installed. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskdiagnostic#admx-diskdiagnostic-dfdalertpolicy"],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":[{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"2c9185047e58e74d":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc","displayName":"List of applications to always report errors for","description":"This policy setting specifies applications for which Windows Error Reporting should always report errors.\r\n\r\nTo create a list of applications for which Windows Error Reporting never reports errors, click Show under the Exclude errors for applications on this list setting, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). Errors that are generated by applications in this list are not reported, even if the Default Application Reporting Settings policy setting is configured to report all application errors.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are always included in error reporting. To add applications to the list, click Show under the Report errors for applications on this list setting, and edit the list of application file names in the Show Contents dialog box. The file names must include the .exe file name extension (for example, notepad.exe). Errors that are generated by applications on this list are always reported, even if the Default dropdown in the Default application reporting policy setting is set to report no application errors.\r\n\r\nIf the Report all errors in Microsoft applications or Report all errors in Windows components check boxes in the Default Application Reporting policy setting are filled, Windows Error Reporting reports errors as if all applications in these categories were added to the list in this policy setting. (Note: The Microsoft applications category includes the Windows components category.)\r\n\r\nIf you disable this policy setting or do not configure it, the Default application reporting settings policy setting takes precedence.\r\n\r\nAlso see the \"Default Application Reporting\" and \"Application Exclusion List\" policies.\r\n\r\nThis setting will be ignored if the 'Configure Error Reporting' setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornoneinc"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_1","displayName":"Enabled","description":null,"helpText":null}]},"2c7163b8bc229227":{"id":"device_vendor_msft_policy_config_admx_logon_run_2_runlistbox2","displayName":"Items to run at logon","description":null,"helpText":"","infoUrls":[],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":null},"2c723824fa871954":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime_scan_scheduletime","displayName":"Specify the time of day to run a scheduled scan","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},"2ccbef4b5bfb73d2":{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes_ncsi_corpsiteprefixesbox","displayName":"Corporate Site Prefix List:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},"2c81fee088544a32":{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2","displayName":"Prohibit access of the Windows Connect Now wizards","description":"This policy setting prohibits access to Windows Connect Now (WCN) wizards. \r\n\r\nIf you enable this policy setting, the wizards are turned off and users have no access to any of the wizard tasks. All the configuration related tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device\" are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can access the wizard tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device.\" The default for this policy setting allows users to access all WCN wizards.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsconnectnow#admx-windowsconnectnow-wcn-disablewcnui-2"],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2_1","displayName":"Enabled","description":null,"helpText":null}]},"2cb6d538beaa35cd":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation","displayName":"Detailed Tracking Audit Process Creation","description":"This policy setting allows you to audit events generated when a process is created or starts. The name of the application or user that created the process is also audited. If you configure this policy setting, an audit event is generated when a process is created. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a process is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditprocesscreation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"2cc57fec8700d260":{"id":"device_vendor_msft_policy_config_browser_allowprelaunch","displayName":"Allow Prelaunch","description":"Allow Microsoft Edge to pre-launch at Windows startup, when the system is idle, and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowprelaunch"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowprelaunch_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowprelaunch_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"2cd88a92ee319c9a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation","displayName":"Ask where to save each file before downloading","description":"Setting the policy to Enabled means users are asked where to save each file before downloading. Setting the policy to Disabled has downloads start immediately, and users aren't asked where to save the file.\r\n\r\nLeaving the policy unset lets users change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation_1","displayName":"Enabled","description":null,"helpText":null}]},"2c778d3ad56cca37":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"2c54283130bf8e1b":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"2c7246df57adac85":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block pop-up windows on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"2ca220803c33f835":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled","displayName":"Edge 3P SERP Telemetry Enabled","description":"Edge3P Telemetry in Microsoft Edge captures the searches user does on third party search providers without identifying the person or the device and captures only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings.\r\n\r\nIf you enable or don't configure this policy, Edge 3P SERP Telemetry feature will be enabled.\r\n\r\nIf you disable this policy, Edge 3P SERP Telemetry feature will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2c76feaf36e47ba1":{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended","displayName":"Allow importing of open tabs","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"2c4e5f7488df0d6a":{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseiprangesareauthoritative","displayName":"Enterprise IP Ranges Are Authoritative","description":"Boolean value that tells the client to accept the configured list and not to use heuristics to attempt to find other subnets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterpriseiprangesareauthoritative"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":[{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseiprangesareauthoritative_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseiprangesareauthoritative_0","displayName":"Disable","description":"Disable","helpText":null}]},"2c92bae0d8418cc9":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_onenoteexe40","displayName":"onent.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_onenoteexe40_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_onenoteexe40_1","displayName":"True","description":null,"helpText":null}]},"2c394f3b6162ba7e":{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208andeudc","displayName":"Exclude Japanese IME Except JIS0208and EUDC","description":"Note The policy is only enforced in Windows 10 for desktop. Allows the users to restrict character code range of conversion by setting the character filter.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#excludejapaneseimeexceptjis0208andeudc"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208andeudc_0","displayName":"No characters are filtered.","description":"No characters are filtered.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208andeudc_1","displayName":"All characters except JIS0208 and EUDC are filtered.","description":"All characters except JIS0208 and EUDC are filtered.","helpText":null}]},"2c5da268941d5c78":{"id":"device_vendor_msft_policy_config_update_activehoursstart","displayName":"Active Hours Start","description":"Allows the IT admin (when used with Update/ActiveHoursEnd) to manage a range of hours where update reboots are not scheduled. This value sets the start time. There is a 12 hour maximum from end time. Note The default maximum difference from end time has been increased to 18 in Windows 10, version 1703. In this version of Windows 10, the maximum range of active hours can now be configured. See Update/ActiveHoursMaxRange above for more information. Supported values are 0-23, where 0 is 12 AM, 1 is 1 AM, etc. The default value is 8 (8 AM).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#activehoursstart"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"2cd507e75f5d707e":{"id":"device_vendor_msft_policy_config_visualstudiov6~policy~visualstudio~installandupdatesettings_availabletabproducts","displayName":"Control what products are available to install on the Visual Studio Installer's Available tab.","description":"This policy can be used to restrict which Visual Studio product shows up on the Installer's Available Tab. For example, including Microsoft.VisualStudio.Product.Professional in the list will cause the Visual Studio Professional edition to be the only available option to install. This policy is only applied to client machines that have just the Visual Studio Installer installed. For more information, see  https://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov6~policy~visualstudio~installandupdatesettings_availabletabproducts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov6~policy~visualstudio~installandupdatesettings_availabletabproducts_1","displayName":"Enabled","description":null,"helpText":null}]},"2c306d02a49f8fd6":{"id":"device_vendor_msft_policy_config_webthreatdefense_automaticdatacollection","displayName":"Automatic Data Collection","description":"Automatically collect website or app content when additional analysis is needed to help identify security threats.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WebThreatDefense#automaticdatacollection"],"categoryId":"20b71dc7-cf08-4534-9e52-d297dd071ca5","categoryName":"Enhanced Phishing Protection","options":[{"id":"device_vendor_msft_policy_config_webthreatdefense_automaticdatacollection_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_webthreatdefense_automaticdatacollection_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"2cb78ec67d7cc1a6":{"id":"intelligencesettings_forceondeviceonlydictation","displayName":"Force On Device Only Dictation","description":"If `true`, forces On-Device Only Dictation.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_forceondeviceonlydictation_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_forceondeviceonlydictation_true","displayName":"True","description":null,"helpText":null}]},"2c64e0e5576a2a2d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys86_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dba1a547-e288-45ac-8553-27a3b564699e","categoryName":"Custom","options":null},"2c41c14f55d7593a":{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect","displayName":"Restrict users to the following language: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000409","displayName":"English","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000411","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000412","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000407","displayName":"German","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000804","displayName":"Simplified Chinese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000404","displayName":"Traditional Chinese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000040c","displayName":"French","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000c0a","displayName":"Spanish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000410","displayName":"Italian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041d","displayName":"Swedish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000413","displayName":"Dutch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000416","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000040b","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000414","displayName":"Norwegian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000406","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000040e","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000415","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000419","displayName":"Russian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000405","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000408","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000816","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041f","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000401","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000040d","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041b","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000424","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000418","displayName":"Romanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041a","displayName":"Croatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000402","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000425","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000427","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000426","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041e","displayName":"Thai","description":null,"helpText":null}]},"2c19a08e56af870b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_sharedfolders","displayName":"Shared Folders (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-sharedfolders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_sharedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_sharedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"2c856a67cffbfac7":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_allowadvancedtcpipconfig","displayName":"Prohibit TCP/IP advanced configuration (User)","description":"Determines whether users can configure advanced TCP/IP settings.\r\n\r\nIf you enable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), the Advanced button on the Internet Protocol (TCP/IP) Properties dialog box is disabled for all users (including administrators). As a result, users cannot open the Advanced TCP/IP Settings Properties page and modify IP settings, such as DNS and WINS server information.\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you disable this setting, the Advanced button is enabled, and all users can open the Advanced TCP/IP Setting dialog box.\r\n\r\nNote: This setting is superseded by settings that prohibit access to properties of connections or connection components. When these policies are set to deny access to the connection properties dialog box or Properties button for connection components, users cannot gain access to the Advanced button for TCP/IP configuration.\r\n\r\nNote: Nonadministrators (excluding Network Configuration Operators) do not have permission to access TCP/IP advanced configuration for a LAN connection, regardless of this setting.\r\n\r\nTip: To open the Advanced TCP/IP Setting dialog box, in the Network Connections folder, right-click a connection icon, and click Properties. For remote access connections, click the Networking tab. In the \"Components checked are used by this connection\" box, click Internet Protocol (TCP/IP), click the Properties button, and then click the Advanced button.\r\n\r\nNote: Changing this setting from Enabled to Not Configured does not enable the Advanced button until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-allowadvancedtcpipconfig"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_allowadvancedtcpipconfig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_allowadvancedtcpipconfig_1","displayName":"Enabled","description":null,"helpText":null}]},"2c4368b8a5978ef3":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_1_lbl_assignedofflinefileslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"2c5e72babedc5097":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nosearchinternettryharderbutton","displayName":"Remove the Search the Internet \"Search again\" link (User)","description":"If you enable this policy, the \"Internet\" \"Search again\" link will not be shown when the user performs a search in the Explorer window.\r\n\r\nIf you disable this policy, there will be an \"Internet\" \"Search again\" link when the user performs a search in the Explorer window. This button launches a search in the default browser with the search terms.\r\n\r\nIf you do not configure this policy (default), there will be an \"Internet\" link when the user performs a search in the Explorer window.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nosearchinternettryharderbutton"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nosearchinternettryharderbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nosearchinternettryharderbutton_1","displayName":"Enabled","description":null,"helpText":null}]},"2cf7131e2f0b9803":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_multicastcheckbox","displayName":"Multicast (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_multicastcheckbox_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_multicastcheckbox_1","displayName":"True","description":null,"helpText":null}]},"2cee0a8541af4d86":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},"2c26756d58f0790f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification","displayName":"Notify a user that a browser relaunch or device restart is recommended or required (User)","description":"Notify users that Google Chrome must be relaunched or Google Chrome OS must be restarted to apply a pending update.\r\n\r\nThis policy setting enables notifications to inform the user that a browser relaunch or device restart is recommended or required. If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google Chrome OS indicates such via a notification in the system tray. If set to 'Recommended', a recurring warning will be shown to the user that a relaunch is recommended. The user can dismiss this warning to defer the relaunch. If set to 'Required', a recurring warning will be shown to the user indicating that a browser relaunch will be forced once the notification period passes. The default period is seven days for Google Chrome and four days for Google Chrome OS, and may be configured via the RelaunchNotificationPeriod policy setting.\r\n\r\nThe user's session is restored following the relaunch/restart.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"2c25a4796fe2c82c":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints. (User)","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Local Network Access checks.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessBlockedForUrls, LocalNetworkAccessBlockedForUrls takes precedence.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"2cd63d0e998bbd96":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook","displayName":"Review tab | Changes | Protect Workbook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook_1","displayName":"True","description":null,"helpText":null}]},"2cc315eeea84aea9":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},"2ce380af509563d1":{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu","displayName":"Let users turn on and use Enterprise Mode from the Tools menu (User)","description":"This policy setting lets you decide whether users can turn on Enterprise Mode for websites with compatibility issues. Optionally, this policy also lets you specify where to get reports (through post messages) about the websites for which users turn on Enterprise Mode using the Tools menu.\n\nIf you turn this setting on, users can see and use the Enterprise Mode option from the Tools menu. If you turn this setting on, but don't specify a report location, Enterprise Mode will still be available to your users, but you won't get any reports.\n\nIf you disable or don't configure this policy setting, the menu option won't appear and users won't be able to run websites in Enterprise Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenterprisemodefromtoolsmenu"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"2cd813886c1c75b6":{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate","displayName":"Locked-Down Intranet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownintranetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"2c1e829ef4ce8688":{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel","displayName":"Configure which channel of Microsoft Edge to use for opening redirected sites (User)","description":"Enables you to configure up to three versions of Microsoft Edge to open a redirected site (in order of preference). Use this policy if your environment is configured to redirect sites from Internet Explorer 11 to Microsoft Edge. If any of the chosen versions are not installed on the device, that preference will be bypassed.\n\nIf both the Windows Update for the next version of Microsoft Edge* and Microsoft Edge Stable channel are installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge Stable channel is used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\nIf the Windows Update for the next version of Microsoft Edge* or Microsoft Edge Stable channel are not installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge version 45 or earlier is automatically used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 0 = Microsoft Edge version 45 or earlier\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\n*For more information about the Windows update for the next version of Microsoft Edge including how to disable it, see https://go.microsoft.com/fwlink/?linkid=2102115. This update applies only to Windows 10 version 1709 and higher.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-configureedgeredirectchannel"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_1","displayName":"Enabled","description":null,"helpText":null}]},"2c84cdf876a3ed72":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"2c3b698aff40d5af":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"2cd9f8d92818308a":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowsmartscreenie"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"2c4cf5af4285830a":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"2c2a16f9b751b791":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation","displayName":"Configure the home page URL (User)","description":"Configures the default home page URL in Microsoft Edge.\r\n\r\nThe home page is the page opened by the Home button. The pages that open on startup are controlled by the 'RestoreOnStartup' (Action to take on startup) policies.\r\n\r\nYou can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.\r\n\r\nIf you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.\r\n\r\nIf you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' (Set the new tab page as the home page) policy isn't enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\nExample value: https://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"2cbc1c19cae95e81":{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended","displayName":"Efficiency mode enabled (User)","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\r\n\r\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when efficiency mode should become active) policy. If the device does not have a battery, efficiency mode will always be active.\r\n\r\nIf you disable this policy, efficiency mode will never become active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect.\r\n\r\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"2c64dee617a75334":{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nLocal Network Access restrictions prevent public websites from making\r\nrequests to devices on a user's local network without explicit user permission.\r\n\r\nIf you enable this policy, Microsoft Edge will\r\nblock any request that would otherwise trigger a DevTools warning\r\ndue to Local Network Access checks.\r\nThese requests will be denied without prompting the user.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will handle\r\nthese requests using the default behavior, which may include showing warnings in DevTools\r\nand allowing the request to proceed depending on the context.\r\n\r\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\r\nunless explicitly granted by the user.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2ca30452cc812e1a":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps (User)","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2cb4b69562c9298d":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nLeaving the policy unset means 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemReadBlockedForUrls' (Block read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"2c811d8b10126172":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode","displayName":"Print Rasterization Mode (User)","description":"Controls how Microsoft Edge prints on Windows.\r\n\r\nWhen printing to a non-PostScript printer on Windows, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nIf you set this policy to 'Full' or don't configure it, Microsoft Edge will do full page rasterization if necessary.\r\n\r\nIf you set this policy to 'Fast', Microsoft Edge will reduce the amount of rasterization which can help reduce print job sizes and increase printing speed.\r\n\r\nPolicy options mapping:\r\n\r\n* Full (0) = Full page rasterization\r\n\r\n* Fast (1) = Avoid rasterization if possible\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},"2c7e509de125cc00":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).\r\n\r\nIf a site matches a URL pattern in this policy, the 'ScreenCaptureAllowed' (Allow or deny screen capture) will not be considered.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"2c17d6b6e3d669e4":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_l_writingassistantadminblockedappslistid","displayName":"Blocked application names (e.g., notepad.exe) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":null},"2c9039abcb640905":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334","displayName":"Display menus and dialog boxes in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_0","displayName":"(same as the system)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1078","displayName":"Afrikaans","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1052","displayName":"Albanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1118","displayName":"Amharic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1025","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1067","displayName":"Armenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1101","displayName":"Assamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1068","displayName":"Azerbaijani (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2117","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1093","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1069","displayName":"Basque","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1059","displayName":"Belarusian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_5146","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1026","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1027","displayName":"Catalan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1170","displayName":"Central Kurdish (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1116","displayName":"Cherokee","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2052","displayName":"Chinese (Simplified)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1028","displayName":"Chinese (Traditional)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1050","displayName":"Croatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1029","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1030","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1164","displayName":"Dari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1043","displayName":"Dutch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1033","displayName":"English","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1061","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1124","displayName":"Filipino","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1035","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1036","displayName":"French","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1110","displayName":"Galician","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1079","displayName":"Georgian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1031","displayName":"German","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1032","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1095","displayName":"Gujarati","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1128","displayName":"Hausa (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1037","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1081","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1038","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1039","displayName":"Icelandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1136","displayName":"Igbo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1057","displayName":"Indonesian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2141","displayName":"Inuktitut (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2108","displayName":"Irish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1076","displayName":"isiXhosa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1077","displayName":"isiZulu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1040","displayName":"Italian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1041","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1099","displayName":"Kannada","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1087","displayName":"Kazakh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1107","displayName":"Khmer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1158","displayName":"K'iche","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1159","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1088","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1089","displayName":"Swahili","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1111","displayName":"Konkani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1042","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1062","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1063","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1134","displayName":"Luxembourgish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1086","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1100","displayName":"Malayalam","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1082","displayName":"Maltese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1153","displayName":"Maori","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1102","displayName":"Marathi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1071","displayName":"Macedonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1104","displayName":"Mongolian (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1121","displayName":"Nepali","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1044","displayName":"Norwegian (Bokmal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2068","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1096","displayName":"Odia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1065","displayName":"Persian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1045","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1046","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2070","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1094","displayName":"Punjabi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2118","displayName":"Punjabi (Pakistan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3179","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1048","displayName":"Romanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1049","displayName":"Russian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1169","displayName":"Scottish Gaelic (United Kingdom)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3098","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_7194","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2074","displayName":"Serbian (Latin, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1132","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1074","displayName":"Setswana","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2137","displayName":"Sindhi (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1115","displayName":"Sinhala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1051","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1060","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3082","displayName":"Spanish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1053","displayName":"Swedish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1064","displayName":"Tajik","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1097","displayName":"Tamil","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1092","displayName":"Tatar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1098","displayName":"Telugu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1054","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1139","displayName":"Tigrinya (Ethiopia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1055","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1090","displayName":"Turkmen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1058","displayName":"Ukrainian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1056","displayName":"Urdu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1152","displayName":"Uyghur (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1091","displayName":"Uzbek (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2051","displayName":"Valencian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1066","displayName":"Vietnamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1106","displayName":"Welsh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1160","displayName":"Wolof","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1130","displayName":"Yoruba","description":null,"helpText":null}]},"2ccaf0230b706335":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore","displayName":"Block the Office Store (User)","description":"This policy setting allows you to prevent users from using or inserting web add-ins that come from the Office Store.\r\n\r\nIf you enable this policy setting, apps from the Office Store are blocked.\r\n\r\nIf you disable or do not configure this policy setting, apps from the Office Store are allowed, unless the \"Block Apps for Office\" policy setting is enabled.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore_1","displayName":"Enabled","description":null,"helpText":null}]},"2c3329b94431c2f4":{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt","displayName":"Show the File Format dialog (User)","description":"This policy setting allows you to control whether the file format dialog has already been shown to the user. If you enable this policy setting, the dialog won't be shown again. If you disable this policy setting, the dialog prompts the user to select a default file format on each boot until one is selected. If you don't configure this policy setting, the dialog prompts the user to select a default file format on each boot until one is selected.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt_1","displayName":"Enabled","description":null,"helpText":null}]},"2cae12382fdbc3c7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing","displayName":"Control Calendar Sharing (User)","description":"By default, users can share an entire calendar by saving it in the iCalendar format, or share a snapshot of a calendar by using e-mail. This setting allows you to specify the detail level in the shared versions of calendars, or to disable sharing of calendars.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_1","displayName":"Enabled","description":null,"helpText":null}]},"2c41cb8d711f4389":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"2ca6b2b142ea015c":{"id":"user_vendor_msft_policy_config_start_disablecontextmenus","displayName":"Disable Context Menus (User)","description":"Enabling this policy prevents context menus from being invoked in the Start Menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#disablecontextmenus"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_disablecontextmenus_0","displayName":"Disabled","description":"Do not disable.","helpText":null},{"id":"user_vendor_msft_policy_config_start_disablecontextmenus_1","displayName":"Enabled","description":"Disable.","helpText":null}]},"2c11de5e6e79e9a6":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},"2ca83a94afbb7165":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext","displayName":"Hidden text (User)","description":"This policy setting controls whether text that is formatted as hidden displays on Word users' monitor screens.\r\n\r\nIf you enable this policy setting, Word displays hidden text at all times. Hidden text on monitor screens displays as underlined with a dotted line.\r\n\r\nIf you disable or do not configure this policy setting, Word does not display text formatted as hidden unless \"Show/Hide ¶\" is selected or Word is configured to show hidden text in the \"Display\" section of the \"Word Options\" dialog.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext_1","displayName":"Enabled","description":null,"helpText":null}]},"2c9b95bd56606c92":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},"2c0aa219a3925da3":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"2cd69d134e32ed84":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},"2c6e41278caf8d97":{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_maxrescanintervalinseconds","displayName":"Max Rescan Interval In Seconds (Windows Insiders only)","description":"Maximum time (in seconds) from the point that no connection could be established using the permissible eSIM profiles on the device to the start of the next round of network discovery attempts. A smaller interval increases network discovery frequency and can decrease battery life significantly. A value of 0 means that the device is to pick a reasonable interval per its own discretion.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null}} \ No newline at end of file +{"2c4200e09889dc18":{"id":"app_allowed_deniedbinaries_item_teamid","displayName":"Team ID","description":"The code signature team identifier of the binary. Use the value \"*APPLE*\" instead of an empty string for Apple binaries with an empty team identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},"2c9e24b1da864820":{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled","displayName":"Allow access to developer settings","description":"If 'True', allow users access developer settings on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might prevent users from accessing developer settings on the device. Available for fully managed, dedicated and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.securitydevelopersettingsenabled_false","displayName":"False","description":"false","helpText":null}]},"2c4e4774b55d0d63":{"id":"com.apple.app.lock_app_options_disablevolumebuttons","displayName":"Disable Volume Buttons","description":"If true, disables the volume buttons.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_disablevolumebuttons_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_disablevolumebuttons_true","displayName":"True","description":null,"helpText":null}]},"2c1131865dc79a22":{"id":"com.apple.applicationaccess_enforcedfingerprinttimeout","displayName":"Enforced Fingerprint Timeout","description":"The value, in seconds, after which the fingerprint unlock will require a password to authenticate. The default value is 48 hours.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},"2cd5065e7d1a4082":{"id":"com.apple.directoryservice.managed_admapuidattributeflag","displayName":"AD Map UID Attribute Flag","description":"If true, enables the AD Map UID Attribute key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapuidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapuidattributeflag_true","displayName":"True","description":null,"helpText":null}]},"2c9171a339834d3b":{"id":"com.apple.managedclient.preferences_disableteamsmeeting","displayName":"Disable Microsoft Teams meeting support","description":"Prevent users from adding Teams to meeting invites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#disable-teams-online-meetings"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_disableteamsmeeting_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableteamsmeeting_true","displayName":"True","description":null,"helpText":null}]},"2c5a46271bfd7198":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo_url","displayName":"URL","description":"The URL from which the image can be downloaded.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"2c0e1f465263572b":{"id":"com.apple.managedclient.preferences_printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printer types on the deny list won't be discovered or have their capabilities fetched.\n\nPlacing all printer types on the deny list effectively disables printing, because there's no print destination for documents.\n\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\n\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\n\nPolicy options mapping:\n\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\n\n* extension (extension) = Extension-based destinations\n\n* pdf (pdf) = The 'Save as PDF' destination\n\n* local (local) = Local printer destinations\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printertypedenylist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"2c4b638c54684513":{"id":"com.apple.managedclient.preferences_uploadbandwidthlimited","displayName":"Set maximum upload throughput","description":"Sets the maximum upload throughput rate in kilobytes (KB)/sec for computers running the OneDrive sync app. The minimum rate is 50 KB/sec and the maximum rate is 100,000 KB/sec.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#uploadbandwidthlimited"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},"2cd87f159db641bb":{"id":"com.apple.proxy.http.global_proxytype","displayName":"Proxy Type","description":"The proxy type. For a manual proxy type, the profile contains the proxy server address, including its port, and optionally a user name and password. For an auto proxy type, you can enter a PAC URL.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxytype_0","displayName":"Manual","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxytype_1","displayName":"Auto","description":null,"helpText":null}]},"2c330668e697a7f4":{"id":"com.apple.security.firewall_allowsigned","displayName":"Allow Signed","description":"If true, allows built-in software to receive incoming connections. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_allowsigned_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_allowsigned_true","displayName":"True","description":null,"helpText":null}]},"2cf092a2b62a93df":{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"2ca5c095141824d8":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended","displayName":"Set the default \"share additional operating system region\" setting (users can override)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting is shared with the web through the default JavaScript locale. If shared, websites can query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format is shared only if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format is always shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months are displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format is never shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\", and the browser display language is set to \"en-US\". Then the OS Regional format is shared if the policy is set to \"Always\"; however, the OS Regional format isn't shared if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282.\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_limited","displayName":"Limited","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_always","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultshareadditionalosregionsetting_recommended_never","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},"2c3b01f06a6113a1":{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch","displayName":"Enforce Google SafeSearch","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\n\nIf you enable this policy, SafeSearch in Google Search is always active.\n\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.forcegooglesafesearch_true","displayName":"Enabled","description":null,"helpText":null}]},"2c404929ef219dee":{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended","displayName":"Allow suggestions from local providers (users can override)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear.\n\nIf you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nSome features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"2c854cefb1904640":{"id":"contentcaching_contentcaching","displayName":"com.apple.configuration.content-cache.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"2caf9770c1882179":{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype","displayName":"Enforce drive encryption type on removable data drives","description":"This policy setting allows you to configure the encryption type used by BitLocker Drive Encryption. This policy setting is applied when you turn on BitLocker. Changing the encryption type has no effect if the drive is already encrypted or if encryption is in progress. Choose full encryption to require that the entire drive be encrypted when BitLocker is turned on. Choose used space only encryption to require that only the portion of the drive used to store data is encrypted when BitLocker is turned on.\r\n\r\nIf you enable this policy setting the encryption type that BitLocker will use to encrypt drives is defined by this policy and the encryption type option will not be presented in the BitLocker setup wizard.\r\n\r\nIf you disable or do not configure this policy setting, the BitLocker setup wizard will ask the user to select the encryption type before turning on BitLocker.\r\n\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","categoryName":"Removable Data Drives","options":[{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_removabledrivesencryptiontype_1","displayName":"Enabled","description":null,"helpText":null}]},"2c6deb475d02d1d9":{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy","displayName":"Disk Diagnostic: Configure custom alert text","description":"This policy setting substitutes custom alert text in the disk diagnostic message shown to users when a disk reports a S.M.A.R.T. fault. \r\n\r\nIf you enable this policy setting, Windows displays custom alert text in the disk diagnostic message. The custom text may not exceed 512 characters. \r\n\r\nIf you disable or do not configure this policy setting, Windows displays the default alert text in the disk diagnostic message. \r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately. \r\n\r\nThis policy setting only takes effect if the Disk Diagnostic scenario policy setting is enabled or not configured and the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console. \r\n\r\nNote: For Windows Server systems, this policy setting applies only if the Desktop Experience optional component is installed and the Remote Desktop Services role is not installed. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-diskdiagnostic#admx-diskdiagnostic-dfdalertpolicy"],"categoryId":"e3ca94a7-e506-4133-8fae-41931dc863a5","categoryName":"Disk Diagnostic","options":[{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_diskdiagnostic_dfdalertpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"2c9185047e58e74d":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc","displayName":"List of applications to always report errors for","description":"This policy setting specifies applications for which Windows Error Reporting should always report errors.\r\n\r\nTo create a list of applications for which Windows Error Reporting never reports errors, click Show under the Exclude errors for applications on this list setting, and then add or remove applications from the list of application file names in the Show Contents dialog box (example: notepad.exe). Errors that are generated by applications in this list are not reported, even if the Default Application Reporting Settings policy setting is configured to report all application errors.\r\n\r\nIf you enable this policy setting, you can create a list of applications that are always included in error reporting. To add applications to the list, click Show under the Report errors for applications on this list setting, and edit the list of application file names in the Show Contents dialog box. The file names must include the .exe file name extension (for example, notepad.exe). Errors that are generated by applications on this list are always reported, even if the Default dropdown in the Default application reporting policy setting is set to report no application errors.\r\n\r\nIf the Report all errors in Microsoft applications or Report all errors in Windows components check boxes in the Default Application Reporting policy setting are filled, Windows Error Reporting reports errors as if all applications in these categories were added to the list in this policy setting. (Note: The Microsoft applications category includes the Windows components category.)\r\n\r\nIf you disable this policy setting or do not configure it, the Default application reporting settings policy setting takes precedence.\r\n\r\nAlso see the \"Default Application Reporting\" and \"Application Exclusion List\" policies.\r\n\r\nThis setting will be ignored if the 'Configure Error Reporting' setting is disabled or not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-pch-allornoneinc"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornoneinc_1","displayName":"Enabled","description":null,"helpText":null}]},"2c7163b8bc229227":{"id":"device_vendor_msft_policy_config_admx_logon_run_2_runlistbox2","displayName":"Items to run at logon","description":null,"helpText":"","infoUrls":[],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":null},"2c723824fa871954":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_scheduletime_scan_scheduletime","displayName":"Specify the time of day to run a scheduled scan","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},"2ccbef4b5bfb73d2":{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpsiteprefixes_ncsi_corpsiteprefixesbox","displayName":"Corporate Site Prefix List:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},"2c81fee088544a32":{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2","displayName":"Prohibit access of the Windows Connect Now wizards","description":"This policy setting prohibits access to Windows Connect Now (WCN) wizards. \r\n\r\nIf you enable this policy setting, the wizards are turned off and users have no access to any of the wizard tasks. All the configuration related tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device\" are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can access the wizard tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device.\" The default for this policy setting allows users to access all WCN wizards.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsconnectnow#admx-windowsconnectnow-wcn-disablewcnui-2"],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_2_1","displayName":"Enabled","description":null,"helpText":null}]},"2cb6d538beaa35cd":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation","displayName":"Detailed Tracking Audit Process Creation","description":"This policy setting allows you to audit events generated when a process is created or starts. The name of the application or user that created the process is also audited. If you configure this policy setting, an audit event is generated when a process is created. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a process is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditprocesscreation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditprocesscreation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"2cc57fec8700d260":{"id":"device_vendor_msft_policy_config_browser_allowprelaunch","displayName":"Allow Prelaunch","description":"Allow Microsoft Edge to pre-launch at Windows startup, when the system is idle, and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowprelaunch"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowprelaunch_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowprelaunch_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"2cd88a92ee319c9a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation","displayName":"Ask where to save each file before downloading","description":"Setting the policy to Enabled means users are asked where to save each file before downloading. Setting the policy to Disabled has downloads start immediately, and users aren't asked where to save the file.\r\n\r\nLeaving the policy unset lets users change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promptfordownloadlocation_1","displayName":"Enabled","description":null,"helpText":null}]},"2c778d3ad56cca37":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"2c54283130bf8e1b":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"2c7246df57adac85":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block pop-up windows on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"2ca220803c33f835":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled","displayName":"Edge 3P SERP Telemetry Enabled","description":"Edge3P Telemetry in Microsoft Edge captures the searches user does on third party search providers without identifying the person or the device and captures only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings.\r\n\r\nIf you enable or don't configure this policy, Edge 3P SERP Telemetry feature will be enabled.\r\n\r\nIf you disable this policy, Edge 3P SERP Telemetry feature will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_edge3pserptelemetryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2c76feaf36e47ba1":{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended","displayName":"Allow importing of open tabs","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_recommended_importopentabs_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"2c4e5f7488df0d6a":{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseiprangesareauthoritative","displayName":"Enterprise IP Ranges Are Authoritative","description":"Boolean value that tells the client to accept the configured list and not to use heuristics to attempt to find other subnets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterpriseiprangesareauthoritative"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":[{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseiprangesareauthoritative_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseiprangesareauthoritative_0","displayName":"Disable","description":"Disable","helpText":null}]},"2c92bae0d8418cc9":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_onenoteexe40","displayName":"onent.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_onenoteexe40_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_onenoteexe40_1","displayName":"True","description":null,"helpText":null}]},"2c394f3b6162ba7e":{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208andeudc","displayName":"Exclude Japanese IME Except JIS0208and EUDC","description":"Note The policy is only enforced in Windows 10 for desktop. Allows the users to restrict character code range of conversion by setting the character filter.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#excludejapaneseimeexceptjis0208andeudc"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208andeudc_0","displayName":"No characters are filtered.","description":"No characters are filtered.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208andeudc_1","displayName":"All characters except JIS0208 and EUDC are filtered.","description":"All characters except JIS0208 and EUDC are filtered.","helpText":null}]},"2c5da268941d5c78":{"id":"device_vendor_msft_policy_config_update_activehoursstart","displayName":"Active Hours Start","description":"Allows the IT admin (when used with Update/ActiveHoursEnd) to manage a range of hours where update reboots are not scheduled. This value sets the start time. There is a 12 hour maximum from end time. Note The default maximum difference from end time has been increased to 18 in Windows 10, version 1703. In this version of Windows 10, the maximum range of active hours can now be configured. See Update/ActiveHoursMaxRange above for more information. Supported values are 0-23, where 0 is 12 AM, 1 is 1 AM, etc. The default value is 8 (8 AM).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#activehoursstart"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"2cd507e75f5d707e":{"id":"device_vendor_msft_policy_config_visualstudiov6~policy~visualstudio~installandupdatesettings_availabletabproducts","displayName":"Control what products are available to install on the Visual Studio Installer's Available tab.","description":"This policy can be used to restrict which Visual Studio product shows up on the Installer's Available Tab. For example, including Microsoft.VisualStudio.Product.Professional in the list will cause the Visual Studio Professional edition to be the only available option to install. This policy is only applied to client machines that have just the Visual Studio Installer installed. For more information, see  https://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov6~policy~visualstudio~installandupdatesettings_availabletabproducts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov6~policy~visualstudio~installandupdatesettings_availabletabproducts_1","displayName":"Enabled","description":null,"helpText":null}]},"2c306d02a49f8fd6":{"id":"device_vendor_msft_policy_config_webthreatdefense_automaticdatacollection","displayName":"Automatic Data Collection","description":"Automatically collect website or app content when additional analysis is needed to help identify security threats.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WebThreatDefense#automaticdatacollection"],"categoryId":"20b71dc7-cf08-4534-9e52-d297dd071ca5","categoryName":"Enhanced Phishing Protection","options":[{"id":"device_vendor_msft_policy_config_webthreatdefense_automaticdatacollection_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_webthreatdefense_automaticdatacollection_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"2cb78ec67d7cc1a6":{"id":"intelligencesettings_forceondeviceonlydictation","displayName":"Force On Device Only Dictation","description":"If `true`, forces On-Device Only Dictation.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_forceondeviceonlydictation_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_forceondeviceonlydictation_true","displayName":"True","description":null,"helpText":null}]},"2c64e0e5576a2a2d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys86_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dba1a547-e288-45ac-8553-27a3b564699e","categoryName":"Custom","options":null},"2c41c14f55d7593a":{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect","displayName":"Restrict users to the following language: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000409","displayName":"English","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000411","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000412","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000407","displayName":"German","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000804","displayName":"Simplified Chinese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000404","displayName":"Traditional Chinese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000040c","displayName":"French","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000c0a","displayName":"Spanish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000410","displayName":"Italian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041d","displayName":"Swedish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000413","displayName":"Dutch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000416","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000040b","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000414","displayName":"Norwegian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000406","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000040e","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000415","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000419","displayName":"Russian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000405","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000408","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000816","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041f","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000401","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000040d","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041b","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000424","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000418","displayName":"Romanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041a","displayName":"Croatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000402","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000425","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000427","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_00000426","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_restrictuilangselect_uilangselect_0000041e","displayName":"Thai","description":null,"helpText":null}]},"2c19a08e56af870b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_sharedfolders","displayName":"Shared Folders (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-sharedfolders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_sharedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_sharedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"2c856a67cffbfac7":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_allowadvancedtcpipconfig","displayName":"Prohibit TCP/IP advanced configuration (User)","description":"Determines whether users can configure advanced TCP/IP settings.\r\n\r\nIf you enable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), the Advanced button on the Internet Protocol (TCP/IP) Properties dialog box is disabled for all users (including administrators). As a result, users cannot open the Advanced TCP/IP Settings Properties page and modify IP settings, such as DNS and WINS server information.\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you disable this setting, the Advanced button is enabled, and all users can open the Advanced TCP/IP Setting dialog box.\r\n\r\nNote: This setting is superseded by settings that prohibit access to properties of connections or connection components. When these policies are set to deny access to the connection properties dialog box or Properties button for connection components, users cannot gain access to the Advanced button for TCP/IP configuration.\r\n\r\nNote: Nonadministrators (excluding Network Configuration Operators) do not have permission to access TCP/IP advanced configuration for a LAN connection, regardless of this setting.\r\n\r\nTip: To open the Advanced TCP/IP Setting dialog box, in the Network Connections folder, right-click a connection icon, and click Properties. For remote access connections, click the Networking tab. In the \"Components checked are used by this connection\" box, click Internet Protocol (TCP/IP), click the Properties button, and then click the Advanced button.\r\n\r\nNote: Changing this setting from Enabled to Not Configured does not enable the Advanced button until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-allowadvancedtcpipconfig"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_allowadvancedtcpipconfig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_allowadvancedtcpipconfig_1","displayName":"Enabled","description":null,"helpText":null}]},"2c4368b8a5978ef3":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_1_lbl_assignedofflinefileslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"2c5e72babedc5097":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nosearchinternettryharderbutton","displayName":"Remove the Search the Internet \"Search again\" link (User)","description":"If you enable this policy, the \"Internet\" \"Search again\" link will not be shown when the user performs a search in the Explorer window.\r\n\r\nIf you disable this policy, there will be an \"Internet\" \"Search again\" link when the user performs a search in the Explorer window. This button launches a search in the default browser with the search terms.\r\n\r\nIf you do not configure this policy (default), there will be an \"Internet\" link when the user performs a search in the Explorer window.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nosearchinternettryharderbutton"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nosearchinternettryharderbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nosearchinternettryharderbutton_1","displayName":"Enabled","description":null,"helpText":null}]},"2cf7131e2f0b9803":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_multicastcheckbox","displayName":"Multicast (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_multicastcheckbox_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_multicastcheckbox_1","displayName":"True","description":null,"helpText":null}]},"2cee0a8541af4d86":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},"2c26756d58f0790f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification","displayName":"Notify a user that a browser relaunch or device restart is recommended or required (User)","description":"Notify users that Google Chrome must be relaunched or Google Chrome OS must be restarted to apply a pending update.\r\n\r\nThis policy setting enables notifications to inform the user that a browser relaunch or device restart is recommended or required. If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google Chrome OS indicates such via a notification in the system tray. If set to 'Recommended', a recurring warning will be shown to the user that a relaunch is recommended. The user can dismiss this warning to defer the relaunch. If set to 'Required', a recurring warning will be shown to the user indicating that a browser relaunch will be forced once the notification period passes. The default period is seven days for Google Chrome and four days for Google Chrome OS, and may be configured via the RelaunchNotificationPeriod policy setting.\r\n\r\nThe user's session is restored following the relaunch/restart.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"2c25a4796fe2c82c":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints. (User)","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Local Network Access checks.\r\n\r\nIf an origin is covered by both this policy and by LocalNetworkAccessBlockedForUrls, LocalNetworkAccessBlockedForUrls takes precedence.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"2cd63d0e998bbd96":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook","displayName":"Review tab | Changes | Protect Workbook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_reviewchangesprotectworkbook_1","displayName":"True","description":null,"helpText":null}]},"2cc315eeea84aea9":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]},"2ce380af509563d1":{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu","displayName":"Let users turn on and use Enterprise Mode from the Tools menu (User)","description":"This policy setting lets you decide whether users can turn on Enterprise Mode for websites with compatibility issues. Optionally, this policy also lets you specify where to get reports (through post messages) about the websites for which users turn on Enterprise Mode using the Tools menu.\n\nIf you turn this setting on, users can see and use the Enterprise Mode option from the Tools menu. If you turn this setting on, but don't specify a report location, Enterprise Mode will still be available to your users, but you won't get any reports.\n\nIf you disable or don't configure this policy setting, the menu option won't appear and users won't be able to run websites in Enterprise Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenterprisemodefromtoolsmenu"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenterprisemodefromtoolsmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"2cd813886c1c75b6":{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate","displayName":"Locked-Down Intranet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownintranetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownintranetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"2c1e829ef4ce8688":{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel","displayName":"Configure which channel of Microsoft Edge to use for opening redirected sites (User)","description":"Enables you to configure up to three versions of Microsoft Edge to open a redirected site (in order of preference). Use this policy if your environment is configured to redirect sites from Internet Explorer 11 to Microsoft Edge. If any of the chosen versions are not installed on the device, that preference will be bypassed.\n\nIf both the Windows Update for the next version of Microsoft Edge* and Microsoft Edge Stable channel are installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge Stable channel is used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\nIf the Windows Update for the next version of Microsoft Edge* or Microsoft Edge Stable channel are not installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge version 45 or earlier is automatically used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 0 = Microsoft Edge version 45 or earlier\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\n*For more information about the Windows update for the next version of Microsoft Edge including how to disable it, see https://go.microsoft.com/fwlink/?linkid=2102115. This update applies only to Windows 10 version 1709 and higher.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-configureedgeredirectchannel"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_1","displayName":"Enabled","description":null,"helpText":null}]},"2c84cdf876a3ed72":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"2c3b698aff40d5af":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"2cd9f8d92818308a":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowsmartscreenie"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"2c4cf5af4285830a":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"2c2a16f9b751b791":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation","displayName":"Configure the home page URL (User)","description":"Configures the default home page URL in Microsoft Edge.\r\n\r\nThe home page is the page opened by the Home button. The pages that open on startup are controlled by the 'RestoreOnStartup' (Action to take on startup) policies.\r\n\r\nYou can either set a URL here or set the home page to open the new tab page. If you select to open the new tab page, then this policy doesn't take effect.\r\n\r\nIf you enable this policy, users can't change their home page URL, but they can choose to use the new tab page as their home page.\r\n\r\nIf you disable or don't configure this policy, users can choose their own home page, as long as the 'HomepageIsNewTabPage' (Set the new tab page as the home page) policy isn't enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\nExample value: https://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"2cbc1c19cae95e81":{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended","displayName":"Efficiency mode enabled (User)","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\r\n\r\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when efficiency mode should become active) policy. If the device does not have a battery, efficiency mode will always be active.\r\n\r\nIf you disable this policy, efficiency mode will never become active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect.\r\n\r\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge_recommended~performance_recommended_efficiencymodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"2c64dee617a75334":{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nLocal Network Access restrictions prevent public websites from making\r\nrequests to devices on a user's local network without explicit user permission.\r\n\r\nIf you enable this policy, Microsoft Edge will\r\nblock any request that would otherwise trigger a DevTools warning\r\ndue to Local Network Access checks.\r\nThese requests will be denied without prompting the user.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will handle\r\nthese requests using the default behavior, which may include showing warnings in DevTools\r\nand allowing the request to proceed depending on the context.\r\n\r\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\r\nunless explicitly granted by the user.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2ca30452cc812e1a":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps (User)","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"2cb4b69562c9298d":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\r\n\r\nLeaving the policy unset means 'DefaultFileSystemReadGuardSetting' (Control use of the File System API for reading) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemReadBlockedForUrls' (Block read access via the File System API on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"2c811d8b10126172":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode","displayName":"Print Rasterization Mode (User)","description":"Controls how Microsoft Edge prints on Windows.\r\n\r\nWhen printing to a non-PostScript printer on Windows, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nIf you set this policy to 'Full' or don't configure it, Microsoft Edge will do full page rasterization if necessary.\r\n\r\nIf you set this policy to 'Fast', Microsoft Edge will reduce the amount of rasterization which can help reduce print job sizes and increase printing speed.\r\n\r\nPolicy options mapping:\r\n\r\n* Full (0) = Full page rasterization\r\n\r\n* Fast (1) = Avoid rasterization if possible\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},"2c7e509de125cc00":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in any of the following policies: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins).\r\n\r\nIf a site matches a URL pattern in this policy, the 'ScreenCaptureAllowed' (Allow or deny screen capture) will not be considered.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_screencaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"2c17d6b6e3d669e4":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_l_writingassistantadminblockedappslistid","displayName":"Blocked application names (e.g., notepad.exe) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":null},"2c9039abcb640905":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334","displayName":"Display menus and dialog boxes in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_0","displayName":"(same as the system)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1078","displayName":"Afrikaans","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1052","displayName":"Albanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1118","displayName":"Amharic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1025","displayName":"Arabic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1067","displayName":"Armenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1101","displayName":"Assamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1068","displayName":"Azerbaijani (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2117","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1093","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1069","displayName":"Basque","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1059","displayName":"Belarusian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_5146","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1026","displayName":"Bulgarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1027","displayName":"Catalan","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1170","displayName":"Central Kurdish (Iraq)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1116","displayName":"Cherokee","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2052","displayName":"Chinese (Simplified)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1028","displayName":"Chinese (Traditional)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1050","displayName":"Croatian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1029","displayName":"Czech","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1030","displayName":"Danish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1164","displayName":"Dari","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1043","displayName":"Dutch","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1033","displayName":"English","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1061","displayName":"Estonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1124","displayName":"Filipino","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1035","displayName":"Finnish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1036","displayName":"French","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1110","displayName":"Galician","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1079","displayName":"Georgian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1031","displayName":"German","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1032","displayName":"Greek","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1095","displayName":"Gujarati","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1128","displayName":"Hausa (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1037","displayName":"Hebrew","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1081","displayName":"Hindi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1038","displayName":"Hungarian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1039","displayName":"Icelandic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1136","displayName":"Igbo","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1057","displayName":"Indonesian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2141","displayName":"Inuktitut (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2108","displayName":"Irish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1076","displayName":"isiXhosa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1077","displayName":"isiZulu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1040","displayName":"Italian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1041","displayName":"Japanese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1099","displayName":"Kannada","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1087","displayName":"Kazakh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1107","displayName":"Khmer","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1158","displayName":"K'iche","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1159","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1088","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1089","displayName":"Swahili","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1111","displayName":"Konkani","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1042","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1062","displayName":"Latvian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1063","displayName":"Lithuanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1134","displayName":"Luxembourgish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1086","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1100","displayName":"Malayalam","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1082","displayName":"Maltese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1153","displayName":"Maori","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1102","displayName":"Marathi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1071","displayName":"Macedonian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1104","displayName":"Mongolian (Cyrillic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1121","displayName":"Nepali","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1044","displayName":"Norwegian (Bokmal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2068","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1096","displayName":"Odia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1065","displayName":"Persian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1045","displayName":"Polish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1046","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2070","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1094","displayName":"Punjabi","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2118","displayName":"Punjabi (Pakistan)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3179","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1048","displayName":"Romanian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1049","displayName":"Russian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1169","displayName":"Scottish Gaelic (United Kingdom)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3098","displayName":"Serbian (Cyrillic, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_7194","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2074","displayName":"Serbian (Latin, Serbia and Montenegro (Former))","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1132","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1074","displayName":"Setswana","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2137","displayName":"Sindhi (Arabic)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1115","displayName":"Sinhala","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1051","displayName":"Slovak","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1060","displayName":"Slovenian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_3082","displayName":"Spanish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1053","displayName":"Swedish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1064","displayName":"Tajik","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1097","displayName":"Tamil","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1092","displayName":"Tatar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1098","displayName":"Telugu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1054","displayName":"Thai","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1139","displayName":"Tigrinya (Ethiopia)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1055","displayName":"Turkish","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1090","displayName":"Turkmen","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1058","displayName":"Ukrainian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1056","displayName":"Urdu","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1152","displayName":"Uyghur (PRC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1091","displayName":"Uzbek (Latin)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_2051","displayName":"Valencian","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1066","displayName":"Vietnamese","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1106","displayName":"Welsh","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1160","displayName":"Wolof","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_l_displaymenusanddialogboxesin334_1130","displayName":"Yoruba","description":null,"helpText":null}]},"2ccaf0230b706335":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore","displayName":"Block the Office Store (User)","description":"This policy setting allows you to prevent users from using or inserting web add-ins that come from the Office Store.\r\n\r\nIf you enable this policy setting, apps from the Office Store are blocked.\r\n\r\nIf you disable or do not configure this policy setting, apps from the Office Store are allowed, unless the \"Block Apps for Office\" policy setting is enabled.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_disableofficestore_1","displayName":"Enabled","description":null,"helpText":null}]},"2c3329b94431c2f4":{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt","displayName":"Show the File Format dialog (User)","description":"This policy setting allows you to control whether the file format dialog has already been shown to the user. If you enable this policy setting, the dialog won't be shown again. If you disable this policy setting, the dialog prompts the user to select a default file format on each boot until one is selected. If you don't configure this policy setting, the dialog prompts the user to select a default file format on each boot until one is selected.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v20~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_shownfilefmtprompt_1","displayName":"Enabled","description":null,"helpText":null}]},"2cae12382fdbc3c7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing","displayName":"Control Calendar Sharing (User)","description":"By default, users can share an entire calendar by saving it in the iCalendar format, or share a snapshot of a calendar by using e-mail. This setting allows you to specify the detail level in the shared versions of calendars, or to disable sharing of calendars.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_controlcalendarsharing_1","displayName":"Enabled","description":null,"helpText":null}]},"2c41cb8d711f4389":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"2ca6b2b142ea015c":{"id":"user_vendor_msft_policy_config_start_disablecontextmenus","displayName":"Disable Context Menus (User)","description":"Enabling this policy prevents context menus from being invoked in the Start Menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#disablecontextmenus"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_disablecontextmenus_0","displayName":"Disabled","description":"Do not disable.","helpText":null},{"id":"user_vendor_msft_policy_config_start_disablecontextmenus_1","displayName":"Enabled","description":"Disable.","helpText":null}]},"2c11de5e6e79e9a6":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},"2ca83a94afbb7165":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext","displayName":"Hidden text (User)","description":"This policy setting controls whether text that is formatted as hidden displays on Word users' monitor screens.\r\n\r\nIf you enable this policy setting, Word displays hidden text at all times. Hidden text on monitor screens displays as underlined with a dotted line.\r\n\r\nIf you disable or do not configure this policy setting, Word does not display text formatted as hidden unless \"Show/Hide ¶\" is selected or Word is configured to show hidden text in the \"Display\" section of the \"Word Options\" dialog.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_hiddentext_1","displayName":"Enabled","description":null,"helpText":null}]},"2c9b95bd56606c92":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},"2c0aa219a3925da3":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"2cd69d134e32ed84":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},"2c6e41278caf8d97":{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_maxrescanintervalinseconds","displayName":"Max Rescan Interval In Seconds (Windows Insiders only)","description":"Maximum time (in seconds) from the point that no connection could be established using the permissible eSIM profiles on the device to the start of the next round of network discovery attempts. A smaller interval increases network discovery frequency and can decrease battery life significantly. A value of 0 means that the device is to pick a reasonable interval per its own discretion.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/30.json b/public/intune-definitions/30.json index 48afe5d82df0..4da969c1c107 100644 --- a/public/intune-definitions/30.json +++ b/public/intune-definitions/30.json @@ -1 +1 @@ -{"3013b903a710e845":{"id":"com.apple.extensiblesso_com.apple.extensiblesso","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"306a27fbeeb9f018":{"id":"com.apple.managedclient.preferences_metricsreportingenabled","displayName":"Enable usage and crash-related data reporting","description":"This policy enables reporting of usage and crash-related data about Microsoft Edge to Microsoft.\n\nEnable this policy to send reporting of usage and crash-related data to Microsoft. Disable this policy to not send the data to Microsoft. In both cases, users can't change or override the setting.\n\nOn Windows 10, Beta and Stable channels, if you don’t configure this policy, Microsoft Edge will default to the Windows diagnostic data setting. If you enable this policy, Microsoft Edge will only send usage data if the Windows Diagnostic data setting is set to Enhanced or Full. If you disable this policy, Microsoft Edge will not send usage data. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings at https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 10, Canary and Dev channels, this policy controls sending usage data. If this policy is not configured, Microsoft Edge will default to the user's preference. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 7, 8, and macOS, this policy controls sending usage and crash-related data. If you don’t configure this policy, Microsoft Edge will default to the user's preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#metricsreportingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_metricsreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_metricsreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"30586df5b81a5695":{"id":"com.apple.managedclient.preferences_synctypeslistdisabled","displayName":"Configure the list of types that are excluded from synchronization","description":"If you enable this policy all the specified data types will be excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", and “collections”. Note that these data type names are case sensitive.\n\nUsers will not be able to override the disabled data types.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#synctypeslistdisabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"30ff41a28a555b36":{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_disk sleep timer","displayName":"Disk Sleep Timer","description":"The disk sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"30a8782c73e4fd08":{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata","displayName":"Allow Cellular Data","description":"If false, disables cellular data for all matching managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":[{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata_true","displayName":"True","description":null,"helpText":null}]},"300612f42ab349de":{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"30daea5c7f8b84c4":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogo","displayName":"Set new tab page company logo (Obsolete)","description":"This policy didn't work as expected due to changes in operational requirements. Therefore, it's obsolete and shouldn't be used.\n\nSpecifies the company logo that's to be used on the new tab page in Microsoft Edge.\n\nThe policy should be configured as a string that expresses the logo(s) in JSON format. For example: { \"default_logo\": { \"url\": \"https://www.contoso.com/logo.png\", \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\" }, \"light_logo\": { \"url\": \"https://www.contoso.com/light_logo.png\", \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\" } }\n\nYou configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication.\n\nThe 'default_logo' is required and used when there's no background image. If 'light_logo' is provided, it's used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that's left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background, while the 'light_logo' should have proper contrast against a background image.\n\nIf you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s).\n\nIf you disable or don't configure this policy, Microsoft Edge shows no company logo or a Microsoft logo on the new tab page.\n\nFor help with determining the SHA-256 hash, see [Get-FileHash](/powershell/module/microsoft.powershell.utility/get-filehash).","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"30c7ef1afe720203":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2","displayName":"Prohibit user configuration of Offline Files","description":"Prevents users from enabling, disabling, or changing the configuration of Offline Files.\r\n\r\nThis setting removes the Offline Files tab from the Folder Options dialog box. It also removes the Settings item from the Offline Files context menu and disables the Settings button on the Offline Files Status dialog box. As a result, users cannot view or change the options on the Offline Files tab or Offline Files dialog box.\r\n\r\nThis is a comprehensive setting that locks down the configuration you establish by using other settings in this folder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: This setting provides a quick method for locking down the default settings for Offline Files. To accept the defaults, just enable this setting. You do not have to disable any other settings in this folder.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-noconfigcache-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2_1","displayName":"Enabled","description":null,"helpText":null}]},"309067ec57105469":{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts","displayName":"Enable Package Scripts","description":"Enables scripts defined in the package manifest of configuration files that should run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpackagescripts"],"categoryId":"efabaf11-42e4-48ab-81ca-4514199d239b","categoryName":"Scripting","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts_1","displayName":"Enabled","description":null,"helpText":null}]},"30117a02a9347c34":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for profile types.","description":"Configuring this policy will allow/disallow ambient authentication for Incognito and Guest profiles in Google Chrome.\r\n\r\nAmbient Authentication is http authentication with default credentials if explicit credentials are not provided via NTLM/Kerberos/Negotiate challenge/response schemes.\r\n\r\nSetting the RegularOnly (value 0), allows ambient authentication for Regular sessions only. Incognito and Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the IncognitoAndRegular (value 1), allows ambient authentication for Incognito and Regular sessions. Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the GuestAndRegular (value 2), allows ambient authentication for Guest and Regular sessions. Incognito sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the All (value 3), allows ambient authentication for all sessions.\r\n\r\nNote that, ambient authentication is always allowed on regular profiles.\r\n\r\nIn Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"300bf984647e33a0":{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablemicrosoftstoresource","displayName":"Enable App Installer Microsoft Store Source","description":"This policy controls the Microsoft Store source included with the Windows Package Manager.\n\nIf you do not configure this setting, the Microsoft Store source for the Windows Package manager will be available and can be removed.\n\nIf you enable this setting, the Microsoft Store source for the Windows Package Manager will be available and cannot be removed.\n\nIf you disable this setting the Microsoft Store source for the Windows Package Manager will not be available.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-enablemicrosoftstoresource"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablemicrosoftstoresource_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablemicrosoftstoresource_1","displayName":"Enabled","description":null,"helpText":null}]},"30803f6ba49df3ad":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix_vhdcompactdisk","displayName":"VHD Compact Disk","description":"[ENABLED BY DEFAULT]\r\n\r\nNOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nCompacts the VHD disk during the sign-out operation and is designed to automatically decrease the Size On Disk of the user's container(s) depending on a pre-defined threshold.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Apps\\VHDCompactDisk\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","categoryName":"FSLogix","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix_vhdcompactdisk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix_vhdcompactdisk_1","displayName":"Enabled","description":null,"helpText":null}]},"308ae2e2a54a2e29":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype","displayName":"Redirect Type","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nConfigures legacy or FSLogix advanced redirection. The default is '2' which is the same as \"Not Configured\".\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\RedirectType\r\nType: DWORD\r\nValues: Legacy = 1, FSLogix Redirection = 2","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_1","displayName":"Enabled","description":null,"helpText":null}]},"3010bacb128bd365":{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate","displayName":"Locked-Down Restricted Sites","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},"3067932b2c806952":{"id":"device_vendor_msft_policy_config_internetexplorer_allowonewordentry","displayName":"Go to an intranet site for a one-word entry in the Address bar","description":"This policy allows the user to go directly to an intranet site for a one-word entry in the Address bar.\n\nIf you enable this policy setting, Internet Explorer goes directly to an intranet site for a one-word entry in the Address bar, if it is available.\n\nIf you disable or do not configure this policy setting, Internet Explorer does not go directly to an intranet site for a one-word entry in the Address bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowonewordentry"],"categoryId":"a1fbe395-3b60-475f-8a34-3710d6b2e09f","categoryName":"Browsing","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowonewordentry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowonewordentry_1","displayName":"Enabled","description":null,"helpText":null}]},"30f8b83bd2362c5c":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_l_configuredservercheckvalues_value","displayName":"Server version names (semicolon separated list): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},"3047aad28a80010b":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},"304ed59f6810227e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_newtabpagelocation","displayName":"New tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"301674ac18fe39ad":{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled","displayName":"Enable Silent Printing","description":"This policy controls whether Microsoft Edge uses silent printing.\r\n\r\nIf you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder.\r\n\r\nIf you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3016f774127ee44e":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_1","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_2","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},"30df65ad219b86a1":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed","displayName":"Allow Internet Explorer mode testing","description":"This policy is a replacement for the ie-mode-test flag policy. It lets users open an IE mode tab from the UI menu option.\r\n\r\n This setting works in conjunction with:\r\n 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'\r\n and\r\n 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\n If you enable this policy, users can open IE mode tab from the UI option and navigate current site to an IE mode site.\r\n\r\n If you disable this policy, users can't see the UI option in the menu directly.\r\n\r\n If you don't configure this policy, you can set up the ie-mode-test flag manually.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"30d7e5eaee20b044":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"304571afec1a6495":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"308bb9ec22bcadd0":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection","description":"Allows you to create a list of protocols, and for each protocol an associated list of allowed origin patterns. These origins won't be silently blocked from launching an external application by anti-flood protection. The trailing separator shouldn't be included when listing the protocol. For example, list \"skype\" instead of \"skype:\" or \"skype://\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to bypass being silently blocked by anti-flood protection if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch may be blocked by anti-flood protection.\r\n\r\nIf you don't configure this policy, no protocols can bypass being silently blocked.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, that are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy doesn't work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"spotify\",\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"msteams\",\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"msoutlook\",\r\n \"allowed_origins\": [\r\n \"*\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"309a275f2defc401":{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208","displayName":"Exclude Japanese IME Except JIS0208","description":"Note The policy is only enforced in Windows 10 for desktop. Allows the users to restrict character code range of conversion by setting the character filter.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#excludejapaneseimeexceptjis0208"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208_0","displayName":"No characters are filtered.","description":"No characters are filtered.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208_1","displayName":"All characters except JIS0208 are filtered.","description":"All characters except JIS0208 are filtered.","helpText":null}]},"305b8dd5b026ee69":{"id":"settings_item_mdmoptions_mdmoptions_idlerebootallowed","displayName":"Idle Reboot Allowed","description":"If `true`, the device automatically reboots while locked after several days of inactivity. The device sets this to `false` by default for a supervised enrollment. Starting in iOS 26.6 and iPadOS 26.6, changing the effective value from reboot allowed to reboot disallowed requires a reboot or a device unlock before the change takes effect.","helpText":null,"infoUrls":[],"categoryId":"dd68a290-1ba7-470f-afca-339f443a767c","categoryName":"MDM Options","options":[{"id":"settings_item_mdmoptions_mdmoptions_idlerebootallowed_false","displayName":"False","description":null,"helpText":null},{"id":"settings_item_mdmoptions_mdmoptions_idlerebootallowed_true","displayName":"True","description":null,"helpText":null}]},"305216ee018fa234":{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setfilerisklevel","displayName":"Default risk level for file attachments (User)","description":"This policy setting allows you to manage the default risk level for file types. To fully customize the risk level for file attachments, you may also need to configure the trust logic for file attachments.\r\n\r\nHigh Risk: If the attachment is in the list of high-risk file types and is from the restricted zone, Windows blocks the user from accessing the file. If the file is from the Internet zone, Windows prompts the user before accessing the file.\r\n\r\nModerate Risk: If the attachment is in the list of moderate-risk file types and is from the restricted or Internet zone, Windows prompts the user before accessing the file.\r\n\r\nLow Risk: If the attachment is in the list of low-risk file types, Windows will not prompt the user before accessing the file, regardless of the file's zone information.\r\n\r\nIf you enable this policy setting, you can specify the default risk level for file types.\r\n\r\nIf you disable this policy setting, Windows sets the default risk level to moderate.\r\n\r\nIf you do not configure this policy setting, Windows sets the default risk level to moderate.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-attachmentmanager#admx-attachmentmanager-am-setfilerisklevel"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setfilerisklevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setfilerisklevel_1","displayName":"Enabled","description":null,"helpText":null}]},"30250688b40c9ee8":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirsitesservices","displayName":"Active Directory Sites and Services (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-activedirsitesservices"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirsitesservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirsitesservices_1","displayName":"Enabled","description":null,"helpText":null}]},"3074d0ea7349685d":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configuremmsproxysettings_proxyaddress","displayName":"Proxy address (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"30402d6b29af9f49":{"id":"user_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc","displayName":"Prevent Using Local Host IP Address For Web RTC (User)","description":"Prevent using localhost IP address for WebRTC","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventusinglocalhostipaddressforwebrtc"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc_0","displayName":"Disabled","description":"Allowed. Show localhost IP addresses.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc_1","displayName":"Enabled","description":"Prevented/Not allowed.","helpText":null}]},"30fdfba9b0becca4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling","displayName":"The IP handling policy of WebRTC (User)","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2). When unset, defaults to using all available interfaces.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_1","displayName":"Enabled","description":null,"helpText":null}]},"303eb81f3498968d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup","displayName":"Disable CNAME lookup when negotiating Kerberos authentication (User)","description":"Setting the policy to Enabled skips CNAME lookup. The server name is used as entered when generating the Kerberos SPN.\r\n\r\nSetting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup_1","displayName":"Enabled","description":null,"helpText":null}]},"30db8a510a261e8b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist","displayName":"Enable CORS check mitigations in the new CORS implementation (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_1","displayName":"Enabled","description":null,"helpText":null}]},"3032f86fbdb3b581":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls","displayName":"Allow the File Handling API on these web apps (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"308d94f703daa1dc":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"30d5e947c830e090":{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions","displayName":"Block Insecure Protocols in Excel Worksheet Functions (User)","description":"\n\t\t This policy controls whether the following Excel functions can access the web via insecure protocols: WEBSERVICE, IMPORTCSV, IMPORTTEXT\n\n\t\t If you enable this policy setting, WEBSERVICE, IMPORTCSV, and IMPORTTEXT functions will be blocked from accessing the web via insecure protocols.\n\n\t\t If you disable or don't configure this policy setting, WEBSERVICE, IMPORTCSV, and IMPORTTEXT functions will be allowed to access the web via insecure protocols.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions_1","displayName":"Enabled","description":null,"helpText":null}]},"30a9c051ad62b215":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles","displayName":"dBase III / IV files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"30a6a3e1c6326de3":{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings","displayName":"Prevent bypassing SmartScreen Filter warnings (User)","description":"This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter prevents the user from browsing to or downloading from sites that are known to host malicious content. SmartScreen Filter also prevents the execution of files that are known to be malicious.\n\nIf you enable this policy setting, SmartScreen Filter warnings block the user.\n\nIf you disable or do not configure this policy setting, the user can bypass SmartScreen Filter warnings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablebypassofsmartscreenwarnings"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},"304cd6497d28f335":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},"30d99ba737533e0f":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_managedsearchengines","displayName":"Manage Search Engines (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"302ab8011fb4b5da":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed","displayName":"Allow user feedback (User)","description":"Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions or customer surveys and to report any issues with the browser. Also, by default, users can't disable (turn off) the Edge Feedback feature.\r\n\r\nIf you enable this policy or don't configure it, users can invoke Edge Feedback.\r\n\r\nIf you disable this policy, users can't invoke Edge Feedback.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"3038ac0517ebcf67":{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles (User)","description":"This policy controls access to page contents for Copilot in the Microsoft Edge sidebar when users are logged into their MSA Copilot account. This policy applies only to Microsoft Entra ID Microsoft Edge profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA Microsoft Edge profiles. This policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with enterprise data protection (EDP) is controlled by the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy.\r\n\r\nIf you enable this policy, Copilot will have access to page content when logged in with Entra ID.\r\n\r\nIf this policy is not configured, the default behavior for non-EU countries is that access is initially enabled. For EU countries, the default behavior is that access is initially disabled. In both cases, if the policy is not configured, users can enable or disable Copilot's access to page content using the setting toggle in Microsoft Edge.\r\n\r\nIf you disable this policy, Copilot will not be able to access page context.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},"3032bacc23e48e08":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_idletimeoutactionsdesc","displayName":"Actions to run when the computer is idle (User)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},"3064d8dfcfd2baf6":{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended","displayName":"Block smart actions for a list of services (User)","description":"List specific services, such as PDFs, that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\r\n\r\nIf you enable the policy: :\r\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\r\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\r\n\r\nIf you disable or don't configure this policy:\r\n - The smart action in the mini and full context menu will be enabled for all profiles.\r\n - Users will see the smart action in the mini and full context menu on text selection.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nsmart_actions_pdf","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"30ca56906667a289":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverterms3","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"30347b0920e53cd9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicemajorversion9","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"302e99e424ced30f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines","displayName":"English (Philippines) (User)","description":"Enables the editing language English (Philippines)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines_1","displayName":"Enabled","description":null,"helpText":null}]},"307dcf9fa1afbb71":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},"30a3185b90dd68f9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess","displayName":"Configure Outlook object model prompt when reading address information (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to a recipient field, such as the ''To:'' field, using the Outlook object model.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access a recipient field using the Outlook object model:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access recipient fields, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"305a75b584cecf14":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_datecolon5","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"30a7bf60e5523107":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency","displayName":"Default Project Currency (User)","description":"Allows you to manage whether users can set the default currency type for their new project plans. If you enable this setting, the default currency type is enforced for all new project plans. If this setting is disabled or not configured, users can set the default currency type for new project plans.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_1","displayName":"Enabled","description":null,"helpText":null}]},"30f628c5200abb44":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration","displayName":"Duration (User)","description":"Specifies the unit of measure for duration, which is elapsed time as compared to a specific date or a given hour.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_1","displayName":"Enabled","description":null,"helpText":null}]},"301e05d83b8574cb":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0","displayName":"Check to enforce setting on; uncheck to enforce setting off (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0_1","displayName":"True","description":null,"helpText":null}]},"304f3b012941344c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes","displayName":"Straight quotes with smart quotes (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},"30b23b4fa844efc8":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"3013b903a710e845":{"id":"com.apple.extensiblesso_com.apple.extensiblesso","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"306a27fbeeb9f018":{"id":"com.apple.managedclient.preferences_metricsreportingenabled","displayName":"Enable usage and crash-related data reporting","description":"This policy enables reporting of usage and crash-related data about Microsoft Edge to Microsoft.\n\nEnable this policy to send reporting of usage and crash-related data to Microsoft. Disable this policy to not send the data to Microsoft. In both cases, users can't change or override the setting.\n\nOn Windows 10, Beta and Stable channels, if you don’t configure this policy, Microsoft Edge will default to the Windows diagnostic data setting. If you enable this policy, Microsoft Edge will only send usage data if the Windows Diagnostic data setting is set to Enhanced or Full. If you disable this policy, Microsoft Edge will not send usage data. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings at https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 10, Canary and Dev channels, this policy controls sending usage data. If this policy is not configured, Microsoft Edge will default to the user's preference. Crash-related data is sent based on the Windows Diagnostic data setting. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 7, 8, and macOS, this policy controls sending usage and crash-related data. If you don’t configure this policy, Microsoft Edge will default to the user's preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#metricsreportingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_metricsreportingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_metricsreportingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"30586df5b81a5695":{"id":"com.apple.managedclient.preferences_synctypeslistdisabled","displayName":"Configure the list of types that are excluded from synchronization","description":"If you enable this policy all the specified data types will be excluded from synchronization. This policy can be used to limit the type of data uploaded to the Microsoft Edge synchronization service.\n\nYou can provide one of the following data types for this policy: \"favorites\", \"settings\", \"passwords\", \"addressesAndMore\", \"extensions\", and “collections”. Note that these data type names are case sensitive.\n\nUsers will not be able to override the disabled data types.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#synctypeslistdisabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"30ff41a28a555b36":{"id":"com.apple.mcx_com.apple.energysaver.portable.acpower_disk sleep timer","displayName":"Disk Sleep Timer","description":"The disk sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"30a8782c73e4fd08":{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata","displayName":"Allow Cellular Data","description":"If false, disables cellular data for all matching managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":[{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.networkusagerules_applicationrules_item_allowcellulardata_true","displayName":"True","description":null,"helpText":null}]},"300612f42ab349de":{"id":"com.apple.tcc.configuration-profile-policy_services_addressbook_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"30daea5c7f8b84c4":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogo","displayName":"Set new tab page company logo (Obsolete)","description":"This policy didn't work as expected due to changes in operational requirements. Therefore, it's obsolete and shouldn't be used.\n\nSpecifies the company logo that's to be used on the new tab page in Microsoft Edge.\n\nThe policy should be configured as a string that expresses the logo(s) in JSON format. For example: { \"default_logo\": { \"url\": \"https://www.contoso.com/logo.png\", \"hash\": \"cd0aa9856147b6c5b4ff2b7dfee5da20aa38253099ef1b4a64aced233c9afe29\" }, \"light_logo\": { \"url\": \"https://www.contoso.com/light_logo.png\", \"hash\": \"517d286edb416bb2625ccfcba9de78296e90da8e32330d4c9c8275c4c1c33737\" } }\n\nYou configure this policy by specifying the URL from which Microsoft Edge can download the logo and its cryptographic hash (SHA-256), which is used to verify the integrity of the download. The logo must be in PNG or SVG format, and its file size must not exceed 16 MB. The logo is downloaded and cached, and it will be redownloaded whenever the URL or the hash changes. The URL must be accessible without any authentication.\n\nThe 'default_logo' is required and used when there's no background image. If 'light_logo' is provided, it's used when the user's new tab page has a background image. We recommend a horizontal logo with a transparent background that's left-aligned and vertically centered. The logo should have a minimum height of 32 pixels and an aspect ratio from 1:1 to 4:1. The 'default_logo' should have proper contrast against a white/black background, while the 'light_logo' should have proper contrast against a background image.\n\nIf you enable this policy, Microsoft Edge downloads and shows the specified logo(s) on the new tab page. Users can't override or hide the logo(s).\n\nIf you disable or don't configure this policy, Microsoft Edge shows no company logo or a Microsoft logo on the new tab page.\n\nFor help with determining the SHA-256 hash, see [Get-FileHash](/powershell/module/microsoft.powershell.utility/get-filehash).","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"30c7ef1afe720203":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2","displayName":"Prohibit user configuration of Offline Files","description":"Prevents users from enabling, disabling, or changing the configuration of Offline Files.\r\n\r\nThis setting removes the Offline Files tab from the Folder Options dialog box. It also removes the Settings item from the Offline Files context menu and disables the Settings button on the Offline Files Status dialog box. As a result, users cannot view or change the options on the Offline Files tab or Offline Files dialog box.\r\n\r\nThis is a comprehensive setting that locks down the configuration you establish by using other settings in this folder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: This setting provides a quick method for locking down the default settings for Offline Files. To accept the defaults, just enable this setting. You do not have to disable any other settings in this folder.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-noconfigcache-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_noconfigcache_2_1","displayName":"Enabled","description":null,"helpText":null}]},"309067ec57105469":{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts","displayName":"Enable Package Scripts","description":"Enables scripts defined in the package manifest of configuration files that should run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-allowpackagescripts"],"categoryId":"efabaf11-42e4-48ab-81ca-4514199d239b","categoryName":"Scripting","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_allowpackagescripts_1","displayName":"Enabled","description":null,"helpText":null}]},"30117a02a9347c34":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for profile types.","description":"Configuring this policy will allow/disallow ambient authentication for Incognito and Guest profiles in Google Chrome.\r\n\r\nAmbient Authentication is http authentication with default credentials if explicit credentials are not provided via NTLM/Kerberos/Negotiate challenge/response schemes.\r\n\r\nSetting the RegularOnly (value 0), allows ambient authentication for Regular sessions only. Incognito and Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the IncognitoAndRegular (value 1), allows ambient authentication for Incognito and Regular sessions. Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the GuestAndRegular (value 2), allows ambient authentication for Guest and Regular sessions. Incognito sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the All (value 3), allows ambient authentication for all sessions.\r\n\r\nNote that, ambient authentication is always allowed on regular profiles.\r\n\r\nIn Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"300bf984647e33a0":{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablemicrosoftstoresource","displayName":"Enable App Installer Microsoft Store Source","description":"This policy controls the Microsoft Store source included with the Windows Package Manager.\n\nIf you do not configure this setting, the Microsoft Store source for the Windows Package manager will be available and can be removed.\n\nIf you enable this setting, the Microsoft Store source for the Windows Package Manager will be available and cannot be removed.\n\nIf you disable this setting the Microsoft Store source for the Windows Package Manager will not be available.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-enablemicrosoftstoresource"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablemicrosoftstoresource_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_enablemicrosoftstoresource_1","displayName":"Enabled","description":null,"helpText":null}]},"30803f6ba49df3ad":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix_vhdcompactdisk","displayName":"VHD Compact Disk","description":"[ENABLED BY DEFAULT]\r\n\r\nNOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nCompacts the VHD disk during the sign-out operation and is designed to automatically decrease the Size On Disk of the user's container(s) depending on a pre-defined threshold.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Apps\\VHDCompactDisk\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","categoryName":"FSLogix","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix_vhdcompactdisk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix_vhdcompactdisk_1","displayName":"Enabled","description":null,"helpText":null}]},"308ae2e2a54a2e29":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype","displayName":"Redirect Type","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nConfigures legacy or FSLogix advanced redirection. The default is '2' which is the same as \"Not Configured\".\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\RedirectType\r\nType: DWORD\r\nValues: Legacy = 1, FSLogix Redirection = 2","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_1","displayName":"Enabled","description":null,"helpText":null}]},"3010bacb128bd365":{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate","displayName":"Locked-Down Restricted Sites","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_iz_partnamerestrictedsiteszonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},"3067932b2c806952":{"id":"device_vendor_msft_policy_config_internetexplorer_allowonewordentry","displayName":"Go to an intranet site for a one-word entry in the Address bar","description":"This policy allows the user to go directly to an intranet site for a one-word entry in the Address bar.\n\nIf you enable this policy setting, Internet Explorer goes directly to an intranet site for a one-word entry in the Address bar, if it is available.\n\nIf you disable or do not configure this policy setting, Internet Explorer does not go directly to an intranet site for a one-word entry in the Address bar.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowonewordentry"],"categoryId":"a1fbe395-3b60-475f-8a34-3710d6b2e09f","categoryName":"Browsing","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowonewordentry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowonewordentry_1","displayName":"Enabled","description":null,"helpText":null}]},"30f8b83bd2362c5c":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_l_configuredservercheckvalues_value","displayName":"Server version names (semicolon separated list): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},"3047aad28a80010b":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},"304ed59f6810227e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_newtabpagelocation","displayName":"New tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"301674ac18fe39ad":{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled","displayName":"Enable Silent Printing","description":"This policy controls whether Microsoft Edge uses silent printing.\r\n\r\nIf you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder.\r\n\r\nIf you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3016f774127ee44e":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_1","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_2","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},"30df65ad219b86a1":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed","displayName":"Allow Internet Explorer mode testing","description":"This policy is a replacement for the ie-mode-test flag policy. It lets users open an IE mode tab from the UI menu option.\r\n\r\n This setting works in conjunction with:\r\n 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'\r\n and\r\n 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy where the list has at least one entry.\r\n\r\n If you enable this policy, users can open IE mode tab from the UI option and navigate current site to an IE mode site.\r\n\r\n If you disable this policy, users can't see the UI option in the menu directly.\r\n\r\n If you don't configure this policy, you can set up the ie-mode-test flag manually.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_internetexplorerintegrationtestingallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"30d7e5eaee20b044":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~sleepingtabs_sleepingtabstimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"304571afec1a6495":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"308bb9ec22bcadd0":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection","description":"Allows you to create a list of protocols, and for each protocol an associated list of allowed origin patterns. These origins won't be silently blocked from launching an external application by anti-flood protection. The trailing separator shouldn't be included when listing the protocol. For example, list \"skype\" instead of \"skype:\" or \"skype://\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to bypass being silently blocked by anti-flood protection if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch may be blocked by anti-flood protection.\r\n\r\nIf you don't configure this policy, no protocols can bypass being silently blocked.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, that are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy doesn't work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"protocol\": \"spotify\",\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"msteams\",\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ]\r\n },\r\n {\r\n \"protocol\": \"msoutlook\",\r\n \"allowed_origins\": [\r\n \"*\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"309a275f2defc401":{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208","displayName":"Exclude Japanese IME Except JIS0208","description":"Note The policy is only enforced in Windows 10 for desktop. Allows the users to restrict character code range of conversion by setting the character filter.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#excludejapaneseimeexceptjis0208"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208_0","displayName":"No characters are filtered.","description":"No characters are filtered.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_excludejapaneseimeexceptjis0208_1","displayName":"All characters except JIS0208 are filtered.","description":"All characters except JIS0208 are filtered.","helpText":null}]},"30ebc74e6e290530":{"id":"plugin_serveraddress","displayName":"Server Address","description":"The server address, which may be the IP address, hostname, or URL.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"305b8dd5b026ee69":{"id":"settings_item_mdmoptions_mdmoptions_idlerebootallowed","displayName":"Idle Reboot Allowed","description":"If `true`, the device automatically reboots while locked after several days of inactivity. The device sets this to `false` by default for a supervised enrollment. Starting in iOS 26.6 and iPadOS 26.6, changing the effective value from reboot allowed to reboot disallowed requires a reboot or a device unlock before the change takes effect.","helpText":null,"infoUrls":[],"categoryId":"dd68a290-1ba7-470f-afca-339f443a767c","categoryName":"MDM Options","options":[{"id":"settings_item_mdmoptions_mdmoptions_idlerebootallowed_false","displayName":"False","description":null,"helpText":null},{"id":"settings_item_mdmoptions_mdmoptions_idlerebootallowed_true","displayName":"True","description":null,"helpText":null}]},"305216ee018fa234":{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setfilerisklevel","displayName":"Default risk level for file attachments (User)","description":"This policy setting allows you to manage the default risk level for file types. To fully customize the risk level for file attachments, you may also need to configure the trust logic for file attachments.\r\n\r\nHigh Risk: If the attachment is in the list of high-risk file types and is from the restricted zone, Windows blocks the user from accessing the file. If the file is from the Internet zone, Windows prompts the user before accessing the file.\r\n\r\nModerate Risk: If the attachment is in the list of moderate-risk file types and is from the restricted or Internet zone, Windows prompts the user before accessing the file.\r\n\r\nLow Risk: If the attachment is in the list of low-risk file types, Windows will not prompt the user before accessing the file, regardless of the file's zone information.\r\n\r\nIf you enable this policy setting, you can specify the default risk level for file types.\r\n\r\nIf you disable this policy setting, Windows sets the default risk level to moderate.\r\n\r\nIf you do not configure this policy setting, Windows sets the default risk level to moderate.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-attachmentmanager#admx-attachmentmanager-am-setfilerisklevel"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setfilerisklevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setfilerisklevel_1","displayName":"Enabled","description":null,"helpText":null}]},"30250688b40c9ee8":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirsitesservices","displayName":"Active Directory Sites and Services (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-activedirsitesservices"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirsitesservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirsitesservices_1","displayName":"Enabled","description":null,"helpText":null}]},"3074d0ea7349685d":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configuremmsproxysettings_proxyaddress","displayName":"Proxy address (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"30402d6b29af9f49":{"id":"user_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc","displayName":"Prevent Using Local Host IP Address For Web RTC (User)","description":"Prevent using localhost IP address for WebRTC","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventusinglocalhostipaddressforwebrtc"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc_0","displayName":"Disabled","description":"Allowed. Show localhost IP addresses.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_preventusinglocalhostipaddressforwebrtc_1","displayName":"Enabled","description":"Prevented/Not allowed.","helpText":null}]},"30fdfba9b0becca4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling","displayName":"The IP handling policy of WebRTC (User)","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2). When unset, defaults to using all available interfaces.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_1","displayName":"Enabled","description":null,"helpText":null}]},"303eb81f3498968d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup","displayName":"Disable CNAME lookup when negotiating Kerberos authentication (User)","description":"Setting the policy to Enabled skips CNAME lookup. The server name is used as entered when generating the Kerberos SPN.\r\n\r\nSetting the policy to Disabled or leaving it unset means CNAME lookup determines the canonical name of the server when generating the Kerberos SPN.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_disableauthnegotiatecnamelookup_1","displayName":"Enabled","description":null,"helpText":null}]},"30db8a510a261e8b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist","displayName":"Enable CORS check mitigations in the new CORS implementation (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_1","displayName":"Enabled","description":null,"helpText":null}]},"3032f86fbdb3b581":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls","displayName":"Allow the File Handling API on these web apps (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"308d94f703daa1dc":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"30d5e947c830e090":{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions","displayName":"Block Insecure Protocols in Excel Worksheet Functions (User)","description":"\n\t\t This policy controls whether the following Excel functions can access the web via insecure protocols: WEBSERVICE, IMPORTCSV, IMPORTTEXT\n\n\t\t If you enable this policy setting, WEBSERVICE, IMPORTCSV, and IMPORTTEXT functions will be blocked from accessing the web via insecure protocols.\n\n\t\t If you disable or don't configure this policy setting, WEBSERVICE, IMPORTCSV, and IMPORTTEXT functions will be allowed to access the web via insecure protocols.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_blockinsecureprotocolsinexcelworksheetfunctions_1","displayName":"Enabled","description":null,"helpText":null}]},"30a9c051ad62b215":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles","displayName":"dBase III / IV files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_dbaseiiiandivfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"30a6a3e1c6326de3":{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings","displayName":"Prevent bypassing SmartScreen Filter warnings (User)","description":"This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter prevents the user from browsing to or downloading from sites that are known to host malicious content. SmartScreen Filter also prevents the execution of files that are known to be malicious.\n\nIf you enable this policy setting, SmartScreen Filter warnings block the user.\n\nIf you disable or do not configure this policy setting, the user can bypass SmartScreen Filter warnings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablebypassofsmartscreenwarnings"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},"304cd6497d28f335":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},"30d99ba737533e0f":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_managedsearchengines","displayName":"Manage Search Engines (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"302ab8011fb4b5da":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed","displayName":"Allow user feedback (User)","description":"Microsoft Edge uses the Edge Feedback feature (enabled by default) to allow users to send feedback, suggestions or customer surveys and to report any issues with the browser. Also, by default, users can't disable (turn off) the Edge Feedback feature.\r\n\r\nIf you enable this policy or don't configure it, users can invoke Edge Feedback.\r\n\r\nIf you disable this policy, users can't invoke Edge Feedback.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userfeedbackallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"3038ac0517ebcf67":{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles (User)","description":"This policy controls access to page contents for Copilot in the Microsoft Edge sidebar when users are logged into their MSA Copilot account. This policy applies only to Microsoft Entra ID Microsoft Edge profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA Microsoft Edge profiles. This policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with enterprise data protection (EDP) is controlled by the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy.\r\n\r\nIf you enable this policy, Copilot will have access to page content when logged in with Entra ID.\r\n\r\nIf this policy is not configured, the default behavior for non-EU countries is that access is initially enabled. For EU countries, the default behavior is that access is initially disabled. In both cases, if the policy is not configured, users can enable or disable Copilot's access to page content using the setting toggle in Microsoft Edge.\r\n\r\nIf you disable this policy, Copilot will not be able to access page context.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotpagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},"3032bacc23e48e08":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_idletimeoutactionsdesc","displayName":"Actions to run when the computer is idle (User)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},"3064d8dfcfd2baf6":{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended","displayName":"Block smart actions for a list of services (User)","description":"List specific services, such as PDFs, that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\r\n\r\nIf you enable the policy: :\r\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\r\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\r\n\r\nIf you disable or don't configure this policy:\r\n - The smart action in the mini and full context menu will be enabled for all profiles.\r\n - Users will see the smart action in the mini and full context menu on text selection.\r\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\r\n\r\nPolicy options mapping:\r\n\r\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nsmart_actions_pdf","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_recommended_smartactionsblocklist_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"30ca56906667a289":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverterms3","displayName":"Service agreement URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"30347b0920e53cd9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicemajorversion9","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"302e99e424ced30f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines","displayName":"English (Philippines) (User)","description":"Enables the editing language English (Philippines)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishphilippines_1","displayName":"Enabled","description":null,"helpText":null}]},"307dcf9fa1afbb71":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},"30a3185b90dd68f9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess","displayName":"Configure Outlook object model prompt when reading address information (User) (Deprecated)","description":"This policy setting controls what happens when an untrusted program attempts to gain access to a recipient field, such as the ''To:'' field, using the Outlook object model.\r\n\r\nIf you enable this policy setting, you can choose from four different options when an untrusted program attempts to access a recipient field using the Outlook object model:\r\n\r\n- Prompt user. The user will be prompted to approve every access attempt.\r\n- Automatically approve. Outlook will automatically grant programmatic access requests from any program. This option can create a significant vulnerability, and is not recommended.\r\n- Automatically deny. Outlook will automatically deny programmatic access requests from any program.\r\n- Prompt user based on computer security. Outlook will only prompt users when antivirus software is out of date or not running. This is the default configuration.\r\n\r\nIf you disable or do not configure this policy setting, when an untrusted application attempts to access recipient fields, Outlook relies on the setting configured in the ''Programmatic Access'' section of the Trust Center.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"305a75b584cecf14":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_datecolon5","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"30a7bf60e5523107":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency","displayName":"Default Project Currency (User)","description":"Allows you to manage whether users can set the default currency type for their new project plans. If you enable this setting, the default currency type is enforced for all new project plans. If this setting is disabled or not configured, users can set the default currency type for new project plans.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_defaultprojectcurrency_1","displayName":"Enabled","description":null,"helpText":null}]},"30f628c5200abb44":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration","displayName":"Duration (User)","description":"Specifies the unit of measure for duration, which is elapsed time as compared to a specific date or a given hour.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_duration_1","displayName":"Enabled","description":null,"helpText":null}]},"301e05d83b8574cb":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0","displayName":"Check to enforce setting on; uncheck to enforce setting off (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarasyoutype_l_checktoenforcesettingonunchecktoenforcesettingoff0_1","displayName":"True","description":null,"helpText":null}]},"304f3b012941344c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes","displayName":"Straight quotes with smart quotes (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_straightquoteswithsmartquotes_1","displayName":"Enabled","description":null,"helpText":null}]},"30b23b4fa844efc8":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/31.json b/public/intune-definitions/31.json index 3d0e310bcc45..cf5459a9c404 100644 --- a/public/intune-definitions/31.json +++ b/public/intune-definitions/31.json @@ -1 +1 @@ -{"31b581a1d5323819":{"id":"com.android.devicerestrictionpolicy.passwordminimumnumericcharacters","displayName":"Number of numeric characters required","description":"Enter the number of numeric characters (1, 2, 3, and so on) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"3195d15a91aa9a65":{"id":"com.apple.applicationaccess_ratingtvshowsgb","displayName":"Rating TV Shows - Great Britain","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsgb_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsgb_1","displayName":"Caution","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsgb_2","displayName":"All","description":null,"helpText":null}]},"3134a25813310af5":{"id":"com.apple.carddav.account_com.apple.carddav.account","displayName":"Top Level Setting Group Collection","description":"com.apple.carddav.account","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},"312b9ec3ac3de423":{"id":"com.apple.finder_prohibitconnectto","displayName":"Prohibit Connect To","description":"If true, prohibits users from using a dialog that lets them view, select, or manually connect to servers on the local network or on the internet.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitconnectto_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitconnectto_true","displayName":"True","description":null,"helpText":null}]},"31a069d29522ad78":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"310616b585e4ef12":{"id":"com.apple.managedclient.preferences_configureshare","displayName":"Configure the Share experience","description":"If you set this policy to 'ShareAllowed' (the default), users will be able to access the Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\n\nIf you set this policy to 'ShareDisallowed', users won't be able to access the Share experience. If the Share button is on the toolbar, it will also be hidden.\n\nPolicy options mapping:\n\n* ShareAllowed (0) = Allow using the Share experience\n\n* ShareDisallowed (1) = Don't allow using the Share experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configureshare"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configureshare_0","displayName":"Allow using the Share experience","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configureshare_1","displayName":"Don't allow using the Share experience","description":null,"helpText":null}]},"311277c1cd0454c9":{"id":"com.apple.managedclient.preferences_showdocstageonlaunch","displayName":"Show Template Gallery on app launch","description":"Show the template picker when launching Word, Excel, and PowerPoint.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_showdocstageonlaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdocstageonlaunch_true","displayName":"True","description":null,"helpText":null}]},"3117a62ae573c56a":{"id":"com.apple.mcxmenuextras_spaces.menu","displayName":"Spaces","description":"If true, enables the Spaces menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_spaces.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_spaces.menu_true","displayName":"True","description":null,"helpText":null}]},"31ff531d5cf1cf66":{"id":"com.apple.preference.security_com.apple.preference.security","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":null},"311f6f7fee17242f":{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"31fda51db74dcfa8":{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition","displayName":"Speech Recognition (deprecated)","description":"Allows the application to use the system Speech Recognition facility and to send speech data to Apple.\n\nDeprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"31ba56878c93e9b9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsingwithcopilotblocklist","displayName":"Browsing with Copilot Blocked URLs","description":"Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list.\n\nUse this policy to define exceptions to broader allowlists. For example, you can set \"BrowsingWithCopilotAllowList\" to '*' to allow all sites, and then use this policy to block access to specific URLs.\n\nThis policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.\n\nIf you don't configure this policy, no exceptions are applied to \"BrowsingWithCopilotAllowList\".\n\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored.\n\nFor information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"31643c5f042b3056":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword (users can override)","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\n\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"31e4b6c54ae224af":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled","displayName":"Clear history for IE and IE mode every time you exit","description":"This policy controls whether browsing history is deleted from Internet Explorer and Internet Explorer mode every time Microsoft Edge is closed.\n\nUsers can configure this setting in the 'Clear browsing data for Internet Explorer' option in the Privacy, search, and services menu of Settings.\n\nIf you enable this policy, Internet Explorer browsing history will be cleared on browser exit.\n\nIf you disable or don't configure this policy, Internet Explorer browsing history won't be cleared on browser exit.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"31fd1d1ecf2fe4b8":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagemanagedquicklinks_recommended","displayName":"Set new tab page quick links (users can override)","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\n\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\n\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' isn't provided, the URL is used as the default title. If 'pinned' isn't provided, the default value is false.\n\nMicrosoft Edge presents these tiles in the order listed, from left to right, with all pinned tiles displayed ahead of nonpinned tiles.\n\nIf you set this policy as mandatory, the 'pinned' field is ignored and all tiles are pinned. The tiles can't be deleted by the user and always appear at the front of the quick links list.\n\nIf you set this policy as recommended, pinned tiles remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying nonpinned links via this policy to an existing browser profile, the links don't appear at all, depending on how they rank compared to the user's browsing history.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"31812aba00625ab6":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_portrait","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_landscape","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},"316483eb22e09734":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2_1","displayName":"Enabled","description":null,"helpText":null}]},"3138261aa2e16dd3":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect","displayName":"SynAttackProtect","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect_0","displayName":"No additional protection, use default settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect_1","displayName":"Connections time out sooner if a SYN attack is detected","description":null,"helpText":null}]},"312093c5406ff8ad":{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle","displayName":"Prune non-republishing printers:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_1","displayName":"Only if Print Server is found","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_2","displayName":"Whenever printer is not found","description":null,"helpText":null}]},"31aa7adfef0bce73":{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2","displayName":"CD and DVD: Deny execute access","description":"This policy setting denies execute access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"31affa59d88cb97f":{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2","displayName":"Do not allow Inkball to run","description":"Prevents start of InkBall game.\r\n\r\nIf you enable this policy, the InkBall game will not run.\r\n\r\nIf you disable this policy, the InkBall game will run.\r\n\r\nIf you do not configure this policy, the InkBall game will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disableinkball-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2_1","displayName":"Enabled","description":null,"helpText":null}]},"31970b8ecb9149ef":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot","displayName":"Microsoft Copilot (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot_1","displayName":"True","description":null,"helpText":null}]},"31c9bd7d56372454":{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_interval","displayName":"Repeat reporting for every (days)","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},"31971574a93bf415":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},"31c8e30098e7bf59":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled","displayName":"Enable lock icon in the omnibox for secure connections","description":"This policy controls the treatment for lock icon in the omnibox.\r\nFrom Chrome M93, there is a new omnibox icon for secure connections.\r\nIf the policy is Enabled, Chrome will use the existing lock icon for secure connections.\r\nIf the policy is Disabled or not set, Chrome will use the default icon for secure connections.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3178978f88826f9d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions. Default.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block malicious downloads, uncommon or unwanted downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_4","displayName":"Block malicious downloads. Recommended.","description":null,"helpText":null}]},"3113ca9d74f08e4b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist_spellchecklanguageblacklistdesc","displayName":"Force disable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"311c2bd53e96bd0e":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},"31c5d5513b769fce":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachcount","displayName":"Reattach Count","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nWhen a VHD(x) volume is detached unexpectedly, the FSLogix system will attempt to re-attach the volume. This value specifies how many times to retry. The default value is 60 retries which is the same as \"Not Configured\".\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ReAttachRetryCount\r\nType: DWORD\r\nValues: Min = 0, Max = 600","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachcount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachcount_1","displayName":"Enabled","description":null,"helpText":null}]},"3149c98387ce8878":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"31afc41beebb1ab6":{"id":"device_vendor_msft_policy_config_kioskbrowser_defaulturl","displayName":"Default URL","description":"Configures the default URL kiosk browsers to navigate on launch and restart.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#defaulturl"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},"3101fba55b569b87":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default pop-up window setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},"3111b727284fc3ae":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_edgesidebarappurlhostforcelistdesc","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"311dfe505289e85e":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"31e22e2185be197b":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled","displayName":"Always open links from certain Microsoft apps in Microsoft Edge","description":"Make Microsoft Edge open links from other supported Microsoft Apps, such as Microsoft Outlook and Microsoft Teams on Windows 10 and above, so that web links can be opened using the correct profile in Microsoft Edge. This does not change the browser set as the default in Windows settings.\r\n\r\nIf you do not configure this policy, the end user will see a prompt to manage this policy the first time Microsoft Edge opens a link from supported Microsoft apps. Users can manage this policy in Microsoft Edge settings at any time. The default browser setting in Windows will not be changed based on the Microsoft Edge setting.\r\n\r\nIf this policy is Enabled, Microsoft Edge will open web links from these apps, and will use the correct profile where possible, even when Microsoft Edge is not set as the default in Windows settings. This policy does not change the browser set as the default in Windows settings.\r\n\r\nIf this policy is disabled, the browser set as the default in Windows settings will be used to open web links from these apps.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"31b77784be430412":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_mse7exe125","displayName":"mse7.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_mse7exe125_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_mse7exe125_1","displayName":"True","description":null,"helpText":null}]},"3100606ed0c0442a":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_pptviewexe74","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_pptviewexe74_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_pptviewexe74_1","displayName":"True","description":null,"helpText":null}]},"31c887570a8e817f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updateblockversion_l_updateblockversionid","displayName":"Block version: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":null},"31a9520d33eec7ed":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremapplicationiduri_sharepointonpremapplicationiduribox","displayName":"Entra Application ID URI:","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"313f07822f8e69d1":{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablefamilyui","displayName":"Disable Family UI","description":"Use this policy setting if you want to disable the display of the family options area in Windows Defender Security Center. If you disable or do not configure this setting, Windows defender Security Center will display this area. Value type is integer. Supported operations are Add, Get, Replace and Delete.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsDefenderSecurityCenter#disablefamilyui"],"categoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","categoryName":"Windows Defender Security Center","options":[{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablefamilyui_0","displayName":"(Disable) The users can see the display of the family options area in Windows Defender Security Center.","description":"(Disable) The users can see the display of the family options area in Windows Defender Security Center.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablefamilyui_1","displayName":"(Enable) The users cannot see the display of the family options area in Windows Defender Security Center.","description":"(Enable) The users cannot see the display of the family options area in Windows Defender Security Center.","helpText":null}]},"3149846b54ff7be2":{"id":"device_vendor_msft_remoteremediation_cloudremediationsettings_autoremediationsettings_settimetoreboot","displayName":"Set Time To Reboot (Windows Insiders only)","description":"Refers to the time in minutes that a device will spend in the recovery environment before attempting to reboot. The maximum time to reboot possible is 72 hours, should be greater than or equal to the retry interval, and only takes effect if auto remediation is on. Otherwise an invalid argument error will be returned and no changes will be made.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/RemoteRemediation-csp/"],"categoryId":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","categoryName":"Remote Remediation","options":null},"31de01e842b29b79":{"id":"settings_item_accessibilitysettings_voiceoverenabled","displayName":"Voice Over Enabled","description":"If true, enables voiceover.","helpText":null,"infoUrls":[],"categoryId":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","categoryName":"Accessibility Settings","options":[{"id":"settings_item_accessibilitysettings_voiceoverenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_voiceoverenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"31d499caafef7455":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled","displayName":"CECPQ2 post-quantum key-agreement enabled for TLS (User)","description":"If this policy is not configured, or is set to enabled, then Google Chrome will follow the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in TLS.\r\n\r\nCECPQ2 results in larger TLS messages which, in very rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"31a16e58ec73327a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on Shutdown: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"31c0c6f7fb8fc399":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting","displayName":"Default notification setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_1","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_2","displayName":"Do not allow any site to show desktop notifications","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_3","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},"3191084bffa54428":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled","displayName":"Enable sending downloads to Google for deep scanning for users enrolled in the Advanced Protection program (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"31330bc741b2962b":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues","displayName":"Show values (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show data point values on hover\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues_1","displayName":"Enabled","description":null,"helpText":null}]},"317cd01e7e1bfc24":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"31a8c557e316f6a2":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},"31d81f238b68df16":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28_1","displayName":"True","description":null,"helpText":null}]},"31bd0ba2acbed1c4":{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter","displayName":"Allow Windows Spotlight On Action Center (User)","description":"This policy allows administrators to prevent Windows spotlight notifications from being displayed in the Action Center. If you enable this policy, Windows spotlight notifications will no longer be displayed in the Action Center. If you disable or do not configure this policy, Microsoft may display notifications in the Action Center that will suggest apps or features to help users be more productive on Windows. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightonactioncenter"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"31f1cdb4e6172b0b":{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate","displayName":"Locked-Down Trusted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},"31c8703efe1f1636":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled","displayName":"Restrict Background Fetch API when called from a Service Worker (User)","description":"This policy controls whether background fetch requests from Service Workers are restricted. If a feature that downloads files in the background is affected, this policy may be relevant.\n\nIf you enable this policy or don't configure it, the restriction is active, and background fetch requests from Service Worker contexts may be blocked.\n\nIf you disable this policy, the restriction is bypassed, allowing Service Workers to make background fetch requests.\n\nThis policy is temporary and will be removed after Microsoft Edge version 152.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3189a57971acc021":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_userdatadir","displayName":"Set the user data directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"31719f835d0f789b":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings","displayName":"Configure extension management settings (User)","description":"Configures extension management settings for Microsoft Edge.\r\n\r\nThis policy controls multiple settings, including settings controlled by any existing extension-related policies. This policy overrides any legacy policies if both are set.\r\n\r\nThis policy maps an extension ID or an update URL to its configuration. With an extension ID, the configuration is applied only to the specified extension. Set a default configuration for the special ID \"*\", to apply to all extensions that aren't specifically listed in this policy. With an update URL, the configuration is applied to all extensions with the exact update URL stated in manifest of this extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043.\r\n\r\nExample value:\r\n\r\n{\r\n \"abcdefghijklmnopabcdefghijklmnop\": {\r\n \"blocked_permissions\": [\r\n \"history\"\r\n ], \r\n \"installation_mode\": \"allowed\", \r\n \"minimum_version_required\": \"1.0.1\"\r\n }, \r\n \"bcdefghijklmnopabcdefghijklmnopa\": {\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.contoso.com\"\r\n ], \r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ], \r\n \"update_url\": \"https://contoso.com/update_url\", \r\n \"runtime_allowed_hosts\": [\r\n \"*://good.contoso.com\"\r\n ], \r\n \"installation_mode\": \"force_installed\"\r\n }, \r\n \"cdefghijklmnopabcdefghijklmnopab\": {\r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"installation_mode\": \"blocked\"\r\n }, \r\n \"*\": {\r\n \"blocked_permissions\": [\r\n \"downloads\", \r\n \"bookmarks\"\r\n ], \r\n \"installation_mode\": \"blocked\", \r\n \"runtime_blocked_hosts\": [\r\n \"*://*.contoso.com\"\r\n ], \r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"allowed_types\": [\r\n \"hosted_app\"\r\n ], \r\n \"runtime_allowed_hosts\": [\r\n \"*://good.contoso.com\"\r\n ], \r\n \"install_sources\": [\r\n \"https://company-intranet/apps\"\r\n ]\r\n }, \r\n \"defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd\": {\r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"installation_mode\": \"blocked\"\r\n }, \r\n \"fghijklmnopabcdefghijklmnopabcde\": {\r\n \"blocked_install_message\": \"Custom removal message.\", \r\n \"installation_mode\": \"removed\"\r\n }, \r\n \"update_url:https://www.contoso.com/update.xml\": {\r\n \"blocked_permissions\": [\r\n \"wallpaper\"\r\n ], \r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ], \r\n \"installation_mode\": \"allowed\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"31ba1dd15e5b88fd":{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled","displayName":"Wallet Donation Enabled (User)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\r\n\r\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\r\n\r\nIf you disable this policy, users can't use the Wallet Donation feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"31019e7fb3c3d76f":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist","displayName":"Browsing with Copilot Allowed URLs (User)","description":"Allows you to define a list of URLs where browsing with Copilot is available. Users cannot modify this list.\r\n\r\nIf you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. For example, you can include '*' to allow all sites, and then use the block list to restrict access to specific URLs.\r\n\r\nYou can define exceptions based on schemes, subdomains, ports, or origins. When multiple filters apply, the most specific match determines whether a URL is allowed or blocked. The block list takes precedence over the allow list.\r\n\r\nIf you disable or do not configure this policy, browsing with Copilot is unavailable on all sites, even if the 'AllowBrowsingWithCopilot' (Controls the availability of browsing with Copilot in Microsoft Edge.) policy is enabled.\r\n\r\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. This policy applies only to the site origin; any path specified in the URL pattern is ignored. For guidance on formatting URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu\r\ncontoso.net\r\nlogin.contoso.us","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"31f2d4de7d5ff614":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia","displayName":"English (Australia) (User)","description":"Enables the editing language English (Australia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia_1","displayName":"Enabled","description":null,"helpText":null}]},"31cf52d755d97726":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits","displayName":"Configure invalid RSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid because of the number of RSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as invalid in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as invalid because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum RSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_1","displayName":"Enabled","description":null,"helpText":null}]},"31f77081d7d81e0c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_pathcolon258","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"31bfcd44047ecee9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309_1","displayName":"True","description":null,"helpText":null}]},"31982ce549aee9b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode","displayName":"Hebrew mode (User)","description":"Specifies the script to use for checking spelling of Hebrew text. This option is available only if you are using a right-to-left language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for that language, and have enabled support for the language through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_1","displayName":"Enabled","description":null,"helpText":null}]},"31a00bae258b7c26":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages","displayName":"Do not allow Home Page URL to be set in folder Properties (User)","description":"By default, users can set a URL to be used as the Home Page for a folder by entering the URL on the Home Page tab on the folder's Properties dialog box. By enabling this setting, you can disallow setting Folder Home Pages for all folders.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages_1","displayName":"Enabled","description":null,"helpText":null}]},"3122a44d455ec016":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_l_empty76","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":null},"31bf25084b3e8db2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules","displayName":"Outlook Protection Rules (User)","description":"This policy setting controls whether the Outlook Protection Rules add-in is enabled.\r\n\r\nIf you enable or do not configure this policy setting the add-in automatically downloads Outlook Protection Rules from Exchange and processes them when each Exchange mailbox user composes a new e-mail. \r\n\r\nIf you disable this policy setting the add-in does not download or process Outlook Protection Rules.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules_1","displayName":"Enabled","description":null,"helpText":null}]},"31bf2f259ee8cb77":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms","displayName":"Run Programs (User)","description":"This policy setting controls the prompting and activation behavior for the \"Run Programs\" option for action buttons in PowerPoint.\r\n\r\nIf you enable this policy setting, you can choose from three options to control how the \"Run Programs\" option functions:\r\n\r\n- Disable (don't run any programs). If users click an action button with the \"Run Programs\" action assigned to it, nothing will happen. This option enforces the default configuration in PowerPoint.\r\n\r\n- Enable (prompt user before running). If users click an action button with the \"Run Programs\" action assigned to it, PowerPoint will prompt them to continue before running the program.\r\n\r\n- Enable all (run without prompting). If users click an action button with the \"Run Programs\" action assigned to it. PowerPoint will run the program automatically, without prompting.\r\n\r\nIf you disable or do not configure this policy setting, if users click an action with the \"Run Programs\" action assigned to it, nothing will happen. This behavior is the same as Enabled -- Disable (don't run any programs).","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"3118dcbce1b0b918":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew","displayName":"Automatically add new resources and tasks (User)","description":"Automatically adds new resources to the resource pool and assigns them default values whenever a new resource name or new resource's initials are added.\r\n \r\nIf you enable this setting, new resources and tasks are automatically inserted into the project.\r\n\r\nIf you disable this setting, users are alerted whenever a new resource or task is created when making a new assignment.\r\n\r\nIf you do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew_1","displayName":"Enabled","description":null,"helpText":null}]},"31cac6c5dfd3b622":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"319ec6ea54fb9189":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_name","displayName":"Name","description":"Specifies the friendly name of the Hyper-V Firewall rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file +{"31b581a1d5323819":{"id":"com.android.devicerestrictionpolicy.passwordminimumnumericcharacters","displayName":"Number of numeric characters required","description":"Enter the number of numeric characters (1, 2, 3, and so on) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"3195d15a91aa9a65":{"id":"com.apple.applicationaccess_ratingtvshowsgb","displayName":"Rating TV Shows - Great Britain","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsgb_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsgb_1","displayName":"Caution","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsgb_2","displayName":"All","description":null,"helpText":null}]},"3134a25813310af5":{"id":"com.apple.carddav.account_com.apple.carddav.account","displayName":"Top Level Setting Group Collection","description":"com.apple.carddav.account","helpText":null,"infoUrls":[],"categoryId":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","categoryName":"Carddav","options":null},"312b9ec3ac3de423":{"id":"com.apple.finder_prohibitconnectto","displayName":"Prohibit Connect To","description":"If true, prohibits users from using a dialog that lets them view, select, or manually connect to servers on the local network or on the internet.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitconnectto_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitconnectto_true","displayName":"True","description":null,"helpText":null}]},"31a069d29522ad78":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"310616b585e4ef12":{"id":"com.apple.managedclient.preferences_configureshare","displayName":"Configure the Share experience","description":"If you set this policy to 'ShareAllowed' (the default), users will be able to access the Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\n\nIf you set this policy to 'ShareDisallowed', users won't be able to access the Share experience. If the Share button is on the toolbar, it will also be hidden.\n\nPolicy options mapping:\n\n* ShareAllowed (0) = Allow using the Share experience\n\n* ShareDisallowed (1) = Don't allow using the Share experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configureshare"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configureshare_0","displayName":"Allow using the Share experience","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configureshare_1","displayName":"Don't allow using the Share experience","description":null,"helpText":null}]},"311277c1cd0454c9":{"id":"com.apple.managedclient.preferences_showdocstageonlaunch","displayName":"Show Template Gallery on app launch","description":"Show the template picker when launching Word, Excel, and PowerPoint.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_showdocstageonlaunch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdocstageonlaunch_true","displayName":"True","description":null,"helpText":null}]},"3117a62ae573c56a":{"id":"com.apple.mcxmenuextras_spaces.menu","displayName":"Spaces","description":"If true, enables the Spaces menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_spaces.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_spaces.menu_true","displayName":"True","description":null,"helpText":null}]},"31ff531d5cf1cf66":{"id":"com.apple.preference.security_com.apple.preference.security","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":null},"311f6f7fee17242f":{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_screencapture_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"31fda51db74dcfa8":{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition","displayName":"Speech Recognition (deprecated)","description":"Allows the application to use the system Speech Recognition facility and to send speech data to Apple.\n\nDeprecated: use the `Privacy` key in the declarative management `com.apple.configuration.app-settings` configuration.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"31ba56878c93e9b9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsingwithcopilotblocklist","displayName":"Browsing with Copilot Blocked URLs","description":"Controls the list of URLs where browsing with Copilot is blocked. Users can't modify this list.\n\nUse this policy to define exceptions to broader allowlists. For example, you can set \"BrowsingWithCopilotAllowList\" to '*' to allow all sites, and then use this policy to block access to specific URLs.\n\nThis policy supports blocking by scheme, subdomain, or port. When multiple URL patterns apply, the most specific match determines whether access is allowed or blocked. Blocklist entries take precedence over allowlist entries.\n\nIf you don't configure this policy, no exceptions are applied to \"BrowsingWithCopilotAllowList\".\n\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. URL matching is based on the site origin only; any path specified in the pattern is ignored.\n\nFor information about URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"31643c5f042b3056":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword (users can override)","description":"Specifies the keyword, which is the shortcut used in the Address Bar to trigger the search for this provider.\n\nThis policy is optional. If you don't configure it, no keyword activates the search provider.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"31e4b6c54ae224af":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled","displayName":"Clear history for IE and IE mode every time you exit","description":"This policy controls whether browsing history is deleted from Internet Explorer and Internet Explorer mode every time Microsoft Edge is closed.\n\nUsers can configure this setting in the 'Clear browsing data for Internet Explorer' option in the Privacy, search, and services menu of Settings.\n\nIf you enable this policy, Internet Explorer browsing history will be cleared on browser exit.\n\nIf you disable or don't configure this policy, Internet Explorer browsing history won't be cleared on browser exit.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodecleardataonexitenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"31fd1d1ecf2fe4b8":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagemanagedquicklinks_recommended","displayName":"Set new tab page quick links (users can override)","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\n\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\n\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' isn't provided, the URL is used as the default title. If 'pinned' isn't provided, the default value is false.\n\nMicrosoft Edge presents these tiles in the order listed, from left to right, with all pinned tiles displayed ahead of nonpinned tiles.\n\nIf you set this policy as mandatory, the 'pinned' field is ignored and all tiles are pinned. The tiles can't be deleted by the user and always appear at the front of the quick links list.\n\nIf you set this policy as recommended, pinned tiles remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying nonpinned links via this policy to an existing browser profile, the links don't appear at all, depending on how they rank compared to the user's browsing history.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"31812aba00625ab6":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout","displayName":"Sets layout for printing","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_portrait","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_landscape","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},"3147840327f53e29":{"id":"device_vendor_msft_maintenancewindows_weeklydayselection","displayName":"Weekly – Day selection","description":"Select the days of the week on which the maintenance window should repeat.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_4","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_8","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_16","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_32","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weeklydayselection_64","displayName":"Saturday","description":null,"helpText":null}]},"316483eb22e09734":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-2"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_2_1","displayName":"Enabled","description":null,"helpText":null}]},"3138261aa2e16dd3":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect","displayName":"SynAttackProtect","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect_0","displayName":"No additional protection, use default settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_synattackprotect_synattackprotect_1","displayName":"Connections time out sooner if a SYN attack is detected","description":null,"helpText":null}]},"312093c5406ff8ad":{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle","displayName":"Prune non-republishing printers:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_1","displayName":"Only if Print Server is found","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_prunedownlevel_prunedownleveltitle_2","displayName":"Whenever printer is not found","description":null,"helpText":null}]},"31aa7adfef0bce73":{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2","displayName":"CD and DVD: Deny execute access","description":"This policy setting denies execute access to the CD and DVD removable storage class.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-cdanddvd-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_cdanddvd_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"31affa59d88cb97f":{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2","displayName":"Do not allow Inkball to run","description":"Prevents start of InkBall game.\r\n\r\nIf you enable this policy, the InkBall game will not run.\r\n\r\nIf you disable this policy, the InkBall game will run.\r\n\r\nIf you do not configure this policy, the InkBall game will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disableinkball-2"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_disableinkball_2_1","displayName":"Enabled","description":null,"helpText":null}]},"31970b8ecb9149ef":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot","displayName":"Microsoft Copilot (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_copilot_1","displayName":"True","description":null,"helpText":null}]},"31c9bd7d56372454":{"id":"device_vendor_msft_policy_config_appvirtualization_allowreportingserver_interval","displayName":"Repeat reporting for every (days)","description":"","helpText":"","infoUrls":[],"categoryId":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","categoryName":"Reporting","options":null},"31971574a93bf415":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options","displayName":"Global Publishing Refresh On Logon","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver5_global_refresh_onlogon_options_1","displayName":"True","description":null,"helpText":null}]},"31c8e30098e7bf59":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled","displayName":"Enable lock icon in the omnibox for secure connections","description":"This policy controls the treatment for lock icon in the omnibox.\r\nFrom Chrome M93, there is a new omnibox icon for secure connections.\r\nIf the policy is Enabled, Chrome will use the existing lock icon for secure connections.\r\nIf the policy is Disabled or not set, Chrome will use the default icon for secure connections.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lockiconinaddressbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3178978f88826f9d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions. Default.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block malicious downloads, uncommon or unwanted downloads and dangerous file types.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_downloadrestrictions_4","displayName":"Block malicious downloads. Recommended.","description":null,"helpText":null}]},"3113ca9d74f08e4b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_spellchecklanguageblacklist_spellchecklanguageblacklistdesc","displayName":"Force disable spellcheck languages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"311c2bd53e96bd0e":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},"31c5d5513b769fce":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachcount","displayName":"Reattach Count","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nWhen a VHD(x) volume is detached unexpectedly, the FSLogix system will attempt to re-attach the volume. This value specifies how many times to retry. The default value is 60 retries which is the same as \"Not Configured\".\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ReAttachRetryCount\r\nType: DWORD\r\nValues: Min = 0, Max = 600","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachcount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachcount_1","displayName":"Enabled","description":null,"helpText":null}]},"3149c98387ce8878":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"31afc41beebb1ab6":{"id":"device_vendor_msft_policy_config_kioskbrowser_defaulturl","displayName":"Default URL","description":"Configures the default URL kiosk browsers to navigate on launch and restart.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#defaulturl"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},"3101fba55b569b87":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default pop-up window setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},"3111b727284fc3ae":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_edgesidebarappurlhostforcelistdesc","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"311dfe505289e85e":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"31e22e2185be197b":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled","displayName":"Always open links from certain Microsoft apps in Microsoft Edge","description":"Make Microsoft Edge open links from other supported Microsoft Apps, such as Microsoft Outlook and Microsoft Teams on Windows 10 and above, so that web links can be opened using the correct profile in Microsoft Edge. This does not change the browser set as the default in Windows settings.\r\n\r\nIf you do not configure this policy, the end user will see a prompt to manage this policy the first time Microsoft Edge opens a link from supported Microsoft apps. Users can manage this policy in Microsoft Edge settings at any time. The default browser setting in Windows will not be changed based on the Microsoft Edge setting.\r\n\r\nIf this policy is Enabled, Microsoft Edge will open web links from these apps, and will use the correct profile where possible, even when Microsoft Edge is not set as the default in Windows settings. This policy does not change the browser set as the default in Windows settings.\r\n\r\nIf this policy is disabled, the browser set as the default in Windows settings will be used to open web links from these apps.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_openmicrosoftlinksinedgeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"31b77784be430412":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_mse7exe125","displayName":"mse7.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_mse7exe125_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_mse7exe125_1","displayName":"True","description":null,"helpText":null}]},"3100606ed0c0442a":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_pptviewexe74","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_pptviewexe74_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_pptviewexe74_1","displayName":"True","description":null,"helpText":null}]},"31c887570a8e817f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updateblockversion_l_updateblockversionid","displayName":"Block version: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":null},"31a9520d33eec7ed":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremapplicationiduri_sharepointonpremapplicationiduribox","displayName":"Entra Application ID URI:","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"313f07822f8e69d1":{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablefamilyui","displayName":"Disable Family UI","description":"Use this policy setting if you want to disable the display of the family options area in Windows Defender Security Center. If you disable or do not configure this setting, Windows defender Security Center will display this area. Value type is integer. Supported operations are Add, Get, Replace and Delete.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsDefenderSecurityCenter#disablefamilyui"],"categoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","categoryName":"Windows Defender Security Center","options":[{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablefamilyui_0","displayName":"(Disable) The users can see the display of the family options area in Windows Defender Security Center.","description":"(Disable) The users can see the display of the family options area in Windows Defender Security Center.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablefamilyui_1","displayName":"(Enable) The users cannot see the display of the family options area in Windows Defender Security Center.","description":"(Enable) The users cannot see the display of the family options area in Windows Defender Security Center.","helpText":null}]},"3149846b54ff7be2":{"id":"device_vendor_msft_remoteremediation_cloudremediationsettings_autoremediationsettings_settimetoreboot","displayName":"Set Time To Reboot (Windows Insiders only)","description":"Refers to the time in minutes that a device will spend in the recovery environment before attempting to reboot. The maximum time to reboot possible is 72 hours, should be greater than or equal to the retry interval, and only takes effect if auto remediation is on. Otherwise an invalid argument error will be returned and no changes will be made.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/RemoteRemediation-csp/"],"categoryId":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","categoryName":"Remote Remediation","options":null},"31de01e842b29b79":{"id":"settings_item_accessibilitysettings_voiceoverenabled","displayName":"Voice Over Enabled","description":"If true, enables voiceover.","helpText":null,"infoUrls":[],"categoryId":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","categoryName":"Accessibility Settings","options":[{"id":"settings_item_accessibilitysettings_voiceoverenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_voiceoverenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"31d499caafef7455":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled","displayName":"CECPQ2 post-quantum key-agreement enabled for TLS (User)","description":"If this policy is not configured, or is set to enabled, then Google Chrome will follow the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in TLS.\r\n\r\nCECPQ2 results in larger TLS messages which, in very rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"31a16e58ec73327a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on Shutdown: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"31c0c6f7fb8fc399":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting","displayName":"Default notification setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_1","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_2","displayName":"Do not allow any site to show desktop notifications","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_defaultnotificationssetting_3","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},"3191084bffa54428":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled","displayName":"Enable sending downloads to Google for deep scanning for users enrolled in the Advanced Protection program (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"31330bc741b2962b":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues","displayName":"Show values (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show data point values on hover\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showvalues_1","displayName":"Enabled","description":null,"helpText":null}]},"317cd01e7e1bfc24":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_l_webpagesandexcel2003xmlspreadsheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"31a8c557e316f6a2":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04","displayName":"Trusted Location #4 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_1","displayName":"Enabled","description":null,"helpText":null}]},"31d81f238b68df16":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders28_1","displayName":"True","description":null,"helpText":null}]},"31bd0ba2acbed1c4":{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter","displayName":"Allow Windows Spotlight On Action Center (User)","description":"This policy allows administrators to prevent Windows spotlight notifications from being displayed in the Action Center. If you enable this policy, Windows spotlight notifications will no longer be displayed in the Action Center. If you disable or do not configure this policy, Microsoft may display notifications in the Action Center that will suggest apps or features to help users be more productive on Windows. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlightonactioncenter"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlightonactioncenter_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"31f1cdb4e6172b0b":{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate","displayName":"Locked-Down Trusted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowslockeddowntrustedsiteszonetemplate_iz_partnametrustedsiteszonelockdowntemplate_4","displayName":"High","description":null,"helpText":null}]},"31c8703efe1f1636":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled","displayName":"Restrict Background Fetch API when called from a Service Worker (User)","description":"This policy controls whether background fetch requests from Service Workers are restricted. If a feature that downloads files in the background is affected, this policy may be relevant.\n\nIf you enable this policy or don't configure it, the restriction is active, and background fetch requests from Service Worker contexts may be blocked.\n\nIf you disable this policy, the restriction is bypassed, allowing Service Workers to make background fetch requests.\n\nThis policy is temporary and will be removed after Microsoft Edge version 152.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_restrictbackgroundfetchfromserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3189a57971acc021":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_userdatadir","displayName":"Set the user data directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"31719f835d0f789b":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings","displayName":"Configure extension management settings (User)","description":"Configures extension management settings for Microsoft Edge.\r\n\r\nThis policy controls multiple settings, including settings controlled by any existing extension-related policies. This policy overrides any legacy policies if both are set.\r\n\r\nThis policy maps an extension ID or an update URL to its configuration. With an extension ID, the configuration is applied only to the specified extension. Set a default configuration for the special ID \"*\", to apply to all extensions that aren't specifically listed in this policy. With an update URL, the configuration is applied to all extensions with the exact update URL stated in manifest of this extension, as described at https://go.microsoft.com/fwlink/?linkid=2095043.\r\n\r\nExample value:\r\n\r\n{\r\n \"abcdefghijklmnopabcdefghijklmnop\": {\r\n \"blocked_permissions\": [\r\n \"history\"\r\n ], \r\n \"installation_mode\": \"allowed\", \r\n \"minimum_version_required\": \"1.0.1\"\r\n }, \r\n \"bcdefghijklmnopabcdefghijklmnopa\": {\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.contoso.com\"\r\n ], \r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ], \r\n \"update_url\": \"https://contoso.com/update_url\", \r\n \"runtime_allowed_hosts\": [\r\n \"*://good.contoso.com\"\r\n ], \r\n \"installation_mode\": \"force_installed\"\r\n }, \r\n \"cdefghijklmnopabcdefghijklmnopab\": {\r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"installation_mode\": \"blocked\"\r\n }, \r\n \"*\": {\r\n \"blocked_permissions\": [\r\n \"downloads\", \r\n \"bookmarks\"\r\n ], \r\n \"installation_mode\": \"blocked\", \r\n \"runtime_blocked_hosts\": [\r\n \"*://*.contoso.com\"\r\n ], \r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"allowed_types\": [\r\n \"hosted_app\"\r\n ], \r\n \"runtime_allowed_hosts\": [\r\n \"*://good.contoso.com\"\r\n ], \r\n \"install_sources\": [\r\n \"https://company-intranet/apps\"\r\n ]\r\n }, \r\n \"defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd\": {\r\n \"blocked_install_message\": \"Custom error message.\", \r\n \"installation_mode\": \"blocked\"\r\n }, \r\n \"fghijklmnopabcdefghijklmnopabcde\": {\r\n \"blocked_install_message\": \"Custom removal message.\", \r\n \"installation_mode\": \"removed\"\r\n }, \r\n \"update_url:https://www.contoso.com/update.xml\": {\r\n \"blocked_permissions\": [\r\n \"wallpaper\"\r\n ], \r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ], \r\n \"installation_mode\": \"allowed\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"31ba1dd15e5b88fd":{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled","displayName":"Wallet Donation Enabled (User)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\r\n\r\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\r\n\r\nIf you disable this policy, users can't use the Wallet Donation feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_walletdonationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"31019e7fb3c3d76f":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist","displayName":"Browsing with Copilot Allowed URLs (User)","description":"Allows you to define a list of URLs where browsing with Copilot is available. Users cannot modify this list.\r\n\r\nIf you enable this policy, browsing with Copilot is available only on the sites specified in the list. To allow a broader set of sites while blocking specific exceptions, configure this policy together with the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. For example, you can include '*' to allow all sites, and then use the block list to restrict access to specific URLs.\r\n\r\nYou can define exceptions based on schemes, subdomains, ports, or origins. When multiple filters apply, the most specific match determines whether a URL is allowed or blocked. The block list takes precedence over the allow list.\r\n\r\nIf you disable or do not configure this policy, browsing with Copilot is unavailable on all sites, even if the 'AllowBrowsingWithCopilot' (Controls the availability of browsing with Copilot in Microsoft Edge.) policy is enabled.\r\n\r\nBrowsing with Copilot supports only HTTP and HTTPS protocols. Wildcards (*) are supported, and subdomains are matched even without wildcards. This policy applies only to the site origin; any path specified in the URL pattern is ignored. For guidance on formatting URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu\r\ncontoso.net\r\nlogin.contoso.us","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"31f2d4de7d5ff614":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia","displayName":"English (Australia) (User)","description":"Enables the editing language English (Australia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishaustralia_1","displayName":"Enabled","description":null,"helpText":null}]},"31cf52d755d97726":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits","displayName":"Configure invalid RSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid because of the number of RSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as invalid in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as invalid because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum RSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvalidrsabits_1","displayName":"Enabled","description":null,"helpText":null}]},"31f77081d7d81e0c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_pathcolon258","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"31bfcd44047ecee9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc18_l_allowsubfolders309_1","displayName":"True","description":null,"helpText":null}]},"31982ce549aee9b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode","displayName":"Hebrew mode (User)","description":"Specifies the script to use for checking spelling of Hebrew text. This option is available only if you are using a right-to-left language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for that language, and have enabled support for the language through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_hebrewmode_1","displayName":"Enabled","description":null,"helpText":null}]},"31a00bae258b7c26":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages","displayName":"Do not allow Home Page URL to be set in folder Properties (User)","description":"By default, users can set a URL to be used as the Home Page for a folder by entering the URL on the Home Page tab on the folder's Properties dialog box. By enabling this setting, you can disallow setting Folder Home Pages for all folders.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_disablefolderhomepages_1","displayName":"Enabled","description":null,"helpText":null}]},"3122a44d455ec016":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_lockedformregions_l_empty76","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":null},"31bf25084b3e8db2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules","displayName":"Outlook Protection Rules (User)","description":"This policy setting controls whether the Outlook Protection Rules add-in is enabled.\r\n\r\nIf you enable or do not configure this policy setting the add-in automatically downloads Outlook Protection Rules from Exchange and processes them when each Exchange mailbox user composes a new e-mail. \r\n\r\nIf you disable this policy setting the add-in does not download or process Outlook Protection Rules.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_outlookprotectionrules_1","displayName":"Enabled","description":null,"helpText":null}]},"31bf2f259ee8cb77":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms","displayName":"Run Programs (User)","description":"This policy setting controls the prompting and activation behavior for the \"Run Programs\" option for action buttons in PowerPoint.\r\n\r\nIf you enable this policy setting, you can choose from three options to control how the \"Run Programs\" option functions:\r\n\r\n- Disable (don't run any programs). If users click an action button with the \"Run Programs\" action assigned to it, nothing will happen. This option enforces the default configuration in PowerPoint.\r\n\r\n- Enable (prompt user before running). If users click an action button with the \"Run Programs\" action assigned to it, PowerPoint will prompt them to continue before running the program.\r\n\r\n- Enable all (run without prompting). If users click an action button with the \"Run Programs\" action assigned to it. PowerPoint will run the program automatically, without prompting.\r\n\r\nIf you disable or do not configure this policy setting, if users click an action with the \"Run Programs\" action assigned to it, nothing will happen. This behavior is the same as Enabled -- Disable (don't run any programs).","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"3118dcbce1b0b918":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew","displayName":"Automatically add new resources and tasks (User)","description":"Automatically adds new resources to the resource pool and assigns them default values whenever a new resource name or new resource's initials are added.\r\n \r\nIf you enable this setting, new resources and tasks are automatically inserted into the project.\r\n\r\nIf you disable this setting, users are alerted whenever a new resource or task is created when making a new assignment.\r\n\r\nIf you do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","categoryName":"General options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneraloptions_l_pjautoaddnew_1","displayName":"Enabled","description":null,"helpText":null}]},"31cac6c5dfd3b622":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"319ec6ea54fb9189":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_name","displayName":"Name","description":"Specifies the friendly name of the Hyper-V Firewall rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/33.json b/public/intune-definitions/33.json index 6b31d9025235..902077a9e9e7 100644 --- a/public/intune-definitions/33.json +++ b/public/intune-definitions/33.json @@ -1 +1 @@ -{"3382ef6813fc3421":{"id":"app_allowed_deniedbinaries_item_signingstate","displayName":"Signing State","description":"The code signing state to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_allowed_deniedbinaries_item_signingstate_0","displayName":"All","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_1","displayName":"TestFlight","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_2","displayName":"DeveloperID","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_3","displayName":"Enterprise","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_4","displayName":"AppStore","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_5","displayName":"Apple","description":null,"helpText":null}]},"335efc04d75bb613":{"id":"com.android.devicerestrictionpolicy.dataroamingblocked","displayName":"Block roaming data services","description":"If 'True', prevents data roaming over the cellular network. If 'False', Intune doesn't change or update this setting. By default, the OS might allow data roaming when the device is on a cellular network. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.dataroamingblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.dataroamingblocked_false","displayName":"False","description":"false","helpText":null}]},"33d355b4064e2cf4":{"id":"com.apple.applicationaccess_allowitunesfilesharing","displayName":"Allow iTunes File Sharing","description":"If false, disables iTunes file sharing services. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowitunesfilesharing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowitunesfilesharing_true","displayName":"True","description":null,"helpText":null}]},"33dc81f4d70c61b0":{"id":"com.apple.applicationaccess_safariallowjavascript","displayName":"Safari Allow Java Script","description":"If false, Safari doesn’t execute JavaScript. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariallowjavascript_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariallowjavascript_true","displayName":"True","description":null,"helpText":null}]},"33ed7f5344280623":{"id":"com.apple.caldav.account_caldavprincipalurl","displayName":"Cal DAV Principal URL","description":"The base URL to the user’s calendar.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},"332c67f6562f8746":{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos","displayName":"Require TLS For LDAP","description":"Require that LDAP connections use TLS. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos_true","displayName":"True","description":null,"helpText":null}]},"33641c8d647442f6":{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_lcid","displayName":"Microsoft AutoUpdate LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"331b82a66457fcff":{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgewalletetreeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"33aaf3e02a99b8dd":{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled","displayName":"Configure Microsoft Edge scareware blocker to block sites detected as potential tech scams","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\n\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\n\nIf you enable or don't configure this policy, Microsoft Edge blocks sites detected as potential tech scams.\n\nIf you disable this policy, Microsoft Edge doesn't block sites detected as potential tech scams.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerblocksdetectedsitesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"33ebc75213360699":{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates","displayName":"Automatically Install Mac OS Updates (Deprecated)","description":"If false, restricts the \"Install macOS Updates\" option and prevents the user from changing the option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates_true","displayName":"True","description":null,"helpText":null}]},"3335f28d23c31bcc":{"id":"com.apple.systempolicy.managed_disableoverride","displayName":"Disable Override","description":"If true, disables the Finder's contextual menu item.","helpText":null,"infoUrls":[],"categoryId":"64538726-8745-4e7a-b370-332f725b58bf","categoryName":"System Policy Managed","options":[{"id":"com.apple.systempolicy.managed_disableoverride_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.managed_disableoverride_true","displayName":"True","description":null,"helpText":null}]},"3307743cdfe1324b":{"id":"com.apple.webcontent-filter_filterbrowsers","displayName":"Filter Browsers","description":"If true, enables the filtering of WebKit traffic.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filterbrowsers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filterbrowsers_true","displayName":"True","description":null,"helpText":null}]},"336854e0d708020e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended","displayName":"Allow features to download assets from the Asset Delivery Service (users can override)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"334b61259066d15c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass","displayName":"Allow users to bypass Enhanced Security Mode","description":"Microsoft Edge lets users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode.\n\nIf you disable this policy, Microsoft Edge can't allow users to bypass Enhanced Security Mode.\n\nIf you enable or don't configure this policy, Microsoft Edge allows users to bypass Enhanced Security Mode.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass_true","displayName":"Enabled","description":null,"helpText":null}]},"33448f1b0808023f":{"id":"device_vendor_msft_laps_policies_passphraselength","displayName":"Passphrase Length","description":"Use this setting to configure the number of passphrase words.\n\nIf not specified, this setting will default to 6 words\n\nThis setting has a minimum allowed value of 3 words.\n\nThis setting has a maximum allowed value of 10 words.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},"33c17f08a36b3e3a":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext","displayName":"Display a custom message when installation is prevented by a policy setting","description":"This policy setting allows you to display a custom message to users in a notification when a device installation is attempted and a policy setting prevents the installation.\r\n\r\nIf you enable this policy setting, Windows displays the text you type in the Detail Text box when a policy setting prevents device installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows displays a default message when a policy setting prevents device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-deniedpolicy-detailtext"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_1","displayName":"Enabled","description":null,"helpText":null}]},"333ea12d9e94690a":{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitvalue","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":null},"3375dfd5e429f19f":{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs","displayName":"Allow job name in event logs","description":"\r\n This policy controls whether the print job name will be included in print event logs.\r\n\r\n If you disable or do not configure this policy setting, the print job name will not be included.\r\n\r\n If you enable this policy setting, the print job name will be included in new log entries.\r\n\r\n Note: This setting does not apply to Branch Office Direct Printing jobs.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-showjobtitleineventlogs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs_1","displayName":"Enabled","description":null,"helpText":null}]},"33bbabc4d9c3fb3c":{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2_customclasses_list","displayName":"GUID for custom removable storage class:","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},"33abded35a15f459":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete","displayName":"Do not delete temp folders upon exit","description":"This policy setting specifies whether Remote Desktop Services retains a user's per-session temporary folders at logoff.\r\n\r\nYou can use this setting to maintain a user's session-specific temporary folders on a remote computer, even if the user logs off from a session. By default, Remote Desktop Services deletes a user's temporary folders when the user logs off.\r\n\r\nIf you enable this policy setting, a user's per-session temporary folders are retained when the user logs off from a session.\r\n\r\nIf you disable this policy setting, temporary folders are deleted when a user logs off, even if the server administrator specifies otherwise.\r\n\r\nIf you do not configure this policy setting, Remote Desktop Services deletes the temporary folders from the remote computer at logoff, unless specified otherwise by the server administrator.\r\n\r\nNote: This setting only takes effect if per-session temporary folders are in use on the server. If you enable the Do not use temporary folders per session policy setting, this policy setting has no effect.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-temp-delete"],"categoryId":"b40b8f80-c0e6-4494-8085-f90cadc167a9","categoryName":"Temporary folders","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete_1","displayName":"Enabled","description":null,"helpText":null}]},"33ceb505b9a44e0b":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs","displayName":"Verify old and new Folder Redirection targets point to the same share before redirecting","description":"This policy setting allows you to prevent data loss when you change the target location for Folder Redirection, and the new and old targets point to the same network share, but have different network paths.\r\n\r\nIf you enable this policy setting, Folder Redirection creates a temporary file in the old location in order to verify that new and old locations point to the same network share. If both new and old locations point to the same share, the target path is updated and files are not copied or deleted. The temporary file is deleted.\r\n\r\nIf you disable or do not configure this policy setting, Folder Redirection does not create a temporary file and functions as if both new and old locations point to different shares when their network paths are different.\r\n\r\nNote: If the paths point to different network shares, this policy setting is not required. If the paths point to the same network share, any data contained in the redirected folders is deleted if this policy setting is not enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-checksamesourceandtargetforfranddfs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs_1","displayName":"Enabled","description":null,"helpText":null}]},"33561f777e2416e3":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},"33132d429b976253":{"id":"device_vendor_msft_policy_config_browser_allowautofill","displayName":"Allow Autofill","description":"This setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowautofill"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowautofill_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowautofill_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"3390a204ccf22107":{"id":"device_vendor_msft_policy_config_browser_setnewtabpageurl","displayName":"Set New Tab Page URL","description":"You can set the default New Tab page URL in Microsoft Edge. Enabling this policy prevents your users from changing the New tab page setting. When enabled and the Allow web content on New Tab page policy is disabled, Microsoft Edge ignores the URL specified in this policy and opens about:blank. If enabled, you can set the default New Tab page URL. If disabled or not configured, the default Microsoft Edge new tab page is used. Default setting: Disabled or not configured Related policy: Allow web content on New Tab page","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#setnewtabpageurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"333a78c980e20a06":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed","displayName":"Allow users to opt in to Safe Browsing extended reporting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"33b329dbc632fb39":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfclockedretrycount_odfclockedretrycount","displayName":"Locked Retry Count (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":null},"33111a08af830fe1":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvhdlocations","displayName":"VHD Locations","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies the network location where the VHD(X) files are stored.\r\n\r\nExamples:\r\n- Sinlge location: \\\\\\\r\n- Multiple locations: \\\\\\;\\\\\\\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\VHDLocations\r\nREG_SZ","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvhdlocations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvhdlocations_1","displayName":"Enabled","description":null,"helpText":null}]},"3395958be7370f1d":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence","displayName":"Userdata persistence","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowuserdatapersistence"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"33542efce22aba5c":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"333545ff354d1a4d":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling","displayName":"Restrict exposure of localhost IP address by WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default_public_and_private_interfaces","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default_public_interface_only","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_disable_non_proxied_udp","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},"33ee2fe19140610f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls","displayName":"Block notifications on specific sites","description":"Define a list of sites, based on URL patterns, that are blocked from displaying notifications.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultNotificationsSetting' (Default notification setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"3394eafddcc6a375":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"332e9a49be6c090a":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_winprojexe20","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_winprojexe20_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_winprojexe20_1","displayName":"True","description":null,"helpText":null}]},"330d65a746792314":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_exprwdexe192","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_exprwdexe192_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_exprwdexe192_1","displayName":"True","description":null,"helpText":null}]},"33a61fdc496be9ff":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling","displayName":"Consistent Mime Handling","description":"Mime Handling","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_1","displayName":"Enabled","description":null,"helpText":null}]},"3395ba10bea1fe79":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_powerpntexe","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_powerpntexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_powerpntexe_1","displayName":"True","description":null,"helpText":null}]},"3315ac0d09d3086e":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_officemgmtcom","displayName":"Office 365 Client Management","description":"This policy setting enables programmatic control of Office 365 clients.\r\n\r\nIf you enable this policy, System Center Configuration Manager or other application management solutions can manage the Office 365 client. After applying the policy, you will be required to restart the Office Click-to-run service. \r\n\r\nIf you disable or do not configure this policy setting, System Center Configuration Manager update workflow will not be able to manage Office 365 clients. You will, however, be able to continue to use the Office Deployment Tool and System Center Configuration Manager’s program and packages or applications deployment methods. \r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI)","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_officemgmtcom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_officemgmtcom_1","displayName":"Enabled","description":null,"helpText":null}]},"33f6e84964d50de1":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatepath_l_updatepathid","displayName":"Location for updates: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":null},"3345b6c5e903ccfd":{"id":"device_vendor_msft_policy_config_smartscreen_enablesmartscreeninshell","displayName":"Enable Smart Screen In Shell","description":" Allows IT Admins to configure SmartScreen for Windows.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-smartscreen#enablesmartscreeninshell"],"categoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","categoryName":"Smart Screen","options":[{"id":"device_vendor_msft_policy_config_smartscreen_enablesmartscreeninshell_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_smartscreen_enablesmartscreeninshell_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"33b506e4ee333512":{"id":"device_vendor_msft_policy_config_update_engagedrestartsnoozeschedule","displayName":"Engaged Restart Snooze Schedule","description":"For Quality Updates, this policy specifies the number of days a user can snooze Engaged restart reminder notifications. The snooze period can be set between 1 and 3 days. Value type is integer. Default is 3 days. Supported value range: 1 - 3. If you disable or do not configure this policy, the default behaviors will be used. If any of the following policies are configured, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installationsAlways automatically restart at scheduled timeSpecify deadline before auto-restart for update installation","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#engagedrestartsnoozeschedule"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"33bb597b93eb0cd7":{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowuserinputfromwirelessdisplayreceiver","displayName":"Allow User Input From Wireless Display Receiver","description":"Setting this policy controls whether or not the wireless display can send input—keyboard, mouse, pen, and touch input if the display supports it—back to the source device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WirelessDisplay#allowuserinputfromwirelessdisplayreceiver"],"categoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowuserinputfromwirelessdisplayreceiver_0","displayName":"Wireless display input disabled.","description":"Wireless display input disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowuserinputfromwirelessdisplayreceiver_1","displayName":"Wireless display input enabled.","description":"Wireless display input enabled.","helpText":null}]},"3376ad96546eb141":{"id":"safari_newtabstartpage","displayName":"New Tab Start Page","description":"Sets the start page for new tabs in Safari.","helpText":null,"infoUrls":[],"categoryId":"e0ab6868-4b53-4310-b665-f7c979941db7","categoryName":"Safari Browser","options":null},"3356f15863d7e032":{"id":"user_vendor_msft_policy_config_admx_helpandsupport_hpexplicitfeedback","displayName":"Turn off Help Ratings (User)","description":"This policy setting specifies whether users can provide ratings for Help content.\r\n\r\nIf you enable this policy setting, ratings controls are not added to Help content.\r\n\r\nIf you disable or do not configure this policy setting, ratings controls are added to Help topics.\r\n\r\nUsers can use the control to provide feedback on the quality and usefulness of the Help and Support content.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-helpandsupport#admx-helpandsupport-hpexplicitfeedback"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_helpandsupport_hpexplicitfeedback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_helpandsupport_hpexplicitfeedback_1","displayName":"Enabled","description":null,"helpText":null}]},"3366580eb09a4603":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosettaskbar","displayName":"Prevent changes to Taskbar and Start Menu Settings (User)","description":"This policy setting allows you to prevent changes to Taskbar and Start Menu Settings.\r\n\r\nIf you enable this policy setting, The user will be prevented from opening the Taskbar Properties dialog box.\r\n\r\nIf the user right-clicks the taskbar and then clicks Properties, a message appears explaining that a setting prevents the action.\r\n\r\nIf you disable or do not configure this policy setting, the Taskbar and Start Menu items are available from Settings on the Start menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosettaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosettaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosettaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"33d7eae18f44f5da":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_enable_ts_gateway_override","displayName":"Allow users to change this setting (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"a561e59a-09b7-4106-a6fa-0b82036a5b49","categoryName":"RD Gateway","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_enable_ts_gateway_override_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_enable_ts_gateway_override_1","displayName":"True","description":null,"helpText":null}]},"333b8491f30df9b3":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word","displayName":"Microsoft Word 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft Word 2010.\r\nBy default, the user settings of Microsoft Word 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word_1","displayName":"Enabled","description":null,"helpText":null}]},"33616a3b5919a322":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled","displayName":"Enable component updates in Google Chrome (User)","description":"Enables component updates for all components in Google Chrome when not set or set to enabled.\r\n\r\nIf set to disabled, updates to components are disabled. However, some components are exempt from this policy: updates to any component that does not contain executable code, or does not significantly alter the behavior of the browser, or is critical for its security will not be disabled.\r\nExamples of such components include the certificate revocation lists and Safe Browsing data.\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.\r\nPlease note that setting this policy to disabled can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"33d35ccdf7035f22":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended","displayName":"Enable Safe Browsing for trusted sources (User)","description":"Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source.\r\n\r\nSetting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source.\r\n\r\nThese restrictions apply to downloads triggered from webpage content, as well as the Download link menu option. These restrictions don't apply to the save or download of the currently displayed page or to saving as PDF from the printing options.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"33dc605a82700412":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter","displayName":"Enable Google Cast (User)","description":"Setting the policy to Enabled or leaving it unset turns on Google Cast, which users can launch from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\r\n\r\nSetting the policy to Disabled turns off Google Cast.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter_1","displayName":"Enabled","description":null,"helpText":null}]},"33be1033589fcd38":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_remoteaccesshostdebugoverridepolicies","displayName":"Policy overrides for Debug builds of the remote access host (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"3343801c0c8ff2ed":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist_renderinchromeframelistdesc","displayName":"Always render the following URL patterns in Google Chrome Frame (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"33a093336780a6d1":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt","displayName":"Prompt users to re-authenticate to the profile (User)","description":"When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser.\r\n\r\nWhen set to PromptInTab, when the user's authentication expires, immediately open a new tab with the Google login page. This only happens if using Chrome Sync.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},"33049e4e27e41897":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed (User)","description":"Controls if Google Chrome interacts with printer drivers from a separate service process. Platform printing calls to query available printers, get print driver settings, and submit documents for printing to local printers are made from a service process. Moving such calls out of the browser process helps improve stability and reduce frozen UI behavior in Print Preview.\r\n\r\nWhen this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks.\r\n\r\nWhen this policy is set to Disabled, Google Chrome will use the browser process for platform printing tasks.\r\n\r\nThis policy will be removed in the future, after the out-of-process print drivers feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"33bf3b8bcff10a0f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},"33fecac801854b08":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},"3302affd6923d21d":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"3351742043003ac2":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004","displayName":"Download unsigned ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_1","displayName":"Prompt","description":null,"helpText":null}]},"3390175462b103cb":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_totalmemorylimitmb","displayName":"Set memory limit for Microsoft Edge instances: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"33c366f147f45243":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications.\r\n\r\nThis policy stopped working in Microsoft Edge 107 and was obsoleted in Microsoft Edge 110.\r\n\r\nThe display-capture permissions-policy gates access to getDisplayMedia(),\r\nas per this spec:\r\nhttps://www.w3.org/TR/screen-capture/#feature-policy-integration\r\nHowever, if this policy is Disabled, this requirement is not enforced,\r\nand getDisplayMedia() is allowed from contexts that would otherwise be\r\nforbidden.\r\n\r\nIf you enable or don't configure this policy, sites can only call getDisplayMedia() from\r\ncontexts which are allowlisted by the display-capture permissions-policy.\r\n\r\nIf you disable this policy, sites can call getDisplayMedia() even from contexts\r\nwhich are not allowlisted by the display-capture permissions policy.\r\nNote that other restrictions may still apply.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"33b22b22642c9ca0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8_1","displayName":"True","description":null,"helpText":null}]},"33b0b1b1784bbf41":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome","displayName":"Replace Label - Home (User)","description":"This policy setting allows you to change or remove the 6th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_1","displayName":"Enabled","description":null,"helpText":null}]},"33164e7c70a8f46c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_l_placesbarname219","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},"333688aa93dd56f2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin","displayName":"Display menus and dialog boxes in (User)","description":"Sets the display language of the user interface for all Office 2016 programs. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_1","displayName":"Enabled","description":null,"helpText":null}]},"33eac2f6a35f47fd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected","displayName":"Protect document metadata for password protected files (User)","description":"This policy setting determines whether metadata is encrypted when an Office Open XML file is password protected.\r\n \r\n If you enable this policy setting, Excel 2016, PowerPoint 2016, and Word 2016 encrypt metadata stored in password-protected Office Open XML files and override any configuration changes on users' computers.\r\n \r\n If you disable this policy setting, Office 2016 applications cannot encrypt metadata in password-protected Office Open XML files, which can reduce security.\r\n \r\n If you do not configure this policy setting, when an Office Open XML document is protected with a password and saved, any metadata associated with the document is encrypted along with the rest of the document's contents. If this configuration is changed, potentially sensitive information such as the document author and hyperlink references could be exposed to unauthorized people.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected_1","displayName":"Enabled","description":null,"helpText":null}]},"3326c5f873ef72f6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_pathcolon13","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"331f3499982b7b4f":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem","displayName":"Lock password protected sections as soon as I navigate away from them (User)","description":"OneNote supports password protecting sections and they are unlocked once a user types the password and can be locked again by either a timeout period or when you navigate away from the section. This option will lock the section once you navigate away from the password protected section.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem_1","displayName":"Enabled","description":null,"helpText":null}]},"33e76b999b79c8cb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan","displayName":"Indicate a missing root certificate as a(n): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_0","displayName":"Neither error nor warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_1","displayName":"Warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_2","displayName":"Error","description":null,"helpText":null}]},"3318021cf41d5db1":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},"33ea884b3e6f2bfa":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"3304180ebf2100ea":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2","displayName":"Default View (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_bar rollup","displayName":"Bar Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_calendar","displayName":"Calendar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_descriptive network diagram","displayName":"Descriptive Network Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_detail gantt","displayName":"Detail Gantt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_gantt chart","displayName":"Gantt Chart","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_leveling gantt","displayName":"Leveling Gantt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_milestone date rollup","displayName":"Milestone Date Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_milestone rollup","displayName":"Milestone Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_network diagram","displayName":"Network Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_relationship diagram","displayName":"Relationship Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource allocation","displayName":"Resource Allocation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource form","displayName":"Resource Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource graph","displayName":"Resource Graph","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource name form","displayName":"Resource Names Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource sheet","displayName":"Resource Sheet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource usage","displayName":"Resource Usage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task details form","displayName":"Task Details Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task entry","displayName":"Task Entry","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task form","displayName":"Task Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task name form","displayName":"Task Name Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task sheet","displayName":"Task Sheet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task usage","displayName":"Task Usage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_tracking gantt","displayName":"Tracking Gantt","description":null,"helpText":null}]},"3399a3566efa0799":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"331223a12fcc7865":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics","displayName":"Diacritics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics_1","displayName":"Enabled","description":null,"helpText":null}]},"33eab334ba1957de":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview","displayName":"Do not open files from the Internet zone in Protected View (User)","description":"This policy setting allows you to determine if files downloaded from the Internet zone open in Protected View.\r\n\r\nIf you enable this policy setting, files downloaded from the Internet zone do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files downloaded from the Internet zone open in Protected View.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"3382ef6813fc3421":{"id":"app_allowed_deniedbinaries_item_signingstate","displayName":"Signing State","description":"The code signing state to match binaries.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_allowed_deniedbinaries_item_signingstate_0","displayName":"All","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_1","displayName":"TestFlight","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_2","displayName":"DeveloperID","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_3","displayName":"Enterprise","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_4","displayName":"AppStore","description":null,"helpText":null},{"id":"app_allowed_deniedbinaries_item_signingstate_5","displayName":"Apple","description":null,"helpText":null}]},"335efc04d75bb613":{"id":"com.android.devicerestrictionpolicy.dataroamingblocked","displayName":"Block roaming data services","description":"If 'True', prevents data roaming over the cellular network. If 'False', Intune doesn't change or update this setting. By default, the OS might allow data roaming when the device is on a cellular network. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.dataroamingblocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.dataroamingblocked_false","displayName":"False","description":"false","helpText":null}]},"33d355b4064e2cf4":{"id":"com.apple.applicationaccess_allowitunesfilesharing","displayName":"Allow iTunes File Sharing","description":"If false, disables iTunes file sharing services. Available in macOS 10.13 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowitunesfilesharing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowitunesfilesharing_true","displayName":"True","description":null,"helpText":null}]},"33dc81f4d70c61b0":{"id":"com.apple.applicationaccess_safariallowjavascript","displayName":"Safari Allow Java Script","description":"If false, Safari doesn’t execute JavaScript. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariallowjavascript_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariallowjavascript_true","displayName":"True","description":null,"helpText":null}]},"33ed7f5344280623":{"id":"com.apple.caldav.account_caldavprincipalurl","displayName":"Cal DAV Principal URL","description":"The base URL to the user’s calendar.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},"332c67f6562f8746":{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos","displayName":"Require TLS For LDAP","description":"Require that LDAP connections use TLS. Available in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":[{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.extensiblesso_extensiondata_requiretlsforldap_kerberos_true","displayName":"True","description":null,"helpText":null}]},"33641c8d647442f6":{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app_lcid","displayName":"Microsoft AutoUpdate LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"331b82a66457fcff":{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled","displayName":"Edge Wallet E-Tree Enabled","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\n\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\n\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgewalletetreeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgewalletetreeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"33aaf3e02a99b8dd":{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled","displayName":"Configure Microsoft Edge scareware blocker to block sites detected as potential tech scams","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\n\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\n\nIf you enable or don't configure this policy, Microsoft Edge blocks sites detected as potential tech scams.\n\nIf you disable this policy, Microsoft Edge doesn't block sites detected as potential tech scams.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerblocksdetectedsitesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockerblocksdetectedsitesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"33ebc75213360699":{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates","displayName":"Automatically Install Mac OS Updates (Deprecated)","description":"If false, restricts the \"Install macOS Updates\" option and prevents the user from changing the option.","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticallyinstallmacosupdates_true","displayName":"True","description":null,"helpText":null}]},"3335f28d23c31bcc":{"id":"com.apple.systempolicy.managed_disableoverride","displayName":"Disable Override","description":"If true, disables the Finder's contextual menu item.","helpText":null,"infoUrls":[],"categoryId":"64538726-8745-4e7a-b370-332f725b58bf","categoryName":"System Policy Managed","options":[{"id":"com.apple.systempolicy.managed_disableoverride_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.managed_disableoverride_true","displayName":"True","description":null,"helpText":null}]},"3307743cdfe1324b":{"id":"com.apple.webcontent-filter_filterbrowsers","displayName":"Filter Browsers","description":"If true, enables the filtering of WebKit traffic.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":[{"id":"com.apple.webcontent-filter_filterbrowsers_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.webcontent-filter_filterbrowsers_true","displayName":"True","description":null,"helpText":null}]},"336854e0d708020e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended","displayName":"Allow features to download assets from the Asset Delivery Service (users can override)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeassetdeliveryserviceenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"334b61259066d15c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass","displayName":"Allow users to bypass Enhanced Security Mode","description":"Microsoft Edge lets users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode.\n\nIf you disable this policy, Microsoft Edge can't allow users to bypass Enhanced Security Mode.\n\nIf you enable or don't configure this policy, Microsoft Edge allows users to bypass Enhanced Security Mode.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodeallowuserbypass_true","displayName":"Enabled","description":null,"helpText":null}]},"3325048365775681":{"id":"contentcaching_allowcachedelete","displayName":"Allow Cache Delete","description":"If `true`, the system purges content from the cache automatically when it needs disk space for other apps when free disk space runs low on the computer. Set to `false` to maximize effectiveness of Content Caching.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_allowcachedelete_false","displayName":"Blocked","description":null,"helpText":null},{"id":"contentcaching_allowcachedelete_true","displayName":"Allowed","description":null,"helpText":null}]},"33448f1b0808023f":{"id":"device_vendor_msft_laps_policies_passphraselength","displayName":"Passphrase Length","description":"Use this setting to configure the number of passphrase words.\n\nIf not specified, this setting will default to 6 words\n\nThis setting has a minimum allowed value of 3 words.\n\nThis setting has a maximum allowed value of 10 words.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},"33c17f08a36b3e3a":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext","displayName":"Display a custom message when installation is prevented by a policy setting","description":"This policy setting allows you to display a custom message to users in a notification when a device installation is attempted and a policy setting prevents the installation.\r\n\r\nIf you enable this policy setting, Windows displays the text you type in the Detail Text box when a policy setting prevents device installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows displays a default message when a policy setting prevents device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-deniedpolicy-detailtext"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_detailtext_1","displayName":"Enabled","description":null,"helpText":null}]},"333ea12d9e94690a":{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_limitvalue","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":null},"3375dfd5e429f19f":{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs","displayName":"Allow job name in event logs","description":"\r\n This policy controls whether the print job name will be included in print event logs.\r\n\r\n If you disable or do not configure this policy setting, the print job name will not be included.\r\n\r\n If you enable this policy setting, the print job name will be included in new log entries.\r\n\r\n Note: This setting does not apply to Branch Office Direct Printing jobs.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-showjobtitleineventlogs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_showjobtitleineventlogs_1","displayName":"Enabled","description":null,"helpText":null}]},"33bbabc4d9c3fb3c":{"id":"device_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_2_customclasses_list","displayName":"GUID for custom removable storage class:","description":null,"helpText":"","infoUrls":[],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":null},"33abded35a15f459":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete","displayName":"Do not delete temp folders upon exit","description":"This policy setting specifies whether Remote Desktop Services retains a user's per-session temporary folders at logoff.\r\n\r\nYou can use this setting to maintain a user's session-specific temporary folders on a remote computer, even if the user logs off from a session. By default, Remote Desktop Services deletes a user's temporary folders when the user logs off.\r\n\r\nIf you enable this policy setting, a user's per-session temporary folders are retained when the user logs off from a session.\r\n\r\nIf you disable this policy setting, temporary folders are deleted when a user logs off, even if the server administrator specifies otherwise.\r\n\r\nIf you do not configure this policy setting, Remote Desktop Services deletes the temporary folders from the remote computer at logoff, unless specified otherwise by the server administrator.\r\n\r\nNote: This setting only takes effect if per-session temporary folders are in use on the server. If you enable the Do not use temporary folders per session policy setting, this policy setting has no effect.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-temp-delete"],"categoryId":"b40b8f80-c0e6-4494-8085-f90cadc167a9","categoryName":"Temporary folders","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_temp_delete_1","displayName":"Enabled","description":null,"helpText":null}]},"33ceb505b9a44e0b":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs","displayName":"Verify old and new Folder Redirection targets point to the same share before redirecting","description":"This policy setting allows you to prevent data loss when you change the target location for Folder Redirection, and the new and old targets point to the same network share, but have different network paths.\r\n\r\nIf you enable this policy setting, Folder Redirection creates a temporary file in the old location in order to verify that new and old locations point to the same network share. If both new and old locations point to the same share, the target path is updated and files are not copied or deleted. The temporary file is deleted.\r\n\r\nIf you disable or do not configure this policy setting, Folder Redirection does not create a temporary file and functions as if both new and old locations point to different shares when their network paths are different.\r\n\r\nNote: If the paths point to different network shares, this policy setting is not required. If the paths point to the same network share, any data contained in the redirected folders is deleted if this policy setting is not enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-checksamesourceandtargetforfranddfs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_checksamesourceandtargetforfranddfs_1","displayName":"Enabled","description":null,"helpText":null}]},"33561f777e2416e3":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options","displayName":"User Publishing Refresh Interval Unit","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options_0","displayName":"Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_unit_options_1","displayName":"Day","description":null,"helpText":null}]},"33132d429b976253":{"id":"device_vendor_msft_policy_config_browser_allowautofill","displayName":"Allow Autofill","description":"This setting lets you decide whether employees can use Autofill to automatically fill in form fields while using Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowautofill"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowautofill_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowautofill_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"3390a204ccf22107":{"id":"device_vendor_msft_policy_config_browser_setnewtabpageurl","displayName":"Set New Tab Page URL","description":"You can set the default New Tab page URL in Microsoft Edge. Enabling this policy prevents your users from changing the New tab page setting. When enabled and the Allow web content on New Tab page policy is disabled, Microsoft Edge ignores the URL specified in this policy and opens about:blank. If enabled, you can set the default New Tab page URL. If disabled or not configured, the default Microsoft Edge new tab page is used. Default setting: Disabled or not configured Related policy: Allow web content on New Tab page","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#setnewtabpageurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"333a78c980e20a06":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed","displayName":"Allow users to opt in to Safe Browsing extended reporting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_safebrowsingextendedreportingoptinallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"33b329dbc632fb39":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfclockedretrycount_odfclockedretrycount","displayName":"Locked Retry Count (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":null},"33111a08af830fe1":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvhdlocations","displayName":"VHD Locations","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies the network location where the VHD(X) files are stored.\r\n\r\nExamples:\r\n- Sinlge location: \\\\\\\r\n- Multiple locations: \\\\\\;\\\\\\\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\VHDLocations\r\nREG_SZ","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvhdlocations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvhdlocations_1","displayName":"Enabled","description":null,"helpText":null}]},"3395958be7370f1d":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence","displayName":"Userdata persistence","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowuserdatapersistence"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"33542efce22aba5c":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"333545ff354d1a4d":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling","displayName":"Restrict exposure of localhost IP address by WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default_public_and_private_interfaces","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_default_public_interface_only","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_webrtclocalhostiphandling_disable_non_proxied_udp","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},"33ee2fe19140610f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls","displayName":"Block notifications on specific sites","description":"Define a list of sites, based on URL patterns, that are blocked from displaying notifications.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultNotificationsSetting' (Default notification setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"3394eafddcc6a375":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_newtabpagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"332e9a49be6c090a":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_winprojexe20","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_winprojexe20_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_winprojexe20_1","displayName":"True","description":null,"helpText":null}]},"330d65a746792314":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_exprwdexe192","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_exprwdexe192_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_exprwdexe192_1","displayName":"True","description":null,"helpText":null}]},"33a61fdc496be9ff":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling","displayName":"Consistent Mime Handling","description":"Mime Handling","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_1","displayName":"Enabled","description":null,"helpText":null}]},"3395ba10bea1fe79":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_powerpntexe","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_powerpntexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_powerpntexe_1","displayName":"True","description":null,"helpText":null}]},"3315ac0d09d3086e":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_officemgmtcom","displayName":"Office 365 Client Management","description":"This policy setting enables programmatic control of Office 365 clients.\r\n\r\nIf you enable this policy, System Center Configuration Manager or other application management solutions can manage the Office 365 client. After applying the policy, you will be required to restart the Office Click-to-run service. \r\n\r\nIf you disable or do not configure this policy setting, System Center Configuration Manager update workflow will not be able to manage Office 365 clients. You will, however, be able to continue to use the Office Deployment Tool and System Center Configuration Manager’s program and packages or applications deployment methods. \r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI)","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_officemgmtcom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_officemgmtcom_1","displayName":"Enabled","description":null,"helpText":null}]},"33f6e84964d50de1":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatepath_l_updatepathid","displayName":"Location for updates: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":null},"3345b6c5e903ccfd":{"id":"device_vendor_msft_policy_config_smartscreen_enablesmartscreeninshell","displayName":"Enable Smart Screen In Shell","description":" Allows IT Admins to configure SmartScreen for Windows.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-smartscreen#enablesmartscreeninshell"],"categoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","categoryName":"Smart Screen","options":[{"id":"device_vendor_msft_policy_config_smartscreen_enablesmartscreeninshell_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_smartscreen_enablesmartscreeninshell_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"33b506e4ee333512":{"id":"device_vendor_msft_policy_config_update_engagedrestartsnoozeschedule","displayName":"Engaged Restart Snooze Schedule","description":"For Quality Updates, this policy specifies the number of days a user can snooze Engaged restart reminder notifications. The snooze period can be set between 1 and 3 days. Value type is integer. Default is 3 days. Supported value range: 1 - 3. If you disable or do not configure this policy, the default behaviors will be used. If any of the following policies are configured, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installationsAlways automatically restart at scheduled timeSpecify deadline before auto-restart for update installation","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#engagedrestartsnoozeschedule"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"33bb597b93eb0cd7":{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowuserinputfromwirelessdisplayreceiver","displayName":"Allow User Input From Wireless Display Receiver","description":"Setting this policy controls whether or not the wireless display can send input—keyboard, mouse, pen, and touch input if the display supports it—back to the source device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WirelessDisplay#allowuserinputfromwirelessdisplayreceiver"],"categoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowuserinputfromwirelessdisplayreceiver_0","displayName":"Wireless display input disabled.","description":"Wireless display input disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowuserinputfromwirelessdisplayreceiver_1","displayName":"Wireless display input enabled.","description":"Wireless display input enabled.","helpText":null}]},"3376ad96546eb141":{"id":"safari_newtabstartpage","displayName":"New Tab Start Page","description":"Sets the start page for new tabs in Safari.","helpText":null,"infoUrls":[],"categoryId":"e0ab6868-4b53-4310-b665-f7c979941db7","categoryName":"Safari Browser","options":null},"3356f15863d7e032":{"id":"user_vendor_msft_policy_config_admx_helpandsupport_hpexplicitfeedback","displayName":"Turn off Help Ratings (User)","description":"This policy setting specifies whether users can provide ratings for Help content.\r\n\r\nIf you enable this policy setting, ratings controls are not added to Help content.\r\n\r\nIf you disable or do not configure this policy setting, ratings controls are added to Help topics.\r\n\r\nUsers can use the control to provide feedback on the quality and usefulness of the Help and Support content.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-helpandsupport#admx-helpandsupport-hpexplicitfeedback"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_helpandsupport_hpexplicitfeedback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_helpandsupport_hpexplicitfeedback_1","displayName":"Enabled","description":null,"helpText":null}]},"3366580eb09a4603":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosettaskbar","displayName":"Prevent changes to Taskbar and Start Menu Settings (User)","description":"This policy setting allows you to prevent changes to Taskbar and Start Menu Settings.\r\n\r\nIf you enable this policy setting, The user will be prevented from opening the Taskbar Properties dialog box.\r\n\r\nIf the user right-clicks the taskbar and then clicks Properties, a message appears explaining that a setting prevents the action.\r\n\r\nIf you disable or do not configure this policy setting, the Taskbar and Start Menu items are available from Settings on the Start menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosettaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosettaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosettaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"33d7eae18f44f5da":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_enable_ts_gateway_override","displayName":"Allow users to change this setting (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"a561e59a-09b7-4106-a6fa-0b82036a5b49","categoryName":"RD Gateway","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_enable_ts_gateway_override_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_enable_ts_gateway_override_1","displayName":"True","description":null,"helpText":null}]},"333b8491f30df9b3":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word","displayName":"Microsoft Word 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft Word 2010.\r\nBy default, the user settings of Microsoft Word 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010word_1","displayName":"Enabled","description":null,"helpText":null}]},"33616a3b5919a322":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled","displayName":"Enable component updates in Google Chrome (User)","description":"Enables component updates for all components in Google Chrome when not set or set to enabled.\r\n\r\nIf set to disabled, updates to components are disabled. However, some components are exempt from this policy: updates to any component that does not contain executable code, or does not significantly alter the behavior of the browser, or is critical for its security will not be disabled.\r\nExamples of such components include the certificate revocation lists and Safe Browsing data.\r\nSee https://developers.google.com/safe-browsing for more info on Safe Browsing.\r\nPlease note that setting this policy to disabled can potentially prevent the Google Chrome developers from providing critical security fixes in a timely manner and is thus not recommended.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_componentupdatesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"33d35ccdf7035f22":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended","displayName":"Enable Safe Browsing for trusted sources (User)","description":"Setting the policy to Enabled or leaving it unset means downloaded files are sent to be analyzed by Safe Browsing, even when it's from a trusted source.\r\n\r\nSetting the policy to Disabled means downloaded files won't be sent to be analyzed by Safe Browsing when it's from a trusted source.\r\n\r\nThese restrictions apply to downloads triggered from webpage content, as well as the Download link menu option. These restrictions don't apply to the save or download of the currently displayed page or to saving as PDF from the printing options.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_safebrowsingfortrustedsourcesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"33dc605a82700412":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter","displayName":"Enable Google Cast (User)","description":"Setting the policy to Enabled or leaving it unset turns on Google Cast, which users can launch from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\r\n\r\nSetting the policy to Disabled turns off Google Cast.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_enablemediarouter_1","displayName":"Enabled","description":null,"helpText":null}]},"33be1033589fcd38":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_remoteaccesshostdebugoverridepolicies","displayName":"Policy overrides for Debug builds of the remote access host (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"3343801c0c8ff2ed":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinchromeframelist_renderinchromeframelistdesc","displayName":"Always render the following URL patterns in Google Chrome Frame (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"33a093336780a6d1":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt","displayName":"Prompt users to re-authenticate to the profile (User)","description":"When set to DoNotPrompt or left unset, Google Chrome does not automatically prompt the user to re-authenticate to the browser.\r\n\r\nWhen set to PromptInTab, when the user's authentication expires, immediately open a new tab with the Google login page. This only happens if using Chrome Sync.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_profilereauthprompt_1","displayName":"Enabled","description":null,"helpText":null}]},"33049e4e27e41897":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed (User)","description":"Controls if Google Chrome interacts with printer drivers from a separate service process. Platform printing calls to query available printers, get print driver settings, and submit documents for printing to local printers are made from a service process. Moving such calls out of the browser process helps improve stability and reduce frozen UI behavior in Print Preview.\r\n\r\nWhen this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks.\r\n\r\nWhen this policy is set to Disabled, Google Chrome will use the browser process for platform printing tasks.\r\n\r\nThis policy will be removed in the future, after the out-of-process print drivers feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"33bf3b8bcff10a0f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_officedataconnectionfiles_l_officedataconnectionfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},"33fecac801854b08":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},"3302affd6923d21d":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"3351742043003ac2":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004","displayName":"Download unsigned ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_iz_partname1004_1","displayName":"Prompt","description":null,"helpText":null}]},"3390175462b103cb":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_totalmemorylimitmb","displayName":"Set memory limit for Microsoft Edge instances: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"33c366f147f45243":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 109.\r\n\r\nThis policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications.\r\n\r\nThis policy stopped working in Microsoft Edge 107 and was obsoleted in Microsoft Edge 110.\r\n\r\nThe display-capture permissions-policy gates access to getDisplayMedia(),\r\nas per this spec:\r\nhttps://www.w3.org/TR/screen-capture/#feature-policy-integration\r\nHowever, if this policy is Disabled, this requirement is not enforced,\r\nand getDisplayMedia() is allowed from contexts that would otherwise be\r\nforbidden.\r\n\r\nIf you enable or don't configure this policy, sites can only call getDisplayMedia() from\r\ncontexts which are allowlisted by the display-capture permissions-policy.\r\n\r\nIf you disable this policy, sites can call getDisplayMedia() even from contexts\r\nwhich are not allowlisted by the display-capture permissions policy.\r\nNote that other restrictions may still apply.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_displaycapturepermissionspolicyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"33b22b22642c9ca0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastservicecreatesharednotes8_1","displayName":"True","description":null,"helpText":null}]},"33b0b1b1784bbf41":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome","displayName":"Replace Label - Home (User)","description":"This policy setting allows you to change or remove the 6th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacehome_1","displayName":"Enabled","description":null,"helpText":null}]},"33164e7c70a8f46c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_l_placesbarname219","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},"333688aa93dd56f2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin","displayName":"Display menus and dialog boxes in (User)","description":"Sets the display language of the user interface for all Office 2016 programs. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displaymenusanddialogboxesin_1","displayName":"Enabled","description":null,"helpText":null}]},"33eac2f6a35f47fd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected","displayName":"Protect document metadata for password protected files (User)","description":"This policy setting determines whether metadata is encrypted when an Office Open XML file is password protected.\r\n \r\n If you enable this policy setting, Excel 2016, PowerPoint 2016, and Word 2016 encrypt metadata stored in password-protected Office Open XML files and override any configuration changes on users' computers.\r\n \r\n If you disable this policy setting, Office 2016 applications cannot encrypt metadata in password-protected Office Open XML files, which can reduce security.\r\n \r\n If you do not configure this policy setting, when an Office Open XML document is protected with a password and saved, any metadata associated with the document is encrypted along with the rest of the document's contents. If this configuration is changed, potentially sensitive information such as the document author and hyperlink references could be exposed to unauthorized people.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_protectdocumentmetadataforpasswordprotected_1","displayName":"Enabled","description":null,"helpText":null}]},"3326c5f873ef72f6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc13_l_pathcolon13","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"331f3499982b7b4f":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem","displayName":"Lock password protected sections as soon as I navigate away from them (User)","description":"OneNote supports password protecting sections and they are unlocked once a user types the password and can be locked again by either a timeout period or when you navigate away from the section. This option will lock the section once you navigate away from the password protected section.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_lockpasswordprotectedsectionsassoonasinavigateawayfromthem_1","displayName":"Enabled","description":null,"helpText":null}]},"33e76b999b79c8cb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan","displayName":"Indicate a missing root certificate as a(n): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_0","displayName":"Neither error nor warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_1","displayName":"Warning","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingrootcertificates_l_indicateamissingrootcertificateasan_2","displayName":"Error","description":null,"helpText":null}]},"3318021cf41d5db1":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders51_1","displayName":"True","description":null,"helpText":null}]},"33ea884b3e6f2bfa":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"3304180ebf2100ea":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2","displayName":"Default View (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_bar rollup","displayName":"Bar Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_calendar","displayName":"Calendar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_descriptive network diagram","displayName":"Descriptive Network Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_detail gantt","displayName":"Detail Gantt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_gantt chart","displayName":"Gantt Chart","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_leveling gantt","displayName":"Leveling Gantt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_milestone date rollup","displayName":"Milestone Date Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_milestone rollup","displayName":"Milestone Rollup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_network diagram","displayName":"Network Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_relationship diagram","displayName":"Relationship Diagram","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource allocation","displayName":"Resource Allocation","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource form","displayName":"Resource Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource graph","displayName":"Resource Graph","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource name form","displayName":"Resource Names Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource sheet","displayName":"Resource Sheet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_resource usage","displayName":"Resource Usage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task details form","displayName":"Task Details Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task entry","displayName":"Task Entry","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task form","displayName":"Task Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task name form","displayName":"Task Name Form","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task sheet","displayName":"Task Sheet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_task usage","displayName":"Task Usage","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_l_pjdefaultview2_tracking gantt","displayName":"Tracking Gantt","description":null,"helpText":null}]},"3399a3566efa0799":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"331223a12fcc7865":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics","displayName":"Diacritics (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_diacritics_1","displayName":"Enabled","description":null,"helpText":null}]},"33eab334ba1957de":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview","displayName":"Do not open files from the Internet zone in Protected View (User)","description":"This policy setting allows you to determine if files downloaded from the Internet zone open in Protected View.\r\n\r\nIf you enable this policy setting, files downloaded from the Internet zone do not open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, files downloaded from the Internet zone open in Protected View.","helpText":"","infoUrls":[],"categoryId":"8391e79d-d618-47c3-979c-83544da43739","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_protectedview_l_donotopenfilesfromtheinternetzoneinprotectedview_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/34.json b/public/intune-definitions/34.json index 6cb71f15c631..94c98fa2285d 100644 --- a/public/intune-definitions/34.json +++ b/public/intune-definitions/34.json @@ -1 +1 @@ -{"34aa2f31fc6e4b8b":{"id":"ade_accountsettings_createlocalprimary","displayName":"Create a local primary account","description":null,"helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_createlocalprimary_0","displayName":"No","description":null,"helpText":null},{"id":"ade_accountsettings_createlocalprimary_1","displayName":"Yes - Standard Account Type","description":null,"helpText":null},{"id":"ade_accountsettings_createlocalprimary_2","displayName":"Yes - Administrator Account Type","description":null,"helpText":null}]},"34d3453851210912":{"id":"com.apple.airprint_com.apple.airprint","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},"348d258aa2076e1d":{"id":"com.apple.applicationaccess_ratingmoviesau","displayName":"Rating Movies - Australia","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_3","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_4","displayName":"MA15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_5","displayName":"R18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_6","displayName":"All","description":null,"helpText":null}]},"34fcc26053a2b49d":{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol","displayName":"DNS Protocol","description":"The encrypted transport protocol used to communicate with the DNS server.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol_0","displayName":"HTTPS","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol_1","displayName":"TLS","description":null,"helpText":null}]},"341198b142b4e2b2":{"id":"com.apple.loginwindow_denylist","displayName":"Deny List","description":"The list of user GUIDs or group GUIDs of users that cannot log in. This list takes priority over the list in the Allow List key.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},"343bb1aa940244f3":{"id":"com.apple.loginwindow_includenetworkuser","displayName":"Include Network User","description":"If true, shows network users when showing a user list.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_includenetworkuser_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_includenetworkuser_true","displayName":"True","description":null,"helpText":null}]},"341fb8bf4629f628":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname","displayName":"Channel Name","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"340211663077748d":{"id":"com.apple.managedclient.preferences_defaultsearchprovidername","displayName":"Default search provider name","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidername"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"349ffe193b747d92":{"id":"com.apple.managedclient.preferences_disablehydrationtoast","displayName":"Disable download toasts","description":"Prevents toasts from appearing when applications cause file contents to be downloaded.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disablehydrationtoast"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disablehydrationtoast_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablehydrationtoast_true","displayName":"True","description":null,"helpText":null}]},"3426560192e961c1":{"id":"com.apple.managedclient.preferences_disablesmtpparsing","displayName":"Disable SMTP parsing","description":"Disables parsing of SMTP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablesmtpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesmtpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},"34be12ccc9ab90bd":{"id":"com.apple.managedclient.preferences_howtocheck","displayName":"Enable AutoUpdate","description":"Specifies whether AutoUpdate should download and install updates. This value should be true unless you need to temporarily halt all updates.","helpText":null,"infoUrls":["https://support.microsoft.com/office/update-office-for-mac-automatically-bfd1e497-c24d-4754-92ab-910a4074d7c1"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_howtocheck_0","displayName":"True","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_howtocheck_1","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_howtocheck_2","displayName":"Manual Check","description":null,"helpText":null}]},"3466091e3299ea4a":{"id":"com.apple.managedclient.preferences_kfmblockoptout","displayName":"Force users to use the Folder Backup feature (Known Folder Move)","description":"This setting forces users to keep their Documents and Desktop folders directed to OneDrive.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmblockoptout"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmblockoptout_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmblockoptout_true","displayName":"True","description":null,"helpText":null}]},"3496a972943b4e59":{"id":"com.apple.managedclient.preferences_windowmanagementallowedforurls","displayName":"Allow Window Management permission on specified sites","description":"Lets you configure a list of site url patterns that specify sites which will automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#windowmanagementallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"34d21a61ded283af":{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule","displayName":"Desktop Schedule","description":"The schedule for turning a computer on and off.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"344fa278523c4862":{"id":"com.apple.system-extension-policy_allowedsystemextensions_generickey_keytobereplaced","displayName":"Team Identifier","description":"Add a Team Identifier of valid and signed system extensions to load. The team identifier must be alphanumeric (letters and numbers) and have 10 characters. For example, enter ABCDE12345.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"3408b68d24e08e76":{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled","displayName":"Enable Microsoft Search in Bing suggestions in the address bar (Obsolete)","description":"Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user enters a search query in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To access Microsoft Search in Bing results, the user must be signed in to Microsoft Edge with their organization's Azure AD account.\n\nIf you disable this policy, users won't see internal results in the Microsoft Edge address bar suggestion list.\n\nStarting with Microsoft Edge version 89, Microsoft Search in Bing suggestions will be available even if Bing isn't the user's default search provider.\n\nThis policy is no longer applicable due to changes in access to work search through Bing-related endpoints.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"34484b946d4f5c39":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions.","description":"Extensions that connect to one of these origins keep running as long as the port is connected.\nIf unset, the policy's default values are used. These are the app origins that offer software development kits (SDKs) that are known to not offer the possibility of restarting a closed connection to a previous state:\n- Smart Card Connector\n- Citrix Receiver (stable, beta, back-up)\n- VMware Horizon (stable, beta)\n\nIf set, the default value list is extended with the newly configured values. The defaults and policy-provided entries grant the exception to the connecting extensions as long as the port is connected.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"34fc3f570339854e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended","displayName":"Allow importing of payment info (users can override)","description":"Allows users to import payment info from another browser into Microsoft Edge.\n\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, payment info isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\n\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"343b72e67796e477":{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nIf you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings, either by the user or by enterprise policy, run. This includes content from other origins and/or small content.\n\nTo control which websites are allowed to run Adobe Flash, see the specifications in the \"DefaultPluginsSetting\", \"PluginsAllowedForUrls\", and \"PluginsBlockedForUrls\" policies.\n\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (sites that aren't specified in the preceding three policies) or small content might be blocked.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode_true","displayName":"Enabled","description":null,"helpText":null}]},"34d2fa470cada735":{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled","displayName":"Enable spellcheck","description":"If you enable or don't configure this policy, the user can use spellcheck.\n\nIf you disable this policy, the user can't use spellcheck and the \"SpellcheckLanguage\" and \"SpellcheckLanguageBlocklist\" policies are also disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"34eb75c404754e9c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess","displayName":"Force WebSQL to be enabled (Obsolete)","description":"This policy was removed in Microsoft Edge 124 and is ignored if set.\n\nWebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.\nIf you enable this policy, WebSQL cannot be disabled.\nIf you disable or don't configure this policy, WebSQL can be disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess_true","displayName":"Enabled","description":null,"helpText":null}]},"346a85b330947337":{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name","displayName":"Select the encryption method for removable data drives:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_3","displayName":"AES-CBC 128-bit (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_4","displayName":"AES-CBC 256-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_6","displayName":"XTS-AES 128-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_7","displayName":"XTS-AES 256-bit","description":null,"helpText":null}]},"346c959a3c62b036":{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name","displayName":"Omit recovery options from the BitLocker setup wizard","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name_1","displayName":"True","description":null,"helpText":null}]},"345af43330013bb2":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},"349104e704a089f7":{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions","displayName":"Prevent the use of security questions for local accounts","description":"If you turn this policy setting on, local users won’t be able to set up and use security questions to reset their passwords.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credui#admx-credui-nolocalpasswordresetquestions"],"categoryId":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","categoryName":"Credential User Interface","options":[{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions_1","displayName":"Enabled","description":null,"helpText":null}]},"3412437afe00db58":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup_scan_missedscheduledscancountbeforecatchup","displayName":"Define the number of scheduled scans that can be missed after which a catch-up scan is forced","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},"34c8bfab22801ec8":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_netlogon_backgroundretryinitialperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"3453f3fbcd7bfc29":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2","displayName":"Specify administratively assigned Offline Files","description":"This policy setting lists network files and folders that are always available for offline use. This ensures that the specified files and folders are available offline to users of the computer.\r\n\r\nIf you enable this policy setting, the files you enter are always available offline to users of the computer. To specify a file or folder, click Show. In the Show Contents dialog box in the Value Name column, type the fully qualified UNC path to the file or folder. Leave the Value column field blank.\r\n\r\nIf you disable this policy setting, the list of files or folders made always available offline (including those inherited from lower precedence GPOs) is deleted and no files or folders are made available for offline use by Group Policy (though users can still specify their own files and folders for offline use).\r\n\r\nIf you do not configure this policy setting, no files or folders are made available for offline use by Group Policy.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy settings will be combined and all specified files will be available for offline use.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-assignedofflinefiles-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_1","displayName":"Enabled","description":null,"helpText":null}]},"34ae875e807ea2d2":{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2","displayName":"Hide previous versions of files on backup location","description":"This policy setting lets you hide entries in the list of previous versions of a file in which the previous version is located on backup media. Previous versions can come from the on-disk restore points or the backup media.\r\n\r\nIf you enable this policy setting, users cannot see any previous versions corresponding to backup copies, and can see only previous versions corresponding to on-disk restore points.\r\n\r\nIf you disable this policy setting, users can see previous versions corresponding to backup copies as well as previous versions corresponding to on-disk restore points.\r\n\r\nIf you do not configure this policy setting, it is disabled by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-hidebackupentries-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2_1","displayName":"Enabled","description":null,"helpText":null}]},"34a3ffc3849e9e0a":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013","displayName":"Microsoft Office 365 SharePoint Designer 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 SharePoint Designer 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 SharePoint Designer 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 SharePoint Designer 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 SharePoint Designer 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 SharePoint Designer 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365sharepointdesigner2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013_1","displayName":"Enabled","description":null,"helpText":null}]},"34a7fa8b19e2300f":{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_slowlinkwaitinterval","displayName":"Time (milliseconds)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},"3429eef73a8c57ef":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions_disabledpluginsexceptionsdesc","displayName":"List of exceptions to the list of disabled plugins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"34141212de7252ee":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_pluginsallowedforurlsdesc","displayName":"Allow the Flash plugin on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"34b95143b48eb886":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_webhidaskforurlsdesc","displayName":"Allow the WebHID API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"348df69ac2a78ede":{"id":"device_vendor_msft_policy_config_datausage_setcost4g","displayName":"Set 4G Cost","description":"This policy setting configures the cost of 4G connections on the local machine. \n\nIf this policy setting is enabled, a drop-down list box presenting possible cost values will be active. Selecting one of the following values from the list will set the cost of all 4G connections on the local machine:\n\n- Unrestricted: Use of this connection is unlimited and not restricted by usage charges and capacity constraints. \n\n- Fixed: Use of this connection is not restricted by usage charges and capacity constraints up to a certain data limit. \n\n- Variable: This connection is costed on a per byte basis.\n\nIf this policy setting is disabled or is not configured, the cost of 4G connections is Fixed by default.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-datausage#datausage-setcost4g"],"categoryId":"edf3754c-b22d-4946-a744-4773240a5883","categoryName":"WWAN Media Cost","options":[{"id":"device_vendor_msft_policy_config_datausage_setcost4g_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_datausage_setcost4g_1","displayName":"Enabled","description":null,"helpText":null}]},"34d631386377fa34":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dodelaycacheserverfallbackbackground","displayName":"DO Delay Cache Server Fallback Background","description":"For background downloads that use a cache server, specifies the time to wait before falling back to download from the original HTTP source.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dodelaycacheserverfallbackbackground"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"34584d7162957d9b":{"id":"device_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains_domainlist","displayName":"Domain allow list","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},"34a1de961a96339d":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},"34424bd6f5aff916":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"3426160a55ea4154":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"3459bcdd2ed102ef":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\r\n\r\nIf you enable, this policy, the option to import search engine settings is automatically selected.\r\n\r\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine_1","displayName":"Enabled","description":null,"helpText":null}]},"3427a1366a28a9f9":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"34b31422ddb913d5":{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it is a temporary policy to support WebSQL in non-secure contexts. It won't work in Microsoft Edge as soon as version 110.\r\nIf you enable this policy, WebSQL in non-secure contexts will be enabled.\r\nIf you disable or don't configure this policy, WebSQL in non-secure contexts will follow the default settings of the broser.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"34776ed615711f3d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_licensingsettings_l_sclcacheoverride_l_sclcacheoverride","displayName":"Folder location: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"2e3f0407-6387-41b4-b6c2-ada4354be759","categoryName":"Licensing Settings","options":null},"34c462040b2c72ef":{"id":"device_vendor_msft_policy_config_search_preventremotequeries","displayName":"Prevent Remote Queries","description":"If enabled, clients will be unable to query this computer's index remotely. Thus, when they are browsing network shares that are stored on this computer, they will not search them using the index. If disabled, client search requests will use this computer's index. .","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Search#preventremotequeries"],"categoryId":"794337be-8833-4b9a-bb88-8a030141578d","categoryName":"Search","options":[{"id":"device_vendor_msft_policy_config_search_preventremotequeries_0","displayName":"Disable.","description":"Disable.","helpText":null},{"id":"device_vendor_msft_policy_config_search_preventremotequeries_1","displayName":"Enable.","description":"Enable.","helpText":null}]},"342881841ecb1d63":{"id":"device_vendor_msft_policy_config_userrights_denylocallogon","displayName":"Deny Local Log On","description":"This security setting determines which service accounts are prevented from registering a process as a service. Note: This security setting does not apply to the System, Local Service, or Network Service accounts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#denylocallogon"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"34bfaa103417d6bc":{"id":"settings_item_accessibilitysettings_boldtextenabled","displayName":"Bold Text Enabled","description":"If 'true', enables bold text.","helpText":null,"infoUrls":[],"categoryId":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","categoryName":"Accessibility Settings","options":[{"id":"settings_item_accessibilitysettings_boldtextenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_boldtextenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"345b1c8e2d2efb2d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders18","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders18_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders18_1","displayName":"True","description":null,"helpText":null}]},"34512feeadf42fa3":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","categoryName":"Miscellaneous","options":null},"34b6eeba9bb1b03f":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedopensearch_opensearchlabel0","displayName":"Site Name 1 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"34df299a387cb699":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled","displayName":"Allow queries to a Google time service (User)","description":"Setting the policy to Enabled or leaving it unset means Google Chrome send occasional queries to a Google server to retrieve an accurate timestamp.\r\n\r\nSetting the policy to Disabled stops Google Chrome from sending these queries.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"34a333942cb43ff1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_autoselectcertificateforurlsdesc","displayName":"Automatically select client certificates for these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"34def4de98905450":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting","displayName":"Default key generation setting (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_1","displayName":"Enabled","description":null,"helpText":null}]},"3494fe9455c7c1dc":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"3447a8dd1e010835":{"id":"user_vendor_msft_policy_config_experience_allowspotlightcollection","displayName":"Allow Spotlight Collection (User)","description":"Specifies whether Spotlight collection is allowed as a Personalization->Background Setting. If you enable this policy setting, Spotlight collection will show as an option in the user's Personalization Settings, and the user will be able to get daily images from Microsoft displayed on their desktop. If you disable this policy setting, Spotlight collection will not show as an option in Personliazation Settings, and the user will not have the choice of getting Microsoft daily images shown on their desktop.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowspotlightcollection"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":null},"34a53dc2c8a6a7ec":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806","displayName":"Launching programs and unsafe files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_1","displayName":"Prompt","description":null,"helpText":null}]},"34124216e2292fae":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200","displayName":"Run ActiveX controls and plugins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_65536","displayName":"Administrator approved","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_1","displayName":"Prompt","description":null,"helpText":null}]},"346e668ec849cc61":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default pop-up window setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},"3493b1bfa900fb7f":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},"34f3f8bceac3af8b":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors","displayName":"Allow certificates signed using SHA-1 when issued by local trust anchors (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nWhen this setting is enabled, Microsoft Edge allows connections secured by SHA-1 signed certificates so long as the the certificate chains to a locally-installed root certificate and is otherwise valid.\r\n\r\nNote that this policy depends on the operating system (OS) certificate verification stack allowing SHA-1 signatures. If an OS update changes the OS handling of SHA-1 certificates, this policy might no longer have effect. Further, this policy is intended as a temporary workaround to give enterprises more time to move away from SHA-1. This policy will be removed in Microsoft Edge 92 releasing in mid 2021.\r\n\r\nIf you don't set this policy or set it to false, or the SHA-1 certificate chains to a publicly trusted certificate root, then Microsoft Edge won't allow certificates signed by SHA-1.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},"347e55651656d5ec":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 120.\r\n\r\nIf you enable this policy, WebRTC peer connections can downgrade to obsolete\r\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\r\nIf you disable or don't set this policy, these TLS/DTLS versions are\r\ndisabled.\r\n\r\nThis policy was removed in Microsoft Edge 121 and is ignored if set.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},"349de932abbc85f0":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft (User)","description":"Lets screen reader users get descriptions of unlabeled images on the web.\r\n\r\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\r\n\r\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\r\n\r\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\r\n\r\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"34f571ef08b40023":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceminorversion5","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"347071d67069b642":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceservercapabilities9","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"345e0e365633d009":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail","displayName":"Replace Label - E-mail (User)","description":"This policy setting allows you to change or remove the 1st label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},"34dc84649d52a8dc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq","displayName":"Central Kurdish (Iraq) (User)","description":"Enables the editing language Central Kurdish (Iraq)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq_1","displayName":"Enabled","description":null,"helpText":null}]},"34dce2c5950655a7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino","displayName":"Filipino (User)","description":"Enables the editing language Filipino","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino_1","displayName":"Enabled","description":null,"helpText":null}]},"346032e24f4ce0f9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations","displayName":"Increase the visibility of Accessibility Checker violations (User)","description":"This policy setting controls whether a document, workbook, or spreadsheet with accessibility errors will cause a loud warning or error slab in the user interface.\r\n\r\nIf you enable this policy setting, you may specify what happens when a document, workbook, or spreadsheet has accessibility errors:\r\n\r\n- Accessibility violations do not change Prepare for Distribution loudness (default)\r\n- Accessibility errors cause the Prepare for Distribution slab to be loud\r\n- Accessibility errors or warnings cause the Prepare for Distribution slab to be loud\r\n\r\nIf you disable or do not configure this policy setting, the Accessibility Checker UI will be presented in its normal state.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_1","displayName":"Enabled","description":null,"helpText":null}]},"347be0bc1347fa00":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex","displayName":"Disable All ActiveX (User)","description":"This policy setting controls whether ActiveX controls are disabled. \r\n\r\nIf you enable this policy setting, Office 2016 applications do not initialize ActiveX controls from non-trusted locations, and do not notify the user that the ActiveX controls are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can set the trust level for ActiveX controls in the Trust Center in the 2016 versions of Microsoft Access, PowerPoint, Word, and Excel. The default configuration does not load untrusted ActiveX controls, but uses the Message Bar to prompt users about the control, and they can then choose whether to run the control.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex_1","displayName":"Enabled","description":null,"helpText":null}]},"3460f04d1b705fdb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning","displayName":"Enable Minimizing VBA Project Digital Signature Invalidation (User)","description":"\r\nThis policy setting allows you to reduce the number of actions in Office that will result in a document's VBA digital signature becoming invalidated.\r\n\r\nThe VBA project may be modified in certain ways that change the project storage but that do not invalidate the source code digital signature. With this setting turned off, these actions will lead to the VBA digital signature being invalidated, and the signature dropped on save if the user does not have the private key available to resign.\r\n\r\nWith this setting on, we will only perform a resign of the project if the source code signature has changed, and will keep the existing signature in other cases. If the VBA project storage is changed and saved, but the old signature retained under this feature, this can lead to an invalidation of the saved compiled VBA project state. If this happens, the VBA project will be forced to recompile each time the document is loaded. This may have negative performance impacts for larger VBA projects. Once a document is in this state, the state will persist until the VBA project is resigned.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning_1","displayName":"Enabled","description":null,"helpText":null}]},"347e865fd428d655":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_datecolon263","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"341d1a10b363ba83":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_pathcolon04","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"34ca816305910334":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections","displayName":"Percentage of unused disk space to allow in sections (User)","description":"Sets the value in the option ''Percentage of unused space to allow in sections without optimizing''.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_1","displayName":"Enabled","description":null,"helpText":null}]},"34ff724fe89fce01":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext","displayName":"Read signed e-mail as plain text (User)","description":"This policy setting determines whether Outlook renders all digitally signed e-mail in plain text format for reading. Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. \r\n\r\nIf you enable this policy setting, the \"Read all standard mail in plain text\" check box option is selected in the \"E-mail Security\" section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays digitally signed e-mail messages in the format they were received in.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext_1","displayName":"Enabled","description":null,"helpText":null}]},"345894b23a815c94":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon","displayName":"Background Color: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_000000","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_12632256","displayName":"Silver","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8421504","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16777215","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_65535","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16711808","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8453888","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16776960","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8421376","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8388736","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_32768","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16711680","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8388608","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_128","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_32896","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_255","displayName":"Blue","description":null,"helpText":null}]},"349f8a1b26549258":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth_l_pjdayspermonth20","displayName":"Days per month (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},"3438819d1ef62791":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"3444ba1a502815dd":{"id":"user_vendor_msft_policy_config_settings_pagevisibilitylist","displayName":"Page Visibility List (User)","description":"Allows IT Admins to either prevent specific pages in the System Settings app from being visible or accessible, or to do so for all pages except those specified. The mode will be specified by the policy string beginning with either the string showonly: or hide:.  Pages are identified by a shortened version of their already published URIs, which is the URI minus the ms-settings: prefix. For example, if the URI for a settings page is ms-settings:bluetooth, the page identifier used in the policy will be just bluetooth. Multiple page identifiers are separated by semicolons. The following example illustrates a policy that would allow access only to the about and bluetooth pages, which have URI ms-settings:about and ms-settings:bluetooth respectively:showonly:about;bluetooth. If the policy is not specified, the behavior will be that no pages are affected. If the policy string is formatted incorrectly, it will be ignored entirely (i. e. treated as not set) to prevent the machine from becoming unserviceable if data corruption occurs. Note that if a page is already hidden for another reason, then it will remain hidden even if it is in a showonly: list. The format of the PageVisibilityList value is as follows: The value is a unicode string up to 10,000 characters long, which will be used without case sensitivity. There are two variants: one that shows only the given pages and one which hides the given pages. The first variant starts with the string showonly: and the second with the string hide:. Following the variant identifier is a semicolon-delimited list of page identifiers, which must not have any extra whitespace. Each page identifier is the ms-settings:xyz URI for the page, minus the ms-settings: prefix, so the identifier for the page with URI ms-settings:network-wifi would be just network-wifi. The default value for this setting is an empty string, which is interpreted as show everything. Example 1, specifies that only the wifi and bluetooth pages should be shown (they have URIs ms-settings:network-wifi and ms-settings:bluetooth). All other pages (and the categories they're in) will be hidden:showonly:network-wifi;bluetooth. Example 2, specifies that the wifi page should not be shown:hide:network-wifi","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#pagevisibilitylist"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":null},"34a33147aac32b44":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse","displayName":"Zoom on roll with IntelliMouse (User)","description":"If selected, lets you zoom in or out from a drawing by rolling the wheel of the Microsoft Intellimouse","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse_1","displayName":"Enabled","description":null,"helpText":null}]},"34752ba962cf78b4":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates","displayName":"Templates (User)","description":"This policy setting allows you to specify the additional location of templates.\r\n\r\nIf you enable this policy setting, you may specify the additional location of templates. These locations are listed on the New screen of the File tab.\r\n\r\nIf you disable or do not configure this policy setting, no additional location of templates is shown.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_1","displayName":"Enabled","description":null,"helpText":null}]},"34cd429187bfb8fd":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"34273b372213575d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]},"34745be7d096ca35":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext","displayName":"Asian fonts also apply to Latin text (User)","description":"Checks/unchecks the corresponding UI option. This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"34aa2f31fc6e4b8b":{"id":"ade_accountsettings_createlocalprimary","displayName":"Create a local primary account","description":null,"helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_createlocalprimary_0","displayName":"No","description":null,"helpText":null},{"id":"ade_accountsettings_createlocalprimary_1","displayName":"Yes - Standard Account Type","description":null,"helpText":null},{"id":"ade_accountsettings_createlocalprimary_2","displayName":"Yes - Administrator Account Type","description":null,"helpText":null}]},"3432c51bf8c62ff9":{"id":"com.android.devicerestrictionpolicy.wipedataflag","displayName":"Remove all eSIMs during a device wipe","description":"If 'True', all eSIMs are removed when a device is wiped. If 'False', Intune doesn't change or update this setting. By default, eSIMs are not removed during a device wipe, except where required by the OS. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wipedataflag_false","displayName":"False","description":"eSIMs are not removed during a device wipe, except where required by the OS.","helpText":null},{"id":"com.android.devicerestrictionpolicy.wipedataflag_true","displayName":"True","description":"All eSIMs are removed when the device is wiped.","helpText":null}]},"34d3453851210912":{"id":"com.apple.airprint_com.apple.airprint","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},"348d258aa2076e1d":{"id":"com.apple.applicationaccess_ratingmoviesau","displayName":"Rating Movies - Australia","description":"The maximum level of movie content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingmoviesau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_1","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_2","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_3","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_4","displayName":"MA15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_5","displayName":"R18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingmoviesau_6","displayName":"All","description":null,"helpText":null}]},"34fcc26053a2b49d":{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol","displayName":"DNS Protocol","description":"The encrypted transport protocol used to communicate with the DNS server.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol_0","displayName":"HTTPS","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_dnssettings_dnsprotocol_1","displayName":"TLS","description":null,"helpText":null}]},"341198b142b4e2b2":{"id":"com.apple.loginwindow_denylist","displayName":"Deny List","description":"The list of user GUIDs or group GUIDs of users that cannot log in. This list takes priority over the list in the Allow List key.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},"343bb1aa940244f3":{"id":"com.apple.loginwindow_includenetworkuser","displayName":"Include Network User","description":"If true, shows network users when showing a user list.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_includenetworkuser_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_includenetworkuser_true","displayName":"True","description":null,"helpText":null}]},"341fb8bf4629f628":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname","displayName":"Channel Name","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"340211663077748d":{"id":"com.apple.managedclient.preferences_defaultsearchprovidername","displayName":"Default search provider name","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidername"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"349ffe193b747d92":{"id":"com.apple.managedclient.preferences_disablehydrationtoast","displayName":"Disable download toasts","description":"Prevents toasts from appearing when applications cause file contents to be downloaded.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#disablehydrationtoast"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_disablehydrationtoast_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablehydrationtoast_true","displayName":"True","description":null,"helpText":null}]},"3426560192e961c1":{"id":"com.apple.managedclient.preferences_disablesmtpparsing","displayName":"Disable SMTP parsing","description":"Disables parsing of SMTP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablesmtpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablesmtpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},"34be12ccc9ab90bd":{"id":"com.apple.managedclient.preferences_howtocheck","displayName":"Enable AutoUpdate","description":"Specifies whether AutoUpdate should download and install updates. This value should be true unless you need to temporarily halt all updates.","helpText":null,"infoUrls":["https://support.microsoft.com/office/update-office-for-mac-automatically-bfd1e497-c24d-4754-92ab-910a4074d7c1"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_howtocheck_0","displayName":"True","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_howtocheck_1","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_howtocheck_2","displayName":"Manual Check","description":null,"helpText":null}]},"3466091e3299ea4a":{"id":"com.apple.managedclient.preferences_kfmblockoptout","displayName":"Force users to use the Folder Backup feature (Known Folder Move)","description":"This setting forces users to keep their Documents and Desktop folders directed to OneDrive.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmblockoptout"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_kfmblockoptout_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_kfmblockoptout_true","displayName":"True","description":null,"helpText":null}]},"3496a972943b4e59":{"id":"com.apple.managedclient.preferences_windowmanagementallowedforurls","displayName":"Allow Window Management permission on specified sites","description":"Lets you configure a list of site url patterns that specify sites which will automatically grant the window management permission. This extends the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\n\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\n\nIf this policy isn't configured for a site, then the policy from \"DefaultWindowManagementSetting\" applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#windowmanagementallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"34d21a61ded283af":{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule","displayName":"Desktop Schedule","description":"The schedule for turning a computer on and off.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"344fa278523c4862":{"id":"com.apple.system-extension-policy_allowedsystemextensions_generickey_keytobereplaced","displayName":"Team Identifier","description":"Add a Team Identifier of valid and signed system extensions to load. The team identifier must be alphanumeric (letters and numbers) and have 10 characters. For example, enter ABCDE12345.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"3408b68d24e08e76":{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled","displayName":"Enable Microsoft Search in Bing suggestions in the address bar (Obsolete)","description":"Enables the display of relevant Microsoft Search in Bing suggestions in the address bar's suggestion list when the user enters a search query in the address bar. If you enable or don't configure this policy, users can see internal results powered by Microsoft Search in Bing in the Microsoft Edge address bar suggestion list. To access Microsoft Search in Bing results, the user must be signed in to Microsoft Edge with their organization's Azure AD account.\n\nIf you disable this policy, users won't see internal results in the Microsoft Edge address bar suggestion list.\n\nStarting with Microsoft Edge version 89, Microsoft Search in Bing suggestions will be available even if Bing isn't the user's default search provider.\n\nThis policy is no longer applicable due to changes in access to work search through Bing-related endpoints.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.addressbarmicrosoftsearchinbingproviderenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"34484b946d4f5c39":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions.","description":"Extensions that connect to one of these origins keep running as long as the port is connected.\nIf unset, the policy's default values are used. These are the app origins that offer software development kits (SDKs) that are known to not offer the possibility of restarting a closed connection to a previous state:\n- Smart Card Connector\n- Citrix Receiver (stable, beta, back-up)\n- VMware Horizon (stable, beta)\n\nIf set, the default value list is extended with the newly configured values. The defaults and policy-provided entries grant the exception to the connecting extensions as long as the port is connected.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"34fc3f570339854e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended","displayName":"Allow importing of payment info (users can override)","description":"Allows users to import payment info from another browser into Microsoft Edge.\n\nIf you enable this policy, the **payment info** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, payment info isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, payment info is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This option means that Microsoft Edge imports payment info on first run, but users can select or clear the **payment info** option during manual import.\n\n**Note:** This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importpaymentinfo_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"343b72e67796e477":{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content (Obsolete)","description":"This policy doesn't work because Flash is no longer supported by Microsoft Edge.\n\nIf you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings, either by the user or by enterprise policy, run. This includes content from other origins and/or small content.\n\nTo control which websites are allowed to run Adobe Flash, see the specifications in the \"DefaultPluginsSetting\", \"PluginsAllowedForUrls\", and \"PluginsBlockedForUrls\" policies.\n\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (sites that aren't specified in the preceding three policies) or small content might be blocked.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.runallflashinallowmode_true","displayName":"Enabled","description":null,"helpText":null}]},"34d2fa470cada735":{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled","displayName":"Enable spellcheck","description":"If you enable or don't configure this policy, the user can use spellcheck.\n\nIf you disable this policy, the user can't use spellcheck and the \"SpellcheckLanguage\" and \"SpellcheckLanguageBlocklist\" policies are also disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.spellcheckenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"34eb75c404754e9c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess","displayName":"Force WebSQL to be enabled (Obsolete)","description":"This policy was removed in Microsoft Edge 124 and is ignored if set.\n\nWebSQL is on by default as of Microsoft Edge version 101, but can be disabled via a Microsoft Edge flag.\nIf you enable this policy, WebSQL cannot be disabled.\nIf you disable or don't configure this policy, WebSQL can be disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.websqlaccess_true","displayName":"Enabled","description":null,"helpText":null}]},"346a85b330947337":{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name","displayName":"Select the encryption method for removable data drives:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp#encryptionmethodbydrivetype"],"categoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","categoryName":"BitLocker Drive Encryption","options":[{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_3","displayName":"AES-CBC 128-bit (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_4","displayName":"AES-CBC 256-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_6","displayName":"XTS-AES 128-bit","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_encryptionmethodbydrivetype_encryptionmethodwithxtsrdvdropdown_name_7","displayName":"XTS-AES 256-bit","description":null,"helpText":null}]},"346c959a3c62b036":{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name","displayName":"Omit recovery options from the BitLocker setup wizard","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_oshiderecoverypage_name_1","displayName":"True","description":null,"helpText":null}]},"345af43330013bb2":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},"349104e704a089f7":{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions","displayName":"Prevent the use of security questions for local accounts","description":"If you turn this policy setting on, local users won’t be able to set up and use security questions to reset their passwords.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credui#admx-credui-nolocalpasswordresetquestions"],"categoryId":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","categoryName":"Credential User Interface","options":[{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credui_nolocalpasswordresetquestions_1","displayName":"Enabled","description":null,"helpText":null}]},"3412437afe00db58":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_missedscheduledscancountbeforecatchup_scan_missedscheduledscancountbeforecatchup","displayName":"Define the number of scheduled scans that can be missed after which a catch-up scan is forced","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},"34c8bfab22801ec8":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_netlogon_backgroundretryinitialperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"3453f3fbcd7bfc29":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2","displayName":"Specify administratively assigned Offline Files","description":"This policy setting lists network files and folders that are always available for offline use. This ensures that the specified files and folders are available offline to users of the computer.\r\n\r\nIf you enable this policy setting, the files you enter are always available offline to users of the computer. To specify a file or folder, click Show. In the Show Contents dialog box in the Value Name column, type the fully qualified UNC path to the file or folder. Leave the Value column field blank.\r\n\r\nIf you disable this policy setting, the list of files or folders made always available offline (including those inherited from lower precedence GPOs) is deleted and no files or folders are made available for offline use by Group Policy (though users can still specify their own files and folders for offline use).\r\n\r\nIf you do not configure this policy setting, no files or folders are made available for offline use by Group Policy.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy settings will be combined and all specified files will be available for offline use.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-assignedofflinefiles-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_assignedofflinefiles_2_1","displayName":"Enabled","description":null,"helpText":null}]},"34ae875e807ea2d2":{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2","displayName":"Hide previous versions of files on backup location","description":"This policy setting lets you hide entries in the list of previous versions of a file in which the previous version is located on backup media. Previous versions can come from the on-disk restore points or the backup media.\r\n\r\nIf you enable this policy setting, users cannot see any previous versions corresponding to backup copies, and can see only previous versions corresponding to on-disk restore points.\r\n\r\nIf you disable this policy setting, users can see previous versions corresponding to backup copies as well as previous versions corresponding to on-disk restore points.\r\n\r\nIf you do not configure this policy setting, it is disabled by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-hidebackupentries-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_hidebackupentries_2_1","displayName":"Enabled","description":null,"helpText":null}]},"34a3ffc3849e9e0a":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013","displayName":"Microsoft Office 365 SharePoint Designer 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 SharePoint Designer 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 SharePoint Designer 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 SharePoint Designer 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 SharePoint Designer 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 SharePoint Designer 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365sharepointdesigner2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365sharepointdesigner2013_1","displayName":"Enabled","description":null,"helpText":null}]},"34a7fa8b19e2300f":{"id":"device_vendor_msft_policy_config_admx_userprofiles_slowlinktimeout_slowlinkwaitinterval","displayName":"Time (milliseconds)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},"3429eef73a8c57ef":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledpluginsexceptions_disabledpluginsexceptionsdesc","displayName":"List of exceptions to the list of disabled plugins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"34141212de7252ee":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pluginsallowedforurls_pluginsallowedforurlsdesc","displayName":"Allow the Flash plugin on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"34b95143b48eb886":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_webhidaskforurlsdesc","displayName":"Allow the WebHID API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"348df69ac2a78ede":{"id":"device_vendor_msft_policy_config_datausage_setcost4g","displayName":"Set 4G Cost","description":"This policy setting configures the cost of 4G connections on the local machine. \n\nIf this policy setting is enabled, a drop-down list box presenting possible cost values will be active. Selecting one of the following values from the list will set the cost of all 4G connections on the local machine:\n\n- Unrestricted: Use of this connection is unlimited and not restricted by usage charges and capacity constraints. \n\n- Fixed: Use of this connection is not restricted by usage charges and capacity constraints up to a certain data limit. \n\n- Variable: This connection is costed on a per byte basis.\n\nIf this policy setting is disabled or is not configured, the cost of 4G connections is Fixed by default.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-datausage#datausage-setcost4g"],"categoryId":"edf3754c-b22d-4946-a744-4773240a5883","categoryName":"WWAN Media Cost","options":[{"id":"device_vendor_msft_policy_config_datausage_setcost4g_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_datausage_setcost4g_1","displayName":"Enabled","description":null,"helpText":null}]},"34d631386377fa34":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dodelaycacheserverfallbackbackground","displayName":"DO Delay Cache Server Fallback Background","description":"For background downloads that use a cache server, specifies the time to wait before falling back to download from the original HTTP source.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dodelaycacheserverfallbackbackground"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"34584d7162957d9b":{"id":"device_vendor_msft_policy_config_internetexplorer_donotblockoutdatedactivexcontrolsonspecificdomains_domainlist","displayName":"Domain allow list","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},"34a1de961a96339d":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},"34424bd6f5aff916":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"3426160a55ea4154":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"3459bcdd2ed102ef":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\r\n\r\nIf you enable, this policy, the option to import search engine settings is automatically selected.\r\n\r\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_importsearchengine_1","displayName":"Enabled","description":null,"helpText":null}]},"3427a1366a28a9f9":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"34b31422ddb913d5":{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it is a temporary policy to support WebSQL in non-secure contexts. It won't work in Microsoft Edge as soon as version 110.\r\nIf you enable this policy, WebSQL in non-secure contexts will be enabled.\r\nIf you disable or don't configure this policy, WebSQL in non-secure contexts will follow the default settings of the broser.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"34776ed615711f3d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_licensingsettings_l_sclcacheoverride_l_sclcacheoverride","displayName":"Folder location: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"2e3f0407-6387-41b4-b6c2-ada4354be759","categoryName":"Licensing Settings","options":null},"34c462040b2c72ef":{"id":"device_vendor_msft_policy_config_search_preventremotequeries","displayName":"Prevent Remote Queries","description":"If enabled, clients will be unable to query this computer's index remotely. Thus, when they are browsing network shares that are stored on this computer, they will not search them using the index. If disabled, client search requests will use this computer's index. .","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Search#preventremotequeries"],"categoryId":"794337be-8833-4b9a-bb88-8a030141578d","categoryName":"Search","options":[{"id":"device_vendor_msft_policy_config_search_preventremotequeries_0","displayName":"Disable.","description":"Disable.","helpText":null},{"id":"device_vendor_msft_policy_config_search_preventremotequeries_1","displayName":"Enable.","description":"Enable.","helpText":null}]},"342881841ecb1d63":{"id":"device_vendor_msft_policy_config_userrights_denylocallogon","displayName":"Deny Local Log On","description":"This security setting determines which service accounts are prevented from registering a process as a service. Note: This security setting does not apply to the System, Local Service, or Network Service accounts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#denylocallogon"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"34bfaa103417d6bc":{"id":"settings_item_accessibilitysettings_boldtextenabled","displayName":"Bold Text Enabled","description":"If 'true', enables bold text.","helpText":null,"infoUrls":[],"categoryId":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","categoryName":"Accessibility Settings","options":[{"id":"settings_item_accessibilitysettings_boldtextenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_boldtextenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"345b1c8e2d2efb2d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders18","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders18_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders18_1","displayName":"True","description":null,"helpText":null}]},"34512feeadf42fa3":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","categoryName":"Miscellaneous","options":null},"34b6eeba9bb1b03f":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedopensearch_opensearchlabel0","displayName":"Site Name 1 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"34df299a387cb699":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled","displayName":"Allow queries to a Google time service (User)","description":"Setting the policy to Enabled or leaving it unset means Google Chrome send occasional queries to a Google server to retrieve an accurate timestamp.\r\n\r\nSetting the policy to Disabled stops Google Chrome from sending these queries.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsernetworktimequeriesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"34a333942cb43ff1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_autoselectcertificateforurls_autoselectcertificateforurlsdesc","displayName":"Automatically select client certificates for these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"34def4de98905450":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting","displayName":"Default key generation setting (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_1","displayName":"Enabled","description":null,"helpText":null}]},"3494fe9455c7c1dc":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumentspreadsheetfiles_l_opendocumentspreadsheetfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"3447a8dd1e010835":{"id":"user_vendor_msft_policy_config_experience_allowspotlightcollection","displayName":"Allow Spotlight Collection (User)","description":"Specifies whether Spotlight collection is allowed as a Personalization->Background Setting. If you enable this policy setting, Spotlight collection will show as an option in the user's Personalization Settings, and the user will be able to get daily images from Microsoft displayed on their desktop. If you disable this policy setting, Spotlight collection will not show as an option in Personliazation Settings, and the user will not have the choice of getting Microsoft daily images shown on their desktop.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowspotlightcollection"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":null},"34a53dc2c8a6a7ec":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806","displayName":"Launching programs and unsafe files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneshowsecuritywarningforpotentiallyunsafefiles_iz_partname1806_1","displayName":"Prompt","description":null,"helpText":null}]},"34124216e2292fae":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200","displayName":"Run ActiveX controls and plugins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_65536","displayName":"Administrator approved","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunactivexcontrolsandplugins_iz_partname1200_1","displayName":"Prompt","description":null,"helpText":null}]},"346e668ec849cc61":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default pop-up window setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},"3493b1bfa900fb7f":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},"34f3f8bceac3af8b":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors","displayName":"Allow certificates signed using SHA-1 when issued by local trust anchors (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nWhen this setting is enabled, Microsoft Edge allows connections secured by SHA-1 signed certificates so long as the the certificate chains to a locally-installed root certificate and is otherwise valid.\r\n\r\nNote that this policy depends on the operating system (OS) certificate verification stack allowing SHA-1 signatures. If an OS update changes the OS handling of SHA-1 certificates, this policy might no longer have effect. Further, this policy is intended as a temporary workaround to give enterprises more time to move away from SHA-1. This policy will be removed in Microsoft Edge 92 releasing in mid 2021.\r\n\r\nIf you don't set this policy or set it to false, or the SHA-1 certificate chains to a publicly trusted certificate root, then Microsoft Edge won't allow certificates signed by SHA-1.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_enablesha1forlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},"347e55651656d5ec":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 120.\r\n\r\nIf you enable this policy, WebRTC peer connections can downgrade to obsolete\r\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\r\nIf you disable or don't set this policy, these TLS/DTLS versions are\r\ndisabled.\r\n\r\nThis policy was removed in Microsoft Edge 121 and is ignored if set.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},"349de932abbc85f0":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft (User)","description":"Lets screen reader users get descriptions of unlabeled images on the web.\r\n\r\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\r\n\r\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\r\n\r\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\r\n\r\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_accessibilityimagelabelsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"34f571ef08b40023":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastserviceminorversion5","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"347071d67069b642":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceservercapabilities9","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"345e0e365633d009":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail","displayName":"Replace Label - E-mail (User)","description":"This policy setting allows you to change or remove the 1st label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},"34dc84649d52a8dc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq","displayName":"Central Kurdish (Iraq) (User)","description":"Enables the editing language Central Kurdish (Iraq)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_centralkurdishiraq_1","displayName":"Enabled","description":null,"helpText":null}]},"34dce2c5950655a7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino","displayName":"Filipino (User)","description":"Enables the editing language Filipino","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_filipino_1","displayName":"Enabled","description":null,"helpText":null}]},"346032e24f4ce0f9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations","displayName":"Increase the visibility of Accessibility Checker violations (User)","description":"This policy setting controls whether a document, workbook, or spreadsheet with accessibility errors will cause a loud warning or error slab in the user interface.\r\n\r\nIf you enable this policy setting, you may specify what happens when a document, workbook, or spreadsheet has accessibility errors:\r\n\r\n- Accessibility violations do not change Prepare for Distribution loudness (default)\r\n- Accessibility errors cause the Prepare for Distribution slab to be loud\r\n- Accessibility errors or warnings cause the Prepare for Distribution slab to be loud\r\n\r\nIf you disable or do not configure this policy setting, the Accessibility Checker UI will be presented in its normal state.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_1","displayName":"Enabled","description":null,"helpText":null}]},"347be0bc1347fa00":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex","displayName":"Disable All ActiveX (User)","description":"This policy setting controls whether ActiveX controls are disabled. \r\n\r\nIf you enable this policy setting, Office 2016 applications do not initialize ActiveX controls from non-trusted locations, and do not notify the user that the ActiveX controls are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can set the trust level for ActiveX controls in the Trust Center in the 2016 versions of Microsoft Access, PowerPoint, Word, and Excel. The default configuration does not load untrusted ActiveX controls, but uses the Message Bar to prompt users about the control, and they can then choose whether to run the control.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_disableallactivex_1","displayName":"Enabled","description":null,"helpText":null}]},"3460f04d1b705fdb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning","displayName":"Enable Minimizing VBA Project Digital Signature Invalidation (User)","description":"\r\nThis policy setting allows you to reduce the number of actions in Office that will result in a document's VBA digital signature becoming invalidated.\r\n\r\nThe VBA project may be modified in certain ways that change the project storage but that do not invalidate the source code digital signature. With this setting turned off, these actions will lead to the VBA digital signature being invalidated, and the signature dropped on save if the user does not have the private key available to resign.\r\n\r\nWith this setting on, we will only perform a resign of the project if the source code signature has changed, and will keep the existing signature in other cases. If the VBA project storage is changed and saved, but the old signature retained under this feature, this can lead to an invalidation of the saved compiled VBA project state. If this happens, the VBA project will be forced to recompile each time the document is loaded. This may have negative performance impacts for larger VBA projects. Once a document is in this state, the state will persist until the VBA project is resigned.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_enableminimizevbaresigning_1","displayName":"Enabled","description":null,"helpText":null}]},"347e865fd428d655":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc07_l_datecolon263","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"341d1a10b363ba83":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_l_pathcolon04","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"34ca816305910334":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections","displayName":"Percentage of unused disk space to allow in sections (User)","description":"Sets the value in the option ''Percentage of unused space to allow in sections without optimizing''.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_1","displayName":"Enabled","description":null,"helpText":null}]},"34ff724fe89fce01":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext","displayName":"Read signed e-mail as plain text (User)","description":"This policy setting determines whether Outlook renders all digitally signed e-mail in plain text format for reading. Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. \r\n\r\nIf you enable this policy setting, the \"Read all standard mail in plain text\" check box option is selected in the \"E-mail Security\" section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays digitally signed e-mail messages in the format they were received in.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_readsignedemailasplaintext_1","displayName":"Enabled","description":null,"helpText":null}]},"345894b23a815c94":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon","displayName":"Background Color: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_000000","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_12632256","displayName":"Silver","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8421504","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16777215","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_65535","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16711808","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8453888","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16776960","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8421376","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8388736","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_32768","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_16711680","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_8388608","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_128","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_32896","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_l_backgroundcolorcolon_255","displayName":"Blue","description":null,"helpText":null}]},"349f8a1b26549258":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdayspermonth_l_pjdayspermonth20","displayName":"Days per month (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},"3438819d1ef62791":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_descriptioncolon54","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"3444ba1a502815dd":{"id":"user_vendor_msft_policy_config_settings_pagevisibilitylist","displayName":"Page Visibility List (User)","description":"Allows IT Admins to either prevent specific pages in the System Settings app from being visible or accessible, or to do so for all pages except those specified. The mode will be specified by the policy string beginning with either the string showonly: or hide:.  Pages are identified by a shortened version of their already published URIs, which is the URI minus the ms-settings: prefix. For example, if the URI for a settings page is ms-settings:bluetooth, the page identifier used in the policy will be just bluetooth. Multiple page identifiers are separated by semicolons. The following example illustrates a policy that would allow access only to the about and bluetooth pages, which have URI ms-settings:about and ms-settings:bluetooth respectively:showonly:about;bluetooth. If the policy is not specified, the behavior will be that no pages are affected. If the policy string is formatted incorrectly, it will be ignored entirely (i. e. treated as not set) to prevent the machine from becoming unserviceable if data corruption occurs. Note that if a page is already hidden for another reason, then it will remain hidden even if it is in a showonly: list. The format of the PageVisibilityList value is as follows: The value is a unicode string up to 10,000 characters long, which will be used without case sensitivity. There are two variants: one that shows only the given pages and one which hides the given pages. The first variant starts with the string showonly: and the second with the string hide:. Following the variant identifier is a semicolon-delimited list of page identifiers, which must not have any extra whitespace. Each page identifier is the ms-settings:xyz URI for the page, minus the ms-settings: prefix, so the identifier for the page with URI ms-settings:network-wifi would be just network-wifi. The default value for this setting is an empty string, which is interpreted as show everything. Example 1, specifies that only the wifi and bluetooth pages should be shown (they have URIs ms-settings:network-wifi and ms-settings:bluetooth). All other pages (and the categories they're in) will be hidden:showonly:network-wifi;bluetooth. Example 2, specifies that the wifi page should not be shown:hide:network-wifi","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#pagevisibilitylist"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":null},"34a33147aac32b44":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse","displayName":"Zoom on roll with IntelliMouse (User)","description":"If selected, lets you zoom in or out from a drawing by rolling the wheel of the Microsoft Intellimouse","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_zoomonrollwithintellimouse_1","displayName":"Enabled","description":null,"helpText":null}]},"34752ba962cf78b4":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates","displayName":"Templates (User)","description":"This policy setting allows you to specify the additional location of templates.\r\n\r\nIf you enable this policy setting, you may specify the additional location of templates. These locations are listed on the New screen of the File tab.\r\n\r\nIf you disable or do not configure this policy setting, no additional location of templates is shown.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_templates_1","displayName":"Enabled","description":null,"helpText":null}]},"34cd429187bfb8fd":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"34273b372213575d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]},"34745be7d096ca35":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext","displayName":"Asian fonts also apply to Latin text (User)","description":"Checks/unchecks the corresponding UI option. This option may be hidden in Word until certain editing languages are enabled.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_asianfontsalsoapplytolatintext_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/38.json b/public/intune-definitions/38.json index e05652f5ef64..d0faaa0af76b 100644 --- a/public/intune-definitions/38.json +++ b/public/intune-definitions/38.json @@ -1 +1 @@ -{"388147e148666a5c":{"id":"ade_accountsettings_adminaccountpasswordrotation","displayName":"Admin account password rotation period (days)","description":null,"helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},"381fb92ef4d2b7b8":{"id":"com.apple.applicationaccess_allowenablingrestrictions","displayName":"Allow Enabling Restrictions","description":"If false, disables the “Enable Restrictions” option in the Restrictions UI in Settings. In iOS 12 or later, if false, disables the “Enable ScreenTime” option in the ScreenTime UI in Settings and disables ScreenTime if already enabled. Requires a supervised device. Available in iOS 8 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenablingrestrictions_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenablingrestrictions_true","displayName":"True","description":null,"helpText":null}]},"38fcc2adea5191ed":{"id":"com.apple.applicationaccess_ratingtvshowsus","displayName":"Rating TV Shows - United States","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsus_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_1","displayName":"TV-Y","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_2","displayName":"TV-Y7","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_3","displayName":"TV-G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_4","displayName":"TV-PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_5","displayName":"TV-14","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_6","displayName":"TB-MA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_7","displayName":"All","description":null,"helpText":null}]},"38b736e9f9c65378":{"id":"com.apple.directoryservice.managed_adrestrictddns","displayName":"AD Restrict DDNS","description":"If true, allows authentication from any domain in the namespace. ","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},"38761ac4bfafd0c4":{"id":"com.apple.managedclient.preferences_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites","description":"Configure the list of URL patterns that are excluded from tracking prevention.\n\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\n\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowtrackingforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"38a79d33629c9ea7":{"id":"com.apple.managedclient.preferences_favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#favoritesbarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_favoritesbarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_favoritesbarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"38e4e77473f70f8b":{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates","displayName":"Prompt the user to select a certificate when multiple certificates match","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches \"AutoSelectCertificateForUrls\".\nIf this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\nIf this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promptonmultiplematchingcertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates_true","displayName":"Enabled","description":null,"helpText":null}]},"381871002390f7f5":{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype","displayName":"Preview Type","description":"The type previews for notifications. This key overrides the value at Settings>Notifications>Show Previews. Available in iOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_0","displayName":"Always: Previews will be shown when the device is locked and unlocked","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_1","displayName":"When Unlocked: Previews will only be shown when the device is unlocked","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_2","displayName":"Never: Previews will never be shown","description":null,"helpText":null}]},"386c41faee2f6178":{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled","displayName":"Enable additional search box in browser","description":"A search box is another text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\n\nIf you enable or don't configure this policy, the search box is visible and available for use.\nUsers can toggle the search box in Microsoft Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\n\nIf you disable this policy, search box won't be visible, and users have to use the address bar or navigate to a search engine to perform web searches.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"38648526a05be54e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed","displayName":"Live captions allowed","description":"Allow users to turn the Live captions feature on or off.\n\nLive captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge into text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device.\n\nNote: This feature isn't generally available. Clients that have the \"ExperimentationAndConfigurationServiceControl\" policy set to 'FullMode' receive the feature before broad availability. Broad availability is announced via Microsoft Edge release notes.\n\nIf you enable or don't configure this policy, users can turn on this feature or turn it off at edge://settings/accessibility.\n\nIf you disable this policy, users can't turn on this accessibility feature. If speech recognition files were downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment.\n\nIf users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) are downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"3839930e1eb6133d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\n\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL is enabled.\n\nIf you disable this policy, web page scrolling to specific text fragments via a URL is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"380c66ac41579e1d":{"id":"device_vendor_msft_defender_configuration_archivemaxdepth","displayName":"Archive Max Depth","description":"Specify the maximum folder depth to extract from archive files for scanning. If this configuration is off or not set, the default value (0) is applied, and all archives are extracted up to the deepest folder for scanning.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"388b13ab5b9c9524":{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme","displayName":"Load a specific theme","description":"Specifies which theme file is applied to the computer the first time a user logs on.\n\nIf you enable this setting, the theme that you specify will be applied when a new user logs on for the first time. This policy does not prevent the user from changing the theme or any of the theme elements such as the desktop background, color, sounds, or screen saver after the first logon.\n\nIf you disable or do not configure this setting, the default theme will be applied at the first logon.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-settheme"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_1","displayName":"Enabled","description":null,"helpText":null}]},"389def23cb51afba":{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"38692432d12b0cff":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},"381394b61713819f":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder","displayName":"Windows Sound Recorder","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder_1","displayName":"True","description":null,"helpText":null}]},"38fcddfbb9f9c9ab":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling","displayName":"The IP handling policy of WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default","displayName":"WebRTC will use all available interfaces when searching for the best path.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default_public_and_private_interfaces","displayName":"WebRTC will only use the interface connecting to the public Internet, but may connect using private IP addresses.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default_public_interface_only","displayName":"WebRTC will only use the interface connecting to the public Internet, and will not connect using private IP addresses.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_disable_non_proxied_udp","displayName":"WebRTC will use TCP on the public-facing interface, and will only use UDP if supported by a configured proxy.","description":null,"helpText":null}]},"3819ab6a8d97ccb5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode","displayName":"Sitelist parsing mode","description":"This policy controls how Google Chrome interprets sitelist/greylist policies for the Legacy Browser Support feature. It affects the following policies: BrowserSwitcherUrlList, BrowserSwitcherUrlGreylist, BrowserSwitcherUseIeSitelist, BrowserSwitcherExternalSitelistUrl, and BrowserSwitcherExternalGreylistUrl.\r\n\r\nIf 'Default' (0) or unset, URL matching is less strict. Rules that do not contain \"/\" look for a substring anywhere in the URL's hostname. Matching the path component of a URL is case-sensitive.\r\n\r\nIf 'IESiteListMode' (1), URL matching is more strict. Rules that do not contain \"/\" only match at the end of the hostname. They must also be at a domain name boundary. Matching the path component of a URL is case-insensitive. This is more compatible with Microsoft® Internet Explorer® and Microsoft® Edge®.\r\n\r\nFor example, with the rules \"example.com\" and \"acme.com/abc\":\r\n\r\n\"http://example.com/\", \"http://subdomain.example.com/\" and \"http://acme.com/abc\" match regardless of parsing mode.\r\n\r\n\"http://notexample.com/\", \"http://example.com.invalid.com/\", \"http://example.comabc/\" only match in 'Default' mode.\r\n\r\n\"http://acme.com/ABC\" only matches in 'IESiteListMode'.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"3893a66b49627680":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"3896b76171ebfbb4":{"id":"device_vendor_msft_policy_config_experience_allowmanualmdmunenrollment","displayName":"Allow Manual MDM Unenrollment","description":"Specifies whether to allow the user to delete the workplace account using the workplace control panel. If the device is Azure Active Directory joined and MDM enrolled (e. g. auto-enrolled), then disabling the MDM unenrollment has no effect. Note The MDM server can always remotely delete the account. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowmanualmdmunenrollment"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowmanualmdmunenrollment_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowmanualmdmunenrollment_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"38e52a1472591a0d":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvolumewaittimemilliseconds_profilesvolumewaittimemilliseconds","displayName":"Volume Wait Time (milliseconds) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"382df75d3c164ed3":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols","displayName":"Allow scripting of Internet Explorer WebBrowser controls","description":"This policy setting determines whether a page can control embedded WebBrowser controls via script.\n\nIf you enable this policy setting, script access to the WebBrowser control is allowed.\n\nIf you disable this policy setting, script access to the WebBrowser control is not allowed.\n\nIf you do not configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptingofinternetexplorerwebbrowsercontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"380ee02d2985d8d5":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions","displayName":"Logon options","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonelogonoptions"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"38c8416894fdafc0":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled","displayName":"Use built-in DNS client","description":"Controls whether to use the built-in DNS client.\r\n\r\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\r\n\r\nIf you enable this policy, the built-in DNS client is used, if it's available.\r\n\r\nIf you disable this policy, the client is never used.\r\n\r\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"385c8ae13aa7e0a0":{"id":"device_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled","displayName":"Enable Read Aloud feature in Microsoft Edge","description":"Enables the Read Aloud feature within Microsoft Edge.\r\nUsing this feature, users can listen to the content on the web page. This enables users to multi-task or improve their reading comprehension by hearing content at their own pace.\r\n\r\nIf you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.\r\nIf you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"384e5252fd582f2c":{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile","displayName":"Switch intranet sites to a work profile","description":"Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet.\r\n\r\nIf you enable or don't configure this policy, navigations to intranet URLs will switch to the most recently used work profile if one exists.\r\n\r\nIf you disable this policy, navigations to intranet URLs will remain in the current browser profile.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_1","displayName":"Enabled","description":null,"helpText":null}]},"3847b657ee2bc011":{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades","description":"As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS whenever possible to improve security. Navigations to captive portals, IP addresses, and non-unique hostnames are excluded from automatic upgrades.\r\n\r\nIf this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.\r\n\r\nIf this policy is disabled, Microsoft Edge won't attempt to upgrade HTTP connections to HTTPS.\r\n\r\nTo exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"382ed86e2d82f217":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for Sleeping Tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"38cbc9814f6b12c8":{"id":"device_vendor_msft_policy_config_mixedreality_headtrackingmode","displayName":"Head Tracking Mode","description":"This policy configures behavior of HUP to determine, which algorithm to use for head tracking. It requires a reboot for the policy to take effect.","helpText":"","infoUrls":[],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":null},"38403a28ae7a4b99":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_spdesignexe163","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_spdesignexe163_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_spdesignexe163_1","displayName":"True","description":null,"helpText":null}]},"381f7d0333d0cfed":{"id":"device_vendor_msft_policy_config_power_unattendedsleeptimeoutpluggedin","displayName":"Unattended Sleep Timeout Plugged In","description":"This policy setting allows you to specify the period of inactivity before Windows transitions to sleep automatically when a user is not present at the computer. If you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows automatically transitions to sleep when left unattended. If you specify 0 seconds, Windows does not automatically transition to sleep. If you disable or do not configure this policy setting, users control this setting. If the user has configured a slide show to run on the lock screen when the machine is locked, this can prevent the sleep transition from occuring. The \"Prevent enabling lock screen slide show\" policy setting can be used to disable the slide show feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#unattendedsleeptimeoutpluggedin"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":null},"38d8644fa10e12e4":{"id":"device_vendor_msft_policy_config_start_hidefrequentlyusedapps","displayName":"Hide Frequently Used Apps","description":"Enabling this policy hides the most used apps from appearing on the start menu and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidefrequentlyusedapps"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hidefrequentlyusedapps_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hidefrequentlyusedapps_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"3856625070b444a0":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions","displayName":"Cloud Policy Details","description":"\n This setting enables and configures the device-based tenant restrictions feature for Azure Active Directory.\n\n When you enable this setting, compliant applications will be prevented from accessing disallowed tenants, according to a policy set in your Azure AD tenant.\n\n Note: Creation of a policy in your home tenant is required, and additional security measures for managed devices are recommended for best protection. Refer to Azure AD Tenant Restrictions for more details.\n\n https://go.microsoft.com/fwlink/?linkid=2148762\n\n Before enabling firewall protection, ensure that an App Control for Business policy that correctly tags applications has been applied to the target devices. Enabling firewall protection without a corresponding App Control for Business policy will prevent all applications from reaching Microsoft endpoints. This firewall setting is not supported on all versions of Windows - see the following link for more information.\n For details about setting up WDAC with tenant restrictions, see https://go.microsoft.com/fwlink/?linkid=2155230","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-tenantrestrictions#tenantrestrictions-configuretenantrestrictions"],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":[{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},"38bad99420c79d97":{"id":"device_vendor_msft_policy_config_windowslogon_configautomaticrestartsignon","displayName":"Configure the mode of automatically signing in and locking last interactive user after a restart or cold boot","description":"This policy setting controls the configuration under which an automatic restart and sign on and lock occurs after a restart or cold boot. If you chose “Disabled” in the “Sign-in and lock last interactive user automatically after a restart” policy, then automatic sign on will not occur and this policy does not need to be configured.\n\nIf you enable this policy setting, you can choose one of the following two options:\n\n1. “Enabled if BitLocker is on and not suspended” specifies that automatic sign on and lock will only occur if BitLocker is active and not suspended during the reboot or shutdown. Personal data can be accessed on the device’s hard drive at this time if BitLocker is not on or suspended during an update. BitLocker suspension temporarily removes protection for system components and data but may be needed in certain circumstances to successfully update boot-critical components.\n BitLocker is suspended during updates if:\n - The device doesn’t have TPM 2.0 and PCR7, or\n - The device doesn’t use a TPM-only protector\n2. “Always Enabled” specifies that automatic sign on will happen even if BitLocker is off or suspended during reboot or shutdown. When BitLocker is not enabled, personal data is accessible on the hard drive. Automatic restart and sign on should only be run under this condition if you are confident that the configured device is in a secure physical location.\n\nIf you disable or don’t configure this setting, automatic sign on will default to the “Enabled if BitLocker is on and not suspended” behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowslogon#windowslogon-configautomaticrestartsignon"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_windowslogon_configautomaticrestartsignon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowslogon_configautomaticrestartsignon_1","displayName":"Enabled","description":null,"helpText":null}]},"3859c176279f49be":{"id":"settings_item_wallpaper","displayName":"Wallpaper","description":"A dictionary that contains wallpaper settings. This setting doesn't support user enrollment. Available in iOS 8 and later. Starting in iOS 16 and iPadOS 17, when setting the wallpaper for the first time, both locations update. After that, you can set either location separately.","helpText":null,"infoUrls":[],"categoryId":"ef7328b1-c666-40fe-a933-57b14bc77dd3","categoryName":"Wallpaper","options":null},"389af8052a8be1b5":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items in the specified applications. \r\n \r\nIf you enable this policy setting you can disable specific command bar buttons and menu items in the user interface for the selected application. The predefined list of command bar buttons and menu items you can disable becomes available to you when you enable this policy setting. \r\n \r\nIf you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"3819bd5422f5a896":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized","displayName":"Start File Explorer with ribbon minimized (User)","description":"This policy setting allows you to specify whether the ribbon appears minimized or in full when new File Explorer windows are opened. If you enable this policy setting, you can set how the ribbon appears the first time users open File Explorer and whenever they open new windows. If you disable or do not configure this policy setting, users can choose how the ribbon appears when they open new windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-explorerribbonstartsminimized"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_1","displayName":"Enabled","description":null,"helpText":null}]},"3845ee004448ac55":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurertspproxysettings_donotuseproxylocal","displayName":"Do not use proxy server for addresses beginning with (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"387eb96b1e202bae":{"id":"user_vendor_msft_policy_config_browser_lockdownfavorites","displayName":"Lockdown Favorites (User)","description":"This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge. If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off. Important Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge. If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#lockdownfavorites"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_lockdownfavorites_0","displayName":"Disabled","description":"Allowed/not locked down. Users can add, import, and make changes to the favorites.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_lockdownfavorites_1","displayName":"Enabled","description":"Prevented/locked down.","helpText":null}]},"38a20f0e8ca45cb3":{"id":"user_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride","displayName":"Prevent Smart Screen Prompt Override (User)","description":"Don't allow Windows Defender SmartScreen warning overrides","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventsmartscreenpromptoverride"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride_0","displayName":"Disabled","description":"Allowed/turned off. Users can ignore the warning and continue to the site.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},"381a511be736aed6":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_allowed","displayName":"Allow users to enable HTTPS-Only Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_disallowed","displayName":"Do not allow users to enable HTTPS-Only Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode (not supported yet)","description":null,"helpText":null}]},"38815e63e278faab":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a PostScript printer on Microsoft® Windows® different PostScript generation methods can affect printing performance.\r\n\r\nWhen this policy is set to Default, Google Chrome will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nWhen this policy is set to Type42, Google Chrome will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nWhen this policy is not set, Google Chrome will be in Default mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},"387d7498df0a7f9f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates","displayName":"Allow insecure algorithms in integrity checks on extension updates and installs (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates_1","displayName":"Enabled","description":null,"helpText":null}]},"38a94d2f2ebe0d34":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_mediacachesize","displayName":"Set media disk cache size: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"38117baa5781d1bd":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings","displayName":"Managed toolbar avatar label setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings_0","displayName":"Always display management label","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings_1","displayName":"Display management labels for 30s","description":null,"helpText":null}]},"384eb6acee8d46e5":{"id":"user_vendor_msft_policy_config_education_defaultprintername","displayName":"Default Printer Name (User)","description":"This policy sets user's default printer","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#defaultprintername"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":null},"385c13d231c3b5e5":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation","displayName":"Alternate startup file location (User)","description":"This policy setting allows you to specify the folder where files will be opened by Excel at startup.\r\n\r\nIf you enable this policy setting, you may specify the folder where files will be opened by Excel at startup. Files will be opened from this folder in addition to the XLSTART folder in the Microsoft Office installation directory (default C:\\Program Files\\Microsoft Office\\Office14\\XLSTART).\r\n\r\nIf you disable or do not configure this policy setting, files will only be opened from the XLSTART folder.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"386180a24c8892f4":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon43","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"38cd97bd898d201d":{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar","displayName":"Allow Microsoft services to provide enhanced suggestions as the user types in the Address bar (User)","description":"This policy setting allows Internet Explorer to provide enhanced suggestions as the user types in the Address bar. To provide enhanced suggestions, the user's keystrokes are sent to Microsoft through Microsoft services.\n\nIf you enable this policy setting, users receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you disable this policy setting, users won't receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you don't configure this policy setting, users can change the Suggestions setting on the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedsuggestionsinaddressbar"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},"38857f04e26619a6":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads","displayName":"Allow file downloads (User)","description":"This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download, not the zone from which the file is delivered.\n\nIf you enable this policy setting, files can be downloaded from the zone.\n\nIf you disable this policy setting, files are prevented from being downloaded from the zone.\n\n If you do not configure this policy setting, files are prevented from being downloaded from the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfiledownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"3813b71e4e07fc42":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_releasechannelpreferencedesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"383aec71d2cb2bf6":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls","displayName":"Sites that can access video capture devices without requesting permission (User)","description":"Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices. Note, however, that the pattern \"*\", which matches any URL, is not supported by this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com/\r\nhttps://[*.]contoso.edu/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},"38acfdc4ec4a7b19":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled","displayName":"Web Select Enabled (User)","description":"Web select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table.\r\n\r\nIf you enable or don't configure this policy, Web select is available through the right click context menu and the CTRL+SHIFT+X keyboard shortcut.\r\n\r\nIf you disable this policy, Web select won't be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"383976cdcc5c7e5a":{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button (User)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_1","displayName":"Enabled","description":null,"helpText":null}]},"38f63382821ca83f":{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_automaticfullscreenblockedforurlsdesc","displayName":"Block automatic full screen on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"38faf986fe515bae":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"389bda5452bfabb2":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed","displayName":"Allow launching of local files in Internet Explorer mode (User)","description":"This policy controls the availability of the --ie-mode-file-url command line argument which is used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nIf you set this policy to false, the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"387a9474655c6b28":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled","displayName":"Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer (User)","description":"This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory.\r\n\r\nIf you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the directory with no items in the directory selected.\r\n\r\nIf you disable or don't configure this policy, file URL links will not open.\r\n\r\nMicrosoft Edge uses the definition of intranet zone as configured for Internet Explorer. Note that https://localhost/ is specifically blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default.\r\n\r\nUsers may opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is disabled.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"381471a2fb06d7ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},"386407584706863a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverinfo3","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"380268c294d3ad69":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber","displayName":"Log File Entries Number (User)","description":"Specify the number of log entries to be removed from the log file when the maximum size limit is exceeded. (1-1000)","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_1","displayName":"Enabled","description":null,"helpText":null}]},"3817d8aa82cf18cd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama","displayName":"Spanish (Panama) (User)","description":"Enables the editing language Spanish (Panama)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama_1","displayName":"Enabled","description":null,"helpText":null}]},"38cb501c345f2ed5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco","displayName":"Tamazight (Arabic, Morocco) (User)","description":"Enables the editing language \"Tamazight (Arabic, Morocco)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},"38f2ae829a9b9880":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_0","displayName":"Accessibility violations do not change loudness (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_1","displayName":"Accessibility errors cause slab to be loud","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_2","displayName":"Accessibility errors or warnings cause slab to be loud","description":null,"helpText":null}]},"38b77e6c424ac3c0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"3837e8fae0584893":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_descriptioncolon248","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"38f8813d027a0181":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort","displayName":"Reduce the end time of short appointments and meetings by a specified number of minutes (User)","description":"\r\n This policy setting allows you to specify how many minutes to reduce the end time of a short appointment or meeting by when a user creates an appointment or meeting. A short appointment or meeting is one that lasts for less than one hour.\r\n\r\n If you enable this policy setting, you specify the number of minutes to reduce the end time of a short appointment or meeting by when a user creates an appointment or meeting. The user can’t change this value by going to File > Options > Calendar.\r\n\r\n Note: You should also enable the “End appointments and meetings early” policy setting.\r\n\r\n If you disable or don’t configure this policy setting, the default value of 5 minutes is used or whatever the user specifies by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_1","displayName":"Enabled","description":null,"helpText":null}]},"38413f933af1179f":{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver","displayName":"Authentication with Exchange Server (User) (Deprecated)","description":"This policy setting controls which authentication method Outlook uses to authenticate with Microsoft Exchange Server. Note - Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more secure authentication method and is supported on Windows 2000 Server and later versions. NTLM authentication is supported in pre-Windows 2000 environments.\r\n \r\nIf you enable this policy setting, you can choose from three different options for controlling how Outlook authenticates with Microsoft Exchange Server:\r\n\r\n- Kerberos/NTLM password authentication. Outlook attempts to authenticate using the Kerberos authentication protocol. If this attempt fails, Outlook attempts to authenticate using NTLM. This option is the default configuration.\r\n\r\n- Kerberos password authentication. Outlook attempts to authenticate using the Kerberos protocol only.\r\n\r\n- NTLM password authentication. Outlook attempts to authenticate using NTLM only.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will attempt to authenticate using the Kerberos authentication protocol. If it cannot (because no Windows 2000 or later domain controllers are available), it will authenticate using NTLM.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_1","displayName":"Enabled","description":null,"helpText":null}]},"388d5bc394141b78":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload","displayName":"Wait to show users a cloud-based presentation until all content is downloaded (User)","description":"\r\nThis policy setting allows you to control whether PowerPoint waits until all content is downloaded before showing a presentation to the user. This policy setting applies to presentations that are opened from a cloud-based location, such as OneDrive Personal, OneDrive for Business, or SharePoint Online.\r\n\r\nBy default, when the user opens a cloud-based presentation in PowerPoint, the user can view the presentation while other content, such as images or video, continues to download. But, some functionality, such as editing and presenting, is limited or not available until the entire contents of the presentation are downloaded.\r\n\r\nIf you enable this policy setting, PowerPoint will wait, when opening a cloud-based presentation, until the entire contents of the presentation are downloaded before showing the presentation to the user.\r\n\r\nYou may want to enable this policy setting if you have add-ins or automated processes that rely on the entire contents of the presentation being available and fully editable as soon as the presentation is shown.\r\n\r\nIf you disable or don't configure this setting, PowerPoint opens cloud-based files more quickly, so the user can start viewing the presentation while the other content downloads.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload_1","displayName":"Enabled","description":null,"helpText":null}]},"3848607a7ed225a7":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"382ff7618a8623a8":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"38ba7209ea8ad106":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday","displayName":"Hours per day (User)","description":"Defines the number of hours that you want Project to assign to a task when the user enters a duration of one day.\r\n\r\nIf you enable this setting, day-long tasks will be assigned the number of hours that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_1","displayName":"Enabled","description":null,"helpText":null}]},"388322be4bce7c68":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"3863fb6105d35dcd":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"3826d0e11b5be1fd":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"388147e148666a5c":{"id":"ade_accountsettings_adminaccountpasswordrotation","displayName":"Admin account password rotation period (days)","description":null,"helpText":null,"infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},"381fb92ef4d2b7b8":{"id":"com.apple.applicationaccess_allowenablingrestrictions","displayName":"Allow Enabling Restrictions","description":"If false, disables the “Enable Restrictions” option in the Restrictions UI in Settings. In iOS 12 or later, if false, disables the “Enable ScreenTime” option in the ScreenTime UI in Settings and disables ScreenTime if already enabled. Requires a supervised device. Available in iOS 8 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenablingrestrictions_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenablingrestrictions_true","displayName":"True","description":null,"helpText":null}]},"38fcc2adea5191ed":{"id":"com.apple.applicationaccess_ratingtvshowsus","displayName":"Rating TV Shows - United States","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsus_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_1","displayName":"TV-Y","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_2","displayName":"TV-Y7","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_3","displayName":"TV-G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_4","displayName":"TV-PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_5","displayName":"TV-14","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_6","displayName":"TB-MA","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsus_7","displayName":"All","description":null,"helpText":null}]},"38b736e9f9c65378":{"id":"com.apple.directoryservice.managed_adrestrictddns","displayName":"AD Restrict DDNS","description":"If true, allows authentication from any domain in the namespace. ","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},"38761ac4bfafd0c4":{"id":"com.apple.managedclient.preferences_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites","description":"Configure the list of URL patterns that are excluded from tracking prevention.\n\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\n\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowtrackingforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"38a79d33629c9ea7":{"id":"com.apple.managedclient.preferences_favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\n\nIf you enable this policy, users will see the favorites bar.\n\nIf you disable this policy, users won't see the favorites bar.\n\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#favoritesbarenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_favoritesbarenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_favoritesbarenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"38e4e77473f70f8b":{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates","displayName":"Prompt the user to select a certificate when multiple certificates match","description":"This policy controls whether the user is prompted to select a client certificate when more than one certificate matches \"AutoSelectCertificateForUrls\".\nIf this policy is set to True, the user is prompted to select a client certificate whenever the auto-selection policy matches multiple certificates.\nIf this policy is set to False or not set, the user may only be prompted when no certificate matches the auto-selection.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promptonmultiplematchingcertificates"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promptonmultiplematchingcertificates_true","displayName":"Enabled","description":null,"helpText":null}]},"381871002390f7f5":{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype","displayName":"Preview Type","description":"The type previews for notifications. This key overrides the value at Settings>Notifications>Show Previews. Available in iOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_0","displayName":"Always: Previews will be shown when the device is locked and unlocked","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_1","displayName":"When Unlocked: Previews will only be shown when the device is unlocked","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_previewtype_2","displayName":"Never: Previews will never be shown","description":null,"helpText":null}]},"386c41faee2f6178":{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled","displayName":"Enable additional search box in browser","description":"A search box is another text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\n\nIf you enable or don't configure this policy, the search box is visible and available for use.\nUsers can toggle the search box in Microsoft Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\n\nIf you disable this policy, search box won't be visible, and users have to use the address bar or navigate to a search engine to perform web searches.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.additionalsearchboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"38648526a05be54e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed","displayName":"Live captions allowed","description":"Allow users to turn the Live captions feature on or off.\n\nLive captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge into text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device.\n\nNote: This feature isn't generally available. Clients that have the \"ExperimentationAndConfigurationServiceControl\" policy set to 'FullMode' receive the feature before broad availability. Broad availability is announced via Microsoft Edge release notes.\n\nIf you enable or don't configure this policy, users can turn on this feature or turn it off at edge://settings/accessibility.\n\nIf you disable this policy, users can't turn on this accessibility feature. If speech recognition files were downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment.\n\nIf users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) are downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.livecaptionsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"3839930e1eb6133d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\n\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL is enabled.\n\nIf you disable this policy, web page scrolling to specific text fragments via a URL is disabled.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.scrolltotextfragmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"380c66ac41579e1d":{"id":"device_vendor_msft_defender_configuration_archivemaxdepth","displayName":"Archive Max Depth","description":"Specify the maximum folder depth to extract from archive files for scanning. If this configuration is off or not set, the default value (0) is applied, and all archives are extracted up to the deepest folder for scanning.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"388b13ab5b9c9524":{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme","displayName":"Load a specific theme","description":"Specifies which theme file is applied to the computer the first time a user logs on.\n\nIf you enable this setting, the theme that you specify will be applied when a new user logs on for the first time. This policy does not prevent the user from changing the theme or any of the theme elements such as the desktop background, color, sounds, or screen saver after the first logon.\n\nIf you disable or do not configure this setting, the default theme will be applied at the first logon.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-settheme"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_1","displayName":"Enabled","description":null,"helpText":null}]},"389def23cb51afba":{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"38692432d12b0cff":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},"381394b61713819f":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder","displayName":"Windows Sound Recorder","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowssoundrecorder_1","displayName":"True","description":null,"helpText":null}]},"38fcddfbb9f9c9ab":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling","displayName":"The IP handling policy of WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default","displayName":"WebRTC will use all available interfaces when searching for the best path.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default_public_and_private_interfaces","displayName":"WebRTC will only use the interface connecting to the public Internet, but may connect using private IP addresses.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_default_public_interface_only","displayName":"WebRTC will only use the interface connecting to the public Internet, and will not connect using private IP addresses.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_webrtciphandling_disable_non_proxied_udp","displayName":"WebRTC will use TCP on the public-facing interface, and will only use UDP if supported by a configured proxy.","description":null,"helpText":null}]},"3819ab6a8d97ccb5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode","displayName":"Sitelist parsing mode","description":"This policy controls how Google Chrome interprets sitelist/greylist policies for the Legacy Browser Support feature. It affects the following policies: BrowserSwitcherUrlList, BrowserSwitcherUrlGreylist, BrowserSwitcherUseIeSitelist, BrowserSwitcherExternalSitelistUrl, and BrowserSwitcherExternalGreylistUrl.\r\n\r\nIf 'Default' (0) or unset, URL matching is less strict. Rules that do not contain \"/\" look for a substring anywhere in the URL's hostname. Matching the path component of a URL is case-sensitive.\r\n\r\nIf 'IESiteListMode' (1), URL matching is more strict. Rules that do not contain \"/\" only match at the end of the hostname. They must also be at a domain name boundary. Matching the path component of a URL is case-insensitive. This is more compatible with Microsoft® Internet Explorer® and Microsoft® Edge®.\r\n\r\nFor example, with the rules \"example.com\" and \"acme.com/abc\":\r\n\r\n\"http://example.com/\", \"http://subdomain.example.com/\" and \"http://acme.com/abc\" match regardless of parsing mode.\r\n\r\n\"http://notexample.com/\", \"http://example.com.invalid.com/\", \"http://example.comabc/\" only match in 'Default' mode.\r\n\r\n\"http://acme.com/ABC\" only matches in 'IESiteListMode'.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherparsingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"3893a66b49627680":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"3896b76171ebfbb4":{"id":"device_vendor_msft_policy_config_experience_allowmanualmdmunenrollment","displayName":"Allow Manual MDM Unenrollment","description":"Specifies whether to allow the user to delete the workplace account using the workplace control panel. If the device is Azure Active Directory joined and MDM enrolled (e. g. auto-enrolled), then disabling the MDM unenrollment has no effect. Note The MDM server can always remotely delete the account. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowmanualmdmunenrollment"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowmanualmdmunenrollment_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowmanualmdmunenrollment_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"38e52a1472591a0d":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvolumewaittimemilliseconds_profilesvolumewaittimemilliseconds","displayName":"Volume Wait Time (milliseconds) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"382df75d3c164ed3":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols","displayName":"Allow scripting of Internet Explorer WebBrowser controls","description":"This policy setting determines whether a page can control embedded WebBrowser controls via script.\n\nIf you enable this policy setting, script access to the WebBrowser control is allowed.\n\nIf you disable this policy setting, script access to the WebBrowser control is not allowed.\n\nIf you do not configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptingofinternetexplorerwebbrowsercontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptingofinternetexplorerwebbrowsercontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"380ee02d2985d8d5":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions","displayName":"Logon options","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonelogonoptions"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"38c8416894fdafc0":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled","displayName":"Use built-in DNS client","description":"Controls whether to use the built-in DNS client.\r\n\r\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\r\n\r\nIf you enable this policy, the built-in DNS client is used, if it's available.\r\n\r\nIf you disable this policy, the client is never used.\r\n\r\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"385c8ae13aa7e0a0":{"id":"device_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled","displayName":"Enable Read Aloud feature in Microsoft Edge","description":"Enables the Read Aloud feature within Microsoft Edge.\r\nUsing this feature, users can listen to the content on the web page. This enables users to multi-task or improve their reading comprehension by hearing content at their own pace.\r\n\r\nIf you enable this policy or don't configure it, the Read Aloud option shows up in the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.\r\nIf you disable this policy, users can't access the Read Aloud feature from the address bar, right click context menu, more menu, on the PDF toolbar, and within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev113~policy~microsoft_edge_readaloudenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"384e5252fd582f2c":{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile","displayName":"Switch intranet sites to a work profile","description":"Allows Microsoft Edge to switch to the appropriate profile when Microsoft Edge detects that a URL is the intranet.\r\n\r\nIf you enable or don't configure this policy, navigations to intranet URLs will switch to the most recently used work profile if one exists.\r\n\r\nIf you disable this policy, navigations to intranet URLs will remain in the current browser profile.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~identity_switchintranetsitestoworkprofile_1","displayName":"Enabled","description":null,"helpText":null}]},"3847b657ee2bc011":{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled","displayName":"Enable automatic HTTPS upgrades","description":"As of Microsoft Edge version 120, Microsoft Edge tries to upgrade HTTP navigations to HTTPS whenever possible to improve security. Navigations to captive portals, IP addresses, and non-unique hostnames are excluded from automatic upgrades.\r\n\r\nIf this policy is enabled or not configured, automatic HTTPS upgrades are turned on by default.\r\n\r\nIf this policy is disabled, Microsoft Edge won't attempt to upgrade HTTP connections to HTTPS.\r\n\r\nTo exempt specific hostnames or hostname patterns from being upgraded, use the HttpAllowlist policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge_httpsupgradesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"382ed86e2d82f217":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for Sleeping Tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"38cbc9814f6b12c8":{"id":"device_vendor_msft_policy_config_mixedreality_headtrackingmode","displayName":"Head Tracking Mode","description":"This policy configures behavior of HUP to determine, which algorithm to use for head tracking. It requires a reboot for the policy to take effect.","helpText":"","infoUrls":[],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":null},"38403a28ae7a4b99":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_spdesignexe163","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_spdesignexe163_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_spdesignexe163_1","displayName":"True","description":null,"helpText":null}]},"381f7d0333d0cfed":{"id":"device_vendor_msft_policy_config_power_unattendedsleeptimeoutpluggedin","displayName":"Unattended Sleep Timeout Plugged In","description":"This policy setting allows you to specify the period of inactivity before Windows transitions to sleep automatically when a user is not present at the computer. If you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows automatically transitions to sleep when left unattended. If you specify 0 seconds, Windows does not automatically transition to sleep. If you disable or do not configure this policy setting, users control this setting. If the user has configured a slide show to run on the lock screen when the machine is locked, this can prevent the sleep transition from occuring. The \"Prevent enabling lock screen slide show\" policy setting can be used to disable the slide show feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#unattendedsleeptimeoutpluggedin"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":null},"38d8644fa10e12e4":{"id":"device_vendor_msft_policy_config_start_hidefrequentlyusedapps","displayName":"Hide Frequently Used Apps","description":"Enabling this policy hides the most used apps from appearing on the start menu and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidefrequentlyusedapps"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hidefrequentlyusedapps_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hidefrequentlyusedapps_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"3856625070b444a0":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions","displayName":"Cloud Policy Details","description":"\n This setting enables and configures the device-based tenant restrictions feature for Azure Active Directory.\n\n When you enable this setting, compliant applications will be prevented from accessing disallowed tenants, according to a policy set in your Azure AD tenant.\n\n Note: Creation of a policy in your home tenant is required, and additional security measures for managed devices are recommended for best protection. Refer to Azure AD Tenant Restrictions for more details.\n\n https://go.microsoft.com/fwlink/?linkid=2148762\n\n Before enabling firewall protection, ensure that an App Control for Business policy that correctly tags applications has been applied to the target devices. Enabling firewall protection without a corresponding App Control for Business policy will prevent all applications from reaching Microsoft endpoints. This firewall setting is not supported on all versions of Windows - see the following link for more information.\n For details about setting up WDAC with tenant restrictions, see https://go.microsoft.com/fwlink/?linkid=2155230","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-tenantrestrictions#tenantrestrictions-configuretenantrestrictions"],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":[{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},"38bad99420c79d97":{"id":"device_vendor_msft_policy_config_windowslogon_configautomaticrestartsignon","displayName":"Configure the mode of automatically signing in and locking last interactive user after a restart or cold boot","description":"This policy setting controls the configuration under which an automatic restart and sign on and lock occurs after a restart or cold boot. If you chose “Disabled” in the “Sign-in and lock last interactive user automatically after a restart” policy, then automatic sign on will not occur and this policy does not need to be configured.\n\nIf you enable this policy setting, you can choose one of the following two options:\n\n1. “Enabled if BitLocker is on and not suspended” specifies that automatic sign on and lock will only occur if BitLocker is active and not suspended during the reboot or shutdown. Personal data can be accessed on the device’s hard drive at this time if BitLocker is not on or suspended during an update. BitLocker suspension temporarily removes protection for system components and data but may be needed in certain circumstances to successfully update boot-critical components.\n BitLocker is suspended during updates if:\n - The device doesn’t have TPM 2.0 and PCR7, or\n - The device doesn’t use a TPM-only protector\n2. “Always Enabled” specifies that automatic sign on will happen even if BitLocker is off or suspended during reboot or shutdown. When BitLocker is not enabled, personal data is accessible on the hard drive. Automatic restart and sign on should only be run under this condition if you are confident that the configured device is in a secure physical location.\n\nIf you disable or don’t configure this setting, automatic sign on will default to the “Enabled if BitLocker is on and not suspended” behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowslogon#windowslogon-configautomaticrestartsignon"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_windowslogon_configautomaticrestartsignon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowslogon_configautomaticrestartsignon_1","displayName":"Enabled","description":null,"helpText":null}]},"387332b68c91e522":{"id":"dnsproxy_appbundleidentifier","displayName":"App Bundle Identifier","description":"The bundle identifier of the app containing the DNS proxy network extension.","helpText":null,"infoUrls":[],"categoryId":"4a6c4488-bbcf-4b5b-9156-7aa1b10a6010","categoryName":"DNS Proxy","options":null},"3859c176279f49be":{"id":"settings_item_wallpaper","displayName":"Wallpaper","description":"A dictionary that contains wallpaper settings. This setting doesn't support user enrollment. Available in iOS 8 and later. Starting in iOS 16 and iPadOS 17, when setting the wallpaper for the first time, both locations update. After that, you can set either location separately.","helpText":null,"infoUrls":[],"categoryId":"ef7328b1-c666-40fe-a933-57b14bc77dd3","categoryName":"Wallpaper","options":null},"389af8052a8be1b5":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable specific command bar buttons and menu items in the specified applications. \r\n \r\nIf you enable this policy setting you can disable specific command bar buttons and menu items in the user interface for the selected application. The predefined list of command bar buttons and menu items you can disable becomes available to you when you enable this policy setting. \r\n \r\nIf you disable or do not configure this policy setting, the predefined list of command bar buttons and menu items are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"3819bd5422f5a896":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized","displayName":"Start File Explorer with ribbon minimized (User)","description":"This policy setting allows you to specify whether the ribbon appears minimized or in full when new File Explorer windows are opened. If you enable this policy setting, you can set how the ribbon appears the first time users open File Explorer and whenever they open new windows. If you disable or do not configure this policy setting, users can choose how the ribbon appears when they open new windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-explorerribbonstartsminimized"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_explorerribbonstartsminimized_1","displayName":"Enabled","description":null,"helpText":null}]},"3845ee004448ac55":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurertspproxysettings_donotuseproxylocal","displayName":"Do not use proxy server for addresses beginning with (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"387eb96b1e202bae":{"id":"user_vendor_msft_policy_config_browser_lockdownfavorites","displayName":"Lockdown Favorites (User)","description":"This policy setting lets you decide whether employees can add, import, sort, or edit the Favorites list on Microsoft Edge. If you enable this setting, employees won't be able to add, import, or change anything in the Favorites list. Also as part of this, Save a Favorite, Import settings, and the context menu items (such as, Create a new folder) are all turned off. Important Don't enable both this setting and the Keep favorites in sync between Internet Explorer and Microsoft Edge setting. Enabling both settings stops employees from syncing their favorites between Internet Explorer and Microsoft Edge. If you disable or don't configure this setting (default), employees can add, import and make changes to the Favorites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#lockdownfavorites"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_lockdownfavorites_0","displayName":"Disabled","description":"Allowed/not locked down. Users can add, import, and make changes to the favorites.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_lockdownfavorites_1","displayName":"Enabled","description":"Prevented/locked down.","helpText":null}]},"38a20f0e8ca45cb3":{"id":"user_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride","displayName":"Prevent Smart Screen Prompt Override (User)","description":"Don't allow Windows Defender SmartScreen warning overrides","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventsmartscreenpromptoverride"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride_0","displayName":"Disabled","description":"Allowed/turned off. Users can ignore the warning and continue to the site.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_preventsmartscreenpromptoverride_1","displayName":"Enabled","description":"Prevented/turned on.","helpText":null}]},"381a511be736aed6":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode","displayName":"Allow HTTPS-Only Mode to be enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_allowed","displayName":"Allow users to enable HTTPS-Only Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_disallowed","displayName":"Do not allow users to enable HTTPS-Only Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_httpsonlymode_httpsonlymode_force_enabled","displayName":"Force enable HTTPS-Only Mode (not supported yet)","description":null,"helpText":null}]},"38815e63e278faab":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a PostScript printer on Microsoft® Windows® different PostScript generation methods can affect printing performance.\r\n\r\nWhen this policy is set to Default, Google Chrome will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nWhen this policy is set to Type42, Google Chrome will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nWhen this policy is not set, Google Chrome will be in Default mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},"387d7498df0a7f9f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates","displayName":"Allow insecure algorithms in integrity checks on extension updates and installs (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_extensionallowinsecureupdates_1","displayName":"Enabled","description":null,"helpText":null}]},"38a94d2f2ebe0d34":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_mediacachesize","displayName":"Set media disk cache size: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"38117baa5781d1bd":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings","displayName":"Managed toolbar avatar label setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings_0","displayName":"Always display management label","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_toolbaravatarlabelsettings_1","displayName":"Display management labels for 30s","description":null,"helpText":null}]},"384eb6acee8d46e5":{"id":"user_vendor_msft_policy_config_education_defaultprintername","displayName":"Default Printer Name (User)","description":"This policy sets user's default printer","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Education#defaultprintername"],"categoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","categoryName":"Education","options":null},"385c13d231c3b5e5":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation","displayName":"Alternate startup file location (User)","description":"This policy setting allows you to specify the folder where files will be opened by Excel at startup.\r\n\r\nIf you enable this policy setting, you may specify the folder where files will be opened by Excel at startup. Files will be opened from this folder in addition to the XLSTART folder in the Microsoft Office installation directory (default C:\\Program Files\\Microsoft Office\\Office14\\XLSTART).\r\n\r\nIf you disable or do not configure this policy setting, files will only be opened from the XLSTART folder.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alternatestartupfilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"386180a24c8892f4":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon43","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"38cd97bd898d201d":{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar","displayName":"Allow Microsoft services to provide enhanced suggestions as the user types in the Address bar (User)","description":"This policy setting allows Internet Explorer to provide enhanced suggestions as the user types in the Address bar. To provide enhanced suggestions, the user's keystrokes are sent to Microsoft through Microsoft services.\n\nIf you enable this policy setting, users receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you disable this policy setting, users won't receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you don't configure this policy setting, users can change the Suggestions setting on the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedsuggestionsinaddressbar"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},"38857f04e26619a6":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads","displayName":"Allow file downloads (User)","description":"This policy setting allows you to manage whether file downloads are permitted from the zone. This option is determined by the zone of the page with the link causing the download, not the zone from which the file is delivered.\n\nIf you enable this policy setting, files can be downloaded from the zone.\n\nIf you disable this policy setting, files are prevented from being downloaded from the zone.\n\n If you do not configure this policy setting, files are prevented from being downloaded from the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfiledownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"3813b71e4e07fc42":{"id":"user_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_releasechannelpreference_releasechannelpreferencedesc_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"383aec71d2cb2bf6":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls","displayName":"Sites that can access video capture devices without requesting permission (User)","description":"Specify websites, based on URL patterns, that can use video capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to video capture devices. Note, however, that the pattern \"*\", which matches any URL, is not supported by this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com/\r\nhttps://[*.]contoso.edu/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_videocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},"38acfdc4ec4a7b19":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled","displayName":"Web Select Enabled (User)","description":"Web select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table.\r\n\r\nIf you enable or don't configure this policy, Web select is available through the right click context menu and the CTRL+SHIFT+X keyboard shortcut.\r\n\r\nIf you disable this policy, Web select won't be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"383976cdcc5c7e5a":{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button (User)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_1","displayName":"Enabled","description":null,"helpText":null}]},"38f63382821ca83f":{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_automaticfullscreenblockedforurlsdesc","displayName":"Block automatic full screen on specified sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"38faf986fe515bae":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"389bda5452bfabb2":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed","displayName":"Allow launching of local files in Internet Explorer mode (User)","description":"This policy controls the availability of the --ie-mode-file-url command line argument which is used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nIf you set this policy to false, the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"387a9474655c6b28":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled","displayName":"Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer (User)","description":"This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory.\r\n\r\nIf you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the directory with no items in the directory selected.\r\n\r\nIf you disable or don't configure this policy, file URL links will not open.\r\n\r\nMicrosoft Edge uses the definition of intranet zone as configured for Internet Explorer. Note that https://localhost/ is specifically blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default.\r\n\r\nUsers may opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is disabled.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"381471a2fb06d7ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffexcel_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},"386407584706863a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverinfo3","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"380268c294d3ad69":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber","displayName":"Log File Entries Number (User)","description":"Specify the number of log entries to be removed from the log file when the maximum size limit is exceeded. (1-1000)","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_1","displayName":"Enabled","description":null,"helpText":null}]},"3817d8aa82cf18cd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama","displayName":"Spanish (Panama) (User)","description":"Enables the editing language Spanish (Panama)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishpanama_1","displayName":"Enabled","description":null,"helpText":null}]},"38cb501c345f2ed5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco","displayName":"Tamazight (Arabic, Morocco) (User)","description":"Enables the editing language \"Tamazight (Arabic, Morocco)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamazightarabicmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},"38f2ae829a9b9880":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_0","displayName":"Accessibility violations do not change loudness (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_1","displayName":"Accessibility errors cause slab to be loud","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_increasevisibilityofaccessibilitycheckerviolations_l_increasevisibilityofaccessibilitycheckerviolationsdropid_2","displayName":"Accessibility errors or warnings cause slab to be loud","description":null,"helpText":null}]},"38b77e6c424ac3c0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey08_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"3837e8fae0584893":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_descriptioncolon248","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"38f8813d027a0181":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort","displayName":"Reduce the end time of short appointments and meetings by a specified number of minutes (User)","description":"\r\n This policy setting allows you to specify how many minutes to reduce the end time of a short appointment or meeting by when a user creates an appointment or meeting. A short appointment or meeting is one that lasts for less than one hour.\r\n\r\n If you enable this policy setting, you specify the number of minutes to reduce the end time of a short appointment or meeting by when a user creates an appointment or meeting. The user can’t change this value by going to File > Options > Calendar.\r\n\r\n Note: You should also enable the “End appointments and meetings early” policy setting.\r\n\r\n If you disable or don’t configure this policy setting, the default value of 5 minutes is used or whatever the user specifies by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlyshort_1","displayName":"Enabled","description":null,"helpText":null}]},"38413f933af1179f":{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver","displayName":"Authentication with Exchange Server (User) (Deprecated)","description":"This policy setting controls which authentication method Outlook uses to authenticate with Microsoft Exchange Server. Note - Exchange Server supports the Kerberos authentication protocol and NTLM for authentication. The Kerberos protocol is the more secure authentication method and is supported on Windows 2000 Server and later versions. NTLM authentication is supported in pre-Windows 2000 environments.\r\n \r\nIf you enable this policy setting, you can choose from three different options for controlling how Outlook authenticates with Microsoft Exchange Server:\r\n\r\n- Kerberos/NTLM password authentication. Outlook attempts to authenticate using the Kerberos authentication protocol. If this attempt fails, Outlook attempts to authenticate using NTLM. This option is the default configuration.\r\n\r\n- Kerberos password authentication. Outlook attempts to authenticate using the Kerberos protocol only.\r\n\r\n- NTLM password authentication. Outlook attempts to authenticate using NTLM only.\r\n\r\nIf you disable or do not configure this policy setting, Outlook will attempt to authenticate using the Kerberos authentication protocol. If it cannot (because no Windows 2000 or later domain controllers are available), it will authenticate using NTLM.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_1","displayName":"Enabled","description":null,"helpText":null}]},"388d5bc394141b78":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload","displayName":"Wait to show users a cloud-based presentation until all content is downloaded (User)","description":"\r\nThis policy setting allows you to control whether PowerPoint waits until all content is downloaded before showing a presentation to the user. This policy setting applies to presentations that are opened from a cloud-based location, such as OneDrive Personal, OneDrive for Business, or SharePoint Online.\r\n\r\nBy default, when the user opens a cloud-based presentation in PowerPoint, the user can view the presentation while other content, such as images or video, continues to download. But, some functionality, such as editing and presenting, is limited or not available until the entire contents of the presentation are downloaded.\r\n\r\nIf you enable this policy setting, PowerPoint will wait, when opening a cloud-based presentation, until the entire contents of the presentation are downloaded before showing the presentation to the user.\r\n\r\nYou may want to enable this policy setting if you have add-ins or automated processes that rely on the entire contents of the presentation being available and fully editable as soon as the presentation is shown.\r\n\r\nIf you disable or don't configure this setting, PowerPoint opens cloud-based files more quickly, so the user can start viewing the presentation while the other content downloads.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disableincrementaldownload_1","displayName":"Enabled","description":null,"helpText":null}]},"3848607a7ed225a7":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"382ff7618a8623a8":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon77","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"38ba7209ea8ad106":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday","displayName":"Hours per day (User)","description":"Defines the number of hours that you want Project to assign to a task when the user enters a duration of one day.\r\n\r\nIf you enable this setting, day-long tasks will be assigned the number of hours that you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjhoursperday_1","displayName":"Enabled","description":null,"helpText":null}]},"388322be4bce7c68":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_datecolon65","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"3863fb6105d35dcd":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"3826d0e11b5be1fd":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/3d.json b/public/intune-definitions/3d.json index 25e1ada02e23..62848d4447d0 100644 --- a/public/intune-definitions/3d.json +++ b/public/intune-definitions/3d.json @@ -1 +1 @@ -{"3ddedd53546ec980":{"id":"app_privacy_permissiondefaults_generickey_bluetooth","displayName":"Bluetooth","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of Bluetooth.\n* `Allow`: The app privacy permission default is set to allow use of Bluetooth.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_bluetooth_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_bluetooth_1","displayName":"Allow","description":null,"helpText":null}]},"3d4e3ea9c358a7e6":{"id":"com.apple.applicationaccess_allowerasecontentandsettings","displayName":"Allow Erase Content And Settings","description":"If false, disables the Erase All Content And Settings option in the Reset UI. Requires a supervised device. Available in iOS 8 and later, and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowerasecontentandsettings_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowerasecontentandsettings_true","displayName":"True","description":null,"helpText":null}]},"3d18e6570a0febf6":{"id":"com.apple.applicationaccess_allowlistedappbundleids","displayName":"Allow Listed App Bundle IDs","description":"If present, this property allows only bundle IDs listed in the array to be shown or launchable. Include the value com.apple.webapp to allow all webclips. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},"3da4813022f61a9c":{"id":"com.apple.dock_minintoapp-immutable","displayName":"Minimize Into Application Immutable","description":"If true, disables the \"Minimize windows into application icon\" checkbox.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_minintoapp-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_minintoapp-immutable_true","displayName":"True","description":null,"helpText":null}]},"3d1352d6ae8fc927":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_lcid","displayName":"Microsoft Teams LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"3db81f609994d7e7":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app","displayName":"Skype for Business","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"3d8f333d94a1512d":{"id":"com.apple.managedclient.preferences_remotedebuggingallowed","displayName":"Allow remote debugging","description":"Controls whether users may use remote debugging.\n\nIf you enable or don't configure this policy, users may use remote debugging by specifying --remote-debug-port and --remote-debugging-pipe command line switches.\n\nIf you disable this policy, users are not allowed to use remote debugging.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#remotedebuggingallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_remotedebuggingallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_remotedebuggingallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"3d6d7e14efa75156":{"id":"com.apple.proxy.http.global_proxypacurl","displayName":"Proxy PAC URL","description":"The URL of the PAC file that defines the proxy configuration. Starting in iOS 13 and macOS 10.15, only URLs that begin with http:// or https:// are allowed.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},"3d46625a198207a8":{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates (Deprecated)","description":"This policy is deprecated because we are moving to a new policy. It won't work in Microsoft Edge as soon as version 104. The new policy to use is \"EdgeAssetDeliveryServiceEnabled\".\n\nLets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\n\nIf you enable this setting or the setting is unconfigured, the list of available templates are downloaded in the background from a Microsoft service every 24 hours.\n\nIf you disable this setting the list of available templates are downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"3dcb14c4e08c2cf9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxybypasslist","displayName":"Configure proxy bypass rules (Deprecated)","description":"This policy is deprecated, use \"ProxySettings\" instead. It doesn't work in Microsoft Edge version 91.\n\nDefines a list of hosts for which Microsoft Edge bypasses any proxy.\n\nThis policy is applied only if the \"ProxySettings\" policy isn't specified and you selected either fixed_servers or pac_script in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy.\n\nIf you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you specified any other method for setting proxy policies.\n\nFor more detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},"3dd7e775374929ad":{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_approvedactivexinstallsiteslist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":null},"3daaafd2182799ae":{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication","displayName":"Hash Publication for BranchCache","description":"This policy setting specifies whether a hash generation service generates hashes, also called content information, for data that is stored in shared folders. This policy setting must be applied to server computers that have the File Services role and both the File Server and the BranchCache for Network Files role services installed.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, hash publication settings are not applied to file servers. In the circumstance where file servers are domain members but you do not want to enable BranchCache on all file servers, you can specify Not Configured for this domain Group Policy setting, and then configure local machine policy to enable BranchCache on individual file servers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual servers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, hash publication is turned on for all file servers where Group Policy is applied. For example, if Hash Publication for BranchCache is enabled in domain Group Policy, hash publication is turned on for all domain member file servers to which the policy is applied. The file servers are then able to create content information for all content that is stored in BranchCache-enabled file shares.\r\n\r\n- Disabled. With this selection, hash publication is turned off for all file servers where Group Policy is applied.\r\n\r\nIn circumstances where this policy setting is enabled, you can also select the following configuration options:\r\n\r\n- Allow hash publication for all shared folders. With this option, BranchCache generates content information for all content in all shares on the file server. \r\n\r\n- Allow hash publication only for shared folders on which BranchCache is enabled. With this option, content information is generated only for shared folders on which BranchCache is enabled. If you use this setting, you must enable BranchCache for individual shares in Share and Storage Management on the file server.\r\n\r\n- Disallow hash publication on all shared folders. With this option, BranchCache does not generate content information for any shares on the computer and does not send content information to client computers that request content.\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-hashpublication"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_1","displayName":"Enabled","description":null,"helpText":null}]},"3d279e844330011b":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet","displayName":"Allow operation while in public network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet_1","displayName":"True","description":null,"helpText":null}]},"3d8356d6c5229f2e":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring","displayName":"Configure local setting override to turn on real-time protection","description":"This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisablerealtimemonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},"3d9150236b78d8f7":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect","displayName":"MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)","description":"MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-enabledeadgwdetect"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect_1","displayName":"Enabled","description":null,"helpText":null}]},"3db9f3cc1e69bf7d":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions","displayName":"Policy creation type","description":"Select Enter XML data to type or paste an XML property list that contains your Application Control policy. Select Use built-in controls to choose from toggles exposed in this Application Control policy. Setting this to Not Configured will result in default behaviour on the device with no added options from the ApplicationControl CSP on the device.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions_upload_xml_selected","displayName":"XML upload","description":"XML upload","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions_built_in_controls_selected","displayName":"Built-in controls","description":"Built-in controls","helpText":null}]},"3d17f9f63f3f8eb9":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1","displayName":"Publishing Server 1 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver1"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_1","displayName":"Enabled","description":null,"helpText":null}]},"3d0f80d2d76f47f1":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls","displayName":"Block access to sensors on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't access sensors like motion and light sensors.\r\n\r\nLeaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nIf the same URL pattern exists in both this policy and the SensorsAllowedForUrls policy, this policy is prioritized and access to motion or light sensors will be blocked.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"3d393b268718cbfa":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode","displayName":"Print PostScript Mode","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a PostScript printer on Microsoft® Windows® different PostScript generation methods can affect printing performance.\r\n\r\nWhen this policy is set to Default, Google Chrome will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nWhen this policy is set to Type42, Google Chrome will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nWhen this policy is not set, Google Chrome will be in Default mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},"3df199e10bb8aac0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl","displayName":"Enterprise web store URL (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_1","displayName":"Enabled","description":null,"helpText":null}]},"3dae503540726fba":{"id":"device_vendor_msft_policy_config_desktopappinstaller_sourceautoupdateinterval_sourceautoupdateinterval","displayName":"Source Auto Update Interval In Minutes","description":"","helpText":"","infoUrls":[],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":null},"3d02f6b70293060e":{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate","displayName":"Locked-Down Local Machine Zone Template","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownlocalmachinezonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"3d7ff327973e3b7e":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources","displayName":"Access data sources across domains","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowaccesstodatasources"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"3d78092d023bbad5":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowuserdatapersistence"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"3db2a92c0714d439":{"id":"device_vendor_msft_policy_config_kioskbrowser_enablehomebutton","displayName":"Enable Home Button","description":"Enable/disable kiosk browser's home button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enablehomebutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"device_vendor_msft_policy_config_kioskbrowser_enablehomebutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_kioskbrowser_enablehomebutton_0","displayName":"Disable","description":"Disable","helpText":null}]},"3df194e57c550775":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_donotdisplaylastsignedin","displayName":"Interactive Logon Do Not Display Last Signed In","description":"Interactive logon: Don't display last signed-in This security setting determines whether the Windows sign-in screen will show the username of the last person who signed in on this PC. If this policy is enabled, the username will not be shown. If this policy is disabled, the username will be shown. Default: Disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_donotdisplaylastsignedin"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_donotdisplaylastsignedin_0","displayName":"Disabled (username will be shown)","description":"Disabled (username will be shown)","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_donotdisplaylastsignedin_1","displayName":"Enabled (username will not be shown)","description":"Enabled (username will not be shown)","helpText":null}]},"3df3f4eed18e84d7":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run","description":"If you enable this policy, all supported datatypes and settings from the specified browser will be silently and automatically imported at first run. During the First Run Experience, the import section will also be skipped.\r\n\r\nThe browser data from Microsoft Edge Legacy will always be silently migrated at the first run, irrespective of the value of this policy. You can use the following values for this policy:\r\n\r\n* 0 = Automatically imports all supported datatypes and settings from the default browser\r\n\r\n* 1 = Automatically imports all supported datatypes and settings from Internet Explorer\r\n\r\n* 2 = Automatically imports all supported datatypes and settings from Google Chrome\r\n\r\n* 3 = Automatically imports all supported datatypes and settings from Safari\r\n\r\n* 4 = Disables automatic import, and the import section of the first-run experience is skipped\r\n\r\n* 5 = Automatically imports all supported datatypes and settings from Mozilla Firefox\r\n\r\nIf this policy is set to the default value (0), then the datatypes corresponding to the default browser on the managed device will be imported.\r\n\r\nIf the browser specified as the value of this policy is not present in the managed device, Microsoft Edge will simply skip the import without any notification to the user.\r\n\r\nIf you set this policy to 'DisabledAutoImport' (4), the import section of the first-run experience is skipped entirely and Microsoft Edge doesn't import browser data and settings automatically.\r\n\r\nIf this policy is set to the value of Internet Explorer (1), the following datatypes will be imported from Internet Explorer:\r\n1. Favorites or bookmarks\r\n2. Saved passwords\r\n3. Search engines\r\n4. Browsing history\r\n5. Home page\r\n\r\nIf this policy is set to the value of Google Chrome (2), the following datatypes will be imported from Google Chrome:\r\n1. Favorites\r\n2. Saved passwords\r\n3. Addresses and more\r\n4. Payment info\r\n5. Browsing history\r\n6. Settings\r\n7. Pinned and Open tabs\r\n8. Extensions\r\n9. Cookies\r\n\r\nNote: For more details on what is imported from Google Chrome, please see https://go.microsoft.com/fwlink/?linkid=2120835\r\n\r\nIf this policy is set to the value of Safari (3), the following datatypes will be imported from Safari:\r\n1. Favorites or bookmarks\r\n2. Browsing history\r\n\r\nStarting with Microsoft Edge version 83, if this policy is set to the value of Mozilla Firefox (5), the following datatypes will be imported from Mozilla Firefox:\r\n1. Favorites or bookmarks\r\n2. Saved passwords\r\n3. Addresses and more\r\n4. Browsing History\r\n\r\nIf you want to restrict specific datatypes from getting imported on the managed devices, you can use this policy with other policies such as 'ImportAutofillFormData' (Allow importing of autofill form data), 'ImportBrowserSettings' (Allow importing of browser settings), 'ImportFavorites' (Allow importing of favorites), and etc.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_1","displayName":"Enabled","description":null,"helpText":null}]},"3da75a626839d477":{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled","displayName":"Text prediction enabled by default","description":"The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, text predictions will be provided for eligible text fields.\r\n\r\nIf you disable this policy, text predictions will not be provided in eligible text fields. Sites may still provide their own text predictions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3d084bd044519ee8":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load blockable mixed content","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow blockable mixed content","description":null,"helpText":null}]},"3ddf6d6c0487c67e":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_autoopenallowedforurlsdesc","displayName":"URLs where AutoOpenFileTypes can apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"3df7376fb8903a65":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu","displayName":"Allow users to access the games menu","description":"If you enable or don't configure this policy, users can access the games menu.\r\n\r\nIf you disable this policy, users won't be able to access the games menu.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"3d8e8d289bfb2f94":{"id":"device_vendor_msft_policy_config_windowsai_disableagentconnectors","displayName":"Disable Agent Connectors (Windows Insiders only)","description":"Enable or Disable Agent Connectors.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableagentconnectors"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_disableagentconnectors_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableagentconnectors_1","displayName":"Force Enable.","description":"Force Enable.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableagentconnectors_2","displayName":"Force Disable.","description":"Force Disable.","helpText":null}]},"3dbcb5a9159347cb":{"id":"enrollment_autopilot_dpp_timeout","displayName":"Minutes allowed before showing installation error","description":"","helpText":"","infoUrls":[],"categoryId":"72e4d72b-e01e-427c-a3b6-05bdcf04ef8d","categoryName":null,"options":null},"3dbcdca25919a8e0":{"id":"settings_item_softwareupdatesettings","displayName":"Software Update Settings (Deprecated)","description":"A dictionary that contains software update settings. This setting doesn't support user enrollment. Available in iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"724d930a-7a3c-4171-a17c-431cee336518","categoryName":"Software Update Settings","options":null},"3d6d6225000f35db":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_1","displayName":"Remove \"Make Available Offline\" for these files and folders (User)","description":"This policy setting allows you to manage a list of files and folders for which you want to block the \"Make Available Offline\" command.\r\n\r\nIf you enable this policy setting, the \"Make Available Offline\" command is not available for the files and folders that you list. To specify these files and folders, click Show. In the Show Contents dialog box, in the Value Name column box, type the fully qualified UNC path to the file or folder. Leave the Value column field blank.\r\n\r\nIf you disable this policy setting, the list of files and folders is deleted, including any lists inherited from lower precedence GPOs, and the \"Make Available Offline\" command is displayed for all files and folders.\r\n\r\nIf you do not configure this policy setting, the \"Make Available Offline\" command is available for all files and folders.\r\n\r\nNotes:\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy settings are combined, and the \"Make Available Offline\" command is unavailable for all specified files and folders.\r\n\r\nThe \"Make Available Offline\" command is called \"Always available offline\" on computers running Windows Server 2012, Windows Server 2008 R2, Windows Server 2008, Windows 8, Windows 7, or Windows Vista.\r\n\r\nThis policy setting does not prevent files from being automatically cached if the network share is configured for \"Automatic Caching.\" It only affects the display of the \"Make Available Offline\" command in File Explorer.\r\n\r\nIf the \"Remove 'Make Available Offline' command\" policy setting is enabled, this setting has no effect.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nopinfiles-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_1_1","displayName":"Enabled","description":null,"helpText":null}]},"3dc52704ba2677fa":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue_applicationlocalevalue","displayName":"Application locale (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"3d9ccdef99d3abb7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled","displayName":"Allow the audio sandbox to run (User)","description":"This policy controls the audio process sandbox.\r\nIf this policy is enabled, the audio process will run sandboxed.\r\nIf this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\nIf this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform.\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3dbeb3c72a78e3a0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled","displayName":"Enable guest mode in browser (User)","description":"If this policy is set to true or not configured, Google Chrome will enable guest logins. Guest logins are Google Chrome profiles where all windows are in incognito mode.\r\n\r\nIf this policy is set to false, Google Chrome will not allow guest profiles to be started.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3d486714fbe808e7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"3dff66cf69affaa8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed","displayName":"Allow collection of WebRTC event logs from Google services (User)","description":"Setting the policy to Enabled means Google Chrome can collect WebRTC event logs from Google services such as Hangouts Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as the time and size of RTP packets, feedback about congestion on the network, and metadata about time and quality of audio and video frames. These logs have no audio or video content from the meeting. To make debugging easier, Google might associate these logs, by means of a session ID, with other logs collected by the Google service itself.\r\n\r\nSetting the policy to Disabled results in no collection or uploading of such logs.\r\n\r\nLeaving the policy unset on versions up to and including M76 means Google Chrome defaults to not being able to collect and upload these logs. Starting at M77, Google Chrome defaults to being able to collect and upload these logs from most profiles affected by cloud-based, user-level enterprise policies. From M77 up to and including M80, Google Chrome can also collect and upload these logs by default from profiles affected by Google Chrome on-premise management.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"3ddb2618c208fddc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist_proxybypasslist","displayName":"Comma-separated list of proxy bypass rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"3d90933617b0ef93":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel","displayName":"Load pictures from Web pages not created in Excel (User)","description":"This policy setting controls whether Excel loads graphics when opening Web pages that were not created in Excel. It configures the \"Load pictures from Web pages not created in Excel\" option under the File tab | Options | Advanced | General | Web Options... | General tab.\r\n \r\nIf you enable or do not configure this policy setting, Excel loads any graphics that are included in the pages, regardless of whether they were originally created in Excel.\r\n \r\nIf you disable this policy setting, Excel will not load any pictures from Web pages that were not created in Excel.","helpText":"","infoUrls":[],"categoryId":"b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel_1","displayName":"Enabled","description":null,"helpText":null}]},"3dd0fdf0c5c2d4ed":{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode","displayName":"Enable global window list in Internet Explorer mode (User)","description":"This setting allows Internet Explorer mode to use the global window list that enables sharing state with other applications.\nThe setting will take effect only when Internet Explorer 11 is disabled as a standalone browser.\n\nIf you enable this policy, Internet Explorer mode will use the global window list.\n\nIf you disable or don’t configure this policy, Internet Explorer mode will continue to maintain a separate window list.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2102921\nTo learn more about disabling Internet Explorer 11 as a standalone browser, see https://go.microsoft.com/fwlink/?linkid=2168340","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-enableglobalwindowlistiniemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode_1","displayName":"Enabled","description":null,"helpText":null}]},"3d22c76cbbb3009b":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols","displayName":"Download signed ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.\n\nIf you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.\n\nIf you disable the policy setting, signed controls cannot be downloaded.\n\nIf you do not configure this policy setting, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"3da09864631a21eb":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowscriptlets"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"3dffc3932818fcba":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowsmartscreenie"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"3d911589a90015a5":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.\n\nIf you enable this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.\n\nIf you do not configure this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptinitiatedwindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_1","displayName":"Enabled","description":null,"helpText":null}]},"3d110716bf1221cc":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page (User)","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\r\n\r\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\r\n\r\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"3dec46ad772d452d":{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription (User)","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\r\n\r\nIf you enable or don't configure this policy, the button will show up on the native PDF viewer in Microsoft Edge. A user will be able to buy Adobe subscription to access their premium offerings.\r\n\r\nIf you disable this policy, the button won't be visible on the native PDF viewer in Microsoft Edge. A user won't be able to discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton_1","displayName":"Enabled","description":null,"helpText":null}]},"3de6083e6bdda9dd":{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled","displayName":"Enables default browser settings campaigns (User)","description":"This policy enables the default browser settings campaign. If a user clicks to accept the campaign, their default browser and/or default search engine will be changed to Microsoft Edge and Microsoft Bing, respectively. If the user dismisses the campaign, the user's browser settings will remain unchanged.\r\n\r\nIf you enable or don't configure this policy, users will be prompted to set Microsoft Edge as the default browser and Microsoft Bing as the default search engine, if they do not have those browser settings.\r\n\r\nIf you disable this policy, users will not be prompted to set Microsoft Edge as the default browser, or to set Microsoft Bing as the default search engine.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3d80624d3852fa29":{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings_webappsettings","displayName":"Web App management settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"3d8d6b30d083823b":{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be opened.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the 'EdgeSidebarAppUrlHostAllowList' (Allow specific apps to be opened in Microsoft Edge sidebar) policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"3d222e69b663786e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions","displayName":"Block additional file extensions for OLE embedding (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365.\r\n\r\nThis policy setting allows you to specify additional file extensions that Office will block when they are embedded as an OLE package in an Office file by using the Object Packager control.\r\n\r\nBy default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759.\r\n\r\nImportant: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user.\r\n\r\nIf you enable this policy setting, enter the additional file extensions to block, separated by semicolons. For example, py;rb.\r\n\r\nIf you disable or don’t configure this policy setting, the default set of file extensions will be blocked.\r\n\r\nIf you want to allow certain file extensions, enable the \"Allow file extensions for OLE embedding\" policy setting. Extensions added to this policy setting will take precedence over extensions in \"Allow file extensions for OLE embedding\"\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"3d45974309fe2a8f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory_l_setdefaultimagedirctorypart","displayName":"Last-used signature image directory: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":null},"3de5b0b8bdfd3648":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond_l_bitssecond","displayName":"Bits/Second: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},"3da3479ad0b5b9cd":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime","displayName":"Do not prune versions over time (User)","description":"This policy setting allows you to turn off OneNote's automatic pruning. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, OneNote will not prune previous versions.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will prune previous versions. The default value is to prune versions over time. You should only enable this policy setting if OneNote should not prune previous versions.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime_1","displayName":"Enabled","description":null,"helpText":null}]},"3dd34cb7b7716fda":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail","displayName":"Disable shared mail folder caching (User)","description":"This policy setting allows you to control the caching of shared mail folders.\r\n\r\nIf you enable this policy setting, Outlook will only cache shared non-mail folders.\r\n\r\nIf you disable or do not configure this policy setting, shared mail and non-mail folders you have access to are cached in your .ost file when you add another mailbox to your profile.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail_1","displayName":"Enabled","description":null,"helpText":null}]},"3da87f5d1f9a01b5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder","displayName":"Empty the Deleted Items folder when Outlook closes (User)","description":"By default, the Deleted Items folder is not emptied when users exit Outlook. By enabling this setting, you can change this behavior so that the Deleted Items folder is emptied when Outlook closes.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"3de34f0cca493051":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_waitxxxsecondsbeforemarkingitemsasread","displayName":"Wait xxx seconds before marking items as read: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},"3d5e08ce9c3644c6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems","displayName":"Archive or delete old items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems_1","displayName":"True","description":null,"helpText":null}]},"3d3d9538fd9bfae6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts","displayName":"Check for duplicate contacts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts_1","displayName":"True","description":null,"helpText":null}]},"3df775e93f4bb747":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback","displayName":"Disable connection fallback between protocols (User)","description":"This policy setting allows you to control the connection transport fallback behavior in Outlook when it attempts to connect to a Microsoft Exchange Server.\r\n \r\nThis policy setting applies if you are using Outlook Anywhere (RPC over HTTP) to connect to a Microsoft Exchange Server. There are two Outlook profile settings on the Microsoft Exchange Proxy Settings dialog box (accessed through the Control Panel or Account Settings), that configure the default connection transport fallback behavior.\r\n \r\n- On fast networks, connect using HTTP first, then connect using TCP/IP\r\n- On slow networks, connect using HTTP first, then connect using TCP/IP\r\n \r\nFor example, if you are on a fast network and you enable the “On fast networks, connect using HTTP first, then connect using TCP/IP” setting in the Microsoft Exchange Proxy Settings dialog box, Outlook first attempts to connect to the Exchange Server using HTTP. If Outlook is unable to connect using HTTP, then it attempts to connect using TCP/IP.\r\n \r\nIf you enable this policy setting, if Outlook connection attempts with Microsoft Exchange Server fail, Outlook does not fallback to the TCP/IP protocol, regardless of what is specified in the Microsoft Exchange Proxy Settings dialog box. \r\n\r\nIf you disable or do not configure this policy setting, Outlook connection attempts with Microsoft Exchange Server can fallback from either TCP/IP to HTTP, or HTTP to TCP/IP, depending on the settings specified in the Microsoft Exchange Proxy Settings dialog box.\r\n","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback_1","displayName":"Enabled","description":null,"helpText":null}]},"3de8278a65106f67":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions","displayName":"Default Internet Calendar subscriptions (User)","description":"This policy setting allows you to deploy Internet Calendar subscriptions.\r\n\r\nIf you enable this policy setting, the URLs listed here will be read and the corresponding Internet Calendar subscriptions will be added to each of the user's profiles. The name you specify here will not be used as the name of the Internet Calendar subscription.\r\n\r\nIf you disable or do not configure this policy setting users will not have any default Internet Calendar subscriptions.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_1","displayName":"Enabled","description":null,"helpText":null}]},"3df69c5a6c50fccd":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"3d2083054c54a9da":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining","displayName":"And move start of remaining parts back to status date (User)","description":"Moves the remaining portion of a task back to start at the status date.\r\n\r\nIf you enable this setting, the remaining portion of the task moves back to start at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining_1","displayName":"Enabled","description":null,"helpText":null}]},"3d28333999cb3b46":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview","displayName":"Default View (User)","description":"Specifies the view that Project displays at startup.\r\n \r\nIf you enable this setting, you can set the default view that is displayed at startup.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_1","displayName":"Enabled","description":null,"helpText":null}]},"3d1e1bc9f0425ffd":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher","displayName":"Show the New template gallery when starting Publisher (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"1a0386fd-354b-441e-a0d6-1523c209dae7","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher_1","displayName":"Enabled","description":null,"helpText":null}]},"3ddd97c4a7cda9b9":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery","displayName":"Save AutoRecover info every (minutes) (User)","description":"This policy setting allows you to specify the Save Autorecover interval in minutes.\r\n\r\nIf you enable this policy setting, you may specify the Save Autorecover interval in minutes (valid range: 1-120).\r\n\r\nIf you disable or do not configure this policy setting, the interval specified in the UI will be used.\r\n","helpText":"","infoUrls":[],"categoryId":"038b49c9-4f13-4ace-be8d-bd076bffa23e","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_1","displayName":"Enabled","description":null,"helpText":null}]},"3d18cabf8b2f4900":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},"3df3ec4dcc917b1e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_1","displayName":"Enabled","description":null,"helpText":null}]},"3da4bf09ffb5c1ce":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries","displayName":"Use online translation dictionaries (User)","description":"This policy setting allows you to prevent online dictionaries from being used for the translation of text through the Research pane.\r\n\r\nIf you enable or do not configure this policy setting, the online dictionaries can be used to translate text through the Research pane.\r\n\r\nIf you disable this policy setting, the online dictionaries cannot be used to translate text through the Research pane.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries_1","displayName":"Enabled","description":null,"helpText":null}]},"3dbc2246469f642f":{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast","displayName":"Disable Unicast Responses To Multicast Broadcast","description":"This value is used as an on/off switch. If it is true, unicast responses to multicast broadcast traffic is blocked. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast_false","displayName":"False","description":"Unicast Responses Not Blocked","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast_true","displayName":"True","description":"Unicast Responses Blocked","helpText":null}]}} \ No newline at end of file +{"3ddedd53546ec980":{"id":"app_privacy_permissiondefaults_generickey_bluetooth","displayName":"Bluetooth","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of Bluetooth.\n* `Allow`: The app privacy permission default is set to allow use of Bluetooth.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_bluetooth_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_bluetooth_1","displayName":"Allow","description":null,"helpText":null}]},"3d4e3ea9c358a7e6":{"id":"com.apple.applicationaccess_allowerasecontentandsettings","displayName":"Allow Erase Content And Settings","description":"If false, disables the Erase All Content And Settings option in the Reset UI. Requires a supervised device. Available in iOS 8 and later, and macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowerasecontentandsettings_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowerasecontentandsettings_true","displayName":"True","description":null,"helpText":null}]},"3d18e6570a0febf6":{"id":"com.apple.applicationaccess_allowlistedappbundleids","displayName":"Allow Listed App Bundle IDs","description":"If present, this property allows only bundle IDs listed in the array to be shown or launchable. Include the value com.apple.webapp to allow all webclips. Requires a supervised device. Available in iOS 9.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},"3da4813022f61a9c":{"id":"com.apple.dock_minintoapp-immutable","displayName":"Minimize Into Application Immutable","description":"If true, disables the \"Minimize windows into application icon\" checkbox.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_minintoapp-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_minintoapp-immutable_true","displayName":"True","description":null,"helpText":null}]},"3d1352d6ae8fc927":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_lcid","displayName":"Microsoft Teams LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"3db81f609994d7e7":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_skype for business.app","displayName":"Skype for Business","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"3d8f333d94a1512d":{"id":"com.apple.managedclient.preferences_remotedebuggingallowed","displayName":"Allow remote debugging","description":"Controls whether users may use remote debugging.\n\nIf you enable or don't configure this policy, users may use remote debugging by specifying --remote-debug-port and --remote-debugging-pipe command line switches.\n\nIf you disable this policy, users are not allowed to use remote debugging.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#remotedebuggingallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_remotedebuggingallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_remotedebuggingallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"3d6d7e14efa75156":{"id":"com.apple.proxy.http.global_proxypacurl","displayName":"Proxy PAC URL","description":"The URL of the PAC file that defines the proxy configuration. Starting in iOS 13 and macOS 10.15, only URLs that begin with http:// or https:// are allowed.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},"3d46625a198207a8":{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled","displayName":"Enables background updates to the list of available templates for Collections and other features that use templates (Deprecated)","description":"This policy is deprecated because we are moving to a new policy. It won't work in Microsoft Edge as soon as version 104. The new policy to use is \"EdgeAssetDeliveryServiceEnabled\".\n\nLets you enable or disable background updates to the list of available templates for Collections and other features that use templates. Templates are used to extract rich metadata from a webpage when the page is saved to a collection.\n\nIf you enable this setting or the setting is unconfigured, the list of available templates are downloaded in the background from a Microsoft service every 24 hours.\n\nIf you disable this setting the list of available templates are downloaded on demand. This type of download might result in small performance penalties for Collections and other features.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.backgroundtemplatelistupdatesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"3dcb14c4e08c2cf9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxybypasslist","displayName":"Configure proxy bypass rules (Deprecated)","description":"This policy is deprecated, use \"ProxySettings\" instead. It doesn't work in Microsoft Edge version 91.\n\nDefines a list of hosts for which Microsoft Edge bypasses any proxy.\n\nThis policy is applied only if the \"ProxySettings\" policy isn't specified and you selected either fixed_servers or pac_script in the \"ProxyMode\" policy. If you selected any other mode for configuring proxy policies, don't enable or configure this policy.\n\nIf you enable this policy, you can create a list of hosts for which Microsoft Edge doesn't use a proxy.\n\nIf you don't configure this policy, no list of hosts is created for which Microsoft Edge bypasses a proxy. Leave this policy unconfigured if you specified any other method for setting proxy policies.\n\nFor more detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},"3dd7e775374929ad":{"id":"device_vendor_msft_policy_config_activexcontrols_approvedinstallationsites_approvedactivexinstallsiteslist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":null},"3daaafd2182799ae":{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication","displayName":"Hash Publication for BranchCache","description":"This policy setting specifies whether a hash generation service generates hashes, also called content information, for data that is stored in shared folders. This policy setting must be applied to server computers that have the File Services role and both the File Server and the BranchCache for Network Files role services installed.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, hash publication settings are not applied to file servers. In the circumstance where file servers are domain members but you do not want to enable BranchCache on all file servers, you can specify Not Configured for this domain Group Policy setting, and then configure local machine policy to enable BranchCache on individual file servers. Because the domain Group Policy setting is not configured, it will not over-write the enabled setting that you use on individual servers where you want to enable BranchCache.\r\n\r\n- Enabled. With this selection, hash publication is turned on for all file servers where Group Policy is applied. For example, if Hash Publication for BranchCache is enabled in domain Group Policy, hash publication is turned on for all domain member file servers to which the policy is applied. The file servers are then able to create content information for all content that is stored in BranchCache-enabled file shares.\r\n\r\n- Disabled. With this selection, hash publication is turned off for all file servers where Group Policy is applied.\r\n\r\nIn circumstances where this policy setting is enabled, you can also select the following configuration options:\r\n\r\n- Allow hash publication for all shared folders. With this option, BranchCache generates content information for all content in all shares on the file server. \r\n\r\n- Allow hash publication only for shared folders on which BranchCache is enabled. With this option, content information is generated only for shared folders on which BranchCache is enabled. If you use this setting, you must enable BranchCache for individual shares in Share and Storage Management on the file server.\r\n\r\n- Disallow hash publication on all shared folders. With this option, BranchCache does not generate content information for any shares on the computer and does not send content information to client computers that request content.\r\n \n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-lanmanserver#admx-lanmanserver-pol-hashpublication"],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_1","displayName":"Enabled","description":null,"helpText":null}]},"3d279e844330011b":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet","displayName":"Allow operation while in public network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowonpublicnet_1","displayName":"True","description":null,"helpText":null}]},"3d8356d6c5229f2e":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring","displayName":"Configure local setting override to turn on real-time protection","description":"This policy setting configures a local override for the configuration to turn on real-time protection. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-localsettingoverridedisablerealtimemonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_localsettingoverridedisablerealtimemonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},"3d9150236b78d8f7":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect","displayName":"MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)","description":"MSS: (EnableDeadGWDetect) Allow automatic detection of dead network gateways (could lead to DoS)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-enabledeadgwdetect"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_enabledeadgwdetect_1","displayName":"Enabled","description":null,"helpText":null}]},"3db9f3cc1e69bf7d":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions","displayName":"Policy creation type","description":"Select Enter XML data to type or paste an XML property list that contains your Application Control policy. Select Use built-in controls to choose from toggles exposed in this Application Control policy. Setting this to Not Configured will result in default behaviour on the device with no added options from the ApplicationControl CSP on the device.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions_upload_xml_selected","displayName":"XML upload","description":"XML upload","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_buildoptions_built_in_controls_selected","displayName":"Built-in controls","description":"Built-in controls","helpText":null}]},"3d17f9f63f3f8eb9":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1","displayName":"Publishing Server 1 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver1"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_1","displayName":"Enabled","description":null,"helpText":null}]},"3d0f80d2d76f47f1":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls","displayName":"Block access to sensors on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't access sensors like motion and light sensors.\r\n\r\nLeaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nIf the same URL pattern exists in both this policy and the SensorsAllowedForUrls policy, this policy is prioritized and access to motion or light sensors will be blocked.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"3d393b268718cbfa":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode","displayName":"Print PostScript Mode","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a PostScript printer on Microsoft® Windows® different PostScript generation methods can affect printing performance.\r\n\r\nWhen this policy is set to Default, Google Chrome will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nWhen this policy is set to Type42, Google Chrome will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nWhen this policy is not set, Google Chrome will be in Default mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},"3df199e10bb8aac0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl","displayName":"Enterprise web store URL (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstoreurl_1","displayName":"Enabled","description":null,"helpText":null}]},"3dae503540726fba":{"id":"device_vendor_msft_policy_config_desktopappinstaller_sourceautoupdateinterval_sourceautoupdateinterval","displayName":"Source Auto Update Interval In Minutes","description":"","helpText":"","infoUrls":[],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":null},"3d02f6b70293060e":{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate","displayName":"Locked-Down Local Machine Zone Template","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownlocalmachinezonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"3d7ff327973e3b7e":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources","displayName":"Access data sources across domains","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowaccesstodatasources"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"3d78092d023bbad5":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowuserdatapersistence"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"3db2a92c0714d439":{"id":"device_vendor_msft_policy_config_kioskbrowser_enablehomebutton","displayName":"Enable Home Button","description":"Enable/disable kiosk browser's home button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enablehomebutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"device_vendor_msft_policy_config_kioskbrowser_enablehomebutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_kioskbrowser_enablehomebutton_0","displayName":"Disable","description":"Disable","helpText":null}]},"3df194e57c550775":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_donotdisplaylastsignedin","displayName":"Interactive Logon Do Not Display Last Signed In","description":"Interactive logon: Don't display last signed-in This security setting determines whether the Windows sign-in screen will show the username of the last person who signed in on this PC. If this policy is enabled, the username will not be shown. If this policy is disabled, the username will be shown. Default: Disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_donotdisplaylastsignedin"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_donotdisplaylastsignedin_0","displayName":"Disabled (username will be shown)","description":"Disabled (username will be shown)","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_donotdisplaylastsignedin_1","displayName":"Enabled (username will not be shown)","description":"Enabled (username will not be shown)","helpText":null}]},"3df3f4eed18e84d7":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun","displayName":"Automatically import another browser's data and settings at first run","description":"If you enable this policy, all supported datatypes and settings from the specified browser will be silently and automatically imported at first run. During the First Run Experience, the import section will also be skipped.\r\n\r\nThe browser data from Microsoft Edge Legacy will always be silently migrated at the first run, irrespective of the value of this policy. You can use the following values for this policy:\r\n\r\n* 0 = Automatically imports all supported datatypes and settings from the default browser\r\n\r\n* 1 = Automatically imports all supported datatypes and settings from Internet Explorer\r\n\r\n* 2 = Automatically imports all supported datatypes and settings from Google Chrome\r\n\r\n* 3 = Automatically imports all supported datatypes and settings from Safari\r\n\r\n* 4 = Disables automatic import, and the import section of the first-run experience is skipped\r\n\r\n* 5 = Automatically imports all supported datatypes and settings from Mozilla Firefox\r\n\r\nIf this policy is set to the default value (0), then the datatypes corresponding to the default browser on the managed device will be imported.\r\n\r\nIf the browser specified as the value of this policy is not present in the managed device, Microsoft Edge will simply skip the import without any notification to the user.\r\n\r\nIf you set this policy to 'DisabledAutoImport' (4), the import section of the first-run experience is skipped entirely and Microsoft Edge doesn't import browser data and settings automatically.\r\n\r\nIf this policy is set to the value of Internet Explorer (1), the following datatypes will be imported from Internet Explorer:\r\n1. Favorites or bookmarks\r\n2. Saved passwords\r\n3. Search engines\r\n4. Browsing history\r\n5. Home page\r\n\r\nIf this policy is set to the value of Google Chrome (2), the following datatypes will be imported from Google Chrome:\r\n1. Favorites\r\n2. Saved passwords\r\n3. Addresses and more\r\n4. Payment info\r\n5. Browsing history\r\n6. Settings\r\n7. Pinned and Open tabs\r\n8. Extensions\r\n9. Cookies\r\n\r\nNote: For more details on what is imported from Google Chrome, please see https://go.microsoft.com/fwlink/?linkid=2120835\r\n\r\nIf this policy is set to the value of Safari (3), the following datatypes will be imported from Safari:\r\n1. Favorites or bookmarks\r\n2. Browsing history\r\n\r\nStarting with Microsoft Edge version 83, if this policy is set to the value of Mozilla Firefox (5), the following datatypes will be imported from Mozilla Firefox:\r\n1. Favorites or bookmarks\r\n2. Saved passwords\r\n3. Addresses and more\r\n4. Browsing History\r\n\r\nIf you want to restrict specific datatypes from getting imported on the managed devices, you can use this policy with other policies such as 'ImportAutofillFormData' (Allow importing of autofill form data), 'ImportBrowserSettings' (Allow importing of browser settings), 'ImportFavorites' (Allow importing of favorites), and etc.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autoimportatfirstrun_1","displayName":"Enabled","description":null,"helpText":null}]},"3da75a626839d477":{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled","displayName":"Text prediction enabled by default","description":"The Microsoft Turing service uses natural language processing to generate predictions for long-form editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, text predictions will be provided for eligible text fields.\r\n\r\nIf you disable this policy, text predictions will not be provided in eligible text fields. Sites may still provide their own text predictions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_textpredictionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3d084bd044519ee8":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load blockable mixed content","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow blockable mixed content","description":null,"helpText":null}]},"3ddf6d6c0487c67e":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_autoopenallowedforurlsdesc","displayName":"URLs where AutoOpenFileTypes can apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"3df7376fb8903a65":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu","displayName":"Allow users to access the games menu","description":"If you enable or don't configure this policy, users can access the games menu.\r\n\r\nIf you disable this policy, users won't be able to access the games menu.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_allowgamesmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"3d8e8d289bfb2f94":{"id":"device_vendor_msft_policy_config_windowsai_disableagentconnectors","displayName":"Disable Agent Connectors (Windows Insiders only)","description":"Enable or Disable Agent Connectors.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableagentconnectors"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_disableagentconnectors_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableagentconnectors_1","displayName":"Force Enable.","description":"Force Enable.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableagentconnectors_2","displayName":"Force Disable.","description":"Force Disable.","helpText":null}]},"3dbcb5a9159347cb":{"id":"enrollment_autopilot_dpp_timeout","displayName":"Minutes allowed before showing installation error","description":"","helpText":"","infoUrls":[],"categoryId":"72e4d72b-e01e-427c-a3b6-05bdcf04ef8d","categoryName":null,"options":null},"3d36ebdf1d15df74":{"id":"plugin_filter_packets","displayName":"Packets","description":"Settings that control the packet filter. If not present, the system doesn't use packet filtering.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"3dbcdca25919a8e0":{"id":"settings_item_softwareupdatesettings","displayName":"Software Update Settings (Deprecated)","description":"A dictionary that contains software update settings. This setting doesn't support user enrollment. Available in iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"724d930a-7a3c-4171-a17c-431cee336518","categoryName":"Software Update Settings","options":null},"3d6d6225000f35db":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_1","displayName":"Remove \"Make Available Offline\" for these files and folders (User)","description":"This policy setting allows you to manage a list of files and folders for which you want to block the \"Make Available Offline\" command.\r\n\r\nIf you enable this policy setting, the \"Make Available Offline\" command is not available for the files and folders that you list. To specify these files and folders, click Show. In the Show Contents dialog box, in the Value Name column box, type the fully qualified UNC path to the file or folder. Leave the Value column field blank.\r\n\r\nIf you disable this policy setting, the list of files and folders is deleted, including any lists inherited from lower precedence GPOs, and the \"Make Available Offline\" command is displayed for all files and folders.\r\n\r\nIf you do not configure this policy setting, the \"Make Available Offline\" command is available for all files and folders.\r\n\r\nNotes:\r\n\r\nThis policy setting appears in the Computer Configuration and User Configuration folders. If both policy settings are configured, the policy settings are combined, and the \"Make Available Offline\" command is unavailable for all specified files and folders.\r\n\r\nThe \"Make Available Offline\" command is called \"Always available offline\" on computers running Windows Server 2012, Windows Server 2008 R2, Windows Server 2008, Windows 8, Windows 7, or Windows Vista.\r\n\r\nThis policy setting does not prevent files from being automatically cached if the network share is configured for \"Automatic Caching.\" It only affects the display of the \"Make Available Offline\" command in File Explorer.\r\n\r\nIf the \"Remove 'Make Available Offline' command\" policy setting is enabled, this setting has no effect.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nopinfiles-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_1_1","displayName":"Enabled","description":null,"helpText":null}]},"3dc52704ba2677fa":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_applicationlocalevalue_applicationlocalevalue","displayName":"Application locale (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"3d9ccdef99d3abb7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled","displayName":"Allow the audio sandbox to run (User)","description":"This policy controls the audio process sandbox.\r\nIf this policy is enabled, the audio process will run sandboxed.\r\nIf this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\nIf this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform.\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3dbeb3c72a78e3a0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled","displayName":"Enable guest mode in browser (User)","description":"If this policy is set to true or not configured, Google Chrome will enable guest logins. Guest logins are Google Chrome profiles where all windows are in incognito mode.\r\n\r\nIf this policy is set to false, Google Chrome will not allow guest profiles to be started.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserguestmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3d486714fbe808e7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"3dff66cf69affaa8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed","displayName":"Allow collection of WebRTC event logs from Google services (User)","description":"Setting the policy to Enabled means Google Chrome can collect WebRTC event logs from Google services such as Hangouts Meet and upload them to Google. These logs have diagnostic information for debugging issues with audio or video meetings in Google Chrome, such as the time and size of RTP packets, feedback about congestion on the network, and metadata about time and quality of audio and video frames. These logs have no audio or video content from the meeting. To make debugging easier, Google might associate these logs, by means of a session ID, with other logs collected by the Google service itself.\r\n\r\nSetting the policy to Disabled results in no collection or uploading of such logs.\r\n\r\nLeaving the policy unset on versions up to and including M76 means Google Chrome defaults to not being able to collect and upload these logs. Starting at M77, Google Chrome defaults to being able to collect and upload these logs from most profiles affected by cloud-based, user-level enterprise policies. From M77 up to and including M80, Google Chrome can also collect and upload these logs by default from profiles affected by Google Chrome on-premise management.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtceventlogcollectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"3ddb2618c208fddc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxybypasslist_proxybypasslist","displayName":"Comma-separated list of proxy bypass rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"3d90933617b0ef93":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel","displayName":"Load pictures from Web pages not created in Excel (User)","description":"This policy setting controls whether Excel loads graphics when opening Web pages that were not created in Excel. It configures the \"Load pictures from Web pages not created in Excel\" option under the File tab | Options | Advanced | General | Web Options... | General tab.\r\n \r\nIf you enable or do not configure this policy setting, Excel loads any graphics that are included in the pages, regardless of whether they were originally created in Excel.\r\n \r\nIf you disable this policy setting, Excel will not load any pictures from Web pages that were not created in Excel.","helpText":"","infoUrls":[],"categoryId":"b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced~l_weboptions~l_general_l_loadpicturesfromwebpagesnotcreatedinexcel_1","displayName":"Enabled","description":null,"helpText":null}]},"3dd0fdf0c5c2d4ed":{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode","displayName":"Enable global window list in Internet Explorer mode (User)","description":"This setting allows Internet Explorer mode to use the global window list that enables sharing state with other applications.\nThe setting will take effect only when Internet Explorer 11 is disabled as a standalone browser.\n\nIf you enable this policy, Internet Explorer mode will use the global window list.\n\nIf you disable or don’t configure this policy, Internet Explorer mode will continue to maintain a separate window list.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2102921\nTo learn more about disabling Internet Explorer 11 as a standalone browser, see https://go.microsoft.com/fwlink/?linkid=2168340","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-enableglobalwindowlistiniemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_enableglobalwindowlistiniemode_1","displayName":"Enabled","description":null,"helpText":null}]},"3d22c76cbbb3009b":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols","displayName":"Download signed ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.\n\nIf you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.\n\nIf you disable the policy setting, signed controls cannot be downloaded.\n\nIf you do not configure this policy setting, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"3da09864631a21eb":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowscriptlets"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"3dffc3932818fcba":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowsmartscreenie"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"3d911589a90015a5":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"This policy setting allows you to manage restrictions on script-initiated pop-up windows and windows that include the title and status bars.\n\nIf you enable this policy setting, Windows Restrictions security will not apply in this zone. The security zone runs without the added layer of security provided by this feature.\n\nIf you disable this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.\n\nIf you do not configure this policy setting, the possible harmful actions contained in script-initiated pop-up windows and windows that include the title and status bars cannot be run. This Internet Explorer security feature will be on in this zone as dictated by the Scripted Windows Security Restrictions feature control setting for the process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptinitiatedwindows"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_1","displayName":"Enabled","description":null,"helpText":null}]},"3d110716bf1221cc":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page (User)","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\r\n\r\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\r\n\r\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslerroroverrideallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"3dec46ad772d452d":{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription (User)","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\r\n\r\nIf you enable or don't configure this policy, the button will show up on the native PDF viewer in Microsoft Edge. A user will be able to buy Adobe subscription to access their premium offerings.\r\n\r\nIf you disable this policy, the button won't be visible on the native PDF viewer in Microsoft Edge. A user won't be able to discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_showacrobatsubscriptionbutton_1","displayName":"Enabled","description":null,"helpText":null}]},"3de6083e6bdda9dd":{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled","displayName":"Enables default browser settings campaigns (User)","description":"This policy enables the default browser settings campaign. If a user clicks to accept the campaign, their default browser and/or default search engine will be changed to Microsoft Edge and Microsoft Bing, respectively. If the user dismisses the campaign, the user's browser settings will remain unchanged.\r\n\r\nIf you enable or don't configure this policy, users will be prompted to set Microsoft Edge as the default browser and Microsoft Bing as the default search engine, if they do not have those browser settings.\r\n\r\nIf you disable this policy, users will not be prompted to set Microsoft Edge as the default browser, or to set Microsoft Bing as the default search engine.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_defaultbrowsersettingscampaignenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3d80624d3852fa29":{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_webappsettings_webappsettings","displayName":"Web App management settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"3d8d6b30d083823b":{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist","displayName":"Control which apps cannot be opened in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL patterns, that cannot be opened in sidebar.\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be opened.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: A blocklist value of '*' means all apps are blocked unless they are explicitly listed in the 'EdgeSidebarAppUrlHostAllowList' (Allow specific apps to be opened in Microsoft Edge sidebar) policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_edgesidebarappurlhostblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"3d222e69b663786e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions","displayName":"Block additional file extensions for OLE embedding (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365.\r\n\r\nThis policy setting allows you to specify additional file extensions that Office will block when they are embedded as an OLE package in an Office file by using the Object Packager control.\r\n\r\nBy default, Office blocks certain file extensions. For a list of those file extensions, go to https://go.microsoft.com/fwlink/?linkid=847759.\r\n\r\nImportant: Malicious scripts and executables can be embedded as an OLE package and can cause harm if clicked by the user.\r\n\r\nIf you enable this policy setting, enter the additional file extensions to block, separated by semicolons. For example, py;rb.\r\n\r\nIf you disable or don’t configure this policy setting, the default set of file extensions will be blocked.\r\n\r\nIf you want to allow certain file extensions, enable the \"Allow file extensions for OLE embedding\" policy setting. Extensions added to this policy setting will take precedence over extensions in \"Allow file extensions for OLE embedding\"\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_blockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"3d45974309fe2a8f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_setdefaultimagedirctory_l_setdefaultimagedirctorypart","displayName":"Last-used signature image directory: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":null},"3de5b0b8bdfd3648":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_specifyratetosampleaudiobitssecond_l_bitssecond","displayName":"Bits/Second: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},"3da3479ad0b5b9cd":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime","displayName":"Do not prune versions over time (User)","description":"This policy setting allows you to turn off OneNote's automatic pruning. With a 2016 format notebook, OneNote will automatically store previous versions of the pages in the notebook, and it will also store a recycle bin for all of the deleted pages and sections.\r\n\r\nIf you enable this policy setting, OneNote will not prune previous versions.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will prune previous versions. The default value is to prune versions over time. You should only enable this policy setting if OneNote should not prune previous versions.","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_donotpruneversionsovertime_1","displayName":"Enabled","description":null,"helpText":null}]},"3dd34cb7b7716fda":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail","displayName":"Disable shared mail folder caching (User)","description":"This policy setting allows you to control the caching of shared mail folders.\r\n\r\nIf you enable this policy setting, Outlook will only cache shared non-mail folders.\r\n\r\nIf you disable or do not configure this policy setting, shared mail and non-mail folders you have access to are cached in your .ost file when you add another mailbox to your profile.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_cacheothersmail_1","displayName":"Enabled","description":null,"helpText":null}]},"3da87f5d1f9a01b5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder","displayName":"Empty the Deleted Items folder when Outlook closes (User)","description":"By default, the Deleted Items folder is not emptied when users exit Outlook. By enabling this setting, you can change this behavior so that the Deleted Items folder is emptied when Outlook closes.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_emptydeleteditemsfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"3de34f0cca493051":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_waitxxxsecondsbeforemarkingitemsasread","displayName":"Wait xxx seconds before marking items as read: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},"3d5e08ce9c3644c6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems","displayName":"Archive or delete old items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","categoryName":"AutoArchive","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_autoarchive_l_autoarchivesettings_l_archiveordeleteolditems_1","displayName":"True","description":null,"helpText":null}]},"3d3d9538fd9bfae6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts","displayName":"Check for duplicate contacts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","categoryName":"Contact Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_contactoptions_l_selectthedefaultsettingforhowtofilenewcontacts_l_checkforduplicatecontacts_1","displayName":"True","description":null,"helpText":null}]},"3df775e93f4bb747":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback","displayName":"Disable connection fallback between protocols (User)","description":"This policy setting allows you to control the connection transport fallback behavior in Outlook when it attempts to connect to a Microsoft Exchange Server.\r\n \r\nThis policy setting applies if you are using Outlook Anywhere (RPC over HTTP) to connect to a Microsoft Exchange Server. There are two Outlook profile settings on the Microsoft Exchange Proxy Settings dialog box (accessed through the Control Panel or Account Settings), that configure the default connection transport fallback behavior.\r\n \r\n- On fast networks, connect using HTTP first, then connect using TCP/IP\r\n- On slow networks, connect using HTTP first, then connect using TCP/IP\r\n \r\nFor example, if you are on a fast network and you enable the “On fast networks, connect using HTTP first, then connect using TCP/IP” setting in the Microsoft Exchange Proxy Settings dialog box, Outlook first attempts to connect to the Exchange Server using HTTP. If Outlook is unable to connect using HTTP, then it attempts to connect using TCP/IP.\r\n \r\nIf you enable this policy setting, if Outlook connection attempts with Microsoft Exchange Server fail, Outlook does not fallback to the TCP/IP protocol, regardless of what is specified in the Microsoft Exchange Proxy Settings dialog box. \r\n\r\nIf you disable or do not configure this policy setting, Outlook connection attempts with Microsoft Exchange Server can fallback from either TCP/IP to HTTP, or HTTP to TCP/IP, depending on the settings specified in the Microsoft Exchange Proxy Settings dialog box.\r\n","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablerpctransportfallback_1","displayName":"Enabled","description":null,"helpText":null}]},"3de8278a65106f67":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions","displayName":"Default Internet Calendar subscriptions (User)","description":"This policy setting allows you to deploy Internet Calendar subscriptions.\r\n\r\nIf you enable this policy setting, the URLs listed here will be read and the corresponding Internet Calendar subscriptions will be added to each of the user's profiles. The name you specify here will not be used as the name of the Internet Calendar subscription.\r\n\r\nIf you disable or do not configure this policy setting users will not have any default Internet Calendar subscriptions.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_defaultwebcalsubscriptions_1","displayName":"Enabled","description":null,"helpText":null}]},"3df69c5a6c50fccd":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_l_powerpoint2007andlaterpresentationsshowstemplatesthemesandaddinfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"3d2083054c54a9da":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining","displayName":"And move start of remaining parts back to status date (User)","description":"Moves the remaining portion of a task back to start at the status date.\r\n\r\nIf you enable this setting, the remaining portion of the task moves back to start at the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjandmoveremaining_1","displayName":"Enabled","description":null,"helpText":null}]},"3d28333999cb3b46":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview","displayName":"Default View (User)","description":"Specifies the view that Project displays at startup.\r\n \r\nIf you enable this setting, you can set the default view that is displayed at startup.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdefaultview_1","displayName":"Enabled","description":null,"helpText":null}]},"3d1e1bc9f0425ffd":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher","displayName":"Show the New template gallery when starting Publisher (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"1a0386fd-354b-441e-a0d6-1523c209dae7","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_general_l_showthenewtemplategallerywhenstartingpublisher_1","displayName":"Enabled","description":null,"helpText":null}]},"3ddd97c4a7cda9b9":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery","displayName":"Save AutoRecover info every (minutes) (User)","description":"This policy setting allows you to specify the Save Autorecover interval in minutes.\r\n\r\nIf you enable this policy setting, you may specify the Save Autorecover interval in minutes (valid range: 1-120).\r\n\r\nIf you disable or do not configure this policy setting, the interval specified in the UI will be used.\r\n","helpText":"","infoUrls":[],"categoryId":"038b49c9-4f13-4ace-be8d-bd076bffa23e","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_save_l_saveautorecoverinfoevery_1","displayName":"Enabled","description":null,"helpText":null}]},"3d18cabf8b2f4900":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},"3df3ec4dcc917b1e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_1","displayName":"Enabled","description":null,"helpText":null}]},"3da4bf09ffb5c1ce":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries","displayName":"Use online translation dictionaries (User)","description":"This policy setting allows you to prevent online dictionaries from being used for the translation of text through the Research pane.\r\n\r\nIf you enable or do not configure this policy setting, the online dictionaries can be used to translate text through the Research pane.\r\n\r\nIf you disable this policy setting, the online dictionaries cannot be used to translate text through the Research pane.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_donotuseonlinetranslationdictionaries_1","displayName":"Enabled","description":null,"helpText":null}]},"3dbc2246469f642f":{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast","displayName":"Disable Unicast Responses To Multicast Broadcast","description":"This value is used as an on/off switch. If it is true, unicast responses to multicast broadcast traffic is blocked. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast_false","displayName":"False","description":"Unicast Responses Not Blocked","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableunicastresponsestomulticastbroadcast_true","displayName":"True","description":"Unicast Responses Blocked","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/3e.json b/public/intune-definitions/3e.json index bcae228bae8d..131154462f5a 100644 --- a/public/intune-definitions/3e.json +++ b/public/intune-definitions/3e.json @@ -1 +1 @@ -{"3e593fa4acc33ad2":{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy","displayName":"Policy","description":"A string that specifies the device's unpairing policy.\n- `None`: The device doesn't automatically unpair. Use this only with a return to service device that you erase and reenroll when assigning it from one user to another.\n- `Hour`: The device automatically unpairs temporarily paired audio accessories at the local time that the `Hour` key specifies.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":[{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy_0","displayName":"None","description":null,"helpText":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy_1","displayName":"Hour","description":null,"helpText":null}]},"3e75fa57f7e52b00":{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill","displayName":"Force Authentication Before Auto Fill","description":"If true, the user must authenticate before passwords or credit card information can be autofilled in Safari and Apps. If this restriction isn’t enforced, the user can toggle this feature in Settings. Only supported on devices with Face ID or Touch ID. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill_true","displayName":"True","description":null,"helpText":null}]},"3e18f6be07044661":{"id":"com.apple.managedclient.preferences_allowedthreats","displayName":"Allowed threats","description":"List of threats (identified by their name) that are not blocked by the product and are instead allowed to run.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#allowed-threats"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"3e91ef692ae5361e":{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled","displayName":"TLS Encrypted ClientHello Enabled","description":"Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy.\n\nIf ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status.\n\nIf you enable or do not configure this policy, Microsoft Edge will follow the default rollout process for ECH.\n\nIf this policy is disabled, Microsoft Edge will not enable ECH.\n\nBecause ECH is an evolving protocol, Microsoft Edge's implementation is subject to change.\n\nAs such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#encryptedclienthelloenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"3e9a37564f9557e4":{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled","displayName":"Allow users to configure Family safety","description":"This policy disables and completely hides the Family safety page in Settings. Navigation to edge://settings/familysafety will also be blocked. The Family safety page describes what features are available for family groups and how to join a family group. Learn more about family safety here: (https://go.microsoft.com/fwlink/?linkid=2098432).\n\nIf you enable this policy or don't configure it, the Family safety page will be shown.\n\nIf you disable this policy, the Family safety page will not be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#familysafetysettingsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"3eacdf23f7444f2c":{"id":"com.apple.managedclient.preferences_importcookies","displayName":"Allow importing of Cookies","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don’t configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importcookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importcookies_true","displayName":"Enabled","description":null,"helpText":null}]},"3e2d47e969b3bcea":{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\n\nWhen enabled or not configured, Microsoft Edge may initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running.\n\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker has started.\n\nThis is a temporary policy and will be removed in version 144 of Microsoft Edge.\n\nFor more information on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serviceworkerautopreloadenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"3efea5459b7c1ca7":{"id":"com.apple.mcxmenuextras_timemachine.menu","displayName":"TimeMachine","description":"If true, enables the TimeMachine menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_timemachine.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_timemachine.menu_true","displayName":"True","description":null,"helpText":null}]},"3e8440d81b06fe30":{"id":"com.apple.mobiledevice.passwordpolicy_minlength","displayName":"Min Length","description":"The minimum overall length of the passcode. This parameter is independent of the also optional Min Complex Characters argument.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"3ec643427f165a2c":{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"3e7550063ad27b9b":{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"3ee677e42221abf0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page (users can override)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\n\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\n\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\n\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\n\nIf you enable this policy, the Copilot new tab page is turned on.\n\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"3e83be6184cd7a52":{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles","description":"This policy controls whether Copilot in the Microsoft Edge side pane can access page content.\n\nThis policy applies only to Microsoft Entra ID profiles in Microsoft Edge. It doesn't apply to Microsoft account (MSA) profiles.\n\nCopilot requires access to page content to summarize pages and interact with text selections.\n\nThis policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with EDP is controlled by the \"EdgeEntraCopilotPageContext\" policy.\n\nIf you enable this policy, Copilot can access page content.\n\nIf you disable this policy, Copilot can't access page content. This also disables the \"M365LinksAutoOpenCopilotEnabled\" feature, because Copilot requires page content access to provide contextual insights for Microsoft 365 links.\n\nIf you don't configure this policy:\n- Access is enabled by default in non-EU regions.\n- Access is disabled by default in EU regions.\n- Users can turn this setting on or off in Microsoft Edge settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},"3ee800e01e1e75d9":{"id":"device_vendor_msft_defender_configuration_dataduplicationlocalretentionperiod","displayName":"Data Duplication Local Retention Period","description":"Define the retention period in days of how much time the evidence data will be kept on the client machine should any transfer to the remote locations would occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"3e5e6f5418ba131d":{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance","displayName":"Disable Cache Maintenance","description":"Defines whether the cache maintenance idle task will perform the cache maintenance or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance_1","displayName":"Cache maintenance is disabled","description":"Cache maintenance is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance_0","displayName":"Cache maintenance is enabled (default)","description":"Cache maintenance is enabled (default)","helpText":null}]},"3e1598fdd214d0a5":{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"3e88e5b641130857":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon","displayName":"MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)","description":"MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoadminlogon"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon_1","displayName":"Enabled","description":null,"helpText":null}]},"3ea05afd673253dd":{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2","displayName":"Floppy Drives: Deny read access","description":"This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"3eb64c78fcff853b":{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy","displayName":"Configure Security Policy for Scripted Diagnostics","description":"This policy setting determines whether scripted diagnostics will execute diagnostic packages that are signed by untrusted publishers.\r\n\r\nIf you enable this policy setting, the scripted diagnostics execution engine validates the signer of any diagnostic package and runs only those signed by trusted publishers.\r\n\r\nIf you disable or do not configure this policy setting, the scripted diagnostics execution engine runs all digitally signed packages.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiageng#admx-sdiageng-scripteddiagnosticssecuritypolicy"],"categoryId":"b6bb653a-73f0-42f4-b097-1ce556310904","categoryName":"Scripted Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"3e09f5f66c857e95":{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync","displayName":"Do not sync","description":"Prevent syncing to and from this PC. This turns off and disables the \"sync your settings\" switch on the \"sync your settings\" page in PC Settings.\r\n\r\nIf you enable this policy setting, \"sync your settings\" will be turned off, and none of the \"sync your setting\" groups will be synced on this PC.\r\n\r\nUse the option \"Allow users to turn syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, \"sync your settings\" is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablesettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},"3ea8314ec25ede5d":{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist","displayName":"File Classification Infrastructure: Specify classification properties list","description":"This policy setting controls which set of properties is available for classifying files on affected computers.\r\n\r\nAdministrators can define the properties for the organization by using Active Directory Domain Services (AD DS), and then group these properties into lists. Administrators can supplement these properties on individual file servers by using File Classification Infrastructure, which is part of the File Server Resource Manager role service.\r\n\r\nIf you enable this policy setting, you can select which list of properties is available for classification on the affected computers. \r\n\r\nIf you disable or do not configure this policy setting, the Global Resource Property List in AD DS provides the default set of properties.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-centralclassificationlist"],"categoryId":"dd9a3dad-5851-4899-a5c1-c23318986846","categoryName":"File Classification Infrastructure","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_1","displayName":"Enabled","description":null,"helpText":null}]},"3e0a3ba5d4531ed1":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive","displayName":"Configure keep-alive connection interval","description":"This policy setting allows you to enter a keep-alive interval to ensure that the session state on the RD Session Host server is consistent with the client state.\r\n\r\nAfter an RD Session Host server client loses the connection to an RD Session Host server, the session on the RD Session Host server might remain active instead of changing to a disconnected state, even if the client is physically disconnected from the RD Session Host server. If the client logs on to the same RD Session Host server again, a new session might be established (if the RD Session Host server is configured to allow multiple sessions), and the original session might still be active.\r\n\r\nIf you enable this policy setting, you must enter a keep-alive interval. The keep-alive interval determines how often, in minutes, the server checks the session state. The range of values you can enter is 1 to 999,999.\r\n\r\nIf you disable or do not configure this policy setting, a keep-alive interval is not set and the server will not check the session state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-keep-alive"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_1","displayName":"Enabled","description":null,"helpText":null}]},"3e56b081da6b1dfa":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_dynamicremovallist","displayName":"Specify additional package family names to remove (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":null},"3e6993fad39d520f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended","displayName":"List of alternate URLs for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'.\r\n\r\nLeaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.\r\n\r\nExample value:\r\n\r\nhttps://search.my.company/suggest#q={searchTerms}\r\nhttps://search.my.company/suggest/search#q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"3e058984d1bcf70c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins_tabcaptureallowedbyoriginsdesc","displayName":"Allow Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},"3ef4984e00b47d7a":{"id":"device_vendor_msft_policy_config_connectivity_hardeneduncpaths_pol_hardenedpaths","displayName":"Hardened UNC Paths:","description":"","helpText":"","infoUrls":[],"categoryId":"643081a4-132d-463e-9d86-c8650cb2a011","categoryName":"Network Provider","options":null},"3e96c582b6b61ad4":{"id":"device_vendor_msft_policy_config_defender_checkforsignaturesbeforerunningscan","displayName":"Check For Signatures Before Running Scan","description":"This policy setting allows you to manage whether a check for new virus and spyware definitions will occur before running a scan. This setting applies to scheduled scans as well as the command line mpcmdrun -SigUpdate, but it has no effect on scans initiated manually from the user interface. If you enable this setting, a check for new definitions will occur before running a scan. If you disable this setting or do not configure this setting, the scan will start using the existing definitions. Supported values:0 (default) - Disabled1 - EnabledOMA-URI Path: . /Vendor/MSFT/Policy/Config/Defender/CheckForSignaturesBeforeRunningScan","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_checkforsignaturesbeforerunningscan_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_defender_checkforsignaturesbeforerunningscan_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"3e375b3ebfdee7f0":{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats","displayName":"Remediation action for Low severity threats","description":"","helpText":"","infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_clean","displayName":"Clean. Service tries to recover files and try to disinfect.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_quarantine","displayName":"Quarantine. Moves files to quarantine.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_remove","displayName":"Remove. Removes files from system.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_allow","displayName":"Allow. Allows file/does none of the above actions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_userdefined","displayName":"User defined. Requires user to make a decision on which action to take.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_block","displayName":"Block. Blocks file execution.","description":null,"helpText":null}]},"3e68923c0b3bbbca":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dovpnkeywords","displayName":"DO Vpn Keywords","description":"Specifies one or more keywords used to recognize VPN connections. To add multiple keywords, separate each by a comma.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dovpnkeywords"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"3e1c4aad46df6a91":{"id":"device_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation","displayName":"Prevent participation in the Customer Experience Improvement Program","description":"This policy setting prevents the user from participating in the Customer Experience Improvement Program (CEIP).\n\nIf you enable this policy setting, the user cannot participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you disable this policy setting, the user must participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you do not configure this policy setting, the user can choose to participate in the CEIP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecustomerexperienceimprovementprogramparticipation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_1","displayName":"Enabled","description":null,"helpText":null}]},"3e63c1ce4cb63164":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"3e7300476f0e0088":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_promptusertochangepasswordbeforeexpiration","displayName":"Interactive Logon Prompt User To Change Password Before Expiration","description":"Interactive logon: Prompt user to change password before expiration Determines how far in advance (in days) users are warned that their password is about to expire. With this advance warning, the user has time to construct a password that is sufficiently strong. Default: 5 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_promptusertochangepasswordbeforeexpiration"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"3ed1e35d09c60936":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_l_galdownloadinitialdelay_value","displayName":"Maximum possible number of minutes to delay download: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},"3ed326c4f40c2070":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_l_trustmodeldata_value","displayName":"Trusted Domains (comma separated list): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},"3e5a64c8544e27ea":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize","displayName":"Set disk cache size, in bytes","description":"Configures the size of the cache, in bytes, used to store files on the disk.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided cache size regardless of whether the user has specified the '--disk-cache-size' flag. The value specified in this policy isn't a hard boundary but rather a suggestion to the caching system; any value below a few megabytes is too small and will be rounded up to a reasonable minimum.\r\n\r\nIf you set the value of this policy to 0, the default cache size is used, and users can't change it.\r\n\r\nIf you don't configure this policy, the default size is used, but users can override it with the '--disk-cache-size' flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"3e532de507bdfa5b":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability","displayName":"Configure InPrivate mode availability","description":"Specifies whether the user can open pages in InPrivate mode in Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Enabled' (0), users can open pages in InPrivate mode.\r\n\r\nSet this policy to 'Disable' (1) to stop users from using InPrivate mode.\r\n\r\nSet this policy to 'Forced' (2) to always use InPrivate mode.\r\n\r\n* 0 = InPrivate mode available\r\n\r\n* 1 = InPrivate mode disabled\r\n\r\n* 2 = InPrivate mode forced","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"3ebe1f33fc99b640":{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\r\nIf you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\r\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\n[*.]contoso.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"3e5784980d780d9c":{"id":"device_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\r\n\r\nIf you enable this policy, mutation events will continue to be fired, even if they've been disabled by default for normal web users.\r\n\r\nIf you disable or don't configure this policy, these events will not be fired.\r\n\r\nThis policy is a temporary workaround, and enterprises should still work to remove their dependencies on these mutation events.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3e3bb0452b038aec":{"id":"device_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox","description":"Setting this policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services when the system configuration supports it.\r\n\r\nSetting this policy to Disabled has a detrimental effect on Microsoft Edge's security because services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn this policy off if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3e28d0f58b69e8bd":{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext","displayName":"Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane","description":"This policy controls whether Copilot in the Microsoft Edge sidepane can access Microsoft Edge page content. This includes page summarization and similar contextual queries sent to Copilot.\r\n\r\nThis policy only applies to users who are signed in to Microsoft Edge with their Entra account and are using Copilot in the sidepane. This policy applies to all Copilot products in the Microsoft Edge sidepane - namely, Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP).\r\n\r\nIf you enable this policy, Copilot will be able to access Microsoft Edge page content when users ask a contextual query to Copilot in the Microsoft Edge sidepane.\r\n\r\nIf you disable this policy, Copilot will not be able to access Microsoft Edge page content.\r\n\r\nIf you don't configure this policy, the default behavior is as follows:\r\n\r\n- For non-EU countries, access is enabled by default.\r\n\r\n- For EU countries, access is disabled by default.\r\n\r\n- In both cases, if the policy is not configured, users can enable or disable Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\r\n\r\nExceptions to the preceding behavior include when a page is protected using data loss prevention (DLP) measures. In that case, Copilot will not be able to access Microsoft Edge page content even when this policy is enabled. This behavior is to ensure the integrity of DLP.\r\n\r\nLearn more about Copilot's data usage and consent at https://go.microsoft.com/fwlink/?linkid=2288056","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},"3ed814651bd1a49f":{"id":"device_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that are not subject to the 'EdgeSidebarAppUrlHostBlockList' (Control which apps cannot be opened in Microsoft Edge sidebar).\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar except the urls listed in 'EdgeSidebarAppUrlHostBlockList'.\r\n\r\nIf you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list.\r\n\r\nBy default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"3e138f2bdcd8fd65":{"id":"device_vendor_msft_policy_config_newsandinterests_disablewidgetsboard","displayName":"Disable Widgets Board","description":"Disable widgets board","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NewsAndInterests#disablewidgetsboard"],"categoryId":"70d374bf-6444-4b74-a879-a29e4d44c566","categoryName":"News And Interests","options":[{"id":"device_vendor_msft_policy_config_newsandinterests_disablewidgetsboard_0","displayName":"Enabled.","description":"Enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_newsandinterests_disablewidgetsboard_1","displayName":"Disabled.","description":"Disabled.","helpText":null}]},"3e5db000f25c4d4b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatebranch","displayName":"Update Channel (Deprecated)","description":"This policy setting controls which update channel Office gets updates from when Office is configured to get updates directly from the Office Content Delivery Network (CDN).\r\n\r\nIf you enable this policy setting, Office gets updates from the update channel that you select.\r\n\r\nIf you disable or don't configure this policy setting, Office gets updates from its default channel, or by the update channel specified by the Office Deployment Tool. The default channel is determined by which Office product that is installed.\r\n\r\nImportant: This policy setting only applies to Office clients, such as Office 365 ProPlus, that come with an Office 365 plan. This policy setting also applies to Visio and Project products that come with an Office 365 plan. This policy has no effect on Office products that are installed by using Windows Installer (MSI).","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatebranch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatebranch_1","displayName":"Enabled","description":null,"helpText":null}]},"3e7871219ea4383a":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb_diskspacecheckthresholdmblist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"3e3e3de185e07c95":{"id":"device_vendor_msft_policy_config_printers_configurecopyfilespolicy_copyfilespolicy_enum","displayName":"Manage processing of Queue-Specific files:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configurecopyfilespolicy_copyfilespolicy_enum_0","displayName":"Do not allow Queue-specific files","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurecopyfilespolicy_copyfilespolicy_enum_1","displayName":"Limit Queue-specific files to Color profiles","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurecopyfilespolicy_copyfilespolicy_enum_2","displayName":"Allow all Queue-specfic files","description":null,"helpText":null}]},"3e54f2c8d8d7c2bf":{"id":"device_vendor_msft_policy_config_remoteassistance_unsolicitedremoteassistance_ra_unsolicit_control_list","displayName":"Permit remote control of this computer:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_remoteassistance_unsolicitedremoteassistance_ra_unsolicit_control_list_1","displayName":"Allow helpers to remotely control the computer","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remoteassistance_unsolicitedremoteassistance_ra_unsolicit_control_list_0","displayName":"Allow helpers to only view the computer","description":null,"helpText":null}]},"3e51cee4a85700d3":{"id":"device_vendor_msft_policy_config_secguidev22h2~policy~cat_secguide_pol_secguide_legacy_jscript_pol_sg_msaccess","displayName":"Access: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":null},"3e9c26d3fcef2587":{"id":"device_vendor_msft_policy_config_userrights_modifyobjectlabel","displayName":"Modify Object Label","description":"This user right determines which user accounts can modify the integrity label of objects, such as files, registry keys, or processes owned by other users. Processes running under a user account can modify the label of an object owned by that user to a lower level without this privilege.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#modifyobjectlabel"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"3e79d5d8683e08d2":{"id":"device_vendor_msft_policy_privilegemanagement_systemsettingrules_{systemsettingrulename}","displayName":"System Setting Rule Name","description":"Unique alpha numeric identifier for the system setting rule. The rule name must not include a forward slash (/).","helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":null},"3e9fc6102b5b76c4":{"id":"device_vendor_msft_reboot_schedule_single","displayName":"Single","description":"Value in ISO8601 date and time format (such as 2025-10-07T10:35:00) is required. Both the date and time are required. A reboot will be scheduled to occur at the specified date and time. Setting a null (empty) date will delete the existing schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Reboot-csp/"],"categoryId":"effee722-f6ec-440e-a892-bf645bc341ff","categoryName":"Reboot","options":null},"3e1d960848847160":{"id":"device_vendor_msft_windowsdefenderapplicationguard_status","displayName":"Status","description":"Returns bitmask that indicates status of Application Guard installation for Microsoft Edge and prerequisites on the device.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/windowsdefenderapplicationguard-csp/"],"categoryId":"cd55f347-a417-4fe9-83ee-8f1f40ac5eb0","categoryName":null,"options":null},"3eb016099f12c2c3":{"id":"mathsettings_calculator_basicmode_addsquareroot","displayName":"Add Square Root","description":"Add the square root button to the basic calculator by replacing the +/- button. Normally, the square root button is available in scientific mode, so this key can be used to make it available when the scientific mode is restricted.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":[{"id":"mathsettings_calculator_basicmode_addsquareroot_false","displayName":"False","description":null,"helpText":null},{"id":"mathsettings_calculator_basicmode_addsquareroot_true","displayName":"True","description":null,"helpText":null}]},"3ec58a7c72b8f167":{"id":"passcode_failedattemptsresetinminutes","displayName":"Failed Attempts Reset In Minutes","description":"The number of minutes before the login is reset after the maximum number of failed attempts. Also set the `MaximumFailedAttempts` key for this to take effect.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":null},"3eb378a3703983bb":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},"3edbea81cf63bdc9":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinfavorites","displayName":"Favorites (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinfavorites_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinfavorites_1","displayName":"True","description":null,"helpText":null}]},"3e3b162794504817":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal","displayName":"Allows a page to perform synchronous XHR requests during page dismissal. (User)","description":"This policy allows an admin to specify that a page may send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to enabled, pages are allowed to send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to disabled or not set, pages are not allowed to send synchronous XHR requests during page dismissal.\r\n\r\nThis policy will be removed in Chrome 93.\r\n\r\nSee https://www.chromestatus.com/feature/4664843055398912 .","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_1","displayName":"Enabled","description":null,"helpText":null}]},"3e72264984403bdd":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication (User)","description":"If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\r\n\r\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3ea2e8440efcdd87":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview","displayName":"Enable Live Preview (User)","description":"Shows or hides the Live Previews that appear when using Galleries that support previews. Live Preview shows how a command would be applied without actually applying it to the document.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview_1","displayName":"Enabled","description":null,"helpText":null}]},"3ec63c81697de6fd":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist","displayName":"Include new rows and columns in table (User)","description":"When working in cells adjacent to a table (known as a \"list\" in previous versions of Excel), enabling this setting causes the adjacent row or column to become part of the table.","helpText":"","infoUrls":[],"categoryId":"67eb1dab-7805-41bb-af5a-798dc7e29f23","categoryName":"Autocorrect Options","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist_1","displayName":"Enabled","description":null,"helpText":null}]},"3e70bc52912a3496":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert","displayName":"Do not show AutoRepublish warning alert (User)","description":"This policy setting controls whether Excel displays an alert before republishing a workbook to the World Wide Web.\r\n\r\nIf you enable this policy setting, no warning appears when the user saves a published workbook when AutoRepublish is enabled.\r\n \r\nIf you disable or do not configure this policy setting, a message dialog appears every time the user saves a published workbook when AutoRepublish is enabled. From this dialog, the user can disable AutoRepublish temporarily or permanently, or select \"Do not show this message again\" to prevent the dialog from appearing after every save. If the user selects \"Do not show this message again\", Excel will continue to automatically republish the data after every save without informing the user.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert_1","displayName":"Enabled","description":null,"helpText":null}]},"3ec1c8670cf7da73":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles","displayName":"Excel 3 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"3eaaba4b94625392":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_diskcachedir","displayName":"Set disk cache directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"3e1959b1010f86ae":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_javascriptblockedforurlsdesc","displayName":"Block JavaScript on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"3e107f41131cfc69":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly (User)","description":"This policy controls whether native host executables launch directly on Windows.\r\n\r\nIf you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly.\r\n\r\nIf you disable this policy, Microsoft Edge will launch hosts using cmd.exe as an intermediary process.\r\n\r\nIf you don't configure this policy, Microsoft Edge will decide which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_1","displayName":"Enabled","description":null,"helpText":null}]},"3eae8c6329130cb3":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"3e6defca008b070a":{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a page or file is printed from Microsoft Edge.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},"3eb32cd3b168b70b":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended","displayName":"Allow importing of shortcuts (User)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"3ef9ea431873f468":{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_30","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"3e2ab4095ec5ab48":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended","displayName":"Sets layout for printing (User)","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"3ece8e4c7436f522":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicesharednotescustomurl1","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"3e615ae5d378cb76":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373_l_withasimplewebdiscussionslink374","displayName":"With a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},"3e8c4cbde33e376b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland","displayName":"English (Ireland) (User)","description":"Enables the editing language English (Ireland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland_1","displayName":"Enabled","description":null,"helpText":null}]},"3e1864edea9f5d7a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2","displayName":"Workflow Cache 2 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_1","displayName":"Enabled","description":null,"helpText":null}]},"3eb38401397fc1fa":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowpath444","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"3e058682fe69c662":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects","displayName":"Check OLE objects (User)","description":"This policy setting determines whether Office checks that an OLE object is properly categorized before loading it. \r\n\r\nIf you enable this policy setting, you can select one of the following options:\r\n- Do not check: Office loads OLE objects without checking if they are properly categorized.\r\n- Override IE kill bit list: Office uses the category list to override IE kill bit checks. (This is also the default behavior for this policy setting). \r\n- Strict allow list: Office only loads properly categorized OLE objects.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the category list to override IE kill bit checks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_1","displayName":"Enabled","description":null,"helpText":null}]},"3e7ece698b74dd07":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages","displayName":"Add signature to OneNote email messages (User)","description":"Checks/Unchecks the option ''Add the following signature to e-mail messages and Web pages created in OneNote''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},"3e9076d3907fb605":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields","displayName":"Suggest names while completing To, Cc, and Bcc fields (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields_1","displayName":"True","description":null,"helpText":null}]},"3e4bfaec6de14738":{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver","displayName":"Select the authentication with Exchange server. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_9","displayName":"Kerberos/NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_16","displayName":"Kerberos Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_10","displayName":"NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_2147545088","displayName":"Insert a smart card","description":null,"helpText":null}]},"3e075a6b9ac05ba4":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},"3eef260ec1ba16a4":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"3e522583501545b4":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"3e72cc467d1b7600":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"3e9b212a5511a53e":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"3e32f051709c5f3c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"3e47e0549d4f2a40":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null}} \ No newline at end of file +{"3e593fa4acc33ad2":{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy","displayName":"Policy","description":"A string that specifies the device's unpairing policy.\n- `None`: The device doesn't automatically unpair. Use this only with a return to service device that you erase and reenroll when assigning it from one user to another.\n- `Hour`: The device automatically unpairs temporarily paired audio accessories at the local time that the `Hour` key specifies.","helpText":null,"infoUrls":[],"categoryId":"a42e2248-d2dc-4476-a92d-d152fd67e04b","categoryName":"Audio Accessory","options":[{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy_0","displayName":"None","description":null,"helpText":null},{"id":"audioaccessory_temporarypairing_configuration_unpairingtime_policy_1","displayName":"Hour","description":null,"helpText":null}]},"3e75fa57f7e52b00":{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill","displayName":"Force Authentication Before Auto Fill","description":"If true, the user must authenticate before passwords or credit card information can be autofilled in Safari and Apps. If this restriction isn’t enforced, the user can toggle this feature in Settings. Only supported on devices with Face ID or Touch ID. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceauthenticationbeforeautofill_true","displayName":"True","description":null,"helpText":null}]},"3e18f6be07044661":{"id":"com.apple.managedclient.preferences_allowedthreats","displayName":"Allowed threats","description":"List of threats (identified by their name) that are not blocked by the product and are instead allowed to run.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#allowed-threats"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"3e91ef692ae5361e":{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled","displayName":"TLS Encrypted ClientHello Enabled","description":"Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy.\n\nIf ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status.\n\nIf you enable or do not configure this policy, Microsoft Edge will follow the default rollout process for ECH.\n\nIf this policy is disabled, Microsoft Edge will not enable ECH.\n\nBecause ECH is an evolving protocol, Microsoft Edge's implementation is subject to change.\n\nAs such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#encryptedclienthelloenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_encryptedclienthelloenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"3e9a37564f9557e4":{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled","displayName":"Allow users to configure Family safety","description":"This policy disables and completely hides the Family safety page in Settings. Navigation to edge://settings/familysafety will also be blocked. The Family safety page describes what features are available for family groups and how to join a family group. Learn more about family safety here: (https://go.microsoft.com/fwlink/?linkid=2098432).\n\nIf you enable this policy or don't configure it, the Family safety page will be shown.\n\nIf you disable this policy, the Family safety page will not be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#familysafetysettingsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_familysafetysettingsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"3eacdf23f7444f2c":{"id":"com.apple.managedclient.preferences_importcookies","displayName":"Allow importing of Cookies","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don’t configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importcookies"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importcookies_true","displayName":"Enabled","description":null,"helpText":null}]},"3e2d47e969b3bcea":{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\n\nWhen enabled or not configured, Microsoft Edge may initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running.\n\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker has started.\n\nThis is a temporary policy and will be removed in version 144 of Microsoft Edge.\n\nFor more information on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#serviceworkerautopreloadenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_serviceworkerautopreloadenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"3efea5459b7c1ca7":{"id":"com.apple.mcxmenuextras_timemachine.menu","displayName":"TimeMachine","description":"If true, enables the TimeMachine menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_timemachine.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_timemachine.menu_true","displayName":"True","description":null,"helpText":null}]},"3e8440d81b06fe30":{"id":"com.apple.mobiledevice.passwordpolicy_minlength","displayName":"Min Length","description":"The minimum overall length of the passcode. This parameter is independent of the also optional Min Complex Characters argument.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"3ec643427f165a2c":{"id":"com.apple.tcc.configuration-profile-policy_services_medialibrary_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"3e7550063ad27b9b":{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"3ee677e42221abf0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page (users can override)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\n\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\n\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\n\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\n\nIf you enable this policy, the Copilot new tab page is turned on.\n\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"3e83be6184cd7a52":{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext","displayName":"Control Copilot access to page context for Microsoft Entra ID profiles","description":"This policy controls whether Copilot in the Microsoft Edge side pane can access page content.\n\nThis policy applies only to Microsoft Entra ID profiles in Microsoft Edge. It doesn't apply to Microsoft account (MSA) profiles.\n\nCopilot requires access to page content to summarize pages and interact with text selections.\n\nThis policy doesn't control access for Copilot with enterprise data protection (EDP). Access for Copilot with EDP is controlled by the \"EdgeEntraCopilotPageContext\" policy.\n\nIf you enable this policy, Copilot can access page content.\n\nIf you disable this policy, Copilot can't access page content. This also disables the \"M365LinksAutoOpenCopilotEnabled\" feature, because Copilot requires page content access to provide contextual insights for Microsoft 365 links.\n\nIf you don't configure this policy:\n- Access is enabled by default in non-EU regions.\n- Access is disabled by default in EU regions.\n- Users can turn this setting on or off in Microsoft Edge settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotpagecontext_true","displayName":"Enabled","description":null,"helpText":null}]},"3ee800e01e1e75d9":{"id":"device_vendor_msft_defender_configuration_dataduplicationlocalretentionperiod","displayName":"Data Duplication Local Retention Period","description":"Define the retention period in days of how much time the evidence data will be kept on the client machine should any transfer to the remote locations would occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"3e5e6f5418ba131d":{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance","displayName":"Disable Cache Maintenance","description":"Defines whether the cache maintenance idle task will perform the cache maintenance or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance_1","displayName":"Cache maintenance is disabled","description":"Cache maintenance is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecachemaintenance_0","displayName":"Cache maintenance is enabled (default)","description":"Cache maintenance is enabled (default)","helpText":null}]},"3ebf6847e28b803e":{"id":"device_vendor_msft_maintenancewindows_duration","displayName":"Duration (hours)","description":"Specify the duration of the maintenance window in hours. Value must be between 2 and 24 hours.","helpText":"Between 2 and 24 hours.","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":null},"3e1598fdd214d0a5":{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_mitrealms_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"3e88e5b641130857":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon","displayName":"MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)","description":"MSS: (AutoAdminLogon) Enable Automatic Logon (not recommended)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autoadminlogon"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autoadminlogon_1","displayName":"Enabled","description":null,"helpText":null}]},"3ea05afd673253dd":{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2","displayName":"Floppy Drives: Deny read access","description":"This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denyread-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"3eb64c78fcff853b":{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy","displayName":"Configure Security Policy for Scripted Diagnostics","description":"This policy setting determines whether scripted diagnostics will execute diagnostic packages that are signed by untrusted publishers.\r\n\r\nIf you enable this policy setting, the scripted diagnostics execution engine validates the signer of any diagnostic package and runs only those signed by trusted publishers.\r\n\r\nIf you disable or do not configure this policy setting, the scripted diagnostics execution engine runs all digitally signed packages.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sdiageng#admx-sdiageng-scripteddiagnosticssecuritypolicy"],"categoryId":"b6bb653a-73f0-42f4-b097-1ce556310904","categoryName":"Scripted Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sdiageng_scripteddiagnosticssecuritypolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"3e09f5f66c857e95":{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync","displayName":"Do not sync","description":"Prevent syncing to and from this PC. This turns off and disables the \"sync your settings\" switch on the \"sync your settings\" page in PC Settings.\r\n\r\nIf you enable this policy setting, \"sync your settings\" will be turned off, and none of the \"sync your setting\" groups will be synced on this PC.\r\n\r\nUse the option \"Allow users to turn syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, \"sync your settings\" is on by default and configurable by the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disablesettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablesettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},"3ea8314ec25ede5d":{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist","displayName":"File Classification Infrastructure: Specify classification properties list","description":"This policy setting controls which set of properties is available for classifying files on affected computers.\r\n\r\nAdministrators can define the properties for the organization by using Active Directory Domain Services (AD DS), and then group these properties into lists. Administrators can supplement these properties on individual file servers by using File Classification Infrastructure, which is part of the File Server Resource Manager role service.\r\n\r\nIf you enable this policy setting, you can select which list of properties is available for classification on the affected computers. \r\n\r\nIf you disable or do not configure this policy setting, the Global Resource Property List in AD DS provides the default set of properties.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-srmfci#admx-srmfci-centralclassificationlist"],"categoryId":"dd9a3dad-5851-4899-a5c1-c23318986846","categoryName":"File Classification Infrastructure","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_centralclassificationlist_1","displayName":"Enabled","description":null,"helpText":null}]},"3e0a3ba5d4531ed1":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive","displayName":"Configure keep-alive connection interval","description":"This policy setting allows you to enter a keep-alive interval to ensure that the session state on the RD Session Host server is consistent with the client state.\r\n\r\nAfter an RD Session Host server client loses the connection to an RD Session Host server, the session on the RD Session Host server might remain active instead of changing to a disconnected state, even if the client is physically disconnected from the RD Session Host server. If the client logs on to the same RD Session Host server again, a new session might be established (if the RD Session Host server is configured to allow multiple sessions), and the original session might still be active.\r\n\r\nIf you enable this policy setting, you must enter a keep-alive interval. The keep-alive interval determines how often, in minutes, the server checks the session state. The range of values you can enter is 1 to 999,999.\r\n\r\nIf you disable or do not configure this policy setting, a keep-alive interval is not set and the server will not check the session state.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-keep-alive"],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_keep_alive_1","displayName":"Enabled","description":null,"helpText":null}]},"3e56b081da6b1dfa":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_dynamicremovallist","displayName":"Specify additional package family names to remove (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":null},"3e6993fad39d520f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended","displayName":"List of alternate URLs for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'.\r\n\r\nLeaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.\r\n\r\nExample value:\r\n\r\nhttps://search.my.company/suggest#q={searchTerms}\r\nhttps://search.my.company/suggest/search#q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovideralternateurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"3e058984d1bcf70c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_tabcaptureallowedbyorigins_tabcaptureallowedbyoriginsdesc","displayName":"Allow Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},"3ef4984e00b47d7a":{"id":"device_vendor_msft_policy_config_connectivity_hardeneduncpaths_pol_hardenedpaths","displayName":"Hardened UNC Paths:","description":"","helpText":"","infoUrls":[],"categoryId":"643081a4-132d-463e-9d86-c8650cb2a011","categoryName":"Network Provider","options":null},"3e96c582b6b61ad4":{"id":"device_vendor_msft_policy_config_defender_checkforsignaturesbeforerunningscan","displayName":"Check For Signatures Before Running Scan","description":"This policy setting allows you to manage whether a check for new virus and spyware definitions will occur before running a scan. This setting applies to scheduled scans as well as the command line mpcmdrun -SigUpdate, but it has no effect on scans initiated manually from the user interface. If you enable this setting, a check for new definitions will occur before running a scan. If you disable this setting or do not configure this setting, the scan will start using the existing definitions. Supported values:0 (default) - Disabled1 - EnabledOMA-URI Path: . /Vendor/MSFT/Policy/Config/Defender/CheckForSignaturesBeforeRunningScan","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_checkforsignaturesbeforerunningscan_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_defender_checkforsignaturesbeforerunningscan_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"3e375b3ebfdee7f0":{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats","displayName":"Remediation action for Low severity threats","description":"","helpText":"","infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_clean","displayName":"Clean. Service tries to recover files and try to disinfect.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_quarantine","displayName":"Quarantine. Moves files to quarantine.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_remove","displayName":"Remove. Removes files from system.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_allow","displayName":"Allow. Allows file/does none of the above actions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_userdefined","displayName":"User defined. Requires user to make a decision on which action to take.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_lowseveritythreats_block","displayName":"Block. Blocks file execution.","description":null,"helpText":null}]},"3e68923c0b3bbbca":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dovpnkeywords","displayName":"DO Vpn Keywords","description":"Specifies one or more keywords used to recognize VPN connections. To add multiple keywords, separate each by a comma.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dovpnkeywords"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"3e1c4aad46df6a91":{"id":"device_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation","displayName":"Prevent participation in the Customer Experience Improvement Program","description":"This policy setting prevents the user from participating in the Customer Experience Improvement Program (CEIP).\n\nIf you enable this policy setting, the user cannot participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you disable this policy setting, the user must participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you do not configure this policy setting, the user can choose to participate in the CEIP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecustomerexperienceimprovementprogramparticipation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_1","displayName":"Enabled","description":null,"helpText":null}]},"3e63c1ce4cb63164":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"3e7300476f0e0088":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_promptusertochangepasswordbeforeexpiration","displayName":"Interactive Logon Prompt User To Change Password Before Expiration","description":"Interactive logon: Prompt user to change password before expiration Determines how far in advance (in days) users are warned that their password is about to expire. With this advance warning, the user has time to construct a password that is sufficiently strong. Default: 5 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_promptusertochangepasswordbeforeexpiration"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"3ed1e35d09c60936":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policygaldownloadinitialdelay_l_galdownloadinitialdelay_value","displayName":"Maximum possible number of minutes to delay download: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},"3ed326c4f40c2070":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policytrustmodeldata_l_trustmodeldata_value","displayName":"Trusted Domains (comma separated list): (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":null},"3e5a64c8544e27ea":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize","displayName":"Set disk cache size, in bytes","description":"Configures the size of the cache, in bytes, used to store files on the disk.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided cache size regardless of whether the user has specified the '--disk-cache-size' flag. The value specified in this policy isn't a hard boundary but rather a suggestion to the caching system; any value below a few megabytes is too small and will be rounded up to a reasonable minimum.\r\n\r\nIf you set the value of this policy to 0, the default cache size is used, and users can't change it.\r\n\r\nIf you don't configure this policy, the default size is used, but users can override it with the '--disk-cache-size' flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"3e532de507bdfa5b":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability","displayName":"Configure InPrivate mode availability","description":"Specifies whether the user can open pages in InPrivate mode in Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Enabled' (0), users can open pages in InPrivate mode.\r\n\r\nSet this policy to 'Disable' (1) to stop users from using InPrivate mode.\r\n\r\nSet this policy to 'Forced' (2) to always use InPrivate mode.\r\n\r\n* 0 = InPrivate mode available\r\n\r\n* 1 = InPrivate mode disabled\r\n\r\n* 2 = InPrivate mode forced","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_inprivatemodeavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"3ebe1f33fc99b640":{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\r\nIf you don't configure this policy, 'DefaultAutomaticDownloadsSetting' (Default automatic downloads setting) applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\r\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com\r\n[*.]contoso.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"3e5784980d780d9c":{"id":"device_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\r\n\r\nIf you enable this policy, mutation events will continue to be fired, even if they've been disabled by default for normal web users.\r\n\r\nIf you disable or don't configure this policy, these events will not be fired.\r\n\r\nThis policy is a temporary workaround, and enterprises should still work to remove their dependencies on these mutation events.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3e3bb0452b038aec":{"id":"device_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox","description":"Setting this policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services when the system configuration supports it.\r\n\r\nSetting this policy to Disabled has a detrimental effect on Microsoft Edge's security because services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn this policy off if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3e28d0f58b69e8bd":{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext","displayName":"Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane","description":"This policy controls whether Copilot in the Microsoft Edge sidepane can access Microsoft Edge page content. This includes page summarization and similar contextual queries sent to Copilot.\r\n\r\nThis policy only applies to users who are signed in to Microsoft Edge with their Entra account and are using Copilot in the sidepane. This policy applies to all Copilot products in the Microsoft Edge sidepane - namely, Microsoft 365 Copilot Business Chat and Microsoft Copilot with enterprise data protection (EDP).\r\n\r\nIf you enable this policy, Copilot will be able to access Microsoft Edge page content when users ask a contextual query to Copilot in the Microsoft Edge sidepane.\r\n\r\nIf you disable this policy, Copilot will not be able to access Microsoft Edge page content.\r\n\r\nIf you don't configure this policy, the default behavior is as follows:\r\n\r\n- For non-EU countries, access is enabled by default.\r\n\r\n- For EU countries, access is disabled by default.\r\n\r\n- In both cases, if the policy is not configured, users can enable or disable Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\r\n\r\nExceptions to the preceding behavior include when a page is protected using data loss prevention (DLP) measures. In that case, Copilot will not be able to access Microsoft Edge page content even when this policy is enabled. This behavior is to ensure the integrity of DLP.\r\n\r\nLearn more about Copilot's data usage and consent at https://go.microsoft.com/fwlink/?linkid=2288056","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge_edgeentracopilotpagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},"3ed814651bd1a49f":{"id":"device_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist","displayName":"Allow specific apps to be opened in Microsoft Edge sidebar","description":"Define a list of sites, based on URL patterns, that are not subject to the 'EdgeSidebarAppUrlHostBlockList' (Control which apps cannot be opened in Microsoft Edge sidebar).\r\n\r\nIf you don't configure this policy, a user can open any app in sidebar except the urls listed in 'EdgeSidebarAppUrlHostBlockList'.\r\n\r\nIf you configure this policy, the apps listed in the allow list could be opened in sidebar even if they are listed in the block list.\r\n\r\nBy default, all apps are allowed. However, if you prohibited apps by policy, you can use the list of allowed apps to change that policy.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev131~policy~microsoft_edge_edgesidebarappurlhostallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"3e138f2bdcd8fd65":{"id":"device_vendor_msft_policy_config_newsandinterests_disablewidgetsboard","displayName":"Disable Widgets Board","description":"Disable widgets board","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NewsAndInterests#disablewidgetsboard"],"categoryId":"70d374bf-6444-4b74-a879-a29e4d44c566","categoryName":"News And Interests","options":[{"id":"device_vendor_msft_policy_config_newsandinterests_disablewidgetsboard_0","displayName":"Enabled.","description":"Enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_newsandinterests_disablewidgetsboard_1","displayName":"Disabled.","description":"Disabled.","helpText":null}]},"3e5db000f25c4d4b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatebranch","displayName":"Update Channel (Deprecated)","description":"This policy setting controls which update channel Office gets updates from when Office is configured to get updates directly from the Office Content Delivery Network (CDN).\r\n\r\nIf you enable this policy setting, Office gets updates from the update channel that you select.\r\n\r\nIf you disable or don't configure this policy setting, Office gets updates from its default channel, or by the update channel specified by the Office Deployment Tool. The default channel is determined by which Office product that is installed.\r\n\r\nImportant: This policy setting only applies to Office clients, such as Office 365 ProPlus, that come with an Office 365 plan. This policy setting also applies to Visio and Project products that come with an Office 365 plan. This policy has no effect on Office products that are installed by using Windows Installer (MSI).","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatebranch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_updatebranch_1","displayName":"Enabled","description":null,"helpText":null}]},"3e7871219ea4383a":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb_diskspacecheckthresholdmblist_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"3e3e3de185e07c95":{"id":"device_vendor_msft_policy_config_printers_configurecopyfilespolicy_copyfilespolicy_enum","displayName":"Manage processing of Queue-Specific files:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configurecopyfilespolicy_copyfilespolicy_enum_0","displayName":"Do not allow Queue-specific files","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurecopyfilespolicy_copyfilespolicy_enum_1","displayName":"Limit Queue-specific files to Color profiles","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurecopyfilespolicy_copyfilespolicy_enum_2","displayName":"Allow all Queue-specfic files","description":null,"helpText":null}]},"3e54f2c8d8d7c2bf":{"id":"device_vendor_msft_policy_config_remoteassistance_unsolicitedremoteassistance_ra_unsolicit_control_list","displayName":"Permit remote control of this computer:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_remoteassistance_unsolicitedremoteassistance_ra_unsolicit_control_list_1","displayName":"Allow helpers to remotely control the computer","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remoteassistance_unsolicitedremoteassistance_ra_unsolicit_control_list_0","displayName":"Allow helpers to only view the computer","description":null,"helpText":null}]},"3e51cee4a85700d3":{"id":"device_vendor_msft_policy_config_secguidev22h2~policy~cat_secguide_pol_secguide_legacy_jscript_pol_sg_msaccess","displayName":"Access: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":null},"3e9c26d3fcef2587":{"id":"device_vendor_msft_policy_config_userrights_modifyobjectlabel","displayName":"Modify Object Label","description":"This user right determines which user accounts can modify the integrity label of objects, such as files, registry keys, or processes owned by other users. Processes running under a user account can modify the label of an object owned by that user to a lower level without this privilege.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#modifyobjectlabel"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"3e79d5d8683e08d2":{"id":"device_vendor_msft_policy_privilegemanagement_systemsettingrules_{systemsettingrulename}","displayName":"System Setting Rule Name","description":"Unique alpha numeric identifier for the system setting rule. The rule name must not include a forward slash (/).","helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":null},"3e9fc6102b5b76c4":{"id":"device_vendor_msft_reboot_schedule_single","displayName":"Single","description":"Value in ISO8601 date and time format (such as 2025-10-07T10:35:00) is required. Both the date and time are required. A reboot will be scheduled to occur at the specified date and time. Setting a null (empty) date will delete the existing schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Reboot-csp/"],"categoryId":"effee722-f6ec-440e-a892-bf645bc341ff","categoryName":"Reboot","options":null},"3e1d960848847160":{"id":"device_vendor_msft_windowsdefenderapplicationguard_status","displayName":"Status","description":"Returns bitmask that indicates status of Application Guard installation for Microsoft Edge and prerequisites on the device.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/windowsdefenderapplicationguard-csp/"],"categoryId":"cd55f347-a417-4fe9-83ee-8f1f40ac5eb0","categoryName":null,"options":null},"3eb016099f12c2c3":{"id":"mathsettings_calculator_basicmode_addsquareroot","displayName":"Add Square Root","description":"Add the square root button to the basic calculator by replacing the +/- button. Normally, the square root button is available in scientific mode, so this key can be used to make it available when the scientific mode is restricted.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":[{"id":"mathsettings_calculator_basicmode_addsquareroot_false","displayName":"False","description":null,"helpText":null},{"id":"mathsettings_calculator_basicmode_addsquareroot_true","displayName":"True","description":null,"helpText":null}]},"3ec58a7c72b8f167":{"id":"passcode_failedattemptsresetinminutes","displayName":"Failed Attempts Reset In Minutes","description":"The number of minutes before the login is reset after the maximum number of failed attempts. Also set the `MaximumFailedAttempts` key for this to take effect.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":null},"3eb378a3703983bb":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},"3edbea81cf63bdc9":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinfavorites","displayName":"Favorites (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinfavorites_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepinfavorites_1","displayName":"True","description":null,"helpText":null}]},"3e3b162794504817":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal","displayName":"Allows a page to perform synchronous XHR requests during page dismissal. (User)","description":"This policy allows an admin to specify that a page may send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to enabled, pages are allowed to send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to disabled or not set, pages are not allowed to send synchronous XHR requests during page dismissal.\r\n\r\nThis policy will be removed in Chrome 93.\r\n\r\nSee https://www.chromestatus.com/feature/4664843055398912 .","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_1","displayName":"Enabled","description":null,"helpText":null}]},"3e72264984403bdd":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication (User)","description":"If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\r\n\r\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"3ea2e8440efcdd87":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview","displayName":"Enable Live Preview (User)","description":"Shows or hides the Live Previews that appear when using Galleries that support previews. Live Preview shows how a command would be applied without actually applying it to the document.","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_disablelivepreview_1","displayName":"Enabled","description":null,"helpText":null}]},"3ec63c81697de6fd":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist","displayName":"Include new rows and columns in table (User)","description":"When working in cells adjacent to a table (known as a \"list\" in previous versions of Excel), enabling this setting causes the adjacent row or column to become part of the table.","helpText":"","infoUrls":[],"categoryId":"67eb1dab-7805-41bb-af5a-798dc7e29f23","categoryName":"Autocorrect Options","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_includenewrowsandcolumnsinlist_1","displayName":"Enabled","description":null,"helpText":null}]},"3e70bc52912a3496":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert","displayName":"Do not show AutoRepublish warning alert (User)","description":"This policy setting controls whether Excel displays an alert before republishing a workbook to the World Wide Web.\r\n\r\nIf you enable this policy setting, no warning appears when the user saves a published workbook when AutoRepublish is enabled.\r\n \r\nIf you disable or do not configure this policy setting, a message dialog appears every time the user saves a published workbook when AutoRepublish is enabled. From this dialog, the user can disable AutoRepublish temporarily or permanently, or select \"Do not show this message again\" to prevent the dialog from appearing after every save. If the user selects \"Do not show this message again\", Excel will continue to automatically republish the data after every save without informing the user.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_donotshowautorepublishwarningalert_1","displayName":"Enabled","description":null,"helpText":null}]},"3ec1c8670cf7da73":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles","displayName":"Excel 3 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel3macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"3eaaba4b94625392":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_diskcachedir","displayName":"Set disk cache directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"3e1959b1010f86ae":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_javascriptblockedforurlsdesc","displayName":"Block JavaScript on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"3e107f41131cfc69":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly (User)","description":"This policy controls whether native host executables launch directly on Windows.\r\n\r\nIf you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly.\r\n\r\nIf you disable this policy, Microsoft Edge will launch hosts using cmd.exe as an intermediary process.\r\n\r\nIf you don't configure this policy, Microsoft Edge will decide which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_1","displayName":"Enabled","description":null,"helpText":null}]},"3eae8c6329130cb3":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_javascriptoptimizerblockedforsitesdesc","displayName":"Block JavaScript optimizations on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"3e6defca008b070a":{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a page or file is printed from Microsoft Edge.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},"3eb32cd3b168b70b":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended","displayName":"Allow importing of shortcuts (User)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importshortcuts_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"3ef9ea431873f468":{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_30","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_sleepingtabstimeout_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"3e2ab4095ec5ab48":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended","displayName":"Sets layout for printing (User)","description":"Configuring this policy sets the layout for printing webpages.\r\n\r\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\r\n\r\nIf you enable this policy, the selected option is set as the layout option.\r\n\r\nPolicy options mapping:\r\n\r\n* portrait (0) = Sets layout option as portrait\r\n\r\n* landscape (1) = Sets layout option as landscape\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended~printing_recommended_printingwebpagelayout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"3ece8e4c7436f522":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicesharednotescustomurl1","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"3e615ae5d378cb76":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withasimplewebdiscussionslink373_l_withasimplewebdiscussionslink374","displayName":"With a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},"3e8c4cbde33e376b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland","displayName":"English (Ireland) (User)","description":"Enables the editing language English (Ireland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_englishireland_1","displayName":"Enabled","description":null,"helpText":null}]},"3e1864edea9f5d7a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2","displayName":"Workflow Cache 2 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_1","displayName":"Enabled","description":null,"helpText":null}]},"3eb38401397fc1fa":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowpath444","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"3e058682fe69c662":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects","displayName":"Check OLE objects (User)","description":"This policy setting determines whether Office checks that an OLE object is properly categorized before loading it. \r\n\r\nIf you enable this policy setting, you can select one of the following options:\r\n- Do not check: Office loads OLE objects without checking if they are properly categorized.\r\n- Override IE kill bit list: Office uses the category list to override IE kill bit checks. (This is also the default behavior for this policy setting). \r\n- Strict allow list: Office only loads properly categorized OLE objects.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the category list to override IE kill bit checks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_checkoleobjects_1","displayName":"Enabled","description":null,"helpText":null}]},"3e7ece698b74dd07":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages","displayName":"Add signature to OneNote email messages (User)","description":"Checks/Unchecks the option ''Add the following signature to e-mail messages and Web pages created in OneNote''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_addsignaturetoonenoteemailmessages_1","displayName":"Enabled","description":null,"helpText":null}]},"3e9076d3907fb605":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields","displayName":"Suggest names while completing To, Cc, and Bcc fields (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_suggestnameswhilecompletingtoccandbccfields_1","displayName":"True","description":null,"helpText":null}]},"3e4bfaec6de14738":{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver","displayName":"Select the authentication with Exchange server. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_9","displayName":"Kerberos/NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_16","displayName":"Kerberos Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_10","displayName":"NTLM Password Authentication","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_authenticationwithexchangeserver_l_selecttheauthenticationwithexchangeserver_2147545088","displayName":"Insert a smart card","description":null,"helpText":null}]},"3e075a6b9ac05ba4":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":null},"3eef260ec1ba16a4":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_microsoftofficeopenxmlconvertersforpowerpoint_l_microsoftofficeopenxmlconvertersforpowerpointdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"3e522583501545b4":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon29","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"3e72cc467d1b7600":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"3e9b212a5511a53e":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_l_pathcolon64","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"3e32f051709c5f3c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"3e47e0549d4f2a40":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc16_l_pathcolon68","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/41.json b/public/intune-definitions/41.json index 28264811980b..15a7d2c8fd37 100644 --- a/public/intune-definitions/41.json +++ b/public/intune-definitions/41.json @@ -1 +1 @@ -{"4109bee226dd1c9d":{"id":"com.apple.cellularprivatenetwork.managed_versionnumber","displayName":"Version Number","description":"The version number of this dataset that the system uses to track updates.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"4159c5cb4b6372bd":{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup","displayName":"Enable Registration During Setup","description":"If `true`, the system enables the PlatformSSO registration process during Setup Assistant on devices running macOS 26 and later. Set this key to `true` when configuring PlatformSSO before enrollment using the `com.apple.psso.required` error response.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup_true","displayName":"Enabled","description":null,"helpText":null}]},"410eed4e015e7e8c":{"id":"com.apple.managedclient.preferences_tags_item_value","displayName":"Value of tag","description":"Only one value per tag type can be set. Type of tags are unique, and should not be repeated in the same configuration profile.","helpText":null,"infoUrls":[],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":null},"411f2bad1d791a71":{"id":"com.apple.managedclient.preferences_tls13earlydataenabled","displayName":"Control whether TLS 1.3 Early Data is enabled in Microsoft Edge","description":"This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge.\n\nTLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance.\n\nEnabled – Microsoft Edge enables TLS 1.3 Early Data.\n\nDisabled – Microsoft Edge disables TLS 1.3 Early Data.\n\nNot configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data.\n\nNOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution.\n\nThis policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tls13earlydataenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tls13earlydataenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tls13earlydataenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"41d52a38fae27c9c":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"415f486b577b213e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled","displayName":"Allow queries to a Browser Network Time service","description":"Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp.\n\nIf you disable this policy, Microsoft Edge stops sending queries to a browser network time service.\n\nIf you enable this policy or don't configure it, Microsoft Edge occasionally sends queries to a browser network time service.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"41308eafb348d376":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages","description":"An \"in-page\" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous \"in-page\" navigation attempt. Conversely, a user can start a navigation that isn't \"in-page\" and that's independent of the current page in several ways by using the browser controls, for example, using the address bar, the back button, or a favorite link.\n\nThis setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that aren't configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode.\n\nThis setting works in conjunction with \"InternetExplorerIntegrationLevel\" policy that's set to 'IEMode', and with \"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry.\n\nIf you disable or don't configure this policy, only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.\n\nIf you set this policy to 'Default', only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.\n\nIf you set this policy to 'AutomaticNavigationsOnly', you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites are kept in Internet Explorer mode.\n\nIf you set this policy to 'AllInPageNavigations', all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended).\n\nIf the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy allows users to reload sites in Internet Explorer mode, then all in-page navigations from unconfigured sites that users have chosen to reload in Internet Explorer mode are kept in Internet Explorer mode, regardless of how this policy is configured.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106.\n\nPolicy options mapping:\n\n* Default (0) = Default\n\n* AutomaticNavigationsOnly (1) = Keep only automatic navigations in Internet Explorer mode\n\n* AllInPageNavigations (2) = Keep all in-page navigations in Internet Explorer mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_default","displayName":"Default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_automaticnavigationsonly","displayName":"Keep only automatic navigations in Internet Explorer mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_allinpagenavigations","displayName":"Keep all in-page navigations in Internet Explorer mode","description":null,"helpText":null}]},"41082ef0df8fafcb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode","displayName":"Configure proxy server settings (Deprecated)","description":"This policy is deprecated and doesn't work in Microsoft Edge version 91. Use \"ProxySettings\" instead.\n\nIf you set this policy to Enabled, you can specify the proxy server Microsoft Edge uses and prevents users from changing proxy settings. Microsoft Edge ignores all proxy-related options specified from the command line. The policy is only applied if the \"ProxySettings\" policy isn't specified.\n\nOther options are ignored if you choose one of the following options:\n * direct = Never use a proxy server and always connect directly\n * system = Use system proxy settings\n * auto_detect = Auto detect the proxy server\n\nIf you choose to use:\n * fixed_servers = Fixed proxy servers. You can specify further options with \"ProxyServer\" and \"ProxyBypassList\".\n * pac_script = A .pac proxy script. Use \"ProxyPacUrl\" to set the URL to a proxy .pac file.\n\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nPolicy options mapping:\n\n* ProxyDisabled (direct) = Never use a proxy\n\n* ProxyAutoDetect (auto_detect) = Auto detect proxy settings\n\n* ProxyPacScript (pac_script) = Use a .pac proxy script\n\n* ProxyFixedServers (fixed_servers) = Use fixed proxy servers\n\n* ProxyUseSystem (system) = Use system proxy settings\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxydisabled","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyautodetect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxypacscript","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyfixedservers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyusesystem","displayName":"Use system proxy settings","description":null,"helpText":null}]},"41dd2952f305b503":{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name","displayName":"Save BitLocker recovery information to AD DS for fixed data drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},"4183538c9c8ce7c9":{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes","displayName":"Randomize Schedule Task Times","description":"In Microsoft Defender Antivirus, randomize the start time of the scan to any interval from 0 to 23 hours. This can be useful in virtual machines or VDI deployments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes_1","displayName":"Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime.","description":"Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime.","helpText":null},{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes_0","displayName":"Scheduled tasks will not be randomized.","description":"Scheduled tasks will not be randomized.","helpText":null}]},"41de8980a0af70fc":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_6","displayName":"Saturday","description":null,"helpText":null}]},"4161f9f6cab4a794":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain","displayName":"Allow operation while in domain","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain_1","displayName":"True","description":null,"helpText":null}]},"41bf9175d76b71e6":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes","displayName":"Process Exclusions","description":"This policy setting allows you to disable real-time scanning for any file opened by any of the specified processes. This policy does not apply to scheduled scans. The process itself will not be excluded. To exclude the process, use the Path exclusion. Processes should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the path to the process image. Note that only executables can be excluded. For example, a process might be defined as: \"c:\\windows\\app.exe\". The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-processes"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_1","displayName":"Enabled","description":null,"helpText":null}]},"4116f86e44f98a15":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize","displayName":"Specify the maximum size of archive files to be scanned","description":"This policy setting allows you to configure the maximum size of archive files such as .ZIP or .CAB that will be scanned. The value represents file size in kilobytes (KB). The default value is 0 and represents no limit to archive size for scanning.\r\n\r\n If you enable this setting, archive files less than or equal to the size specified will be scanned.\r\n\r\n If you disable or do not configure this setting, archive files will be scanned according to the default value.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-archivemaxsize"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_1","displayName":"Enabled","description":null,"helpText":null}]},"41e935b9b81b0f5e":{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls","displayName":"Prohibit User Installs","description":"This policy setting allows you to configure user installs. To configure this policy setting, set it to enabled and use the drop-down list to select the behavior you want.\r\n\r\nIf you do not configure this policy setting, or if the policy setting is enabled and \"Allow User Installs\" is selected, the installer allows and makes use of products that are installed per user, and products that are installed per computer. If the installer finds a per-user install of an application, this hides a per-computer installation of that same product.\r\n\r\nIf you enable this policy setting and \"Hide User Installs\" is selected, the installer ignores per-user applications. This causes a per-computer installed application to be visible to users, even if those users have a per-user install of the product registered in their user profile.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disableuserinstalls"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_1","displayName":"Enabled","description":null,"helpText":null}]},"41b2f46799b89e2c":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016","displayName":"Microsoft Office 365 Outlook 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016_1","displayName":"Enabled","description":null,"helpText":null}]},"41ad5a95c507f4c0":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient","displayName":"Enable Windows NTP Client","description":"This policy setting specifies whether the Windows NTP Client is enabled.\r\n\r\nEnabling the Windows NTP Client allows your computer to synchronize its computer clock with other NTP servers. You might want to disable this service if you decide to use a third-party time provider.\r\n\r\nIf you enable this policy setting, you can set the local computer clock to synchronize time with NTP servers.\r\n\r\nIf you disable or do not configure this policy setting, the local computer clock does not synchronize time with NTP servers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-enable-ntpclient"],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient_1","displayName":"Enabled","description":null,"helpText":null}]},"410dbe3b0dba164c":{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout","displayName":"Account Logon Logoff Audit Account Lockout","description":"This policy setting allows you to audit events generated by a failed attempt to log on to an account that is locked out. If you configure this policy setting, an audit event is generated when an account cannot log on to a computer because the account is locked out. Success audits record successful attempts and Failure audits record unsuccessful attempts. Logon events are essential for understanding user activity and to detect potential attacks.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditaccountlockout"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"412e1c4846e29af6":{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen","displayName":"Allow Smart Screen","description":"This setting lets you decide whether to turn on Windows Defender SmartScreen.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsmartscreen"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen_0","displayName":"Block","description":"Turned off. Do not protect users from potential threats and prevent users from turning it on.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen_1","displayName":"Allow","description":"Turned on. Protect users from potential threats and prevent users from turning it off.","helpText":null}]},"41f6258e7b947065":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks","displayName":"Import bookmarks from default browser on first run","description":"Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.\r\n\r\nUsers can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks_1","displayName":"Enabled","description":null,"helpText":null}]},"41006760dc66a77f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode","displayName":"Print Rasterization Mode","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a non-PostScript printer on Microsoft® Windows®, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nWhen this policy is set to Full, Google Chrome will do full page rasterization if necessary.\r\n\r\nWhen this policy is set to Fast, Google Chrome will avoid rasterization if possible, reducing the amount of rasterization can help reduce print job sizes and increase printing speed.\r\n\r\nWhen this policy is not set, Google Chrome will be in Full mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},"41f4ecbe2197029f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger","displayName":"Password protection warning trigger","description":"Setting the policy lets you control the triggering of password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\r\n\r\nUse PasswordProtectionLoginURLs and PasswordProtectionChangePasswordURL to set which password to protect.\r\n\r\nIf this policy is set to:\r\n\r\n* PasswordProtectionWarningOff, no password protection warning will be shown.\r\n\r\n* PasswordProtectionWarningOnPasswordReuse, password protection warning will be shown when the user reuses their protected password on a non-allowed site.\r\n\r\n* PasswordProtectionWarningOnPhishingReuse, password protection warning will be shown when the user reuses their protected password on a phishing site.\r\n\r\nLeaving the policy unset has the password protection service only protect Google passwords, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_1","displayName":"Enabled","description":null,"helpText":null}]},"41d72f3d0dfabad4":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"411a258b39927a4c":{"id":"device_vendor_msft_policy_config_defender_realtimescandirection","displayName":"Real Time Scan Direction","description":"Controls which sets of files should be monitored. Note If AllowOnAccessProtection is not allowed, then this configuration can be used to monitor specific files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#realtimescandirection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_realtimescandirection_0","displayName":"Monitor all files (bi-directional).","description":"Monitor all files (bi-directional).","helpText":null},{"id":"device_vendor_msft_policy_config_defender_realtimescandirection_1","displayName":"Monitor incoming files.","description":"Monitor incoming files.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_realtimescandirection_2","displayName":"Monitor outgoing files.","description":"Monitor outgoing files.","helpText":null}]},"4198caf44c1abca2":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdxsectorsize_odfcvhdxsectorsize","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdxsectorsize_odfcvhdxsectorsize_512","displayName":"512 bytes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdxsectorsize_odfcvhdxsectorsize_4096","displayName":"4 KB","description":null,"helpText":null}]},"41a9903fd0f65c9e":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"41ce4f43ec6c9dce":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultJavaScriptSetting' (Default JavaScript setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4187c2e9bcba3380":{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled","displayName":"Web Select Enabled","description":"Web select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table.\r\n\r\nIf you enable or don't configure this policy, Web select is available through the right click context menu and the CTRL+SHIFT+X keyboard shortcut.\r\n\r\nIf you disable this policy, Web select won't be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"410fb815c7c4bff6":{"id":"device_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\r\n\r\nIf you disable this policy, Microsoft Edge does not send authentications requests to these services and users will need to manually sign-in.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"41c0d4bc25d270c3":{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled","displayName":"Extensions Performance Detector enabled","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\r\n\r\nIf you enable or don't configure this policy, users will receive Extensions Performance Detector notifications from Browser Essentials. When there is an active alert, users will be able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (ie. extensions that cannot be disabled).\r\n\r\nIf you disable this policy, users will not receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"41e0009cf503f0d2":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"41235695d273ed88":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_idletimeout","displayName":"Delay before running idle actions: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},"41427e3bef71432b":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\r\nIf you enable this policy or don't set it, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\r\nIf you disable this policy, warnings will not be shown for insecure forms, and autofill will work normally.\r\n\r\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"417602be0791c29a":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed","displayName":"Allow launching of local files in Internet Explorer mode","description":"This policy controls the availability of the --ie-mode-file-url command line argument which is used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nIf you set this policy to false, the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"4175e23c0b212583":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"41859d78e05023f7":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb","displayName":"Set the maximum size of a user's OneDrive that can download automatically","description":"This setting is used in conjunction with \"Silently sign in users to the OneDrive sync app with their Windows credentials.\" This setting lets you prompt users who have more than a specified amount of content in OneDrive to choose folders to sync during setup of the OneDrive sync app (OneDrive.exe).\r\n\r\nIf you enable this setting, users who have more content than the value you specify will be shown the Choose Folders dialog box by default during OneDrive Setup.\r\n\r\nIf you disable or do not configure this setting, when users set up the sync app, all files will be selected to sync.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb_1","displayName":"Enabled","description":null,"helpText":null}]},"41223788f2122831":{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlocklegacyauthn","displayName":" Disconnect remote session on lock for legacy authentication","description":"This policy setting allows you to configure the user experience when the Remote Desktop session is locked by the user or by a policy. You can specify whether the remote session will show the remote lock screen or disconnect when the remote session is locked. Disconnecting the remote session ensures that a remote session cannot be left on the lock screen and cannot reconnect automatically due to loss of network connectivity.\n\nThis policy applies only when using legacy authentication to authenticate to the remote PC. Legacy authentication is limited to username and password, or certificates like smartcards. Legacy authentication doesn't leverage the Microsoft identity platform, such as Microsoft Entra ID. Legacy authentication includes the NTLM, CredSSP, RDSTLS, TLS, and RDP basic authentication protocols.\n\nIf you enable this policy setting, Remote Desktop connections using legacy authentication will disconnect the remote session when the remote session is locked. Users can reconnect when they're ready and re-enter their credentials when prompted.\n\nIf you disable or do not configure this policy setting, Remote Desktop connections using legacy authentication will show the remote lock screen when the remote session is locked. Users can unlock the remote session using their username and password, or certificates.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-disconnectonlocklegacyauthn"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlocklegacyauthn_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlocklegacyauthn_1","displayName":"Enabled","description":null,"helpText":null}]},"41b93afb87204cf4":{"id":"device_vendor_msft_policy_config_update_updateserviceurlalternate","displayName":"Update Service Url Alternate","description":"Specifies an alternate intranet server to host updates from Microsoft Update. You can then use this update service to automatically update computers on your network. This setting lets you specify a server on your network to function as an internal update service. The Automatic Updates client will search this service for updates that apply to the computers on your network. To use this setting, you must set two server name values: the server from which the Automatic Updates client detects and downloads updates, and the server to which updated workstations upload statistics. You can set both values to be the same server. An optional server name value can be specified to configure Windows Update agent, and download updates from an alternate download server instead of WSUS Server. Value type is string and the default value is an empty string, . If the setting is not configured, and if Automatic Updates is not disabled by policy or user preference, the Automatic Updates client connects directly to the Windows Update site on the Internet. NoteIf the Configure Automatic Updates Group Policy is disabled, then this policy has no effect. If the Alternate Download Server Group Policy is not set, it will use the WSUS server by default to download updates. This policy is not supported on Windows RT. Setting this policy will not have any effect on Windows RT PCs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#updateserviceurlalternate"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"4161a88c65cdcd44":{"id":"device_vendor_msft_policy_config_userrights_accessfromnetwork","displayName":"Access From Network","description":"This user right determines which users and groups are allowed to connect to the computer over the network. Remote Desktop Services are not affected by this user right.Note: Remote Desktop Services was called Terminal Services in previous versions of Windows Server.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#accessfromnetwork"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"41ad1c2803146036":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werexlusion_1_werexlusionlist","displayName":"List of applications to be excluded (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"41f59b7e3cde5b99":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werqueue_1_werqueuebehavior","displayName":"Queuing behavior: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werqueue_1_werqueuebehavior_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werqueue_1_werqueuebehavior_1","displayName":"Always queue","description":null,"helpText":null}]},"417bd0c35f1b7802":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_appletalkrouting","displayName":"AppleTalk Routing (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-appletalkrouting"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_appletalkrouting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_appletalkrouting_1","displayName":"Enabled","description":null,"helpText":null}]},"41c5dc1e4c693d07":{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_1","displayName":"For tablet pen input, don’t show the Input Panel icon (User)","description":"Prevents the Tablet PC Input Panel icon from appearing next to any text entry area in applications where this behavior is available. This policy applies only when using a tablet pen as an input device.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will never appear next to text entry areas when using a tablet pen as an input device. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will appear next to any text entry area in applications where this behavior is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-iptiptarget-1"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_1_1","displayName":"Enabled","description":null,"helpText":null}]},"4126f40f95b7baf1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled","displayName":"Enable Google Cloud Print proxy (User)","description":"Setting the policy to Enabled or leaving it unset lets Google Chrome act as a proxy between Google Cloud Print and legacy printers connected to the machine. Using their Google Account, users may turn on the cloud print proxy by authentication.\r\n\r\nSetting the policy to Disabled means users can't turn on the proxy, and the machine can't share its printers with Google Cloud Print.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"412541163443807d":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel","displayName":"Set a custom enterprise label for a managed profile (User)","description":"This policy controls a custom label used to identify managed profiles. For managed profiles, this label will be shown next to the avatar in the toolbar. The custom label will not be translated.\r\n\r\nWhen this policy is applied, any strings that surpass 16 characters will be truncated with a “...” Please refrain from using extended names.\r\n\r\nThis policy can only be set as a user policy.\r\n\r\nNote that this policy has no effect if the EnterpriseProfileBadgeToolbarSettings policy is set to hide_expanded_enterprise_toolbar_badge (value 1).\r\n\r\nExample value: Chromium","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_1","displayName":"Enabled","description":null,"helpText":null}]},"4172657f53d2d8ea":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (User)","description":"A list of certificates that are not trusted or distrusted in Google Chrome\r\nbut can be used as hints for path-building. Certificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"41706af341209d75":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowsmartscreenie"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"414067ab75adfa5f":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"41b4afa20b4a2d62":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype","displayName":"New tab page experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},"410d6e5863aba34d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest","displayName":"Default subject for a review request (User)","description":"Defines the default subject text for a review request.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_1","displayName":"Enabled","description":null,"helpText":null}]},"4116196340c5d2e9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_l_withasimplewebdiscussionslink362","displayName":"With a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},"41ff8dc6e2983634":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003","displayName":"Encryption type for password protected Office 97-2003 files (User)","description":"This policy setting enables you to specify an encryption type for password-protected Office 97-2003 files.\r\n \r\nIf you enable this policy setting, you can specify the type of encryption that Office applications will use to encrypt password-protected files in the older Office 97-2003 file formats. The chosen encryption type must have a corresponding cryptographic service provider (CSP) installed on the computer that encrypts the file. See the HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\ registry key for a list of CSPs installed on the local computer. Specify the encryption type to use by entering it in the provided text box in the following form:\r\n\r\n,,.\r\nFor example, Microsoft Enhanced Cryptographic Provider v1.0,RC4,128\r\n\r\nIf you do not configure this policy setting, Excel, PowerPoint, and Word use Office 97/2000 Compatible encryption, a proprietary encryption method, to encrypt password-protected Office 97-2003 files.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_1","displayName":"Enabled","description":null,"helpText":null}]},"4131d2b07d2d59ab":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_pathcolon298","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"4139205d0758a0e4":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig","displayName":"Require trusted publisher signatures for macros that are always loaded (User)","description":"This policy setting controls signature requirements for macros that are automatically loaded when Office applications start.\r\n\r\nMacros that are always loaded include VBA add-ins and templates that load automatically: Excel add-ins (xla/xlam), PowerPoint add-ins (ppa/ppam), Access add-ins (accda/mda), and Word templates (dot/dotm).\r\n\r\nIf you enable this policy setting:\r\n- Unsigned macros that are always loaded are silently disabled and don't load.\r\n- Signed but untrusted macros that are always loaded display a red Message Bar with no option for users to enable them for the current session.\r\n- Macros signed by a trusted publisher are allowed to always load.\r\n\r\nIf you disable or don't configure this policy setting, macros that are always on can load without requiring trusted publisher signatures.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig_1","displayName":"Enabled","description":null,"helpText":null}]},"4168c62c791c85e4":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},"41ba9ba85a3f5783":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates","displayName":"Store deleted items in owner's mailbox instead of delegate's mailbox (User)","description":"This policy setting allows you to store deleted items in the owner's mailbox instead of the delegate's mailbox.\r\n\r\nIf you enable this policy setting, deleted items are stored in the owner's Deleted Items folder. For this setting to work correctly, the owner must also give the delegate permission to write to the owner's Deleted Items folder.\r\n\r\nIf you disable or do not configure this policy setting, items deleted by a delegate are stored in the delegate's Deleted Items Folder instead of the owner's Deleted Items folder.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates_1","displayName":"Enabled","description":null,"helpText":null}]},"4158a14a44fc69e5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking","displayName":"Automatic name checking (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking_1","displayName":"True","description":null,"helpText":null}]},"4172b65eb6f8fe83":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom","displayName":"Set Outlook object model custom actions execution prompt (User) (Deprecated)","description":"This policy setting controls whether Outlook prompts users before executing a custom action. Custom actions add functionality to Outlook that can be triggered as part of a rule. Among other possible features, custom actions can be created that reply to messages in ways that circumvent the Outlook model's programmatic send protections. \r\n\r\nIf you enable this policy setting, you can choose from four options to control how Outlook functions when a custom action is executed that uses the Outlook object model: \r\n\r\n* Prompt User \r\n* Automatically Approve \r\n* Automatically Deny \r\n* Prompt user based on computer security. This option enforces the default configuration in Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook or another program initiates a custom action using the Outlook object model, users are prompted to allow or reject the action. If this configuration is changed, malicious code can use the Outlook object model to compromise sensitive information or otherwise cause data and computing resources to be at risk. This is the equivalent of choosing Enabled -- Prompt user based on computer security.","helpText":"","infoUrls":[],"categoryId":"e11f4bd4-9041-49c9-9b8c-163827d606ce","categoryName":"Custom Form Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_1","displayName":"Enabled","description":null,"helpText":null}]},"417408db48e961ce":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"41b701d02c8475d2":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"41494bce454a918c":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage","displayName":"Project Guide Functionality and Layout page (User)","description":"Choose whether the side pane displays the default Project Guide or a custom Project Guide your organization has developed.\r\n\r\nIf you enable this setting, the Project Guide you specified will be displayed when the Project Guide is opened.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_1","displayName":"Enabled","description":null,"helpText":null}]},"4151df1a2d74ec20":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23","displayName":"Duration is entered in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_3","displayName":"Minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_5","displayName":"Hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_7","displayName":"Days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_9","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_11","displayName":"Months","description":null,"helpText":null}]},"41fb2bcb837140a2":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Publisher\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Publisher\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},"41e4613ff5bcaae2":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup","displayName":"Start-up (User)","description":"Displays the additional location for macros and add-ons opened when you start Visio.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_1","displayName":"Enabled","description":null,"helpText":null}]},"4184855c78ca5335":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior","displayName":"Smart style behavior (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"412c2567027ab447":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes","displayName":"Interface Types","description":"String value. Multiple interface types can be included in the string by separating each value with a \",\". Acceptable values are \"RemoteAccess\", \"Wireless\", \"Lan\", and \"All\".\n If more than one interface type is specified, the strings must be separated by a comma.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_remoteaccess","displayName":"Remote Access","description":"RemoteAccess","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_wireless","displayName":"Wireless","description":"Wireless","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_lan","displayName":"Lan","description":"Lan","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_mobilebroadband","displayName":"[Not Supported] Mobile Broadband","description":"MobileBroadband","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_mbb","displayName":"Mobile Broadband","description":"MobileBroadband","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_all","displayName":"All","description":"All","helpText":null}]},"413c0ab1f72c8c3f":{"id":"vendor_msft_firewall_mdmstore_publicprofile_logfilepath","displayName":"Log File Path","description":"This value is a string that represents a file path to the log where the firewall logs dropped packets and successful connections. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},"41f750704ff3ca00":{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_screenoffdurationtotriggernetworkdiscoveryinminutes","displayName":"Screen Off Duration To Trigger Network Discovery In Minutes (Windows Insiders only)","description":"When the device experiences screen off and back on, this value configures the minimum duration (in minutes) of the screen off period that will trigger network discovery.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null}} \ No newline at end of file +{"4109bee226dd1c9d":{"id":"com.apple.cellularprivatenetwork.managed_versionnumber","displayName":"Version Number","description":"The version number of this dataset that the system uses to track updates.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"4159c5cb4b6372bd":{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup","displayName":"Enable Registration During Setup","description":"If `true`, the system enables the PlatformSSO registration process during Setup Assistant on devices running macOS 26 and later. Set this key to `true` when configuring PlatformSSO before enrollment using the `com.apple.psso.required` error response.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enableregistrationduringsetup_true","displayName":"Enabled","description":null,"helpText":null}]},"410eed4e015e7e8c":{"id":"com.apple.managedclient.preferences_tags_item_value","displayName":"Value of tag","description":"Only one value per tag type can be set. Type of tags are unique, and should not be repeated in the same configuration profile.","helpText":null,"infoUrls":[],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":null},"411f2bad1d791a71":{"id":"com.apple.managedclient.preferences_tls13earlydataenabled","displayName":"Control whether TLS 1.3 Early Data is enabled in Microsoft Edge","description":"This policy controls whether TLS 1.3 Early Data is enabled in Microsoft Edge.\n\nTLS 1.3 Early Data is an extension that allows an HTTP request to be sent in parallel with the TLS handshake. When enabled and supported by the server, this can improve page load performance.\n\nEnabled – Microsoft Edge enables TLS 1.3 Early Data.\n\nDisabled – Microsoft Edge disables TLS 1.3 Early Data.\n\nNot configured – Microsoft Edge follows the default rollout process for TLS 1.3 Early Data.\n\nNOTE: When this feature is enabled, whether TLS 1.3 Early Data is used depends on server support. Most modern TLS servers and middleware can handle or reject Early Data without interrupting the connection. However, improperly implemented TLS stacks may cause connection failures. If such issues occur, contact the device or software vendor for a resolution.\n\nThis policy is temporary and intended to help test for compatibility issues. It may be removed in a future release once the feature is fully rolled out.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tls13earlydataenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_tls13earlydataenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_tls13earlydataenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"41d52a38fae27c9c":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"415f486b577b213e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled","displayName":"Allow queries to a Browser Network Time service","description":"Prevents Microsoft Edge from occasionally sending queries to a browser network time service to retrieve an accurate timestamp.\n\nIf you disable this policy, Microsoft Edge stops sending queries to a browser network time service.\n\nIf you enable this policy or don't configure it, Microsoft Edge occasionally sends queries to a browser network time service.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.browsernetworktimequeriesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"41308eafb348d376":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages","description":"An \"in-page\" navigation is started from a link, a script, or a form on the current page. It can also be a server-side redirect of a previous \"in-page\" navigation attempt. Conversely, a user can start a navigation that isn't \"in-page\" and that's independent of the current page in several ways by using the browser controls, for example, using the address bar, the back button, or a favorite link.\n\nThis setting lets you specify whether navigations from pages loaded in Internet Explorer mode to unconfigured sites (that aren't configured in the Enterprise Mode Site List) switch back to Microsoft Edge or remain in Internet Explorer mode.\n\nThis setting works in conjunction with \"InternetExplorerIntegrationLevel\" policy that's set to 'IEMode', and with \"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry.\n\nIf you disable or don't configure this policy, only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.\n\nIf you set this policy to 'Default', only sites configured to open in Internet Explorer mode open in that mode. Any site not configured to open in Internet Explorer mode is redirected back to Microsoft Edge.\n\nIf you set this policy to 'AutomaticNavigationsOnly', you get the default experience except that all automatic navigations (such as 302 redirects) to unconfigured sites are kept in Internet Explorer mode.\n\nIf you set this policy to 'AllInPageNavigations', all navigations from pages loaded in IE mode to unconfigured sites are kept in Internet Explorer mode (Least Recommended).\n\nIf the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy allows users to reload sites in Internet Explorer mode, then all in-page navigations from unconfigured sites that users have chosen to reload in Internet Explorer mode are kept in Internet Explorer mode, regardless of how this policy is configured.\n\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2105106.\n\nPolicy options mapping:\n\n* Default (0) = Default\n\n* AutomaticNavigationsOnly (1) = Keep only automatic navigations in Internet Explorer mode\n\n* AllInPageNavigations (2) = Keep all in-page navigations in Internet Explorer mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_default","displayName":"Default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_automaticnavigationsonly","displayName":"Keep only automatic navigations in Internet Explorer mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsiteredirect_allinpagenavigations","displayName":"Keep all in-page navigations in Internet Explorer mode","description":null,"helpText":null}]},"41082ef0df8fafcb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode","displayName":"Configure proxy server settings (Deprecated)","description":"This policy is deprecated and doesn't work in Microsoft Edge version 91. Use \"ProxySettings\" instead.\n\nIf you set this policy to Enabled, you can specify the proxy server Microsoft Edge uses and prevents users from changing proxy settings. Microsoft Edge ignores all proxy-related options specified from the command line. The policy is only applied if the \"ProxySettings\" policy isn't specified.\n\nOther options are ignored if you choose one of the following options:\n * direct = Never use a proxy server and always connect directly\n * system = Use system proxy settings\n * auto_detect = Auto detect the proxy server\n\nIf you choose to use:\n * fixed_servers = Fixed proxy servers. You can specify further options with \"ProxyServer\" and \"ProxyBypassList\".\n * pac_script = A .pac proxy script. Use \"ProxyPacUrl\" to set the URL to a proxy .pac file.\n\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nPolicy options mapping:\n\n* ProxyDisabled (direct) = Never use a proxy\n\n* ProxyAutoDetect (auto_detect) = Auto detect proxy settings\n\n* ProxyPacScript (pac_script) = Use a .pac proxy script\n\n* ProxyFixedServers (fixed_servers) = Use fixed proxy servers\n\n* ProxyUseSystem (system) = Use system proxy settings\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxydisabled","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyautodetect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxypacscript","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyfixedservers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxymode_proxyusesystem","displayName":"Use system proxy settings","description":null,"helpText":null}]},"41dd2952f305b503":{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name","displayName":"Save BitLocker recovery information to AD DS for fixed data drives","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvactivedirectorybackup_name_1","displayName":"True","description":null,"helpText":null}]},"4183538c9c8ce7c9":{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes","displayName":"Randomize Schedule Task Times","description":"In Microsoft Defender Antivirus, randomize the start time of the scan to any interval from 0 to 23 hours. This can be useful in virtual machines or VDI deployments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes_1","displayName":"Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime.","description":"Widen or narrow the randomization period for scheduled scans. Specify a randomization window of between 1 and 23 hours by using the setting SchedulerRandomizationTime.","helpText":null},{"id":"device_vendor_msft_defender_configuration_randomizescheduletasktimes_0","displayName":"Scheduled tasks will not be randomized.","description":"Scheduled tasks will not be randomized.","helpText":null}]},"41de8980a0af70fc":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysto_6","displayName":"Saturday","description":null,"helpText":null}]},"4161f9f6cab4a794":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain","displayName":"Allow operation while in domain","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablelltdio_lltd_enablelltdio_allowondomain_1","displayName":"True","description":null,"helpText":null}]},"41bf9175d76b71e6":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes","displayName":"Process Exclusions","description":"This policy setting allows you to disable real-time scanning for any file opened by any of the specified processes. This policy does not apply to scheduled scans. The process itself will not be excluded. To exclude the process, use the Path exclusion. Processes should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of the path to the process image. Note that only executables can be excluded. For example, a process might be defined as: \"c:\\windows\\app.exe\". The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-processes"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_processes_1","displayName":"Enabled","description":null,"helpText":null}]},"4116f86e44f98a15":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize","displayName":"Specify the maximum size of archive files to be scanned","description":"This policy setting allows you to configure the maximum size of archive files such as .ZIP or .CAB that will be scanned. The value represents file size in kilobytes (KB). The default value is 0 and represents no limit to archive size for scanning.\r\n\r\n If you enable this setting, archive files less than or equal to the size specified will be scanned.\r\n\r\n If you disable or do not configure this setting, archive files will be scanned according to the default value.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-archivemaxsize"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_archivemaxsize_1","displayName":"Enabled","description":null,"helpText":null}]},"41e935b9b81b0f5e":{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls","displayName":"Prohibit User Installs","description":"This policy setting allows you to configure user installs. To configure this policy setting, set it to enabled and use the drop-down list to select the behavior you want.\r\n\r\nIf you do not configure this policy setting, or if the policy setting is enabled and \"Allow User Installs\" is selected, the installer allows and makes use of products that are installed per user, and products that are installed per computer. If the installer finds a per-user install of an application, this hides a per-computer installation of that same product.\r\n\r\nIf you enable this policy setting and \"Hide User Installs\" is selected, the installer ignores per-user applications. This causes a per-computer installed application to be visible to users, even if those users have a per-user install of the product registered in their user profile.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disableuserinstalls"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disableuserinstalls_1","displayName":"Enabled","description":null,"helpText":null}]},"41b2f46799b89e2c":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016","displayName":"Microsoft Office 365 Outlook 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2016_1","displayName":"Enabled","description":null,"helpText":null}]},"41ad5a95c507f4c0":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient","displayName":"Enable Windows NTP Client","description":"This policy setting specifies whether the Windows NTP Client is enabled.\r\n\r\nEnabling the Windows NTP Client allows your computer to synchronize its computer clock with other NTP servers. You might want to disable this service if you decide to use a third-party time provider.\r\n\r\nIf you enable this policy setting, you can set the local computer clock to synchronize time with NTP servers.\r\n\r\nIf you disable or do not configure this policy setting, the local computer clock does not synchronize time with NTP servers.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-w32time#admx-w32time-w32time-policy-enable-ntpclient"],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":[{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_enable_ntpclient_1","displayName":"Enabled","description":null,"helpText":null}]},"410dbe3b0dba164c":{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout","displayName":"Account Logon Logoff Audit Account Lockout","description":"This policy setting allows you to audit events generated by a failed attempt to log on to an account that is locked out. If you configure this policy setting, an audit event is generated when an account cannot log on to a computer because the account is locked out. Success audits record successful attempts and Failure audits record unsuccessful attempts. Logon events are essential for understanding user activity and to detect potential attacks.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditaccountlockout"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditaccountlockout_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"412e1c4846e29af6":{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen","displayName":"Allow Smart Screen","description":"This setting lets you decide whether to turn on Windows Defender SmartScreen.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsmartscreen"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen_0","displayName":"Block","description":"Turned off. Do not protect users from potential threats and prevent users from turning it on.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsmartscreen_1","displayName":"Allow","description":"Turned on. Protect users from potential threats and prevent users from turning it off.","helpText":null}]},"41f6258e7b947065":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks","displayName":"Import bookmarks from default browser on first run","description":"Setting the policy to Enabled imports bookmarks from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no bookmarks are imported on first run.\r\n\r\nUsers can trigger an import dialog and the bookmarks checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importbookmarks_1","displayName":"Enabled","description":null,"helpText":null}]},"41006760dc66a77f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode","displayName":"Print Rasterization Mode","description":"Controls how Google Chrome prints on Microsoft® Windows®.\r\n\r\nWhen printing to a non-PostScript printer on Microsoft® Windows®, sometimes print jobs need to be rasterized to print correctly.\r\n\r\nWhen this policy is set to Full, Google Chrome will do full page rasterization if necessary.\r\n\r\nWhen this policy is set to Fast, Google Chrome will avoid rasterization if possible, reducing the amount of rasterization can help reduce print job sizes and increase printing speed.\r\n\r\nWhen this policy is not set, Google Chrome will be in Full mode.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printrasterizationmode_1","displayName":"Enabled","description":null,"helpText":null}]},"41f4ecbe2197029f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger","displayName":"Password protection warning trigger","description":"Setting the policy lets you control the triggering of password protection warning. Password protection alerts users when they reuse their protected password on potentially suspicious sites.\r\n\r\nUse PasswordProtectionLoginURLs and PasswordProtectionChangePasswordURL to set which password to protect.\r\n\r\nIf this policy is set to:\r\n\r\n* PasswordProtectionWarningOff, no password protection warning will be shown.\r\n\r\n* PasswordProtectionWarningOnPasswordReuse, password protection warning will be shown when the user reuses their protected password on a non-allowed site.\r\n\r\n* PasswordProtectionWarningOnPhishingReuse, password protection warning will be shown when the user reuses their protected password on a phishing site.\r\n\r\nLeaving the policy unset has the password protection service only protect Google passwords, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_passwordprotectionwarningtrigger_1","displayName":"Enabled","description":null,"helpText":null}]},"41d72f3d0dfabad4":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"411a258b39927a4c":{"id":"device_vendor_msft_policy_config_defender_realtimescandirection","displayName":"Real Time Scan Direction","description":"Controls which sets of files should be monitored. Note If AllowOnAccessProtection is not allowed, then this configuration can be used to monitor specific files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#realtimescandirection"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_realtimescandirection_0","displayName":"Monitor all files (bi-directional).","description":"Monitor all files (bi-directional).","helpText":null},{"id":"device_vendor_msft_policy_config_defender_realtimescandirection_1","displayName":"Monitor incoming files.","description":"Monitor incoming files.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_realtimescandirection_2","displayName":"Monitor outgoing files.","description":"Monitor outgoing files.","helpText":null}]},"4198caf44c1abca2":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdxsectorsize_odfcvhdxsectorsize","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdxsectorsize_odfcvhdxsectorsize_512","displayName":"512 bytes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdxsectorsize_odfcvhdxsectorsize_4096","displayName":"4 KB","description":null,"helpText":null}]},"41a9903fd0f65c9e":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"41ce4f43ec6c9dce":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultJavaScriptSetting' (Default JavaScript setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_javascriptblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4187c2e9bcba3380":{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled","displayName":"Web Select Enabled","description":"Web select lets users select and copy web content while preserving its formatting when pasted in most cases. It also allows more targeted selection on some web elements, such as copying a single column in a table.\r\n\r\nIf you enable or don't configure this policy, Web select is available through the right click context menu and the CTRL+SHIFT+X keyboard shortcut.\r\n\r\nIf you disable this policy, Web select won't be available.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_webselectenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"410fb815c7c4bff6":{"id":"device_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\r\n\r\nIf you disable this policy, Microsoft Edge does not send authentications requests to these services and users will need to manually sign-in.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev126~policy~microsoft_edge~identity_proactiveauthworkflowenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"41c0d4bc25d270c3":{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled","displayName":"Extensions Performance Detector enabled","description":"This policy controls if users can access the Extensions Performance Detector Recommended Action feature in Browser Essentials. This feature alerts extension users if their extensions are causing performance regressions in the browser and allows them to take action to resolve the issue.\r\n\r\nIf you enable or don't configure this policy, users will receive Extensions Performance Detector notifications from Browser Essentials. When there is an active alert, users will be able to view the impact of extensions on their browser's performance and make an informed decision to disable impacting extensions. The detector will exclude browser-managed extensions, such as Google Docs offline, component extensions, and organization-managed extensions (ie. extensions that cannot be disabled).\r\n\r\nIf you disable this policy, users will not receive notifications or be able to view the Extensions Performance Detector Recommended Action.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev130~policy~microsoft_edge~performance_extensionsperformancedetectorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"41e0009cf503f0d2":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"41235695d273ed88":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_idletimeout","displayName":"Delay before running idle actions: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},"41427e3bef71432b":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled","displayName":"Enable warnings for insecure forms (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy controls the handling of insecure forms (forms submitted over HTTP) embedded in secure (HTTPS) sites in the browser.\r\nIf you enable this policy or don't set it, a full page warning will be shown when an insecure form is submitted. Additionally, a warning bubble will be shown next to the form fields when they are focused, and autofill will be disabled for those forms.\r\nIf you disable this policy, warnings will not be shown for insecure forms, and autofill will work normally.\r\n\r\nThis policy may be removed as soon as Edge 132. The feature is enabled by default since Edge 131.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_insecureformswarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"417602be0791c29a":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed","displayName":"Allow launching of local files in Internet Explorer mode","description":"This policy controls the availability of the --ie-mode-file-url command line argument which is used to launch Microsoft Edge with a local file specified on the command line into Internet Explorer mode.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, or don't configure it, the user is allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nIf you set this policy to false, the user isn't allowed to use the --ie-mode-file-url command line argument for launching local files in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"4175e23c0b212583":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"41859d78e05023f7":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb","displayName":"Set the maximum size of a user's OneDrive that can download automatically","description":"This setting is used in conjunction with \"Silently sign in users to the OneDrive sync app with their Windows credentials.\" This setting lets you prompt users who have more than a specified amount of content in OneDrive to choose folders to sync during setup of the OneDrive sync app (OneDrive.exe).\r\n\r\nIf you enable this setting, users who have more content than the value you specify will be shown the Choose Folders dialog box by default during OneDrive Setup.\r\n\r\nIf you disable or do not configure this setting, when users set up the sync app, all files will be selected to sync.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_diskspacecheckthresholdmb_1","displayName":"Enabled","description":null,"helpText":null}]},"41223788f2122831":{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlocklegacyauthn","displayName":" Disconnect remote session on lock for legacy authentication","description":"This policy setting allows you to configure the user experience when the Remote Desktop session is locked by the user or by a policy. You can specify whether the remote session will show the remote lock screen or disconnect when the remote session is locked. Disconnecting the remote session ensures that a remote session cannot be left on the lock screen and cannot reconnect automatically due to loss of network connectivity.\n\nThis policy applies only when using legacy authentication to authenticate to the remote PC. Legacy authentication is limited to username and password, or certificates like smartcards. Legacy authentication doesn't leverage the Microsoft identity platform, such as Microsoft Entra ID. Legacy authentication includes the NTLM, CredSSP, RDSTLS, TLS, and RDP basic authentication protocols.\n\nIf you enable this policy setting, Remote Desktop connections using legacy authentication will disconnect the remote session when the remote session is locked. Users can reconnect when they're ready and re-enter their credentials when prompted.\n\nIf you disable or do not configure this policy setting, Remote Desktop connections using legacy authentication will show the remote lock screen when the remote session is locked. Users can unlock the remote session using their username and password, or certificates.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-disconnectonlocklegacyauthn"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlocklegacyauthn_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlocklegacyauthn_1","displayName":"Enabled","description":null,"helpText":null}]},"41b93afb87204cf4":{"id":"device_vendor_msft_policy_config_update_updateserviceurlalternate","displayName":"Update Service Url Alternate","description":"Specifies an alternate intranet server to host updates from Microsoft Update. You can then use this update service to automatically update computers on your network. This setting lets you specify a server on your network to function as an internal update service. The Automatic Updates client will search this service for updates that apply to the computers on your network. To use this setting, you must set two server name values: the server from which the Automatic Updates client detects and downloads updates, and the server to which updated workstations upload statistics. You can set both values to be the same server. An optional server name value can be specified to configure Windows Update agent, and download updates from an alternate download server instead of WSUS Server. Value type is string and the default value is an empty string, . If the setting is not configured, and if Automatic Updates is not disabled by policy or user preference, the Automatic Updates client connects directly to the Windows Update site on the Internet. NoteIf the Configure Automatic Updates Group Policy is disabled, then this policy has no effect. If the Alternate Download Server Group Policy is not set, it will use the WSUS server by default to download updates. This policy is not supported on Windows RT. Setting this policy will not have any effect on Windows RT PCs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#updateserviceurlalternate"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"4161a88c65cdcd44":{"id":"device_vendor_msft_policy_config_userrights_accessfromnetwork","displayName":"Access From Network","description":"This user right determines which users and groups are allowed to connect to the computer over the network. Remote Desktop Services are not affected by this user right.Note: Remote Desktop Services was called Terminal Services in previous versions of Windows Server.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#accessfromnetwork"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"41bf55ad16ffee11":{"id":"plugin_plugin","displayName":"com.apple.configuration.webcontent-filter.plugin","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"41ad1c2803146036":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werexlusion_1_werexlusionlist","displayName":"List of applications to be excluded (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"41f59b7e3cde5b99":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werqueue_1_werqueuebehavior","displayName":"Queuing behavior: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werqueue_1_werqueuebehavior_0","displayName":"Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werqueue_1_werqueuebehavior_1","displayName":"Always queue","description":null,"helpText":null}]},"417bd0c35f1b7802":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_appletalkrouting","displayName":"AppleTalk Routing (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-appletalkrouting"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_appletalkrouting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_appletalkrouting_1","displayName":"Enabled","description":null,"helpText":null}]},"41c5dc1e4c693d07":{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_1","displayName":"For tablet pen input, don’t show the Input Panel icon (User)","description":"Prevents the Tablet PC Input Panel icon from appearing next to any text entry area in applications where this behavior is available. This policy applies only when using a tablet pen as an input device.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will never appear next to text entry areas when using a tablet pen as an input device. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will appear next to any text entry area in applications where this behavior is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-iptiptarget-1"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_1_1","displayName":"Enabled","description":null,"helpText":null}]},"4126f40f95b7baf1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled","displayName":"Enable Google Cloud Print proxy (User)","description":"Setting the policy to Enabled or leaving it unset lets Google Chrome act as a proxy between Google Cloud Print and legacy printers connected to the machine. Using their Google Account, users may turn on the cloud print proxy by authentication.\r\n\r\nSetting the policy to Disabled means users can't turn on the proxy, and the machine can't share its printers with Google Cloud Print.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_cloudprintproxyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"412541163443807d":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel","displayName":"Set a custom enterprise label for a managed profile (User)","description":"This policy controls a custom label used to identify managed profiles. For managed profiles, this label will be shown next to the avatar in the toolbar. The custom label will not be translated.\r\n\r\nWhen this policy is applied, any strings that surpass 16 characters will be truncated with a “...” Please refrain from using extended names.\r\n\r\nThis policy can only be set as a user policy.\r\n\r\nNote that this policy has no effect if the EnterpriseProfileBadgeToolbarSettings policy is set to hide_expanded_enterprise_toolbar_badge (value 1).\r\n\r\nExample value: Chromium","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisecustomlabel_1","displayName":"Enabled","description":null,"helpText":null}]},"4172657f53d2d8ea":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (User)","description":"A list of certificates that are not trusted or distrusted in Google Chrome\r\nbut can be used as hints for path-building. Certificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"41706af341209d75":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowsmartscreenie"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"414067ab75adfa5f":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallforcelist_extensioninstallforcelistdesc","displayName":"Extension/App IDs and update URLs to be silently installed (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"41b4afa20b4a2d62":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype","displayName":"New tab page experience (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_0","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagesetfeedtype_newtabpagesetfeedtype_1","displayName":"Office 365 feed experience","description":null,"helpText":null}]},"410d6e5863aba34d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest","displayName":"Default subject for a review request (User)","description":"Defines the default subject text for a review request.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_defaultsubjectforareviewrequest_1","displayName":"Enabled","description":null,"helpText":null}]},"4116196340c5d2e9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_l_withasimplewebdiscussionslink362","displayName":"With a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},"41ff8dc6e2983634":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003","displayName":"Encryption type for password protected Office 97-2003 files (User)","description":"This policy setting enables you to specify an encryption type for password-protected Office 97-2003 files.\r\n \r\nIf you enable this policy setting, you can specify the type of encryption that Office applications will use to encrypt password-protected files in the older Office 97-2003 file formats. The chosen encryption type must have a corresponding cryptographic service provider (CSP) installed on the computer that encrypts the file. See the HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Cryptography\\Defaults\\Provider\\ registry key for a list of CSPs installed on the local computer. Specify the encryption type to use by entering it in the provided text box in the following form:\r\n\r\n,,.\r\nFor example, Microsoft Enhanced Cryptographic Provider v1.0,RC4,128\r\n\r\nIf you do not configure this policy setting, Excel, PowerPoint, and Word use Office 97/2000 Compatible encryption, a proprietary encryption method, to encrypt password-protected Office 97-2003 files.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforpasswordprotectedoffice972003_1","displayName":"Enabled","description":null,"helpText":null}]},"4131d2b07d2d59ab":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_pathcolon298","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"4139205d0758a0e4":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig","displayName":"Require trusted publisher signatures for macros that are always loaded (User)","description":"This policy setting controls signature requirements for macros that are automatically loaded when Office applications start.\r\n\r\nMacros that are always loaded include VBA add-ins and templates that load automatically: Excel add-ins (xla/xlam), PowerPoint add-ins (ppa/ppam), Access add-ins (accda/mda), and Word templates (dot/dotm).\r\n\r\nIf you enable this policy setting:\r\n- Unsigned macros that are always loaded are silently disabled and don't load.\r\n- Signed but untrusted macros that are always loaded display a red Message Bar with no option for users to enable them for the current session.\r\n- Macros signed by a trusted publisher are allowed to always load.\r\n\r\nIf you disable or don't configure this policy setting, macros that are always on can load without requiring trusted publisher signatures.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_requirealwaysonmacrosig_1","displayName":"Enabled","description":null,"helpText":null}]},"4168c62c791c85e4":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},"41ba9ba85a3f5783":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates","displayName":"Store deleted items in owner's mailbox instead of delegate's mailbox (User)","description":"This policy setting allows you to store deleted items in the owner's mailbox instead of the delegate's mailbox.\r\n\r\nIf you enable this policy setting, deleted items are stored in the owner's Deleted Items folder. For this setting to work correctly, the owner must also give the delegate permission to write to the owner's Deleted Items folder.\r\n\r\nIf you disable or do not configure this policy setting, items deleted by a delegate are stored in the delegate's Deleted Items Folder instead of the owner's Deleted Items folder.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_locationofitemsdeletedbydelegates_1","displayName":"Enabled","description":null,"helpText":null}]},"4158a14a44fc69e5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking","displayName":"Automatic name checking (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whensendingamessage_l_automaticnamechecking_1","displayName":"True","description":null,"helpText":null}]},"4172b65eb6f8fe83":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom","displayName":"Set Outlook object model custom actions execution prompt (User) (Deprecated)","description":"This policy setting controls whether Outlook prompts users before executing a custom action. Custom actions add functionality to Outlook that can be triggered as part of a rule. Among other possible features, custom actions can be created that reply to messages in ways that circumvent the Outlook model's programmatic send protections. \r\n\r\nIf you enable this policy setting, you can choose from four options to control how Outlook functions when a custom action is executed that uses the Outlook object model: \r\n\r\n* Prompt User \r\n* Automatically Approve \r\n* Automatically Deny \r\n* Prompt user based on computer security. This option enforces the default configuration in Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook or another program initiates a custom action using the Outlook object model, users are prompted to allow or reject the action. If this configuration is changed, malicious code can use the Outlook object model to compromise sensitive information or otherwise cause data and computing resources to be at risk. This is the equivalent of choosing Enabled -- Prompt user based on computer security.","helpText":"","infoUrls":[],"categoryId":"e11f4bd4-9041-49c9-9b8c-163827d606ce","categoryName":"Custom Form Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_1","displayName":"Enabled","description":null,"helpText":null}]},"417408db48e961ce":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"41b701d02c8475d2":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"41494bce454a918c":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage","displayName":"Project Guide Functionality and Layout page (User)","description":"Choose whether the side pane displays the default Project Guide or a custom Project Guide your organization has developed.\r\n\r\nIf you enable this setting, the Project Guide you specified will be displayed when the Project Guide is opened.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"81bc8383-43a5-4c6a-9d51-951e86028934","categoryName":"Project Guide settings for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjpgsettingsforproject1_l_pjusedefaultstartpage_1","displayName":"Enabled","description":null,"helpText":null}]},"4151df1a2d74ec20":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23","displayName":"Duration is entered in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_3","displayName":"Minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_5","displayName":"Hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_7","displayName":"Days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_9","displayName":"Weeks","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjdurationunits_l_pjdurationunits23_11","displayName":"Months","description":null,"helpText":null}]},"41fb2bcb837140a2":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\Publisher\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\Publisher\\Addins.\r\n\r\nYou can also obtain the ProgID of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},"41e4613ff5bcaae2":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup","displayName":"Start-up (User)","description":"Displays the additional location for macros and add-ons opened when you start Visio.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_startup_1","displayName":"Enabled","description":null,"helpText":null}]},"4184855c78ca5335":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior","displayName":"Smart style behavior (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_smartstylebehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"412c2567027ab447":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes","displayName":"Interface Types","description":"String value. Multiple interface types can be included in the string by separating each value with a \",\". Acceptable values are \"RemoteAccess\", \"Wireless\", \"Lan\", and \"All\".\n If more than one interface type is specified, the strings must be separated by a comma.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_remoteaccess","displayName":"Remote Access","description":"RemoteAccess","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_wireless","displayName":"Wireless","description":"Wireless","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_lan","displayName":"Lan","description":"Lan","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_mobilebroadband","displayName":"[Not Supported] Mobile Broadband","description":"MobileBroadband","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_mbb","displayName":"Mobile Broadband","description":"MobileBroadband","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_interfacetypes_all","displayName":"All","description":"All","helpText":null}]},"413c0ab1f72c8c3f":{"id":"vendor_msft_firewall_mdmstore_publicprofile_logfilepath","displayName":"Log File Path","description":"This value is a string that represents a file path to the log where the firewall logs dropped packets and successful connections. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured, otherwise the MdmStore value wins if it is configured, otherwise the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},"41f750704ff3ca00":{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_screenoffdurationtotriggernetworkdiscoveryinminutes","displayName":"Screen Off Duration To Trigger Network Discovery In Minutes (Windows Insiders only)","description":"When the device experiences screen off and back on, this value configures the minimum duration (in minutes) of the screen off period that will trigger network discovery.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/42.json b/public/intune-definitions/42.json index 508a6e7457b4..48a5f3024473 100644 --- a/public/intune-definitions/42.json +++ b/public/intune-definitions/42.json @@ -1 +1 @@ -{"4205fcace5f50e48":{"id":"com.apple.applicationaccess_allowsharedstream","displayName":"Allow Shared Stream","description":"If false, disables Shared Photo Stream. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsharedstream_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsharedstream_true","displayName":"True","description":null,"helpText":null}]},"42e2a1f819e2200c":{"id":"com.apple.asam_allowedapplications_item_bundleidentifier","displayName":"Bundle Identifier","description":"The unique bundle identifier. If two dictionaries contain the same Bundle Identifier value but a different Team Identifier value, this will be considered an error and the profile won't be installed.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},"42c534340d9e497c":{"id":"com.apple.extensiblesso_extensiondata_pwnotificationdays_kerberos","displayName":"Password Notification Days","description":"The number of days prior to password expiration when a notification of password expiration will be sent to the user. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"42b04235c5d62ef0":{"id":"com.apple.managedclient.preferences_enablefilehashcomputation","displayName":"Enable file hash computation","description":"Enables or disables file hash computation feature. When this feature is enabled Windows defender will compute hashes for files it scans. This will help in improving the accuracy of Custom Indicator matches. However, enabling Enable file hash computation may impact device performance.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#configure-file-hash-computation-feature"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_enablefilehashcomputation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablefilehashcomputation_true","displayName":"True","description":null,"helpText":null}]},"427fa79effdbb0ca":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo_url","displayName":"URL","description":"The URL from which the image can be downloaded.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"42eef4795f96f8b6":{"id":"com.apple.mcxmenuextras_cpu.menu","displayName":"CPU","description":"If true, enables the CPU menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_cpu.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_cpu.menu_true","displayName":"True","description":null,"helpText":null}]},"427146eedb46fed7":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"42fc11e583c43b05":{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended","displayName":"Clear cached images and files when Microsoft Edge closes (users can override)","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files are deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"42e93593592dec05":{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled","displayName":"Enable the Copilot new tab page","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\n\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\n\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\n\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\n\nIf you enable this policy, the Copilot new tab page is turned on.\n\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"420879d4407a2ba4":{"id":"device_vendor_msft_pkcscertificate_renewalthreshold","displayName":"Renewal threshold (%)","description":"Enter the percentage (between 1 and 99 percent) of remaining certificate lifetime that is allowed before a device can request renewal of the certificate. The recommended amount in Intune is 20%. (1-99)","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},"42bd52bbc9a83f92":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_6","displayName":"Saturday","description":null,"helpText":null}]},"4215dd54814fec33":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},"42a1921c4d96fdfe":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp","displayName":"Continue experiences on this device","description":"\r\nThis policy setting determines whether the Windows device is allowed to participate in cross-device experiences (continue experiences).\r\n\r\nIf you enable this policy setting, the Windows device is discoverable by other Windows devices that belong to the same user, and can participate in cross-device experiences.\r\n\r\nIf you disable this policy setting, the Windows device is not discoverable by other devices, and cannot participate in cross-device experiences.\r\n\r\nIf you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablecdp"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp_1","displayName":"Enabled","description":null,"helpText":null}]},"4268e34a170c9949":{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep","displayName":"Turn off Data Execution Prevention for HTML Help Executible","description":"This policy setting allows you to exclude HTML Help Executable from being monitored by software-enforced Data Execution Prevention.\r\n\r\n Data Execution Prevention (DEP) is designed to block malicious code that takes advantage of exception-handling mechanisms in Windows by monitoring your programs to make sure that they use system memory safely.\r\n\r\n If you enable this policy setting, DEP for HTML Help Executable is turned off. This will allow certain legacy ActiveX controls to function without DEP shutting down HTML Help Executable.\r\n\r\n If you disable or do not configure this policy setting, DEP is turned on for HTML Help Executable. This provides an additional security benefit, but HTLM Help stops if DEP detects system memory abnormalities.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-disablehhdep"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep_1","displayName":"Enabled","description":null,"helpText":null}]},"42ea3da3001c314a":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval_scan_quickscaninterval","displayName":"Specify the interval to run quick scans per day","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},"428031fe667225fc":{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc","displayName":"Allow automatic sleep with Open Network Files (on battery)","description":"This policy setting allows you to manage automatic sleep with open network files.\r\n\r\nIf you enable this policy setting, the computer automatically sleeps when network files are open.\r\n\r\nIf you disable or do not configure this policy setting, the computer does not automatically sleep when network files are open.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystemsleepwithremotefilesopendc"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc_1","displayName":"Enabled","description":null,"helpText":null}]},"425aba2179c2a7bd":{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel_enterreservebatterynotificationlevel","displayName":"Reserve Battery Notification Level (percent):","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":null},"42782b2abb65ea4b":{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate","displayName":"Set IP-HTTPS State","description":"This policy setting allows you to configure IP-HTTPS, a tunneling technology that uses the HTTPS protocol to provide IP connectivity to a remote network.\r\n\r\nIf you disable or do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, you can specify an IP-HTTPS server URL. You will be able to configure IP-HTTPS with one of the following settings:\r\n\r\nPolicy Default State: The IP-HTTPS interface is used when there are no other connectivity options.\r\n\r\nPolicy Enabled State: The IP-HTTPS interface is always present, even if the host has other connectivity options.\r\n\r\nPolicy Disabled State: No IP-HTTPS interfaces are present on the host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-iphttps-clientstate"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_1","displayName":"Enabled","description":null,"helpText":null}]},"42a2f4ac6ae70368":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics","displayName":"Configure RemoteFX","description":"This policy setting allows you to control the availability of RemoteFX on both a Remote Desktop Virtualization Host (RD Virtualization Host) server and a Remote Desktop Session Host (RD Session Host) server.\r\n\r\nWhen deployed on an RD Virtualization Host server, RemoteFX delivers a rich user experience by rendering content on the server by using graphics processing units (GPUs). By default, RemoteFX for RD Virtualization Host uses server-side GPUs to deliver a rich user experience over LAN connections and RDP 7.1.\r\n\r\nWhen deployed on an RD Session Host server, RemoteFX delivers a rich user experience by using a hardware-accelerated compression scheme.\r\n\r\nIf you enable this policy setting, RemoteFX will be used to deliver a rich user experience over LAN connections and RDP 7.1.\r\n\r\nIf you disable this policy setting, RemoteFX will be disabled.\r\n\r\nIf you do not configure this policy setting, the default behavior will be used. By default, RemoteFX for RD Virtualization Host is enabled and RemoteFX for RD Session Host is disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-enablevirtualgraphics"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},"427919135b0a0263":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc_ts_sd_loc","displayName":"Configure RD Connection Broker server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":null},"425882a3fdbf05fe":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness","displayName":"Microsoft OneDrive for Business 2016","description":"\r\nThis policy setting configures the synchronization of user settings for OneDrive for Business 2016.\r\nBy default, the user settings of OneDrive for Business 2016 synchronize between computers. Use the policy setting to prevent the user settings of OneDrive for Business 2016 from synchronization between computers.\r\nIf you enable this policy setting, OneDrive for Business 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, OneDrive for Business 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onedriveforbusiness"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness_1","displayName":"Enabled","description":null,"helpText":null}]},"429ea199685a6826":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project","displayName":"Microsoft Project 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Project 2016.\r\nBy default, the user settings of Microsoft Project 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Project 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Project 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Project 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016project"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project_1","displayName":"Enabled","description":null,"helpText":null}]},"427f8bc9ba6741a5":{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8","displayName":"Turn off Automatic Download of updates on Win8 machines","description":"Enables or disables the automatic download of app updates on PCs running Windows 8.\r\n\r\nIf you enable this setting, the automatic download of app updates is turned off.\r\n\r\nIf you disable this setting, the automatic download of app updates is turned on.\r\n\r\nIf you don't configure this setting, the automatic download of app updates is determined by a registry setting that the user can change using Settings in the Microsoft Store.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-disableautodownloadwin8"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8_1","displayName":"Enabled","description":null,"helpText":null}]},"423540868c7256e1":{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced","displayName":"Require PIN pairing","description":"This policy applies to Wireless Display connections. This policy means that the use of a PIN for pairing to Wireless Display devices is required rather than optional.\r\n\r\nConversely it means that Push Button is NOT allowed.\r\n\r\nIf this policy setting is disabled or is not configured, by default Push Button pairing is allowed (but not necessarily preferred).\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wlansvc#admx-wlansvc-setpinenforced"],"categoryId":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced_1","displayName":"Enabled","description":null,"helpText":null}]},"42584e014f7dcce1":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended","displayName":"Parameters for instant URL which uses POST","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"42f12814a3300545":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profileslockedretrycount_profileslockedretrycount","displayName":"Locked Retry Count (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"4210f651c8ab399f":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowlessprivilegedsites"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"428cc81652da564c":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"4218650c77aa0197":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled.","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\r\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\r\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\r\n\r\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\r\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\r\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\r\n\r\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"42a1df4f3b11aa15":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"42258b2c69efa1de":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes","displayName":"Configure allowed extension types","description":"Controls which extension types can be installed and limits runtime access.\r\n\r\nThis setting defines the allowed types of extensions and which hosts they can interact with. The value is a list of strings, each of which should be one of the following: \"extension\", \"theme\", \"user_script\", and \"hosted_app\". See the Microsoft Edge extensions documentation for more information on these types.\r\n\r\nNote that this policy also affects extensions to be force-installed by using 'ExtensionInstallForcelist' (Control which extensions are installed silently) policy.\r\n\r\nIf you enable this policy, only extensions that match a type in the list are installed.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable extension types are enforced.\r\n\r\nExample value:\r\n\r\nhosted_app","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_1","displayName":"Enabled","description":null,"helpText":null}]},"4232d1106fd58d65":{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_defaultdownloaddirectory","displayName":"Set default download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":null},"4262ed8c35597976":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled","displayName":"Enable the Collections feature","description":"Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.\r\n\r\nIf you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.\r\n\r\nIf you disable this policy, users can't access and use Collections in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"42041352295af940":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"A list of URLs to which 'AutoOpenFileTypes' (List of file types that should be automatically opened on download) will apply to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\r\n\r\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in 'AutoOpenFileTypes'. If either condition is false, the download won't automatically open by policy.\r\n\r\nIf you don't set this policy, all downloads where the file type is in 'AutoOpenFileTypes' will automatically open.\r\n\r\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"420ba864335431f0":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_sensorsallowedforurlsdesc","displayName":"Allow access to sensors on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"426a195af6190cff":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemWriteAskForUrls' (Allow write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"426315ffd1ae5a81":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Prevent redirection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Redirect sites based on the incompatible sites sitelist","description":null,"helpText":null}]},"42c83414bce9308d":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting","displayName":"Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app","description":"This setting lets you enable reporting of sites that Microsoft Edge users add to their local IE Mode site list. The user must be signed into Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\r\n\r\nIf you configure this policy, Microsoft Edge will send a report to the M365 Admin Center Site Lists app when a user adds a site to their local IE mode site list. The report will show the URL of the site the user added, minus any query string or fragment. The user's identity isn't reported.\r\n\r\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the M365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge will still attempt to send reports if this step hasn't been completed. However, the reports will not be stored in the Site Lists app.\r\n\r\nWhen enabling this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will never send reports about URLs added to a user's local site list to the Site Lists app.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_1","displayName":"Enabled","description":null,"helpText":null}]},"4278be076588f05b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_powerpntexe59","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_powerpntexe59_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_powerpntexe59_1","displayName":"True","description":null,"helpText":null}]},"42c1415799d81654":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_mspubexe100","displayName":"mspub.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_mspubexe100_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_mspubexe100_1","displayName":"True","description":null,"helpText":null}]},"42446a63c2dbd9d6":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_setbitsasprimary","displayName":"Prioritize BITS","description":"This policy setting prioritizes the use of Windows Background Interface Transfer Service (BITS) by the Office client when downloading Office updates from the Office Content Delivery Network (CDN).\r\n\r\nIf enabled, BITS will be used on devices that are downloading Office updates directly from the Office CDN and throttle values used by BITS will be honored. The device will not leverage BITS if updates are obtained from a local UNC share.\r\n\r\nIf disable or not configured, BITS will not be prioritized and http will be the primary transport for downloading updates.\r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI)","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_setbitsasprimary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_setbitsasprimary_1","displayName":"Enabled","description":null,"helpText":null}]},"42d53fafcee7c0d5":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockexternalsync","displayName":"Prevent users from syncing libraries and folders shared from other organizations","description":"This setting controls whether users in your organization are allowed to sync OneDrive for Business or SharePoint content that has been shared by users in a different organization. This is a collaboration feature called B2B Sync.\r\n\r\nIf you enable this setting, users will not be able to start syncing a OneDrive for Business or SharePoint library or folder that was shared from an external organization. Any shared libraries or folders already being synced will stop syncing.\r\n\r\nIf you disable or do not configure this setting, users will be able to sync OneDrive for Business and SharePoint libraries and folders that have been shared from external organizations.\r\n\r\nFor more info about B2B Sync, see: https://docs.microsoft.com/en-us/onedrive/b2b-sync","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockexternalsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockexternalsync_1","displayName":"Enabled","description":null,"helpText":null}]},"42ab88745eda9d98":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization","displayName":"Specify the OneDrive location in a hybrid environment","description":"This setting defines whether the OneDrive sync app (OneDrive.exe) should authenticate against SharePoint Online or SharePoint Server 2019 if the identity exists in both identity providers. To use this setting, you must also enable \"Specify SharePoint Server URL and organization name\". This setting affects only OneDrive for Business sync functionality. It does not impact syncing team sites in SharePoint Online or SharePoint Server 2019.\r\n\r\nIf you enable this setting, you can select one of two options:\r\n\r\nSharePoint Online: The sync app will look first in SharePoint Online for a user's OneDrive. If the sync app is already configured with SharePoint Online for the user, it will attempt to configure a OneDrive for Business instance in SharePoint Server 2019 for that user.\r\n\r\nSharePoint Server 2019: The sync app will look first in SharePoint Server 2019 for a user's OneDrive for Business. If the sync app is already configured with SharePoint Server 2019 for the user, it will attempt to configure a OneDrive instance in SharePoint Online for that user.\r\n\r\nIf you disable or do not configure this setting, the sync app will look first in SharePoint Online for the user's OneDrive.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_1","displayName":"Enabled","description":null,"helpText":null}]},"4292546e3646296b":{"id":"device_vendor_msft_policy_config_system_allowfontproviders","displayName":"Allow Font Providers","description":"Boolean policy setting that determines whether Windows is allowed to download fonts and font catalog data from an online font provider. If you enable this setting, Windows periodically queries an online font provider to determine whether a new font catalog is available. Windows may also download font data if needed to format or render text. If you disable this policy setting, Windows does not connect to an online font provider and only enumerates locally-installed fonts. This MDM setting corresponds to the EnableFontProviders Group Policy setting. If both the Group Policy and the MDM settings are configured, the group policy setting takes precedence. If neither is configured, the behavior depends on a DisableFontProviders registry value. In server editions, this registry value is set to 1 by default, so the default behavior is false (disabled). In all other editions, the registry value is not set by default, so the default behavior is true (enabled). This setting is used by lower-level components for text display and fond handling and has not direct effect on web browsers, which may download web fonts used in web content. NoteReboot is required after setting the policy; alternatively you can stop and restart the FontCache service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#allowfontproviders"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_allowfontproviders_0","displayName":"Not allowed. No traffic to fs.microsoft.com and only locally installed fonts are available.","description":"Not allowed. No traffic to fs.microsoft.com and only locally installed fonts are available.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowfontproviders_1","displayName":"Allowed. There may be network traffic to fs.microsoft.com and downloadable fonts are available to apps that support them.","description":"Allowed. There may be network traffic to fs.microsoft.com and downloadable fonts are available to apps that support them.","helpText":null}]},"424967f5e3d7b767":{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautorebootforqualityupdates","displayName":"Configure Deadline No Auto Reboot For Quality Updates","description":"When enabled, devices will not automatically restart outside of active hours until the deadline and grace period have expired for quality updates, even if an update is ready for restart. When disabled, an automatic restart may be attempted outside of active hours after update is ready for restart before the deadline is reached. Takes effect only if Update/ConfigureDeadlineForQualityUpdates is configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlinenoautorebootforqualityupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautorebootforqualityupdates_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautorebootforqualityupdates_1","displayName":"Enabled.","description":"Enabled.","helpText":null}]},"4278f9b7080ae529":{"id":"device_vendor_msft_policy_config_update_scheduledinstallthirdweek","displayName":"Scheduled Install Third Week","description":"Enables the IT admin to schedule the update installation on the third week of the month. Value type is integer. Supported values:0 - no update in the schedule1 - update is scheduled every third week of the month","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduledinstallthirdweek"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_scheduledinstallthirdweek_0","displayName":"no update in the schedule","description":"no update in the schedule","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduledinstallthirdweek_1","displayName":"update is scheduled every third week of the month","description":"update is scheduled every third week of the month","helpText":null}]},"42693436fe751721":{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings","displayName":"Print Settings","description":"This policy setting allows you to decide how the print functionality behaves while in Microsoft Defender Application Guard.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsDefenderApplicationGuard-csp/"],"categoryId":"cd55f347-a417-4fe9-83ee-8f1f40ac5eb0","categoryName":null,"options":[{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_0","displayName":"Disable all print functionality","description":"Disables all print functionality.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_1","displayName":"Enable XPS printing","description":"Enables only XPS printing.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_2","displayName":"Enable PDF printing","description":"Enables only PDF printing.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_4","displayName":"Enable local printing","description":"Enables only local printing.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_8","displayName":"Enable network printing","description":"Enables only network printing.","helpText":null}]},"429757cff02ebb2e":{"id":"mathsettings_calculator_mathnotesmode","displayName":"Math Notes Mode","description":"If present, configures the Math Notes mode of the calculator. If not present, math notes mode is enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":null},"428249cfe4bceb71":{"id":"user_vendor_msft_policy_config_admx_explorer_turnoffspianimations","displayName":"Turn off common control and window animations (User)","description":"This policy is similar to settings directly available to computer users. Disabling animations can improve usability for users with some visual disabilities as well as improving performance and battery life in some scenarios.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-turnoffspianimations"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_explorer_turnoffspianimations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_explorer_turnoffspianimations_1","displayName":"Enabled","description":null,"helpText":null}]},"4204d5382618d3a6":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_publickey","displayName":"Public Key Policies (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-publickey"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_publickey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_publickey_1","displayName":"Enabled","description":null,"helpText":null}]},"4272c91dd3be7718":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_1_lbl_customgoofflineactionslist","displayName":"Customize actions: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"42f5020b1ca739b5":{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_1","displayName":"Custom Classes: Deny read access (User)","description":"This policy setting denies read access to custom removable storage classes.\r\n\r\nIf you enable this policy setting, read access is denied to these removable storage classes.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to these removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-customclasses-denyread-access-1"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_1_1","displayName":"Enabled","description":null,"helpText":null}]},"4247a46cf7819795":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1","displayName":"Set time limit for active Remote Desktop Services sessions (User)","description":"This policy setting allows you to specify the maximum amount of time that a Remote Desktop Services session can be active before it is automatically disconnected.\r\n\r\nIf you enable this policy setting, you must select the desired time limit in the Active session limit list. Remote Desktop Services will automatically disconnect active sessions after the specified amount of time. The user receives a warning two minutes before the Remote Desktop Services session disconnects, which allows the user to save open files and close programs. If you have a console session, active session time limits do not apply.\r\n\r\nIf you disable or do not configure this policy setting, this policy setting is not specified at the Group Policy level. By default, Remote Desktop Services allows sessions to remain active for an unlimited amount of time. \r\n\r\nIf you want Remote Desktop Services to end instead of disconnect a session when the time limit is reached, you can configure the policy setting Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Session Time Limits\\End session when time limits are reached.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the Computer Configuration policy setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sessions-limits-1"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_1","displayName":"Enabled","description":null,"helpText":null}]},"424be66e5e450626":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_udpcheckbox","displayName":"UDP (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_udpcheckbox_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_udpcheckbox_1","displayName":"True","description":null,"helpText":null}]},"423729967ffd6852":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally","displayName":"Always Open PDF files externally (User)","description":"Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application.\r\n\r\nSetting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally_1","displayName":"Enabled","description":null,"helpText":null}]},"4292f9eb35c74642":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault","displayName":"Print PDF as Image Default (User)","description":"Controls if Google Chrome makes the Print as image option default to set when printing PDFs.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available.\r\n\r\nFor Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault_1","displayName":"Enabled","description":null,"helpText":null}]},"42d6585a6aef14a8":{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode","displayName":"Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows (User)","description":"This policy setting determines whether Internet Explorer 11 uses 64-bit processes (for greater security) or 32-bit processes (for greater compatibility) when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nImportant: Some ActiveX controls and toolbars may not be available when 64-bit processes are used.\n\nIf you enable this policy setting, Internet Explorer 11 will use 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nIf you disable this policy setting, Internet Explorer 11 will use 32-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nIf you don't configure this policy setting, users can turn this feature on or off using Internet Explorer settings. This feature is turned off by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableprocessesinenhancedprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"420e918428810749":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions) (User)","description":"Enables user-level installation of native messaging hosts.\r\n\r\nIf you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.\r\n\r\nBy default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},"42aa7743e18864e8":{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites (User)","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or it will\r\nfail. Users' personal settings may allow certain origins to call this API\r\nwithout a prior user gesture.\r\n\r\nThis policy supersedes users' personal settings and blocks matching origins\r\nfrom calling the API without a prior user gesture.\r\n\r\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\nWildcards (*) are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy or user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"427897a05a0a6acd":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled","displayName":"Enable additional search box in browser (User)","description":"A search box is an additional text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\r\n\r\nIf you enable or don't configure this policy, the search box will be visible and available for use.\r\nUsers can toggle the search box in Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\r\n\r\nIf you disable this policy, search box will not be visible, and users will have to use the address bar or navigate to a search engine to perform web searches.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"424626133705b417":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist","displayName":"Block access to a list of URLs in InPrivate mode. (User)","description":"This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge.\r\n\r\nAdministrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nIf both 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.) and 'InPrivateModeUrlAllowlist' (Allow access to a list of URLs in InPrivate mode.) are configured, the allowlist takes precedence.\r\n- URLs that match the allowlist are allowed.\r\n- URLs that match the blocklist but not the allowlist are blocked.\r\n- URLs that match neither list follow the behavior defined by the general 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs) policies.\r\n\r\nIf 'InPrivateModeUrlAllowlist' is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.\r\n\r\nIf 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) and 'InPrivateModeUrlAllowlist' is configured, InPrivate mode is available only for URLs that match the allowlist.\r\n\r\nThis policy applies only to InPrivate mode. To block URLs across all browsing modes, use 'URLBlocklist'.\r\n\r\nThis policy supports up to 1000 entries.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"4259c8ba2367d457":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies","displayName":"Allow importing of Cookies (User)","description":"Allows users to import Cookies from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Cookies aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Cookies are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies_1","displayName":"Enabled","description":null,"helpText":null}]},"42520fc891fc9982":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_1","displayName":"Enabled","description":null,"helpText":null}]},"4234dc94170fe9b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicemajorversion0","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"42ca7e879fc9c218":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd","displayName":"Replace Label - Work Address (User)","description":"This policy setting allows you to change or remove the 13th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_1","displayName":"Enabled","description":null,"helpText":null}]},"425b04e308b456da":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowpath434","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"429e16639013a85e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties","displayName":"Encrypt document properties (User)","description":"This policy setting allows you configure if the document properties are encrypted. This applies to OLE documents (Office 97-2003 compatible) if the application is configured for CAPI RC4.\r\n\r\nIf you enable this policy setting, the document properties will be encrypted.\r\n\r\nIf you disable or do not configure this policy setting, the document properties will not be encrypted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"429aa3f6dea16447":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_pathcolon02","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"42135a3f2d2e9d7f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_pathcolon05","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"4270ae09071d2417":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11","displayName":"Unsafe Location #11 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_1","displayName":"Enabled","description":null,"helpText":null}]},"429d17208dcb6682":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles","displayName":"Set Workgroup path for label page size update files (User)","description":"This policy setting allows you to specify the Workgroup path for the label page size update files. This is useful if the organization has a centralized template depot. \r\n\r\nIf you enable this policy setting, you may enter the path to the PSX update files.\r\n\r\nIf you disable or do not configure this policy setting, there is no Workgroup path for the shared label templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"421d0708cb03c389":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406","displayName":"PowerPoint: web page format compatibility (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_2","displayName":"All browsers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_1","displayName":"Windows Internet Explorer 4.0 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_0","displayName":"Based on installed browsers","description":null,"helpText":null}]},"42bb5e9f1aae0284":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},"42fcecb52c4da978":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance","displayName":"Set importance (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_1","displayName":"Enabled","description":null,"helpText":null}]},"42b8d77e10b9d271":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview","displayName":"Configure Cross Folder Content in conversation view (User)","description":"This policy setting controls how conversation view in Outlook is loaded and whether Cross Folder Content is turned on or off.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- On and cross-store (default): Cross Folder Content is on and cross-store. Data will be pulled from all connected data files whether they are cached or online. \r\n- Off: Cross Folder Content is turned off.\r\n- On and current: Cross Folder Content is on, but data is only pulled from the current data file. \r\n- On and local: Cross Folder Content is on, but data is only pulled from the current data file and any other local data files.\r\n\r\nIf you disable or do not configure this policy setting, Cross Folder Content will be turned on and pulled from all connected data files.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_1","displayName":"Enabled","description":null,"helpText":null}]},"420e7ce8098b8fff":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2","displayName":"Allow Active X One Off Forms (User)","description":"By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"42790accd3da55c7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver","displayName":"Enter seconds to wait to download changes from server (User)","description":"Specifies number of seconds to wait before downloading changes from the Exchange server.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_1","displayName":"Enabled","description":null,"helpText":null}]},"426373cafdfbd463":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel","displayName":"Stop checking to ensure heading styles do not skip style level (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that headings in a document are used in order.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that headings in a document are used in order.\r\n\r\nIf you disable or do not configure this policy setting, the ordering of headings in a document will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel_1","displayName":"Enabled","description":null,"helpText":null}]},"422f05e21ff4896d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},"42533ba1c56a255e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"42c9af143fcf3f7d":{"id":"ade_setupassistant_accessibilityappearance","displayName":"Accessibility appearance","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_accessibilityappearance_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_accessibilityappearance_1","displayName":"Show","description":null,"helpText":null}]},"4205fcace5f50e48":{"id":"com.apple.applicationaccess_allowsharedstream","displayName":"Allow Shared Stream","description":"If false, disables Shared Photo Stream. Available in iOS 6 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsharedstream_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsharedstream_true","displayName":"True","description":null,"helpText":null}]},"42e2a1f819e2200c":{"id":"com.apple.asam_allowedapplications_item_bundleidentifier","displayName":"Bundle Identifier","description":"The unique bundle identifier. If two dictionaries contain the same Bundle Identifier value but a different Team Identifier value, this will be considered an error and the profile won't be installed.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},"42c534340d9e497c":{"id":"com.apple.extensiblesso_extensiondata_pwnotificationdays_kerberos","displayName":"Password Notification Days","description":"The number of days prior to password expiration when a notification of password expiration will be sent to the user. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"42b04235c5d62ef0":{"id":"com.apple.managedclient.preferences_enablefilehashcomputation","displayName":"Enable file hash computation","description":"Enables or disables file hash computation feature. When this feature is enabled Windows defender will compute hashes for files it scans. This will help in improving the accuracy of Custom Indicator matches. However, enabling Enable file hash computation may impact device performance.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#configure-file-hash-computation-feature"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_enablefilehashcomputation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enablefilehashcomputation_true","displayName":"True","description":null,"helpText":null}]},"427fa79effdbb0ca":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo_url","displayName":"URL","description":"The URL from which the image can be downloaded.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"42eef4795f96f8b6":{"id":"com.apple.mcxmenuextras_cpu.menu","displayName":"CPU","description":"If true, enables the CPU menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_cpu.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_cpu.menu_true","displayName":"True","description":null,"helpText":null}]},"427146eedb46fed7":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"42fc11e583c43b05":{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended","displayName":"Clear cached images and files when Microsoft Edge closes (users can override)","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files are deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"42e93593592dec05":{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled","displayName":"Enable the Copilot new tab page","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\n\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\n\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\n\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\n\nIf you enable this policy, the Copilot new tab page is turned on.\n\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.copilotnewtabpageenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"420879d4407a2ba4":{"id":"device_vendor_msft_pkcscertificate_renewalthreshold","displayName":"Renewal threshold (%)","description":"Enter the percentage (between 1 and 99 percent) of remaining certificate lifetime that is allowed before a device can request renewal of the certificate. The recommended amount in Intune is 20%. (1-99)","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},"42bd52bbc9a83f92":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workdaysfrom_6","displayName":"Saturday","description":null,"helpText":null}]},"4215dd54814fec33":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":null},"42a1921c4d96fdfe":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp","displayName":"Continue experiences on this device","description":"\r\nThis policy setting determines whether the Windows device is allowed to participate in cross-device experiences (continue experiences).\r\n\r\nIf you enable this policy setting, the Windows device is discoverable by other Windows devices that belong to the same user, and can participate in cross-device experiences.\r\n\r\nIf you disable this policy setting, the Windows device is not discoverable by other devices, and cannot participate in cross-device experiences.\r\n\r\nIf you do not configure this policy setting, the default behavior depends on the Windows edition. Changes to this policy take effect on reboot.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-enablecdp"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_enablecdp_1","displayName":"Enabled","description":null,"helpText":null}]},"4268e34a170c9949":{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep","displayName":"Turn off Data Execution Prevention for HTML Help Executible","description":"This policy setting allows you to exclude HTML Help Executable from being monitored by software-enforced Data Execution Prevention.\r\n\r\n Data Execution Prevention (DEP) is designed to block malicious code that takes advantage of exception-handling mechanisms in Windows by monitoring your programs to make sure that they use system memory safely.\r\n\r\n If you enable this policy setting, DEP for HTML Help Executable is turned off. This will allow certain legacy ActiveX controls to function without DEP shutting down HTML Help Executable.\r\n\r\n If you disable or do not configure this policy setting, DEP is turned on for HTML Help Executable. This provides an additional security benefit, but HTLM Help stops if DEP detects system memory abnormalities.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-help#admx-help-disablehhdep"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_help_disablehhdep_1","displayName":"Enabled","description":null,"helpText":null}]},"42ea3da3001c314a":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_quickscaninterval_scan_quickscaninterval","displayName":"Specify the interval to run quick scans per day","description":null,"helpText":"","infoUrls":[],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":null},"428031fe667225fc":{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc","displayName":"Allow automatic sleep with Open Network Files (on battery)","description":"This policy setting allows you to manage automatic sleep with open network files.\r\n\r\nIf you enable this policy setting, the computer automatically sleeps when network files are open.\r\n\r\nIf you disable or do not configure this policy setting, the computer does not automatically sleep when network files are open.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystemsleepwithremotefilesopendc"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystemsleepwithremotefilesopendc_1","displayName":"Enabled","description":null,"helpText":null}]},"425aba2179c2a7bd":{"id":"device_vendor_msft_policy_config_admx_power_reservebatterynotificationlevel_enterreservebatterynotificationlevel","displayName":"Reserve Battery Notification Level (percent):","description":null,"helpText":"","infoUrls":[],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":null},"42782b2abb65ea4b":{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate","displayName":"Set IP-HTTPS State","description":"This policy setting allows you to configure IP-HTTPS, a tunneling technology that uses the HTTPS protocol to provide IP connectivity to a remote network.\r\n\r\nIf you disable or do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, you can specify an IP-HTTPS server URL. You will be able to configure IP-HTTPS with one of the following settings:\r\n\r\nPolicy Default State: The IP-HTTPS interface is used when there are no other connectivity options.\r\n\r\nPolicy Enabled State: The IP-HTTPS interface is always present, even if the host has other connectivity options.\r\n\r\nPolicy Disabled State: No IP-HTTPS interfaces are present on the host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-iphttps-clientstate"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_iphttps_clientstate_1","displayName":"Enabled","description":null,"helpText":null}]},"42a2f4ac6ae70368":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics","displayName":"Configure RemoteFX","description":"This policy setting allows you to control the availability of RemoteFX on both a Remote Desktop Virtualization Host (RD Virtualization Host) server and a Remote Desktop Session Host (RD Session Host) server.\r\n\r\nWhen deployed on an RD Virtualization Host server, RemoteFX delivers a rich user experience by rendering content on the server by using graphics processing units (GPUs). By default, RemoteFX for RD Virtualization Host uses server-side GPUs to deliver a rich user experience over LAN connections and RDP 7.1.\r\n\r\nWhen deployed on an RD Session Host server, RemoteFX delivers a rich user experience by using a hardware-accelerated compression scheme.\r\n\r\nIf you enable this policy setting, RemoteFX will be used to deliver a rich user experience over LAN connections and RDP 7.1.\r\n\r\nIf you disable this policy setting, RemoteFX will be disabled.\r\n\r\nIf you do not configure this policy setting, the default behavior will be used. By default, RemoteFX for RD Virtualization Host is enabled and RemoteFX for RD Session Host is disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-enablevirtualgraphics"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_enablevirtualgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},"427919135b0a0263":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_sd_loc_ts_sd_loc","displayName":"Configure RD Connection Broker server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":null},"425882a3fdbf05fe":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness","displayName":"Microsoft OneDrive for Business 2016","description":"\r\nThis policy setting configures the synchronization of user settings for OneDrive for Business 2016.\r\nBy default, the user settings of OneDrive for Business 2016 synchronize between computers. Use the policy setting to prevent the user settings of OneDrive for Business 2016 from synchronization between computers.\r\nIf you enable this policy setting, OneDrive for Business 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, OneDrive for Business 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onedriveforbusiness"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onedriveforbusiness_1","displayName":"Enabled","description":null,"helpText":null}]},"429ea199685a6826":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project","displayName":"Microsoft Project 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Project 2016.\r\nBy default, the user settings of Microsoft Project 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Project 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Project 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Project 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016project"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016project_1","displayName":"Enabled","description":null,"helpText":null}]},"427f8bc9ba6741a5":{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8","displayName":"Turn off Automatic Download of updates on Win8 machines","description":"Enables or disables the automatic download of app updates on PCs running Windows 8.\r\n\r\nIf you enable this setting, the automatic download of app updates is turned off.\r\n\r\nIf you disable this setting, the automatic download of app updates is turned on.\r\n\r\nIf you don't configure this setting, the automatic download of app updates is determined by a registry setting that the user can change using Settings in the Microsoft Store.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-disableautodownloadwin8"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableautodownloadwin8_1","displayName":"Enabled","description":null,"helpText":null}]},"423540868c7256e1":{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced","displayName":"Require PIN pairing","description":"This policy applies to Wireless Display connections. This policy means that the use of a PIN for pairing to Wireless Display devices is required rather than optional.\r\n\r\nConversely it means that Push Button is NOT allowed.\r\n\r\nIf this policy setting is disabled or is not configured, by default Push Button pairing is allowed (but not necessarily preferred).\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wlansvc#admx-wlansvc-setpinenforced"],"categoryId":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wlansvc_setpinenforced_1","displayName":"Enabled","description":null,"helpText":null}]},"42584e014f7dcce1":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended","displayName":"Parameters for instant URL which uses POST","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"42f12814a3300545":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profileslockedretrycount_profileslockedretrycount","displayName":"Locked Retry Count (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"4210f651c8ab399f":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowlessprivilegedsites"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"428cc81652da564c":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"4218650c77aa0197":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled","displayName":"Controls whether unload event handlers can be disabled.","description":"unload event handlers are being deprecated. Whether they fire depends on the unload Permissions-Policy.\r\nCurrently, they are allowed by policy by default. In the future they will gradually move to being disallowed by default and sites must explicitly enable them using Permissions-Policy headers.\r\nThis enterprise policy can be used to opt out of this gradual deprecation by forcing the default to stay enabled.\r\n\r\nPages might depend on unload event handlers to save data or signal the end of a user session to the server.\r\nThis is not recommended because it's unreliable and impacts performance by blocking use of BackForwardCache.\r\nRecommended alternatives exist, but the unload event has been used for a long time. Some applications might still rely on them.\r\n\r\nIf you disable this policy or don't configure it, unload event handlers will gradually be deprecated in-line with the deprecation rollout and sites which don't set Permissions-Policy header will stop firing `unload` events.\r\n\r\nIf you enable this policy then unload event handlers will continue to work by default.","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_forcepermissionpolicyunloaddefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"42a1df4f3b11aa15":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderencodings_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"42258b2c69efa1de":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes","displayName":"Configure allowed extension types","description":"Controls which extension types can be installed and limits runtime access.\r\n\r\nThis setting defines the allowed types of extensions and which hosts they can interact with. The value is a list of strings, each of which should be one of the following: \"extension\", \"theme\", \"user_script\", and \"hosted_app\". See the Microsoft Edge extensions documentation for more information on these types.\r\n\r\nNote that this policy also affects extensions to be force-installed by using 'ExtensionInstallForcelist' (Control which extensions are installed silently) policy.\r\n\r\nIf you enable this policy, only extensions that match a type in the list are installed.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable extension types are enforced.\r\n\r\nExample value:\r\n\r\nhosted_app","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_1","displayName":"Enabled","description":null,"helpText":null}]},"4232d1106fd58d65":{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_defaultdownloaddirectory","displayName":"Set default download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":null},"4262ed8c35597976":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled","displayName":"Enable the Collections feature","description":"Lets you allow users to access the Collections feature, where they can collect, organize, share, and export content more efficiently and with Office integration.\r\n\r\nIf you enable or don't configure this policy, users can access and use the Collections feature in Microsoft Edge.\r\n\r\nIf you disable this policy, users can't access and use Collections in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_edgecollectionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"42041352295af940":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"A list of URLs to which 'AutoOpenFileTypes' (List of file types that should be automatically opened on download) will apply to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\r\n\r\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in 'AutoOpenFileTypes'. If either condition is false, the download won't automatically open by policy.\r\n\r\nIf you don't set this policy, all downloads where the file type is in 'AutoOpenFileTypes' will automatically open.\r\n\r\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autoopenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"420ba864335431f0":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_sensorsallowedforurlsdesc","displayName":"Allow access to sensors on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"426a195af6190cff":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemWriteAskForUrls' (Allow write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"426315ffd1ae5a81":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Prevent redirection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Redirect sites based on the incompatible sites sitelist","description":null,"helpText":null}]},"42c83414bce9308d":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting","displayName":"Configure reporting of IE Mode user list entries to the M365 Admin Center Site Lists app","description":"This setting lets you enable reporting of sites that Microsoft Edge users add to their local IE Mode site list. The user must be signed into Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\r\n\r\nIf you configure this policy, Microsoft Edge will send a report to the M365 Admin Center Site Lists app when a user adds a site to their local IE mode site list. The report will show the URL of the site the user added, minus any query string or fragment. The user's identity isn't reported.\r\n\r\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the M365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge will still attempt to send reports if this step hasn't been completed. However, the reports will not be stored in the Site Lists app.\r\n\r\nWhen enabling this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will never send reports about URLs added to a user's local site list to the Site Lists app.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudusersitesreporting_1","displayName":"Enabled","description":null,"helpText":null}]},"4278be076588f05b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_powerpntexe59","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_powerpntexe59_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_powerpntexe59_1","displayName":"True","description":null,"helpText":null}]},"42c1415799d81654":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_mspubexe100","displayName":"mspub.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_mspubexe100_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_mspubexe100_1","displayName":"True","description":null,"helpText":null}]},"42446a63c2dbd9d6":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_setbitsasprimary","displayName":"Prioritize BITS","description":"This policy setting prioritizes the use of Windows Background Interface Transfer Service (BITS) by the Office client when downloading Office updates from the Office Content Delivery Network (CDN).\r\n\r\nIf enabled, BITS will be used on devices that are downloading Office updates directly from the Office CDN and throttle values used by BITS will be honored. The device will not leverage BITS if updates are obtained from a local UNC share.\r\n\r\nIf disable or not configured, BITS will not be prioritized and http will be the primary transport for downloading updates.\r\n\r\nImportant: This policy setting only applies to Office 365 clients that are installed by using Click-to-Run, including Office 365 ProPlus, Office 365 Business, Visio Pro for Office 365 and Project Pro for Office 365. It doesn't apply to Office products that use Windows Installer (MSI)","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_setbitsasprimary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_setbitsasprimary_1","displayName":"Enabled","description":null,"helpText":null}]},"42d53fafcee7c0d5":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockexternalsync","displayName":"Prevent users from syncing libraries and folders shared from other organizations","description":"This setting controls whether users in your organization are allowed to sync OneDrive for Business or SharePoint content that has been shared by users in a different organization. This is a collaboration feature called B2B Sync.\r\n\r\nIf you enable this setting, users will not be able to start syncing a OneDrive for Business or SharePoint library or folder that was shared from an external organization. Any shared libraries or folders already being synced will stop syncing.\r\n\r\nIf you disable or do not configure this setting, users will be able to sync OneDrive for Business and SharePoint libraries and folders that have been shared from external organizations.\r\n\r\nFor more info about B2B Sync, see: https://docs.microsoft.com/en-us/onedrive/b2b-sync","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockexternalsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockexternalsync_1","displayName":"Enabled","description":null,"helpText":null}]},"42ab88745eda9d98":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization","displayName":"Specify the OneDrive location in a hybrid environment","description":"This setting defines whether the OneDrive sync app (OneDrive.exe) should authenticate against SharePoint Online or SharePoint Server 2019 if the identity exists in both identity providers. To use this setting, you must also enable \"Specify SharePoint Server URL and organization name\". This setting affects only OneDrive for Business sync functionality. It does not impact syncing team sites in SharePoint Online or SharePoint Server 2019.\r\n\r\nIf you enable this setting, you can select one of two options:\r\n\r\nSharePoint Online: The sync app will look first in SharePoint Online for a user's OneDrive. If the sync app is already configured with SharePoint Online for the user, it will attempt to configure a OneDrive for Business instance in SharePoint Server 2019 for that user.\r\n\r\nSharePoint Server 2019: The sync app will look first in SharePoint Server 2019 for a user's OneDrive for Business. If the sync app is already configured with SharePoint Server 2019 for the user, it will attempt to configure a OneDrive instance in SharePoint Online for that user.\r\n\r\nIf you disable or do not configure this setting, the sync app will look first in SharePoint Online for the user's OneDrive.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_1","displayName":"Enabled","description":null,"helpText":null}]},"4292546e3646296b":{"id":"device_vendor_msft_policy_config_system_allowfontproviders","displayName":"Allow Font Providers","description":"Boolean policy setting that determines whether Windows is allowed to download fonts and font catalog data from an online font provider. If you enable this setting, Windows periodically queries an online font provider to determine whether a new font catalog is available. Windows may also download font data if needed to format or render text. If you disable this policy setting, Windows does not connect to an online font provider and only enumerates locally-installed fonts. This MDM setting corresponds to the EnableFontProviders Group Policy setting. If both the Group Policy and the MDM settings are configured, the group policy setting takes precedence. If neither is configured, the behavior depends on a DisableFontProviders registry value. In server editions, this registry value is set to 1 by default, so the default behavior is false (disabled). In all other editions, the registry value is not set by default, so the default behavior is true (enabled). This setting is used by lower-level components for text display and fond handling and has not direct effect on web browsers, which may download web fonts used in web content. NoteReboot is required after setting the policy; alternatively you can stop and restart the FontCache service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#allowfontproviders"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_allowfontproviders_0","displayName":"Not allowed. No traffic to fs.microsoft.com and only locally installed fonts are available.","description":"Not allowed. No traffic to fs.microsoft.com and only locally installed fonts are available.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowfontproviders_1","displayName":"Allowed. There may be network traffic to fs.microsoft.com and downloadable fonts are available to apps that support them.","description":"Allowed. There may be network traffic to fs.microsoft.com and downloadable fonts are available to apps that support them.","helpText":null}]},"424967f5e3d7b767":{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautorebootforqualityupdates","displayName":"Configure Deadline No Auto Reboot For Quality Updates","description":"When enabled, devices will not automatically restart outside of active hours until the deadline and grace period have expired for quality updates, even if an update is ready for restart. When disabled, an automatic restart may be attempted outside of active hours after update is ready for restart before the deadline is reached. Takes effect only if Update/ConfigureDeadlineForQualityUpdates is configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlinenoautorebootforqualityupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautorebootforqualityupdates_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautorebootforqualityupdates_1","displayName":"Enabled.","description":"Enabled.","helpText":null}]},"4278f9b7080ae529":{"id":"device_vendor_msft_policy_config_update_scheduledinstallthirdweek","displayName":"Scheduled Install Third Week","description":"Enables the IT admin to schedule the update installation on the third week of the month. Value type is integer. Supported values:0 - no update in the schedule1 - update is scheduled every third week of the month","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduledinstallthirdweek"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_scheduledinstallthirdweek_0","displayName":"no update in the schedule","description":"no update in the schedule","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduledinstallthirdweek_1","displayName":"update is scheduled every third week of the month","description":"update is scheduled every third week of the month","helpText":null}]},"42693436fe751721":{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings","displayName":"Print Settings","description":"This policy setting allows you to decide how the print functionality behaves while in Microsoft Defender Application Guard.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsDefenderApplicationGuard-csp/"],"categoryId":"cd55f347-a417-4fe9-83ee-8f1f40ac5eb0","categoryName":null,"options":[{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_0","displayName":"Disable all print functionality","description":"Disables all print functionality.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_1","displayName":"Enable XPS printing","description":"Enables only XPS printing.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_2","displayName":"Enable PDF printing","description":"Enables only PDF printing.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_4","displayName":"Enable local printing","description":"Enables only local printing.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_printingsettings_8","displayName":"Enable network printing","description":"Enables only network printing.","helpText":null}]},"429757cff02ebb2e":{"id":"mathsettings_calculator_mathnotesmode","displayName":"Math Notes Mode","description":"If present, configures the Math Notes mode of the calculator. If not present, math notes mode is enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":null},"428249cfe4bceb71":{"id":"user_vendor_msft_policy_config_admx_explorer_turnoffspianimations","displayName":"Turn off common control and window animations (User)","description":"This policy is similar to settings directly available to computer users. Disabling animations can improve usability for users with some visual disabilities as well as improving performance and battery life in some scenarios.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-turnoffspianimations"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_explorer_turnoffspianimations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_explorer_turnoffspianimations_1","displayName":"Enabled","description":null,"helpText":null}]},"4204d5382618d3a6":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_publickey","displayName":"Public Key Policies (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-publickey"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_publickey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_publickey_1","displayName":"Enabled","description":null,"helpText":null}]},"4272c91dd3be7718":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_customgoofflineactions_1_lbl_customgoofflineactionslist","displayName":"Customize actions: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"42f5020b1ca739b5":{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_1","displayName":"Custom Classes: Deny read access (User)","description":"This policy setting denies read access to custom removable storage classes.\r\n\r\nIf you enable this policy setting, read access is denied to these removable storage classes.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to these removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-customclasses-denyread-access-1"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denyread_access_1_1","displayName":"Enabled","description":null,"helpText":null}]},"4247a46cf7819795":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1","displayName":"Set time limit for active Remote Desktop Services sessions (User)","description":"This policy setting allows you to specify the maximum amount of time that a Remote Desktop Services session can be active before it is automatically disconnected.\r\n\r\nIf you enable this policy setting, you must select the desired time limit in the Active session limit list. Remote Desktop Services will automatically disconnect active sessions after the specified amount of time. The user receives a warning two minutes before the Remote Desktop Services session disconnects, which allows the user to save open files and close programs. If you have a console session, active session time limits do not apply.\r\n\r\nIf you disable or do not configure this policy setting, this policy setting is not specified at the Group Policy level. By default, Remote Desktop Services allows sessions to remain active for an unlimited amount of time. \r\n\r\nIf you want Remote Desktop Services to end instead of disconnect a session when the time limit is reached, you can configure the policy setting Computer Configuration\\Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Session Time Limits\\End session when time limits are reached.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the Computer Configuration policy setting takes precedence.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-sessions-limits-1"],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_1","displayName":"Enabled","description":null,"helpText":null}]},"424be66e5e450626":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_udpcheckbox","displayName":"UDP (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_udpcheckbox_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_udpcheckbox_1","displayName":"True","description":null,"helpText":null}]},"423729967ffd6852":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally","displayName":"Always Open PDF files externally (User)","description":"Setting the policy to Enabled turns the internal PDF viewer off in Google Chrome, treats PDF files as a download, and lets users open PDFs with the default application.\r\n\r\nSetting the policy to Disabled means that unless users turns off the PDF plugin, it will open PDF files.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, users can choose whether to open PDF externally or not.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alwaysopenpdfexternally_1","displayName":"Enabled","description":null,"helpText":null}]},"4292f9eb35c74642":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault","displayName":"Print PDF as Image Default (User)","description":"Controls if Google Chrome makes the Print as image option default to set when printing PDFs.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available.\r\n\r\nFor Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printpdfasimagedefault_1","displayName":"Enabled","description":null,"helpText":null}]},"42d6585a6aef14a8":{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode","displayName":"Turn on 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows (User)","description":"This policy setting determines whether Internet Explorer 11 uses 64-bit processes (for greater security) or 32-bit processes (for greater compatibility) when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nImportant: Some ActiveX controls and toolbars may not be available when 64-bit processes are used.\n\nIf you enable this policy setting, Internet Explorer 11 will use 64-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nIf you disable this policy setting, Internet Explorer 11 will use 32-bit tab processes when running in Enhanced Protected Mode on 64-bit versions of Windows.\n\nIf you don't configure this policy setting, users can turn this feature on or off using Internet Explorer settings. This feature is turned off by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableprocessesinenhancedprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableprocessesinenhancedprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"420e918428810749":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions) (User)","description":"Enables user-level installation of native messaging hosts.\r\n\r\nIf you disable this policy, Microsoft Edge will only use native messaging hosts installed on the system level.\r\n\r\nBy default, if you don't configure this policy, Microsoft Edge will allow usage of user-level native messaging hosts.","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},"42aa7743e18864e8":{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites (User)","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or it will\r\nfail. Users' personal settings may allow certain origins to call this API\r\nwithout a prior user gesture.\r\n\r\nThis policy supersedes users' personal settings and blocks matching origins\r\nfrom calling the API without a prior user gesture.\r\n\r\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\nWildcards (*) are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy or user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~contentsettings_automaticfullscreenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"427897a05a0a6acd":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled","displayName":"Enable additional search box in browser (User)","description":"A search box is an additional text input field located next to the address bar in a web browser. It allows users to perform web searches directly from the browser interface.\r\n\r\nIf you enable or don't configure this policy, the search box will be visible and available for use.\r\nUsers can toggle the search box in Edge Settings page edge://settings/appearance#SearchBoxInToolbar.\r\n\r\nIf you disable this policy, search box will not be visible, and users will have to use the address bar or navigate to a search engine to perform web searches.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_additionalsearchboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"424626133705b417":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist","displayName":"Block access to a list of URLs in InPrivate mode. (User)","description":"This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge.\r\n\r\nAdministrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nIf both 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.) and 'InPrivateModeUrlAllowlist' (Allow access to a list of URLs in InPrivate mode.) are configured, the allowlist takes precedence.\r\n- URLs that match the allowlist are allowed.\r\n- URLs that match the blocklist but not the allowlist are blocked.\r\n- URLs that match neither list follow the behavior defined by the general 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs) policies.\r\n\r\nIf 'InPrivateModeUrlAllowlist' is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.\r\n\r\nIf 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) and 'InPrivateModeUrlAllowlist' is configured, InPrivate mode is available only for URLs that match the allowlist.\r\n\r\nThis policy applies only to InPrivate mode. To block URLs across all browsing modes, use 'URLBlocklist'.\r\n\r\nThis policy supports up to 1000 entries.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"4259c8ba2367d457":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies","displayName":"Allow importing of Cookies (User)","description":"Allows users to import Cookies from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Cookies aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Cookies are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importcookies_1","displayName":"Enabled","description":null,"helpText":null}]},"42520fc891fc9982":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode","displayName":"Configure when efficiency mode should become active (User)","description":"This policy setting lets you configure when efficiency mode will become active. By default, efficiency mode is set to 'BalancedSavings'. On devices with no battery, the default is for efficiency mode to never become active.\r\n\r\nIndividual sites may be blocked from participating in efficiency mode by configuring the policy 'SleepingTabsBlockedForUrls' (Block sleeping tabs on specific sites).\r\n\r\nSet this policy to 'AlwaysActive' and efficiency mode will always be active.\r\n\r\nSet this policy to 'NeverActive' and efficiency mode will never become active.\r\n\r\nSet this policy to 'ActiveWhenUnplugged' and efficiency mode will become active when the device is unplugged.\r\n\r\nSet this policy to 'ActiveWhenUnpluggedBatteryLow' and efficiency mode will become active when the device is unplugged and the battery is low.\r\n\r\nSet this policy to 'BalancedSavings' and when the device is unplugged, efficiency mode will take moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode will take additional steps to save battery.\r\n\r\nSet this policy to 'MaximumSavings' and when the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nIf the device does not have a battery, efficiency mode will never become active in any mode other than 'AlwaysActive' unless the setting or 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is enabled.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921\r\n\r\nPolicy options mapping:\r\n\r\n* AlwaysActive (0) = Efficiency mode is always active\r\n\r\n* NeverActive (1) = Efficiency mode is never active\r\n\r\n* ActiveWhenUnplugged (2) = Efficiency mode is active when the device is unplugged\r\n\r\n* ActiveWhenUnpluggedBatteryLow (3) = Efficiency mode is active when the device is unplugged and the battery is low\r\n\r\n* BalancedSavings (4) = When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\n* MaximumSavings (5) = When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~performance_efficiencymode_1","displayName":"Enabled","description":null,"helpText":null}]},"4234dc94170fe9b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicemajorversion0","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"42ca7e879fc9c218":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd","displayName":"Replace Label - Work Address (User)","description":"This policy setting allows you to change or remove the 13th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceworkadd_1","displayName":"Enabled","description":null,"helpText":null}]},"425b04e308b456da":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowpath434","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"429e16639013a85e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties","displayName":"Encrypt document properties (User)","description":"This policy setting allows you configure if the document properties are encrypted. This applies to OLE documents (Office 97-2003 compatible) if the application is configured for CAPI RC4.\r\n\r\nIf you enable this policy setting, the document properties will be encrypted.\r\n\r\nIf you disable or do not configure this policy setting, the document properties will not be encrypted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_encryptdocumentproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"429aa3f6dea16447":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_pathcolon02","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"42135a3f2d2e9d7f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc05_l_pathcolon05","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"4270ae09071d2417":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11","displayName":"Unsafe Location #11 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc11_1","displayName":"Enabled","description":null,"helpText":null}]},"429d17208dcb6682":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles","displayName":"Set Workgroup path for label page size update files (User)","description":"This policy setting allows you to specify the Workgroup path for the label page size update files. This is useful if the organization has a centralized template depot. \r\n\r\nIf you enable this policy setting, you may enter the path to the PSX update files.\r\n\r\nIf you disable or do not configure this policy setting, there is no Workgroup path for the shared label templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"421d0708cb03c389":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406","displayName":"PowerPoint: web page format compatibility (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f56761a-8e8b-4788-a589-a73ab91818e6","categoryName":"Web Archives","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_2","displayName":"All browsers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_1","displayName":"Windows Internet Explorer 4.0 or later","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_webarchives_l_powerpointwebpageformatcompatibility_l_powerpointwebpageformatcompatibility406_0","displayName":"Based on installed browsers","description":null,"helpText":null}]},"42bb5e9f1aae0284":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},"42fcecb52c4da978":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance","displayName":"Set importance (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_1","displayName":"Enabled","description":null,"helpText":null}]},"42b8d77e10b9d271":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview","displayName":"Configure Cross Folder Content in conversation view (User)","description":"This policy setting controls how conversation view in Outlook is loaded and whether Cross Folder Content is turned on or off.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n- On and cross-store (default): Cross Folder Content is on and cross-store. Data will be pulled from all connected data files whether they are cached or online. \r\n- Off: Cross Folder Content is turned off.\r\n- On and current: Cross Folder Content is on, but data is only pulled from the current data file. \r\n- On and local: Cross Folder Content is on, but data is only pulled from the current data file and any other local data files.\r\n\r\nIf you disable or do not configure this policy setting, Cross Folder Content will be turned on and pulled from all connected data files.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_configurecrossfoldercontentinconversationview_1","displayName":"Enabled","description":null,"helpText":null}]},"420e7ce8098b8fff":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2","displayName":"Allow Active X One Off Forms (User)","description":"By default, third-party ActiveX controls are not allowed to run in one-off forms in Outlook. You can change this behavior so that Safe Controls (Microsoft Forms 2.0 controls and the Outlook Recipient and Body controls) are allowed in one-off forms, or so that all ActiveX controls are allowed to run.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"42790accd3da55c7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver","displayName":"Enter seconds to wait to download changes from server (User)","description":"Specifies number of seconds to wait before downloading changes from the Exchange server.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_1","displayName":"Enabled","description":null,"helpText":null}]},"426373cafdfbd463":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel","displayName":"Stop checking to ensure heading styles do not skip style level (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that headings in a document are used in order.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that headings in a document are used in order.\r\n\r\nIf you disable or do not configure this policy setting, the ordering of headings in a document will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingheadingstylesdonotskipstylelevel_1","displayName":"Enabled","description":null,"helpText":null}]},"422f05e21ff4896d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},"42533ba1c56a255e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility","displayName":"Specify encryption compatibility (User)","description":"This policy setting allows you to specify the encrypted database compatibility.\r\n\r\nIf you enable this policy setting, the compatibility format specified will be applied during encryption for new files\r\n- Use legacy format\r\n- Use next generation format\r\n- All files save with next generation format\r\n\r\nIf you disable or do not configure this policy setting, the default setting, \"Use next generation format,\" will be applied.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_specifyencryptioncompatibility_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/46.json b/public/intune-definitions/46.json index d6e73a2f1084..0e9985e5c260 100644 --- a/public/intune-definitions/46.json +++ b/public/intune-definitions/46.json @@ -1 +1 @@ -{"46071188eea24b2e":{"id":"com.apple.assetcache.managed_autoactivation","displayName":"Auto Activation","description":"If true, automatically activates the content cache when possible and prevents it from being disabled. If the Allow Content Caching restriction is set to false, Auto Activation is also false.\r\nRemoving a profile that set Auto Activation to true does not deactivate the Content Cache.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_autoactivation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_autoactivation_true","displayName":"True","description":null,"helpText":null}]},"46258851b31a1cdb":{"id":"com.apple.discrecording_com.apple.discrecording","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","categoryName":"Media Management Disc Burning","options":null},"468d312b7799ea04":{"id":"com.apple.font_com.apple.font","displayName":"com.apple.font","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5401711f-292a-487a-be18-f99593a0477c","categoryName":"Font","options":null},"463fe611a35e1e25":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_lcid","displayName":"Microsoft Defender LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"46158a3831e1fecb":{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app","displayName":"Microsoft Auto Update","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"460b4b8c00119ca1":{"id":"com.apple.mcx_enableguestaccount","displayName":"Enable Guest Account","description":"If true, enables the guest account.","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":[{"id":"com.apple.mcx_enableguestaccount_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_enableguestaccount_true","displayName":"True","description":null,"helpText":null}]},"4632a7ec10200389":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"4619ac725ed108b5":{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled","displayName":"Re-enable the Event.path API until Microsoft Edge version 115 (Obsolete)","description":"Starting in Microsoft Edge version 109, the nonstandard API Event.path is removed to improve web compatibility. This policy re-enables the API until version 115.\n\nIf you enable this policy, the Event.path API is available.\n\nIf you disable this policy, the Event.path API is unavailable.\n\nIf you don't configure this policy, the Event.path API is in the following default states: available before version 109, and unavailable in version 109 to version 114.\n\nThis policy is made obsolete after Microsoft Edge version 115.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"467344a6f6aa6ddc":{"id":"com.microsoft.edge.mamedgeappconfigsettings.geolocationblockedforurls","displayName":"Block geolocation on these sites","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\n\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\n\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\n\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"46237acc98a830d9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingpapersizedefault","displayName":"Default printing page size","description":"Overrides default printing page size.\n\nName should contain one of the listed formats or 'custom' if required paper size isn't in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\n\nIf the page size is unavailable on the printer chosen by the user, this policy is ignored.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"46db2af163a1fbfb":{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn","displayName":"Invalid certificate name (CN)","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn_1","displayName":"True","description":null,"helpText":null}]},"46c3e64a73369b86":{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx","displayName":"Installation Policy for unsigned ActiveX control","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx_0","displayName":"Don't install","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx_1","displayName":"Prompt the user","description":null,"helpText":null}]},"466fc46a7028d768":{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache","displayName":"Do not allow the BITS client to use Windows Branch Cache","description":"This setting affects whether the BITS client is allowed to use Windows Branch Cache. If the Windows Branch Cache component is installed and enabled on a computer, BITS jobs on that computer can use Windows Branch Cache by default.\r\n\r\n If you enable this policy setting, the BITS client does not use Windows Branch Cache.\r\n\r\n If you disable or do not configure this policy setting, the BITS client uses Windows Branch Cache.\r\n\r\n Note: This policy setting does not affect the use of Windows Branch Cache by applications other than BITS. This policy setting does not apply to BITS transfers over SMB. This setting has no effect if the computer's administrative settings for Windows Branch Cache disable its use entirely.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-disablebranchcache"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache_1","displayName":"Enabled","description":null,"helpText":null}]},"468b7df648681675":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto","displayName":"Allow cryptography algorithms compatible with Windows NT 4.0","description":"This policy setting controls whether the Net Logon service will allow the use of older cryptography algorithms that are used in Windows NT 4.0. The cryptography algorithms used in Windows NT 4.0 and earlier are not as secure as newer algorithms used in Windows 2000 or later, including this version of Windows.\r\n\r\nBy default, Net Logon will not allow the older cryptography algorithms to be used and will not include them in the negotiation of cryptography algorithms. Therefore, computers running Windows NT 4.0 will not be able to establish a connection to this domain controller.\r\n \r\nIf you enable this policy setting, Net Logon will allow the negotiation and use of older cryptography algorithms compatible with Windows NT 4.0. However, using the older algorithms represents a potential security risk.\r\n\r\nIf you disable this policy setting, Net Logon will not allow the negotiation and use of older cryptography algorithms. \r\n\r\nIf you do not configure this policy setting, Net Logon will not allow the negotiation and use of older cryptography algorithms.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allownt4crypto"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto_1","displayName":"Enabled","description":null,"helpText":null}]},"462ca0161e852bb0":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns","displayName":"Specify dynamic registration of the DC Locator DNS Records","description":"This policy setting determines if dynamic registration of the domain controller (DC) locator DNS resource records is enabled. These DNS records are dynamically registered by the Net Logon service and are used by the Locator algorithm to locate the DC.\r\n\r\nIf you enable this policy setting, DCs to which this setting is applied dynamically register DC Locator DNS resource records through dynamic DNS update-enabled network connections.\r\n\r\nIf you disable this policy setting, DCs will not register DC Locator DNS resource records.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-usedynamicdns"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns_1","displayName":"Enabled","description":null,"helpText":null}]},"462dae51a5c00996":{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_refreshrate","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":null},"46450fb0ab3b182b":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp","displayName":"Always show desktop on connection","description":"This policy setting determines whether the desktop is always displayed after a client connects to a remote computer or an initial program can run. It can be used to require that the desktop be displayed after a client connects to a remote computer, even if an initial program is already specified in the default user profile, Remote Desktop Connection, Remote Desktop Services client, or through Group Policy.\r\n\r\nIf you enable this policy setting, the desktop is always displayed when a client connects to a remote computer. This policy setting overrides any initial program policy settings.\r\n\r\nIf you disable or do not configure this policy setting, an initial program can be specified that runs on the remote computer after the client connects to the remote computer. If an initial program is not specified, the desktop is always displayed on the remote computer after the client connects to the remote computer.\r\n\r\nNote: If this policy setting is enabled, then the \"Start a program on connection\" policy setting is ignored.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-turnoff-singleapp"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp_1","displayName":"Enabled","description":null,"helpText":null}]},"46f6baa5e7f540f7":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4","displayName":"Publishing Server 4 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver4"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_1","displayName":"Enabled","description":null,"helpText":null}]},"46213c014a5a6d22":{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode","displayName":"Account Logon Logoff Audit I Psec Quick Mode","description":"This policy setting allows you to audit events generated by Internet Key Exchange protocol (IKE) and Authenticated Internet Protocol (AuthIP) during Quick Mode negotiations. If you configure this policy setting, an audit event is generated during an IPsec Quick Mode negotiation. Success audits record successful attempts and Failure audits record unsuccessful attempts.If you do not configure this policy setting, no audit event is generated during an IPsec Quick Mode negotiation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditipsecquickmode"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"465511aab20489c4":{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization","displayName":"Allow Search Engine Customization","description":"Allow search engine customization for MDM enrolled devices. Users can change their default search engine. If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge Settings. If this setting is disabled, users will be unable to add search engines or change the default used in the address bar. This policy will only apply on domain joined machines or when the device is MDM enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsearchenginecustomization"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"46cda2521c3073a8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Controls the mode of DNS-over-HTTPS (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"46fcf62c3c7456a0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled","displayName":"Enables managed extensions to use the Enterprise Hardware Platform API","description":"Setting the policy to True lets extensions installed by enterprise policy use the Enterprise Hardware Platform API.\r\n\r\nSetting the policy to False or leaving it unset prevents extensions from using this API.\r\n\r\nNote: This policy also applies to component extensions, such as the Hangout Services extension.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"465523ecf4d27873":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled","displayName":"Enable Media Recommendations","description":"By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"469334794ae2c3cf":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended","displayName":"Enable AutoFill","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"de643352-007f-4a47-8c83-d75a79516b39","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"464eeca9691d26df":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled","displayName":"Force WebSQL in third-party contexts to be re-enabled.","description":"WebSQL in third-party contexts (e.g., cross-site iframes) is off by default as of M97 and will be fully removed in M101.\r\nIf this policy is set to false or unset, WebSQL in third party contexts will remain off.\r\nIf this policy is set to true, WebSQL in third-party contexts will be re-enabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"46fe6ed4aa7956a3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls","displayName":"Allow insecure content on these sites","description":"Allows you to set a list of url patterns that specify sites which are allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, and users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4615af69b3fb74f5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername","displayName":"Default search provider name","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_1","displayName":"Enabled","description":null,"helpText":null}]},"46ccbd00b8f10b88":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"463ca614cd47fc0f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended","displayName":"Enable origin-keyed process isolation by default.","description":"Enables origin-keyed process isolation for most pages (i.e., those assigned to an origin-keyed agent cluster by default). This improves security but also increases the number of processes created. Users are allowed to override the set policy value via the command-line flags or chrome://flags (both to turn this feature on or off).\r\n\r\nSetting the policy to Enabled results in most origins being isolated, even from other origins in the same site. See also the IsolateOrigins and SitePerProcess policies.\r\n\r\nSetting the policy to Disabled results in no origins being isolated from the rest of their site unless an origin explicitly asks to.\r\n\r\nNot setting the policy results in the browser determining which origins to isolate and when to isolate them.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"46d6ae8c50289af8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled","displayName":"Enable strict MIME type checking for worker scripts","description":"This policy enables strict MIME type checking for worker scripts.\r\n\r\nWhen enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour. Worker scripts with legacy MIME types will be rejected.\r\n\r\nWhen disabled, then worker scripts will use lax MIME type checking, so that worker scripts with legacy MIME types, e.g. text/ascii, will continue to be loaded and executed.\r\n\r\nBrowsers traditionally used lax MIME type checking, so that resources with a number of legacy MIME types were supported. E.g. for JavaScript resources, text/ascii is a legacy supported MIME type. This may cause security issues, by allowing to load resources as scripts that were never intended to be used as such. Chrome will transition to use strict MIME type checking in the near future. The enabled policy will track the default behaviour. Disabling this policy allows administrators to retain the legacy behaviour, if desired.\r\n\r\nSee https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage for details about JavaScript / ECMAScript media types.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"460f775e952b336b":{"id":"device_vendor_msft_policy_config_deviceguard_requireplatformsecurityfeatures","displayName":"Require Platform Security Features","description":"Select Platform Security Level: 1 - Turns on VBS with Secure Boot, 3 - Turns on VBS with Secure Boot and DMA. DMA requires hardware support.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#requireplatformsecurityfeatures"],"categoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","categoryName":"Device Guard","options":[{"id":"device_vendor_msft_policy_config_deviceguard_requireplatformsecurityfeatures_1","displayName":"Turns on VBS with Secure Boot.","description":"Turns on VBS with Secure Boot.","helpText":null},{"id":"device_vendor_msft_policy_config_deviceguard_requireplatformsecurityfeatures_3","displayName":"Turns on VBS with Secure Boot and direct memory access (DMA). DMA requires hardware support.","description":"Turns on VBS with Secure Boot and direct memory access (DMA). DMA requires hardware support.","helpText":null}]},"461edc316726a6ec":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachcount_profilesreattachcount","displayName":"Reattach Count (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"46a14458a4114975":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page","description":"By default, there are two Bing chat entry-points on new tab page. One is inside the new tab page search box, and one is in the Bing Autosuggest drawer on-click.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge Enterprise new tab page and the Bing chat entry-points are there for users.\r\n\r\nIf you disable this policy, Bing chat entry-points don't appear on the new tab page.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"461b49ad7c5836ef":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled","displayName":"Control whether storage quota APIs will return static values","description":"Controls how the Storage Quota APIs report the available quota to websites.\r\n\r\nWhen enabled, the Storage Quota APIs return a static quota value equal to the current usage plus the smaller of 10 GiB or the device's total storage rounded up to the nearest 1 GiB.\r\n\r\nWhen disabled, the Storage Quota APIs return a dynamic quota value that reflects the actual available device storage.\r\n\r\nWhen unset, the browser uses the default platform behavior.\r\n\r\nThis policy does not affect sites with unlimited storage permissions or enforced quota settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"467c843e2186f823":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 120.\r\n\r\nIf you enable this policy, WebRTC peer connections can downgrade to obsolete\r\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\r\nIf you disable or don't set this policy, these TLS/DTLS versions are\r\ndisabled.\r\n\r\nThis policy was removed in Microsoft Edge 121 and is ignored if set.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},"469c30ae0a399d0e":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended","displayName":"Enable Microsoft Defender SmartScreen DNS requests","description":"This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen will make DNS requests.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen will not make any DNS requests.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"46c38c0b8ea71956":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werarchive_1_werarchivebehavior","displayName":"Archive behavior: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werarchive_1_werarchivebehavior_2","displayName":"Store all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werarchive_1_werarchivebehavior_1","displayName":"Store parameters only","description":null,"helpText":null}]},"46c64ec7bfe00d3b":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_preventcddvdmetadataretrieval","displayName":"Prevent CD and DVD Media Information Retrieval (User)","description":"This policy setting allows you to prevent media information for CDs and DVDs from being retrieved from the Internet.\r\n\r\nIf you enable this policy setting, the Player is prevented from automatically obtaining media information from the Internet for CDs and DVDs played by users. In addition, the Retrieve media information for CDs and DVDs from the Internet check box on the Privacy Options tab in the first use dialog box and on the Privacy tab in the Player are not selected and are not available.\r\n\r\nIf you disable or do not configure this policy setting, users can change the setting of the Retrieve media information for CDs and DVDs from the Internet check box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-preventcddvdmetadataretrieval"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_preventcddvdmetadataretrieval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_preventcddvdmetadataretrieval_1","displayName":"Enabled","description":null,"helpText":null}]},"4669079a0c787d22":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability","displayName":"Control where Developer Tools can be used (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_0","displayName":"Disallow usage of the Developer Tools on extensions installed by enterprise policy, allow usage of the Developer Tools in other contexts","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_1","displayName":"Allow usage of the Developer Tools","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_2","displayName":"Disallow usage of the Developer Tools","description":null,"helpText":null}]},"4675789a2396e16f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter","displayName":"Move selection after Enter (User)","description":"Enabling this policy selects the Advanced (Editing Options) user option to \"After pressing Enter, move selection\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter_1","displayName":"Enabled","description":null,"helpText":null}]},"4667e731482292f4":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles","displayName":"Excel add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"463ffb41f9d4426b":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"466f6b816f76b13b":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400","displayName":"Allow active scripting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_1","displayName":"Prompt","description":null,"helpText":null}]},"463a9eb4b29a97c7":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy_maxconnectionsperproxy","displayName":"Maximum number of concurrent connections to the proxy server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"465d27531bba77c5":{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132.\r\n\r\nThe :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge in order to comply with changes that have been made in Firefox and Safari. This policy lets the deprecated syntax to be used until Stable 132.\r\n\r\nThis deprecation might break some Microsoft Edge-only websites that use the deprecated :--foo syntax.\r\n\r\nIf you enable this policy, the deprecated syntax will be enabled.\r\n\r\nIf you disable this policy or don't set it, the deprecated syntax will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"466af048983ad54d":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended","displayName":"Configure Edge Scareware Blocker Protection (User)","description":"This policy setting allows administrators to control whether Microsoft Edge enables the Scareware Blocker, an AI-powered feature that provides warning messages to help protect users from potential tech scams.\r\n\r\nIf this policy is enabled, Edge Scareware Blocker will warn users of potential tech scams.\r\n\r\nIf this policy is disabled, Edge Scareware Blocker will not warn users of potential tech scams.\r\n\r\nIf this policy is not configured, Edge Scareware Blocker will not warn users of potential tech scams, but users can choose warnings in settings.\r\n\r\nBy configuring this policy, administrators determine whether users receive proactive scam warnings or must manually enable them.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"463e3233f1c58b8e":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_loopbacknetworkblockedforurlsdesc","displayName":"Block sites from making network requests to the local device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"46709da38ff6371a":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls","displayName":"Allow access to sensors on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policy (if there is a match), the 'DefaultSensorsSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'SensorsBlockedForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"46a7702502dd453d":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended","displayName":"Enable Password reveal button (User)","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\r\n\r\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\r\n\r\nIf you disable this policy, the browser user setting won't display the password reveal button.\r\n\r\nFor accessibility, users can change the browser setting from the default policy.\r\n\r\nThis policy only affects the browser password reveal button, it doesn't affect websites' custom reveal buttons.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"46c7d23ea2f79804":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment_l_onlycontaininganattachment356","displayName":"Only containing an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},"46fbab7bd4d7be46":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome_l_homemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"461f556c8eef1d34":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy_l_enteraurl","displayName":"Enter a URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},"46da940d79ae8738":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"46b882ceaa0e910b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_datecolon315","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"460234b9a24eae39":{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier","displayName":"Multiplier for Presence sync interval for notebooks stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between polls to SharePoint to determine active users of notebooks. OneNote will sync notebooks at a faster rate when other users are interacting with a notebook.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently to determine if there are other users currently interacting with notebooks. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow detection of concurrent users in notebooks but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will poll for active users of notebooks at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},"4696c7e4ef558eba":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize","displayName":"Legacy PST: Absolute maximum size (User)","description":"Specifies the maximum allowable size (in bytes) for an Outlook 97-2002 Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_1","displayName":"Enabled","description":null,"helpText":null}]},"46a026faae795239":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext","displayName":"Enable down-level meeting text (User)","description":"This policy setting controls whether Outlook automatically displays the meeting time and location in the meeting request body.\r\n\r\nIf you enable this policy setting, Outlook automatically displays the meeting time and location in the meeting request body.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not automatically display the meeting time and location in the meeting request body.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext_1","displayName":"Enabled","description":null,"helpText":null}]},"461cf25a307c769c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor","displayName":"Change color used to highlight search matches (User)","description":"By default, search matches are highlighted in yellow. This setting allows you to change the color used for highlighting matches in search results.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_1","displayName":"Enabled","description":null,"helpText":null}]},"4612ffd539f51931":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority","displayName":"Required Certificate Authority (User)","description":"This policy setting enables you to designate a required certificate authority for Outlook to use for encryption and digital signatures.\r\n\r\nIf you enable this policy setting, you can specify a required certificate authority by entering an X.509 distinguished name in the text field that is provided. The name must conform to the X.509 certificate format exactly. For example:\r\n\r\nCN=WoodgroveBankCA, DC=WoodgroveBank, DC=com\r\n\r\nIf you disable or do not configure this policy setting, Outlook trusts any certificate authorities that are represented by certificates in the Trusted Root Certification Authorities store on users' computers.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_1","displayName":"Enabled","description":null,"helpText":null}]},"46ababde4872c5b4":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast","displayName":"Stop checking for text color contrast (User)","description":"This policy setting prevents the Accessibility Checker from flagging text with low contrast and readability.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging text with low contrast and readability.\r\n\r\nIf you disable or do not configure this policy setting, text will be scanned for color contrast and the results will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast_1","displayName":"Enabled","description":null,"helpText":null}]},"46e3dd54c3182581":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"4677268328878ab4":{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience","displayName":"Disable Privacy Experience (User)","description":"Enabling this policy prevents the privacy experience from launching during user logon for new and upgraded users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#disableprivacyexperience"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience_0","displayName":"Disabled","description":"Allow the 'choose privacy settings for your device' screen for a new user during their first logon or when an existing user logs in for the first time after an upgrade.","helpText":null},{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience_1","displayName":"Enabled","description":"Do not allow the 'choose privacy settings for your device' screen when a new user logs in or an existing user logs in for the first time after an upgrade.","helpText":null}]},"46459ba0ea65813a":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},"46b2903819c9ef13":{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps","displayName":"Hide Frequently Used Apps (User)","description":"Enabling this policy hides the most used apps from appearing on the start menu and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidefrequentlyusedapps"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"4657bf0652024cf6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting","displayName":"Define styles based on your formatting (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"468206ce427a3131":{"id":"com.android.devicerestrictionpolicy.stayonpluggedmodes","displayName":"Screen on while device plugged in","description":"Select the battery charging modes for which the device screen stays on while plugged in. When the device is connected using one of the selected power sources, the screen will not turn off automatically. 'AC' keeps the screen on when the device is charging over an AC adapter. 'USB' keeps the screen on when the device is charging over USB. 'Wireless' keeps the screen on when the device is charging wirelessly. When '0 selected' (no modes chosen), the device follows its default screen timeout behavior. When using this setting, it is recommended to clear the 'Time to lock screen' setting so that the device doesn't lock itself while it stays on. Available for fully managed and dedicated devices.","helpText":"Select the power sources that should keep the screen on while charging. Allowed values: AC, USB, WIRELESS. Wireless requires Android 8.1 or later. Selections are combined across policies.","infoUrls":[],"categoryId":"95000481-a8b5-4e18-99e3-367666aee03f","categoryName":"Power","options":[{"id":"com.android.devicerestrictionpolicy.stayonpluggedmodes_ac","displayName":"AC","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.stayonpluggedmodes_usb","displayName":"USB","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.stayonpluggedmodes_wireless","displayName":"Wireless","description":null,"helpText":null}]},"46071188eea24b2e":{"id":"com.apple.assetcache.managed_autoactivation","displayName":"Auto Activation","description":"If true, automatically activates the content cache when possible and prevents it from being disabled. If the Allow Content Caching restriction is set to false, Auto Activation is also false.\r\nRemoving a profile that set Auto Activation to true does not deactivate the Content Cache.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_autoactivation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_autoactivation_true","displayName":"True","description":null,"helpText":null}]},"46258851b31a1cdb":{"id":"com.apple.discrecording_com.apple.discrecording","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","categoryName":"Media Management Disc Burning","options":null},"468d312b7799ea04":{"id":"com.apple.font_com.apple.font","displayName":"com.apple.font","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5401711f-292a-487a-be18-f99593a0477c","categoryName":"Font","options":null},"463fe611a35e1e25":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender.app_lcid","displayName":"Microsoft Defender LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"46158a3831e1fecb":{"id":"com.apple.managedclient.preferences_applicationssystem_library_application support_microsoft_mau2.0_microsoft autoupdate.app","displayName":"Microsoft Auto Update","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"460b4b8c00119ca1":{"id":"com.apple.mcx_enableguestaccount","displayName":"Enable Guest Account","description":"If true, enables the guest account.","helpText":null,"infoUrls":[],"categoryId":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","categoryName":"Accounts","options":[{"id":"com.apple.mcx_enableguestaccount_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_enableguestaccount_true","displayName":"True","description":null,"helpText":null}]},"4632a7ec10200389":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappbundles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"4619ac725ed108b5":{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled","displayName":"Re-enable the Event.path API until Microsoft Edge version 115 (Obsolete)","description":"Starting in Microsoft Edge version 109, the nonstandard API Event.path is removed to improve web compatibility. This policy re-enables the API until version 115.\n\nIf you enable this policy, the Event.path API is available.\n\nIf you disable this policy, the Event.path API is unavailable.\n\nIf you don't configure this policy, the Event.path API is in the following default states: available before version 109, and unavailable in version 109 to version 114.\n\nThis policy is made obsolete after Microsoft Edge version 115.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.eventpathenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"467344a6f6aa6ddc":{"id":"com.microsoft.edge.mamedgeappconfigsettings.geolocationblockedforurls","displayName":"Block geolocation on these sites","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\n\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\n\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\n\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"46237acc98a830d9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingpapersizedefault","displayName":"Default printing page size","description":"Overrides default printing page size.\n\nName should contain one of the listed formats or 'custom' if required paper size isn't in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\n\nIf the page size is unavailable on the printer chosen by the user, this policy is ignored.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":null},"46db2af163a1fbfb":{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn","displayName":"Invalid certificate name (CN)","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_ignoreinvalidcn_1","displayName":"True","description":null,"helpText":null}]},"46c3e64a73369b86":{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx","displayName":"Installation Policy for unsigned ActiveX control","description":null,"helpText":"","infoUrls":[],"categoryId":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","categoryName":"ActiveX Installer Service","options":[{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx_0","displayName":"Don't install","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_activexinstallservice_axisurlzonepolicies_installunsignedocx_1","displayName":"Prompt the user","description":null,"helpText":null}]},"466fc46a7028d768":{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache","displayName":"Do not allow the BITS client to use Windows Branch Cache","description":"This setting affects whether the BITS client is allowed to use Windows Branch Cache. If the Windows Branch Cache component is installed and enabled on a computer, BITS jobs on that computer can use Windows Branch Cache by default.\r\n\r\n If you enable this policy setting, the BITS client does not use Windows Branch Cache.\r\n\r\n If you disable or do not configure this policy setting, the BITS client uses Windows Branch Cache.\r\n\r\n Note: This policy setting does not affect the use of Windows Branch Cache by applications other than BITS. This policy setting does not apply to BITS transfers over SMB. This setting has no effect if the computer's administrative settings for Windows Branch Cache disable its use entirely.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-disablebranchcache"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_disablebranchcache_1","displayName":"Enabled","description":null,"helpText":null}]},"468b7df648681675":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto","displayName":"Allow cryptography algorithms compatible with Windows NT 4.0","description":"This policy setting controls whether the Net Logon service will allow the use of older cryptography algorithms that are used in Windows NT 4.0. The cryptography algorithms used in Windows NT 4.0 and earlier are not as secure as newer algorithms used in Windows 2000 or later, including this version of Windows.\r\n\r\nBy default, Net Logon will not allow the older cryptography algorithms to be used and will not include them in the negotiation of cryptography algorithms. Therefore, computers running Windows NT 4.0 will not be able to establish a connection to this domain controller.\r\n \r\nIf you enable this policy setting, Net Logon will allow the negotiation and use of older cryptography algorithms compatible with Windows NT 4.0. However, using the older algorithms represents a potential security risk.\r\n\r\nIf you disable this policy setting, Net Logon will not allow the negotiation and use of older cryptography algorithms. \r\n\r\nIf you do not configure this policy setting, Net Logon will not allow the negotiation and use of older cryptography algorithms.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-allownt4crypto"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_allownt4crypto_1","displayName":"Enabled","description":null,"helpText":null}]},"462ca0161e852bb0":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns","displayName":"Specify dynamic registration of the DC Locator DNS Records","description":"This policy setting determines if dynamic registration of the domain controller (DC) locator DNS resource records is enabled. These DNS records are dynamically registered by the Net Logon service and are used by the Locator algorithm to locate the DC.\r\n\r\nIf you enable this policy setting, DCs to which this setting is applied dynamically register DC Locator DNS resource records through dynamic DNS update-enabled network connections.\r\n\r\nIf you disable this policy setting, DCs will not register DC Locator DNS resource records.\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-usedynamicdns"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_usedynamicdns_1","displayName":"Enabled","description":null,"helpText":null}]},"462dae51a5c00996":{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_refreshrate","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":null},"46450fb0ab3b182b":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp","displayName":"Always show desktop on connection","description":"This policy setting determines whether the desktop is always displayed after a client connects to a remote computer or an initial program can run. It can be used to require that the desktop be displayed after a client connects to a remote computer, even if an initial program is already specified in the default user profile, Remote Desktop Connection, Remote Desktop Services client, or through Group Policy.\r\n\r\nIf you enable this policy setting, the desktop is always displayed when a client connects to a remote computer. This policy setting overrides any initial program policy settings.\r\n\r\nIf you disable or do not configure this policy setting, an initial program can be specified that runs on the remote computer after the client connects to the remote computer. If an initial program is not specified, the desktop is always displayed on the remote computer after the client connects to the remote computer.\r\n\r\nNote: If this policy setting is enabled, then the \"Start a program on connection\" policy setting is ignored.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-turnoff-singleapp"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_turnoff_singleapp_1","displayName":"Enabled","description":null,"helpText":null}]},"46f6baa5e7f540f7":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4","displayName":"Publishing Server 4 Settings","description":" Publishing Server Display Name: Displays the name of publishing server.\n \n Publishing Server URL: Displays the URL of publishing server.\n \n Global Publishing Refresh: Enables global publishing refresh (Boolean).\n \n Global Publishing Refresh On Logon: Triggers a global publishing refresh on logon (Boolean).\n \n Global Publishing Refresh Interval: Specifies the publishing refresh interval using the GlobalRefreshIntervalUnit. To disable package refresh, select 0.\n \n Global Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n \n User Publishing Refresh: Enables user publishing refresh (Boolean).\n \n User Publishing Refresh On Logon: Triggers a user publishing refresh on logon (Boolean).\n \n User Publishing Refresh Interval: Specifies the publishing refresh interval using the UserRefreshIntervalUnit. To disable package refresh, select 0.\n \n User Publishing Refresh Interval Unit: Specifies the interval unit (Hour 0-23, Day 0-31).\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-publishingallowserver4"],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_1","displayName":"Enabled","description":null,"helpText":null}]},"46213c014a5a6d22":{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode","displayName":"Account Logon Logoff Audit I Psec Quick Mode","description":"This policy setting allows you to audit events generated by Internet Key Exchange protocol (IKE) and Authenticated Internet Protocol (AuthIP) during Quick Mode negotiations. If you configure this policy setting, an audit event is generated during an IPsec Quick Mode negotiation. Success audits record successful attempts and Failure audits record unsuccessful attempts.If you do not configure this policy setting, no audit event is generated during an IPsec Quick Mode negotiation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditipsecquickmode"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditipsecquickmode_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"465511aab20489c4":{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization","displayName":"Allow Search Engine Customization","description":"Allow search engine customization for MDM enrolled devices. Users can change their default search engine. If this setting is turned on or not configured, users can add new search engines and change the default used in the address bar from within Microsoft Edge Settings. If this setting is disabled, users will be unable to add search engines or change the default used in the address bar. This policy will only apply on domain joined machines or when the device is MDM enrolled. For more information, see Microsoft browser extension policy (aka.ms/browserpolicy).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsearchenginecustomization"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowsearchenginecustomization_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"46cda2521c3073a8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Controls the mode of DNS-over-HTTPS (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"46fcf62c3c7456a0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled","displayName":"Enables managed extensions to use the Enterprise Hardware Platform API","description":"Setting the policy to True lets extensions installed by enterprise policy use the Enterprise Hardware Platform API.\r\n\r\nSetting the policy to False or leaving it unset prevents extensions from using this API.\r\n\r\nNote: This policy also applies to component extensions, such as the Hangout Services extension.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"465523ecf4d27873":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled","displayName":"Enable Media Recommendations","description":"By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"469334794ae2c3cf":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended","displayName":"Enable AutoFill","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"de643352-007f-4a47-8c83-d75a79516b39","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~deprecatedpolicies_recommended_autofillenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"464eeca9691d26df":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled","displayName":"Force WebSQL in third-party contexts to be re-enabled.","description":"WebSQL in third-party contexts (e.g., cross-site iframes) is off by default as of M97 and will be fully removed in M101.\r\nIf this policy is set to false or unset, WebSQL in third party contexts will remain off.\r\nIf this policy is set to true, WebSQL in third-party contexts will be re-enabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_websqlinthirdpartycontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"46fe6ed4aa7956a3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls","displayName":"Allow insecure content on these sites","description":"Allows you to set a list of url patterns that specify sites which are allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, and users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4615af69b3fb74f5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername","displayName":"Default search provider name","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_1","displayName":"Enabled","description":null,"helpText":null}]},"46ccbd00b8f10b88":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"463ca614cd47fc0f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended","displayName":"Enable origin-keyed process isolation by default.","description":"Enables origin-keyed process isolation for most pages (i.e., those assigned to an origin-keyed agent cluster by default). This improves security but also increases the number of processes created. Users are allowed to override the set policy value via the command-line flags or chrome://flags (both to turn this feature on or off).\r\n\r\nSetting the policy to Enabled results in most origins being isolated, even from other origins in the same site. See also the IsolateOrigins and SitePerProcess policies.\r\n\r\nSetting the policy to Disabled results in no origins being isolated from the rest of their site unless an origin explicitly asks to.\r\n\r\nNot setting the policy results in the browser determining which origins to isolate and when to isolate them.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_originkeyedprocessesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"46d6ae8c50289af8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled","displayName":"Enable strict MIME type checking for worker scripts","description":"This policy enables strict MIME type checking for worker scripts.\r\n\r\nWhen enabled or unset, then worker scripts will use strict MIME type checking for JavaScript, which is the new default behaviour. Worker scripts with legacy MIME types will be rejected.\r\n\r\nWhen disabled, then worker scripts will use lax MIME type checking, so that worker scripts with legacy MIME types, e.g. text/ascii, will continue to be loaded and executed.\r\n\r\nBrowsers traditionally used lax MIME type checking, so that resources with a number of legacy MIME types were supported. E.g. for JavaScript resources, text/ascii is a legacy supported MIME type. This may cause security issues, by allowing to load resources as scripts that were never intended to be used as such. Chrome will transition to use strict MIME type checking in the near future. The enabled policy will track the default behaviour. Disabling this policy allows administrators to retain the legacy behaviour, if desired.\r\n\r\nSee https://html.spec.whatwg.org/multipage/scripting.html#scriptingLanguage for details about JavaScript / ECMAScript media types.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_strictmimetypecheckforworkerscriptsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"460f775e952b336b":{"id":"device_vendor_msft_policy_config_deviceguard_requireplatformsecurityfeatures","displayName":"Require Platform Security Features","description":"Select Platform Security Level: 1 - Turns on VBS with Secure Boot, 3 - Turns on VBS with Secure Boot and DMA. DMA requires hardware support.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#requireplatformsecurityfeatures"],"categoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","categoryName":"Device Guard","options":[{"id":"device_vendor_msft_policy_config_deviceguard_requireplatformsecurityfeatures_1","displayName":"Turns on VBS with Secure Boot.","description":"Turns on VBS with Secure Boot.","helpText":null},{"id":"device_vendor_msft_policy_config_deviceguard_requireplatformsecurityfeatures_3","displayName":"Turns on VBS with Secure Boot and direct memory access (DMA). DMA requires hardware support.","description":"Turns on VBS with Secure Boot and direct memory access (DMA). DMA requires hardware support.","helpText":null}]},"461edc316726a6ec":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachcount_profilesreattachcount","displayName":"Reattach Count (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"46a14458a4114975":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page","description":"By default, there are two Bing chat entry-points on new tab page. One is inside the new tab page search box, and one is in the Bing Autosuggest drawer on-click.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge Enterprise new tab page and the Bing chat entry-points are there for users.\r\n\r\nIf you disable this policy, Bing chat entry-points don't appear on the new tab page.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~startup_newtabpagebingchatenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"461b49ad7c5836ef":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled","displayName":"Control whether storage quota APIs will return static values","description":"Controls how the Storage Quota APIs report the available quota to websites.\r\n\r\nWhen enabled, the Storage Quota APIs return a static quota value equal to the current usage plus the smaller of 10 GiB or the device's total storage rounded up to the nearest 1 GiB.\r\n\r\nWhen disabled, the Storage Quota APIs return a dynamic quota value that reflects the actual available device storage.\r\n\r\nWhen unset, the browser uses the default platform behavior.\r\n\r\nThis policy does not affect sites with unlimited storage permissions or enforced quota settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge_staticstoragequotaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"467c843e2186f823":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols","displayName":"Allow legacy TLS/DTLS downgrade in WebRTC (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 120.\r\n\r\nIf you enable this policy, WebRTC peer connections can downgrade to obsolete\r\nversions of the TLS/DTLS (DTLS 1.0, TLS 1.0 and TLS 1.1) protocols.\r\nIf you disable or don't set this policy, these TLS/DTLS versions are\r\ndisabled.\r\n\r\nThis policy was removed in Microsoft Edge 121 and is ignored if set.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webrtcallowlegacytlsprotocols_1","displayName":"Enabled","description":null,"helpText":null}]},"469c30ae0a399d0e":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended","displayName":"Enable Microsoft Defender SmartScreen DNS requests","description":"This policy lets you configure whether to enable DNS requests made by Microsoft Defender SmartScreen. Note: Disabling DNS requests will prevent Microsoft Defender SmartScreen from getting IP addresses, and potentially impact the IP-based protections provided.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen will make DNS requests.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen will not make any DNS requests.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreendnsrequestsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"46c38c0b8ea71956":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werarchive_1_werarchivebehavior","displayName":"Archive behavior: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werarchive_1_werarchivebehavior_2","displayName":"Store all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werarchive_1_werarchivebehavior_1","displayName":"Store parameters only","description":null,"helpText":null}]},"46c64ec7bfe00d3b":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_preventcddvdmetadataretrieval","displayName":"Prevent CD and DVD Media Information Retrieval (User)","description":"This policy setting allows you to prevent media information for CDs and DVDs from being retrieved from the Internet.\r\n\r\nIf you enable this policy setting, the Player is prevented from automatically obtaining media information from the Internet for CDs and DVDs played by users. In addition, the Retrieve media information for CDs and DVDs from the Internet check box on the Privacy Options tab in the first use dialog box and on the Privacy tab in the Player are not selected and are not available.\r\n\r\nIf you disable or do not configure this policy setting, users can change the setting of the Retrieve media information for CDs and DVDs from the Internet check box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-preventcddvdmetadataretrieval"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_preventcddvdmetadataretrieval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_preventcddvdmetadataretrieval_1","displayName":"Enabled","description":null,"helpText":null}]},"4669079a0c787d22":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability","displayName":"Control where Developer Tools can be used (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_0","displayName":"Disallow usage of the Developer Tools on extensions installed by enterprise policy, allow usage of the Developer Tools in other contexts","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_1","displayName":"Allow usage of the Developer Tools","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_developertoolsavailability_2","displayName":"Disallow usage of the Developer Tools","description":null,"helpText":null}]},"4675789a2396e16f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter","displayName":"Move selection after Enter (User)","description":"Enabling this policy selects the Advanced (Editing Options) user option to \"After pressing Enter, move selection\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_moveselectionafterenter_1","displayName":"Enabled","description":null,"helpText":null}]},"4667e731482292f4":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles","displayName":"Excel add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"463ffb41f9d4426b":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"466f6b816f76b13b":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400","displayName":"Allow active scripting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_iz_partname1400_1","displayName":"Prompt","description":null,"helpText":null}]},"463a9eb4b29a97c7":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_maxconnectionsperproxy_maxconnectionsperproxy","displayName":"Maximum number of concurrent connections to the proxy server: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"465d27531bba77c5":{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled","displayName":"Controls whether the deprecated :--foo syntax for CSS custom state is enabled (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132.\r\n\r\nThe :--foo syntax for the CSS custom state feature is being changed to :state(foo) in Microsoft Edge in order to comply with changes that have been made in Firefox and Safari. This policy lets the deprecated syntax to be used until Stable 132.\r\n\r\nThis deprecation might break some Microsoft Edge-only websites that use the deprecated :--foo syntax.\r\n\r\nIf you enable this policy, the deprecated syntax will be enabled.\r\n\r\nIf you disable this policy or don't set it, the deprecated syntax will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev127~policy~microsoft_edge_csscustomstatedeprecatedsyntaxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"466af048983ad54d":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended","displayName":"Configure Edge Scareware Blocker Protection (User)","description":"This policy setting allows administrators to control whether Microsoft Edge enables the Scareware Blocker, an AI-powered feature that provides warning messages to help protect users from potential tech scams.\r\n\r\nIf this policy is enabled, Edge Scareware Blocker will warn users of potential tech scams.\r\n\r\nIf this policy is disabled, Edge Scareware Blocker will not warn users of potential tech scams.\r\n\r\nIf this policy is not configured, Edge Scareware Blocker will not warn users of potential tech scams, but users can choose warnings in settings.\r\n\r\nBy configuring this policy, administrators determine whether users receive proactive scam warnings or must manually enable them.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerprotectionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"463e3233f1c58b8e":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_loopbacknetworkblockedforurlsdesc","displayName":"Block sites from making network requests to the local device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"46709da38ff6371a":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls","displayName":"Allow access to sensors on specific sites (User)","description":"Define a list of sites, based on URL patterns, that can access and use sensors such as motion and light sensors.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultSensorsSetting' (Default sensors setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor URL patterns that don't match this policy, the following order of precedence is used: The 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policy (if there is a match), the 'DefaultSensorsSetting' policy (if set), or the user's personal settings.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'SensorsBlockedForUrls' policy. You can't allow and block a URL.\r\n\r\nFor detailed information about valid URL patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"46a7702502dd453d":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended","displayName":"Enable Password reveal button (User)","description":"Lets you configure the default display of the browser password reveal button for password input fields on websites.\r\n\r\nIf you enable or don't configure this policy, the browser user setting defaults to displaying the password reveal button.\r\n\r\nIf you disable this policy, the browser user setting won't display the password reveal button.\r\n\r\nFor accessibility, users can change the browser setting from the default policy.\r\n\r\nThis policy only affects the browser password reveal button, it doesn't affect websites' custom reveal buttons.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordrevealenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"46c7d23ea2f79804":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_onlycontaininganattachment_l_onlycontaininganattachment356","displayName":"Only containing an attachment (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":null},"46fbab7bd4d7be46":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehome_l_homemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"461f556c8eef1d34":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_urlforlocationofdocumenttemplatespolicy_l_enteraurl","displayName":"Enter a URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":null},"46da940d79ae8738":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey20_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"46b882ceaa0e910b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc20_l_datecolon315","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"460234b9a24eae39":{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier","displayName":"Multiplier for Presence sync interval for notebooks stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between polls to SharePoint to determine active users of notebooks. OneNote will sync notebooks at a faster rate when other users are interacting with a notebook.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently to determine if there are other users currently interacting with notebooks. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow detection of concurrent users in notebooks but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will poll for active users of notebooks at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointpresenceintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},"4696c7e4ef558eba":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize","displayName":"Legacy PST: Absolute maximum size (User)","description":"Specifies the maximum allowable size (in bytes) for an Outlook 97-2002 Data File.","helpText":"","infoUrls":[],"categoryId":"cb6472c8-3e22-4029-af98-8a97f03a5a44","categoryName":"PST Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous~l_pstsettings_l_legacypstabsolutemaximumsize_1","displayName":"Enabled","description":null,"helpText":null}]},"46a026faae795239":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext","displayName":"Enable down-level meeting text (User)","description":"This policy setting controls whether Outlook automatically displays the meeting time and location in the meeting request body.\r\n\r\nIf you enable this policy setting, Outlook automatically displays the meeting time and location in the meeting request body.\r\n\r\nIf you disable or do not configure this policy setting, Outlook does not automatically display the meeting time and location in the meeting request body.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_enablemeetingdownleveltext_1","displayName":"Enabled","description":null,"helpText":null}]},"461cf25a307c769c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor","displayName":"Change color used to highlight search matches (User)","description":"By default, search matches are highlighted in yellow. This setting allows you to change the color used for highlighting matches in search results.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_hithighlightingcolor_1","displayName":"Enabled","description":null,"helpText":null}]},"4612ffd539f51931":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority","displayName":"Required Certificate Authority (User)","description":"This policy setting enables you to designate a required certificate authority for Outlook to use for encryption and digital signatures.\r\n\r\nIf you enable this policy setting, you can specify a required certificate authority by entering an X.509 distinguished name in the text field that is provided. The name must conform to the X.509 certificate format exactly. For example:\r\n\r\nCN=WoodgroveBankCA, DC=WoodgroveBank, DC=com\r\n\r\nIf you disable or do not configure this policy setting, Outlook trusts any certificate authorities that are represented by certificates in the Trusted Root Certification Authorities store on users' computers.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_1","displayName":"Enabled","description":null,"helpText":null}]},"46ababde4872c5b4":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast","displayName":"Stop checking for text color contrast (User)","description":"This policy setting prevents the Accessibility Checker from flagging text with low contrast and readability.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging text with low contrast and readability.\r\n\r\nIf you disable or do not configure this policy setting, text will be scanned for color contrast and the results will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtextcontrast_1","displayName":"Enabled","description":null,"helpText":null}]},"46e3dd54c3182581":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"4677268328878ab4":{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience","displayName":"Disable Privacy Experience (User)","description":"Enabling this policy prevents the privacy experience from launching during user logon for new and upgraded users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#disableprivacyexperience"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience_0","displayName":"Disabled","description":"Allow the 'choose privacy settings for your device' screen for a new user during their first logon or when an existing user logs in for the first time after an upgrade.","helpText":null},{"id":"user_vendor_msft_policy_config_privacy_disableprivacyexperience_1","displayName":"Enabled","description":"Do not allow the 'choose privacy settings for your device' screen when a new user logs in or an existing user logs in for the first time after an upgrade.","helpText":null}]},"46459ba0ea65813a":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_2","displayName":"Disable all with notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_3","displayName":"Disable all except digitally signed macros","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_4","displayName":"Disable all without notification","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_vbawarningspolicy_l_empty0_1","displayName":"Enable all macros (not recommended)","description":null,"helpText":null}]},"46b2903819c9ef13":{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps","displayName":"Hide Frequently Used Apps (User)","description":"Enabling this policy hides the most used apps from appearing on the start menu and disables the corresponding toggle in the Settings app.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidefrequentlyusedapps"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidefrequentlyusedapps_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"4657bf0652024cf6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting","displayName":"Define styles based on your formatting (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_definestylesbasedonyourformatting_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/49.json b/public/intune-definitions/49.json index 0d0c551e5161..35f15fb05aed 100644 --- a/public/intune-definitions/49.json +++ b/public/intune-definitions/49.json @@ -1 +1 @@ -{"49c0706662ca5ba8":{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_1","displayName":"Enabled","description":null,"helpText":null}]},"49527647d335c01f":{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly","displayName":"Force WiFi To Allowed Networks Only","description":"If true, limits device to only join Wi-Fi networks set-up via configuration profile. Requires a supervised device. Available in iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly_true","displayName":"True","description":null,"helpText":null}]},"49fa1dc1d2733630":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_application id","displayName":"Microsoft PowerPoint Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"492ef7ce51a84378":{"id":"com.apple.systemconfiguration_proxies_httpsenable","displayName":"HTTPS Enable","description":"If true, enables secure web proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_httpsenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_httpsenable_1","displayName":"True","description":null,"helpText":null}]},"49e318cf1403919d":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"493c8d927b046987":{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files are deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_true","displayName":"Enabled","description":null,"helpText":null}]},"49ad39c2902984ca":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for an image URL that uses POST (users can override)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nSpecify Bing's Image Search URL Post Params as:\n'imageBin={google:imageThumbnailBase64}'.\n\nSpecify Google's Image Search URL Post Params as:\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\n\nIf you don't set this policy, image search requests are sent using the GET method.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"49d976846eda6a7f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled","displayName":"Enable Discover access to page contents for AAD profiles (Obsolete)","description":"This policy is obsolete as of Microsoft Edge version 127. Two new Microsoft Edge Policies took its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles) and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles).\n\nThis policy didn't allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Microsoft Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allows force-disabling of Copilot page access.\n\nThis policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. To summarize pages and interact with text selections, it must access the page contents. When enabled, page contents are sent to Bing. This policy doesn't affect MSA profiles.\n\nIf you enable or don't configure this policy, Discover has access to page contents.\n\nIf you disable this policy, Discover can't access page contents.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"495dcf846ed1863e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords","displayName":"Allow importing of saved passwords","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\n\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\n\nIf you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_true","displayName":"Enabled","description":null,"helpText":null}]},"49cd22e741b34f97":{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (users can override)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords aren't cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"492ec8cda7d02aa5":{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention","displayName":"Block tracking of users' web-browsing activity","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\n\nIf you disable this policy or don't configure it, users set their own level of tracking prevention.\n\nPolicy options mapping:\n\n* TrackingPreventionOff (0) = Off (no tracking prevention)\n\n* TrackingPreventionBasic (1) = Basic (blocks harmful trackers, content and ads will be personalized)\n\n* TrackingPreventionBalanced (2) = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\n\n* TrackingPreventionStrict (3) = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionoff","displayName":"Off (no tracking prevention)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionbasic","displayName":"Basic (blocks harmful trackers, content and ads will be personalized)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionbalanced","displayName":"Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionstrict","displayName":"Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)","description":null,"helpText":null}]},"491675504f96eb11":{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions","displayName":"Choose how BitLocker-protected operating system drives can be recovered","description":"This policy setting allows you to control how BitLocker-protected operating system drives are recovered in the absence of the required startup key information. This policy setting is applied when you turn on BitLocker.\n\nThe \"Allow certificate-based data recovery agent\" check box is used to specify whether a data recovery agent can be used with BitLocker-protected operating system drives. Before a data recovery agent can be used it must be added from the Public Key Policies item in either the Group Policy Management Console or the Local Group Policy Editor. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about adding data recovery agents.\n\nIn \"Configure user storage of BitLocker recovery information\" select whether users are allowed, required, or not allowed to generate a 48-digit recovery password or a 256-bit recovery key.\n\nSelect \"Omit recovery options from the BitLocker setup wizard\" to prevent users from specifying recovery options when they turn on BitLocker on a drive. This means that you will not be able to specify which recovery option to use when you turn on BitLocker, instead BitLocker recovery options for the drive are determined by the policy setting.\n\nIn \"Save BitLocker recovery information to Active Directory Domain Services\", choose which BitLocker recovery information to store in AD DS for operating system drives. If you select \"Backup recovery password and key package\", both the BitLocker recovery password and key package are stored in AD DS. Storing the key package supports recovering data from a drive that has been physically corrupted. If you select \"Backup recovery password only,\" only the recovery password is stored in AD DS.\n\nSelect the \"Do not enable BitLocker until recovery information is stored in AD DS for operating system drives\" check box if you want to prevent users from enabling BitLocker unless the computer is connected to the domain and the backup of BitLocker recovery information to AD DS succeeds.\n\nNote: If the \"Do not enable BitLocker until recovery information is stored in AD DS for operating system drives\" check box is selected, a recovery password is automatically generated.\n\nIf you enable this policy setting, you can control the methods available to users to recover data from BitLocker-protected operating system drives.\n\nIf this policy setting is disabled or not configured, the default recovery options are supported for BitLocker recovery. By default a DRA is allowed, the recovery options can be specified by the user including the recovery password and recovery key, and recovery information is not backed up to AD DS.\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"49835ec03aa37d59":{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules_listbox_contenturirules","displayName":"Content URI Rules:","description":null,"helpText":"","infoUrls":[],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":null},"49c6e234123c7f3f":{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r","displayName":"Local Link to a Remote Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r_1","displayName":"True","description":null,"helpText":null}]},"49e80a53280a81f7":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode","displayName":"Configure user Group Policy loopback processing mode","description":"This policy setting directs the system to apply the set of Group Policy objects for the computer to any user who logs on to a computer affected by this setting. It is intended for special-use computers, such as those in public places, laboratories, and classrooms, where you must modify the user setting based on the computer that is being used.\r\n\r\nBy default, the user's Group Policy Objects determine which user settings apply. If this setting is enabled, then, when a user logs on to this computer, the computer's Group Policy Objects determine which set of Group Policy Objects applies.\r\n\r\nIf you enable this setting, you can select one of the following modes from the Mode box:\r\n\r\n\"Replace\" indicates that the user settings defined in the computer's Group Policy Objects replace the user settings normally applied to the user.\r\n\r\n\"Merge\" indicates that the user settings defined in the computer's Group Policy Objects and the user settings normally applied to the user are combined. If the settings conflict, the user settings in the computer's Group Policy Objects take precedence over the user's normal settings.\r\n\r\nIf you disable this setting or do not configure it, the user's Group Policy Objects determines which user settings apply.\r\n\r\nNote: This setting is effective only when both the computer account and the user account are in at least Windows 2000 domains.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-userpolicymode"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_1","displayName":"Enabled","description":null,"helpText":null}]},"497b5552ca38bf97":{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate","displayName":"Extend Point and Print connection to search Windows Update","description":"This policy setting allows you to manage where client computers search for Point and Printer drivers.\r\n\r\nIf you enable this policy setting, the client computer will continue to search for compatible Point and Print drivers from Windows Update after it fails to find the compatible driver from the local driver store and the server driver cache.\r\n\r\nIf you disable this policy setting, the client computer will only search the local driver store and server driver cache for compatible Point and Print drivers. If it is unable to find a compatible driver, then the Point and Print connection will fail.\r\n\r\nThis policy setting is not configured by default, and the behavior depends on the version of Windows that you are using.\r\nBy default, Windows Ultimate, Professional and Home SKUs will continue to search for compatible Point and Print drivers from Windows Update, if needed. However, you must explicitly enable this policy setting for other versions of Windows (for example Windows Enterprise, and all versions of Windows Server 2008 R2 and later) to have the same behavior.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-donotinstallcompatibledriverfromwindowsupdate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},"49c3f9be48c8e2f3":{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2","displayName":"Turn off the Store application","description":"Denies or allows access to the Store application.\r\n\r\nIf you enable this setting, access to the Store application is denied. Access to the Store is required for installing app updates.\r\n\r\nIf you disable or don't configure this setting, access to the Store application is allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-removewindowsstore-2"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2_1","displayName":"Enabled","description":null,"helpText":null}]},"49327ee80b5fa556":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_autoopenfiletypesdesc","displayName":"List of file types that should be automatically opened on download (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"49ddbefd92d53a8d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_explicitlyallowednetworkportsdesc","displayName":"Explicitly allowed network ports (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"49aab8d7a5987075":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability","displayName":"Profile picker availability on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_0","displayName":"Profile picker available at startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_1","displayName":"Profile picker disabled at startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_2","displayName":"Profile picker forced at startup","description":null,"helpText":null}]},"4915ae5e70c84c33":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_defaultsearchprovidericonurl","displayName":"Default search provider icon (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"490209ddd78385f1":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings","displayName":"Extension management settings","description":"Setting the policy controls extension management settings for Google Chrome, including any controlled by existing extension-related policies. The policy supersedes any legacy policies that might be set.\r\n\r\nThis policy maps an extension ID or an update URL to its specific setting only. A default configuration can be set for the special ID \"*\", which applies to all extensions without a custom configuration in this policy. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest ( http://support.google.com/chrome/a?p=Configure_ExtensionSettings_policy ). If the 'override_update_url' flag is set to true, the extension is installed and updated using the \"update\" URL specified in the ExtensionInstallForcelist policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is a Chrome Web Store url.\r\n\r\nNote: For Windows® instances not joined to a Microsoft® Active Directory® domain, forced installation is limited to apps and extensions listed in the Chrome Web Store.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ExtensionSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"abcdefghijklmnopabcdefghijklmnop\": {\r\n \"installation_mode\": \"allowed\",\r\n \"blocked_permissions\": [\r\n \"history\"\r\n ],\r\n \"minimum_version_required\": \"1.0.1\",\r\n \"toolbar_pin\": \"force_pinned\"\r\n },\r\n \"bcdefghijklmnopabcdefghijklmnopa\": {\r\n \"installation_mode\": \"force_installed\",\r\n \"update_url\": \"https://example.com/update_url\",\r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ],\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.example.com\"\r\n ],\r\n \"runtime_allowed_hosts\": [\r\n \"*://good.example.com\"\r\n ]\r\n },\r\n \"cdefghijklmnopabcdefghijklmnopab\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_install_message\": \"Custom error message.\"\r\n },\r\n \"defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_install_message\": \"Custom error message.\"\r\n },\r\n \"update_url:https://www.example.com/update.xml\": {\r\n \"blocked_permissions\": [\r\n \"wallpaper\"\r\n ],\r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ],\r\n \"installation_mode\": \"allowed\"\r\n },\r\n \"fghijklmnopabcdefghijklmnopabcde\": {\r\n \"installation_mode\": \"removed\",\r\n \"blocked_install_message\": \"Custom removal message.\"\r\n },\r\n \"ghijklmnopabcdefghijklmnopabcdef\": {\r\n \"installation_mode\": \"force_installed\",\r\n \"update_url\": \"https://example.com/update_url\",\r\n \"override_update_url\": true\r\n },\r\n \"*\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_permissions\": [\r\n \"downloads\",\r\n \"bookmarks\"\r\n ],\r\n \"install_sources\": [\r\n \"https://company-intranet/chromeapps\"\r\n ],\r\n \"allowed_types\": [\r\n \"hosted_app\"\r\n ],\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.example.com\"\r\n ],\r\n \"runtime_allowed_hosts\": [\r\n \"*://good.example.com\"\r\n ],\r\n \"blocked_install_message\": \"Custom error message.\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"491c3e1beaad9fa6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls_filehandlingblockedforurlsdesc","displayName":"Block the File Handling API on these web apps (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"499ddb3fe9c7cf5f":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeoutlookpersonalization","displayName":"Include Outlook Personalization","description":"[ENABLED BY DEFAULT]\r\n\r\nOutlook personalization data will be included in the ODFC Container.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\IncludeOutlookPersonalization\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeoutlookpersonalization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeoutlookpersonalization_1","displayName":"Enabled","description":null,"helpText":null}]},"4928a837121f0728":{"id":"device_vendor_msft_policy_config_internetexplorer_allowaddonlist_addonlist","displayName":"Add-on List","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},"492db2ce0b51ec98":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials","displayName":"Require logon credentials","description":"\r\nRequires the user to provide logon credentials for Microsoft Lync rather than automatically using the Windows credentials when Microsoft Lync authenticates the user using NTLM or Kerberos.\r\n\r\nIf you enable this policy setting, Microsoft Lync requires the user to provide logon credentials.\r\n\r\nIf you disable or do not configure this policy setting, Microsoft Lync authenticates the user based on the logon credentials for Windows.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},"497705a2ed952037":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Online revocation checks don't provide a significant security benefit and are disabled by default.\r\n\r\nIf you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. \"Soft fail\" means that if the revocation server can't be reached, the certificate will be considered valid.\r\n\r\nIf you disable the policy or don't configure it, Microsoft Edge won't perform online revocation checks.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks_1","displayName":"Enabled","description":null,"helpText":null}]},"492b266927fb4178":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch","displayName":"Enforce Bing SafeSearch (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_0","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_1","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_2","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},"49243d6ef11de6f3":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.\r\n\r\nThis policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.\r\n\r\nBing's suggest URL can be specified as:\r\n\r\n'{bing:baseURL}qbox?query={searchTerms}'.\r\n\r\nGoogle's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},"491f607d46c56e35":{"id":"device_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins_allhttpauthschemesallowedfororiginsdesc","displayName":"List of origins that allow all HTTP authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},"4978dc958a5de515":{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\r\n\r\nIf an origin is covered by both this policy and by 'LocalNetworkAccessAllowedForUrls' (Allow sites to make requests to local network endpoints.), this policy takes precedence.\r\n\r\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\r\n\r\nNote: This policy improves local network security by blocking specified public websites from accessing private IP addresses. It helps prevent unauthorized external sites from reaching internal resources unless explicitly permitted. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"492fd606333b4c74":{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports","description":"There is a list of restricted ports built into Microsoft Edge. Connections to these ports will fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on.\r\n\r\nPorts are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for error code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (for example port 80 or 443).\r\n\r\nMalicious websites can easily detect that this policy is set, and for which ports, then use that information to target attacks.\r\n\r\nEach port listed in this policy is labeled with a date that it can be unblocked until. After that date the port will be restricted regardless of if it's specified by the value of this policy.\r\n\r\nLeaving the value empty or unset means that all restricted ports will be blocked. Invalid port values set through this policy will be ignored while valid ones will still be applied.\r\n\r\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\r\n\r\nPolicy options mapping:\r\n\r\n* 554 (554) = port 554 (can be unblocked until 2021/10/15)\r\n\r\n* 10080 (10080) = port 10080 (can be unblocked until 2022/04/01)\r\n\r\n* 6566 (6566) = port 6566 (can be unblocked until 2021/10/15)\r\n\r\n* 989 (989) = port 989 (can be unblocked until 2022/02/01)\r\n\r\n* 990 (990) = port 990 (can be unblocked until 2022/02/01)\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\n10080","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_1","displayName":"Enabled","description":null,"helpText":null}]},"4925205a5eba28ec":{"id":"device_vendor_msft_policy_config_mssecurityguide_enablestructuredexceptionhandlingoverwriteprotection","displayName":"Enable Structured Exception Handling Overwrite Protection (SEHOP)","description":"If this setting is enabled, SEHOP is enforced. For more information, see https://support.microsoft.com/en-us/help/956607/how-to-enable-structured-exception-handling-overwrite-protection-sehop-in-windows-operating-systems.\n\nIf this setting is disabled or not configured, SEHOP is not enforced for 32-bit processes.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-mssecurityguide#mssecurityguide-enablestructuredexceptionhandlingoverwriteprotection"],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_mssecurityguide_enablestructuredexceptionhandlingoverwriteprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_mssecurityguide_enablestructuredexceptionhandlingoverwriteprotection_1","displayName":"Enabled","description":null,"helpText":null}]},"49517dc7fc6b6f7a":{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_pictures_checkbox","displayName":"Pictures (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_pictures_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_pictures_checkbox_1","displayName":"True","description":null,"helpText":null}]},"49f164b894406ce6":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_sharepointonpremprioritization_dropdown","displayName":"Authenticate first against: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_sharepointonpremprioritization_dropdown_0","displayName":"SharePoint Online","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_sharepointonpremprioritization_dropdown_1","displayName":"SharePoint Server 2019","description":null,"helpText":null}]},"49a8bb1b03904c4c":{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_disableautoconfig_disableautoconfigtypes","displayName":"Disabled Account Types: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"49e682c1ebb64fdc":{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery","displayName":"Select Power Button Action On Battery","description":"This policy setting specifies the action that Windows takes when a user presses the power button. Possible actions include: 0 - Take no action 1 - Sleep 2 - Hibernate 3 - Shut down If you enable this policy setting, you must select the desired action. If you disable this policy setting or do not configure it, users can see and change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#selectpowerbuttonactiononbattery"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":[{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery_0","displayName":"Take no action","description":"Take no action","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery_1","displayName":"Sleep","description":"Sleep","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery_2","displayName":"System hibernate sleep state","description":"System hibernate sleep state","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery_3","displayName":"System shutdown","description":"System shutdown","helpText":null}]},"49c50140298175aa":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscalendar_forcedenytheseapps","displayName":"Let Apps Access Calendar Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to the calendar. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscalendar_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"499f6f013d85f1a0":{"id":"device_vendor_msft_policy_config_start_hidelock","displayName":"Hide Lock","description":"Enabling this policy hides \"Lock\" from appearing in the user tile in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidelock"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hidelock_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hidelock_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"49b9d9936aa9b426":{"id":"device_vendor_msft_policy_config_start_hiderestart","displayName":"Hide Restart","description":"Enabling this policy hides \"Restart/Update and restart\" from appearing in the power button in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hiderestart"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hiderestart_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hiderestart_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"49f325080f5ffdc9":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_payloadtenantid","displayName":"Azure AD Directory ID:","description":"","helpText":"","infoUrls":[],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":null},"49a4a81390a13ef5":{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy","displayName":"Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy_1","displayName":"Always allow updates (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy_2","displayName":"Manual updates only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy_3","displayName":"Automatic silent updates only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy_0","displayName":"Updates disabled","description":null,"helpText":null}]},"49ca135cbd54f81f":{"id":"enrollment_autopilot_dpp_language","displayName":"Language (Region)","description":"Specify the language and region that will be used.","helpText":"","infoUrls":[],"categoryId":"72e4d72b-e01e-427c-a3b6-05bdcf04ef8d","categoryName":null,"options":[{"id":"enrollment_autopilot_dpp_language_0","displayName":"Operating system default","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_1","displayName":"User select","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_2","displayName":"Arabic (U.A.E.)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_3","displayName":"Arabic (Bahrain)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_4","displayName":"Arabic (Algeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_5","displayName":"Arabic (Egypt)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_6","displayName":"Arabic (Iraq)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_7","displayName":"Arabic (Jordan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_8","displayName":"Arabic (Kuwait)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_9","displayName":"Arabic (Lebanon)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_10","displayName":"Arabic (Libya)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_11","displayName":"Arabic (Morocco)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_12","displayName":"Arabic (Oman)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_13","displayName":"Arabic (Qatar)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_14","displayName":"Arabic (Saudi Arabia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_15","displayName":"Arabic (Syria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_16","displayName":"Arabic (Tunisia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_17","displayName":"Arabic (Yemen)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_18","displayName":"Azerbaijani (Cyrillic, Azerbaijan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_19","displayName":"Azerbaijani (Latin, Azerbaijan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_20","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_21","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_22","displayName":"Bosnian (Cyrillic)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_23","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_24","displayName":"Chinese (PRC)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_25","displayName":"Chinese (Hong Kong S.A.R.)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_26","displayName":"Chinese (Macao S.A.R.)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_27","displayName":"Chinese (Singapore)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_28","displayName":"Chinese (Taiwan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_29","displayName":"Croatian (Latin)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_30","displayName":"Croatian (Croatia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_31","displayName":"Dutch (Belgium)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_32","displayName":"Dutch (Netherlands)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_33","displayName":"English (Australia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_34","displayName":"English (Belize)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_35","displayName":"English (Canada)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_36","displayName":"English (Caribbean)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_37","displayName":"English (Ireland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_38","displayName":"English (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_39","displayName":"English (Jamaica)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_40","displayName":"English (Malaysia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_41","displayName":"English (New Zealand)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_42","displayName":"English (Republic of the Philippines)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_43","displayName":"English (Singapore)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_44","displayName":"English (Trinidad and Tobago)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_45","displayName":"English (United Kingdom)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_46","displayName":"English (United States)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_47","displayName":"English (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_48","displayName":"English (Zimbabwe)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_49","displayName":"French (Belgium)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_50","displayName":"French (Canada)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_51","displayName":"French (Switzerland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_52","displayName":"French (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_53","displayName":"French (Luxembourg)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_54","displayName":"French (Monaco)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_55","displayName":"German (Austria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_56","displayName":"German (Switzerland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_57","displayName":"German (Germany)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_58","displayName":"German (Liechtenstein)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_59","displayName":"German (Luxembourg)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_60","displayName":"Inuktitut (Syllabics, Canada)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_61","displayName":"Inuktitut (Latin, Canada)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_62","displayName":"Italian (Switzerland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_63","displayName":"Italian (Italy)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_64","displayName":"Malay (Brunei Darussalam)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_65","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_66","displayName":"Mongolian (Traditional Mongolian, PRC)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_67","displayName":"Mongolian (Cyrillic, Mongolia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_68","displayName":"Norwegian (Bokmål)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_69","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_70","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_71","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_72","displayName":"Quechua (Bolivia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_73","displayName":"Quechua (Ecuador)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_74","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_75","displayName":"Sami, Lule (Norway)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_76","displayName":"Sami, Lule (Sweden)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_77","displayName":"Sami, Northern (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_78","displayName":"Sami, Northern (Norway)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_79","displayName":"Sami, Northern (Sweden)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_80","displayName":"Sami, Southern (Norway)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_81","displayName":"Sami, Southern (Sweden)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_82","displayName":"Sami, Inari (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_83","displayName":"Sami, Skolt (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_84","displayName":"Afrikaans (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_85","displayName":"Albanian (Albania)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_86","displayName":"Alsatian (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_87","displayName":"Amharic (Ethiopia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_88","displayName":"Armenian (Armenia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_89","displayName":"Assamese (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_90","displayName":"Bashkir (Russia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_91","displayName":"Basque (Basque)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_92","displayName":"Belarusian (Belarus)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_93","displayName":"Breton (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_94","displayName":"Bulgarian (Bulgaria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_95","displayName":"Catalan (Catalan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_96","displayName":"Corsican (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_97","displayName":"Czech (Czech Republic)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_98","displayName":"Danish (Denmark)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_99","displayName":"Dari (Afghanistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_100","displayName":"Divehi (Maldives)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_101","displayName":"Estonian (Estonia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_102","displayName":"Faroese (Faroe Islands)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_103","displayName":"Filipino (Philippines)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_104","displayName":"Finnish (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_105","displayName":"Frisian (Netherlands)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_106","displayName":"Galician (Galician)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_107","displayName":"Georgian (Georgia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_108","displayName":"Greek (Greece)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_109","displayName":"Greenlandic (Greenland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_110","displayName":"Gujarati (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_111","displayName":"Hausa (Latin, Nigeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_112","displayName":"Hebrew (Israel)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_113","displayName":"Hindi (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_114","displayName":"Hungarian (Hungary)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_115","displayName":"Icelandic (Iceland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_116","displayName":"Igbo (Nigeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_117","displayName":"Indonesian (Indonesia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_118","displayName":"Irish (Ireland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_119","displayName":"isiXhosa (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_120","displayName":"isiZulu (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_121","displayName":"Japanese (Japan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_122","displayName":"Kannada (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_123","displayName":"Kazakh (Kazakhstan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_124","displayName":"Khmer (Cambodia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_125","displayName":"K'iche (Guatemala)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_126","displayName":"Kinyarwanda (Rwanda)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_127","displayName":"Kiswahili (Kenya)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_128","displayName":"Konkani (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_129","displayName":"Korean (Korea)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_130","displayName":"Kyrgyz (Kyrgyzstan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_131","displayName":"Lao (Lao P.D.R.)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_132","displayName":"Latvian (Latvia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_133","displayName":"Lithuanian (Lithuania)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_134","displayName":"Lower Sorbian (Germany)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_135","displayName":"Luxembourgish (Luxembourg)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_136","displayName":"Macedonian (Macedonia, FYRO)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_137","displayName":"Malayalam (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_138","displayName":"Maltese (Malta)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_139","displayName":"Maori (New Zealand)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_140","displayName":"Mapudungun (Chile)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_141","displayName":"Marathi (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_142","displayName":"Mohawk (Mohawk)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_143","displayName":"Nepali (Nepal)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_144","displayName":"Occitan (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_145","displayName":"Odia (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_146","displayName":"Pashto (Afghanistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_147","displayName":"Persian","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_148","displayName":"Polish (Poland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_149","displayName":"Punjabi (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_150","displayName":"Romanian (Romania)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_151","displayName":"Romansh (Switzerland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_152","displayName":"Russian (Russia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_153","displayName":"Sanskrit (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_154","displayName":"Sesotho sa Leboa (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_156","displayName":"Setswana (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_157","displayName":"Sinhala (Sri Lanka)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_158","displayName":"Slovak (Slovakia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_159","displayName":"Slovenian (Slovenia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_160","displayName":"Swedish (Sweden)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_161","displayName":"Syriac (Syria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_162","displayName":"Tajik (Cyrillic, Tajikistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_163","displayName":"Tamazight (Latin, Algeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_164","displayName":"Tamil (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_165","displayName":"Tatar (Russia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_166","displayName":"Telugu (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_167","displayName":"Thai (Thailand)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_168","displayName":"Tibetan","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_169","displayName":"Turkish (Turkey)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_170","displayName":"Turkmen (Turkmenistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_171","displayName":"Uighur (PRC)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_172","displayName":"Ukrainian (Ukraine)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_173","displayName":"Urdu (Islamic Republic of Pakistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_174","displayName":"Vietnamese (Vietnam)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_175","displayName":"Welsh (United Kingdom)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_176","displayName":"Wolof (Senegal)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_177","displayName":"Yakut (Russia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_178","displayName":"Yi (PRC)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_179","displayName":"Yoruba (Nigeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_180","displayName":"Serbian (Cyrillic)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_181","displayName":"Serbian (Cyrillic, Serbia and Montenegro)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_182","displayName":"Serbian (Latin)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_183","displayName":"Serbian (Latin, Serbia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_184","displayName":"Lower Sorbian (Germany)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_185","displayName":"Upper Sorbian (Germany)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_186","displayName":"Spanish (Spain, Traditional Sort)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_187","displayName":"Spanish (Argentina)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_188","displayName":"Spanish (Bolivia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_189","displayName":"Spanish (Chile)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_190","displayName":"Spanish (Colombia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_191","displayName":"Spanish (Costa Rica)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_192","displayName":"Spanish (Dominican Republic)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_193","displayName":"Spanish (Ecuador)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_194","displayName":"Spanish (Guatemala)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_195","displayName":"Spanish (Honduras)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_196","displayName":"Spanish (Mexico)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_197","displayName":"Spanish (Nicaragua)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_198","displayName":"Spanish (Panama)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_199","displayName":"Spanish (Peru)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_200","displayName":"Spanish (Puerto Rico)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_201","displayName":"Spanish (Paraguay)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_202","displayName":"Spanish (El Salvador)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_203","displayName":"Spanish (United States)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_204","displayName":"Spanish (Uruguay)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_205","displayName":"Spanish (Venezuela)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_206","displayName":"Swedish (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_207","displayName":"Uzbek (Cyrillic, Uzbekistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_208","displayName":"Uzbek (Latin, Uzbekistan)","description":null,"helpText":null}]},"4905455d2c13d7cb":{"id":"mathsettings_calculator_programmermode_enabled","displayName":"Enabled","description":"Controls whether the mode is enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":[{"id":"mathsettings_calculator_programmermode_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"mathsettings_calculator_programmermode_enabled_true","displayName":"True","description":null,"helpText":null}]},"493e4cd6c180589d":{"id":"settings_item_mdmoptions_mdmoptions_promptusertoallowbootstraptokenforauthentication","displayName":"Prompt User To Allow Bootstrap Token For Authentication","description":"If `true`, warn the user that they need to reboot into RecoveryOS and allow the MDM server to use the Bootstrap Token for authentication for certain sensitive operations; for example, enabling kernel extensions or installing certain types of software updates. Set this value to `false` if your MDM server doesn't need to perform these operations. The value provided here overrides the value specified in MDM, and only applies when `BootstrapTokenAllowedForAuthentication` is `true` in the `SecurityInfo` response. This value is available for a Mac with Apple silicon in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"dd68a290-1ba7-470f-afca-339f443a767c","categoryName":"MDM Options","options":[{"id":"settings_item_mdmoptions_mdmoptions_promptusertoallowbootstraptokenforauthentication_false","displayName":"Blocked","description":null,"helpText":null},{"id":"settings_item_mdmoptions_mdmoptions_promptusertoallowbootstraptokenforauthentication_true","displayName":"Allowed","description":null,"helpText":null}]},"494eabf785d1c280":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_db_dragdropclose","displayName":"Prevent adding, dragging, dropping and closing the Taskbar's toolbars (User)","description":"Prevents users from manipulating desktop toolbars.\r\n\r\nIf you enable this setting, users cannot add or remove toolbars from the desktop. Also, users cannot drag toolbars on to or off of docked toolbars.\r\n\r\nNote: If users have added or removed toolbars, this setting prevents them from restoring the default configuration.\r\n\r\nTip: To view the toolbars that can be added to the desktop, right-click a docked toolbar (such as the taskbar beside the Start button), and point to \"Toolbars.\"\r\n\r\nAlso, see the \"Prohibit adjusting desktop toolbars\" setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-sz-db-dragdropclose"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_desktop_sz_db_dragdropclose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_sz_db_dragdropclose_1","displayName":"Enabled","description":null,"helpText":null}]},"49a99805b3f8bfce":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_1","displayName":"Prevent use of Offline Files folder (User)","description":"Disables the Offline Files folder.\r\n\r\nThis setting disables the \"View Files\" button on the Offline Files tab. As a result, users cannot use the Offline Files folder to view or open copies of network files stored on their computer. Also, they cannot use the folder to view characteristics of offline files, such as their server status, type, or location.\r\n\r\nThis setting does not prevent users from working offline or from saving local copies of files available offline. Also, it does not prevent them from using other programs, such as Windows Explorer, to view their offline files.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To view the Offline Files Folder, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then click \"View Files.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nocacheviewer-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_1_1","displayName":"Enabled","description":null,"helpText":null}]},"499a1338200b6c7e":{"id":"user_vendor_msft_policy_config_admx_startmenu_noclose","displayName":"Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands (User)","description":"This policy setting prevents users from performing the following commands from the Start menu or Windows Security screen: Shut Down, Restart, Sleep, and Hibernate. This policy setting does not prevent users from running Windows-based programs that perform these functions.\r\n\r\nIf you enable this policy setting, the Power button and the Shut Down, Restart, Sleep, and Hibernate commands are removed from the Start menu. The Power button is also removed from the Windows Security screen, which appears when you press CTRL+ALT+DELETE.\r\n\r\nIf you disable or do not configure this policy setting, the Power button and the Shut Down, Restart, Sleep, and Hibernate commands are available on the Start menu. The Power button on the Windows Security screen is also available.\r\n\r\nNote: Third-party programs certified as compatible with Microsoft Windows Vista, Windows XP SP2, Windows XP SP1, Windows XP, or Windows 2000 Professional are required to support this policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-noclose"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_noclose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_noclose_1","displayName":"Enabled","description":null,"helpText":null}]},"49adf89ffedacd43":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_2_trusted_certificate_thumbprints","displayName":"Comma-separated list of SHA1 trusted certificate thumbprints: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":null},"491fc5ac7ea82dce":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown","displayName":"Allow OpenSearch queries in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-intranetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"49b83d32b8bcbc9a":{"id":"user_vendor_msft_policy_config_browser_disablelockdownofstartpages","displayName":"Disable Lockdown Of Start Pages (User)","description":"You can configure Microsoft Edge to disable the lockdown of Start pages allowing users to change or customize their start pages. To do this, you must also enable the Configure Start Pages or Configure Open Microsoft With policy. When enabled, all configured start pages are editable. Any Start page configured using the Configure Start pages policy is not locked down allowing users to edit their Start pages. If disabled or not configured, the Start pages configured in the Configure Start Pages policy cannot be changed and remain locked down. Supported devices: Domain-joined or MDM-enrolled Related policy: - Configure Start Pages - Configure Open Microsoft Edge With","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#disablelockdownofstartpages"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_disablelockdownofstartpages_0","displayName":"Disabled","description":"Lock down Start pages configured in either the ConfigureOpenEdgeWith policy and HomePages policy.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_disablelockdownofstartpages_1","displayName":"Enabled","description":"Unlocked. Users can make changes to all configured start pages.","helpText":null}]},"4976ead7c011ffdb":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled","displayName":"Enable Get Image Descriptions from Google. (User)","description":"The Get Image Descriptions from Google\r\naccessibility feature enables visually-impaired screen reader users to\r\nget descriptions of unlabeled images on the web. Users who choose to enable it\r\nwill have the option of using an anonymous Google service to provide\r\nautomatic descriptions for unlabeled images they encounter on the web.\r\n\r\nIf this feature is enabled, the content of images will be sent to Google\r\nservers in order to generate a description. No cookies or other user\r\ndata is sent, and Google does not save or log any image content.\r\n\r\nIf this policy is set to Enabled, the\r\nGet Image Descriptions from Google\r\nfeature will be enabled, though it will only affect users who are using a\r\nscreen reader or other similar assistive technology.\r\n\r\nIf this policy is set to Disabled, users will not have the option of enabling\r\nthe feature.\r\n\r\nIf this policy is not set, user can choose to use this feature or not.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"49b74d3d77fd941d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts. (User)","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf unset, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the InsecurePrivateNetworkRequestsAllowed policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4989a12d25ad7690":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors","displayName":"Require online OCSP/CRL checks for local trust anchors (User)","description":"Setting the policy to True means Google Chrome always performs revocation checking for successfully validated server certificates signed by locally installed CA certificates. If Google Chrome can't get revocation status information, Google Chrome treats these certificates as revoked (hard-fail).\r\n\r\nSetting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},"49ead5276610c27c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on these sites (User)","description":"Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4992d102fcc29af0":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls","displayName":"Allow automatic fullscreen on these sites (User)","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or will\r\notherwise fail. Users' personal settings may allow certain origins to call\r\nthis API without a prior user gesture, as described in\r\nhttps://chromestatus.com/feature/6218822004768768.\r\n\r\nThis policy supersedes users' personal settings and allows matching origins to\r\ncall the API without a prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy nor user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"49aef6bd88cbf88c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates","displayName":"Excel 95-97 workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"49fbdb2a38800b98":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8_1","displayName":"True","description":null,"helpText":null}]},"49c5db9aa2e6d43a":{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory_daystokeep_prompt","displayName":"Days to keep pages in History (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":null},"493c14afed95f612":{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_secondaryhomepageslist","displayName":"Secondary home pages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},"49daf3f9ab3291ac":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"49a9e8a466c1ce0c":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled","displayName":"Use built-in DNS client (User)","description":"Controls whether to use the built-in DNS client.\r\n\r\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\r\n\r\nIf you enable this policy, the built-in DNS client is used, if it's available.\r\n\r\nIf you disable this policy, the client is never used.\r\n\r\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4921d84a09269f8b":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls","displayName":"Block images on specific sites (User)","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4964fc9727217810":{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled","displayName":"Enable editing profile in settings (User)","description":"This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page.\r\n\r\nIf you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page.\r\n\r\nIf you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"49a56f4c01493cb8":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains","displayName":"Allow specified sites to access file:// URLs in the PDF Viewer (User)","description":"Controls which sites can access file:// URLs in the PDF Viewer.\r\n\r\nIf you enable this policy, sites in the list can access file:// URLs in the PDF Viewer.\r\n\r\nIf you disable or don't configure this policy, sites cannot access file:// URLs in the PDF Viewer.\r\n\r\nExample value:\r\n\r\nexample.com\r\ncontoso.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_1","displayName":"Enabled","description":null,"helpText":null}]},"49da01a60b888f13":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_1","displayName":"All eligible navigations","description":null,"helpText":null}]},"49c39d4e495ed0f2":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"49aaa31a9c3dc464":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice_l_officelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"491d7424ee4f1834":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright","displayName":"Open Office file links in Office Online (User)","description":"\r\n This policy setting controls which version of Office opens when a hyperlink to an Office file stored on OneDrive, OneDrive for Business, or a SharePoint Online team site is selected.\r\n\r\n By default, a hyperlink to a file stored in one of these locations opens the file in the Office client version of Word, Excel, or PowerPoint. This is the version of Office that is installed on the user’s computer. If Office isn’t installed on the user’s computer, the file is opened in the Office Online version of the program in the user’s web browser.\r\n\r\n If you enable this policy setting, a hyperlink to an Office file stored in one of these locations opens the file in the Office Online version of Word, Excel, or PowerPoint. This opens the file in the user’s web browser.\r\n\r\n If you disable or don’t configure this policy setting, a hyperlink to an Office file stored in one of these locations opens the file in the Office client version of Word, Excel, or PowerPoint, if Office is installed on the user’s computer.\r\n\r\n Note: This policy setting only applies to subscription versions of the Office client, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright_1","displayName":"Enabled","description":null,"helpText":null}]},"49e6a1fa1a3e056c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowpath499","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"49d898ef6923982d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowfriendly461","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"49f9843b11a76871":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag2","displayName":"Label 2: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},"49daded2bc65228f":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard","displayName":"Prevent users from removing Application Guard protection on files. (User)","description":"This policy setting allows you to control whether users can remove Application Guard protection and open a document with full trust in Office.\r\n\r\nIf you enable this policy setting, users can continue to work with Office documents in Application Guard, however, they cannot remove protection and open a document outside Application Guard.\r\n\r\nIf you disable or do not configure this policy settings, Office will by default allow users to remove protection and open a document with full trust.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},"49d30f15d0f03d50":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the Editor Options dialog box.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},"495e5b533c6ae660":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing","displayName":"Prevent My Department Calendar from appearing (User)","description":"This policy setting prevents My Department Calendar from appearing in the navigation pane.\r\n\r\nIf you enable this policy setting, My Department Calendar will not appear in the navigation pane.\r\n\r\nIf you disable or do not configure this policy setting, My Department Calendar will appear in the navigation pane.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing_1","displayName":"Enabled","description":null,"helpText":null}]},"4975a730aaaf5fc9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail","displayName":"Permanently delete Junk E-mail (User)","description":"This policy setting determines whether suspected junk e-mail is permanently deleted instead of moved to the Junk E-mail folder.\r\n\r\nIf you enable this policy setting, suspected junk e-mail is immediately deleted and not moved into the Deleted Items folder.\r\n\r\nIf you disable or do not configure this policy setting, suspected junk e-mail is moved into the Junk E-mail folder.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail_1","displayName":"Enabled","description":null,"helpText":null}]},"49f22de19cf44169":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist","displayName":"Specify path to Safe Recipients list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Safe Recipients list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_1","displayName":"Enabled","description":null,"helpText":null}]},"498d864d762b2940":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2","displayName":"Set Outlook object model custom actions execution prompt (User)","description":"This policy setting controls whether Outlook prompts users before executing a custom action. Custom actions add functionality to Outlook that can be triggered as part of a rule. Among other possible features, custom actions can be created that reply to messages in ways that circumvent the Outlook model's programmatic send protections. \r\n\r\nIf you enable this policy setting, you can choose from four options to control how Outlook functions when a custom action is executed that uses the Outlook object model: \r\n\r\n* Prompt User \r\n* Automatically Approve \r\n* Automatically Deny \r\n* Prompt user based on computer security. This option enforces the default configuration in Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook or another program initiates a custom action using the Outlook object model, users are prompted to allow or reject the action. If this configuration is changed, malicious code can use the Outlook object model to compromise sensitive information or otherwise cause data and computing resources to be at risk. This is the equivalent of choosing Enabled -- Prompt user based on computer security.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"49a066546d66b7b8":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall","displayName":"Calculate all open projects (User)","description":"Specifies that Project should recalculate all open projects.\r\n\r\nIf you enable this setting, all open projects will be recalculated anytime Project does a calculation.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","categoryName":"Calculation options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall_1","displayName":"Enabled","description":null,"helpText":null}]},"49e3a66586e3a094":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects_l_pjfilelocprojects31","displayName":"Projects (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":null},"4966ccf56aa54361":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"49262764de14a0c6":{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport","displayName":"Allow Recall Export (User) (Windows Insiders only)","description":"This policy allows you to determine whether Recall and snapshot information can be exported. Recall and snapshot information may be sensitive, and the files that are exported are unencrypted. Users can export from Settings > Privacy & Security > Recall & Snapshots > Advanced Settings > Export your Recall and snapshot info. Users are warned that the files are unencrypted before exporting. When you set this policy to enabled, users will be able to export Recall and snapshot information. If the policy is set to disabled or not configured, users will not be able to export their Recall and snapshot information.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#allowrecallexport"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport_0","displayName":"Deny export of Recall and snapshots information","description":"Deny export of Recall and snapshots information","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport_1","displayName":"Allow export of Recall and snapshot information","description":"Allow export of Recall and snapshot information","helpText":null}]},"49edeac2cae14b31":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},"49249f488d029ca5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},"495c1d4d047b220c":{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation","displayName":"Stop checking for table alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"49c0706662ca5ba8":{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_1","displayName":"Enabled","description":null,"helpText":null}]},"49527647d335c01f":{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly","displayName":"Force WiFi To Allowed Networks Only","description":"If true, limits device to only join Wi-Fi networks set-up via configuration profile. Requires a supervised device. Available in iOS 14.5 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forcewifitoallowednetworksonly_true","displayName":"True","description":null,"helpText":null}]},"49fa1dc1d2733630":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app_application id","displayName":"Microsoft PowerPoint Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"492ef7ce51a84378":{"id":"com.apple.systemconfiguration_proxies_httpsenable","displayName":"HTTPS Enable","description":"If true, enables secure web proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_httpsenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_httpsenable_1","displayName":"True","description":null,"helpText":null}]},"49e318cf1403919d":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"493c8d927b046987":{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files are deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users can't configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearcachedimagesandfilesonexit_true","displayName":"Enabled","description":null,"helpText":null}]},"49ad39c2902984ca":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurlpostparams_recommended","displayName":"Parameters for an image URL that uses POST (users can override)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it's replaced with real image thumbnail data. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nSpecify Bing's Image Search URL Post Params as:\n'imageBin={google:imageThumbnailBase64}'.\n\nSpecify Google's Image Search URL Post Params as:\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\n\nIf you don't set this policy, image search requests are sent using the GET method.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"49d976846eda6a7f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled","displayName":"Enable Discover access to page contents for AAD profiles (Obsolete)","description":"This policy is obsolete as of Microsoft Edge version 127. Two new Microsoft Edge Policies took its place. Those policies are CopilotPageContext (Control Copilot access to page contents for AAD profiles) and CopilotCDPPageContext (Control Copilot with Commercial Data Protection access to page contents for AAD profiles).\n\nThis policy didn't allow for separate control of Copilot and Copilot with Commercial Data Protection. The new policies allow separate control of these versions of Copilot. The new policies also allow admins to force-enable Copilot access to Microsoft Edge page contents by enabling the policy, whereas DiscoverPageContextEnabled only allows force-disabling of Copilot page access.\n\nThis policy controls Discover access to page contents for AAD profiles. Discover is an extension that hosts Bing Chat. To summarize pages and interact with text selections, it must access the page contents. When enabled, page contents are sent to Bing. This policy doesn't affect MSA profiles.\n\nIf you enable or don't configure this policy, Discover has access to page contents.\n\nIf you disable this policy, Discover can't access page contents.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.discoverpagecontextenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"495dcf846ed1863e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords","displayName":"Allow importing of saved passwords","description":"Allows users to import saved passwords from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import saved passwords is automatically selected.\n\nIf you disable this policy, saved passwords aren't imported on first run, and users can't import them manually.\n\nIf you don't configure this policy, no passwords are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports passwords on first run, but users can select or clear the **passwords** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsavedpasswords_true","displayName":"Enabled","description":null,"helpText":null}]},"49cd22e741b34f97":{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (users can override)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords aren't cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"492ec8cda7d02aa5":{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention","displayName":"Block tracking of users' web-browsing activity","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\n\nIf you disable this policy or don't configure it, users set their own level of tracking prevention.\n\nPolicy options mapping:\n\n* TrackingPreventionOff (0) = Off (no tracking prevention)\n\n* TrackingPreventionBasic (1) = Basic (blocks harmful trackers, content and ads will be personalized)\n\n* TrackingPreventionBalanced (2) = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\n\n* TrackingPreventionStrict (3) = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionoff","displayName":"Off (no tracking prevention)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionbasic","displayName":"Basic (blocks harmful trackers, content and ads will be personalized)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionbalanced","displayName":"Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.trackingprevention_trackingpreventionstrict","displayName":"Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)","description":null,"helpText":null}]},"4981297e44659489":{"id":"contentcaching_peerfilterranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"491675504f96eb11":{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions","displayName":"Choose how BitLocker-protected operating system drives can be recovered","description":"This policy setting allows you to control how BitLocker-protected operating system drives are recovered in the absence of the required startup key information. This policy setting is applied when you turn on BitLocker.\n\nThe \"Allow certificate-based data recovery agent\" check box is used to specify whether a data recovery agent can be used with BitLocker-protected operating system drives. Before a data recovery agent can be used it must be added from the Public Key Policies item in either the Group Policy Management Console or the Local Group Policy Editor. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about adding data recovery agents.\n\nIn \"Configure user storage of BitLocker recovery information\" select whether users are allowed, required, or not allowed to generate a 48-digit recovery password or a 256-bit recovery key.\n\nSelect \"Omit recovery options from the BitLocker setup wizard\" to prevent users from specifying recovery options when they turn on BitLocker on a drive. This means that you will not be able to specify which recovery option to use when you turn on BitLocker, instead BitLocker recovery options for the drive are determined by the policy setting.\n\nIn \"Save BitLocker recovery information to Active Directory Domain Services\", choose which BitLocker recovery information to store in AD DS for operating system drives. If you select \"Backup recovery password and key package\", both the BitLocker recovery password and key package are stored in AD DS. Storing the key package supports recovering data from a drive that has been physically corrupted. If you select \"Backup recovery password only,\" only the recovery password is stored in AD DS.\n\nSelect the \"Do not enable BitLocker until recovery information is stored in AD DS for operating system drives\" check box if you want to prevent users from enabling BitLocker unless the computer is connected to the domain and the backup of BitLocker recovery information to AD DS succeeds.\n\nNote: If the \"Do not enable BitLocker until recovery information is stored in AD DS for operating system drives\" check box is selected, a recovery password is automatically generated.\n\nIf you enable this policy setting, you can control the methods available to users to recover data from BitLocker-protected operating system drives.\n\nIf this policy setting is disabled or not configured, the default recovery options are supported for BitLocker recovery. By default a DRA is allowed, the recovery options can be specified by the user including the recovery password and recovery key, and recovery information is not backed up to AD DS.\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"49835ec03aa37d59":{"id":"device_vendor_msft_policy_config_admx_appxruntime_appxruntimeapplicationcontenturirules_listbox_contenturirules","displayName":"Content URI Rules:","description":null,"helpText":"","infoUrls":[],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":null},"49c6e234123c7f3f":{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r","displayName":"Local Link to a Remote Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2r_1","displayName":"True","description":null,"helpText":null}]},"49e80a53280a81f7":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode","displayName":"Configure user Group Policy loopback processing mode","description":"This policy setting directs the system to apply the set of Group Policy objects for the computer to any user who logs on to a computer affected by this setting. It is intended for special-use computers, such as those in public places, laboratories, and classrooms, where you must modify the user setting based on the computer that is being used.\r\n\r\nBy default, the user's Group Policy Objects determine which user settings apply. If this setting is enabled, then, when a user logs on to this computer, the computer's Group Policy Objects determine which set of Group Policy Objects applies.\r\n\r\nIf you enable this setting, you can select one of the following modes from the Mode box:\r\n\r\n\"Replace\" indicates that the user settings defined in the computer's Group Policy Objects replace the user settings normally applied to the user.\r\n\r\n\"Merge\" indicates that the user settings defined in the computer's Group Policy Objects and the user settings normally applied to the user are combined. If the settings conflict, the user settings in the computer's Group Policy Objects take precedence over the user's normal settings.\r\n\r\nIf you disable this setting or do not configure it, the user's Group Policy Objects determines which user settings apply.\r\n\r\nNote: This setting is effective only when both the computer account and the user account are in at least Windows 2000 domains.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-userpolicymode"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_userpolicymode_1","displayName":"Enabled","description":null,"helpText":null}]},"497b5552ca38bf97":{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate","displayName":"Extend Point and Print connection to search Windows Update","description":"This policy setting allows you to manage where client computers search for Point and Printer drivers.\r\n\r\nIf you enable this policy setting, the client computer will continue to search for compatible Point and Print drivers from Windows Update after it fails to find the compatible driver from the local driver store and the server driver cache.\r\n\r\nIf you disable this policy setting, the client computer will only search the local driver store and server driver cache for compatible Point and Print drivers. If it is unable to find a compatible driver, then the Point and Print connection will fail.\r\n\r\nThis policy setting is not configured by default, and the behavior depends on the version of Windows that you are using.\r\nBy default, Windows Ultimate, Professional and Home SKUs will continue to search for compatible Point and Print drivers from Windows Update, if needed. However, you must explicitly enable this policy setting for other versions of Windows (for example Windows Enterprise, and all versions of Windows Server 2008 R2 and later) to have the same behavior.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-donotinstallcompatibledriverfromwindowsupdate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_donotinstallcompatibledriverfromwindowsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},"49c3f9be48c8e2f3":{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2","displayName":"Turn off the Store application","description":"Denies or allows access to the Store application.\r\n\r\nIf you enable this setting, access to the Store application is denied. Access to the Store is required for installing app updates.\r\n\r\nIf you disable or don't configure this setting, access to the Store application is allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-removewindowsstore-2"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_removewindowsstore_2_1","displayName":"Enabled","description":null,"helpText":null}]},"49327ee80b5fa556":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_autoopenfiletypesdesc","displayName":"List of file types that should be automatically opened on download (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"49ddbefd92d53a8d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_explicitlyallowednetworkportsdesc","displayName":"Explicitly allowed network ports (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"49aab8d7a5987075":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability","displayName":"Profile picker availability on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_0","displayName":"Profile picker available at startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_1","displayName":"Profile picker disabled at startup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_2","displayName":"Profile picker forced at startup","description":null,"helpText":null}]},"4915ae5e70c84c33":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_defaultsearchprovidericonurl","displayName":"Default search provider icon (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"490209ddd78385f1":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings","displayName":"Extension management settings","description":"Setting the policy controls extension management settings for Google Chrome, including any controlled by existing extension-related policies. The policy supersedes any legacy policies that might be set.\r\n\r\nThis policy maps an extension ID or an update URL to its specific setting only. A default configuration can be set for the special ID \"*\", which applies to all extensions without a custom configuration in this policy. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest ( http://support.google.com/chrome/a?p=Configure_ExtensionSettings_policy ). If the 'override_update_url' flag is set to true, the extension is installed and updated using the \"update\" URL specified in the ExtensionInstallForcelist policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is a Chrome Web Store url.\r\n\r\nNote: For Windows® instances not joined to a Microsoft® Active Directory® domain, forced installation is limited to apps and extensions listed in the Chrome Web Store.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=ExtensionSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"abcdefghijklmnopabcdefghijklmnop\": {\r\n \"installation_mode\": \"allowed\",\r\n \"blocked_permissions\": [\r\n \"history\"\r\n ],\r\n \"minimum_version_required\": \"1.0.1\",\r\n \"toolbar_pin\": \"force_pinned\"\r\n },\r\n \"bcdefghijklmnopabcdefghijklmnopa\": {\r\n \"installation_mode\": \"force_installed\",\r\n \"update_url\": \"https://example.com/update_url\",\r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ],\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.example.com\"\r\n ],\r\n \"runtime_allowed_hosts\": [\r\n \"*://good.example.com\"\r\n ]\r\n },\r\n \"cdefghijklmnopabcdefghijklmnopab\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_install_message\": \"Custom error message.\"\r\n },\r\n \"defghijklmnopabcdefghijklmnopabc,efghijklmnopabcdefghijklmnopabcd\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_install_message\": \"Custom error message.\"\r\n },\r\n \"update_url:https://www.example.com/update.xml\": {\r\n \"blocked_permissions\": [\r\n \"wallpaper\"\r\n ],\r\n \"allowed_permissions\": [\r\n \"downloads\"\r\n ],\r\n \"installation_mode\": \"allowed\"\r\n },\r\n \"fghijklmnopabcdefghijklmnopabcde\": {\r\n \"installation_mode\": \"removed\",\r\n \"blocked_install_message\": \"Custom removal message.\"\r\n },\r\n \"ghijklmnopabcdefghijklmnopabcdef\": {\r\n \"installation_mode\": \"force_installed\",\r\n \"update_url\": \"https://example.com/update_url\",\r\n \"override_update_url\": true\r\n },\r\n \"*\": {\r\n \"installation_mode\": \"blocked\",\r\n \"blocked_permissions\": [\r\n \"downloads\",\r\n \"bookmarks\"\r\n ],\r\n \"install_sources\": [\r\n \"https://company-intranet/chromeapps\"\r\n ],\r\n \"allowed_types\": [\r\n \"hosted_app\"\r\n ],\r\n \"runtime_blocked_hosts\": [\r\n \"*://*.example.com\"\r\n ],\r\n \"runtime_allowed_hosts\": [\r\n \"*://good.example.com\"\r\n ],\r\n \"blocked_install_message\": \"Custom error message.\"\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensionsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"491c3e1beaad9fa6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingblockedforurls_filehandlingblockedforurlsdesc","displayName":"Block the File Handling API on these web apps (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"499ddb3fe9c7cf5f":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeoutlookpersonalization","displayName":"Include Outlook Personalization","description":"[ENABLED BY DEFAULT]\r\n\r\nOutlook personalization data will be included in the ODFC Container.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\IncludeOutlookPersonalization\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeoutlookpersonalization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeoutlookpersonalization_1","displayName":"Enabled","description":null,"helpText":null}]},"4928a837121f0728":{"id":"device_vendor_msft_policy_config_internetexplorer_allowaddonlist_addonlist","displayName":"Add-on List","description":"","helpText":"","infoUrls":[],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":null},"492db2ce0b51ec98":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials","displayName":"Require logon credentials","description":"\r\nRequires the user to provide logon credentials for Microsoft Lync rather than automatically using the Windows credentials when Microsoft Lync authenticates the user using NTLM or Kerberos.\r\n\r\nIf you enable this policy setting, Microsoft Lync requires the user to provide logon credentials.\r\n\r\nIf you disable or do not configure this policy setting, Microsoft Lync authenticates the user based on the logon credentials for Windows.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablentcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},"497705a2ed952037":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Online revocation checks don't provide a significant security benefit and are disabled by default.\r\n\r\nIf you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. \"Soft fail\" means that if the revocation server can't be reached, the certificate will be considered valid.\r\n\r\nIf you disable the policy or don't configure it, Microsoft Edge won't perform online revocation checks.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enableonlinerevocationchecks_1","displayName":"Enabled","description":null,"helpText":null}]},"492b266927fb4178":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch","displayName":"Enforce Bing SafeSearch (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_0","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_1","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcebingsafesearch_forcebingsafesearch_2","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},"49243d6ef11de6f3":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions","description":"Specifies the URL for the search engine used to provide search suggestions. The URL contains the string '{searchTerms}', which is replaced at query time by the text the user has entered so far.\r\n\r\nThis policy is optional. If you don't configure it, users won't see search suggestions; they will see suggestions from their browsing history and favorites.\r\n\r\nBing's suggest URL can be specified as:\r\n\r\n'{bing:baseURL}qbox?query={searchTerms}'.\r\n\r\nGoogle's suggest URL can be specified as: '{google:baseURL}complete/search?output=chrome&q={searchTerms}'.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/suggest?q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidersuggesturl_1","displayName":"Enabled","description":null,"helpText":null}]},"491f607d46c56e35":{"id":"device_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge~httpauthentication_allhttpauthschemesallowedfororigins_allhttpauthschemesallowedfororiginsdesc","displayName":"List of origins that allow all HTTP authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},"4978dc958a5de515":{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls","displayName":"Block sites from making requests to local network endpoints.","description":"List of URL patterns. Requests initiated from websites served by matching origins are blocked from issuing Local Network Access requests.\r\n\r\nIf an origin is covered by both this policy and by 'LocalNetworkAccessAllowedForUrls' (Allow sites to make requests to local network endpoints.), this policy takes precedence.\r\n\r\nDepending on the stage of the rollout of Local Network Access, LocalNetworkAccessRestrictionsEnabled may also need to be enabled for this policy to block Local Network Access requests.\r\n\r\nFor origins not covered by the patterns specified here, the user's personal configuration will apply.\r\n\r\nFor detailed information on valid URL patterns, please see https://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns.\r\n\r\nNote: This policy improves local network security by blocking specified public websites from accessing private IP addresses. It helps prevent unauthorized external sites from reaching internal resources unless explicitly permitted. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"492fd606333b4c74":{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports","displayName":"Explicitly allowed network ports","description":"There is a list of restricted ports built into Microsoft Edge. Connections to these ports will fail. This policy allows bypassing that list. The set of ports is defined as a comma-separated list that outgoing connections should be permitted on.\r\n\r\nPorts are restricted to prevent Microsoft Edge from being used as a vector to exploit various network vulnerabilities. Setting this policy may expose your network to attacks. This policy is intended as a temporary workaround for error code \"ERR_UNSAFE_PORT\" while migrating a service running on a blocked port to a standard port (for example port 80 or 443).\r\n\r\nMalicious websites can easily detect that this policy is set, and for which ports, then use that information to target attacks.\r\n\r\nEach port listed in this policy is labeled with a date that it can be unblocked until. After that date the port will be restricted regardless of if it's specified by the value of this policy.\r\n\r\nLeaving the value empty or unset means that all restricted ports will be blocked. Invalid port values set through this policy will be ignored while valid ones will still be applied.\r\n\r\nThis policy overrides the \"--explicitly-allowed-ports\" command-line option.\r\n\r\nPolicy options mapping:\r\n\r\n* 554 (554) = port 554 (can be unblocked until 2021/10/15)\r\n\r\n* 10080 (10080) = port 10080 (can be unblocked until 2022/04/01)\r\n\r\n* 6566 (6566) = port 6566 (can be unblocked until 2021/10/15)\r\n\r\n* 989 (989) = port 989 (can be unblocked until 2022/02/01)\r\n\r\n* 990 (990) = port 990 (can be unblocked until 2022/02/01)\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\n10080","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_explicitlyallowednetworkports_1","displayName":"Enabled","description":null,"helpText":null}]},"4925205a5eba28ec":{"id":"device_vendor_msft_policy_config_mssecurityguide_enablestructuredexceptionhandlingoverwriteprotection","displayName":"Enable Structured Exception Handling Overwrite Protection (SEHOP)","description":"If this setting is enabled, SEHOP is enforced. For more information, see https://support.microsoft.com/en-us/help/956607/how-to-enable-structured-exception-handling-overwrite-protection-sehop-in-windows-operating-systems.\n\nIf this setting is disabled or not configured, SEHOP is not enforced for 32-bit processes.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-mssecurityguide#mssecurityguide-enablestructuredexceptionhandlingoverwriteprotection"],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_mssecurityguide_enablestructuredexceptionhandlingoverwriteprotection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_mssecurityguide_enablestructuredexceptionhandlingoverwriteprotection_1","displayName":"Enabled","description":null,"helpText":null}]},"49517dc7fc6b6f7a":{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_pictures_checkbox","displayName":"Pictures (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_pictures_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_pictures_checkbox_1","displayName":"True","description":null,"helpText":null}]},"49f164b894406ce6":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_sharepointonpremprioritization_dropdown","displayName":"Authenticate first against: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_sharepointonpremprioritization_dropdown_0","displayName":"SharePoint Online","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_sharepointonpremprioritization_sharepointonpremprioritization_dropdown_1","displayName":"SharePoint Server 2019","description":null,"helpText":null}]},"49a8bb1b03904c4c":{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_disableautoconfig_disableautoconfigtypes","displayName":"Disabled Account Types: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"49e682c1ebb64fdc":{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery","displayName":"Select Power Button Action On Battery","description":"This policy setting specifies the action that Windows takes when a user presses the power button. Possible actions include: 0 - Take no action 1 - Sleep 2 - Hibernate 3 - Shut down If you enable this policy setting, you must select the desired action. If you disable this policy setting or do not configure it, users can see and change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#selectpowerbuttonactiononbattery"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":[{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery_0","displayName":"Take no action","description":"Take no action","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery_1","displayName":"Sleep","description":"Sleep","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery_2","displayName":"System hibernate sleep state","description":"System hibernate sleep state","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectpowerbuttonactiononbattery_3","displayName":"System shutdown","description":"System shutdown","helpText":null}]},"49c50140298175aa":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscalendar_forcedenytheseapps","displayName":"Let Apps Access Calendar Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to the calendar. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscalendar_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"499f6f013d85f1a0":{"id":"device_vendor_msft_policy_config_start_hidelock","displayName":"Hide Lock","description":"Enabling this policy hides \"Lock\" from appearing in the user tile in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidelock"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hidelock_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hidelock_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"49b9d9936aa9b426":{"id":"device_vendor_msft_policy_config_start_hiderestart","displayName":"Hide Restart","description":"Enabling this policy hides \"Restart/Update and restart\" from appearing in the power button in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hiderestart"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hiderestart_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hiderestart_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"49f325080f5ffdc9":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_payloadtenantid","displayName":"Azure AD Directory ID:","description":"","helpText":"","infoUrls":[],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":null},"49a4a81390a13ef5":{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy","displayName":"Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy_1","displayName":"Always allow updates (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy_2","displayName":"Manual updates only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy_3","displayName":"Automatic silent updates only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_applications_pol_defaultupdatepolicy_part_updatepolicy_0","displayName":"Updates disabled","description":null,"helpText":null}]},"49ca135cbd54f81f":{"id":"enrollment_autopilot_dpp_language","displayName":"Language (Region)","description":"Specify the language and region that will be used.","helpText":"","infoUrls":[],"categoryId":"72e4d72b-e01e-427c-a3b6-05bdcf04ef8d","categoryName":null,"options":[{"id":"enrollment_autopilot_dpp_language_0","displayName":"Operating system default","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_1","displayName":"User select","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_2","displayName":"Arabic (U.A.E.)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_3","displayName":"Arabic (Bahrain)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_4","displayName":"Arabic (Algeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_5","displayName":"Arabic (Egypt)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_6","displayName":"Arabic (Iraq)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_7","displayName":"Arabic (Jordan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_8","displayName":"Arabic (Kuwait)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_9","displayName":"Arabic (Lebanon)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_10","displayName":"Arabic (Libya)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_11","displayName":"Arabic (Morocco)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_12","displayName":"Arabic (Oman)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_13","displayName":"Arabic (Qatar)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_14","displayName":"Arabic (Saudi Arabia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_15","displayName":"Arabic (Syria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_16","displayName":"Arabic (Tunisia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_17","displayName":"Arabic (Yemen)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_18","displayName":"Azerbaijani (Cyrillic, Azerbaijan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_19","displayName":"Azerbaijani (Latin, Azerbaijan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_20","displayName":"Bangla (Bangladesh)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_21","displayName":"Bangla (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_22","displayName":"Bosnian (Cyrillic)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_23","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_24","displayName":"Chinese (PRC)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_25","displayName":"Chinese (Hong Kong S.A.R.)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_26","displayName":"Chinese (Macao S.A.R.)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_27","displayName":"Chinese (Singapore)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_28","displayName":"Chinese (Taiwan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_29","displayName":"Croatian (Latin)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_30","displayName":"Croatian (Croatia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_31","displayName":"Dutch (Belgium)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_32","displayName":"Dutch (Netherlands)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_33","displayName":"English (Australia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_34","displayName":"English (Belize)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_35","displayName":"English (Canada)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_36","displayName":"English (Caribbean)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_37","displayName":"English (Ireland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_38","displayName":"English (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_39","displayName":"English (Jamaica)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_40","displayName":"English (Malaysia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_41","displayName":"English (New Zealand)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_42","displayName":"English (Republic of the Philippines)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_43","displayName":"English (Singapore)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_44","displayName":"English (Trinidad and Tobago)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_45","displayName":"English (United Kingdom)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_46","displayName":"English (United States)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_47","displayName":"English (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_48","displayName":"English (Zimbabwe)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_49","displayName":"French (Belgium)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_50","displayName":"French (Canada)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_51","displayName":"French (Switzerland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_52","displayName":"French (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_53","displayName":"French (Luxembourg)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_54","displayName":"French (Monaco)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_55","displayName":"German (Austria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_56","displayName":"German (Switzerland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_57","displayName":"German (Germany)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_58","displayName":"German (Liechtenstein)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_59","displayName":"German (Luxembourg)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_60","displayName":"Inuktitut (Syllabics, Canada)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_61","displayName":"Inuktitut (Latin, Canada)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_62","displayName":"Italian (Switzerland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_63","displayName":"Italian (Italy)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_64","displayName":"Malay (Brunei Darussalam)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_65","displayName":"Malay (Malaysia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_66","displayName":"Mongolian (Traditional Mongolian, PRC)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_67","displayName":"Mongolian (Cyrillic, Mongolia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_68","displayName":"Norwegian (Bokmål)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_69","displayName":"Norwegian (Nynorsk)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_70","displayName":"Portuguese (Brazil)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_71","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_72","displayName":"Quechua (Bolivia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_73","displayName":"Quechua (Ecuador)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_74","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_75","displayName":"Sami, Lule (Norway)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_76","displayName":"Sami, Lule (Sweden)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_77","displayName":"Sami, Northern (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_78","displayName":"Sami, Northern (Norway)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_79","displayName":"Sami, Northern (Sweden)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_80","displayName":"Sami, Southern (Norway)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_81","displayName":"Sami, Southern (Sweden)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_82","displayName":"Sami, Inari (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_83","displayName":"Sami, Skolt (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_84","displayName":"Afrikaans (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_85","displayName":"Albanian (Albania)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_86","displayName":"Alsatian (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_87","displayName":"Amharic (Ethiopia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_88","displayName":"Armenian (Armenia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_89","displayName":"Assamese (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_90","displayName":"Bashkir (Russia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_91","displayName":"Basque (Basque)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_92","displayName":"Belarusian (Belarus)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_93","displayName":"Breton (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_94","displayName":"Bulgarian (Bulgaria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_95","displayName":"Catalan (Catalan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_96","displayName":"Corsican (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_97","displayName":"Czech (Czech Republic)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_98","displayName":"Danish (Denmark)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_99","displayName":"Dari (Afghanistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_100","displayName":"Divehi (Maldives)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_101","displayName":"Estonian (Estonia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_102","displayName":"Faroese (Faroe Islands)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_103","displayName":"Filipino (Philippines)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_104","displayName":"Finnish (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_105","displayName":"Frisian (Netherlands)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_106","displayName":"Galician (Galician)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_107","displayName":"Georgian (Georgia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_108","displayName":"Greek (Greece)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_109","displayName":"Greenlandic (Greenland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_110","displayName":"Gujarati (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_111","displayName":"Hausa (Latin, Nigeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_112","displayName":"Hebrew (Israel)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_113","displayName":"Hindi (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_114","displayName":"Hungarian (Hungary)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_115","displayName":"Icelandic (Iceland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_116","displayName":"Igbo (Nigeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_117","displayName":"Indonesian (Indonesia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_118","displayName":"Irish (Ireland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_119","displayName":"isiXhosa (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_120","displayName":"isiZulu (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_121","displayName":"Japanese (Japan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_122","displayName":"Kannada (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_123","displayName":"Kazakh (Kazakhstan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_124","displayName":"Khmer (Cambodia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_125","displayName":"K'iche (Guatemala)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_126","displayName":"Kinyarwanda (Rwanda)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_127","displayName":"Kiswahili (Kenya)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_128","displayName":"Konkani (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_129","displayName":"Korean (Korea)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_130","displayName":"Kyrgyz (Kyrgyzstan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_131","displayName":"Lao (Lao P.D.R.)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_132","displayName":"Latvian (Latvia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_133","displayName":"Lithuanian (Lithuania)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_134","displayName":"Lower Sorbian (Germany)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_135","displayName":"Luxembourgish (Luxembourg)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_136","displayName":"Macedonian (Macedonia, FYRO)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_137","displayName":"Malayalam (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_138","displayName":"Maltese (Malta)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_139","displayName":"Maori (New Zealand)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_140","displayName":"Mapudungun (Chile)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_141","displayName":"Marathi (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_142","displayName":"Mohawk (Mohawk)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_143","displayName":"Nepali (Nepal)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_144","displayName":"Occitan (France)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_145","displayName":"Odia (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_146","displayName":"Pashto (Afghanistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_147","displayName":"Persian","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_148","displayName":"Polish (Poland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_149","displayName":"Punjabi (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_150","displayName":"Romanian (Romania)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_151","displayName":"Romansh (Switzerland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_152","displayName":"Russian (Russia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_153","displayName":"Sanskrit (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_154","displayName":"Sesotho sa Leboa (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_156","displayName":"Setswana (South Africa)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_157","displayName":"Sinhala (Sri Lanka)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_158","displayName":"Slovak (Slovakia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_159","displayName":"Slovenian (Slovenia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_160","displayName":"Swedish (Sweden)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_161","displayName":"Syriac (Syria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_162","displayName":"Tajik (Cyrillic, Tajikistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_163","displayName":"Tamazight (Latin, Algeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_164","displayName":"Tamil (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_165","displayName":"Tatar (Russia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_166","displayName":"Telugu (India)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_167","displayName":"Thai (Thailand)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_168","displayName":"Tibetan","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_169","displayName":"Turkish (Turkey)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_170","displayName":"Turkmen (Turkmenistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_171","displayName":"Uighur (PRC)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_172","displayName":"Ukrainian (Ukraine)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_173","displayName":"Urdu (Islamic Republic of Pakistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_174","displayName":"Vietnamese (Vietnam)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_175","displayName":"Welsh (United Kingdom)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_176","displayName":"Wolof (Senegal)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_177","displayName":"Yakut (Russia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_178","displayName":"Yi (PRC)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_179","displayName":"Yoruba (Nigeria)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_180","displayName":"Serbian (Cyrillic)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_181","displayName":"Serbian (Cyrillic, Serbia and Montenegro)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_182","displayName":"Serbian (Latin)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_183","displayName":"Serbian (Latin, Serbia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_184","displayName":"Lower Sorbian (Germany)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_185","displayName":"Upper Sorbian (Germany)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_186","displayName":"Spanish (Spain, Traditional Sort)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_187","displayName":"Spanish (Argentina)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_188","displayName":"Spanish (Bolivia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_189","displayName":"Spanish (Chile)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_190","displayName":"Spanish (Colombia)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_191","displayName":"Spanish (Costa Rica)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_192","displayName":"Spanish (Dominican Republic)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_193","displayName":"Spanish (Ecuador)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_194","displayName":"Spanish (Guatemala)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_195","displayName":"Spanish (Honduras)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_196","displayName":"Spanish (Mexico)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_197","displayName":"Spanish (Nicaragua)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_198","displayName":"Spanish (Panama)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_199","displayName":"Spanish (Peru)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_200","displayName":"Spanish (Puerto Rico)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_201","displayName":"Spanish (Paraguay)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_202","displayName":"Spanish (El Salvador)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_203","displayName":"Spanish (United States)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_204","displayName":"Spanish (Uruguay)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_205","displayName":"Spanish (Venezuela)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_206","displayName":"Swedish (Finland)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_207","displayName":"Uzbek (Cyrillic, Uzbekistan)","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_language_208","displayName":"Uzbek (Latin, Uzbekistan)","description":null,"helpText":null}]},"4905455d2c13d7cb":{"id":"mathsettings_calculator_programmermode_enabled","displayName":"Enabled","description":"Controls whether the mode is enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":[{"id":"mathsettings_calculator_programmermode_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"mathsettings_calculator_programmermode_enabled_true","displayName":"True","description":null,"helpText":null}]},"493e4cd6c180589d":{"id":"settings_item_mdmoptions_mdmoptions_promptusertoallowbootstraptokenforauthentication","displayName":"Prompt User To Allow Bootstrap Token For Authentication","description":"If `true`, warn the user that they need to reboot into RecoveryOS and allow the MDM server to use the Bootstrap Token for authentication for certain sensitive operations; for example, enabling kernel extensions or installing certain types of software updates. Set this value to `false` if your MDM server doesn't need to perform these operations. The value provided here overrides the value specified in MDM, and only applies when `BootstrapTokenAllowedForAuthentication` is `true` in the `SecurityInfo` response. This value is available for a Mac with Apple silicon in macOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"dd68a290-1ba7-470f-afca-339f443a767c","categoryName":"MDM Options","options":[{"id":"settings_item_mdmoptions_mdmoptions_promptusertoallowbootstraptokenforauthentication_false","displayName":"Blocked","description":null,"helpText":null},{"id":"settings_item_mdmoptions_mdmoptions_promptusertoallowbootstraptokenforauthentication_true","displayName":"Allowed","description":null,"helpText":null}]},"494eabf785d1c280":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_db_dragdropclose","displayName":"Prevent adding, dragging, dropping and closing the Taskbar's toolbars (User)","description":"Prevents users from manipulating desktop toolbars.\r\n\r\nIf you enable this setting, users cannot add or remove toolbars from the desktop. Also, users cannot drag toolbars on to or off of docked toolbars.\r\n\r\nNote: If users have added or removed toolbars, this setting prevents them from restoring the default configuration.\r\n\r\nTip: To view the toolbars that can be added to the desktop, right-click a docked toolbar (such as the taskbar beside the Start button), and point to \"Toolbars.\"\r\n\r\nAlso, see the \"Prohibit adjusting desktop toolbars\" setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-sz-db-dragdropclose"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_desktop_sz_db_dragdropclose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_sz_db_dragdropclose_1","displayName":"Enabled","description":null,"helpText":null}]},"49a99805b3f8bfce":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_1","displayName":"Prevent use of Offline Files folder (User)","description":"Disables the Offline Files folder.\r\n\r\nThis setting disables the \"View Files\" button on the Offline Files tab. As a result, users cannot use the Offline Files folder to view or open copies of network files stored on their computer. Also, they cannot use the folder to view characteristics of offline files, such as their server status, type, or location.\r\n\r\nThis setting does not prevent users from working offline or from saving local copies of files available offline. Also, it does not prevent them from using other programs, such as Windows Explorer, to view their offline files.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To view the Offline Files Folder, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then click \"View Files.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-nocacheviewer-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_nocacheviewer_1_1","displayName":"Enabled","description":null,"helpText":null}]},"499a1338200b6c7e":{"id":"user_vendor_msft_policy_config_admx_startmenu_noclose","displayName":"Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands (User)","description":"This policy setting prevents users from performing the following commands from the Start menu or Windows Security screen: Shut Down, Restart, Sleep, and Hibernate. This policy setting does not prevent users from running Windows-based programs that perform these functions.\r\n\r\nIf you enable this policy setting, the Power button and the Shut Down, Restart, Sleep, and Hibernate commands are removed from the Start menu. The Power button is also removed from the Windows Security screen, which appears when you press CTRL+ALT+DELETE.\r\n\r\nIf you disable or do not configure this policy setting, the Power button and the Shut Down, Restart, Sleep, and Hibernate commands are available on the Start menu. The Power button on the Windows Security screen is also available.\r\n\r\nNote: Third-party programs certified as compatible with Microsoft Windows Vista, Windows XP SP2, Windows XP SP1, Windows XP, or Windows 2000 Professional are required to support this policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-noclose"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_noclose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_noclose_1","displayName":"Enabled","description":null,"helpText":null}]},"49adf89ffedacd43":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_trusted_certificate_thumbprints_2_trusted_certificate_thumbprints","displayName":"Comma-separated list of SHA1 trusted certificate thumbprints: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":null},"491fc5ac7ea82dce":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown","displayName":"Allow OpenSearch queries in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-intranetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_intranetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"49b83d32b8bcbc9a":{"id":"user_vendor_msft_policy_config_browser_disablelockdownofstartpages","displayName":"Disable Lockdown Of Start Pages (User)","description":"You can configure Microsoft Edge to disable the lockdown of Start pages allowing users to change or customize their start pages. To do this, you must also enable the Configure Start Pages or Configure Open Microsoft With policy. When enabled, all configured start pages are editable. Any Start page configured using the Configure Start pages policy is not locked down allowing users to edit their Start pages. If disabled or not configured, the Start pages configured in the Configure Start Pages policy cannot be changed and remain locked down. Supported devices: Domain-joined or MDM-enrolled Related policy: - Configure Start Pages - Configure Open Microsoft Edge With","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#disablelockdownofstartpages"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_disablelockdownofstartpages_0","displayName":"Disabled","description":"Lock down Start pages configured in either the ConfigureOpenEdgeWith policy and HomePages policy.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_disablelockdownofstartpages_1","displayName":"Enabled","description":"Unlocked. Users can make changes to all configured start pages.","helpText":null}]},"4976ead7c011ffdb":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled","displayName":"Enable Get Image Descriptions from Google. (User)","description":"The Get Image Descriptions from Google\r\naccessibility feature enables visually-impaired screen reader users to\r\nget descriptions of unlabeled images on the web. Users who choose to enable it\r\nwill have the option of using an anonymous Google service to provide\r\nautomatic descriptions for unlabeled images they encounter on the web.\r\n\r\nIf this feature is enabled, the content of images will be sent to Google\r\nservers in order to generate a description. No cookies or other user\r\ndata is sent, and Google does not save or log any image content.\r\n\r\nIf this policy is set to Enabled, the\r\nGet Image Descriptions from Google\r\nfeature will be enabled, though it will only affect users who are using a\r\nscreen reader or other similar assistive technology.\r\n\r\nIf this policy is set to Disabled, users will not have the option of enabling\r\nthe feature.\r\n\r\nIf this policy is not set, user can choose to use this feature or not.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_accessibilityimagelabelsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"49b74d3d77fd941d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts. (User)","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf unset, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the InsecurePrivateNetworkRequestsAllowed policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4989a12d25ad7690":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors","displayName":"Require online OCSP/CRL checks for local trust anchors (User)","description":"Setting the policy to True means Google Chrome always performs revocation checking for successfully validated server certificates signed by locally installed CA certificates. If Google Chrome can't get revocation status information, Google Chrome treats these certificates as revoked (hard-fail).\r\n\r\nSetting the policy to False or leaving it unset means Google Chrome uses existing online revocation-checking settings.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_requireonlinerevocationchecksforlocalanchors_1","displayName":"Enabled","description":null,"helpText":null}]},"49ead5276610c27c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on these sites (User)","description":"Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4992d102fcc29af0":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls","displayName":"Allow automatic fullscreen on these sites (User)","description":"For security reasons, the\r\nrequestFullscreen() web API\r\nrequires a prior user gesture (\"transient activation\") to be called or will\r\notherwise fail. Users' personal settings may allow certain origins to call\r\nthis API without a prior user gesture, as described in\r\nhttps://chromestatus.com/feature/6218822004768768.\r\n\r\nThis policy supersedes users' personal settings and allows matching origins to\r\ncall the API without a prior user gesture.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nOrigins matching both blocked and allowed policy patterns will be blocked.\r\nOrigins not specified by policy nor user settings will require a prior user\r\ngesture to call this API.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"49aef6bd88cbf88c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates","displayName":"Excel 95-97 workbooks and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel9597workbooksandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"49fbdb2a38800b98":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_allowsubfolders8_1","displayName":"True","description":null,"helpText":null}]},"49c5db9aa2e6d43a":{"id":"user_vendor_msft_policy_config_internetexplorer_disableconfiguringhistory_daystokeep_prompt","displayName":"Days to keep pages in History (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":null},"493c14afed95f612":{"id":"user_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_secondaryhomepageslist","displayName":"Secondary home pages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":null},"49daf3f9ab3291ac":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"49a9e8a466c1ce0c":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled","displayName":"Use built-in DNS client (User)","description":"Controls whether to use the built-in DNS client.\r\n\r\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\r\n\r\nIf you enable this policy, the built-in DNS client is used, if it's available.\r\n\r\nIf you disable this policy, the client is never used.\r\n\r\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_builtindnsclientenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4921d84a09269f8b":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls","displayName":"Block images on specific sites (User)","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"4964fc9727217810":{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled","displayName":"Enable editing profile in settings (User)","description":"This policy controls whether users can modify profile properties (such as profile avatar) from the profile settings page.\r\n\r\nIf you enable or don't configure this policy, users can edit profile properties. The edit button is available on the profile settings page.\r\n\r\nIf you disable this policy, users can't edit profile properties. The edit button is disabled on the profile settings page.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~identity_editprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"49a56f4c01493cb8":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains","displayName":"Allow specified sites to access file:// URLs in the PDF Viewer (User)","description":"Controls which sites can access file:// URLs in the PDF Viewer.\r\n\r\nIf you enable this policy, sites in the list can access file:// URLs in the PDF Viewer.\r\n\r\nIf you disable or don't configure this policy, sites cannot access file:// URLs in the PDF Viewer.\r\n\r\nExample value:\r\n\r\nexample.com\r\ncontoso.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge~contentsettings_pdflocalfileaccessallowedfordomains_1","displayName":"Enabled","description":null,"helpText":null}]},"49da01a60b888f13":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload","displayName":"Require that the Enterprise Mode Site List is available before tab navigation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_delaynavigationsforinitialsitelistdownload_delaynavigationsforinitialsitelistdownload_1","displayName":"All eligible navigations","description":null,"helpText":null}]},"49c39d4e495ed0f2":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"49aaa31a9c3dc464":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceoffice_l_officelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"491d7424ee4f1834":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright","displayName":"Open Office file links in Office Online (User)","description":"\r\n This policy setting controls which version of Office opens when a hyperlink to an Office file stored on OneDrive, OneDrive for Business, or a SharePoint Online team site is selected.\r\n\r\n By default, a hyperlink to a file stored in one of these locations opens the file in the Office client version of Word, Excel, or PowerPoint. This is the version of Office that is installed on the user’s computer. If Office isn’t installed on the user’s computer, the file is opened in the Office Online version of the program in the user’s web browser.\r\n\r\n If you enable this policy setting, a hyperlink to an Office file stored in one of these locations opens the file in the Office Online version of Word, Excel, or PowerPoint. This opens the file in the user’s web browser.\r\n\r\n If you disable or don’t configure this policy setting, a hyperlink to an Office file stored in one of these locations opens the file in the Office client version of Word, Excel, or PowerPoint, if Office is installed on the user’s computer.\r\n\r\n Note: This policy setting only applies to subscription versions of the Office client, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablelinksopenright_1","displayName":"Enabled","description":null,"helpText":null}]},"49e6a1fa1a3e056c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowpath499","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"49d898ef6923982d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowfriendly461","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"49f9843b11a76871":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitcustomtags_l_officereadinesstoolkitcustomtagstag2","displayName":"Label 2: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":null},"49daded2bc65228f":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard","displayName":"Prevent users from removing Application Guard protection on files. (User)","description":"This policy setting allows you to control whether users can remove Application Guard protection and open a document with full trust in Office.\r\n\r\nIf you enable this policy setting, users can continue to work with Office documents in Application Guard, however, they cannot remove protection and open a document outside Application Guard.\r\n\r\nIf you disable or do not configure this policy settings, Office will by default allow users to remove protection and open a document with full trust.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnofftrustpromotionfordocumentsinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},"49d30f15d0f03d50":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties","displayName":"Show Mini Toolbar on selection (User)","description":"Disabling this policy setting will result in Mini Toolbar not being displayed on text selection. By default, Mini Toolbar on selection is enabled and its visibility can be changed via a setting in the Editor Options dialog box.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_allowselectionfloaties_1","displayName":"Enabled","description":null,"helpText":null}]},"495e5b533c6ae660":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing","displayName":"Prevent My Department Calendar from appearing (User)","description":"This policy setting prevents My Department Calendar from appearing in the navigation pane.\r\n\r\nIf you enable this policy setting, My Department Calendar will not appear in the navigation pane.\r\n\r\nIf you disable or do not configure this policy setting, My Department Calendar will appear in the navigation pane.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_preventmydepartmentcalendarfromappearing_1","displayName":"Enabled","description":null,"helpText":null}]},"4975a730aaaf5fc9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail","displayName":"Permanently delete Junk E-mail (User)","description":"This policy setting determines whether suspected junk e-mail is permanently deleted instead of moved to the Junk E-mail folder.\r\n\r\nIf you enable this policy setting, suspected junk e-mail is immediately deleted and not moved into the Deleted Items folder.\r\n\r\nIf you disable or do not configure this policy setting, suspected junk e-mail is moved into the Junk E-mail folder.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_permanentlydeletejunkemail_1","displayName":"Enabled","description":null,"helpText":null}]},"49f22de19cf44169":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist","displayName":"Specify path to Safe Recipients list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Safe Recipients list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosaferecipientslist_1","displayName":"Enabled","description":null,"helpText":null}]},"498d864d762b2940":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2","displayName":"Set Outlook object model custom actions execution prompt (User)","description":"This policy setting controls whether Outlook prompts users before executing a custom action. Custom actions add functionality to Outlook that can be triggered as part of a rule. Among other possible features, custom actions can be created that reply to messages in ways that circumvent the Outlook model's programmatic send protections. \r\n\r\nIf you enable this policy setting, you can choose from four options to control how Outlook functions when a custom action is executed that uses the Outlook object model: \r\n\r\n* Prompt User \r\n* Automatically Approve \r\n* Automatically Deny \r\n* Prompt user based on computer security. This option enforces the default configuration in Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook or another program initiates a custom action using the Outlook object model, users are prompted to allow or reject the action. If this configuration is changed, malicious code can use the Outlook object model to compromise sensitive information or otherwise cause data and computing resources to be at risk. This is the equivalent of choosing Enabled -- Prompt user based on computer security.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_onexecutecustomactionoom_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"49a066546d66b7b8":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall","displayName":"Calculate all open projects (User)","description":"Specifies that Project should recalculate all open projects.\r\n\r\nIf you enable this setting, all open projects will be recalculated anytime Project does a calculation.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","categoryName":"Calculation options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcproject_l_pjcalcall_1","displayName":"Enabled","description":null,"helpText":null}]},"49e3a66586e3a094":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjfilelocations_l_pjfilelocprojects_l_pjfilelocprojects31","displayName":"Projects (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d679b407-a753-40aa-bc9f-175f363b0eff","categoryName":"File locations","options":null},"4966ccf56aa54361":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"49262764de14a0c6":{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport","displayName":"Allow Recall Export (User) (Windows Insiders only)","description":"This policy allows you to determine whether Recall and snapshot information can be exported. Recall and snapshot information may be sensitive, and the files that are exported are unencrypted. Users can export from Settings > Privacy & Security > Recall & Snapshots > Advanced Settings > Export your Recall and snapshot info. Users are warned that the files are unencrypted before exporting. When you set this policy to enabled, users will be able to export Recall and snapshot information. If the policy is set to disabled or not configured, users will not be able to export their Recall and snapshot information.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#allowrecallexport"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport_0","displayName":"Deny export of Recall and snapshots information","description":"Deny export of Recall and snapshots information","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_allowrecallexport_1","displayName":"Allow export of Recall and snapshot information","description":"Allow export of Recall and snapshot information","helpText":null}]},"49edeac2cae14b31":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setparametersforcngcontext_l_setparametersforcngcontextid","displayName":"Parameters (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},"49249f488d029ca5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17","displayName":"Trusted Location #17 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_1","displayName":"Enabled","description":null,"helpText":null}]},"495c1d4d047b220c":{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation","displayName":"Stop checking for table alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that tables contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that tables contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, tables will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v9~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtablealttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/4c.json b/public/intune-definitions/4c.json index fc68403d4829..e1a717101ede 100644 --- a/public/intune-definitions/4c.json +++ b/public/intune-definitions/4c.json @@ -1 +1 @@ -{"4c1ea7e81f721bd7":{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming","displayName":"Allow Global Background Fetch When Roaming","description":"If false, disables global background fetch activity when an iOS phone is roaming. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming_true","displayName":"True","description":null,"helpText":null}]},"4c87bb53cce4a40d":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app","displayName":"Microsoft OneNote","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"4ce0b9bec17eb3c2":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app","displayName":"Microsoft Remote Desktop (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"4ceda1cb1aa05905":{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled","displayName":"Configure default state of Allow extensions from other stores setting","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\n\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\nIf the user has already turned on the setting and then turned it off, this setting may not work.\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\nuser settings and the setting will remain as it is.\n\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#controldefaultstateofallowextensionfromotherstoressettingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled_true","displayName":"Allowed","description":null,"helpText":null}]},"4cf763d7aed6677a":{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled","displayName":"Configure Microsoft Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\n\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\n\nIf you enable this policy, Microsoft Edge shares URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\n\nIf you disable or don't configure this policy, Microsoft Edge doesn't share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockersenddetectedsitestosmartscreenenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"4cd820735c392ecc":{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype","displayName":"Alert Type","description":"The type of alert for notifications for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_1","displayName":"Temporary Banner","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_2","displayName":"Persistent Banner","description":null,"helpText":null}]},"4c4ede02a5d3512d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar (Deprecated)","description":"This policy didn't work as expected due to changes in operational requirements. Therefore, the policy is deprecated and shouldn't be used.\n\nSpecifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge, the shortcut takes users to their Microsoft Office apps and docs.\n If you enable or don't configure this policy, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\n If you disable this policy, the shortcut isn't shown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar_true","displayName":"Enabled","description":null,"helpText":null}]},"4cdf51f076fcef47":{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled","displayName":"Configure Speech Recognition","description":"Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data leaves the machine.\n\nIf you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.\n\nIf you disable this policy, Speech Recognition isn't available through the Web Speech API.\n\nRead more about this feature here:\nSpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"4ce983183e8610ea":{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry","displayName":"Disable Network Protection Perf Telemetry","description":"This setting disables the gathering and send of performance telemetry from Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry_1","displayName":"Network protection telemetry is disabled","description":"Network protection telemetry is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry_0","displayName":"Network protection telemetry is enabled","description":"Network protection telemetry is enabled","helpText":null}]},"4cc45b3ae6ee0cdf":{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcoloralpha","displayName":"Alpha","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},"4c28742a37c9ac2e":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4_1","displayName":"Enabled","description":null,"helpText":null}]},"4c186ee0eb4c296f":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings","displayName":"Enable file screens","description":"This policy setting enables administrators to block certain file types from being created in the folders that have been made available offline.\r\n\r\nIf you enable this policy setting, a user will be unable to create files with the specified file extensions in any of the folders that have been made available offline.\r\n\r\nIf you disable or do not configure this policy setting, a user can create a file of any type in the folders that have been made available offline.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-exclusionlistsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"4c9b502cef569721":{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates","displayName":"Allow time invalid certificates","description":"This policy setting permits those certificates to be displayed for logon that are either expired or not yet valid.\r\n\r\nUnder previous versions of Microsoft Windows, certificates were required to contain a valid time and not be expired. The certificate must still be accepted by the domain controller in order to be used. This setting only controls the displaying of the certificate on the client machine. \r\n\r\nIf you enable this policy setting certificates will be listed on the logon screen regardless of whether they have an invalid time or their time validity has expired.\r\n\r\nIf you disable or do not configure this policy setting, certificates which are expired or not yet valid will not be listed on the logon screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowtimeinvalidcertificates"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"4c0bd3f8246887cf":{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring","displayName":"Turn on certificate propagation from smart card","description":"This policy setting allows you to manage the certificate propagation that occurs when a smart card is inserted.\r\n\r\nIf you enable or do not configure this policy setting then certificate propagation will occur when you insert your smart card.\r\n\r\nIf you disable this policy setting, certificate propagation will not occur and the certificates will not be made available to applications such as Outlook.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-certpropenabledstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring_1","displayName":"Enabled","description":null,"helpText":null}]},"4c155b3b66ce6d52":{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_emailmessagetext","displayName":"Add the following text to the end of the email:","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":null},"4c6c79ab615fe72b":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare","displayName":"Audit File Share Access","description":"This policy setting allows you to audit attempts to access a shared folder. If you configure this policy setting, an audit event is generated when an attempt is made to access a shared folder. If this policy setting is defined, the administrator can specify whether to audit only successes, only failures, or both successes and failures. Note: There are no system access control lists (SACLs) for shared folders. If this policy setting is enabled, access to all shared folders on the system is audited.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfileshare"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"4c67d0b4e3156958":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist_extensioninstallblacklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"4c4ef4536804ea17":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault","displayName":"Default printing page size","description":"Overrides default printing page size.\r\n\r\nname should contain one of the listed formats or 'custom' if required paper size is not in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\r\n\r\nIf the page size is unavailable on the printer chosen by the user this policy is ignored.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=PrintingPaperSizeDefault for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"name\": \"custom\",\r\n \"custom_size\": {\r\n \"width\": 210000,\r\n \"height\": 297000\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_1","displayName":"Enabled","description":null,"helpText":null}]},"4c0c88b6c57d8135":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder","displayName":"Specify whether the plugin finder should be disabled (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder_1","displayName":"Enabled","description":null,"helpText":null}]},"4c9d25ecd58442fc":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to BlockWindowManagement (value 2) automatically denies the window management permission to sites by default. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nSetting the policy to AskWindowManagement (value 3) will prompt the user when the window management permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nLeaving the policy unset means the AskWindowManagement policy applies, but users can change this setting.\r\n\r\nThis replaces the deprecated DefaultWindowPlacementSetting policy.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"4c1b86cba7103560":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets","description":"This policy allows to control the Related Website Sets feature enablement.\r\n\r\nThis policy overrides the FirstPartySetsEnabled policy.\r\n\r\nWhen this policy is unset or set to True, the Related Website Sets feature is enabled.\r\n\r\nWhen this policy is set to False, the Related Website Sets feature is disabled.","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c1c41d9bbb0ede9":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands","displayName":"Block process creations originating from PSExec and WMI commands","description":"This rule blocks processes created through PsExec and WMI from running. Both PsExec and WMI can remotely execute code, so there is a risk of malware abusing this functionality for command and control purposes, or to spread an infection throughout an organization's network.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands_warn","displayName":"Warn","description":null,"helpText":null}]},"4c6fd5ad1701844a":{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent","displayName":"Submit Samples Consent","description":"Checks for the user consent level in Windows Defender to send data. If the required consent has already been granted, Windows Defender submits them. If not, (and if the user has specified never to ask), the UI is launched to ask for user consent (when Defender/AllowCloudProtection is allowed) before sending data.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent_0","displayName":"Always prompt.","description":"Always prompt.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent_1","displayName":"Send safe samples automatically.","description":"Send safe samples automatically.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent_2","displayName":"Never send.","description":"Never send.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent_3","displayName":"Send all samples automatically.","description":"Send all samples automatically.","helpText":null}]},"4c98bd723fbf60e2":{"id":"device_vendor_msft_policy_config_devicelock_enforcelockscreenandlogonimage","displayName":"Enforce Lock Screen And Logon Image","description":"Value type is a string, which is the full image filepath and filename.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#enforcelockscreenandlogonimage"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":null},"4c371ded612b45ee":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_profilesshutdownonuserlogoff","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_profilesshutdownonuserlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_profilesshutdownonuserlogoff_1","displayName":"Shutdown on any logoff","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_profilesshutdownonuserlogoff_2","displayName":"Shutdown on any FSLogix Profile logoff","description":null,"helpText":null}]},"4ca5483724ae327e":{"id":"device_vendor_msft_policy_config_internetexplorer_addsearchprovider","displayName":"Add a specific list of search providers to the user's list of search providers","description":"This policy setting allows you to add a specific list of search providers to the user's default list of search providers. Normally, search providers can be added from third-party toolbars or in Setup. The user can also add a search provider from the provider's website.\n\nIf you enable this policy setting, the user can add and remove search providers, but only from the set of search providers specified in the list of policy keys for search providers (found under [HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\SearchScopes]). Note: This list can be created from a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.\n\nIf you disable or do not configure this policy setting, the user can configure their list of search providers unless another policy setting restricts such configuration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-addsearchprovider"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_addsearchprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_addsearchprovider_1","displayName":"Enabled","description":null,"helpText":null}]},"4c2de28cc9a23e71":{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp","displayName":"[Deprecated] Disable Internet Explorer 11 as a standalone browser","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\r\n\r\nIf you enable this policy, it:\r\n- Prevents Internet Explorer 11 from launching as a standalone browser.\r\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\r\n- Redirects all attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\r\n- Overrides any other policies that redirect to Internet Explorer 11.\r\n\r\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_1","displayName":"Enabled","description":null,"helpText":null}]},"4ce481ea27af31b9":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"4c6e0303efec178a":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},"4ce153d41a918211":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004","displayName":"Download unsigned ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_1","displayName":"Prompt","description":null,"helpText":null}]},"4cd595778d35553a":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},"4cdf8c859344dd6e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled","displayName":"Continue running background apps after Microsoft Edge closes","description":"Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there.\r\n\r\nIf you enable this policy, background mode is turned on.\r\n\r\nIf you disable this policy, background mode is turned off.\r\n\r\nIf you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c094c9d435be456":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended","displayName":"Set the new tab page as the home page","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\r\n\r\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\r\n\r\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\r\n\r\nIf not configured users can choose whether the new tab page is their home page.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"4c2d4045e44efc16":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist_developertoolsavailabilityallowlistdesc","displayName":"List of URL patterns for which developer tools are allowed to be opened (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"4cbc9b72ca8caaa4":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page.","description":"This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled.\r\n\r\nIf you set this policy to 'EnableBothWorkDiscover' (0) or do not configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.\r\n\r\nIf you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the new tab page.\r\n\r\nIf you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the new tab page.\r\n\r\nThis policy works with the SetNTPDefaultFeedTab policy, which controls which feed tab is selected by default when both tabs are available.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableBothWorkDiscover (0) = Enable both Work and Discover tabs\r\n\r\n* EnableOnlyWork (1) = Enable only Work tab\r\n\r\n* EnableOnlyDiscover (2) = Enable only Discover tab\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_1","displayName":"Enabled","description":null,"helpText":null}]},"4c7b5d43a847befc":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites_1","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites_2","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},"4c48eea4531a2a5b":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended","displayName":"Allow importing of browser settings","description":"Allows users to import browser settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"4c932e62af3884e5":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_webappinstallforcelist","displayName":"URLs for Web Apps to be silently installed. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"4cd54569c71da0a2":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_powerpntexe129","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_powerpntexe129_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_powerpntexe129_1","displayName":"True","description":null,"helpText":null}]},"4c4a0b168d30c03c":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_payloadpolicyid","displayName":"Policy GUID:","description":"","helpText":"","infoUrls":[],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":null},"4cf68c2d82e63c64":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_sharedinstallationpath_sharedinstallationpath_textbox","displayName":"Shared Installation Path (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":null},"4caad5c1e98fa06a":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_lanchangeproperties","displayName":"Prohibit access to properties of components of a LAN connection (User)","description":"Determines whether Administrators and Network Configuration Operators can change the properties of components used by a LAN connection.\r\n\r\nThis setting determines whether the Properties button for components of a LAN connection is enabled.\r\n\r\nIf you enable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), the Properties button is disabled for Administrators. Network Configuration Operators are prohibited from accessing connection components, regardless of the \"Enable Network Connections settings for Administrators\" setting.\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting does not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you disable this setting or do not configure it, the Properties button is enabled for administrators and Network Configuration Operators.\r\n\r\nThe Local Area Connection Properties dialog box includes a list of the network components that the connection uses. To view or change the properties of a component, click the name of the component, and then click the Properties button beneath the component list.\r\n\r\nNote: Not all network components have configurable properties. For components that are not configurable, the Properties button is always disabled.\r\n\r\nNote: When the \"Prohibit access to properties of a LAN connection\" setting is enabled, users are blocked from accessing the Properties button for LAN connection components.\r\n\r\nNote: Network Configuration Operators only have permission to change TCP/IP properties. Properties for all other components are unavailable to these users.\r\n\r\nNote: Nonadministrators are already prohibited from accessing properties of components for a LAN connection, regardless of this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-lanchangeproperties"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_lanchangeproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_lanchangeproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"4c7c5cc8f6936774":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common","displayName":"Microsoft Office 2016 Common Settings (User)","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2016 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2016 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2016 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2016 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_1","displayName":"Enabled","description":null,"helpText":null}]},"4ccbcca3dec677d5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked","displayName":"Block Browser Legacy Extension Points (User)","description":"Setting the policy to Enabled or leaving it unset will enable ProcessExtensionPointDisablePolicy to block legacy extension points in the Browser process.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's browser process.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked_1","displayName":"Enabled","description":null,"helpText":null}]},"4c376418bbfe5612":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting","displayName":"Default cookies setting (User)","description":"Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults.\r\n\r\nWhile no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_1","displayName":"Enabled","description":null,"helpText":null}]},"4c5c3f99fd80bee3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl","displayName":"Default search provider new tab page URL (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page.\r\n\r\nLeaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.\r\n\r\nExample value: https://search.my.company/newtab","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_1","displayName":"Enabled","description":null,"helpText":null}]},"4c5f5a41d58e3546":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled","displayName":"Enable leak detection for entered credentials (User)","description":"Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.\r\n\r\nThis behavior will not trigger if Safe Browsing is disabled (either by policy or by the user). In order to force Safe Browsing on, use the SafeBrowsingEnabled policy or the SafeBrowsingProtectionLevel policy.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c9cdd9795ca3e4d":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled","displayName":"Choose whether the Privacy Sandbox Fingerprinting Protection feature is to be enabled in Incognito mode. (User)","description":"A policy to control whether the Privacy Sandbox Fingerprinting Protection setting is to be enabled in Incognito mode or disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Fingerprinting Protection feature setting will be turned off for your users.\r\nIf you set this policy to Enabled, your users will have the Fingerprinting Protection feature setting turned on in Incognito mode.\r\nIf the policy is not set, users will be able to turn on or off the Fingerprinting Protection feature for Incognito mode in their UI settings. The default state will be false or disabled, meaning the Fingerprinting Protection feature will be turned off.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c96968f6daf8218":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled","displayName":"Enable download bubble UI (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4cdc716899061412":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3","displayName":"Checked: Allow edit. Unchecked: Do not allow edit. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_1","displayName":"True","description":null,"helpText":null}]},"4ccf853b6d5560e1":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon53","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"4c7247903e8728d7":{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites","displayName":"Prevent deleting websites that the user has visited (User)","description":"This policy setting prevents the user from deleting the history of websites that he or she has visited. This feature is available in the Delete Browsing History dialog box.\n\nIf you enable this policy setting, websites that the user has visited are preserved when he or she clicks Delete.\n\nIf you disable this policy setting, websites that the user has visited are deleted when he or she clicks Delete.\n\nIf you do not configure this policy setting, the user can choose whether to delete or preserve visited websites when he or she clicks Delete.\n\nIf the \"Prevent access to Delete Browsing History\" policy setting is enabled, this policy setting is enabled by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disabledeletinguservisitedwebsites"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites_1","displayName":"Enabled","description":null,"helpText":null}]},"4c2e6513c7f4b8ab":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"4cb88bca6fdfcaa6":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps after Microsoft Edge closes (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there.\r\n\r\nIf you enable this policy, background mode is turned on.\r\n\r\nIf you disable this policy, background mode is turned off.\r\n\r\nIf you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"4cba73d0eec85c63":{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended","displayName":"Edge 3P SERP Telemetry Enabled (User)","description":"Edge3P Telemetry in Microsoft Edge captures the searches user does on third party search providers without identifying the person or the device and captures only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings.\r\n\r\nIf you enable or don't configure this policy, Edge 3P SERP Telemetry feature will be enabled.\r\n\r\nIf you disable this policy, Edge 3P SERP Telemetry feature will be disabled.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"4c0b774337f4b17f":{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins_webauthenticationremotedesktopallowedoriginsdesc","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"4ca622710239ec5a":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled","displayName":"Manage QuickView Office files capability in Microsoft Edge (User)","description":"Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets)\r\n\r\nIf you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.\r\n\r\nIf you disable this policy, these files will be downloaded to be viewed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c636e828b8f693a":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb6409fc-fb52-413d-ae4b-eff017b52b30","categoryName":"Experimentation","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_2","displayName":"Allow users to override feature flags using command line arguments only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_1","displayName":"Allow users to override feature flags","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_0","displayName":"Prevent users from overriding feature flags","description":null,"helpText":null}]},"4c911a21a8770710":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},"4cb153bc8258a7e7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview","displayName":"When choosing 'Send for Review...' (User)","description":"\"Send link and attachment\": When choosing Send for Review for a document on a server, send both a link and an attachment. | \"Only send link\": When choosing Send for Review for a document on a server, send only a link. | \"Prompt user\": When choosing Send for Review for a document on a server, prompt the user for what to send.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},"4c8b3f36796b16d0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon","displayName":"Turn off Coming Soon (User)","description":"\r\n This policy setting controls whether Coming Soon is available to users. Coming Soon provides information in an Office app, such as Word or Excel, about upcoming feature changes to that app and lets users try out those changes ahead of time. By default, Coming Soon is available to users.\r\n\r\n If you enable this policy setting, Coming Soon is turned off and isn't available to users.\r\n\r\n If you disable or don't configure this policy setting, Coming Soon is available to users.\r\n ","helpText":"","infoUrls":[],"categoryId":"e0dfe97e-348d-4d30-a6a1-e0de1989236e","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon_1","displayName":"Enabled","description":null,"helpText":null}]},"4c169e3af3dd74ce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions","displayName":"Show additional sharing choices under the File tab (User)","description":"This policy settings controls what is displayed when the user goes to File > Share in Word, Excel, or PowerPoint.\r\n\r\nBy default, choosing File > Share takes the user to the Share dialog, which provides various choices for sharing. These choices used to appear under File > Share, but no longer appear there by default. There are some additional choices that used to appear under File > Share, but don’t appear in the Share dialog.\r\n\r\nIf you enable this policy setting, the user isn’t taken to the Share dialog and the user sees all the sharing choices under File > Share. For example, several options to share by email or an option to share by instant message.\r\n\r\nIf you disable or don’t configure this policy setting, choosing File > Share takes the user to the Share dialog, which doesn’t have all the sharing choices.\r\n\r\nNote: The user can also add buttons for these additional sharing choices to the ribbon or to the quick access toolbar, regardless of how this policy setting is configured.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"4c81e6ccc2495a00":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts","displayName":"Do not display paths in alerts (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts_1","displayName":"Enabled","description":null,"helpText":null}]},"4c75708850d6101d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary_l_path2504","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"4c6958e862298d0e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"4c50b8796eb14b1e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},"4c8dbf6b7cc5288c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload","displayName":"Frequency for polling the server to download published links (User)","description":"Minimum time to wait (in seconds) before polling SharePoint Server to download published links.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_1","displayName":"Enabled","description":null,"helpText":null}]},"4c8755ef59604833":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists","displayName":"Automatic bulleted lists (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists_1","displayName":"Enabled","description":null,"helpText":null}]},"4c78860663790bc3":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},"4c46840a20fd1d71":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}","displayName":" Firewall Rule Name","description":"Unique alpha numeric identifier for the rule. The rule name must not include a forward slash (/).","helpText":"","infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},"4c9b79b633a9853f":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall","displayName":"Enable Private Network Firewall","description":"This value is an on/off switch for the Hyper-V Firewall enforcement.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},"4c9f758691ebda7f":{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]}} \ No newline at end of file +{"4c1ea7e81f721bd7":{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming","displayName":"Allow Global Background Fetch When Roaming","description":"If false, disables global background fetch activity when an iOS phone is roaming. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowglobalbackgroundfetchwhenroaming_true","displayName":"True","description":null,"helpText":null}]},"4c87bb53cce4a40d":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app","displayName":"Microsoft OneNote","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"4ce0b9bec17eb3c2":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft remote desktop.app","displayName":"Microsoft Remote Desktop (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"4ceda1cb1aa05905":{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled","displayName":"Configure default state of Allow extensions from other stores setting","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\n\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\nIf the user has already turned on the setting and then turned it off, this setting may not work.\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\nuser settings and the setting will remain as it is.\n\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#controldefaultstateofallowextensionfromotherstoressettingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_controldefaultstateofallowextensionfromotherstoressettingenabled_true","displayName":"Allowed","description":null,"helpText":null}]},"4cf763d7aed6677a":{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled","displayName":"Configure Microsoft Edge Scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\n\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\n\nIf you enable this policy, Microsoft Edge shares URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\n\nIf you disable or don't configure this policy, Microsoft Edge doesn't share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockersenddetectedsitestosmartscreenenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockersenddetectedsitestosmartscreenenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"4cd820735c392ecc":{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype","displayName":"Alert Type","description":"The type of alert for notifications for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_1","displayName":"Temporary Banner","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_alerttype_2","displayName":"Persistent Banner","description":null,"helpText":null}]},"4c4ede02a5d3512d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar (Deprecated)","description":"This policy didn't work as expected due to changes in operational requirements. Therefore, the policy is deprecated and shouldn't be used.\n\nSpecifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge, the shortcut takes users to their Microsoft Office apps and docs.\n If you enable or don't configure this policy, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\n If you disable this policy, the shortcut isn't shown.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showofficeshortcutinfavoritesbar_true","displayName":"Enabled","description":null,"helpText":null}]},"4cdf51f076fcef47":{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled","displayName":"Configure Speech Recognition","description":"Set whether websites can use the W3C Web Speech API to recognize speech from the user. The Microsoft Edge implementation of the Web Speech API uses Azure Cognitive Services, so voice data leaves the machine.\n\nIf you enable or don't configure this policy, web-based applications that use the Web Speech API can use Speech Recognition.\n\nIf you disable this policy, Speech Recognition isn't available through the Web Speech API.\n\nRead more about this feature here:\nSpeechRecognition API: https://go.microsoft.com/fwlink/?linkid=2143388\nCognitive Services: https://go.microsoft.com/fwlink/?linkid=2143680","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.speechrecognitionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"4ce983183e8610ea":{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry","displayName":"Disable Network Protection Perf Telemetry","description":"This setting disables the gathering and send of performance telemetry from Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry_1","displayName":"Network protection telemetry is disabled","description":"Network protection telemetry is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablenetworkprotectionperftelemetry_0","displayName":"Network protection telemetry is enabled","description":"Network protection telemetry is enabled","helpText":null}]},"4c13e89b9ae74691":{"id":"device_vendor_msft_maintenancewindows_weekinmonth","displayName":"Week in Month","description":"Select the week of the month on which the maintenance window should run.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_weekinmonth_1","displayName":"First","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weekinmonth_2","displayName":"Second","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weekinmonth_3","displayName":"Third","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weekinmonth_4","displayName":"Fourth","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_weekinmonth_5","displayName":"Last","description":null,"helpText":null}]},"4cc45b3ae6ee0cdf":{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_dwmdefaultcolorizationcoloralpha","displayName":"Alpha","description":null,"helpText":"","infoUrls":[],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":null},"4c28742a37c9ac2e":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\r\n\r\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\r\n\r\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\r\n\r\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-retention-4"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_retention_4_1","displayName":"Enabled","description":null,"helpText":null}]},"4c186ee0eb4c296f":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings","displayName":"Enable file screens","description":"This policy setting enables administrators to block certain file types from being created in the folders that have been made available offline.\r\n\r\nIf you enable this policy setting, a user will be unable to create files with the specified file extensions in any of the folders that have been made available offline.\r\n\r\nIf you disable or do not configure this policy setting, a user can create a file of any type in the folders that have been made available offline.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-exclusionlistsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_exclusionlistsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"4c9b502cef569721":{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates","displayName":"Allow time invalid certificates","description":"This policy setting permits those certificates to be displayed for logon that are either expired or not yet valid.\r\n\r\nUnder previous versions of Microsoft Windows, certificates were required to contain a valid time and not be expired. The certificate must still be accepted by the domain controller in order to be used. This setting only controls the displaying of the certificate on the client machine. \r\n\r\nIf you enable this policy setting certificates will be listed on the logon screen regardless of whether they have an invalid time or their time validity has expired.\r\n\r\nIf you disable or do not configure this policy setting, certificates which are expired or not yet valid will not be listed on the logon screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowtimeinvalidcertificates"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowtimeinvalidcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"4c0bd3f8246887cf":{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring","displayName":"Turn on certificate propagation from smart card","description":"This policy setting allows you to manage the certificate propagation that occurs when a smart card is inserted.\r\n\r\nIf you enable or do not configure this policy setting then certificate propagation will occur when you insert your smart card.\r\n\r\nIf you disable this policy setting, certificate propagation will not occur and the certificates will not be made available to applications such as Outlook.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-certpropenabledstring"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certpropenabledstring_1","displayName":"Enabled","description":null,"helpText":null}]},"4c155b3b66ce6d52":{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_emailmessagetext","displayName":"Add the following text to the end of the email:","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":null},"4c6c79ab615fe72b":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare","displayName":"Audit File Share Access","description":"This policy setting allows you to audit attempts to access a shared folder. If you configure this policy setting, an audit event is generated when an attempt is made to access a shared folder. If this policy setting is defined, the administrator can specify whether to audit only successes, only failures, or both successes and failures. Note: There are no system access control lists (SACLs) for shared folders. If this policy setting is enabled, access to all shared folders on the system is audited.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditfileshare"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditfileshare_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"4c67d0b4e3156958":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallblacklist_extensioninstallblacklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"4c4ef4536804ea17":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault","displayName":"Default printing page size","description":"Overrides default printing page size.\r\n\r\nname should contain one of the listed formats or 'custom' if required paper size is not in the list. If 'custom' value is provided custom_size property should be specified. It describes the desired height and width in micrometers. Otherwise custom_size property shouldn't be specified. Policy that violates these rules is ignored.\r\n\r\nIf the page size is unavailable on the printer chosen by the user this policy is ignored.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=PrintingPaperSizeDefault for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"name\": \"custom\",\r\n \"custom_size\": {\r\n \"width\": 210000,\r\n \"height\": 297000\r\n }\r\n}","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_1","displayName":"Enabled","description":null,"helpText":null}]},"4c0c88b6c57d8135":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder","displayName":"Specify whether the plugin finder should be disabled (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablepluginfinder_1","displayName":"Enabled","description":null,"helpText":null}]},"4c9d25ecd58442fc":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to BlockWindowManagement (value 2) automatically denies the window management permission to sites by default. This will limit the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nSetting the policy to AskWindowManagement (value 3) will prompt the user when the window management permission is requested by default. If users allow the permission, it will extend the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nLeaving the policy unset means the AskWindowManagement policy applies, but users can change this setting.\r\n\r\nThis replaces the deprecated DefaultWindowPlacementSetting policy.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwindowmanagementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"4c1b86cba7103560":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled","displayName":"Enable Related Website Sets","description":"This policy allows to control the Related Website Sets feature enablement.\r\n\r\nThis policy overrides the FirstPartySetsEnabled policy.\r\n\r\nWhen this policy is unset or set to True, the Related Website Sets feature is enabled.\r\n\r\nWhen this policy is set to False, the Related Website Sets feature is disabled.","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c1c41d9bbb0ede9":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands","displayName":"Block process creations originating from PSExec and WMI commands","description":"This rule blocks processes created through PsExec and WMI from running. Both PsExec and WMI can remotely execute code, so there is a risk of malware abusing this functionality for command and control purposes, or to spread an infection throughout an organization's network.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockprocesscreationsfrompsexecandwmicommands_warn","displayName":"Warn","description":null,"helpText":null}]},"4c6fd5ad1701844a":{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent","displayName":"Submit Samples Consent","description":"Checks for the user consent level in Windows Defender to send data. If the required consent has already been granted, Windows Defender submits them. If not, (and if the user has specified never to ask), the UI is launched to ask for user consent (when Defender/AllowCloudProtection is allowed) before sending data.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent_0","displayName":"Always prompt.","description":"Always prompt.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent_1","displayName":"Send safe samples automatically.","description":"Send safe samples automatically.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent_2","displayName":"Never send.","description":"Never send.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_submitsamplesconsent_3","displayName":"Send all samples automatically.","description":"Send all samples automatically.","helpText":null}]},"4c98bd723fbf60e2":{"id":"device_vendor_msft_policy_config_devicelock_enforcelockscreenandlogonimage","displayName":"Enforce Lock Screen And Logon Image","description":"Value type is a string, which is the full image filepath and filename.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#enforcelockscreenandlogonimage"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":null},"4c371ded612b45ee":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_profilesshutdownonuserlogoff","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_profilesshutdownonuserlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_profilesshutdownonuserlogoff_1","displayName":"Shutdown on any logoff","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_profilesshutdownonuserlogoff_2","displayName":"Shutdown on any FSLogix Profile logoff","description":null,"helpText":null}]},"4ca5483724ae327e":{"id":"device_vendor_msft_policy_config_internetexplorer_addsearchprovider","displayName":"Add a specific list of search providers to the user's list of search providers","description":"This policy setting allows you to add a specific list of search providers to the user's default list of search providers. Normally, search providers can be added from third-party toolbars or in Setup. The user can also add a search provider from the provider's website.\n\nIf you enable this policy setting, the user can add and remove search providers, but only from the set of search providers specified in the list of policy keys for search providers (found under [HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\SearchScopes]). Note: This list can be created from a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.\n\nIf you disable or do not configure this policy setting, the user can configure their list of search providers unless another policy setting restricts such configuration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-addsearchprovider"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_addsearchprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_addsearchprovider_1","displayName":"Enabled","description":null,"helpText":null}]},"4c2de28cc9a23e71":{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp","displayName":"[Deprecated] Disable Internet Explorer 11 as a standalone browser","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\r\n\r\nIf you enable this policy, it:\r\n- Prevents Internet Explorer 11 from launching as a standalone browser.\r\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\r\n- Redirects all attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\r\n- Overrides any other policies that redirect to Internet Explorer 11.\r\n\r\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_1","displayName":"Enabled","description":null,"helpText":null}]},"4ce481ea27af31b9":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowautomaticpromptingforactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"4c6e0303efec178a":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},"4ce153d41a918211":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004","displayName":"Download unsigned ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadunsignedactivexcontrols_iz_partname1004_1","displayName":"Prompt","description":null,"helpText":null}]},"4cd595778d35553a":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},"4cdf8c859344dd6e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled","displayName":"Continue running background apps after Microsoft Edge closes","description":"Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there.\r\n\r\nIf you enable this policy, background mode is turned on.\r\n\r\nIf you disable this policy, background mode is turned off.\r\n\r\nIf you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_backgroundmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c094c9d435be456":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended","displayName":"Set the new tab page as the home page","description":"Configures the default home page in Microsoft Edge. You can set the home page to a URL you specify or to the new tab page.\r\n\r\nIf you enable this policy, the new tab page is always used for the home page, and the home page URL location is ignored.\r\n\r\nIf you disable this policy, the user's home page can't be the new tab page, unless the URL is set to 'edge://newtab'.\r\n\r\nIf not configured users can choose whether the new tab page is their home page.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_homepageisnewtabpage_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"4c2d4045e44efc16":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_developertoolsavailabilityallowlist_developertoolsavailabilityallowlistdesc","displayName":"List of URL patterns for which developer tools are allowed to be opened (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"4cbc9b72ca8caaa4":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page.","description":"This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled.\r\n\r\nIf you set this policy to 'EnableBothWorkDiscover' (0) or do not configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.\r\n\r\nIf you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the new tab page.\r\n\r\nIf you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the new tab page.\r\n\r\nThis policy works with the SetNTPDefaultFeedTab policy, which controls which feed tab is selected by default when both tabs are available.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableBothWorkDiscover (0) = Enable both Work and Discover tabs\r\n\r\n* EnableOnlyWork (1) = Enable only Work tab\r\n\r\n* EnableOnlyDiscover (2) = Enable only Discover tab\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_1","displayName":"Enabled","description":null,"helpText":null}]},"4c7b5d43a847befc":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites_1","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_adssettingforintrusiveadssites_2","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},"4c48eea4531a2a5b":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended","displayName":"Allow importing of browser settings","description":"Allows users to import browser settings from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browser settings** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browser settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, browser settings are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports the settings on first run, but users can select or clear the **browser settings** option during manual import.\r\n\r\n**Note**: This policy currently manages importing Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_importbrowsersettings_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"4c932e62af3884e5":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_webappinstallforcelist","displayName":"URLs for Web Apps to be silently installed. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"4cd54569c71da0a2":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_powerpntexe129","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_powerpntexe129_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_powerpntexe129_1","displayName":"True","description":null,"helpText":null}]},"4c4a0b168d30c03c":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_payloadpolicyid","displayName":"Policy GUID:","description":"","helpText":"","infoUrls":[],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":null},"4cf68c2d82e63c64":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_sharedinstallationpath_sharedinstallationpath_textbox","displayName":"Shared Installation Path (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":null},"4caad5c1e98fa06a":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_lanchangeproperties","displayName":"Prohibit access to properties of components of a LAN connection (User)","description":"Determines whether Administrators and Network Configuration Operators can change the properties of components used by a LAN connection.\r\n\r\nThis setting determines whether the Properties button for components of a LAN connection is enabled.\r\n\r\nIf you enable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), the Properties button is disabled for Administrators. Network Configuration Operators are prohibited from accessing connection components, regardless of the \"Enable Network Connections settings for Administrators\" setting.\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting does not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you disable this setting or do not configure it, the Properties button is enabled for administrators and Network Configuration Operators.\r\n\r\nThe Local Area Connection Properties dialog box includes a list of the network components that the connection uses. To view or change the properties of a component, click the name of the component, and then click the Properties button beneath the component list.\r\n\r\nNote: Not all network components have configurable properties. For components that are not configurable, the Properties button is always disabled.\r\n\r\nNote: When the \"Prohibit access to properties of a LAN connection\" setting is enabled, users are blocked from accessing the Properties button for LAN connection components.\r\n\r\nNote: Network Configuration Operators only have permission to change TCP/IP properties. Properties for all other components are unavailable to these users.\r\n\r\nNote: Nonadministrators are already prohibited from accessing properties of components for a LAN connection, regardless of this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-lanchangeproperties"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_lanchangeproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_lanchangeproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"4c7c5cc8f6936774":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common","displayName":"Microsoft Office 2016 Common Settings (User)","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2016 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2016 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2016 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2016 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_1","displayName":"Enabled","description":null,"helpText":null}]},"4ccbcca3dec677d5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked","displayName":"Block Browser Legacy Extension Points (User)","description":"Setting the policy to Enabled or leaving it unset will enable ProcessExtensionPointDisablePolicy to block legacy extension points in the Browser process.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security and stability as unknown and potentially hostile code can load inside Google Chrome's browser process. Only turn off the policy if there are compatibility issues with third-party software that must run inside Google Chrome's browser process.\r\n\r\nNote: Read more about Process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlegacyextensionpointsblocked_1","displayName":"Enabled","description":null,"helpText":null}]},"4c376418bbfe5612":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting","displayName":"Default cookies setting (User)","description":"Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults.\r\n\r\nWhile no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultcookiessetting_1","displayName":"Enabled","description":null,"helpText":null}]},"4c5c3f99fd80bee3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl","displayName":"Default search provider new tab page URL (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page.\r\n\r\nLeaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.\r\n\r\nExample value: https://search.my.company/newtab","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidernewtaburl_1","displayName":"Enabled","description":null,"helpText":null}]},"4c5f5a41d58e3546":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled","displayName":"Enable leak detection for entered credentials (User)","description":"Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.\r\n\r\nThis behavior will not trigger if Safe Browsing is disabled (either by policy or by the user). In order to force Safe Browsing on, use the SafeBrowsingEnabled policy or the SafeBrowsingProtectionLevel policy.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~passwordmanager_passwordleakdetectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c9cdd9795ca3e4d":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled","displayName":"Choose whether the Privacy Sandbox Fingerprinting Protection feature is to be enabled in Incognito mode. (User)","description":"A policy to control whether the Privacy Sandbox Fingerprinting Protection setting is to be enabled in Incognito mode or disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Fingerprinting Protection feature setting will be turned off for your users.\r\nIf you set this policy to Enabled, your users will have the Fingerprinting Protection feature setting turned on in Incognito mode.\r\nIf the policy is not set, users will be able to turn on or off the Fingerprinting Protection feature for Incognito mode in their UI settings. The default state will be false or disabled, meaning the Fingerprinting Protection feature will be turned off.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxfingerprintingprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c96968f6daf8218":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled","displayName":"Enable download bubble UI (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_downloadbubbleenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4cdc716899061412":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3","displayName":"Checked: Allow edit. Unchecked: Do not allow edit. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsstr3_1","displayName":"True","description":null,"helpText":null}]},"4ccf853b6d5560e1":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon53","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"4c7247903e8728d7":{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites","displayName":"Prevent deleting websites that the user has visited (User)","description":"This policy setting prevents the user from deleting the history of websites that he or she has visited. This feature is available in the Delete Browsing History dialog box.\n\nIf you enable this policy setting, websites that the user has visited are preserved when he or she clicks Delete.\n\nIf you disable this policy setting, websites that the user has visited are deleted when he or she clicks Delete.\n\nIf you do not configure this policy setting, the user can choose whether to delete or preserve visited websites when he or she clicks Delete.\n\nIf the \"Prevent access to Delete Browsing History\" policy setting is enabled, this policy setting is enabled by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disabledeletinguservisitedwebsites"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disabledeletinguservisitedwebsites_1","displayName":"Enabled","description":null,"helpText":null}]},"4c2e6513c7f4b8ab":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"4cb88bca6fdfcaa6":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps after Microsoft Edge closes (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and keep running after the last browser window is closed. In this scenario, background apps and the current browsing session remain active, including any session cookies. An open background process displays an icon in the system tray and can always be closed from there.\r\n\r\nIf you enable this policy, background mode is turned on.\r\n\r\nIf you disable this policy, background mode is turned off.\r\n\r\nIf you don't configure this policy, background mode is initially turned off, and the user can configure its behavior in edge://settings/system.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"4cba73d0eec85c63":{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended","displayName":"Edge 3P SERP Telemetry Enabled (User)","description":"Edge3P Telemetry in Microsoft Edge captures the searches user does on third party search providers without identifying the person or the device and captures only if the user has consented to this collection of data. User can turn off the collection at any time in the browser settings.\r\n\r\nIf you enable or don't configure this policy, Edge 3P SERP Telemetry feature will be enabled.\r\n\r\nIf you disable this policy, Edge 3P SERP Telemetry feature will be disabled.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended_edge3pserptelemetryenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"4c0b774337f4b17f":{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_webauthenticationremotedesktopallowedorigins_webauthenticationremotedesktopallowedoriginsdesc","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"4ca622710239ec5a":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled","displayName":"Manage QuickView Office files capability in Microsoft Edge (User)","description":"Allows you to set whether users can view publicly accessible Office files on the web that aren't on OneDrive or SharePoint. (For example: Word documents, PowerPoint presentations, and Excel spreadsheets)\r\n\r\nIf you enable or don't configure this policy, these files can be viewed in Microsoft Edge using Office Viewer instead of downloading the files.\r\n\r\nIf you disable this policy, these files will be downloaded to be viewed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_quickviewofficefilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"4c636e828b8f693a":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb6409fc-fb52-413d-ae4b-eff017b52b30","categoryName":"Experimentation","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_2","displayName":"Allow users to override feature flags using command line arguments only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_1","displayName":"Allow users to override feature flags","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_featureflagoverridescontrol_0","displayName":"Prevent users from overriding feature flags","description":null,"helpText":null}]},"4c911a21a8770710":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},"4cb153bc8258a7e7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview","displayName":"When choosing 'Send for Review...' (User)","description":"\"Send link and attachment\": When choosing Send for Review for a document on a server, send both a link and an attachment. | \"Only send link\": When choosing Send for Review for a document on a server, send only a link. | \"Prompt user\": When choosing Send for Review for a document on a server, prompt the user for what to send.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_whenchoosingsendforreview_1","displayName":"Enabled","description":null,"helpText":null}]},"4c8b3f36796b16d0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon","displayName":"Turn off Coming Soon (User)","description":"\r\n This policy setting controls whether Coming Soon is available to users. Coming Soon provides information in an Office app, such as Word or Excel, about upcoming feature changes to that app and lets users try out those changes ahead of time. By default, Coming Soon is available to users.\r\n\r\n If you enable this policy setting, Coming Soon is turned off and isn't available to users.\r\n\r\n If you disable or don't configure this policy setting, Coming Soon is available to users.\r\n ","helpText":"","infoUrls":[],"categoryId":"e0dfe97e-348d-4d30-a6a1-e0de1989236e","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_other_l_disablecomingsoon_1","displayName":"Enabled","description":null,"helpText":null}]},"4c169e3af3dd74ce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions","displayName":"Show additional sharing choices under the File tab (User)","description":"This policy settings controls what is displayed when the user goes to File > Share in Word, Excel, or PowerPoint.\r\n\r\nBy default, choosing File > Share takes the user to the Share dialog, which provides various choices for sharing. These choices used to appear under File > Share, but no longer appear there by default. There are some additional choices that used to appear under File > Share, but don’t appear in the Share dialog.\r\n\r\nIf you enable this policy setting, the user isn’t taken to the Share dialog and the user sees all the sharing choices under File > Share. For example, several options to share by email or an option to share by instant message.\r\n\r\nIf you disable or don’t configure this policy setting, choosing File > Share takes the user to the Share dialog, which doesn’t have all the sharing choices.\r\n\r\nNote: The user can also add buttons for these additional sharing choices to the ribbon or to the quick access toolbar, regardless of how this policy setting is configured.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_alwaysshowfilesharemoreoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"4c81e6ccc2495a00":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts","displayName":"Do not display paths in alerts (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotdisplaypathsinalerts_1","displayName":"Enabled","description":null,"helpText":null}]},"4c75708850d6101d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_homeworkflowlibrary_l_path2504","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"4c6958e862298d0e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"4c50b8796eb14b1e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},"4c8dbf6b7cc5288c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload","displayName":"Frequency for polling the server to download published links (User)","description":"Minimum time to wait (in seconds) before polling SharePoint Server to download published links.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_frequencyforpollingtheservertodownload_1","displayName":"Enabled","description":null,"helpText":null}]},"4c8755ef59604833":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists","displayName":"Automatic bulleted lists (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_automaticbulletedlists_1","displayName":"Enabled","description":null,"helpText":null}]},"4c78860663790bc3":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},"4c46840a20fd1d71":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}","displayName":" Firewall Rule Name","description":"Unique alpha numeric identifier for the rule. The rule name must not include a forward slash (/).","helpText":"","infoUrls":[],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},"4c9b79b633a9853f":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall","displayName":"Enable Private Network Firewall","description":"This value is an on/off switch for the Hyper-V Firewall enforcement.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]},"4c9f758691ebda7f":{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/50.json b/public/intune-definitions/50.json index adf25779e27e..0fb00d8ebc61 100644 --- a/public/intune-definitions/50.json +++ b/public/intune-definitions/50.json @@ -1 +1 @@ -{"5038952785cf1cbf":{"id":"ade_accountsettings_createlocaladmin","displayName":"Create a local admin account","description":null,"helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_createlocaladmin_0","displayName":"No","description":null,"helpText":null},{"id":"ade_accountsettings_createlocaladmin_1","displayName":"Yes","description":null,"helpText":null}]},"50de61a1064d8c05":{"id":"com.apple.dnssettings.managed_prohibitdisablement","displayName":"Prohibit Disablement","description":"If true, prohibits users from disabling DNS settings. This key is only available on supervised devices.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_prohibitdisablement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_prohibitdisablement_true","displayName":"Enabled","description":null,"helpText":null}]},"50a8f33e8b1c357d":{"id":"com.apple.managedclient.preferences_forceephemeralprofiles","displayName":"Enable use of ephemeral profiles","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\n\nIf you enable this policy, profiles run in ephemeral mode. This lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\n\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\n\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user has enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forceephemeralprofiles"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forceephemeralprofiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forceephemeralprofiles_true","displayName":"Enabled","description":null,"helpText":null}]},"50a0769ae49df32a":{"id":"com.apple.managedclient.preferences_importhistory","displayName":"Allow importing of browsing history","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\n\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS) and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importhistory"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importhistory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importhistory_true","displayName":"Enabled","description":null,"helpText":null}]},"50d60fc73d44d1f1":{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container","displayName":"Default launch container","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container_0","displayName":"tab","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container_1","displayName":"window","description":null,"helpText":null}]},"50d2949c22e519b5":{"id":"com.apple.mobiledevice.passwordpolicy_com.apple.mobiledevice.passwordpolicy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"5085f39ba4f0fbfb":{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen","displayName":"Show In Lock Screen","description":"If true, enables notifications on the lock screen for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen_true","displayName":"True","description":null,"helpText":null}]},"50fe702ef8091db9":{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload","displayName":"Enable XProtect Malware Upload","description":"If false, will prevent Gatekeeper from prompting the user to upload blocked malware to Apple for purposes of improving malware detection.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload_true","displayName":"Enabled","description":null,"helpText":null}]},"5003cfa26047898d":{"id":"com.apple.universalaccess_mousedrivermaxspeed","displayName":"Mouse Driver Max Speed","description":"The maximum speed for the cursor when using Mouse Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},"500febc680700d8f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\nThis policy also applies to component extensions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled_true","displayName":"Enabled","description":null,"helpText":null}]},"50e56084313cf5af":{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeurlblocklist","displayName":"Block access to a list of URLs in InPrivate mode.","description":"This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge.\n\nAdministrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nIf both \"InPrivateModeUrlBlocklist\" and \"InPrivateModeUrlAllowlist\" are configured, the allowlist takes precedence.\n- URLs that match the allowlist are allowed.\n- URLs that match the blocklist but not the allowlist are blocked.\n- URLs that match neither list follow the behavior defined by the general \"URLBlocklist\" and \"URLAllowlist\" policies.\n\nIf \"InPrivateModeUrlAllowlist\" is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.\n\nIf \"InPrivateModeAvailability\" is set to disallow (value 1) and \"InPrivateModeUrlAllowlist\" is configured, InPrivate mode is available only for URLs that match the allowlist.\n\nThis policy applies only to InPrivate mode. To block URLs across all browsing modes, use \"URLBlocklist\".\n\nThis policy supports up to 1000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"5045bdf73a9ee016":{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended","displayName":"Visual search enabled (users can override)","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search is disabled and you can't get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"50c35acd49ef8084":{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation","displayName":"Configure Recovery Password Rotation","description":" Allows Admin to configure Numeric Recovery Password Rotation upon use for OS and fixed drives on Entra ID and Hybrid domain joined devices.\n When not configured, Rotation is turned on by default for Entra ID only and off on Hybrid. The Policy will be effective only when \n Active Directory back up for recovery password is configured to required.\n For OS drive: Turn on \"Do not enable Bitlocker until recovery information is stored to AD DS for operating system drives\"\n For Fixed drives: Turn on \"Do not enable Bitlocker until recovery information is stored to AD DS for fixed data drives\"\n \n Supported Values: 0 - Numeric Recovery Passwords rotation OFF.\n 1 - Numeric Recovery Passwords Rotation upon use ON for Entra ID joined devices. Default value\n 2 - Numeric Recovery Passwords Rotation upon use ON for both Entra ID and Hybrid devices\n \n If you want to disable this policy use the following SyncML:\n \n 112./Device/Vendor/MSFT/BitLocker/ConfigureRecoveryPasswordRotationint0","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_0","displayName":"Refresh off (default)","description":"Refresh off (default)","helpText":null},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_1","displayName":"Refresh on for Entra ID-joined devices","description":"Refresh on for Entra ID-joined devices","helpText":null},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_2","displayName":"Refresh on for both Entra ID-joined and hybrid-joined devices","description":"Refresh on for both Entra ID-joined and hybrid-joined devices","helpText":null}]},"50a65f9ed33f5e58":{"id":"device_vendor_msft_defender_configuration_supportloglocation","displayName":"Support Log Location","description":"The support log location setting allows the administrator to specify where the Microsoft Defender Antivirus diagnostic data collection tool (MpCmdRun.exe) will save the resulting log files. This setting is configured with an MDM solution, such as Intune, and is available for Windows 10 Enterprise.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"50b2950684f543ba":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize_bits_maxsize","displayName":"Percentage of disk space to be used for the BITS peercache:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"503036fa4da32e00":{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled","displayName":"Allow logon scripts when NetBIOS or WINS is disabled","description":"This policy setting allows user logon scripts to run when the logon cross-forest, DNS suffixes are not configured, and NetBIOS or WINS is disabled. This policy setting affects all user accounts interactively logging on to the computer.\r\n\r\nIf you enable this policy setting, user logon scripts run if NetBIOS or WINS is disabled during cross-forest logons without the DNS suffixes being configured.\r\n\r\nIf you disable or do not configure this policy setting, user account cross-forest, interactive logging cannot run logon scripts if NetBIOS or WINS is disabled, and the DNS suffixes are not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-allow-logon-script-netbiosdisabled"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5015b82167046f77":{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges","displayName":"MSI Always Install With Elevated Privileges","description":"This policy setting directs Windows Installer to use elevated permissions when it installs any program on the system. If you enable this policy setting, privileges are extended to all programs. These privileges are usually reserved for programs that have been assigned to the user (offered on the desktop), assigned to the computer (installed automatically), or made available in Add or Remove Programs in Control Panel. This profile setting lets users install programs that require access to directories that the user might not have permission to view or change, including directories on highly restricted computers. If you disable or do not configure this policy setting, the system applies the current user's permissions when it installs programs that a system administrator does not distribute or offer. Note: This policy setting appears both in the Computer Configuration and User Configuration folders. To make this policy setting effective, you must enable it in both folders. Caution: Skilled users can take advantage of the permissions this policy setting grants to change their privileges and gain permanent access to restricted files and folders. Note that the User Configuration version of this policy setting is not guaranteed to be secure.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#msialwaysinstallwithelevatedprivileges"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"500ec663937f6ecd":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"5031cd86e7ea2deb":{"id":"device_vendor_msft_policy_config_authentication_configurewebsigninallowedurls","displayName":"Configure Web Sign In Allowed Urls","description":"Specifies a list of URLs that are navigable in Web Sign-in based authentication scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#configurewebsigninallowedurls"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":null},"50b22d36a38d3325":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer","displayName":"Allow remote access users to transfer files to/from the host","description":"Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host. This doesn't apply to remote assistance connections, which don't support file transfer.\r\n\r\nSetting the policy to Disabled disallows file transfer.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_1","displayName":"Enabled","description":null,"helpText":null}]},"50782e609218fb2f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure","displayName":"Enable trust in Symantec Corporation's Legacy PKI Infrastructure","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure_1","displayName":"Enabled","description":null,"helpText":null}]},"503f500e84d5b6f7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename","displayName":"Enterprise web store name (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_1","displayName":"Enabled","description":null,"helpText":null}]},"500a82d15f0cbba8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls","displayName":"Allow the File Handling API on these web apps","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"5086614d61c3069a":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser","displayName":"Enterprise Logo URL for a managed browser","description":"A URL to an image that will be used as an enterprise badge for a managed browser. The URL must point to an image.\r\n\r\nIt is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px.\r\n\r\nNote that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nExample value: https://example.com/image.png","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_1","displayName":"Enabled","description":null,"helpText":null}]},"506681b9687d7a17":{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc","displayName":"Allow Option To Show This PC","description":"When This PC location is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshowthispc"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"50760113c85c348b":{"id":"device_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature","displayName":"Turn off the flip ahead with page prediction feature","description":"This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.\n\nMicrosoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn't available for Internet Explorer for the desktop.\n\nIf you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn't loaded into the background.\n\nIf you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.\n\nIf you don't configure this setting, users can turn this behavior on or off, using the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableflipaheadfeature"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_1","displayName":"Enabled","description":null,"helpText":null}]},"501c9a293675128d":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues","displayName":"Additional server versions supported","description":"\r\nSpecify a semicolon separated list of server version names, e.g. RTC/2.9;RTC/3.0;RTC/4.0, to which Microsoft Lync allows logon in addition to the server versions that are supported by default. Space character is treated as part of the version string.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1","displayName":"Enabled","description":null,"helpText":null}]},"50b44f98d3b86fd8":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled","displayName":"Enable ending processes in the Browser task manager","description":"If you enable or don't configure this policy, users can end processes in the Browser task manager. If you disable it, users can't end processes, and the End process button is disabled in the Browser task manager.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5021fbf412024b3c":{"id":"device_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly","description":"This policy controls whether native host executables launch directly on Windows.\r\n\r\nIf you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly.\r\n\r\nIf you disable this policy, Microsoft Edge will launch hosts using cmd.exe as an intermediary process.\r\n\r\nIf you don't configure this policy, Microsoft Edge will decide which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_1","displayName":"Enabled","description":null,"helpText":null}]},"50bf5174e2eac242":{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled","displayName":"Let users snip a Math problem and get the solution with a step-by-step explanation in Microsoft Edge (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125.\r\n\r\nThis policy is obsoleted because Math Solver is deprecated from Edge. This policy won't work in Microsoft Edge version 126. This policy lets you manage whether users can use the Math Solver tool in Microsoft Edge or not.\r\n\r\nIf you enable or don't configure the policy, then a user can take a snip of the Math problem and get the solution including a step-by-step explanation of the solution in a Microsoft Edge side pane.\r\n\r\nIf you disable the policy, then the Math Solver tool will be disabled and users will not be able to use it.\r\n\r\nNote: Setting the 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) policy to disabled will also disable the Math Solver component.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"50675f160cf49e9c":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill","description":"The feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is auto-filled into a web form. This ensures that non-authorized persons can't use saved passwords for autofill. Note that this feature does not protect against locally-running malware.\r\n\r\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\r\n\r\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill will not have any authentication flow.\r\n\r\nIf you set this policy to 'WithDevicePassword', users will have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is auto filled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\r\n\r\nIf you set this policy to 'WithCustomPrimaryPassword', users will be asked to create their custom password and then to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords will get auto-filled after successful authentication. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\r\n\r\nIf you set this policy to 'AutofillOff', saved passwords will no longer be suggested for autofill.\r\n\r\nPolicy options mapping:\r\n\r\n* Automatically (0) = Automatically\r\n\r\n* WithDevicePassword (1) = With device password\r\n\r\n* WithCustomPrimaryPassword (2) = With custom primary password\r\n\r\n* AutofillOff (3) = Autofill off\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"50fdcc8b4bca3699":{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode","displayName":"Configure when efficiency mode should become active (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null}]},"507a844ca520e031":{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (Device) (obsolete)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null}]},"5020713cee5a7ac6":{"id":"device_vendor_msft_policy_config_msslegacy_ipv6sourceroutingprotectionlevel_disableipsourceroutingipv6","displayName":"DisableIPSourceRoutingIPv6","description":"","helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_msslegacy_ipv6sourceroutingprotectionlevel_disableipsourceroutingipv6_0","displayName":"No additional protection, source routed packets are allowed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_msslegacy_ipv6sourceroutingprotectionlevel_disableipsourceroutingipv6_1","displayName":"Medium, source routed packets ignored when IP forwarding is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_msslegacy_ipv6sourceroutingprotectionlevel_disableipsourceroutingipv6_2","displayName":"Highest protection, source routing is completely disabled","description":null,"helpText":null}]},"50a9ea2aa637d89d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_winwordexe49","displayName":"winword.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_winwordexe49_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_winwordexe49_1","displayName":"True","description":null,"helpText":null}]},"50289e334a263b64":{"id":"device_vendor_msft_policy_config_quiettime_mutenotificationsclockedout","displayName":"Mute notifications","description":"This will automatically mute Microsoft Teams notifications when managed account is in non-working time. Note: Configuring this setting will prevent end users from editing their global quiet time settings.","helpText":null,"infoUrls":[],"categoryId":"fde9be9c-e0ab-4dd8-9df3-0794e608d15a","categoryName":null,"options":{"id":"device_vendor_msft_policy_config_quiettime_mutenotificationsclockedout_1","displayName":"Require","description":null,"helpText":null}},"502fbbd606131fb1":{"id":"device_vendor_msft_policy_config_remotedesktopservices_clientconnectionencryptionlevel_ts_encryption_level","displayName":"Encryption Level","description":"","helpText":"","infoUrls":[],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_clientconnectionencryptionlevel_ts_encryption_level_1","displayName":"Low Level","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_clientconnectionencryptionlevel_ts_encryption_level_2","displayName":"Client Compatible","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_clientconnectionencryptionlevel_ts_encryption_level_3","displayName":"High Level","description":null,"helpText":null}]},"5090642c4dbc89c7":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1.upadtes~policy~avd_gp_node_avd_server_watermarking_part_watermarkingwidthfactor","displayName":"Width of grid box in percent relative to QR code bitmap width (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":null},"50e67d2965a35f1e":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications_pol_defaultmeteredupdates_part_defaultmeteredupdatespolicy","displayName":"Default Metered Updates policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications_pol_defaultmeteredupdates_part_defaultmeteredupdatespolicy_1","displayName":"Default Metered Updates Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications_pol_defaultmeteredupdates_part_defaultmeteredupdatespolicy_2","displayName":"Default Metered Updates Allowed","description":null,"helpText":null}]},"50052838d59460a3":{"id":"settings_item_timezone","displayName":"Time Zone","description":"A dictionary that contains time zone settings. This setting is available only on supervised devices and doesn't support user enrollment. Available in iOS 14 and later, tvOS 14 and later, and visionOS 2 and later.","helpText":null,"infoUrls":[],"categoryId":"2c156b7e-99c8-4a21-a828-4f9b94479b0d","categoryName":"Time Zone","options":null},"507cfa9342f194ac":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon69","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"50342b8417aab6b4":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1","displayName":"Configure Default consent (User)","description":"This policy setting determines the default consent behavior of Windows Error Reporting.\r\n\r\nIf you enable this policy setting, you can set the default consent handling for error reports. The following list describes the Consent level settings that are available in the pull-down menu in this policy setting:\r\n\r\n- Always ask before sending data: Windows prompts users for consent to send reports.\r\n\r\n- Send parameters: Only the minimum data that is required to check for an existing solution is sent automatically, and Windows prompts users for consent to send any additional data that is requested by Microsoft.\r\n\r\n- Send parameters and safe additional data: the minimum data that is required to check for an existing solution, along with data which Windows has determined (within a high probability) does not contain personally-identifiable information is sent automatically, and Windows prompts the user for consent to send any additional data that is requested by Microsoft.\r\n\r\n- Send all data: any error reporting data requested by Microsoft is sent automatically.\r\n\r\nIf this policy setting is disabled or not configured, then the consent level defaults to the highest-privacy setting: Always ask before sending data.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werdefaultconsent-1"],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_1","displayName":"Enabled","description":null,"helpText":null}]},"50b34856887b5083":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_services","displayName":"Services (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-services"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_services_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_services_1","displayName":"Enabled","description":null,"helpText":null}]},"502cefbceb367c15":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled","displayName":"Enable AutoFill for credit cards (User)","description":"Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.\r\n\r\nSetting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"503cd7ebc7046ce1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls","displayName":"Block cookies on these sites (User)","description":"Setting the policy lets you make a list of URL patterns that specify sites that can't set cookies.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nWhile no specific policy takes precedence, see CookiesAllowedForUrls and CookiesSessionOnlyForUrls. URL patterns among these 3 policies must not conflict.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"50da40cf6467f9fd":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar (User)","description":"For work and school profiles, the toolbar will show a \"Work\" or \"School\" label by default next to the toolbar avatar. The label will only be shown if the signed in account is managed.\r\n\r\nSetting this policy to hide_expanded_enterprise_toolbar_badge (value 1) will hide the enterprise badge for a managed profile in the toolbar.\r\n\r\nLeaving this policy unset or setting it to show_expanded_enterprise_toolbar_badge (value 0) will show the enterprise badge.\r\n\r\nThe label is customizable via the EnterpriseCustomLabel policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"5032f9ac0a78041b":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether Excel keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, Excel keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, Excel does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},"50a12c2b56ed0cb3":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},"505958d943276cdd":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"5004eabb1fb5e6bc":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},"5043018278025e9a":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist_proxybypasslist","displayName":"Comma-separated list of proxy bypass rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},"508204de8b73b1f5":{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings","displayName":"Dynamic Code Settings (User)","description":"This policy controls the dynamic code settings for Microsoft Edge.\r\n\r\nDisabling dynamic code improves the security of Microsoft Edge by preventing potentially hostile dynamic code and third-party code from making changes to Microsoft Edge's behavior. However this might cause compatibility issues with third-party software that must run in the browser process.\r\n\r\nIf you set this policy to 0 (the default) or leave unset, then Microsoft Edge will use the default settings.\r\n\r\nIf you set this policy to 1 – (EnabledForBrowser) then the Microsoft Edge browser process is prevented from creating dynamic code.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default dynamic code settings\r\n\r\n* EnabledForBrowser (1) = Prevent the browser process from creating dynamic code\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"50c49caa9fc8b19f":{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page. (User)","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\r\n\r\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\r\n\r\nIf this policy is not configured, the default neutralStrokeActive (#cecece) color will be used as the backplate color.\r\n\r\nExample value: #cecece","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_1","displayName":"Enabled","description":null,"helpText":null}]},"500cd374fc9ceef3":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Prevent redirection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Redirect sites based on the incompatible sites sitelist","description":null,"helpText":null}]},"500c055963215f7f":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled","displayName":"Windows Hello For HTTP Auth Enabled (User)","description":"Indicates if Windows Credential UI should be used to respond to NTLM and Negotiate authentication challenges.\r\n\r\nIf you disable this policy, a basic username and password prompt will be used to respond to NTLM and Negotiate challenges. If you enable or don't configure this policy, Windows Credential UI will be used.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5017725cbc53b308":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},"50da54dbb0fcb894":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype","displayName":"Select the Shorten Events Type (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_none","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_end_early","displayName":"End Early","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_start_late","displayName":"Start Late","description":null,"helpText":null}]},"508a30723495b60e":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon10","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"5019b20bac189bc7":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui","displayName":"Resource Assigments (User)","description":"Specifies that the feedback triangle should appear in a corner of a field if the user assigns additional resources to a task that already has resources assigned.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of a field if users assign additional resources to a task that already has resources assigned.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui_1","displayName":"Enabled","description":null,"helpText":null}]},"5059a1262616cffe":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks","displayName":"Autolink inserted or moved tasks (User)","description":"This policy setting automatically links tasks when you cut, move, or insert them.\r\n\r\nIf you enable this policy setting, tasks will automatically be linked when you cut, move, or insert them.\r\n\r\nIf you disable or do not configure this policy setting, tasks will not automatically be linked when you cut, move, or insert them.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks_1","displayName":"Enabled","description":null,"helpText":null}]},"505163bed94405f8":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword","displayName":"When formatting, automatically format entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword_1","displayName":"Enabled","description":null,"helpText":null}]},"50887bcacc1d49c4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting_1","displayName":"Enabled","description":null,"helpText":null}]},"50d74b668263a4e7":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting","displayName":"Correct keyboard setting (User)","description":"This policy setting allows you to set the \"Correct keyboard setting\" option in Word Options | Proofing | \"AutoCorrect Options...\" | AutoCorrect.\r\n\r\nIf you enable this policy setting, \"Correct keyboard setting\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Correct keyboard setting\" will not be set.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"50cf035eeb1e95c2":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword","displayName":"Legacy converters for Word (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_1","displayName":"Enabled","description":null,"helpText":null}]},"5058eb5e1a42755b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"50f7cbe2c6029369":{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge","displayName":"Global Ports Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, global port firewall rules in the local store are ignored and not enforced. The setting only has meaning if it is set or enumerated in the Group Policy store or if it is enumerated from the GroupPolicyRSoPStore. The merge law for this option is to let the value GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge_false","displayName":"False","description":"GlobalPortsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge_true","displayName":"True","description":"GlobalPortsAllowUserPrefMerge On","helpText":null}]}} \ No newline at end of file +{"5038952785cf1cbf":{"id":"ade_accountsettings_createlocaladmin","displayName":"Create a local admin account","description":null,"helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":[{"id":"ade_accountsettings_createlocaladmin_0","displayName":"No","description":null,"helpText":null},{"id":"ade_accountsettings_createlocaladmin_1","displayName":"Yes","description":null,"helpText":null}]},"50de61a1064d8c05":{"id":"com.apple.dnssettings.managed_prohibitdisablement","displayName":"Prohibit Disablement","description":"If true, prohibits users from disabling DNS settings. This key is only available on supervised devices.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_prohibitdisablement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_prohibitdisablement_true","displayName":"Enabled","description":null,"helpText":null}]},"50a8f33e8b1c357d":{"id":"com.apple.managedclient.preferences_forceephemeralprofiles","displayName":"Enable use of ephemeral profiles","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\n\nIf you enable this policy, profiles run in ephemeral mode. This lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\n\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\n\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user has enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forceephemeralprofiles"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forceephemeralprofiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forceephemeralprofiles_true","displayName":"Enabled","description":null,"helpText":null}]},"50a0769ae49df32a":{"id":"com.apple.managedclient.preferences_importhistory","displayName":"Allow importing of browsing history","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\n\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS) and Apple Safari (macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importhistory"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importhistory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importhistory_true","displayName":"Enabled","description":null,"helpText":null}]},"50d60fc73d44d1f1":{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container","displayName":"Default launch container","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container_0","displayName":"tab","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_default_launch_container_1","displayName":"window","description":null,"helpText":null}]},"50d2949c22e519b5":{"id":"com.apple.mobiledevice.passwordpolicy_com.apple.mobiledevice.passwordpolicy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"5085f39ba4f0fbfb":{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen","displayName":"Show In Lock Screen","description":"If true, enables notifications on the lock screen for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_showinlockscreen_true","displayName":"True","description":null,"helpText":null}]},"50fe702ef8091db9":{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload","displayName":"Enable XProtect Malware Upload","description":"If false, will prevent Gatekeeper from prompting the user to upload blocked malware to Apple for purposes of improving malware detection.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_enablexprotectmalwareupload_true","displayName":"Enabled","description":null,"helpText":null}]},"5003cfa26047898d":{"id":"com.apple.universalaccess_mousedrivermaxspeed","displayName":"Mouse Driver Max Speed","description":"The maximum speed for the cursor when using Mouse Keys.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},"500febc680700d8f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\nThis policy also applies to component extensions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enterprisehardwareplatformapienabled_true","displayName":"Enabled","description":null,"helpText":null}]},"50e56084313cf5af":{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeurlblocklist","displayName":"Block access to a list of URLs in InPrivate mode.","description":"This policy controls which URLs are blocked from loading in InPrivate mode in Microsoft Edge.\n\nAdministrators can specify a list of URL patterns that are blocked when users browse in InPrivate mode. For information about the supported URL pattern format, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nIf both \"InPrivateModeUrlBlocklist\" and \"InPrivateModeUrlAllowlist\" are configured, the allowlist takes precedence.\n- URLs that match the allowlist are allowed.\n- URLs that match the blocklist but not the allowlist are blocked.\n- URLs that match neither list follow the behavior defined by the general \"URLBlocklist\" and \"URLAllowlist\" policies.\n\nIf \"InPrivateModeUrlAllowlist\" is configured and this policy is not configured, only URLs on the allowlist can be opened in InPrivate mode.\n\nIf \"InPrivateModeAvailability\" is set to disallow (value 1) and \"InPrivateModeUrlAllowlist\" is configured, InPrivate mode is available only for URLs that match the allowlist.\n\nThis policy applies only to InPrivate mode. To block URLs across all browsing modes, use \"URLBlocklist\".\n\nThis policy supports up to 1000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"5045bdf73a9ee016":{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended","displayName":"Visual search enabled (users can override)","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search is enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search is disabled and you can't get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.visualsearchenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"503e1634238cdcad":{"id":"contentcaching_peerlistenranges_item_type","displayName":"Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_peerlistenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"contentcaching_peerlistenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},"50c35acd49ef8084":{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation","displayName":"Configure Recovery Password Rotation","description":" Allows Admin to configure Numeric Recovery Password Rotation upon use for OS and fixed drives on Entra ID and Hybrid domain joined devices.\n When not configured, Rotation is turned on by default for Entra ID only and off on Hybrid. The Policy will be effective only when \n Active Directory back up for recovery password is configured to required.\n For OS drive: Turn on \"Do not enable Bitlocker until recovery information is stored to AD DS for operating system drives\"\n For Fixed drives: Turn on \"Do not enable Bitlocker until recovery information is stored to AD DS for fixed data drives\"\n \n Supported Values: 0 - Numeric Recovery Passwords rotation OFF.\n 1 - Numeric Recovery Passwords Rotation upon use ON for Entra ID joined devices. Default value\n 2 - Numeric Recovery Passwords Rotation upon use ON for both Entra ID and Hybrid devices\n \n If you want to disable this policy use the following SyncML:\n \n 112./Device/Vendor/MSFT/BitLocker/ConfigureRecoveryPasswordRotationint0","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/BitLocker-csp/"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_0","displayName":"Refresh off (default)","description":"Refresh off (default)","helpText":null},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_1","displayName":"Refresh on for Entra ID-joined devices","description":"Refresh on for Entra ID-joined devices","helpText":null},{"id":"device_vendor_msft_bitlocker_configurerecoverypasswordrotation_2","displayName":"Refresh on for both Entra ID-joined and hybrid-joined devices","description":"Refresh on for both Entra ID-joined and hybrid-joined devices","helpText":null}]},"50a65f9ed33f5e58":{"id":"device_vendor_msft_defender_configuration_supportloglocation","displayName":"Support Log Location","description":"The support log location setting allows the administrator to specify where the Microsoft Defender Antivirus diagnostic data collection tool (MpCmdRun.exe) will save the resulting log files. This setting is configured with an MDM solution, such as Intune, and is available for Windows 10 Enterprise.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"50b2950684f543ba":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxcachesize_bits_maxsize","displayName":"Percentage of disk space to be used for the BITS peercache:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"503036fa4da32e00":{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled","displayName":"Allow logon scripts when NetBIOS or WINS is disabled","description":"This policy setting allows user logon scripts to run when the logon cross-forest, DNS suffixes are not configured, and NetBIOS or WINS is disabled. This policy setting affects all user accounts interactively logging on to the computer.\r\n\r\nIf you enable this policy setting, user logon scripts run if NetBIOS or WINS is disabled during cross-forest logons without the DNS suffixes being configured.\r\n\r\nIf you disable or do not configure this policy setting, user account cross-forest, interactive logging cannot run logon scripts if NetBIOS or WINS is disabled, and the DNS suffixes are not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-scripts#admx-scripts-allow-logon-script-netbiosdisabled"],"categoryId":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","categoryName":"Scripts","options":[{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_scripts_allow_logon_script_netbiosdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5015b82167046f77":{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges","displayName":"MSI Always Install With Elevated Privileges","description":"This policy setting directs Windows Installer to use elevated permissions when it installs any program on the system. If you enable this policy setting, privileges are extended to all programs. These privileges are usually reserved for programs that have been assigned to the user (offered on the desktop), assigned to the computer (installed automatically), or made available in Add or Remove Programs in Control Panel. This profile setting lets users install programs that require access to directories that the user might not have permission to view or change, including directories on highly restricted computers. If you disable or do not configure this policy setting, the system applies the current user's permissions when it installs programs that a system administrator does not distribute or offer. Note: This policy setting appears both in the Computer Configuration and User Configuration folders. To make this policy setting effective, you must enable it in both folders. Caution: Skilled users can take advantage of the permissions this policy setting grants to change their privileges and gain permanent access to restricted files and folders. Note that the User Configuration version of this policy setting is not guaranteed to be secure.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#msialwaysinstallwithelevatedprivileges"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msialwaysinstallwithelevatedprivileges_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"500ec663937f6ecd":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"5031cd86e7ea2deb":{"id":"device_vendor_msft_policy_config_authentication_configurewebsigninallowedurls","displayName":"Configure Web Sign In Allowed Urls","description":"Specifies a list of URLs that are navigable in Web Sign-in based authentication scenarios.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Authentication#configurewebsigninallowedurls"],"categoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","categoryName":"Authentication","options":null},"50b22d36a38d3325":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer","displayName":"Allow remote access users to transfer files to/from the host","description":"Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host. This doesn't apply to remote assistance connections, which don't support file transfer.\r\n\r\nSetting the policy to Disabled disallows file transfer.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_1","displayName":"Enabled","description":null,"helpText":null}]},"50782e609218fb2f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure","displayName":"Enable trust in Symantec Corporation's Legacy PKI Infrastructure","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enablesymanteclegacyinfrastructure_1","displayName":"Enabled","description":null,"helpText":null}]},"503f500e84d5b6f7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename","displayName":"Enterprise web store name (deprecated)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enterprisewebstorename_1","displayName":"Enabled","description":null,"helpText":null}]},"500a82d15f0cbba8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls","displayName":"Allow the File Handling API on these web apps","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_filehandlingallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"5086614d61c3069a":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser","displayName":"Enterprise Logo URL for a managed browser","description":"A URL to an image that will be used as an enterprise badge for a managed browser. The URL must point to an image.\r\n\r\nIt is recommended to use the favicon (example https://www.google.com/favicon.ico) or an icon no smaller than 48 x 48 px.\r\n\r\nNote that this policy is only applied for managed browsers, so it will have no effect for managed users on unmanaged browsers.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nExample value: https://example.com/image.png","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriselogourlforbrowser_1","displayName":"Enabled","description":null,"helpText":null}]},"506681b9687d7a17":{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc","displayName":"Allow Option To Show This PC","description":"When This PC location is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshowthispc"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"50760113c85c348b":{"id":"device_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature","displayName":"Turn off the flip ahead with page prediction feature","description":"This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.\n\nMicrosoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn't available for Internet Explorer for the desktop.\n\nIf you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn't loaded into the background.\n\nIf you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.\n\nIf you don't configure this setting, users can turn this behavior on or off, using the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableflipaheadfeature"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_1","displayName":"Enabled","description":null,"helpText":null}]},"501c9a293675128d":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues","displayName":"Additional server versions supported","description":"\r\nSpecify a semicolon separated list of server version names, e.g. RTC/2.9;RTC/3.0;RTC/4.0, to which Microsoft Lync allows logon in addition to the server versions that are supported by default. Space character is treated as part of the version string.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policyconfiguredservercheckvalues_1","displayName":"Enabled","description":null,"helpText":null}]},"50b44f98d3b86fd8":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled","displayName":"Enable ending processes in the Browser task manager","description":"If you enable or don't configure this policy, users can end processes in the Browser task manager. If you disable it, users can't end processes, and the End process button is disabled in the Browser task manager.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_taskmanagerendprocessenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5021fbf412024b3c":{"id":"device_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly","displayName":"Force Windows executable Native Messaging hosts to launch directly","description":"This policy controls whether native host executables launch directly on Windows.\r\n\r\nIf you enable this policy, Microsoft Edge is forced to launch native messaging hosts implemented as executables directly.\r\n\r\nIf you disable this policy, Microsoft Edge will launch hosts using cmd.exe as an intermediary process.\r\n\r\nIf you don't configure this policy, Microsoft Edge will decide which approach to use based on a progressive rollout from the legacy behavior to the Launch Directly behavior, guided by ecosystem compatibility.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_nativehostsexecutableslaunchdirectly_1","displayName":"Enabled","description":null,"helpText":null}]},"50bf5174e2eac242":{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled","displayName":"Let users snip a Math problem and get the solution with a step-by-step explanation in Microsoft Edge (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125.\r\n\r\nThis policy is obsoleted because Math Solver is deprecated from Edge. This policy won't work in Microsoft Edge version 126. This policy lets you manage whether users can use the Math Solver tool in Microsoft Edge or not.\r\n\r\nIf you enable or don't configure the policy, then a user can take a snip of the Math problem and get the solution including a step-by-step explanation of the solution in a Microsoft Edge side pane.\r\n\r\nIf you disable the policy, then the Math Solver tool will be disabled and users will not be able to use it.\r\n\r\nNote: Setting the 'ComponentUpdatesEnabled' (Enable component updates in Microsoft Edge) policy to disabled will also disable the Math Solver component.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev91~policy~microsoft_edge_mathsolverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"50675f160cf49e9c":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill","description":"The feature helps users add an additional layer of privacy to their online accounts by requiring device authentication (as a way of confirming the user's identity) before the saved password is auto-filled into a web form. This ensures that non-authorized persons can't use saved passwords for autofill. Note that this feature does not protect against locally-running malware.\r\n\r\nThis group policy configures the radio button selector that enables this feature for users. It also has a frequency control where users can specify how often they would like to be prompted for authentication.\r\n\r\nIf you set this policy to 'Automatically', disable this policy, or don't configure this policy, autofill will not have any authentication flow.\r\n\r\nIf you set this policy to 'WithDevicePassword', users will have to enter their device password (or preferred mode of authentication under Windows) to prove their identity before their password is auto filled. Authentication modes include Windows Hello, PIN, face recognition, or fingerprint. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\r\n\r\nIf you set this policy to 'WithCustomPrimaryPassword', users will be asked to create their custom password and then to be redirected to Settings. After the custom password is set, users can authenticate themselves using the custom password and their passwords will get auto-filled after successful authentication. The frequency for authentication prompt will be set to 'Ask permission once per browsing session' by default. However, users can change it to the other option, which is 'Always ask permission'.\r\n\r\nIf you set this policy to 'AutofillOff', saved passwords will no longer be suggested for autofill.\r\n\r\nPolicy options mapping:\r\n\r\n* Automatically (0) = Automatically\r\n\r\n* WithDevicePassword (1) = With device password\r\n\r\n* WithCustomPrimaryPassword (2) = With custom primary password\r\n\r\n* AutofillOff (3) = Autofill off\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_primarypasswordsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"50fdcc8b4bca3699":{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode","displayName":"Configure when efficiency mode should become active (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_0","displayName":"Efficiency mode is always active","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_1","displayName":"Efficiency mode is never active","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_2","displayName":"Efficiency mode is active when the device is unplugged","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_3","displayName":"Efficiency mode is active when the device is unplugged and the battery is low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_4","displayName":"When the device is unplugged, efficiency mode takes moderate steps to save battery. When the device is unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96.1~policy~microsoft_edge~performance_efficiencymode_efficiencymode_5","displayName":"When the device is unplugged or unplugged and the battery is low, efficiency mode takes additional steps to save battery.","description":null,"helpText":null}]},"507a844ca520e031":{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (Device) (obsolete)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null}]},"5020713cee5a7ac6":{"id":"device_vendor_msft_policy_config_msslegacy_ipv6sourceroutingprotectionlevel_disableipsourceroutingipv6","displayName":"DisableIPSourceRoutingIPv6","description":"","helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_msslegacy_ipv6sourceroutingprotectionlevel_disableipsourceroutingipv6_0","displayName":"No additional protection, source routed packets are allowed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_msslegacy_ipv6sourceroutingprotectionlevel_disableipsourceroutingipv6_1","displayName":"Medium, source routed packets ignored when IP forwarding is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_msslegacy_ipv6sourceroutingprotectionlevel_disableipsourceroutingipv6_2","displayName":"Highest protection, source routing is completely disabled","description":null,"helpText":null}]},"50a9ea2aa637d89d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_winwordexe49","displayName":"winword.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_winwordexe49_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_winwordexe49_1","displayName":"True","description":null,"helpText":null}]},"50289e334a263b64":{"id":"device_vendor_msft_policy_config_quiettime_mutenotificationsclockedout","displayName":"Mute notifications","description":"This will automatically mute Microsoft Teams notifications when managed account is in non-working time. Note: Configuring this setting will prevent end users from editing their global quiet time settings.","helpText":null,"infoUrls":[],"categoryId":"fde9be9c-e0ab-4dd8-9df3-0794e608d15a","categoryName":null,"options":{"id":"device_vendor_msft_policy_config_quiettime_mutenotificationsclockedout_1","displayName":"Require","description":null,"helpText":null}},"502fbbd606131fb1":{"id":"device_vendor_msft_policy_config_remotedesktopservices_clientconnectionencryptionlevel_ts_encryption_level","displayName":"Encryption Level","description":"","helpText":"","infoUrls":[],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_clientconnectionencryptionlevel_ts_encryption_level_1","displayName":"Low Level","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_clientconnectionencryptionlevel_ts_encryption_level_2","displayName":"Client Compatible","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_clientconnectionencryptionlevel_ts_encryption_level_3","displayName":"High Level","description":null,"helpText":null}]},"5090642c4dbc89c7":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1.upadtes~policy~avd_gp_node_avd_server_watermarking_part_watermarkingwidthfactor","displayName":"Width of grid box in percent relative to QR code bitmap width (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":null},"50f0b4c2e7c97042":{"id":"device_vendor_msft_policy_config_update_maintenancewindowweeklysunday","displayName":"Maintenance Window Weekly Sunday","description":"If the maintenance window repeat schedule is set to weekly, configure whether Sunday is included in the weekly schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowweeklysunday"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"50e67d2965a35f1e":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications_pol_defaultmeteredupdates_part_defaultmeteredupdatespolicy","displayName":"Default Metered Updates policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications_pol_defaultmeteredupdates_part_defaultmeteredupdatespolicy_1","displayName":"Default Metered Updates Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications_pol_defaultmeteredupdates_part_defaultmeteredupdatespolicy_2","displayName":"Default Metered Updates Allowed","description":null,"helpText":null}]},"50052838d59460a3":{"id":"settings_item_timezone","displayName":"Time Zone","description":"A dictionary that contains time zone settings. This setting is available only on supervised devices and doesn't support user enrollment. Available in iOS 14 and later, tvOS 14 and later, and visionOS 2 and later.","helpText":null,"infoUrls":[],"categoryId":"2c156b7e-99c8-4a21-a828-4f9b94479b0d","categoryName":"Time Zone","options":null},"507cfa9342f194ac":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon69","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"50342b8417aab6b4":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1","displayName":"Configure Default consent (User)","description":"This policy setting determines the default consent behavior of Windows Error Reporting.\r\n\r\nIf you enable this policy setting, you can set the default consent handling for error reports. The following list describes the Consent level settings that are available in the pull-down menu in this policy setting:\r\n\r\n- Always ask before sending data: Windows prompts users for consent to send reports.\r\n\r\n- Send parameters: Only the minimum data that is required to check for an existing solution is sent automatically, and Windows prompts users for consent to send any additional data that is requested by Microsoft.\r\n\r\n- Send parameters and safe additional data: the minimum data that is required to check for an existing solution, along with data which Windows has determined (within a high probability) does not contain personally-identifiable information is sent automatically, and Windows prompts the user for consent to send any additional data that is requested by Microsoft.\r\n\r\n- Send all data: any error reporting data requested by Microsoft is sent automatically.\r\n\r\nIf this policy setting is disabled or not configured, then the consent level defaults to the highest-privacy setting: Always ask before sending data.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werdefaultconsent-1"],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_1","displayName":"Enabled","description":null,"helpText":null}]},"50b34856887b5083":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_services","displayName":"Services (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-services"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_services_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_services_1","displayName":"Enabled","description":null,"helpText":null}]},"502cefbceb367c15":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled","displayName":"Enable AutoFill for credit cards (User)","description":"Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.\r\n\r\nSetting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"503cd7ebc7046ce1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls","displayName":"Block cookies on these sites (User)","description":"Setting the policy lets you make a list of URL patterns that specify sites that can't set cookies.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nWhile no specific policy takes precedence, see CookiesAllowedForUrls and CookiesSessionOnlyForUrls. URL patterns among these 3 policies must not conflict.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"50da40cf6467f9fd":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar (User)","description":"For work and school profiles, the toolbar will show a \"Work\" or \"School\" label by default next to the toolbar avatar. The label will only be shown if the signed in account is managed.\r\n\r\nSetting this policy to hide_expanded_enterprise_toolbar_badge (value 1) will hide the enterprise badge for a managed profile in the toolbar.\r\n\r\nLeaving this policy unset or setting it to show_expanded_enterprise_toolbar_badge (value 0) will show the enterprise badge.\r\n\r\nThe label is customizable via the EnterpriseCustomLabel policy.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"5032f9ac0a78041b":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether Excel keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, Excel keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, Excel does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},"50a12c2b56ed0cb3":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_exceladdinfiles_l_exceladdinfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]},"505958d943276cdd":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"5004eabb1fb5e6bc":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},"5043018278025e9a":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxybypasslist_proxybypasslist","displayName":"Comma-separated list of proxy bypass rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},"508204de8b73b1f5":{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings","displayName":"Dynamic Code Settings (User)","description":"This policy controls the dynamic code settings for Microsoft Edge.\r\n\r\nDisabling dynamic code improves the security of Microsoft Edge by preventing potentially hostile dynamic code and third-party code from making changes to Microsoft Edge's behavior. However this might cause compatibility issues with third-party software that must run in the browser process.\r\n\r\nIf you set this policy to 0 (the default) or leave unset, then Microsoft Edge will use the default settings.\r\n\r\nIf you set this policy to 1 – (EnabledForBrowser) then the Microsoft Edge browser process is prevented from creating dynamic code.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default dynamic code settings\r\n\r\n* EnabledForBrowser (1) = Prevent the browser process from creating dynamic code\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_dynamiccodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"50c49caa9fc8b19f":{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page. (User)","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\r\n\r\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\r\n\r\nIf this policy is not configured, the default neutralStrokeActive (#cecece) color will be used as the backplate color.\r\n\r\nExample value: #cecece","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge~startup_newtabpagecompanylogobackplatecolor_1","displayName":"Enabled","description":null,"helpText":null}]},"500cd374fc9ceef3":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Prevent redirection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Redirect sites based on the incompatible sites sitelist","description":null,"helpText":null}]},"500c055963215f7f":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled","displayName":"Windows Hello For HTTP Auth Enabled (User)","description":"Indicates if Windows Credential UI should be used to respond to NTLM and Negotiate authentication challenges.\r\n\r\nIf you disable this policy, a basic username and password prompt will be used to respond to NTLM and Negotiate challenges. If you enable or don't configure this policy, Windows Credential UI will be used.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge~httpauthentication_windowshelloforhttpauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5017725cbc53b308":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"Warning: These locations are used as a trusted source for opening files in Word, Excel, PowerPoint, Access, InfoPath, and Visio. Macros and ActiveX controls in these documents will execute without user warning. If you change or add a location make sure that the new location is secure.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},"50da54dbb0fcb894":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype","displayName":"Select the Shorten Events Type (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_none","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_end_early","displayName":"End Early","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_l_selecttheshorteneventstype_start_late","displayName":"Start Late","description":null,"helpText":null}]},"508a30723495b60e":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon10","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"5019b20bac189bc7":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui","displayName":"Resource Assigments (User)","description":"Specifies that the feedback triangle should appear in a corner of a field if the user assigns additional resources to a task that already has resources assigned.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of a field if users assign additional resources to a task that already has resources assigned.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjresourceassignooui_1","displayName":"Enabled","description":null,"helpText":null}]},"5059a1262616cffe":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks","displayName":"Autolink inserted or moved tasks (User)","description":"This policy setting automatically links tasks when you cut, move, or insert them.\r\n\r\nIf you enable this policy setting, tasks will automatically be linked when you cut, move, or insert them.\r\n\r\nIf you disable or do not configure this policy setting, tasks will not automatically be linked when you cut, move, or insert them.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjautolinktasks_1","displayName":"Enabled","description":null,"helpText":null}]},"505163bed94405f8":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword","displayName":"When formatting, automatically format entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenformattingautomaticallyformatentireword_1","displayName":"Enabled","description":null,"helpText":null}]},"50887bcacc1d49c4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_draganddroptextediting_1","displayName":"Enabled","description":null,"helpText":null}]},"50d74b668263a4e7":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting","displayName":"Correct keyboard setting (User)","description":"This policy setting allows you to set the \"Correct keyboard setting\" option in Word Options | Proofing | \"AutoCorrect Options...\" | AutoCorrect.\r\n\r\nIf you enable this policy setting, \"Correct keyboard setting\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Correct keyboard setting\" will not be set.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correctkeyboardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"50cf035eeb1e95c2":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword","displayName":"Legacy converters for Word (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforword_1","displayName":"Enabled","description":null,"helpText":null}]},"5058eb5e1a42755b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"50f7cbe2c6029369":{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge","displayName":"Global Ports Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, global port firewall rules in the local store are ignored and not enforced. The setting only has meaning if it is set or enumerated in the Group Policy store or if it is enumerated from the GroupPolicyRSoPStore. The merge law for this option is to let the value GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge_false","displayName":"False","description":"GlobalPortsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_domainprofile_globalportsallowuserprefmerge_true","displayName":"True","description":"GlobalPortsAllowUserPrefMerge On","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/51.json b/public/intune-definitions/51.json index da2c79e236b0..5009a1d4c184 100644 --- a/public/intune-definitions/51.json +++ b/public/intune-definitions/51.json @@ -1 +1 @@ -{"5130c63db1c633e6":{"id":"com.android.devicerestrictionpolicy.passwordminimumlettercharacters","displayName":"Number of characters required","description":"Enter the number of characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"518ce53980dc1ae8":{"id":"com.apple.airprint_airprint_item_port","displayName":"Port","description":"The listening port of the AirPrint destination. Available only in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},"513952e6d11afa42":{"id":"com.apple.applicationaccess_allowlivevoicemail","displayName":"Allow Live Voicemail","description":"If set to false, disables live voicemail on the device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlivevoicemail_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlivevoicemail_true","displayName":"Enabled","description":null,"helpText":null}]},"5103a1486e5b8a87":{"id":"com.apple.assetcache.managed_peerlistenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},"518c1fd6951cf9b2":{"id":"com.apple.managedclient.preferences_blockexternalextensions","displayName":"Blocks external extensions from being installed","description":"Control the installation of external extensions.\n\nIf you enable this setting, external extensions are blocked from being installed.\n\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\n\nExternal extensions and their installation are documented at https://docs.microsoft.com/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blockexternalextensions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blockexternalextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockexternalextensions_true","displayName":"Enabled","description":null,"helpText":null}]},"51b007296344a7ca":{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing","displayName":"Disable DNS over TCP parsing","description":"Disables parsing of DNS over TCP","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},"51ee1266a7e536b7":{"id":"com.apple.managedclient.preferences_efficiencymodeenabled","displayName":"Efficiency mode enabled","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\n\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the \"EfficiencyMode\" policy. If the device does not have a battery, efficiency mode will always be active.\n\nIf you disable this policy, efficiency mode will never become active. The \"EfficiencyMode\" and \"EfficiencyModeOnPowerEnabled\" policies will have no effect.\n\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"51a4b9d1f2eef0b9":{"id":"com.apple.managedclient.preferences_localprovidersenabled","displayName":"Allow suggestions from local providers","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\n\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localprovidersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localprovidersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localprovidersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"511fa92924b9e7cc":{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_protocol","displayName":"Protocol","description":"The protocol for the protocol handler.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"519996673020f4bf":{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\n\nIf you disable this policy, post-quantum key agreement will not be offered for WebRTC.\n\nIf you don't configure this policy, post-quantum key agreement will not be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\n\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\n\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcpostquantumkeyagreement"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement_true","displayName":"Enabled","description":null,"helpText":null}]},"51e51337e7b54c33":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended","displayName":"Configure the new tab page search box experience (users can override)","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\".\n\n If you disable or don't configure this policy and:\n\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\n- If the address bar default search engine isn't Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\n\n\nIf you enable this policy and set it to:\n\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\n\nPolicy options mapping:\n\n* bing (bing) = Search box (Recommended)\n\n* redirect (redirect) = Address bar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended_redirect","displayName":"Address bar","description":null,"helpText":null}]},"517e6e3c7eb02acb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.registeredprotocolhandlers","displayName":"Register protocol handlers","description":"Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use.\n\nTo register a protocol handler:\n\n- Set the protocol property to the scheme (for example, \"mailto\")\n- Set the URL property to the URL property of the application that handlers the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\n\nUsers can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"51f6df9932f8480f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.registeredprotocolhandlers_recommended","displayName":"Register protocol handlers (users can override)","description":"Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use.\n\nTo register a protocol handler:\n\n- Set the protocol property to the scheme (for example, \"mailto\")\n- Set the URL property to the URL property of the application that handlers the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\n\nUsers can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers.\n\nIn the examples in this section, the URL points to the Outlook on the Web (OWA) endpoint used in Exchange Online. If you're targeting Exchange Server (on-premises), use the following URL and replace mail.contoso.com with your organization's OWA endpoint:\n\nhttps://mail.contoso.com/?path=/mail/action/compose&mailtouri=%s","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"5148b4742fef03db":{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice","displayName":"Require Security Device","description":"A Trusted Platform Module (TPM) provides additional security benefits over software because data stored within it cannot be used on other devices.\n\nIf you enable this policy setting, only devices with a usable TPM provision Windows Hello for Business.\n\nIf you disable or do not configure this policy setting, the TPM is still preferred, but all devices provision Windows Hello for Business using software if the TPM is non-functional or unavailable.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice_true","displayName":"true","description":"Enabled","helpText":null}]},"51d5e5ae98646e89":{"id":"device_vendor_msft_pkcscertificate_keystorageprovider","displayName":"Key storage provider (KSP)","description":"Select where you want to store the certificate’s key.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},"516b3c3a6effa3bb":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_23","displayName":"11 PM","description":null,"helpText":null}]},"51994a4f6c6448f2":{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy_configcipolicyfilepathtext","displayName":"Code Integrity Policy file path:","description":null,"helpText":"","infoUrls":[],"categoryId":"909339a5-8f04-4fa2-8807-5d38c83ef547","categoryName":"Device Guard","options":null},"5173f324dbfd0f04":{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck","displayName":"Include device claims","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck_1","displayName":"True","description":null,"helpText":null}]},"5180542819ac5934":{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state","displayName":"Set ISATAP State","description":"This policy setting allows you to configure Intra-Site Automatic Tunnel Addressing Protocol (ISATAP), an address-to-router and host-to-host, host-to-router and router-to-host automatic tunneling technology that is used to provide unicast IPv6 connectivity between IPv6 hosts across an IPv4 intranet.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\nIf you enable this policy setting, you can configure ISATAP with one of the following settings:\r\n\r\nPolicy Default State: If the ISATAP router name is resolved successfully, the host will have ISATAP configured with a link-local address and an address for each prefix received from the ISATAP router through stateless address auto-configuration. If the ISATAP router name is not resolved successfully, ISATAP connectivity is not available on the host using the corresponding IPv4 address.\r\n\r\nPolicy Enabled State: If the ISATAP name is resolved successfully, the host will have ISATAP configured with a link-local address and an address for each prefix received from the ISATAP router through stateless address auto-configuration. If the ISATAP name is not resolved successfully, the host will have an ISATAP interface configured with a link-local address.\r\n\r\nPolicy Disabled State: No ISATAP interfaces are present on the host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-isatap-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_1","displayName":"Enabled","description":null,"helpText":null}]},"510d528b9d2db7ba":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook","displayName":"Microsoft Outlook 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Outlook 2013.\r\nBy default, the user settings of Microsoft Outlook 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Outlook 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Outlook 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Outlook 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013outlook"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook_1","displayName":"Enabled","description":null,"helpText":null}]},"51fda9714afd98b8":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016","displayName":"Microsoft Office 365 Visio 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_1","displayName":"Enabled","description":null,"helpText":null}]},"51afd5ba49f6cf22":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-trusted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted_1","displayName":"Enabled","description":null,"helpText":null}]},"51870a396e6a0fa9":{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall","displayName":"MSI Allow User Control Over Install","description":"This policy setting permits users to change installation options that typically are available only to system administrators. If you enable this policy setting, some of the security features of Windows Installer are bypassed. It permits installations to complete that otherwise would be halted due to a security violation. If you disable or do not configure this policy setting, the security features of Windows Installer prevent users from changing installation options typically reserved for system administrators, such as specifying the directory to which files are installed. If Windows Installer detects that an installation package has permitted the user to change a protected option, it stops the installation and displays a message. These security features operate only when the installation program is running in a privileged security context in which it has access to directories denied to the user. This policy setting is designed for less restrictive environments. It can be used to circumvent errors in an installation program that prevents software from being installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#msiallowusercontroloverinstall"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"51298b23a0c08eb5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter","displayName":"Use System Default Printer as Default","description":"Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter_1","displayName":"Enabled","description":null,"helpText":null}]},"51cbc57038fd77e3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting","displayName":"Default key generation setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_1","displayName":"Enabled","description":null,"helpText":null}]},"5130d28d4174b79f":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdunregistertimeout_odfcccdunregistertimeout","displayName":"CCD Unregister Timeout (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":null},"51318ab1b2a2512b":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},"519e64417fe5a668":{"id":"device_vendor_msft_policy_config_lanmanserver_auditinsecureguestlogon","displayName":"Audit Insecure Guest Logon","description":"This policy controls whether the SMB server will enable the audit event when the client is logged on as guest account. If you enable this policy setting, the SMB server will log the event when the client is logged on as guest account. If you disable or do not configure this policy setting, the SMB server will not log the event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanServer#auditinsecureguestlogon"],"categoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_lanmanserver_auditinsecureguestlogon_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanserver_auditinsecureguestlogon_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"51ea34c786138af3":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"51174ad5711f092a":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\r\n\r\nThis policy is optional. If you don't configure it, image search isn't available.\r\n\r\nSpecify Bing's Image Search URL as:\r\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\r\n\r\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\r\n\r\nSee 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_1","displayName":"Enabled","description":null,"helpText":null}]},"51d702872ec2ebe9":{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_precisegeolocationallowedforurlsdesc","displayName":"Allow precise geolocation on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"51442002740f035b":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"51c5927d42963694":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"513dcb7554b0f0ca":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_winprojexe132","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_winprojexe132_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_winprojexe132_1","displayName":"True","description":null,"helpText":null}]},"51c01ede9b548663":{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection","displayName":"Restrict clipboard transfer from client to server","description":"This policy setting allows you to restrict clipboard data transfers from client to server.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from client to server.\r\n\r\n- Allow plain text copying from client to server.\r\n\r\n- Allow plain text and images copying from client to server.\r\n\r\n- Allow plain text, images and Rich Text Format copying from client to server.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from client to server.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from client to server if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitclienttoserverclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},"51604a871f4c7a3b":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1.upadtes~policy~avd_gp_node_avd_server_watermarking_part_watermarkingqrscale","displayName":"QR code bitmap scale factor (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":null},"51b4e114ba3921d7":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_port_redirector_part_udpredirectorport","displayName":"UDP port (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":null},"518c2eb90325fb0b":{"id":"device_vendor_msft_policy_config_textinput_allowlinguisticdatacollection","displayName":"Allow Linguistic Data Collection","description":"This policy setting controls the ability to send inking and typing data to Microsoft to improve the language recognition and suggestion capabilities of apps and services running on Windows.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#allowlinguisticdatacollection"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_allowlinguisticdatacollection_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_allowlinguisticdatacollection_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"51cf5f8f3fc3211b":{"id":"device_vendor_msft_policy_config_update_allowmuupdateservice","displayName":"Allow MU Update Service","description":"Allows the IT admin to manage whether to scan for app updates from Microsoft Update.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#allowmuupdateservice"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_allowmuupdateservice_0","displayName":"Not allowed or not configured.","description":"Not allowed or not configured.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowmuupdateservice_1","displayName":"Allowed. Accepts updates received through Microsoft Update.","description":"Allowed. Accepts updates received through Microsoft Update.","helpText":null}]},"511f5ff377913f29":{"id":"device_vendor_msft_policy_config_update_configuredeadlinegraceperiodforfeatureupdates","displayName":"Configure Deadline Grace Period For Feature Updates","description":"Minimum number of days from update installation until restarts occur automatically for feature updates. This policy only takes effect when Update/ConfigureDeadlineForFeatureUpdates is configured. If Update/ConfigureDeadlineForFeatureUpdates is configured but this policy is not, then the value configured by Update/ConfigureDeadlineGracePeriod will be used. If Update/ConfigureDeadlineGracePeriod is also not configured, then the default value of 2 days will take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlinegraceperiodforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"51c4505815be779f":{"id":"safari_safari","displayName":"com.apple.configuration.safari.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"e0ab6868-4b53-4310-b665-f7c979941db7","categoryName":"Safari Browser","options":null},"51450f9cdbe73102":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_history","displayName":"PIN History (User)","description":"This policy specifies the number of past PINs that can be stored in the history that can’t be used. Valid values are 0 to 50 inclusive. If this policy is set to 0, then storage of previous PINs is not required. PIN history is not preserved through PIN reset.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"51e8967f7f9b5148":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions","displayName":"Process Mitigation Options (User)","description":"\r\n This security feature provides a means to override individual process MitigationOptions settings. This can be used to enforce a number of security policies specific to applications. The application name is specified as the Value name, including extension. The Value is specified as a bit field with a series of flags in particular positions. Bits can be set to either 0 (setting is forced off), 1 (setting is forced on), or ? (setting retains its existing value prior to GPO evaluation). The recognized bit locations are:\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE (0x00000001)\r\n Enables data execution prevention (DEP) for the child process\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ATL_THUNK_ENABLE (0x00000002)\r\n Enables DEP-ATL thunk emulation for the child process. DEP-ATL thunk emulation causes the system to intercept NX faults that originate from the Active Template Library (ATL) thunk layer.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_SEHOP_ENABLE (0x00000004)\r\n Enables structured exception handler overwrite protection (SEHOP) for the child process. SEHOP blocks exploits that use the structured exception handler (SEH) overwrite technique.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON (0x00000100)\r\n The force Address Space Layout Randomization (ASLR) policy forcibly rebases images that are not dynamic base compatible by acting as though an image base collision happened at load time. If relocations are required, images that do not have a base relocation section will not be loaded.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_ON (0x00010000)\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF (0x00020000)\r\n The bottom-up randomization policy, which includes stack randomization options, causes a random location to be used as the lowest user address.\r\n\r\n For instance, to enable PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE and PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON, disable PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF, and to leave all other options at their default values, specify a value of:\r\n ???????????????0???????1???????1\r\n\r\n Setting flags not specified here to any value other than ? results in undefined behavior.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-processmitigationoptions"],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"user_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"51af72ae7a85d867":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_grouppolicytab","displayName":"Group Policy tab for Active Directory Tools (User)","description":"Permits or prohibits use of the Group Policy tab in property sheets for the Active Directory Users and Computers and Active Directory Sites and Services snap-ins.\n\nIf you enable this setting, the Group Policy tab is displayed in the property sheet for a site, domain, or organizational unit displayed by the Active Directory Users and Computers and Active Directory Sites and Services snap-ins. If you disable the setting, the Group Policy tab is not displayed in those snap-ins.\n\nIf this setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this tab is displayed.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users will not have access to the Group Policy tab.\n\n To explicitly permit use of the Group Policy tab, enable this setting. If this setting is not configured (or disabled), the Group Policy tab is inaccessible.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users will have access to the Group Policy tab.\n\n To explicitly prohibit use of the Group Policy tab, disable this setting. If this setting is not configured (or enabled), the Group Policy tab is accessible.\n\nWhen the Group Policy tab is inaccessible, it does not appear in the site, domain, or organizational unit property sheets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-grouppolicytab"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_grouppolicytab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_grouppolicytab_1","displayName":"Enabled","description":null,"helpText":null}]},"5106f9c560c25cec":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_deletealluserconnection","displayName":"Ability to delete all user remote access connections (User)","description":"Determines whether users can delete all user remote access connections.\r\n\r\nTo create an all-user remote access connection, on the Connection Availability page in the New Connection Wizard, click the \"For all users\" option.\r\n\r\nIf you enable this setting, all users can delete shared remote access connections. In addition, if your file system is NTFS, users need to have Write access to Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\Connections\\Pbk to delete a shared remote access connection.\r\n\r\nIf you disable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), users (including administrators) cannot delete all-user remote access connections. (By default, users can still delete their private connections, but you can change the default by using the \"Prohibit deletion of remote access connections\" setting.)\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you do not configure this setting, only Administrators and Network Configuration Operators can delete all user remote access connections.\r\n\r\nImportant: When enabled, the \"Prohibit deletion of remote access connections\" setting takes precedence over this setting. Users (including administrators) cannot delete any remote access connections, and this setting is ignored.\r\n\r\nNote: LAN connections are created and deleted automatically by the system when a LAN adapter is installed or removed. You cannot use the Network Connections folder to create or delete a LAN connection.\r\n\r\nNote: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-deletealluserconnection"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_deletealluserconnection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_deletealluserconnection_1","displayName":"Enabled","description":null,"helpText":null}]},"51980ad39887362b":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync","displayName":"Microsoft Lync 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Lync 2013.\r\nBy default, the user settings of Microsoft Lync 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Lync 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync_1","displayName":"Enabled","description":null,"helpText":null}]},"517445a44eeb2c57":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_tcpcheckbox","displayName":"TCP (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_tcpcheckbox_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_tcpcheckbox_1","displayName":"True","description":null,"helpText":null}]},"5186b1af25137cd2":{"id":"user_vendor_msft_policy_config_browser_allowtabpreloading","displayName":"Allow Tab Preloading (User)","description":"Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowtabpreloading"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowtabpreloading_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowtabpreloading_1","displayName":"Allow","description":"Allowed. Preload Start and New tab pages.","helpText":null}]},"511922bb8d827257":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls_videocaptureallowedurlsdesc","displayName":"URLs that will be granted access to video capture devices without prompt (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"51362bff9feb236b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist","displayName":"Authentication server allowlist (User)","description":"Setting the policy specifies which servers should be allowed for integrated authentication. Integrated authentication is only on when Google Chrome gets an authentication challenge from a proxy or from a server in this permitted list.\r\n\r\nLeaving the policy unset means Google Chrome tries to detect if a server is on the intranet. Only then will it respond to IWA requests. If a server is detected as internet, then Google Chrome ignores IWA requests from it.\r\n\r\nNote: Separate multiple server names with commas. Wildcards, *, are allowed.\r\n\r\nExample value: *.example.com,example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"51b11ca5c3e9e4ce":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"51b28c4185cbed85":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_profileseparationdomainexceptionlistdesc","displayName":"Enterprise profile separation secondary domain allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":null},"51ed90df2dda6fe6":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"51a43d03d280067c":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"511d894d0b5523fc":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"511fa97352444127":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced","displayName":"OneAuth Authentication Flow Enforced for signin (User)","description":"This policy allows users to decide whether to use the OneAuth library for sign-in and token fetch in Microsoft Edge on Windows 10 RS3 and above.\r\n\r\nIf you disable or don't configure this policy, signin process will use Windows Account Manager. Microsoft Edge would be able to use accounts you logged in to Windows, Microsoft Office, or other Microsoft applications for login, without the needing of password. Or you can provide valid account and password to sign in, which will be stored in Windows Account Manager for future usage. You will be able to investigate all accounts stored in Windows Account Manager through Windows Settings -> Accounts -> Email and accounts page.\r\n\r\nIf you enable this policy, OneAuth authentication flow will be used for account signin. The OneAuth authentication flow has fewer dependencies and can work without Windows shell. The account you use would not be stored in the Email and accounts page.\r\n\r\nThis policy will only take effect on Windows 10 RS3 and above. On Windows 10 below RS3, OneAuth is used for authentication in Microsoft Edge by default.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced_1","displayName":"Enabled","description":null,"helpText":null}]},"51de751ab12f33ae":{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments","displayName":"Show recommended files on the File tab or start page (User)","description":"This policy setting allows you to control whether users see a list of recommended files on the File tab or start page in Word, Excel, and PowerPoint, on devices running Windows.\r\n\r\nIf you enable this policy setting, users will see a list of recommended files on the File tab or start page.\r\n\r\nIf you disable this policy setting, users won't see a list of recommended files on the File tab or start page.\r\n\r\nIf you don't configure this policy setting, users will see a list of recommended files on the File tab or start page.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2146780.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"51364e5e535f7fe9":{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas","displayName":"Accept all EULAs (User)","description":"By default, users are required to accept a EULA upon activating an Office license. By setting this policy, all EULAs will be automatically accepted machine-wide and no prompts will be shown.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas_1","displayName":"Enabled","description":null,"helpText":null}]},"51fce38fce464d88":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment","displayName":"With a simple Web discussions link and an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},"5111a833c4215c4b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook_1","displayName":"True","description":null,"helpText":null}]},"51861ddcefc6ab32":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician","displayName":"Galician (User)","description":"Enables the editing language Galician","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician_1","displayName":"Enabled","description":null,"helpText":null}]},"517a89b882e56e9e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi","displayName":"Hindi (User)","description":"Enables the editing language Hindi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi_1","displayName":"Enabled","description":null,"helpText":null}]},"51a6714181d87902":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons","displayName":"Show Paste Options button when content is pasted (User)","description":"This policy setting configures the Paste Options button.\r\n\r\nIf you enable this policy setting, the Paste Options button is displayed after content is pasted.\r\n\r\nIf you disable or do not configure this policy setting, the Paste Options button is not displayed.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},"517922ffce9d84b2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowpath474","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"5122a6ae6dcc87d6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"51a24110efbabf88":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_descriptioncolon260","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"51f66020d26e1ef9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding","displayName":"Default or specific encoding (User)","description":"When enabled, either default encoding or a specified encoding will be used.","helpText":"","infoUrls":[],"categoryId":"025c640e-51e2-4f04-85e3-a13f30b5e08c","categoryName":"Encoding","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_1","displayName":"Enabled","description":null,"helpText":null}]},"5197d3c6f350cd89":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1","displayName":"Encode attachments in UUENCODE format (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1_1","displayName":"True","description":null,"helpText":null}]},"51674a67d205c835":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime","displayName":"Start time: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_480","displayName":"8:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_0","displayName":"12:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_30","displayName":"12:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_60","displayName":"1:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_90","displayName":"1:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_120","displayName":"2:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_150","displayName":"2:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_180","displayName":"3:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_210","displayName":"3:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_240","displayName":"4:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_270","displayName":"4:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_300","displayName":"5:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_330","displayName":"5:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_360","displayName":"6:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_390","displayName":"6:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_420","displayName":"7:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_450","displayName":"7:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_510","displayName":"8:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_540","displayName":"9:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_570","displayName":"9:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_600","displayName":"10:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_630","displayName":"10:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_660","displayName":"11:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_690","displayName":"11:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_720","displayName":"12:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_750","displayName":"12:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_780","displayName":"1:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_810","displayName":"1:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_840","displayName":"2:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_870","displayName":"2:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_900","displayName":"3:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_930","displayName":"3:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_960","displayName":"4:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_990","displayName":"4:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1020","displayName":"5:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1050","displayName":"5:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1080","displayName":"6:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1110","displayName":"6:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1140","displayName":"7:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1170","displayName":"7:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1200","displayName":"8:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1230","displayName":"8:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1260","displayName":"9:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1290","displayName":"9:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1320","displayName":"10:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1350","displayName":"10:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1380","displayName":"11:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1410","displayName":"11:30 PM","description":null,"helpText":null}]},"51d08b39f3a60d5d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange","displayName":"Exchange Unicode Mode - Silent OST format change (User)","description":"This policy setting allows .OST files to silently update to Unicode format from ANSI.\r\n\r\nIf you enable this policy setting, it will only have meaning if the related policy setting \"Exchange Unicode Mode - Ignore OST format\" is enabled and set to the options listed below.\r\n\r\nThe behavior is as follows -\r\n\r\n\"Ignore OST Format\" policy setting is enabled and set to \"Create new OST if format doesn't match mode\"; \"Silent OST Format Change\" policy setting is enabled:\r\nIf Outlook detects a mode that is different than the current .OST mode, then a new .OST is created without prompting the user.\r\n\r\n\"Ignore OST Format\" policy setting is enabled and set to \"Prompt to create new OST if format doesn't match mode\"; \"Silent OST Format Change\" policy setting is enabled:\r\nIf Outlook detects a mode that is different than the current .OST mode, the user is prompted to allow a delay in the conversion to the mode set by policy. By clicking Ok, a new OST is created without a prompt for a new .OST name.\r\n\r\nIf you disable or do not configure this policy setting, users will be prompted to enter a new name for the updated .OST file.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange_1","displayName":"Enabled","description":null,"helpText":null}]},"5119d55b517df199":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_0","displayName":"disable (don't run any programs)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_1","displayName":"enable (prompt user before running)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_2","displayName":"enable all (run without prompting)","description":null,"helpText":null}]},"518edb420a28b4be":{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser","displayName":"List of Approved USB-connected print devices (User)","description":"\r\n\r\n This setting is a component of the Device Control Printing Restrictions. To use this setting, enable Device Control Printing by enabling the \"Enable Device Control Printing Restrictions\" setting.\r\n\r\n When Device Control Printing is enabled, the system uses the specified list of vid/pid values to determine if the current USB connected printer is approved for local printing.\r\n\r\n Type all the approved vid/pid combinations (separated by commas) that correspond to approved USB printer models. When a user tries to print to a USB printer queue the device vid/pid will be compared to the approved list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-approvedusbprintdevicesuser"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_1","displayName":"Enabled","description":null,"helpText":null}]},"51c67109a327fcf3":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4","displayName":"Shapesheet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4_1","displayName":"True","description":null,"helpText":null}]},"51a8c8c7e82c2510":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_1","displayName":"True","description":null,"helpText":null}]},"5149703d59e7e9a6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"51e0f0a31225eda8":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]}} \ No newline at end of file +{"5130c63db1c633e6":{"id":"com.android.devicerestrictionpolicy.passwordminimumlettercharacters","displayName":"Number of characters required","description":"Enter the number of characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"518ce53980dc1ae8":{"id":"com.apple.airprint_airprint_item_port","displayName":"Port","description":"The listening port of the AirPrint destination. Available only in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","categoryName":"AirPrint","options":null},"513952e6d11afa42":{"id":"com.apple.applicationaccess_allowlivevoicemail","displayName":"Allow Live Voicemail","description":"If set to false, disables live voicemail on the device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlivevoicemail_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlivevoicemail_true","displayName":"Enabled","description":null,"helpText":null}]},"5103a1486e5b8a87":{"id":"com.apple.assetcache.managed_peerlistenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},"518c1fd6951cf9b2":{"id":"com.apple.managedclient.preferences_blockexternalextensions","displayName":"Blocks external extensions from being installed","description":"Control the installation of external extensions.\n\nIf you enable this setting, external extensions are blocked from being installed.\n\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\n\nExternal extensions and their installation are documented at https://docs.microsoft.com/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#blockexternalextensions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_blockexternalextensions_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockexternalextensions_true","displayName":"Enabled","description":null,"helpText":null}]},"51b007296344a7ca":{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing","displayName":"Disable DNS over TCP parsing","description":"Disables parsing of DNS over TCP","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disablednsovertcpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},"51ee1266a7e536b7":{"id":"com.apple.managedclient.preferences_efficiencymodeenabled","displayName":"Efficiency mode enabled","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\n\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the \"EfficiencyMode\" policy. If the device does not have a battery, efficiency mode will always be active.\n\nIf you disable this policy, efficiency mode will never become active. The \"EfficiencyMode\" and \"EfficiencyModeOnPowerEnabled\" policies will have no effect.\n\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymodeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"51a4b9d1f2eef0b9":{"id":"com.apple.managedclient.preferences_localprovidersenabled","displayName":"Allow suggestions from local providers","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\n\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localprovidersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localprovidersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localprovidersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"511fa92924b9e7cc":{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers_item_protocol","displayName":"Protocol","description":"The protocol for the protocol handler.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"519996673020f4bf":{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy controls the use of post-quantum key agreement for WebRTC in Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge will offer post-quantum key agreement for WebRTC.\n\nIf you disable this policy, post-quantum key agreement will not be offered for WebRTC.\n\nIf you don't configure this policy, post-quantum key agreement will not be offered for WebRTC. A future version of Microsoft Edge may enable this feature by default.\n\nOffering a post-quantum key agreement is backwards compatible. Existing datagram transport layer security (DTLS) peers and networking middleware are expected to ignore the new option and continue using previous options.\n\nHowever, devices that don't correctly implement DTLS may malfunction when offered the new option. For example, they may disconnect in response to unrecognized options or larger message sizes. Such devices aren’t post-quantum-ready and may interfere with an organization's post-quantum transition. If this issue occurs, administrators should contact the device vendor for a fix.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcpostquantumkeyagreement"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtcpostquantumkeyagreement_true","displayName":"Enabled","description":null,"helpText":null}]},"51e51337e7b54c33":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended","displayName":"Configure the new tab page search box experience (users can override)","description":"You can configure the new tab page search box to use \"Search box (Recommended)\" or \"Address bar\" to search on new tabs. This policy only works if you set the search engine to a value other than Bing by setting the following two policies: \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\".\n\n If you disable or don't configure this policy and:\n\n- If the address bar default search engine is Bing, the new tab page uses the search box to search on new tabs.\n- If the address bar default search engine isn't Bing, users are offered an additional choice (use \"Address bar\") when searching on new tabs.\n\n\nIf you enable this policy and set it to:\n\n- \"Search box (Recommended)\" ('bing'), the new tab page uses the search box to search on new tabs.\n- \"Address bar\" ('redirect'), the new tab page search box uses the address bar to search on new tabs.\n\nPolicy options mapping:\n\n* bing (bing) = Search box (Recommended)\n\n* redirect (redirect) = Address bar\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesearchbox_recommended_redirect","displayName":"Address bar","description":null,"helpText":null}]},"517e6e3c7eb02acb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.registeredprotocolhandlers","displayName":"Register protocol handlers","description":"Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use.\n\nTo register a protocol handler:\n\n- Set the protocol property to the scheme (for example, \"mailto\")\n- Set the URL property to the URL property of the application that handlers the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\n\nUsers can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"51f6df9932f8480f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.registeredprotocolhandlers_recommended","displayName":"Register protocol handlers (users can override)","description":"Set this policy (recommended only) to register a list of protocol handlers. This list is merged with ones registered by the user and both are available to use.\n\nTo register a protocol handler:\n\n- Set the protocol property to the scheme (for example, \"mailto\")\n- Set the URL property to the URL property of the application that handlers the scheme specified in the \"protocol\" field. The pattern can include a \"%s\" placeholder, which the handled URL replaces.\n\nUsers can't remove a protocol handler registered by this policy. However, they can install a new default protocol handler to override the existing protocol handlers.\n\nIn the examples in this section, the URL points to the Outlook on the Web (OWA) endpoint used in Exchange Online. If you're targeting Exchange Server (on-premises), use the following URL and replace mail.contoso.com with your organization's OWA endpoint:\n\nhttps://mail.contoso.com/?path=/mail/action/compose&mailtouri=%s","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"5148b4742fef03db":{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice","displayName":"Require Security Device","description":"A Trusted Platform Module (TPM) provides additional security benefits over software because data stored within it cannot be used on other devices.\n\nIf you enable this policy setting, only devices with a usable TPM provision Windows Hello for Business.\n\nIf you disable or do not configure this policy setting, the TPM is still preferred, but all devices provision Windows Hello for Business using software if the TPM is non-functional or unavailable.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_requiresecuritydevice_true","displayName":"true","description":"Enabled","helpText":null}]},"51d5e5ae98646e89":{"id":"device_vendor_msft_pkcscertificate_keystorageprovider","displayName":"Key storage provider (KSP)","description":"Select where you want to store the certificate’s key.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},"516b3c3a6effa3bb":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancehoursto_23","displayName":"11 PM","description":null,"helpText":null}]},"51994a4f6c6448f2":{"id":"device_vendor_msft_policy_config_admx_deviceguard_configcipolicy_configcipolicyfilepathtext","displayName":"Code Integrity Policy file path:","description":null,"helpText":"","infoUrls":[],"categoryId":"909339a5-8f04-4fa2-8807-5d38c83ef547","categoryName":"Device Guard","options":null},"5173f324dbfd0f04":{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck","displayName":"Include device claims","description":null,"helpText":"","infoUrls":[],"categoryId":"32180186-7378-4d45-b0cc-c533a124bdbc","categoryName":"Access- Denied Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_srmfci_accessdeniedconfiguration_includedeviceclaimscheck_1","displayName":"True","description":null,"helpText":null}]},"5180542819ac5934":{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state","displayName":"Set ISATAP State","description":"This policy setting allows you to configure Intra-Site Automatic Tunnel Addressing Protocol (ISATAP), an address-to-router and host-to-host, host-to-router and router-to-host automatic tunneling technology that is used to provide unicast IPv6 connectivity between IPv6 hosts across an IPv4 intranet.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\nIf you enable this policy setting, you can configure ISATAP with one of the following settings:\r\n\r\nPolicy Default State: If the ISATAP router name is resolved successfully, the host will have ISATAP configured with a link-local address and an address for each prefix received from the ISATAP router through stateless address auto-configuration. If the ISATAP router name is not resolved successfully, ISATAP connectivity is not available on the host using the corresponding IPv4 address.\r\n\r\nPolicy Enabled State: If the ISATAP name is resolved successfully, the host will have ISATAP configured with a link-local address and an address for each prefix received from the ISATAP router through stateless address auto-configuration. If the ISATAP name is not resolved successfully, the host will have an ISATAP interface configured with a link-local address.\r\n\r\nPolicy Disabled State: No ISATAP interfaces are present on the host.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-isatap-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_isatap_state_1","displayName":"Enabled","description":null,"helpText":null}]},"510d528b9d2db7ba":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook","displayName":"Microsoft Outlook 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Outlook 2013.\r\nBy default, the user settings of Microsoft Outlook 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Outlook 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Outlook 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Outlook 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013outlook"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013outlook_1","displayName":"Enabled","description":null,"helpText":null}]},"51fda9714afd98b8":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016","displayName":"Microsoft Office 365 Visio 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_1","displayName":"Enabled","description":null,"helpText":null}]},"51afd5ba49f6cf22":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-trusted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_trusted_1","displayName":"Enabled","description":null,"helpText":null}]},"51870a396e6a0fa9":{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall","displayName":"MSI Allow User Control Over Install","description":"This policy setting permits users to change installation options that typically are available only to system administrators. If you enable this policy setting, some of the security features of Windows Installer are bypassed. It permits installations to complete that otherwise would be halted due to a security violation. If you disable or do not configure this policy setting, the security features of Windows Installer prevent users from changing installation options typically reserved for system administrators, such as specifying the directory to which files are installed. If Windows Installer detects that an installation package has permitted the user to change a protected option, it stops the installation and displays a message. These security features operate only when the installation program is running in a privileged security context in which it has access to directories denied to the user. This policy setting is designed for less restrictive environments. It can be used to circumvent errors in an installation program that prevents software from being installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#msiallowusercontroloverinstall"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_msiallowusercontroloverinstall_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"51298b23a0c08eb5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter","displayName":"Use System Default Printer as Default","description":"Setting the policy to Enabled means Google Chrome uses the OS default printer as the default destination for print preview.\r\n\r\nSetting the policy to Disabled or leaving it unset means Google Chrome uses the most recently used printer as the default destination for print preview.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpreviewusesystemdefaultprinter_1","displayName":"Enabled","description":null,"helpText":null}]},"51cbc57038fd77e3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting","displayName":"Default key generation setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_1","displayName":"Enabled","description":null,"helpText":null}]},"5130d28d4174b79f":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdunregistertimeout_odfcccdunregistertimeout","displayName":"CCD Unregister Timeout (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":null},"51318ab1b2a2512b":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},"519e64417fe5a668":{"id":"device_vendor_msft_policy_config_lanmanserver_auditinsecureguestlogon","displayName":"Audit Insecure Guest Logon","description":"This policy controls whether the SMB server will enable the audit event when the client is logged on as guest account. If you enable this policy setting, the SMB server will log the event when the client is logged on as guest account. If you disable or do not configure this policy setting, the SMB server will not log the event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanServer#auditinsecureguestlogon"],"categoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_lanmanserver_auditinsecureguestlogon_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanserver_auditinsecureguestlogon_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"51ea34c786138af3":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"51174ad5711f092a":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\r\n\r\nThis policy is optional. If you don't configure it, image search isn't available.\r\n\r\nSpecify Bing's Image Search URL as:\r\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\r\n\r\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\r\n\r\nSee 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_1","displayName":"Enabled","description":null,"helpText":null}]},"51d702872ec2ebe9":{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_precisegeolocationallowedforurls_precisegeolocationallowedforurlsdesc","displayName":"Allow precise geolocation on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"51442002740f035b":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"51c5927d42963694":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins","displayName":"Allow Same Origin Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can capture tabs with their same Origin.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'TabCaptureAllowedByOrigins' (Allow Tab capture by these origins), 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"513dcb7554b0f0ca":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_winprojexe132","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_winprojexe132_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_winprojexe132_1","displayName":"True","description":null,"helpText":null}]},"51c01ede9b548663":{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection","displayName":"Restrict clipboard transfer from client to server","description":"This policy setting allows you to restrict clipboard data transfers from client to server.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from client to server.\r\n\r\n- Allow plain text copying from client to server.\r\n\r\n- Allow plain text and images copying from client to server.\r\n\r\n- Allow plain text, images and Rich Text Format copying from client to server.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from client to server.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from client to server if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitclienttoserverclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitclienttoserverclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},"51604a871f4c7a3b":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1.upadtes~policy~avd_gp_node_avd_server_watermarking_part_watermarkingqrscale","displayName":"QR code bitmap scale factor (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":null},"51b4e114ba3921d7":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_port_redirector_part_udpredirectorport","displayName":"UDP port (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":null},"518c2eb90325fb0b":{"id":"device_vendor_msft_policy_config_textinput_allowlinguisticdatacollection","displayName":"Allow Linguistic Data Collection","description":"This policy setting controls the ability to send inking and typing data to Microsoft to improve the language recognition and suggestion capabilities of apps and services running on Windows.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#allowlinguisticdatacollection"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_allowlinguisticdatacollection_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_allowlinguisticdatacollection_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"51cf5f8f3fc3211b":{"id":"device_vendor_msft_policy_config_update_allowmuupdateservice","displayName":"Allow MU Update Service","description":"Allows the IT admin to manage whether to scan for app updates from Microsoft Update.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#allowmuupdateservice"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_allowmuupdateservice_0","displayName":"Not allowed or not configured.","description":"Not allowed or not configured.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowmuupdateservice_1","displayName":"Allowed. Accepts updates received through Microsoft Update.","description":"Allowed. Accepts updates received through Microsoft Update.","helpText":null}]},"511f5ff377913f29":{"id":"device_vendor_msft_policy_config_update_configuredeadlinegraceperiodforfeatureupdates","displayName":"Configure Deadline Grace Period For Feature Updates","description":"Minimum number of days from update installation until restarts occur automatically for feature updates. This policy only takes effect when Update/ConfigureDeadlineForFeatureUpdates is configured. If Update/ConfigureDeadlineForFeatureUpdates is configured but this policy is not, then the value configured by Update/ConfigureDeadlineGracePeriod will be used. If Update/ConfigureDeadlineGracePeriod is also not configured, then the default value of 2 days will take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlinegraceperiodforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"5181a23de486feb3":{"id":"plugin_filter_packets_enabled","displayName":"Enabled","description":"If `true`, the system enables filtering network packets.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":[{"id":"plugin_filter_packets_enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"plugin_filter_packets_enabled_true","displayName":"Enabled","description":null,"helpText":null}]},"51c4505815be779f":{"id":"safari_safari","displayName":"com.apple.configuration.safari.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"e0ab6868-4b53-4310-b665-f7c979941db7","categoryName":"Safari Browser","options":null},"51450f9cdbe73102":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_history","displayName":"PIN History (User)","description":"This policy specifies the number of past PINs that can be stored in the history that can’t be used. Valid values are 0 to 50 inclusive. If this policy is set to 0, then storage of previous PINs is not required. PIN history is not preserved through PIN reset.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"51e8967f7f9b5148":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions","displayName":"Process Mitigation Options (User)","description":"\r\n This security feature provides a means to override individual process MitigationOptions settings. This can be used to enforce a number of security policies specific to applications. The application name is specified as the Value name, including extension. The Value is specified as a bit field with a series of flags in particular positions. Bits can be set to either 0 (setting is forced off), 1 (setting is forced on), or ? (setting retains its existing value prior to GPO evaluation). The recognized bit locations are:\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE (0x00000001)\r\n Enables data execution prevention (DEP) for the child process\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ATL_THUNK_ENABLE (0x00000002)\r\n Enables DEP-ATL thunk emulation for the child process. DEP-ATL thunk emulation causes the system to intercept NX faults that originate from the Active Template Library (ATL) thunk layer.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_SEHOP_ENABLE (0x00000004)\r\n Enables structured exception handler overwrite protection (SEHOP) for the child process. SEHOP blocks exploits that use the structured exception handler (SEH) overwrite technique.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON (0x00000100)\r\n The force Address Space Layout Randomization (ASLR) policy forcibly rebases images that are not dynamic base compatible by acting as though an image base collision happened at load time. If relocations are required, images that do not have a base relocation section will not be loaded.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_ON (0x00010000)\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF (0x00020000)\r\n The bottom-up randomization policy, which includes stack randomization options, causes a random location to be used as the lowest user address.\r\n\r\n For instance, to enable PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE and PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON, disable PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF, and to leave all other options at their default values, specify a value of:\r\n ???????????????0???????1???????1\r\n\r\n Setting flags not specified here to any value other than ? results in undefined behavior.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-processmitigationoptions"],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"user_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"51af72ae7a85d867":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_grouppolicytab","displayName":"Group Policy tab for Active Directory Tools (User)","description":"Permits or prohibits use of the Group Policy tab in property sheets for the Active Directory Users and Computers and Active Directory Sites and Services snap-ins.\n\nIf you enable this setting, the Group Policy tab is displayed in the property sheet for a site, domain, or organizational unit displayed by the Active Directory Users and Computers and Active Directory Sites and Services snap-ins. If you disable the setting, the Group Policy tab is not displayed in those snap-ins.\n\nIf this setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this tab is displayed.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users will not have access to the Group Policy tab.\n\n To explicitly permit use of the Group Policy tab, enable this setting. If this setting is not configured (or disabled), the Group Policy tab is inaccessible.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users will have access to the Group Policy tab.\n\n To explicitly prohibit use of the Group Policy tab, disable this setting. If this setting is not configured (or enabled), the Group Policy tab is accessible.\n\nWhen the Group Policy tab is inaccessible, it does not appear in the site, domain, or organizational unit property sheets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-grouppolicytab"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_grouppolicytab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_grouppolicytab_1","displayName":"Enabled","description":null,"helpText":null}]},"5106f9c560c25cec":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_deletealluserconnection","displayName":"Ability to delete all user remote access connections (User)","description":"Determines whether users can delete all user remote access connections.\r\n\r\nTo create an all-user remote access connection, on the Connection Availability page in the New Connection Wizard, click the \"For all users\" option.\r\n\r\nIf you enable this setting, all users can delete shared remote access connections. In addition, if your file system is NTFS, users need to have Write access to Documents and Settings\\All Users\\Application Data\\Microsoft\\Network\\Connections\\Pbk to delete a shared remote access connection.\r\n\r\nIf you disable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), users (including administrators) cannot delete all-user remote access connections. (By default, users can still delete their private connections, but you can change the default by using the \"Prohibit deletion of remote access connections\" setting.)\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you do not configure this setting, only Administrators and Network Configuration Operators can delete all user remote access connections.\r\n\r\nImportant: When enabled, the \"Prohibit deletion of remote access connections\" setting takes precedence over this setting. Users (including administrators) cannot delete any remote access connections, and this setting is ignored.\r\n\r\nNote: LAN connections are created and deleted automatically by the system when a LAN adapter is installed or removed. You cannot use the Network Connections folder to create or delete a LAN connection.\r\n\r\nNote: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-deletealluserconnection"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_deletealluserconnection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_deletealluserconnection_1","displayName":"Enabled","description":null,"helpText":null}]},"51980ad39887362b":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync","displayName":"Microsoft Lync 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Lync 2013.\r\nBy default, the user settings of Microsoft Lync 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Lync 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013lync_1","displayName":"Enabled","description":null,"helpText":null}]},"517445a44eeb2c57":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_tcpcheckbox","displayName":"TCP (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_tcpcheckbox_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_windowsstreamingmediaprotocols_tcpcheckbox_1","displayName":"True","description":null,"helpText":null}]},"5186b1af25137cd2":{"id":"user_vendor_msft_policy_config_browser_allowtabpreloading","displayName":"Allow Tab Preloading (User)","description":"Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowtabpreloading"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowtabpreloading_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowtabpreloading_1","displayName":"Allow","description":"Allowed. Preload Start and New tab pages.","helpText":null}]},"511922bb8d827257":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_videocaptureallowedurls_videocaptureallowedurlsdesc","displayName":"URLs that will be granted access to video capture devices without prompt (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"51362bff9feb236b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist","displayName":"Authentication server allowlist (User)","description":"Setting the policy specifies which servers should be allowed for integrated authentication. Integrated authentication is only on when Google Chrome gets an authentication challenge from a proxy or from a server in this permitted list.\r\n\r\nLeaving the policy unset means Google Chrome tries to detect if a server is on the intranet. Only then will it respond to IWA requests. If a server is detected as internet, then Google Chrome ignores IWA requests from it.\r\n\r\nNote: Separate multiple server names with commas. Wildcards, *, are allowed.\r\n\r\nExample value: *.example.com,example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authserverallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"51b11ca5c3e9e4ce":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"51b28c4185cbed85":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_profileseparationdomainexceptionlistdesc","displayName":"Enterprise profile separation secondary domain allowlist (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":null},"51ed90df2dda6fe6":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"51a43d03d280067c":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"511d894d0b5523fc":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"511fa97352444127":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced","displayName":"OneAuth Authentication Flow Enforced for signin (User)","description":"This policy allows users to decide whether to use the OneAuth library for sign-in and token fetch in Microsoft Edge on Windows 10 RS3 and above.\r\n\r\nIf you disable or don't configure this policy, signin process will use Windows Account Manager. Microsoft Edge would be able to use accounts you logged in to Windows, Microsoft Office, or other Microsoft applications for login, without the needing of password. Or you can provide valid account and password to sign in, which will be stored in Windows Account Manager for future usage. You will be able to investigate all accounts stored in Windows Account Manager through Windows Settings -> Accounts -> Email and accounts page.\r\n\r\nIf you enable this policy, OneAuth authentication flow will be used for account signin. The OneAuth authentication flow has fewer dependencies and can work without Windows shell. The account you use would not be stored in the Email and accounts page.\r\n\r\nThis policy will only take effect on Windows 10 RS3 and above. On Windows 10 below RS3, OneAuth is used for authentication in Microsoft Edge by default.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_oneauthauthenticationenforced_1","displayName":"Enabled","description":null,"helpText":null}]},"51de751ab12f33ae":{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments","displayName":"Show recommended files on the File tab or start page (User)","description":"This policy setting allows you to control whether users see a list of recommended files on the File tab or start page in Word, Excel, and PowerPoint, on devices running Windows.\r\n\r\nIf you enable this policy setting, users will see a list of recommended files on the File tab or start page.\r\n\r\nIf you disable this policy setting, users won't see a list of recommended files on the File tab or start page.\r\n\r\nIf you don't configure this policy setting, users will see a list of recommended files on the File tab or start page.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2146780.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v11~policy~l_microsoftofficesystem~l_miscellaneous437_l_officerecommendeddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"51364e5e535f7fe9":{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas","displayName":"Accept all EULAs (User)","description":"By default, users are required to accept a EULA upon activating an Office license. By setting this policy, all EULAs will be automatically accepted machine-wide and no prompts will be shown.","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v19~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_acceptalleulas_1","displayName":"Enabled","description":null,"helpText":null}]},"51fce38fce464d88":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment","displayName":"With a simple Web discussions link and an attachment (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslinkandanattachment_1","displayName":"Enabled","description":null,"helpText":null}]},"5111a833c4215c4b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyoutlook_1","displayName":"True","description":null,"helpText":null}]},"51861ddcefc6ab32":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician","displayName":"Galician (User)","description":"Enables the editing language Galician","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_galician_1","displayName":"Enabled","description":null,"helpText":null}]},"517a89b882e56e9e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi","displayName":"Hindi (User)","description":"Enables the editing language Hindi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_hindi_1","displayName":"Enabled","description":null,"helpText":null}]},"51a6714181d87902":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons","displayName":"Show Paste Options button when content is pasted (User)","description":"This policy setting configures the Paste Options button.\r\n\r\nIf you enable this policy setting, the Paste Options button is displayed after content is pasted.\r\n\r\nIf you disable or do not configure this policy setting, the Paste Options button is not displayed.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_showpasteoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},"517922ffce9d84b2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache10_l_workflowpath474","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"5122a6ae6dcc87d6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey03_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"51a24110efbabf88":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_descriptioncolon260","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"51f66020d26e1ef9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding","displayName":"Default or specific encoding (User)","description":"When enabled, either default encoding or a specified encoding will be used.","helpText":"","infoUrls":[],"categoryId":"025c640e-51e2-4f04-85e3-a13f30b5e08c","categoryName":"Encoding","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_encoding_l_defaultorspecificencoding_1","displayName":"Enabled","description":null,"helpText":null}]},"5197d3c6f350cd89":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1","displayName":"Encode attachments in UUENCODE format (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_encodeattachmentsinuuencodeformatwhensending1_1","displayName":"True","description":null,"helpText":null}]},"51674a67d205c835":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime","displayName":"Start time: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_480","displayName":"8:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_0","displayName":"12:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_30","displayName":"12:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_60","displayName":"1:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_90","displayName":"1:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_120","displayName":"2:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_150","displayName":"2:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_180","displayName":"3:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_210","displayName":"3:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_240","displayName":"4:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_270","displayName":"4:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_300","displayName":"5:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_330","displayName":"5:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_360","displayName":"6:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_390","displayName":"6:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_420","displayName":"7:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_450","displayName":"7:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_510","displayName":"8:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_540","displayName":"9:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_570","displayName":"9:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_600","displayName":"10:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_630","displayName":"10:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_660","displayName":"11:00 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_690","displayName":"11:30 AM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_720","displayName":"12:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_750","displayName":"12:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_780","displayName":"1:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_810","displayName":"1:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_840","displayName":"2:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_870","displayName":"2:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_900","displayName":"3:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_930","displayName":"3:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_960","displayName":"4:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_990","displayName":"4:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1020","displayName":"5:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1050","displayName":"5:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1080","displayName":"6:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1110","displayName":"6:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1140","displayName":"7:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1170","displayName":"7:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1200","displayName":"8:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1230","displayName":"8:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1260","displayName":"9:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1290","displayName":"9:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1320","displayName":"10:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1350","displayName":"10:30 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1380","displayName":"11:00 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_workinghours_l_starttime_1410","displayName":"11:30 PM","description":null,"helpText":null}]},"51d08b39f3a60d5d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange","displayName":"Exchange Unicode Mode - Silent OST format change (User)","description":"This policy setting allows .OST files to silently update to Unicode format from ANSI.\r\n\r\nIf you enable this policy setting, it will only have meaning if the related policy setting \"Exchange Unicode Mode - Ignore OST format\" is enabled and set to the options listed below.\r\n\r\nThe behavior is as follows -\r\n\r\n\"Ignore OST Format\" policy setting is enabled and set to \"Create new OST if format doesn't match mode\"; \"Silent OST Format Change\" policy setting is enabled:\r\nIf Outlook detects a mode that is different than the current .OST mode, then a new .OST is created without prompting the user.\r\n\r\n\"Ignore OST Format\" policy setting is enabled and set to \"Prompt to create new OST if format doesn't match mode\"; \"Silent OST Format Change\" policy setting is enabled:\r\nIf Outlook detects a mode that is different than the current .OST mode, the user is prompted to allow a delay in the conversion to the mode set by policy. By clicking Ok, a new OST is created without a prompt for a new .OST name.\r\n\r\nIf you disable or do not configure this policy setting, users will be prompted to enter a new name for the updated .OST file.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodesilentostformatchange_1","displayName":"Enabled","description":null,"helpText":null}]},"5119d55b517df199":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_0","displayName":"disable (don't run any programs)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_1","displayName":"enable (prompt user before running)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_runprograms_l_empty_2","displayName":"enable all (run without prompting)","description":null,"helpText":null}]},"518edb420a28b4be":{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser","displayName":"List of Approved USB-connected print devices (User)","description":"\r\n\r\n This setting is a component of the Device Control Printing Restrictions. To use this setting, enable Device Control Printing by enabling the \"Enable Device Control Printing Restrictions\" setting.\r\n\r\n When Device Control Printing is enabled, the system uses the specified list of vid/pid values to determine if the current USB connected printer is approved for local printing.\r\n\r\n Type all the approved vid/pid combinations (separated by commas) that correspond to approved USB printer models. When a user tries to print to a USB printer queue the device vid/pid will be compared to the approved list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-approvedusbprintdevicesuser"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_approvedusbprintdevicesuser_1","displayName":"Enabled","description":null,"helpText":null}]},"51c67109a327fcf3":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4","displayName":"Shapesheet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid4_1","displayName":"True","description":null,"helpText":null}]},"51a8c8c7e82c2510":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc19_l_allowsubfolders83_1","displayName":"True","description":null,"helpText":null}]},"5149703d59e7e9a6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_opendocumenttextfiles_l_opendocumenttextfilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"51e0f0a31225eda8":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_plaintextfiles_l_plaintextfilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/54.json b/public/intune-definitions/54.json index 8fa959f04422..b7d1e1985443 100644 --- a/public/intune-definitions/54.json +++ b/public/intune-definitions/54.json @@ -1 +1 @@ -{"543fb6cb3554686f":{"id":"app_privacy_permissiondefaults_generickey_camera","displayName":"Camera","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the camera.\n* `Allow`: The app privacy permission default is set to allow use of the camera.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_camera_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_camera_1","displayName":"Allow","description":null,"helpText":null}]},"541181db27ad93a7":{"id":"com.apple.dock_mineffect","displayName":"Minimize Effect","description":"The minimize effect.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_mineffect_0","displayName":"Genie","description":null,"helpText":null},{"id":"com.apple.dock_mineffect_1","displayName":"Scale","description":null,"helpText":null}]},"5420ee1e6f7ffbfc":{"id":"com.apple.extensiblesso_extensiondata_sitecode_kerberos","displayName":"Site Code","description":"The name of the Active Directory site the Kerberos extension should use. Most administrators will never need to modify this value, as the Kerberos extension can normally find the site automatically.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"54354b5e439ce6af":{"id":"com.apple.managedclient.preferences_newtabpagelocation","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\n\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\n\nThis policy doesn't determine which page opens on startup; that's controlled by the \"RestoreOnStartup\" policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\n\nIf you don't configure this policy, the default new tab page is used.\n\nIf you configure this policy *and* the \"NewTabPageSetFeedType\" policy, this policy has precedence.\n\nIf an invalid URL is provided, new tabs will open about://blank.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagelocation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"54db32c4537d7e47":{"id":"com.apple.managedclient.preferences_useragentreduction","displayName":"Enable or disable the User-Agent Reduction (deprecated)","description":"The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch\n\nIf you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.\n\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins.\n\nSet this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header.\n\nTo learn more about the User-Agent string, read here:\n\nhttps://go.microsoft.com/fwlink/?linkid=2186267\n\nPolicy options mapping:\n\n* Default (0) = Reduced User Agent, or controlled by experimentation.\n\n* ForceDisabled (1) = Full (legacy) User Agent.\n\n* ForceEnabled (2) = Reduced User Agent.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#useragentreduction"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_useragentreduction_0","displayName":"Reduced User Agent, or controlled by experimentation.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentreduction_1","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentreduction_2","displayName":"Reduced User Agent.","description":null,"helpText":null}]},"543ee7cae274761a":{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass","displayName":"Ask For Secure Token Auth Bypass","description":"If true, bypasses the secure token authorization dialog. This dialog only appears on APFS volumes.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass_true","displayName":"True","description":null,"helpText":null}]},"5478427bec1304c1":{"id":"com.apple.universalaccess_voiceoveronoffkey","displayName":"Voice Over On Off Key","description":"If true, enables Voice Over.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_voiceoveronoffkey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_voiceoveronoffkey_true","displayName":"True","description":null,"helpText":null}]},"5434a674f643191e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended","displayName":"Configure auto discard sleeping tabs (users can override)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab needs to be reloaded.\n\nIf the \"SleepingTabsEnabled\" policy is enabled, then this feature is enabled by default.\n\nIf the \"SleepingTabsEnabled\" is disabled, then this feature is disabled by default and can't be enabled.\n\nIf enabled, idle background tabs will be discarded after 1.5 days.\n\nIf disabled, idle background tab won't be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"540f8b83884572c5":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode","description":"From Microsoft Edge version 96, navigations that switch between Internet Explorer mode and Microsoft Edge include form data.\n\nIf you enable this policy, you specify which data types are included in navigations between Microsoft Edge and Internet Explorer mode.\n\nIf you disable or don't configure this policy, Microsoft Edge uses the new behavior of including form data in navigations that change modes.\n\nTo learn more, see https://go.microsoft.com/fwlink/?linkid=2174004.\n\nPolicy options mapping:\n\n* IncludeNone (0) = Do not send form data or headers\n\n* IncludeFormDataOnly (1) = Send form data only\n\n* IncludeHeadersOnly (2) = Send additional headers only\n\n* IncludeFormDataAndHeaders (3) = Send form data and additional headers\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includenone","displayName":"Do not send form data or headers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeformdataonly","displayName":"Send form data only","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeheadersonly","displayName":"Send additional headers only","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeformdataandheaders","displayName":"Send form data and additional headers","description":null,"helpText":null}]},"54895542d7479dbd":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled","displayName":"Hide the company logo on the Microsoft Edge new tab page","description":"By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.\n\nIf you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and the company logo is there for users.\n\nIf you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"54318a5cba2e7174":{"id":"device_vendor_msft_email_usernameattributeaad","displayName":"Username attribute from AAD","description":"The attribute Intune gets from Azure AD to dynamically generate the username that will be used by this profile e.g. MyName@contoso.com (UPN) or MyName (username).","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},"542ef948a60bf6bd":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser","displayName":"Limit the maximum number of BITS jobs for each user","description":"This policy setting limits the number of BITS jobs that can be created by a user. By default, BITS limits the total number of jobs that can be created by a user to 60 jobs. You can use this setting to raise or lower the maximum number of BITS jobs a user can create.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of BITS jobs a user can create to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will use the default user BITS job limit of 300 jobs.\r\n\r\n Note: This limit must be lower than the setting specified in the \"Maximum number of BITS jobs for this computer\" policy setting, or 300 if the \"Maximum number of BITS jobs for this computer\" policy setting is not configured. BITS jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxjobsperuser"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_1","displayName":"Enabled","description":null,"helpText":null}]},"54fb175cf8450f53":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry","displayName":"Configure registry policy processing","description":"This policy setting determines when registry policies are updated.\r\n\r\nThis policy setting affects all policies in the Administrative Templates folder and any other policies that store values in the registry. It overrides customized settings that the program implementing a registry policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-registry"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_1","displayName":"Enabled","description":null,"helpText":null}]},"541df009443e0957":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11_1","displayName":"True","description":null,"helpText":null}]},"549fd431554627df":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery","displayName":"Allow security intelligence updates when running on battery power","description":"This policy setting allows you to configure security intelligence updates when the computer is running on battery power.\r\n\r\n If you enable or do not configure this setting, security intelligence updates will occur as usual regardless of power state.\r\n\r\n If you disable this setting, security intelligence updates will be turned off while the computer is running on battery power.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-disablescheduledsignatureupdateonbattery"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},"549aaf68a8c67640":{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall","displayName":"Turn off Push To Install service","description":"If you enable this setting, users will not be able to push Apps to this device from the Microsoft Store running on other devices or the web.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pushtoinstall#admx-pushtoinstall-disablepushtoinstall"],"categoryId":"05305a87-0b19-41bb-bf1e-0bd92bfcdc16","categoryName":"Push To Install","options":[{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},"5425e08f5368140a":{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation","displayName":"Maintain RPC Troubleshooting State Information","description":"This policy setting determines whether the RPC Runtime maintains RPC state information for the system, and how much information it maintains. Basic state information, which consists only of the most commonly needed state data, is required for troubleshooting RPC problems.\r\n\r\nIf you disable this policy setting, the RPC runtime defaults to \"Auto2\" level.\r\n\r\nIf you do not configure this policy setting, the RPC defaults to \"Auto2\" level. \r\n\r\nIf you enable this policy setting, you can use the drop-down box to determine which systems maintain RPC state information.\r\n\r\n-- \"None\" indicates that the system does not maintain any RPC state information. Note: Because the basic state information required for troubleshooting has a negligible effect on performance and uses only about 4K of memory, this setting is not recommended for most installations.\r\n\r\n-- \"Auto1\" directs RPC to maintain basic state information only if the computer has at least 64 MB of memory.\r\n\r\n-- \"Auto2\" directs RPC to maintain basic state information only if the computer has at least 128 MB of memory and is running Windows 2000 Server, Windows 2000 Advanced Server, or Windows 2000 Datacenter Server. \r\n\r\n-- \"Server\" directs RPC to maintain basic state information on the computer, regardless of its capacity.\r\n\r\n-- \"Full\" directs RPC to maintain complete RPC state information on the system, regardless of its capacity. Because this level can degrade performance, it is recommended for use only while you are investigating an RPC problem.\r\n\r\nNote: To retrieve the RPC state information from a system that maintains it, you must use a debugging tool.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcstateinformation"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_1","displayName":"Enabled","description":null,"helpText":null}]},"5445bae20c38487a":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer","displayName":"Do not allow client printer redirection","description":"This policy setting allows you to specify whether to prevent the mapping of client printers in Remote Desktop Services sessions.\r\n\r\nYou can use this policy setting to prevent users from redirecting print jobs from the remote computer to a printer attached to their local (client) computer. By default, Remote Desktop Services allows this client printer mapping.\r\n\r\nIf you enable this policy setting, users cannot redirect print jobs from the remote computer to a local client printer in Remote Desktop Services sessions.\r\n\r\nIf you disable this policy setting, users can redirect print jobs with client printer mapping.\r\n\r\nIf you do not configure this policy setting, client printer mapping is not specified at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-printer"],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer_1","displayName":"Enabled","description":null,"helpText":null}]},"54254e2c11dbbe3a":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels","displayName":"Options:","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_0","displayName":"No remote control allowed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_1","displayName":"Full Control with user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_2","displayName":"Full Control without user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_3","displayName":"View Session with user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_4","displayName":"View Session without user's permission","description":null,"helpText":null}]},"548789691f9e8d17":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable","displayName":"Allow RDP redirection of other supported RemoteFX USB devices from this computer","description":"This policy setting allows you to permit RDP redirection of other supported RemoteFX USB devices from this computer. Redirected RemoteFX USB devices will not be available for local usage on this computer.\r\n\r\nIf you enable this policy setting, you can choose to give the ability to redirect other supported RemoteFX USB devices over RDP to all users or only to users who are in the Administrators group on the computer.\r\n\r\nIf you disable or do not configure this policy setting, other supported RemoteFX USB devices are not available for RDP redirection by using any user account.\r\n\r\nFor this change to take effect, you must restart Windows.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-usb-redirection-disable"],"categoryId":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","categoryName":"Remote FX USB Device Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_1","displayName":"Enabled","description":null,"helpText":null}]},"543a9779d74a8755":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-localmachinelockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"5458589d130a4520":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject","displayName":"Object Access Audit Kernel Object","description":"This policy setting allows you to audit attempts to access the kernel, which include mutexes and semaphores. Only kernel objects with a matching system access control list (SACL) generate security audit events. Note: The Audit: Audit the access of global system objects policy setting controls the default SACL of kernel objects.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditkernelobject"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"544827aa6f645875":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode","displayName":"Print PostScript Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_1","displayName":"Type42","description":null,"helpText":null}]},"548d36cb6fe21bc9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled","displayName":"Enable TLS 1.3 Early Data","description":"TLS 1.3 Early Data is an extension to TLS 1.3 to send an HTTP request simultaneously with the TLS handshake.\r\n\r\nIf this policy is not configured, Google Chrome will follow the default rollout process for TLS 1.3 Early Data.\r\n\r\nIf it is enabled, Google Chrome will enable TLS 1.3 Early Data.\r\n\r\nIf it is disabled, Google Chrome will not enable TLS 1.3 Early Data.\r\n\r\nWhen the feature is enabled, Google Chrome may or may not use TLS 1.3 Early Data depending on server support.\r\n\r\nTLS 1.3 Early Data is an established protocol. Existing TLS servers, middleboxes, and security software are expected to either handle or reject TLS 1.3 Early Data without dropping the connection.\r\n\r\nHowever, devices that do not correctly implement TLS may malfunction and disconnect when TLS 1.3 Early Data is in use. If this occurs, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure to control the feature and will be removed afterwards. The policy may be enabled to allow you to test for issues and disabled while issues are being resolved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"548c0b8acd65eb1e":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"A list of certificates that are not trusted or distrusted in Google Chrome\r\nbut can be used as hints for path-building. Certificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"54d999cd1e68bf92":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings","displayName":"Settings for Tab Organizer","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_1","displayName":"Enabled","description":null,"helpText":null}]},"54780b81c911123d":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},"5468081ff091dc9e":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},"5459b1362a5baac1":{"id":"device_vendor_msft_policy_config_lanmanserver_enableauthratelimiter","displayName":"Enable Auth Rate Limiter","description":"This policy controls whether the SMB server will enable or disable the authentication rate limiter. If you disable this policy setting, the authentication rate limiter will not be enabled. If you do not configure this policy setting, the authentication rate limiter may still be working depending on the delay settings (the recommended delay value is 2000ms).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanServer#enableauthratelimiter"],"categoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_lanmanserver_enableauthratelimiter_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanserver_enableauthratelimiter_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"5406769cb6a49c57":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"54e62237a568d924":{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_webhidaskforurlsdesc","displayName":"Allow the WebHID API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"54f3cf8b4e89fdb1":{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled","displayName":"Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer","description":"This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory.\r\n\r\nIf you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the directory with no items in the directory selected.\r\n\r\nIf you disable or don't configure this policy, file URL links will not open.\r\n\r\nMicrosoft Edge uses the definition of intranet zone as configured for Internet Explorer. Note that https://localhost/ is specifically blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default.\r\n\r\nUsers may opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is disabled.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"54f8eedca0e46166":{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled","displayName":"Enable Follow service in Microsoft Edge (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 126.\r\n\r\nLets Microsoft Edge browser enable Follow service and apply it to users.\r\n\r\nUsers can use the Follow feature for an influencer, site, or topic in Microsoft Edge..\r\n\r\nIf you enable or don't configure this policy, Follow in Microsoft Edge can be applied.\r\n\r\nIf you disable this policy, Microsoft Edge will not communicate with Follow service to provide the follow feature.\r\n\r\nThis policy is obsolete after version 126.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"540f1404e2674f59":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_enableautomaticupdates","displayName":"Enable Automatic Updates","description":"This policy setting controls whether the Office automatic updates are enabled or disabled for all Office products installed via Click-to-Run. This policy has no effect on Office products installed via Windows Installer. \r\n\r\nIf you enable or do not configure this policy setting, Office periodically checks for updates. When updates are detected, Office downloads and applies them in the background. \r\n\r\nIf you disable this policy setting, Office won't check for updates.","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_enableautomaticupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_enableautomaticupdates_1","displayName":"Enabled","description":null,"helpText":null}]},"54b1b11bd4bb301c":{"id":"device_vendor_msft_policy_config_printers_configurerpclistenerpolicy_rpclistenerprotocols_enum","displayName":"Protocols to allow for incoming RPC connections:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configurerpclistenerpolicy_rpclistenerprotocols_enum_3","displayName":"RPC over named pipes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpclistenerpolicy_rpclistenerprotocols_enum_5","displayName":"RPC over TCP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpclistenerpolicy_rpclistenerprotocols_enum_7","displayName":"RPC over named pipes and TCP","description":null,"helpText":null}]},"541f56b712ed7e71":{"id":"device_vendor_msft_policy_config_remoteshell_allowremoteshellaccess","displayName":"Allow Remote Shell Access","description":"This policy setting configures access to remote shells.\n\nIf you enable or do not configure this policy setting, new remote shell connections are accepted by the server.\n\nIf you set this policy to ‘disabled’, new remote shell connections are rejected by the server.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remoteshell#remoteshell-allowremoteshellaccess"],"categoryId":"f69e6993-2e88-4938-bfe5-cea9ab21a858","categoryName":"Windows Remote Shell","options":[{"id":"device_vendor_msft_policy_config_remoteshell_allowremoteshellaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remoteshell_allowremoteshellaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"546e14914fbf3579":{"id":"device_vendor_msft_policy_config_userrights_createpermanentsharedobjects","displayName":"Create Permanent Shared Objects","description":"This user right determines which accounts can be used by processes to create a directory object using the object manager. This user right is used internally by the operating system and is useful to kernel-mode components that extend the object namespace. Because components that are running in kernel mode already have this user right assigned to them, it is not necessary to specifically assign it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#createpermanentsharedobjects"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"5465f7336e13f652":{"id":"device_vendor_msft_windowsadvancedthreatprotection_configuration_telemetryreportingfrequency","displayName":"[Deprecated] Telemetry Reporting Frequency","description":"Return or set Windows Defender Advanced Threat Protection telemetry reporting frequency. Allowed values are: 1 - Normal, 2 - Expedite. This setting is deprecated and no longer has impact on devices.","helpText":null,"infoUrls":[],"categoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","categoryName":"Microsoft Defender for Endpoint","options":[{"id":"device_vendor_msft_windowsadvancedthreatprotection_configuration_telemetryreportingfrequency_1","displayName":"Normal","description":null,"helpText":null},{"id":"device_vendor_msft_windowsadvancedthreatprotection_configuration_telemetryreportingfrequency_2","displayName":"Expedite","description":null,"helpText":null}]},"548f3f07c5288311":{"id":"enrollment_autopilot_dpp_enablecue","displayName":"Automatically launch the Company Portal app and display status for remaining configuration","description":"If the Company Portal app is not configured to install in system context, assigned to the Device group, and selected in the list of Apps, it will not launch automatically and display onboarding status.","helpText":"","infoUrls":[],"categoryId":"cb87b1bb-252b-4515-bb27-f8d0e5ff57b6","categoryName":null,"options":[{"id":"enrollment_autopilot_dpp_enablecue_0","displayName":"No","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_enablecue_1","displayName":"Yes","description":null,"helpText":null}]},"54d9b0a35d518a51":{"id":"linux_mdatp_managed_antivirusengine_scanhistorymaximumitems","displayName":"Scan history size","description":"Specify the maximum number of entries to keep in the scan history. Entries include all on-demand scans performed in the past and all antivirus detections.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#maximum-number-of-items-in-the-antivirus-scan-history"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"541a7ea25636bdab":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon32","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"54fd6696e6d7c21c":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon77","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"540258ee79be98ee":{"id":"user_vendor_msft_policy_config_admx_explorer_preventitemcreationinusersfilesfolder","displayName":"Prevent users from adding files to the root of their Users Files folder. (User)","description":"This policy setting allows administrators to prevent users from adding new items such as files or folders to the root of their Users Files folder in File Explorer.\r\n\r\nIf you enable this policy setting, users will no longer be able to add new items such as files or folders to the root of their Users Files folder in File Explorer.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to add new items such as files or folders to the root of their Users Files folder in File Explorer.\r\n\r\n\r\nNote: Enabling this policy setting does not prevent the user from being able to add new items such as files and folders to their actual file system profile folder at %userprofile%.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-preventitemcreationinusersfilesfolder"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_explorer_preventitemcreationinusersfilesfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_explorer_preventitemcreationinusersfilesfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"54039fbf4e7d9fff":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_hidecontentviewmodesnippets","displayName":"Turn off the display of snippets in Content view mode (User)","description":"This policy setting allows you to turn off the display of snippets in Content view mode.\r\n\r\nIf you enable this policy setting, File Explorer will not display snippets in Content view mode.\r\n\r\nIf you disable or do not configure this policy setting, File Explorer shows snippets in Content view mode by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-hidecontentviewmodesnippets"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_hidecontentviewmodesnippets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_hidecontentviewmodesnippets_1","displayName":"Enabled","description":null,"helpText":null}]},"549c7327b5693cc2":{"id":"user_vendor_msft_policy_config_browser_enterprisemodesitelist","displayName":"Enterprise Mode Site List (User)","description":"This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisemodesitelist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"54515f27cc38502a":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind","displayName":"Ctrl+F (Home | Editing | Find & Select | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind_1","displayName":"True","description":null,"helpText":null}]},"54b643b7156162a7":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"54e3f97df1dead33":{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider","displayName":"Add a specific list of search providers to the user's list of search providers (User)","description":"This policy setting allows you to add a specific list of search providers to the user's default list of search providers. Normally, search providers can be added from third-party toolbars or in Setup. The user can also add a search provider from the provider's website.\n\nIf you enable this policy setting, the user can add and remove search providers, but only from the set of search providers specified in the list of policy keys for search providers (found under [HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\SearchScopes]). Note: This list can be created from a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.\n\nIf you disable or do not configure this policy setting, the user can configure their list of search providers unless another policy setting restricts such configuration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-addsearchprovider"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider_1","displayName":"Enabled","description":null,"helpText":null}]},"54dd9b5c4f9272d8":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"5442bce990e6b7f0":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride","displayName":"Override for the CPU performance tier (User)","description":"This policy allows you to override the value returned by the CPU Performance API (that is, navigator.cpuPerformance).\n\nIf you enable this policy, the value of navigator.cpuPerformance is overridden with the specified value.\n\nIf you don’t configure this policy, the default performance tier calculation is used.\n\nYou can specify a value from 0 through 4.\n\nFor more information, see https://github.com/WICG/cpu-performance.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_1","displayName":"Enabled","description":null,"helpText":null}]},"545b93c2de987181":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended","displayName":"Print headers and footers (User)","description":"Force 'headers and footers' to be on or off in the printing dialog.\r\n\r\nIf you don't configure this policy, users can decide whether to print headers and footers.\r\n\r\nIf you disable this policy, users can't print headers and footers.\r\n\r\nIf you enable this policy, users always print headers and footers.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"541b2ca3a336e14b":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (User)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when:\r\n- The 'Passwords' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy ClearBrowsingDataOnExit is enabled\r\n\r\nIf you enable this policy, passwords won't be cleared when the browser closes.\r\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"54bbcde361e377bc":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS (User)","description":"This policy configures whether Microsoft Edge will offer a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers.\r\n\r\nIf you enable this policy, Microsoft Edge will offer a post-quantum key agreement in TLS connections. TLS connections will be protected from quantum computers when communicating with compatible servers.\r\n\r\nIf you disable this policy, Microsoft Edge will not offer a post-quantum key agreement in TLS connections. User traffic will be unprotected from decryption by quantum computers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will follow the default rollout process for offering a post-quantum key agreement.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\r\n\r\nHowever, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge. You can enable it to test for issues and you can disable it while you resolve issues.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"54d2ea577162eedb":{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions.\r\n\r\nIf an origin is specified by both this policy and the 'LocalNetworkAccessBlockedForUrls' (Block sites from making requests to local network endpoints.) policy, the blocked list takes precedence.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions will apply.\r\n\r\nFor guidance on valid URL pattern syntax, see:\r\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\r\n\r\nNote: This policy enables controlled exceptions to local network access restrictions. It allows specific public websites to access private IP addresses when necessary for trusted local communication scenarios. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"54f4adccefeb5e95":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (obsolete) (User)","description":"Lets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\r\n\r\nYou can set the following values for this policy:\r\n\r\n* 1 = Revert to legacy SameSite behavior for cookies on all sites\r\n\r\n* 2 = Use SameSite-by-default behavior for cookies on all sites\r\n\r\nIf you don't set this policy, the default behavior for cookies that don't specify a SameSite attribute will depend on other configuration sources for the SameSite-by-default feature. This feature might be set by a field trial or by enabling the same-site-by-default-cookies flag in edge://flags.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"54c59699eaf15482":{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled","displayName":"Enable support for Windows OS routing table rules when making peer to peer connections via WebRTC (User)","description":"Controls whether WebRTC will respect the Windows OS routing table rules when making peer to peer connections, thus enabling split tunnel VPNs.\r\n\r\nIf you disable this policy or don't configure it, WebRTC will not consider the routing table and may make peer to peer connections over any available network.\r\n\r\nIf you enable this policy, WebRTC will prefer to make peer to peer connections using the indicated network interface for the remote address as indicated in the routing table.\r\n\r\nThis policy is only available on Windows.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"549e62484c5ce4c2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes","displayName":"Office solutions to exclude from Office Telemetry Agent reporting (User)","description":"This policy setting allows you to prevent telemetry data for Office solutions from being reported to Office Telemetry Dashboard.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent does not upload telemetry data for the specified Office solutions to Office Telemetry Dashboard.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data for all available solution types.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_1","displayName":"Enabled","description":null,"helpText":null}]},"541ce34dc7ccc4ec":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow","displayName":"Mark messages as read in reading window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow_1","displayName":"True","description":null,"helpText":null}]},"547c433e76031a57":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2","displayName":"Do not allow Outlook object model scripts to run for public folders (User)","description":"This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.\r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you do not configure this policy setting, Outlook will not run any scripts associated with public folders by default. Users can configure the setting in the Trust Center by selecting the “Allow script in public folders” check box.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"5429229a07b510fb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"54d87ac2e12de761":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"54c6c581e28819d8":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},"5472758a2dba2ead":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"54c9f7674188b54f":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"542feef3aee17768":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},"5449ab0e20c4c879":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5","displayName":"Cursor visual selection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5_0","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5_1","displayName":"Continuous","description":null,"helpText":null}]},"54fcb14726078f6c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas","displayName":"Default file format (User)","description":"This policy setting determines the default file format for saving files in Word.\r\n\r\nIf you enable this policy setting, you can set the default file format from among the following options: \r\n\r\n- Word Document (*.docx): This option is the default configuration in Word.\r\n- Single Files Web Page (*.mht)\r\n- Web Page (*.htm; *.html)\r\n- Web Page, Filtered (*.htm, *.html)\r\n- Rich Text Format (*.rtf)\r\n- Plain Text (*.txt)\r\n- Word 6.0/95 (*.doc)\r\n- Word 6.0/95 - Chinese (Simplified) (*.doc)\r\n- Word 6.0/95 - Chinese (Traditional) (*.doc)\r\n- Word 6.0/95 - Japanese (*.doc)\r\n- Word 6.0/95 - Korean (*.doc)\r\n- Word 97-2002 and 6.0/95 - RTF\r\n- Word 5.1 for Macintosh (*.mcw)\r\n- Word 5.0 for Macintosh (*.mcw)\r\n- Word 2.x for Windows (*.doc)\r\n- Works 4.0 for Windows (*.wps)\r\n- WordPerfect 5.x for Windows (*.doc)\r\n- WordPerfect 5.1 for DOS (*.doc)\r\n- Word Macro-Enabled Document (*.docm)\r\n- Word Template (*.dotx)\r\n- Word Macro-Enabled Template (*.dotm)\r\n- Word 97 - 2003 Document (*.doc)\r\n- Word 97 - 2003 Template (*.dot)\r\n- Word XML Document (*.xml)\r\n- Strict Open XML Document (*.docx)\r\n- OpenDocument Text (*.odt)\r\n\r\nUsers can choose to save presentations or documents in a different file format than the default.\r\n\r\nIf you disable or do not configure this policy setting, Word saves new files in the Office Open XML format: Word files have a .docx extension. For users who run recent versions of Word, Microsoft offers the Microsoft Office Compatibility Pack, which enables them to open and save Office Open XML files. If some users in your organization cannot install the Compatibility Pack, or are running versions of Word older than Microsoft Office 2000 with Service Pack 3, they might not be able to access Office Open XML files.\r\n\r\nThis policy setting is often set in combination with the \"Save As Open XML in Compatibility Mode\" policy setting.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_1","displayName":"Enabled","description":null,"helpText":null}]},"5433dd496f30bd20":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha","displayName":"Warn before printing, saving or sending a file that contains tracked changes or comments (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha_1","displayName":"Enabled","description":null,"helpText":null}]},"54626781f901b336":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"543fb6cb3554686f":{"id":"app_privacy_permissiondefaults_generickey_camera","displayName":"Camera","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of the camera.\n* `Allow`: The app privacy permission default is set to allow use of the camera.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_camera_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_camera_1","displayName":"Allow","description":null,"helpText":null}]},"541181db27ad93a7":{"id":"com.apple.dock_mineffect","displayName":"Minimize Effect","description":"The minimize effect.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_mineffect_0","displayName":"Genie","description":null,"helpText":null},{"id":"com.apple.dock_mineffect_1","displayName":"Scale","description":null,"helpText":null}]},"5420ee1e6f7ffbfc":{"id":"com.apple.extensiblesso_extensiondata_sitecode_kerberos","displayName":"Site Code","description":"The name of the Active Directory site the Kerberos extension should use. Most administrators will never need to modify this value, as the Kerberos extension can normally find the site automatically.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"54354b5e439ce6af":{"id":"com.apple.managedclient.preferences_newtabpagelocation","displayName":"Configure the new tab page URL","description":"Configures the default URL for the new tab page.\n\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\n\nThis policy doesn't determine which page opens on startup; that's controlled by the \"RestoreOnStartup\" policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\n\nIf you don't configure this policy, the default new tab page is used.\n\nIf you configure this policy *and* the \"NewTabPageSetFeedType\" policy, this policy has precedence.\n\nIf an invalid URL is provided, new tabs will open about://blank.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagelocation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"54db32c4537d7e47":{"id":"com.apple.managedclient.preferences_useragentreduction","displayName":"Enable or disable the User-Agent Reduction (deprecated)","description":"The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch\n\nIf you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.\n\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins.\n\nSet this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header.\n\nTo learn more about the User-Agent string, read here:\n\nhttps://go.microsoft.com/fwlink/?linkid=2186267\n\nPolicy options mapping:\n\n* Default (0) = Reduced User Agent, or controlled by experimentation.\n\n* ForceDisabled (1) = Full (legacy) User Agent.\n\n* ForceEnabled (2) = Reduced User Agent.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#useragentreduction"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_useragentreduction_0","displayName":"Reduced User Agent, or controlled by experimentation.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentreduction_1","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_useragentreduction_2","displayName":"Reduced User Agent.","description":null,"helpText":null}]},"543ee7cae274761a":{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass","displayName":"Ask For Secure Token Auth Bypass","description":"If true, bypasses the secure token authorization dialog. This dialog only appears on APFS volumes.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_cachedaccounts.askforsecuretokenauthbypass_true","displayName":"True","description":null,"helpText":null}]},"5478427bec1304c1":{"id":"com.apple.universalaccess_voiceoveronoffkey","displayName":"Voice Over On Off Key","description":"If true, enables Voice Over.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_voiceoveronoffkey_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_voiceoveronoffkey_true","displayName":"True","description":null,"helpText":null}]},"5434a674f643191e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended","displayName":"Configure auto discard sleeping tabs (users can override)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab needs to be reloaded.\n\nIf the \"SleepingTabsEnabled\" policy is enabled, then this feature is enabled by default.\n\nIf the \"SleepingTabsEnabled\" is disabled, then this feature is disabled by default and can't be enabled.\n\nIf enabled, idle background tabs will be discarded after 1.5 days.\n\nIf disabled, idle background tab won't be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autodiscardsleepingtabsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"540f8b83884572c5":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode","description":"From Microsoft Edge version 96, navigations that switch between Internet Explorer mode and Microsoft Edge include form data.\n\nIf you enable this policy, you specify which data types are included in navigations between Microsoft Edge and Internet Explorer mode.\n\nIf you disable or don't configure this policy, Microsoft Edge uses the new behavior of including form data in navigations that change modes.\n\nTo learn more, see https://go.microsoft.com/fwlink/?linkid=2174004.\n\nPolicy options mapping:\n\n* IncludeNone (0) = Do not send form data or headers\n\n* IncludeFormDataOnly (1) = Send form data only\n\n* IncludeHeadersOnly (2) = Send additional headers only\n\n* IncludeFormDataAndHeaders (3) = Send form data and additional headers\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includenone","displayName":"Do not send form data or headers","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeformdataonly","displayName":"Send form data only","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeheadersonly","displayName":"Send additional headers only","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcomplexnavdatatypes_includeformdataandheaders","displayName":"Send form data and additional headers","description":null,"helpText":null}]},"54895542d7479dbd":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled","displayName":"Hide the company logo on the Microsoft Edge new tab page","description":"By default, the company logo is shown on the new tab page if the company logo is configured in Admin Portal.\n\nIf you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and the company logo is there for users.\n\nIf you disable this policy, the company logo doesn't appear on Microsoft Edge new tab page.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagecompanylogoenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"54f6d8092c2b5575":{"id":"contentcaching_denyactivation","displayName":"Deny Activation","description":"If `true`, the system disables Content Caching. This is the inverse of the `allowContentCaching` restriction in MDM. It overrides the `AutoActivation` key. Use this key to prevent launching the Content Caching service.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_denyactivation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_denyactivation_true","displayName":"Enabled","description":null,"helpText":null}]},"54e835f5527c10c7":{"id":"contentcaching_listenrangesonly","displayName":"Listen Ranges Only","description":"If `true`, the content cache provides content to the clients in the `ListenRanges`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_listenrangesonly_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_listenrangesonly_true","displayName":"Enabled","description":null,"helpText":null}]},"54318a5cba2e7174":{"id":"device_vendor_msft_email_usernameattributeaad","displayName":"Username attribute from AAD","description":"The attribute Intune gets from Azure AD to dynamically generate the username that will be used by this profile e.g. MyName@contoso.com (UPN) or MyName (username).","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},"54f50023ea26cbcd":{"id":"device_vendor_msft_maintenancewindows_repeatschedule","displayName":"Repeat schedule","description":"Select how often the maintenance window repeats.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_repeatschedule_1","displayName":"None","description":"No repeat schedule","helpText":null},{"id":"device_vendor_msft_maintenancewindows_repeatschedule_2","displayName":"Daily","description":"Repeat daily","helpText":null},{"id":"device_vendor_msft_maintenancewindows_repeatschedule_3","displayName":"Weekly","description":"Repeat weekly on selected days","helpText":null},{"id":"device_vendor_msft_maintenancewindows_repeatschedule_4","displayName":"Monthly","description":"Repeat monthly","helpText":null}]},"542ef948a60bf6bd":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser","displayName":"Limit the maximum number of BITS jobs for each user","description":"This policy setting limits the number of BITS jobs that can be created by a user. By default, BITS limits the total number of jobs that can be created by a user to 60 jobs. You can use this setting to raise or lower the maximum number of BITS jobs a user can create.\r\n\r\n If you enable this policy setting, BITS will limit the maximum number of BITS jobs a user can create to the specified number.\r\n\r\n If you disable or do not configure this policy setting, BITS will use the default user BITS job limit of 300 jobs.\r\n\r\n Note: This limit must be lower than the setting specified in the \"Maximum number of BITS jobs for this computer\" policy setting, or 300 if the \"Maximum number of BITS jobs for this computer\" policy setting is not configured. BITS jobs created by services and the local administrator account do not count toward this limit.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-bits#admx-bits-bits-maxjobsperuser"],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxjobsperuser_1","displayName":"Enabled","description":null,"helpText":null}]},"54fb175cf8450f53":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry","displayName":"Configure registry policy processing","description":"This policy setting determines when registry policies are updated.\r\n\r\nThis policy setting affects all policies in the Administrative Templates folder and any other policies that store values in the registry. It overrides customized settings that the program implementing a registry policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they are updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-registry"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_1","displayName":"Enabled","description":null,"helpText":null}]},"541df009443e0957":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11","displayName":"Do not apply during periodic background processing","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_cse_nobackground11_1","displayName":"True","description":null,"helpText":null}]},"549fd431554627df":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery","displayName":"Allow security intelligence updates when running on battery power","description":"This policy setting allows you to configure security intelligence updates when the computer is running on battery power.\r\n\r\n If you enable or do not configure this setting, security intelligence updates will occur as usual regardless of power state.\r\n\r\n If you disable this setting, security intelligence updates will be turned off while the computer is running on battery power.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-disablescheduledsignatureupdateonbattery"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_disablescheduledsignatureupdateonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},"549aaf68a8c67640":{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall","displayName":"Turn off Push To Install service","description":"If you enable this setting, users will not be able to push Apps to this device from the Microsoft Store running on other devices or the web.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pushtoinstall#admx-pushtoinstall-disablepushtoinstall"],"categoryId":"05305a87-0b19-41bb-bf1e-0bd92bfcdc16","categoryName":"Push To Install","options":[{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pushtoinstall_disablepushtoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},"5425e08f5368140a":{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation","displayName":"Maintain RPC Troubleshooting State Information","description":"This policy setting determines whether the RPC Runtime maintains RPC state information for the system, and how much information it maintains. Basic state information, which consists only of the most commonly needed state data, is required for troubleshooting RPC problems.\r\n\r\nIf you disable this policy setting, the RPC runtime defaults to \"Auto2\" level.\r\n\r\nIf you do not configure this policy setting, the RPC defaults to \"Auto2\" level. \r\n\r\nIf you enable this policy setting, you can use the drop-down box to determine which systems maintain RPC state information.\r\n\r\n-- \"None\" indicates that the system does not maintain any RPC state information. Note: Because the basic state information required for troubleshooting has a negligible effect on performance and uses only about 4K of memory, this setting is not recommended for most installations.\r\n\r\n-- \"Auto1\" directs RPC to maintain basic state information only if the computer has at least 64 MB of memory.\r\n\r\n-- \"Auto2\" directs RPC to maintain basic state information only if the computer has at least 128 MB of memory and is running Windows 2000 Server, Windows 2000 Advanced Server, or Windows 2000 Datacenter Server. \r\n\r\n-- \"Server\" directs RPC to maintain basic state information on the computer, regardless of its capacity.\r\n\r\n-- \"Full\" directs RPC to maintain complete RPC state information on the system, regardless of its capacity. Because this level can degrade performance, it is recommended for use only while you are investigating an RPC problem.\r\n\r\nNote: To retrieve the RPC state information from a system that maintains it, you must use a debugging tool.\r\n\r\nNote: This policy setting will not be applied until the system is rebooted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-rpc#admx-rpc-rpcstateinformation"],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcstateinformation_1","displayName":"Enabled","description":null,"helpText":null}]},"5445bae20c38487a":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer","displayName":"Do not allow client printer redirection","description":"This policy setting allows you to specify whether to prevent the mapping of client printers in Remote Desktop Services sessions.\r\n\r\nYou can use this policy setting to prevent users from redirecting print jobs from the remote computer to a printer attached to their local (client) computer. By default, Remote Desktop Services allows this client printer mapping.\r\n\r\nIf you enable this policy setting, users cannot redirect print jobs from the remote computer to a local client printer in Remote Desktop Services sessions.\r\n\r\nIf you disable this policy setting, users can redirect print jobs with client printer mapping.\r\n\r\nIf you do not configure this policy setting, client printer mapping is not specified at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-printer"],"categoryId":"f1455024-7de9-448f-8d8f-a42db2af0a35","categoryName":"Printer Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_printer_1","displayName":"Enabled","description":null,"helpText":null}]},"54254e2c11dbbe3a":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels","displayName":"Options:","description":null,"helpText":"","infoUrls":[],"categoryId":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","categoryName":"Connections","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_0","displayName":"No remote control allowed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_1","displayName":"Full Control with user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_2","displayName":"Full Control without user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_3","displayName":"View Session with user's permission","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotecontrol_2_ts_remotecontrol_levels_4","displayName":"View Session without user's permission","description":null,"helpText":null}]},"548789691f9e8d17":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable","displayName":"Allow RDP redirection of other supported RemoteFX USB devices from this computer","description":"This policy setting allows you to permit RDP redirection of other supported RemoteFX USB devices from this computer. Redirected RemoteFX USB devices will not be available for local usage on this computer.\r\n\r\nIf you enable this policy setting, you can choose to give the ability to redirect other supported RemoteFX USB devices over RDP to all users or only to users who are in the Administrators group on the computer.\r\n\r\nIf you disable or do not configure this policy setting, other supported RemoteFX USB devices are not available for RDP redirection by using any user account.\r\n\r\nFor this change to take effect, you must restart Windows.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-usb-redirection-disable"],"categoryId":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","categoryName":"Remote FX USB Device Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_usb_redirection_disable_1","displayName":"Enabled","description":null,"helpText":null}]},"543a9779d74a8755":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-localmachinelockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"5458589d130a4520":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject","displayName":"Object Access Audit Kernel Object","description":"This policy setting allows you to audit attempts to access the kernel, which include mutexes and semaphores. Only kernel objects with a matching system access control list (SACL) generate security audit events. Note: The Audit: Audit the access of global system objects policy setting controls the default SACL of kernel objects.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditkernelobject"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditkernelobject_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"544827aa6f645875":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode","displayName":"Print PostScript Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpostscriptmode_printpostscriptmode_1","displayName":"Type42","description":null,"helpText":null}]},"548d36cb6fe21bc9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled","displayName":"Enable TLS 1.3 Early Data","description":"TLS 1.3 Early Data is an extension to TLS 1.3 to send an HTTP request simultaneously with the TLS handshake.\r\n\r\nIf this policy is not configured, Google Chrome will follow the default rollout process for TLS 1.3 Early Data.\r\n\r\nIf it is enabled, Google Chrome will enable TLS 1.3 Early Data.\r\n\r\nIf it is disabled, Google Chrome will not enable TLS 1.3 Early Data.\r\n\r\nWhen the feature is enabled, Google Chrome may or may not use TLS 1.3 Early Data depending on server support.\r\n\r\nTLS 1.3 Early Data is an established protocol. Existing TLS servers, middleboxes, and security software are expected to either handle or reject TLS 1.3 Early Data without dropping the connection.\r\n\r\nHowever, devices that do not correctly implement TLS may malfunction and disconnect when TLS 1.3 Early Data is in use. If this occurs, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure to control the feature and will be removed afterwards. The policy may be enabled to allow you to test for issues and disabled while issues are being resolved.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tls13earlydataenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"548c0b8acd65eb1e":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"A list of certificates that are not trusted or distrusted in Google Chrome\r\nbut can be used as hints for path-building. Certificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIIFljCCA36gAwIBAgINAgO8U1lrNMcY9QFQZjANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjEwHhcNMjAwODEzMDAwMDQyWhcNMjcwOTMwMDAwMDQyWjBGMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzETMBEGA1UEAxMKR1RTIENBIDFDMzCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAPWI3+dijB43+DdCkH9sh9D7ZYIl/ejLa6T/belaI+KZ9hzpkgOZE3wJCor6QtZeViSqejOEH9Hpabu5dOxXTGZok3c3VVP+ORBNtzS7XyV3NzsXlOo85Z3VvMO0Q+sup0fvsEQRY9i0QYXdQTBIkxu/t/bgRQIh4JZCF8/ZK2VWNAcmBA2o/X3KLu/qSHw3TT8An4Pf73WELnlXXPxXbhqW//yMmqaZviXZf5YsBvcRKgKAgOtjGDxQSYflispfGStZloEAoPtR28p3CwvJlk/vcEnHXG0g/Zm0tOLKLnf9LdwLtmsTDIwZKxeWmLnwi/agJ7u2441Rj72ux5uxiZ0CAwEAAaOCAYAwggF8MA4GA1UdDwEB/wQEAwIBhjAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQUinR/r4XN7pXNPZzQ4kYU83E1HScwHwYDVR0jBBgwFoAU5K8rJnEaK0gnhS9SZizv8IkTcT4waAYIKwYBBQUHAQEEXDBaMCYGCCsGAQUFBzABhhpodHRwOi8vb2NzcC5wa2kuZ29vZy9ndHNyMTAwBggrBgEFBQcwAoYkaHR0cDovL3BraS5nb29nL3JlcG8vY2VydHMvZ3RzcjEuZGVyMDQGA1UdHwQtMCswKaAnoCWGI2h0dHA6Ly9jcmwucGtpLmdvb2cvZ3RzcjEvZ3RzcjEuY3JsMFcGA1UdIARQME4wOAYKKwYBBAHWeQIFAzAqMCgGCCsGAQUFBwIBFhxodHRwczovL3BraS5nb29nL3JlcG9zaXRvcnkvMAgGBmeBDAECATAIBgZngQwBAgIwDQYJKoZIhvcNAQELBQADggIBAIl9rCBcDDy+mqhXlRu0rvqrpXJxtDaV/d9AEQNMwkYUuxQkq/BQcSLbrcRuf8/xam/IgxvYzolfh2yHuKkMo5uhYpSTld9brmYZCwKWnvy15xBpPnrLRklfRuFBsdeYTWU0AIAaP0+fbH9JAIFTQaSSIYKCGvGjRFsqUBITTcFTNvNCCK9U+o53UxtkOCcXCb1YyRt8OS1b887U7ZfbFAO/CVMkH8IMBHmYJvJh8VNS/UKMG2YrPxWhu//2m+OBmgEGcYk1KCTd4b3rGS3hSMs9WYNRtHTGnXzGsYZbr8w0xNPM1IERlQCh9BIiAfq0g3GvjLeMcySsN1PCAJA/Ef5c7TaUEDu9Ka7ixzpiO2xj2YC/WXGsYye5TBeg2vZzFb8q3o/zpWwygTMD0IZRcZk0upONXbVRWPeyk+gB9lm+cZv9TSjOz23HFtz30dZGm6fKa+l3D/2gthsjgx0QGtkJAITgRNOidSOzNIb2ILCkXhAd4FJGAJ2xDx8hcFH1mt0G/FX0Kw4zd8NLQsLxdxP8c4CU6x+7Nz/OAipmsHMdMqUybDKwjuDEI/9bfU1lcKwrmz3O2+BtjjKAvpafkmO8l7tdufThcV4q5O8DIrGKZTqPwJNl1IXNDw9bg1kWRxYtnCQ6yICmJhSFm/Y3m6xv+cXDBlHz4n/FsRC6UfTd","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"54d999cd1e68bf92":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings","displayName":"Settings for Tab Organizer","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_1","displayName":"Enabled","description":null,"helpText":null}]},"54780b81c911123d":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},"5468081ff091dc9e":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},"5459b1362a5baac1":{"id":"device_vendor_msft_policy_config_lanmanserver_enableauthratelimiter","displayName":"Enable Auth Rate Limiter","description":"This policy controls whether the SMB server will enable or disable the authentication rate limiter. If you disable this policy setting, the authentication rate limiter will not be enabled. If you do not configure this policy setting, the authentication rate limiter may still be working depending on the delay settings (the recommended delay value is 2000ms).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanServer#enableauthratelimiter"],"categoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_lanmanserver_enableauthratelimiter_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanserver_enableauthratelimiter_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"5406769cb6a49c57":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"54e62237a568d924":{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_webhidaskforurls_webhidaskforurlsdesc","displayName":"Allow the WebHID API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"54f3cf8b4e89fdb1":{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled","displayName":"Allow intranet zone file URL links from Microsoft Edge to open in Windows File Explorer","description":"This setting allows file URL links to intranet zone files from intranet zone HTTPS websites to open Windows File Explorer for that file or directory.\r\n\r\nIf you enable this policy, intranet zone file URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the parent directory of the file and select the file. Intranet zone directory URL links originating from intranet zone HTTPS pages will open Windows File Explorer to the directory with no items in the directory selected.\r\n\r\nIf you disable or don't configure this policy, file URL links will not open.\r\n\r\nMicrosoft Edge uses the definition of intranet zone as configured for Internet Explorer. Note that https://localhost/ is specifically blocked as an exception of allowed intranet zone host, while loopback addresses (127.0.0.*, [::1]) are considered internet zone by default.\r\n\r\nUsers may opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is disabled.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~contentsettings_intranetfilelinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"54f8eedca0e46166":{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled","displayName":"Enable Follow service in Microsoft Edge (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 126.\r\n\r\nLets Microsoft Edge browser enable Follow service and apply it to users.\r\n\r\nUsers can use the Follow feature for an influencer, site, or topic in Microsoft Edge..\r\n\r\nIf you enable or don't configure this policy, Follow in Microsoft Edge can be applied.\r\n\r\nIf you disable this policy, Microsoft Edge will not communicate with Follow service to provide the follow feature.\r\n\r\nThis policy is obsolete after version 126.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_edgefollowenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"540f1404e2674f59":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_enableautomaticupdates","displayName":"Enable Automatic Updates","description":"This policy setting controls whether the Office automatic updates are enabled or disabled for all Office products installed via Click-to-Run. This policy has no effect on Office products installed via Windows Installer. \r\n\r\nIf you enable or do not configure this policy setting, Office periodically checks for updates. When updates are detected, Office downloads and applies them in the background. \r\n\r\nIf you disable this policy setting, Office won't check for updates.","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_enableautomaticupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_enableautomaticupdates_1","displayName":"Enabled","description":null,"helpText":null}]},"54b1b11bd4bb301c":{"id":"device_vendor_msft_policy_config_printers_configurerpclistenerpolicy_rpclistenerprotocols_enum","displayName":"Protocols to allow for incoming RPC connections:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configurerpclistenerpolicy_rpclistenerprotocols_enum_3","displayName":"RPC over named pipes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpclistenerpolicy_rpclistenerprotocols_enum_5","displayName":"RPC over TCP","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpclistenerpolicy_rpclistenerprotocols_enum_7","displayName":"RPC over named pipes and TCP","description":null,"helpText":null}]},"541f56b712ed7e71":{"id":"device_vendor_msft_policy_config_remoteshell_allowremoteshellaccess","displayName":"Allow Remote Shell Access","description":"This policy setting configures access to remote shells.\n\nIf you enable or do not configure this policy setting, new remote shell connections are accepted by the server.\n\nIf you set this policy to ‘disabled’, new remote shell connections are rejected by the server.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remoteshell#remoteshell-allowremoteshellaccess"],"categoryId":"f69e6993-2e88-4938-bfe5-cea9ab21a858","categoryName":"Windows Remote Shell","options":[{"id":"device_vendor_msft_policy_config_remoteshell_allowremoteshellaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remoteshell_allowremoteshellaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"546e14914fbf3579":{"id":"device_vendor_msft_policy_config_userrights_createpermanentsharedobjects","displayName":"Create Permanent Shared Objects","description":"This user right determines which accounts can be used by processes to create a directory object using the object manager. This user right is used internally by the operating system and is useful to kernel-mode components that extend the object namespace. Because components that are running in kernel mode already have this user right assigned to them, it is not necessary to specifically assign it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#createpermanentsharedobjects"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"5465f7336e13f652":{"id":"device_vendor_msft_windowsadvancedthreatprotection_configuration_telemetryreportingfrequency","displayName":"[Deprecated] Telemetry Reporting Frequency","description":"Return or set Windows Defender Advanced Threat Protection telemetry reporting frequency. Allowed values are: 1 - Normal, 2 - Expedite. This setting is deprecated and no longer has impact on devices.","helpText":null,"infoUrls":[],"categoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","categoryName":"Microsoft Defender for Endpoint","options":[{"id":"device_vendor_msft_windowsadvancedthreatprotection_configuration_telemetryreportingfrequency_1","displayName":"Normal","description":null,"helpText":null},{"id":"device_vendor_msft_windowsadvancedthreatprotection_configuration_telemetryreportingfrequency_2","displayName":"Expedite","description":null,"helpText":null}]},"548f3f07c5288311":{"id":"enrollment_autopilot_dpp_enablecue","displayName":"Automatically launch the Company Portal app and display status for remaining configuration","description":"If the Company Portal app is not configured to install in system context, assigned to the Device group, and selected in the list of Apps, it will not launch automatically and display onboarding status.","helpText":"","infoUrls":[],"categoryId":"cb87b1bb-252b-4515-bb27-f8d0e5ff57b6","categoryName":null,"options":[{"id":"enrollment_autopilot_dpp_enablecue_0","displayName":"No","description":null,"helpText":null},{"id":"enrollment_autopilot_dpp_enablecue_1","displayName":"Yes","description":null,"helpText":null}]},"54d9b0a35d518a51":{"id":"linux_mdatp_managed_antivirusengine_scanhistorymaximumitems","displayName":"Scan history size","description":"Specify the maximum number of entries to keep in the scan history. Entries include all on-demand scans performed in the past and all antivirus detections.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#maximum-number-of-items-in-the-antivirus-scan-history"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"541a7ea25636bdab":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_datecolon32","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"54fd6696e6d7c21c":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon77","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"540258ee79be98ee":{"id":"user_vendor_msft_policy_config_admx_explorer_preventitemcreationinusersfilesfolder","displayName":"Prevent users from adding files to the root of their Users Files folder. (User)","description":"This policy setting allows administrators to prevent users from adding new items such as files or folders to the root of their Users Files folder in File Explorer.\r\n\r\nIf you enable this policy setting, users will no longer be able to add new items such as files or folders to the root of their Users Files folder in File Explorer.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to add new items such as files or folders to the root of their Users Files folder in File Explorer.\r\n\r\n\r\nNote: Enabling this policy setting does not prevent the user from being able to add new items such as files and folders to their actual file system profile folder at %userprofile%.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-preventitemcreationinusersfilesfolder"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_explorer_preventitemcreationinusersfilesfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_explorer_preventitemcreationinusersfilesfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"54039fbf4e7d9fff":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_hidecontentviewmodesnippets","displayName":"Turn off the display of snippets in Content view mode (User)","description":"This policy setting allows you to turn off the display of snippets in Content view mode.\r\n\r\nIf you enable this policy setting, File Explorer will not display snippets in Content view mode.\r\n\r\nIf you disable or do not configure this policy setting, File Explorer shows snippets in Content view mode by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-hidecontentviewmodesnippets"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_hidecontentviewmodesnippets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_hidecontentviewmodesnippets_1","displayName":"Enabled","description":null,"helpText":null}]},"549c7327b5693cc2":{"id":"user_vendor_msft_policy_config_browser_enterprisemodesitelist","displayName":"Enterprise Mode Site List (User)","description":"This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisemodesitelist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"54515f27cc38502a":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind","displayName":"Ctrl+F (Home | Editing | Find & Select | Find) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlfhomeeditingfind_1","displayName":"True","description":null,"helpText":null}]},"54b643b7156162a7":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4worksheets_l_excel4worksheetsdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"54e3f97df1dead33":{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider","displayName":"Add a specific list of search providers to the user's list of search providers (User)","description":"This policy setting allows you to add a specific list of search providers to the user's default list of search providers. Normally, search providers can be added from third-party toolbars or in Setup. The user can also add a search provider from the provider's website.\n\nIf you enable this policy setting, the user can add and remove search providers, but only from the set of search providers specified in the list of policy keys for search providers (found under [HKCU or HKLM\\Software\\policies\\Microsoft\\Internet Explorer\\SearchScopes]). Note: This list can be created from a custom administrative template file. For information about creating this custom administrative template file, see the Internet Explorer documentation on search providers.\n\nIf you disable or do not configure this policy setting, the user can configure their list of search providers unless another policy setting restricts such configuration.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-addsearchprovider"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_addsearchprovider_1","displayName":"Enabled","description":null,"helpText":null}]},"54dd9b5c4f9272d8":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"5442bce990e6b7f0":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride","displayName":"Override for the CPU performance tier (User)","description":"This policy allows you to override the value returned by the CPU Performance API (that is, navigator.cpuPerformance).\n\nIf you enable this policy, the value of navigator.cpuPerformance is overridden with the specified value.\n\nIf you don’t configure this policy, the default performance tier calculation is used.\n\nYou can specify a value from 0 through 4.\n\nFor more information, see https://github.com/WICG/cpu-performance.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_cpuperformancetieroverride_1","displayName":"Enabled","description":null,"helpText":null}]},"545b93c2de987181":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended","displayName":"Print headers and footers (User)","description":"Force 'headers and footers' to be on or off in the printing dialog.\r\n\r\nIf you don't configure this policy, users can decide whether to print headers and footers.\r\n\r\nIf you disable this policy, users can't print headers and footers.\r\n\r\nIf you enable this policy, users always print headers and footers.","helpText":"","infoUrls":[],"categoryId":"6b71fbf6-7156-471a-b488-3eece04bda86","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~printing_recommended_printheaderfooter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"541b2ca3a336e14b":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes (User)","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when:\r\n- The 'Passwords' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy ClearBrowsingDataOnExit is enabled\r\n\r\nIf you enable this policy, passwords won't be cleared when the browser closes.\r\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"54bbcde361e377bc":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS (User)","description":"This policy configures whether Microsoft Edge will offer a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers.\r\n\r\nIf you enable this policy, Microsoft Edge will offer a post-quantum key agreement in TLS connections. TLS connections will be protected from quantum computers when communicating with compatible servers.\r\n\r\nIf you disable this policy, Microsoft Edge will not offer a post-quantum key agreement in TLS connections. User traffic will be unprotected from decryption by quantum computers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will follow the default rollout process for offering a post-quantum key agreement.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\r\n\r\nHowever, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices are not post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge. You can enable it to test for issues and you can disable it while you resolve issues.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge_postquantumkeyagreementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"54d2ea577162eedb":{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls","displayName":"Allow sites to make requests to local network endpoints. (User)","description":"Specifies a list of URL patterns for which requests initiated from matching origins are exempt from Local Network Access restrictions.\r\n\r\nIf an origin is specified by both this policy and the 'LocalNetworkAccessBlockedForUrls' (Block sites from making requests to local network endpoints.) policy, the blocked list takes precedence.\r\n\r\nFor origins not covered by this policy, the user's personal settings and local network access restrictions will apply.\r\n\r\nFor guidance on valid URL pattern syntax, see:\r\nhttps://learn.microsoft.com/deployedge/edge-learnmore-ent-policy-url-patterns\r\n\r\nNote: This policy enables controlled exceptions to local network access restrictions. It allows specific public websites to access private IP addresses when necessary for trusted local communication scenarios. For more information about Local Network Access, see https://wicg.github.io/local-network-access/.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu\r\n*","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev140~policy~microsoft_edge~network_localnetworkaccessallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"54f4adccefeb5e95":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled","displayName":"Enable default legacy SameSite cookie behavior setting (obsolete) (User)","description":"Lets you revert all cookies to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", and removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute.\r\n\r\nYou can set the following values for this policy:\r\n\r\n* 1 = Revert to legacy SameSite behavior for cookies on all sites\r\n\r\n* 2 = Use SameSite-by-default behavior for cookies on all sites\r\n\r\nIf you don't set this policy, the default behavior for cookies that don't specify a SameSite attribute will depend on other configuration sources for the SameSite-by-default feature. This feature might be set by a field trial or by enabling the same-site-by-default-cookies flag in edge://flags.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_legacysamesitecookiebehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"54c59699eaf15482":{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled","displayName":"Enable support for Windows OS routing table rules when making peer to peer connections via WebRTC (User)","description":"Controls whether WebRTC will respect the Windows OS routing table rules when making peer to peer connections, thus enabling split tunnel VPNs.\r\n\r\nIf you disable this policy or don't configure it, WebRTC will not consider the routing table and may make peer to peer connections over any available network.\r\n\r\nIf you enable this policy, WebRTC will prefer to make peer to peer connections using the indicated network interface for the remote address as indicated in the routing table.\r\n\r\nThis policy is only available on Windows.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev94~policy~microsoft_edge_webrtcrespectosroutingtableenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"549e62484c5ce4c2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes","displayName":"Office solutions to exclude from Office Telemetry Agent reporting (User)","description":"This policy setting allows you to prevent telemetry data for Office solutions from being reported to Office Telemetry Dashboard.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent does not upload telemetry data for the specified Office solutions to Office Telemetry Dashboard.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data for all available solution types.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_1","displayName":"Enabled","description":null,"helpText":null}]},"541ce34dc7ccc4ec":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow","displayName":"Mark messages as read in reading window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markmessagesasreadinreadingwindow_1","displayName":"True","description":null,"helpText":null}]},"547c433e76031a57":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2","displayName":"Do not allow Outlook object model scripts to run for public folders (User)","description":"This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.\r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you do not configure this policy setting, Outlook will not run any scripts associated with public folders by default. Users can configure the setting in the Trust Center by selecting the “Allow script in public folders” check box.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"5429229a07b510fb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"54d87ac2e12de761":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"54c6c581e28819d8":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},"5472758a2dba2ead":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm","displayName":"Specify CNG hash algorithm (User)","description":"This policy setting allows you to specify the hash algorithm used.\r\n\r\nIf you enable this policy setting, the hashing algorithm selected will be used by CNG.\r\n\r\nIf you disable or do not configure this policy setting, the default CNG hash algorithm will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycnghashalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"54c9f7674188b54f":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_descriptioncolon26","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"542feef3aee17768":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},"5449ab0e20c4c879":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5","displayName":"Cursor visual selection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5_0","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_visualselection_l_visualselection5_1","displayName":"Continuous","description":null,"helpText":null}]},"54fcb14726078f6c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas","displayName":"Default file format (User)","description":"This policy setting determines the default file format for saving files in Word.\r\n\r\nIf you enable this policy setting, you can set the default file format from among the following options: \r\n\r\n- Word Document (*.docx): This option is the default configuration in Word.\r\n- Single Files Web Page (*.mht)\r\n- Web Page (*.htm; *.html)\r\n- Web Page, Filtered (*.htm, *.html)\r\n- Rich Text Format (*.rtf)\r\n- Plain Text (*.txt)\r\n- Word 6.0/95 (*.doc)\r\n- Word 6.0/95 - Chinese (Simplified) (*.doc)\r\n- Word 6.0/95 - Chinese (Traditional) (*.doc)\r\n- Word 6.0/95 - Japanese (*.doc)\r\n- Word 6.0/95 - Korean (*.doc)\r\n- Word 97-2002 and 6.0/95 - RTF\r\n- Word 5.1 for Macintosh (*.mcw)\r\n- Word 5.0 for Macintosh (*.mcw)\r\n- Word 2.x for Windows (*.doc)\r\n- Works 4.0 for Windows (*.wps)\r\n- WordPerfect 5.x for Windows (*.doc)\r\n- WordPerfect 5.1 for DOS (*.doc)\r\n- Word Macro-Enabled Document (*.docm)\r\n- Word Template (*.dotx)\r\n- Word Macro-Enabled Template (*.dotm)\r\n- Word 97 - 2003 Document (*.doc)\r\n- Word 97 - 2003 Template (*.dot)\r\n- Word XML Document (*.xml)\r\n- Strict Open XML Document (*.docx)\r\n- OpenDocument Text (*.odt)\r\n\r\nUsers can choose to save presentations or documents in a different file format than the default.\r\n\r\nIf you disable or do not configure this policy setting, Word saves new files in the Office Open XML format: Word files have a .docx extension. For users who run recent versions of Word, Microsoft offers the Microsoft Office Compatibility Pack, which enables them to open and save Office Open XML files. If some users in your organization cannot install the Compatibility Pack, or are running versions of Word older than Microsoft Office 2000 with Service Pack 3, they might not be able to access Office Open XML files.\r\n\r\nThis policy setting is often set in combination with the \"Save As Open XML in Compatibility Mode\" policy setting.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_savewordfilesas_1","displayName":"Enabled","description":null,"helpText":null}]},"5433dd496f30bd20":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha","displayName":"Warn before printing, saving or sending a file that contains tracked changes or comments (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_warnbeforeprintingsavingorsendingafilethatcontainstrackedcha_1","displayName":"Enabled","description":null,"helpText":null}]},"54626781f901b336":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/55.json b/public/intune-definitions/55.json index 3d2e752ed043..e4d1d489851d 100644 --- a/public/intune-definitions/55.json +++ b/public/intune-definitions/55.json @@ -1 +1 @@ -{"555e4204a38115b9":{"id":"app_privacy_permissiondefaults_generickey_keytobereplaced","displayName":"Permission Defaults","description":"The dictionary of app privacy permission defaults. Each key in the dictionary is an app identifier. The dictionary values represent the permission defaults that the device applies for each matching app.\n\nIn iOS, the app identifier is a bundle ID, for example, \"com.example.app\".\n\nIn macOS, the app identifier is a composed identifier. The format of the composed identifier is either \"Bundle-ID\", \"Bundle-ID (Team-ID)\", or \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the app. \"Team-ID\" is the team identifier from the app's code signature. \"Designated-Requirement\" is the designated requirement string from the code signature of the app. For example, \"com.example.app\" for the bundle ID format, \"com.example.app (ABCD1234)\" for the team ID format, or \"com.example.app {anchor apple generic}\" for the designated requirement format. The device only applies defaults for an app if its code signature matches the composed identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},"55a0be763fd03178":{"id":"com.apple.dock_static-others_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-others_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},"55676a3484aa7889":{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\n\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\n\nIf you enable this policy, Microsoft Edge will send data to the Microsoft Edge service when a user tries to install a blocked extension.\n\nIf you disable or don't configure this policy, Microsoft Edge won't send any data to the Microsoft Edge service about blocked extensions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementextensionsfeedbackenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"551240fa69f51467":{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (Deprecated)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed in a cloud service.\n\nIf you disable this policy, users can receive related matches in Find on Page on limited sites. The results are processed on the user's device.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relatedmatchescloudserviceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"558af17e33efbee3":{"id":"com.apple.managedclient.preferences_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\n\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\n\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcudpportrange"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"55fb29654154d678":{"id":"com.apple.mcx_sleepdisabled","displayName":"Sleep Disabled","description":"If true, disables sleep.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_sleepdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_sleepdisabled_true","displayName":"True","description":null,"helpText":null}]},"55e274477aa648ff":{"id":"com.apple.mcxmenuextras_user.menu","displayName":"User","description":"If true, enables the User menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_user.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_user.menu_true","displayName":"True","description":null,"helpText":null}]},"55cf7465e72bddec":{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled","displayName":"Notifications Enabled","description":"If true, enables notifications for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled_true","displayName":"True","description":null,"helpText":null}]},"55a0e16dcf0963bd":{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed","displayName":"Proxy Captive Login Allowed","description":"If true, allows the device to bypass the proxy server to display the login page for captive networks.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed_true","displayName":"True","description":null,"helpText":null}]},"55e3afe63d257015":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"55118a33943fd2e2":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"551400f65588dec4":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters","displayName":"Configure local setting override for the scan type to use for a scheduled scan","description":"This policy setting configures a local override for the configuration of the scan type to use during a scheduled scan. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescanparameters"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters_1","displayName":"Enabled","description":null,"helpText":null}]},"5596570b7a88ac21":{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint","displayName":"Allow Print Spooler to accept client connections","description":"This policy controls whether the print spooler will accept client connections.\r\n\r\nWhen the policy is unconfigured or enabled, the spooler will always accept client connections.\r\n\r\nWhen the policy is disabled, the spooler will not accept client connections nor allow users to share printers. All printers currently shared will continue to be shared.\r\n\r\nThe spooler must be restarted for changes to this policy to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-registerspoolerremoterpcendpoint"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"558d74efc77e4994":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory","displayName":"Join RD Connection Broker","description":"This policy setting allows you to specify whether the RD Session Host server should join a farm in RD Connection Broker. RD Connection Broker tracks user sessions and allows a user to reconnect to their existing session in a load-balanced RD Session Host server farm. To participate in RD Connection Broker, the Remote Desktop Session Host role service must be installed on the server.\r\n\r\nIf the policy setting is enabled, the RD Session Host server joins the farm that is specified in the RD Connection Broker farm name policy setting. The farm exists on the RD Connection Broker server that is specified in the Configure RD Connection Broker server name policy setting.\r\n\r\nIf you disable this policy setting, the server does not join a farm in RD Connection Broker, and user session tracking is not performed. If the policy setting is disabled, you cannot use either the Remote Desktop Session Host Configuration tool or the Remote Desktop Services WMI Provider to join the server to RD Connection Broker.\r\n\r\nIf the policy setting is not configured, the policy setting is not specified at the Group Policy level. \r\n\r\nNotes:\r\n\r\n 1. If you enable this policy setting, you must also enable the Configure RD Connection Broker farm name and Configure RD Connection Broker server name policy settings.\r\n\r\n 2. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-join-session-directory"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory_1","displayName":"Enabled","description":null,"helpText":null}]},"55c49c4eb0c71be6":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_updateinterval","displayName":"UpdateInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"5595709c7867257e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor","displayName":"Configure the color of the browser's theme","description":"This policy allows admins to configure the color of Google Chrome's theme. The input string should be a valid hex color string matching the format \"#RRGGBB\".\r\n\r\nSetting the policy to a valid hex color causes a theme based on that color to be automatically generated and applied to the browser. Users won't be able to change the theme set by the policy.\r\n\r\nLeaving the policy unset lets users change their browser's theme as preferred.\r\n\r\nExample value: #FFFFFF","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_1","displayName":"Enabled","description":null,"helpText":null}]},"55a1c9d1d3b0f47a":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings","displayName":"Dynamic Code Settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings_0","displayName":"Default dynamic code settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings_1","displayName":"Prevent the browser process from creating dynamic code","description":null,"helpText":null}]},"55bb632d7b2a8b60":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist","displayName":"Blocklist for install types of extensions","description":"The blocklist controls which extensions install types are disallowed.\r\n\r\nSetting \"command_line\" will block extension from being loaded from\r\ncommand line.\r\n\r\nExample value:\r\n\r\ncommand_line","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"556acec19d935f43":{"id":"device_vendor_msft_policy_config_defender_scanparameter","displayName":"Scan Parameter","description":"Selects whether to perform a quick scan or full scan.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_scanparameter_1","displayName":"Quick scan","description":"Quick scan","helpText":null},{"id":"device_vendor_msft_policy_config_defender_scanparameter_2","displayName":"Full scan","description":"Full scan","helpText":null}]},"55f4f12d5a4fc1b1":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilescleanoutnotifications","displayName":"Clean Out Notifications","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nThis setting cleans out stale entries created by the Windows Push Notification Platform (WPN) and Windows Notification Facility (WFN) which under some conditions leads to slow sign-ins. Only enable this setting if directed by a Microsoft Support Engineer.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\CleanOutNotifications\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilescleanoutnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilescleanoutnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"55ca0e9f24dd8649":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenablecrosssitescriptingfilter"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},"55695e06f9f76fd3":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_onlyelevateexecutablefilesthataresignedandvalidated","displayName":"User Account Control Only Elevate Executable Files That Are Signed And Validated","description":"User Account Control: Only elevate executable files that are signed and validated This policy setting enforces public key infrastructure (PKI) signature checks for any interactive applications that request elevation of privilege. Enterprise administrators can control which applications are allowed to run by adding certificates to the Trusted Publishers certificate store on local computers. The options are: • Enabled: Enforces the PKI certification path validation for a given executable file before it is permitted to run. • Disabled: (Default) Does not enforce PKI certification path validation before a given executable file is permitted to run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#useraccountcontrol_onlyelevateexecutablefilesthataresignedandvalidated"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_onlyelevateexecutablefilesthataresignedandvalidated_0","displayName":"Disabled: Does not enforce validation.","description":"Disabled: Does not enforce validation.","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_onlyelevateexecutablefilesthataresignedandvalidated_1","displayName":"Enabled: Enforces validation.","description":"Enabled: Enforces validation.","helpText":null}]},"55943fe875baae1d":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls","displayName":"Allow WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'WebUsbBlockedForUrls' (Block WebUSB on specific sites) policy - you can't both allow and block a URL.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"558fc53a2550a175":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_browsingwithcopilotallowlistdesc","displayName":"Browsing with Copilot Allowed URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"550ca2ddb4f0010c":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin","displayName":"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account","description":"Enable the use of Active Directory accounts for automatic sign in if your users' machines are Domain Joined and your environment is not hybrid joined. If you want users automatically signed in with their Azure Active Directory accounts instead, please Azure AD join (See https://go.microsoft.com/fwlink/?linkid=2118197 for more information) or hybrid join (See https://go.microsoft.com/fwlink/?linkid=2118365 for more information) your environment.\r\n\r\nIf you have configured the 'BrowserSignin' (Browser sign-in settings) policy to disabled, this policy will not take any effect.\r\n\r\nIf you enable this policy and set it to \"Sign in and make domain account non-removable\", Microsoft Edge will automatically sign in users that are on domain joined machines using their Active Directory accounts.\r\n\r\nIf you set this policy to \"Disabled\" or don't set it, Microsoft Edge will not automatically sign in users that are on domain joined machines with Active Directory accounts.\r\n\r\n* 0 = Disabled\r\n\r\n* 1 = Sign in and make domain account non-removable","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_1","displayName":"Enabled","description":null,"helpText":null}]},"55841c1d830bd363":{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages","description":"This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site.\r\n\r\nIf you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_1","displayName":"Enabled","description":null,"helpText":null}]},"555a8d76e6757788":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_winprojexe34","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_winprojexe34_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_winprojexe34_1","displayName":"True","description":null,"helpText":null}]},"55d5b8894bbdda74":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_visioexe5","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_visioexe5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_visioexe5_1","displayName":"True","description":null,"helpText":null}]},"5584109daa097b96":{"id":"device_vendor_msft_policy_config_update_scheduledinstallfirstweek","displayName":"Scheduled Install First Week","description":"Enables the IT admin to schedule the update installation on the first week of the month. Value type is integer. Supported values:0 - no update in the schedule1 - update is scheduled every first week of the month","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduledinstallfirstweek"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_scheduledinstallfirstweek_0","displayName":"no update in the schedule","description":"no update in the schedule","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduledinstallfirstweek_1","displayName":"update is scheduled every first week of the month","description":"update is scheduled every first week of the month","helpText":null}]},"55e1c1a1d6448f83":{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_nestedvirtualizationusersettingconfigurable","displayName":"Allow nested virtualization","description":"When set to disabled, this policy disables nested virtualization configuration via .wslconfig (wsl2.nestedVirtualization). This policy only applies to Store WSL.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_nestedvirtualizationusersettingconfigurable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_nestedvirtualizationusersettingconfigurable_1","displayName":"Enabled","description":null,"helpText":null}]},"55f34dd6faa169dc":{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_path","displayName":"Path","description":"Path to exclude, wildcards are supported","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"558bb5770b1aa2eb":{"id":"passcode_customregex_regex","displayName":"Regex","description":"A regular expression string to match against the password to determine whether it complies with a policy. The regular expression uses the ICU syntax. The string can't exceed 2048 characters in length.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":null},"55642b137ad87473":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_resultantsetofpolicysnapin","displayName":"Resultant Set of Policy snap-in (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-resultantsetofpolicysnapin"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_resultantsetofpolicysnapin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_resultantsetofpolicysnapin_1","displayName":"Enabled","description":null,"helpText":null}]},"55ada6e8ba08ccfa":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation_defaultlibrarieslocation","displayName":"Default Libraries definition location (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"55bb1083f6144a86":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_donotuseproxylocal","displayName":"Do not use proxy server for addresses beginning with (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"5567479c34e10af4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API (User)","description":"If set to Enabled, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\r\n\r\nIf the policy is set to Disabled or left unset, the default behavior will apply.\r\n\r\nThe U2F Security Key API is deprecated and it will be disabled by default in Chrome 98.\r\n\r\nThis is a temporary opt-out mechanism. The U2F API will be removed from Chrome in Chrome 104, at which point this policy will cease to be supported.\r\n\r\nFor more information about the deprecation of the U2F Security Key API, please refer to https://groups.google.com/a/chromium.org/g/blink-dev/c/xHC3AtU_65A.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"552b4ce2cc713728":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon78","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"5572af6a4b3ccbf9":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"5533030f78c26c49":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"552bbfd65d31da22":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls_localfontsallowedforurlsdesc","displayName":"Allow Local Fonts permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"55ee7ab578e3e9a1":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet","displayName":"Enhanced Security Mode configuration for Intranet zone sites (User)","description":"Microsoft Edge will apply Enhanced Security Mode on Intranet zone sites by default. This may lead to Intranet zone sites acting in an unexpected manner.\r\n\r\nIf you enable this policy, Microsoft Edge won't apply Enhanced Security Mode on Intranet zone sites.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will apply Enhanced Security Mode on Intranet zone sites.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet_1","displayName":"Enabled","description":null,"helpText":null}]},"55aa44ecdca5be0e":{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":null},"55bce9d267208a02":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets\r\n\r\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all its ccTLD variants. See https://github.com/WICG/first-party-sets for more information on how Microsoft Edge uses Related Website Sets.\r\n\r\n\r\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set.\r\n\r\nWhen this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this, the policy's Related Website Set will be added to the Microsoft Edge's list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set will be updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set will be added to the browser's list of Related Website Sets.\r\n\r\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site can't be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists.\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"additions\": [{\"associatedSites\": [\"https://associate2.test\"], \"ccTLDs\": {\"https://associate2.test\": [\"https://associate2.com\"]}, \"primary\": \"https://primary2.test\", \"serviceSites\": [\"https://associate2-content.test\"]}], \"replacements\": [{\"associatedSites\": [\"https://associate1.test\"], \"ccTLDs\": {\"https://associate1.test\": [\"https://associate1.co.uk\"]}, \"primary\": \"https://primary1.test\", \"serviceSites\": [\"https://associate1-content.test\"]}]}","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},"554c779367d509f0":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_spellchecklanguageblocklistdesc","displayName":"Force disable spellcheck languages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"552662b7e7b10176":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors. (User)","description":"This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\r\n\r\nIf you enable this policy or don't set it, Microsoft Edge will enable these security protections for all connections.\r\n\r\nIf you disable this policy, Microsoft Edge will disable these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\r\n\r\nThis policy may be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED. A later version of Microsoft Edge will enable this option by default.\r\n\r\nAfter it is enabled by default, administrators who need more time to upgrade affected proxies may use this policy to temporarily disable this security feature. This policy will be removed after version 85.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"55f213b0664d0378":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended","displayName":"Block Sleeping Tabs on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are not allowed to be put to sleep by Sleeping Tabs.\r\n\r\nIf the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is disabled, this list is not used and no sites will be put to sleep automatically.\r\n\r\nIf you don't configure this policy, all sites will be eligible to be put to sleep unless the user's personal configuration blocks them.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"55f0ac970100ea96":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverurl1","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"5512b8b9772ad17f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway","displayName":"Sami, Northern (Norway) (User)","description":"Enables the editing language \"Sami, Northern (Norway)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway_1","displayName":"Enabled","description":null,"helpText":null}]},"553a744760fb5aed":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates","displayName":"Spanish (United States) (User)","description":"Enables the editing language Spanish (United States)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates_1","displayName":"Enabled","description":null,"helpText":null}]},"550ffcb1bbb6a613":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14","displayName":"Unsafe Location #14 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"552b07a2c52d8b80":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname_l_font","displayName":"Font: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":null},"55c9535849af6026":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_l_weatherupdatefrequencyintervalspinid","displayName":"Update frequency (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},"55f7cbda409ca8ac":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2_l_minimumkeysizeinbits","displayName":"Minimum key size (in bits): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},"55a6f0375b8cc220":{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications","displayName":"Disable Outlook tenant admin notifications (User)","description":"This policy setting determines if tenant admins can receive support notifications in Outlook.\r\n\r\nDefault (0): Tenant admins who are signed in will receive status updates about potential issues and fixes that are impacting their tenant.\r\n\r\nIf you enable this setting, tenant admins who are signed in won't receive status updates about potential issues and fixes that are impacting their tenant.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"552f5dfcd629427f":{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel","displayName":"Select level: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_4294967295","displayName":"No Protection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_6","displayName":"Low (Default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_3","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_2147483648","displayName":"Trusted Lists Only","description":null,"helpText":null}]},"5592c5ae2bf5e1fb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"55c1d118a220fa0d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear","displayName":"Fiscal year starts in (User)","description":"Specifies the month that begins the fiscal year.\r\n\r\nIf you enable this setting, the fiscal year will start on the month you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_1","displayName":"Enabled","description":null,"helpText":null}]},"55221f0ea5b8010a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_pathcolon80","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"55767598c95b714e":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults","displayName":"Search results (User)","description":"Specifies whether results are returned in alphabetical order by shape name or by stencil name (group). Click By Group to help distinguish between shapes that have the same name but appear on different stencils. Selecting this option is also useful if you want to locate the stencil containing the shape.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_1","displayName":"Enabled","description":null,"helpText":null}]},"55c2ba8f5ba0f625":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste","displayName":"Use the Insert key for paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste_1","displayName":"Enabled","description":null,"helpText":null}]},"55691a1b1b289bf8":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly","displayName":"Show vertical ruler in Print Layout view (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly_1","displayName":"Enabled","description":null,"helpText":null}]},"554f480a797b0f5a":{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp","displayName":"Disable Stateful Ftp","description":"This value is an on/off switch. If off, the firewall performs stateful File Transfer Protocol (FTP) filtering to allow secondary connections. FALSE means off; TRUE means on, so the stateful FTP is disabled. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp_false","displayName":"False","description":"Stateful FTP enabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp_true","displayName":"True","description":"Stateful FTP disabled","helpText":null}]}} \ No newline at end of file +{"555e4204a38115b9":{"id":"app_privacy_permissiondefaults_generickey_keytobereplaced","displayName":"Permission Defaults","description":"The dictionary of app privacy permission defaults. Each key in the dictionary is an app identifier. The dictionary values represent the permission defaults that the device applies for each matching app.\n\nIn iOS, the app identifier is a bundle ID, for example, \"com.example.app\".\n\nIn macOS, the app identifier is a composed identifier. The format of the composed identifier is either \"Bundle-ID\", \"Bundle-ID (Team-ID)\", or \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the app. \"Team-ID\" is the team identifier from the app's code signature. \"Designated-Requirement\" is the designated requirement string from the code signature of the app. For example, \"com.example.app\" for the bundle ID format, \"com.example.app (ABCD1234)\" for the team ID format, or \"com.example.app {anchor apple generic}\" for the designated requirement format. The device only applies defaults for an app if its code signature matches the composed identifier.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":null},"55a0be763fd03178":{"id":"com.apple.dock_static-others_item_tile-type","displayName":"Tile Type","description":"The type of tile.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-others_item_tile-type_0","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-type_1","displayName":"Directory","description":null,"helpText":null},{"id":"com.apple.dock_static-others_item_tile-type_2","displayName":"URL","description":null,"helpText":null}]},"55676a3484aa7889":{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\n\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\n\nIf you enable this policy, Microsoft Edge will send data to the Microsoft Edge service when a user tries to install a blocked extension.\n\nIf you disable or don't configure this policy, Microsoft Edge won't send any data to the Microsoft Edge service about blocked extensions.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementextensionsfeedbackenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementextensionsfeedbackenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"551240fa69f51467":{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (Deprecated)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed in a cloud service.\n\nIf you disable this policy, users can receive related matches in Find on Page on limited sites. The results are processed on the user's device.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relatedmatchescloudserviceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_relatedmatchescloudserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"558af17e33efbee3":{"id":"com.apple.managedclient.preferences_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\n\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\n\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtcudpportrange"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"55fb29654154d678":{"id":"com.apple.mcx_sleepdisabled","displayName":"Sleep Disabled","description":"If true, disables sleep.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_sleepdisabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_sleepdisabled_true","displayName":"True","description":null,"helpText":null}]},"55e274477aa648ff":{"id":"com.apple.mcxmenuextras_user.menu","displayName":"User","description":"If true, enables the User menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_user.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_user.menu_true","displayName":"True","description":null,"helpText":null}]},"55cf7465e72bddec":{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled","displayName":"Notifications Enabled","description":"If true, enables notifications for this app. Available in iOS 9.3 and later and macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":[{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.notificationsettings_notificationsettings_item_notificationsenabled_true","displayName":"True","description":null,"helpText":null}]},"55a0e16dcf0963bd":{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed","displayName":"Proxy Captive Login Allowed","description":"If true, allows the device to bypass the proxy server to display the login page for captive networks.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxycaptiveloginallowed_true","displayName":"True","description":null,"helpText":null}]},"55e3afe63d257015":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyappdata_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"55118a33943fd2e2":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"551400f65588dec4":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters","displayName":"Configure local setting override for the scan type to use for a scheduled scan","description":"This policy setting configures a local override for the configuration of the scan type to use during a scheduled scan. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescanparameters"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescanparameters_1","displayName":"Enabled","description":null,"helpText":null}]},"5596570b7a88ac21":{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint","displayName":"Allow Print Spooler to accept client connections","description":"This policy controls whether the print spooler will accept client connections.\r\n\r\nWhen the policy is unconfigured or enabled, the spooler will always accept client connections.\r\n\r\nWhen the policy is disabled, the spooler will not accept client connections nor allow users to share printers. All printers currently shared will continue to be shared.\r\n\r\nThe spooler must be restarted for changes to this policy to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-registerspoolerremoterpcendpoint"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_registerspoolerremoterpcendpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"558d74efc77e4994":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory","displayName":"Join RD Connection Broker","description":"This policy setting allows you to specify whether the RD Session Host server should join a farm in RD Connection Broker. RD Connection Broker tracks user sessions and allows a user to reconnect to their existing session in a load-balanced RD Session Host server farm. To participate in RD Connection Broker, the Remote Desktop Session Host role service must be installed on the server.\r\n\r\nIf the policy setting is enabled, the RD Session Host server joins the farm that is specified in the RD Connection Broker farm name policy setting. The farm exists on the RD Connection Broker server that is specified in the Configure RD Connection Broker server name policy setting.\r\n\r\nIf you disable this policy setting, the server does not join a farm in RD Connection Broker, and user session tracking is not performed. If the policy setting is disabled, you cannot use either the Remote Desktop Session Host Configuration tool or the Remote Desktop Services WMI Provider to join the server to RD Connection Broker.\r\n\r\nIf the policy setting is not configured, the policy setting is not specified at the Group Policy level. \r\n\r\nNotes:\r\n\r\n 1. If you enable this policy setting, you must also enable the Configure RD Connection Broker farm name and Configure RD Connection Broker server name policy settings.\r\n\r\n 2. For Windows Server 2008, this policy setting is supported on at least Windows Server 2008 Standard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-join-session-directory"],"categoryId":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","categoryName":"RD Connection Broker","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_join_session_directory_1","displayName":"Enabled","description":null,"helpText":null}]},"55c49c4eb0c71be6":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_updateinterval","displayName":"UpdateInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"5595709c7867257e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor","displayName":"Configure the color of the browser's theme","description":"This policy allows admins to configure the color of Google Chrome's theme. The input string should be a valid hex color string matching the format \"#RRGGBB\".\r\n\r\nSetting the policy to a valid hex color causes a theme based on that color to be automatically generated and applied to the browser. Users won't be able to change the theme set by the policy.\r\n\r\nLeaving the policy unset lets users change their browser's theme as preferred.\r\n\r\nExample value: #FFFFFF","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_1","displayName":"Enabled","description":null,"helpText":null}]},"55a1c9d1d3b0f47a":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings","displayName":"Dynamic Code Settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings_0","displayName":"Default dynamic code settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_dynamiccodesettings_1","displayName":"Prevent the browser process from creating dynamic code","description":null,"helpText":null}]},"55bb632d7b2a8b60":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist","displayName":"Blocklist for install types of extensions","description":"The blocklist controls which extensions install types are disallowed.\r\n\r\nSetting \"command_line\" will block extension from being loaded from\r\ncommand line.\r\n\r\nExample value:\r\n\r\ncommand_line","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"556acec19d935f43":{"id":"device_vendor_msft_policy_config_defender_scanparameter","displayName":"Scan Parameter","description":"Selects whether to perform a quick scan or full scan.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_scanparameter_1","displayName":"Quick scan","description":"Quick scan","helpText":null},{"id":"device_vendor_msft_policy_config_defender_scanparameter_2","displayName":"Full scan","description":"Full scan","helpText":null}]},"55f4f12d5a4fc1b1":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilescleanoutnotifications","displayName":"Clean Out Notifications","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nThis setting cleans out stale entries created by the Windows Push Notification Platform (WPN) and Windows Notification Facility (WFN) which under some conditions leads to slow sign-ins. Only enable this setting if directed by a Microsoft Support Engineer.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\CleanOutNotifications\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilescleanoutnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilescleanoutnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"55ca0e9f24dd8649":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenablecrosssitescriptingfilter"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},"55695e06f9f76fd3":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_onlyelevateexecutablefilesthataresignedandvalidated","displayName":"User Account Control Only Elevate Executable Files That Are Signed And Validated","description":"User Account Control: Only elevate executable files that are signed and validated This policy setting enforces public key infrastructure (PKI) signature checks for any interactive applications that request elevation of privilege. Enterprise administrators can control which applications are allowed to run by adding certificates to the Trusted Publishers certificate store on local computers. The options are: • Enabled: Enforces the PKI certification path validation for a given executable file before it is permitted to run. • Disabled: (Default) Does not enforce PKI certification path validation before a given executable file is permitted to run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#useraccountcontrol_onlyelevateexecutablefilesthataresignedandvalidated"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_onlyelevateexecutablefilesthataresignedandvalidated_0","displayName":"Disabled: Does not enforce validation.","description":"Disabled: Does not enforce validation.","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_onlyelevateexecutablefilesthataresignedandvalidated_1","displayName":"Enabled: Enforces validation.","description":"Enabled: Enforces validation.","helpText":null}]},"55943fe875baae1d":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls","displayName":"Allow WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nThe URL patterns defined in this policy can't conflict with those configured in the 'WebUsbBlockedForUrls' (Block WebUSB on specific sites) policy - you can't both allow and block a URL.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"558fc53a2550a175":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_browsingwithcopilotallowlistdesc","displayName":"Browsing with Copilot Allowed URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"550ca2ddb4f0010c":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin","displayName":"Configure automatic sign in with an Active Directory domain account when there is no Azure AD domain account","description":"Enable the use of Active Directory accounts for automatic sign in if your users' machines are Domain Joined and your environment is not hybrid joined. If you want users automatically signed in with their Azure Active Directory accounts instead, please Azure AD join (See https://go.microsoft.com/fwlink/?linkid=2118197 for more information) or hybrid join (See https://go.microsoft.com/fwlink/?linkid=2118365 for more information) your environment.\r\n\r\nIf you have configured the 'BrowserSignin' (Browser sign-in settings) policy to disabled, this policy will not take any effect.\r\n\r\nIf you enable this policy and set it to \"Sign in and make domain account non-removable\", Microsoft Edge will automatically sign in users that are on domain joined machines using their Active Directory accounts.\r\n\r\nIf you set this policy to \"Disabled\" or don't set it, Microsoft Edge will not automatically sign in users that are on domain joined machines with Active Directory accounts.\r\n\r\n* 0 = Disabled\r\n\r\n* 1 = Sign in and make domain account non-removable","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_configureonpremisesaccountautosignin_1","displayName":"Enabled","description":null,"helpText":null}]},"55841c1d830bd363":{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment","displayName":"Configure the pixel adjustment between window.open widths sourced from IE mode pages vs. Edge mode pages","description":"This setting lets you specify a custom adjustment to the width of popup windows generated via window.open from the Internet Explorer mode site.\r\n\r\nIf you configure this policy, Microsoft Edge will add the adjustment value to the width, in pixels. The exact difference depends on the UI configuration of both IE and Edge, but a typical difference is 4.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will treat IE mode window.open the same as Edge mode window.open in window width calculations.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_internetexplorerintegrationwindowopenwidthadjustment_1","displayName":"Enabled","description":null,"helpText":null}]},"555a8d76e6757788":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_winprojexe34","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_winprojexe34_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_winprojexe34_1","displayName":"True","description":null,"helpText":null}]},"55d5b8894bbdda74":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_visioexe5","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_visioexe5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_visioexe5_1","displayName":"True","description":null,"helpText":null}]},"5584109daa097b96":{"id":"device_vendor_msft_policy_config_update_scheduledinstallfirstweek","displayName":"Scheduled Install First Week","description":"Enables the IT admin to schedule the update installation on the first week of the month. Value type is integer. Supported values:0 - no update in the schedule1 - update is scheduled every first week of the month","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduledinstallfirstweek"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_scheduledinstallfirstweek_0","displayName":"no update in the schedule","description":"no update in the schedule","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduledinstallfirstweek_1","displayName":"update is scheduled every first week of the month","description":"update is scheduled every first week of the month","helpText":null}]},"55e1c1a1d6448f83":{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_nestedvirtualizationusersettingconfigurable","displayName":"Allow nested virtualization","description":"When set to disabled, this policy disables nested virtualization configuration via .wslconfig (wsl2.nestedVirtualization). This policy only applies to Store WSL.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_nestedvirtualizationusersettingconfigurable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_nestedvirtualizationusersettingconfigurable_1","displayName":"Enabled","description":null,"helpText":null}]},"557861e9a6c48704":{"id":"dnsproxy_providercomposedidentifier","displayName":"Provider Composed Identifier","description":"The identifier of the provider to use for this configuration. Useful for apps that contain more than one DNS proxy extension.\n\nIn iOS and visionOS, the identifier is a bundle ID, for example, \"com.example.app\".\n\nIn macOS, the identifier is a composed identifier. The format of the composed identifier is either \"Bundle-ID\" or \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the provider. \"Designated-Requirement\" is the designated requirement string from the code signature of the provider. For example, \"com.example.app\" for the bundle ID format, or \"com.example.app {anchor apple generic}\" for the designated requirement format.","helpText":null,"infoUrls":[],"categoryId":"4a6c4488-bbcf-4b5b-9156-7aa1b10a6010","categoryName":"DNS Proxy","options":null},"55f34dd6faa169dc":{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_path","displayName":"Path","description":"Path to exclude, wildcards are supported","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"558bb5770b1aa2eb":{"id":"passcode_customregex_regex","displayName":"Regex","description":"A regular expression string to match against the password to determine whether it complies with a policy. The regular expression uses the ICU syntax. The string can't exceed 2048 characters in length.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":null},"55642b137ad87473":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_resultantsetofpolicysnapin","displayName":"Resultant Set of Policy snap-in (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-resultantsetofpolicysnapin"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_resultantsetofpolicysnapin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_resultantsetofpolicysnapin_1","displayName":"Enabled","description":null,"helpText":null}]},"55ada6e8ba08ccfa":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_defaultlibrarieslocation_defaultlibrarieslocation","displayName":"Default Libraries definition location (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"55bb1083f6144a86":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_donotuseproxylocal","displayName":"Do not use proxy server for addresses beginning with (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"5567479c34e10af4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API (User)","description":"If set to Enabled, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\r\n\r\nIf the policy is set to Disabled or left unset, the default behavior will apply.\r\n\r\nThe U2F Security Key API is deprecated and it will be disabled by default in Chrome 98.\r\n\r\nThis is a temporary opt-out mechanism. The U2F API will be removed from Chrome in Chrome 104, at which point this policy will cease to be supported.\r\n\r\nFor more information about the deprecation of the U2F Security Key API, please refer to https://groups.google.com/a/chromium.org/g/blink-dev/c/xHC3AtU_65A.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_u2fsecuritykeyapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"552b4ce2cc713728":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_datecolon78","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"5572af6a4b3ccbf9":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"5533030f78c26c49":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"552bbfd65d31da22":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_localfontsallowedforurls_localfontsallowedforurlsdesc","displayName":"Allow Local Fonts permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"55ee7ab578e3e9a1":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet","displayName":"Enhanced Security Mode configuration for Intranet zone sites (User)","description":"Microsoft Edge will apply Enhanced Security Mode on Intranet zone sites by default. This may lead to Intranet zone sites acting in an unexpected manner.\r\n\r\nIf you enable this policy, Microsoft Edge won't apply Enhanced Security Mode on Intranet zone sites.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will apply Enhanced Security Mode on Intranet zone sites.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_enhancesecuritymodebypassintranet_1","displayName":"Enabled","description":null,"helpText":null}]},"55aa44ecdca5be0e":{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":null},"55bce9d267208a02":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets\r\n\r\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all its ccTLD variants. See https://github.com/WICG/first-party-sets for more information on how Microsoft Edge uses Related Website Sets.\r\n\r\n\r\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set.\r\n\r\nWhen this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this, the policy's Related Website Set will be added to the Microsoft Edge's list of Related Website Sets.\r\n\r\nFor all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set will be updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set will be added to the browser's list of Related Website Sets.\r\n\r\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site can't be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists.\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"additions\": [{\"associatedSites\": [\"https://associate2.test\"], \"ccTLDs\": {\"https://associate2.test\": [\"https://associate2.com\"]}, \"primary\": \"https://primary2.test\", \"serviceSites\": [\"https://associate2-content.test\"]}], \"replacements\": [{\"associatedSites\": [\"https://associate1.test\"], \"ccTLDs\": {\"https://associate1.test\": [\"https://associate1.co.uk\"]}, \"primary\": \"https://primary1.test\", \"serviceSites\": [\"https://associate1-content.test\"]}]}","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},"554c779367d509f0":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_spellchecklanguageblocklist_spellchecklanguageblocklistdesc","displayName":"Force disable spellcheck languages (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"552662b7e7b10176":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled","displayName":"Enable a TLS 1.3 security feature for local trust anchors. (User)","description":"This policy controls a security feature in TLS 1.3 that protects connections against downgrade attacks. It is backwards-compatible and will not affect connections to compliant TLS 1.2 servers or proxies. However, older versions of some TLS-intercepting proxies have an implementation flaw which causes them to be incompatible.\r\n\r\nIf you enable this policy or don't set it, Microsoft Edge will enable these security protections for all connections.\r\n\r\nIf you disable this policy, Microsoft Edge will disable these security protections for connections authenticated with locally-installed CA certificates. These protections are always enabled for connections authenticated with publicly-trusted CA certificates.\r\n\r\nThis policy may be used to test for any affected proxies and upgrade them. Affected proxies are expected to fail connections with an error code of ERR_TLS13_DOWNGRADE_DETECTED. A later version of Microsoft Edge will enable this option by default.\r\n\r\nAfter it is enabled by default, administrators who need more time to upgrade affected proxies may use this policy to temporarily disable this security feature. This policy will be removed after version 85.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_tls13hardeningforlocalanchorsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"55f213b0664d0378":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended","displayName":"Block Sleeping Tabs on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are not allowed to be put to sleep by Sleeping Tabs.\r\n\r\nIf the policy 'SleepingTabsEnabled' (Configure Sleeping Tabs) is disabled, this list is not used and no sites will be put to sleep automatically.\r\n\r\nIf you don't configure this policy, all sites will be eligible to be put to sleep unless the user's personal configuration blocks them.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabsblockedforurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"55f0ac970100ea96":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceserverurl1","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"5512b8b9772ad17f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway","displayName":"Sami, Northern (Norway) (User)","description":"Enables the editing language \"Sami, Northern (Norway)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_saminorthernnorway_1","displayName":"Enabled","description":null,"helpText":null}]},"553a744760fb5aed":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates","displayName":"Spanish (United States) (User)","description":"Enables the editing language Spanish (United States)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishunitedstates_1","displayName":"Enabled","description":null,"helpText":null}]},"550ffcb1bbb6a613":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14","displayName":"Unsafe Location #14 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"552b07a2c52d8b80":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontname_l_font","displayName":"Font: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":null},"55c9535849af6026":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_l_weatherupdatefrequencyintervalspinid","displayName":"Update frequency (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},"55f7cbda409ca8ac":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_v2_l_minimumkeysizeinbits","displayName":"Minimum key size (in bits): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},"55a6f0375b8cc220":{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications","displayName":"Disable Outlook tenant admin notifications (User)","description":"This policy setting determines if tenant admins can receive support notifications in Outlook.\r\n\r\nDefault (0): Tenant admins who are signed in will receive status updates about potential issues and fixes that are impacting their tenant.\r\n\r\nIf you enable this setting, tenant admins who are signed in won't receive status updates about potential issues and fixes that are impacting their tenant.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableadminnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"552f5dfcd629427f":{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel","displayName":"Select level: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_4294967295","displayName":"No Protection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_6","displayName":"Low (Default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_3","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_v2_l_selectlevel_2147483648","displayName":"Trusted Lists Only","description":null,"helpText":null}]},"5592c5ae2bf5e1fb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_webpages_l_webpagesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"55c1d118a220fa0d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear","displayName":"Fiscal year starts in (User)","description":"Specifies the month that begins the fiscal year.\r\n\r\nIf you enable this setting, the fiscal year will start on the month you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_1","displayName":"Enabled","description":null,"helpText":null}]},"55221f0ea5b8010a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_l_pathcolon80","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"55767598c95b714e":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults","displayName":"Search results (User)","description":"Specifies whether results are returned in alphabetical order by shape name or by stencil name (group). Click By Group to help distinguish between shapes that have the same name but appear on different stencils. Selecting this option is also useful if you want to locate the stencil containing the shape.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchresults_1","displayName":"Enabled","description":null,"helpText":null}]},"55c2ba8f5ba0f625":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste","displayName":"Use the Insert key for paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usetheinskeyforpaste_1","displayName":"Enabled","description":null,"helpText":null}]},"55691a1b1b289bf8":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly","displayName":"Show vertical ruler in Print Layout view (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalrulerprintviewonly_1","displayName":"Enabled","description":null,"helpText":null}]},"554f480a797b0f5a":{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp","displayName":"Disable Stateful Ftp","description":"This value is an on/off switch. If off, the firewall performs stateful File Transfer Protocol (FTP) filtering to allow secondary connections. FALSE means off; TRUE means on, so the stateful FTP is disabled. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp_false","displayName":"False","description":"Stateful FTP enabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_disablestatefulftp_true","displayName":"True","description":"Stateful FTP disabled","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/59.json b/public/intune-definitions/59.json index ffcf97dd407e..760e04dc7657 100644 --- a/public/intune-definitions/59.json +++ b/public/intune-definitions/59.json @@ -1 +1 @@ -{"59a65b60b1d63f40":{"id":".globalpreferences_.globalpreferences","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"1829cdc1-1bed-4058-9aba-9b778cd3d955","categoryName":"Global Preferences","options":null},"59647e905ad71747":{"id":"com.apple.applicationaccess_safariacceptcookies","displayName":"Safari Accept Cookies","description":"This value defines the conditions under which the device accepts cookies. The user-facing settings changed in iOS 11, although the possible values remain the same. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariacceptcookies_0","displayName":"Prevent Cross-Site Tracking and Block All Cookies are enabled and the user canʼt disable either setting.","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariacceptcookies_1","displayName":"Prevent Cross-Site Tracking is enabled and the user canʼt disable it. Block All Cookies is not enabled, although the user can enable it.","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariacceptcookies_2","displayName":"Prevent Cross-Site Tracking is enabled and Block All Cookies is not enabled. The user can toggle either setting.","description":null,"helpText":null}]},"59bca7058192f801":{"id":"com.apple.cellular_attachapn_password","displayName":"Password","description":"The password for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},"5970974bbe55bc2b":{"id":"com.apple.dnssettings.managed_ondemandrules_item_ssidmatch","displayName":"SSID Match","description":"An array of SSIDs to match against the current network. If the network is not a Wi-Fi network or if the SSID does not appear in this array, the match fails. Omit this key and the corresponding array to match against any SSID.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},"59251eb09e97aac9":{"id":"com.apple.managedclient.preferences_urlblocklist","displayName":"Block access to a list of URLs","description":"Define a list of sites, based on URL patterns, that are blocked (your users can't load them).\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can define exceptions in the \"URLAllowlist\" policy. These policies are limited to 1000 entries; subsequent entries are ignored.\n\nNote that blocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.\n\nThis policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users might still be able to visit 'contoso.com' and click on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.\n\nIf you don't configure this policy, no URLs are blocked.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#urlblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"598d800d600f97df":{"id":"com.apple.mcxmenuextras_pppoe.menu","displayName":"PPPoE","description":"If true, enables the PPPoE menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_pppoe.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_pppoe.menu_true","displayName":"True","description":null,"helpText":null}]},"590f42edd02dc4a4":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"5922720306d4e177":{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name","displayName":"Configure storage of BitLocker recovery information to AD DS:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name_1","displayName":"Store recovery passwords and key packages","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name_2","displayName":"Store recovery passwords only","description":null,"helpText":null}]},"59828e7aa6f30be7":{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver","displayName":"Allow Datagram Processing On Win Server","description":"This settings controls whether Network Protection is allowed to enable datagram processing on Windows Server. If false, the value of DisableDatagramProcessing will be ignored and default to disabling Datagram inspection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver_1","displayName":"Datagram processing on Windows Server is enabled.","description":"Datagram processing on Windows Server is enabled.","helpText":null},{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver_0","displayName":"Datagram processing on Windows Server is disabled.","description":"Datagram processing on Windows Server is disabled.","helpText":null}]},"59094eae172dd0e7":{"id":"device_vendor_msft_defender_configuration_disablehttpparsing","displayName":"Disable Http Parsing","description":"This setting disables HTTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablehttpparsing_1","displayName":"HTTP parsing is disabled","description":"HTTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablehttpparsing_0","displayName":"HTTP parsing is enabled","description":"HTTP parsing is enabled","helpText":null}]},"5930e13b75b94c4b":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_transferrateop2","displayName":"Connection speed (Kbps):","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"59280d629b838816":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet","displayName":"Prohibit operation while in private network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet_1","displayName":"True","description":null,"helpText":null}]},"59af6476acf22501":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"5973f1f22c0dcac4":{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer","displayName":"Send Intranet Trafficto Internet Explorer","description":"Sends all intranet traffic over to Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#sendintranettraffictointernetexplorer"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer_0","displayName":"Disabled","description":"All sites, including intranet sites, open in Microsoft Edge automatically.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer_1","displayName":"Enabled","description":"Only intranet sites open in Internet Explorer 11 automatically.","helpText":null}]},"5927d97a5eb87737":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled","displayName":"Enable alternate error pages","description":"Setting the policy to True means Google Chrome uses alternate error pages built into (such as \"page not found\"). Setting the policy to False means Google Chrome never uses alternate error pages.\r\n\r\nIf you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"59c967c1e0226277":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin","description":"\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing will be deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allows to re-enable cross-origin WebAssembly module sharing to offer a longer transition period in the deprecation process.\r\n\r\nWhen set to True, sites can send WebAssembly modules also cross-origin without restrictions.\r\n\r\nWhen set to False or not set, sites can only send WebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"59dd57beca3635d8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions.","description":"Extensions that connect to one of these origins will be be kept running as long as the port is connected.\r\n\r\nIf unset, the policy's default values will be used. These are app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\r\n- Smart Card Connector\r\n- Citrix Receiver (stable, beta, back-up)\r\n- VMware Horizon (stable, beta)\r\n\r\nIf set, the default value list is extended with the newly configured values. Both defaults and the policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.\r\n\r\nExample value:\r\n\r\nchrome-extension://abcdefghijklmnopabcdefghijklmnop/\r\nchrome-extension://bcdefghijklmnopabcdefghijklmnopa/","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_1","displayName":"Enabled","description":null,"helpText":null}]},"593597ed9cf1f83d":{"id":"device_vendor_msft_policy_config_experience_allowwindowsconsumerfeatures","displayName":"Allow Windows Consumer Features","description":"This policy allows IT admins to turn on experiences that are typically for consumers only, such as Start suggestions, Membership notifications, Post-OOBE app install and redirect tiles.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-experience#allowwindowsconsumerfeatures"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowwindowsconsumerfeatures_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowwindowsconsumerfeatures_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"59a6662f28c2a5a6":{"id":"device_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard","displayName":"Prevent running First Run wizard","description":"This policy setting prevents Internet Explorer from running the First Run wizard the first time a user starts the browser after installing Internet Explorer or Windows.\n\nIf you enable this policy setting, you must make one of the following choices:\n • Skip the First Run wizard, and go directly to the user's home page.\n • Skip the First Run wizard, and go directly to the \"Welcome to Internet Explorer\" webpage.\n\nStarting with Windows 8, the \"Welcome to Internet Explorer\" webpage is not available. The user's home page will display regardless of which option is chosen.\n\nIf you disable or do not configure this policy setting, Internet Explorer may run the First Run wizard the first time the browser is started after installation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablefirstrunwizard"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_1","displayName":"Enabled","description":null,"helpText":null}]},"59ba779eb3a18c93":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},"593135ecbf649077":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients","displayName":"Network Security Minimum Session Security For NTLMSSP Based Clients","description":"Network security: Minimum session security for NTLM SSP based (including secure RPC) clients This security setting allows a client to require the negotiation of 128-bit encryption and/or NTLMv2 session security. These values are dependent on the LAN Manager Authentication Level security setting value. The options are: Require NTLMv2 session security: The connection will fail if NTLMv2 protocol is not negotiated. Require 128-bit encryption: The connection will fail if strong encryption (128-bit) is not negotiated. Default: Windows XP, Windows Vista, Windows 2000 Server, Windows Server 2003, and Windows Server 2008: No requirements. Windows 7 and Windows Server 2008 R2: Require 128-bit encryption","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_minimumsessionsecurityforntlmsspbasedclients"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients_0","displayName":"None","description":"None","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients_524288","displayName":"Require NTLMv2 session security","description":"Require NTLMv2 session security","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients_536870912","displayName":"Require 128-bit encryption","description":"Require 128-bit encryption","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients_537395200","displayName":"Require NTLM and 128-bit encryption","description":"Require NTLM and 128-bit encryption","helpText":null}]},"59279a2c540447c3":{"id":"device_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories_webcontentfilteringblockedcategoriesdesc","displayName":"List of blocked categories (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"59338561f8873b0f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword","displayName":"Disable user name and password","description":"Disable user name and password","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_1","displayName":"Enabled","description":null,"helpText":null}]},"59a9d236b2ab9378":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_pptviewexe130","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_pptviewexe130_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_pptviewexe130_1","displayName":"True","description":null,"helpText":null}]},"598c40ae922e7bf9":{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakespluggedin","displayName":"Require a password when a computer wakes (plugged in)","description":"This policy setting specifies whether or not the user is prompted for a password when the system resumes from sleep.\n\nIf you enable or do not configure this policy setting, the user is prompted for a password when the system resumes from sleep.\n\nIf you disable this policy setting, the user is not prompted for a password when the system resumes from sleep.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-requirepasswordwhencomputerwakespluggedin"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakespluggedin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakespluggedin_1","displayName":"Enabled","description":null,"helpText":null}]},"593a014373fa609f":{"id":"device_vendor_msft_policy_config_remotemanagement_trustedhosts_trustedhosts_list","displayName":"TrustedHostsList:","description":"","helpText":"","infoUrls":[],"categoryId":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","categoryName":"Win RM Client","options":null},"590572b7a5da101d":{"id":"device_vendor_msft_policy_config_textinput_allowkeyboardtextsuggestions","displayName":"Allow Keyboard Text Suggestions","description":"Note The policy is only enforced in Windows 10 for desktop. Specifies whether text prediction is enabled or disabled for the on-screen keyboard, touch keyboard, and handwriting recognition tool. When this policy is set to disabled, text prediction is disabled. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#allowkeyboardtextsuggestions"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_allowkeyboardtextsuggestions_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_allowkeyboardtextsuggestions_1","displayName":"Allow","description":"Enabled.","helpText":null}]},"598ac053d42e807f":{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy","displayName":"Turn off automatic updates for Windows App","description":"Controls how the Windows App checks for and installs updates.\n\nIf you enable this policy, choose one of the following options:\n \n Enable updates: Windows App will automatically check for and install updates from all sources.\n Disable updates from all locations: Windows App will not check for or install updates from any source.\n Disable updates from the Microsoft Store: Windows App will not download updates from the Microsoft Store but may still update from other sources.\n Disable updates from non-store CDN location: Windows App will not download updates from non-store CDN sources but may still update from the Microsoft Store.\n\nIf you disable or do not configure this policy, automatic updates are enabled for Windows App.\n ","helpText":"","infoUrls":[],"categoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","categoryName":"Windows App","options":[{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"59b90277088e95ae":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},"598adfaea103589f":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"593c8d6aa5724d22":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"59b926d37051232d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},"59432db0c816ff16":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon55","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"594f63ed99ebd94b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iaslogging","displayName":"IAS Logging (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-iaslogging"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iaslogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iaslogging_1","displayName":"Enabled","description":null,"helpText":null}]},"595a5679985ab1cf":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_wirednetworkpolicy","displayName":"Wired Network (IEEE 802.3) Policies (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-wirednetworkpolicy"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_wirednetworkpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_wirednetworkpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"594b46686bdc25b2":{"id":"user_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_1","displayName":"Tape Drives: Deny write access (User)","description":"This policy setting denies write access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denywrite-access-1"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"user_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_1_1","displayName":"Enabled","description":null,"helpText":null}]},"59beb453368d10db":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings","displayName":"Roaming Credentials (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_1","displayName":"True","description":null,"helpText":null}]},"592ad8a70aa0138e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended","displayName":"Print Headers and Footers (User)","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"599d4aac281e4c58":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions","displayName":"URL pattern Exceptions to tab discarding (User)","description":"This policy makes it so that any URL matching one or more of the patterns it specifies (using the URLBlocklist filter format) will never be discarded by the browser.\r\nThis applies to memory pressure and high efficiency mode discarding.\r\nA discarded page is unloaded and its resources fully reclaimed. The tab its associated with remains in the tabstrip, but making it visible will trigger a full reload.\r\n\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://*\r\n*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_1","displayName":"Enabled","description":null,"helpText":null}]},"59148408fe45e9db":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability","displayName":"Manage the deprecated prefixed video fullscreen API's availability (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_runtime-enabled","displayName":"Follows regular deprecation timelines for the PrefixedVideoFullscreen API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_disabled","displayName":"Disables prefixed video fullscreen APIs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_enabled","displayName":"Enables prefixed video fullscreen APIs","description":null,"helpText":null}]},"595dda2387304591":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81","displayName":"Default sheet direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81_1","displayName":"Right-to-Left","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81_0","displayName":"Left-to-Right","description":null,"helpText":null}]},"596df0fdea845b75":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab","displayName":"Show custom templates tab by default in Excel on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in Excel on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in Excel on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Excel on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},"590b73c9383e4dc8":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge (User)","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\r\n\r\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5970fd4009394089":{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins","displayName":"View XFA-based PDF files using IE Mode for allowed file origin. (User)","description":"Internet Explorer (IE) mode uses the Adobe Acrobat Active-X PDF Plugin to open XFA-based PDF files. This policy will only work if the Active-X plugin is already on the user's device, it's not installed as part of this policy.\r\n\r\nIt's important to note that XFA is a legacy technology that is deprecated by its original creators. It is not an ISO standard and as such, doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities.\r\n\r\nGiven the deprecated status of XFA technology and the lack of any investment by its creators, we strongly recommend that you start planning your transition to a more advanced HTML\\PDF form-based solutions.\r\n\r\nIn the interim, this policy provides a workaround for users to view XFA PDF in Microsoft Edge.\r\n\r\nIf you enable this policy, you can configure the list of origins from which XFA PDF files will be automatically opened in Microsoft Edge using IE Mode.\r\n\r\nIf you disable or don't configure the policy, XFA PDFs won't be considered for opening via Internet Explorer mode.\r\n\r\nFor detailed information on valid URL patterns, see - https://go.microsoft.com/fwlink/?linkid=2095322\r\n\r\nAlternatively, 'ViewXFAPDFInIEModeAllowedFileHash' (View XFA-based PDF files using IE Mode for allowed file hash.) can also be used to configure list of file hashes instead of URL origins, which will enable those files to be automatically opened in Microsoft Edge using IE Mode.\r\n\r\nExample value:\r\n\r\nhttps://contesso.sharepoint.com/accounts/\r\nhttps://contesso.sharepoint.com/transport/\r\nfile://account_forms/","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"59261371908359af":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (User)","description":"Configure the list of URL patterns for sites that the browser will attempt to perform the Token Binding protocol with.\r\nFor the domains on this list, the browser will send the Token Binding ClientHello in the TLS handshake (See https://tools.ietf.org/html/rfc8472).\r\nIf the server responds with a valid ServerHello response, the browser will create and send Token Binding messages on subsequent https requests. See https://tools.ietf.org/html/rfc8471 for more info.\r\n\r\nIf this list is empty, Token Binding will be disabled.\r\n\r\nThis policy is only available on Windows 10 devices with Virtual Secure Mode capability.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\n[*.]mydomain2.com\r\n[*.].mydomain2.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"59c83ce403ba3cd9":{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app (User)","description":"This setting lets you enable reporting of sites that might need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed into Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\r\n\r\nIf you configure this policy, Microsoft Edge will send a report to the M365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer engines several times. This usually indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report will show the URL of the site that is the redirect target, minus any query string or fragment. The user's identity isn't reported.\r\n\r\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the M365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge will still attempt to send reports if this step hasn't been completed. However, the reports will not be stored in the Site Lists app.\r\n\r\nWhen enabling this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will never send reports about potentially misconfigured neutral sites to the Site Lists app.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_1","displayName":"Enabled","description":null,"helpText":null}]},"5996ef16fa673c65":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicenotesdefaulturl7","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"59ee89204abb886a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen","displayName":"Arabic (Yemen) (User)","description":"Enables the editing language Arabic (Yemen)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen_1","displayName":"Enabled","description":null,"helpText":null}]},"59729c69225c5b08":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},"598a07e9aacef3e2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea","displayName":"Tigrinya (Eritrea) (User)","description":"Enables the editing language Tigrinya (Eritrea)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea_1","displayName":"Enabled","description":null,"helpText":null}]},"595c7621625ab3ec":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma","displayName":"Use system font instead of the Office default UI font (User)","description":"Use the system font instead of the Office default UI font. | Unchecked: Use the Office default UI font.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma_1","displayName":"Enabled","description":null,"helpText":null}]},"59ddb7386c957e22":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid","displayName":"[Deprecated] Connected experiences in Office that download online content (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid_1","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid_2","displayName":"Disabled","description":null,"helpText":null}]},"5952392716f6e5fc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits","displayName":"Configure invalid DSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid because of the number of DSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as invalid in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as invalid because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum DSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_1","displayName":"Enabled","description":null,"helpText":null}]},"59777fa612605fcb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat","displayName":"Allow PNG as an output format (User)","description":"This policy setting determines whether Office 2016 applications can output graphics in Portable Network Graphics (PNG) format when documents are saved as Web pages.\r\n\r\nIf you enable this policy setting, Office 2016 applications can save graphics in PNG format and users cannot change this configuration.\r\n\r\nIf you disable this policy setting, Office 2016 applications cannot save graphics in PNG format and users cannot change this configuration.\r\n\r\nIf you do not configure this policy setting, Office 2016 applications do not save graphics in the PNG format. Users can change this functionality by opening the application's Options dialog box, clicking Advanced, clicking Web Options, and selecting the Allow PNG as a graphics format check box.","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat_1","displayName":"Enabled","description":null,"helpText":null}]},"5997509c7ddaa81e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice","displayName":"Check if Office is the default editor for Web pages created in Office (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice_1","displayName":"Enabled","description":null,"helpText":null}]},"597878012aa28c1b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62_1","displayName":"True","description":null,"helpText":null}]},"59754055cbaaaac5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems","displayName":"Do not display reminders on Calendar items by default (User)","description":"By default, when users create Calendar items, the Reminder: check box in the item is set. By disabling this setting, you can change the default behavior so that the Reminder: check box is cleared by default .","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems_1","displayName":"Enabled","description":null,"helpText":null}]},"5958cf697d6ed274":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency","displayName":"EAS Sync Frequency (User)","description":"This policy setting allows you to specify the number of minutes that Outlook automatically syncs the users' Exchange ActiveSync (EAS) accounts.\r\n\r\nIf you enable this policy setting, you can specify the number of minutes.\r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically syncs the users’ EAS accounts every 59 minutes.","helpText":"","infoUrls":[],"categoryId":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","categoryName":"Exchange ActiveSync","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_1","displayName":"Enabled","description":null,"helpText":null}]},"59255cb2c0b9dfa1":{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel","displayName":"Junk E-mail protection level (User) (Deprecated)","description":"This policy setting controls your Junk E-mail protection level. The Junk E-mail Filter in Outlook helps to prevent junk e-mail messages, also known as spam, from cluttering user's Inbox. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n\r\nIf you enable this policy setting, you can select one of the four listed options available. After you select an option, users will not be able to change it.\r\n\r\nIf you disable this policy setting, Outlook reverts to the user-defined protection level.\r\n\r\nIf you do not configure this policy setting, users can change their junk e-mail filtering options.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},"59dc735210509d36":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"5977120fa021d0fc":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"5970466632e911a2":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage","displayName":"File tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage_1","displayName":"True","description":null,"helpText":null}]},"595a6fff50632e2f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"596bc9f169336711":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart","displayName":"Color for tracking insertions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_2","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_3","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_4","displayName":"Turquoise","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_5","displayName":"Bright Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_6","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_7","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_8","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_9","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_10","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_11","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_12","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_13","displayName":"Violet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_14","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_15","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_16","displayName":"Gray 50%","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_17","displayName":"Gray 25%","description":null,"helpText":null}]}} \ No newline at end of file +{"59a65b60b1d63f40":{"id":".globalpreferences_.globalpreferences","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"1829cdc1-1bed-4058-9aba-9b778cd3d955","categoryName":"Global Preferences","options":null},"59647e905ad71747":{"id":"com.apple.applicationaccess_safariacceptcookies","displayName":"Safari Accept Cookies","description":"This value defines the conditions under which the device accepts cookies. The user-facing settings changed in iOS 11, although the possible values remain the same. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_safariacceptcookies_0","displayName":"Prevent Cross-Site Tracking and Block All Cookies are enabled and the user canʼt disable either setting.","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariacceptcookies_1","displayName":"Prevent Cross-Site Tracking is enabled and the user canʼt disable it. Block All Cookies is not enabled, although the user can enable it.","description":null,"helpText":null},{"id":"com.apple.applicationaccess_safariacceptcookies_2","displayName":"Prevent Cross-Site Tracking is enabled and Block All Cookies is not enabled. The user can toggle either setting.","description":null,"helpText":null}]},"59bca7058192f801":{"id":"com.apple.cellular_attachapn_password","displayName":"Password","description":"The password for the APN.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":null},"5970974bbe55bc2b":{"id":"com.apple.dnssettings.managed_ondemandrules_item_ssidmatch","displayName":"SSID Match","description":"An array of SSIDs to match against the current network. If the network is not a Wi-Fi network or if the SSID does not appear in this array, the match fails. Omit this key and the corresponding array to match against any SSID.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},"59251eb09e97aac9":{"id":"com.apple.managedclient.preferences_urlblocklist","displayName":"Block access to a list of URLs","description":"Define a list of sites, based on URL patterns, that are blocked (your users can't load them).\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can define exceptions in the \"URLAllowlist\" policy. These policies are limited to 1000 entries; subsequent entries are ignored.\n\nNote that blocking internal 'edge://*' URLs isn't recommended - this may lead to unexpected errors.\n\nThis policy doesn't prevent the page from updating dynamically through JavaScript. For example, if you block 'contoso.com/abc', users might still be able to visit 'contoso.com' and click on a link to visit 'contoso.com/abc', as long as the page doesn't refresh.\n\nIf you don't configure this policy, no URLs are blocked.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#urlblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"598d800d600f97df":{"id":"com.apple.mcxmenuextras_pppoe.menu","displayName":"PPPoE","description":"If true, enables the PPPoE menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_pppoe.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_pppoe.menu_true","displayName":"True","description":null,"helpText":null}]},"590f42edd02dc4a4":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"59dfd58f293a5a6b":{"id":"contentcaching_peerlocalsubnetsonly","displayName":"Peer Local Subnets Only","description":"If `true`, the content cache only peers with other content caches on the same immediate local network, rather than with content caches that use the same public IP address as the device. When `PeerLocalSubnetsOnly` is `true`, it overrides the configuration of `PeerFilterRanges` and `PeerListenRanges`. If the network changes, the local network peering restrictions update appropriately. If `false`, the content cache defers to `PeerFilterRanges` and `PeerListenRanges` for configuring the peering restrictions.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_peerlocalsubnetsonly_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_peerlocalsubnetsonly_true","displayName":"Enabled","description":null,"helpText":null}]},"59b5c5a18081806e":{"id":"contentcaching_personalcachelimit","displayName":"Personal Cache Limit","description":"The maximum number of bytes of disk space to use for the personal content cache. The content cache limits the maximum value to the `CacheLimit` value. Set to `0` to use the overall `CacheLimit`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"5922720306d4e177":{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name","displayName":"Configure storage of BitLocker recovery information to AD DS:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name_1","displayName":"Store recovery passwords and key packages","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrecoveryoptions_osactivedirectorybackupdropdown_name_2","displayName":"Store recovery passwords only","description":null,"helpText":null}]},"59828e7aa6f30be7":{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver","displayName":"Allow Datagram Processing On Win Server","description":"This settings controls whether Network Protection is allowed to enable datagram processing on Windows Server. If false, the value of DisableDatagramProcessing will be ignored and default to disabling Datagram inspection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver_1","displayName":"Datagram processing on Windows Server is enabled.","description":"Datagram processing on Windows Server is enabled.","helpText":null},{"id":"device_vendor_msft_defender_configuration_allowdatagramprocessingonwinserver_0","displayName":"Datagram processing on Windows Server is disabled.","description":"Datagram processing on Windows Server is disabled.","helpText":null}]},"59094eae172dd0e7":{"id":"device_vendor_msft_defender_configuration_disablehttpparsing","displayName":"Disable Http Parsing","description":"This setting disables HTTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablehttpparsing_1","displayName":"HTTP parsing is disabled","description":"HTTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablehttpparsing_0","displayName":"HTTP parsing is enabled","description":"HTTP parsing is enabled","helpText":null}]},"5930e13b75b94c4b":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_transferrateop2","displayName":"Connection speed (Kbps):","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"59280d629b838816":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet","displayName":"Prohibit operation while in private network","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_prohibitonprivatenet_1","displayName":"True","description":null,"helpText":null}]},"59af6476acf22501":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"5973f1f22c0dcac4":{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer","displayName":"Send Intranet Trafficto Internet Explorer","description":"Sends all intranet traffic over to Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#sendintranettraffictointernetexplorer"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer_0","displayName":"Disabled","description":"All sites, including intranet sites, open in Microsoft Edge automatically.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_sendintranettraffictointernetexplorer_1","displayName":"Enabled","description":"Only intranet sites open in Internet Explorer 11 automatically.","helpText":null}]},"5927d97a5eb87737":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled","displayName":"Enable alternate error pages","description":"Setting the policy to True means Google Chrome uses alternate error pages built into (such as \"page not found\"). Setting the policy to False means Google Chrome never uses alternate error pages.\r\n\r\nIf you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alternateerrorpagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"59c967c1e0226277":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin","description":"\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing will be deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allows to re-enable cross-origin WebAssembly module sharing to offer a longer transition period in the deprecation process.\r\n\r\nWhen set to True, sites can send WebAssembly modules also cross-origin without restrictions.\r\n\r\nWhen set to False or not set, sites can only send WebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"59dd57beca3635d8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions.","description":"Extensions that connect to one of these origins will be be kept running as long as the port is connected.\r\n\r\nIf unset, the policy's default values will be used. These are app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\r\n- Smart Card Connector\r\n- Citrix Receiver (stable, beta, back-up)\r\n- VMware Horizon (stable, beta)\r\n\r\nIf set, the default value list is extended with the newly configured values. Both defaults and the policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.\r\n\r\nExample value:\r\n\r\nchrome-extension://abcdefghijklmnopabcdefghijklmnop/\r\nchrome-extension://bcdefghijklmnopabcdefghijklmnopa/","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_1","displayName":"Enabled","description":null,"helpText":null}]},"593597ed9cf1f83d":{"id":"device_vendor_msft_policy_config_experience_allowwindowsconsumerfeatures","displayName":"Allow Windows Consumer Features","description":"This policy allows IT admins to turn on experiences that are typically for consumers only, such as Start suggestions, Membership notifications, Post-OOBE app install and redirect tiles.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-experience#allowwindowsconsumerfeatures"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowwindowsconsumerfeatures_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowwindowsconsumerfeatures_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"59a6662f28c2a5a6":{"id":"device_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard","displayName":"Prevent running First Run wizard","description":"This policy setting prevents Internet Explorer from running the First Run wizard the first time a user starts the browser after installing Internet Explorer or Windows.\n\nIf you enable this policy setting, you must make one of the following choices:\n • Skip the First Run wizard, and go directly to the user's home page.\n • Skip the First Run wizard, and go directly to the \"Welcome to Internet Explorer\" webpage.\n\nStarting with Windows 8, the \"Welcome to Internet Explorer\" webpage is not available. The user's home page will display regardless of which option is chosen.\n\nIf you disable or do not configure this policy setting, Internet Explorer may run the First Run wizard the first time the browser is started after installation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablefirstrunwizard"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablefirstrunwizard_1","displayName":"Enabled","description":null,"helpText":null}]},"59ba779eb3a18c93":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},"593135ecbf649077":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients","displayName":"Network Security Minimum Session Security For NTLMSSP Based Clients","description":"Network security: Minimum session security for NTLM SSP based (including secure RPC) clients This security setting allows a client to require the negotiation of 128-bit encryption and/or NTLMv2 session security. These values are dependent on the LAN Manager Authentication Level security setting value. The options are: Require NTLMv2 session security: The connection will fail if NTLMv2 protocol is not negotiated. Require 128-bit encryption: The connection will fail if strong encryption (128-bit) is not negotiated. Default: Windows XP, Windows Vista, Windows 2000 Server, Windows Server 2003, and Windows Server 2008: No requirements. Windows 7 and Windows Server 2008 R2: Require 128-bit encryption","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_minimumsessionsecurityforntlmsspbasedclients"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients_0","displayName":"None","description":"None","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients_524288","displayName":"Require NTLMv2 session security","description":"Require NTLMv2 session security","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients_536870912","displayName":"Require 128-bit encryption","description":"Require 128-bit encryption","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_minimumsessionsecurityforntlmsspbasedclients_537395200","displayName":"Require NTLM and 128-bit encryption","description":"Require NTLM and 128-bit encryption","helpText":null}]},"59279a2c540447c3":{"id":"device_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_webcontentfilteringblockedcategories_webcontentfilteringblockedcategoriesdesc","displayName":"List of blocked categories (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"59338561f8873b0f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword","displayName":"Disable user name and password","description":"Disable user name and password","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_1","displayName":"Enabled","description":null,"helpText":null}]},"59a9d236b2ab9378":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_pptviewexe130","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_pptviewexe130_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_pptviewexe130_1","displayName":"True","description":null,"helpText":null}]},"598c40ae922e7bf9":{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakespluggedin","displayName":"Require a password when a computer wakes (plugged in)","description":"This policy setting specifies whether or not the user is prompted for a password when the system resumes from sleep.\n\nIf you enable or do not configure this policy setting, the user is prompted for a password when the system resumes from sleep.\n\nIf you disable this policy setting, the user is not prompted for a password when the system resumes from sleep.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-requirepasswordwhencomputerwakespluggedin"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakespluggedin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakespluggedin_1","displayName":"Enabled","description":null,"helpText":null}]},"593a014373fa609f":{"id":"device_vendor_msft_policy_config_remotemanagement_trustedhosts_trustedhosts_list","displayName":"TrustedHostsList:","description":"","helpText":"","infoUrls":[],"categoryId":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","categoryName":"Win RM Client","options":null},"590572b7a5da101d":{"id":"device_vendor_msft_policy_config_textinput_allowkeyboardtextsuggestions","displayName":"Allow Keyboard Text Suggestions","description":"Note The policy is only enforced in Windows 10 for desktop. Specifies whether text prediction is enabled or disabled for the on-screen keyboard, touch keyboard, and handwriting recognition tool. When this policy is set to disabled, text prediction is disabled. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#allowkeyboardtextsuggestions"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_allowkeyboardtextsuggestions_0","displayName":"Block","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_allowkeyboardtextsuggestions_1","displayName":"Allow","description":"Enabled.","helpText":null}]},"598ac053d42e807f":{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy","displayName":"Turn off automatic updates for Windows App","description":"Controls how the Windows App checks for and installs updates.\n\nIf you enable this policy, choose one of the following options:\n \n Enable updates: Windows App will automatically check for and install updates from all sources.\n Disable updates from all locations: Windows App will not check for or install updates from any source.\n Disable updates from the Microsoft Store: Windows App will not download updates from the Microsoft Store but may still update from other sources.\n Disable updates from non-store CDN location: Windows App will not download updates from non-store CDN sources but may still update from the Microsoft Store.\n\nIf you disable or do not configure this policy, automatic updates are enabled for Windows App.\n ","helpText":"","infoUrls":[],"categoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","categoryName":"Windows App","options":[{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"5974038feb17e3e4":{"id":"dnsproxy_visiblename","displayName":"Visible Name","description":"The name of the DNS proxy configuration that the system displays on the device.","helpText":null,"infoUrls":[],"categoryId":"4a6c4488-bbcf-4b5b-9156-7aa1b10a6010","categoryName":"DNS Proxy","options":null},"59b90277088e95ae":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},"598adfaea103589f":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"593c8d6aa5724d22":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"59b926d37051232d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},"59432db0c816ff16":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_pathcolon55","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"594f63ed99ebd94b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iaslogging","displayName":"IAS Logging (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-iaslogging"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iaslogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iaslogging_1","displayName":"Enabled","description":null,"helpText":null}]},"595a5679985ab1cf":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_wirednetworkpolicy","displayName":"Wired Network (IEEE 802.3) Policies (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-wirednetworkpolicy"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_wirednetworkpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_wirednetworkpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"594b46686bdc25b2":{"id":"user_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_1","displayName":"Tape Drives: Deny write access (User)","description":"This policy setting denies write access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denywrite-access-1"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"user_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_1_1","displayName":"Enabled","description":null,"helpText":null}]},"59beb453368d10db":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings","displayName":"Roaming Credentials (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_1","displayName":"True","description":null,"helpText":null}]},"592ad8a70aa0138e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended","displayName":"Print Headers and Footers (User)","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printheaderfooter_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"599d4aac281e4c58":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions","displayName":"URL pattern Exceptions to tab discarding (User)","description":"This policy makes it so that any URL matching one or more of the patterns it specifies (using the URLBlocklist filter format) will never be discarded by the browser.\r\nThis applies to memory pressure and high efficiency mode discarding.\r\nA discarded page is unloaded and its resources fully reclaimed. The tab its associated with remains in the tabstrip, but making it visible will trigger a full reload.\r\n\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://*\r\n*","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_tabdiscardingexceptions_1","displayName":"Enabled","description":null,"helpText":null}]},"59148408fe45e9db":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability","displayName":"Manage the deprecated prefixed video fullscreen API's availability (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_runtime-enabled","displayName":"Follows regular deprecation timelines for the PrefixedVideoFullscreen API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_disabled","displayName":"Disables prefixed video fullscreen APIs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_prefixedvideofullscreenapiavailability_enabled","displayName":"Enables prefixed video fullscreen APIs","description":null,"helpText":null}]},"595dda2387304591":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81","displayName":"Default sheet direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81_1","displayName":"Right-to-Left","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_l_defaultdirection81_0","displayName":"Left-to-Right","description":null,"helpText":null}]},"596df0fdea845b75":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab","displayName":"Show custom templates tab by default in Excel on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in Excel on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in Excel on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Excel on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},"590b73c9383e4dc8":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge (User)","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nThe Picture in Picture floating overlay button lets user to watch videos in a floating window on top of other windows.\r\n\r\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge_pictureinpictureoverlayenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5970fd4009394089":{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins","displayName":"View XFA-based PDF files using IE Mode for allowed file origin. (User)","description":"Internet Explorer (IE) mode uses the Adobe Acrobat Active-X PDF Plugin to open XFA-based PDF files. This policy will only work if the Active-X plugin is already on the user's device, it's not installed as part of this policy.\r\n\r\nIt's important to note that XFA is a legacy technology that is deprecated by its original creators. It is not an ISO standard and as such, doesn't align with the modern web architecture. Continued use poses potential risks and vulnerabilities.\r\n\r\nGiven the deprecated status of XFA technology and the lack of any investment by its creators, we strongly recommend that you start planning your transition to a more advanced HTML\\PDF form-based solutions.\r\n\r\nIn the interim, this policy provides a workaround for users to view XFA PDF in Microsoft Edge.\r\n\r\nIf you enable this policy, you can configure the list of origins from which XFA PDF files will be automatically opened in Microsoft Edge using IE Mode.\r\n\r\nIf you disable or don't configure the policy, XFA PDFs won't be considered for opening via Internet Explorer mode.\r\n\r\nFor detailed information on valid URL patterns, see - https://go.microsoft.com/fwlink/?linkid=2095322\r\n\r\nAlternatively, 'ViewXFAPDFInIEModeAllowedFileHash' (View XFA-based PDF files using IE Mode for allowed file hash.) can also be used to configure list of file hashes instead of URL origins, which will enable those files to be automatically opened in Microsoft Edge using IE Mode.\r\n\r\nExample value:\r\n\r\nhttps://contesso.sharepoint.com/accounts/\r\nhttps://contesso.sharepoint.com/transport/\r\nfile://account_forms/","helpText":"","infoUrls":[],"categoryId":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","categoryName":"PDF Reader","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~pdf_viewxfapdfiniemodeallowedorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"59261371908359af":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (User)","description":"Configure the list of URL patterns for sites that the browser will attempt to perform the Token Binding protocol with.\r\nFor the domains on this list, the browser will send the Token Binding ClientHello in the TLS handshake (See https://tools.ietf.org/html/rfc8472).\r\nIf the server responds with a valid ServerHello response, the browser will create and send Token Binding messages on subsequent https requests. See https://tools.ietf.org/html/rfc8471 for more info.\r\n\r\nIf this list is empty, Token Binding will be disabled.\r\n\r\nThis policy is only available on Windows 10 devices with Virtual Secure Mode capability.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\n[*.]mydomain2.com\r\n[*.].mydomain2.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"59c83ce403ba3cd9":{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app (User)","description":"This setting lets you enable reporting of sites that might need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed into Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\r\n\r\nIf you configure this policy, Microsoft Edge will send a report to the M365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer engines several times. This usually indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report will show the URL of the site that is the redirect target, minus any query string or fragment. The user's identity isn't reported.\r\n\r\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the M365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge will still attempt to send reports if this step hasn't been completed. However, the reports will not be stored in the Site Lists app.\r\n\r\nWhen enabling this policy, you must specify your O365 tenant ID. To learn more about finding your O365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will never send reports about potentially misconfigured neutral sites to the Site Lists app.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2165707\r\n\r\nExample value: aba95e58-070f-4784-8dcd-e5fd46c2c6d6","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_1","displayName":"Enabled","description":null,"helpText":null}]},"5996ef16fa673c65":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicenotesdefaulturl7","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"59ee89204abb886a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen","displayName":"Arabic (Yemen) (User)","description":"Enables the editing language Arabic (Yemen)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicyemen_1","displayName":"Enabled","description":null,"helpText":null}]},"59729c69225c5b08":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Serbian (Cyrillic, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_serbiancyrillicbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},"598a07e9aacef3e2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea","displayName":"Tigrinya (Eritrea) (User)","description":"Enables the editing language Tigrinya (Eritrea)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tigrinyaeritrea_1","displayName":"Enabled","description":null,"helpText":null}]},"595c7621625ab3ec":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma","displayName":"Use system font instead of the Office default UI font (User)","description":"Use the system font instead of the Office default UI font. | Unchecked: Use the Office default UI font.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_usesystemfontinsteadoftahoma_1","displayName":"Enabled","description":null,"helpText":null}]},"59ddb7386c957e22":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid","displayName":"[Deprecated] Connected experiences in Office that download online content (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid_1","displayName":"Enabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_officeexperiencesdownloadingcontent_l_officeexperiencesdownloadingcontentdropid_2","displayName":"Disabled","description":null,"helpText":null}]},"5952392716f6e5fc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits","displayName":"Configure invalid DSA public key size (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as invalid because of the number of DSA public key bits used in the digital signature.\r\n\r\nIf you enable this policy setting, you can specify the number of bits that Office treats as invalid in a digital signature. For example: 512, 768, etc.\r\n\r\nIf you don’t configure this policy setting, Office won’t treat any digital signatures as invalid because of the number of bits in the public key.\r\n\r\nEnabling this policy causes the minimum DSA public key size to be the next largest option.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignatureinvaliddsabits_1","displayName":"Enabled","description":null,"helpText":null}]},"59777fa612605fcb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat","displayName":"Allow PNG as an output format (User)","description":"This policy setting determines whether Office 2016 applications can output graphics in Portable Network Graphics (PNG) format when documents are saved as Web pages.\r\n\r\nIf you enable this policy setting, Office 2016 applications can save graphics in PNG format and users cannot change this configuration.\r\n\r\nIf you disable this policy setting, Office 2016 applications cannot save graphics in PNG format and users cannot change this configuration.\r\n\r\nIf you do not configure this policy setting, Office 2016 applications do not save graphics in the PNG format. Users can change this functionality by opening the application's Options dialog box, clicking Advanced, clicking Web Options, and selecting the Allow PNG as a graphics format check box.","helpText":"","infoUrls":[],"categoryId":"8ee1d8d2-582f-401b-927a-993016f4290d","categoryName":"Browsers","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_browsers_l_allowpngasanoutputformat_1","displayName":"Enabled","description":null,"helpText":null}]},"5997509c7ddaa81e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice","displayName":"Check if Office is the default editor for Web pages created in Office (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_checkifofficeisthedefaulteditorforwebpagescreatedinoffice_1","displayName":"Enabled","description":null,"helpText":null}]},"597878012aa28c1b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage62_1","displayName":"True","description":null,"helpText":null}]},"59754055cbaaaac5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems","displayName":"Do not display reminders on Calendar items by default (User)","description":"By default, when users create Calendar items, the Reminder: check box in the item is set. By disabling this setting, you can change the default behavior so that the Reminder: check box is cleared by default .","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_remindersoncalendaritems_1","displayName":"Enabled","description":null,"helpText":null}]},"5958cf697d6ed274":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency","displayName":"EAS Sync Frequency (User)","description":"This policy setting allows you to specify the number of minutes that Outlook automatically syncs the users' Exchange ActiveSync (EAS) accounts.\r\n\r\nIf you enable this policy setting, you can specify the number of minutes.\r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically syncs the users’ EAS accounts every 59 minutes.","helpText":"","infoUrls":[],"categoryId":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","categoryName":"Exchange ActiveSync","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_eas_l_eassyncfrequency_1","displayName":"Enabled","description":null,"helpText":null}]},"59255cb2c0b9dfa1":{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel","displayName":"Junk E-mail protection level (User) (Deprecated)","description":"This policy setting controls your Junk E-mail protection level. The Junk E-mail Filter in Outlook helps to prevent junk e-mail messages, also known as spam, from cluttering user's Inbox. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n\r\nIf you enable this policy setting, you can select one of the four listed options available. After you select an option, users will not be able to change it.\r\n\r\nIf you disable this policy setting, Outlook reverts to the user-defined protection level.\r\n\r\nIf you do not configure this policy setting, users can change their junk e-mail filtering options.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v6~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_junkemailprotectionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},"59dc735210509d36":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"5977120fa021d0fc":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc02_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"5970466632e911a2":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage","displayName":"File tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailsendthispage_1","displayName":"True","description":null,"helpText":null}]},"595a6fff50632e2f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"596bc9f169336711":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart","displayName":"Color for tracking insertions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_2","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_3","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_4","displayName":"Turquoise","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_5","displayName":"Bright Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_6","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_7","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_8","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_9","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_10","displayName":"Dark Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_11","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_12","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_13","displayName":"Violet","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_14","displayName":"Dark Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_15","displayName":"Dark Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_16","displayName":"Gray 50%","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_insertionscolor_l_insertionscolorpart_17","displayName":"Gray 25%","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/5a.json b/public/intune-definitions/5a.json index 995fc4a5c01a..d974aa33b7d9 100644 --- a/public/intune-definitions/5a.json +++ b/public/intune-definitions/5a.json @@ -1 +1 @@ -{"5a3c209aa40ff313":{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked","displayName":"Block date and time changes","description":"If 'True', prevents users from manually setting the date and time. If False, Intune doesn't change or update this setting. By default, the OS might allow users to the set date and time on the device. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked_true","displayName":"True","description":"True","helpText":null}]},"5a2c83bc48f090bc":{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification","displayName":"Allow Diagnostic Submission Modification","description":"If false, disables changing the diagnostic submission and app analytics settings in the Diagnostics & Usage UI in Settings. Requires a supervised device. Available in iOS 9.3.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification_true","displayName":"Enabled","description":null,"helpText":null}]},"5a0216197c17c80e":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"5a3a8129fdbafdb6":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"5a183467934e1da0":{"id":"com.apple.loginwindow_restartdisabledwhileloggedin","displayName":"Restart Disabled While Logged In","description":"If true, disables the Restart menu item when the user is logged in.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_restartdisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_restartdisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},"5aee2e3fcb24ed40":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_lcid","displayName":"Microsoft Teams classic LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"5ab870b18272b5ba":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_lcid","displayName":"OneDrive LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"5afb32088ecc18b5":{"id":"com.apple.managedclient.preferences_earlypreview","displayName":"Enable / disable early preview","description":"Whether EDR early preview features are enabled or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-early-preview"],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":[{"id":"com.apple.managedclient.preferences_earlypreview_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_earlypreview_true","displayName":"Enabled","description":null,"helpText":null}]},"5a95e70c60a0d5fc":{"id":"com.apple.managedclient.preferences_extensionallowedtypes","displayName":"Configure allowed extension types","description":"Controls which extension types can be installed and limits runtime access.\n\nThis setting defines the allowed types of extensions and which hosts they can interact with. The value is a list of strings, each of which should be one of the following: \"extension\", \"theme\", \"user_script\", and \"hosted_app\". See the Microsoft Edge extensions documentation for more information on these types.\n\nNote that this policy also affects extensions to be force-installed by using \"ExtensionInstallForcelist\" policy.\n\nIf you enable this policy, only extensions that match a type in the list are installed.\n\nIf you don't configure this policy, no restrictions on the acceptable extension types are enforced.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionallowedtypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"5ae64603a6e24c7c":{"id":"com.apple.managedclient.preferences_pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites","description":"Define a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pluginsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"5accd04c60230b51":{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss","displayName":"Automatic Restart On Power Loss","description":"If true, enables \"Start up automatically after a power failure.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss_1","displayName":"True","description":null,"helpText":null}]},"5a9022ff7c55c77a":{"id":"com.apple.mcxmenuextras_ink.menu","displayName":"Ink","description":"If true, enables the Ink menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ink.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ink.menu_true","displayName":"True","description":null,"helpText":null}]},"5ab242ccf8b34499":{"id":"com.apple.mcxprinting_defaultprinter","displayName":"Default Printer","description":"The default printer for the user.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},"5ae497eb9a4240ae":{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"5a1aab903b270477":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"5a598b712fb41eb7":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"5af21f237453f536":{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\n\nIf you enable or don't configure this policy, Microsoft Edge can initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running.\n\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker starts.\n\nThis is a temporary policy and is removed in version 144 of Microsoft Edge.\n\nFor more information on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"5a6c71c5ac094ee2":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended","displayName":"Show Home button on toolbar (users can override)","description":"Shows the Home button on Microsoft Edge's toolbar.\n\nEnable this policy to always show the Home button. Disable it to never show the button.\n\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"5a266f81700a54c0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended","displayName":"Wallet Donation Enabled (Deprecated) (users can override)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.\n\nThis policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"5a881a91a77ff156":{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled","displayName":"Password Expiration Protection Enabled ","description":"Use this setting to configure additional enforcement of maximum password age for the managed local administrator account.\n\nWhen this setting is enabled, planned password expiration that would result in a password age greater than that dictated by \"PasswordAgeDays\" policy is NOT allowed. When such expiration is detected, the password is changed immediately and the new password expiration date is set according to policy.\n\nIf not specified, this setting defaults to True.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled_false","displayName":"Allow configured password expiriration timestamp to exceed maximum password age","description":"Allow configured password expiriration timestamp to exceed maximum password age","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled_true","displayName":"Do not allow configured password expiriration timestamp to exceed maximum password age","description":"Do not allow configured password expiriration timestamp to exceed maximum password age","helpText":null}]},"5aa44a980d5d11b6":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess","displayName":"Configure Direct Access connections as a fast network connection","description":"This policy setting allows an administrator to define the Direct Access connection to be considered a fast network connection for the purposes of applying and updating Group Policy.\r\n\r\nWhen Group Policy detects the bandwidth speed of a Direct Access connection, the detection can sometimes fail to provide any bandwidth speed information. If Group Policy detects a bandwidth speed, Group Policy will follow the normal rules for evaluating if the Direct Access connection is a fast or slow network connection. If no bandwidth speed is detected, Group Policy will default to a slow network connection. This policy setting allows the administrator the option to override the default to slow network connection and instead default to using a fast network connection in the case that no network bandwidth speed is determined.\r\n\r\nNote: When Group Policy detects a slow network connection, Group Policy will only process those client side extensions configured for processing across a slow link (slow network connection).\r\n\r\nIf you enable this policy, when Group Policy cannot determine the bandwidth speed across Direct Access, Group Policy will evaluate the network connection as a fast link and process all client side extensions.\r\n\r\nIf you disable this setting or do not configure it, Group Policy will evaluate the network connection as a slow link and process only those client side extensions configured to process over a slow link.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-slowlinkdefaultfordirectaccess"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"5ae60be6abfcc204":{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},"5a03d99d1da3c87e":{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2","displayName":"Specify a custom active power plan","description":"This policy setting specifies the active power plan from a specified power plan’s GUID. The GUID for a custom power plan GUID can be retrieved by using powercfg, the power configuration command line tool. \r\n\r\nIf you enable this policy setting, you must specify a power plan, specified as a GUID using the following format: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX (For example, 103eea6e-9fcd-4544-a713-c282d8e50083), indicating the power plan to be active.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-customactiveschemeoverride-2"],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_1","displayName":"Enabled","description":null,"helpText":null}]},"5a4cde6cf99f5a9a":{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter","displayName":"Active Power Plan:","description":null,"helpText":"","infoUrls":[],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_381b4222-f694-41f0-9685-ff5bb260df2e","displayName":"Automatic (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_a1841308-3541-4fab-bc81-f71556f20b4a","displayName":"Power Saver","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c","displayName":"High Performance","description":null,"helpText":null}]},"5a7c333f0a3b6e89":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup","displayName":"Outlook 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Outlook 2016.\r\nMicrosoft Outlook 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Outlook 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Outlook 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Outlook 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016outlookbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"5a043840cda35ea5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting","displayName":"Default key generation setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting_1","displayName":"Allow all sites to use key generation","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting_2","displayName":"Do not allow any site to use key generation","description":null,"helpText":null}]},"5a409a1ca00d4134":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings","displayName":"Dynamic Code Settings","description":"This policy controls the dynamic code settings for Google Chrome.\r\n\r\nDisabling dynamic code improves the security of Google Chrome by preventing potentially hostile dynamic code and third-party code from making changes to Google Chrome's behavior, but might cause compatibility issues with third-party software (e.g. certain printer drivers) that must run inside the browser process.\r\n\r\nIf the policy is set to 0 - Default or left unset then Google Chrome will use the default settings.\r\n\r\nIf the policy is set to 1 - DisabledForBrowser then the Google Chrome browser process will be prevented from creating dynamic code.\r\n\r\nNote: Read more about process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"5acd4c760975c67e":{"id":"device_vendor_msft_policy_config_defender_excludedprocesses","displayName":"Excluded Processes","description":"Allows an administrator to specify a list of files opened by processes to ignore during a scan. ImportantThe process itself is not excluded from the scan, but can be by using the Defender/ExcludedPaths policy to exclude its path. Each file type must be separated by a |. For example, C:\\Example. exe|C:\\Example1. exe.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#excludedprocesses"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"5a32bab74ea1142c":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcsizeinmbs_odfcsizeinmbs","displayName":"Size In MBs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":null},"5a767e0a45c2f377":{"id":"device_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses","displayName":"Internet Explorer Processes","description":"Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server.\n\nThis policy setting determines whether Internet Explorer requires that all file-type information provided by Web servers be consistent. For example, if the MIME type of a file is text/plain but the MIME sniff indicates that the file is really an executable file, Internet Explorer renames the file by saving it in the Internet Explorer cache and changing its extension.\n\nIf you enable this policy setting, Internet Explorer requires consistent MIME data for all received files.\n\nIf you disable this policy setting, Internet Explorer will not require consistent MIME data for all received files.\n\nIf you do not configure this policy setting, Internet Explorer requires consistent MIME data for all received files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-consistentmimehandlinginternetexplorerprocesses"],"categoryId":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","categoryName":"Consistent Mime Handling","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},"5ae5f19b88a820b8":{"id":"device_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys","displayName":"Enable extended hot keys in Internet Explorer mode","description":"This policy setting lets admins enable extended Microsoft Edge Internet Explorer mode hotkeys, such as \"Ctrl+S\" to have \"Save as\" functionality.\n\nIf you enable this policy, extended hotkey functionality is enabled in Internet Explorer mode and work the same as Internet Explorer.\n\nIf you disable, or don't configure this policy, extended hotkeys will not work in Internet Explorer mode.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2102115","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-enableextendediemodehotkeys"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys_1","displayName":"Enabled","description":null,"helpText":null}]},"5ac4fae5b320b32b":{"id":"device_vendor_msft_policy_config_internetexplorer_jscriptreplacement","displayName":"Replace JScript by loading JScript9Legacy in place of JScript.","description":"This policy setting specifies whether JScript or JScript9Legacy is loaded.\n \nIf you enable this policy setting or not configured, JScript9Legacy will be loaded in situations where JScript is instantiated.\n\nIf you disable this policy, then JScript will be utilized.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-jscriptreplacement"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_jscriptreplacement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_jscriptreplacement_1","displayName":"Enabled","description":null,"helpText":null}]},"5ad1094ad8b32875":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"5a6f5a78c744a035":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_recoveryconsole_allowautomaticadministrativelogon","displayName":"Recovery Console Allow Automatic Administrative Logon","description":"Recovery console: Allow automatic administrative logon This security setting determines if the password for the Administrator account must be given before access to the system is granted. If this option is enabled, the Recovery Console does not require you to provide a password, and it automatically logs on to the system. Default: This policy is not defined and automatic administrative logon is not allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#recoveryconsole_allowautomaticadministrativelogon"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"5aed7ae1dd535207":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls","displayName":"Block images on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"5a8fd1a3a9028339":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed","displayName":"Enable the Search bar (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nEnables the search bar. When enabled, users can use the search bar to search the web from their desktop or from an application. The search bar provides a search box that shows web suggestions and opens all web searches in Microsoft Edge. The search box provides search (powered by Bing) and URL suggestions. The search bar can be launched from the \"More tools\" menu or jump list in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy:\r\nThe search bar will be automatically enabled for all profiles.\r\nThe option to enable the search bar at startup will be toggled on if the 'WebWidgetIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy is enabled.\r\nIf the 'WebWidgetIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup will be toggled off.\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge \"More tools\" menu. Users can launch the search bar from \"More tools\".\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge jump list menu. Users can launch the search bar from the Microsoft Edge jump list menu.\r\nThe search bar can be turned off by the \"Quit\" option in the System tray or by closing the search bar from the 3 dot menu. The search bar will be restarted on system reboot if auto-start is enabled.\r\n\r\n\r\nIf you disable this policy:\r\nThe search bar will be disabled for all profiles.\r\nThe option to launch the search bar from Microsoft Edge \"More tools\" menu will be disabled.\r\nThe option to launch the search bar from Microsoft Edge jump list menu will be disabled.\r\n\r\nThis policy is deprecated due to the deprecation of the Web widget's vertical layout. This policy will be made obsolete in 119 release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"5a7bd0b49be637ba":{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings","description":"Configures browsing data lifetime settings for Microsoft Edge.\r\nThis policy controls the lifetime of selected browsing data. This policy has no effect if Sync is enabled.\r\nThe available data types are the 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\nMicrosoft Edge will regularly remove data of selected types that is older than 'time_to_live_in_hours'. Because data deletion only happens at certain intervals, some data might be kept slightly longer but never more than twice its expected 'time_to_live_in_hours'.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ], \r\n \"time_to_live_in_hours\": 24\r\n }, \r\n {\r\n \"data_types\": [\r\n \"password_signin\", \r\n \"autofill\"\r\n ], \r\n \"time_to_live_in_hours\": 12\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},"5a2e1a088b457dd5":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode","displayName":"Print PostScript Mode","description":"Controls how Microsoft Edge prints on Microsoft Windows.\r\n\r\nPrinting to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance.\r\n\r\nIf you set this policy to Default, Microsoft Edge will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nIf you set this policy to Type42, Microsoft Edge will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will be in Default mode.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default\r\n\r\n* Type42 (1) = Type42\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},"5a8f361553269237":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity","displayName":"Local Machine Zone Lockdown Security","description":"Local Machine Zone Lockdown","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},"5a229b068d5dd121":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_powerpntexe157","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_powerpntexe157_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_powerpntexe157_1","displayName":"True","description":null,"helpText":null}]},"5a44701db75e58d0":{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autologoff","displayName":"Automatically log off users after inactive interval","description":"Automatically signs out of the Windows App after a period of inactivity. This does not sign the user out of any remote session.\n\nIf you enable this policy, specify the inactivity timeout in minutes. After the specified time of inactivity, the Windows App will automatically sign out.\n\nIf you disable or do not configure this policy, the Windows App will remain signed in regardless of inactivity.\n ","helpText":"","infoUrls":[],"categoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","categoryName":"Windows App","options":[{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autologoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autologoff_1","displayName":"Enabled","description":null,"helpText":null}]},"5aa29220901c0682":{"id":"device_vendor_msft_policy_config_windowslogon_disablelockscreenappnotifications","displayName":"Turn off app notifications on the lock screen","description":"This policy setting allows you to prevent app notifications from appearing on the lock screen.\n\nIf you enable this policy setting, no app notifications are displayed on the lock screen.\n\nIf you disable or do not configure this policy setting, users can choose which apps display notifications on the lock screen.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowslogon#windowslogon-disablelockscreenappnotifications"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_windowslogon_disablelockscreenappnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowslogon_disablelockscreenappnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"5ac688c56f838d27":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders22","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders22_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders22_1","displayName":"True","description":null,"helpText":null}]},"5a697b0d55d66f0f":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize84_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"6730f0be-a129-4b48-942f-e4ddf69fee66","categoryName":"Customizable Error Messages","options":null},"5a9348391f6cc457":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorunmacro","displayName":"Database Tools | Macro | Run Macro (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorunmacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorunmacro_1","displayName":"True","description":null,"helpText":null}]},"5a2becc61ac6ee09":{"id":"user_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_1","displayName":"Prevent restoring local previous versions (User)","description":"This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a local file.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a local file. If the user clicks the Restore button, Windows attempts to restore the file from the local disk.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a local file.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablelocalrestore-1"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"user_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_1_1","displayName":"Enabled","description":null,"helpText":null}]},"5a3b3483869ab7f4":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives","displayName":"Hide these specified drives in My Computer (User)","description":"This policy setting allows you to hide these specified drives in My Computer.\r\n\r\nThis policy setting allows you to remove the icons representing selected hard drives from My Computer and File Explorer. Also, the drive letters representing the selected drives do not appear in the standard Open dialog box.\r\n\r\nIf you enable this policy setting, select a drive or combination of drives in the drop-down list.\r\n\r\nNote: This policy setting removes the drive icons. Users can still gain access to drive contents by using other methods, such as by typing the path to a directory on the drive in the Map Network Drive dialog box, in the Run dialog box, or in a command window.\r\n\r\nAlso, this policy setting does not prevent users from using programs to access these drives or their contents. And, it does not prevent users from using the Disk Management snap-in to view and change drive characteristics.\r\n\r\nIf you disable or do not configure this policy setting, all drives are displayed, or select the \"Do not restrict drives\" option in the drop-down list.\r\n\r\nAlso, see the \"Prevent access to drives from My Computer\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nodrives"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_1","displayName":"Enabled","description":null,"helpText":null}]},"5a831745fe932ff6":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewondrive","displayName":"Prevent access to drives from My Computer (User)","description":"Prevents users from using My Computer to gain access to the content of selected drives.\r\n\r\nIf you enable this setting, users can browse the directory structure of the selected drives in My Computer or File Explorer, but they cannot open folders and access the contents. Also, they cannot use the Run dialog box or the Map Network Drive dialog box to view the directories on these drives.\r\n\r\nTo use this setting, select a drive or combination of drives from the drop-down list. To allow access to all drive directories, disable this setting or select the \"Do not restrict drives\" option from the drop-down list.\r\n\r\nNote: The icons representing the specified drives still appear in My Computer, but if users double-click the icons, a message appears explaining that a setting prevents the action.\r\n\r\n Also, this setting does not prevent users from using programs to access local and network drives. And, it does not prevent them from using the Disk Management snap-in to view and change drive characteristics.\r\n\r\nAlso, see the \"Hide these specified drives in My Computer\" setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-noviewondrive"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewondrive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewondrive_1","displayName":"Enabled","description":null,"helpText":null}]},"5a045df1cfea5310":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped. (User)","description":"\r\nThe display-capture permissions-policy gates access to getDisplayMedia(), as per this spec: https://www.w3.org/TR/screen-capture/#feature-policy-integration. However, if this policy is Disabled, this requirement is not enforced, and getDisplayMedia() is allowed from contexts that would otherwise be forbidden. This Enterprise policy is temporary; it's intended to be removed after Google Chrome version 100. It is intended to unblock Enterprise users whose application is non-spec compliant, but needs time to be fixed.\r\n\r\nWhen enabled or not set, sites can only call getDisplayMedia() from contexts which are allowlisted by the display-capture permissions-policy.\r\n\r\nWhen disabled, sites can call getDisplayMedia() even from contexts which are not allowlisted by the display-capture permissions policy. Note that other restrictions may still apply.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5a8692d590c40443":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_securitykeypermitattestationdesc","displayName":"URLs/domains automatically permitted direct Security Key attestation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"5a7c9909d44e7e95":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled","displayName":"Enable Native Window Occlusion (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5ae82b8ec9388e9c":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_webhidallowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"5ad5345ffded38e2":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings","displayName":"Settings for AI-powered History Search (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_0","displayName":"Allow AI History Search and improve AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_1","displayName":"Allow AI History Search without improving AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_2","displayName":"Do not allow AI History Search.","description":null,"helpText":null}]},"5a3a9ce95ca2d49a":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":null},"5ad72e853c057209":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed","displayName":"Allow Safe Browsing Proxied Real Time Checks (User)","description":"This controls whether Safe Browsing's standard protection mode is allowed to\r\nsend partial hashes of URLs to Google through a proxy via Oblivious HTTP\r\nin order to determine whether they are safe to visit.\r\n\r\nThe proxy allows browsers to upload partial hashes of URLs to Google\r\nwithout them being linked to the user's IP address. The policy also allows\r\nbrowsers to upload the partial hashes of URLs with higher frequency for\r\nbetter Safe Browsing protection quality.\r\n\r\nThis policy will be ignored if Safe Browsing is disabled or set to enhanced\r\nprotection mode.\r\n\r\nSetting the policy to Enabled or leaving it unset allows the\r\nhigher-protection proxied lookups.\r\n\r\nSetting the policy to Disabled disallows the higher-protection proxied\r\nlookups. Partial hashes of URLs will be uploaded to Google directly with much\r\nlower frequency, which will degrade protection.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"5acec4f88db93d5a":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},"5a7379295a85ead5":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"5a2d400f3d5202d6":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled","displayName":"Enable sign-in to Microsoft Edge using non-Microsoft accounts (User)","description":"This policy controls whether users can sign in to Microsoft Edge using non-Microsoft accounts, such as Google or Apple accounts.\n\nIf you enable this policy or don't configure it, users can sign in to Microsoft Edge with non-Microsoft accounts when the feature is available. Related sign-in entry points, such as Google or Apple sign-in buttons in the profile flyout and unified sign-in experience, are shown when available.\n\nIf you disable this policy, users can't sign in to Microsoft Edge with non-Microsoft accounts. Related sign-in entry points and code paths are hidden and disabled, regardless of related feature flag settings.\n\nUsers can still sign in with Microsoft accounts.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5a62e8128a1d27d8":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge (User)","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"5a38f933757b2a6e":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (User)","description":"Setting this policy defines the return value of Managed Configuration API for given origin.\r\n\r\nManaged Configuration API is a key-value configuration that can be accessed via navigator.device.getManagedConfiguration() javascript call. This API is only available to origins which correspond to force-installed web applications via 'WebAppInstallForceList' (Configure list of force-installed Web Apps).\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"managed_configuration_hash\": \"asd891jedasd12ue9h\",\r\n \"managed_configuration_url\": \"https://static.contoso.com/configuration.json\",\r\n \"origin\": \"https://www.contoso.com\"\r\n },\r\n {\r\n \"managed_configuration_hash\": \"djio12easd89u12aws\",\r\n \"managed_configuration_url\": \"https://static.contoso.com/configuration2.json\",\r\n \"origin\": \"https://www.example.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_1","displayName":"Enabled","description":null,"helpText":null}]},"5a072d276de01611":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled","displayName":"Enable new SmartScreen library (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107.\r\n\r\nThis policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client.\r\n\r\nAllows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will use the new SmartScreen library (libSmartScreenN).\r\n\r\nIf you disable this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nBefore Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.\r\nThis also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5ad6e3fdff9cb1c1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint","displayName":"Turn off AutoSave by default in PowerPoint (User)","description":"This policy setting allows you to turn off AutoSave by default in PowerPoint. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in PowerPoint. But, the user can enable AutoSave for PowerPoint by going to File > Options > Save. Or, the user can enable AutoSave for a specific PowerPoint file by using the AutoSave toggle in the title bar.\r\n \r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n \r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"5afd081aabf07493":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverinfo2","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"5a20d94c3b964ed2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project","displayName":"Microsoft Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project_1","displayName":"True","description":null,"helpText":null}]},"5aa09ae8bebd1555":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation","displayName":"Disable user from setting personal site as default location (User)","description":"Checked: User is not able to define the default location to the personal site. | Unchecked: Default location is not restricted.","helpText":"","infoUrls":[],"categoryId":"13123148-c522-437f-b316-d78f5cc0d28d","categoryName":"Shared Workspace","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation_1","displayName":"Enabled","description":null,"helpText":null}]},"5a7cfd2e13509fce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo","displayName":"Use local user name and initials values regardless of signed-in user (User)","description":"This policy setting controls whether Office uses the user name and initials of the user currently signed-in, or the user name and initials that are specified in the Options dialog box.\r\n\r\nIf you enable this policy setting, regardless of any user currently signed-in, Office uses the user name and initials specified in the Options dialog box.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the user name and initials from the information provided by the user that is currently signed-in.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo_1","displayName":"Enabled","description":null,"helpText":null}]},"5a3b00cbfa8ebf66":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7","displayName":"Workflow Cache 7 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_1","displayName":"Enabled","description":null,"helpText":null}]},"5ab5ee6edd8645bb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces","displayName":"Default servers and data for Meeting Workspaces (User)","description":"Using this policy, you can define default servers and server data for Meeting Workspaces. It is recommended that you draft this policy in a text editor and paste it into the text box in the setting. You can add up to five servers by listing them in the \"Default server:\" text box. Each server is defined by a pipe-delimited list, with a total of six pipes per server record. The OrganizerName field is left blank. For example: http://server1 | Friendly name for server1 | templateLCID | templateID | TemplateName | OrganizerName | http://server2 | ... and so on. For more information, see the Office 2016 Resource Kit on TechNet.","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_1","displayName":"Enabled","description":null,"helpText":null}]},"5add5ec057c89bf9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview","displayName":"Do not allow horizontal calendar view (User)","description":"This policy setting allows you to prevent horizontal calendar view.\r\n\r\nIf you enable this policy setting, horizontal calendar view is not allowed.\r\n\r\nIf you disable or do not configure this policy setting, horizontal calendar view is allowed.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview_1","displayName":"Enabled","description":null,"helpText":null}]},"5a0abb07b8653d9d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts","displayName":"Prevent personal Microsoft accounts from using MAPI (User)","description":"This policy setting governs whether personal Microsoft accounts can be configured to use MAPI in Outlook.\r\n\r\nA personal Microsoft account is an account hosted on Outlook.com, Hotmail.com, Live.com, Msn.com or any variation on those domains.\r\n\r\nIf you enable this policy, users won’t be able to configure a personal Microsoft account to use MAPI in Outlook.\r\n\r\nThis means that in the Add Account dialog box in Outlook, users must choose “Manual setup or additional server types,” then choose Next, and then choose “POP or IMAP.”\r\n\r\nIf you disable or don’t configure this policy setting, users can configure a personal Microsoft account to use MAPI in Outlook. They can do this by choosing “E-mail” account in the Add Account dialog box.\r\n\r\nNote that personal Microsoft accounts that are configured to use MAPI will be automatically configured to use Cached Exchange Mode, and this can’t be changed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts_1","displayName":"Enabled","description":null,"helpText":null}]},"5a8880fd936aa860":{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension","displayName":"Recommend the Microsoft Outlook Extension (User)","description":"This policy setting controls whether Windows 10 users of the Outlook app and the Outlook web app will see a recommendation to install the new Microsoft Outlook extension for Microsoft Edge. If a user chooses to click the recommendation, they will be taken to the Microsoft Outlook extension page where they can choose to install this web-based, productivity add on. Your users can dismiss the recommendation and will only see the recommendation twice. If your users choose to install the extension, they will be able to access their mail, calendar, contacts, and tasks from an icon in Microsoft Edge without requiring that they open another browser tab. The extension is a “mini” version of Outlook on the web which operates as a one-click flyout from the browser header.\r\n\r\nIn the future, Microsoft may release a version of this extension for the Chrome browser. Microsoft will respect this policy for future promotions of a Chrome extension, as well.\r\n\r\nIf you enable or do not configure this policy setting, the recommendation will be presented to the user.\r\n\r\nIf you disable this policy setting, the recommendation will not be presented to the user.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise and Outlook web app.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2165458","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension_1","displayName":"Enabled","description":null,"helpText":null}]},"5a5793858368dc46":{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin","displayName":"Deactivate Outlook web add-ins whose equivalent COM or VSTO add-in is installed (User)","description":"This policy setting allows you to deactivate Outlook web add-ins if the associated COM or VSTO add-in is installed.\r\n\r\nIf you enable this policy setting, users will not be able to use Outlook web add-ins where the corresponding COM or VSTO add-in is installed and you have provided the following information for each add-in.\r\n \"Value name\": Specify the Id of the Outlook web add-in, as noted in its manifest. Note: Do not add {} around the Id.\r\n \"Value\": Specify the programmatic ID (ProgID) for the Outlook COM or VSTO add-in.\r\n\r\nIf you disable or don't configure this policy setting, users will continue to be able to use any versions of the add-in that are installed.\r\n\r\nFor more information about when to use this setting, see https://go.microsoft.com/fwlink/p/?linkid=2156690","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_1","displayName":"Enabled","description":null,"helpText":null}]},"5a88ee782d37c6bb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions","displayName":"Stop checking for media files which might need captions (User)","description":"This policy setting prevents the Accessibility Checker from flagging media files that might need caption information.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging media files that might need caption information.\r\n\r\nIf you disable or do not configure this policy setting, presentations will be scanned for media files and the results will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions_1","displayName":"Enabled","description":null,"helpText":null}]},"5adb7a99d916ef09":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16","displayName":"Week starts on (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_6","displayName":"Saturday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_0","displayName":"Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_1","displayName":"Monday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_4","displayName":"Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_5","displayName":"Friday","description":null,"helpText":null}]},"5a3fd6f6f3237eac":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"5a7561c8ad115315":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter","displayName":"Prompt user to setup printer (User)","description":"When set, Publisher will show a prompt to the user to start the Printer Setup Wizard when a new printer is found.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter_1","displayName":"Enabled","description":null,"helpText":null}]},"5aabd30ade1f7ada":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay_l_setmaximumnumberofmruitemstodisplayspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":null},"5afee95a1b29cc29":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"Specify command bar buttons and menu items to disable.","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"5a2af52f9f05336e":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"5a62d8ceccf60a34":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint","displayName":"Don't show the option to transform a document to a Sway web page (User)","description":"This policy setting controls whether the File menu option to transform a Word document to a Sway web page is shown to the user. By default, this option is shown to the user.\r\n\r\nIf you enable this policy setting, the File menu option to transform a Word document to a Sway web page is hidden from the user. \r\n\r\nIf you disable or don't configure this policy setting, the File menu option to transform a Word document to a Sway web page is shown to the user.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"5a3c209aa40ff313":{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked","displayName":"Block date and time changes","description":"If 'True', prevents users from manually setting the date and time. If False, Intune doesn't change or update this setting. By default, the OS might allow users to the set date and time on the device. Available for fully managed, dedicated and corporate-owned work profile (at work profile level) devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.datetimeconfigurationblocked_true","displayName":"True","description":"True","helpText":null}]},"5a2c83bc48f090bc":{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification","displayName":"Allow Diagnostic Submission Modification","description":"If false, disables changing the diagnostic submission and app analytics settings in the Diagnostics & Usage UI in Settings. Requires a supervised device. Available in iOS 9.3.2 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdiagnosticsubmissionmodification_true","displayName":"Enabled","description":null,"helpText":null}]},"5a0216197c17c80e":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"5a3a8129fdbafdb6":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekend-allowance_end","displayName":"End","description":"The curfew end time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"5a183467934e1da0":{"id":"com.apple.loginwindow_restartdisabledwhileloggedin","displayName":"Restart Disabled While Logged In","description":"If true, disables the Restart menu item when the user is logged in.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":[{"id":"com.apple.loginwindow_restartdisabledwhileloggedin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.loginwindow_restartdisabledwhileloggedin_true","displayName":"True","description":null,"helpText":null}]},"5aee2e3fcb24ed40":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams classic.app_lcid","displayName":"Microsoft Teams classic LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"5ab870b18272b5ba":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_onedrive.app_lcid","displayName":"OneDrive LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"5afb32088ecc18b5":{"id":"com.apple.managedclient.preferences_earlypreview","displayName":"Enable / disable early preview","description":"Whether EDR early preview features are enabled or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-early-preview"],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":[{"id":"com.apple.managedclient.preferences_earlypreview_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_earlypreview_true","displayName":"Enabled","description":null,"helpText":null}]},"5a95e70c60a0d5fc":{"id":"com.apple.managedclient.preferences_extensionallowedtypes","displayName":"Configure allowed extension types","description":"Controls which extension types can be installed and limits runtime access.\n\nThis setting defines the allowed types of extensions and which hosts they can interact with. The value is a list of strings, each of which should be one of the following: \"extension\", \"theme\", \"user_script\", and \"hosted_app\". See the Microsoft Edge extensions documentation for more information on these types.\n\nNote that this policy also affects extensions to be force-installed by using \"ExtensionInstallForcelist\" policy.\n\nIf you enable this policy, only extensions that match a type in the list are installed.\n\nIf you don't configure this policy, no restrictions on the acceptable extension types are enforced.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensionallowedtypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"5ae64603a6e24c7c":{"id":"com.apple.managedclient.preferences_pluginsallowedforurls","displayName":"Allow the Adobe Flash plug-in on specific sites","description":"Define a list of sites, based on URL patterns, that can run the Adobe Flash plug-in.\n\nIf you don't configure this policy, the global default value from the \"DefaultPluginsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#pluginsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"5accd04c60230b51":{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss","displayName":"Automatic Restart On Power Loss","description":"If true, enables \"Start up automatically after a power failure.\"","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_automatic restart on power loss_1","displayName":"True","description":null,"helpText":null}]},"5a9022ff7c55c77a":{"id":"com.apple.mcxmenuextras_ink.menu","displayName":"Ink","description":"If true, enables the Ink menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ink.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ink.menu_true","displayName":"True","description":null,"helpText":null}]},"5ab242ccf8b34499":{"id":"com.apple.mcxprinting_defaultprinter","displayName":"Default Printer","description":"The default printer for the user.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},"5ae497eb9a4240ae":{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"5a1aab903b270477":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"5a598b712fb41eb7":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicysysadminfiles_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"5af21f237453f536":{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"This policy controls whether Microsoft Edge enables the ServiceWorkerAutoPreload feature.\n\nIf you enable or don't configure this policy, Microsoft Edge can initiate the main resource network request concurrently with the Service Worker bootstrap process. This can improve performance in scenarios where the Service Worker isn't already running.\n\nIf you disable this policy, Microsoft Edge will wait to dispatch the navigation request until after the Service Worker starts.\n\nThis is a temporary policy and is removed in version 144 of Microsoft Edge.\n\nFor more information on the feature, see https://github.com/WICG/service-worker-auto-preload.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.serviceworkerautopreloadenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"5a6c71c5ac094ee2":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended","displayName":"Show Home button on toolbar (users can override)","description":"Shows the Home button on Microsoft Edge's toolbar.\n\nEnable this policy to always show the Home button. Disable it to never show the button.\n\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showhomebutton_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"5a266f81700a54c0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended","displayName":"Wallet Donation Enabled (Deprecated) (users can override)","description":"The Wallet Donation feature in Microsoft Edge allows users to view their donation summary, explore Nonprofit organizations (NPOs), donate to an NPO, manage their monthly donations, and view their donation history.\n\nIf you enable or don't configure this policy, users can use the Wallet Donation feature.\n\nIf you disable this policy, users can't use the Wallet Donation feature.\n\nThis policy is deprecated because the Wallet Donation feature has been removed from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.walletdonationenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"5ad332990c891ef3":{"id":"contentcaching_listenranges_item_type","displayName":"Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_listenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"contentcaching_listenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},"5a881a91a77ff156":{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled","displayName":"Password Expiration Protection Enabled ","description":"Use this setting to configure additional enforcement of maximum password age for the managed local administrator account.\n\nWhen this setting is enabled, planned password expiration that would result in a password age greater than that dictated by \"PasswordAgeDays\" policy is NOT allowed. When such expiration is detected, the password is changed immediately and the new password expiration date is set according to policy.\n\nIf not specified, this setting defaults to True.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":[{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled_false","displayName":"Allow configured password expiriration timestamp to exceed maximum password age","description":"Allow configured password expiriration timestamp to exceed maximum password age","helpText":null},{"id":"device_vendor_msft_laps_policies_passwordexpirationprotectionenabled_true","displayName":"Do not allow configured password expiriration timestamp to exceed maximum password age","description":"Do not allow configured password expiriration timestamp to exceed maximum password age","helpText":null}]},"5aa44a980d5d11b6":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess","displayName":"Configure Direct Access connections as a fast network connection","description":"This policy setting allows an administrator to define the Direct Access connection to be considered a fast network connection for the purposes of applying and updating Group Policy.\r\n\r\nWhen Group Policy detects the bandwidth speed of a Direct Access connection, the detection can sometimes fail to provide any bandwidth speed information. If Group Policy detects a bandwidth speed, Group Policy will follow the normal rules for evaluating if the Direct Access connection is a fast or slow network connection. If no bandwidth speed is detected, Group Policy will default to a slow network connection. This policy setting allows the administrator the option to override the default to slow network connection and instead default to using a fast network connection in the case that no network bandwidth speed is determined.\r\n\r\nNote: When Group Policy detects a slow network connection, Group Policy will only process those client side extensions configured for processing across a slow link (slow network connection).\r\n\r\nIf you enable this policy, when Group Policy cannot determine the bandwidth speed across Direct Access, Group Policy will evaluate the network connection as a fast link and process all client side extensions.\r\n\r\nIf you disable this setting or do not configure it, Group Policy will evaluate the network connection as a slow link and process only those client side extensions configured to process over a slow link.\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-slowlinkdefaultfordirectaccess"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_slowlinkdefaultfordirectaccess_1","displayName":"Enabled","description":null,"helpText":null}]},"5ae60be6abfcc204":{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectupdatefailurespolicy_detectupdatefailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},"5a03d99d1da3c87e":{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2","displayName":"Specify a custom active power plan","description":"This policy setting specifies the active power plan from a specified power plan’s GUID. The GUID for a custom power plan GUID can be retrieved by using powercfg, the power configuration command line tool. \r\n\r\nIf you enable this policy setting, you must specify a power plan, specified as a GUID using the following format: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX (For example, 103eea6e-9fcd-4544-a713-c282d8e50083), indicating the power plan to be active.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-customactiveschemeoverride-2"],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_customactiveschemeoverride_2_1","displayName":"Enabled","description":null,"helpText":null}]},"5a4cde6cf99f5a9a":{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter","displayName":"Active Power Plan:","description":null,"helpText":"","infoUrls":[],"categoryId":"290ec637-e780-4e95-9834-6368ac0437d1","categoryName":"Power Management","options":[{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_381b4222-f694-41f0-9685-ff5bb260df2e","displayName":"Automatic (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_a1841308-3541-4fab-bc81-f71556f20b4a","displayName":"Power Saver","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_inboxactiveschemeoverride_2_inboxactiveschemeoverrideenter_8c5e7fda-e8bf-4a96-9a85-a6e23a8c635c","displayName":"High Performance","description":null,"helpText":null}]},"5a7c333f0a3b6e89":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup","displayName":"Outlook 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Outlook 2016.\r\nMicrosoft Outlook 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Outlook 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Outlook 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Outlook 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016outlookbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016outlookbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"5a043840cda35ea5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting","displayName":"Default key generation setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting_1","displayName":"Allow all sites to use key generation","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultkeygensetting_defaultkeygensetting_2","displayName":"Do not allow any site to use key generation","description":null,"helpText":null}]},"5a409a1ca00d4134":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings","displayName":"Dynamic Code Settings","description":"This policy controls the dynamic code settings for Google Chrome.\r\n\r\nDisabling dynamic code improves the security of Google Chrome by preventing potentially hostile dynamic code and third-party code from making changes to Google Chrome's behavior, but might cause compatibility issues with third-party software (e.g. certain printer drivers) that must run inside the browser process.\r\n\r\nIf the policy is set to 0 - Default or left unset then Google Chrome will use the default settings.\r\n\r\nIf the policy is set to 1 - DisabledForBrowser then the Google Chrome browser process will be prevented from creating dynamic code.\r\n\r\nNote: Read more about process mitigation policies ( https://chromium.googlesource.com/chromium/src/+/HEAD/docs/design/sandbox.md#Process-mitigation-policies ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_dynamiccodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"5acd4c760975c67e":{"id":"device_vendor_msft_policy_config_defender_excludedprocesses","displayName":"Excluded Processes","description":"Allows an administrator to specify a list of files opened by processes to ignore during a scan. ImportantThe process itself is not excluded from the scan, but can be by using the Defender/ExcludedPaths policy to exclude its path. Each file type must be separated by a |. For example, C:\\Example. exe|C:\\Example1. exe.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#excludedprocesses"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"5a32bab74ea1142c":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcsizeinmbs_odfcsizeinmbs","displayName":"Size In MBs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":null},"5a767e0a45c2f377":{"id":"device_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses","displayName":"Internet Explorer Processes","description":"Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server.\n\nThis policy setting determines whether Internet Explorer requires that all file-type information provided by Web servers be consistent. For example, if the MIME type of a file is text/plain but the MIME sniff indicates that the file is really an executable file, Internet Explorer renames the file by saving it in the Internet Explorer cache and changing its extension.\n\nIf you enable this policy setting, Internet Explorer requires consistent MIME data for all received files.\n\nIf you disable this policy setting, Internet Explorer will not require consistent MIME data for all received files.\n\nIf you do not configure this policy setting, Internet Explorer requires consistent MIME data for all received files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-consistentmimehandlinginternetexplorerprocesses"],"categoryId":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","categoryName":"Consistent Mime Handling","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},"5ae5f19b88a820b8":{"id":"device_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys","displayName":"Enable extended hot keys in Internet Explorer mode","description":"This policy setting lets admins enable extended Microsoft Edge Internet Explorer mode hotkeys, such as \"Ctrl+S\" to have \"Save as\" functionality.\n\nIf you enable this policy, extended hotkey functionality is enabled in Internet Explorer mode and work the same as Internet Explorer.\n\nIf you disable, or don't configure this policy, extended hotkeys will not work in Internet Explorer mode.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2102115","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-enableextendediemodehotkeys"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_enableextendediemodehotkeys_1","displayName":"Enabled","description":null,"helpText":null}]},"5ac4fae5b320b32b":{"id":"device_vendor_msft_policy_config_internetexplorer_jscriptreplacement","displayName":"Replace JScript by loading JScript9Legacy in place of JScript.","description":"This policy setting specifies whether JScript or JScript9Legacy is loaded.\n \nIf you enable this policy setting or not configured, JScript9Legacy will be loaded in situations where JScript is instantiated.\n\nIf you disable this policy, then JScript will be utilized.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-jscriptreplacement"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_jscriptreplacement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_jscriptreplacement_1","displayName":"Enabled","description":null,"helpText":null}]},"5ad1094ad8b32875":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"5a6f5a78c744a035":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_recoveryconsole_allowautomaticadministrativelogon","displayName":"Recovery Console Allow Automatic Administrative Logon","description":"Recovery console: Allow automatic administrative logon This security setting determines if the password for the Administrator account must be given before access to the system is granted. If this option is enabled, the Recovery Console does not require you to provide a password, and it automatically logs on to the system. Default: This policy is not defined and automatic administrative logon is not allowed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#recoveryconsole_allowautomaticadministrativelogon"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"5aed7ae1dd535207":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls","displayName":"Block images on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultImagesSetting' (Default images setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"5a8fd1a3a9028339":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed","displayName":"Enable the Search bar (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nEnables the search bar. When enabled, users can use the search bar to search the web from their desktop or from an application. The search bar provides a search box that shows web suggestions and opens all web searches in Microsoft Edge. The search box provides search (powered by Bing) and URL suggestions. The search bar can be launched from the \"More tools\" menu or jump list in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy:\r\nThe search bar will be automatically enabled for all profiles.\r\nThe option to enable the search bar at startup will be toggled on if the 'WebWidgetIsEnabledOnStartup' (Allow the Search bar at Windows startup) policy is enabled.\r\nIf the 'WebWidgetIsEnabledOnStartup' is disabled or not configured, the option to enable the search bar at startup will be toggled off.\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge \"More tools\" menu. Users can launch the search bar from \"More tools\".\r\nUsers will see the menu item to launch the search bar from the Microsoft Edge jump list menu. Users can launch the search bar from the Microsoft Edge jump list menu.\r\nThe search bar can be turned off by the \"Quit\" option in the System tray or by closing the search bar from the 3 dot menu. The search bar will be restarted on system reboot if auto-start is enabled.\r\n\r\n\r\nIf you disable this policy:\r\nThe search bar will be disabled for all profiles.\r\nThe option to launch the search bar from Microsoft Edge \"More tools\" menu will be disabled.\r\nThe option to launch the search bar from Microsoft Edge jump list menu will be disabled.\r\n\r\nThis policy is deprecated due to the deprecation of the Web widget's vertical layout. This policy will be made obsolete in 119 release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"5a7bd0b49be637ba":{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings","description":"Configures browsing data lifetime settings for Microsoft Edge.\r\nThis policy controls the lifetime of selected browsing data. This policy has no effect if Sync is enabled.\r\nThe available data types are the 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\nMicrosoft Edge will regularly remove data of selected types that is older than 'time_to_live_in_hours'. Because data deletion only happens at certain intervals, some data might be kept slightly longer but never more than twice its expected 'time_to_live_in_hours'.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ], \r\n \"time_to_live_in_hours\": 24\r\n }, \r\n {\r\n \"data_types\": [\r\n \"password_signin\", \r\n \"autofill\"\r\n ], \r\n \"time_to_live_in_hours\": 12\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},"5a2e1a088b457dd5":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode","displayName":"Print PostScript Mode","description":"Controls how Microsoft Edge prints on Microsoft Windows.\r\n\r\nPrinting to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance.\r\n\r\nIf you set this policy to Default, Microsoft Edge will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nIf you set this policy to Type42, Microsoft Edge will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will be in Default mode.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default\r\n\r\n* Type42 (1) = Type42\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},"5a8f361553269237":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity","displayName":"Local Machine Zone Lockdown Security","description":"Local Machine Zone Lockdown","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},"5a229b068d5dd121":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_powerpntexe157","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_powerpntexe157_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_powerpntexe157_1","displayName":"True","description":null,"helpText":null}]},"5a44701db75e58d0":{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autologoff","displayName":"Automatically log off users after inactive interval","description":"Automatically signs out of the Windows App after a period of inactivity. This does not sign the user out of any remote session.\n\nIf you enable this policy, specify the inactivity timeout in minutes. After the specified time of inactivity, the Windows App will automatically sign out.\n\nIf you disable or do not configure this policy, the Windows App will remain signed in regardless of inactivity.\n ","helpText":"","infoUrls":[],"categoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","categoryName":"Windows App","options":[{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autologoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autologoff_1","displayName":"Enabled","description":null,"helpText":null}]},"5aa29220901c0682":{"id":"device_vendor_msft_policy_config_windowslogon_disablelockscreenappnotifications","displayName":"Turn off app notifications on the lock screen","description":"This policy setting allows you to prevent app notifications from appearing on the lock screen.\n\nIf you enable this policy setting, no app notifications are displayed on the lock screen.\n\nIf you disable or do not configure this policy setting, users can choose which apps display notifications on the lock screen.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowslogon#windowslogon-disablelockscreenappnotifications"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_windowslogon_disablelockscreenappnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowslogon_disablelockscreenappnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"5ac688c56f838d27":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders22","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders22_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders22_1","displayName":"True","description":null,"helpText":null}]},"5a697b0d55d66f0f":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize84_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"6730f0be-a129-4b48-942f-e4ddf69fee66","categoryName":"Customizable Error Messages","options":null},"5a9348391f6cc457":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorunmacro","displayName":"Database Tools | Macro | Run Macro (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorunmacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrorunmacro_1","displayName":"True","description":null,"helpText":null}]},"5a2becc61ac6ee09":{"id":"user_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_1","displayName":"Prevent restoring local previous versions (User)","description":"This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a local file.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a local file. If the user clicks the Restore button, Windows attempts to restore the file from the local disk.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a local file.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablelocalrestore-1"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"user_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_1_1","displayName":"Enabled","description":null,"helpText":null}]},"5a3b3483869ab7f4":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives","displayName":"Hide these specified drives in My Computer (User)","description":"This policy setting allows you to hide these specified drives in My Computer.\r\n\r\nThis policy setting allows you to remove the icons representing selected hard drives from My Computer and File Explorer. Also, the drive letters representing the selected drives do not appear in the standard Open dialog box.\r\n\r\nIf you enable this policy setting, select a drive or combination of drives in the drop-down list.\r\n\r\nNote: This policy setting removes the drive icons. Users can still gain access to drive contents by using other methods, such as by typing the path to a directory on the drive in the Map Network Drive dialog box, in the Run dialog box, or in a command window.\r\n\r\nAlso, this policy setting does not prevent users from using programs to access these drives or their contents. And, it does not prevent users from using the Disk Management snap-in to view and change drive characteristics.\r\n\r\nIf you disable or do not configure this policy setting, all drives are displayed, or select the \"Do not restrict drives\" option in the drop-down list.\r\n\r\nAlso, see the \"Prevent access to drives from My Computer\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nodrives"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_1","displayName":"Enabled","description":null,"helpText":null}]},"5a831745fe932ff6":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewondrive","displayName":"Prevent access to drives from My Computer (User)","description":"Prevents users from using My Computer to gain access to the content of selected drives.\r\n\r\nIf you enable this setting, users can browse the directory structure of the selected drives in My Computer or File Explorer, but they cannot open folders and access the contents. Also, they cannot use the Run dialog box or the Map Network Drive dialog box to view the directories on these drives.\r\n\r\nTo use this setting, select a drive or combination of drives from the drop-down list. To allow access to all drive directories, disable this setting or select the \"Do not restrict drives\" option from the drop-down list.\r\n\r\nNote: The icons representing the specified drives still appear in My Computer, but if users double-click the icons, a message appears explaining that a setting prevents the action.\r\n\r\n Also, this setting does not prevent users from using programs to access local and network drives. And, it does not prevent them from using the Disk Management snap-in to view and change drive characteristics.\r\n\r\nAlso, see the \"Hide these specified drives in My Computer\" setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-noviewondrive"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewondrive_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewondrive_1","displayName":"Enabled","description":null,"helpText":null}]},"5a045df1cfea5310":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped. (User)","description":"\r\nThe display-capture permissions-policy gates access to getDisplayMedia(), as per this spec: https://www.w3.org/TR/screen-capture/#feature-policy-integration. However, if this policy is Disabled, this requirement is not enforced, and getDisplayMedia() is allowed from contexts that would otherwise be forbidden. This Enterprise policy is temporary; it's intended to be removed after Google Chrome version 100. It is intended to unblock Enterprise users whose application is non-spec compliant, but needs time to be fixed.\r\n\r\nWhen enabled or not set, sites can only call getDisplayMedia() from contexts which are allowlisted by the display-capture permissions-policy.\r\n\r\nWhen disabled, sites can call getDisplayMedia() even from contexts which are not allowlisted by the display-capture permissions policy. Note that other restrictions may still apply.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_displaycapturepermissionspolicyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5a8692d590c40443":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_securitykeypermitattestationdesc","displayName":"URLs/domains automatically permitted direct Security Key attestation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"5a7c9909d44e7e95":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled","displayName":"Enable Native Window Occlusion (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_nativewindowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5ae82b8ec9388e9c":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowdevicesforurls_webhidallowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices with the given vendor and product IDs. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"5ad5345ffded38e2":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings","displayName":"Settings for AI-powered History Search (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_0","displayName":"Allow AI History Search and improve AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_1","displayName":"Allow AI History Search without improving AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_historysearchsettings_2","displayName":"Do not allow AI History Search.","description":null,"helpText":null}]},"5a3a9ce95ca2d49a":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~relatedwebsitesets_relatedwebsitesetsoverrides_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","categoryName":"Related Website Sets Settings","options":null},"5ad72e853c057209":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed","displayName":"Allow Safe Browsing Proxied Real Time Checks (User)","description":"This controls whether Safe Browsing's standard protection mode is allowed to\r\nsend partial hashes of URLs to Google through a proxy via Oblivious HTTP\r\nin order to determine whether they are safe to visit.\r\n\r\nThe proxy allows browsers to upload partial hashes of URLs to Google\r\nwithout them being linked to the user's IP address. The policy also allows\r\nbrowsers to upload the partial hashes of URLs with higher frequency for\r\nbetter Safe Browsing protection quality.\r\n\r\nThis policy will be ignored if Safe Browsing is disabled or set to enhanced\r\nprotection mode.\r\n\r\nSetting the policy to Enabled or leaving it unset allows the\r\nhigher-protection proxied lookups.\r\n\r\nSetting the policy to Disabled disallows the higher-protection proxied\r\nlookups. Partial hashes of URLs will be uploaded to Google directly with much\r\nlower frequency, which will degrade protection.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingproxiedrealtimechecksallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"5acec4f88db93d5a":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount","displayName":"Set CNG password spin count (User)","description":"This policy setting allows you to specify the number of times to spin (rehash) the password verifier.\r\n\r\nIf you enable this policy setting, the number specified will be the number of times the password will be rehashed.\r\n\r\nIf you disable or do not configure this policy setting, the default (100000) will be used.","helpText":"","infoUrls":[],"categoryId":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_cryptography_l_setcngpasswordspincount_1","displayName":"Enabled","description":null,"helpText":null}]},"5a7379295a85ead5":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"5a2d400f3d5202d6":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled","displayName":"Enable sign-in to Microsoft Edge using non-Microsoft accounts (User)","description":"This policy controls whether users can sign in to Microsoft Edge using non-Microsoft accounts, such as Google or Apple accounts.\n\nIf you enable this policy or don't configure it, users can sign in to Microsoft Edge with non-Microsoft accounts when the feature is available. Related sign-in entry points, such as Google or Apple sign-in buttons in the profile flyout and unified sign-in experience, are shown when available.\n\nIf you disable this policy, users can't sign in to Microsoft Edge with non-Microsoft accounts. Related sign-in entry points and code paths are hidden and disabled, regardless of related feature flag settings.\n\nUsers can still sign in with Microsoft accounts.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~identity_nonmicrosoftaccountsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5a62e8128a1d27d8":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates","displayName":"TLS server certificates that should be trusted by Microsoft Edge (User)","description":"This policy enables a list of TLS certificates that should be trusted by Microsoft Edge for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"5a38f933757b2a6e":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (User)","description":"Setting this policy defines the return value of Managed Configuration API for given origin.\r\n\r\nManaged Configuration API is a key-value configuration that can be accessed via navigator.device.getManagedConfiguration() javascript call. This API is only available to origins which correspond to force-installed web applications via 'WebAppInstallForceList' (Configure list of force-installed Web Apps).\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"managed_configuration_hash\": \"asd891jedasd12ue9h\",\r\n \"managed_configuration_url\": \"https://static.contoso.com/configuration.json\",\r\n \"origin\": \"https://www.contoso.com\"\r\n },\r\n {\r\n \"managed_configuration_hash\": \"djio12easd89u12aws\",\r\n \"managed_configuration_url\": \"https://static.contoso.com/configuration2.json\",\r\n \"origin\": \"https://www.example.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_1","displayName":"Enabled","description":null,"helpText":null}]},"5a072d276de01611":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled","displayName":"Enable new SmartScreen library (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107.\r\n\r\nThis policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client.\r\n\r\nAllows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will use the new SmartScreen library (libSmartScreenN).\r\n\r\nIf you disable this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nBefore Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.\r\nThis also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge~smartscreen_newsmartscreenlibraryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5ad6e3fdff9cb1c1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint","displayName":"Turn off AutoSave by default in PowerPoint (User)","description":"This policy setting allows you to turn off AutoSave by default in PowerPoint. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in PowerPoint. But, the user can enable AutoSave for PowerPoint by going to File > Options > Save. Or, the user can enable AutoSave for a specific PowerPoint file by using the AutoSave toggle in the title bar.\r\n \r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n \r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"5afd081aabf07493":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceserverinfo2","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"5a20d94c3b964ed2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project","displayName":"Microsoft Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_project_1","displayName":"True","description":null,"helpText":null}]},"5aa09ae8bebd1555":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation","displayName":"Disable user from setting personal site as default location (User)","description":"Checked: User is not able to define the default location to the personal site. | Unchecked: Default location is not restricted.","helpText":"","infoUrls":[],"categoryId":"13123148-c522-437f-b316-d78f5cc0d28d","categoryName":"Shared Workspace","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize~l_sharedworkspace_l_disableuserfromsettingpersonalsiteasdefaultlocation_1","displayName":"Enabled","description":null,"helpText":null}]},"5a7cfd2e13509fce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo","displayName":"Use local user name and initials values regardless of signed-in user (User)","description":"This policy setting controls whether Office uses the user name and initials of the user currently signed-in, or the user name and initials that are specified in the Options dialog box.\r\n\r\nIf you enable this policy setting, regardless of any user currently signed-in, Office uses the user name and initials specified in the Options dialog box.\r\n\r\nIf you disable or do not configure this policy setting, Office uses the user name and initials from the information provided by the user that is currently signed-in.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_uselocaluserinfo_1","displayName":"Enabled","description":null,"helpText":null}]},"5a3b00cbfa8ebf66":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7","displayName":"Workflow Cache 7 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_1","displayName":"Enabled","description":null,"helpText":null}]},"5ab5ee6edd8645bb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces","displayName":"Default servers and data for Meeting Workspaces (User)","description":"Using this policy, you can define default servers and server data for Meeting Workspaces. It is recommended that you draft this policy in a text editor and paste it into the text box in the setting. You can add up to five servers by listing them in the \"Default server:\" text box. Each server is defined by a pipe-delimited list, with a total of six pipes per server record. The OrganizerName field is left blank. For example: http://server1 | Friendly name for server1 | templateLCID | templateID | TemplateName | OrganizerName | http://server2 | ... and so on. For more information, see the Office 2016 Resource Kit on TechNet.","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_defaultserversanddataformeetingworkspaces_1","displayName":"Enabled","description":null,"helpText":null}]},"5add5ec057c89bf9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview","displayName":"Do not allow horizontal calendar view (User)","description":"This policy setting allows you to prevent horizontal calendar view.\r\n\r\nIf you enable this policy setting, horizontal calendar view is not allowed.\r\n\r\nIf you disable or do not configure this policy setting, horizontal calendar view is allowed.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_donotallowhorizontalcalendarview_1","displayName":"Enabled","description":null,"helpText":null}]},"5a0abb07b8653d9d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts","displayName":"Prevent personal Microsoft accounts from using MAPI (User)","description":"This policy setting governs whether personal Microsoft accounts can be configured to use MAPI in Outlook.\r\n\r\nA personal Microsoft account is an account hosted on Outlook.com, Hotmail.com, Live.com, Msn.com or any variation on those domains.\r\n\r\nIf you enable this policy, users won’t be able to configure a personal Microsoft account to use MAPI in Outlook.\r\n\r\nThis means that in the Add Account dialog box in Outlook, users must choose “Manual setup or additional server types,” then choose Next, and then choose “POP or IMAP.”\r\n\r\nIf you disable or don’t configure this policy setting, users can configure a personal Microsoft account to use MAPI in Outlook. They can do this by choosing “E-mail” account in the Add Account dialog box.\r\n\r\nNote that personal Microsoft accounts that are configured to use MAPI will be automatically configured to use Cached Exchange Mode, and this can’t be changed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disableexchangeconsumeraccounts_1","displayName":"Enabled","description":null,"helpText":null}]},"5a8880fd936aa860":{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension","displayName":"Recommend the Microsoft Outlook Extension (User)","description":"This policy setting controls whether Windows 10 users of the Outlook app and the Outlook web app will see a recommendation to install the new Microsoft Outlook extension for Microsoft Edge. If a user chooses to click the recommendation, they will be taken to the Microsoft Outlook extension page where they can choose to install this web-based, productivity add on. Your users can dismiss the recommendation and will only see the recommendation twice. If your users choose to install the extension, they will be able to access their mail, calendar, contacts, and tasks from an icon in Microsoft Edge without requiring that they open another browser tab. The extension is a “mini” version of Outlook on the web which operates as a one-click flyout from the browser header.\r\n\r\nIn the future, Microsoft may release a version of this extension for the Chrome browser. Microsoft will respect this policy for future promotions of a Chrome extension, as well.\r\n\r\nIf you enable or do not configure this policy setting, the recommendation will be presented to the user.\r\n\r\nIf you disable this policy setting, the recommendation will not be presented to the user.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise and Outlook web app.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2165458","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v8~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_recommendoutlookextension_1","displayName":"Enabled","description":null,"helpText":null}]},"5a5793858368dc46":{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin","displayName":"Deactivate Outlook web add-ins whose equivalent COM or VSTO add-in is installed (User)","description":"This policy setting allows you to deactivate Outlook web add-ins if the associated COM or VSTO add-in is installed.\r\n\r\nIf you enable this policy setting, users will not be able to use Outlook web add-ins where the corresponding COM or VSTO add-in is installed and you have provided the following information for each add-in.\r\n \"Value name\": Specify the Id of the Outlook web add-in, as noted in its manifest. Note: Do not add {} around the Id.\r\n \"Value\": Specify the programmatic ID (ProgID) for the Outlook COM or VSTO add-in.\r\n\r\nIf you disable or don't configure this policy setting, users will continue to be able to use any versions of the add-in that are installed.\r\n\r\nFor more information about when to use this setting, see https://go.microsoft.com/fwlink/p/?linkid=2156690","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_1","displayName":"Enabled","description":null,"helpText":null}]},"5a88ee782d37c6bb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions","displayName":"Stop checking for media files which might need captions (User)","description":"This policy setting prevents the Accessibility Checker from flagging media files that might need caption information.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging media files that might need caption information.\r\n\r\nIf you disable or do not configure this policy setting, presentations will be scanned for media files and the results will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingformediafilescaptions_1","displayName":"Enabled","description":null,"helpText":null}]},"5adb7a99d916ef09":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16","displayName":"Week starts on (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_6","displayName":"Saturday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_0","displayName":"Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_1","displayName":"Monday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_4","displayName":"Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjweekstarts_l_pjweekstarts16_5","displayName":"Friday","description":null,"helpText":null}]},"5a3fd6f6f3237eac":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"5a7561c8ad115315":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter","displayName":"Prompt user to setup printer (User)","description":"When set, Publisher will show a prompt to the user to start the Printer Setup Wizard when a new printer is found.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_promptusertosetupprinter_1","displayName":"Enabled","description":null,"helpText":null}]},"5aabd30ade1f7ada":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setmaximumnumberofmruitemstodisplay_l_setmaximumnumberofmruitemstodisplayspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":null},"5afee95a1b29cc29":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"Specify command bar buttons and menu items to disable.","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"5a2af52f9f05336e":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_descriptioncolon46","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"5a62d8ceccf60a34":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint","displayName":"Don't show the option to transform a document to a Sway web page (User)","description":"This policy setting controls whether the File menu option to transform a Word document to a Sway web page is shown to the user. By default, this option is shown to the user.\r\n\r\nIf you enable this policy setting, the File menu option to transform a Word document to a Sway web page is hidden from the user. \r\n\r\nIf you disable or don't configure this policy setting, the File menu option to transform a Word document to a Sway web page is shown to the user.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_digitalprint_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/5b.json b/public/intune-definitions/5b.json index 57fd22c3d8e4..e6b24a3e7538 100644 --- a/public/intune-definitions/5b.json +++ b/public/intune-definitions/5b.json @@ -1 +1 @@ -{"5b6617f085870b50":{"id":"ade_setupassistant_intelligence","displayName":"Intelligence","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_intelligence_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_intelligence_1","displayName":"Show","description":null,"helpText":null}]},"5b0c7ec16f23efde":{"id":"com.apple.cellularprivatenetwork.managed_networkidentifier","displayName":"Network Identifier","description":"A string using the 3GPP \"Coordinated NID\" (option 1 or option 2) format (defined in 3GPP 31.102, Section 12.7.1). The device uses this value to match a SIM present on the device.\n\nAll combinations of `NetworkIdentifier` and `CsgNetworkIdentifier` must be unique across all profiles installed on the device.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"5b171ed595863657":{"id":"com.apple.dictionary_parentalcontrol","displayName":"Parental Control","description":"If true, enables parental controls dictionary restrictions.","helpText":null,"infoUrls":[],"categoryId":"65087b94-7e45-4d74-a50d-df4377b67499","categoryName":"Parental Controls Dictionary","options":[{"id":"com.apple.dictionary_parentalcontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dictionary_parentalcontrol_true","displayName":"True","description":null,"helpText":null}]},"5bb15c85d6c8a78b":{"id":"com.apple.dock_size-immutable","displayName":"Size Immutable","description":"If true, locks the size slider.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_size-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_size-immutable_true","displayName":"True","description":null,"helpText":null}]},"5ba52e99ea4dcec4":{"id":"com.apple.managedclient.preferences_linkedaccountenabled","displayName":"Enable the linked account feature (Deprecated)","description":"Microsoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.\n\nIf you enable or don't configure this policy, linked account information will be shown on a flyout. When the Azure AD profile doesn't have a linked account it will show \"Add account\".\n\nIf you disable this policy, linked accounts will be turned off and no extra information will be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#linkedaccountenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_linkedaccountenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_linkedaccountenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"5baed40f555d2c30":{"id":"com.apple.managedclient.preferences_mandatoryextensionsforinprivatenavigation","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode","description":"This policy lets you specify a list of extension IDs that must be explicitly allowed by the user to run in InPrivate mode in order to enable InPrivate browsing.\n\nIf users don't allow all listed extensions to run in InPrivate mode, they'll be unable to navigate using InPrivate.\n\nIf any extension in the list isn't installed, InPrivate navigation is blocked.\n\nThis policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#mandatoryextensionsforinprivatenavigation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"5b1dbd769483a0d1":{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon will be shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\n\nThis policy only applies when users are accessing Copilot in the sidepane.\n\nIf the policy is enabled: Copilot will appear in the toolbar.\n\nIf the policy is disabled: Copilot won't appear in the toolbar.\n\nIf the policy isn't configured: Otherwise, Copilot shows in the toolbar and users may enable or disable Copilot from showing by using the Show Copilot toggle in settings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsoft365copilotchaticonenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"5b50761a5abb8ef4":{"id":"com.apple.mcx.filevault2_userecoverykey","displayName":"Use Recovery Key","description":"If true, creates a personal recovery key and displays it to the user.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":{"id":"com.apple.mcx.filevault2_userecoverykey_true","displayName":"Enabled","description":null,"helpText":null}},"5b766469e8a422fa":{"id":"com.apple.system-extension-policy_allowedsystemextensions","displayName":"Allowed System Extensions","description":"A dictionary of approved system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension to install. It’s an error for the same team identifier to appear in both the AllowedTeamIdentifiers array and as a key in this dictionary.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"5b39d13a87f45913":{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence","displayName":"File Provider Presence","description":"Allows a File Provider application to know when the user is using files managed by the File Provider.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"5b34058cbb9cac2a":{"id":"com.apple.xsan.preferences_usedlc","displayName":"Use DLC","description":"If true, use the DLC for all volumes.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":[{"id":"com.apple.xsan.preferences_usedlc_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.xsan.preferences_usedlc_true","displayName":"True","description":null,"helpText":null}]},"5b85c4bd0d233508":{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeurlallowlist","displayName":"Allow access to a list of URLs in InPrivate mode.","description":"This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in \"InPrivateModeUrlBlocklist\". See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322).\n\nIf both this policy and \"InPrivateModeUrlBlocklist\" are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to \"URLBlocklist\" and \"URLAllowlist\".\n\nIf this policy is configured and \"InPrivateModeUrlBlocklist\" is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked.\n\nIf \"InPrivateModeAvailability\" is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist.\n\nIf this policy is not configured, no exceptions are applied to \"InPrivateModeUrlBlocklist\" or \"InPrivateModeAvailability\".\n\nThis policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the \"URLAllowlist\" policy.\n\nThis policy supports up to 1000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"5b3090f0739947b1":{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled","displayName":"Allow suggestions from local providers","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear.\n\nIf you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nSome features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"5bc995bbc6e166e0":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10_1","displayName":"True","description":null,"helpText":null}]},"5b694e2d67f94bf0":{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2","displayName":"Turn off the \"Order Prints\" picture task","description":"This policy setting specifies whether the \"Order Prints Online\" task is available from Picture Tasks in Windows folders.\r\n\r\nThe Order Prints Online Wizard is used to download a list of providers and allow users to order prints online.\r\n\r\nIf you enable this policy setting, the task \"Order Prints Online\" is removed from Picture Tasks in File Explorer folders.\r\n\r\nIf you disable or do not configure this policy setting, the task is displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremoveorderprints-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2_1","displayName":"Enabled","description":null,"helpText":null}]},"5b8296098c67b0fc":{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap","displayName":"Do not allow sessions without mutual CHAP","description":"If enabled then only those sessions that are configured for mutual CHAP may be established. If disabled then sessions that are configured for mutual CHAP or sessions not configured for mutual CHAP may be established.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-requiremutualchap"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap_1","displayName":"Enabled","description":null,"helpText":null}]},"5bbf1b24d5947b34":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel","displayName":"Microsoft Excel 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Excel 2013.\r\nBy default, the user settings of Microsoft Excel 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Excel 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel_1","displayName":"Enabled","description":null,"helpText":null}]},"5bb34481bad21740":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013","displayName":"Microsoft Office 365 PowerPoint 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_1","displayName":"Enabled","description":null,"helpText":null}]},"5bdf537513e7a193":{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate","displayName":"Prevent Automatic Updates","description":"This policy setting allows you to turn off do not show first use dialog boxes.\r\n\r\nIf you enable this policy setting, the Privacy Options and Installation Options dialog boxes are prevented from being displayed the first time a user starts Windows Media Player.\r\n\r\nThis policy setting prevents the dialog boxes which allow users to select privacy, file types, and other desktop options from being displayed when the Player is first started. Some of the options can be configured by using other Windows Media Player group policies.\r\n\r\nIf you disable or do not configure this policy setting, the dialog boxes are displayed when the user starts the Player for the first time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-disableautoupdate"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate_1","displayName":"Enabled","description":null,"helpText":null}]},"5be746d34f8c14da":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub","displayName":"Feedback Hub","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub_1","displayName":"True","description":null,"helpText":null}]},"5b1fc344fa7f1969":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},"5b27e1bebefe5a6a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls","displayName":"Allow images on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that may display images.\r\n\r\nLeaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nNote that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"5b089b401a03b37c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch to ServiceWorker-controlled URLs","description":"SpeculationRules prefetch can be issued to URLs that are controlled by\r\nServiceWorker. However, legacy code did not allow it and canceled the prefetch\r\nrequests. This policy enables to control the behavior.\r\n\r\nSetting this policy to Enabled or not set allows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is\r\nenabled). This is the current default behavior and is aligned with the\r\nspecifications.\r\n\r\nSetting this policy to Disabled disallows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs. This is the legacy behavior.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5ba86cd1fc53bf0c":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingrulecompilation","displayName":"Rule Compilation","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging Rule Compilation component.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\RuleCompilation\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingrulecompilation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingrulecompilation_1","displayName":"Enabled","description":null,"helpText":null}]},"5b6d0525c1190dfa":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcsiddirectorynamepattern","displayName":"SID Directory Name Pattern","description":"Specifies a string pattern used when creating a Profile or ODFC container folder. Use this setting to define how FSLogix will attempt to create a users Profile or ODFC container folder. FSLogix will use the VHDLocations or CCDLocations as the location where to create and this setting defines what to create.\r\n\r\nNOTE: When using this configuration setting, be sure the SIDDIRNameMatch value matches this setting.\r\n\r\n- This setting has NO EFFECT when FlipFlopProfileDirectoryName is enabled.\r\n- This setting has NO EFFECT when NoProfileContainingFolder is enabled.\r\n- NoProfileContainingFolder > FlipFlopProfileDirectoryName > SIDDirNamePattern (this setting)\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\SIDDirNamePattern\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"81eb92d0-acda-4ea2-8183-29ed5457276b","categoryName":"Container and Directory Naming","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcsiddirectorynamepattern_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcsiddirectorynamepattern_1","displayName":"Enabled","description":null,"helpText":null}]},"5b3435da518b13b6":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"5b95fc0d92fd3509":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowlessprivilegedsites"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"5b303d6eb8fced48":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_machineinactivitylimit","displayName":"[Deprecated] Interactive Logon Machine Inactivity Limit (Deprecated)","description":"Interactive logon: Machine inactivity limit. Windows notices inactivity of a logon session, and if the amount of inactive time exceeds the inactivity limit, then the screen saver will run, locking the session. Default: not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#localpoliciessecurityoptions-interactivelogon-machineinactivitylimit"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_machineinactivitylimit_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_machineinactivitylimit_1","displayName":"Enabled (session will lock after amount of inactive time exceeds the inactivity limit)","description":"Enabled (session will lock after amount of inactive time exceeds the inactivity limit)","helpText":null}]},"5bf569c42ba7653d":{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action","displayName":"Group and user action","description":"This Setting allows an administrator to manage local groups on a Device. Possible settings: 1. Update Group Membership: Update a group and add and/or remove members though the 'U' action. When using Update, existing group members that are not specified in the policy remain untouched. 2. Replace Group Membership: Restrict a group by replacing group membership through the 'R' action. When using Replace, existing group membership is replaced by the list of members specified in the add member section. This option works in the same way as a Restricted Group and any group members that are not specified in the policy are removed. Caution: If the same group is configured with both Replace and Update, then Replace will win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups"],"categoryId":"b86100f0-e4ae-4f93-9dae-dd253a96726f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action_add_update","displayName":"Add (Update)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action_remove_update","displayName":"Remove (Update)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action_add_restrict","displayName":"Add (Replace)","description":null,"helpText":null}]},"5b7d7fba6ca45c39":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\r\n\r\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\r\n\r\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\r\n\r\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_1","displayName":"Enabled","description":null,"helpText":null}]},"5bd25df4c04456fe":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_nativemessagingallowlistdesc","displayName":"Names of the native messaging hosts to exempt from the block list (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},"5b212df3c19df39e":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled","displayName":"Allow M365 authentication popups in work profiles","description":"This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles.\r\n\r\nWhen users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in.\r\n\r\nIf you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.\r\n\r\nIf you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5b47bfe0fe5b78e8":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_visioexe187","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_visioexe187_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_visioexe187_1","displayName":"True","description":null,"helpText":null}]},"5bdab7f9086a3ee6":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_outlookexe162","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_outlookexe162_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_outlookexe162_1","displayName":"True","description":null,"helpText":null}]},"5b79c508107ea86d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_vltosubscription","displayName":"Upgrade Office 2019 to Office 365 ProPlus","description":"This policy setting allows you to upgrade volume licensed versions of Office Professional Plus 2019 to Office 365 ProPlus.\r\n\r\nNote: For the user to be able to use Office 365 ProPlus, you must have purchased an Office 365 plan that includes Office 365 ProPlus, and you must have assigned the user a license to use Office 365 ProPlus.\r\n\r\nIf you enable this policy setting, the installed volume licensed version of Office 2019 on the user's computer will be upgraded to Office 365 ProPlus. We also recommend that you use Group Policy to specify an update path and an update channel for Office 365 ProPlus.\r\n\r\nNote: If there are volume licensed versions of Visio and Project on the user's computer, those won't be upgraded to Office 365 subscription versions.\r\n\r\nIf you disable or don't configure this policy setting, Office 2019 isn't automatically upgraded to Office 365 ProPlus. But, you can initiate the upgrade by using some other method, such as by using the Office Deployment Tool.","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_vltosubscription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_vltosubscription_1","displayName":"Enabled","description":null,"helpText":null}]},"5bfc570b9f1b51bb":{"id":"device_vendor_msft_policy_config_update_autorestartdeadlineperiodindays","displayName":"Auto Restart Deadline Period In Days","description":"For Quality Updates, this policy specifies the deadline in days before automatically executing a scheduled restart outside of active hours. The deadline can be set between 2 and 30 days from the time the restart is scheduled. The system will reboot on or after the specified deadline. The reboot is prioritized over any configured Active Hours and any existing system and user busy checks. Value type is integer. Default is 7 days. Supported values range: 2-30. Note that the PC must restart for certain updates to take effect. If you enable this policy, a restart will automatically occur the specified number of days after the restart was scheduled. If you disable or do not configure this policy, the PC will restart according to the default schedule. If any of the following two policies are enabled, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installations. Always automatically restart at scheduled time.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#autorestartdeadlineperiodindays"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"5bd0e35edab3d208":{"id":"device_vendor_msft_policy_privilegemanagement_systemsettingrules_{systemsettingrulename}_elevationaction","displayName":"Elevation action","description":"Specifies the elevation action for this system setting rule.","helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":[{"id":"device_vendor_msft_policy_privilegemanagement_systemsettingrules_{systemsettingrulename}_self","displayName":"User confirmed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_privilegemanagement_systemsettingrules_{systemsettingrulename}_automatic","displayName":"Automatic","description":null,"helpText":null}]},"5b3d86aedcdba858":{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_$type","displayName":"Type","description":null,"helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_$type_0","displayName":"Path","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_$type_1","displayName":"File extension","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_$type_2","displayName":"Process name","description":null,"helpText":null}]},"5bf2af543e851992":{"id":"softwareupdate_rapidsecurityresponse_enable","displayName":"Enable","description":"If set to 'false', Background Security Improvements aren't offered for user installation. The system can still install Background Security Improvements with Software Update and Enforce Latest configurations. If set to 'true', the system offers Background Security Improvements to the user.","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":[{"id":"softwareupdate_rapidsecurityresponse_enable_false","displayName":"False","description":null,"helpText":null},{"id":"softwareupdate_rapidsecurityresponse_enable_true","displayName":"True","description":null,"helpText":null}]},"5b3dbe4305bae49e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":null},"5b06cb48784ca5a1":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize84_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"6730f0be-a129-4b48-942f-e4ddf69fee66","categoryName":"Customizable Error Messages","options":null},"5b4b34e8b51f2a20":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent","displayName":"Consent level (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent_1","displayName":"Always ask before sending data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent_2","displayName":"Send parameters","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent_3","displayName":"Send parameters and safe additional data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent_4","displayName":"Send all data","description":null,"helpText":null}]},"5b25a0707f91235e":{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_activexcontrol","displayName":"ActiveX Control (User)","description":"Permits or prohibits use of this snap-in.\n\nIf you enable this setting, the snap-in is permitted. If you disable the setting, the snap-in is prohibited.\n\nIf this setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted.\n\n To explicitly permit use of this snap-in, enable this setting. If this setting is not configured (or disabled), this snap-in is prohibited.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited.\n\n To explicitly prohibit use of this snap-in, disable this setting. If this setting is not configured (or enabled), the snap-in is permitted.\n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmc#admx-mmc-mmc-activexcontrol"],"categoryId":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","categoryName":"Restricted Permitted snap-ins","options":[{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_activexcontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_activexcontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"5b0529afbb6a7f07":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ipsecmanage","displayName":"IP Security Policy Management (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-ipsecmanage"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ipsecmanage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ipsecmanage_1","displayName":"Enabled","description":null,"helpText":null}]},"5be1aadd4c15c842":{"id":"user_vendor_msft_policy_config_admx_pentraining_pentrainingoff_1","displayName":"Turn off Tablet PC Pen Training (User)","description":"Turns off Tablet PC Pen Training.\r\n\r\nIf you enable this policy setting, users cannot open Tablet PC Pen Training.\r\n\r\nIf you disable or do not configure this policy setting, users can open Tablet PC Pen Training.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pentraining#admx-pentraining-pentrainingoff-1"],"categoryId":"fe65603b-1980-446b-ae17-516eb885c6be","categoryName":"Tablet PC Pen Training","options":[{"id":"user_vendor_msft_policy_config_admx_pentraining_pentrainingoff_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_pentraining_pentrainingoff_1_1","displayName":"Enabled","description":null,"helpText":null}]},"5bb8e07c072eae73":{"id":"user_vendor_msft_policy_config_admx_sensors_disablesensors_1","displayName":"Turn off sensors (User)","description":"\r\n This policy setting turns off the sensor feature for this computer.\r\n\r\n If you enable this policy setting, the sensor feature is turned off, and all programs on this computer cannot use the sensor feature.\r\n\r\n If you disable or do not configure this policy setting, all programs on this computer can use the sensor feature.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sensors#admx-sensors-disablesensors-1"],"categoryId":"b40cfb22-8f17-4317-bcbb-c1c871497446","categoryName":"Location and Sensors","options":[{"id":"user_vendor_msft_policy_config_admx_sensors_disablesensors_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_sensors_disablesensors_1_1","displayName":"Enabled","description":null,"helpText":null}]},"5ba652029a52e5b2":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for profile types. (User)","description":"Configuring this policy will allow/disallow ambient authentication for Incognito and Guest profiles in Google Chrome.\r\n\r\nAmbient Authentication is http authentication with default credentials if explicit credentials are not provided via NTLM/Kerberos/Negotiate challenge/response schemes.\r\n\r\nSetting the RegularOnly (value 0), allows ambient authentication for Regular sessions only. Incognito and Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the IncognitoAndRegular (value 1), allows ambient authentication for Incognito and Regular sessions. Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the GuestAndRegular (value 2), allows ambient authentication for Guest and Regular sessions. Incognito sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the All (value 3), allows ambient authentication for all sessions.\r\n\r\nNote that, ambient authentication is always allowed on regular profiles.\r\n\r\nIn Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5ba329704b483a44":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled","displayName":"Browser experiments icon in toolbar (User)","description":"Setting the policy to Enabled or leaving the policy unset means that users can access browser experimental features through an icon in the toolbar\r\n\r\nSetting the policy to Disabled removes the browser experimental features icon from the toolbar.\r\n\r\nchrome://flags and any other means of turning off and on browser features will still behave as expected regardless of whether this policy is Enabled or Disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5b252404f57d88af":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata","displayName":"Import autofill form data from default browser on first run (User)","description":"Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.\r\n\r\nUsers can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata_1","displayName":"Enabled","description":null,"helpText":null}]},"5b505fb81e74e4c8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (User)","description":"Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices.\r\n\r\nLeaving the policy unset lets sites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"5be2abd3cad829bf":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level Native Messaging hosts (installed without admin permissions) (User)","description":"Setting the policy to Enabled or leaving it unset means Google Chrome can use native messaging hosts installed at the user level.\r\n\r\nSetting the policy to Disabled means Google Chrome can only use these hosts if installed at the system level.","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},"5b436792b18bda67":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls","displayName":"Block key generation on these sites (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"5b0261599ee71c96":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_ntpshortcuts","displayName":"Setting shortcuts on the New Tab Page (Beta) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"5b7e513c16885049":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},"5bc5537b18f1f36b":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_popupsallowedforurlsdesc","displayName":"Allow pop-up windows on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"5b005928fdb5ef0a":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_webusbblockedforurlsdesc","displayName":"Block WebUSB on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"5b18e14f3361f6f3":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled","displayName":"Allow suggestions from local providers (User)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\r\n\r\nIf you enable this policy, suggestions from local providers are used.\r\n\r\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\r\n\r\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\r\n\r\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy.\r\n\r\nThis policy requires a browser restart to finish applying.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5bfb772adde5e1ce":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup","displayName":"Allow the Search bar at Windows startup (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 119.\r\n\r\nThis policy is obsolete due to the deprecation of the Web widget, which is now known as Edge search bar. Admins should use SearchbarIsEnabledOnStartup for Edge search bar instead. Allows the Search bar to start running at Windows startup.\r\n\r\nIf you enable this policy the Search bar will start running at Windows startup by default. If the Search bar is disabled via 'WebWidgetAllowed' (Enable the Search bar) policy, this policy will not start the Search bar on Windows startup.\r\n\r\nIf you disable this policy, the Search bar will not start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup will be disabled and toggled off in Microsoft Edge settings.\r\n\r\nIf you don't configure this policy, the Search bar will not start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup will be toggled off in Microsoft Edge settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},"5b02c91410904ede":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended","displayName":"Enable new SmartScreen library (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107.\r\n\r\nThis policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client.\r\n\r\nAllows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will use the new SmartScreen library (libSmartScreenN).\r\n\r\nIf you disable this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nBefore Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.\r\nThis also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"5b0cdb0aa702db2f":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"Controls how Microsoft Edge prints on Microsoft Windows.\r\n\r\nPrinting to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance.\r\n\r\nIf you set this policy to Default, Microsoft Edge will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nIf you set this policy to Type42, Microsoft Edge will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will be in Default mode.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default\r\n\r\n* Type42 (1) = Type42\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},"5bc643d204e0e547":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel","displayName":"[Deprecated] Don’t AutoSave files in Excel (User)","description":"Important: This policy setting will be removed in a future release and will no longer be supported. Please use the \"Turn off AutoSave by default in Excel\" policy setting instead.\r\n \r\nThis policy setting controls whether files can be AutoSaved in the desktop version of Excel after Excel has been updated with new features. By default, Auto Saving files is Enabled.\r\n\r\nIf you enable this policy setting files will not be able to be AutoSaved.\r\n\r\nIf you disable or don’t configure this policy setting files will be able to be AutoSaved.\r\n\r\nNote: There are separate policy settings for Word, Excel, and PowerPoint.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel_1","displayName":"Enabled","description":null,"helpText":null}]},"5bf7195553de479c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicenotesdefaulturl1","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"5be4d353a12adee8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath","displayName":"Microsoft InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath_1","displayName":"True","description":null,"helpText":null}]},"5b981d516ecbdbfb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowcachename488","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"5bd719349fde4c44":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowcachename458","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"5b0d526b326dc4e2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_0","displayName":"No XAdES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_1","displayName":"XAdES-BES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_2","displayName":"XAdES-T","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_3","displayName":"XAdES-C","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_4","displayName":"XAdES-X","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_5","displayName":"XAdES-X-L","description":null,"helpText":null}]},"5bfee8bcf4981286":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition","displayName":"Auto Bullet Recognition (User)","description":"Checks/Unchecks the option ''Apply bullets to lists automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},"5bfafc56487710a7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1","displayName":"Prevent users from changing Months of Free/Busy information being published (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1_1","displayName":"True","description":null,"helpText":null}]},"5bfe697f93720772":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable specific shortcut key combinations in the specified applications. \r\n\r\nIf you enable this policy setting you can disable specific shortcut keys for the selected application. The predefined list of shortcut keys you can disable becomes available to you when you enable this policy setting. \r\n\r\nIf you disable or do not configure this policy setting, the predefined list of shortcut keys are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_1","displayName":"Enabled","description":null,"helpText":null}]},"5b51d33059495fa3":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"5b4acd0c629664c7":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},"5ba6a9bacda3da0c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"5bb7211f9d789d58":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},"5b586a0701121648":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct","displayName":"Stop checking to ensure headings are succinct (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that headings in a document are succinct.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that headings in a document are succinct.\r\n\r\nIf you disable or do not configure this policy setting, document headings will be checked for length and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct_1","displayName":"Enabled","description":null,"helpText":null}]},"5b1ce37952888fe7":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype","displayName":"Replace text as you type (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},"5be2cc93d3cb258d":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal","displayName":"Edge Traversal","description":"Indicates whether edge traversal is enabled or disabled for this rule.\n\nThe EdgeTraversal property indicates that specific inbound traffic is allowed to tunnel through NATs and other edge devices using the Teredo tunneling technology. In order for this setting to work correctly, the application or service with the inbound firewall rule needs to support IPv6. The primary application of this setting allows listeners on the host to be globally addressable through a Teredo IPv6 address.\n\nNew rules have the EdgeTraversal property disabled by default.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal_1","displayName":"Enabled","description":"Enabled","helpText":null}]}} \ No newline at end of file +{"5b6617f085870b50":{"id":"ade_setupassistant_intelligence","displayName":"Intelligence","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_intelligence_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_intelligence_1","displayName":"Show","description":null,"helpText":null}]},"5b0c7ec16f23efde":{"id":"com.apple.cellularprivatenetwork.managed_networkidentifier","displayName":"Network Identifier","description":"A string using the 3GPP \"Coordinated NID\" (option 1 or option 2) format (defined in 3GPP 31.102, Section 12.7.1). The device uses this value to match a SIM present on the device.\n\nAll combinations of `NetworkIdentifier` and `CsgNetworkIdentifier` must be unique across all profiles installed on the device.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"5b171ed595863657":{"id":"com.apple.dictionary_parentalcontrol","displayName":"Parental Control","description":"If true, enables parental controls dictionary restrictions.","helpText":null,"infoUrls":[],"categoryId":"65087b94-7e45-4d74-a50d-df4377b67499","categoryName":"Parental Controls Dictionary","options":[{"id":"com.apple.dictionary_parentalcontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dictionary_parentalcontrol_true","displayName":"True","description":null,"helpText":null}]},"5bb15c85d6c8a78b":{"id":"com.apple.dock_size-immutable","displayName":"Size Immutable","description":"If true, locks the size slider.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_size-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_size-immutable_true","displayName":"True","description":null,"helpText":null}]},"5ba52e99ea4dcec4":{"id":"com.apple.managedclient.preferences_linkedaccountenabled","displayName":"Enable the linked account feature (Deprecated)","description":"Microsoft Edge guides a user to the account management page where they can link a Microsoft Account (MSA) to an Azure Active Directory (Azure AD) account.\n\nIf you enable or don't configure this policy, linked account information will be shown on a flyout. When the Azure AD profile doesn't have a linked account it will show \"Add account\".\n\nIf you disable this policy, linked accounts will be turned off and no extra information will be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#linkedaccountenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_linkedaccountenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_linkedaccountenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"5baed40f555d2c30":{"id":"com.apple.managedclient.preferences_mandatoryextensionsforinprivatenavigation","displayName":"Specify extensions users must allow in order to navigate using InPrivate mode","description":"This policy lets you specify a list of extension IDs that must be explicitly allowed by the user to run in InPrivate mode in order to enable InPrivate browsing.\n\nIf users don't allow all listed extensions to run in InPrivate mode, they'll be unable to navigate using InPrivate.\n\nIf any extension in the list isn't installed, InPrivate navigation is blocked.\n\nThis policy only applies when InPrivate mode is enabled. If InPrivate mode is disabled using the InPrivateModeAvailability policy, this policy has no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#mandatoryextensionsforinprivatenavigation"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"5b1dbd769483a0d1":{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled","displayName":"Control whether Microsoft 365 Copilot Chat shows in the Microsoft Edge for Business toolbar","description":"For users in an Entra ID Microsoft Edge profile, this policy controls whether the Microsoft 365 Copilot Chat icon will be shown in the Microsoft Edge for Business toolbar for Microsoft 365 Copilot licensed and unlicensed users.\n\nThis policy only applies when users are accessing Copilot in the sidepane.\n\nIf the policy is enabled: Copilot will appear in the toolbar.\n\nIf the policy is disabled: Copilot won't appear in the toolbar.\n\nIf the policy isn't configured: Otherwise, Copilot shows in the toolbar and users may enable or disable Copilot from showing by using the Show Copilot toggle in settings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsoft365copilotchaticonenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsoft365copilotchaticonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"5b50761a5abb8ef4":{"id":"com.apple.mcx.filevault2_userecoverykey","displayName":"Use Recovery Key","description":"If true, creates a personal recovery key and displays it to the user.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":{"id":"com.apple.mcx.filevault2_userecoverykey_true","displayName":"Enabled","description":null,"helpText":null}},"5b766469e8a422fa":{"id":"com.apple.system-extension-policy_allowedsystemextensions","displayName":"Allowed System Extensions","description":"A dictionary of approved system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension to install. It’s an error for the same team identifier to appear in both the AllowedTeamIdentifiers array and as a key in this dictionary.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"5b39d13a87f45913":{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence","displayName":"File Provider Presence","description":"Allows a File Provider application to know when the user is using files managed by the File Provider.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"5b34058cbb9cac2a":{"id":"com.apple.xsan.preferences_usedlc","displayName":"Use DLC","description":"If true, use the DLC for all volumes.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":[{"id":"com.apple.xsan.preferences_usedlc_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.xsan.preferences_usedlc_true","displayName":"True","description":null,"helpText":null}]},"5b85c4bd0d233508":{"id":"com.microsoft.edge.mamedgeappconfigsettings.inprivatemodeurlallowlist","displayName":"Allow access to a list of URLs in InPrivate mode.","description":"This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in \"InPrivateModeUrlBlocklist\". See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322).\n\nIf both this policy and \"InPrivateModeUrlBlocklist\" are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to \"URLBlocklist\" and \"URLAllowlist\".\n\nIf this policy is configured and \"InPrivateModeUrlBlocklist\" is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked.\n\nIf \"InPrivateModeAvailability\" is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist.\n\nIf this policy is not configured, no exceptions are applied to \"InPrivateModeUrlBlocklist\" or \"InPrivateModeAvailability\".\n\nThis policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the \"URLAllowlist\" policy.\n\nThis policy supports up to 1000 entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"5b3090f0739947b1":{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled","displayName":"Allow suggestions from local providers","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\n\nIf you enable this policy, suggestions from local providers are used.\n\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions won't appear.\n\nIf you don't configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\n\nSome features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the \"SavingBrowserHistoryDisabled\" policy.\n\nThis policy requires a browser restart to finish applying.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.localprovidersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"5be40b4ae14e0473":{"id":"contentcaching_allowsharedcaching","displayName":"Allow Shared Caching","description":"If `true`, the system caches non-iCloud content, such as apps and software updates. Changes to this value don't have an immediate effect. Clients may take some time to react to changes.\n\n> Note:\n> At least one of the `AllowPersonalCaching` or `AllowSharedCaching` keys need to be `true`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_allowsharedcaching_false","displayName":"Blocked","description":null,"helpText":null},{"id":"contentcaching_allowsharedcaching_true","displayName":"Allowed","description":null,"helpText":null}]},"5b8c21d7b58aa3df":{"id":"contentcaching_parents","displayName":"Parents","description":"An array of the local IP addresses of other content caches that this cache should download from or upload to, instead of downloading from or uploading to Apple directly. The system ignores invalid addresses and addresses of computers that aren't content caches. The system skips Parent caches that become unavailable. If all parent content caches become unavailable, the content cache downloads from or uploads to Apple directly, until a parent content cache becomes available again.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"5bc995bbc6e166e0":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_registry_cse_nochanges10_1","displayName":"True","description":null,"helpText":null}]},"5b694e2d67f94bf0":{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2","displayName":"Turn off the \"Order Prints\" picture task","description":"This policy setting specifies whether the \"Order Prints Online\" task is available from Picture Tasks in Windows folders.\r\n\r\nThe Order Prints Online Wizard is used to download a list of providers and allow users to order prints online.\r\n\r\nIf you enable this policy setting, the task \"Order Prints Online\" is removed from Picture Tasks in File Explorer folders.\r\n\r\nIf you disable or do not configure this policy setting, the task is displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremoveorderprints-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellremoveorderprints_2_1","displayName":"Enabled","description":null,"helpText":null}]},"5b8296098c67b0fc":{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap","displayName":"Do not allow sessions without mutual CHAP","description":"If enabled then only those sessions that are configured for mutual CHAP may be established. If disabled then sessions that are configured for mutual CHAP or sessions not configured for mutual CHAP may be established.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-iscsi#admx-iscsi-iscsisecurity-requiremutualchap"],"categoryId":"6c1d9109-e4d1-4718-a537-dd685464fdbe","categoryName":"i SCSI Security","options":[{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_iscsi_iscsisecurity_requiremutualchap_1","displayName":"Enabled","description":null,"helpText":null}]},"5bbf1b24d5947b34":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel","displayName":"Microsoft Excel 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Excel 2013.\r\nBy default, the user settings of Microsoft Excel 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Excel 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excel_1","displayName":"Enabled","description":null,"helpText":null}]},"5bb34481bad21740":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013","displayName":"Microsoft Office 365 PowerPoint 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_1","displayName":"Enabled","description":null,"helpText":null}]},"5bdf537513e7a193":{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate","displayName":"Prevent Automatic Updates","description":"This policy setting allows you to turn off do not show first use dialog boxes.\r\n\r\nIf you enable this policy setting, the Privacy Options and Installation Options dialog boxes are prevented from being displayed the first time a user starts Windows Media Player.\r\n\r\nThis policy setting prevents the dialog boxes which allow users to select privacy, file types, and other desktop options from being displayed when the Player is first started. Some of the options can be configured by using other Windows Media Player group policies.\r\n\r\nIf you disable or do not configure this policy setting, the dialog boxes are displayed when the user starts the Player for the first time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-disableautoupdate"],"categoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","categoryName":"Windows Media Player","options":[{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsmediaplayer_disableautoupdate_1","displayName":"Enabled","description":null,"helpText":null}]},"5be746d34f8c14da":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub","displayName":"Feedback Hub","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_windowsfeedbackhub_1","displayName":"True","description":null,"helpText":null}]},"5b1fc344fa7f1969":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},"5b27e1bebefe5a6a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls","displayName":"Allow images on these sites","description":"Setting the policy lets you set a list of URL patterns that specify sites that may display images.\r\n\r\nLeaving the policy unset means DefaultImagesSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nNote that previously this policy was erroneously enabled on Android, but this functionality has never been fully supported on Android.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"5b089b401a03b37c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled","displayName":"Allow SpeculationRules prefetch to ServiceWorker-controlled URLs","description":"SpeculationRules prefetch can be issued to URLs that are controlled by\r\nServiceWorker. However, legacy code did not allow it and canceled the prefetch\r\nrequests. This policy enables to control the behavior.\r\n\r\nSetting this policy to Enabled or not set allows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs (if the PrefetchServiceWorker feature flag is\r\nenabled). This is the current default behavior and is aligned with the\r\nspecifications.\r\n\r\nSetting this policy to Disabled disallows SpeculationRules prefetch to\r\nServiceWorker-controlled URLs. This is the legacy behavior.\r\n\r\nThis policy is intended to be temporary and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_prefetchwithserviceworkerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5ba86cd1fc53bf0c":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingrulecompilation","displayName":"Rule Compilation","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging Rule Compilation component.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\RuleCompilation\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingrulecompilation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingrulecompilation_1","displayName":"Enabled","description":null,"helpText":null}]},"5b6d0525c1190dfa":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcsiddirectorynamepattern","displayName":"SID Directory Name Pattern","description":"Specifies a string pattern used when creating a Profile or ODFC container folder. Use this setting to define how FSLogix will attempt to create a users Profile or ODFC container folder. FSLogix will use the VHDLocations or CCDLocations as the location where to create and this setting defines what to create.\r\n\r\nNOTE: When using this configuration setting, be sure the SIDDIRNameMatch value matches this setting.\r\n\r\n- This setting has NO EFFECT when FlipFlopProfileDirectoryName is enabled.\r\n- This setting has NO EFFECT when NoProfileContainingFolder is enabled.\r\n- NoProfileContainingFolder > FlipFlopProfileDirectoryName > SIDDirNamePattern (this setting)\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\SIDDirNamePattern\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"81eb92d0-acda-4ea2-8183-29ed5457276b","categoryName":"Container and Directory Naming","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcsiddirectorynamepattern_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcsiddirectorynamepattern_1","displayName":"Enabled","description":null,"helpText":null}]},"5b3435da518b13b6":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"5b95fc0d92fd3509":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowlessprivilegedsites"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"5b303d6eb8fced48":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_machineinactivitylimit","displayName":"[Deprecated] Interactive Logon Machine Inactivity Limit (Deprecated)","description":"Interactive logon: Machine inactivity limit. Windows notices inactivity of a logon session, and if the amount of inactive time exceeds the inactivity limit, then the screen saver will run, locking the session. Default: not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#localpoliciessecurityoptions-interactivelogon-machineinactivitylimit"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_machineinactivitylimit_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_machineinactivitylimit_1","displayName":"Enabled (session will lock after amount of inactive time exceeds the inactivity limit)","description":"Enabled (session will lock after amount of inactive time exceeds the inactivity limit)","helpText":null}]},"5bf569c42ba7653d":{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action","displayName":"Group and user action","description":"This Setting allows an administrator to manage local groups on a Device. Possible settings: 1. Update Group Membership: Update a group and add and/or remove members though the 'U' action. When using Update, existing group members that are not specified in the policy remain untouched. 2. Replace Group Membership: Restrict a group by replacing group membership through the 'R' action. When using Replace, existing group membership is replaced by the list of members specified in the add member section. This option works in the same way as a Restricted Group and any group members that are not specified in the policy are removed. Caution: If the same group is configured with both Replace and Update, then Replace will win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups"],"categoryId":"b86100f0-e4ae-4f93-9dae-dd253a96726f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action_add_update","displayName":"Add (Update)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action_remove_update","displayName":"Remove (Update)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_action_add_restrict","displayName":"Add (Replace)","description":null,"helpText":null}]},"5b7d7fba6ca45c39":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\r\n\r\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\r\n\r\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\r\n\r\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_1","displayName":"Enabled","description":null,"helpText":null}]},"5bd25df4c04456fe":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_nativemessagingallowlistdesc","displayName":"Names of the native messaging hosts to exempt from the block list (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},"5b212df3c19df39e":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled","displayName":"Allow M365 authentication popups in work profiles","description":"This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles.\r\n\r\nWhen users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in.\r\n\r\nIf you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.\r\n\r\nIf you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~identity_m365authpopupsinworkenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5b47bfe0fe5b78e8":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_visioexe187","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_visioexe187_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_visioexe187_1","displayName":"True","description":null,"helpText":null}]},"5bdab7f9086a3ee6":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_outlookexe162","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_outlookexe162_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_outlookexe162_1","displayName":"True","description":null,"helpText":null}]},"5b79c508107ea86d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_vltosubscription","displayName":"Upgrade Office 2019 to Office 365 ProPlus","description":"This policy setting allows you to upgrade volume licensed versions of Office Professional Plus 2019 to Office 365 ProPlus.\r\n\r\nNote: For the user to be able to use Office 365 ProPlus, you must have purchased an Office 365 plan that includes Office 365 ProPlus, and you must have assigned the user a license to use Office 365 ProPlus.\r\n\r\nIf you enable this policy setting, the installed volume licensed version of Office 2019 on the user's computer will be upgraded to Office 365 ProPlus. We also recommend that you use Group Policy to specify an update path and an update channel for Office 365 ProPlus.\r\n\r\nNote: If there are volume licensed versions of Visio and Project on the user's computer, those won't be upgraded to Office 365 subscription versions.\r\n\r\nIf you disable or don't configure this policy setting, Office 2019 isn't automatically upgraded to Office 365 ProPlus. But, you can initiate the upgrade by using some other method, such as by using the Office Deployment Tool.","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_vltosubscription_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_updates_l_vltosubscription_1","displayName":"Enabled","description":null,"helpText":null}]},"5bfc570b9f1b51bb":{"id":"device_vendor_msft_policy_config_update_autorestartdeadlineperiodindays","displayName":"Auto Restart Deadline Period In Days","description":"For Quality Updates, this policy specifies the deadline in days before automatically executing a scheduled restart outside of active hours. The deadline can be set between 2 and 30 days from the time the restart is scheduled. The system will reboot on or after the specified deadline. The reboot is prioritized over any configured Active Hours and any existing system and user busy checks. Value type is integer. Default is 7 days. Supported values range: 2-30. Note that the PC must restart for certain updates to take effect. If you enable this policy, a restart will automatically occur the specified number of days after the restart was scheduled. If you disable or do not configure this policy, the PC will restart according to the default schedule. If any of the following two policies are enabled, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installations. Always automatically restart at scheduled time.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#autorestartdeadlineperiodindays"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"5bd0e35edab3d208":{"id":"device_vendor_msft_policy_privilegemanagement_systemsettingrules_{systemsettingrulename}_elevationaction","displayName":"Elevation action","description":"Specifies the elevation action for this system setting rule.","helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":[{"id":"device_vendor_msft_policy_privilegemanagement_systemsettingrules_{systemsettingrulename}_self","displayName":"User confirmed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_privilegemanagement_systemsettingrules_{systemsettingrulename}_automatic","displayName":"Automatic","description":null,"helpText":null}]},"5b3d86aedcdba858":{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_$type","displayName":"Type","description":null,"helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_$type_0","displayName":"Path","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_$type_1","displayName":"File extension","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_exclusions_item_$type_2","displayName":"Process name","description":null,"helpText":null}]},"5bf2af543e851992":{"id":"softwareupdate_rapidsecurityresponse_enable","displayName":"Enable","description":"If set to 'false', Background Security Improvements aren't offered for user installation. The system can still install Background Security Improvements with Software Update and Enforce Latest configurations. If set to 'true', the system offers Background Security Improvements to the user.","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":[{"id":"softwareupdate_rapidsecurityresponse_enable_false","displayName":"False","description":null,"helpText":null},{"id":"softwareupdate_rapidsecurityresponse_enable_true","displayName":"True","description":null,"helpText":null}]},"5b3dbe4305bae49e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":null},"5b06cb48784ca5a1":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize84_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"6730f0be-a129-4b48-942f-e4ddf69fee66","categoryName":"Customizable Error Messages","options":null},"5b4b34e8b51f2a20":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent","displayName":"Consent level (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"184981d4-712b-425e-b0a3-93eac7fbd3ee","categoryName":"Consent","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent_1","displayName":"Always ask before sending data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent_2","displayName":"Send parameters","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent_3","displayName":"Send parameters and safe additional data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdefaultconsent_1_werconsent_4","displayName":"Send all data","description":null,"helpText":null}]},"5b25a0707f91235e":{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_activexcontrol","displayName":"ActiveX Control (User)","description":"Permits or prohibits use of this snap-in.\n\nIf you enable this setting, the snap-in is permitted. If you disable the setting, the snap-in is prohibited.\n\nIf this setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted.\n\n To explicitly permit use of this snap-in, enable this setting. If this setting is not configured (or disabled), this snap-in is prohibited.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited.\n\n To explicitly prohibit use of this snap-in, disable this setting. If this setting is not configured (or enabled), the snap-in is permitted.\n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmc#admx-mmc-mmc-activexcontrol"],"categoryId":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","categoryName":"Restricted Permitted snap-ins","options":[{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_activexcontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_activexcontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"5b0529afbb6a7f07":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ipsecmanage","displayName":"IP Security Policy Management (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-ipsecmanage"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ipsecmanage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ipsecmanage_1","displayName":"Enabled","description":null,"helpText":null}]},"5be1aadd4c15c842":{"id":"user_vendor_msft_policy_config_admx_pentraining_pentrainingoff_1","displayName":"Turn off Tablet PC Pen Training (User)","description":"Turns off Tablet PC Pen Training.\r\n\r\nIf you enable this policy setting, users cannot open Tablet PC Pen Training.\r\n\r\nIf you disable or do not configure this policy setting, users can open Tablet PC Pen Training.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pentraining#admx-pentraining-pentrainingoff-1"],"categoryId":"fe65603b-1980-446b-ae17-516eb885c6be","categoryName":"Tablet PC Pen Training","options":[{"id":"user_vendor_msft_policy_config_admx_pentraining_pentrainingoff_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_pentraining_pentrainingoff_1_1","displayName":"Enabled","description":null,"helpText":null}]},"5bb8e07c072eae73":{"id":"user_vendor_msft_policy_config_admx_sensors_disablesensors_1","displayName":"Turn off sensors (User)","description":"\r\n This policy setting turns off the sensor feature for this computer.\r\n\r\n If you enable this policy setting, the sensor feature is turned off, and all programs on this computer cannot use the sensor feature.\r\n\r\n If you disable or do not configure this policy setting, all programs on this computer can use the sensor feature.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sensors#admx-sensors-disablesensors-1"],"categoryId":"b40cfb22-8f17-4317-bcbb-c1c871497446","categoryName":"Location and Sensors","options":[{"id":"user_vendor_msft_policy_config_admx_sensors_disablesensors_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_sensors_disablesensors_1_1","displayName":"Enabled","description":null,"helpText":null}]},"5ba652029a52e5b2":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for profile types. (User)","description":"Configuring this policy will allow/disallow ambient authentication for Incognito and Guest profiles in Google Chrome.\r\n\r\nAmbient Authentication is http authentication with default credentials if explicit credentials are not provided via NTLM/Kerberos/Negotiate challenge/response schemes.\r\n\r\nSetting the RegularOnly (value 0), allows ambient authentication for Regular sessions only. Incognito and Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the IncognitoAndRegular (value 1), allows ambient authentication for Incognito and Regular sessions. Guest sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the GuestAndRegular (value 2), allows ambient authentication for Guest and Regular sessions. Incognito sessions wouldn't be allowed to ambiently authenticate.\r\n\r\nSetting the All (value 3), allows ambient authentication for all sessions.\r\n\r\nNote that, ambient authentication is always allowed on regular profiles.\r\n\r\nIn Google Chrome version 81 and later, if the policy is left not set, ambient authentication will be enabled in regular sessions only.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ambientauthenticationinprivatemodesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5ba329704b483a44":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled","displayName":"Browser experiments icon in toolbar (User)","description":"Setting the policy to Enabled or leaving the policy unset means that users can access browser experimental features through an icon in the toolbar\r\n\r\nSetting the policy to Disabled removes the browser experimental features icon from the toolbar.\r\n\r\nchrome://flags and any other means of turning off and on browser features will still behave as expected regardless of whether this policy is Enabled or Disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserlabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5b252404f57d88af":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata","displayName":"Import autofill form data from default browser on first run (User)","description":"Setting the policy to Enabled imports autofill form data from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no autofill form data is imported on first run.\r\n\r\nUsers can trigger an import dialog and the autofill form data checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importautofillformdata_1","displayName":"Enabled","description":null,"helpText":null}]},"5b505fb81e74e4c8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (User)","description":"Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices.\r\n\r\nLeaving the policy unset lets sites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"5be2abd3cad829bf":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts","displayName":"Allow user-level Native Messaging hosts (installed without admin permissions) (User)","description":"Setting the policy to Enabled or leaving it unset means Google Chrome can use native messaging hosts installed at the user level.\r\n\r\nSetting the policy to Disabled means Google Chrome can only use these hosts if installed at the system level.","helpText":"","infoUrls":[],"categoryId":"895e0884-6b60-4bb0-b2ab-3a1642103db7","categoryName":"Native Messaging","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~nativemessaging_nativemessaginguserlevelhosts_1","displayName":"Enabled","description":null,"helpText":null}]},"5b436792b18bda67":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls","displayName":"Block key generation on these sites (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"5b0261599ee71c96":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_ntpshortcuts","displayName":"Setting shortcuts on the New Tab Page (Beta) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"5b7e513c16885049":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_personaltemplatespath_l_personaltemplatespath","displayName":"Personal templates path (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},"5bc5537b18f1f36b":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_popupsallowedforurls_popupsallowedforurlsdesc","displayName":"Allow pop-up windows on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"5b005928fdb5ef0a":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusbblockedforurls_webusbblockedforurlsdesc","displayName":"Block WebUSB on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"5b18e14f3361f6f3":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled","displayName":"Allow suggestions from local providers (User)","description":"Allow suggestions from suggestion providers on the device (local providers), for example, Favorites and Browsing History, in Microsoft Edge's Address Bar and Auto-Suggest List.\r\n\r\nIf you enable this policy, suggestions from local providers are used.\r\n\r\nIf you disable this policy, suggestions from local providers are never used. Local history and local favorites suggestions will not appear.\r\n\r\nIf you do not configure this policy, suggestions from local providers are allowed but the user can change that using the settings toggle.\r\n\r\nNote that some features may not be available if a policy to disable this feature has been applied. For example, Browsing History suggestions will not be available if you enable the 'SavingBrowserHistoryDisabled' (Disable saving browser history) policy.\r\n\r\nThis policy requires a browser restart to finish applying.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_localprovidersenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"5bfb772adde5e1ce":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup","displayName":"Allow the Search bar at Windows startup (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 119.\r\n\r\nThis policy is obsolete due to the deprecation of the Web widget, which is now known as Edge search bar. Admins should use SearchbarIsEnabledOnStartup for Edge search bar instead. Allows the Search bar to start running at Windows startup.\r\n\r\nIf you enable this policy the Search bar will start running at Windows startup by default. If the Search bar is disabled via 'WebWidgetAllowed' (Enable the Search bar) policy, this policy will not start the Search bar on Windows startup.\r\n\r\nIf you disable this policy, the Search bar will not start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup will be disabled and toggled off in Microsoft Edge settings.\r\n\r\nIf you don't configure this policy, the Search bar will not start at Windows startup for all profiles. The option to start the Edge search bar at Windows startup will be toggled off in Microsoft Edge settings.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_webwidgetisenabledonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},"5b02c91410904ede":{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended","displayName":"Enable new SmartScreen library (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 107.\r\n\r\nThis policy doesn't work because it was only intended to be a short-term mechanism to support the update to a new SmartScreen client.\r\n\r\nAllows the Microsoft Edge browser to load the new SmartScreen library (libSmartScreenN) for any SmartScreen checks on site URLs or application downloads.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will use the new SmartScreen library (libSmartScreenN).\r\n\r\nIf you disable this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nBefore Microsoft Edge version 103, if you don't configure this policy, Microsoft Edge will use the old SmartScreen library (libSmartScreen).\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management.\r\nThis also includes macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended~smartscreen_recommended_newsmartscreenlibraryenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"5b0cdb0aa702db2f":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode","displayName":"Print PostScript Mode (User)","description":"Controls how Microsoft Edge prints on Microsoft Windows.\r\n\r\nPrinting to a PostScript printer on Microsoft Windows different PostScript generation methods can affect printing performance.\r\n\r\nIf you set this policy to Default, Microsoft Edge will use a set of default options when generating PostScript. For text in particular, text will always be rendered using Type 3 fonts.\r\n\r\nIf you set this policy to Type42, Microsoft Edge will render text using Type 42 fonts if possible. This should increase printing speed for some PostScript printers.\r\n\r\nIf you don't configure this policy, Microsoft Edge will be in Default mode.\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = Default\r\n\r\n* Type42 (1) = Type42\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printpostscriptmode_1","displayName":"Enabled","description":null,"helpText":null}]},"5bc643d204e0e547":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel","displayName":"[Deprecated] Don’t AutoSave files in Excel (User)","description":"Important: This policy setting will be removed in a future release and will no longer be supported. Please use the \"Turn off AutoSave by default in Excel\" policy setting instead.\r\n \r\nThis policy setting controls whether files can be AutoSaved in the desktop version of Excel after Excel has been updated with new features. By default, Auto Saving files is Enabled.\r\n\r\nIf you enable this policy setting files will not be able to be AutoSaved.\r\n\r\nIf you disable or don’t configure this policy setting files will be able to be AutoSaved.\r\n\r\nNote: There are separate policy settings for Word, Excel, and PowerPoint.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_dontautosaveinformationexcel_1","displayName":"Enabled","description":null,"helpText":null}]},"5bf7195553de479c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicenotesdefaulturl1","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"5be4d353a12adee8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath","displayName":"Microsoft InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_infopath_1","displayName":"True","description":null,"helpText":null}]},"5b981d516ecbdbfb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowcachename488","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"5bd719349fde4c44":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache7_l_workflowcachename458","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"5b0d526b326dc4e2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_0","displayName":"No XAdES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_1","displayName":"XAdES-BES","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_2","displayName":"XAdES-T","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_3","displayName":"XAdES-C","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_4","displayName":"XAdES-X","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_requestedxadeslevelforsignaturegeneration_l_requestedxadeslevelforsignaturegenerationdropid_5","displayName":"XAdES-X-L","description":null,"helpText":null}]},"5bfee8bcf4981286":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition","displayName":"Auto Bullet Recognition (User)","description":"Checks/Unchecks the option ''Apply bullets to lists automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autobulletrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},"5bfafc56487710a7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1","displayName":"Prevent users from changing Months of Free/Busy information being published (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_preventusersfromchangingmonthsoffreebusyinformation1_1","displayName":"True","description":null,"helpText":null}]},"5bfe697f93720772":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable specific shortcut key combinations in the specified applications. \r\n\r\nIf you enable this policy setting you can disable specific shortcut keys for the selected application. The predefined list of shortcut keys you can disable becomes available to you when you enable this policy setting. \r\n\r\nIf you disable or do not configure this policy setting, the predefined list of shortcut keys are enabled for the application.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_1","displayName":"Enabled","description":null,"helpText":null}]},"5b51d33059495fa3":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc17_l_descriptioncolon74","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"5b4acd0c629664c7":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]},"5ba6a9bacda3da0c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"5bb7211f9d789d58":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc10_l_allowsubfolders47_1","displayName":"True","description":null,"helpText":null}]},"5b586a0701121648":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct","displayName":"Stop checking to ensure headings are succinct (User)","description":"This policy setting prevents the Accessibility Checker from checking to ensure that headings in a document are succinct.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from checking to ensure that headings in a document are succinct.\r\n\r\nIf you disable or do not configure this policy setting, document headings will be checked for length and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensureheadingsaresuccinct_1","displayName":"Enabled","description":null,"helpText":null}]},"5b1ce37952888fe7":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype","displayName":"Replace text as you type (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_replacetextasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},"5be2cc93d3cb258d":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal","displayName":"Edge Traversal","description":"Indicates whether edge traversal is enabled or disabled for this rule.\n\nThe EdgeTraversal property indicates that specific inbound traffic is allowed to tunnel through NATs and other edge devices using the Teredo tunneling technology. In order for this setting to work correctly, the application or service with the inbound firewall rule needs to support IPv6. The primary application of this setting allows listeners on the host to be globally addressable through a Teredo IPv6 address.\n\nNew rules have the EdgeTraversal property disabled by default.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_edgetraversal_1","displayName":"Enabled","description":"Enabled","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/64.json b/public/intune-definitions/64.json index 5b82011af4a6..0b4ce7586963 100644 --- a/public/intune-definitions/64.json +++ b/public/intune-definitions/64.json @@ -1 +1 @@ -{"6443d9080bd9fe52":{"id":"ade_setupassistant_passcode","displayName":"Passcode","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_passcode_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_passcode_1","displayName":"Show","description":null,"helpText":null}]},"645ab0a1c86bd9ca":{"id":"com.apple.managedclient.preferences_performancedetectorenabled","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#performancedetectorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_performancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_performancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"6446359bc1084085":{"id":"com.apple.system-extension-policy_nonremovablesystemextensions_generickey_keytobereplaced","displayName":"Non Removable System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled when SIP is enabled. It's an error for the same mapping to appear in the dictionary values corresponding to 'RemovableSystemExtensions' and 'NonRemovableSystemExtensions' keys.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"64991350c67550c4":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended","displayName":"Configure the Microsoft Edge new tab page experience (Obsolete) (users can override)","description":"This policy is obsolete because the new version of the enterprise new tab page no longer requires choosing between different content types. Instead, the content that's presented to the user can be controlled via the Microsoft 365 admin center. To get to the Microsoft 365 admin center, sign in at https://admin.microsoft.com with your admin account.\n\nLets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\n\nIf you set this policy to 'News', users see the Microsoft News feed experience on the new tab page.\n\nIf you set this policy to 'Office', users with an Azure Active Directory browser sign-in see the Office 365 feed experience on the new tab page.\n\nIf you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience. Users without an Azure Active Directory browser sign-in to see the standard new tab page experience.\n\nIf you enable this policy *and* the \"NewTabPageLocation\" policy, \"NewTabPageLocation\" has precedence.\n\nPolicy options mapping:\n\n* News (0) = Microsoft News feed experience\n\n* Office (1) = Office 365 feed experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended_news","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended_office","displayName":"Office 365 feed experience","description":null,"helpText":null}]},"640e8dd28b62a7cc":{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (Deprecated)","description":"This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets\n\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites.\nA set can also contain a list of service sites that it owns, and a map from a site to all its ccTLD variants. For more information on how Microsoft Edge uses Related Website Sets, see https://github.com/WICG/first-party-sets.\n\n\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set.\n\nWhen this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets.\n\nFor all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this step, the policy's Related Website Set is added to the Microsoft Edge's list of Related Website Sets.\n\nFor all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set is updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set is added to the browser's list of Related Website Sets.\n\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\nmore than one set. This requirement is also required for both the replacements list\nand the additions list. Similarly, a site can't be in both the\nreplacements list and the additions list.\n\nWildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists.\n\nThis policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.","helpText":null,"infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":null},"64d9d0736c3a0f5f":{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_storagecapacitystopdeletion","displayName":"Storage Capacity Stop Deletion","description":"Stop deleting profiles when available storage capacity is brought up to this threshold, given as percent of total storage available for profiles.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},"64cde00985596c02":{"id":"device_vendor_msft_defender_configuration_disableftpparsing","displayName":"Disable Ftp Parsing","description":"This setting disables FTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disableftpparsing_1","displayName":"FTP parsing is disabled","description":"FTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disableftpparsing_0","displayName":"FTP parsing is enabled","description":"FTP parsing is enabled","helpText":null}]},"64cd794bcd6e93ff":{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict","displayName":"Restrict system locales","description":"This policy setting restricts the permitted system locales to the specified list. If the list is empty, it locks the system locale to its current value. This policy setting does not change the existing system locale; however, the next time that an administrator attempts to change the computer's system locale, they will be restricted to the specified list.\r\n\r\nThe locale list is specified using language names, separated by a semicolon (;). For example, en-US is English (United States). Specifying \"en-US;en-CA\" would restrict the system locale to English (United States) and English (Canada).\r\n\r\nIf you enable this policy setting, administrators can select a system locale only from the specified system locale list.\r\n\r\nIf you disable or do not configure this policy setting, administrators can select any system locale shipped with the operating system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-localesystemrestrict"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_1","displayName":"Enabled","description":null,"helpText":null}]},"6451429721c4ce1b":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2","displayName":"Synchronize all offline files before logging off","description":"Determines whether offline files are fully synchronized when users log off.\r\n\r\nThis setting also disables the \"Synchronize all offline files before logging off\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nIf you enable this setting, offline files are fully synchronized. Full synchronization ensures that offline files are complete and current.\r\n\r\nIf you disable this setting, the system only performs a quick synchronization. Quick synchronization ensures that files are complete, but does not ensure that they are current.\r\n\r\nIf you do not configure this setting, the system performs a quick synchronization by default, but users can change this option.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To change the synchronization method without changing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then select the \"Synchronize all offline files before logging off\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatlogoff-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},"64647e757d06566e":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv","displayName":"Qualitative service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Qualitative service type (ServiceTypeQualitative). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Qualitative service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypequalitative-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_1","displayName":"Enabled","description":null,"helpText":null}]},"6428a11ba8eb5114":{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar","displayName":"Prevent changes to Taskbar and Start Menu Settings","description":"This policy setting allows you to prevent changes to Taskbar and Start Menu Settings.\n\nIf you enable this policy setting, The user will be prevented from opening the Taskbar Properties dialog box.\n\nIf the user right-clicks the taskbar and then clicks Properties, a message appears explaining that a setting prevents the action.\n\nIf you disable or do not configure this policy setting, the Taskbar and Start Menu items are available from Settings on the Start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosettaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"648d841bcc2944c8":{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart","displayName":"Prevent users from uninstalling applications from Start","description":"If you enable this setting, users cannot uninstall apps from Start.\n\nIf you disable this setting or do not configure it, users can access the uninstall command from Start","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nouninstallfromstart"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_1","displayName":"Enabled","description":null,"helpText":null}]},"641324e039819430":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled","displayName":"Ping the settings storage location before sync","description":"This policy setting allows you to configure the User Experience Virtualization (UE-V) sync provider to ping the settings storage path before attempting to sync settings. If the ping is successful then the sync provider attempts to synchronize the settings packages. If the ping is unsuccessful then the sync provider doesn’t attempt the synchronization. \r\nIf you enable this policy setting, the sync provider pings the settings storage location before synchronizing settings packages.\r\nIf you disable this policy setting, the sync provider doesn’t ping the settings storage location before synchronizing settings packages. \r\nIf you do not configure this policy, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncproviderpingenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"641aa8a042cfd43b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Setting the policy to Enabled means browsing history is not saved, tab syncing is off and users can't change this setting.\r\n\r\nSetting the policy to Disabled or leaving it unset saves browsing history.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"648a74e607640a70":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting","displayName":"Enable deprecated privet printing","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting_1","displayName":"Enabled","description":null,"helpText":null}]},"64e9a75f420c59d2":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability","displayName":"Control availability of extensions unpublished on the Chrome Web Store. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability_0","displayName":"Allow unpublished extensions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability_1","displayName":"Disable unpublished extensions","description":null,"helpText":null}]},"64329e66f0de40bc":{"id":"device_vendor_msft_policy_config_defender_controlledfolderaccessallowedapplications","displayName":"Controlled Folder Access Allowed Applications","description":"The previous name was GuardedFoldersAllowedApplications and changed to ControlledFolderAccessAllowedApplications. This policy setting allows user-specified applications to the controlled folder access feature. Adding an allowed application means the controlled folder access feature will allow the application to modify or delete content in certain folders such as My Documents. In most cases it will not be necessary to add entries. Windows Defender Antivirus will automatically detect and dynamically add applications that are friendly. Value type is string. Use the | as the substring separator.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#controlledfolderaccessallowedapplications"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"64c327feb703105b":{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork","displayName":"Allow Option To Show Network","description":"When the Network folder is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshownetwork"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"64e539c8629bdbd6":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles","displayName":"Allow loading of XAML files","description":"This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.\n\nIf you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.\n\nIf you disable this policy setting, XAML files are not loaded inside Internet Explorer. The user cannot change this behavior.\n\nIf you do not configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowloadingofxamlfiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"6435c117444711a4":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"64b9d5bd550ee6fe":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled","displayName":"Enable AutoFill for payment instruments","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. This includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for payment instruments.\r\n\r\nIf you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"64d41a7cd1733bb2":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines","displayName":"Manage Search Engines","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\r\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\r\n\r\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default.\r\n\r\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\r\n\r\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\r\n\r\nIf the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allow_search_engine_discovery\": true\r\n }, \r\n {\r\n \"is_default\": true, \r\n \"suggest_url\": \"https://www.example1.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example1.com/search?q={searchTerms}\", \r\n \"name\": \"Example1\", \r\n \"keyword\": \"example1.com\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example2.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example2.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example2\", \r\n \"keyword\": \"example2.com\", \r\n \"image_search_post_params\": \"content={imageThumbnail},url={imageURL},sbisrc={SearchSource}\", \r\n \"search_url\": \"https://www.example2.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example3.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example3.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example3\", \r\n \"keyword\": \"example3.com\", \r\n \"encoding\": \"UTF-8\", \r\n \"search_url\": \"https://www.example3.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"search_url\": \"https://www.example4.com/search?q={searchTerms}\", \r\n \"name\": \"Example4\", \r\n \"keyword\": \"example4.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_1","displayName":"Enabled","description":null,"helpText":null}]},"6450b4b926b09e42":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"644bb6fb988af96d":{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled","displayName":"Allows users to translate videos to different languages.","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\r\nWith this feature, users can watch videos translated into their selected language in real time.\r\n\r\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\r\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\r\n\r\nThese components may be updated periodically to improve performance and translation quality.\r\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\r\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\r\nFor more details, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\r\n\r\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\r\nusers will see the Translate button when hovering over videos.\r\n\r\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button won’t be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"643cc747d9ef4230":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\r\n\r\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\r\n\r\nIf you disable this setting, employees will not receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"6438d904d5bcce9c":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed","displayName":"Allow sites configured for Internet Explorer mode to open in Microsoft Edge","description":"This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list.\r\n\r\nUsers can configure this setting in the \"More tools\" menu by selecting 'Open sites in Microsoft Edge'.\r\n\r\nIf you enable this policy, the option to 'Open sites in Microsoft Edge' will be visible under \"More tools\". Users use this option to test IE mode sites on a modern browser.\r\n\r\nIf you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the \"More tools\" menu. However, users can access this menu option with the --ie-mode-test flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"64936fd32d8cbbb5":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessbackgroundspatialperception_forcedenytheseapps","displayName":"Let Apps Access Background Spatial Perception Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are denied access to the user's movements while the apps are running in the background. This setting overrides the default LetAppsAccessBackgroundSpatialPerception policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessbackgroundspatialperception_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"648a91ae9e7e0a53":{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning","displayName":"[Deprecated] Schedule Imminent Restart Warning","description":"Allows the IT Admin to specify the period for auto-restart imminent warning notifications. The default value is 15 (minutes).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#update-scheduleimminentrestartwarning"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"64612de443fb8b61":{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging","displayName":"Turn on PowerShell Script Block Logging","description":"\n This policy setting enables logging of all PowerShell script input to the Microsoft-Windows-PowerShell/Operational event log. If you enable this policy setting,\n Windows PowerShell will log the processing of commands, script blocks, functions, and scripts - whether invoked interactively, or through automation.\n \n If you disable this policy setting, logging of PowerShell script input is disabled.\n \n If you enable the Script Block Invocation Logging, PowerShell additionally logs events when invocation of a command, script block, function, or script\n starts or stops. Enabling Invocation Logging generates a high volume of event logs.\n \n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowspowershell#windowspowershell-turnonpowershellscriptblocklogging"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_1","displayName":"Enabled","description":null,"helpText":null}]},"64a8ff9fbdcb3e2a":{"id":"diskmanagement_diskmanagement","displayName":"com.apple.configuration.diskmanagement.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"83febe72-a64f-4051-9071-1efae1ea9a15","categoryName":"Disk Management","options":null},"64642347b1169d63":{"id":"intelligencesettings_apps_safari","displayName":"Safari","description":"If present, configures Safari intelligence features.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":null},"6497c4349a36304f":{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_lowpriorityscheduledscan","displayName":"Run with low CPU priority","description":"This policy setting allows you to enable or disable low CPU priority for scheduled scans. If you enable this setting, low CPU priority will be used during scheduled scans. If you disable or do not configure this setting, not changes will be made to CPU priority for scheduled scans.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#scheduled-scan"],"categoryId":"0e1122f8-2bbf-475b-bce0-9e43a2f5e475","categoryName":"Schedule Scan","options":[{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_lowpriorityscheduledscan_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_lowpriorityscheduledscan_true","displayName":"Enabled","description":null,"helpText":null}]},"64683496b592741c":{"id":"linux_mdatp_managed_networkprotection_enforcementlevel","displayName":"Enforcement Level","description":"Specifies if network protection is disabled, in audit mode, or enforced","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-protection-linux?view=o365-worldwide"],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"linux_mdatp_managed_networkprotection_enforcementlevel_0","displayName":"disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_networkprotection_enforcementlevel_1","displayName":"audit","description":null,"helpText":null},{"id":"linux_mdatp_managed_networkprotection_enforcementlevel_2","displayName":"block","description":null,"helpText":null}]},"6495ac22cf7cd01d":{"id":"linux_platformupdatecontrols_version","displayName":"Platform Update Version","description":"Specifies the update channel for platform updates. 'N' is the latest version, 'N-1' is the previous version, 'N-2' is two versions back. Select 'Fixed' to pin to a specific version number.","helpText":null,"infoUrls":["https://learn.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#platform-update-preferences"],"categoryId":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","categoryName":"Platform Update","options":[{"id":"linux_platformupdatecontrols_version_n","displayName":"N","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_version_n1","displayName":"N-1","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_version_n2","displayName":"N-2","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_version_fixed","displayName":"Fixed","description":null,"helpText":null}]},"6456bb717f356382":{"id":"settings_item_timezone_timezone","displayName":"Time Zone","description":"The Internet Assigned Numbers Authority (IANA) time zone database name.\n\nIf the `forceAutomaticDateAndTime` restriction is set in `Restrictions`, this setting fails with an error. Otherwise, setting this value disables automatic time zone logic. The user is still be able to change the time zone; for example, by turning automatic date and time back on. The intention is to allow setting the time zone when automatic determination isn't be available, such as when Location Services are off.","helpText":null,"infoUrls":[],"categoryId":"2c156b7e-99c8-4a21-a828-4f9b94479b0d","categoryName":"Time Zone","options":null},"649bc151f5496793":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"64e7da289bdddedd":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders14","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders14_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders14_1","displayName":"True","description":null,"helpText":null}]},"64997e2ab409d5bc":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_1","displayName":"Send data when on connected to a restricted/costed network (User)","description":"This policy setting determines whether Windows Error Reporting (WER) checks for a network cost policy that restricts the amount of data that is sent over the network.\r\n\r\nIf you enable this policy setting, WER does not check for network cost policy restrictions, and transmits data even if network cost is restricted.\r\n\r\nIf you disable or do not configure this policy setting, WER does not send data, but will check the network cost policy again if the network profile is changed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassnetworkcostthrottling-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_1_1","displayName":"Enabled","description":null,"helpText":null}]},"6432cd0328658742":{"id":"user_vendor_msft_policy_config_admx_printing_intranetprintersurl_intranetprintersurl_link","displayName":"Printers Page URL (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},"649327e89067362f":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner","displayName":"Microsoft SharePoint Designer 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Designer 2010.\r\nBy default, the user settings of Microsoft SharePoint Designer 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Designer 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Designer 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Designer 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointdesigner"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner_1","displayName":"Enabled","description":null,"helpText":null}]},"64dcb7ea6860c71e":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configuremmsproxysettings_bypassproxylocal","displayName":"Bypass proxy for local addresses (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configuremmsproxysettings_bypassproxylocal_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configuremmsproxysettings_bypassproxylocal_1","displayName":"True","description":null,"helpText":null}]},"644e2c9be3bc434b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon","displayName":"Hide the web store from the New Tab Page and app launcher (User)","description":"Hide the Chrome Web Store app and footer link from the New Tab Page and Google Chrome OS app launcher.\r\n\r\nWhen this policy is set to true, the icons are hidden.\r\n\r\nWhen this policy is set to false or is not configured, the icons are visible.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon_1","displayName":"Enabled","description":null,"helpText":null}]},"6463980d38fd1ac0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended","displayName":"Application locale (User)","description":"Setting the policy specifies the locale Google Chrome uses.\r\n\r\nTurning it off or leaving it unset means the locale will be the first valid locale from:\r\n1) The user specified locale (if configured).\r\n2) The system locale.\r\n3) The fallback locale (en-US).\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"646f453bf72bd4b8":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_0","displayName":"Show expanded enterprise toolbar badge","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_1","displayName":"Hide expanded enterprise toolbar badge","description":null,"helpText":null}]},"64692a08bb60e4b9":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},"64c4b13a2339a2d6":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"647fb1310c58f2a5":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null}]},"64924f1c6c17db2c":{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled","displayName":"Efficiency mode enabled (User)","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\r\n\r\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when efficiency mode should become active) policy. If the device does not have a battery, efficiency mode will always be active.\r\n\r\nIf you disable this policy, efficiency mode will never become active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect.\r\n\r\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"645939f402f5275b":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"64d15046b462b4e5":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled","displayName":"Allow users to open files using the ClickOnce protocol (User)","description":"Allow users to open files using the ClickOnce protocol. The ClickOnce protocol allows websites to request that the browser open files from a specific URL using the ClickOnce file handler on the user's computer or device.\r\n\r\nIf you enable this policy, users can open files using the ClickOnce protocol. This policy overrides the user's ClickOnce setting in the edge://flags/ page.\r\n\r\nIf you disable this policy, users can't open files using the ClickOnce protocol. Instead, the file will be saved to the file system using the browser. This policy overrides the user's ClickOnce setting in the edge://flags/ page.\r\n\r\nIf you don't configure this policy, users can't open files using the ClickOnce protocol. Users have the option to enable the use of the ClickOnce protocol with the edge://flags/ page.\r\n\r\nDisabling ClickOnce may prevent ClickOnce applications (.application files) from launching properly.\r\n\r\nFor more information about ClickOnce, see https://go.microsoft.com/fwlink/?linkid=2103872 and https://go.microsoft.com/fwlink/?linkid=2099880.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"64cb89daac549094":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist","displayName":"Disable printer types on the deny list (User)","description":"The printer types on the deny list won't be discovered or have their capabilities fetched.\r\n\r\nPlacing all printer types on the deny list effectively disables printing, because there's no print destination for documents.\r\n\r\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\r\n\r\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\r\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\r\n\r\nIn Microsoft version 93 or later, if you set this policy to 'pdf' it also disables the 'save as Pdf' option from the right click context menu.\r\n\r\nIn Microsoft version 103 or later, if you set this policy to 'onedrive' it also disables the 'save as Pdf (OneDrive)' option from print preview.\r\n\r\nPolicy options mapping:\r\n\r\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\r\n\r\n* extension (extension) = Extension-based destinations\r\n\r\n* pdf (pdf) = The 'Save as PDF' destination. (93 or later, also disables from context menu)\r\n\r\n* local (local) = Local printer destinations\r\n\r\n* onedrive (onedrive) = Save as PDF (OneDrive) printer destinations. (103 or later)\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nlocal\r\nprivet","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},"644ba90b113ac99f":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled","displayName":"Discover feature In Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.\r\n\r\nThis policy lets you configure the Discover feature in Microsoft Edge.\r\n\r\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\r\n\r\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"64cbd37cf6c48128":{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping","displayName":"Disable caching when opening server-only files. (User)","description":"This policy setting controls disabling caching when opening server-only files.\r\n\r\nCaching files helps Office speed up server-only file opens but could cause conflicts for organizations that rename files or change file contents directly on SharePoint.\r\n\r\nThe cache is meant to improve performance so disabling it is expected to hurt performance.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping_1","displayName":"Enabled","description":null,"helpText":null}]},"640dd1fca61cbb49":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicesharednotescustomurl9","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"64ed10373f998c8f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout_l_setdocumentsynchronizationtimeoutspinid","displayName":"in milliseconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","categoryName":"Co-authoring","options":null},"64b7582057f47dae":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},"648b68ce805a5c3e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart","displayName":"Enable MS Graph as Default Chart Tool in PowerPoint and Word (User)","description":"Enables administrators to set the default chart creation tool to MS Graph instead of the default Excel Chart in PowerPoint and Word. Also blocks conversion of Graph charts to Office charts.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart_1","displayName":"Enabled","description":null,"helpText":null}]},"64d65730cbead800":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian","displayName":"Latvian (User)","description":"Enables the editing language Latvian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian_1","displayName":"Enabled","description":null,"helpText":null}]},"6462964703f7b1d2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences","displayName":"[Deprecated] Allow the use of connected experiences in Office (User)","description":"\r\n This policy setting allows you to control whether connected experiences are available to your users when they're using Office.\r\n\r\n Connected experiences include experiences that analyze content, such as Editor in Word, experiences that download online content, such as PowerPoint QuickStarter, and other connected experiences, such as document co-authoring and online file storage. It also includes additional optional connected experiences, such as the LinkedIn features of the Resume Assistant in Word or the 3D Maps feature in Excel, which uses Bing. See the Note at the end for more information about other policy settings that you can use to control these connected experiences.\r\n\r\n If you enable this policy setting, these connected experiences will be available to your users.\r\n\r\n If you disable this policy setting, these connected experiences won't be available to your users.\r\n\r\n Note: If you disable this policy setting, nearly all connected experiences will be turned off. However, limited Office functionality will remain available, such as synching a mailbox in Outlook. Essential services, such as the licensing service that confirms that you’re properly licensed to use Office, will also remain available.\r\n\r\n If you don't configure this policy setting, these connected experiences will be available to your users.\r\n\r\n Note: You can use these other policy settings if you want to disable just a certain group of connected experiences:\"Allow the use of connected experiences in Office that analyze content,\" \"Allow the use of connected experiences in Office that download online content,\" and \"Allow the use of additional optional connected experiences in Office.\"\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085689\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},"64ebe14809d3c95d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_descriptioncolon276","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"64b032b94faaa508":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02_1","displayName":"True","description":null,"helpText":null}]},"640dcb42f30f3a5c":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver","displayName":"Continue syncing when devices have battery saver mode turned on (User)","description":"This setting lets you turn off the auto-pause feature for devices that have battery saver mode turned on.\r\n\r\nIf you enable this setting, syncing will continue when users turn on battery saver mode. OneDrive will not automatically pause syncing.\r\n\r\nIf you disable or do not configure this setting, syncing will pause automatically when battery saver mode is detected and a notification will be displayed. Users can choose not to pause syncing by clicking \"Sync Anyway\" in the notification. When syncing is paused, users can resume syncing by clicking the OneDrive cloud icon in the notification area of the taskbar and then clicking the alert at the top of the activity center.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver_1","displayName":"Enabled","description":null,"helpText":null}]},"6458ddf3807e122d":{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart","displayName":"Start OneDrive automatically when signing in to Windows (User)","description":"This setting overrides a user's choice, ensuring OneDrive will automatically start every time they sign in to Windows. \r\n \r\nIf you configure this setting, OneDrive will start automatically when a user signs in to Windows. The OneDrive sync app must be restarted after this setting is enabled for the setting to take effect.\r\n\r\nIf you do not configure this setting or set it to any value other than 1, the user can choose to automatically start OneDrive (default choice) or to disable OneDrive from starting in OneDrive sync app settings.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart_1","displayName":"Enabled","description":null,"helpText":null}]},"64d80b5cff5cd3de":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_l_enterpercentage","displayName":"Enter Percentage: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},"64510f2c91172343":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook","displayName":"Security setting for macros (User) (Deprecated)","description":"This policy setting controls the security level for macros in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for handling macros in Outlook: \r\n\r\n- Always warn. This option corresponds to the \"Warnings for all macros\" option in the \"Macro Security\" section of the Outlook Trust Center. Outlook disables all macros that are not opened from a trusted location, even if the macros are signed by a trusted publisher. For each disabled macro, Outlook displays a security alert dialog box with information about the macro and its digital signature (if present), and allows users to enable the macro or leave it disabled. \r\n\r\n- Never warn, disable all. This option corresponds to the \"No warnings and disable all macros\" option in the Trust Center. Outlook disables all macros that are not opened from trusted locations, and does not notify users. \r\n\r\n- Warning for signed, disable unsigned. This option corresponds to the \"Warnings for signed macros; all unsigned macros are disabled\" option in the Trust Center. Outlook handles macros as follows: \r\n\r\n--If a macro is digitally signed by a trusted publisher, the macro can run if the user has already trusted the publisher. \r\n\r\n--If a macro has a valid signature from a publisher that the user has not trusted, the security alert dialog box for the macro lets the user choose whether to enable the macro for the current session, disable the macro for the current session, or to add the publisher to the Trusted Publishers list so that it will run without prompting the user in the future. \r\n\r\n--If a macro does not have a valid signature, Outlook disables it without prompting the user, unless it is opened from a trusted location. \r\n\r\nThis option is the default configuration in Outlook. \r\n\r\n- No security check. This option corresponds to the \"No security check for macros (Not recommended)\" option in the Trust Center. Outlook runs all macros without prompting users. This configuration makes users' computers vulnerable to potentially malicious code and is not recommended. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of Enabled -- Warning for signed, disable unsigned.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"64ad5b00e9c43aef":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":null},"64e35d5b876171c8":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod","displayName":"Default task Earned Value method (User)","description":"Specifies the method used for earned value analysis.\r\n\r\nIf you enable this setting, Project will calculate earned value using the method you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_1","displayName":"Enabled","description":null,"helpText":null}]},"64882ac65c094687":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},"64d6c87191b357d3":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling","displayName":"Check grammar with spelling (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling_1","displayName":"Enabled","description":null,"helpText":null}]},"64eead8e31303859":{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_priority","displayName":"Priority (Windows Insiders only)","description":"Priority of a policy compared to the others where 1 represents the highest priority. Thus, the smaller this value is, the higher preference this specific network will receive in establishing a data connection. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},"64f2cccc6a87735f":{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_preferredprofilewakeconnectiontimerinseconds","displayName":"Preferred Profile Wake Connection Timer In Seconds (Windows Insiders only)","description":"When the device is woken from sleep with the most-preferred profile already enabled, this value configures the amount of time (in seconds) before the agent will give up on waiting for connection re-establishment with the most-preferred profile and start network discovery.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null}} \ No newline at end of file +{"6443d9080bd9fe52":{"id":"ade_setupassistant_passcode","displayName":"Passcode","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_passcode_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_passcode_1","displayName":"Show","description":null,"helpText":null}]},"645ab0a1c86bd9ca":{"id":"com.apple.managedclient.preferences_performancedetectorenabled","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\n\nIf you enable or don't configure this policy, performance detector is turned on.\n\nIf you disable this policy, performance detector is turned off.\n\nThe user can configure its behavior in edge://settings/system.\n\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#performancedetectorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_performancedetectorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_performancedetectorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"6446359bc1084085":{"id":"com.apple.system-extension-policy_nonremovablesystemextensions_generickey_keytobereplaced","displayName":"Non Removable System Extensions","description":"A dictionary of system extensions on the computer. The dictionary maps the team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension which cannot be disabled or uninstalled when SIP is enabled. It's an error for the same mapping to appear in the dictionary values corresponding to 'RemovableSystemExtensions' and 'NonRemovableSystemExtensions' keys.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"64991350c67550c4":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended","displayName":"Configure the Microsoft Edge new tab page experience (Obsolete) (users can override)","description":"This policy is obsolete because the new version of the enterprise new tab page no longer requires choosing between different content types. Instead, the content that's presented to the user can be controlled via the Microsoft 365 admin center. To get to the Microsoft 365 admin center, sign in at https://admin.microsoft.com with your admin account.\n\nLets you choose either the Microsoft News or Office 365 feed experience for the new tab page.\n\nIf you set this policy to 'News', users see the Microsoft News feed experience on the new tab page.\n\nIf you set this policy to 'Office', users with an Azure Active Directory browser sign-in see the Office 365 feed experience on the new tab page.\n\nIf you disable or don't configure this policy, users with an Azure Active Directory browser sign-in are offered the Office 365 new tab page feed experience, and the standard new tab page feed experience. Users without an Azure Active Directory browser sign-in to see the standard new tab page experience.\n\nIf you enable this policy *and* the \"NewTabPageLocation\" policy, \"NewTabPageLocation\" has precedence.\n\nPolicy options mapping:\n\n* News (0) = Microsoft News feed experience\n\n* Office (1) = Office 365 feed experience\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended_news","displayName":"Microsoft News feed experience","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpagesetfeedtype_recommended_office","displayName":"Office 365 feed experience","description":null,"helpText":null}]},"640e8dd28b62a7cc":{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (Deprecated)","description":"This policy provides a way to override the list of sets Microsoft Edge uses for Related Website Sets\n\nEach set in the browser's list of Related Website Sets must meet the requirements of a Related Website Set. A Related Website Set must contain a primary site and one or more member sites.\nA set can also contain a list of service sites that it owns, and a map from a site to all its ccTLD variants. For more information on how Microsoft Edge uses Related Website Sets, see https://github.com/WICG/first-party-sets.\n\n\nAll sites in a Related Website Set must be a registrable domain served over HTTPS. Each site in a Related Website Set must also be unique, which means a site can't be listed more than once in a Related Website Set.\n\nWhen this policy is given an empty dictionary, Microsoft Edge uses the public list of Related Website Sets.\n\nFor all sites in a Related Website Set from the replacements list, if a site is also present on a Related Website Set in the browser's list, then that site will be removed from the browser's Related Website Set. After this step, the policy's Related Website Set is added to the Microsoft Edge's list of Related Website Sets.\n\nFor all sites in a Related Website Set from the additions list, if a site is also present on a Related Website Set in Microsoft Edge's list, then the browser's Related Website Set is updated so that the new Related Website Set can be added to the browser's list. After the browser's list has been updated, the policy's Related Website Set is added to the browser's list of Related Website Sets.\n\nThe browser's list of Related Website Sets requires that for all sites in its list, no site is in\nmore than one set. This requirement is also required for both the replacements list\nand the additions list. Similarly, a site can't be in both the\nreplacements list and the additions list.\n\nWildcards (*) aren't supported as a policy value, or as a value within any Related Website Set in these lists.\n\nThis policy is deprecated as of Microsoft Edge version 144 with the deprecation of Related Website Sets.","helpText":null,"infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":null},"64d9d0736c3a0f5f":{"id":"device_vendor_msft_accountmanagement_userprofilemanagement_storagecapacitystopdeletion","displayName":"Storage Capacity Stop Deletion","description":"Stop deleting profiles when available storage capacity is brought up to this threshold, given as percent of total storage available for profiles.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/AccountManagement-csp/"],"categoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","categoryName":"Account Management","options":null},"64cde00985596c02":{"id":"device_vendor_msft_defender_configuration_disableftpparsing","displayName":"Disable Ftp Parsing","description":"This setting disables FTP Parsing for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disableftpparsing_1","displayName":"FTP parsing is disabled","description":"FTP parsing is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disableftpparsing_0","displayName":"FTP parsing is enabled","description":"FTP parsing is enabled","helpText":null}]},"64cd794bcd6e93ff":{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict","displayName":"Restrict system locales","description":"This policy setting restricts the permitted system locales to the specified list. If the list is empty, it locks the system locale to its current value. This policy setting does not change the existing system locale; however, the next time that an administrator attempts to change the computer's system locale, they will be restricted to the specified list.\r\n\r\nThe locale list is specified using language names, separated by a semicolon (;). For example, en-US is English (United States). Specifying \"en-US;en-CA\" would restrict the system locale to English (United States) and English (Canada).\r\n\r\nIf you enable this policy setting, administrators can select a system locale only from the specified system locale list.\r\n\r\nIf you disable or do not configure this policy setting, administrators can select any system locale shipped with the operating system.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-localesystemrestrict"],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_localesystemrestrict_1","displayName":"Enabled","description":null,"helpText":null}]},"6451429721c4ce1b":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2","displayName":"Synchronize all offline files before logging off","description":"Determines whether offline files are fully synchronized when users log off.\r\n\r\nThis setting also disables the \"Synchronize all offline files before logging off\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nIf you enable this setting, offline files are fully synchronized. Full synchronization ensures that offline files are complete and current.\r\n\r\nIf you disable this setting, the system only performs a quick synchronization. Quick synchronization ensures that files are complete, but does not ensure that they are current.\r\n\r\nIf you do not configure this setting, the system performs a quick synchronization by default, but users can change this option.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To change the synchronization method without changing a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then select the \"Synchronize all offline files before logging off\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-syncatlogoff-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_syncatlogoff_2_1","displayName":"Enabled","description":null,"helpText":null}]},"64647e757d06566e":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv","displayName":"Qualitative service type","description":"Specifies an alternate link layer (Layer-2) priority value for packets with the Qualitative service type (ServiceTypeQualitative). The Packet Scheduler inserts the corresponding priority value in the Layer-2 header of the packets.\r\n\r\nIf you enable this setting, you can change the default priority value associated with the Qualitative service type.\r\n\r\nIf you disable this setting, the system uses the default priority value of 0.\r\n\r\nImportant: If the Layer-2 priority value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypequalitative-pv"],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_pv_1","displayName":"Enabled","description":null,"helpText":null}]},"6428a11ba8eb5114":{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar","displayName":"Prevent changes to Taskbar and Start Menu Settings","description":"This policy setting allows you to prevent changes to Taskbar and Start Menu Settings.\n\nIf you enable this policy setting, The user will be prevented from opening the Taskbar Properties dialog box.\n\nIf the user right-clicks the taskbar and then clicks Properties, a message appears explaining that a setting prevents the action.\n\nIf you disable or do not configure this policy setting, the Taskbar and Start Menu items are available from Settings on the Start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosettaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nosettaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"648d841bcc2944c8":{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart","displayName":"Prevent users from uninstalling applications from Start","description":"If you enable this setting, users cannot uninstall apps from Start.\n\nIf you disable this setting or do not configure it, users can access the uninstall command from Start","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nouninstallfromstart"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_nouninstallfromstart_1","displayName":"Enabled","description":null,"helpText":null}]},"641324e039819430":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled","displayName":"Ping the settings storage location before sync","description":"This policy setting allows you to configure the User Experience Virtualization (UE-V) sync provider to ping the settings storage path before attempting to sync settings. If the ping is successful then the sync provider attempts to synchronize the settings packages. If the ping is unsuccessful then the sync provider doesn’t attempt the synchronization. \r\nIf you enable this policy setting, the sync provider pings the settings storage location before synchronizing settings packages.\r\nIf you disable this policy setting, the sync provider doesn’t ping the settings storage location before synchronizing settings packages. \r\nIf you do not configure this policy, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncproviderpingenabled"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_syncproviderpingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"641aa8a042cfd43b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Setting the policy to Enabled means browsing history is not saved, tab syncing is off and users can't change this setting.\r\n\r\nSetting the policy to Disabled or leaving it unset saves browsing history.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_savingbrowserhistorydisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"648a74e607640a70":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting","displayName":"Enable deprecated privet printing","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledeprecatedprivetprinting_1","displayName":"Enabled","description":null,"helpText":null}]},"64e9a75f420c59d2":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability","displayName":"Control availability of extensions unpublished on the Chrome Web Store. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability_0","displayName":"Allow unpublished extensions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionunpublishedavailability_extensionunpublishedavailability_1","displayName":"Disable unpublished extensions","description":null,"helpText":null}]},"64329e66f0de40bc":{"id":"device_vendor_msft_policy_config_defender_controlledfolderaccessallowedapplications","displayName":"Controlled Folder Access Allowed Applications","description":"The previous name was GuardedFoldersAllowedApplications and changed to ControlledFolderAccessAllowedApplications. This policy setting allows user-specified applications to the controlled folder access feature. Adding an allowed application means the controlled folder access feature will allow the application to modify or delete content in certain folders such as My Documents. In most cases it will not be necessary to add entries. Windows Defender Antivirus will automatically detect and dynamically add applications that are friendly. Value type is string. Use the | as the substring separator.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#controlledfolderaccessallowedapplications"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"64c327feb703105b":{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork","displayName":"Allow Option To Show Network","description":"When the Network folder is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshownetwork"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"64e539c8629bdbd6":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles","displayName":"Allow loading of XAML files","description":"This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.\n\nIf you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.\n\nIf you disable this policy setting, XAML files are not loaded inside Internet Explorer. The user cannot change this behavior.\n\nIf you do not configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowloadingofxamlfiles"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowloadingofxamlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"6435c117444711a4":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"64b9d5bd550ee6fe":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled","displayName":"Enable AutoFill for payment instruments","description":"Enables Microsoft Edge's AutoFill feature and lets users auto complete payment instruments like credit or debit cards in web forms using previously stored information. This includes suggesting new payment instruments like Buy Now Pay Later (BNPL) in web forms and Express Checkout.\r\n\r\nIf you enable this policy or don't configure it, users can control AutoFill for payment instruments.\r\n\r\nIf you disable this policy, AutoFill never suggests, fills, or recommends new payment Instruments. Additionally, it won't save any payment instrument information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"64d41a7cd1733bb2":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines","displayName":"Manage Search Engines","description":"Lets you configure a list of up to 10 search engines, one of which must be marked as the default search engine.\r\nYou do not need to specify the encoding. Starting in Microsoft Edge 80, the suggest_url and image_search_url parameters are optional. The optional parameter, image_search_post_params (consists of comma-separated name/value pairs), is available starting in Microsoft Edge 80.\r\n\r\nStarting in Microsoft Edge 83, you can enable search engine discovery with the allow_search_engine_discovery optional parameter. This parameter must be the first item in the list. If allow_search_engine_discovery is not specified, search engine discovery will be disabled by default.\r\n\r\nIf you enable this policy, users can't add, remove, or change any search engine in the list. Users can set their default search engine to any search engine in the list.\r\n\r\nIf you disable or don't configure this policy, users can modify the search engines list as desired.\r\n\r\nIf the 'DefaultSearchProviderSearchURL' (Default search provider search URL) policy is set, this policy (ManagedSearchEngines) is ignored. The user must restart their browser to finish applying this policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allow_search_engine_discovery\": true\r\n }, \r\n {\r\n \"is_default\": true, \r\n \"suggest_url\": \"https://www.example1.com/qbox?query={searchTerms}\", \r\n \"search_url\": \"https://www.example1.com/search?q={searchTerms}\", \r\n \"name\": \"Example1\", \r\n \"keyword\": \"example1.com\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example2.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example2.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example2\", \r\n \"keyword\": \"example2.com\", \r\n \"image_search_post_params\": \"content={imageThumbnail},url={imageURL},sbisrc={SearchSource}\", \r\n \"search_url\": \"https://www.example2.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"suggest_url\": \"https://www.example3.com/qbox?query={searchTerms}\", \r\n \"image_search_url\": \"https://www.example3.com/images/detail/search?iss=sbiupload\", \r\n \"name\": \"Example3\", \r\n \"keyword\": \"example3.com\", \r\n \"encoding\": \"UTF-8\", \r\n \"search_url\": \"https://www.example3.com/search?q={searchTerms}\"\r\n }, \r\n {\r\n \"search_url\": \"https://www.example4.com/search?q={searchTerms}\", \r\n \"name\": \"Example4\", \r\n \"keyword\": \"example4.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedsearchengines_1","displayName":"Enabled","description":null,"helpText":null}]},"6450b4b926b09e42":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"644bb6fb988af96d":{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled","displayName":"Allows users to translate videos to different languages.","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\r\nWith this feature, users can watch videos translated into their selected language in real time.\r\n\r\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\r\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\r\n\r\nThese components may be updated periodically to improve performance and translation quality.\r\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\r\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\r\nFor more details, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\r\n\r\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\r\nusers will see the Translate button when hovering over videos.\r\n\r\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button won’t be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"643cc747d9ef4230":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\r\n\r\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\r\n\r\nIf you disable this setting, employees will not receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_showpdfdefaultrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"6438d904d5bcce9c":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed","displayName":"Allow sites configured for Internet Explorer mode to open in Microsoft Edge","description":"This policy lets sites configured to open in Internet Explorer mode to be opened by Microsoft Edge for testing on a modern browser without removing them from the site list.\r\n\r\nUsers can configure this setting in the \"More tools\" menu by selecting 'Open sites in Microsoft Edge'.\r\n\r\nIf you enable this policy, the option to 'Open sites in Microsoft Edge' will be visible under \"More tools\". Users use this option to test IE mode sites on a modern browser.\r\n\r\nIf you disable or don't configure this policy, users can't see the option 'Open in Microsoft Edge' under the \"More tools\" menu. However, users can access this menu option with the --ie-mode-test flag.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_internetexplorermodetabinedgemodeallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"64936fd32d8cbbb5":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessbackgroundspatialperception_forcedenytheseapps","displayName":"Let Apps Access Background Spatial Perception Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. Listed apps are denied access to the user's movements while the apps are running in the background. This setting overrides the default LetAppsAccessBackgroundSpatialPerception policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessbackgroundspatialperception_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"64bb31b74d3c4bcf":{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbasedoccurrenceinmonth","displayName":"Maintenance Window Monthly Week Based Occurrence In Month","description":"If the maintenance window repeat schedule is set to monthly, and set to repeat on the a specific day of a specific week, configure the specific week to repeat maintenance window occurrence. 1=first week, 2=second week, 3=third week, 4=fourth week, 5=last week.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowmonthlyweekbasedoccurrenceinmonth"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbasedoccurrenceinmonth_1","displayName":"First","description":"First","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbasedoccurrenceinmonth_2","displayName":"Second","description":"Second","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbasedoccurrenceinmonth_3","displayName":"Third","description":"Third","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbasedoccurrenceinmonth_4","displayName":"Fourth","description":"Fourth","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbasedoccurrenceinmonth_5","displayName":"Last","description":"Last","helpText":null}]},"648a91ae9e7e0a53":{"id":"device_vendor_msft_policy_config_update_scheduleimminentrestartwarning","displayName":"[Deprecated] Schedule Imminent Restart Warning","description":"Allows the IT Admin to specify the period for auto-restart imminent warning notifications. The default value is 15 (minutes).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#update-scheduleimminentrestartwarning"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"64612de443fb8b61":{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging","displayName":"Turn on PowerShell Script Block Logging","description":"\n This policy setting enables logging of all PowerShell script input to the Microsoft-Windows-PowerShell/Operational event log. If you enable this policy setting,\n Windows PowerShell will log the processing of commands, script blocks, functions, and scripts - whether invoked interactively, or through automation.\n \n If you disable this policy setting, logging of PowerShell script input is disabled.\n \n If you enable the Script Block Invocation Logging, PowerShell additionally logs events when invocation of a command, script block, function, or script\n starts or stops. Enabling Invocation Logging generates a high volume of event logs.\n \n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowspowershell#windowspowershell-turnonpowershellscriptblocklogging"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_1","displayName":"Enabled","description":null,"helpText":null}]},"64a8ff9fbdcb3e2a":{"id":"diskmanagement_diskmanagement","displayName":"com.apple.configuration.diskmanagement.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"83febe72-a64f-4051-9071-1efae1ea9a15","categoryName":"Disk Management","options":null},"64642347b1169d63":{"id":"intelligencesettings_apps_safari","displayName":"Safari","description":"If present, configures Safari intelligence features.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":null},"6497c4349a36304f":{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_lowpriorityscheduledscan","displayName":"Run with low CPU priority","description":"This policy setting allows you to enable or disable low CPU priority for scheduled scans. If you enable this setting, low CPU priority will be used during scheduled scans. If you disable or do not configure this setting, not changes will be made to CPU priority for scheduled scans.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#scheduled-scan"],"categoryId":"0e1122f8-2bbf-475b-bce0-9e43a2f5e475","categoryName":"Schedule Scan","options":[{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_lowpriorityscheduledscan_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scheduledscan_lowpriorityscheduledscan_true","displayName":"Enabled","description":null,"helpText":null}]},"64683496b592741c":{"id":"linux_mdatp_managed_networkprotection_enforcementlevel","displayName":"Enforcement Level","description":"Specifies if network protection is disabled, in audit mode, or enforced","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/network-protection-linux?view=o365-worldwide"],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"linux_mdatp_managed_networkprotection_enforcementlevel_0","displayName":"disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_networkprotection_enforcementlevel_1","displayName":"audit","description":null,"helpText":null},{"id":"linux_mdatp_managed_networkprotection_enforcementlevel_2","displayName":"block","description":null,"helpText":null}]},"6495ac22cf7cd01d":{"id":"linux_platformupdatecontrols_version","displayName":"Platform Update Version","description":"Specifies the update channel for platform updates. 'N' is the latest version, 'N-1' is the previous version, 'N-2' is two versions back. Select 'Fixed' to pin to a specific version number.","helpText":null,"infoUrls":["https://learn.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#platform-update-preferences"],"categoryId":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","categoryName":"Platform Update","options":[{"id":"linux_platformupdatecontrols_version_n","displayName":"N","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_version_n1","displayName":"N-1","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_version_n2","displayName":"N-2","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_version_fixed","displayName":"Fixed","description":null,"helpText":null}]},"646a7971ced3b54c":{"id":"plugin_filter_grade","displayName":"Grade","description":"The system uses this value to derive the relative order of content filters. Filters with a grade of `firewall` see network traffic before filters with a grade of `inspector`. However, the system doesn't define the order of filters within a grade.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":[{"id":"plugin_filter_grade_0","displayName":"firewall","description":null,"helpText":null},{"id":"plugin_filter_grade_1","displayName":"inspector","description":null,"helpText":null}]},"6456bb717f356382":{"id":"settings_item_timezone_timezone","displayName":"Time Zone","description":"The Internet Assigned Numbers Authority (IANA) time zone database name.\n\nIf the `forceAutomaticDateAndTime` restriction is set in `Restrictions`, this setting fails with an error. Otherwise, setting this value disables automatic time zone logic. The user is still be able to change the time zone; for example, by turning automatic date and time back on. The intention is to allow setting the time zone when automatic determination isn't be available, such as when Location Services are off.","helpText":null,"infoUrls":[],"categoryId":"2c156b7e-99c8-4a21-a828-4f9b94479b0d","categoryName":"Time Zone","options":null},"649bc151f5496793":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"64e7da289bdddedd":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders14","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders14_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_allowsubfolders14_1","displayName":"True","description":null,"helpText":null}]},"64997e2ab409d5bc":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_1","displayName":"Send data when on connected to a restricted/costed network (User)","description":"This policy setting determines whether Windows Error Reporting (WER) checks for a network cost policy that restricts the amount of data that is sent over the network.\r\n\r\nIf you enable this policy setting, WER does not check for network cost policy restrictions, and transmits data even if network cost is restricted.\r\n\r\nIf you disable or do not configure this policy setting, WER does not send data, but will check the network cost policy again if the network profile is changed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassnetworkcostthrottling-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassnetworkcostthrottling_1_1","displayName":"Enabled","description":null,"helpText":null}]},"6432cd0328658742":{"id":"user_vendor_msft_policy_config_admx_printing_intranetprintersurl_intranetprintersurl_link","displayName":"Printers Page URL (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},"649327e89067362f":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner","displayName":"Microsoft SharePoint Designer 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Designer 2010.\r\nBy default, the user settings of Microsoft SharePoint Designer 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Designer 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Designer 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Designer 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointdesigner"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointdesigner_1","displayName":"Enabled","description":null,"helpText":null}]},"64dcb7ea6860c71e":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configuremmsproxysettings_bypassproxylocal","displayName":"Bypass proxy for local addresses (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configuremmsproxysettings_bypassproxylocal_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configuremmsproxysettings_bypassproxylocal_1","displayName":"True","description":null,"helpText":null}]},"644e2c9be3bc434b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon","displayName":"Hide the web store from the New Tab Page and app launcher (User)","description":"Hide the Chrome Web Store app and footer link from the New Tab Page and Google Chrome OS app launcher.\r\n\r\nWhen this policy is set to true, the icons are hidden.\r\n\r\nWhen this policy is set to false or is not configured, the icons are visible.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_hidewebstoreicon_1","displayName":"Enabled","description":null,"helpText":null}]},"6463980d38fd1ac0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended","displayName":"Application locale (User)","description":"Setting the policy specifies the locale Google Chrome uses.\r\n\r\nTurning it off or leaving it unset means the locale will be the first valid locale from:\r\n1) The user specified locale (if configured).\r\n2) The system locale.\r\n3) The fallback locale (en-US).\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_applicationlocalevalue_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"646f453bf72bd4b8":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_0","displayName":"Show expanded enterprise toolbar badge","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_1","displayName":"Hide expanded enterprise toolbar badge","description":null,"helpText":null}]},"64692a08bb60e4b9":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":null},"64c4b13a2339a2d6":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"647fb1310c58f2a5":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null}]},"64924f1c6c17db2c":{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled","displayName":"Efficiency mode enabled (User)","description":"Enables efficiency mode which helps extend battery life by saving computer resources. By default, efficiency mode is enabled for devices with a battery and disabled otherwise.\r\n\r\nIf you enable this policy, efficiency mode will become active according to the setting chosen by the user. You can configure the efficiency mode setting using the 'EfficiencyMode' (Configure when efficiency mode should become active) policy. If the device does not have a battery, efficiency mode will always be active.\r\n\r\nIf you disable this policy, efficiency mode will never become active. The 'EfficiencyMode' and 'EfficiencyModeOnPowerEnabled' (Enable efficiency mode when the device is connected to a power source) policies will have no effect.\r\n\r\nIf you don't configure this policy, efficiency mode will be enabled for devices with a battery and disabled otherwise. Users can choose the efficiency mode option they want in edge://settings/system.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"645939f402f5275b":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"64d15046b462b4e5":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled","displayName":"Allow users to open files using the ClickOnce protocol (User)","description":"Allow users to open files using the ClickOnce protocol. The ClickOnce protocol allows websites to request that the browser open files from a specific URL using the ClickOnce file handler on the user's computer or device.\r\n\r\nIf you enable this policy, users can open files using the ClickOnce protocol. This policy overrides the user's ClickOnce setting in the edge://flags/ page.\r\n\r\nIf you disable this policy, users can't open files using the ClickOnce protocol. Instead, the file will be saved to the file system using the browser. This policy overrides the user's ClickOnce setting in the edge://flags/ page.\r\n\r\nIf you don't configure this policy, users can't open files using the ClickOnce protocol. Users have the option to enable the use of the ClickOnce protocol with the edge://flags/ page.\r\n\r\nDisabling ClickOnce may prevent ClickOnce applications (.application files) from launching properly.\r\n\r\nFor more information about ClickOnce, see https://go.microsoft.com/fwlink/?linkid=2103872 and https://go.microsoft.com/fwlink/?linkid=2099880.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clickonceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"64cb89daac549094":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist","displayName":"Disable printer types on the deny list (User)","description":"The printer types on the deny list won't be discovered or have their capabilities fetched.\r\n\r\nPlacing all printer types on the deny list effectively disables printing, because there's no print destination for documents.\r\n\r\nIf you don't configure this policy, or the printer list is empty, all printer types are discoverable.\r\n\r\nPrinter destinations include extension printers and local printers. Extension printers are also known as print provider destinations, and include any destination that belongs to a Microsoft Edge extension.\r\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\r\n\r\nIn Microsoft version 93 or later, if you set this policy to 'pdf' it also disables the 'save as Pdf' option from the right click context menu.\r\n\r\nIn Microsoft version 103 or later, if you set this policy to 'onedrive' it also disables the 'save as Pdf (OneDrive)' option from print preview.\r\n\r\nPolicy options mapping:\r\n\r\n* privet (privet) = Zeroconf-based (mDNS + DNS-SD) protocol destinations\r\n\r\n* extension (extension) = Extension-based destinations\r\n\r\n* pdf (pdf) = The 'Save as PDF' destination. (93 or later, also disables from context menu)\r\n\r\n* local (local) = Local printer destinations\r\n\r\n* onedrive (onedrive) = Save as PDF (OneDrive) printer destinations. (103 or later)\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\nlocal\r\nprivet","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~printing_printertypedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},"644ba90b113ac99f":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled","displayName":"Discover feature In Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.\r\n\r\nThis policy lets you configure the Discover feature in Microsoft Edge.\r\n\r\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\r\n\r\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgediscoverenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"64cbd37cf6c48128":{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping","displayName":"Disable caching when opening server-only files. (User)","description":"This policy setting controls disabling caching when opening server-only files.\r\n\r\nCaching files helps Office speed up server-only file opens but could cause conflicts for organizations that rename files or change file contents directly on SharePoint.\r\n\r\nThe cache is meant to improve performance so disabling it is expected to hurt performance.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v15~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableresourceidnamemapping_1","displayName":"Enabled","description":null,"helpText":null}]},"640dd1fca61cbb49":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastservicesharednotescustomurl9","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"64ed10373f998c8f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_coauthoring_l_setdocumentsynchronizationtimeout_l_setdocumentsynchronizationtimeoutspinid","displayName":"in milliseconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","categoryName":"Co-authoring","options":null},"64b7582057f47dae":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},"648b68ce805a5c3e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart","displayName":"Enable MS Graph as Default Chart Tool in PowerPoint and Word (User)","description":"Enables administrators to set the default chart creation tool to MS Graph instead of the default Excel Chart in PowerPoint and Word. Also blocks conversion of Graph charts to Office charts.","helpText":"","infoUrls":[],"categoryId":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","categoryName":"Graph settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_graphsettings_l_enablemsgraphasdefaultchart_1","displayName":"Enabled","description":null,"helpText":null}]},"64d65730cbead800":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian","displayName":"Latvian (User)","description":"Enables the editing language Latvian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_latvian_1","displayName":"Enabled","description":null,"helpText":null}]},"6462964703f7b1d2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences","displayName":"[Deprecated] Allow the use of connected experiences in Office (User)","description":"\r\n This policy setting allows you to control whether connected experiences are available to your users when they're using Office.\r\n\r\n Connected experiences include experiences that analyze content, such as Editor in Word, experiences that download online content, such as PowerPoint QuickStarter, and other connected experiences, such as document co-authoring and online file storage. It also includes additional optional connected experiences, such as the LinkedIn features of the Resume Assistant in Word or the 3D Maps feature in Excel, which uses Bing. See the Note at the end for more information about other policy settings that you can use to control these connected experiences.\r\n\r\n If you enable this policy setting, these connected experiences will be available to your users.\r\n\r\n If you disable this policy setting, these connected experiences won't be available to your users.\r\n\r\n Note: If you disable this policy setting, nearly all connected experiences will be turned off. However, limited Office functionality will remain available, such as synching a mailbox in Outlook. Essential services, such as the licensing service that confirms that you’re properly licensed to use Office, will also remain available.\r\n\r\n If you don't configure this policy setting, these connected experiences will be available to your users.\r\n\r\n Note: You can use these other policy settings if you want to disable just a certain group of connected experiences:\"Allow the use of connected experiences in Office that analyze content,\" \"Allow the use of connected experiences in Office that download online content,\" and \"Allow the use of additional optional connected experiences in Office.\"\r\n\r\n For more information, see https://go.microsoft.com/fwlink/p/?linkid=2085689\r\n ","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_connectedofficeexperiences_1","displayName":"Enabled","description":null,"helpText":null}]},"64ebe14809d3c95d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc10_l_descriptioncolon276","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"64b032b94faaa508":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc02_l_allowsubfolders02_1","displayName":"True","description":null,"helpText":null}]},"640dcb42f30f3a5c":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver","displayName":"Continue syncing when devices have battery saver mode turned on (User)","description":"This setting lets you turn off the auto-pause feature for devices that have battery saver mode turned on.\r\n\r\nIf you enable this setting, syncing will continue when users turn on battery saver mode. OneDrive will not automatically pause syncing.\r\n\r\nIf you disable or do not configure this setting, syncing will pause automatically when battery saver mode is detected and a notification will be displayed. Users can choose not to pause syncing by clicking \"Sync Anyway\" in the notification. When syncing is paused, users can resume syncing by clicking the OneDrive cloud icon in the notification area of the taskbar and then clicking the alert at the top of the activity center.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablepauseonbatterysaver_1","displayName":"Enabled","description":null,"helpText":null}]},"6458ddf3807e122d":{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart","displayName":"Start OneDrive automatically when signing in to Windows (User)","description":"This setting overrides a user's choice, ensuring OneDrive will automatically start every time they sign in to Windows. \r\n \r\nIf you configure this setting, OneDrive will start automatically when a user signs in to Windows. The OneDrive sync app must be restarted after this setting is enabled for the setting to take effect.\r\n\r\nIf you do not configure this setting or set it to any value other than 1, the user can choose to automatically start OneDrive (default choice) or to disable OneDrive from starting in OneDrive sync app settings.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_enableautostart_1","displayName":"Enabled","description":null,"helpText":null}]},"64d80b5cff5cd3de":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_percentageofunuseddiskspacetoallowinsections_l_enterpercentage","displayName":"Enter Percentage: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":null},"64510f2c91172343":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook","displayName":"Security setting for macros (User) (Deprecated)","description":"This policy setting controls the security level for macros in Outlook. \r\n\r\nIf you enable this policy setting, you can choose from four options for handling macros in Outlook: \r\n\r\n- Always warn. This option corresponds to the \"Warnings for all macros\" option in the \"Macro Security\" section of the Outlook Trust Center. Outlook disables all macros that are not opened from a trusted location, even if the macros are signed by a trusted publisher. For each disabled macro, Outlook displays a security alert dialog box with information about the macro and its digital signature (if present), and allows users to enable the macro or leave it disabled. \r\n\r\n- Never warn, disable all. This option corresponds to the \"No warnings and disable all macros\" option in the Trust Center. Outlook disables all macros that are not opened from trusted locations, and does not notify users. \r\n\r\n- Warning for signed, disable unsigned. This option corresponds to the \"Warnings for signed macros; all unsigned macros are disabled\" option in the Trust Center. Outlook handles macros as follows: \r\n\r\n--If a macro is digitally signed by a trusted publisher, the macro can run if the user has already trusted the publisher. \r\n\r\n--If a macro has a valid signature from a publisher that the user has not trusted, the security alert dialog box for the macro lets the user choose whether to enable the macro for the current session, disable the macro for the current session, or to add the publisher to the Trusted Publishers list so that it will run without prompting the user in the future. \r\n\r\n--If a macro does not have a valid signature, Outlook disables it without prompting the user, unless it is opened from a trusted location. \r\n\r\nThis option is the default configuration in Outlook. \r\n\r\n- No security check. This option corresponds to the \"No security check for macros (Not recommended)\" option in the Trust Center. Outlook runs all macros without prompting users. This configuration makes users' computers vulnerable to potentially malicious code and is not recommended. \r\n\r\nIf you disable or do not configure this policy setting, the behavior is the equivalent of Enabled -- Warning for signed, disable unsigned.","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"64ad5b00e9c43aef":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","categoryName":"Trust Center","options":null},"64e35d5b876171c8":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod","displayName":"Default task Earned Value method (User)","description":"Specifies the method used for earned value analysis.\r\n\r\nIf you enable this setting, Project will calculate earned value using the method you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevmethod_1","displayName":"Enabled","description":null,"helpText":null}]},"64882ac65c094687":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},"64d6c87191b357d3":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling","displayName":"Check grammar with spelling (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_checkgrammarwithspelling_1","displayName":"Enabled","description":null,"helpText":null}]},"64eead8e31303859":{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_priority","displayName":"Priority (Windows Insiders only)","description":"Priority of a policy compared to the others where 1 represents the highest priority. Thus, the smaller this value is, the higher preference this specific network will receive in establishing a data connection. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null},"64f2cccc6a87735f":{"id":"vendor_msft_wirelessnetworkpreference_parameters_cellularparameters_preferredprofilewakeconnectiontimerinseconds","displayName":"Preferred Profile Wake Connection Timer In Seconds (Windows Insiders only)","description":"When the device is woken from sleep with the most-preferred profile already enabled, this value configures the amount of time (in seconds) before the agent will give up on waiting for connection re-establishment with the most-preferred profile and start network discovery.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/69.json b/public/intune-definitions/69.json index e9997c7f598f..3722d0997b2e 100644 --- a/public/intune-definitions/69.json +++ b/public/intune-definitions/69.json @@ -1 +1 @@ -{"692e8daef999e1c9":{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints","displayName":"Skip first use hints","description":"If 'True', hides or skips suggestions from apps that step through tutorials, or hints when the app starts. If 'False', Intune doesn't change or update this setting. By default, the OS might show these suggestions when the app starts. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints_false","displayName":"False","description":"false","helpText":null}]},"691a0be5fe58f295":{"id":"com.apple.applicationaccess_allowlockscreentodayview","displayName":"Allow Lock Screen Today View","description":"If false, disables the Today view in Notification Center on the lock screen. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreentodayview_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreentodayview_true","displayName":"True","description":null,"helpText":null}]},"69dadbecedc3a086":{"id":"com.apple.managedclient.preferences_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\n\nIf you enable this policy, services and export targets that match the given list are blocked.\n\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\n\nPolicy options mapping:\n\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\n\n* collections_share (collections_share) = Sharing of Collections\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#collectionsservicesandexportsblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"69d2b29d6c2de415":{"id":"com.apple.mcx.timemachine_com.apple.mcx.timemachine","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},"698c300f2119c8c1":{"id":"com.apple.subscribedcalendar.account_subcalaccountpassword","displayName":"Account Password","description":"The user’s password.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},"6930c51eda50465a":{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},"6946d416d2c6f694":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"6913d8b12caeec6e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended","displayName":"Enable Wallet Checkout feature (users can override)","description":"Enables Wallet Checkout feature in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.\n\nIf you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"69250dc929dd5136":{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering","displayName":"Disable Inbound Connection Filtering","description":"This setting disables Inbound connection filtering for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering_1","displayName":"Inbound connection filtering is disabled","description":"Inbound connection filtering is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering_0","displayName":"Inbound connection filtering is enabled","description":"Inbound connection filtering is enabled","helpText":null}]},"69d61f645b084c4c":{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel","displayName":"Security Intelligence Updates Channel","description":"Enable this policy to specify when devices receive Microsoft Defender security intelligence updates during the daily gradual rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_0","displayName":"Not configured (Default). Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which may not be suitable for devices in a production or critical environment","description":"Not configured (Default). Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which may not be suitable for devices in a production or critical environment","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_4","displayName":"Current Channel (Staged): Same as Current Channel (Broad).","description":"Current Channel (Staged): Same as Current Channel (Broad).","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_5","displayName":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.","description":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.","helpText":null}]},"69e3be12d4bde83b":{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerserver","displayName":"Corporate server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"69b82bbc633e5a3a":{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2","displayName":"Turn off the \"Publish to Web\" task for files and folders","description":"This policy setting specifies whether the tasks \"Publish this file to the Web,\" \"Publish this folder to the Web,\" and \"Publish the selected items to the Web\" are available from File and Folder Tasks in Windows folders.\r\n\r\nThe Web Publishing Wizard is used to download a list of providers and allow users to publish content to the web.\r\n\r\nIf you enable this policy setting, these tasks are removed from the File and Folder tasks in Windows folders.\r\n\r\nIf you disable or do not configure this policy setting, the tasks are shown.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremovepublishtoweb-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2_1","displayName":"Enabled","description":null,"helpText":null}]},"694133f708ce4238":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning","displayName":"Turn on reparse point scanning","description":"This policy setting allows you to configure reparse point scanning. If you allow reparse points to be scanned, there is a possible risk of recursion. However, the engine supports following reparse points to a maximum depth so at worst scanning could be slowed. Reparse point scanning is disabled by default and this is the recommended state for this functionality. \r\n\r\n If you enable this setting, reparse point scanning will be enabled.\r\n\r\n If you disable or do not configure this setting, reparse point scanning will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablereparsepointscanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning_1","displayName":"Enabled","description":null,"helpText":null}]},"69fbf050967ab686":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6","displayName":"MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)","description":"MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxdataretransmissionsipv6"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_1","displayName":"Enabled","description":null,"helpText":null}]},"69decf2e17f96d87":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_javascriptjitblockedforsitesdesc","displayName":"Block JavaScript from using JIT on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"699d020baca5cdd2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"698cf6d9eea84eb6":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to apply restrictions to requests to local network endpoints","description":"When this policy is set to Enabled, any time when a warning is supposed to be\r\ndisplayed in the DevTools due to Local Network Access checks failing, the\r\nmain request will be blocked instead.\r\n\r\nWhen this policy is set to Disabled or unset, Local Network Access requests will use the\r\ndefault handling of these requests.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"694306bb24ab2356":{"id":"device_vendor_msft_policy_config_cryptography_tlsciphersuites","displayName":"TLS Cipher Suites","description":"Lists the Cryptographic Cipher Algorithms allowed for SSL connections. Format is a semicolon delimited list. Last write wins.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cryptography#tlsciphersuites"],"categoryId":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","categoryName":"Cryptography","options":null},"69484af823040189":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductiononlyexclusions","displayName":"Attack Surface Reduction Only Exclusions","description":"This policy setting allows you to prevent Attack Surface reduction rules from matching on files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: c:\\Windows to exclude all files in this directory. A fully qualified resource name might be defined as: C:\\Windows\\App.exe. Value type is string.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#attacksurfacereductiononlyexclusions"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"698ddac1bfcbce0b":{"id":"device_vendor_msft_policy_config_desktopappinstaller_enableappinstaller","displayName":"Enable App Installer","description":"This policy controls whether the Windows Package Manager can be used by users.\n\nIf you enable or do not configure this setting, users will be able to use the Windows Package Manager.\n\nIf you disable this setting, users will not be able to use the Windows Package Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-enableappinstaller"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_enableappinstaller_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_enableappinstaller_1","displayName":"Enabled","description":null,"helpText":null}]},"69ef08d28ab2ed61":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcoutlookcachedmode","displayName":"Outlook Cached Mode","description":"When the ODFC Container is successfully attached, set Outlook to work in cached mode for the user. The setting change will only be effective for the specific user and for the length of the user session.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\OutlookCachedMode\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled (only if container is attached)","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcoutlookcachedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcoutlookcachedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"699d28b4e610a509":{"id":"device_vendor_msft_policy_config_kerberos_upnnamehints","displayName":"UPN Name Hints","description":"Devices joined to Azure Active Directory in a hybrid environment need to interact with Active Directory Domain Controllers, but they lack the built-in ability to find a Domain Controller that a domain-joined device has. This can cause failures when such a device needs to resolve an AAD UPN into an Active Directory Principal. This parameter adds a list of domains that an Azure Active Directory joined device should attempt to contact if it is otherwise unable to resolve a UPN to a principal.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Kerberos#upnnamehints"],"categoryId":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","categoryName":"Kerberos","options":null},"69c0ede215a2a341":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_pluginsblockedforurlsdesc","displayName":"Block the Adobe Flash plug-in on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"691fcffcf47d04cc":{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled","displayName":"Synonyms are provided when using Microsoft Editor spell checker","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature.\r\n\r\nIf you enable this policy, Microsoft Editor spell checker will provide synonyms for suggestions for misspelled words.\r\n\r\nIf you disable or don't configure this policy, Microsoft Editor spell checker will not provide synonyms for suggestions for misspelled words.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy or the 'MicrosoftEditorProofingEnabled' (Spell checking provided by Microsoft Editor) policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"691c58127371f77d":{"id":"device_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context","description":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that can be used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\r\n\r\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\r\n\r\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\r\n\r\nMicrosoft Edge will require cross-origin isolation when using SharedArrayBuffers from Microsoft Edge 91 onward for Web Compatibility reasons.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"69122b3ec34a32dc":{"id":"device_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector","displayName":"Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a file is attached to Microsoft Edge.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*\"\r\n ]\r\n },\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},"69005f9fdee43759":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled","displayName":"Suggest similar pages when a webpage can’t be found","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"69db3da8cd042a2f":{"id":"device_vendor_msft_policy_config_power_turnoffhybridsleeppluggedin","displayName":"Turn Off Hybrid Sleep Plugged In","description":"This policy setting allows you to turn off hybrid sleep. If you set this to 0, a hiberfile is not generated when the system transitions to sleep (Stand By). If you do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#turnoffhybridsleeppluggedin"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":[{"id":"device_vendor_msft_policy_config_power_turnoffhybridsleeppluggedin_0","displayName":"","description":"","helpText":null},{"id":"device_vendor_msft_policy_config_power_turnoffhybridsleeppluggedin_1","displayName":"hybrid sleep","description":"hybrid sleep","helpText":null}]},"693cd968a8edb564":{"id":"device_vendor_msft_policy_config_update_autorestartdeadlineperiodindaysforfeatureupdates","displayName":"Auto Restart Deadline Period In Days For Feature Updates","description":"For Feature Updates, this policy specifies the deadline in days before automatically executing a scheduled restart outside of active hours. The deadline can be set between 2 and 30 days from the time the restart is scheduled. The system will reboot on or after the specified deadline. The reboot is prioritized over any configured Active Hours and any existing system and user busy checks. Value type is integer. Default is 7 days. Supported values range: 2-30. Note that the PC must restart for certain updates to take effect. If you enable this policy, a restart will automatically occur the specified number of days after the restart was scheduled. If you disable or do not configure this policy, the PC will restart according to the default schedule. If any of the following two policies are enabled, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installations. Always automatically restart at scheduled time.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#autorestartdeadlineperiodindaysforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"69a98749db6c3163":{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautoreboot","displayName":"Configure Deadline No Auto Reboot","description":"When enabled, devices will not automatically restart outside of active hours until the deadline and grace period have expired, even if an update is ready for restart. When disabled, an automatic restart may be attempted outside of active hours after update is ready for restart before the deadline is reached. Takes effect only if Update/ConfigureDeadlineForQualityUpdates or Update/ConfigureDeadlineForFeatureUpdates is configured.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlinenoautoreboot"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautoreboot_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautoreboot_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"6960a75a8fb0cab7":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},"699bb50112dc7cab":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method","displayName":"Set RD Gateway authentication method (User)","description":"Specifies the authentication method that clients must use when attempting to connect to an RD Session Host server through an RD Gateway server. You can enforce this policy setting or you can allow users to overwrite this policy setting. By default, when you enable this policy setting, it is enforced. When this policy setting is enforced, users cannot override this setting, even if they select the \"Use these RD Gateway server settings\" option on the client.\r\n\r\nTo allow users to overwrite this policy setting, select the \"Allow users to change this setting\" check box. When you do this, users can specify an alternate authentication method by configuring settings on the client, using an RDP file, or using an HTML script. If users do not specify an alternate authentication method, the authentication method that you specify in this policy setting is used by default.\r\n\r\nIf you disable or do not configure this policy setting, the authentication method that is specified by the user is used, if one is specified. If an authentication method is not specified, the Negotiate protocol that is enabled on the client or a smart card can be used for authentication.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-gateway-policy-auth-method"],"categoryId":"a561e59a-09b7-4106-a6fa-0b82036a5b49","categoryName":"RD Gateway","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_1","displayName":"Enabled","description":null,"helpText":null}]},"694986ff6b8db300":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_radc_defaultconnection_ts_radc_defaultconnectionurl","displayName":"Default connection URL: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3a901a80-e2b6-470c-9658-d66ba5458370","categoryName":"Remote App and Desktop Connections","options":null},"69ba0c5284ed982e":{"id":"user_vendor_msft_policy_config_admx_wincal_turnoffwincal_1","displayName":"Turn off Windows Calendar (User)","description":"Windows Calendar is a feature that allows users to manage appointments and tasks by creating personal calendars, publishing them, and subscribing to other users calendars.\r\n\r\nIf you enable this setting, Windows Calendar will be turned off.\r\n\r\nIf you disable or do not configure this setting, Windows Calendar will be turned on.\r\n\r\nThe default is for Windows Calendar to be turned on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wincal#admx-wincal-turnoffwincal-1"],"categoryId":"fff51673-04b8-4277-98ef-4baffbd8d192","categoryName":"Windows Calendar","options":[{"id":"user_vendor_msft_policy_config_admx_wincal_turnoffwincal_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_wincal_turnoffwincal_1_1","displayName":"Enabled","description":null,"helpText":null}]},"696ad6aa32ccb23f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"690261c4483dadb8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer","displayName":"Allow remote access users to transfer files to/from the host (User)","description":"Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host. This doesn't apply to remote assistance connections, which don't support file transfer.\r\n\r\nSetting the policy to Disabled disallows file transfer.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_1","displayName":"Enabled","description":null,"helpText":null}]},"694dccaa8f68bde8":{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate","displayName":"Local Machine Zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_4","displayName":"High","description":null,"helpText":null}]},"69e6511c9246c4e6":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://learn.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneenableprotectedmode"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"69711a007ebadf71":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls_certificatetransparencyenforcementdisabledforurlsdesc","displayName":"Disable Certificate Transparency enforcement for specific URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"69bbc7dc89f487ad":{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails","displayName":"Show thumbnail images for browsing history (User)","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\r\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past 7 days.\r\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\r\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\r\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails_1","displayName":"Enabled","description":null,"helpText":null}]},"69c8b0cbd4af7de2":{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled (User)","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"695ae33ae8436966":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1_1","displayName":"True","description":null,"helpText":null}]},"693569b8170a395f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2_l_work2mapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"69bcc2f21c8023bc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint_1","displayName":"True","description":null,"helpText":null}]},"69126ec338de528a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel","displayName":"Enable additional actions in Excel (User)","description":"This policy setting controls whether Excel can provide additional actions for certain words and phrases in a workbook through the right-click menu, and whether users can configure this behavior by checking or unchecking the \"Enable additional actions in the right-click menu\" option under the File tab | Options | Proofing | AutoCorrect Options | Actions tab. If additional actions functionality is turned on, Excel can recognize dates and financial symbols and provide additional actions for them.\r\n\r\nIf you enable or do not configure this policy setting, users can configure Excel to provide additional actions. Note: Excel does not provide additional actions until users check the \"Enable additional actions in the right-click menu\" option in the UI.\r\n\r\nIf you disable this policy setting, users cannot configure Excel to provide additional actions.","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel_1","displayName":"Enabled","description":null,"helpText":null}]},"69076f9cb4a22f4e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes","displayName":"Use this response when you propose new meeting times (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_1","displayName":"Enabled","description":null,"helpText":null}]},"69d541f52725c666":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor","displayName":"Briefly change the mouse cursor (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor_1","displayName":"True","description":null,"helpText":null}]},"690a7f2ff665fc0d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles","displayName":"Select Cached Exchange Mode for new profiles (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_1","displayName":"Download Headers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_2","displayName":"Download Full Items","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_3","displayName":"Download Headers and then Full Items","description":null,"helpText":null}]},"697d0da0afce68e0":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt_1","displayName":"True","description":null,"helpText":null}]},"693550cf8f6c554f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},"690999bc21a456fd":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"690ec45a268ca2be":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"Number of folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":null},"6943d73a78f74633":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents","displayName":"Enable Automation events (User)","description":"Enables Visio events to be sent to Visio add-ons and VBA macros. If cleared, disables all Visio events. If you clear this option, some drawing types in Visio that rely on Automation events may not have full functionality.","helpText":"","infoUrls":[],"categoryId":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","categoryName":"General Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents_1","displayName":"Enabled","description":null,"helpText":null}]},"6990667637993a10":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"695fdbb70b3435c8":{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]}} \ No newline at end of file +{"692e8daef999e1c9":{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints","displayName":"Skip first use hints","description":"If 'True', hides or skips suggestions from apps that step through tutorials, or hints when the app starts. If 'False', Intune doesn't change or update this setting. By default, the OS might show these suggestions when the app starts. Available for fully managed and dedicated devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsrecommendskippingfirstusehints_false","displayName":"False","description":"false","helpText":null}]},"691a0be5fe58f295":{"id":"com.apple.applicationaccess_allowlockscreentodayview","displayName":"Allow Lock Screen Today View","description":"If false, disables the Today view in Notification Center on the lock screen. Available in iOS 7 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlockscreentodayview_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlockscreentodayview_true","displayName":"True","description":null,"helpText":null}]},"69dadbecedc3a086":{"id":"com.apple.managedclient.preferences_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\n\nIf you enable this policy, services and export targets that match the given list are blocked.\n\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\n\nPolicy options mapping:\n\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\n\n* collections_share (collections_share) = Sharing of Collections\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#collectionsservicesandexportsblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"69d2b29d6c2de415":{"id":"com.apple.mcx.timemachine_com.apple.mcx.timemachine","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},"698c300f2119c8c1":{"id":"com.apple.subscribedcalendar.account_subcalaccountpassword","displayName":"Account Password","description":"The user’s password.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":null},"6930c51eda50465a":{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_reminders_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},"6946d416d2c6f694":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicydesktopfolder_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"6913d8b12caeec6e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended","displayName":"Enable Wallet Checkout feature (users can override)","description":"Enables Wallet Checkout feature in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.\n\nIf you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"69250dc929dd5136":{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering","displayName":"Disable Inbound Connection Filtering","description":"This setting disables Inbound connection filtering for Network Protection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering_1","displayName":"Inbound connection filtering is disabled","description":"Inbound connection filtering is disabled","helpText":null},{"id":"device_vendor_msft_defender_configuration_disableinboundconnectionfiltering_0","displayName":"Inbound connection filtering is enabled","description":"Inbound connection filtering is enabled","helpText":null}]},"69d61f645b084c4c":{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel","displayName":"Security Intelligence Updates Channel","description":"Enable this policy to specify when devices receive Microsoft Defender security intelligence updates during the daily gradual rollout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_0","displayName":"Not configured (Default). Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which may not be suitable for devices in a production or critical environment","description":"Not configured (Default). Microsoft will either assign the device to Current Channel (Broad) or a beta channel early in the gradual release cycle. The channel selected by Microsoft might be one that receives updates early during the gradual release cycle, which may not be suitable for devices in a production or critical environment","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_4","displayName":"Current Channel (Staged): Same as Current Channel (Broad).","description":"Current Channel (Staged): Same as Current Channel (Broad).","helpText":null},{"id":"device_vendor_msft_defender_configuration_securityintelligenceupdateschannel_5","displayName":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.","description":"Current Channel (Broad): Devices will be offered updates only after the gradual release cycle completes. Suggested to apply to a broad set of devices in all populations, including production.","helpText":null}]},"6929ca54a524810a":{"id":"device_vendor_msft_maintenancewindows_monthlyscheduletype","displayName":"Monthly – Schedule type","description":"Select the type of monthly schedule for the maintenance window.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_monthlyscheduletype_1","displayName":"Day-based","description":"Schedule by a specific day of the month","helpText":null},{"id":"device_vendor_msft_maintenancewindows_monthlyscheduletype_2","displayName":"Week-based","description":"Schedule by a specific week and day of the month","helpText":null},{"id":"device_vendor_msft_maintenancewindows_monthlyscheduletype_3","displayName":"Last day of month","description":"Schedule on the last day of every month","helpText":null}]},"69e3be12d4bde83b":{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_wercerserver","displayName":"Corporate server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"69b82bbc633e5a3a":{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2","displayName":"Turn off the \"Publish to Web\" task for files and folders","description":"This policy setting specifies whether the tasks \"Publish this file to the Web,\" \"Publish this folder to the Web,\" and \"Publish the selected items to the Web\" are available from File and Folder Tasks in Windows folders.\r\n\r\nThe Web Publishing Wizard is used to download a list of providers and allow users to publish content to the web.\r\n\r\nIf you enable this policy setting, these tasks are removed from the File and Folder tasks in Windows folders.\r\n\r\nIf you disable or do not configure this policy setting, the tasks are shown.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremovepublishtoweb-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_2_1","displayName":"Enabled","description":null,"helpText":null}]},"694133f708ce4238":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning","displayName":"Turn on reparse point scanning","description":"This policy setting allows you to configure reparse point scanning. If you allow reparse points to be scanned, there is a possible risk of recursion. However, the engine supports following reparse points to a maximum depth so at worst scanning could be slowed. Reparse point scanning is disabled by default and this is the recommended state for this functionality. \r\n\r\n If you enable this setting, reparse point scanning will be enabled.\r\n\r\n If you disable or do not configure this setting, reparse point scanning will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablereparsepointscanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablereparsepointscanning_1","displayName":"Enabled","description":null,"helpText":null}]},"69fbf050967ab686":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6","displayName":"MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)","description":"MSS: (TcpMaxDataRetransmissions IPv6) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxdataretransmissionsipv6"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissionsipv6_1","displayName":"Enabled","description":null,"helpText":null}]},"69decf2e17f96d87":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_javascriptjitblockedforsitesdesc","displayName":"Block JavaScript from using JIT on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"699d020baca5cdd2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"698cf6d9eea84eb6":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to apply restrictions to requests to local network endpoints","description":"When this policy is set to Enabled, any time when a warning is supposed to be\r\ndisplayed in the DevTools due to Local Network Access checks failing, the\r\nmain request will be blocked instead.\r\n\r\nWhen this policy is set to Disabled or unset, Local Network Access requests will use the\r\ndefault handling of these requests.\r\n\r\nSee https://wicg.github.io/local-network-access/ for Local Network Access restrictions.","helpText":"","infoUrls":[],"categoryId":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","categoryName":"Local Network Access settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~localnetworkaccesssettings_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"694306bb24ab2356":{"id":"device_vendor_msft_policy_config_cryptography_tlsciphersuites","displayName":"TLS Cipher Suites","description":"Lists the Cryptographic Cipher Algorithms allowed for SSL connections. Format is a semicolon delimited list. Last write wins.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cryptography#tlsciphersuites"],"categoryId":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","categoryName":"Cryptography","options":null},"69484af823040189":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductiononlyexclusions","displayName":"Attack Surface Reduction Only Exclusions","description":"This policy setting allows you to prevent Attack Surface reduction rules from matching on files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: c:\\Windows to exclude all files in this directory. A fully qualified resource name might be defined as: C:\\Windows\\App.exe. Value type is string.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#attacksurfacereductiononlyexclusions"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"698ddac1bfcbce0b":{"id":"device_vendor_msft_policy_config_desktopappinstaller_enableappinstaller","displayName":"Enable App Installer","description":"This policy controls whether the Windows Package Manager can be used by users.\n\nIf you enable or do not configure this setting, users will be able to use the Windows Package Manager.\n\nIf you disable this setting, users will not be able to use the Windows Package Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-enableappinstaller"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_enableappinstaller_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_enableappinstaller_1","displayName":"Enabled","description":null,"helpText":null}]},"69ef08d28ab2ed61":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcoutlookcachedmode","displayName":"Outlook Cached Mode","description":"When the ODFC Container is successfully attached, set Outlook to work in cached mode for the user. The setting change will only be effective for the specific user and for the length of the user session.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\OutlookCachedMode\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled (only if container is attached)","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcoutlookcachedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcoutlookcachedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"699d28b4e610a509":{"id":"device_vendor_msft_policy_config_kerberos_upnnamehints","displayName":"UPN Name Hints","description":"Devices joined to Azure Active Directory in a hybrid environment need to interact with Active Directory Domain Controllers, but they lack the built-in ability to find a Domain Controller that a domain-joined device has. This can cause failures when such a device needs to resolve an AAD UPN into an Active Directory Principal. This parameter adds a list of domains that an Azure Active Directory joined device should attempt to contact if it is otherwise unable to resolve a UPN to a principal.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Kerberos#upnnamehints"],"categoryId":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","categoryName":"Kerberos","options":null},"69c0ede215a2a341":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_pluginsblockedforurlsdesc","displayName":"Block the Adobe Flash plug-in on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"691fcffcf47d04cc":{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled","displayName":"Synonyms are provided when using Microsoft Editor spell checker","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages, and synonyms can be suggested as an integrated feature.\r\n\r\nIf you enable this policy, Microsoft Editor spell checker will provide synonyms for suggestions for misspelled words.\r\n\r\nIf you disable or don't configure this policy, Microsoft Editor spell checker will not provide synonyms for suggestions for misspelled words.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy or the 'MicrosoftEditorProofingEnabled' (Spell checking provided by Microsoft Editor) policy are set to disabled, or the user disables spell checking or chooses not to use Microsoft Editor spell checker in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorsynonymsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"691c58127371f77d":{"id":"device_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed","displayName":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context","description":"Specifies whether SharedArrayBuffers can be used in a non cross-origin-isolated context. A SharedArrayBuffer is a binary data buffer that can be used to create views on shared memory. SharedArrayBuffers have a memory access vulnerability in several popular CPUs.\r\n\r\nIf you enable this policy, sites are allowed to use SharedArrayBuffers with no restrictions.\r\n\r\nIf you disable or don't configure this policy, sites are allowed to use SharedArrayBuffers only when cross-origin isolated.\r\n\r\nMicrosoft Edge will require cross-origin isolation when using SharedArrayBuffers from Microsoft Edge 91 onward for Web Compatibility reasons.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev111~policy~microsoft_edge_sharedarraybufferunrestrictedaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"69122b3ec34a32dc":{"id":"device_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector","displayName":"Configuration policy for files attached for Microsoft Edge for Business Data Loss Prevention Connectors","description":"List of Microsoft Edge for Business Data Loss Prevention Connectors services settings to be applied when a file is attached to Microsoft Edge.\r\n\r\nConnector Fields\r\n\r\n1. url_list,\r\ntags,\r\nenable,\r\ndisable\r\nThese fields determine whether the connector sends data for analysis when content is entered on a specific page, and which tags to include in the analysis request.\r\nA tag associated with an enable pattern is included in the request if the page URL matches the pattern—unless a corresponding disable pattern also matches.\r\nAnalysis is triggered if at least one tag is included in the request.\r\n\r\n2. service_provider\r\nIdentifies the analysis service provider the configuration applies to.\r\n\r\n3. block_until_verdict\r\nIf set to 1, Microsoft Edge waits for a response from the analysis service before giving the page access to the data.\r\nAny other integer value allows the page to access the data immediately.\r\n\r\n4. default_action\r\nIf set to block, Microsoft Edge denies page access to the data if an error occurs while contacting the analysis service.\r\nAny other value permits the page to access the data.\r\n\r\nThis policy requires additional setup to take effect. For configuration guidance, see https://go.microsoft.com/fwlink/?linkid=2320413.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"block_until_verdict\": 0,\r\n \"default_action\": \"allow\",\r\n \"disable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*.us.com\"\r\n ]\r\n }\r\n ],\r\n \"enable\": [\r\n {\r\n \"tags\": [\r\n \"malware\"\r\n ],\r\n \"url_list\": [\r\n \"*\"\r\n ]\r\n },\r\n {\r\n \"tags\": [\r\n \"dlp\"\r\n ],\r\n \"url_list\": [\r\n \"*.them.com\",\r\n \"*.others.com\"\r\n ]\r\n }\r\n ],\r\n \"service_provider\": \"local_system_agent\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onfileattachedenterpriseconnector_1","displayName":"Enabled","description":null,"helpText":null}]},"69005f9fdee43759":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled","displayName":"Suggest similar pages when a webpage can’t be found","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_alternateerrorpagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"69db3da8cd042a2f":{"id":"device_vendor_msft_policy_config_power_turnoffhybridsleeppluggedin","displayName":"Turn Off Hybrid Sleep Plugged In","description":"This policy setting allows you to turn off hybrid sleep. If you set this to 0, a hiberfile is not generated when the system transitions to sleep (Stand By). If you do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#turnoffhybridsleeppluggedin"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":[{"id":"device_vendor_msft_policy_config_power_turnoffhybridsleeppluggedin_0","displayName":"","description":"","helpText":null},{"id":"device_vendor_msft_policy_config_power_turnoffhybridsleeppluggedin_1","displayName":"hybrid sleep","description":"hybrid sleep","helpText":null}]},"693cd968a8edb564":{"id":"device_vendor_msft_policy_config_update_autorestartdeadlineperiodindaysforfeatureupdates","displayName":"Auto Restart Deadline Period In Days For Feature Updates","description":"For Feature Updates, this policy specifies the deadline in days before automatically executing a scheduled restart outside of active hours. The deadline can be set between 2 and 30 days from the time the restart is scheduled. The system will reboot on or after the specified deadline. The reboot is prioritized over any configured Active Hours and any existing system and user busy checks. Value type is integer. Default is 7 days. Supported values range: 2-30. Note that the PC must restart for certain updates to take effect. If you enable this policy, a restart will automatically occur the specified number of days after the restart was scheduled. If you disable or do not configure this policy, the PC will restart according to the default schedule. If any of the following two policies are enabled, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installations. Always automatically restart at scheduled time.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#autorestartdeadlineperiodindaysforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"69a98749db6c3163":{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautoreboot","displayName":"Configure Deadline No Auto Reboot","description":"When enabled, devices will not automatically restart outside of active hours until the deadline and grace period have expired, even if an update is ready for restart. When disabled, an automatic restart may be attempted outside of active hours after update is ready for restart before the deadline is reached. Takes effect only if Update/ConfigureDeadlineForQualityUpdates or Update/ConfigureDeadlineForFeatureUpdates is configured.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlinenoautoreboot"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautoreboot_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_update_configuredeadlinenoautoreboot_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"6960a75a8fb0cab7":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},"699bb50112dc7cab":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method","displayName":"Set RD Gateway authentication method (User)","description":"Specifies the authentication method that clients must use when attempting to connect to an RD Session Host server through an RD Gateway server. You can enforce this policy setting or you can allow users to overwrite this policy setting. By default, when you enable this policy setting, it is enforced. When this policy setting is enforced, users cannot override this setting, even if they select the \"Use these RD Gateway server settings\" option on the client.\r\n\r\nTo allow users to overwrite this policy setting, select the \"Allow users to change this setting\" check box. When you do this, users can specify an alternate authentication method by configuring settings on the client, using an RDP file, or using an HTML script. If users do not specify an alternate authentication method, the authentication method that you specify in this policy setting is used by default.\r\n\r\nIf you disable or do not configure this policy setting, the authentication method that is specified by the user is used, if one is specified. If an authentication method is not specified, the Negotiate protocol that is enabled on the client or a smart card can be used for authentication.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-gateway-policy-auth-method"],"categoryId":"a561e59a-09b7-4106-a6fa-0b82036a5b49","categoryName":"RD Gateway","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_1","displayName":"Enabled","description":null,"helpText":null}]},"694986ff6b8db300":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_radc_defaultconnection_ts_radc_defaultconnectionurl","displayName":"Default connection URL: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3a901a80-e2b6-470c-9658-d66ba5458370","categoryName":"Remote App and Desktop Connections","options":null},"69ba0c5284ed982e":{"id":"user_vendor_msft_policy_config_admx_wincal_turnoffwincal_1","displayName":"Turn off Windows Calendar (User)","description":"Windows Calendar is a feature that allows users to manage appointments and tasks by creating personal calendars, publishing them, and subscribing to other users calendars.\r\n\r\nIf you enable this setting, Windows Calendar will be turned off.\r\n\r\nIf you disable or do not configure this setting, Windows Calendar will be turned on.\r\n\r\nThe default is for Windows Calendar to be turned on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wincal#admx-wincal-turnoffwincal-1"],"categoryId":"fff51673-04b8-4277-98ef-4baffbd8d192","categoryName":"Windows Calendar","options":[{"id":"user_vendor_msft_policy_config_admx_wincal_turnoffwincal_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_wincal_turnoffwincal_1_1","displayName":"Enabled","description":null,"helpText":null}]},"696ad6aa32ccb23f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"690261c4483dadb8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer","displayName":"Allow remote access users to transfer files to/from the host (User)","description":"Setting the policy to Enabled or leaving it unset allows users connected to a remote access host to transfer files between the client and the host. This doesn't apply to remote assistance connections, which don't support file transfer.\r\n\r\nSetting the policy to Disabled disallows file transfer.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostallowfiletransfer_1","displayName":"Enabled","description":null,"helpText":null}]},"694dccaa8f68bde8":{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate","displayName":"Local Machine Zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlocalmachinezonetemplate_iz_partnamelocalmachinezonetemplate_4","displayName":"High","description":null,"helpText":null}]},"69e6511c9246c4e6":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://learn.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneenableprotectedmode"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"69711a007ebadf71":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforurls_certificatetransparencyenforcementdisabledforurlsdesc","displayName":"Disable Certificate Transparency enforcement for specific URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"69bbc7dc89f487ad":{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails","displayName":"Show thumbnail images for browsing history (User)","description":"This policy lets you configure whether the history thumbnail feature collects and saves images for the sites you visit. When enabled, this feature makes it easier to identify sites when you hover over your history results.\r\nIf you don't configure this policy, the thumbnail feature is turned on after a user visits the history hub twice in the past 7 days.\r\nIf you enable this policy, the history thumbnail collects and saves images for visited sites.\r\nIf you disable this policy, the history thumbnail doesn't collect and save images for visited sites.\r\nWhen the feature is disabled, existing images are deleted on a per user basis, and the feature no longer collects or saves images when a site is visited.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_showhistorythumbnails_1","displayName":"Enabled","description":null,"helpText":null}]},"69c8b0cbd4af7de2":{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled (User)","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_aadwebsitessousingthisprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"695ae33ae8436966":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicecreatesharednotes1_1","displayName":"True","description":null,"helpText":null}]},"693569b8170a395f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacework2_l_work2mapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"69bcc2f21c8023bc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuipowerpoint_1","displayName":"True","description":null,"helpText":null}]},"69126ec338de528a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel","displayName":"Enable additional actions in Excel (User)","description":"This policy setting controls whether Excel can provide additional actions for certain words and phrases in a workbook through the right-click menu, and whether users can configure this behavior by checking or unchecking the \"Enable additional actions in the right-click menu\" option under the File tab | Options | Proofing | AutoCorrect Options | Actions tab. If additional actions functionality is turned on, Excel can recognize dates and financial symbols and provide additional actions for them.\r\n\r\nIf you enable or do not configure this policy setting, users can configure Excel to provide additional actions. Note: Excel does not provide additional actions until users check the \"Enable additional actions in the right-click menu\" option in the UI.\r\n\r\nIf you disable this policy setting, users cannot configure Excel to provide additional actions.","helpText":"","infoUrls":[],"categoryId":"69931627-230d-4df9-bbef-e3eac64ea8ef","categoryName":"Additional Actions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess~l_additionalactions_l_enableadditionalactionsinexcel_1","displayName":"Enabled","description":null,"helpText":null}]},"69076f9cb4a22f4e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes","displayName":"Use this response when you propose new meeting times (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_usethisresponsewhenyouproposenewmeetingtimes_1","displayName":"Enabled","description":null,"helpText":null}]},"69d541f52725c666":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor","displayName":"Briefly change the mouse cursor (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_brieflychangethemousecursor_1","displayName":"True","description":null,"helpText":null}]},"690a7f2ff665fc0d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles","displayName":"Select Cached Exchange Mode for new profiles (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_1","displayName":"Download Headers","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_2","displayName":"Download Full Items","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_l_selectcachedexchangemodefornewprofiles_3","displayName":"Download Headers and then Full Items","description":null,"helpText":null}]},"697d0da0afce68e0":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt","displayName":"Developer tab | Code | Visual Basic (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrovisualbasiceditorppt_1","displayName":"True","description":null,"helpText":null}]},"693550cf8f6c554f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},"690999bc21a456fd":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"690ec45a268ca2be":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"Number of folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":null},"6943d73a78f74633":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents","displayName":"Enable Automation events (User)","description":"Enables Visio events to be sent to Visio add-ons and VBA macros. If cleared, disables all Visio events. If you clear this option, some drawing types in Visio that rely on Automation events may not have full functionality.","helpText":"","infoUrls":[],"categoryId":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","categoryName":"General Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_generaloptions_l_enableautomationevents_1","displayName":"Enabled","description":null,"helpText":null}]},"6990667637993a10":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"695fdbb70b3435c8":{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge","displayName":"Auth Apps Allow User Pref Merge","description":"This value is used as an on/off switch. If this value is false, authorized application firewall rules in the local store are ignored and not enforced. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge_false","displayName":"False","description":"AuthAppsAllowUserPrefMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_authappsallowuserprefmerge_true","displayName":"True","description":"AuthAppsAllowUserPrefMerge On","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/70.json b/public/intune-definitions/70.json index 19af3445c513..da8253ec32f0 100644 --- a/public/intune-definitions/70.json +++ b/public/intune-definitions/70.json @@ -1 +1 @@ -{"7072d337b35b9aa6":{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy","displayName":"App auto-updates (work profile-level)","description":"Define the auto update policy for apps. Devices check for app updates daily. If set to 'User choice', the end user can set their preference in managed Google Play. If set to 'Never', apps will never auto-update. If set to 'Wi-Fi only', apps will only auto-update when the device is connected to Wi-Fi. If set to 'Always', apps will always auto-update. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_notconfigured","displayName":"Not configured","description":"Not configured; this value is ignored.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_userchoice","displayName":"User choice","description":"The user can control auto-updates.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_never","displayName":"Never","description":"Apps are never auto-updated.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_wifionly","displayName":"Wi-Fi only","description":"Apps are auto-updated over Wi-Fi only.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_always","displayName":"Always","description":"Apps are auto-updated at any time. Data charges may apply.","helpText":null}]},"70255112d3e8f18d":{"id":"com.apple.managedclient.preferences_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value would prevent file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#exemptdomainfiletypepairsfromfiletypedownloadwarnings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"709fa9d9b3119646":{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads","description":"This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.\n\nIf you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.\n\nIf you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#preventsmartscreenpromptoverrideforfiles"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles_true","displayName":"Enabled","description":null,"helpText":null}]},"70d62a95af17be8b":{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin","displayName":"Create At Login","description":"If true, creates the mobile account at login time.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin_true","displayName":"True","description":null,"helpText":null}]},"701e6a59cb80ab70":{"id":"com.apple.mcxprinting_userprinterlist_printer","displayName":"Printer","description":"A dictionary of printer details.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},"70c5e29e9ca2de47":{"id":"com.apple.xsan.preferences_preferdlc","displayName":"Prefer DLC","description":"An array of StorNext volume names. If the Xsan client is attempting to mount a volume named in this array, the Xsan client attempts to mount the volume using DLC. If DLC isn't available, the client attempts to mount the volume if its LUNs are available through Fibre Channel. The volume name must not also appear in Deny DLC.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},"70419e94b0e91c87":{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled","displayName":"Display Local UI","description":"Determines whether the local user interface of the LUI is available (true if available, false otherwise). Initially populated by the LPA when the eUICC tree is created, can be queried and changed by the MDM server.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled_true","displayName":"Enabled","description":"Enabled","helpText":null}]},"700024ace70797ba":{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage","displayName":"Remove Program Compatibility Property Page","description":"This policy controls the visibility of the Program Compatibility property page shell extension. This shell extension is visible on the property context-menu of any program shortcut or executable file.\r\n\r\nThe compatibility property page displays a list of options that can be selected and applied to the application to resolve the most common issues affecting legacy applications. Enabling this policy setting removes the property page from the context-menus, but does not affect previous compatibility settings applied to application using this interface.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatremoveprogramcompatproppage"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage_1","displayName":"Enabled","description":null,"helpText":null}]},"706edc9318614b51":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5_1","displayName":"True","description":null,"helpText":null}]},"701e81d5ed8a40e2":{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo","displayName":"Hash publication actions:","description":null,"helpText":"","infoUrls":[],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_0","displayName":"Allow hash publication only for shared folders on which BranchCache is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_1","displayName":"Disallow hash publication on all shared folders","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_2","displayName":"Allow hash publication for all shared folders","description":null,"helpText":null}]},"701443b9037b5204":{"id":"device_vendor_msft_policy_config_admx_nca_customcommands_customcommands_control","displayName":"CustomCommands","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},"70b863ad8e654b7a":{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling","displayName":"Specify passive polling","description":"This Policy setting enables you to specify passive polling behavior. NCSI polls various measurements throughout the network stack on a frequent interval to determine if network connectivity has been lost. Use the options to control the passive polling behavior.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-passivepolling"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_1","displayName":"Enabled","description":null,"helpText":null}]},"70061fadc2344b22":{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"cebd5934-9dfe-4278-966d-b9d880cb30e7","categoryName":"Windows Shutdown Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},"704d88691593dc4b":{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2","displayName":"Allow network connectivity during connected-standby (plugged in)","description":"This policy setting allows you to control the network connectivity state in standby on modern standby-capable systems.\r\n\r\nIf you enable this policy setting, network connectivity will be maintained in standby.\r\n\r\nIf you disable this policy setting, network connectivity in standby is not guaranteed. This connectivity restriction currently applies to WLAN networks only, and is subject to change.\r\n\r\nIf you do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-acconnectivityinstandby-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2_1","displayName":"Enabled","description":null,"helpText":null}]},"700fbd63e0de7c54":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},"70bbd30392fda4b7":{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2","displayName":"Disable text prediction","description":"Prevents the Touch Keyboard and Handwriting panel (a.k.a. Tablet PC Input Panel in Windows 7 and Windows Vista) from providing text prediction suggestions. This policy applies for both the on-screen keyboard and the handwriting tab when the feature is available for the current input area and input language.\r\n\r\nTouch Keyboard and Handwriting panel enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will not provide text prediction suggestions. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will provide text prediction suggestions. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will provide text prediction suggestions. Users will be able to configure this setting on the Text Completion tab in Input Panel Options in Windows 7 and Windows Vista.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-prediction-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2_1","displayName":"Enabled","description":null,"helpText":null}]},"7034d0f6c7e9f4ce":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp","displayName":"Use advanced RemoteFX graphics for RemoteApp","description":"This policy setting allows you to enable RemoteApp programs to use advanced graphics, including support for transparency, live thumbnails, and seamless application moves. This policy setting applies only to RemoteApp programs and does not apply to remote desktop sessions.\r\n\r\nIf you enable or do not configure this policy setting, RemoteApp programs published from this RD Session Host server will use these advanced graphics.\r\n\r\nIf you disable this policy setting, RemoteApp programs published from this RD Session Host server will not use these advanced graphics. You may want to choose this option if you discover that applications published as RemoteApp programs do not support these advanced graphics. \r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-advanced-remotefx-remoteapp"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp_1","displayName":"Enabled","description":null,"helpText":null}]},"70e3ca18459f1af9":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_crosssitesyncflags","displayName":"CrossSiteSyncFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},"70a285c431c3cbee":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory","description":"Setting the policy changes the default directory that Chrome downloads files to, but users can change the directory.\r\n\r\nLeaving the policy unset means Chrome uses its platform-specific default directory.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"70ab2c10551fe0a8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters","displayName":"Command-line parameters for switching from the alternative browser.","description":"Setting the policy to a list of strings means the strings are joined with spaces and passed from Internet Explorer® to Google Chrome as command-line parameters. If an parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line.\r\n\r\nEnvironment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable.\r\n\r\nLeaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter.\r\n\r\nNote: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect.\r\n\r\nExample value:\r\n\r\n--force-dark-mode","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_1","displayName":"Enabled","description":null,"helpText":null}]},"70008ebe083c1027":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled","displayName":"Enable RC4 cipher suites in TLS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"707815afab996b27":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled","displayName":"Enable showing promotional content","description":"Setting the policy to True or leaving it unset lets Google Chrome show users product promotional content.\r\n\r\nSetting the policy to False prevents Google Chrome from showing product promotional content.\r\n\r\nSetting the policy controls the presentation of promotional content, including the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"7090100e6956ddbf":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource","displayName":"DO Group Id Source","description":"Specifies the source of group ID used for peer selection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dogroupidsource"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":[{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_0","displayName":"Not Set","description":"Not Set","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_1","displayName":"AD site","description":"AD site","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_2","displayName":"Authenticated domain SID","description":"Authenticated domain SID","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_3","displayName":"DHCP Option ID","description":"DHCP Option ID","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_4","displayName":"DNS Suffix","description":"DNS Suffix","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_5","displayName":"Entra ID Tenant ID","description":"Entra ID Tenant ID","helpText":null}]},"705bbb37a8d7c5db":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"7082827792fab7b8":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":null},"707c32b9ff7c14c7":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Enable support for Signed HTTP Exchange (SXG).\r\n\r\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\r\n\r\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"700e92e0cee07ef5":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"70deba07d14e0dd2":{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},"709a681bf3de70a5":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_javascriptjitallowedforsitesdesc","displayName":"Allow JavaScript to use JIT on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"70405560d9b54319":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mse7exe13","displayName":"mse7.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mse7exe13_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mse7exe13_1","displayName":"True","description":null,"helpText":null}]},"70065c15f1c7547d":{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakesonbattery","displayName":"Require a password when a computer wakes (on battery)","description":"This policy setting specifies whether or not the user is prompted for a password when the system resumes from sleep.\n\nIf you enable or do not configure this policy setting, the user is prompted for a password when the system resumes from sleep.\n\nIf you disable this policy setting, the user is not prompted for a password when the system resumes from sleep.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-requirepasswordwhencomputerwakesonbattery"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakesonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakesonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},"70ec4ced02378b15":{"id":"device_vendor_msft_policy_config_textinput_touchkeyboarddictationbuttonavailability","displayName":"Touch Keyboard Dictation Button Availability","description":"Specifies whether the dictation input button is enabled or disabled for the touch keyboard. When this policy is set to disabled, the dictation input button on touch keyboard is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#touchkeyboarddictationbuttonavailability"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_touchkeyboarddictationbuttonavailability_0","displayName":"The OS determines when it's most appropriate to be available.","description":"The OS determines when it's most appropriate to be available.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_touchkeyboarddictationbuttonavailability_1","displayName":"Dictation button on the keyboard is always available.","description":"Dictation button on the keyboard is always available.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_touchkeyboarddictationbuttonavailability_2","displayName":"Dictation button on the keyboard is always disabled.","description":"Dictation button on the keyboard is always disabled.","helpText":null}]},"704cc3639f042eac":{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_createdesktopshortcutmicrosoftedgebeta","displayName":"Prevent Desktop Shortcut creation upon install","description":"If you enable this policy a desktop shortcut is created when Microsoft Edge is installed.\r\n If you disable this policy, no desktop shortcut will be created when Microsoft Edge is installed.\r\n If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. \r\n If Microsoft Edge is already installed, this policy will have no effect.\r\n\r\n If you don't configure this policy for a channel, the 'CreateDesktopShortcut default' policy configuration determines shortcut creation when Microsoft Edge is installed.","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":[{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_createdesktopshortcutmicrosoftedgebeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_createdesktopshortcutmicrosoftedgebeta_1","displayName":"Enabled","description":null,"helpText":null}]},"70a9f6adfa26c642":{"id":"intelligencesettings_allowimagewand","displayName":"Allow Image Wand","description":"If `false`, disables Image Wand.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_allowimagewand_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_allowimagewand_true","displayName":"True","description":null,"helpText":null}]},"70a32a12659aadd8":{"id":"intelligencesettings_apps_mail","displayName":"Mail","description":"If present, configures Mail Intelligence features.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":null},"7030b34d7ef8d564":{"id":"user_vendor_msft_policy_config_admx_desktop_ad_querylimit_ad_querylimit_box","displayName":"Number of objects returned: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"99ba9e42-9872-4a03-a615-fc4a4cebc067","categoryName":"Active Directory","options":null},"70f730bd0f05a0dd":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_2","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_3","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},"701d58179d441a74":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},"701aeb36f33b6ec9":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled","displayName":"Re-enable deprecated/removed Mutation Events (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"70da847264db3211":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},"7049a093fb752a6a":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"702b847238bc3a70":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod","displayName":"Set the time period for update notifications (User)","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"70789c4d8dae5a6b":{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting","displayName":"'Set the default \"share additional operating system region\" setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},"70047f1f4172adf8":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_clipboardallowedforurlsdesc","displayName":"Allow clipboard use on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"705fecdaf212e954":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (User)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_1","displayName":"Enabled","description":null,"helpText":null}]},"70c0663dccd21845":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed","displayName":"Allow media autoplay for websites (User)","description":"This policy sets the media autoplay policy for websites.\r\n\r\nThe default setting, \"Not configured\" respects the current media autoplay settings and lets users configure their autoplay settings.\r\n\r\nSetting to \"Enabled\" sets media autoplay to \"Allow\". All websites are allowed to autoplay media. Users can’t override this policy.\r\n\r\nSetting to \"Disabled\" sets media autoplay to \"Block\". No websites are allowed to autoplay media. Users can’t override this policy.\r\n\r\nA tab will need to be closed and re-opened for this policy to take effect.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"7012fb17ee19b6ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing","displayName":"Outlook: Ad hoc reviewing (User)","description":"\"Enable ad hoc reviewing\": Enables the ad-hoc review feature. | \"Exclude author's e-mail in documents\": Enables the ad-hoc review feature, but the authors e-mail is not recorded on the sent document. | \"Disable ad hoc reviewing\": Disables the ad-hoc review feature.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_1","displayName":"Enabled","description":null,"helpText":null}]},"70d6a9e341fa9728":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile_l_profilelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"705a8dfcae81715c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars","displayName":"Do not show ScreenTips on toolbars (User)","description":"This policy setting allows you to configure the \"Show ScreenTips on Toolbars\" option.\r\n\r\nIf you enable this policy setting, ScreenTips will not be shown on toolbars.\r\n\r\nIf you disable or do not configure this policy setting, ScreenTips will be shown on toolbars.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars_1","displayName":"Enabled","description":null,"helpText":null}]},"706d091d2d818abb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword","displayName":"Disallow in Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword_1","displayName":"True","description":null,"helpText":null}]},"700daf1ae3fd644f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia","displayName":"Croatian (Croatia) (User)","description":"Enables the editing language Croatian (Croatia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia_1","displayName":"Enabled","description":null,"helpText":null}]},"701c3b5d32620bb5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning_l_empty432","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},"70e51f5da1f98514":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags","displayName":"Specify custom tags for Office telemetry data (User)","description":"This policy setting allows you to add custom tags to the Office telemetry data that is sent by Office Telemetry Agent.\r\n\r\nIf you enable this policy setting, the specified custom tags are shown in Office Telemetry Dashboard, where you can filter the collected data by the tag name. You can specify any string that you want to categorize and filter the collected data (for example, department name, title of user, and so forth).\r\n\r\nIf you disable or do not configure this policy setting, no custom tags are shown in Office Telemetry Dashboard, and you cannot filter the data that is sent by Office Telemetry Agent.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_1","displayName":"Enabled","description":null,"helpText":null}]},"70c5a70b22ce9e66":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument","displayName":"Turn off Trusted Documents for VBA macros (User)","description":"This policy setting allows you to turn off the Trusted Documents feature for documents containing VBA macros.\r\n\r\nIf you enable this policy setting, users will always see security notifications for VBA macros in documents. When users click \"Enable Content\" for VBA macros, Office will not create a trust record for the document, ensuring that the user is prompted every time they open the document.\r\n\r\nIf you disable or don't configure this policy setting, the Trusted Documents feature allows users to always allow VBA macros in a document so that the user is not prompted the next time they open that document. Trusted documents are exempt from security notifications.\r\n\r\nNote: Enabling this policy setting does not clear existing trusted documents that were previously trusted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument_1","displayName":"Enabled","description":null,"helpText":null}]},"70554aa5651deaf5":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers","displayName":"Show Note Containers (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers_1","displayName":"Enabled","description":null,"helpText":null}]},"701116cac939a601":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},"70a23be6e2aabd1a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver","displayName":"Path to DAV server (User)","description":"This setting allows you to define the path to a DAV server that should be used when users publish their calendars via DAV.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_1","displayName":"Enabled","description":null,"helpText":null}]},"70caf51102524072":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound","displayName":"Play a sound (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound_1","displayName":"True","description":null,"helpText":null}]},"70e140d59d3d15e8":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization","displayName":"Block network activity synchronization (User)","description":"This policy setting allows you to block synchronization of status updates between Outlook and social networks.\r\n\r\nIf you enable this policy setting, social network activity synchronization is blocked.\r\n\r\nIf you disable or you do not configure this policy setting, social network activity synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},"7074cde3f1b6cd4a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_l_empty35","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},"70edb3a09c5aebd0":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether PowerPoint keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, PowerPoint keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, PowerPoint does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},"70e33d4349aeb65f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"708853c901e578e4":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview","displayName":"File tab | Share | E-mail Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview_1","displayName":"True","description":null,"helpText":null}]},"7058cb942f7c08ce":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave","displayName":"Prompt for document properties on first save (User)","description":"Indicates whether the properties dialog box opens when a file is saved for the first time. File properties include author name and information such as the status of the file, preview settings and other properties.","helpText":"","infoUrls":[],"categoryId":"73415dea-0103-4427-83c5-6c97bf81af1d","categoryName":"Save Documents","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave_1","displayName":"Enabled","description":null,"helpText":null}]},"70b0bbaf9d7874f1":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates","displayName":"Word 6.0 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"70ecdb79fef72196":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates","displayName":"Word 97 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"70ee4fa09140e484":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},"7047e3ee62de5d8f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},"70e5c30d8172caa2":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction","displayName":"Direction","description":"The rule is enabled based on the traffic direction as following.\n\nIN - the rule applies to inbound traffic.\nOUT - the rule applies to outbound traffic.\n\nIf not specified the detault is OUT.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction_in","displayName":"The rule applies to inbound traffic.","description":"The rule applies to inbound traffic.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction_out","displayName":"The rule applies to outbound traffic.","description":"The rule applies to outbound traffic.","helpText":null}]},"70edcfb9264cb9ed":{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype","displayName":"License Type","description":"Get/Replace License Type: User Based License = 0, Device Based License = 1\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsLicensing-csp/"],"categoryId":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","categoryName":"Windows Licensing","options":[{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype_0","displayName":"User Based License","description":"User Based License","helpText":null},{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype_1","displayName":"Device Based License","description":"Device Based License","helpText":null}]}} \ No newline at end of file +{"7072d337b35b9aa6":{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy","displayName":"App auto-updates (work profile-level)","description":"Define the auto update policy for apps. Devices check for app updates daily. If set to 'User choice', the end user can set their preference in managed Google Play. If set to 'Never', apps will never auto-update. If set to 'Wi-Fi only', apps will only auto-update when the device is connected to Wi-Fi. If set to 'Always', apps will always auto-update. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"2257f7e1-3e88-4d4d-a666-437bbe42baca","categoryName":"Applications","options":[{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_notconfigured","displayName":"Not configured","description":"Not configured; this value is ignored.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_userchoice","displayName":"User choice","description":"The user can control auto-updates.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_never","displayName":"Never","description":"Apps are never auto-updated.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_wifionly","displayName":"Wi-Fi only","description":"Apps are auto-updated over Wi-Fi only.","helpText":null},{"id":"com.android.devicerestrictionpolicy.appsautoupdatepolicy_always","displayName":"Always","description":"Apps are auto-updated at any time. Data charges may apply.","helpText":null}]},"70255112d3e8f18d":{"id":"com.apple.managedclient.preferences_exemptdomainfiletypepairsfromfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains","description":"You can enable this policy to create a dictionary of file type extensions with a corresponding list of domains that will be exempted from file type extension-based download warnings. This lets enterprise administrators block file type extension-based download warnings for files that are associated with a listed domain. For example, if the \"jnlp\" extension is associated with \"website1.com\", users would not see a warning when downloading \"jnlp\" files from \"website1.com\", but see a download warning when downloading \"jnlp\" files from \"website2.com\".\n\nFiles with file type extensions specified for domains identified by this policy will still be subject to non-file type extension-based security warnings such as mixed-content download warnings and Microsoft Defender SmartScreen warnings.\n\nIf you disable this policy or don't configure it, file types that trigger extension-based download warnings will show warnings to the user.\n\nIf you enable this policy:\n\n* The URL pattern should be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.\n* The file type extension entered must be in lower-cased ASCII. The leading separator should not be included when listing the file type extension, so list \"jnlp\" should be used instead of \".jnlp\".\n\nExample:\n\nThe following example value would prevent file type extension-based download warnings on swf, exe, and jnlp extensions for *.contoso.com domains. It will show the user a file type extension-based download warning on any other domain for exe and jnlp files, but not for swf files.\n\n[\n { \"file_extension\": \"jnlp\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"exe\", \"domains\": [\"contoso.com\"] },\n { \"file_extension\": \"swf\", \"domains\": [\"*\"] }\n]\n\nNote that while the preceding example shows the suppression of file type extension-based download warnings for \"swf\" files for all domains, applying suppression of such warnings for all domains for any dangerous file type extension is not recommended due to security concerns. It is shown in the example merely to demonstrate the ability to do so.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#exemptdomainfiletypepairsfromfiletypedownloadwarnings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"709fa9d9b3119646":{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles","displayName":"Prevent bypassing of Microsoft Defender SmartScreen warnings about downloads","description":"This policy lets you determine whether users can override Microsoft Defender SmartScreen warnings about unverified downloads.\n\nIf you enable this policy, users in your organization can't ignore Microsoft Defender SmartScreen warnings, and they're prevented from completing the unverified downloads.\n\nIf you disable or don't configure this policy, users can ignore Microsoft Defender SmartScreen warnings and complete unverified downloads.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#preventsmartscreenpromptoverrideforfiles"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_preventsmartscreenpromptoverrideforfiles_true","displayName":"Enabled","description":null,"helpText":null}]},"70d62a95af17be8b":{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin","displayName":"Create At Login","description":"If true, creates the mobile account at login time.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.cachedaccounts.createatlogin_true","displayName":"True","description":null,"helpText":null}]},"701e6a59cb80ab70":{"id":"com.apple.mcxprinting_userprinterlist_printer","displayName":"Printer","description":"A dictionary of printer details.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},"70c5e29e9ca2de47":{"id":"com.apple.xsan.preferences_preferdlc","displayName":"Prefer DLC","description":"An array of StorNext volume names. If the Xsan client is attempting to mount a volume named in this array, the Xsan client attempts to mount the volume using DLC. If DLC isn't available, the client attempts to mount the volume if its LUNs are available through Fibre Channel. The volume name must not also appear in Deny DLC.","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},"70419e94b0e91c87":{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled","displayName":"Display Local UI","description":"Determines whether the local user interface of the LUI is available (true if available, false otherwise). Initially populated by the LPA when the eUICC tree is created, can be queried and changed by the MDM server.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":[{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_euiccs_{euicc}_policies_localuienabled_true","displayName":"Enabled","description":"Enabled","helpText":null}]},"700024ace70797ba":{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage","displayName":"Remove Program Compatibility Property Page","description":"This policy controls the visibility of the Program Compatibility property page shell extension. This shell extension is visible on the property context-menu of any program shortcut or executable file.\r\n\r\nThe compatibility property page displays a list of options that can be selected and applied to the application to resolve the most common issues affecting legacy applications. Enabling this policy setting removes the property page from the context-menus, but does not affect previous compatibility settings applied to application using this interface.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatremoveprogramcompatproppage"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatremoveprogramcompatproppage_1","displayName":"Enabled","description":null,"helpText":null}]},"706edc9318614b51":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5","displayName":"Allow processing across a slow network connection","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_iem_cse_slowlink5_1","displayName":"True","description":null,"helpText":null}]},"701e81d5ed8a40e2":{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo","displayName":"Hash publication actions:","description":null,"helpText":"","infoUrls":[],"categoryId":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","categoryName":"Lanman Server","options":[{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_0","displayName":"Allow hash publication only for shared folders on which BranchCache is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_1","displayName":"Disallow hash publication on all shared folders","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_lanmanserver_pol_hashpublication_lbl_hashpublicationactioncombo_2","displayName":"Allow hash publication for all shared folders","description":null,"helpText":null}]},"701443b9037b5204":{"id":"device_vendor_msft_policy_config_admx_nca_customcommands_customcommands_control","displayName":"CustomCommands","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},"70b863ad8e654b7a":{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling","displayName":"Specify passive polling","description":"This Policy setting enables you to specify passive polling behavior. NCSI polls various measurements throughout the network stack on a frequent interval to determine if network connectivity has been lost. Use the options to control the passive polling behavior.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ncsi#admx-ncsi-ncsi-passivepolling"],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":[{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_passivepolling_1","displayName":"Enabled","description":null,"helpText":null}]},"70061fadc2344b22":{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"cebd5934-9dfe-4278-966d-b9d880cb30e7","categoryName":"Windows Shutdown Performance Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_performancediagnostics_wdiscenarioexecutionpolicy_3_wdiscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},"704d88691593dc4b":{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2","displayName":"Allow network connectivity during connected-standby (plugged in)","description":"This policy setting allows you to control the network connectivity state in standby on modern standby-capable systems.\r\n\r\nIf you enable this policy setting, network connectivity will be maintained in standby.\r\n\r\nIf you disable this policy setting, network connectivity in standby is not guaranteed. This connectivity restriction currently applies to WLAN networks only, and is subject to change.\r\n\r\nIf you do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-acconnectivityinstandby-2"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_acconnectivityinstandby_2_1","displayName":"Enabled","description":null,"helpText":null}]},"700fbd63e0de7c54":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypequalitative_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},"70bbd30392fda4b7":{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2","displayName":"Disable text prediction","description":"Prevents the Touch Keyboard and Handwriting panel (a.k.a. Tablet PC Input Panel in Windows 7 and Windows Vista) from providing text prediction suggestions. This policy applies for both the on-screen keyboard and the handwriting tab when the feature is available for the current input area and input language.\r\n\r\nTouch Keyboard and Handwriting panel enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will not provide text prediction suggestions. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will provide text prediction suggestions. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will provide text prediction suggestions. Users will be able to configure this setting on the Text Completion tab in Input Panel Options in Windows 7 and Windows Vista.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-prediction-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_prediction_2_1","displayName":"Enabled","description":null,"helpText":null}]},"7034d0f6c7e9f4ce":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp","displayName":"Use advanced RemoteFX graphics for RemoteApp","description":"This policy setting allows you to enable RemoteApp programs to use advanced graphics, including support for transparency, live thumbnails, and seamless application moves. This policy setting applies only to RemoteApp programs and does not apply to remote desktop sessions.\r\n\r\nIf you enable or do not configure this policy setting, RemoteApp programs published from this RD Session Host server will use these advanced graphics.\r\n\r\nIf you disable this policy setting, RemoteApp programs published from this RD Session Host server will not use these advanced graphics. You may want to choose this option if you discover that applications published as RemoteApp programs do not support these advanced graphics. \r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-advanced-remotefx-remoteapp"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_advanced_remotefx_remoteapp_1","displayName":"Enabled","description":null,"helpText":null}]},"70e3ca18459f1af9":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_crosssitesyncflags","displayName":"CrossSiteSyncFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},"70a285c431c3cbee":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory","description":"Setting the policy changes the default directory that Chrome downloads files to, but users can change the directory.\r\n\r\nLeaving the policy unset means Chrome uses its platform-specific default directory.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"70ab2c10551fe0a8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters","displayName":"Command-line parameters for switching from the alternative browser.","description":"Setting the policy to a list of strings means the strings are joined with spaces and passed from Internet Explorer® to Google Chrome as command-line parameters. If an parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line.\r\n\r\nEnvironment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable.\r\n\r\nLeaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter.\r\n\r\nNote: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect.\r\n\r\nExample value:\r\n\r\n--force-dark-mode","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_1","displayName":"Enabled","description":null,"helpText":null}]},"70008ebe083c1027":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled","displayName":"Enable RC4 cipher suites in TLS","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"707815afab996b27":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled","displayName":"Enable showing promotional content","description":"Setting the policy to True or leaving it unset lets Google Chrome show users product promotional content.\r\n\r\nSetting the policy to False prevents Google Chrome from showing product promotional content.\r\n\r\nSetting the policy controls the presentation of promotional content, including the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_promotionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"7090100e6956ddbf":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource","displayName":"DO Group Id Source","description":"Specifies the source of group ID used for peer selection.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dogroupidsource"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":[{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_0","displayName":"Not Set","description":"Not Set","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_1","displayName":"AD site","description":"AD site","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_2","displayName":"Authenticated domain SID","description":"Authenticated domain SID","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_3","displayName":"DHCP Option ID","description":"DHCP Option ID","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_4","displayName":"DNS Suffix","description":"DNS Suffix","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dogroupidsource_5","displayName":"Entra ID Tenant ID","description":"Entra ID Tenant ID","helpText":null}]},"705bbb37a8d7c5db":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"7082827792fab7b8":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~identity_recommended_automaticprofileswitchingsitelist_recommended_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"04b46099-4ee5-4def-8e04-569c988057a9","categoryName":"Identity and sign-in","options":null},"707c32b9ff7c14c7":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Enable support for Signed HTTP Exchange (SXG).\r\n\r\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\r\n\r\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"700e92e0cee07ef5":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"70deba07d14e0dd2":{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},"709a681bf3de70a5":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_javascriptjitallowedforsitesdesc","displayName":"Allow JavaScript to use JIT on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"70405560d9b54319":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mse7exe13","displayName":"mse7.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mse7exe13_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mse7exe13_1","displayName":"True","description":null,"helpText":null}]},"70065c15f1c7547d":{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakesonbattery","displayName":"Require a password when a computer wakes (on battery)","description":"This policy setting specifies whether or not the user is prompted for a password when the system resumes from sleep.\n\nIf you enable or do not configure this policy setting, the user is prompted for a password when the system resumes from sleep.\n\nIf you disable this policy setting, the user is not prompted for a password when the system resumes from sleep.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-requirepasswordwhencomputerwakesonbattery"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakesonbattery_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_requirepasswordwhencomputerwakesonbattery_1","displayName":"Enabled","description":null,"helpText":null}]},"70ec4ced02378b15":{"id":"device_vendor_msft_policy_config_textinput_touchkeyboarddictationbuttonavailability","displayName":"Touch Keyboard Dictation Button Availability","description":"Specifies whether the dictation input button is enabled or disabled for the touch keyboard. When this policy is set to disabled, the dictation input button on touch keyboard is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#touchkeyboarddictationbuttonavailability"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_touchkeyboarddictationbuttonavailability_0","displayName":"The OS determines when it's most appropriate to be available.","description":"The OS determines when it's most appropriate to be available.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_touchkeyboarddictationbuttonavailability_1","displayName":"Dictation button on the keyboard is always available.","description":"Dictation button on the keyboard is always available.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_touchkeyboarddictationbuttonavailability_2","displayName":"Dictation button on the keyboard is always disabled.","description":"Dictation button on the keyboard is always disabled.","helpText":null}]},"7028cd9c846954a5":{"id":"device_vendor_msft_policy_config_update_maintenancewindowweeklythursday","displayName":"Maintenance Window Weekly Thursday","description":"If the maintenance window repeat schedule is set to weekly, configure whether Thursday is included in the weekly schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowweeklythursday"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"704cc3639f042eac":{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_createdesktopshortcutmicrosoftedgebeta","displayName":"Prevent Desktop Shortcut creation upon install","description":"If you enable this policy a desktop shortcut is created when Microsoft Edge is installed.\r\n If you disable this policy, no desktop shortcut will be created when Microsoft Edge is installed.\r\n If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. \r\n If Microsoft Edge is already installed, this policy will have no effect.\r\n\r\n If you don't configure this policy for a channel, the 'CreateDesktopShortcut default' policy configuration determines shortcut creation when Microsoft Edge is installed.","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":[{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_createdesktopshortcutmicrosoftedgebeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_createdesktopshortcutmicrosoftedgebeta_1","displayName":"Enabled","description":null,"helpText":null}]},"70a9f6adfa26c642":{"id":"intelligencesettings_allowimagewand","displayName":"Allow Image Wand","description":"If `false`, disables Image Wand.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_allowimagewand_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_allowimagewand_true","displayName":"True","description":null,"helpText":null}]},"70a32a12659aadd8":{"id":"intelligencesettings_apps_mail","displayName":"Mail","description":"If present, configures Mail Intelligence features.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":null},"7030b34d7ef8d564":{"id":"user_vendor_msft_policy_config_admx_desktop_ad_querylimit_ad_querylimit_box","displayName":"Number of objects returned: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"99ba9e42-9872-4a03-a615-fc4a4cebc067","categoryName":"Active Directory","options":null},"70f730bd0f05a0dd":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_2","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_3","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},"701d58179d441a74":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},"701aeb36f33b6ec9":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled","displayName":"Re-enable deprecated/removed Mutation Events (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"70da847264db3211":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18","displayName":"Trusted Location #18 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_1","displayName":"Enabled","description":null,"helpText":null}]},"7049a093fb752a6a":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"7079dc2e95784462":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled","displayName":"Enable clipboard suggestions in the address bar (User)","description":"This policy controls whether suggestions based on clipboard content are shown in the address bar suggestion dropdown.\n\nIf you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown.\n\nIf you disable this policy, Microsoft Edge doesn't show suggestions based on clipboard content in the address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"702b847238bc3a70":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod","displayName":"Set the time period for update notifications (User)","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the 'RelaunchNotification' (Notify a user that a browser restart is recommended or required for pending updates) policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"70789c4d8dae5a6b":{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting","displayName":"'Set the default \"share additional operating system region\" setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},"70047f1f4172adf8":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_clipboardallowedforurlsdesc","displayName":"Allow clipboard use on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"705fecdaf212e954":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (User)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?LinkId=2341535.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_1","displayName":"Enabled","description":null,"helpText":null}]},"70c0663dccd21845":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed","displayName":"Allow media autoplay for websites (User)","description":"This policy sets the media autoplay policy for websites.\r\n\r\nThe default setting, \"Not configured\" respects the current media autoplay settings and lets users configure their autoplay settings.\r\n\r\nSetting to \"Enabled\" sets media autoplay to \"Allow\". All websites are allowed to autoplay media. Users can’t override this policy.\r\n\r\nSetting to \"Disabled\" sets media autoplay to \"Block\". No websites are allowed to autoplay media. Users can’t override this policy.\r\n\r\nA tab will need to be closed and re-opened for this policy to take effect.\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_autoplayallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"7012fb17ee19b6ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing","displayName":"Outlook: Ad hoc reviewing (User)","description":"\"Enable ad hoc reviewing\": Enables the ad-hoc review feature. | \"Exclude author's e-mail in documents\": Enables the ad-hoc review feature, but the authors e-mail is not recorded on the sent document. | \"Disable ad hoc reviewing\": Disables the ad-hoc review feature.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlookadhocreviewing_1","displayName":"Enabled","description":null,"helpText":null}]},"70d6a9e341fa9728":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceprofile_l_profilelabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"705a8dfcae81715c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars","displayName":"Do not show ScreenTips on toolbars (User)","description":"This policy setting allows you to configure the \"Show ScreenTips on Toolbars\" option.\r\n\r\nIf you enable this policy setting, ScreenTips will not be shown on toolbars.\r\n\r\nIf you disable or do not configure this policy setting, ScreenTips will be shown on toolbars.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_donotshowscreentipsontoolbars_1","displayName":"Enabled","description":null,"helpText":null}]},"706d091d2d818abb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword","displayName":"Disallow in Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyword_1","displayName":"True","description":null,"helpText":null}]},"700daf1ae3fd644f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia","displayName":"Croatian (Croatia) (User)","description":"Enables the editing language Croatian (Croatia)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_croatiancroatia_1","displayName":"Enabled","description":null,"helpText":null}]},"701c3b5d32620bb5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings~l_sharepointserver_l_minimumtimetowaitbeforerescanning_l_empty432","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","categoryName":"SharePoint Server","options":null},"70e51f5da1f98514":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags","displayName":"Specify custom tags for Office telemetry data (User)","description":"This policy setting allows you to add custom tags to the Office telemetry data that is sent by Office Telemetry Agent.\r\n\r\nIf you enable this policy setting, the specified custom tags are shown in Office Telemetry Dashboard, where you can filter the collected data by the tag name. You can specify any string that you want to categorize and filter the collected data (for example, department name, title of user, and so forth).\r\n\r\nIf you disable or do not configure this policy setting, no custom tags are shown in Office Telemetry Dashboard, and you cannot filter the data that is sent by Office Telemetry Agent.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_1","displayName":"Enabled","description":null,"helpText":null}]},"70c5a70b22ce9e66":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument","displayName":"Turn off Trusted Documents for VBA macros (User)","description":"This policy setting allows you to turn off the Trusted Documents feature for documents containing VBA macros.\r\n\r\nIf you enable this policy setting, users will always see security notifications for VBA macros in documents. When users click \"Enable Content\" for VBA macros, Office will not create a trust record for the document, ensuring that the user is prompted every time they open the document.\r\n\r\nIf you disable or don't configure this policy setting, the Trusted Documents feature allows users to always allow VBA macros in a document so that the user is not prompted the next time they open that document. Trusted documents are exempt from security notifications.\r\n\r\nNote: Enabling this policy setting does not clear existing trusted documents that were previously trusted.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_blockvbamacrotrusteddocument_1","displayName":"Enabled","description":null,"helpText":null}]},"70554aa5651deaf5":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers","displayName":"Show Note Containers (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"44774d3d-387b-4fa7-8de4-d82b039c06d1","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_display_l_shownotecontainers_1","displayName":"Enabled","description":null,"helpText":null}]},"701116cac939a601":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycnghashalgorithm_l_specifycnghashalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},"70a23be6e2aabd1a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver","displayName":"Path to DAV server (User)","description":"This setting allows you to define the path to a DAV server that should be used when users publish their calendars via DAV.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_1","displayName":"Enabled","description":null,"helpText":null}]},"70caf51102524072":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound","displayName":"Play a sound (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_playasound_1","displayName":"True","description":null,"helpText":null}]},"70e140d59d3d15e8":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization","displayName":"Block network activity synchronization (User)","description":"This policy setting allows you to block synchronization of status updates between Outlook and social networks.\r\n\r\nIf you enable this policy setting, social network activity synchronization is blocked.\r\n\r\nIf you disable or you do not configure this policy setting, social network activity synchronization is allowed.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_blocknetworkactivitysynchronization_1","displayName":"Enabled","description":null,"helpText":null}]},"7074cde3f1b6cd4a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_defaultsharepointlists_l_empty35","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":null},"70edb3a09c5aebd0":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions","displayName":"Keep the last AutoSaved versions of files for the next session (User)","description":"This policy setting determines whether PowerPoint keeps the last AutoSaved version of a file if a user closes a file without saving it. (Note: AutoSave applies only when AutoRecover is enabled.)\r\n\r\nIf you enable or do not configure this policy setting, PowerPoint keeps the last AutoSaved version of the file and makes it available to the user the next time the file is opened if the user closes a file without saving it.\r\n\r\nIf you disable this policy setting, PowerPoint does not keep the last AutoSaved version of the file if the user closes a file without saving it.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_keeplastautosavedversions_1","displayName":"Enabled","description":null,"helpText":null}]},"70e33d4349aeb65f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"708853c901e578e4":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview","displayName":"File tab | Share | E-mail Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendemailemailpreview_1","displayName":"True","description":null,"helpText":null}]},"7058cb942f7c08ce":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave","displayName":"Prompt for document properties on first save (User)","description":"Indicates whether the properties dialog box opens when a file is saved for the first time. File properties include author name and information such as the status of the file, preview settings and other properties.","helpText":"","infoUrls":[],"categoryId":"73415dea-0103-4427-83c5-6c97bf81af1d","categoryName":"Save Documents","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_savedocuments_l_promptfordocumentpropertiesonfirstsave_1","displayName":"Enabled","description":null,"helpText":null}]},"70b0bbaf9d7874f1":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates","displayName":"Word 6.0 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"70ecdb79fef72196":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates","displayName":"Word 97 binary documents and templates (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Word files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.\r\n","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word97binarydocumentsandtemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"70ee4fa09140e484":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},"7047e3ee62de5d8f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},"70e5c30d8172caa2":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction","displayName":"Direction","description":"The rule is enabled based on the traffic direction as following.\n\nIN - the rule applies to inbound traffic.\nOUT - the rule applies to outbound traffic.\n\nIf not specified the detault is OUT.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction_in","displayName":"The rule applies to inbound traffic.","description":"The rule applies to inbound traffic.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_direction_out","displayName":"The rule applies to outbound traffic.","description":"The rule applies to outbound traffic.","helpText":null}]},"70edcfb9264cb9ed":{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype","displayName":"License Type","description":"Get/Replace License Type: User Based License = 0, Device Based License = 1\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsLicensing-csp/"],"categoryId":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","categoryName":"Windows Licensing","options":[{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype_0","displayName":"User Based License","description":"User Based License","helpText":null},{"id":"vendor_msft_windowslicensing_devicelicensingservice_licensetype_1","displayName":"Device Based License","description":"Device Based License","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/76.json b/public/intune-definitions/76.json index 425f9c58b189..fd8910e54529 100644 --- a/public/intune-definitions/76.json +++ b/public/intune-definitions/76.json @@ -1 +1 @@ -{"76e07cd7f589526c":{"id":"com.android.devicerestrictionpolicy.passwordminimumnonlettercharacters","displayName":"Number of non-letter characters required","description":"Enter the number of non-letters (anything other than letters in the alphabet) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"7633a49d3f398ffe":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_lcid","displayName":"Microsoft Outlook LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"76151c731d29c40e":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app","displayName":"Windows App","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"761b4587555dd427":{"id":"com.apple.managedclient.preferences_nativemessagingblocklist","displayName":"Configure native messaging block list","description":"Specifies which native messaging hosts that shouldn't be used.\n\nUse '*' to block all native messaging hosts unless they are explicitly listed in the allow list.\n\nIf you don't configure this policy, Microsoft Edge will load all installed native messaging hosts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#nativemessagingblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"76b7924b5a4d34e4":{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_url","displayName":"URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"76e70855b04583b2":{"id":"com.apple.systempreferences_disabledpreferencepanes","displayName":"Disabled Preference Panes","description":"The list of disabled System Preferences panes.","helpText":null,"infoUrls":[],"categoryId":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","categoryName":"System Preferences","options":null},"7649926b8952c6b1":{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled","displayName":"Search Filters Enabled","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions are shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown can't display the ribbon of available filters.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"7680b0193a8a4408":{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist","displayName":"Ignoring Delegation Failure:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist_0","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist_1","displayName":"On","description":null,"helpText":null}]},"7631f1553da47ae9":{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},"76c80e10e29c6e80":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-trusted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted_1","displayName":"Enabled","description":null,"helpText":null}]},"76e96111900cd2f8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist_remoteaccesshostdomainlistdesc","displayName":"Configure the required domain names for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},"76e24129f0d21178":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as\r\n'[*.]example.com') that will not be upgraded to HTTPS and will not show an\r\nerror interstitial if HTTPS-First Mode is enabled. Organizations can use this\r\npolicy to maintain access to servers that do not support HTTPS, without\r\nneeding to disable HTTPS Upgrades and/or HTTPS-First Mode.\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their\r\nA-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead,\r\nHTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their\r\nspecific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"769bbfff7e218363":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled","displayName":"Allow using Google Assistant on the web, e.g. to enable changing passwords automatically","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"762507073a90f669":{"id":"device_vendor_msft_policy_config_experience_allowcortana","displayName":"Allow Cortana","description":"Specifies whether Cortana is allowed on the device. If you enable or don’t configure this setting, Cortana is allowed on the device. If you disable this setting, Cortana is turned off. When Cortana is off, users will still be able to use search to find items on the device. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowcortana"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowcortana_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowcortana_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"76f3fbef4fa15647":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_numberofpreviouslogonstocache","displayName":"Interactive Logon Number Of Previous Logons To Cache","description":"Interactive logon: Number of previous logons to cache (in case domain controller is not available) Each unique user's logon information is cached locally so that, in the event that a domain controller is unavailable during subsequent logon attempts, they are able to log on. The cached logon information is stored from the previous logon session. If a domain controller is unavailable and a user's logon information is not cached, the user is prompted with this message: There are currently no logon servers available to service the logon request. In this policy setting, a value of 0 disables logon caching. Any value above 50 only caches 50 logon attempts. Windows supports a maximum of 50 cache entries and the number of entries consumed per user depends on the credential. For example, a maximum of 50 unique password user accounts can be cached on a Windows system, but only 25 smart card user accounts can be cached because both the password information and the smart card information are stored. When a user with cached logon information logs on again, the user’s individual cached information is replaced. Default: Windows Server 2008: 25 All Other Versions: 10\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_numberofpreviouslogonstocache"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"76cd1184dbdf4bc5":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_donotallowstorageofpasswordsandcredentialsfornetworkauthentication","displayName":"Network Access Do Not Allow Storage Of Passwords And Credentials For Network Authentication","description":"Network access: Do not allow storage of passwords and credentials for network authentication This security setting determines whether Credential Manager saves passwords and credentials for later use when it gains domain authentication. If you enable this setting, Credential Manager does not store passwords and credentials on the computer. If you disable or do not configure this policy setting, Credential Manager will store passwords and credentials on this computer for later use for domain authentication. Note: When configuring this security setting, changes will not take effect until you restart Windows. Default: Disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_donotallowstorageofpasswordsandcredentialsfornetworkauthentication"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"76c178d327068ee3":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup","displayName":"Action to take on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"7664ca6e31bd7ead":{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.\r\n\r\nThis policy can be overridden for specific url patterns using the 'WebHidAskForUrls' (Allow the WebHID API on these sites) and 'WebHidBlockedForUrls' (Block the WebHID API on these sites) policies.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API\r\n\r\n* AskWebHid (3) = Allow sites to ask the user to grant access to a HID device\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"76222ca4b9abd657":{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended","displayName":"Edge Wallet E-Tree Enabled","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\r\n\r\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\r\n\r\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"76c69949654af552":{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass","displayName":"Allow users to bypass Enhanced Security Mode","description":"Microsoft Edge will let users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode.\r\n\r\nIf you disable this policy, Microsoft Edge won't allow users to bypass Enhanced Security Mode.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will allow users to bypass Enhanced Security Mode.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass_1","displayName":"Enabled","description":null,"helpText":null}]},"7680f1e862d1fe16":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls_webrtclocalipsallowedurlsdesc","displayName":"Manage exposure of local IP addressess by WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"76af6917874a9e33":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts","displayName":"Allow importing of shortcuts","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"769926c3b6c9ccb9":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_0","displayName":"Do not send form data or headers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_1","displayName":"Send form data only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_2","displayName":"Send additional headers only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_3","displayName":"Send form data and additional headers","description":null,"helpText":null}]},"7639063b7f5debe2":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_winwordexe161","displayName":"winword.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_winwordexe161_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_winwordexe161_1","displayName":"True","description":null,"helpText":null}]},"763020ffe976e7bd":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscalendar_forceallowtheseapps","displayName":"Let Apps Access Calendar Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to the calendar. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscalendar_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"7680c4d5858fff79":{"id":"device_vendor_msft_policy_config_textinput_allowjapanesenonpublishingstandardglyph","displayName":"Allow Japanese Non Publishing Standard Glyph","description":"Note The policy is only enforced in Windows 10 for desktop. Allows the Japanese non-publishing standard glyph. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#allowjapanesenonpublishingstandardglyph"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_allowjapanesenonpublishingstandardglyph_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_allowjapanesenonpublishingstandardglyph_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"763cb5181c4e6a75":{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_part_edgepreviewenrollmenttype","displayName":"Enrollment type (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_part_edgepreviewenrollmenttype_1","displayName":"Allow Opt-out","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_part_edgepreviewenrollmenttype_3","displayName":"Required","description":null,"helpText":null}]},"76e0aec8a80908d0":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_administratorupdatesenabled_administratorupdatesenableddropid","displayName":"Microsoft Update Channel","description":"","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_administratorupdatesenabled_administratorupdatesenableddropid_1","displayName":"WSUS/SCCM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_administratorupdatesenabled_administratorupdatesenableddropid_2","displayName":"WSUS/SCCM and Microsoft Updates/Intune","description":null,"helpText":null}]},"76060970ad53736f":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_removeoutofsupport","displayName":"Remove out-of-support components during updates","description":"This setting will cause updates to automatically remove all components from all Visual Studio installations that have transitioned to an out-of-support state.\r\n \r\nIf set to 1 (enabled), then the Visual Studio installer will remove all out-of-support components during all subsequent updates. \r\n \r\nIf set to 0 (disabled) or missing entirely, then the remove out-of-support components behavior will respect other locations where this can be configured, such as commandline parameter or the Update Settings dialog.\r\n \r\nThis functionality requires the Visual Studio 2022 version 17.4 installer to be installed on the client machine. \r\n\r\nFor more information, see http://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_removeoutofsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_removeoutofsupport_1","displayName":"Enabled","description":null,"helpText":null}]},"7625f7765530ea7f":{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopc","displayName":"Allow Projection To PC","description":"This policy setting allows you to turn off projection to a PC If you set it to 0, your PC can't be discoverable or projected to over Wi-Fi Direct. If you set it to 1, your PC can be discoverable and projected to over Wi-Fi Direct. The user has an option to turn it always on or off except for manual launch, too.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WirelessDisplay#allowprojectiontopc"],"categoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopc_0","displayName":"Projection to PC is not allowed. Always off and the user cannot enable it.","description":"Projection to PC is not allowed. Always off and the user cannot enable it.","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopc_1","displayName":"Projection to PC is allowed. Enabled only above the lock screen.","description":"Projection to PC is allowed. Enabled only above the lock screen.","helpText":null}]},"7601c1309d565f45":{"id":"settings_item_mdmoptions","displayName":"MDM Options","description":"A dictionary that contains settings related to the MDM protocol. This setting doesn't support user enrollment. Available in iOS 7 and later, macOS 10.15 and later, and visionOS 2 and later.","helpText":null,"infoUrls":[],"categoryId":"dd68a290-1ba7-470f-afca-339f443a767c","categoryName":"MDM Options","options":null},"76ff337d5ca7e0db":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrocreateshortcutmenufrommacro","displayName":"Database Tools | Macro | Create Shortcut Menu from Macro (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrocreateshortcutmenufrommacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrocreateshortcutmenufrommacro_1","displayName":"True","description":null,"helpText":null}]},"7608cab9a7581473":{"id":"user_vendor_msft_policy_config_admx_msi_searchorder_searchorder","displayName":"Search order (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":null},"7640f54ac6a6029c":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word","displayName":"Microsoft Word 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Word 2013.\r\nBy default, the user settings of Microsoft Word 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word_1","displayName":"Enabled","description":null,"helpText":null}]},"761dab051d10d9a9":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown","displayName":"Pick one of the following combinations (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_3","displayName":"Restrict A and B drives only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_4","displayName":"Restrict C drive only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_8","displayName":"Restrict D drive only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_7","displayName":"Restrict A, B and C drives only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_15","displayName":"Restrict A, B, C and D drives only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_67108863","displayName":"Restrict all drives","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_0","displayName":"Do not restrict drives","description":null,"helpText":null}]},"76b14671c9e4efd9":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay","displayName":"Maximum fetch delay after a policy invalidation (User)","description":"Setting the policy specifies the maximum delay in milliseconds between receiving a policy invalidation and fetching the new policy from the device management service. Valid values range from 1,000 (1 second) to 300,000 (5 minutes). Values outside this range will be clamped to the respective boundary.\r\n\r\nLeaving the policy unset means Google Chrome uses the default value of 10 seconds.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"765c73932896555f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_registeredprotocolhandlers","displayName":"Register protocol handlers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"962a2377-ad9a-4654-a526-a77c14152fd7","categoryName":"Content settings","options":null},"762090c36311b2ed":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_0","displayName":"Scan encrypted macros (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_1","displayName":"Scan if anti-virus software available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_2","displayName":"Load macros without scanning","description":null,"helpText":null}]},"765de9b39166244a":{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate","displayName":"Internet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"7610149fcc1ffd28":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script (User)","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script can perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowcopypasteviascript"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"765a0553d5ca6c5c":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowsmartscreenie"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"76495b0fd0467215":{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls","displayName":"Block geolocation on these sites (User)","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\r\n\r\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\r\n\r\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\r\n\r\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"76d0d51924ffe98d":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments (User)","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\r\n​\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"76b081e9cd331e3a":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"767fb78d95d77ffb":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended","displayName":"Show Microsoft Rewards experiences (User)","description":"Show Microsoft Rewards experience and notifications.\r\nIf you enable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.\r\n\r\nIf you disable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will not see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be disabled and toggled off.\r\n\r\nIf you don't configure this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"769bc883402ffe5b":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps","displayName":"Apps blocked by Writing Assistance admin policy (User)","description":"This policy setting allows administrators to specify a list of applications where Writing Assistance will be blocked.\nIf you enable this policy setting, enter one application executable name per line (e.g., notepad.exe). Writing Assistance will be disabled in those applications.\nIf you disable or do not configure this policy setting, Writing Assistance will not be blocked by this policy in any application.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_1","displayName":"Enabled","description":null,"helpText":null}]},"76a4019de5b2e130":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07","displayName":"Configure presentation service in PowerPoint and Word 8 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_1","displayName":"Enabled","description":null,"helpText":null}]},"7621ece5d0de4e31":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu","displayName":"Do not display Hover Menu (User)","description":"This policy setting allows you to stop the Hover Menu from displaying when a user hovers over a contact’s presence icon or display name with the mouse cursor.\r\n\r\nIf you enable this policy setting, when a user hovers over a contact’s presence icon or display name with the mouse cursor, the Hover Menu will not be displayed.\r\n\r\nIf you disable or do not configure this policy setting, the Hover Menu appears when a user hovers over a contact’s presence icon or display name with the mouse cursor.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu_1","displayName":"Enabled","description":null,"helpText":null}]},"7639dbb58a7354e1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook_1","displayName":"True","description":null,"helpText":null}]},"76e77c6cd10cccca":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage","displayName":"Primary Editing Language (User)","description":"Defines the editing options for Office 2016 programs. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node. Please refer to the Office Resource Kit documentation for important information on setting the installed version of Microsoft Office.","helpText":"","infoUrls":[],"categoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","categoryName":"Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_1","displayName":"Enabled","description":null,"helpText":null}]},"762aef8c81bd5a4b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic","displayName":"Uzbek (Cyrillic) (User)","description":"Enables the editing language Uzbek (Cyrillic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic_1","displayName":"Enabled","description":null,"helpText":null}]},"7688de8323f0b715":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata","displayName":"Send personal information (User)","description":"This policy setting controls whether users can send personal information to Office. When users choose to send information Office 2016 applications automatically send information to Office.\r\n\r\nIf you enable this policy setting, users will opt into sending personal information to Office. If your organization has policies that govern the use of external resources, opting users into the program might cause them to violate these policies.\r\n\r\nIf you disable this policy setting, Office 2016 users cannot send personal information to Office.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata_1","displayName":"Enabled","description":null,"helpText":null}]},"761185acb0002c6f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity","displayName":"Automation Security (User)","description":"This policy setting controls whether macros can run in an Office 2016 application that is opened programmatically by another application. \r\n\r\nIf you enable this policy setting, you can choose from three options for controlling macro behavior in Excel, PowerPoint, and Word when the application is opened programmatically: \r\n\r\n- Disable macros by default - All macros are disabled in the programmatically opened application. \r\n\r\n- Macros enabled (default) - Macros can run in the programmatically opened application. This option enforces the default configuration in Excel, PowerPoint, and Word. \r\n\r\n- User application macro security level - Macro functionality is determined by the setting in the \"Macro Settings\" section of the Trust Center. \r\n\r\nIf you disable or do not configure this policy setting, when a separate program is used to launch Microsoft Excel, PowerPoint, or Word programmatically, any macros can run in the programmatically opened application without being blocked.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},"761c010b97e9a60b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation","displayName":"Turn off error reporting for files that fail file validation (User)","description":"This policy determines whether error reports and files that fail file validation should be sent using the Watson dialog.\r\n\r\nIf you enable this policy setting, users will not see the Watson dialog. Files that fail file validation will not be sent by the Watson dialog to Microsoft.\r\n\r\nIf you disable or do not configure this policy setting, the Watson dialog to send files that fail validation will show up once every two weeks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},"76e60f2eafbc531c":{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs","displayName":"Allow VBA to load typelib references by path from untrusted intranet locations (User)","description":"This policy setting permits VBA to load typelib references by explicit path read from the project data if that path points to an intranet location that is not explicitly in the system trusted sites list.\r\n\r\nBy default, VBA will attempt to load typelibs referenced in a project by searching for the library GUID in the registry. If it is not found in the registry, VBA will attempt to load the typelib or project reference using the path stored in the project for the reference as long as the reference does not point to an internet or intranet location that is not in the trusted sites list.\r\n\r\nIf you enable this policy setting, VBA will treat intranet paths like local machine paths, and therefore VBA will attempt to search for unregistered references in intranet locations that are not local machine or in the system's trusted sites list.\r\n\r\nIf you disable or don’t configure this policy setting, VBA maintains its default behavior and will refuse to load typelibs on intranet paths if it does not find the typelib registered in HKEY_CLASSES_ROOT.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs_1","displayName":"Enabled","description":null,"helpText":null}]},"7616cb53d0a81880":{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid","displayName":"Show Outlook Loop components for supported apps (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_1","displayName":"Always show automatically.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_2","displayName":"Only show automatically within tenant.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_3","displayName":"Don’t show automatically.","description":null,"helpText":null}]},"769546c95d4e578d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions","displayName":"Configure form regions permissions (User)","description":"By default, all form region customizations are permitted to run in Outlook. By using this setting, you can disable all form region customizations, or specify that form regions must be registered on a per-computer basis, rather than a per-user basis.","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_1","displayName":"Enabled","description":null,"helpText":null}]},"761099d131882961":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody","displayName":"Change the limit for the number of MIME body parts (User)","description":"By default, the limit is 250 for the number of MIME body parts when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_1","displayName":"Enabled","description":null,"helpText":null}]},"76c8ddb573cf21ba":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_0","displayName":"Automatically Deny","description":null,"helpText":null}]},"76b883f8d4935b7f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface","displayName":"Configure Outlook Anywhere user interface options (User)","description":"This policy setting allows you to determine whether users can view and change user interface (UI) options for Outlook Anywhere.\r\n\r\nIf you enable this policy setting, users can view and change UI options for Outlook Anywhere.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to use the Outlook Anywhere feature, but they will not be able to view or change UI options for it.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_1","displayName":"Enabled","description":null,"helpText":null}]},"765f189c7fc9ab4e":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File tab | Share | Send Using E-mail (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},"769ea5841846a2fc":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},"7693c7b432bf8889":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17","displayName":"Fiscal year starts in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_1","displayName":"January","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_2","displayName":"February","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_3","displayName":"March","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_4","displayName":"April","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_5","displayName":"May","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_6","displayName":"June","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_7","displayName":"July","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_8","displayName":"August","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_9","displayName":"September","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_10","displayName":"October","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_11","displayName":"November","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_12","displayName":"December","description":null,"helpText":null}]},"7618dfbfef143232":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview","displayName":"Web tab | View | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_1","displayName":"True","description":null,"helpText":null}]},"767a4e5410800aa8":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings","displayName":"Show file save warnings (User)","description":"Indicates whether a warning message is displayed when you save files that contain errors such as invalid XML code.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings_1","displayName":"Enabled","description":null,"helpText":null}]},"769b5e29dc665f0c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames","displayName":"Month names (User)","description":"Used for complex scripts. Specifies if month names shall be of calendar type Gregorian Arabic, Gregorian transliterated English, or Gregorian transliterated French.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"76e07cd7f589526c":{"id":"com.android.devicerestrictionpolicy.passwordminimumnonlettercharacters","displayName":"Number of non-letter characters required","description":"Enter the number of non-letters (anything other than letters in the alphabet) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"7633a49d3f398ffe":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft outlook.app_lcid","displayName":"Microsoft Outlook LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"76151c731d29c40e":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app","displayName":"Windows App","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"761b4587555dd427":{"id":"com.apple.managedclient.preferences_nativemessagingblocklist","displayName":"Configure native messaging block list","description":"Specifies which native messaging hosts that shouldn't be used.\n\nUse '*' to block all native messaging hosts unless they are explicitly listed in the allow list.\n\nIf you don't configure this policy, Microsoft Edge will load all installed native messaging hosts.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#nativemessagingblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"76b7924b5a4d34e4":{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_url","displayName":"URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"76e70855b04583b2":{"id":"com.apple.systempreferences_disabledpreferencepanes","displayName":"Disabled Preference Panes","description":"The list of disabled System Preferences panes.","helpText":null,"infoUrls":[],"categoryId":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","categoryName":"System Preferences","options":null},"7649926b8952c6b1":{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled","displayName":"Search Filters Enabled","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions are shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown can't display the ribbon of available filters.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchfiltersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"7680b0193a8a4408":{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist","displayName":"Ignoring Delegation Failure:","description":null,"helpText":"","infoUrls":[],"categoryId":"f1278d6b-60ec-4369-88cf-21df47caaec6","categoryName":"Remote Procedure Call","options":[{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist_0","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_rpc_rpcignoredelegationfailure_rpcignoredelegationfailurelist_1","displayName":"On","description":null,"helpText":null}]},"7631f1553da47ae9":{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenarioexecutionpolicy_wdidpsscenarioexecutionpolicylevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},"76c80e10e29c6e80":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-trusted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trusted_1","displayName":"Enabled","description":null,"helpText":null}]},"76e96111900cd2f8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostdomainlist_remoteaccesshostdomainlistdesc","displayName":"Configure the required domain names for remote access hosts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},"76e24129f0d21178":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist","displayName":"HTTP Allowlist","description":"Setting the policy specifies a list of hostnames or hostname patterns (such as\r\n'[*.]example.com') that will not be upgraded to HTTPS and will not show an\r\nerror interstitial if HTTPS-First Mode is enabled. Organizations can use this\r\npolicy to maintain access to servers that do not support HTTPS, without\r\nneeding to disable HTTPS Upgrades and/or HTTPS-First Mode.\r\n\r\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their\r\nA-label format, and all ASCII letters must be lowercase.\r\n\r\nBlanket host wildcards (i.e., \"*\" or \"[*]\") are not allowed. Instead,\r\nHTTPS-First Mode and HTTPS Upgrades should be explicitly disabled via their\r\nspecific policies.\r\n\r\nNote: This policy does not apply to HSTS upgrades.\r\n\r\nExample value:\r\n\r\ntestserver.example.com\r\n[*.]example.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_httpallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"769bbfff7e218363":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled","displayName":"Allow using Google Assistant on the web, e.g. to enable changing passwords automatically","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_assistantwebenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"762507073a90f669":{"id":"device_vendor_msft_policy_config_experience_allowcortana","displayName":"Allow Cortana","description":"Specifies whether Cortana is allowed on the device. If you enable or don’t configure this setting, Cortana is allowed on the device. If you disable this setting, Cortana is turned off. When Cortana is off, users will still be able to use search to find items on the device. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowcortana"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowcortana_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowcortana_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"76f3fbef4fa15647":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_numberofpreviouslogonstocache","displayName":"Interactive Logon Number Of Previous Logons To Cache","description":"Interactive logon: Number of previous logons to cache (in case domain controller is not available) Each unique user's logon information is cached locally so that, in the event that a domain controller is unavailable during subsequent logon attempts, they are able to log on. The cached logon information is stored from the previous logon session. If a domain controller is unavailable and a user's logon information is not cached, the user is prompted with this message: There are currently no logon servers available to service the logon request. In this policy setting, a value of 0 disables logon caching. Any value above 50 only caches 50 logon attempts. Windows supports a maximum of 50 cache entries and the number of entries consumed per user depends on the credential. For example, a maximum of 50 unique password user accounts can be cached on a Windows system, but only 25 smart card user accounts can be cached because both the password information and the smart card information are stored. When a user with cached logon information logs on again, the user’s individual cached information is replaced. Default: Windows Server 2008: 25 All Other Versions: 10\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_numberofpreviouslogonstocache"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"76cd1184dbdf4bc5":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_donotallowstorageofpasswordsandcredentialsfornetworkauthentication","displayName":"Network Access Do Not Allow Storage Of Passwords And Credentials For Network Authentication","description":"Network access: Do not allow storage of passwords and credentials for network authentication This security setting determines whether Credential Manager saves passwords and credentials for later use when it gains domain authentication. If you enable this setting, Credential Manager does not store passwords and credentials on the computer. If you disable or do not configure this policy setting, Credential Manager will store passwords and credentials on this computer for later use for domain authentication. Note: When configuring this security setting, changes will not take effect until you restart Windows. Default: Disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_donotallowstorageofpasswordsandcredentialsfornetworkauthentication"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"76d40c404e0e73d3":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled","displayName":"Enable service-based extraction for Reading Mode in Microsoft Edge","description":"This policy controls whether Microsoft Edge can use the Microsoft online extraction service to improve Reading Mode rendering.\n\nIf you enable or don't configure this policy, Microsoft Edge can send the text of the page being read to the service for processing.\n\nIf you disable this policy, Microsoft Edge doesn't send the text of the page being read to the service. Reading Mode remains available, but extraction quality may be limited.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"76c178d327068ee3":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup","displayName":"Action to take on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"7664ca6e31bd7ead":{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.\r\n\r\nThis policy can be overridden for specific url patterns using the 'WebHidAskForUrls' (Allow the WebHID API on these sites) and 'WebHidBlockedForUrls' (Block the WebHID API on these sites) policies.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockWebHid (2) = Do not allow any site to request access to HID devices via the WebHID API\r\n\r\n* AskWebHid (3) = Allow sites to ask the user to grant access to a HID device\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge~contentsettings_defaultwebhidguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"76222ca4b9abd657":{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended","displayName":"Edge Wallet E-Tree Enabled","description":"The Edge Wallet E-Tree feature in Microsoft Edge allows users to plant a E-Tree for their own.\r\n\r\nIf you enable or don't configure this policy, users can use the Edge Wallet E-Tree feature.\r\n\r\nIf you disable this policy, users can't use the Edge Wallet E-Tree feature.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_recommended_edgewalletetreeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"76c69949654af552":{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass","displayName":"Allow users to bypass Enhanced Security Mode","description":"Microsoft Edge will let users bypass Enhanced Security Mode on a site via Settings page or PageInfo flyout. This policy lets you configure whether users can bypass Enhanced Security Mode.\r\n\r\nIf you disable this policy, Microsoft Edge won't allow users to bypass Enhanced Security Mode.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will allow users to bypass Enhanced Security Mode.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_enhancesecuritymodeallowuserbypass_1","displayName":"Enabled","description":null,"helpText":null}]},"7680f1e862d1fe16":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webrtclocalipsallowedurls_webrtclocalipsallowedurlsdesc","displayName":"Manage exposure of local IP addressess by WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"76af6917874a9e33":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts","displayName":"Allow importing of shortcuts","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"769926c3b6c9ccb9":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes","displayName":"Configure whether form data and HTTP headers will be sent when entering or exiting Internet Explorer mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_0","displayName":"Do not send form data or headers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_1","displayName":"Send form data only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_2","displayName":"Send additional headers only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_internetexplorerintegrationcomplexnavdatatypes_internetexplorerintegrationcomplexnavdatatypes_3","displayName":"Send form data and additional headers","description":null,"helpText":null}]},"7639063b7f5debe2":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_winwordexe161","displayName":"winword.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_winwordexe161_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_winwordexe161_1","displayName":"True","description":null,"helpText":null}]},"763020ffe976e7bd":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscalendar_forceallowtheseapps","displayName":"Let Apps Access Calendar Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to the calendar. This setting overrides the default LetAppsAccessCalendar policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscalendar_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"7680c4d5858fff79":{"id":"device_vendor_msft_policy_config_textinput_allowjapanesenonpublishingstandardglyph","displayName":"Allow Japanese Non Publishing Standard Glyph","description":"Note The policy is only enforced in Windows 10 for desktop. Allows the Japanese non-publishing standard glyph. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TextInput#allowjapanesenonpublishingstandardglyph"],"categoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","categoryName":"Text Input","options":[{"id":"device_vendor_msft_policy_config_textinput_allowjapanesenonpublishingstandardglyph_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_textinput_allowjapanesenonpublishingstandardglyph_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"763cb5181c4e6a75":{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_part_edgepreviewenrollmenttype","displayName":"Enrollment type (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_part_edgepreviewenrollmenttype_1","displayName":"Allow Opt-out","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_part_edgepreviewenrollmenttype_3","displayName":"Required","description":null,"helpText":null}]},"76e0aec8a80908d0":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_administratorupdatesenabled_administratorupdatesenableddropid","displayName":"Microsoft Update Channel","description":"","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_administratorupdatesenabled_administratorupdatesenableddropid_1","displayName":"WSUS/SCCM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_administratorupdatesenabled_administratorupdatesenableddropid_2","displayName":"WSUS/SCCM and Microsoft Updates/Intune","description":null,"helpText":null}]},"76060970ad53736f":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_removeoutofsupport","displayName":"Remove out-of-support components during updates","description":"This setting will cause updates to automatically remove all components from all Visual Studio installations that have transitioned to an out-of-support state.\r\n \r\nIf set to 1 (enabled), then the Visual Studio installer will remove all out-of-support components during all subsequent updates. \r\n \r\nIf set to 0 (disabled) or missing entirely, then the remove out-of-support components behavior will respect other locations where this can be configured, such as commandline parameter or the Update Settings dialog.\r\n \r\nThis functionality requires the Visual Studio 2022 version 17.4 installer to be installed on the client machine. \r\n\r\nFor more information, see http://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_removeoutofsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_removeoutofsupport_1","displayName":"Enabled","description":null,"helpText":null}]},"7625f7765530ea7f":{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopc","displayName":"Allow Projection To PC","description":"This policy setting allows you to turn off projection to a PC If you set it to 0, your PC can't be discoverable or projected to over Wi-Fi Direct. If you set it to 1, your PC can be discoverable and projected to over Wi-Fi Direct. The user has an option to turn it always on or off except for manual launch, too.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WirelessDisplay#allowprojectiontopc"],"categoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopc_0","displayName":"Projection to PC is not allowed. Always off and the user cannot enable it.","description":"Projection to PC is not allowed. Always off and the user cannot enable it.","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_allowprojectiontopc_1","displayName":"Projection to PC is allowed. Enabled only above the lock screen.","description":"Projection to PC is allowed. Enabled only above the lock screen.","helpText":null}]},"7601c1309d565f45":{"id":"settings_item_mdmoptions","displayName":"MDM Options","description":"A dictionary that contains settings related to the MDM protocol. This setting doesn't support user enrollment. Available in iOS 7 and later, macOS 10.15 and later, and visionOS 2 and later.","helpText":null,"infoUrls":[],"categoryId":"dd68a290-1ba7-470f-afca-339f443a767c","categoryName":"MDM Options","options":null},"76ff337d5ca7e0db":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrocreateshortcutmenufrommacro","displayName":"Database Tools | Macro | Create Shortcut Menu from Macro (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrocreateshortcutmenufrommacro_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrocreateshortcutmenufrommacro_1","displayName":"True","description":null,"helpText":null}]},"7608cab9a7581473":{"id":"user_vendor_msft_policy_config_admx_msi_searchorder_searchorder","displayName":"Search order (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":null},"7640f54ac6a6029c":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word","displayName":"Microsoft Word 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Word 2013.\r\nBy default, the user settings of Microsoft Word 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013word_1","displayName":"Enabled","description":null,"helpText":null}]},"761dab051d10d9a9":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown","displayName":"Pick one of the following combinations (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_3","displayName":"Restrict A and B drives only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_4","displayName":"Restrict C drive only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_8","displayName":"Restrict D drive only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_7","displayName":"Restrict A, B and C drives only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_15","displayName":"Restrict A, B, C and D drives only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_67108863","displayName":"Restrict all drives","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nodrives_nodrivesdropdown_0","displayName":"Do not restrict drives","description":null,"helpText":null}]},"76b14671c9e4efd9":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay","displayName":"Maximum fetch delay after a policy invalidation (User)","description":"Setting the policy specifies the maximum delay in milliseconds between receiving a policy invalidation and fetching the new policy from the device management service. Valid values range from 1,000 (1 second) to 300,000 (5 minutes). Values outside this range will be clamped to the respective boundary.\r\n\r\nLeaving the policy unset means Google Chrome uses the default value of 10 seconds.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxinvalidationfetchdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"765c73932896555f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_registeredprotocolhandlers","displayName":"Register protocol handlers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"962a2377-ad9a-4654-a526-a77c14152fd7","categoryName":"Content settings","options":null},"762090c36311b2ed":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_0","displayName":"Scan encrypted macros (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_1","displayName":"Scan if anti-virus software available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_determinewhethertoforceencryptedexcel_l_determinewhethertoforceencryptedexceldropid_2","displayName":"Load macros without scanning","description":null,"helpText":null}]},"765de9b39166244a":{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate","displayName":"Internet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"7610149fcc1ffd28":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script (User)","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script can perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowcopypasteviascript"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"765a0553d5ca6c5c":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowsmartscreenie"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"76495b0fd0467215":{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls","displayName":"Block geolocation on these sites (User)","description":"Use this policy to define a list of URL patterns for sites that are blocked from accessing the user's geolocation. These sites also can't prompt the user for location permissions.\r\n\r\nIf you enable this policy, the list you provide determines which sites are blocked from requesting or accessing geolocation.\r\n\r\nIf you disable or don't configure this policy, DefaultGeolocationSetting applies to all sites, if configured. If it's not configured, the user’s personal browser setting is used.\r\n\r\nFor detailed information on valid url patterns, see the documentation on pattern formats: https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"76d0d51924ffe98d":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments (User)","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\r\n​\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"76b081e9cd331e3a":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"767fb78d95d77ffb":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended","displayName":"Show Microsoft Rewards experiences (User)","description":"Show Microsoft Rewards experience and notifications.\r\nIf you enable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.\r\n\r\nIf you disable this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will not see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be disabled and toggled off.\r\n\r\nIf you don't configure this policy:\r\n - Microsoft account users (excludes Azure AD accounts) in search and earn markets will see the Microsoft Rewards experience in their Microsoft Edge user profile.\r\n - The setting to enable Microsoft Rewards in Microsoft Edge settings will be enabled and toggled on.\r\n - The setting to enable Give mode will be enabled and respect the user's setting.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended_showmicrosoftrewards_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"769bc883402ffe5b":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps","displayName":"Apps blocked by Writing Assistance admin policy (User)","description":"This policy setting allows administrators to specify a list of applications where Writing Assistance will be blocked.\nIf you enable this policy setting, enter one application executable name per line (e.g., notepad.exe). Writing Assistance will be disabled in those applications.\nIf you disable or do not configure this policy setting, Writing Assistance will not be blocked by this policy in any application.\n ","helpText":"","infoUrls":[],"categoryId":"05a6f86f-dab7-4888-97a1-db3457f00974","categoryName":"Writing Assistance","options":[{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_writingassistance_l_writingassistantadminblockedapps_1","displayName":"Enabled","description":null,"helpText":null}]},"76a4019de5b2e130":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07","displayName":"Configure presentation service in PowerPoint and Word 8 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_1","displayName":"Enabled","description":null,"helpText":null}]},"7621ece5d0de4e31":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu","displayName":"Do not display Hover Menu (User)","description":"This policy setting allows you to stop the Hover Menu from displaying when a user hovers over a contact’s presence icon or display name with the mouse cursor.\r\n\r\nIf you enable this policy setting, when a user hovers over a contact’s presence icon or display name with the mouse cursor, the Hover Menu will not be displayed.\r\n\r\nIf you disable or do not configure this policy setting, the Hover Menu appears when a user hovers over a contact’s presence icon or display name with the mouse cursor.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayhovermenu_1","displayName":"Enabled","description":null,"helpText":null}]},"7639dbb58a7354e1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuioutlook_1","displayName":"True","description":null,"helpText":null}]},"76e77c6cd10cccca":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage","displayName":"Primary Editing Language (User)","description":"Defines the editing options for Office 2016 programs. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node. Please refer to the Office Resource Kit documentation for important information on setting the installed version of Microsoft Office.","helpText":"","infoUrls":[],"categoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","categoryName":"Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages_l_primaryeditinglanguage_1","displayName":"Enabled","description":null,"helpText":null}]},"762aef8c81bd5a4b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic","displayName":"Uzbek (Cyrillic) (User)","description":"Enables the editing language Uzbek (Cyrillic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_uzbekcyrillic_1","displayName":"Enabled","description":null,"helpText":null}]},"7688de8323f0b715":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata","displayName":"Send personal information (User)","description":"This policy setting controls whether users can send personal information to Office. When users choose to send information Office 2016 applications automatically send information to Office.\r\n\r\nIf you enable this policy setting, users will opt into sending personal information to Office. If your organization has policies that govern the use of external resources, opting users into the program might cause them to violate these policies.\r\n\r\nIf you disable this policy setting, Office 2016 users cannot send personal information to Office.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to \"Enabled\".","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendcustomerdata_1","displayName":"Enabled","description":null,"helpText":null}]},"761185acb0002c6f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity","displayName":"Automation Security (User)","description":"This policy setting controls whether macros can run in an Office 2016 application that is opened programmatically by another application. \r\n\r\nIf you enable this policy setting, you can choose from three options for controlling macro behavior in Excel, PowerPoint, and Word when the application is opened programmatically: \r\n\r\n- Disable macros by default - All macros are disabled in the programmatically opened application. \r\n\r\n- Macros enabled (default) - Macros can run in the programmatically opened application. This option enforces the default configuration in Excel, PowerPoint, and Word. \r\n\r\n- User application macro security level - Macro functionality is determined by the setting in the \"Macro Settings\" section of the Trust Center. \r\n\r\nIf you disable or do not configure this policy setting, when a separate program is used to launch Microsoft Excel, PowerPoint, or Word programmatically, any macros can run in the programmatically opened application without being blocked.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},"761c010b97e9a60b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation","displayName":"Turn off error reporting for files that fail file validation (User)","description":"This policy determines whether error reports and files that fail file validation should be sent using the Watson dialog.\r\n\r\nIf you enable this policy setting, users will not see the Watson dialog. Files that fail file validation will not be sent by the Watson dialog to Microsoft.\r\n\r\nIf you disable or do not configure this policy setting, the Watson dialog to send files that fail validation will show up once every two weeks.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_turnofferrorreportingforfilesthatfailfilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},"76e60f2eafbc531c":{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs","displayName":"Allow VBA to load typelib references by path from untrusted intranet locations (User)","description":"This policy setting permits VBA to load typelib references by explicit path read from the project data if that path points to an intranet location that is not explicitly in the system trusted sites list.\r\n\r\nBy default, VBA will attempt to load typelibs referenced in a project by searching for the library GUID in the registry. If it is not found in the registry, VBA will attempt to load the typelib or project reference using the path stored in the project for the reference as long as the reference does not point to an internet or intranet location that is not in the trusted sites list.\r\n\r\nIf you enable this policy setting, VBA will treat intranet paths like local machine paths, and therefore VBA will attempt to search for unregistered references in intranet locations that are not local machine or in the system's trusted sites list.\r\n\r\nIf you disable or don’t configure this policy setting, VBA maintains its default behavior and will refuse to load typelibs on intranet paths if it does not find the typelib registered in HKEY_CLASSES_ROOT.\r\n ","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v6~policy~l_microsoftofficesystem~l_securitysettings_l_allowvbaintranetrefs_1","displayName":"Enabled","description":null,"helpText":null}]},"7616cb53d0a81880":{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid","displayName":"Show Outlook Loop components for supported apps (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_1","displayName":"Always show automatically.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_2","displayName":"Only show automatically within tenant.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v13~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_showoutlookloopcomponentsforsupportedapps_l_showoutlookloopcomponentsid_3","displayName":"Don’t show automatically.","description":null,"helpText":null}]},"769546c95d4e578d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions","displayName":"Configure form regions permissions (User)","description":"By default, all form region customizations are permitted to run in Outlook. By using this setting, you can disable all form region customizations, or specify that form regions must be registered on a per-computer basis, rather than a per-user basis.","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_1","displayName":"Enabled","description":null,"helpText":null}]},"761099d131882961":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody","displayName":"Change the limit for the number of MIME body parts (User)","description":"By default, the limit is 250 for the number of MIME body parts when an e-mail message is converted from MIME to MAPI. The number can be set to any positive integer. This helps prevent scenarios in which Outlook hangs while attempting conversion.","helpText":"","infoUrls":[],"categoryId":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","categoryName":"MIME to MAPI Conversion","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_mimitomapiconversion_l_changelimitmimebody_1","displayName":"Enabled","description":null,"helpText":null}]},"76c8ddb573cf21ba":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapiopenmessage_l_simplemapi_setting_0","displayName":"Automatically Deny","description":null,"helpText":null}]},"76b883f8d4935b7f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface","displayName":"Configure Outlook Anywhere user interface options (User)","description":"This policy setting allows you to determine whether users can view and change user interface (UI) options for Outlook Anywhere.\r\n\r\nIf you enable this policy setting, users can view and change UI options for Outlook Anywhere.\r\n\r\nIf you disable or do not configure this policy setting, users will be able to use the Outlook Anywhere feature, but they will not be able to view or change UI options for it.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enableexchangeoverinternetuserinterface_1","displayName":"Enabled","description":null,"helpText":null}]},"765f189c7fc9ab4e":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File tab | Share | Send Using E-mail (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},"769ea5841846a2fc":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},"7693c7b432bf8889":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17","displayName":"Fiscal year starts in (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_1","displayName":"January","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_2","displayName":"February","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_3","displayName":"March","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_4","displayName":"April","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_5","displayName":"May","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_6","displayName":"June","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_7","displayName":"July","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_8","displayName":"August","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_9","displayName":"September","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_10","displayName":"October","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_11","displayName":"November","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjfiscalyear_l_pjfiscalyear17_12","displayName":"December","description":null,"helpText":null}]},"7618dfbfef143232":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview","displayName":"Web tab | View | Web Page Preview (User)","description":"","helpText":"","infoUrls":[],"categoryId":"441d6cc4-e51f-453e-a44d-8394509415be","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filewebpagepreview_1","displayName":"True","description":null,"helpText":null}]},"767a4e5410800aa8":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings","displayName":"Show file save warnings (User)","description":"Indicates whether a warning message is displayed when you save files that contain errors such as invalid XML code.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_showfilesavewarnings_1","displayName":"Enabled","description":null,"helpText":null}]},"769b5e29dc665f0c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames","displayName":"Month names (User)","description":"Used for complex scripts. Specifies if month names shall be of calendar type Gregorian Arabic, Gregorian transliterated English, or Gregorian transliterated French.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_monthnames_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/86.json b/public/intune-definitions/86.json index f767fa368617..0fdfb7fb1d2a 100644 --- a/public/intune-definitions/86.json +++ b/public/intune-definitions/86.json @@ -1 +1 @@ -{"864ed8f35fa5bb00":{"id":"ade_setupassistant_unlockwithwatch","displayName":"Auto unlock with Apple Watch","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_unlockwithwatch_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_unlockwithwatch_1","displayName":"Show","description":null,"helpText":null}]},"869135b6dae3099d":{"id":"com.apple.dock_orientation","displayName":"Orientation","description":"The orientation of the dock. ","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_orientation_0","displayName":"Bottom","description":null,"helpText":null},{"id":"com.apple.dock_orientation_1","displayName":"Left","description":null,"helpText":null},{"id":"com.apple.dock_orientation_2","displayName":"Right","description":null,"helpText":null}]},"8692c442cb1adedf":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"86403cba8079515d":{"id":"com.apple.managedclient.preferences_defaultserialguardsetting","displayName":"Control use of the Serial API","description":"Set whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\n\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\n\nYou can override this policy for specific URL patterns by using the \"SerialAskForUrls\" and \"SerialBlockedForUrls\" policies.\n\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\n\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultserialguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultserialguardsetting_0","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultserialguardsetting_1","displayName":"Allow sites to ask for user permission to access a serial port","description":null,"helpText":null}]},"868dbc912f26d44e":{"id":"com.apple.managedclient.preferences_promotionaltabsenabled","displayName":"Enable full-tab promotional content (deprecated)","description":"Control the presentation of full-tab promotional or educational content. This setting controls the presentation of welcome pages that help users sign into Microsoft Edge, choose their default browser, or learn about product features.\n\nIf you enable this policy (set it true) or don't configure it, Microsoft Edge can show full-tab content to users to provide product information.\n\nIf you disable (set to false) this policy, Microsoft Edge can't show full-tab content to users.\n\nThis is deprecated - use ShowRecommendationsEnabled instead.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promotionaltabsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promotionaltabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promotionaltabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8632dcaf267e6499":{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled","displayName":"Enable QR Code Generator","description":"This policy enables the QR Code generator feature in Microsoft Edge.\n\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\n\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#qrcodegeneratorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"867fc6a57e55fa72":{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Enable support for Signed HTTP Exchange (SXG).\n\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\n\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#signedhttpexchangeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"862dd45be50ae0b1":{"id":"com.apple.security.firewall_applications","displayName":"Applications","description":"The list of apps with connections controlled by the firewall.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},"862e921fe320530c":{"id":"device_vendor_msft_defender_configuration_asronlyperruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"867fd056b8d7d8d8":{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection","displayName":"Allow Microsoft Account Connection","description":"Specifies whether the user is allowed to use an MSA account for non-email related connection authentication and services. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#AllowMicrosoftAccountConnection"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":[{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"8657647b6aa54776":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You cannot configure write permissions for this log.\r\n\r\nIf you enable this policy setting, only those users whose security descriptor matches the configured specified value can access the log.\r\n\r\nIf you disable this policy setting, only system software and administrators can read or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-6"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_1","displayName":"Enabled","description":null,"helpText":null}]},"866be4ebce0ad6cb":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6_1","displayName":"True","description":null,"helpText":null}]},"86c893fea6f0d5ef":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles","displayName":"Always use local ADM files for Group Policy Object Editor","description":"This policy setting lets you always use local ADM files for the Group Policy snap-in.\r\n\r\nBy default, when you edit a Group Policy Object (GPO) using the Group Policy Object Editor snap-in, the ADM files are loaded from that GPO into the Group Policy Object Editor snap-in. This allows you to use the same version of the ADM files that were used to create the GPO while editing this GPO.\r\n\r\nThis leads to the following behavior:\r\n\r\n- If you originally created the GPO with, for example, an English system, the GPO contains English ADM files.\r\n\r\n- If you later edit the GPO from a different-language system, you get the English ADM files as they were in the GPO.\r\n\r\nYou can change this behavior by using this setting.\r\n\r\nIf you enable this setting, the Group Policy Object Editor snap-in always uses local ADM files in your %windir%\\inf directory when editing GPOs.\r\n\r\nThis leads to the following behavior:\r\n\r\n- If you had originally created the GPO with an English system, and then you edit the GPO with a Japanese system, the Group Policy Object Editor snap-in uses the local Japanese ADM files, and you see the text in Japanese under Administrative Templates.\r\n\r\nIf you disable or do not configure this setting, the Group Policy Object Editor snap-in always loads all ADM files from the actual GPO.\r\n\r\nNote: If the ADMs that you require are not all available locally in your %windir%\\inf directory, you might not be able to see all the settings that have been configured in the GPO that you are editing.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-onlyuselocaladminfiles"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"863017f0d0eb1abb":{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_hosttorealm_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"86e1dddb865be85f":{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage","displayName":"Disable logging via package settings","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage_1","displayName":"Disable logging via package settings off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage_0","displayName":"Disable logging via package settings on","description":null,"helpText":null}]},"8681dd49e6c41c23":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"8608412fbefb5cd8":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_ntpclienteventlogflags","displayName":"EventLogFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},"863116b5a2f1a014":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type","displayName":"Rule Type","description":"Rule Type","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisher","displayName":"Publisher","description":"Creates a rule for a file that is signed by the software publisher. Upload the output generated by the binary file information extractor for your selected reference file.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filehash","displayName":"File Hash","description":"Creates a rule for a file based on its corresponding hash values. Upload a CSV file containing a list of hash values you want to include in this rule or directly type your hash values in the text area below.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filepath","displayName":"File Path","description":"Creates a rule for a specific file path or folder. Selecting folder will affect all files in a folder.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes","displayName":"File Attributes","description":"Creates a rule for a file based on one of its attributes. Select a file to use as reference for your rule.","helpText":null}]},"86dc35756f912165":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\r\n\r\nIf this policy is unset or disabled, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site, so if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\r\n\r\nIf the policy is enabled, HTTP auth credentials entered in the context of one site will automatically be used in the context of another.\r\n\r\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\r\n\r\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures, and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"869435cefc56c619":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended","displayName":"Print PDF as Image Default","description":"Controls if Google Chrome makes the Print as image option default to set when printing PDFs.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available.\r\n\r\nFor Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"86931c30e74daa25":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling","displayName":"The IP handling policy of WebRTC","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2). When unset, defaults to using all available interfaces.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_1","displayName":"Enabled","description":null,"helpText":null}]},"862addab74ccf51f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},"8604267234db704a":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent","displayName":"Block Office applications from creating executable content","description":"This rule prevents Office apps, including Word, Excel, and PowerPoint, from creating potentially malicious executable content, by blocking malicious code from being written to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent_warn","displayName":"Warn","description":null,"helpText":null}]},"8654c660c2d8de77":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription","displayName":"Block persistence through WMI event subscription","description":"This rule prevents malware from abusing WMI to attain persistence on a device. Fileless threats employ various tactics to stay hidden, to avoid being seen in the file system, and to gain periodic execution control. Some threats can abuse the WMI repository and event model to stay hidden.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription_warn","displayName":"Warn","description":null,"helpText":null}]},"861fdd9e6bdaba31":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforunregister_odfchealthyprovidersrequiredforunregister","displayName":"Healthy Providers Required For Unregister (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":null},"86f8357f1ec59d7d":{"id":"device_vendor_msft_policy_config_internetexplorer_newtabdefaultpage","displayName":"Specify default behavior for a new tab","description":"This policy setting allows you to specify what is displayed when the user opens a new tab.\n\nIf you enable this policy setting, you can choose which page to display when the user opens a new tab: blank page (about:blank), the first home page, the new tab page or the new tab page with my news feed.\n\nIf you disable or do not configure this policy setting, the user can select his or her preference for this behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-newtabdefaultpage"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_1","displayName":"Enabled","description":null,"helpText":null}]},"86a07d6a7aa56c58":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},"86b20d198c1b36d2":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder","displayName":"Configure the location of the browser executable folder","description":"This policy configures WebView2 applications to use the WebView2 Runtime in the specified path. The folder should contain the following files: msedgewebview2.exe, msedge.dll, and so on.\r\n\r\nTo set the value for the folder path, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications.\r\n\r\nExample value:\r\n\r\nName: *, Value: C:\\Program Files\\Microsoft Edge WebView2 Runtime Redistributable 85.0.541.0 x64","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_1","displayName":"Enabled","description":null,"helpText":null}]},"86d33bfa1cc42e45":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed","displayName":"Allow or block audio capture","description":"Allows you to set whether a user is prompted to grant a website access to their audio capture device. This policy applies to all URLs except for those configured in the 'AudioCaptureAllowedUrls' (Sites that can access audio capture devices without requesting permission) list.\r\n\r\nIf you enable this policy or don't configure it (the default setting), the user is prompted for audio capture access except from the URLs in the 'AudioCaptureAllowedUrls' list. These listed URLs are granted access without prompting.\r\n\r\nIf you disable this policy, the user is not prompted, and audio capture is accessible only to the URLs configured in 'AudioCaptureAllowedUrls'.\r\n\r\nThis policy affects all types of audio inputs, not only the built-in microphone.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"869b380897d6b8b6":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls_webhidallowdevicesforurls","displayName":"Allow listed sites connect to specific HID devices (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"86dc059e7fd80b08":{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled","displayName":"Enable exporting saved passwords from Password Manager","description":"This policy controls whether the Export Password button in edge://wallet/passwords is enabled.\r\n\r\nIf enabled or not configured, users can export saved passwords.\r\nIf disabled, the Export Password button is unavailable, preventing password exports.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86c94f361b4bdb1e":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_1","displayName":"Keep only automatic navigations in Internet Explorer mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_2","displayName":"Keep all in-page navigations in Internet Explorer mode","description":null,"helpText":null}]},"86f9776de076f1e9":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled","displayName":"Control the IntensiveWakeUpThrottling feature","description":"When enabled the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.\r\n\r\nThis is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. See https://bit.ly/30b1XR4 for more details.\r\n\r\nIf you enable this policy, the feature will be force enabled, and users will not be able to override this setting.\r\nIf you disable this policy, the feature will be force disabled, and users will not be able to override this setting.\r\nIf you don't configure this policy, the feature will be controlled by its own internal logic. Users can manually configure this setting.\r\n\r\nNote that the policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all the loaded tabs receive a consistent policy setting. It is harmless for processes to be running with different values of this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86cd5d090f9e5525":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\r\n\r\nRequired diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\r\n\r\nUp to version 121, this policy is not supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nFor version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection.\r\n\r\nUse one of the following settings to configure this policy:\r\n\r\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\r\n\r\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\r\n\r\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\r\n\r\nPolicy options mapping:\r\n\r\n* Off (0) = Off (Not recommended)\r\n\r\n* RequiredData (1) = Required data\r\n\r\n* OptionalData (2) = Optional data\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_1","displayName":"Enabled","description":null,"helpText":null}]},"865e5e0320981694":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\r\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\r\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\r\n\r\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\r\n\r\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"86e5158280833408":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_spdesignexe23","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_spdesignexe23_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_spdesignexe23_1","displayName":"True","description":null,"helpText":null}]},"86bccf141ed5566b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_onenoteexe138","displayName":"onent.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_onenoteexe138_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_onenoteexe138_1","displayName":"True","description":null,"helpText":null}]},"865f87389bf0e947":{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_checkbox_useroverride","displayName":"Allow users to turn \"accessibility\" syncing on.","description":"","helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},"86da7d8aed44a756":{"id":"device_vendor_msft_policy_config_userrights_createsymboliclinks","displayName":"Create Symbolic Links","description":"This user right determines if the user can create a symbolic link from the computer he is logged on to. Caution: This privilege should only be given to trusted users. Symbolic links can expose security vulnerabilities in applications that aren't designed to handle them. Note: This setting can be used in conjunction a symlink filesystem setting that can be manipulated with the command line utility to control the kinds of symlinks that are allowed on the machine. Type 'fsutil behavior set symlinkevaluation /?' at the command line to get more information about fsutil and symbolic links.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#createsymboliclinks"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"865eeecda76ae850":{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customkernelusersettingconfigurable","displayName":"Allow custom kernel configuration","description":"When set to disabled, this policy disables custom kernel configuration via .wslconfig (wsl2.kernel). This policy only applies to Store WSL.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customkernelusersettingconfigurable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customkernelusersettingconfigurable_1","displayName":"Enabled","description":null,"helpText":null}]},"86bb35409772779d":{"id":"device_vendor_msft_wifi_profile_{ssid}_wlanxml","displayName":"Wireless security type","description":"XML describing the network configuration and follows Windows WLAN_profile schema. Link to schema: http://msdn.microsoft.com/en-us/library/windows/desktop/ms707341(v=vs.85).aspx","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/wifi-csp"],"categoryId":"c4e48b1b-6d88-434f-a717-d5bab28eb245","categoryName":"Wi-Fi Connection","options":null},"8638a0d5135a4a72":{"id":"intelligencesettings_apps","displayName":"Apps","description":"If present, configures app-specific Intelligence features.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":null},"865ccbd5ce7c5f2c":{"id":"settings_item_wallpaper_image","displayName":"Image","description":"A Base64-encoded image in either PNG or JPG format to use for wallpaper.","helpText":null,"infoUrls":[],"categoryId":"ef7328b1-c666-40fe-a933-57b14bc77dd3","categoryName":"Wallpaper","options":null},"861946ce0e1e0dfb":{"id":"softwareupdate_notifications","displayName":"Notifications","description":"If 'true', the device shows all software update enforcement notifications. If 'false', the device only shows notifications triggered one hour before the enforcement deadline, and the restart countdown notification. Only applicable on Supervised devices with iOS 18+ and MacOS 15+","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":[{"id":"softwareupdate_notifications_false","displayName":"Disabled","description":null,"helpText":null},{"id":"softwareupdate_notifications_true","displayName":"Enabled","description":null,"helpText":null}]},"86cbf1333ad04da5":{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_agentuser","displayName":"Agent user account","description":"","helpText":"","infoUrls":[],"categoryId":"ea5fabb0-6eec-4c3e-8c6d-7523739207c3","categoryName":null,"options":[{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_agentuser_","displayName":"None","description":"No agent user identity specified","helpText":null},{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_agentuser_0","displayName":"Entra identity profile","description":"Use Entra identity profile to identify the agent user","helpText":null}]},"869a159b971bee91":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},"86b299c90e1dd9db":{"id":"user_vendor_msft_policy_config_admx_framepanes_nopreviewpane","displayName":"Turn on or off details pane (User)","description":"This policy setting shows or hides the Details Pane in File Explorer.\r\n\r\nIf you enable this policy setting and configure it to hide the pane, the Details Pane in File Explorer is hidden and cannot be turned on by the user.\r\n\r\nIf you enable this policy setting and configure it to show the pane, the Details Pane is always visible and cannot be hidden by the user. Note: This has a side effect of not being able to toggle to the Preview Pane since the two cannot be displayed at the same time.\r\n\r\nIf you disable, or do not configure this policy setting, the Details Pane is hidden by default and can be displayed by the user. This is the default policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-framepanes#admx-framepanes-nopreviewpane"],"categoryId":"4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","categoryName":"Explorer Frame Pane","options":[{"id":"user_vendor_msft_policy_config_admx_framepanes_nopreviewpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_framepanes_nopreviewpane_1","displayName":"Enabled","description":null,"helpText":null}]},"865667ade317a7c7":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_1","displayName":"Administrative Templates (Users) (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-admusers-1"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_1_1","displayName":"Enabled","description":null,"helpText":null}]},"86d64ce2498cdb5b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_2","displayName":"Administrative Templates (Users) (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-admusers-2"],"categoryId":"73935f55-c845-40ce-819e-838c0041f6fa","categoryName":"Resultant Set of Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_2_1","displayName":"Enabled","description":null,"helpText":null}]},"861c6cd8958aa930":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_listbox_modulenames","displayName":"Module Names (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},"86c8df53f670c66e":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013","displayName":"Microsoft Office 365 Common 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2013 applications.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings which are common between the Microsoft Office Suite 2013 applications will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings which are common between the Microsoft Office Suite 2013 applications from synchronization between computers with UE-V.\r\nIf you enable this policy setting, user settings which are common between the Microsoft Office Suite 2013 applications continue to synchronize with UE-V.\r\nIf you disable this policy setting, user settings which are common between the Microsoft Office Suite 2013 applications are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365common2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013_1","displayName":"Enabled","description":null,"helpText":null}]},"862d95190abe20ac":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_proxyport","displayName":"Proxy port (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"86d5fa9b0b2647cf":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended","displayName":"Enable network prediction (User)","description":"This policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages.\r\n\r\nIf you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"86c0f19dba42e7d1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl","displayName":"Default search provider icon (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderIconURL specifies the default search provider's favorite icon URL.\r\n\r\nLeaving DefaultSearchProviderIconURL unset means there's no icon for the search provider.\r\n\r\nExample value: https://search.my.company/favicon.ico","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_1","displayName":"Enabled","description":null,"helpText":null}]},"86959a633c4f2962":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},"8667b4380fa0dace":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowuserdatapersistence"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"86b5fffdba9a1731":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode (User)","description":"Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.\r\n\r\nSet to Strict (2) to enforce Strict Restricted Mode on YouTube.\r\n\r\nSet to Moderate (1) to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.\r\n\r\nSet to Off (0) or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.\r\n\r\n* 0 = Do not enforce Restricted Mode on YouTube\r\n\r\n* 1 = Enforce at least Moderate Restricted Mode on YouTube\r\n\r\n* 2 = Enforce Strict Restricted Mode for YouTube","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_1","displayName":"Enabled","description":null,"helpText":null}]},"868d246f9b803456":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist","displayName":"Allow specific extensions to be installed (User)","description":"By default, all extensions are allowed. However, if you block all extensions by setting the 'ExtensionInstallBlockList' policy to \"*,\" users can only install extensions defined in this policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"86b4c2152c87d0a6":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled","displayName":"Re-enable the Event.path API until Microsoft Edge version 115 (User)","description":"Starting in Microsoft Edge version 109, the non-standard API Event.path will be removed to improve web compatibility. This policy re-enables the API until version 115.\r\n\r\nIf you enable this policy, the Event.path API will be available.\r\n\r\nIf you disable this policy, the Event.path API will be unavailable.\r\n\r\nIf this policy is not set, the Event.path API will be in the following default states: available before version 109, and unavailable in version 109 to version 114.\r\n\r\nThis policy will be made obsolete after Microsoft Edge version 115.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86f2d6c21f58eb0d":{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override (User)","description":"This policy enables an override of the IPv6 reachability check. When overridden, the\r\nsystem will always query AAAA records when resolving host names. It applies to\r\nall users and interfaces on the device.\r\n\r\nIf you enable this policy, the IPv6 reachability check will be overridden.\r\n\r\nIf you disable or don't configure this policy, the IPv6 reachability check will not be overridden.\r\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86a5d7046da965ee":{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector_onbulkdataentryenterpriseconnector","displayName":"Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"86c656fa7e742692":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page (User)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\r\n\r\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\r\n\r\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\r\n\r\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\r\n\r\nIf you enable this policy, the Copilot new tab page is turned on.\r\n\r\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"86ed0ecebe21732b":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_1","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_3","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_4","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},"860517a1df867899":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"869f6743e2bff0d6":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"86cd23f946c43440":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverurl4","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"866014a7393dbe1c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext","displayName":"Default save prompt text (User)","description":"Sets the text displayed when the user saves a document in any format other than the default.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_1","displayName":"Enabled","description":null,"helpText":null}]},"86a778b903d4f085":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word","displayName":"Microsoft Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word_1","displayName":"True","description":null,"helpText":null}]},"8634167570bd39c0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_datecolon259","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"86249eadfd9a9151":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems","displayName":"Suppress external signature services menu item (User)","description":"This policy setting controls whether Outlook displays the \"Add Signature Services\" menu item. \r\n\r\nIf you enable this policy setting, Outlook does not display the \"Add Signature Services\" menu item on the Signature Line drop-down menu. \r\n\r\nIf you disable or do not configure this policy setting, users can select \"Add Signature Services\" (from the Signature Line drop-down menu on the Insert tab of the Ribbon in Excel, PowerPoint, and Word) to see a list of signature service providers on Office.com.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"86c2757c91de5464":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag3","displayName":"Tag 3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},"86b5905b92399ac7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66_1","displayName":"True","description":null,"helpText":null}]},"86c596758d982a8d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages","displayName":"Use this encoding for outgoing messages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28596","displayName":"Arabic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1256","displayName":"Arabic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28594","displayName":"Baltic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1257","displayName":"Baltic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28592","displayName":"Central European (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1250","displayName":"Central European (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_54936","displayName":"Chinese Simplified (GB18030)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_936","displayName":"Chinese Simplified (GB2312)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_52936","displayName":"Chinese Simplified (HZ)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_950","displayName":"Chinese Traditional (Big5)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28595","displayName":"Cyrillic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_20866","displayName":"Cyrillic (KOI8-R)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_21866","displayName":"Cyrillic (KOI8-U)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1251","displayName":"Cyrillic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28597","displayName":"Greek (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1253","displayName":"Greek (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_38598","displayName":"Hebrew (ISO-Logical)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1255","displayName":"Hebrew (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_51932","displayName":"Japanese (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50220","displayName":"Japanese (JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50221","displayName":"Japanese (JIS-Allow 1 byte Kana)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_932","displayName":"Japanese (Shift-JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_949","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_51949","displayName":"Korean (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28593","displayName":"Latin 3 (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28605","displayName":"Latin 9(ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_874","displayName":"Thai (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28599","displayName":"Turkish (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1254","displayName":"Turkish (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_65000","displayName":"Unicode (UTF-7)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_65001","displayName":"Unicode (UTF-8)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_20127","displayName":"US-ASCII","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50000","displayName":"User Defined","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1258","displayName":"Vietnamese (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28591","displayName":"Western European (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1252","displayName":"Western European (Windows)","description":null,"helpText":null}]},"86ba9df2d9329d02":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration","displayName":"Turn off Legacy Group Calendar migration (User)","description":"This policy setting controls the migration of legacy Group Calendar. \r\n\r\nIf you enable this policy setting, migration will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, migration will be turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration_1","displayName":"Enabled","description":null,"helpText":null}]},"86edda1aa1b573e8":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2_l_removedextensions","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},"868e873c21ca5fb9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade","displayName":"Do not create new OST file on upgrade (User)","description":"This policy setting controls whether Outlook creates a new OST file when you upgrade to Outlook 2016. The new OST file uses less space on the disk. When a new OST file is created, the contents from the previous version of Outlook are downloaded from the Exchange Server.\r\n\r\nIf you enable this policy setting, Outlook continues to use the existing OST file created by the installed earlier version of Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when you upgrade to Outlook 2016, a new OST file is created, and the contents from the installed earlier version of Outlook are downloaded from the Exchange server.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},"86ad7337093ccf28":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane","displayName":"Show Shape Search pane (User)","description":"Displays the shape search user interface elements of the stencil window.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane_1","displayName":"Enabled","description":null,"helpText":null}]},"863fa5891c3237e8":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},"864313ec909dc565":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"864ed8f35fa5bb00":{"id":"ade_setupassistant_unlockwithwatch","displayName":"Auto unlock with Apple Watch","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_unlockwithwatch_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_unlockwithwatch_1","displayName":"Show","description":null,"helpText":null}]},"869135b6dae3099d":{"id":"com.apple.dock_orientation","displayName":"Orientation","description":"The orientation of the dock. ","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_orientation_0","displayName":"Bottom","description":null,"helpText":null},{"id":"com.apple.dock_orientation_1","displayName":"Left","description":null,"helpText":null},{"id":"com.apple.dock_orientation_2","displayName":"Right","description":null,"helpText":null}]},"8692c442cb1adedf":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft onenote.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"86403cba8079515d":{"id":"com.apple.managedclient.preferences_defaultserialguardsetting","displayName":"Control use of the Serial API","description":"Set whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\n\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\n\nYou can override this policy for specific URL patterns by using the \"SerialAskForUrls\" and \"SerialBlockedForUrls\" policies.\n\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\n\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultserialguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultserialguardsetting_0","displayName":"Do not allow any site to request access to serial ports via the Serial API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultserialguardsetting_1","displayName":"Allow sites to ask for user permission to access a serial port","description":null,"helpText":null}]},"868dbc912f26d44e":{"id":"com.apple.managedclient.preferences_promotionaltabsenabled","displayName":"Enable full-tab promotional content (deprecated)","description":"Control the presentation of full-tab promotional or educational content. This setting controls the presentation of welcome pages that help users sign into Microsoft Edge, choose their default browser, or learn about product features.\n\nIf you enable this policy (set it true) or don't configure it, Microsoft Edge can show full-tab content to users to provide product information.\n\nIf you disable (set to false) this policy, Microsoft Edge can't show full-tab content to users.\n\nThis is deprecated - use ShowRecommendationsEnabled instead.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#promotionaltabsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_promotionaltabsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_promotionaltabsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8632dcaf267e6499":{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled","displayName":"Enable QR Code Generator","description":"This policy enables the QR Code generator feature in Microsoft Edge.\n\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\n\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#qrcodegeneratorenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_qrcodegeneratorenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"867fc6a57e55fa72":{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support","description":"Enable support for Signed HTTP Exchange (SXG).\n\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\n\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#signedhttpexchangeenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_signedhttpexchangeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"862dd45be50ae0b1":{"id":"com.apple.security.firewall_applications","displayName":"Applications","description":"The list of apps with connections controlled by the firewall.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},"862e921fe320530c":{"id":"device_vendor_msft_defender_configuration_asronlyperruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"867fd056b8d7d8d8":{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection","displayName":"Allow Microsoft Account Connection","description":"Specifies whether the user is allowed to use an MSA account for non-email related connection authentication and services. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Accounts#AllowMicrosoftAccountConnection"],"categoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","categoryName":"Accounts","options":[{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_accounts_allowmicrosoftaccountconnection_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"8657647b6aa54776":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You cannot configure write permissions for this log.\r\n\r\nIf you enable this policy setting, only those users whose security descriptor matches the configured specified value can access the log.\r\n\r\nIf you disable this policy setting, only system software and administrators can read or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-6"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_6_1","displayName":"Enabled","description":null,"helpText":null}]},"866be4ebce0ad6cb":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_ipsecurity_cse_nochanges6_1","displayName":"True","description":null,"helpText":null}]},"86c893fea6f0d5ef":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles","displayName":"Always use local ADM files for Group Policy Object Editor","description":"This policy setting lets you always use local ADM files for the Group Policy snap-in.\r\n\r\nBy default, when you edit a Group Policy Object (GPO) using the Group Policy Object Editor snap-in, the ADM files are loaded from that GPO into the Group Policy Object Editor snap-in. This allows you to use the same version of the ADM files that were used to create the GPO while editing this GPO.\r\n\r\nThis leads to the following behavior:\r\n\r\n- If you originally created the GPO with, for example, an English system, the GPO contains English ADM files.\r\n\r\n- If you later edit the GPO from a different-language system, you get the English ADM files as they were in the GPO.\r\n\r\nYou can change this behavior by using this setting.\r\n\r\nIf you enable this setting, the Group Policy Object Editor snap-in always uses local ADM files in your %windir%\\inf directory when editing GPOs.\r\n\r\nThis leads to the following behavior:\r\n\r\n- If you had originally created the GPO with an English system, and then you edit the GPO with a Japanese system, the Group Policy Object Editor snap-in uses the local Japanese ADM files, and you see the text in Japanese under Administrative Templates.\r\n\r\nIf you disable or do not configure this setting, the Group Policy Object Editor snap-in always loads all ADM files from the actual GPO.\r\n\r\nNote: If the ADMs that you require are not all available locally in your %windir%\\inf directory, you might not be able to see all the settings that have been configured in the GPO that you are editing.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-onlyuselocaladminfiles"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_onlyuselocaladminfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"863017f0d0eb1abb":{"id":"device_vendor_msft_policy_config_admx_kerberos_hosttorealm_hosttorealm_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"86e1dddb865be85f":{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage","displayName":"Disable logging via package settings","description":null,"helpText":"","infoUrls":[],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage_1","displayName":"Disable logging via package settings off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableloggingfrompackage_disableloggingfrompackage_0","displayName":"Disable logging via package settings on","description":null,"helpText":null}]},"8681dd49e6c41c23":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_slowlinksettings_lbl_slowlinksettingslist_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"8608412fbefb5cd8":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_ntpclienteventlogflags","displayName":"EventLogFlags","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},"863116b5a2f1a014":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type","displayName":"Rule Type","description":"Rule Type","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_publisher","displayName":"Publisher","description":"Creates a rule for a file that is signed by the software publisher. Upload the output generated by the binary file information extractor for your selected reference file.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filehash","displayName":"File Hash","description":"Creates a rule for a file based on its corresponding hash values. Upload a CSV file containing a list of hash values you want to include in this rule or directly type your hash values in the text area below.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filepath","displayName":"File Path","description":"Creates a rule for a specific file path or folder. Selecting folder will affect all files in a folder.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_fileattributes","displayName":"File Attributes","description":"Creates a rule for a file based on one of its attributes. Select a file to use as reference for your rule.","helpText":null}]},"86dc35756f912165":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\r\n\r\nIf this policy is unset or disabled, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site, so if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\r\n\r\nIf the policy is enabled, HTTP auth credentials entered in the context of one site will automatically be used in the context of another.\r\n\r\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\r\n\r\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures, and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_globallyscopehttpauthcacheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"869435cefc56c619":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended","displayName":"Print PDF as Image Default","description":"Controls if Google Chrome makes the Print as image option default to set when printing PDFs.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will default to setting the Print as image option in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome then the user selection for Print as image option will be initially unset. The user will be allowed to select it for each individual PDFs print job, if the option is available.\r\n\r\nFor Microsoft® Windows® or macOS this policy only has an effect if PrintPdfAsImageAvailability is also enabled.","helpText":"","infoUrls":[],"categoryId":"20ceae56-e189-46ec-a440-791ce7454017","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~printing_recommended_printpdfasimagedefault_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"86931c30e74daa25":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling","displayName":"The IP handling policy of WebRTC","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection. See RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2). When unset, defaults to using all available interfaces.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtciphandling_1","displayName":"Enabled","description":null,"helpText":null}]},"862addab74ccf51f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability","displayName":"Control Manifest v2 extension availability (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_0","displayName":"Default browser behavior","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_1","displayName":"Manifest v2 is disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_2","displayName":"Manifest v2 is enabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_extensionmanifestv2availability_extensionmanifestv2availability_3","displayName":"Manifest v2 is enabled for forced extensions only","description":null,"helpText":null}]},"8604267234db704a":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent","displayName":"Block Office applications from creating executable content","description":"This rule prevents Office apps, including Word, Excel, and PowerPoint, from creating potentially malicious executable content, by blocking malicious code from being written to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfromcreatingexecutablecontent_warn","displayName":"Warn","description":null,"helpText":null}]},"8654c660c2d8de77":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription","displayName":"Block persistence through WMI event subscription","description":"This rule prevents malware from abusing WMI to attain persistence on a device. Fileless threats employ various tactics to stay hidden, to avoid being seen in the file system, and to gain periodic execution control. Some threats can abuse the WMI repository and event model to stay hidden.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockpersistencethroughwmieventsubscription_warn","displayName":"Warn","description":null,"helpText":null}]},"861fdd9e6bdaba31":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforunregister_odfchealthyprovidersrequiredforunregister","displayName":"Healthy Providers Required For Unregister (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":null},"86f8357f1ec59d7d":{"id":"device_vendor_msft_policy_config_internetexplorer_newtabdefaultpage","displayName":"Specify default behavior for a new tab","description":"This policy setting allows you to specify what is displayed when the user opens a new tab.\n\nIf you enable this policy setting, you can choose which page to display when the user opens a new tab: blank page (about:blank), the first home page, the new tab page or the new tab page with my news feed.\n\nIf you disable or do not configure this policy setting, the user can select his or her preference for this behavior.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-newtabdefaultpage"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_newtabdefaultpage_1","displayName":"Enabled","description":null,"helpText":null}]},"86a07d6a7aa56c58":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206","displayName":"Internet Explorer web browser control","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_iz_partname1206_3","displayName":"Disable","description":null,"helpText":null}]},"86b20d198c1b36d2":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder","displayName":"Configure the location of the browser executable folder","description":"This policy configures WebView2 applications to use the WebView2 Runtime in the specified path. The folder should contain the following files: msedgewebview2.exe, msedge.dll, and so on.\r\n\r\nTo set the value for the folder path, provide a Value name and Value pair. Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications.\r\n\r\nExample value:\r\n\r\nName: *, Value: C:\\Program Files\\Microsoft Edge WebView2 Runtime Redistributable 85.0.541.0 x64","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_1","displayName":"Enabled","description":null,"helpText":null}]},"86d33bfa1cc42e45":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed","displayName":"Allow or block audio capture","description":"Allows you to set whether a user is prompted to grant a website access to their audio capture device. This policy applies to all URLs except for those configured in the 'AudioCaptureAllowedUrls' (Sites that can access audio capture devices without requesting permission) list.\r\n\r\nIf you enable this policy or don't configure it (the default setting), the user is prompted for audio capture access except from the URLs in the 'AudioCaptureAllowedUrls' list. These listed URLs are granted access without prompting.\r\n\r\nIf you disable this policy, the user is not prompted, and audio capture is accessible only to the URLs configured in 'AudioCaptureAllowedUrls'.\r\n\r\nThis policy affects all types of audio inputs, not only the built-in microphone.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"869b380897d6b8b6":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdevicesforurls_webhidallowdevicesforurls","displayName":"Allow listed sites connect to specific HID devices (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"86dc059e7fd80b08":{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled","displayName":"Enable exporting saved passwords from Password Manager","description":"This policy controls whether the Export Password button in edge://wallet/passwords is enabled.\r\n\r\nIf enabled or not configured, users can export saved passwords.\r\nIf disabled, the Export Password button is unavailable, preventing password exports.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev136~policy~microsoft_edge~passwordmanager_passwordexportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86c94f361b4bdb1e":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect","displayName":"Specify how \"in-page\" navigations to unconfigured sites behave when started from Internet Explorer mode pages (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_0","displayName":"Default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_1","displayName":"Keep only automatic navigations in Internet Explorer mode","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_internetexplorerintegrationsiteredirect_internetexplorerintegrationsiteredirect_2","displayName":"Keep all in-page navigations in Internet Explorer mode","description":null,"helpText":null}]},"86f9776de076f1e9":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled","displayName":"Control the IntensiveWakeUpThrottling feature","description":"When enabled the IntensiveWakeUpThrottling feature causes Javascript timers in background tabs to be aggressively throttled and coalesced, running no more than once per minute after a page has been backgrounded for 5 minutes or more.\r\n\r\nThis is a web standards compliant feature, but it may break functionality on some websites by causing certain actions to be delayed by up to a minute. However, it results in significant CPU and battery savings when enabled. See https://bit.ly/30b1XR4 for more details.\r\n\r\nIf you enable this policy, the feature will be force enabled, and users will not be able to override this setting.\r\nIf you disable this policy, the feature will be force disabled, and users will not be able to override this setting.\r\nIf you don't configure this policy, the feature will be controlled by its own internal logic. Users can manually configure this setting.\r\n\r\nNote that the policy is applied per renderer process, with the most recent value of the policy setting in force when a renderer process starts. A full restart is required to ensure that all the loaded tabs receive a consistent policy setting. It is harmless for processes to be running with different values of this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_intensivewakeupthrottlingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86cd5d090f9e5525":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\r\n\r\nRequired diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\r\n\r\nUp to version 121, this policy is not supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nFor version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection.\r\n\r\nUse one of the following settings to configure this policy:\r\n\r\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\r\n\r\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\r\n\r\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\r\n\r\nPolicy options mapping:\r\n\r\n* Off (0) = Off (Not recommended)\r\n\r\n* RequiredData (1) = Required data\r\n\r\n* OptionalData (2) = Optional data\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_1","displayName":"Enabled","description":null,"helpText":null}]},"865e5e0320981694":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\r\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\r\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\r\n\r\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\r\n\r\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"86e5158280833408":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_spdesignexe23","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_spdesignexe23_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_spdesignexe23_1","displayName":"True","description":null,"helpText":null}]},"86bccf141ed5566b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_onenoteexe138","displayName":"onent.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_onenoteexe138_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_onenoteexe138_1","displayName":"True","description":null,"helpText":null}]},"865f87389bf0e947":{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_checkbox_useroverride","displayName":"Allow users to turn \"accessibility\" syncing on.","description":"","helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},"86da7d8aed44a756":{"id":"device_vendor_msft_policy_config_userrights_createsymboliclinks","displayName":"Create Symbolic Links","description":"This user right determines if the user can create a symbolic link from the computer he is logged on to. Caution: This privilege should only be given to trusted users. Symbolic links can expose security vulnerabilities in applications that aren't designed to handle them. Note: This setting can be used in conjunction a symlink filesystem setting that can be manipulated with the command line utility to control the kinds of symlinks that are allowed on the machine. Type 'fsutil behavior set symlinkevaluation /?' at the command line to get more information about fsutil and symbolic links.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#createsymboliclinks"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"865eeecda76ae850":{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customkernelusersettingconfigurable","displayName":"Allow custom kernel configuration","description":"When set to disabled, this policy disables custom kernel configuration via .wslconfig (wsl2.kernel). This policy only applies to Store WSL.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customkernelusersettingconfigurable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv1~policy~wsl_customkernelusersettingconfigurable_1","displayName":"Enabled","description":null,"helpText":null}]},"86bb35409772779d":{"id":"device_vendor_msft_wifi_profile_{ssid}_wlanxml","displayName":"Wireless security type","description":"XML describing the network configuration and follows Windows WLAN_profile schema. Link to schema: http://msdn.microsoft.com/en-us/library/windows/desktop/ms707341(v=vs.85).aspx","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/wifi-csp"],"categoryId":"c4e48b1b-6d88-434f-a717-d5bab28eb245","categoryName":"Wi-Fi Connection","options":null},"86fc30d2f5e44a3a":{"id":"dnsproxy_dnsproxy","displayName":"com.apple.configuration.network.dns-proxy","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"4a6c4488-bbcf-4b5b-9156-7aa1b10a6010","categoryName":"DNS Proxy","options":null},"8638a0d5135a4a72":{"id":"intelligencesettings_apps","displayName":"Apps","description":"If present, configures app-specific Intelligence features.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":null},"865ccbd5ce7c5f2c":{"id":"settings_item_wallpaper_image","displayName":"Image","description":"A Base64-encoded image in either PNG or JPG format to use for wallpaper.","helpText":null,"infoUrls":[],"categoryId":"ef7328b1-c666-40fe-a933-57b14bc77dd3","categoryName":"Wallpaper","options":null},"861946ce0e1e0dfb":{"id":"softwareupdate_notifications","displayName":"Notifications","description":"If 'true', the device shows all software update enforcement notifications. If 'false', the device only shows notifications triggered one hour before the enforcement deadline, and the restart countdown notification. Only applicable on Supervised devices with iOS 18+ and MacOS 15+","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":[{"id":"softwareupdate_notifications_false","displayName":"Disabled","description":null,"helpText":null},{"id":"softwareupdate_notifications_true","displayName":"Enabled","description":null,"helpText":null}]},"86cbf1333ad04da5":{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_agentuser","displayName":"Agent user account","description":"","helpText":"","infoUrls":[],"categoryId":"ea5fabb0-6eec-4c3e-8c6d-7523739207c3","categoryName":null,"options":[{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_agentuser_","displayName":"None","description":"No agent user identity specified","helpText":null},{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_agentuser_0","displayName":"Entra identity profile","description":"Use Entra identity profile to identify the agent user","helpText":null}]},"869a159b971bee91":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10","displayName":"Trusted Location #10 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_1","displayName":"Enabled","description":null,"helpText":null}]},"86b299c90e1dd9db":{"id":"user_vendor_msft_policy_config_admx_framepanes_nopreviewpane","displayName":"Turn on or off details pane (User)","description":"This policy setting shows or hides the Details Pane in File Explorer.\r\n\r\nIf you enable this policy setting and configure it to hide the pane, the Details Pane in File Explorer is hidden and cannot be turned on by the user.\r\n\r\nIf you enable this policy setting and configure it to show the pane, the Details Pane is always visible and cannot be hidden by the user. Note: This has a side effect of not being able to toggle to the Preview Pane since the two cannot be displayed at the same time.\r\n\r\nIf you disable, or do not configure this policy setting, the Details Pane is hidden by default and can be displayed by the user. This is the default policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-framepanes#admx-framepanes-nopreviewpane"],"categoryId":"4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","categoryName":"Explorer Frame Pane","options":[{"id":"user_vendor_msft_policy_config_admx_framepanes_nopreviewpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_framepanes_nopreviewpane_1","displayName":"Enabled","description":null,"helpText":null}]},"865667ade317a7c7":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_1","displayName":"Administrative Templates (Users) (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-admusers-1"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_1_1","displayName":"Enabled","description":null,"helpText":null}]},"86d64ce2498cdb5b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_2","displayName":"Administrative Templates (Users) (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-admusers-2"],"categoryId":"73935f55-c845-40ce-819e-838c0041f6fa","categoryName":"Resultant Set of Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admusers_2_1","displayName":"Enabled","description":null,"helpText":null}]},"861c6cd8958aa930":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_listbox_modulenames","displayName":"Module Names (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":null},"86c8df53f670c66e":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013","displayName":"Microsoft Office 365 Common 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2013 applications.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings which are common between the Microsoft Office Suite 2013 applications will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings which are common between the Microsoft Office Suite 2013 applications from synchronization between computers with UE-V.\r\nIf you enable this policy setting, user settings which are common between the Microsoft Office Suite 2013 applications continue to synchronize with UE-V.\r\nIf you disable this policy setting, user settings which are common between the Microsoft Office Suite 2013 applications are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365common2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365common2013_1","displayName":"Enabled","description":null,"helpText":null}]},"862d95190abe20ac":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_proxyport","displayName":"Proxy port (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":null},"86d5fa9b0b2647cf":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended","displayName":"Enable network prediction (User)","description":"This policy controls network prediction in Google Chrome. It controls DNS prefetching, TCP, and SSL preconnection and prerendering of webpages.\r\n\r\nIf you set the policy, users can't change it. Leaving it unset turns on network prediction, but the user can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_networkpredictionoptions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"86c0f19dba42e7d1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl","displayName":"Default search provider icon (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderIconURL specifies the default search provider's favorite icon URL.\r\n\r\nLeaving DefaultSearchProviderIconURL unset means there's no icon for the search provider.\r\n\r\nExample value: https://search.my.company/favicon.ico","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_1","displayName":"Enabled","description":null,"helpText":null}]},"86959a633c4f2962":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},"8667b4380fa0dace":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowuserdatapersistence"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"8681d520973ace84":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled","displayName":"Enable service-based extraction for Reading Mode in Microsoft Edge (User)","description":"This policy controls whether Microsoft Edge can use the Microsoft online extraction service to improve Reading Mode rendering.\n\nIf you enable or don't configure this policy, Microsoft Edge can send the text of the page being read to the service for processing.\n\nIf you disable this policy, Microsoft Edge doesn't send the text of the page being read to the service. Reading Mode remains available, but extraction quality may be limited.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_edgereadingmodeservicebasedextractionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86b5fffdba9a1731":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict","displayName":"Force minimum YouTube Restricted Mode (User)","description":"Enforces a minimum Restricted Mode on YouTube and prevents users from picking a less restricted mode.\r\n\r\nSet to Strict (2) to enforce Strict Restricted Mode on YouTube.\r\n\r\nSet to Moderate (1) to enforce the user to only use Moderate Restricted Mode and Strict Restricted Mode on YouTube. They can't disable Restricted Mode.\r\n\r\nSet to Off (0) or don't configure this policy to not enforce Restricted Mode on YouTube. External policies such as YouTube policies might still enforce Restricted Mode.\r\n\r\n* 0 = Do not enforce Restricted Mode on YouTube\r\n\r\n* 1 = Enforce at least Moderate Restricted Mode on YouTube\r\n\r\n* 2 = Enforce Strict Restricted Mode for YouTube","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceyoutuberestrict_1","displayName":"Enabled","description":null,"helpText":null}]},"868d246f9b803456":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist","displayName":"Allow specific extensions to be installed (User)","description":"By default, all extensions are allowed. However, if you block all extensions by setting the 'ExtensionInstallBlockList' policy to \"*,\" users can only install extensions defined in this policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"86b4c2152c87d0a6":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled","displayName":"Re-enable the Event.path API until Microsoft Edge version 115 (User)","description":"Starting in Microsoft Edge version 109, the non-standard API Event.path will be removed to improve web compatibility. This policy re-enables the API until version 115.\r\n\r\nIf you enable this policy, the Event.path API will be available.\r\n\r\nIf you disable this policy, the Event.path API will be unavailable.\r\n\r\nIf this policy is not set, the Event.path API will be in the following default states: available before version 109, and unavailable in version 109 to version 114.\r\n\r\nThis policy will be made obsolete after Microsoft Edge version 115.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_eventpathenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86f2d6c21f58eb0d":{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override (User)","description":"This policy enables an override of the IPv6 reachability check. When overridden, the\r\nsystem will always query AAAA records when resolving host names. It applies to\r\nall users and interfaces on the device.\r\n\r\nIf you enable this policy, the IPv6 reachability check will be overridden.\r\n\r\nIf you disable or don't configure this policy, the IPv6 reachability check will not be overridden.\r\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"86a5d7046da965ee":{"id":"user_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onbulkdataentryenterpriseconnector_onbulkdataentryenterpriseconnector","displayName":"Configuration policy for bulk data entry for Microsoft Edge for Business Data Loss Prevention Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"86c656fa7e742692":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page (User)","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\r\n\r\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\r\n\r\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\r\n\r\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\r\n\r\nIf you enable this policy, the Copilot new tab page is turned on.\r\n\r\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"86ed0ecebe21732b":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_1","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_3","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_configurefriendlyurlformat_configurefriendlyurlformat_4","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},"860517a1df867899":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"869f6743e2bff0d6":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"86cd23f946c43440":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverurl4","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"866014a7393dbe1c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext","displayName":"Default save prompt text (User)","description":"Sets the text displayed when the user saves a document in any format other than the default.","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_1","displayName":"Enabled","description":null,"helpText":null}]},"86a778b903d4f085":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word","displayName":"Microsoft Word (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_l_word_1","displayName":"True","description":null,"helpText":null}]},"8634167570bd39c0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc06_l_datecolon259","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"86249eadfd9a9151":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems","displayName":"Suppress external signature services menu item (User)","description":"This policy setting controls whether Outlook displays the \"Add Signature Services\" menu item. \r\n\r\nIf you enable this policy setting, Outlook does not display the \"Add Signature Services\" menu item on the Signature Line drop-down menu. \r\n\r\nIf you disable or do not configure this policy setting, users can select \"Add Signature Services\" (from the Signature Line drop-down menu on the Insert tab of the Ribbon in Excel, PowerPoint, and Word) to see a list of signature service providers on Office.com.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_supressexternalsigningservicesmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"86c2757c91de5464":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag3","displayName":"Tag 3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},"86b5905b92399ac7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_l_showassociatedwebpage66_1","displayName":"True","description":null,"helpText":null}]},"86c596758d982a8d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages","displayName":"Use this encoding for outgoing messages: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","categoryName":"International Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28596","displayName":"Arabic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1256","displayName":"Arabic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28594","displayName":"Baltic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1257","displayName":"Baltic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28592","displayName":"Central European (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1250","displayName":"Central European (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_54936","displayName":"Chinese Simplified (GB18030)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_936","displayName":"Chinese Simplified (GB2312)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_52936","displayName":"Chinese Simplified (HZ)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_950","displayName":"Chinese Traditional (Big5)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28595","displayName":"Cyrillic (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_20866","displayName":"Cyrillic (KOI8-R)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_21866","displayName":"Cyrillic (KOI8-U)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1251","displayName":"Cyrillic (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28597","displayName":"Greek (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1253","displayName":"Greek (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_38598","displayName":"Hebrew (ISO-Logical)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1255","displayName":"Hebrew (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_51932","displayName":"Japanese (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50220","displayName":"Japanese (JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50221","displayName":"Japanese (JIS-Allow 1 byte Kana)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_932","displayName":"Japanese (Shift-JIS)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_949","displayName":"Korean","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_51949","displayName":"Korean (EUC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28593","displayName":"Latin 3 (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28605","displayName":"Latin 9(ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_874","displayName":"Thai (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28599","displayName":"Turkish (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1254","displayName":"Turkish (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_65000","displayName":"Unicode (UTF-7)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_65001","displayName":"Unicode (UTF-8)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_20127","displayName":"US-ASCII","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_50000","displayName":"User Defined","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1258","displayName":"Vietnamese (Windows)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_28591","displayName":"Western European (ISO)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internationaloptions_l_encodingforoutgoingmessages_l_usethisencodingforoutgoingmessages_1252","displayName":"Western European (Windows)","description":null,"helpText":null}]},"86ba9df2d9329d02":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration","displayName":"Turn off Legacy Group Calendar migration (User)","description":"This policy setting controls the migration of legacy Group Calendar. \r\n\r\nIf you enable this policy setting, migration will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, migration will be turned on.","helpText":"","infoUrls":[],"categoryId":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","categoryName":"Schedule View","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_scheduleview_l_turnofflegacygroupcalendarmigration_1","displayName":"Enabled","description":null,"helpText":null}]},"86edda1aa1b573e8":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_v2_l_removedextensions","displayName":"Removed Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":null},"868e873c21ca5fb9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade","displayName":"Do not create new OST file on upgrade (User)","description":"This policy setting controls whether Outlook creates a new OST file when you upgrade to Outlook 2016. The new OST file uses less space on the disk. When a new OST file is created, the contents from the previous version of Outlook are downloaded from the Exchange Server.\r\n\r\nIf you enable this policy setting, Outlook continues to use the existing OST file created by the installed earlier version of Outlook. \r\n\r\nIf you disable or do not configure this policy setting, when you upgrade to Outlook 2016, a new OST file is created, and the contents from the installed earlier version of Outlook are downloaded from the Exchange server.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_donotcreatenewostonupgrade_1","displayName":"Enabled","description":null,"helpText":null}]},"86ad7337093ccf28":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane","displayName":"Show Shape Search pane (User)","description":"Displays the shape search user interface elements of the stencil window.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_showshapesearchpane_1","displayName":"Enabled","description":null,"helpText":null}]},"863fa5891c3237e8":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},"864313ec909dc565":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/88.json b/public/intune-definitions/88.json index ad1343cb6095..b193528cb2d2 100644 --- a/public/intune-definitions/88.json +++ b/public/intune-definitions/88.json @@ -1 +1 @@ -{"88acef79b745d05f":{"id":"ade_accountsettings_adminaccountname","displayName":"Admin account username","description":"The account name for the administrator account. This field is to be defaulted to 'Admin'. For macOS ADE enrollment policies without user device affinity, we recommend configuring {{serialNumber}} as the unique identifier of userless devices.","helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},"88528fd5c25c604c":{"id":"com.android.devicerestrictionpolicy.passwordminimumsymbolcharacters","displayName":"Number of symbol characters required","description":"Enter the number of symbol characters (&, #, %, and so on) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"887e8b0824e435a5":{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly","displayName":"Peer Local Subnets Only","description":"If true, the content cache only peers with other content caches on the same immediate local network, rather than with content caches that use the same public IP address as the device. When Peer Local Subnets Only is true, it overrides the configuration of Peer Filter Ranges and Peer Listen Ranges. If the network changes, the local network peering restrictions update appropriately. If false, the content cache defers to Peer Filter Ranges and Peer Listen Ranges for configuring the peering restrictions.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly_true","displayName":"True","description":null,"helpText":null}]},"88b1e48510cc5b93":{"id":"com.apple.cellularprivatenetwork.managed_datasetname","displayName":"Data Set Name","description":"The name of the private network configuration data set.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"88f43b82c36116c3":{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\n\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge does not send authentications requests to these services and users will need to manually sign-in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proactiveauthworkflowenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"889653a2a1335c75":{"id":"com.apple.managedclient.preferences_urlallowlist","displayName":"Define a list of allowed URLs","description":"Allow access to the listed URLs, as exceptions to the URL block list.\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can use this policy to open exceptions to restrictive block lists. For example, you can include '*' in the block list to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\n\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the block list.\n\nThis policy is limited to 1000 entries; subsequent entries are ignored.\n\nIf you don't configure this policy, there are no exceptions to the block list in the \"URLBlocklist\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#urlallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"887d9ebee0d7153d":{"id":"com.apple.mcx.filevault2_outputpath","displayName":"Output Path","description":"The path to the location where the recovery key and computer information property list are stored.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},"88a7957fc5cc4f7c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft","description":"Lets screen reader users get descriptions of unlabeled images on the web.\n\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\n\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\n\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\n\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"88997f2658c035cf":{"id":"com.microsoft.edge.mamedgeappconfigsettings.imagesallowedforurls","displayName":"Allow images on these sites","description":"Define a list of sites, based on URL patterns, that can display images.\n\nIf you don't configure this policy, the global default value is used for all sites either from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"881f49124711326e":{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn_1","displayName":"True","description":null,"helpText":null}]},"88bc068e46fb2255":{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver","displayName":"Define KDC proxy servers settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"8804f6c1a5eea25f":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain","displayName":"Allow operation while in domain","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain_1","displayName":"True","description":null,"helpText":null}]},"88472e6b40f6158e":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy","displayName":"Server authentication certificate template","description":"This policy setting allows you to specify the name of the certificate template that determines which certificate is automatically selected to authenticate an RD Session Host server.\r\n\r\nA certificate is needed to authenticate an RD Session Host server when TLS 1.0, 1.1 or 1.2 is used to secure communication between a client and an RD Session Host server during RDP connections.\r\n\r\nIf you enable this policy setting, you need to specify a certificate template name. Only certificates created by using the specified certificate template will be considered when a certificate to authenticate the RD Session Host server is automatically selected. Automatic certificate selection only occurs when a specific certificate has not been selected.\r\n\r\nIf no certificate can be found that was created with the specified certificate template, the RD Session Host server will issue a certificate enrollment request and will use the current certificate until the request is completed. If more than one certificate is found that was created with the specified certificate template, the certificate that will expire latest and that matches the current name of the RD Session Host server will be selected.\r\n\r\nIf you disable or do not configure this policy, the certificate template name is not specified at the Group Policy level. By default, a self-signed certificate is used to authenticate the RD Session Host server. \r\n\r\nNote: If you select a specific certificate to be used to authenticate the RD Session Host server, that certificate will take precedence over this policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-certificate-template-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_1","displayName":"Enabled","description":null,"helpText":null}]},"880a25f81eba62a1":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainloggingrate","displayName":"ChainLoggingRate","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"88b00e48666c2399":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_minpollinterval","displayName":"MinPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"88551c0e456ce96f":{"id":"device_vendor_msft_policy_config_applicationcontrol_policies_{policyguid}_xml","displayName":"App Control for Business policy","description":"The format of the XML property list varies depending on the settings you are configuring for the ApplicationControl CSP. Microsoft Endpoint Manager will validate the XML format; but not validate the settings behaviour, the settings applicability nor sign the policy binary. ApplicationControl CSP supports base and supplemental policies for devices running the Windows 1903 build and later. Supplemental policies are required to loosen a base policy; and are always less restrictive. A supplemental policy needs to support a specific base policy that has been deployed to the same client. If not, there is no effect on assigned Windows devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":null},"88b9dc0dc0d7d1aa":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch","displayName":"Snipping Tool (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch_1","displayName":"True","description":null,"helpText":null}]},"88a286f4a7802943":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\r\n\r\nDisabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitBlockedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT disabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise JavaScript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"888503d03def2cf5":{"id":"device_vendor_msft_policy_config_defender_allowfullscanremovabledrivescanning","displayName":"Allow Full Scan Removable Drive Scanning","description":"Allows or disallows a full scan of removable drives. During a quick scan, removable drives may still be scanned.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_allowfullscanremovabledrivescanning_0","displayName":"Not allowed. Turns off scanning on removable drives.","description":"Not allowed. Turns off scanning on removable drives.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_allowfullscanremovabledrivescanning_1","displayName":"Allowed. Scans removable drives.","description":"Allowed. Scans removable drives.","helpText":null}]},"88cb5c69f67f9bf8":{"id":"device_vendor_msft_policy_config_devicelock_preventlockscreenslideshow","displayName":"Prevent enabling lock screen slide show","description":"Disables the lock screen slide show settings in PC Settings and prevents a slide show from playing on the lock screen.\n\nBy default, users can enable a slide show that will run after they lock the machine.\n\nIf you enable this setting, users will no longer be able to modify slide show settings in PC Settings, and no slide show will ever start.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-devicelock#devicelock-preventlockscreenslideshow"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_devicelock_preventlockscreenslideshow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_devicelock_preventlockscreenslideshow_1","displayName":"Enabled","description":null,"helpText":null}]},"88cee726488ae712":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowsmartscreenie"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"88afc0b9a3553615":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"8863e5ae5e87446d":{"id":"device_vendor_msft_policy_config_kerberos_setmaximumcontexttokensize","displayName":"Set maximum Kerberos SSPI context token buffer size","description":"This policy setting allows you to set the value returned to applications which request the maximum size of the SSPI context token buffer size.\r\n \r\nThe size of the context token buffer determines the maximum size of SSPI context tokens an application expects and allocates. Depending upon authentication request processing and group memberships, the buffer might be smaller than the actual size of the SSPI context token. \r\n\r\nIf you enable this policy setting, the Kerberos client or server uses the configured value, or the locally allowed maximum value, whichever is smaller.\r\n\r\nIf you disable or do not configure this policy setting, the Kerberos client or server uses the locally configured value or the default value. \r\n\r\nNote: This policy setting configures the existing MaxTokenSize registry value in HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Kerberos\\Parameters, which was added in Windows XP and Windows Server 2003, with a default value of 12,000 bytes. Beginning with Windows 8 the default is 48,000 bytes. Due to HTTP's base64 encoding of authentication context tokens, it is not advised to set this value more than 48,000 bytes.\r\n\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-kerberos#kerberos-setmaximumcontexttokensize"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_kerberos_setmaximumcontexttokensize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_setmaximumcontexttokensize_1","displayName":"Enabled","description":null,"helpText":null}]},"88b7e9fd2f17b43e":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_messagetextforusersattemptingtologon","displayName":"Interactive Logon Message Text For Users Attempting To Log On","description":"Interactive logon: Message text for users attempting to log on This security setting specifies a text message that is displayed to users when they log on. This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited. Default: No message.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_messagetextforusersattemptingtologon"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"88b78436698d35c3":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowlocalsystemtousecomputeridentityforntlm","displayName":"Network Security Allow Local System To Use Computer Identity For NTLM","description":"Network security: Allow Local System to use computer identity for NTLM This policy setting allows Local System services that use Negotiate to use the computer identity when reverting to NTLM authentication. If you enable this policy setting, services running as Local System that use Negotiate will use the computer identity. This might cause some authentication requests between Windows operating systems to fail and log an error. If you disable this policy setting, services running as Local System that use Negotiate when reverting to NTLM authentication will authenticate anonymously. By default, this policy is enabled on Windows 7 and above. By default, this policy is disabled on Windows Vista. This policy is supported on at least Windows Vista or Windows Server 2008. Note: Windows Vista or Windows Server 2008 do not expose this setting in Group Policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_allowlocalsystemtousecomputeridentityforntlm"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowlocalsystemtousecomputeridentityforntlm_1","displayName":"Allow","description":"Allow","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowlocalsystemtousecomputeridentityforntlm_0","displayName":"Block","description":"Block","helpText":null}]},"8851c71fb94a53e8":{"id":"device_vendor_msft_policy_config_mixedreality_automaticdisplayadjustment","displayName":"Automatic Display Adjustment","description":"This policy controls if the HoloLens displays will be automatically adjusted for your eyes to improve hologram visual quality when an user wears the device. When this feature is enabled, a new user upon wearing the device will not be prompted to calibrate and yet the displays will be adjusted to suite them automatically. However if an immersive application is launched that depends on eye tracking interactions, the user will be prompted to perform the calibration.","helpText":"","infoUrls":[],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_automaticdisplayadjustment_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_automaticdisplayadjustment_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"88c4b9e8f155b516":{"id":"device_vendor_msft_policy_config_onedrivengscv4~policy~onedrivengsc_enableodignorelistfromgpo_enableodignorelistfromgpolistbox","displayName":"Keywords: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"8871b0eaaaf72210":{"id":"device_vendor_msft_policy_config_printers_configureredirectionguardpolicy","displayName":"Configure Redirection Guard","description":"\nDetermines whether Redirection Guard is enabled for the print spooler.\n\nYou can enable this setting to configure the Redirection Guard policy being applied to spooler.\n\nIf you disable or do not configure this policy setting, Redirection Guard will default to being 'Enabled'.\n\nIf you enable this setting you may select the following options:\n\n-- Enabled : Redirection Guard will prevent any file redirections from being followed\n\n-- Disabed : Redirection Guard will not be enabled and file redirections may be used within the spooler process\n\n-- Audit : Redirection Guard will log events as though it were enabled but will not actually prevent file redirections from being used within the spooler.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-configureredirectionguardpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configureredirectionguardpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configureredirectionguardpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"88f5d9ac0b987108":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices","displayName":"Let Apps Access Trusted Devices","description":"This policy setting specifies whether Windows apps can access trusted devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstrusteddevices"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"888c33382b323012":{"id":"device_vendor_msft_policy_config_updatev95~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetchannelmicrosoftedge","displayName":"Target Channel override","description":"Specifies which Channel Microsoft Edge should be updated to.\r\n\r\nIf you enable this poicy, the Microsoft Edge will be updated to the Channel according to how you configure the following options:\r\n\r\n - Stable: Microsoft Edge will be updated to the latest stable version.\r\n - Beta: Microsoft Edge will be updated to the latest beta version.\r\n - Dev: Microsoft Edge will be updated to the latest dev version.\r\n - Extended Stable: Microsoft Edge will be updated to the latest extended stable version, which follows a longer release cadence than stable. For more information, visit https://go.microsoft.com/fwlink/?linkid=2163508.\r\n\r\nIf you do not configure this policy, Microsoft Edge will be updated to the latest version available for the default Channel.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev95~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetchannelmicrosoftedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev95~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetchannelmicrosoftedge_1","displayName":"Enabled","description":null,"helpText":null}]},"8899c9e966ef9485":{"id":"user_vendor_msft_pde_protectfolders_protectpictures","displayName":"Protect Pictures (User)","description":"Allows the Admin to enable Personal Data Encryption on Pictures folder. Set to '1' to set this policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/personaldataencryption-csp/"],"categoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","categoryName":"Personal Data Encryption","options":[{"id":"user_vendor_msft_pde_protectfolders_protectpictures_0","displayName":"Disable Personal Data Encryption on the folder. If the folder is currently protected by Personal Data Encryption, this will result in unprotecting the folder.","description":"Disable Personal Data Encryption on the folder. If the folder is currently protected by Personal Data Encryption, this will result in unprotecting the folder.","helpText":null},{"id":"user_vendor_msft_pde_protectfolders_protectpictures_1","displayName":"Enable Personal Data Encryption on the folder.","description":"Enable Personal Data Encryption on the folder.","helpText":null}]},"8857b68c9e2b1eaa":{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffhistorybasedpredictiveinput","displayName":"Turn off history-based predictive input (User)","description":"This policy setting allows you to turn off history-based predictive input.\r\n\r\nIf you enable this policy setting, history-based predictive input is turned off.\r\n\r\nIf you disable or do not configure this policy setting, history-based predictive input is on by default.\r\n\r\nThis policy setting applies to Japanese Microsoft IME only.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eaime#admx-eaime-l-turnoffhistorybasedpredictiveinput"],"categoryId":"7d331987-7e2d-4975-b23b-d99a5af26ddf","categoryName":"IME","options":[{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffhistorybasedpredictiveinput_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffhistorybasedpredictiveinput_1","displayName":"Enabled","description":null,"helpText":null}]},"8880df1bf374145b":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013","displayName":"Microsoft Office 365 Lync 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_1","displayName":"Enabled","description":null,"helpText":null}]},"8877f82f901833c7":{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailyendminute_quiethoursdailyendminutecontrol","displayName":"Minutes after midnight: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":null},"8868ded198cff442":{"id":"user_vendor_msft_policy_config_browser_preventlivetiledatacollection","displayName":"Prevent Live Tile Data Collection (User)","description":"This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu. Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventlivetiledatacollection"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_preventlivetiledatacollection_0","displayName":"Disabled","description":"Collect and send Live Tile metadata.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_preventlivetiledatacollection_1","displayName":"Enabled","description":"No data collected.","helpText":null}]},"88e56279f215d8d4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist_policylistmultiplesourcemergelistdesc","displayName":"Allow merging list policies from different sources (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"88e65713a0eee8bc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist","displayName":"Configure extension installation allow list (User)","description":"Setting the policy specifies which extensions are not subject to the blocklist.\r\n\r\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\r\n\r\nBy default, all extensions are allowed. But, if you prohibited extensions by policy, use the list of allowed extensions to change that policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"88c633bdcbfd74a1":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties","displayName":"Prompt for workbook properties (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"88fa1a44650ecf98":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles","displayName":"Excel 2 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"88547194c9ae5ea5":{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},"88aafdf50759e2e7":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"8890c64f8ede1570":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709","displayName":"Enable dragging of content from different domains across windows (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_3","displayName":"Disable","description":null,"helpText":null}]},"888f464c345793f5":{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox (User)","description":"Setting this policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services when the system configuration supports it.\r\n\r\nSetting this policy to Disabled has a detrimental effect on Microsoft Edge's security because services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn this policy off if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"88e4f1a679096573":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended","displayName":"Discover feature In Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.\r\n\r\nThis policy lets you configure the Discover feature in Microsoft Edge.\r\n\r\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\r\n\r\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"880ae666ae7eaca6":{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_enhancesecuritymodebypasslistdomainsdesc","displayName":"Configure the list of domains for which enhance security mode will not be enforced (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"883538985a53bbde":{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum","displayName":"Configure Get Diagnostics: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e86f24d3-8531-4298-b064-692ea795b1d9","categoryName":"Diagnostics","options":[{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_1","displayName":"Upload diagnostic logs to Microsoft","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_2","displayName":"Capture diagnostic logs in a local archive, dont upload logs to Microsoft","description":null,"helpText":null}]},"882c28f343865460":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceminorversion2","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"88d09760f8dd59a7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd_l_homeaddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"88a11788e51b8e1c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations","displayName":"Disable built-in color variations (User)","description":"Specify whether or not to show the built-in color variations.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations_1","displayName":"Enabled","description":null,"helpText":null}]},"88d0850637170d14":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia","displayName":"Odia (User)","description":"Enables the editing language Odia","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia_1","displayName":"Enabled","description":null,"helpText":null}]},"88568d96cac4d2fc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink_l_changedestinationurlforsharepointhyperlinkid","displayName":"Destination URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"88291f2b81a82553":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13","displayName":"Workflow Cache 13 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_1","displayName":"Enabled","description":null,"helpText":null}]},"88bd30c1b5b63358":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection","displayName":"Allow Microsoft to follow up on feedback submitted by users (User)","description":"This policy setting controls whether Microsoft can follow up on feedback submitted by users to help understand the feedback, troubleshoot an issue submitted through feedback, or share back how Microsoft used the feedback to improve the product.\r\n\r\nMicrosoft may send transactional emails or request follow-up conversations via email, voice, or other means related to the feedback or survey response. In some circumstances, Microsoft may ask for additional information to assist with troubleshooting.\r\n\r\nIf you enable this policy setting, Microsoft may follow up on feedback submitted. \r\n\r\nIf you disable or don’t configure this policy setting, Microsoft will not follow up on feedback submitted by your users.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This policy setting has no effect if the \"Allow users to submit feedback to Microsoft\" policy setting or the “Allow users to receive and respond to in-product surveys from Microsoft” policy setting is set to Disabled.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection_1","displayName":"Enabled","description":null,"helpText":null}]},"885406f558fcc15a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage","displayName":"Outbox Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Outbox Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"8819e14d77732f05":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_l_minimumkeysizeinbits","displayName":"Minimum key size (in bits): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},"882eff92f3e571b7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit_l_outlookrestartmanagerretrylimitspinid","displayName":"(1 - 10 occurrences) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},"880eb2658243bc74":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab","displayName":"Show custom templates tab by default in PowerPoint on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in PowerPoint on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in PowerPoint on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in PowerPoint on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},"884d3ad66c6bf17c":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions","displayName":"[Deprecated] PowerPoint Designer Options (User)","description":"Important: This policy setting is no longer supported and will be removed in a future release. Please use the \"PowerPoint Designer Options\" policy setting from the PowerPoint policy set instead.\r\n\r\nThis policy setting allows an administrator to enable or disable PowerPoint Designer","helpText":"","infoUrls":[],"categoryId":"77ca5e78-a1fe-456e-9814-034b1ea2658d","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_1","displayName":"Enabled","description":null,"helpText":null}]},"88502b1d4aa4a8bb":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"8807e31cad0974c8":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto","displayName":"Save checked-out files to (User)","description":"This policy setting allows you to choose if checked-out files are saved to the server drafts location or the web server. \r\n\r\nIf you enable this policy setting, you can choose where checked-out files are saved:\r\n- Server drafts location: The server drafts location on this computer\r\n- Web server: The web server\r\n\r\nIf you disable or do not configure this policy setting, checked-out files are stored in the server drafts location.","helpText":"","infoUrls":[],"categoryId":"2eed22da-106f-4c93-9a45-5ce803b50233","categoryName":"Offline Editing","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_1","displayName":"Enabled","description":null,"helpText":null}]},"88a9dedc613efc4a":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},"884d2df2f622722f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"88bd5f34bd831397":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"88acef79b745d05f":{"id":"ade_accountsettings_adminaccountname","displayName":"Admin account username","description":"The account name for the administrator account. This field is to be defaulted to 'Admin'. For macOS ADE enrollment policies without user device affinity, we recommend configuring {{serialNumber}} as the unique identifier of userless devices.","helpText":"","infoUrls":[],"categoryId":"6c217eb1-e939-4a7d-8a27-da4b6dbf9513","categoryName":null,"options":null},"88528fd5c25c604c":{"id":"com.android.devicerestrictionpolicy.passwordminimumsymbolcharacters","displayName":"Number of symbol characters required","description":"Enter the number of symbol characters (&, #, %, and so on) the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"887e8b0824e435a5":{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly","displayName":"Peer Local Subnets Only","description":"If true, the content cache only peers with other content caches on the same immediate local network, rather than with content caches that use the same public IP address as the device. When Peer Local Subnets Only is true, it overrides the configuration of Peer Filter Ranges and Peer Listen Ranges. If the network changes, the local network peering restrictions update appropriately. If false, the content cache defers to Peer Filter Ranges and Peer Listen Ranges for configuring the peering restrictions.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerlocalsubnetsonly_true","displayName":"True","description":null,"helpText":null}]},"88b1e48510cc5b93":{"id":"com.apple.cellularprivatenetwork.managed_datasetname","displayName":"Data Set Name","description":"The name of the private network configuration data set.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"88f43b82c36116c3":{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled","displayName":"Enable proactive authentication","description":"This policy controls the proactive authentication in Microsoft Edge, that connects the signed-in user identity with Microsoft Bing, MSN and Copilot services for a smooth and consistent sign-in experience.\n\nIf you enable or don't configure this policy, Microsoft Edge authentication requests are automatically sent to the services using the account that is signed-in to the browser.\n\nIf you disable this policy, Microsoft Edge does not send authentications requests to these services and users will need to manually sign-in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proactiveauthworkflowenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proactiveauthworkflowenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"889653a2a1335c75":{"id":"com.apple.managedclient.preferences_urlallowlist","displayName":"Define a list of allowed URLs","description":"Allow access to the listed URLs, as exceptions to the URL block list.\n\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\n\nYou can use this policy to open exceptions to restrictive block lists. For example, you can include '*' in the block list to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\n\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the block list.\n\nThis policy is limited to 1000 entries; subsequent entries are ignored.\n\nIf you don't configure this policy, there are no exceptions to the block list in the \"URLBlocklist\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#urlallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"887d9ebee0d7153d":{"id":"com.apple.mcx.filevault2_outputpath","displayName":"Output Path","description":"The path to the location where the recovery key and computer information property list are stored.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},"88a7957fc5cc4f7c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled","displayName":"Let screen reader users get image descriptions from Microsoft","description":"Lets screen reader users get descriptions of unlabeled images on the web.\n\nIf you enable or don't configure this policy, users have the option of using an anonymous Microsoft service. This service provides automatic descriptions for unlabeled images users encounter on the web when they're using a screen reader.\n\nIf you disable this policy, users can't enable the Get Image Descriptions from Microsoft feature.\n\nWhen this feature is enabled, the content of images that need a generated description is sent to Microsoft servers to generate a description.\n\nNo cookies or other user data is sent to Microsoft, and Microsoft doesn't save or log any image content.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.accessibilityimagelabelsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"88997f2658c035cf":{"id":"com.microsoft.edge.mamedgeappconfigsettings.imagesallowedforurls","displayName":"Allow images on these sites","description":"Define a list of sites, based on URL patterns, that can display images.\n\nIf you don't configure this policy, the global default value is used for all sites either from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"881f49124711326e":{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn","displayName":"Concatenate OS defaults with input above","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowdefcredentialswhenntlmonly_concatenatedefaults_adcn_1","displayName":"True","description":null,"helpText":null}]},"88bc068e46fb2255":{"id":"device_vendor_msft_policy_config_admx_kerberos_kdcproxyserver_kdcproxyserver","displayName":"Define KDC proxy servers settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":null},"8804f6c1a5eea25f":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain","displayName":"Allow operation while in domain","description":null,"helpText":"","infoUrls":[],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_lltd_enablerspndr_allowondomain_1","displayName":"True","description":null,"helpText":null}]},"88472e6b40f6158e":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy","displayName":"Server authentication certificate template","description":"This policy setting allows you to specify the name of the certificate template that determines which certificate is automatically selected to authenticate an RD Session Host server.\r\n\r\nA certificate is needed to authenticate an RD Session Host server when TLS 1.0, 1.1 or 1.2 is used to secure communication between a client and an RD Session Host server during RDP connections.\r\n\r\nIf you enable this policy setting, you need to specify a certificate template name. Only certificates created by using the specified certificate template will be considered when a certificate to authenticate the RD Session Host server is automatically selected. Automatic certificate selection only occurs when a specific certificate has not been selected.\r\n\r\nIf no certificate can be found that was created with the specified certificate template, the RD Session Host server will issue a certificate enrollment request and will use the current certificate until the request is completed. If more than one certificate is found that was created with the specified certificate template, the certificate that will expire latest and that matches the current name of the RD Session Host server will be selected.\r\n\r\nIf you disable or do not configure this policy, the certificate template name is not specified at the Group Policy level. By default, a self-signed certificate is used to authenticate the RD Session Host server. \r\n\r\nNote: If you select a specific certificate to be used to authenticate the RD Session Host server, that certificate will take precedence over this policy setting.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-certificate-template-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_certificate_template_policy_1","displayName":"Enabled","description":null,"helpText":null}]},"880a25f81eba62a1":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chainloggingrate","displayName":"ChainLoggingRate","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"88b00e48666c2399":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_minpollinterval","displayName":"MinPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"88551c0e456ce96f":{"id":"device_vendor_msft_policy_config_applicationcontrol_policies_{policyguid}_xml","displayName":"App Control for Business policy","description":"The format of the XML property list varies depending on the settings you are configuring for the ApplicationControl CSP. Microsoft Endpoint Manager will validate the XML format; but not validate the settings behaviour, the settings applicability nor sign the policy binary. ApplicationControl CSP supports base and supplemental policies for devices running the Windows 1903 build and later. Supplemental policies are required to loosen a base policy; and are always less restrictive. A supplemental policy needs to support a specific base policy that has been deployed to the same client. If not, there is no effect on assigned Windows devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-application-control/windows-defender-application-control-design-guide"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":null},"88b9dc0dc0d7d1aa":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch","displayName":"Snipping Tool (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_screensketch_1","displayName":"True","description":null,"helpText":null}]},"88a286f4a7802943":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\r\n\r\nDisabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitBlockedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT disabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise JavaScript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"888503d03def2cf5":{"id":"device_vendor_msft_policy_config_defender_allowfullscanremovabledrivescanning","displayName":"Allow Full Scan Removable Drive Scanning","description":"Allows or disallows a full scan of removable drives. During a quick scan, removable drives may still be scanned.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_allowfullscanremovabledrivescanning_0","displayName":"Not allowed. Turns off scanning on removable drives.","description":"Not allowed. Turns off scanning on removable drives.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_allowfullscanremovabledrivescanning_1","displayName":"Allowed. Scans removable drives.","description":"Allowed. Scans removable drives.","helpText":null}]},"88cb5c69f67f9bf8":{"id":"device_vendor_msft_policy_config_devicelock_preventlockscreenslideshow","displayName":"Prevent enabling lock screen slide show","description":"Disables the lock screen slide show settings in PC Settings and prevents a slide show from playing on the lock screen.\n\nBy default, users can enable a slide show that will run after they lock the machine.\n\nIf you enable this setting, users will no longer be able to modify slide show settings in PC Settings, and no slide show will ever start.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-devicelock#devicelock-preventlockscreenslideshow"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"device_vendor_msft_policy_config_devicelock_preventlockscreenslideshow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_devicelock_preventlockscreenslideshow_1","displayName":"Enabled","description":null,"helpText":null}]},"88cee726488ae712":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowsmartscreenie"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"88afc0b9a3553615":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"8863e5ae5e87446d":{"id":"device_vendor_msft_policy_config_kerberos_setmaximumcontexttokensize","displayName":"Set maximum Kerberos SSPI context token buffer size","description":"This policy setting allows you to set the value returned to applications which request the maximum size of the SSPI context token buffer size.\r\n \r\nThe size of the context token buffer determines the maximum size of SSPI context tokens an application expects and allocates. Depending upon authentication request processing and group memberships, the buffer might be smaller than the actual size of the SSPI context token. \r\n\r\nIf you enable this policy setting, the Kerberos client or server uses the configured value, or the locally allowed maximum value, whichever is smaller.\r\n\r\nIf you disable or do not configure this policy setting, the Kerberos client or server uses the locally configured value or the default value. \r\n\r\nNote: This policy setting configures the existing MaxTokenSize registry value in HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Kerberos\\Parameters, which was added in Windows XP and Windows Server 2003, with a default value of 12,000 bytes. Beginning with Windows 8 the default is 48,000 bytes. Due to HTTP's base64 encoding of authentication context tokens, it is not advised to set this value more than 48,000 bytes.\r\n\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-kerberos#kerberos-setmaximumcontexttokensize"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_kerberos_setmaximumcontexttokensize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_setmaximumcontexttokensize_1","displayName":"Enabled","description":null,"helpText":null}]},"88b7e9fd2f17b43e":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_messagetextforusersattemptingtologon","displayName":"Interactive Logon Message Text For Users Attempting To Log On","description":"Interactive logon: Message text for users attempting to log on This security setting specifies a text message that is displayed to users when they log on. This text is often used for legal reasons, for example, to warn users about the ramifications of misusing company information or to warn them that their actions may be audited. Default: No message.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_messagetextforusersattemptingtologon"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"88b78436698d35c3":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowlocalsystemtousecomputeridentityforntlm","displayName":"Network Security Allow Local System To Use Computer Identity For NTLM","description":"Network security: Allow Local System to use computer identity for NTLM This policy setting allows Local System services that use Negotiate to use the computer identity when reverting to NTLM authentication. If you enable this policy setting, services running as Local System that use Negotiate will use the computer identity. This might cause some authentication requests between Windows operating systems to fail and log an error. If you disable this policy setting, services running as Local System that use Negotiate when reverting to NTLM authentication will authenticate anonymously. By default, this policy is enabled on Windows 7 and above. By default, this policy is disabled on Windows Vista. This policy is supported on at least Windows Vista or Windows Server 2008. Note: Windows Vista or Windows Server 2008 do not expose this setting in Group Policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_allowlocalsystemtousecomputeridentityforntlm"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowlocalsystemtousecomputeridentityforntlm_1","displayName":"Allow","description":"Allow","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowlocalsystemtousecomputeridentityforntlm_0","displayName":"Block","description":"Block","helpText":null}]},"8851c71fb94a53e8":{"id":"device_vendor_msft_policy_config_mixedreality_automaticdisplayadjustment","displayName":"Automatic Display Adjustment","description":"This policy controls if the HoloLens displays will be automatically adjusted for your eyes to improve hologram visual quality when an user wears the device. When this feature is enabled, a new user upon wearing the device will not be prompted to calibrate and yet the displays will be adjusted to suite them automatically. However if an immersive application is launched that depends on eye tracking interactions, the user will be prompted to perform the calibration.","helpText":"","infoUrls":[],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_automaticdisplayadjustment_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_automaticdisplayadjustment_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"88c4b9e8f155b516":{"id":"device_vendor_msft_policy_config_onedrivengscv4~policy~onedrivengsc_enableodignorelistfromgpo_enableodignorelistfromgpolistbox","displayName":"Keywords: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"8871b0eaaaf72210":{"id":"device_vendor_msft_policy_config_printers_configureredirectionguardpolicy","displayName":"Configure Redirection Guard","description":"\nDetermines whether Redirection Guard is enabled for the print spooler.\n\nYou can enable this setting to configure the Redirection Guard policy being applied to spooler.\n\nIf you disable or do not configure this policy setting, Redirection Guard will default to being 'Enabled'.\n\nIf you enable this setting you may select the following options:\n\n-- Enabled : Redirection Guard will prevent any file redirections from being followed\n\n-- Disabed : Redirection Guard will not be enabled and file redirections may be used within the spooler process\n\n-- Audit : Redirection Guard will log events as though it were enabled but will not actually prevent file redirections from being used within the spooler.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-configureredirectionguardpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configureredirectionguardpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configureredirectionguardpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"88f5d9ac0b987108":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices","displayName":"Let Apps Access Trusted Devices","description":"This policy setting specifies whether Windows apps can access trusted devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstrusteddevices"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstrusteddevices_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"8894f58d7a355e5a":{"id":"device_vendor_msft_policy_config_update_maintenancewindowstarttime","displayName":"Maintenance Window Start Time","description":"Configure the start time for the maintenance window in HH:MM format (for example, 23:30).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowstarttime"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"888c33382b323012":{"id":"device_vendor_msft_policy_config_updatev95~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetchannelmicrosoftedge","displayName":"Target Channel override","description":"Specifies which Channel Microsoft Edge should be updated to.\r\n\r\nIf you enable this poicy, the Microsoft Edge will be updated to the Channel according to how you configure the following options:\r\n\r\n - Stable: Microsoft Edge will be updated to the latest stable version.\r\n - Beta: Microsoft Edge will be updated to the latest beta version.\r\n - Dev: Microsoft Edge will be updated to the latest dev version.\r\n - Extended Stable: Microsoft Edge will be updated to the latest extended stable version, which follows a longer release cadence than stable. For more information, visit https://go.microsoft.com/fwlink/?linkid=2163508.\r\n\r\nIf you do not configure this policy, Microsoft Edge will be updated to the latest version available for the default Channel.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev95~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetchannelmicrosoftedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev95~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_targetchannelmicrosoftedge_1","displayName":"Enabled","description":null,"helpText":null}]},"8899c9e966ef9485":{"id":"user_vendor_msft_pde_protectfolders_protectpictures","displayName":"Protect Pictures (User)","description":"Allows the Admin to enable Personal Data Encryption on Pictures folder. Set to '1' to set this policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/personaldataencryption-csp/"],"categoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","categoryName":"Personal Data Encryption","options":[{"id":"user_vendor_msft_pde_protectfolders_protectpictures_0","displayName":"Disable Personal Data Encryption on the folder. If the folder is currently protected by Personal Data Encryption, this will result in unprotecting the folder.","description":"Disable Personal Data Encryption on the folder. If the folder is currently protected by Personal Data Encryption, this will result in unprotecting the folder.","helpText":null},{"id":"user_vendor_msft_pde_protectfolders_protectpictures_1","displayName":"Enable Personal Data Encryption on the folder.","description":"Enable Personal Data Encryption on the folder.","helpText":null}]},"8857b68c9e2b1eaa":{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffhistorybasedpredictiveinput","displayName":"Turn off history-based predictive input (User)","description":"This policy setting allows you to turn off history-based predictive input.\r\n\r\nIf you enable this policy setting, history-based predictive input is turned off.\r\n\r\nIf you disable or do not configure this policy setting, history-based predictive input is on by default.\r\n\r\nThis policy setting applies to Japanese Microsoft IME only.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eaime#admx-eaime-l-turnoffhistorybasedpredictiveinput"],"categoryId":"7d331987-7e2d-4975-b23b-d99a5af26ddf","categoryName":"IME","options":[{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffhistorybasedpredictiveinput_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffhistorybasedpredictiveinput_1","displayName":"Enabled","description":null,"helpText":null}]},"8880df1bf374145b":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013","displayName":"Microsoft Office 365 Lync 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_1","displayName":"Enabled","description":null,"helpText":null}]},"8877f82f901833c7":{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailyendminute_quiethoursdailyendminutecontrol","displayName":"Minutes after midnight: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":null},"8868ded198cff442":{"id":"user_vendor_msft_policy_config_browser_preventlivetiledatacollection","displayName":"Prevent Live Tile Data Collection (User)","description":"This policy lets you decide whether Microsoft Edge can gather Live Tile metadata from the ieonline.microsoft.com service to provide a better experience while pinning a Live Tile to the Start menu. Due to Protected Settings (aka.ms/browserpolicy), this policy will only apply on domain-joined machines or when the device is MDM-enrolled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventlivetiledatacollection"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_preventlivetiledatacollection_0","displayName":"Disabled","description":"Collect and send Live Tile metadata.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_preventlivetiledatacollection_1","displayName":"Enabled","description":"No data collected.","helpText":null}]},"88e56279f215d8d4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policylistmultiplesourcemergelist_policylistmultiplesourcemergelistdesc","displayName":"Allow merging list policies from different sources (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"88e65713a0eee8bc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist","displayName":"Configure extension installation allow list (User)","description":"Setting the policy specifies which extensions are not subject to the blocklist.\r\n\r\nA blocklist value of * means all extensions are blocked and users can only install extensions listed in the allow list.\r\n\r\nBy default, all extensions are allowed. But, if you prohibited extensions by policy, use the list of allowed extensions to change that policy.\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"88c633bdcbfd74a1":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties","displayName":"Prompt for workbook properties (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_promptforworkbookproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"88fa1a44650ecf98":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles","displayName":"Excel 2 macrosheets and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel2macrosheetsandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"88547194c9ae5ea5":{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},"88aafdf50759e2e7":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"8890c64f8ede1570":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709","displayName":"Enable dragging of content from different domains across windows (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainsacrosswindows_iz_partname2709_3","displayName":"Disable","description":null,"helpText":null}]},"888f464c345793f5":{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox (User)","description":"Setting this policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services when the system configuration supports it.\r\n\r\nSetting this policy to Disabled has a detrimental effect on Microsoft Edge's security because services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn this policy off if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev129~policy~microsoft_edge~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"88e4f1a679096573":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended","displayName":"Discover feature In Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 105.\r\n\r\nThis policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.\r\n\r\nThis policy lets you configure the Discover feature in Microsoft Edge.\r\n\r\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\r\n\r\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\r\n\r\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_recommended_edgediscoverenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"880ae666ae7eaca6":{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_enhancesecuritymodebypasslistdomainsdesc","displayName":"Configure the list of domains for which enhance security mode will not be enforced (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"883538985a53bbde":{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum","displayName":"Configure Get Diagnostics: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e86f24d3-8531-4298-b064-692ea795b1d9","categoryName":"Diagnostics","options":[{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_1","displayName":"Upload diagnostic logs to Microsoft","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v17~policy~l_microsoftofficesystem~l_diagnostics_l_configuregetdiagnostics_l_configuregetdiagnosticsenum_2","displayName":"Capture diagnostic logs in a local archive, dont upload logs to Microsoft","description":null,"helpText":null}]},"882c28f343865460":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastserviceminorversion2","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"88d09760f8dd59a7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacehomeadd_l_homeaddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"88a11788e51b8e1c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations","displayName":"Disable built-in color variations (User)","description":"Specify whether or not to show the built-in color variations.","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_disablebuiltincolorvariations_1","displayName":"Enabled","description":null,"helpText":null}]},"88d0850637170d14":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia","displayName":"Odia (User)","description":"Enables the editing language Odia","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_odia_1","displayName":"Enabled","description":null,"helpText":null}]},"88568d96cac4d2fc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_changedestinationurlforsharepointhyperlink_l_changedestinationurlforsharepointhyperlinkid","displayName":"Destination URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"88291f2b81a82553":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13","displayName":"Workflow Cache 13 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_1","displayName":"Enabled","description":null,"helpText":null}]},"88bd30c1b5b63358":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection","displayName":"Allow Microsoft to follow up on feedback submitted by users (User)","description":"This policy setting controls whether Microsoft can follow up on feedback submitted by users to help understand the feedback, troubleshoot an issue submitted through feedback, or share back how Microsoft used the feedback to improve the product.\r\n\r\nMicrosoft may send transactional emails or request follow-up conversations via email, voice, or other means related to the feedback or survey response. In some circumstances, Microsoft may ask for additional information to assist with troubleshooting.\r\n\r\nIf you enable this policy setting, Microsoft may follow up on feedback submitted. \r\n\r\nIf you disable or don’t configure this policy setting, Microsoft will not follow up on feedback submitted by your users.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This policy setting has no effect if the \"Allow users to submit feedback to Microsoft\" policy setting or the “Allow users to receive and respond to in-product surveys from Microsoft” policy setting is set to Disabled.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_emailcollection_1","displayName":"Enabled","description":null,"helpText":null}]},"885406f558fcc15a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage","displayName":"Outbox Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Outbox Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_outboxfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"8819e14d77732f05":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_minimumencryptionsettings_l_minimumkeysizeinbits","displayName":"Minimum key size (in bits): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},"882eff92f3e571b7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_outlookrestartmanagerretrylimit_l_outlookrestartmanagerretrylimitspinid","displayName":"(1 - 10 occurrences) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":null},"880eb2658243bc74":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab","displayName":"Show custom templates tab by default in PowerPoint on the Office Start screen and in File | New (User)","description":"This policy setting controls whether custom templates (when they exist) show as the default tab in PowerPoint on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, users will the see custom templates tab as the default tab in PowerPoint on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in PowerPoint on the Office Start screen and in File | New, unless all Office-provided templates have been disabled.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_defaultcustomtab_1","displayName":"Enabled","description":null,"helpText":null}]},"884d3ad66c6bf17c":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions","displayName":"[Deprecated] PowerPoint Designer Options (User)","description":"Important: This policy setting is no longer supported and will be removed in a future release. Please use the \"PowerPoint Designer Options\" policy setting from the PowerPoint policy set instead.\r\n\r\nThis policy setting allows an administrator to enable or disable PowerPoint Designer","helpText":"","infoUrls":[],"categoryId":"77ca5e78-a1fe-456e-9814-034b1ea2658d","categoryName":"PowerPoint Designer","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_powerpointdesigner_l_powerpointdesigneroptions_1","displayName":"Enabled","description":null,"helpText":null}]},"88502b1d4aa4a8bb":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm","displayName":"Specify CNG random number generator algorithm (User)","description":"This policy setting allows you to configure the CNG random number generator to use.\r\n\r\nIf you enable this policy setting, the random number generator specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default random number generator will be used.","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"8807e31cad0974c8":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto","displayName":"Save checked-out files to (User)","description":"This policy setting allows you to choose if checked-out files are saved to the server drafts location or the web server. \r\n\r\nIf you enable this policy setting, you can choose where checked-out files are saved:\r\n- Server drafts location: The server drafts location on this computer\r\n- Web server: The web server\r\n\r\nIf you disable or do not configure this policy setting, checked-out files are stored in the server drafts location.","helpText":"","infoUrls":[],"categoryId":"2eed22da-106f-4c93-9a45-5ce803b50233","categoryName":"Offline Editing","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save~l_offlineediting_l_savecheckedoutfilesto_1","displayName":"Enabled","description":null,"helpText":null}]},"88a9dedc613efc4a":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_allowsubfolders27_1","displayName":"True","description":null,"helpText":null}]},"884d2df2f622722f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"88bd5f34bd831397":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon82","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/89.json b/public/intune-definitions/89.json index b7eed49b5a20..5d0ac39a95b9 100644 --- a/public/intune-definitions/89.json +++ b/public/intune-definitions/89.json @@ -1 +1 @@ -{"893597a1323412fc":{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol","displayName":"Allow Video Conferencing Remote Control (Deprecated)","description":"If `false`, disables the ability for a remote FaceTime session to request control of the device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol_true","displayName":"True","description":null,"helpText":null}]},"89d763b56f932f84":{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},"89bbe9d57f00c375":{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin","displayName":"Enable Create User At Login","description":"Enables creating new users at the login window with either Passwords or SmartCards. Requires 'UseSharedDeviceKeys' is true.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin_true","displayName":"Enabled","description":null,"helpText":null}]},"899d15db2ec51481":{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads","description":"Controls whether ads are blocked on sites with intrusive ads. You can set this policy to one of the following options:\n\n* 1 = Allow ads on all sites.\n\n* 2 = Block ads on sites with intrusive ads (Default value).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#adssettingforintrusiveadssites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites_0","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites_1","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},"89d216f17c33513e":{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled","displayName":"Enable efficiency mode when the device is connected to a power source","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\n\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\n\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\n\nThis policy has no effect if the \"EfficiencyModeEnabled\" policy is disabled.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymodeonpowerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"891902ba5217baa4":{"id":"com.apple.managedclient.preferences_proxysettings","displayName":"Proxy Settings","description":"Configures the proxy settings for Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nThis policy overrides the following individual policies:\n\n\"ProxyMode\"\n\"ProxyPacUrl\"\n\"ProxyServer\"\n\"ProxyBypassList\"\n\nThe ProxyMode field lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings.\n\nThe ProxyPacUrl field is a URL to a proxy .pac file.\n\nThe ProxyServer field is a URL for the proxy server.\n\nThe ProxyBypassList field is a list of proxy hosts that Microsoft Edge bypasses.\n\nIf you choose the 'direct' value as 'ProxyMode', a proxy is never used and all other fields are ignored.\n\nIf you choose the 'system' value as 'ProxyMode', the systems's proxy is used and all other fields are ignored.\n\nIf you choose the 'auto_detect' value as 'ProxyMode', all other fields are ignored.\n\nIf you choose the 'fixed_server' value as 'ProxyMode', the 'ProxyServer' and 'ProxyBypassList' fields are used.\n\nIf you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' and 'ProxyBypassList' fields are used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxysettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"89aae537752f7971":{"id":"com.apple.mcx_cachedaccounts.expiry.delete.disusedseconds","displayName":"Expiry Delete Disused Seconds","description":"The minimum number of seconds a mobile account can exist before an automatic attempt is made to remove the mobile account. Set to 0 to try to remove it at next login or logout time. Set to -1 to never try to remove the mobile account.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":null},"899c019295c06933":{"id":"com.apple.mcx_com.apple.mcx-mobileaccounts","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":null},"8993cfd9865f4156":{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"896a300853a31f96":{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"89d28bbc9cc94d57":{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended","displayName":"Allow HTTPS-Only Mode to be enabled (users can override)","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS.\n\nIf this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode.\nIf this setting is set to Disallowed, HTTPS-Only Mode will be disabled.\nIf this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode.\nIf this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode.\n\nThe settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it.\n\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nPolicy options mapping:\n\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\n\n* disallowed (disallowed) = Disable HTTPS-Only Mode\n\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\n\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_allowed","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_disallowed","displayName":"Disable HTTPS-Only Mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},"891b7e43ecfa4886":{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow websites to make requests to any network endpoint in an insecure manner. (Obsolete)","description":"Controls whether websites are allowed to make requests to more-private network endpoints.\n\nWhen this policy is enabled, all Private Network Access checks are disabled for all origins. This may allow attackers to perform cross-site request forgery (CSRF) attacks on private network servers.\n\nWhen this policy is disabled or not configured, the default behavior for requests to more-private network endpoints depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests, PrivateNetworkAccessSendPreflights, and PrivateNetworkAccessRespectPreflightResults feature flags. These flags may be controlled by experimentation or set via the command line.\n\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\n\nA network endpoint is more private than another if:\n1) Its IP address is localhost and the other isn't.\n2) Its IP address is private and the other is public.\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\n\nWhen this policy enabled, websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.\n\nThis policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.","helpText":null,"infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"89e914032e971317":{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration","displayName":"Specify search order for device driver source locations","description":"This policy setting allows you to specify the order in which Windows searches source locations for device drivers. \r\n\r\nIf you enable this policy setting, you can select whether Windows searches for drivers on Windows Update unconditionally, only if necessary, or not at all.\r\n\r\nNote that searching always implies that Windows will attempt to search Windows Update exactly one time. With this setting, Windows will not continually search for updates. This setting is used to ensure that the best software will be found for the device, even if the network is temporarily available.\r\n\r\nIf the setting for searching only if needed is specified, then Windows will search for a driver only if a driver is not locally available on the system.\r\n\r\nIf you disable or do not configure this policy setting, members of the Administrators group can determine the priority order in which Windows searches source locations for device drivers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicesetup#admx-devicesetup-driversearchplaces-searchorderconfiguration"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},"89ab8cd47d19e0ec":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk","displayName":"Report all errors in Windows components.","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk_1","displayName":"True","description":null,"helpText":null}]},"895f0f41953366ec":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2","displayName":"Reminder balloon frequency","description":"Determines how often reminder balloon updates appear.\r\n\r\nIf you enable this setting, you can select how often reminder balloons updates appear and also prevent users from changing this setting.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the update interval.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To set reminder balloon frequency without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, and then click the Offline Files tab. This setting corresponds to the \"Display reminder balloons every ... minutes\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderfreq-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_1","displayName":"Enabled","description":null,"helpText":null}]},"89bbe03bad1f31e8":{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku","displayName":"Allow certificates with no extended key usage certificate attribute","description":"This policy setting lets you allow certificates without an Extended Key Usage (EKU) set to be used for logon.\r\n\r\nIn versions of Windows prior to Windows Vista, smart card certificates that are used for logon require an enhanced key usage (EKU) extension with a smart card logon object identifier. This policy setting can be used to modify that restriction.\r\n\r\nIf you enable this policy setting, certificates with the following attributes can also be used to log on with a smart card:\r\n- Certificates with no EKU\r\n- Certificates with an All Purpose EKU\r\n- Certificates with a Client Authentication EKU\r\n\r\nIf you disable or do not configure this policy setting, only certificates that contain the smart card logon object identifier can be used to log on with a smart card.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowcertificateswithnoeku"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku_1","displayName":"Enabled","description":null,"helpText":null}]},"890e02503b4fd54a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT enabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"8910ce0607a16c7d":{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate","displayName":"Locked-Down Restricted Sites Zone Template","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownrestrictedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"893bc0e44a0bfcac":{"id":"device_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation","displayName":"Check for server certificate revocation","description":"This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates. Certificates are revoked when they have been compromised or are no longer valid, and this option protects users from submitting confidential data to a site that may be fraudulent or not secure.\n\nIf you enable this policy setting, Internet Explorer will check to see if server certificates have been revoked.\n\nIf you disable this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.\n\nIf you do not configure this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checkservercertificaterevocation"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_1","displayName":"Enabled","description":null,"helpText":null}]},"89a100bb3c7ae92b":{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport","displayName":"Turn off encryption support","description":"This policy setting allows you to turn off support for Transport Layer Security (TLS) 1.0, TLS 1.1, TLS 1.2, Secure Sockets Layer (SSL) 2.0, or SSL 3.0 in the browser. TLS and SSL are protocols that help protect communication between the browser and the target server. When the browser attempts to set up a protected communication with the target server, the browser and server negotiate which protocol and version to use. The browser and server attempt to match each other’s list of supported protocols and versions, and they select the most preferred match.\n\nIf you enable this policy setting, the browser negotiates or does not negotiate an encryption tunnel by using the encryption methods that you select from the drop-down list.\n\nIf you disable or do not configure this policy setting, the user can select which encryption method the browser supports.\n\nNote: SSL 2.0 is off by default and is no longer supported starting with Windows 10 Version 1607. SSL 2.0 is an outdated security protocol, and enabling SSL 2.0 impairs the performance and functionality of TLS 1.0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableencryptionsupport"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_1","displayName":"Enabled","description":null,"helpText":null}]},"89195e00765adc6b":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowsmartscreenie"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"89d0f367c2b99559":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"8963830fc2d1d626":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\r\n\r\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"89405c1c02b88cf6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended","displayName":"Disable synchronization of data using Microsoft sync services","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"8954b8cdf2d4ba0a":{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"8915b941fae5ffb4":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_outlookexe176","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_outlookexe176_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_outlookexe176_1","displayName":"True","description":null,"helpText":null}]},"894f4a1531c20aef":{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_deferupdatedays","displayName":"Delay downloading and installing updates for Office","description":"This policy setting allows you to delay downloading and installing updates for Office by a specified number of days.\r\n\r\nNote: This policy setting won’t apply if you are using some other method to manage updates. For example, if you use System Center Configuration Manager to deploy Office updates or if you use Group Policy to specify a target version. Also, updates won’t be delayed if you are switching Office to a different update channel.\r\n\r\nIf you enable this policy setting, Office will delay downloading and applying updates by the number of days specified. The maximum value that you can specify is 14. If you specify 0, Office will download and apply updates as soon as Office detects that updates are available.\r\n\r\nNote: If you have also specified a deadline for updates to be installed, the deadline won't be considered until after the delay that you specify with this policy setting.\r\n\r\nIf you disable or don’t configure this policy setting, Office will download and apply updates as soon as Office detects that updates are available.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus, as well as subscription versions of Visio and Project.","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_deferupdatedays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_deferupdatedays_1","displayName":"Enabled","description":null,"helpText":null}]},"896764d559f8dd02":{"id":"device_vendor_msft_policy_config_system_allowexperimentation","displayName":"Allow Experimentation","description":"NoteThis policy is not supported in Windows 10, version 1607. This policy setting determines the level that Microsoft can experiment with the product to study user preferences or device behavior. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#allowexperimentation"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_allowexperimentation_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowexperimentation_1","displayName":"Permits Microsoft to configure device settings only.","description":"Permits Microsoft to configure device settings only.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowexperimentation_2","displayName":"Allows Microsoft to conduct full experimentation.","description":"Allows Microsoft to conduct full experimentation.","helpText":null}]},"892ed6fe0b6238fa":{"id":"keyboardsettings_allowpredictivetext","displayName":"Allow Predictive Text","description":"If `false`, disables predictive text.","helpText":null,"infoUrls":[],"categoryId":"dba26132-cba6-4178-93c3-f02476532f08","categoryName":"Keyboard Settings","options":[{"id":"keyboardsettings_allowpredictivetext_false","displayName":"False","description":null,"helpText":null},{"id":"keyboardsettings_allowpredictivetext_true","displayName":"True","description":null,"helpText":null}]},"89fac1fad5ee1c90":{"id":"linux_mdatp_managed_antivirusengine_exclusionsmergepolicy","displayName":"Exclusions merge","description":"Specify the merge policy for exclusions. This can be a combination of administrator-defined and user-defined exclusions (merge) or only administrator-defined exclusions (admin_only). This setting can be used to restrict local users from defining their own exclusions.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#exclusion-merge-policy"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_exclusionsmergepolicy_0","displayName":"merge","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_exclusionsmergepolicy_1","displayName":"admin_only","description":null,"helpText":null}]},"89d67b09052a655b":{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_estimatefilehandlerrisk","displayName":"Trust logic for file attachments (User)","description":"This policy setting allows you to configure the logic that Windows uses to determine the risk for file attachments.\r\n\r\nPreferring the file handler instructs Windows to use the file handler data over the file type data. For example, trust notepad.exe, but don't trust .txt files.\r\n\r\nPreferring the file type instructs Windows to use the file type data over the file handler data. For example, trust .txt files, regardless of the file handler.\r\n\r\nUsing both the file handler and type data is the most restrictive option. Windows chooses the more restrictive recommendation which will cause users to see more trust prompts than choosing the other options.\r\n\r\nIf you enable this policy setting, you can choose the order in which Windows processes risk assessment data.\r\n\r\nIf you disable this policy setting, Windows uses its default trust logic, which prefers the file handler over the file type.\r\n\r\nIf you do not configure this policy setting, Windows uses its default trust logic, which prefers the file handler over the file type.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-attachmentmanager#admx-attachmentmanager-am-estimatefilehandlerrisk"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_estimatefilehandlerrisk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_estimatefilehandlerrisk_1","displayName":"Enabled","description":null,"helpText":null}]},"89dcec7f3a418f63":{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_nologoff","displayName":"Remove Logoff (User)","description":"This policy setting disables or removes all menu items and buttons that log the user off the system.\r\n\r\nIf you enable this policy setting, users will not see the Log off menu item when they press Ctrl+Alt+Del. This will prevent them from logging off unless they restart or shutdown the computer, or clicking Log off from the Start menu.\r\n\r\nAlso, see the 'Remove Logoff on the Start Menu' policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can see and select the Log off menu item when they press Ctrl+Alt+Del.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ctrlaltdel#admx-ctrlaltdel-nologoff"],"categoryId":"5536b5f4-3d31-4290-acea-9bef323bb83d","categoryName":"Ctrl Alt Del Options","options":[{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_nologoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_nologoff_1","displayName":"Enabled","description":null,"helpText":null}]},"89cb478d181f2d51":{"id":"user_vendor_msft_policy_config_admx_desktop_noactivedesktop","displayName":"Disable Active Desktop (User)","description":"Disables Active Desktop and prevents users from enabling it.\r\n\r\nThis setting prevents users from trying to enable or disable Active Desktop while a policy controls it.\r\n\r\nIf you disable this setting or do not configure it, Active Desktop is disabled by default, but users can enable it.\r\n\r\nNote: If both the \"Enable Active Desktop\" setting and the \"Disable Active Desktop\" setting are enabled, the \"Disable Active Desktop\" setting is ignored. If the \"Turn on Classic Shell\" setting (in User Configuration\\Administrative Templates\\Windows Components\\Windows Explorer) is enabled, Active Desktop is disabled, and both these policies are ignored.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-noactivedesktop"],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_noactivedesktop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_noactivedesktop_1","displayName":"Enabled","description":null,"helpText":null}]},"8934b35ce9c09f09":{"id":"user_vendor_msft_policy_config_admx_startmenu_quicklaunchenabled","displayName":"Show QuickLaunch on Taskbar (User)","description":"This policy setting controls whether the QuickLaunch bar is displayed in the Taskbar.\r\n\r\nIf you enable this policy setting, the QuickLaunch bar will be visible and cannot be turned off.\r\n\r\nIf you disable this policy setting, the QuickLaunch bar will be hidden and cannot be turned on.\r\n\r\nIf you do not configure this policy setting, then users will be able to turn the QuickLaunch bar on and off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-quicklaunchenabled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_quicklaunchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_quicklaunchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"891e74359c45803f":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"89485a17b03b7b39":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowfontdownloads"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"890409edb80ccfbb":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},"8916e758ee511176":{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor (User)","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\r\n\r\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8953bae0e00bad7a":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled","displayName":"Configure whether a user always has a default profile automatically signed in with their work or school account (User)","description":"This policy determines if a user can remove the Microsoft Edge profile automatically signed in with a user's work or school account.\r\n\r\nIf you enable this policy, a non-removable profile will be created with the user's work or school account on Windows. This profile can't be signed out or removed.\r\n\r\nIf you disable or don't configure this policy, the profile automatically signed in with a user's work or school account on Windows can be signed out or removed by the user.\r\n\r\nIf you want to configure browser sign in, use the 'BrowserSignin' (Browser sign-in settings) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"897a17f688b70129":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support (User)","description":"Enable support for Signed HTTP Exchange (SXG).\r\n\r\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\r\n\r\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"89d1021df1bb25c1":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins_sslerroroverrideallowedfororiginsdesc","displayName":"Allow users to proceed from the HTTPS warning page for specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"890be91281d977b7":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices (User)","description":"Setting the policy lets you list sites that are automatically granted permission to access USB serial devices with vendor and product IDs that match the vendor_id and product_id fields.\r\n\r\nOptionally you can omit the product_id field. This enables site access to all the vendor's devices. When you provide a product ID, then you give the site access to a specific device from the vendor but not all devices.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the 'WebUsbAllowDevicesForUrls' (Grant access to specific sites to connect to specific USB devices) policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://specific-device.example.com\"\r\n ]\r\n },\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://all-vendor-devices.example.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"89871df4f303c748":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations","displayName":"Menu animations (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_1","displayName":"Enabled","description":null,"helpText":null}]},"89ba473596261c12":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher","displayName":"Disallow in Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher_1","displayName":"True","description":null,"helpText":null}]},"89594abb3b431920":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl","displayName":"Additional permissions request URL (User)","description":"Specifies a location where a user can obtain more information about getting access to IRM content.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_1","displayName":"Enabled","description":null,"helpText":null}]},"89de0399566a5f9c":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith","displayName":"Turn off link creation with [[ ]] (User)","description":"This policy setting allows you to turn off link creation with [[ ]]. OneNote allows users to automatically create links by putting [[ ]] around a term. OneNote will then automatically create a new page in that section and create a link on that text.\r\n\r\nIf you enable this policy setting, users will not be able to use [[ ]] to create a link and a new page.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will automatically create links when users use [[ ]].","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith_1","displayName":"Enabled","description":null,"helpText":null}]},"8924f15dfe1b36c8":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"893639a782edc1af":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},"89ece0c6aea71369":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text","displayName":"Text (User)","description":"Specifies the unit of measure for indents, line spacing and other text measurements. The default unit for type size is points (1 point = 1/72 in.). You can enter type size in another unit of measure (for example, 1ft or 12 in) but you can't change the default.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_1","displayName":"Enabled","description":null,"helpText":null}]},"890c57237a13360c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"899200203a61a28b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":null},"8953618b6c5d8cf4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},"89d02d8a3e5fe0a4":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_app_filepath","displayName":"File Path","description":"The file path of an app is simply its location on the client device. For example, C:\\Windows\\System\\Notepad.exe or %WINDIR%\\Notepad.exe. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},"899b856911a6e7cb":{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]}} \ No newline at end of file +{"893597a1323412fc":{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol","displayName":"Allow Video Conferencing Remote Control (Deprecated)","description":"If `false`, disables the ability for a remote FaceTime session to request control of the device.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowvideoconferencingremotecontrol_true","displayName":"True","description":null,"helpText":null}]},"89d763b56f932f84":{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type","displayName":"File Type","description":"The type of file","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_0","displayName":"URL","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_1","displayName":"File","description":null,"helpText":null},{"id":"com.apple.dock_persistent-apps_item_tile-data_file-type_2","displayName":"Directory","description":null,"helpText":null}]},"89bbe9d57f00c375":{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin","displayName":"Enable Create User At Login","description":"Enables creating new users at the login window with either Passwords or SmartCards. Requires 'UseSharedDeviceKeys' is true.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_enablecreateuseratlogin_true","displayName":"Enabled","description":null,"helpText":null}]},"899d15db2ec51481":{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads","description":"Controls whether ads are blocked on sites with intrusive ads. You can set this policy to one of the following options:\n\n* 1 = Allow ads on all sites.\n\n* 2 = Block ads on sites with intrusive ads (Default value).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#adssettingforintrusiveadssites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites_0","displayName":"Allow ads on all sites","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_adssettingforintrusiveadssites_1","displayName":"Block ads on sites with intrusive ads. (Default value)","description":null,"helpText":null}]},"89d216f17c33513e":{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled","displayName":"Enable efficiency mode when the device is connected to a power source","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\n\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\n\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\n\nThis policy has no effect if the \"EfficiencyModeEnabled\" policy is disabled.\n\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#efficiencymodeonpowerenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_efficiencymodeonpowerenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"891902ba5217baa4":{"id":"com.apple.managedclient.preferences_proxysettings","displayName":"Proxy Settings","description":"Configures the proxy settings for Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge ignores all proxy-related options specified from the command line.\n\nIf you don't configure this policy, users can choose their own proxy settings.\n\nThis policy overrides the following individual policies:\n\n\"ProxyMode\"\n\"ProxyPacUrl\"\n\"ProxyServer\"\n\"ProxyBypassList\"\n\nThe ProxyMode field lets you specify the proxy server used by Microsoft Edge and prevents users from changing proxy settings.\n\nThe ProxyPacUrl field is a URL to a proxy .pac file.\n\nThe ProxyServer field is a URL for the proxy server.\n\nThe ProxyBypassList field is a list of proxy hosts that Microsoft Edge bypasses.\n\nIf you choose the 'direct' value as 'ProxyMode', a proxy is never used and all other fields are ignored.\n\nIf you choose the 'system' value as 'ProxyMode', the systems's proxy is used and all other fields are ignored.\n\nIf you choose the 'auto_detect' value as 'ProxyMode', all other fields are ignored.\n\nIf you choose the 'fixed_server' value as 'ProxyMode', the 'ProxyServer' and 'ProxyBypassList' fields are used.\n\nIf you choose the 'pac_script' value as 'ProxyMode', the 'ProxyPacUrl' and 'ProxyBypassList' fields are used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxysettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"89aae537752f7971":{"id":"com.apple.mcx_cachedaccounts.expiry.delete.disusedseconds","displayName":"Expiry Delete Disused Seconds","description":"The minimum number of seconds a mobile account can exist before an automatic attempt is made to remove the mobile account. Set to 0 to try to remove it at next login or logout time. Set to -1 to never try to remove the mobile account.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":null},"899c019295c06933":{"id":"com.apple.mcx_com.apple.mcx-mobileaccounts","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":null},"8993cfd9865f4156":{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_camera_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"896a300853a31f96":{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_speechrecognition_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"89d28bbc9cc94d57":{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended","displayName":"Allow HTTPS-Only Mode to be enabled (users can override)","description":"This policy controls whether users can enable HTTPS-Only Mode (Always Use Secure Connections) in Settings. HTTPS-Only Mode attempts to upgrade all navigation to HTTPS.\n\nIf this setting isn't set or is set to Allowed, users are able to enable HTTPS-Only Mode.\nIf this setting is set to Disallowed, HTTPS-Only Mode will be disabled.\nIf this setting is set to Force Enabled, HTTPS-Only Mode is enabled in Strict mode.\nIf this setting is set to Force Balance Enabled, HTTPS-Only Mode is enabled in Balanced mode.\n\nThe settings Force Enabled and Force Enabled can be recommended to users. HTTPS-Only Mode will be set to Strict or Balanced initially, but users are allowed to change it.\n\nIf you set this policy to a value that isn't supported by the version of Microsoft Edge that receives the policy, Microsoft Edge defaults to the Allowed setting.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nPolicy options mapping:\n\n* allowed (allowed) = Don't restrict users' HTTPS-Only Mode setting\n\n* disallowed (disallowed) = Disable HTTPS-Only Mode\n\n* force_enabled (force_enabled) = Force enable HTTPS-Only Mode in Strict mode\n\n* force_balanced_enabled (force_balanced_enabled) = Force enable HTTPS-Only Mode in Balanced Mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_allowed","displayName":"Don't restrict users' HTTPS-Only Mode setting","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_disallowed","displayName":"Disable HTTPS-Only Mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_force_enabled","displayName":"Force enable HTTPS-Only Mode in Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.httpsonlymode_recommended_force_balanced_enabled","displayName":"Force enable HTTPS-Only Mode in Balanced Mode","description":null,"helpText":null}]},"891b7e43ecfa4886":{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed","displayName":"Specifies whether to allow websites to make requests to any network endpoint in an insecure manner. (Obsolete)","description":"Controls whether websites are allowed to make requests to more-private network endpoints.\n\nWhen this policy is enabled, all Private Network Access checks are disabled for all origins. This may allow attackers to perform cross-site request forgery (CSRF) attacks on private network servers.\n\nWhen this policy is disabled or not configured, the default behavior for requests to more-private network endpoints depend on the user's personal configuration for the BlockInsecurePrivateNetworkRequests, PrivateNetworkAccessSendPreflights, and PrivateNetworkAccessRespectPreflightResults feature flags. These flags may be controlled by experimentation or set via the command line.\n\nThis policy relates to the Private Network Access specification. See https://wicg.github.io/private-network-access/ for more details.\n\nA network endpoint is more private than another if:\n1) Its IP address is localhost and the other isn't.\n2) Its IP address is private and the other is public.\nIn the future, depending on spec evolution, this policy might apply to all cross-origin requests directed at private IPs or localhost.\n\nWhen this policy enabled, websites are allowed to make requests to any network endpoint, subject to other cross-origin checks.\n\nThis policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.","helpText":null,"infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"8999c4183de36c9d":{"id":"contentcaching_peerlistenranges","displayName":"Peer Listen Ranges","description":"An array of dictionaries describing a range of peer IP addresses the content cache responds to. When `PeerListenRanges` is an empty array, the content cache responds with an error to all cache queries.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"89e914032e971317":{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration","displayName":"Specify search order for device driver source locations","description":"This policy setting allows you to specify the order in which Windows searches source locations for device drivers. \r\n\r\nIf you enable this policy setting, you can select whether Windows searches for drivers on Windows Update unconditionally, only if necessary, or not at all.\r\n\r\nNote that searching always implies that Windows will attempt to search Windows Update exactly one time. With this setting, Windows will not continually search for updates. This setting is used to ensure that the best software will be found for the device, even if the network is temporarily available.\r\n\r\nIf the setting for searching only if needed is specified, then Windows will search for a driver only if a driver is not locally available on the system.\r\n\r\nIf you disable or do not configure this policy setting, members of the Administrators group can determine the priority order in which Windows searches source locations for device drivers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-devicesetup#admx-devicesetup-driversearchplaces-searchorderconfiguration"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_1","displayName":"Enabled","description":null,"helpText":null}]},"89ab8cd47d19e0ec":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk","displayName":"Report all errors in Windows components.","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonewincomp_chk_1","displayName":"True","description":null,"helpText":null}]},"895f0f41953366ec":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2","displayName":"Reminder balloon frequency","description":"Determines how often reminder balloon updates appear.\r\n\r\nIf you enable this setting, you can select how often reminder balloons updates appear and also prevent users from changing this setting.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the update interval.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To set reminder balloon frequency without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, and then click the Offline Files tab. This setting corresponds to the \"Display reminder balloons every ... minutes\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderfreq-2"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_1","displayName":"Enabled","description":null,"helpText":null}]},"89bbe03bad1f31e8":{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku","displayName":"Allow certificates with no extended key usage certificate attribute","description":"This policy setting lets you allow certificates without an Extended Key Usage (EKU) set to be used for logon.\r\n\r\nIn versions of Windows prior to Windows Vista, smart card certificates that are used for logon require an enhanced key usage (EKU) extension with a smart card logon object identifier. This policy setting can be used to modify that restriction.\r\n\r\nIf you enable this policy setting, certificates with the following attributes can also be used to log on with a smart card:\r\n- Certificates with no EKU\r\n- Certificates with an All Purpose EKU\r\n- Certificates with a Client Authentication EKU\r\n\r\nIf you disable or do not configure this policy setting, only certificates that contain the smart card logon object identifier can be used to log on with a smart card.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-allowcertificateswithnoeku"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_allowcertificateswithnoeku_1","displayName":"Enabled","description":null,"helpText":null}]},"890e02503b4fd54a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT enabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"8910ce0607a16c7d":{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate","displayName":"Locked-Down Restricted Sites Zone Template","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownrestrictedsiteszonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowlockeddownrestrictedsiteszonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"893bc0e44a0bfcac":{"id":"device_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation","displayName":"Check for server certificate revocation","description":"This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates. Certificates are revoked when they have been compromised or are no longer valid, and this option protects users from submitting confidential data to a site that may be fraudulent or not secure.\n\nIf you enable this policy setting, Internet Explorer will check to see if server certificates have been revoked.\n\nIf you disable this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.\n\nIf you do not configure this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checkservercertificaterevocation"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_1","displayName":"Enabled","description":null,"helpText":null}]},"89a100bb3c7ae92b":{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport","displayName":"Turn off encryption support","description":"This policy setting allows you to turn off support for Transport Layer Security (TLS) 1.0, TLS 1.1, TLS 1.2, Secure Sockets Layer (SSL) 2.0, or SSL 3.0 in the browser. TLS and SSL are protocols that help protect communication between the browser and the target server. When the browser attempts to set up a protected communication with the target server, the browser and server negotiate which protocol and version to use. The browser and server attempt to match each other’s list of supported protocols and versions, and they select the most preferred match.\n\nIf you enable this policy setting, the browser negotiates or does not negotiate an encryption tunnel by using the encryption methods that you select from the drop-down list.\n\nIf you disable or do not configure this policy setting, the user can select which encryption method the browser supports.\n\nNote: SSL 2.0 is off by default and is no longer supported starting with Windows 10 Version 1607. SSL 2.0 is an outdated security protocol, and enabling SSL 2.0 impairs the performance and functionality of TLS 1.0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableencryptionsupport"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_1","displayName":"Enabled","description":null,"helpText":null}]},"89195e00765adc6b":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowsmartscreenie"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"89d0f367c2b99559":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"8963830fc2d1d626":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\r\n\r\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_editfavoritesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"89405c1c02b88cf6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended","displayName":"Disable synchronization of data using Microsoft sync services","description":"Disables data synchronization in Microsoft Edge. This policy also prevents the sync consent prompt from appearing.\r\n\r\nIf you don't set this policy or apply it as recommended, users will be able to turn sync on or off. If you apply this policy as mandatory, users will not be able to turn sync on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_syncdisabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"8954b8cdf2d4ba0a":{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant an extended background lifetime to connecting extensions. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"8915b941fae5ffb4":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_outlookexe176","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_outlookexe176_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_outlookexe176_1","displayName":"True","description":null,"helpText":null}]},"894f4a1531c20aef":{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_deferupdatedays","displayName":"Delay downloading and installing updates for Office","description":"This policy setting allows you to delay downloading and installing updates for Office by a specified number of days.\r\n\r\nNote: This policy setting won’t apply if you are using some other method to manage updates. For example, if you use System Center Configuration Manager to deploy Office updates or if you use Group Policy to specify a target version. Also, updates won’t be delayed if you are switching Office to a different update channel.\r\n\r\nIf you enable this policy setting, Office will delay downloading and applying updates by the number of days specified. The maximum value that you can specify is 14. If you specify 0, Office will download and apply updates as soon as Office detects that updates are available.\r\n\r\nNote: If you have also specified a deadline for updates to be installed, the deadline won't be considered until after the delay that you specify with this policy setting.\r\n\r\nIf you disable or don’t configure this policy setting, Office will download and apply updates as soon as Office detects that updates are available.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus, as well as subscription versions of Visio and Project.","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_deferupdatedays_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_deferupdatedays_1","displayName":"Enabled","description":null,"helpText":null}]},"896764d559f8dd02":{"id":"device_vendor_msft_policy_config_system_allowexperimentation","displayName":"Allow Experimentation","description":"NoteThis policy is not supported in Windows 10, version 1607. This policy setting determines the level that Microsoft can experiment with the product to study user preferences or device behavior. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#allowexperimentation"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_allowexperimentation_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowexperimentation_1","displayName":"Permits Microsoft to configure device settings only.","description":"Permits Microsoft to configure device settings only.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowexperimentation_2","displayName":"Allows Microsoft to conduct full experimentation.","description":"Allows Microsoft to conduct full experimentation.","helpText":null}]},"892ed6fe0b6238fa":{"id":"keyboardsettings_allowpredictivetext","displayName":"Allow Predictive Text","description":"If `false`, disables predictive text.","helpText":null,"infoUrls":[],"categoryId":"dba26132-cba6-4178-93c3-f02476532f08","categoryName":"Keyboard Settings","options":[{"id":"keyboardsettings_allowpredictivetext_false","displayName":"False","description":null,"helpText":null},{"id":"keyboardsettings_allowpredictivetext_true","displayName":"True","description":null,"helpText":null}]},"89fac1fad5ee1c90":{"id":"linux_mdatp_managed_antivirusengine_exclusionsmergepolicy","displayName":"Exclusions merge","description":"Specify the merge policy for exclusions. This can be a combination of administrator-defined and user-defined exclusions (merge) or only administrator-defined exclusions (admin_only). This setting can be used to restrict local users from defining their own exclusions.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#exclusion-merge-policy"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_exclusionsmergepolicy_0","displayName":"merge","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_exclusionsmergepolicy_1","displayName":"admin_only","description":null,"helpText":null}]},"89d67b09052a655b":{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_estimatefilehandlerrisk","displayName":"Trust logic for file attachments (User)","description":"This policy setting allows you to configure the logic that Windows uses to determine the risk for file attachments.\r\n\r\nPreferring the file handler instructs Windows to use the file handler data over the file type data. For example, trust notepad.exe, but don't trust .txt files.\r\n\r\nPreferring the file type instructs Windows to use the file type data over the file handler data. For example, trust .txt files, regardless of the file handler.\r\n\r\nUsing both the file handler and type data is the most restrictive option. Windows chooses the more restrictive recommendation which will cause users to see more trust prompts than choosing the other options.\r\n\r\nIf you enable this policy setting, you can choose the order in which Windows processes risk assessment data.\r\n\r\nIf you disable this policy setting, Windows uses its default trust logic, which prefers the file handler over the file type.\r\n\r\nIf you do not configure this policy setting, Windows uses its default trust logic, which prefers the file handler over the file type.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-attachmentmanager#admx-attachmentmanager-am-estimatefilehandlerrisk"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_estimatefilehandlerrisk_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_estimatefilehandlerrisk_1","displayName":"Enabled","description":null,"helpText":null}]},"89dcec7f3a418f63":{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_nologoff","displayName":"Remove Logoff (User)","description":"This policy setting disables or removes all menu items and buttons that log the user off the system.\r\n\r\nIf you enable this policy setting, users will not see the Log off menu item when they press Ctrl+Alt+Del. This will prevent them from logging off unless they restart or shutdown the computer, or clicking Log off from the Start menu.\r\n\r\nAlso, see the 'Remove Logoff on the Start Menu' policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can see and select the Log off menu item when they press Ctrl+Alt+Del.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ctrlaltdel#admx-ctrlaltdel-nologoff"],"categoryId":"5536b5f4-3d31-4290-acea-9bef323bb83d","categoryName":"Ctrl Alt Del Options","options":[{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_nologoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_ctrlaltdel_nologoff_1","displayName":"Enabled","description":null,"helpText":null}]},"89cb478d181f2d51":{"id":"user_vendor_msft_policy_config_admx_desktop_noactivedesktop","displayName":"Disable Active Desktop (User)","description":"Disables Active Desktop and prevents users from enabling it.\r\n\r\nThis setting prevents users from trying to enable or disable Active Desktop while a policy controls it.\r\n\r\nIf you disable this setting or do not configure it, Active Desktop is disabled by default, but users can enable it.\r\n\r\nNote: If both the \"Enable Active Desktop\" setting and the \"Disable Active Desktop\" setting are enabled, the \"Disable Active Desktop\" setting is ignored. If the \"Turn on Classic Shell\" setting (in User Configuration\\Administrative Templates\\Windows Components\\Windows Explorer) is enabled, Active Desktop is disabled, and both these policies are ignored.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-noactivedesktop"],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_noactivedesktop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_noactivedesktop_1","displayName":"Enabled","description":null,"helpText":null}]},"8934b35ce9c09f09":{"id":"user_vendor_msft_policy_config_admx_startmenu_quicklaunchenabled","displayName":"Show QuickLaunch on Taskbar (User)","description":"This policy setting controls whether the QuickLaunch bar is displayed in the Taskbar.\r\n\r\nIf you enable this policy setting, the QuickLaunch bar will be visible and cannot be turned off.\r\n\r\nIf you disable this policy setting, the QuickLaunch bar will be hidden and cannot be turned on.\r\n\r\nIf you do not configure this policy setting, then users will be able to turn the QuickLaunch bar on and off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-quicklaunchenabled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_quicklaunchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_quicklaunchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"891e74359c45803f":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"89485a17b03b7b39":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowfontdownloads"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"890409edb80ccfbb":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},"8916e758ee511176":{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor (User)","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\r\n\r\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8953bae0e00bad7a":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled","displayName":"Configure whether a user always has a default profile automatically signed in with their work or school account (User)","description":"This policy determines if a user can remove the Microsoft Edge profile automatically signed in with a user's work or school account.\r\n\r\nIf you enable this policy, a non-removable profile will be created with the user's work or school account on Windows. This profile can't be signed out or removed.\r\n\r\nIf you disable or don't configure this policy, the profile automatically signed in with a user's work or school account on Windows can be signed out or removed by the user.\r\n\r\nIf you want to configure browser sign in, use the 'BrowserSignin' (Browser sign-in settings) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"897a17f688b70129":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled","displayName":"Enable Signed HTTP Exchange (SXG) support (User)","description":"Enable support for Signed HTTP Exchange (SXG).\r\n\r\nIf this policy isn't set or enabled, Microsoft Edge will accept web contents served as Signed HTTP Exchanges.\r\n\r\nIf this policy is set to disabled, Signed HTTP Exchanges can't be loaded.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_signedhttpexchangeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"89d1021df1bb25c1":{"id":"user_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_sslerroroverrideallowedfororigins_sslerroroverrideallowedfororiginsdesc","displayName":"Allow users to proceed from the HTTPS warning page for specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"890be91281d977b7":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls","displayName":"Automatically grant sites permission to connect to USB serial devices (User)","description":"Setting the policy lets you list sites that are automatically granted permission to access USB serial devices with vendor and product IDs that match the vendor_id and product_id fields.\r\n\r\nOptionally you can omit the product_id field. This enables site access to all the vendor's devices. When you provide a product ID, then you give the site access to a specific device from the vendor but not all devices.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the Web Serial API. To grant access to USB devices through the WebUSB API see the 'WebUsbAllowDevicesForUrls' (Grant access to specific sites to connect to specific USB devices) policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"product_id\": 5678,\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://specific-device.example.com\"\r\n ]\r\n },\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://all-vendor-devices.example.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowusbdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"89871df4f303c748":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations","displayName":"Menu animations (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_menuanimations_1","displayName":"Enabled","description":null,"helpText":null}]},"89ba473596261c12":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher","displayName":"Disallow in Publisher (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypublisher_1","displayName":"True","description":null,"helpText":null}]},"89594abb3b431920":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl","displayName":"Additional permissions request URL (User)","description":"Specifies a location where a user can obtain more information about getting access to IRM content.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_additionalpermissionsrequesturl_1","displayName":"Enabled","description":null,"helpText":null}]},"89de0399566a5f9c":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith","displayName":"Turn off link creation with [[ ]] (User)","description":"This policy setting allows you to turn off link creation with [[ ]]. OneNote allows users to automatically create links by putting [[ ]] around a term. OneNote will then automatically create a new page in that section and create a link on that text.\r\n\r\nIf you enable this policy setting, users will not be able to use [[ ]] to create a link and a new page.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will automatically create links when users use [[ ]].","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_turnofflinkcreationwith_1","displayName":"Enabled","description":null,"helpText":null}]},"8924f15dfe1b36c8":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_descriptioncolon66","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"893639a782edc1af":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist","displayName":"Number of folders in the Recent Folders list (User)","description":"This policy setting specifies the number of unpinned entries displayed in the Recent Folders list that appears when users click Open or Save As on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of unpinned entries to be between 0 and 20. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 5 unpinned items are displayed in the Recent Folders list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Folders list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","categoryName":"General options for Microsoft Project","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral~l_pjgeneralprojoptions_l_setnumberofplacesintherecentplaceslist_1","displayName":"Enabled","description":null,"helpText":null}]},"89ece0c6aea71369":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text","displayName":"Text (User)","description":"Specifies the unit of measure for indents, line spacing and other text measurements. The default unit for type size is points (1 point = 1/72 in.). You can enter type size in another unit of measure (for example, 1ft or 12 in) but you can't change the default.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_text_1","displayName":"Enabled","description":null,"helpText":null}]},"890c57237a13360c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc04_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"899200203a61a28b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems174_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":null},"8953618b6c5d8cf4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},"89d02d8a3e5fe0a4":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_app_filepath","displayName":"File Path","description":"The file path of an app is simply its location on the client device. For example, C:\\Windows\\System\\Notepad.exe or %WINDIR%\\Notepad.exe. You can define one application to be used in each Firewall rule. If you specify multiple conditions in a single rule, these will be treated as an AND operation. i.e program=svchost.exe AND service=mpssvc, etc. All of the app related conditions in a single rule work to scope the traffic even further, so they must all correspond to the specific app/service.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null},"899b856911a6e7cb":{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction","displayName":"Default Outbound Action","description":"This value is the action that the firewall does by default (and evaluates at the very end) on outbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 0 [Allow]. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction_0","displayName":"Allow","description":"Allow Outbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_defaultoutboundaction_1","displayName":"Block","description":"Block Outbound By Default","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/8e.json b/public/intune-definitions/8e.json index 14e96b00429f..49e4d45070e2 100644 --- a/public/intune-definitions/8e.json +++ b/public/intune-definitions/8e.json @@ -1 +1 @@ -{"8e38f1dffe7aac7f":{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations","displayName":"Block Wi-Fi access point configuration","description":"If 'True', prevents users from creating or changing any Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations_true","displayName":"True","description":"True","helpText":null}]},"8ef5acf158636ff2":{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync","displayName":"Allow Enterprise Book Metadata Sync","description":"If false, disables sync of Enterprise books, notes, and highlights. Available in iOS 8 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync_true","displayName":"True","description":null,"helpText":null}]},"8eba678ad8352f4b":{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess","displayName":"Allow Files Network Drive Access","description":"If false, prevents connecting to network drives in the Files app. Requires a supervised device. Available in iOS 13.1 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess_true","displayName":"True","description":null,"helpText":null}]},"8ed047fbe3930872":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"8eb77f5c7f65fa3b":{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches","displayName":"Configure whether Microsoft Edge should automatically select a certificate when there are multiple certificate matches for a site configured with \"AutoSelectCertificateForUrls\"","description":"Toggles whether users are prompted to select a certificate if there are multiple certificates available and a site is configured with \"AutoSelectCertificateForUrls\". If you don't configure \"AutoSelectCertificateForUrls\" for a site, the user will always be prompted to select a certificate.\n\nIf you set this policy to True, Microsoft Edge will prompt a user to select a certificate for sites on the list defined in \"AutoSelectCertificateForUrls\" if and only if there is more than one certificate.\n\nIf you set this policy to False or don't configure it, Microsoft Edge will automatically select a certificate even if there are multiple matches for a certificate. The user will not be prompted to select a certificate for sites on the list defined in \"AutoSelectCertificateForUrls\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcecertificatepromptsonmultiplematches"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches_true","displayName":"Enabled","description":null,"helpText":null}]},"8e01dbc18a96a488":{"id":"com.apple.managedclient.preferences_passwordmonitorallowed","displayName":"Allow Microsoft Edge to monitor user passwords","description":"If you enable this policy and a user consents to enabling the policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\n\nIf you disable this policy, users will not be asked for permission to enable this feature and will not be alerted. Their passwords will not be scanned.\n\nIf you disable this policy, users can't change or override the policy. However, if you enable or don't configure the policy, users can turn this feature on or off.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordmonitorallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordmonitorallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordmonitorallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"8e8f36d1cfa52728":{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS","description":"This policy configures whether Microsoft Edge offers a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers.\n\nIf you enable or don't configure this policy, Microsoft Edge offers a post-quantum key agreement in TLS connections. TLS connections are protected from quantum computers when communicating with compatible servers.\n\nIf you disable this policy, Microsoft Edge will not offer a post-quantum key agreement in TLS connections. User traffic is unprotected from decryption by quantum computers.\n\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\n\nHowever, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices aren't post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix.\n\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge. You can enable it to test for issues and you can disable it while you resolve issues.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#postquantumkeyagreementenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8e2dc5bbd17b277a":{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled","displayName":"Configure Microsoft Edge Scareware blocker protection","description":"This policy setting allows administrators to control whether Microsoft Edge enables Scareware blocker, an AI-powered feature for protecting users from potential tech scams. To support this feature, Microsoft Edge downloads a machine learning model file from Microsoft to the device.\n\nIf you enable or don’t configure this policy, Microsoft Edge Scareware blocker uses local AI to detect potential tech scams.\n\nIf you disable this policy, Microsoft Edge Scareware blocker is disabled. The machine learning model file doesn't download to the device, and if downloaded deletion occurs.\n\nWhen this policy is enabled, the policies \"ScarewareBlockerBlocksDetectedSitesEnabled\", \"ScarewareBlockerSendDetectedSitesToSmartScreenEnabled\", and \"ScarewareBlockerAllowListDomains\" can be used to configure the behavior of the Scareware blocker feature. If both of those policies are disabled, enabling this policy has no effect.\n\nWhen this policy is disabled, the policies \"ScarewareBlockerBlocksDetectedSitesEnabled\", \"ScarewareBlockerSendDetectedSitesToSmartScreenEnabled\", and \"ScarewareBlockerAllowListDomains\" have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerprotectionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8e8a379df57ae62b":{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"8eb261975e763a1b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallforcelist","displayName":"Control which extensions are installed silently","description":"Set this policy to specify a list of apps and extensions that install silently, without user interaction. Users can't uninstall or turn off this setting. Permissions are granted implicitly, including the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. Note: These two APIs aren't available to apps and extensions that aren't force-installed.\n\nIf you don't set this policy, no apps or extensions are autoinstalled and users can uninstall any app in Microsoft Edge.\n\nThis policy supersedes \"ExtensionInstallBlocklist\" policy. If a previously force-installed app or extension is removed from this list, Microsoft Edge automatically uninstalls it.\n\nFor Windows instances not joined to a Microsoft Active Directory domain, forced installation is limited to apps and extensions listed in the Microsoft Edge Add-ons website.\n\nOn macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, or joined to a domain via MCX.\n\nThe source code of any extension can be altered by users with developer tools, potentially rendering the extension unfunctional. If there's a concern, configure the \"DeveloperToolsAvailability\" policy.\n\nEach list item of the policy is a string that contains an extension ID and, optionally, and an optional \"update\" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on edge://extensions when in Developer mode. If specified, the \"update\" URL should point to an Update Manifest XML document ( https://go.microsoft.com/fwlink/?linkid=2095043 ). The update URL should use one of the following schemes: http, https, or file. By default, the Microsoft Edge Add-ons website's update URL is used. The \"update\" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest. The update url for subsequent updates can be overridden using the ExtensionSettings policy. See https://learn.microsoft.com/deployedge/microsoft-edge-manage-extensions-ref-guide.\n\nNote: This policy doesn't apply to InPrivate mode. Read about hosting extensions at [Publish and update extensions in the Microsoft Edge Add-ons website](/microsoft-edge/extensions-chromium/enterprise/hosting-and-updating).\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"8e39cec03778f554":{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride","displayName":"Prevent bypassing Edge Website Typo Protection prompts for sites","description":"This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites.\n\nIf you enable this setting, users can't ignore Edge Website Typo Protection warnings, and they're blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.\n\nThis only takes effect when TyposquattingCheckerEnabled policy isn't set or is set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},"8e1be6aeb12f6a83":{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_personalcolors_accent","displayName":"Accent color:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},"8eaa3ec523aafee3":{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_wermaxqueuesize","displayName":"Maximum size of the queue (MB):","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"8e78c7ca4b0d50c6":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_gprefreshrateoffset2","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"8e92c54c63b7fc52":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo","displayName":"Action:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo_0","displayName":"Work offline","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo_1","displayName":"Never go offline","description":null,"helpText":null}]},"8ef8ca1cad09c257":{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},"8eaa94e0ef6d2919":{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2","displayName":"Removable Disks: Deny execute access","description":"This policy setting denies execute access to removable disks.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removabledisks-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"8e9e1388c0a62404":{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior","displayName":"Set the default behavior for AutoRun","description":"This policy setting sets the default behavior for Autorun commands.\n\n Autorun commands are generally stored in autorun.inf files. They often launch the installation program or other routines.\n\n Prior to Windows Vista, when media containing an autorun command is inserted, the system will automatically execute the program without user intervention.\n\n This creates a major security concern as code may be executed without user's knowledge. The default behavior starting with Windows Vista is to prompt the user whether autorun command is to be run. The autorun command is represented as a handler in the Autoplay dialog.\n\n If you enable this policy setting, an Administrator can change the default Windows Vista or later behavior for autorun to:\n\n a) Completely disable autorun commands, or\n b) Revert back to pre-Windows Vista behavior of automatically executing the autorun command.\n\n If you disable or not configure this policy setting, Windows Vista or later will prompt the user whether autorun command is to be run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-setdefaultautorunbehavior"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"8e2228f7c4208801":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots","displayName":"Disable taking screenshots","description":"Setting the policy to True disallows screenshots taken with keyboard shortcuts or extension APIs. Setting the policy to False allows screenshots.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots_1","displayName":"Enabled","description":null,"helpText":null}]},"8eecc9711f13afc9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled","displayName":"Allow automatic sign-in to Microsoft® cloud identity providers","description":"Configures automatic user sign-in for accounts backed by a Microsoft® cloud identity provider.\r\n\r\nBy setting this policy to 1 (Enabled), users who sign into their computer with an account backed by a Microsoft® cloud identity provider (i.e., Microsoft® Azure® Active Directory® or the consumer Microsoft® account identity provider) or who have added a work or school account to Microsoft® Windows® can be signed into web properties using that identity automatically. Information pertaining to the user's device and account is transmitted to the user's cloud identity provider for each authentication event.\r\n\r\nBy setting this policy to 0 (Disabled) or leaving it unset, automatic sign-in as described above is disabled.\r\n\r\nThis feature is available starting in Microsoft® Windows® 10.\r\n\r\nNote: This policy doesn't apply to Incognito or Guest modes.","helpText":"","infoUrls":[],"categoryId":"463e6791-7d54-4964-a36b-63bbedb7d0cd","categoryName":"Microsoft Active Directory management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8e335fe100da47e7":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdproxydirectory_ccdproxydirectory","displayName":"Proxy Directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f2d139ed-a314-48b7-b700-4d11adfcc309","categoryName":"Cloud Cache Service","options":null},"8e092030673716f1":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdlocations","displayName":"VHD Locations","description":"Specifies the network location where the VHD(X) files are stored.\r\n\r\nExamples:\r\n- Sinlge location: \\\\\\\r\n- Multiple locations: \\\\\\;\\\\\\\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\VHDLocations\r\nREG_SZ","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdlocations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdlocations_1","displayName":"Enabled","description":null,"helpText":null}]},"8e700a87bd0e6905":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles","displayName":"Allow loading of XAML files","description":"This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.\n\nIf you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.\n\nIf you disable this policy setting, XAML files are not loaded inside Internet Explorer. The user cannot change this behavior.\n\nIf you do not configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowloadingofxamlfiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"8e52cce460728f9e":{"id":"device_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton","displayName":"Enable End Session Button","description":"Enable/disable kiosk browser's end session button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enableendsessionbutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"device_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_0","displayName":"Disable","description":"Disable","helpText":null}]},"8eb7aa45fd688cbd":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowpku2uauthenticationrequests","displayName":"Network Security Allow PKU2U Authentication Requests","description":"Network security: Allow PKU2U authentication requests to this computer to use online identities. This policy will be turned off by default on domain joined machines. This would prevent online identities from authenticating to the domain joined machine.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_allowpku2uauthenticationrequests"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowpku2uauthenticationrequests_0","displayName":"Block","description":"Block","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowpku2uauthenticationrequests_1","displayName":"Allow","description":"Allow","helpText":null}]},"8e7690da4bebd557":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_imagesallowedforurlsdesc","displayName":"Allow images on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"8ead1f7aeaa5c7c5":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\r\n\r\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\r\n\r\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\r\n\r\nIf you disable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you configure both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"8eb1de9e8e927a16":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_volumeactivation_l_preventtokenactivationdialogfromclosing","displayName":"Prevent Token Activation dialog from closing","description":"This policy setting allows you to prevent the Token Activation prompt for activation dialog from closing.\r\n\r\nIf you enable this policy setting, the \"Close\" button and the \"X\" button at the upper right of the dialog are suppressed. If the user proceeds with activation and fails, the buttons will be enabled the next time the dialog appears.\r\n\r\nIf you disable or do not configure this policy setting, the user may close the dialog when prompted for activation.","helpText":"","infoUrls":[],"categoryId":"712d184f-d9ac-45fc-9eea-aade3a22b55e","categoryName":"Volume Activation","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_volumeactivation_l_preventtokenactivationdialogfromclosing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_volumeactivation_l_preventtokenactivationdialogfromclosing_1","displayName":"Enabled","description":null,"helpText":null}]},"8e42e3f6201e38af":{"id":"device_vendor_msft_policy_config_printers_managedriverexclusionlist_driver_exclusionlistentry_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"8e59ad830e664e75":{"id":"device_vendor_msft_policy_config_wirelessdisplay_requirepinforpairing","displayName":"Require Pin For Pairing","description":"This policy setting allows you to require a pin for pairing. If you set this to 0, a pin isn't required for pairing. If you set this to 1, the pairing ceremony for new devices will always require a PIN. If you set this to 2, all pairings will require PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WirelessDisplay#requirepinforpairing"],"categoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_wirelessdisplay_requirepinforpairing_0","displayName":"PIN is not required.","description":"PIN is not required.","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_requirepinforpairing_1","displayName":"Pairing ceremony for new devices will always require a PIN","description":"Pairing ceremony for new devices will always require a PIN","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_requirepinforpairing_2","displayName":"All pairings will require PIN","description":"All pairings will require PIN","helpText":null}]},"8e2a34e599eea728":{"id":"extensionsettings_managedextensions_generickey_alloweddomains","displayName":"Allowed Domains","description":"Controls the domains and sub-domains the extension is granted access to. Any non-prefixed domains take precedence over prefixed domains, and DeniedDomains takes precedence over AllowedDomains. Any domains not specified in AllowedDomains or DeniedDomains are configurable by the user.","helpText":null,"infoUrls":[],"categoryId":"7d9e5b9b-84e7-473c-b6ca-a1629448df55","categoryName":"Safari Extension Settings","options":null},"8ea59e16d709e9ba":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n\r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users.","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"8e4aef9064ca943d":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_newgpolinksdisabled","displayName":"Create new Group Policy Object links disabled by default (User)","description":"This policy setting allows you to create new Group Policy object links in the disabled state.\r\n\r\nIf you enable this setting, you can create all new Group Policy object links in the disabled state by default. After you configure and test the new object links by using a policy compliant Group Policy management tool such as Active Directory Users and Computers or Active Directory Sites and Services, you can enable the object links for use on the system.\r\n\r\nIf you disable this setting or do not configure it, new Group Policy object links are created in the enabled state. If you do not want them to be effective until they are configured and tested, you must disable the object link.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-newgpolinksdisabled"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"user_vendor_msft_policy_config_admx_grouppolicy_newgpolinksdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_grouppolicy_newgpolinksdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8ee4d47703f15bba":{"id":"user_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_1","displayName":"Do not allow Snipping Tool to run (User)","description":"Prevents the snipping tool from running.\r\n\r\nIf you enable this policy setting, the Snipping Tool will not run.\r\n\r\nIf you disable this policy setting, the Snipping Tool will run.\r\n\r\nIf you do not configure this policy setting, the Snipping Tool will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disablesnippingtool-1"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"user_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_1_1","displayName":"Enabled","description":null,"helpText":null}]},"8ef3e70480feb31e":{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_1","displayName":"Prevent launch an application (User)","description":"Prevents the user from launching an application from a Tablet PC hardware button.\r\n\r\nIf you enable this policy, applications cannot be launched from a hardware button, and \"Launch an application\" is removed from the drop down menu for configuring button actions (in the Tablet PC Control Panel buttons tab).\r\n\r\nIf you disable this policy, applications can be launched from a hardware button.\r\n\r\nIf you do not configure this policy, applications can be launched from a hardware button.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventlaunchapp-1"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_1_1","displayName":"Enabled","description":null,"helpText":null}]},"8e332dade20a147f":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016","displayName":"Microsoft Office 365 Access 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Access 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Access 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Access 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Access 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Access 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365access2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016_1","displayName":"Enabled","description":null,"helpText":null}]},"8eb9b7373d2257e8":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013","displayName":"Microsoft Office 365 Publisher 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Publisher 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Publisher 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Publisher 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Publisher 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Publisher 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365publisher2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013_1","displayName":"Enabled","description":null,"helpText":null}]},"8ea2ab6f9e4270b4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access (User)","description":"Enables the use of a default search provider on the context menu.\r\n\r\nIf you set this policy to disabled the search context menu item that relies on your default search provider will not be available.\r\n\r\nIf this policy is set to enabled or not set, the context menu item for your default search provider will be available.\r\n\r\nThe policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"8e55643b5cdbed2a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"8ea6c29ac4ab6c10":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_remoteaccesshostmaximumsessiondurationminutes","displayName":"Maximum session duration allowed for remote access connections: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},"8e020a00288ed7b1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup","displayName":"Action on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_5","displayName":"Open New Tab Page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"8e0476b547bce6ca":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_windowplacementblockedforurlsdesc","displayName":"Block Window Placement permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"8eac07c2972ea8e6":{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode","displayName":"Turn on Enhanced Protected Mode (User)","description":"Enhanced Protected Mode provides additional protection against malicious websites by using 64-bit processes on 64-bit versions of Windows. For computers running at least Windows 8, Enhanced Protected Mode also limits the locations Internet Explorer can read from in the registry and the file system.\n\nIf you enable this policy setting, Enhanced Protected Mode will be turned on. Any zone that has Protected Mode enabled will use Enhanced Protected Mode. Users will not be able to disable Enhanced Protected Mode.\n\nIf you disable this policy setting, Enhanced Protected Mode will be turned off. Any zone that has Protected Mode enabled will use the version of Protected Mode introduced in Internet Explorer 7 for Windows Vista.\n\nIf you do not configure this policy, users will be able to turn on or turn off Enhanced Protected Mode on the Advanced tab of the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"8ea1f8591caa3127":{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles","displayName":"Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet (User)","description":"This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter warns the user about executable files that Internet Explorer users do not commonly download from the Internet.\n\nIf you enable this policy setting, SmartScreen Filter warnings block the user.\n\nIf you disable or do not configure this policy setting, the user can bypass SmartScreen Filter warnings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablebypassofsmartscreenwarningsaboutuncommonfiles"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"8e47efd21597e027":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker","displayName":"Use Pop-up Blocker (User)","description":"This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.\n\nIf you enable this policy setting, most unwanted pop-up windows are prevented from appearing.\n\nIf you disable this policy setting, pop-up windows are not prevented from appearing.\n\nIf you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneusepopupblocker"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_1","displayName":"Enabled","description":null,"helpText":null}]},"8e350c04f1319ff6":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"8e3f65cd328b7fe4":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"8eb1cb59aa26d4eb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled","displayName":"Enable spellcheck (User)","description":"If you enable or don't configure this policy, the user can use spellcheck.\r\n\r\nIf you disable this policy, the user can't use spellcheck and the 'SpellcheckLanguage' (Enable specific spellcheck languages) and 'SpellcheckLanguageBlocklist' (Force disable spellcheck languages) policies are also disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8e113d914e837044":{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled","displayName":"Allows users to translate videos to different languages. (User)","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\r\nWith this feature, users can watch videos translated into their selected language in real time.\r\n\r\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\r\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\r\n\r\nThese components may be updated periodically to improve performance and translation quality.\r\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\r\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\r\nFor more details, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\r\n\r\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\r\nusers will see the Translate button when hovering over videos.\r\n\r\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button won’t be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8efff8afd34d4697":{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_30","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"8e5ea06b04737726":{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist","displayName":"Configure the list of domains for which the password manager UI (Save and Fill) will be disabled (User)","description":"Configure the list of domains where Microsoft Edge should disable the password manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\r\n\r\nIf you enable this policy, the password manager will be disabled for the specified set of domains.\r\n\r\nIf you disable or don't configure this policy, password manager will work as usual for all domains.\r\n\r\nIf you configure this policy, that is, add domains for which password manager is blocked, users can't change or override the behavior in Microsoft Edge. In addition, users can't use password manager for those URLs.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com/\r\nhttps://login.contoso.com","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"8e3962cde8a23d43":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverurl3","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"8ef8e64459d6dcbf":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel","displayName":"Disallow in Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel_1","displayName":"True","description":null,"helpText":null}]},"8e9ce498947b3f22":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic","displayName":"Kashmiri (Arabic) (User)","description":"Enables the editing language Kashmiri (Arabic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic_1","displayName":"Enabled","description":null,"helpText":null}]},"8e4e7f9282cdc29d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowcachename493","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"8ed353202d884352":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16","displayName":"Escrow Key #16 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_1","displayName":"Enabled","description":null,"helpText":null}]},"8e2ff233113aba21":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds_l_rewindfromstartofparagraphbysec","displayName":"Rewind from start of paragraph by: (sec) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},"8e6eaeed84f6ef51":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2","displayName":"Display Level 1 attachments (User)","description":"This policy setting controls whether Outlook blocks potentially dangerous attachments designated Level 1. \r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n \r\nIf you enable this policy setting, Outlook users can gain access to Level 1 file type attachments by first saving the attachments to disk and then opening them, as with Level 2 attachments. \r\n\r\nIf you disable this policy setting, Level 1 attachments do not display under any circumstances. \r\n\r\nIf you do not configure this policy setting, Outlook completely blocks access to Level 1 files, and requires users to save Level 2 files to disk before opening them.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"8e1b88bd51bb80cd":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve","displayName":"Configure Simple MAPI name resolution prompt (User)","description":"This policy setting allows you to specify what occurs when a program attempts to gain access to an Address Book, using Simple MAPI.\r\n\r\nIf you enable this policy setting, you can choose whether Outlook always allows access to the Address Book, always disallows access to the Address Book, or prompts the user to specify whether to allow or disallow access to the Address Book.\r\n\r\nIf you disable or do not configure this policy setting, Outlook prompts the user to specify whether to allow or disallow access to the Address Book.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_1","displayName":"Enabled","description":null,"helpText":null}]},"8e9c8103456ef369":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype","displayName":"Shorten appointments and meetings (User)","description":"\r\n This policy setting allows you to shorten the default duration of appointments and meetings by a specified number of minutes. If you enable this policy setting, you can choose between the following options: End Early, Start Late, None.\r\n If you select End Early, meetings and appointments will end early by the specified number of minutes. \r\n If you select Start Late, meetings and appointments will start late by the specified number of minutes. \r\n If you select None, the default meeting duration will not be shortened. \r\n In all cases, the settings for this feature will be disabled in the Outlook Options dialog. \r\n If you don’t configure this policy setting, users can modify these settings by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_1","displayName":"Enabled","description":null,"helpText":null}]},"8e9aa78958e12fac":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},"8e8b7fdadfd51b6b":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},"8ec8b53cf6890ca4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting","displayName":"Rely on CSS for font formatting (User)","description":"This policy setting allows you to configure the \"Use Cascading Style Sheets (CSS) for appearance of messages\" option found under Microsoft Outlook's File tab | Outlook Options | Mail | Message format.\r\n\r\nIf you enable this policy setting, the option is checked.\r\n\r\nIf you disable or do not configure this policy setting, the option is not checked.\r\n","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting_1","displayName":"Enabled","description":null,"helpText":null}]},"8e97c5dbeed12384":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_0","displayName":"Balloons on","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_2","displayName":"Comments and formatting only in balloons","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_1","displayName":"Balloons off (revisions inline)","description":null,"helpText":null}]}} \ No newline at end of file +{"8e38f1dffe7aac7f":{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations","displayName":"Block Wi-Fi access point configuration","description":"If 'True', prevents users from creating or changing any Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device. Available for fully managed, dedicated and corporate-owned work profile devices. ","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurations_true","displayName":"True","description":"True","helpText":null}]},"8ef5acf158636ff2":{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync","displayName":"Allow Enterprise Book Metadata Sync","description":"If false, disables sync of Enterprise books, notes, and highlights. Available in iOS 8 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowenterprisebookmetadatasync_true","displayName":"True","description":null,"helpText":null}]},"8eba678ad8352f4b":{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess","displayName":"Allow Files Network Drive Access","description":"If false, prevents connecting to network drives in the Files app. Requires a supervised device. Available in iOS 13.1 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesnetworkdriveaccess_true","displayName":"True","description":null,"helpText":null}]},"8ed047fbe3930872":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_start","displayName":"Start","description":"The curfew start time, in the format %d:%d:%d.","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":null},"8eb77f5c7f65fa3b":{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches","displayName":"Configure whether Microsoft Edge should automatically select a certificate when there are multiple certificate matches for a site configured with \"AutoSelectCertificateForUrls\"","description":"Toggles whether users are prompted to select a certificate if there are multiple certificates available and a site is configured with \"AutoSelectCertificateForUrls\". If you don't configure \"AutoSelectCertificateForUrls\" for a site, the user will always be prompted to select a certificate.\n\nIf you set this policy to True, Microsoft Edge will prompt a user to select a certificate for sites on the list defined in \"AutoSelectCertificateForUrls\" if and only if there is more than one certificate.\n\nIf you set this policy to False or don't configure it, Microsoft Edge will automatically select a certificate even if there are multiple matches for a certificate. The user will not be prompted to select a certificate for sites on the list defined in \"AutoSelectCertificateForUrls\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcecertificatepromptsonmultiplematches"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcecertificatepromptsonmultiplematches_true","displayName":"Enabled","description":null,"helpText":null}]},"8e01dbc18a96a488":{"id":"com.apple.managedclient.preferences_passwordmonitorallowed","displayName":"Allow Microsoft Edge to monitor user passwords","description":"If you enable this policy and a user consents to enabling the policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\n\nIf you disable this policy, users will not be asked for permission to enable this feature and will not be alerted. Their passwords will not be scanned.\n\nIf you disable this policy, users can't change or override the policy. However, if you enable or don't configure the policy, users can turn this feature on or off.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#passwordmonitorallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_passwordmonitorallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passwordmonitorallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"8e8f36d1cfa52728":{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled","displayName":"Enable post-quantum key agreement for TLS","description":"This policy configures whether Microsoft Edge offers a post-quantum key agreement algorithm in TLS. This lets supporting servers protect user traffic from being decrypted by quantum computers.\n\nIf you enable or don't configure this policy, Microsoft Edge offers a post-quantum key agreement in TLS connections. TLS connections are protected from quantum computers when communicating with compatible servers.\n\nIf you disable this policy, Microsoft Edge will not offer a post-quantum key agreement in TLS connections. User traffic is unprotected from decryption by quantum computers.\n\nOffering a post-quantum key agreement is backwards-compatible. Existing TLS servers and networking middleware are expected to ignore the new option and continue selecting previous options.\n\nHowever, devices that don't implement TLS correctly may malfunction when offered the new option. For example, they might disconnect in response to unrecognized options or the resulting larger messages. These devices aren't post-quantum-ready and will interfere with an enterprise's post-quantum transition. If this issue is encountered, administrators should contact the vendor for a fix.\n\nThis policy is a temporary measure and will be removed in future versions of Microsoft Edge. You can enable it to test for issues and you can disable it while you resolve issues.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#postquantumkeyagreementenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_postquantumkeyagreementenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8e2dc5bbd17b277a":{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled","displayName":"Configure Microsoft Edge Scareware blocker protection","description":"This policy setting allows administrators to control whether Microsoft Edge enables Scareware blocker, an AI-powered feature for protecting users from potential tech scams. To support this feature, Microsoft Edge downloads a machine learning model file from Microsoft to the device.\n\nIf you enable or don’t configure this policy, Microsoft Edge Scareware blocker uses local AI to detect potential tech scams.\n\nIf you disable this policy, Microsoft Edge Scareware blocker is disabled. The machine learning model file doesn't download to the device, and if downloaded deletion occurs.\n\nWhen this policy is enabled, the policies \"ScarewareBlockerBlocksDetectedSitesEnabled\", \"ScarewareBlockerSendDetectedSitesToSmartScreenEnabled\", and \"ScarewareBlockerAllowListDomains\" can be used to configure the behavior of the Scareware blocker feature. If both of those policies are disabled, enabling this policy has no effect.\n\nWhen this policy is disabled, the policies \"ScarewareBlockerBlocksDetectedSitesEnabled\", \"ScarewareBlockerSendDetectedSitesToSmartScreenEnabled\", and \"ScarewareBlockerAllowListDomains\" have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scarewareblockerprotectionenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scarewareblockerprotectionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8e8a379df57ae62b":{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype_0","displayName":"bundleID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"8eb261975e763a1b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallforcelist","displayName":"Control which extensions are installed silently","description":"Set this policy to specify a list of apps and extensions that install silently, without user interaction. Users can't uninstall or turn off this setting. Permissions are granted implicitly, including the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. Note: These two APIs aren't available to apps and extensions that aren't force-installed.\n\nIf you don't set this policy, no apps or extensions are autoinstalled and users can uninstall any app in Microsoft Edge.\n\nThis policy supersedes \"ExtensionInstallBlocklist\" policy. If a previously force-installed app or extension is removed from this list, Microsoft Edge automatically uninstalls it.\n\nFor Windows instances not joined to a Microsoft Active Directory domain, forced installation is limited to apps and extensions listed in the Microsoft Edge Add-ons website.\n\nOn macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, or joined to a domain via MCX.\n\nThe source code of any extension can be altered by users with developer tools, potentially rendering the extension unfunctional. If there's a concern, configure the \"DeveloperToolsAvailability\" policy.\n\nEach list item of the policy is a string that contains an extension ID and, optionally, and an optional \"update\" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on edge://extensions when in Developer mode. If specified, the \"update\" URL should point to an Update Manifest XML document ( https://go.microsoft.com/fwlink/?linkid=2095043 ). The update URL should use one of the following schemes: http, https, or file. By default, the Microsoft Edge Add-ons website's update URL is used. The \"update\" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest. The update url for subsequent updates can be overridden using the ExtensionSettings policy. See https://learn.microsoft.com/deployedge/microsoft-edge-manage-extensions-ref-guide.\n\nNote: This policy doesn't apply to InPrivate mode. Read about hosting extensions at [Publish and update extensions in the Microsoft Edge Add-ons website](/microsoft-edge/extensions-chromium/enterprise/hosting-and-updating).\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"8e39cec03778f554":{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride","displayName":"Prevent bypassing Edge Website Typo Protection prompts for sites","description":"This policy setting lets you decide whether users can override the Edge Website Typo Protection warnings about potential typosquatting websites.\n\nIf you enable this setting, users can't ignore Edge Website Typo Protection warnings, and they're blocked from continuing to the site.\n\nIf you disable or don't configure this setting, users can ignore Edge Website Typo Protection warnings and continue to the site.\n\nThis only takes effect when TyposquattingCheckerEnabled policy isn't set or is set to enabled.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.preventtyposquattingpromptoverride_true","displayName":"Enabled","description":null,"helpText":null}]},"8ebccf56d7238520":{"id":"device_vendor_msft_maintenancewindows_workloadtype","displayName":"Workload type","description":"Select one or more workloads for the maintenance window.","helpText":"Select one or more workloads.","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":{"id":"device_vendor_msft_maintenancewindows_workloadtype_1","displayName":"Updates","description":"Windows Updates workload","helpText":null}},"8e1be6aeb12f6a83":{"id":"device_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_personalcolors_personalcolors_accent","displayName":"Accent color:","description":null,"helpText":"","infoUrls":[],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":null},"8eaa3ec523aafee3":{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_wermaxqueuesize","displayName":"Maximum size of the queue (MB):","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"8e78c7ca4b0d50c6":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_gprefreshrateoffset2","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"8e92c54c63b7fc52":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo","displayName":"Action:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo_0","displayName":"Work offline","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_goofflineaction_2_lbl_goofflineactioncombo_1","displayName":"Never go offline","description":null,"helpText":null}]},"8ef8ca1cad09c257":{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel","displayName":"Scenario Execution Level","description":null,"helpText":"","infoUrls":[],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel_1","displayName":"Detection and Troubleshooting Only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectdeprecatedcomponentfailurespolicy_detectdeprecatedcomponentfailureslevel_2","displayName":"Detection, Troubleshooting and Resolution","description":null,"helpText":null}]},"8eaa94e0ef6d2919":{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2","displayName":"Removable Disks: Deny execute access","description":"This policy setting denies execute access to removable disks.\r\n\r\nIf you enable this policy setting, execute access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, execute access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-removabledisks-denyexecute-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_removabledisks_denyexecute_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"8e9e1388c0a62404":{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior","displayName":"Set the default behavior for AutoRun","description":"This policy setting sets the default behavior for Autorun commands.\n\n Autorun commands are generally stored in autorun.inf files. They often launch the installation program or other routines.\n\n Prior to Windows Vista, when media containing an autorun command is inserted, the system will automatically execute the program without user intervention.\n\n This creates a major security concern as code may be executed without user's knowledge. The default behavior starting with Windows Vista is to prompt the user whether autorun command is to be run. The autorun command is represented as a handler in the Autoplay dialog.\n\n If you enable this policy setting, an Administrator can change the default Windows Vista or later behavior for autorun to:\n\n a) Completely disable autorun commands, or\n b) Revert back to pre-Windows Vista behavior of automatically executing the autorun command.\n\n If you disable or not configure this policy setting, Windows Vista or later will prompt the user whether autorun command is to be run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-setdefaultautorunbehavior"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"8e2228f7c4208801":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots","displayName":"Disable taking screenshots","description":"Setting the policy to True disallows screenshots taken with keyboard shortcuts or extension APIs. Setting the policy to False allows screenshots.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disablescreenshots_1","displayName":"Enabled","description":null,"helpText":null}]},"8eecc9711f13afc9":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled","displayName":"Allow automatic sign-in to Microsoft® cloud identity providers","description":"Configures automatic user sign-in for accounts backed by a Microsoft® cloud identity provider.\r\n\r\nBy setting this policy to 1 (Enabled), users who sign into their computer with an account backed by a Microsoft® cloud identity provider (i.e., Microsoft® Azure® Active Directory® or the consumer Microsoft® account identity provider) or who have added a work or school account to Microsoft® Windows® can be signed into web properties using that identity automatically. Information pertaining to the user's device and account is transmitted to the user's cloud identity provider for each authentication event.\r\n\r\nBy setting this policy to 0 (Disabled) or leaving it unset, automatic sign-in as described above is disabled.\r\n\r\nThis feature is available starting in Microsoft® Windows® 10.\r\n\r\nNote: This policy doesn't apply to Incognito or Guest modes.","helpText":"","infoUrls":[],"categoryId":"463e6791-7d54-4964-a36b-63bbedb7d0cd","categoryName":"Microsoft Active Directory management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~activedirectorymanagement_cloudapauthenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8e335fe100da47e7":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdproxydirectory_ccdproxydirectory","displayName":"Proxy Directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f2d139ed-a314-48b7-b700-4d11adfcc309","categoryName":"Cloud Cache Service","options":null},"8e092030673716f1":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdlocations","displayName":"VHD Locations","description":"Specifies the network location where the VHD(X) files are stored.\r\n\r\nExamples:\r\n- Sinlge location: \\\\\\\r\n- Multiple locations: \\\\\\;\\\\\\\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\VHDLocations\r\nREG_SZ","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdlocations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvhdlocations_1","displayName":"Enabled","description":null,"helpText":null}]},"8e700a87bd0e6905":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles","displayName":"Allow loading of XAML files","description":"This policy setting allows you to manage the loading of Extensible Application Markup Language (XAML) files. XAML is an XML-based declarative markup language commonly used for creating rich user interfaces and graphics that take advantage of the Windows Presentation Foundation.\n\nIf you enable this policy setting and set the drop-down box to Enable, XAML files are automatically loaded inside Internet Explorer. The user cannot change this behavior. If you set the drop-down box to Prompt, the user is prompted for loading XAML files.\n\nIf you disable this policy setting, XAML files are not loaded inside Internet Explorer. The user cannot change this behavior.\n\nIf you do not configure this policy setting, the user can decide whether to load XAML files inside Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowloadingofxamlfiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowloadingofxamlfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"8e52cce460728f9e":{"id":"device_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton","displayName":"Enable End Session Button","description":"Enable/disable kiosk browser's end session button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enableendsessionbutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"device_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_0","displayName":"Disable","description":"Disable","helpText":null}]},"8eb7aa45fd688cbd":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowpku2uauthenticationrequests","displayName":"Network Security Allow PKU2U Authentication Requests","description":"Network security: Allow PKU2U authentication requests to this computer to use online identities. This policy will be turned off by default on domain joined machines. This would prevent online identities from authenticating to the domain joined machine.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_allowpku2uauthenticationrequests"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowpku2uauthenticationrequests_0","displayName":"Block","description":"Block","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowpku2uauthenticationrequests_1","displayName":"Allow","description":"Allow","helpText":null}]},"8e7690da4bebd557":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_imagesallowedforurlsdesc","displayName":"Allow images on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"8ead1f7aeaa5c7c5":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\r\n\r\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\r\n\r\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\r\n\r\nIf you disable this policy, don't enable the 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) policy, because they both deal with deleting data. If you configure both, the 'ClearBrowsingDataOnExit' policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_clearcachedimagesandfilesonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"8eb1de9e8e927a16":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_volumeactivation_l_preventtokenactivationdialogfromclosing","displayName":"Prevent Token Activation dialog from closing","description":"This policy setting allows you to prevent the Token Activation prompt for activation dialog from closing.\r\n\r\nIf you enable this policy setting, the \"Close\" button and the \"X\" button at the upper right of the dialog are suppressed. If the user proceeds with activation and fails, the buttons will be enabled the next time the dialog appears.\r\n\r\nIf you disable or do not configure this policy setting, the user may close the dialog when prompted for activation.","helpText":"","infoUrls":[],"categoryId":"712d184f-d9ac-45fc-9eea-aade3a22b55e","categoryName":"Volume Activation","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_volumeactivation_l_preventtokenactivationdialogfromclosing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_volumeactivation_l_preventtokenactivationdialogfromclosing_1","displayName":"Enabled","description":null,"helpText":null}]},"8e42e3f6201e38af":{"id":"device_vendor_msft_policy_config_printers_managedriverexclusionlist_driver_exclusionlistentry_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"8e0fa36d4dc8b27b":{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbaseddayoftheweek","displayName":"Maintenance Window Monthly Week Based Day Of The Week","description":"If the maintenance window repeat schedule is set to monthly, and set to repeat on the a specific day of a specific week, configure the specific day of the week to repeat maintenance window occurrence: 1=Sunday, 2=Monday, 3=Tuesday, 4=Wednesday, 5=Thursday, 6=Friday, 7=Saturday","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowmonthlyweekbaseddayoftheweek"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbaseddayoftheweek_1","displayName":"Sunday","description":"Sunday","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbaseddayoftheweek_2","displayName":"Monday","description":"Monday","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbaseddayoftheweek_3","displayName":"Tuesday","description":"Tuesday","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbaseddayoftheweek_4","displayName":"Wednesday","description":"Wednesday","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbaseddayoftheweek_5","displayName":"Thursday","description":"Thursday","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbaseddayoftheweek_6","displayName":"Friday","description":"Friday","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyweekbaseddayoftheweek_7","displayName":"Saturday","description":"Saturday","helpText":null}]},"8e59ad830e664e75":{"id":"device_vendor_msft_policy_config_wirelessdisplay_requirepinforpairing","displayName":"Require Pin For Pairing","description":"This policy setting allows you to require a pin for pairing. If you set this to 0, a pin isn't required for pairing. If you set this to 1, the pairing ceremony for new devices will always require a PIN. If you set this to 2, all pairings will require PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WirelessDisplay#requirepinforpairing"],"categoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","categoryName":"Wireless Display","options":[{"id":"device_vendor_msft_policy_config_wirelessdisplay_requirepinforpairing_0","displayName":"PIN is not required.","description":"PIN is not required.","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_requirepinforpairing_1","displayName":"Pairing ceremony for new devices will always require a PIN","description":"Pairing ceremony for new devices will always require a PIN","helpText":null},{"id":"device_vendor_msft_policy_config_wirelessdisplay_requirepinforpairing_2","displayName":"All pairings will require PIN","description":"All pairings will require PIN","helpText":null}]},"8e2a34e599eea728":{"id":"extensionsettings_managedextensions_generickey_alloweddomains","displayName":"Allowed Domains","description":"Controls the domains and sub-domains the extension is granted access to. Any non-prefixed domains take precedence over prefixed domains, and DeniedDomains takes precedence over AllowedDomains. Any domains not specified in AllowedDomains or DeniedDomains are configurable by the user.","helpText":null,"infoUrls":[],"categoryId":"7d9e5b9b-84e7-473c-b6ca-a1629448df55","categoryName":"Safari Extension Settings","options":null},"8e25854ebb56e60c":{"id":"plugin_filter_packets_providercomposedidentifier","displayName":"Provider Composed Identifier","description":"The packet provider identifier. This string identifies the filter data provider when the filter starts running. Required when Enabled is true.\n\nThe identifier is a composed identifier. The format of the composed identifier is \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the provider. \"Designated-Requirement\" is the designated requirement string from the code signature of the provider. For example, \"com.example.app {anchor apple generic}\".","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"8ea59e16d709e9ba":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n\r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users.","helpText":"","infoUrls":[],"categoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"8e4aef9064ca943d":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_newgpolinksdisabled","displayName":"Create new Group Policy Object links disabled by default (User)","description":"This policy setting allows you to create new Group Policy object links in the disabled state.\r\n\r\nIf you enable this setting, you can create all new Group Policy object links in the disabled state by default. After you configure and test the new object links by using a policy compliant Group Policy management tool such as Active Directory Users and Computers or Active Directory Sites and Services, you can enable the object links for use on the system.\r\n\r\nIf you disable this setting or do not configure it, new Group Policy object links are created in the enabled state. If you do not want them to be effective until they are configured and tested, you must disable the object link.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-newgpolinksdisabled"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"user_vendor_msft_policy_config_admx_grouppolicy_newgpolinksdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_grouppolicy_newgpolinksdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8ee4d47703f15bba":{"id":"user_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_1","displayName":"Do not allow Snipping Tool to run (User)","description":"Prevents the snipping tool from running.\r\n\r\nIf you enable this policy setting, the Snipping Tool will not run.\r\n\r\nIf you disable this policy setting, the Snipping Tool will run.\r\n\r\nIf you do not configure this policy setting, the Snipping Tool will run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-disablesnippingtool-1"],"categoryId":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","categoryName":"Accessories","options":[{"id":"user_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletshell_disablesnippingtool_1_1","displayName":"Enabled","description":null,"helpText":null}]},"8ef3e70480feb31e":{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_1","displayName":"Prevent launch an application (User)","description":"Prevents the user from launching an application from a Tablet PC hardware button.\r\n\r\nIf you enable this policy, applications cannot be launched from a hardware button, and \"Launch an application\" is removed from the drop down menu for configuring button actions (in the Tablet PC Control Panel buttons tab).\r\n\r\nIf you disable this policy, applications can be launched from a hardware button.\r\n\r\nIf you do not configure this policy, applications can be launched from a hardware button.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventlaunchapp-1"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_1_1","displayName":"Enabled","description":null,"helpText":null}]},"8e332dade20a147f":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016","displayName":"Microsoft Office 365 Access 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Access 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Access 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Access 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Access 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Access 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365access2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365access2016_1","displayName":"Enabled","description":null,"helpText":null}]},"8eb9b7373d2257e8":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013","displayName":"Microsoft Office 365 Publisher 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Publisher 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Publisher 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Publisher 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Publisher 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Publisher 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365publisher2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365publisher2013_1","displayName":"Enabled","description":null,"helpText":null}]},"8ea2ab6f9e4270b4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access (User)","description":"Enables the use of a default search provider on the context menu.\r\n\r\nIf you set this policy to disabled the search context menu item that relies on your default search provider will not be available.\r\n\r\nIf this policy is set to enabled or not set, the context menu item for your default search provider will be available.\r\n\r\nThe policy value is only appled when the DefaultSearchProviderEnabled policy is enabled, and is not applicable otherwise.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_defaultsearchprovidercontextmenuaccessallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"8e55643b5cdbed2a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersuggesturl_defaultsearchprovidersuggesturl","displayName":"Default search provider suggest URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"8ea6c29ac4ab6c10":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_remoteaccesshostmaximumsessiondurationminutes","displayName":"Maximum session duration allowed for remote access connections: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},"8e020a00288ed7b1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup","displayName":"Action on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_5","displayName":"Open New Tab Page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"8e0476b547bce6ca":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_windowplacementblockedforurlsdesc","displayName":"Block Window Placement permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"8eac07c2972ea8e6":{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode","displayName":"Turn on Enhanced Protected Mode (User)","description":"Enhanced Protected Mode provides additional protection against malicious websites by using 64-bit processes on 64-bit versions of Windows. For computers running at least Windows 8, Enhanced Protected Mode also limits the locations Internet Explorer can read from in the registry and the file system.\n\nIf you enable this policy setting, Enhanced Protected Mode will be turned on. Any zone that has Protected Mode enabled will use Enhanced Protected Mode. Users will not be able to disable Enhanced Protected Mode.\n\nIf you disable this policy setting, Enhanced Protected Mode will be turned off. Any zone that has Protected Mode enabled will use the version of Protected Mode introduced in Internet Explorer 7 for Windows Vista.\n\nIf you do not configure this policy, users will be able to turn on or turn off Enhanced Protected Mode on the Advanced tab of the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedprotectedmode"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowenhancedprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"8ea1f8591caa3127":{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles","displayName":"Prevent bypassing SmartScreen Filter warnings about files that are not commonly downloaded from the Internet (User)","description":"This policy setting determines whether the user can bypass warnings from SmartScreen Filter. SmartScreen Filter warns the user about executable files that Internet Explorer users do not commonly download from the Internet.\n\nIf you enable this policy setting, SmartScreen Filter warnings block the user.\n\nIf you disable or do not configure this policy setting, the user can bypass SmartScreen Filter warnings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablebypassofsmartscreenwarningsaboutuncommonfiles"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablebypassofsmartscreenwarningsaboutuncommonfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"8e47efd21597e027":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker","displayName":"Use Pop-up Blocker (User)","description":"This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.\n\nIf you enable this policy setting, most unwanted pop-up windows are prevented from appearing.\n\nIf you disable this policy setting, pop-up windows are not prevented from appearing.\n\nIf you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneusepopupblocker"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneusepopupblocker_1","displayName":"Enabled","description":null,"helpText":null}]},"8e350c04f1319ff6":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"8e3f65cd328b7fe4":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"8eb1cb59aa26d4eb":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled","displayName":"Enable spellcheck (User)","description":"If you enable or don't configure this policy, the user can use spellcheck.\r\n\r\nIf you disable this policy, the user can't use spellcheck and the 'SpellcheckLanguage' (Enable specific spellcheck languages) and 'SpellcheckLanguageBlocklist' (Force disable spellcheck languages) policies are also disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_spellcheckenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8e113d914e837044":{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled","displayName":"Allows users to translate videos to different languages. (User)","description":"This policy configures the on-device real-time video translation feature in Microsoft Edge.\r\nWith this feature, users can watch videos translated into their selected language in real time.\r\n\r\nWhen a user selects the Translate icon and chooses a source (video language) and target language (translated language),\r\ntranslation components are downloaded on first use (approximately 200 MB per language pair).\r\n\r\nThese components may be updated periodically to improve performance and translation quality.\r\nTranslation is performed locally on the user’s device and no data is sent outside of the device.\r\nThe feature is available only for non-DRM videos, on supported high-end devices, with select language pairs, and in select regions.\r\nFor more details, see https://www.microsoft.com/en-us/edge/features/real-time-video-translation.\r\n\r\nIf you enable or don’t configure this policy, the on-device real-time video translation feature is enabled and\r\nusers will see the Translate button when hovering over videos.\r\n\r\nIf you disable this policy, the on-device real-time video translation feature is disabled and the Translate button won’t be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_livevideotranslationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8efff8afd34d4697":{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_30","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"8e5ea06b04737726":{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist","displayName":"Configure the list of domains for which the password manager UI (Save and Fill) will be disabled (User)","description":"Configure the list of domains where Microsoft Edge should disable the password manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\r\n\r\nIf you enable this policy, the password manager will be disabled for the specified set of domains.\r\n\r\nIf you disable or don't configure this policy, password manager will work as usual for all domains.\r\n\r\nIf you configure this policy, that is, add domains for which password manager is blocked, users can't change or override the behavior in Microsoft Edge. In addition, users can't use password manager for those URLs.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com/\r\nhttps://login.contoso.com","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge~passwordmanager_passwordmanagerblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"8e3962cde8a23d43":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice03_l_broadcastserviceserverurl3","displayName":"Service URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"8ef8e64459d6dcbf":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel","displayName":"Disallow in Excel (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyexcel_1","displayName":"True","description":null,"helpText":null}]},"8e9ce498947b3f22":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic","displayName":"Kashmiri (Arabic) (User)","description":"Enables the editing language Kashmiri (Arabic)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_kashmiriarabic_1","displayName":"Enabled","description":null,"helpText":null}]},"8e4e7f9282cdc29d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowcachename493","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"8ed353202d884352":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16","displayName":"Escrow Key #16 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey16_1","displayName":"Enabled","description":null,"helpText":null}]},"8e2ff233113aba21":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_audioandvideo_l_rewindfromstartofparagraphbythefollowingnumberofseconds_l_rewindfromstartofparagraphbysec","displayName":"Rewind from start of paragraph by: (sec) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","categoryName":"Audio and Video","options":null},"8e6eaeed84f6ef51":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2","displayName":"Display Level 1 attachments (User)","description":"This policy setting controls whether Outlook blocks potentially dangerous attachments designated Level 1. \r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n \r\nIf you enable this policy setting, Outlook users can gain access to Level 1 file type attachments by first saving the attachments to disk and then opening them, as with Level 2 attachments. \r\n\r\nIf you disable this policy setting, Level 1 attachments do not display under any circumstances. \r\n\r\nIf you do not configure this policy setting, Outlook completely blocks access to Level 1 files, and requires users to save Level 2 files to disk before opening them.","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1attachments_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"8e1b88bd51bb80cd":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve","displayName":"Configure Simple MAPI name resolution prompt (User)","description":"This policy setting allows you to specify what occurs when a program attempts to gain access to an Address Book, using Simple MAPI.\r\n\r\nIf you enable this policy setting, you can choose whether Outlook always allows access to the Address Book, always disallows access to the Address Book, or prompts the user to specify whether to allow or disallow access to the Address Book.\r\n\r\nIf you disable or do not configure this policy setting, Outlook prompts the user to specify whether to allow or disallow access to the Address Book.","helpText":"","infoUrls":[],"categoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","categoryName":"Programmatic Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_simplemapinameresolve_1","displayName":"Enabled","description":null,"helpText":null}]},"8e9c8103456ef369":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype","displayName":"Shorten appointments and meetings (User)","description":"\r\n This policy setting allows you to shorten the default duration of appointments and meetings by a specified number of minutes. If you enable this policy setting, you can choose between the following options: End Early, Start Late, None.\r\n If you select End Early, meetings and appointments will end early by the specified number of minutes. \r\n If you select Start Late, meetings and appointments will start late by the specified number of minutes. \r\n If you select None, the default meeting duration will not be shortened. \r\n In all cases, the settings for this feature will be disabled in the Outlook Options dialog. \r\n If you don’t configure this policy setting, users can modify these settings by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_shorteneventstype_1","displayName":"Enabled","description":null,"helpText":null}]},"8e9aa78958e12fac":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},"8e8b7fdadfd51b6b":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc01_l_allowsubfolders_1","displayName":"True","description":null,"helpText":null}]},"8ec8b53cf6890ca4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting","displayName":"Rely on CSS for font formatting (User)","description":"This policy setting allows you to configure the \"Use Cascading Style Sheets (CSS) for appearance of messages\" option found under Microsoft Outlook's File tab | Outlook Options | Mail | Message format.\r\n\r\nIf you enable this policy setting, the option is checked.\r\n\r\nIf you disable or do not configure this policy setting, the option is not checked.\r\n","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_relyoncssforfontformatting_1","displayName":"Enabled","description":null,"helpText":null}]},"8e97c5dbeed12384":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_0","displayName":"Balloons on","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_2","displayName":"Comments and formatting only in balloons","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_balloons_l_empty_1","displayName":"Balloons off (revisions inline)","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/8f.json b/public/intune-definitions/8f.json index 4f2606ddf8e2..a256d7e26588 100644 --- a/public/intune-definitions/8f.json +++ b/public/intune-definitions/8f.json @@ -1 +1 @@ -{"8fe7da57862d7157":{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked","displayName":"Block setting wallpaper","description":"If 'True', the device is prevented from changing the wallpaper. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the user to set a wallpaper. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked_true","displayName":"True","description":"True","helpText":null}]},"8f36ef40ca262d30":{"id":"com.apple.cellular_apns_item_authenticationtype","displayName":"Authentication Type","description":"The authentication type for logging in.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_authenticationtype_0","displayName":"CHAP","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_authenticationtype_1","displayName":"PAP","description":null,"helpText":null}]},"8f81cba897a7103e":{"id":"com.apple.managedclient.preferences_editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\n\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#editfavoritesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_editfavoritesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_editfavoritesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8f76e20b0f84980e":{"id":"com.apple.mcxprinting_allowlocalprinters","displayName":"Allow Local Printers","description":"If true, allows printers that connect directly to a user's computer.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_allowlocalprinters_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_allowlocalprinters_true","displayName":"True","description":null,"helpText":null}]},"8f997ecae99794fc":{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"8fc2c4119e33c825":{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"8f7f91021ef0ae7b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped (Obsolete)","description":"This policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications.\n\nThis policy stopped working in Microsoft Edge version 107 and was obsoleted in Microsoft Edge 110.\n\nThe display-capture permissions-policy gates access to getDisplayMedia(),\nas per this spec:\nhttps://www.w3.org/TR/screen-capture/#feature-policy-integration\nHowever, if this policy is Disabled, this requirement isn't enforced,\nand getDisplayMedia() is allowed from contexts that would otherwise be\nforbidden.\n\nIf you enable or don't configure this policy, sites can only call getDisplayMedia() from\ncontexts that are allowlisted by the display-capture permissions-policy.\n\nIf you disable this policy, sites can call getDisplayMedia() even from contexts\nwhich are not allowlisted by the display-capture permissions policy.\nOther restrictions may still apply.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8f492b084c9f8aef":{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\n\nThe Picture in Picture floating overlay button lets the user watch videos in a floating window on top of other windows.\n\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\n\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8f24378c775659b6":{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled","displayName":"Enable search suggestions","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\n\nIf you enable this policy, web search suggestions are used.\n\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\n\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8fde5de1ea9dd643":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_excludedidlist_groupid","displayName":"Excluded Devices","description":"The group(s) that the policy will not be applied to.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},"8feb3bc96a1fc34c":{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback","displayName":"Turn off SwitchBack Compatibility Engine","description":"The policy controls the state of the Switchback compatibility engine in the system. \r\n\r\nSwitchback is a mechanism that provides generic compatibility mitigations to older applications by providing older behavior to old applications and new behavior to new applications. \r\n\r\nSwitchback is on by default.\r\n\r\nIf you enable this policy setting, Switchback will be turned off. Turning Switchback off may degrade the compatibility of older applications. This option is useful for server administrators who require performance and are aware of compatibility of the applications they are using. \r\n\r\nIf you disable or do not configure this policy setting, the Switchback will be turned on.\r\n\r\nPlease reboot the system after changing the setting to ensure that your system accurately reflects those changes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffswitchback"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback_1","displayName":"Enabled","description":null,"helpText":null}]},"8f6c065757baf83f":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},"8feeba6772dfa62c":{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l","displayName":"Local Link to Local Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l_1","displayName":"True","description":null,"helpText":null}]},"8fca9a1adc337dd7":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths","displayName":"Path Exclusions","description":"This policy setting allows you to disable scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: \"c:\\Windows\" to exclude all files in this directory. A fully qualified resource name might be defined as: \"C:\\Windows\\App.exe\". The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-paths"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_1","displayName":"Enabled","description":null,"helpText":null}]},"8f7168522ed5e7c7":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications","displayName":"Turn off enhanced notifications","description":"\r\n Use this policy setting to specify if you want Microsoft Defender Antivirus enhanced notifications to display on clients.\r\n \r\n If you disable or do not configure this setting, Microsoft Defender Antivirus enhanced notifications will display on clients.\r\n \r\n If you enable this setting, Microsoft Defender Antivirus enhanced notifications will not display on clients.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-disableenhancednotifications"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"8fd9e87d704fdc60":{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi","displayName":"Turn off Windows Installer","description":"This policy setting restricts the use of Windows Installer.\r\n\r\nIf you enable this policy setting, you can prevent users from installing software on their systems or permit users to install only those programs offered by a system administrator. You can use the options in the Disable Windows Installer box to establish an installation setting.\r\n\r\n-- The \"Never\" option indicates Windows Installer is fully enabled. Users can install and upgrade software. This is the default behavior for Windows Installer on Windows 2000 Professional, Windows XP Professional and Windows Vista when the policy is not configured.\r\n\r\n-- The \"For non-managed applications only\" option permits users to install only those programs that a system administrator assigns (offers on the desktop) or publishes (adds them to Add or Remove Programs). This is the default behavior of Windows Installer on Windows Server 2003 family when the policy is not configured.\r\n\r\n-- The \"Always\" option indicates that Windows Installer is disabled.\r\n\r\nThis policy setting affects Windows Installer only. It does not prevent users from using other methods to install and upgrade programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablemsi"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_1","displayName":"Enabled","description":null,"helpText":null}]},"8f993c70ba623dff":{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc","displayName":"Allow applications to prevent automatic sleep (on battery)","description":"This policy setting allows applications and services to prevent automatic sleep.\r\n\r\nIf you enable this policy setting, any application, service, or device driver prevents Windows from automatically transitioning to sleep after a period of user inactivity.\r\n\r\nIf you disable or do not configure this policy setting, applications, services, or drivers do not prevent Windows from automatically transitioning to sleep. Only user input is used to determine if Windows should automatically sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystempowerrequestdc"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc_1","displayName":"Enabled","description":null,"helpText":null}]},"8f67e3ef5c502e38":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_resolvepeerbackoffmaxtimes","displayName":"ResolvePeerBackoffMaxTimes","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},"8f0a7df8a919670b":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-internet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet_1","displayName":"Enabled","description":null,"helpText":null}]},"8fd6a486a309ea1f":{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock","displayName":"Allow Developer Unlock","description":"Specifies whether developer unlock is allowed. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowdeveloperunlock"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_0","displayName":"Explicit deny.","description":"Explicit deny.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_1","displayName":"Explicit allow unlock.","description":"Explicit allow unlock.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_65535","displayName":"Not configured.","description":"Not configured.","helpText":null}]},"8fb652fba3a7e9ad":{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata","displayName":"Allow Shared User App Data","description":"With this policy, you can configure Windows 10 to share application data among multiple users on the system and with other instances of that app. Data shared through the SharedLocal folder is available through the Windows. Storage API. If you previously enabled this policy and now want to disable it, any shared app data remains in the SharedLocal folder.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowshareduserappdata"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata_0","displayName":"Block","description":"Prevented/not allowed, but Microsoft Edge downloads book files to a per-user folder for each user.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata_1","displayName":"Allow","description":"Allowed. Microsoft Edge downloads book files into a shared folder. For this policy to work correctly, you must also enable the Allow a Windows app to share application data between users group policy. Also, the users must be signed in with a school or work account.","helpText":null}]},"8fbb409c06ec4fba":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled","displayName":"Allow the audio sandbox to run","description":"This policy controls the audio process sandbox.\r\nIf this policy is enabled, the audio process will run sandboxed.\r\nIf this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\nIf this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform.\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8fd813f25f40300d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank","description":"Setting the policy to Disabled allows popups targeting _blank to access (via JavaScript) the page that requested to open the popup.\r\n\r\nSetting the policy to Enabled or leaving it unset causes the window.opener property to be set to null unless the anchor specifies rel=\"opener\".\r\n\r\nThis policy will be removed in Google Chrome version 95.\r\n\r\nSee https://chromestatus.com/feature/6140064063029248.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},"8febc42b53eb345f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_insecurecontentblockedforurlsdesc","displayName":"Block insecure content on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"8f905e27218f234b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. Unset policy is treated as no restriction.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_1","displayName":"Enabled","description":null,"helpText":null}]},"8f346a9f97217893":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls_automaticfullscreenblockedforurlsdesc","displayName":"Block automatic fullscreen on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"8f844f2fabffe446":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled","displayName":"Allow users to select cast devices with an access code or QR code from within the Google Cast menu.","description":"This policy controls whether a user will be presented with an option, within the Google Cast menu which allows them to cast to cast devices that do not appear in the Google Cast menu, using either the access code or QR code displayed on the cast devices's screen.\r\nBy default, a user must reenter the access code or rescan the QR code in order to initiate a subsequent casting session, but if the AccessCodeCastDeviceDuration policy has been set to a non-zero value (the default is zero), then the cast device will remain in the list of available cast devices until the specified period of time has expired.\r\nWhen this policy is set to Enabled, users will be presented with the option to select cast devices by using an access code or by scanning a QR code.\r\nWhen this policy is set to Disabled or not set, users will not be given the option to select cast devices by using an access code or by scanning a QR code.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f4e3c854d997eed":{"id":"device_vendor_msft_policy_config_defender_cloudextendedtimeout","displayName":"Cloud Extended Timeout","description":"This feature allows Windows Defender Antivirus to block a suspicious file for up to 60 seconds, and scan it in the cloud to make sure it's safe. Value type is integer, range is 0 - 50. The typical cloud check timeout is 10 seconds. To enable the extended cloud check feature, specify the extended time in seconds, up to an additional 50 seconds. For example, if the desired timeout is 60 seconds, specify 50 seconds in this setting, which will enable the extended cloud check feature, and will raise the total time to 60 seconds. NoteThis feature depends on three other MAPS settings the must all be enabled- Configure the 'Block at First Sight' feature; Join Microsoft MAPS; Send file samples when further analysis is required.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"8fc4f55745a82e70":{"id":"device_vendor_msft_policy_config_deliveryoptimization_domaxcacheage","displayName":"DO Max Cache Age","description":"Specifies the maximum time in seconds that each file is held in the Delivery Optimization cache after downloading successfully.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#domaxcacheage"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"8f08ae7d4d615c1c":{"id":"device_vendor_msft_policy_config_filesystem_devdriveattachpolicy","displayName":"Dev drive filter attach policy","description":"Dev drive is a drive optimized for performance considering developer scenarios and by default no file system filters are attached to it. Filters listed in this setting will be allowed to attach even on a dev drive.\r\n\r\nA reboot is required for this setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-filesystem#filesystem-devdriveattachpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_filesystem_devdriveattachpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_filesystem_devdriveattachpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"8f4e04a8f57442c3":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath_0","displayName":"Take no action","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath_1","displayName":"Redirect TEMP and TMP to local drive","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath_2","displayName":"Redirect INetCache to local drive","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath_3","displayName":"Redirect TEMP, TMP and INetCache to local drive","description":null,"helpText":null}]},"8f1ff06320cddaff":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"8f3d7fb2f1403a51":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"8fc776be56cfa1b7":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel","displayName":"Network Security LAN Manager Authentication Level","description":"Network security LAN Manager authentication level This security setting determines which challenge/response authentication protocol is used for network logons. This choice affects the level of authentication protocol used by clients, the level of session security negotiated, and the level of authentication accepted by servers as follows: Send LM and NTLM responses: Clients use LM and NTLM authentication and never use NTLMv2 session security; domain controllers accept LM, NTLM, and NTLMv2 authentication. Send LM and NTLM - use NTLMv2 session security if negotiated: Clients use LM and NTLM authentication and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication. Send NTLM response only: Clients use NTLM authentication only and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication. Send NTLMv2 response only: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication. Send NTLMv2 response only\\refuse LM: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers refuse LM (accept only NTLM and NTLMv2 authentication). Send NTLMv2 response only\\refuse LM and NTLM: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers refuse LM and NTLM (accept only NTLMv2 authentication). Important This setting can affect the ability of computers running Windows 2000 Server, Windows 2000 Professional, Windows XP Professional, and the Windows Server 2003 family to communicate with computers running Windows NT 4.0 and earlier over the network. For example, at the time of this writing, computers running Windows NT 4.0 SP4 and earlier did not support NTLMv2. Computers running Windows 95 and Windows 98 did not support NTLM. Default: Windows 2000 and windows XP: send LM and NTLM responses Windows Server 2003: Send NTLM response only Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: Send NTLMv2 response only","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_lanmanagerauthenticationlevel"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_0","displayName":"Send LM and NTLM responses","description":"Send LM and NTLM responses","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_1","displayName":"Send LM and NTLM-use NTLMv2 session security if negotiated","description":"Send LM and NTLM-use NTLMv2 session security if negotiated","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_2","displayName":"Send LM and NTLM responses only","description":"Send LM and NTLM responses only","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_3","displayName":"Send LM and NTLMv2 responses only","description":"Send LM and NTLMv2 responses only","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_4","displayName":"Send LM and NTLMv2 responses only. Refuse LM","description":"Send LM and NTLMv2 responses only. Refuse LM","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_5","displayName":"Send LM and NTLMv2 responses only. Refuse LM and NTLM","description":"Send LM and NTLMv2 responses only. Refuse LM and NTLM","helpText":null}]},"8fb38d1b0604e484":{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup","displayName":"access group","description":"This Setting allows an administrator to manage local groups on a Device. Possible settings: 1. Update Group Membership: Update a group and add and/or remove members though the 'U' action. When using Update, existing group members that are not specified in the policy remain untouched. 2. Replace Group Membership: Restrict a group by replacing group membership through the 'R' action. When using Replace, existing group membership is replaced by the list of members specified in the add member section. This option works in the same way as a Restricted Group and any group members that are not specified in the policy are removed. Caution: If the same group is configured with both Replace and Update, then Replace will win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups"],"categoryId":"b86100f0-e4ae-4f93-9dae-dd253a96726f","categoryName":null,"options":null},"8f4041700e5dd7eb":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton","displayName":"Show Home button on toolbar","description":"Shows the Home button on Microsoft Edge's toolbar.\r\n\r\nEnable this policy to always show the Home button. Disable it to never show the button.\r\n\r\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton_1","displayName":"Enabled","description":null,"helpText":null}]},"8fa207bcc126526e":{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_1","displayName":"Enabled","description":null,"helpText":null}]},"8f0bb44a94d27307":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls","displayName":"Allow idle detection on these sites","description":"Allows you to specify a list of URL patterns for sites that are allowed to use the Idle Detection API.\r\n\r\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\r\n\r\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported. For detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=209532.\r\n\r\nURL patterns specified in the blocklist take precedence over this allowlist. This allowlist takes precedence over the DefaultIdleDetectionSetting policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"8ffcceda08c00d7a":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled","displayName":"Show Hubs Sidebar","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f31275b6f9ee359":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_spdesignexe79","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_spdesignexe79_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_spdesignexe79_1","displayName":"True","description":null,"helpText":null}]},"8f0d1e85968bfc3c":{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_granularfeedbackcontrol_receivesurveys_checkbox","displayName":"Receive user satisfication surveys (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_granularfeedbackcontrol_receivesurveys_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_granularfeedbackcontrol_receivesurveys_checkbox_1","displayName":"True","description":null,"helpText":null}]},"8f322f96065dde8b":{"id":"device_vendor_msft_policy_config_privacy_letappssyncwithdevices_forceallowtheseapps","displayName":"Let Apps Sync With Devices Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will be allowed to communicate with unpaired wireless devices. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappssyncwithdevices_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"8fa39dff8aafcb71":{"id":"device_vendor_msft_policy_config_remoteassistance_customizewarningmessages_ra_options_share_control_message","displayName":"Display warning message before sharing control:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":null},"8f6e8ded51d3ab7d":{"id":"device_vendor_msft_policy_config_start_importedgeassets","displayName":"Import Edge Assets","description":"This policy setting allows you to import Edge assets to be used with StartLayout policy. Start layout can contain secondary tile from Edge app which looks for Edge local asset file. Edge local asset would not exist and cause Edge secondary tile to appear empty in this case. This policy only gets applied when StartLayout policy is modified.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#importedgeassets"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":null},"8fbd08808278bb1c":{"id":"device_vendor_msft_policy_config_update_allowupdateservice","displayName":"Allow Update Service","description":"Specifies whether the device could use Microsoft Update, Windows Server Update Services (WSUS), or Microsoft Store. Even when Windows Update is configured to receive updates from an intranet update service, it will periodically retrieve information from the public Windows Update service to enable future connections to Windows Update, and other services like Microsoft Update or the Microsoft Store. Enabling this policy will disable that functionality, and may cause connection to public services such as the Microsoft Store to stop working. Note This policy applies only when the desktop or device is configured to connect to an intranet update service using the Specify intranet Microsoft update service location policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#allowupdateservice"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_allowupdateservice_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowupdateservice_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"8f7aeaf467728cbf":{"id":"device_vendor_msft_policy_config_windowsai_disableagentworkspaces","displayName":"Disable Agent Workspaces (Windows Insiders only)","description":"Enable or Disable Agent Workspaces.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableagentworkspaces"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_disableagentworkspaces_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableagentworkspaces_1","displayName":"Force Enable.","description":"Force Enable.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableagentworkspaces_2","displayName":"Force Disable.","description":"Force Disable.","helpText":null}]},"8febf0a1ceccabaa":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},"8f722c6a36dfb265":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon45","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"8f2bb74ae993098c":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_admincomponents_title_sz_atc_admindeleteitem","displayName":"Enter URL(s) of desktop item(s) to Delete (space separated): (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":null},"8ff0cfbe12afe588":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdisable_1","displayName":"Disable Windows Error Reporting (User)","description":"This policy setting turns off Windows Error Reporting, so that reports are not collected or sent to either Microsoft or internal servers within your organization when software unexpectedly stops working or fails.\r\n\r\nIf you enable this policy setting, Windows Error Reporting does not send any problem information to Microsoft. Additionally, solution information is not available in Security and Maintenance in Control Panel.\r\n\r\nIf you disable or do not configure this policy setting, the Turn off Windows Error Reporting policy setting in Computer Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings takes precedence. If Turn off Windows Error Reporting is also either disabled or not configured, user settings in Control Panel for Windows Error Reporting are applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werdisable-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdisable_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdisable_1_1","displayName":"Enabled","description":null,"helpText":null}]},"8fd00f537f307bee":{"id":"user_vendor_msft_policy_config_admx_startmenu_nopinnedprograms","displayName":"Remove pinned programs list from the Start Menu (User)","description":"If you enable this setting, the \"Pinned Programs\" list is removed from the Start menu. Users cannot pin programs to the Start menu. \r\n\r\nIn Windows XP and Windows Vista, the Internet and email checkboxes are removed from the 'Customize Start Menu' dialog. \r\n\r\nIf you disable this setting or do not configure it, the \"Pinned Programs\" list remains on the Start menu. Users can pin and unpin programs in the Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nopinnedprograms"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nopinnedprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nopinnedprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"8f2597ab66acad40":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup","displayName":"Project 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Project 2013.\r\nMicrosoft Project 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Project 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Project 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Project 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013projectbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"8f22f005412c2292":{"id":"user_vendor_msft_policy_config_attachmentmanager_donotpreservezoneinformation","displayName":"Do not preserve zone information in file attachments (User)","description":"This policy setting allows you to manage whether Windows marks file attachments with information about their zone of origin (such as restricted, Internet, intranet, local). This requires NTFS in order to function correctly, and will fail without notice on FAT32. By not preserving the zone information, Windows cannot make proper risk assessments.\n\nIf you enable this policy setting, Windows does not mark file attachments with their zone information.\n\nIf you disable this policy setting, Windows marks file attachments with their zone information.\n\nIf you do not configure this policy setting, Windows marks file attachments with their zone information.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-attachmentmanager#attachmentmanager-donotpreservezoneinformation"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_attachmentmanager_donotpreservezoneinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_attachmentmanager_donotpreservezoneinformation_1","displayName":"Enabled","description":null,"helpText":null}]},"8ff40ac76e7bc86d":{"id":"user_vendor_msft_policy_config_browser_homepages","displayName":"Home Pages (User)","description":"When you enable the Configure Open Microsoft Edge With policy, you can configure one or more Start pages. When you enable this policy, users are not allowed to make changes to their Start pages. If enabled, you must include URLs to the pages, separating multiple pages using angle brackets in the following format: If disabled or not configured, the webpages specified in App settings loads as the default Start pages. Version 1703 or later: If you do not want to send traffic to Microsoft, enable this policy and use the value, which honors domain- and non-domain-joined devices, when it is the only configured URL. Version 1809: If enabled, and you select either Start page, New Tab page, or previous page in the Configure Open Microsoft Edge With policy, Microsoft Edge ignores the Configure Start Pages policy. If not configured or you set the Configure Open Microsoft Edge With policy to a specific page or pages, Microsoft Edge uses the Configure Start Pages policy. Supported devices: Domain-joined or MDM-enrolled Related policy: - Configure Open Microsoft Edge With - Disable Lockdown of Start Pages","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#homepages"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"8f0636068636db9d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability","displayName":"Profile picker availability on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_0","displayName":"Profile picker available at startup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_1","displayName":"Profile picker disabled at startup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_2","displayName":"Profile picker forced at startup","description":null,"helpText":null}]},"8f295faf7271d5f0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_1","displayName":"Enabled","description":null,"helpText":null}]},"8f05dd3029bef3b6":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources","displayName":"Configure extension, app, and user script install sources (User)","description":"Setting the policy specifies which URLs may install extensions, apps, and themes. Before Google Chrome 21, users could click on a link to a *.crx file, and Google Chrome would offer to install the file after a few warnings. Afterwards, such files must be downloaded and dragged to the Google Chrome settings page. This setting allows specific URLs to have the old, easier installation flow.\r\n\r\nEach item in this list is an extension-style match pattern (see https://developer.chrome.com/extensions/match_patterns). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (the referrer) must be allowed by these patterns.\r\n\r\nExtensionInstallBlocklist takes precedence over this policy. That is, an extension on the blocklist won't be installed, even if it happens from a site on this list.\r\n\r\nExample value:\r\n\r\nhttps://corp.mycompany.com/*","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_1","displayName":"Enabled","description":null,"helpText":null}]},"8f9db0c1bbcf8560":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled","displayName":"Specifies whether in-product Google Chrome surveys are shown to users. (User)","description":"Google Chrome in-product surveys collect user feedback for the browser. Survey responses are not associated with user accounts.\r\nWhen this policy is Enabled or not set, in-product surveys may be shown to users.\r\nWhen this policy is Disabled, in-product surveys are not shown to users.\r\n\r\nThis policy has no effect if MetricsReportingEnabled is set to Disabled, which disables in-product surveys as well.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f4454a443c77d4d":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled","displayName":"Enable sharing user credentials with other users (User)","description":"Setting the policy to Enabled lets users send to and receive from family members (according to Family Service) their passwords.\r\nWhen the policy is Enabled or not set, there is a button in the Password Manager allowing to send a password.\r\nThe received passwords are stored into user's account and are available in the Password Manager.\r\n\r\nSetting the policy to Disabled means users can't send passwords from Password Manager to other users, and can't receive passwords from other users.\r\n\r\nThe feature is not available if synchronization of Passwords is turned off (either via user settings or SyncDisabled policy is Enabled).\r\n\r\nManaged accounts aren't eligible to join or create a family group and therefore cannot share passwords.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f72b72baa0ac2e7":{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled","displayName":"Enable CryptoWallet feature (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 128.\r\n\r\nThis policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There is no replacement for this policy.\r\n Enables CryptoWallet feature in Microsoft Edge.\r\n\r\n If you enable this policy or don't configure it, users can use CryptoWallet feature which allows users to securely store, manage and transact digital assets such as Bitcoin, Ethereum and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature.\r\n\r\n If you disable this policy, users can't use CryptoWallet feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f2126048bce2745":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_2","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_3","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},"8f81e9b132ecd608":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled","displayName":"Allow the audio process to run with priority above normal on Windows (User)","description":"This policy controls the priority of the audio process on Windows.\r\nIf this policy is enabled, the audio process will run with above normal priority.\r\nIf this policy is disabled, the audio process will run with normal priority.\r\nIf this policy is not configured, the default configuration for the audio process will be used.\r\nThis policy is intended as a temporary measure to give enterprises the ability to\r\nrun audio with higher priority to address certain performance issues with audio capture.\r\nThis policy will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f0a8205fe287be8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverdescription6","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"8f872f1cf9b5f17e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations","displayName":"Allow roaming of all user customizations (User)","description":"This policy setting allows roaming of both the Quick Access Toolbar and Ribbon customizations. \r\n\r\nIf you enable this policy setting, users' Quick Access Toolbar and Ribbon customizations will be available to them on any computer on their network when they log on. \r\n\r\nIf you disable or do not configure this policy setting, users' Quick Access Toolbar and Ribbon customizations will only be available to them on the computer on which they made the customizations.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations_1","displayName":"Enabled","description":null,"helpText":null}]},"8f23053317e3d473":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_l_empty420","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":null},"8f18ad227191dc0a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary_l_setupdateintervalforoutlookcontactsdictionaryspinid","displayName":"(in minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},"8f326e033144c4ed":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion","displayName":"Do not expand Contact Groups (User)","description":"This policy setting controls whether Outlook users can expand Contact Groups when addressing e-mail messages. \r\n\r\nIf you enable this policy setting, Outlook users cannot expand Contact Groups. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook users add a Contact Group to the To, CC, or BCC fields of an e-mail message or other item, they can expand the Contact Group to see the e-mail addresses of everyone in the group.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion_1","displayName":"Enabled","description":null,"helpText":null}]},"8f6001df236b5386":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9","displayName":"Options (User)","description":"Sets the value in the option \"Publish [] month(s) of Calendar free/busy information on the server\".","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_1","displayName":"Enabled","description":null,"helpText":null}]},"8f8e10221c599c13":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies","displayName":"Do not automatically sign replies (User)","description":"This policy setting allows you to specify whether replies will be automatically signed.\r\n\r\nIf you enable this policy setting, the option to respond automatically to a signed message with a signed response will be overridden, and an unsigned response will be the default reply to a signed message.\r\n\r\nIf you disable or do not configure this policy setting, a signed response will be the default reply to a signed message.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies_1","displayName":"Enabled","description":null,"helpText":null}]},"8fa182a15cfdfa8f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins, or specify the file name of PowerPoint add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\PowerPoint\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\PowerPoint\\Addins.\r\n\r\nTo obtain the file name of an add-in, click the File menu in the application where the add-in is installed. Click Options, click Add-ins, and then use the Location column to determine the file name of the add-in.\r\n\r\nYou can also obtain the ProgID or the file name of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},"8fe0c142d1bcec43":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters","displayName":"Graphic Filters (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_1","displayName":"Enabled","description":null,"helpText":null}]},"8fbeb67f84f8055a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"8fef9aa320104a32":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy","displayName":"Add control characters in Cut and Copy (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy_1","displayName":"Enabled","description":null,"helpText":null}]},"8f821f8fee1e05da":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries","displayName":"Show text boundaries (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"8fe7da57862d7157":{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked","displayName":"Block setting wallpaper","description":"If 'True', the device is prevented from changing the wallpaper. If 'False', Intune doesn't change or update this setting. By default, the OS might allow the user to set a wallpaper. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.setwallpaperblocked_true","displayName":"True","description":"True","helpText":null}]},"8f36ef40ca262d30":{"id":"com.apple.cellular_apns_item_authenticationtype","displayName":"Authentication Type","description":"The authentication type for logging in.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_authenticationtype_0","displayName":"CHAP","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_authenticationtype_1","displayName":"PAP","description":null,"helpText":null}]},"8f81cba897a7103e":{"id":"com.apple.managedclient.preferences_editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\n\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#editfavoritesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_editfavoritesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_editfavoritesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8f76e20b0f84980e":{"id":"com.apple.mcxprinting_allowlocalprinters","displayName":"Allow Local Printers","description":"If true, allows printers that connect directly to a user's computer.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_allowlocalprinters_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_allowlocalprinters_true","displayName":"True","description":null,"helpText":null}]},"8f997ecae99794fc":{"id":"com.apple.tcc.configuration-profile-policy_services_appleevents_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"8fc2c4119e33c825":{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_fileproviderpresence_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"8f7f91021ef0ae7b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled","displayName":"Specifies whether the display-capture permissions-policy is checked or skipped (Obsolete)","description":"This policy is obsolete. The policy was a temporary workaround for non-spec-compliant enterprise applications.\n\nThis policy stopped working in Microsoft Edge version 107 and was obsoleted in Microsoft Edge 110.\n\nThe display-capture permissions-policy gates access to getDisplayMedia(),\nas per this spec:\nhttps://www.w3.org/TR/screen-capture/#feature-policy-integration\nHowever, if this policy is Disabled, this requirement isn't enforced,\nand getDisplayMedia() is allowed from contexts that would otherwise be\nforbidden.\n\nIf you enable or don't configure this policy, sites can only call getDisplayMedia() from\ncontexts that are allowlisted by the display-capture permissions-policy.\n\nIf you disable this policy, sites can call getDisplayMedia() even from contexts\nwhich are not allowlisted by the display-capture permissions policy.\nOther restrictions may still apply.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.displaycapturepermissionspolicyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8f492b084c9f8aef":{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled","displayName":"Enable Picture in Picture overlay feature on supported webpages in Microsoft Edge","description":"This policy lets you configure the Picture in Picture floating overlay button in Microsoft Edge.\n\nThe Picture in Picture floating overlay button lets the user watch videos in a floating window on top of other windows.\n\nIf you enable or don't configure this policy, you can use the Picture in Picture floating overlay button in Microsoft Edge.\n\nIf you disable this policy, you can't use the Picture in Picture floating overlay button in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.pictureinpictureoverlayenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8f24378c775659b6":{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled","displayName":"Enable search suggestions","description":"Enables web search suggestions in Microsoft Edge's Address Bar and Auto-Suggest List and prevents users from changing this policy.\n\nIf you enable this policy, web search suggestions are used.\n\nIf you disable this policy, web search suggestions are never used, however local history and local favorites suggestions still appear. If you disable this policy, neither the typed characters, nor the URLs visited will be included in telemetry to Microsoft.\n\nIf this policy is left not set, search suggestions are enabled but the user can change that.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.searchsuggestenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"8ff038a97acba669":{"id":"contentcaching_autoenabletetheredcaching","displayName":"Auto Enable Tethered Caching","description":"If `true`, the system automatically enables Internet connection sharing when possible and prevent disabling Internet connection sharing. `DenyTetheredCaching` overrides `AutoEnableTetheredCaching`. Tethered caching requires Content Caching.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_autoenabletetheredcaching_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_autoenabletetheredcaching_true","displayName":"Enabled","description":null,"helpText":null}]},"8fde5de1ea9dd643":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_excludedidlist_groupid","displayName":"Excluded Devices","description":"The group(s) that the policy will not be applied to.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},"8feb3bc96a1fc34c":{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback","displayName":"Turn off SwitchBack Compatibility Engine","description":"The policy controls the state of the Switchback compatibility engine in the system. \r\n\r\nSwitchback is a mechanism that provides generic compatibility mitigations to older applications by providing older behavior to old applications and new behavior to new applications. \r\n\r\nSwitchback is on by default.\r\n\r\nIf you enable this policy setting, Switchback will be turned off. Turning Switchback off may degrade the compatibility of older applications. This option is useful for server administrators who require performance and are aware of compatibility of the applications they are using. \r\n\r\nIf you disable or do not configure this policy setting, the Switchback will be turned on.\r\n\r\nPlease reboot the system after changing the setting to ensure that your system accurately reflects those changes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffswitchback"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffswitchback_1","displayName":"Enabled","description":null,"helpText":null}]},"8f6c065757baf83f":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit","displayName":"Normal Priority Unit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_1","displayName":"Kbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_2","displayName":"Mbps","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancenormalpriorityunit_3","displayName":"Unlimited","description":null,"helpText":null}]},"8feeba6772dfa62c":{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l","displayName":"Local Link to Local Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassl2l_1","displayName":"True","description":null,"helpText":null}]},"8fca9a1adc337dd7":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths","displayName":"Path Exclusions","description":"This policy setting allows you to disable scheduled and real-time scanning for files under the paths specified or for the fully qualified resources specified. Paths should be added under the Options for this setting. Each entry must be listed as a name value pair, where the name should be a string representation of a path or a fully qualified resource name. As an example, a path might be defined as: \"c:\\Windows\" to exclude all files in this directory. A fully qualified resource name might be defined as: \"C:\\Windows\\App.exe\". The value is not used and it is recommended that this be set to 0.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-exclusions-paths"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exclusions_paths_1","displayName":"Enabled","description":null,"helpText":null}]},"8f7168522ed5e7c7":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications","displayName":"Turn off enhanced notifications","description":"\r\n Use this policy setting to specify if you want Microsoft Defender Antivirus enhanced notifications to display on clients.\r\n \r\n If you disable or do not configure this setting, Microsoft Defender Antivirus enhanced notifications will display on clients.\r\n \r\n If you enable this setting, Microsoft Defender Antivirus enhanced notifications will not display on clients.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-reporting-disableenhancednotifications"],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_disableenhancednotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"8fd9e87d704fdc60":{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi","displayName":"Turn off Windows Installer","description":"This policy setting restricts the use of Windows Installer.\r\n\r\nIf you enable this policy setting, you can prevent users from installing software on their systems or permit users to install only those programs offered by a system administrator. You can use the options in the Disable Windows Installer box to establish an installation setting.\r\n\r\n-- The \"Never\" option indicates Windows Installer is fully enabled. Users can install and upgrade software. This is the default behavior for Windows Installer on Windows 2000 Professional, Windows XP Professional and Windows Vista when the policy is not configured.\r\n\r\n-- The \"For non-managed applications only\" option permits users to install only those programs that a system administrator assigns (offers on the desktop) or publishes (adds them to Add or Remove Programs). This is the default behavior of Windows Installer on Windows Server 2003 family when the policy is not configured.\r\n\r\n-- The \"Always\" option indicates that Windows Installer is disabled.\r\n\r\nThis policy setting affects Windows Installer only. It does not prevent users from using other methods to install and upgrade programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablemsi"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disablemsi_1","displayName":"Enabled","description":null,"helpText":null}]},"8f993c70ba623dff":{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc","displayName":"Allow applications to prevent automatic sleep (on battery)","description":"This policy setting allows applications and services to prevent automatic sleep.\r\n\r\nIf you enable this policy setting, any application, service, or device driver prevents Windows from automatically transitioning to sleep after a period of user inactivity.\r\n\r\nIf you disable or do not configure this policy setting, applications, services, or drivers do not prevent Windows from automatically transitioning to sleep. Only user input is used to determine if Windows should automatically sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystempowerrequestdc"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestdc_1","displayName":"Enabled","description":null,"helpText":null}]},"8f67e3ef5c502e38":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_resolvepeerbackoffmaxtimes","displayName":"ResolvePeerBackoffMaxTimes","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},"8f0a7df8a919670b":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-internet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internet_1","displayName":"Enabled","description":null,"helpText":null}]},"8fd6a486a309ea1f":{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock","displayName":"Allow Developer Unlock","description":"Specifies whether developer unlock is allowed. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowdeveloperunlock"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_0","displayName":"Explicit deny.","description":"Explicit deny.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_1","displayName":"Explicit allow unlock.","description":"Explicit allow unlock.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowdeveloperunlock_65535","displayName":"Not configured.","description":"Not configured.","helpText":null}]},"8fb652fba3a7e9ad":{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata","displayName":"Allow Shared User App Data","description":"With this policy, you can configure Windows 10 to share application data among multiple users on the system and with other instances of that app. Data shared through the SharedLocal folder is available through the Windows. Storage API. If you previously enabled this policy and now want to disable it, any shared app data remains in the SharedLocal folder.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#allowshareduserappdata"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata_0","displayName":"Block","description":"Prevented/not allowed, but Microsoft Edge downloads book files to a per-user folder for each user.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_allowshareduserappdata_1","displayName":"Allow","description":"Allowed. Microsoft Edge downloads book files into a shared folder. For this policy to work correctly, you must also enable the Allow a Windows app to share application data between users group policy. Also, the users must be signed in with a school or work account.","helpText":null}]},"8fbb409c06ec4fba":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled","displayName":"Allow the audio sandbox to run","description":"This policy controls the audio process sandbox.\r\nIf this policy is enabled, the audio process will run sandboxed.\r\nIf this policy is disabled, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\r\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\r\nIf this policy is not set, the default configuration for the audio sandbox will be used, which may differ per platform.\r\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiosandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8fd813f25f40300d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank","description":"Setting the policy to Disabled allows popups targeting _blank to access (via JavaScript) the page that requested to open the popup.\r\n\r\nSetting the policy to Enabled or leaving it unset causes the window.opener property to be set to null unless the anchor specifies rel=\"opener\".\r\n\r\nThis policy will be removed in Google Chrome version 95.\r\n\r\nSee https://chromestatus.com/feature/6140064063029248.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},"8febc42b53eb345f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_insecurecontentblockedforurlsdesc","displayName":"Block insecure content on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"8f905e27218f234b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. Unset policy is treated as no restriction.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingallowedbackgroundgraphicsmodes_1","displayName":"Enabled","description":null,"helpText":null}]},"8f346a9f97217893":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_automaticfullscreenblockedforurls_automaticfullscreenblockedforurlsdesc","displayName":"Block automatic fullscreen on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"8f844f2fabffe446":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled","displayName":"Allow users to select cast devices with an access code or QR code from within the Google Cast menu.","description":"This policy controls whether a user will be presented with an option, within the Google Cast menu which allows them to cast to cast devices that do not appear in the Google Cast menu, using either the access code or QR code displayed on the cast devices's screen.\r\nBy default, a user must reenter the access code or rescan the QR code in order to initiate a subsequent casting session, but if the AccessCodeCastDeviceDuration policy has been set to a non-zero value (the default is zero), then the cast device will remain in the list of available cast devices until the specified period of time has expired.\r\nWhen this policy is set to Enabled, users will be presented with the option to select cast devices by using an access code or by scanning a QR code.\r\nWhen this policy is set to Disabled or not set, users will not be given the option to select cast devices by using an access code or by scanning a QR code.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f4e3c854d997eed":{"id":"device_vendor_msft_policy_config_defender_cloudextendedtimeout","displayName":"Cloud Extended Timeout","description":"This feature allows Windows Defender Antivirus to block a suspicious file for up to 60 seconds, and scan it in the cloud to make sure it's safe. Value type is integer, range is 0 - 50. The typical cloud check timeout is 10 seconds. To enable the extended cloud check feature, specify the extended time in seconds, up to an additional 50 seconds. For example, if the desired timeout is 60 seconds, specify 50 seconds in this setting, which will enable the extended cloud check feature, and will raise the total time to 60 seconds. NoteThis feature depends on three other MAPS settings the must all be enabled- Configure the 'Block at First Sight' feature; Join Microsoft MAPS; Send file samples when further analysis is required.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"8fc4f55745a82e70":{"id":"device_vendor_msft_policy_config_deliveryoptimization_domaxcacheage","displayName":"DO Max Cache Age","description":"Specifies the maximum time in seconds that each file is held in the Delivery Optimization cache after downloading successfully.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#domaxcacheage"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"8f08ae7d4d615c1c":{"id":"device_vendor_msft_policy_config_filesystem_devdriveattachpolicy","displayName":"Dev drive filter attach policy","description":"Dev drive is a drive optimized for performance considering developer scenarios and by default no file system filters are attached to it. Filters listed in this setting will be allowed to attach even on a dev drive.\r\n\r\nA reboot is required for this setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-filesystem#filesystem-devdriveattachpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_filesystem_devdriveattachpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_filesystem_devdriveattachpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"8f4e04a8f57442c3":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath_0","displayName":"Take no action","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath_1","displayName":"Redirect TEMP and TMP to local drive","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath_2","displayName":"Redirect INetCache to local drive","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilessettempfolderstolocalpath_profilessettempfolderstolocalpath_3","displayName":"Redirect TEMP, TMP and INetCache to local drive","description":null,"helpText":null}]},"8f1ff06320cddaff":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"8f3d7fb2f1403a51":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"8fc776be56cfa1b7":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel","displayName":"Network Security LAN Manager Authentication Level","description":"Network security LAN Manager authentication level This security setting determines which challenge/response authentication protocol is used for network logons. This choice affects the level of authentication protocol used by clients, the level of session security negotiated, and the level of authentication accepted by servers as follows: Send LM and NTLM responses: Clients use LM and NTLM authentication and never use NTLMv2 session security; domain controllers accept LM, NTLM, and NTLMv2 authentication. Send LM and NTLM - use NTLMv2 session security if negotiated: Clients use LM and NTLM authentication and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication. Send NTLM response only: Clients use NTLM authentication only and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication. Send NTLMv2 response only: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers accept LM, NTLM, and NTLMv2 authentication. Send NTLMv2 response only\\refuse LM: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers refuse LM (accept only NTLM and NTLMv2 authentication). Send NTLMv2 response only\\refuse LM and NTLM: Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it; domain controllers refuse LM and NTLM (accept only NTLMv2 authentication). Important This setting can affect the ability of computers running Windows 2000 Server, Windows 2000 Professional, Windows XP Professional, and the Windows Server 2003 family to communicate with computers running Windows NT 4.0 and earlier over the network. For example, at the time of this writing, computers running Windows NT 4.0 SP4 and earlier did not support NTLMv2. Computers running Windows 95 and Windows 98 did not support NTLM. Default: Windows 2000 and windows XP: send LM and NTLM responses Windows Server 2003: Send NTLM response only Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2: Send NTLMv2 response only","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_lanmanagerauthenticationlevel"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_0","displayName":"Send LM and NTLM responses","description":"Send LM and NTLM responses","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_1","displayName":"Send LM and NTLM-use NTLMv2 session security if negotiated","description":"Send LM and NTLM-use NTLMv2 session security if negotiated","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_2","displayName":"Send LM and NTLM responses only","description":"Send LM and NTLM responses only","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_3","displayName":"Send LM and NTLMv2 responses only","description":"Send LM and NTLMv2 responses only","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_4","displayName":"Send LM and NTLMv2 responses only. Refuse LM","description":"Send LM and NTLMv2 responses only. Refuse LM","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_lanmanagerauthenticationlevel_5","displayName":"Send LM and NTLMv2 responses only. Refuse LM and NTLM","description":"Send LM and NTLMv2 responses only. Refuse LM and NTLM","helpText":null}]},"8fb38d1b0604e484":{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup","displayName":"access group","description":"This Setting allows an administrator to manage local groups on a Device. Possible settings: 1. Update Group Membership: Update a group and add and/or remove members though the 'U' action. When using Update, existing group members that are not specified in the policy remain untouched. 2. Replace Group Membership: Restrict a group by replacing group membership through the 'R' action. When using Replace, existing group membership is replaced by the list of members specified in the add member section. This option works in the same way as a Restricted Group and any group members that are not specified in the policy are removed. Caution: If the same group is configured with both Replace and Update, then Replace will win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups"],"categoryId":"b86100f0-e4ae-4f93-9dae-dd253a96726f","categoryName":null,"options":null},"8f4041700e5dd7eb":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton","displayName":"Show Home button on toolbar","description":"Shows the Home button on Microsoft Edge's toolbar.\r\n\r\nEnable this policy to always show the Home button. Disable it to never show the button.\r\n\r\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_showhomebutton_1","displayName":"Enabled","description":null,"helpText":null}]},"8fa207bcc126526e":{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton","displayName":"Pin browser essentials toolbar button","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~performance_pinbrowseressentialstoolbarbutton_1","displayName":"Enabled","description":null,"helpText":null}]},"8f0bb44a94d27307":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls","displayName":"Allow idle detection on these sites","description":"Allows you to specify a list of URL patterns for sites that are allowed to use the Idle Detection API.\r\n\r\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\r\n\r\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported. For detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=209532.\r\n\r\nURL patterns specified in the blocklist take precedence over this allowlist. This allowlist takes precedence over the DefaultIdleDetectionSetting policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"8ffcceda08c00d7a":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled","displayName":"Show Hubs Sidebar","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_hubssidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f31275b6f9ee359":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_spdesignexe79","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_spdesignexe79_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_spdesignexe79_1","displayName":"True","description":null,"helpText":null}]},"8f0d1e85968bfc3c":{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_granularfeedbackcontrol_receivesurveys_checkbox","displayName":"Receive user satisfication surveys (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_granularfeedbackcontrol_receivesurveys_checkbox_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv6~policy~onedrivengsc_enablefeedbackandsupport_granularfeedbackcontrol_receivesurveys_checkbox_1","displayName":"True","description":null,"helpText":null}]},"8f322f96065dde8b":{"id":"device_vendor_msft_policy_config_privacy_letappssyncwithdevices_forceallowtheseapps","displayName":"Let Apps Sync With Devices Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps will be allowed to communicate with unpaired wireless devices. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappssyncwithdevices_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"8fa39dff8aafcb71":{"id":"device_vendor_msft_policy_config_remoteassistance_customizewarningmessages_ra_options_share_control_message","displayName":"Display warning message before sharing control:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":null},"8f6e8ded51d3ab7d":{"id":"device_vendor_msft_policy_config_start_importedgeassets","displayName":"Import Edge Assets","description":"This policy setting allows you to import Edge assets to be used with StartLayout policy. Start layout can contain secondary tile from Edge app which looks for Edge local asset file. Edge local asset would not exist and cause Edge secondary tile to appear empty in this case. This policy only gets applied when StartLayout policy is modified.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#importedgeassets"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":null},"8fbd08808278bb1c":{"id":"device_vendor_msft_policy_config_update_allowupdateservice","displayName":"Allow Update Service","description":"Specifies whether the device could use Microsoft Update, Windows Server Update Services (WSUS), or Microsoft Store. Even when Windows Update is configured to receive updates from an intranet update service, it will periodically retrieve information from the public Windows Update service to enable future connections to Windows Update, and other services like Microsoft Update or the Microsoft Store. Enabling this policy will disable that functionality, and may cause connection to public services such as the Microsoft Store to stop working. Note This policy applies only when the desktop or device is configured to connect to an intranet update service using the Specify intranet Microsoft update service location policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#allowupdateservice"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_allowupdateservice_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowupdateservice_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"8f7aeaf467728cbf":{"id":"device_vendor_msft_policy_config_windowsai_disableagentworkspaces","displayName":"Disable Agent Workspaces (Windows Insiders only)","description":"Enable or Disable Agent Workspaces.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableagentworkspaces"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_disableagentworkspaces_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableagentworkspaces_1","displayName":"Force Enable.","description":"Force Enable.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableagentworkspaces_2","displayName":"Force Disable.","description":"Force Disable.","helpText":null}]},"8febf0a1ceccabaa":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03","displayName":"Trusted Location #3 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_1","displayName":"Enabled","description":null,"helpText":null}]},"8f722c6a36dfb265":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_descriptioncolon45","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"8f2bb74ae993098c":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_admincomponents_title_sz_atc_admindeleteitem","displayName":"Enter URL(s) of desktop item(s) to Delete (space separated): (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":null},"8ff0cfbe12afe588":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdisable_1","displayName":"Disable Windows Error Reporting (User)","description":"This policy setting turns off Windows Error Reporting, so that reports are not collected or sent to either Microsoft or internal servers within your organization when software unexpectedly stops working or fails.\r\n\r\nIf you enable this policy setting, Windows Error Reporting does not send any problem information to Microsoft. Additionally, solution information is not available in Security and Maintenance in Control Panel.\r\n\r\nIf you disable or do not configure this policy setting, the Turn off Windows Error Reporting policy setting in Computer Configuration/Administrative Templates/System/Internet Communication Management/Internet Communication settings takes precedence. If Turn off Windows Error Reporting is also either disabled or not configured, user settings in Control Panel for Windows Error Reporting are applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werdisable-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdisable_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werdisable_1_1","displayName":"Enabled","description":null,"helpText":null}]},"8fd00f537f307bee":{"id":"user_vendor_msft_policy_config_admx_startmenu_nopinnedprograms","displayName":"Remove pinned programs list from the Start Menu (User)","description":"If you enable this setting, the \"Pinned Programs\" list is removed from the Start menu. Users cannot pin programs to the Start menu. \r\n\r\nIn Windows XP and Windows Vista, the Internet and email checkboxes are removed from the 'Customize Start Menu' dialog. \r\n\r\nIf you disable this setting or do not configure it, the \"Pinned Programs\" list remains on the Start menu. Users can pin and unpin programs in the Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nopinnedprograms"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nopinnedprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nopinnedprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"8f2597ab66acad40":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup","displayName":"Project 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Project 2013.\r\nMicrosoft Project 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Project 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Project 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Project 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013projectbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013projectbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"8f22f005412c2292":{"id":"user_vendor_msft_policy_config_attachmentmanager_donotpreservezoneinformation","displayName":"Do not preserve zone information in file attachments (User)","description":"This policy setting allows you to manage whether Windows marks file attachments with information about their zone of origin (such as restricted, Internet, intranet, local). This requires NTFS in order to function correctly, and will fail without notice on FAT32. By not preserving the zone information, Windows cannot make proper risk assessments.\n\nIf you enable this policy setting, Windows does not mark file attachments with their zone information.\n\nIf you disable this policy setting, Windows marks file attachments with their zone information.\n\nIf you do not configure this policy setting, Windows marks file attachments with their zone information.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-attachmentmanager#attachmentmanager-donotpreservezoneinformation"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_attachmentmanager_donotpreservezoneinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_attachmentmanager_donotpreservezoneinformation_1","displayName":"Enabled","description":null,"helpText":null}]},"8ff40ac76e7bc86d":{"id":"user_vendor_msft_policy_config_browser_homepages","displayName":"Home Pages (User)","description":"When you enable the Configure Open Microsoft Edge With policy, you can configure one or more Start pages. When you enable this policy, users are not allowed to make changes to their Start pages. If enabled, you must include URLs to the pages, separating multiple pages using angle brackets in the following format: If disabled or not configured, the webpages specified in App settings loads as the default Start pages. Version 1703 or later: If you do not want to send traffic to Microsoft, enable this policy and use the value, which honors domain- and non-domain-joined devices, when it is the only configured URL. Version 1809: If enabled, and you select either Start page, New Tab page, or previous page in the Configure Open Microsoft Edge With policy, Microsoft Edge ignores the Configure Start Pages policy. If not configured or you set the Configure Open Microsoft Edge With policy to a specific page or pages, Microsoft Edge uses the Configure Start Pages policy. Supported devices: Domain-joined or MDM-enrolled Related policy: - Configure Open Microsoft Edge With - Disable Lockdown of Start Pages","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#homepages"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"8f0636068636db9d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability","displayName":"Profile picker availability on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_0","displayName":"Profile picker available at startup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_1","displayName":"Profile picker disabled at startup","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_profilepickeronstartupavailability_profilepickeronstartupavailability_2","displayName":"Profile picker forced at startup","description":null,"helpText":null}]},"8f295faf7271d5f0":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_1","displayName":"Enabled","description":null,"helpText":null}]},"8f05dd3029bef3b6":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources","displayName":"Configure extension, app, and user script install sources (User)","description":"Setting the policy specifies which URLs may install extensions, apps, and themes. Before Google Chrome 21, users could click on a link to a *.crx file, and Google Chrome would offer to install the file after a few warnings. Afterwards, such files must be downloaded and dragged to the Google Chrome settings page. This setting allows specific URLs to have the old, easier installation flow.\r\n\r\nEach item in this list is an extension-style match pattern (see https://developer.chrome.com/extensions/match_patterns). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (the referrer) must be allowed by these patterns.\r\n\r\nExtensionInstallBlocklist takes precedence over this policy. That is, an extension on the blocklist won't be installed, even if it happens from a site on this list.\r\n\r\nExample value:\r\n\r\nhttps://corp.mycompany.com/*","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_1","displayName":"Enabled","description":null,"helpText":null}]},"8f9db0c1bbcf8560":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled","displayName":"Specifies whether in-product Google Chrome surveys are shown to users. (User)","description":"Google Chrome in-product surveys collect user feedback for the browser. Survey responses are not associated with user accounts.\r\nWhen this policy is Enabled or not set, in-product surveys may be shown to users.\r\nWhen this policy is Disabled, in-product surveys are not shown to users.\r\n\r\nThis policy has no effect if MetricsReportingEnabled is set to Disabled, which disables in-product surveys as well.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_feedbacksurveysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f4454a443c77d4d":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled","displayName":"Enable sharing user credentials with other users (User)","description":"Setting the policy to Enabled lets users send to and receive from family members (according to Family Service) their passwords.\r\nWhen the policy is Enabled or not set, there is a button in the Password Manager allowing to send a password.\r\nThe received passwords are stored into user's account and are available in the Password Manager.\r\n\r\nSetting the policy to Disabled means users can't send passwords from Password Manager to other users, and can't receive passwords from other users.\r\n\r\nThe feature is not available if synchronization of Passwords is turned off (either via user settings or SyncDisabled policy is Enabled).\r\n\r\nManaged accounts aren't eligible to join or create a family group and therefore cannot share passwords.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordsharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f72b72baa0ac2e7":{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled","displayName":"Enable CryptoWallet feature (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 128.\r\n\r\nThis policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There is no replacement for this policy.\r\n Enables CryptoWallet feature in Microsoft Edge.\r\n\r\n If you enable this policy or don't configure it, users can use CryptoWallet feature which allows users to securely store, manage and transact digital assets such as Bitcoin, Ethereum and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature.\r\n\r\n If you disable this policy, users can't use CryptoWallet feature.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev112~policy~microsoft_edge_cryptowalletenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f2126048bce2745":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting","displayName":"Control use of the File System API for writing (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_2","displayName":"Don't allow any site to request write access to files and directories","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemwriteguardsetting_defaultfilesystemwriteguardsetting_3","displayName":"Allow sites to ask the user to grant write access to files and directories","description":null,"helpText":null}]},"8f81e9b132ecd608":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled","displayName":"Allow the audio process to run with priority above normal on Windows (User)","description":"This policy controls the priority of the audio process on Windows.\r\nIf this policy is enabled, the audio process will run with above normal priority.\r\nIf this policy is disabled, the audio process will run with normal priority.\r\nIf this policy is not configured, the default configuration for the audio process will be used.\r\nThis policy is intended as a temporary measure to give enterprises the ability to\r\nrun audio with higher priority to address certain performance issues with audio capture.\r\nThis policy will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_audioprocesshighpriorityenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"8f0a8205fe287be8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_l_broadcastserviceserverdescription6","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"8f872f1cf9b5f17e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations","displayName":"Allow roaming of all user customizations (User)","description":"This policy setting allows roaming of both the Quick Access Toolbar and Ribbon customizations. \r\n\r\nIf you enable this policy setting, users' Quick Access Toolbar and Ribbon customizations will be available to them on any computer on their network when they log on. \r\n\r\nIf you disable or do not configure this policy setting, users' Quick Access Toolbar and Ribbon customizations will only be available to them on the computer on which they made the customizations.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_allowroamingquickaccesstoolbarribboncustomizations_1","displayName":"Enabled","description":null,"helpText":null}]},"8f23053317e3d473":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_igx_l_logfileentriesnumber_l_empty420","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"055293ad-c585-40c0-b66c-76ff5cc0a332","categoryName":"Microsoft Office SmartArt","options":null},"8f18ad227191dc0a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookcontactsdictionary_l_setupdateintervalforoutlookcontactsdictionaryspinid","displayName":"(in minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},"8f326e033144c4ed":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion","displayName":"Do not expand Contact Groups (User)","description":"This policy setting controls whether Outlook users can expand Contact Groups when addressing e-mail messages. \r\n\r\nIf you enable this policy setting, Outlook users cannot expand Contact Groups. \r\n\r\nIf you disable or do not configure this policy setting, when Outlook users add a Contact Group to the To, CC, or BCC fields of an e-mail message or other item, they can expand the Contact Group to see the e-mail addresses of everyone in the group.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disabledistributionlistexpansion_1","displayName":"Enabled","description":null,"helpText":null}]},"8f6001df236b5386":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9","displayName":"Options (User)","description":"Sets the value in the option \"Publish [] month(s) of Calendar free/busy information on the server\".","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_1","displayName":"Enabled","description":null,"helpText":null}]},"8f8e10221c599c13":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies","displayName":"Do not automatically sign replies (User)","description":"This policy setting allows you to specify whether replies will be automatically signed.\r\n\r\nIf you enable this policy setting, the option to respond automatically to a signed message with a signed response will be overridden, and an unsigned response will be the default reply to a signed message.\r\n\r\nIf you disable or do not configure this policy setting, a signed response will be the default reply to a signed message.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_donotautomaticallysignreplies_1","displayName":"Enabled","description":null,"helpText":null}]},"8fa182a15cfdfa8f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins","displayName":"List of managed add-ins (User)","description":"This policy setting allows you to specify which add-ins are always enabled, always disabled (blocked), or configurable by the user. To block add-ins that are not managed by this policy setting, you must also configure the \"Block all unmanaged add-ins\" policy setting.\r\n\r\nTo enable this policy setting, provide the following information for each add-in:\r\n\r\nIn \"Value name,\" specify the programmatic identifier (ProgID) for COM add-ins, or specify the file name of PowerPoint add-ins.\r\n\r\nTo obtain the ProgID for an add-in, use Registry Editor on the client computer where the add-in is installed to locate key names under HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Office\\PowerPoint\\Addins or HKEY_CURRENT_USER\\SOFTWARE\\Microsoft\\Office\\PowerPoint\\Addins.\r\n\r\nTo obtain the file name of an add-in, click the File menu in the application where the add-in is installed. Click Options, click Add-ins, and then use the Location column to determine the file name of the add-in.\r\n\r\nYou can also obtain the ProgID or the file name of an add-in by using Office Telemetry Dashboard.\r\n\r\nIn \"Value,\" specify the value as follows:\r\n\r\nTo specify that an add-in is always disabled (blocked), type 0.\r\n\r\nTo specify that an add-in is always enabled, type 1.\r\n\r\nTo specify that an add-in is configurable by the user and not blocked by the \"Block all unmanaged add-ins\" policy setting when enabled, type 2.\r\n\r\nIf you disable or do not enable this policy setting, the list of managed add-ins is deleted. If the \"Block all unmanaged add-ins\" policy setting is enabled, then all add-ins are blocked.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_listofmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},"8fe0c142d1bcec43":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters","displayName":"Graphic Filters (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_graphicfilters_1","displayName":"Enabled","description":null,"helpText":null}]},"8fbeb67f84f8055a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"8fef9aa320104a32":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy","displayName":"Add control characters in Cut and Copy (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addcontrolcharactersincutandcopy_1","displayName":"Enabled","description":null,"helpText":null}]},"8f821f8fee1e05da":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries","displayName":"Show text boundaries (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_textboundaries_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/93.json b/public/intune-definitions/93.json index c91d3da9632d..2ed610160537 100644 --- a/public/intune-definitions/93.json +++ b/public/intune-definitions/93.json @@ -1 +1 @@ -{"9366a35e3a805df4":{"id":"ade_requiresharedipadtemporarysessiononly","displayName":"Require Shared iPad temporary session only","description":"Available for devices running iPadOS versions 14.5 and later. When set to Yes, users only see the Guest Welcome pane, and can only sign in as a guest user. Users can't sign in with a Managed Apple ID.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_requiresharedipadtemporarysessiononly_0","displayName":"Not configured","description":null,"helpText":null},{"id":"ade_requiresharedipadtemporarysessiononly_1","displayName":"Yes","description":null,"helpText":null}]},"936d3519140990f6":{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked","displayName":"Block ultra wideband","description":"If 'True', the device prevents ultra wideband functionality, restricting user access to the setting. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default ultra wideband behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked_false","displayName":"False","description":"The user is allowed to toggle ultra wideband on or off.","helpText":null},{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked_true","displayName":"True","description":"Ultra wideband is disabled. The user is not allowed to toggle ultra wideband on or off.","helpText":null}]},"930e3c96069a395c":{"id":"com.apple.applicationaccess_forceondeviceonlydictation","displayName":"Force On Device Only Dictation (Deprecated)","description":"If true, disables connections to Siri servers for the purposes of dictation. Available in iOS 14.5 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceondeviceonlydictation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceondeviceonlydictation_true","displayName":"True","description":null,"helpText":null}]},"939e9670caf78faf":{"id":"com.apple.familycontrols.contentfilter_filterdenylist","displayName":"Filter Deny List","description":"The array of URLs that defines a deny list. When `restrictWeb` and `useContentFilter` are enabled, no URLs in the deny list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},"93bf02674d6be176":{"id":"com.apple.managedclient.preferences_networkpredictionoptions","displayName":"Enable network prediction","description":"Enables network prediction and prevents users from changing this setting.\n\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\n\nIf you don't configure this policy, network prediction is enabled but the user can change it.\n\n* 0 = Predict network actions on any network connection\n\n* 2 = Don't predict network actions on any network connection","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#networkpredictionoptions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular. (Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},"931346fa7ef388f7":{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled","displayName":"Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured","description":"This policy only works if you set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4) and the \"RestoreOnStartupURLs\" policy as mandatory.\nIf you enable this policy, users are allowed to add and remove their own URLs to open when starting Edge while maintaining the admin specified mandatory list of sites specified by setting \"RestoreOnStartup\" policy to open a list of URLS and providing the list of sites in the \"RestoreOnStartupURLs\" policy.\n\nIf you disable or don't configure this policy, there is no change to how the \"RestoreOnStartup\" and \"RestoreOnStartupURLs\" policies work.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartupuserurlsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"93e2b35e10ab93e1":{"id":"com.apple.mcx.filevault2_usekeychain","displayName":"Use Keychain","description":"If 'true' and no certificate information is provided in this payload, the keychain created at '/Library/Keychains/FileVaultMaster.keychain' is used when the institutional recovery key is added.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_usekeychain_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_usekeychain_true","displayName":"Enabled","description":null,"helpText":null}]},"938c5ef47804826a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\n\nIf you don't configure this policy, no app is forced to be shown in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used, and no sidebar can be shown.\n\nFor detailed information about valid URL, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: URL patterns aren't supported in this policy. You should provide the exact URL of the app.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"93604917bef7e465":{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog","description":"This policy controls whether the \"Always allow this site to open links of this type\" checkbox is shown on external protocol launch confirmation prompts. This policy only applies to https:// links.\n\nIf you enable this policy, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.\n\nIf you disable this policy, the \"Always allow\" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked.\n\nPrior to Microsoft Edge 83, if you don't configure this policy, the \"Always allow\" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked.\n\nOn Microsoft Edge 83, if you don't configure this policy, the checkbox visibility is controlled by the \"Enable remembering protocol launch prompting preferences\" flag in edge://flags\n\nAs of Microsoft Edge 84, if you don't configure this policy, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox_true","displayName":"Enabled","description":null,"helpText":null}]},"93c6fea8beec3848":{"id":"com.microsoft.edge.mamedgeappconfigsettings.hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check","description":"Setting the policy specifies a list of hostnames that bypass preloaded HSTS (HTTP Strict Transport Security) upgrades from http to https.\n\nOnly single-label hostnames are allowed in this policy, and this policy only applies to static HSTS-preloaded entries (for example, \"app\", \"new\", \"search\", and \"play\"). This policy doesn't prevent HSTS upgrades for servers that have dynamically requested HSTS upgrades using a Strict-Transport-Security response header.\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified and not to subdomains of those names.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"93a797966b23c8c7":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"93be27adeaab432d":{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals","displayName":"Enable ESS with Supported Peripherals","description":"Enhanced Sign-in Security (ESS) isolates both biometric template data and matching operations to trusted hardware or specified memory regions, meaning the rest of the operating system cannot access or tamper with them. Because the channel of communication between the sensors and the algorithm is also secured, it is impossible for malware to inject or replay data in order to simulate a user signing in or to lock a user out of their machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals_0","displayName":"Enhanced sign-in security will be disabled on all systems. If a user already has a secure Windows Hello enrollment, they will lose their enrollment and must reset PIN, and they will have the option to re-enroll in normal face and fingerprint. Peripheral usage will be enabled by disabling Enhanced sign-in security. OS will not attempt to start secure components, even if the secure hardware and software components are present. (not recommended)","description":"Enhanced sign-in security will be disabled on all systems. If a user already has a secure Windows Hello enrollment, they will lose their enrollment and must reset PIN, and they will have the option to re-enroll in normal face and fingerprint. Peripheral usage will be enabled by disabling Enhanced sign-in security. OS will not attempt to start secure components, even if the secure hardware and software components are present. (not recommended)","helpText":null},{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals_1","displayName":"Enhanced sign-in security will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. For systems with one secure modality (face or fingerprint) and one insecure modality (fingerprint or face), only the secure sensor can be used for sign-in and the insecure sensor(s) will be blocked. This includes peripheral devices, which are unsupported and will be unusable. (default and recommended for highest security)","description":"Enhanced sign-in security will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. For systems with one secure modality (face or fingerprint) and one insecure modality (fingerprint or face), only the secure sensor can be used for sign-in and the insecure sensor(s) will be blocked. This includes peripheral devices, which are unsupported and will be unusable. (default and recommended for highest security)","helpText":null}]},"931cc42047b1349f":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalprioritylimit","displayName":"Normal Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"93670288d345d946":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security","displayName":"Configure security policy processing","description":"This policy setting determines when security policies are updated.\r\n\r\nThis policy setting affects all policies that use the security component of Group Policy, such as those in Windows Settings\\Security Settings.\r\n\r\nThis policy setting overrides customized settings that the program implementing the security policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they be updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-security"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_1","displayName":"Enabled","description":null,"helpText":null}]},"937e97bb410bd0c8":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl_proxypacurl","displayName":"Define proxy auto-config (.pac) for connecting to the network","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},"9373c89d72ac4400":{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia","displayName":"Allow users to use media source while elevated","description":"This policy setting allows users to install programs from removable media during privileged installations.\r\n\r\nIf you enable this policy setting, all users are permitted to install programs from removable media, such as floppy disks and CD-ROMs, even when the installation program is running with elevated system privileges.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. By default, users can install from removable media when the installation runs in their own security context.\r\n\r\nIf you disable or do not configure this policy setting, by default, users can install programs from removable media only when the installation runs in the user's security context. During privileged installations, such as those offered on the desktop or displayed in Add or Remove Programs, only system administrators can install from removable media.\r\n\r\nAlso, see the \"Prevent removable media source for any install\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownmedia"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia_1","displayName":"Enabled","description":null,"helpText":null}]},"936a4af7397e0821":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords","displayName":"Specify DC Locator DNS records not registered by the DCs","description":"This policy setting determines which DC Locator DNS records are not registered by the Net Logon service.\r\n\r\nIf you enable this policy setting, select Enabled and specify a list of space-delimited mnemonics (instructions) for the DC Locator DNS records that will not be registered by the DCs to which this setting is applied.\r\n\r\nSelect the mnemonics from the following list:\r\n\r\nMnemonic Type DNS Record\r\n\r\nLdapIpAddress A \r\nLdap SRV _ldap._tcp.\r\nLdapAtSite SRV _ldap._tcp.._sites.\r\nPdc SRV _ldap._tcp.pdc._msdcs.\r\nGc SRV _ldap._tcp.gc._msdcs.\r\nGcAtSite SRV _ldap._tcp.._sites.gc._msdcs.\r\nDcByGuid SRV _ldap._tcp..domains._msdcs.\r\nGcIpAddress A gc._msdcs.\r\nDsaCname CNAME ._msdcs.\r\nKdc SRV _kerberos._tcp.dc._msdcs.\r\nKdcAtSite SRV _kerberos._tcp.._sites.dc._msdcs.\r\nDc SRV _ldap._tcp.dc._msdcs.\r\nDcAtSite SRV _ldap._tcp.._sites.dc._msdcs.\r\nRfc1510Kdc SRV _kerberos._tcp.\r\nRfc1510KdcAtSite SRV _kerberos._tcp.._sites.\r\nGenericGc SRV _gc._tcp.\r\nGenericGcAtSite SRV _gc._tcp.._sites.\r\nRfc1510UdpKdc SRV _kerberos._udp.\r\nRfc1510Kpwd SRV _kpasswd._tcp.\r\nRfc1510UdpKpwd SRV _kpasswd._udp.\r\n\r\nIf you disable this policy setting, DCs configured to perform dynamic registration of DC Locator DNS records register all DC Locator DNS resource records.\r\n\r\nIf you do not configure this policy setting, DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsavoidregisterrecords"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_1","displayName":"Enabled","description":null,"helpText":null}]},"9364674040654698":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level","displayName":"Audio Quality","description":null,"helpText":"","infoUrls":[],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_1","displayName":"Dynamic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_7","displayName":"High","description":null,"helpText":null}]},"93d89aa53365e21a":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common","displayName":"Microsoft Office 2013 Common Settings","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2013 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2013 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2013 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2013 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2013 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2013 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common_1","displayName":"Enabled","description":null,"helpText":null}]},"930e1aa814af4fd8":{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles","displayName":"Delete user profiles older than a specified number of days on system restart","description":"This policy setting allows an administrator to automatically delete user profiles on system restart that have not been used within a specified number of days. Note: One day is interpreted as 24 hours after a specific user profile was accessed.\r\n\r\nIf you enable this policy setting, the User Profile Service will automatically delete on the next system restart all user profiles on the computer that have not been used within the specified number of days. \r\n\r\nIf you disable or do not configure this policy setting, User Profile Service will not automatically delete any profiles on the next system restart.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-cleanupprofiles"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},"93ef8e4ffb4b616f":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxnegphasecorrection","displayName":"MaxNegPhaseCorrection","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"933f0a1498cd8fc7":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted","displayName":"Detailed Tracking Audit Token Right Adjusted","description":"This policy setting allows you to audit events generated by adjusting the privileges of a token.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_audittokenrightadjusted"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"93c772db7738a3d3":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry","displayName":"Object Access Audit Registry","description":"This policy setting allows you to audit attempts to access registry objects. A security audit event is generated only for objects that have system access control lists (SACLs) specified, and only if the type of access requested, such as Read, Write, or Modify, and the account making the request match the settings in the SACL. If you configure this policy setting, an audit event is generated each time an account accesses a registry object with a matching SACL. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an account accesses a registry object with a matching SACL. Note: You can set a SACL on a registry object using the Permissions dialog box.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditregistry"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"934e69ed1055f9a4":{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager","displayName":"Allow Password Manager","description":"This setting lets you decide whether employees can save their passwords locally, using Password Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowpasswordmanager"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"932fe91cd4bc53b4":{"id":"device_vendor_msft_policy_config_browser_preventturningoffrequiredextensions","displayName":"Prevent Turning Off Required Extensions","description":"You can define a list of extensions in Microsoft Edge that users cannot turn off. You must deploy extensions through any available enterprise deployment channel, such as Microsoft Intune. When you enable this policy, users cannot uninstall extensions from their computer, but they can configure options for extensions defined in this policy, such as allow for InPrivate browsing. Any additional permissions requested by future updates of the extension gets granted automatically. When you enable this policy, you must provide a semi-colon delimited list of extension package family names (PFNs). For example, adding Microsoft.OneNoteWebClipper_8wekyb3d8bbwe;Microsoft.OfficeOnline_8wekyb3d8bbwe prevents a user from turning off the OneNote Web Clipper and Office Online extension. When enabled, removing extensions from the list does not uninstall the extension from the user’s computer automatically. To uninstall the extension, use any available enterprise deployment channel. If you enable the Allow Developer Tools policy, then this policy does not prevent users from debugging and altering the logic on an extension. If disabled or not configured, extensions defined as part of this policy get ignored. Default setting: Disabled or not configured Related policies: Allow Developer Tools Related Documents: - Find a package family name (PFN) for per-app VPN (https://docs.microsoft.com/en-us/sccm/protect/deploy-use/find-a-pfn-for-per-app-vpn) - How to manage apps you purchased from the Microsoft Store for Business with Microsoft Intune (https://docs.microsoft.com/en-us/intune/windows-store-for-business) - How to assign apps to groups with Microsoft Intune (https://docs.microsoft.com/en-us/intune/apps-deploy) - Manage apps from the Microsoft Store for Business with System Center Configuration Manager (https://docs.microsoft.com/en-us/sccm/apps/deploy-use/manage-apps-from-the-windows-store-for-business) - How to add Windows line-of-business (LOB) apps to Microsoft Intune (https://docs.microsoft.com/en-us/intune/lob-apps-windows)","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventturningoffrequiredextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"935989986dcd9778":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages","displayName":"Configure the content and order of preferred languages","description":"This policy allows admins to configure the order of the preferred languages in Google Chrome's settings.\r\n\r\nThe order of the list will appear in the same order under the \"Order languages based on your preference\" section in chrome://settings/languages. Users won't be able to remove or reorder languages set by the policy, but will be able to add languages underneath those set by the policy. Users will also have full control over the browser's UI language and translation/spell check settings, unless enforced by other policies.\r\n\r\nLeaving the policy unset lets users manipulate the entire list of preferred languages.\r\n\r\nExample value:\r\n\r\nen-US","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_1","displayName":"Enabled","description":null,"helpText":null}]},"930ea8f232db1366":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"93cd819cedd24a09":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible","displayName":"Show Outlook Calendar card on the New Tab Page","description":"This policy controls the visibility of the Outlook Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the Outlook Calendar data in the browser.\r\n\r\nOutlook data will not be stored by the browser.\r\n\r\nThe Outlook card shows the next calendar event, along with a glanceable look at the rest of the day's meetings. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their next meeting.\r\n\r\nThe Microsoft Outlook card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Outlook, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards.\r\n\r\nIf the NTPCardsVisible is disabled, the Outlook Card will not be shown. If NTPCardsVisible is enabled, the Outlook card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the Outlook card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible_1","displayName":"Enabled","description":null,"helpText":null}]},"93f1c80063be4d05":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer","displayName":"Restrict CPU core sharing for renderer process","description":"This policy mitigates side-channel cross process memory attacks by isolating the renderer process on the CPU core and preventing other processes from sharing the same core. The mitigation is supported on Microsoft® Windows® 11 24H2 and above. If the OS does not have the required scheduling support, this policy will have no effect. This policy may slow down performance in some demanding scenarios similar to disabling hyperthreading. For more information refer https://learn.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy\r\nIf this policy is enabled, all other processes will not be scheduled on the same CPU core when the renderer process is running.\r\nIf this policy is disabled, all other processes can be scheduled on the same CPU core if a renderer process is running on it.\r\nIf this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core. This may vary depending on Google Chrome release, currently running field trials, and platform.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_1","displayName":"Enabled","description":null,"helpText":null}]},"93beed163ad3753b":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dodelaybackgrounddownloadfromhttp","displayName":"DO Delay Background Download From Http","description":"For background downloads that use P2P, specifies the time to wait before starting to download from the HTTP source.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dodelaybackgrounddownloadfromhttp"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"932735da2901be41":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdmaxcachesizeinmbs","displayName":"CCD Max Cache Size in MBs","description":"CcdMaxCacheSizeInMBs specifies the maximum local cache size in megabytes, per user, during normal operation. Normal operation assumes that all Cloud Cache providers are available, and that storage performance is adequate to accept I/O at the rate necessary to accommodate profile utilization.\r\n\r\nCAUTION: Do not use this setting unless the performance and technical aspects to this setting are fully understood as this setting is a leading cause to poor performance and has limited use cases.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\CcdMaxCacheSizeInMBs\r\nType: DWORD\r\nValues: Min (No Limit) = 0, Max = 10000000","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdmaxcachesizeinmbs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdmaxcachesizeinmbs_1","displayName":"Enabled","description":null,"helpText":null}]},"935ba7ffe0a92c36":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforregister_odfchealthyprovidersrequiredforregister","displayName":"Healthy Providers Required For Register (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":null},"93f8c0b8bdc6dea0":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect","displayName":"Disable HTTP fallback for SIP connection","description":"Prevents from HTTP being used for SIP connection in case TLS or TCP fail.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"9356e62a5f23a0f2":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies","displayName":"Allow socket pool size randomization for proxies","description":"Controls whether Microsoft Edge randomizes socket pool sizes for proxy connections.\n\nSocket pool size randomization is a security mechanism that helps prevent attackers from using deterministic connection limits to infer cross-site information. For example, if the configured proxy socket pool limit is 128, Microsoft Edge can randomly set the effective limit between 128 and 256. This can allow up to twice as many proxy connections, though the expected increase is closer to 1.2x in practice.\n\nThis policy affects the limits configured by the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server for non-WebSocket requests) and 'MaxConnectionsPerProxyForWebSocket' (Maximum number of concurrent connections to the proxy server for WebSocket requests) policies. When this policy is enabled, the effective upper limit can be randomized up to 2x the values configured by those policies.\n\nIf you enable this policy or don't configure it, Microsoft Edge enables socket pool size randomization for proxy connections.\n\nIf you disable this policy, Microsoft Edge disables socket pool size randomization for proxy connections. The values configured by 'MaxConnectionsPerProxy' and 'MaxConnectionsPerProxyForWebSocket' are used as the upper limits without randomization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies_1","displayName":"Enabled","description":null,"helpText":null}]},"93bf8ab7dc3a60b2":{"id":"intelligencesettings_apps_calendar","displayName":"Calendar","description":"If present, configures Calendar and Reminders Intelligence features.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":null},"937b91301f6f4591":{"id":"setrecoverylock_recoverylockpasswordrotationschedule","displayName":"Recovery Lock Password Rotation Schedule","description":"Configure how often (in months) the recovery lock password should be rotated.","helpText":null,"infoUrls":[],"categoryId":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","categoryName":"Recovery Lock Password","options":[{"id":"setrecoverylock_recoverylockpasswordrotationschedule_0","displayName":"1 month","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_1","displayName":"2 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_2","displayName":"3 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_3","displayName":"4 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_4","displayName":"5 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_5","displayName":"6 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_6","displayName":"7 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_7","displayName":"8 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_8","displayName":"9 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_9","displayName":"10 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_10","displayName":"11 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_11","displayName":"12 months","description":null,"helpText":null}]},"9344145323c341ad":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_descriptioncolon29","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"9357b3c17248f2a7":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_rasconnect","displayName":"Prohibit connecting and disconnecting a remote access connection (User)","description":"Determines whether users can connect and disconnect remote access connections.\r\n\r\nIf you enable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), double-clicking the icon has no effect, and the Connect and Disconnect menu items are disabled for all users (including administrators).\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you disable this setting or do not configure it, the Connect and Disconnect options for remote access connections are available to all users. Users can connect or disconnect a remote access connection by double-clicking the icon representing the connection, by right-clicking it, or by using the File menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-rasconnect"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_rasconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_rasconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"93b1a731961f99a0":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016","displayName":"Microsoft Office 365 Visio 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_1","displayName":"Enabled","description":null,"helpText":null}]},"934f837ef704950d":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_library2","displayName":"Location 3 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"9395b321581b31df":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist_urlblocklistdesc","displayName":"Block access to a list of URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"93be729de1882696":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls","displayName":"Allow JavaScript on these sites (User)","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can run JavaScript.\r\n\r\nLeaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"93265e288a76ee49":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_popupsallowedforurlsdesc","displayName":"Allow popups on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"93552c02f20faa2e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},"93f338fdbecaa1a1":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled","displayName":"Enable Live Caption (User)","description":"Enable the Live Caption feature.\r\n\r\nIf this policy is set to Enabled, Live Caption will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Caption will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.","helpText":"","infoUrls":[],"categoryId":"d9432f48-3072-4171-9031-4ebead394151","categoryName":"Accessibility settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"930edcaf462998b4":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_cahintcertificatesdesc","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"93ba5d8f9aa68b21":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon5","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"930cef3547a6ecf1":{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist_compatview_sitelist","displayName":"List of sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":null},"9342708aa7f36de7":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"9324e465da3aa6cd":{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton","displayName":"Enable End Session Button (User)","description":"Enable/disable kiosk browser's end session button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enableendsessionbutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_0","displayName":"Disable","description":"Disable","helpText":null}]},"938c037d62df8ef9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability","displayName":"Control where developer tools can be used (User)","description":"Control where developer tools can be used.\r\n\r\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (0, the default), users can access the developer tools and the JavaScript console in general, but not in the context of extensions installed by enterprise policy.\r\n\r\nIf you set this policy to 'DeveloperToolsAllowed' (1), users can access the developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\r\n\r\nIf you set this policy to 'DeveloperToolsDisallowed' (2), users can't access the developer tools or inspect website elements. Keyboard shortcuts and menu or context menu entries that open the developer tools or the JavaScript Console are disabled.\r\n\r\n* 0 = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\r\n\r\n* 1 = Allow using the developer tools\r\n\r\n* 2 = Don't allow using the developer tools","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"9375adb167dc577a":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard use on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"931ce240f3d6757e":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts","displayName":"Allow importing of shortcuts (User)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"932f30503f19e023":{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_3","displayName":"Basic mode","description":null,"helpText":null}]},"9373c1eca06d20ca":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo","displayName":"Edo (User)","description":"Enables the editing language Edo","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo_1","displayName":"Enabled","description":null,"helpText":null}]},"931631f0c079f5b9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowdescrip490","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"93798a5364f9492c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_0","displayName":"Windows XP","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_1","displayName":"Windows Vista","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_2","displayName":"Windows 7","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_3","displayName":"Windows 8","description":null,"helpText":null}]},"93ac321e23b06772":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts","displayName":"Prevent users from adding other types of e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts_1","displayName":"True","description":null,"helpText":null}]},"93ce85ff698ea2e6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending","displayName":"Force selection of account before sending (User)","description":"This policy setting enables you to force users to select an e-mail account from which to send outgoing e-mail.\r\n\r\nIf you enable this policy setting, users must choose an e-mail account before they can send an e-mail.\r\n\r\nIf you disable or do not configure this policy setting, e-mail is sent from the default e-mail account if users do not select a specific e-mail account.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending_1","displayName":"Enabled","description":null,"helpText":null}]},"9367093975c4a90f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar","displayName":"REST updates for calendars (User)","description":"This policy determines if Outlook can use REST to update calendars.\r\n\r\n If you enable this policy, Outlook will use REST to update supported Office 365 and Outlook.com calendars.\r\n\r\n If you disable this policy, Outlook won't use REST to update any calendars.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},"93ce7cb3823fa12a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui","displayName":"Hide Junk Mail UI (User)","description":"This policy setting controls whether the Junk E-mail Filter is enabled in Outlook. The Junk E-mail Filter in Outlook is designed to intercept the most obvious junk e-mail, or spam, and send it to users' Junk E-mail folders. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n \r\nIf you enable this policy setting, junk e-mail filtering in Outlook is turned off entirely, in addition to hiding the filtering controls from users. In addition, you can use the \"Junk E-mail Protection level\" policy setting to preset a filtering level and prevent users from changing it. Note - This policy setting does not affect the configuration of the Microsoft Exchange Server Intelligent Message Filter (IMF), which provides server-level junk e-mail filtering. \r\n\r\nIf you disable or do not configure this policy setting, the Junk E-mail Filter in Outlook is enabled.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui_1","displayName":"Enabled","description":null,"helpText":null}]},"93d9d29626f581f0":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"931d25da8bcf7c75":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]}} \ No newline at end of file +{"9366a35e3a805df4":{"id":"ade_requiresharedipadtemporarysessiononly","displayName":"Require Shared iPad temporary session only","description":"Available for devices running iPadOS versions 14.5 and later. When set to Yes, users only see the Guest Welcome pane, and can only sign in as a guest user. Users can't sign in with a Managed Apple ID.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_requiresharedipadtemporarysessiononly_0","displayName":"Not configured","description":null,"helpText":null},{"id":"ade_requiresharedipadtemporarysessiononly_1","displayName":"Yes","description":null,"helpText":null}]},"936d3519140990f6":{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked","displayName":"Block ultra wideband","description":"If 'True', the device prevents ultra wideband functionality, restricting user access to the setting. If 'False', Intune doesn't change or update this setting. By default, the OS follows the default ultra wideband behavior. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked_false","displayName":"False","description":"The user is allowed to toggle ultra wideband on or off.","helpText":null},{"id":"com.android.devicerestrictionpolicy.ultrawidebandblocked_true","displayName":"True","description":"Ultra wideband is disabled. The user is not allowed to toggle ultra wideband on or off.","helpText":null}]},"930e3c96069a395c":{"id":"com.apple.applicationaccess_forceondeviceonlydictation","displayName":"Force On Device Only Dictation (Deprecated)","description":"If true, disables connections to Siri servers for the purposes of dictation. Available in iOS 14.5 and later. Also available for user enrollment.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceondeviceonlydictation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceondeviceonlydictation_true","displayName":"True","description":null,"helpText":null}]},"939e9670caf78faf":{"id":"com.apple.familycontrols.contentfilter_filterdenylist","displayName":"Filter Deny List","description":"The array of URLs that defines a deny list. When `restrictWeb` and `useContentFilter` are enabled, no URLs in the deny list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},"93bf02674d6be176":{"id":"com.apple.managedclient.preferences_networkpredictionoptions","displayName":"Enable network prediction","description":"Enables network prediction and prevents users from changing this setting.\n\nThis controls DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.\n\nIf you don't configure this policy, network prediction is enabled but the user can change it.\n\n* 0 = Predict network actions on any network connection\n\n* 2 = Don't predict network actions on any network connection","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#networkpredictionoptions"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular. (Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},"931346fa7ef388f7":{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled","displayName":"Allow users to add and remove their own sites during startup when the RestoreOnStartupURLs policy is configured","description":"This policy only works if you set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4) and the \"RestoreOnStartupURLs\" policy as mandatory.\nIf you enable this policy, users are allowed to add and remove their own URLs to open when starting Edge while maintaining the admin specified mandatory list of sites specified by setting \"RestoreOnStartup\" policy to open a list of URLS and providing the list of sites in the \"RestoreOnStartupURLs\" policy.\n\nIf you disable or don't configure this policy, there is no change to how the \"RestoreOnStartup\" and \"RestoreOnStartupURLs\" policies work.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartupuserurlsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_restoreonstartupuserurlsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"93e2b35e10ab93e1":{"id":"com.apple.mcx.filevault2_usekeychain","displayName":"Use Keychain","description":"If 'true' and no certificate information is provided in this payload, the keychain created at '/Library/Keychains/FileVaultMaster.keychain' is used when the institutional recovery key is added.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_usekeychain_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_usekeychain_true","displayName":"Enabled","description":null,"helpText":null}]},"938c5ef47804826a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\n\nIf you don't configure this policy, no app is forced to be shown in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used, and no sidebar can be shown.\n\nFor detailed information about valid URL, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: URL patterns aren't supported in this policy. You should provide the exact URL of the app.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"93604917bef7e465":{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox","displayName":"Show an \"Always open\" checkbox in external protocol dialog","description":"This policy controls whether the \"Always allow this site to open links of this type\" checkbox is shown on external protocol launch confirmation prompts. This policy only applies to https:// links.\n\nIf you enable this policy, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.\n\nIf you disable this policy, the \"Always allow\" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked.\n\nPrior to Microsoft Edge 83, if you don't configure this policy, the \"Always allow\" checkbox isn't displayed. The user is prompted for confirmation every time an external protocol is invoked.\n\nOn Microsoft Edge 83, if you don't configure this policy, the checkbox visibility is controlled by the \"Enable remembering protocol launch prompting preferences\" flag in edge://flags\n\nAs of Microsoft Edge 84, if you don't configure this policy, when an external protocol confirmation prompt is shown, the user can select \"Always allow\" to skip all future confirmation prompts for the protocol on this site.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.externalprotocoldialogshowalwaysopencheckbox_true","displayName":"Enabled","description":null,"helpText":null}]},"93c6fea8beec3848":{"id":"com.microsoft.edge.mamedgeappconfigsettings.hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check","description":"Setting the policy specifies a list of hostnames that bypass preloaded HSTS (HTTP Strict Transport Security) upgrades from http to https.\n\nOnly single-label hostnames are allowed in this policy, and this policy only applies to static HSTS-preloaded entries (for example, \"app\", \"new\", \"search\", and \"play\"). This policy doesn't prevent HSTS upgrades for servers that have dynamically requested HSTS upgrades using a Strict-Transport-Security response header.\n\nSupplied hostnames must be canonicalized: Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific single-label hostnames specified and not to subdomains of those names.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"93a797966b23c8c7":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"9397fe8fa1e4509e":{"id":"contentcaching_denytetheredcaching","displayName":"Deny Tethered Caching","description":"If `true`, the system disables tethered caching.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_denytetheredcaching_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_denytetheredcaching_true","displayName":"Enabled","description":null,"helpText":null}]},"93be27adeaab432d":{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals","displayName":"Enable ESS with Supported Peripherals","description":"Enhanced Sign-in Security (ESS) isolates both biometric template data and matching operations to trusted hardware or specified memory regions, meaning the rest of the operating system cannot access or tamper with them. Because the channel of communication between the sensors and the algorithm is also secured, it is impossible for malware to inject or replay data in order to simulate a user signing in or to lock a user out of their machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals_0","displayName":"Enhanced sign-in security will be disabled on all systems. If a user already has a secure Windows Hello enrollment, they will lose their enrollment and must reset PIN, and they will have the option to re-enroll in normal face and fingerprint. Peripheral usage will be enabled by disabling Enhanced sign-in security. OS will not attempt to start secure components, even if the secure hardware and software components are present. (not recommended)","description":"Enhanced sign-in security will be disabled on all systems. If a user already has a secure Windows Hello enrollment, they will lose their enrollment and must reset PIN, and they will have the option to re-enroll in normal face and fingerprint. Peripheral usage will be enabled by disabling Enhanced sign-in security. OS will not attempt to start secure components, even if the secure hardware and software components are present. (not recommended)","helpText":null},{"id":"device_vendor_msft_passportforwork_biometrics_enableesswithsupportedperipherals_1","displayName":"Enhanced sign-in security will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. For systems with one secure modality (face or fingerprint) and one insecure modality (fingerprint or face), only the secure sensor can be used for sign-in and the insecure sensor(s) will be blocked. This includes peripheral devices, which are unsupported and will be unusable. (default and recommended for highest security)","description":"Enhanced sign-in security will be enabled on systems with capable software and hardware, following the existing default behavior in Windows. For systems with one secure modality (face or fingerprint) and one insecure modality (fingerprint or face), only the secure sensor can be used for sign-in and the insecure sensor(s) will be blocked. This includes peripheral devices, which are unsupported and will be unusable. (default and recommended for highest security)","helpText":null}]},"931cc42047b1349f":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_nonworknormalprioritylimit","displayName":"Normal Priority Limit:","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":null},"93670288d345d946":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security","displayName":"Configure security policy processing","description":"This policy setting determines when security policies are updated.\r\n\r\nThis policy setting affects all policies that use the security component of Group Policy, such as those in Windows Settings\\Security Settings.\r\n\r\nThis policy setting overrides customized settings that the program implementing the security policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Do not apply during periodic background processing\" option prevents the system from updating affected policies in the background while the computer is in use. When background updates are disabled, policy changes will not take effect until the next user logon or system restart.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy implementations specify that they be updated only when changed. However, you might want to update unchanged policies, such as reapplying a desired policy setting in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-security"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_security_1","displayName":"Enabled","description":null,"helpText":null}]},"937e97bb410bd0c8":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxypacurl_proxypacurl","displayName":"Define proxy auto-config (.pac) for connecting to the network","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},"9373c89d72ac4400":{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia","displayName":"Allow users to use media source while elevated","description":"This policy setting allows users to install programs from removable media during privileged installations.\r\n\r\nIf you enable this policy setting, all users are permitted to install programs from removable media, such as floppy disks and CD-ROMs, even when the installation program is running with elevated system privileges.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. By default, users can install from removable media when the installation runs in their own security context.\r\n\r\nIf you disable or do not configure this policy setting, by default, users can install programs from removable media only when the installation runs in the user's security context. During privileged installations, such as those offered on the desktop or displayed in Add or Remove Programs, only system administrators can install from removable media.\r\n\r\nAlso, see the \"Prevent removable media source for any install\" policy setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownmedia"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownmedia_1","displayName":"Enabled","description":null,"helpText":null}]},"936a4af7397e0821":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords","displayName":"Specify DC Locator DNS records not registered by the DCs","description":"This policy setting determines which DC Locator DNS records are not registered by the Net Logon service.\r\n\r\nIf you enable this policy setting, select Enabled and specify a list of space-delimited mnemonics (instructions) for the DC Locator DNS records that will not be registered by the DCs to which this setting is applied.\r\n\r\nSelect the mnemonics from the following list:\r\n\r\nMnemonic Type DNS Record\r\n\r\nLdapIpAddress A \r\nLdap SRV _ldap._tcp.\r\nLdapAtSite SRV _ldap._tcp.._sites.\r\nPdc SRV _ldap._tcp.pdc._msdcs.\r\nGc SRV _ldap._tcp.gc._msdcs.\r\nGcAtSite SRV _ldap._tcp.._sites.gc._msdcs.\r\nDcByGuid SRV _ldap._tcp..domains._msdcs.\r\nGcIpAddress A gc._msdcs.\r\nDsaCname CNAME ._msdcs.\r\nKdc SRV _kerberos._tcp.dc._msdcs.\r\nKdcAtSite SRV _kerberos._tcp.._sites.dc._msdcs.\r\nDc SRV _ldap._tcp.dc._msdcs.\r\nDcAtSite SRV _ldap._tcp.._sites.dc._msdcs.\r\nRfc1510Kdc SRV _kerberos._tcp.\r\nRfc1510KdcAtSite SRV _kerberos._tcp.._sites.\r\nGenericGc SRV _gc._tcp.\r\nGenericGcAtSite SRV _gc._tcp.._sites.\r\nRfc1510UdpKdc SRV _kerberos._udp.\r\nRfc1510Kpwd SRV _kpasswd._tcp.\r\nRfc1510UdpKpwd SRV _kpasswd._udp.\r\n\r\nIf you disable this policy setting, DCs configured to perform dynamic registration of DC Locator DNS records register all DC Locator DNS resource records.\r\n\r\nIf you do not configure this policy setting, DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsavoidregisterrecords"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsavoidregisterrecords_1","displayName":"Enabled","description":null,"helpText":null}]},"9364674040654698":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level","displayName":"Audio Quality","description":null,"helpText":"","infoUrls":[],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_1","displayName":"Dynamic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_audio_quality_ts_audio_quality_level_7","displayName":"High","description":null,"helpText":null}]},"93d89aa53365e21a":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common","displayName":"Microsoft Office 2013 Common Settings","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2013 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2013 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2013 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2013 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2013 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2013 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013common_1","displayName":"Enabled","description":null,"helpText":null}]},"930e1aa814af4fd8":{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles","displayName":"Delete user profiles older than a specified number of days on system restart","description":"This policy setting allows an administrator to automatically delete user profiles on system restart that have not been used within a specified number of days. Note: One day is interpreted as 24 hours after a specific user profile was accessed.\r\n\r\nIf you enable this policy setting, the User Profile Service will automatically delete on the next system restart all user profiles on the computer that have not been used within the specified number of days. \r\n\r\nIf you disable or do not configure this policy setting, User Profile Service will not automatically delete any profiles on the next system restart.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-cleanupprofiles"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},"93ef8e4ffb4b616f":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxnegphasecorrection","displayName":"MaxNegPhaseCorrection","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"933f0a1498cd8fc7":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted","displayName":"Detailed Tracking Audit Token Right Adjusted","description":"This policy setting allows you to audit events generated by adjusting the privileges of a token.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_audittokenrightadjusted"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_audittokenrightadjusted_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"93c772db7738a3d3":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry","displayName":"Object Access Audit Registry","description":"This policy setting allows you to audit attempts to access registry objects. A security audit event is generated only for objects that have system access control lists (SACLs) specified, and only if the type of access requested, such as Read, Write, or Modify, and the account making the request match the settings in the SACL. If you configure this policy setting, an audit event is generated each time an account accesses a registry object with a matching SACL. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an account accesses a registry object with a matching SACL. Note: You can set a SACL on a registry object using the Permissions dialog box.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditregistry"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditregistry_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"934e69ed1055f9a4":{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager","displayName":"Allow Password Manager","description":"This setting lets you decide whether employees can save their passwords locally, using Password Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowpasswordmanager"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowpasswordmanager_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"932fe91cd4bc53b4":{"id":"device_vendor_msft_policy_config_browser_preventturningoffrequiredextensions","displayName":"Prevent Turning Off Required Extensions","description":"You can define a list of extensions in Microsoft Edge that users cannot turn off. You must deploy extensions through any available enterprise deployment channel, such as Microsoft Intune. When you enable this policy, users cannot uninstall extensions from their computer, but they can configure options for extensions defined in this policy, such as allow for InPrivate browsing. Any additional permissions requested by future updates of the extension gets granted automatically. When you enable this policy, you must provide a semi-colon delimited list of extension package family names (PFNs). For example, adding Microsoft.OneNoteWebClipper_8wekyb3d8bbwe;Microsoft.OfficeOnline_8wekyb3d8bbwe prevents a user from turning off the OneNote Web Clipper and Office Online extension. When enabled, removing extensions from the list does not uninstall the extension from the user’s computer automatically. To uninstall the extension, use any available enterprise deployment channel. If you enable the Allow Developer Tools policy, then this policy does not prevent users from debugging and altering the logic on an extension. If disabled or not configured, extensions defined as part of this policy get ignored. Default setting: Disabled or not configured Related policies: Allow Developer Tools Related Documents: - Find a package family name (PFN) for per-app VPN (https://docs.microsoft.com/en-us/sccm/protect/deploy-use/find-a-pfn-for-per-app-vpn) - How to manage apps you purchased from the Microsoft Store for Business with Microsoft Intune (https://docs.microsoft.com/en-us/intune/windows-store-for-business) - How to assign apps to groups with Microsoft Intune (https://docs.microsoft.com/en-us/intune/apps-deploy) - Manage apps from the Microsoft Store for Business with System Center Configuration Manager (https://docs.microsoft.com/en-us/sccm/apps/deploy-use/manage-apps-from-the-windows-store-for-business) - How to add Windows line-of-business (LOB) apps to Microsoft Intune (https://docs.microsoft.com/en-us/intune/lob-apps-windows)","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventturningoffrequiredextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"935989986dcd9778":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages","displayName":"Configure the content and order of preferred languages","description":"This policy allows admins to configure the order of the preferred languages in Google Chrome's settings.\r\n\r\nThe order of the list will appear in the same order under the \"Order languages based on your preference\" section in chrome://settings/languages. Users won't be able to remove or reorder languages set by the policy, but will be able to add languages underneath those set by the policy. Users will also have full control over the browser's UI language and translation/spell check settings, unless enforced by other policies.\r\n\r\nLeaving the policy unset lets users manipulate the entire list of preferred languages.\r\n\r\nExample value:\r\n\r\nen-US","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_forcedlanguages_1","displayName":"Enabled","description":null,"helpText":null}]},"930ea8f232db1366":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"93cd819cedd24a09":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible","displayName":"Show Outlook Calendar card on the New Tab Page","description":"This policy controls the visibility of the Outlook Card on the New Tab Page. The card will only be displayed on the New Tab Page if the policy is enabled and your organization authorized the usage of the Outlook Calendar data in the browser.\r\n\r\nOutlook data will not be stored by the browser.\r\n\r\nThe Outlook card shows the next calendar event, along with a glanceable look at the rest of the day's meetings. It aims to address the issue of context switching and enhance productivity by giving users a shortcut to their next meeting.\r\n\r\nThe Microsoft Outlook card will require additional admin configuration. For detailed information on connecting the Chrome New Tab Page Card to Outlook, please see https://support.google.com/chrome/a?p=chrome_ntp_microsoft_cards.\r\n\r\nIf the NTPCardsVisible is disabled, the Outlook Card will not be shown. If NTPCardsVisible is enabled, the Outlook card will be shown if this policy is also enabled and there is data to be shown. If NTPCardsVisible is unset, the Outlook card will be shown if this policy is also enabled, the user has the card enabled in Customize Chrome, and there is data to be shown.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpoutlookcardvisible_1","displayName":"Enabled","description":null,"helpText":null}]},"93f1c80063be4d05":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer","displayName":"Restrict CPU core sharing for renderer process","description":"This policy mitigates side-channel cross process memory attacks by isolating the renderer process on the CPU core and preventing other processes from sharing the same core. The mitigation is supported on Microsoft® Windows® 11 24H2 and above. If the OS does not have the required scheduling support, this policy will have no effect. This policy may slow down performance in some demanding scenarios similar to disabling hyperthreading. For more information refer https://learn.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy\r\nIf this policy is enabled, all other processes will not be scheduled on the same CPU core when the renderer process is running.\r\nIf this policy is disabled, all other processes can be scheduled on the same CPU core if a renderer process is running on it.\r\nIf this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core. This may vary depending on Google Chrome release, currently running field trials, and platform.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_1","displayName":"Enabled","description":null,"helpText":null}]},"93beed163ad3753b":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dodelaybackgrounddownloadfromhttp","displayName":"DO Delay Background Download From Http","description":"For background downloads that use P2P, specifies the time to wait before starting to download from the HTTP source.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dodelaybackgrounddownloadfromhttp"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"932735da2901be41":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdmaxcachesizeinmbs","displayName":"CCD Max Cache Size in MBs","description":"CcdMaxCacheSizeInMBs specifies the maximum local cache size in megabytes, per user, during normal operation. Normal operation assumes that all Cloud Cache providers are available, and that storage performance is adequate to accept I/O at the rate necessary to accommodate profile utilization.\r\n\r\nCAUTION: Do not use this setting unless the performance and technical aspects to this setting are fully understood as this setting is a leading cause to poor performance and has limited use cases.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\CcdMaxCacheSizeInMBs\r\nType: DWORD\r\nValues: Min (No Limit) = 0, Max = 10000000","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdmaxcachesizeinmbs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdmaxcachesizeinmbs_1","displayName":"Enabled","description":null,"helpText":null}]},"935ba7ffe0a92c36":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforregister_odfchealthyprovidersrequiredforregister","displayName":"Healthy Providers Required For Register (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":null},"93f8c0b8bdc6dea0":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect","displayName":"Disable HTTP fallback for SIP connection","description":"Prevents from HTTP being used for SIP connection in case TLS or TCP fail.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"9356e62a5f23a0f2":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies","displayName":"Allow socket pool size randomization for proxies","description":"Controls whether Microsoft Edge randomizes socket pool sizes for proxy connections.\n\nSocket pool size randomization is a security mechanism that helps prevent attackers from using deterministic connection limits to infer cross-site information. For example, if the configured proxy socket pool limit is 128, Microsoft Edge can randomly set the effective limit between 128 and 256. This can allow up to twice as many proxy connections, though the expected increase is closer to 1.2x in practice.\n\nThis policy affects the limits configured by the 'MaxConnectionsPerProxy' (Maximum number of concurrent connections to the proxy server for non-WebSocket requests) and 'MaxConnectionsPerProxyForWebSocket' (Maximum number of concurrent connections to the proxy server for WebSocket requests) policies. When this policy is enabled, the effective upper limit can be randomized up to 2x the values configured by those policies.\n\nIf you enable this policy or don't configure it, Microsoft Edge enables socket pool size randomization for proxy connections.\n\nIf you disable this policy, Microsoft Edge disables socket pool size randomization for proxy connections. The values configured by 'MaxConnectionsPerProxy' and 'MaxConnectionsPerProxyForWebSocket' are used as the upper limits without randomization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_allowsocketpoolsizerandomizationforproxies_1","displayName":"Enabled","description":null,"helpText":null}]},"93bf8ab7dc3a60b2":{"id":"intelligencesettings_apps_calendar","displayName":"Calendar","description":"If present, configures Calendar and Reminders Intelligence features.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":null},"937b91301f6f4591":{"id":"setrecoverylock_recoverylockpasswordrotationschedule","displayName":"Recovery Lock Password Rotation Schedule","description":"Configure how often (in months) the recovery lock password should be rotated.","helpText":null,"infoUrls":[],"categoryId":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","categoryName":"Recovery Lock Password","options":[{"id":"setrecoverylock_recoverylockpasswordrotationschedule_0","displayName":"1 month","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_1","displayName":"2 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_2","displayName":"3 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_3","displayName":"4 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_4","displayName":"5 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_5","displayName":"6 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_6","displayName":"7 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_7","displayName":"8 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_8","displayName":"9 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_9","displayName":"10 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_10","displayName":"11 months","description":null,"helpText":null},{"id":"setrecoverylock_recoverylockpasswordrotationschedule_11","displayName":"12 months","description":null,"helpText":null}]},"9344145323c341ad":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_descriptioncolon29","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"9357b3c17248f2a7":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_rasconnect","displayName":"Prohibit connecting and disconnecting a remote access connection (User)","description":"Determines whether users can connect and disconnect remote access connections.\r\n\r\nIf you enable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), double-clicking the icon has no effect, and the Connect and Disconnect menu items are disabled for all users (including administrators).\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting will not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you disable this setting or do not configure it, the Connect and Disconnect options for remote access connections are available to all users. Users can connect or disconnect a remote access connection by double-clicking the icon representing the connection, by right-clicking it, or by using the File menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-rasconnect"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_rasconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_rasconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"93b1a731961f99a0":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016","displayName":"Microsoft Office 365 Visio 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2016_1","displayName":"Enabled","description":null,"helpText":null}]},"934f837ef704950d":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_library2","displayName":"Location 3 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"9395b321581b31df":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlblocklist_urlblocklistdesc","displayName":"Block access to a list of URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"93be729de1882696":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls","displayName":"Allow JavaScript on these sites (User)","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can run JavaScript.\r\n\r\nLeaving the policy unset means DefaultJavaScriptSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"93265e288a76ee49":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsallowedforurls_popupsallowedforurlsdesc","displayName":"Allow popups on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"93552c02f20faa2e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingpapersizedefault_printingpapersizedefault","displayName":"Default printing page size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},"93f338fdbecaa1a1":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled","displayName":"Enable Live Caption (User)","description":"Enable the Live Caption feature.\r\n\r\nIf this policy is set to Enabled, Live Caption will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Caption will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Caption is disabled initially but can be enabled by the user anytime.","helpText":"","infoUrls":[],"categoryId":"d9432f48-3072-4171-9031-4ebead394151","categoryName":"Accessibility settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~accessibility_livecaptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"930edcaf462998b4":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cahintcertificates_cahintcertificatesdesc","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"93ba5d8f9aa68b21":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon5","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"930cef3547a6ecf1":{"id":"user_vendor_msft_policy_config_internetexplorer_allowinternetexplorer7policylist_compatview_sitelist","displayName":"List of sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":null},"9342708aa7f36de7":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"9324e465da3aa6cd":{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton","displayName":"Enable End Session Button (User)","description":"Enable/disable kiosk browser's end session button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enableendsessionbutton"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"user_vendor_msft_policy_config_kioskbrowser_enableendsessionbutton_0","displayName":"Disable","description":"Disable","helpText":null}]},"938c037d62df8ef9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability","displayName":"Control where developer tools can be used (User)","description":"Control where developer tools can be used.\r\n\r\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (0, the default), users can access the developer tools and the JavaScript console in general, but not in the context of extensions installed by enterprise policy.\r\n\r\nIf you set this policy to 'DeveloperToolsAllowed' (1), users can access the developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\r\n\r\nIf you set this policy to 'DeveloperToolsDisallowed' (2), users can't access the developer tools or inspect website elements. Keyboard shortcuts and menu or context menu entries that open the developer tools or the JavaScript Console are disabled.\r\n\r\n* 0 = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\r\n\r\n* 1 = Allow using the developer tools\r\n\r\n* 2 = Don't allow using the developer tools","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"9375adb167dc577a":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_clipboardblockedforurlsdesc","displayName":"Block clipboard use on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"931ce240f3d6757e":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts","displayName":"Allow importing of shortcuts (User)","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\r\n\r\nIf you disable this policy, Shortcuts aren't imported on first run.\r\n\r\nIf you don’t configure this policy, Shortcuts are imported on first run.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\r\n\r\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_importshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"932f30503f19e023":{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_0","displayName":"Standard mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_1","displayName":"Balanced mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_2","displayName":"Strict mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_enhancesecuritymode_3","displayName":"Basic mode","description":null,"helpText":null}]},"9373c1eca06d20ca":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo","displayName":"Edo (User)","description":"Enables the editing language Edo","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_edo_1","displayName":"Enabled","description":null,"helpText":null}]},"931631f0c079f5b9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowdescrip490","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"93798a5364f9492c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_0","displayName":"Windows XP","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_1","displayName":"Windows Vista","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_2","displayName":"Windows 7","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_minsigsupportos_l_minsigsupportosdropid_3","displayName":"Windows 8","description":null,"helpText":null}]},"93ac321e23b06772":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts","displayName":"Prevent users from adding other types of e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingothertypesofemailaccounts_1","displayName":"True","description":null,"helpText":null}]},"93ce85ff698ea2e6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending","displayName":"Force selection of account before sending (User)","description":"This policy setting enables you to force users to select an e-mail account from which to send outgoing e-mail.\r\n\r\nIf you enable this policy setting, users must choose an e-mail account before they can send an e-mail.\r\n\r\nIf you disable or do not configure this policy setting, e-mail is sent from the default e-mail account if users do not select a specific e-mail account.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_forceselectionofaccountbeforesending_1","displayName":"Enabled","description":null,"helpText":null}]},"9367093975c4a90f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar","displayName":"REST updates for calendars (User)","description":"This policy determines if Outlook can use REST to update calendars.\r\n\r\n If you enable this policy, Outlook will use REST to update supported Office 365 and Outlook.com calendars.\r\n\r\n If you disable this policy, Outlook won't use REST to update any calendars.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_restupdatesforcalendar_1","displayName":"Enabled","description":null,"helpText":null}]},"93ce7cb3823fa12a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui","displayName":"Hide Junk Mail UI (User)","description":"This policy setting controls whether the Junk E-mail Filter is enabled in Outlook. The Junk E-mail Filter in Outlook is designed to intercept the most obvious junk e-mail, or spam, and send it to users' Junk E-mail folders. The filter evaluates each incoming message based on several factors, including the time when the message was sent and the content of the message. The filter does not single out any particular sender or message type, but instead analyzes each message based on its content and structure to discover whether or not it is probably spam.\r\n \r\nIf you enable this policy setting, junk e-mail filtering in Outlook is turned off entirely, in addition to hiding the filtering controls from users. In addition, you can use the \"Junk E-mail Protection level\" policy setting to preset a filtering level and prevent users from changing it. Note - This policy setting does not affect the configuration of the Microsoft Exchange Server Intelligent Message Filter (IMF), which provides server-level junk e-mail filtering. \r\n\r\nIf you disable or do not configure this policy setting, the Junk E-mail Filter in Outlook is enabled.","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_hidejunkmailui_1","displayName":"Enabled","description":null,"helpText":null}]},"93d9d29626f581f0":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc12_l_pathcolon52","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"931d25da8bcf7c75":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/94.json b/public/intune-definitions/94.json index 73401f14b8e7..7a151d4ddc52 100644 --- a/public/intune-definitions/94.json +++ b/public/intune-definitions/94.json @@ -1 +1 @@ -{"94be7ba91f33be74":{"id":"ade_macos_awaitconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_macos_awaitconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_macos_awaitconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},"94323fb0c1cfc39f":{"id":"com.apple.domains_crosssitetrackingpreventionrelaxedapps","displayName":"Cross Site Tracking Prevention Relaxed Apps","description":"An array of up to 10 strings representing app bundle-ids. Apps matching the bundle-ids listed here have relaxed enforcement of cross-site tracking prevention for the domains listed in `CrossSiteTrackingPreventionRelaxedDomains`.\n\nAvailable in iOS 18 and later and macOS 15 and later.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},"94eb62d612016c33":{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_generickey_kerberos_string","displayName":"Domain Realm Mapping","description":"An array of DNS Suffixes that map to the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"94407b5a3740880d":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled_true","displayName":"True","description":null,"helpText":null}]},"94f767af1900b116":{"id":"com.apple.managedclient.preferences_builtindnsclientenabled","displayName":"Use built-in DNS client","description":"Controls whether to use the built-in DNS client.\n\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\n\nIf you enable this policy, the built-in DNS client is used, if it's available.\n\nIf you disable this policy, the client is never used.\n\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtindnsclientenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtindnsclientenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtindnsclientenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9468a2c47a6bc2aa":{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clearcachedimagesandfilesonexit"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit_true","displayName":"Enabled","description":null,"helpText":null}]},"945a24e9bc6d5dea":{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Online revocation checks don't provide a significant security benefit and are disabled by default.\n\nIf you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. \"Soft fail\" means that if the revocation server can't be reached, the certificate will be considered valid.\n\nIf you disable the policy or don't configure it, Microsoft Edge won't perform online revocation checks.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableonlinerevocationchecks"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks_true","displayName":"Enabled","description":null,"helpText":null}]},"94772d68177953d0":{"id":"com.apple.managedclient.preferences_showcasticonintoolbar","displayName":"Show the cast icon in the toolbar","description":"Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it.\n\nIf you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.\n\nIf you've also set the \"EnableMediaRouter\" policy to false, then this policy is ignored, and the toolbar icon isn't shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showcasticonintoolbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showcasticonintoolbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showcasticonintoolbar_true","displayName":"Enabled","description":null,"helpText":null}]},"94c8f2a5ea0a455c":{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\n\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\n\nIf you disable this setting, employees will not receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showpdfdefaultrecommendationsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"94f405df6c6640d4":{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentregex","displayName":"Password Content Regex","description":"A regular expression string that they system matches against the password to determine whether it complies with a policy. The regular expression uses the ICU syntax (). The string must not exceed 2048 characters in length.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"9469b554f948e3fe":{"id":"com.apple.mobiledevice.passwordpolicy_minutesuntilfailedloginreset","displayName":"Minutes Until Failed Login Reset","description":"The number of minutes before the login is reset after the maximum number of unsuccessful login attempts is reached. This key requires setting Max Failed Attempts. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"94b09153943a4ef1":{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent","displayName":"Listen Event","description":"Allows the application to use CoreGraphics and HID APIs to listen to (receive) CGEvents and HID events from all processes. A profile can't grant access to these events; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"9421a8f7bb9f7c2b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the Favorites check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_true","displayName":"Enabled","description":null,"helpText":null}]},"941add0621c49882":{"id":"command_remotedesktop_remotedesktop","displayName":"Remote Desktop","description":"Enable/Disable Remote Desktop on the device","helpText":null,"infoUrls":[],"categoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","categoryName":"Remote Desktop","options":[{"id":"command_remotedesktop_remotedesktop_true","displayName":"Enable","description":null,"helpText":null},{"id":"command_remotedesktop_remotedesktop_false","displayName":"Disable","description":null,"helpText":null}]},"94929c29e026d4b2":{"id":"device_vendor_msft_email_emailserver","displayName":"Email Server","description":"The Exchange location (URL) of the email server to which the app you specified connects to get email.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},"94bd17fb0a23ed8b":{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration","displayName":"Restrict delegation of credentials to remote servers","description":"When running in Restricted Admin or Remote Credential Guard mode, participating apps do not expose signed in or supplied credentials to a remote host. Restricted Admin limits access to resources located on other servers or networks from the remote host because credentials are not delegated. Remote Credential Guard does not limit access to resources because it redirects all requests back to the client device.\r\n\r\nParticipating apps:\r\nRemote Desktop Client\r\n\r\nIf you enable this policy setting, the following options are supported:\r\n \r\nRestrict credential delegation: Participating applications must use Restricted Admin or Remote Credential Guard to connect to remote hosts.\r\n \r\nRequire Remote Credential Guard: Participating applications must use Remote Credential Guard to connect to remote hosts.\r\n \r\nRequire Restricted Admin: Participating applications must use Restricted Admin to connect to remote hosts.\r\n\r\nIf you disable or do not configure this policy setting, Restricted Admin and Remote Credential Guard mode are not enforced and participating apps can delegate credentials to remote devices.\r\n\r\nNote: To disable most credential delegation, it may be sufficient to deny delegation in Credential Security Support Provider (CredSSP) by modifying Administrative template settings (located at Computer Configuration\\Administrative Templates\\System\\Credentials Delegation).\r\n\r\nNote: On Windows 8.1 and Windows Server 2012 R2, enabling this policy will enforce Restricted Administration mode, regardless of the mode chosen. These versions do not support Remote Credential Guard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-restrictedremoteadministration"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_1","displayName":"Enabled","description":null,"helpText":null}]},"94487dae2c4eb054":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable or do not configure this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_1","displayName":"Enabled","description":null,"helpText":null}]},"94b661923e479a70":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue_signatureupdate_assignaturedue","displayName":"Define the number of days before spyware security intelligence is considered out of date","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},"945d5696e356352d":{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse","displayName":"Allow users to browse for source while elevated","description":"This policy setting allows users to search for installation files during privileged installations.\r\n\r\nIf you enable this policy setting, the Browse button in the \"Use feature from\" dialog box is enabled. As a result, users can search for installation files even when the installation program is running with elevated system privileges.\r\n\r\nBecause the installation is running with elevated system privileges, users can browse through directories that their own permissions would not allow.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. Also, see the \"Remove browse dialog box for new source\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, by default, only system administrators can browse during installations with elevated privileges, such as installations offered on the desktop or displayed in Add or Remove Programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownbrowse"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse_1","displayName":"Enabled","description":null,"helpText":null}]},"944981b389bb7a8d":{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers","displayName":"Specify permitted managers","description":"This policy setting determines the permitted list of hosts that can submit a query to the Simple Network Management (SNMP) agent running on the client computer.\r\n\r\nSimple Network Management Protocol is a protocol designed to give a user the capability to remotely manage a computer network by polling and setting terminal values and monitoring network events.\r\n\r\nThe manager is located on the host computer on the network. The manager's role is to poll the agents for certain requested information.\r\n\r\nIf you enable this policy setting, the SNMP agent only accepts requests from the list of permitted managers that you configure using this setting.\r\n\r\nIf you disable or do not configure this policy setting, SNMP service takes the permitted managers configured on the local computer instead.\r\n\r\nBest practice: For security purposes, it is recommended to restrict the HKLM\\SOFTWARE\\Policies\\SNMP\\Parameters\\PermittedManagers key to allow only the local admin group full control.\r\n\r\nNote: This policy setting has no effect if the SNMP agent is not installed on the client computer.\r\n\r\nAlso, see the other two SNMP policy settings: \"Specify trap configuration\" and \"Specify Community Name\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-snmp#admx-snmp-snmp-permittedmanagers"],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":[{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_1","displayName":"Enabled","description":null,"helpText":null}]},"944d2251a302b4f0":{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar","displayName":"Configure Favorites Bar","description":"The favorites bar shows your user's links to sites they have added to it. With this policy, you can specify whether to set the favorites bar to always be visible or hidden on any page. If enabled, favorites bar is always visible on any page, and the favorites bar toggle in Settings sets to On, but disabled preventing your users from making changes. An error message also shows at the top of the Settings pane indicating that your organization manages some settings. The show bar/hide bar option is hidden from the context menu. If disabled, the favorites bar is hidden, and the favorites bar toggle resets to Off, but disabled preventing your users from making changes. An error message also shows at the top of the Settings pane indicating that your organization manages some settings. If not configured, the favorites bar is hidden but is visible on the Start and New Tab pages, and the favorites bar toggle in Settings sets to Off but is enabled allowing the user to make changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurefavoritesbar"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar_0","displayName":"Disabled","description":"Hide the favorites bar on all pages. Also, the favorites bar toggle, in Settings, is set to Off and disabled preventing users from making changes. Microsoft Edge also hides the “show bar/hide bar” option in the context menu.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar_1","displayName":"Enabled","description":"Show the favorites bar on all pages. Also, the favorites bar toggle, in Settings, is set to On and disabled preventing users from making changes. Microsoft Edge also hides the “show bar/hide bar” option in the context menu.","helpText":null}]},"948e598a6fa69258":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins","displayName":"Allow running plugins that are outdated","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins_1","displayName":"Enabled","description":null,"helpText":null}]},"94307bc164142ce7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_newtabpagelocation","displayName":"New Tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},"94f94608211375d7":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings","displayName":"Enable automated password change","description":"This policy controls the availability of Google Chrome's automated password change feature.\r\n\r\nIf enabled, a user can trigger a process where the browser attempts to change their password on a website automatically. This process is managed by Generative AI. The new password is saved in the browser's password manager.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"94c549e462176368":{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats","displayName":"Remediation action for High severity threats","description":"","helpText":"","infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_clean","displayName":"Clean. Service tries to recover files and try to disinfect.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_quarantine","displayName":"Quarantine. Moves files to quarantine.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_remove","displayName":"Remove. Removes files from system.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_allow","displayName":"Allow. Allows file/does none of the above actions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_userdefined","displayName":"User defined. Requires user to make a decision on which action to take.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_block","displayName":"Block. Blocks file execution.","description":null,"helpText":null}]},"942926abbb33cfbb":{"id":"device_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing","displayName":"Turn off InPrivate Browsing","description":"This policy setting allows you to turn off the InPrivate Browsing feature.\n\nInPrivate Browsing prevents Internet Explorer from storing data about a user's browsing session. This includes cookies, temporary Internet files, history, and other data.\n\nIf you enable this policy setting, InPrivate Browsing is turned off.\n\nIf you disable this policy setting, InPrivate Browsing is available for use.\n\nIf you do not configure this policy setting, InPrivate Browsing can be turned on or off through the registry.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinprivatebrowsing"],"categoryId":"f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},"943af4d0f08396ee":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver","displayName":"Include local path when user is uploading files to a server","description":"This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.\n\nIf you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.\n\nIf you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.\n\nIf you do not configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneincludelocalpathwhenuploadingfilestoserver"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},"94e23314dd589ce8":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001","displayName":"Download signed ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_1","displayName":"Prompt","description":null,"helpText":null}]},"94c953ddec39957d":{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256","displayName":"PK Init Hash Algorithm SHA256","description":"Configure SHA-256 hash algorithm for certificate logon","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Kerberos#pkinithashalgorithmsha256"],"categoryId":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256_0","displayName":"Not Supported","description":"Not Supported","helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256_1","displayName":"Default","description":"Default","helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256_2","displayName":"Audited","description":"Audited","helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256_3","displayName":"Supported","description":"Supported","helpText":null}]},"94adbfb519bcf352":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_shutdown_clearvirtualmemorypagefile","displayName":"Shutdown Clear Virtual Memory Page File","description":"Shutdown: Clear virtual memory pagefile This security setting determines whether the virtual memory pagefile is cleared when the system is shut down. Virtual memory support uses a system pagefile to swap pages of memory to disk when they are not used. On a running system, this pagefile is opened exclusively by the operating system, and it is well protected. However, systems that are configured to allow booting to other operating systems might have to make sure that the system pagefile is wiped clean when this system shuts down. This ensures that sensitive information from process memory that might go into the pagefile is not available to an unauthorized user who manages to directly access the pagefile. When this policy is enabled, it causes the system pagefile to be cleared upon clean shutdown. If you enable this security option, the hibernation file (hiberfil.sys) is also zeroed out when hibernation is disabled. Default: Disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#shutdown_clearvirtualmemorypagefile"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_shutdown_clearvirtualmemorypagefile_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_shutdown_clearvirtualmemorypagefile_0","displayName":"Disable","description":"Disable","helpText":null}]},"940d01cbe3b79b4d":{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc","displayName":"Local group","description":"This Setting allows an administrator to manage local groups on a Device. Possible settings: 1. Update Group Membership: Update a group and add and/or remove members though the 'U' action. When using Update, existing group members that are not specified in the policy remain untouched. 2. Replace Group Membership: Restrict a group by replacing group membership through the 'R' action. When using Replace, existing group membership is replaced by the list of members specified in the add member section. This option works in the same way as a Restricted Group and any group members that are not specified in the policy are removed. Caution: If the same group is configured with both Replace and Update, then Replace will win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups"],"categoryId":"b86100f0-e4ae-4f93-9dae-dd253a96726f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_administrators","displayName":"Administrators","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_users","displayName":"Users","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_guests","displayName":"Guests","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_powerusers","displayName":"Power Users","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_remotedesktopusers","displayName":"Remote Desktop Users","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_remotemanagementusers","displayName":"Remote Management Users","description":null,"helpText":null}]},"94ecb7c834ca277e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9494dbc7d110a4e6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"943d2daacbdaaaba":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled","displayName":"DataURL Whitespace Preservation for all media types","description":"This policy provides a temporary opt-out for changes to how Edge handles whitepsace in data URLS.\r\nPreviously, whitespace would be kept only if the top level media type was text or contained the media type string xml.\r\nNow, whitespace will be preserved in all data URLs, regardless of media type.\r\n\r\nIf this policy is left unset or is set to True, the new behavior is enabled.\r\n\r\nWhen this policy is set to False, the old behavior is enabled.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"947aef90cc978eed":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"943f5fc34d4abbe6":{"id":"device_vendor_msft_policy_config_update_engagedrestarttransitionscheduleforfeatureupdates","displayName":"Engaged Restart Transition Schedule For Feature Updates","description":"For Feature Updates, this policy specifies the timing before transitioning from Auto restarts scheduled_outside of active hours to Engaged restart, which requires the user to schedule. The period can be set between 2 and 30 days from the time the restart becomes pending. Value type is integer. Default value is 7 days. Supported value range: 2 - 30. If you disable or do not configure this policy, the default behaviors will be used. If any of the following policies are configured, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installationsAlways automatically restart at scheduled timeSpecify deadline before auto-restart for update installation","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#engagedrestarttransitionscheduleforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"940648929e061a96":{"id":"device_vendor_msft_policy_config_wifi_wlanscanmode","displayName":"WLAN Scan Mode","description":"Allow an enterprise to control the WLAN scanning behavior and how aggressively devices should be actively scanning for Wi-Fi networks to get devices connected. Supported values are 0-500, where 100 = normal scan frequency and 500 = low scan frequency. The default value is 0. Supported operations are Add, Delete, Get, and Replace.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-wifi#wlanscanmode"],"categoryId":"0a803a48-789a-48b0-b928-e52d56ab17f1","categoryName":"Wi-Fi Settings","options":null},"94367dcab2dcceea":{"id":"device_vendor_msft_policy_config_windowslogon_enumeratelocalusersondomainjoinedcomputers","displayName":"Enumerate local users on domain-joined computers","description":"This policy setting allows local users to be enumerated on domain-joined computers. \n\nIf you enable this policy setting, Logon UI will enumerate all local users on domain-joined computers.\n\nIf you disable or do not configure this policy setting, the Logon UI will not enumerate local users on domain-joined computers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowslogon#windowslogon-enumeratelocalusersondomainjoinedcomputers"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_windowslogon_enumeratelocalusersondomainjoinedcomputers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowslogon_enumeratelocalusersondomainjoinedcomputers_1","displayName":"Enabled","description":null,"helpText":null}]},"94c64e0515a13f06":{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_internalname","displayName":"Internal name","description":null,"helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":null},"94f044c4209cfe37":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_minimumpinlength","displayName":"Minimum PIN Length (User)","description":"Minimum PIN length configures the minimum number of characters required for the PIN. The lowest number you can configure for this policy setting is 4. The largest number you can configure must be less than the number configured in the Maximum PIN length policy setting or the number 127, whichever is the lowest.\n\nIf you configure this policy setting, the PIN length must be greater than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be greater than or equal to 4.\n\nNOTE: If the above specified conditions for the minimum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"949e3e22509db916":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"6730f0be-a129-4b48-942f-e4ddf69fee66","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},"94b76b72647c6ec7":{"id":"user_vendor_msft_policy_config_admx_icm_shellremoveorderprints_1","displayName":"Turn off the \"Order Prints\" picture task (User)","description":"This policy setting specifies whether the \"Order Prints Online\" task is available from Picture Tasks in Windows folders.\r\n\r\nThe Order Prints Online Wizard is used to download a list of providers and allow users to order prints online.\r\n\r\nIf you enable this policy setting, the task \"Order Prints Online\" is removed from Picture Tasks in File Explorer folders.\r\n\r\nIf you disable or do not configure this policy setting, the task is displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremoveorderprints-1"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_icm_shellremoveorderprints_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_icm_shellremoveorderprints_1_1","displayName":"Enabled","description":null,"helpText":null}]},"94b576b4c8f7b10b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_tpmmanagement","displayName":"TPM Management (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-tpmmanagement"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_tpmmanagement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_tpmmanagement_1","displayName":"Enabled","description":null,"helpText":null}]},"9468ceae05b3d74e":{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity","displayName":"Turn off password security in Input Panel (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_4","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_5","displayName":"High","description":null,"helpText":null}]},"948e6700ad0da00b":{"id":"user_vendor_msft_policy_config_admx_wordwheel_customsearch_customsearch_nameprompt","displayName":"The string or DLL resource from which to load the string shown in the Instant Search menu. (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"72972c43-36a3-4034-8cc8-334c99087798","categoryName":"Instant Search","options":null},"940dd24fb5b2e7c5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended","displayName":"URLs to open on startup (User)","description":"If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open.\r\n\r\nIf not set, the New Tab page opens on start up.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://example.com\r\nhttps://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"94d75bf6116917b8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled","displayName":"Allow background tabs freeze (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"94950956db2b8555":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions. (User)","description":"Extensions that connect to one of these origins will be be kept running as long as the port is connected.\r\n\r\nIf unset, the policy's default values will be used. These are app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\r\n- Smart Card Connector\r\n- Citrix Receiver (stable, beta, back-up)\r\n- VMware Horizon (stable, beta)\r\n\r\nIf set, the default value list is extended with the newly configured values. Both defaults and the policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.\r\n\r\nExample value:\r\n\r\nchrome-extension://abcdefghijklmnopabcdefghijklmnop/\r\nchrome-extension://bcdefghijklmnopabcdefghijklmnopa/","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_1","displayName":"Enabled","description":null,"helpText":null}]},"949887b17fef96a3":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist","displayName":"Blocklist for install types of extensions (User)","description":"The blocklist controls which extensions install types are disallowed.\r\n\r\nSetting \"command_line\" will block extension from being loaded from\r\ncommand line.\r\n\r\nExample value:\r\n\r\ncommand_line","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"941964004a0ebf5f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon11","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"9486b1c592f6abf2":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay","displayName":"Enable four-digit year display (User)","description":"When this setting is not enabled, Excel follows the Short date style setting under Regional Settings in Control Panel. When this setting is enabled, Excel always displays four digits when you type a date that includes a four-digit year, which may override the Short date style setting under Regional Settings in Control Panel.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay_1","displayName":"Enabled","description":null,"helpText":null}]},"94e4ccb98e1aa62a":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"94ecdc4965163f72":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, users are queried whether to allow the control to be loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"94df499c1976e2bf":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled","displayName":"Allow users to configure Site safety services (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy is obselete as the feature is being removed after Microsoft Edge version 127.\r\n\r\nThis policy disables site safety services from showing top site info in the page info dialog.\r\n\r\nIf you enable this policy or don't configure it, the top site info will be shown.\r\n\r\nIf you disable this policy, the top site info will not be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"94d2a2a7a99a9363":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (User)","description":"Configure the list of Edge Website Typo Protection trusted domains. This means:\r\nEdge Website Typo Protection won't check for potentially malicious typosquatting websites.\r\n\r\nIf you enable this policy, Edge Website Typo Protection trusts these domains.\r\nIf you disable or don't set this policy, default Edge Website Typo Protection protection is applied to all resources.\r\n\r\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.\r\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allow and block lists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators).\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"949418eca1e75765":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_inprivatemodeurlallowlistdesc","displayName":"Allow access to a list of URLs in InPrivate mode. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"94874ff264204316":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls_sensorsblockedforurlsdesc","displayName":"Block access to sensors on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9431aab66afdd0ff":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"948e3b38ad1c1de7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_l_placesbarname225","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},"9429bef31725a164":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook_1","displayName":"True","description":null,"helpText":null}]},"9487cb822729fbae":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal","displayName":"Portuguese (Portugal) (User)","description":"Enables the editing language Portuguese (Portugal)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal_1","displayName":"Enabled","description":null,"helpText":null}]},"94a780bef4517999":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_datecolon251","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"94aaac4cf94cdb33":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_descriptioncolon300","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"94d231097dceade4":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit","displayName":"Limit the sync app upload speed to a fixed rate (User)","description":"This setting lets you configure the maximum speed at which the OneDrive sync app (OneDrive.exe) can upload files. This rate is a fixed value in kilobytes per second. The lower the rate, the slower the computer will upload files. The minimum rate that can be set is 1 KB/s and the maximum rate is 100000 KB/s. Any input lower than 50 KB/s will set the limit to 50 KB/s, even if the UI shows the inputted rate.\r\n\r\nIf you enable this setting, computers will use the maximum upload rate that you specify, and users will not be able to change it in OneDrive settings.\r\n\r\nIf you disable or do not configure this setting, users can choose to limit the upload rate to a fixed value (in KB/second), or set it to \"Adjust automatically\" which will use 70% of upload throughput to respond to increases and decreases in throughput.\r\n\r\nInstead of using this setting to limit the upload rate, we recommend enabling \"Limit the sync app upload rate to a percentage of throughput\" to set a limit that adjusts to changing conditions. You should not enable both settings at the same time.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_1","displayName":"Enabled","description":null,"helpText":null}]},"948d30673dfa656e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29","displayName":"\r\nSets which ActiveX controls to allow.\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_0","displayName":"Load only Outlook Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_1","displayName":"Allows only Safe Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_2","displayName":"Allows all ActiveX Controls","description":null,"helpText":null}]},"944efa42a0814953":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting_1","displayName":"Enabled","description":null,"helpText":null}]},"9404800fcbc32ef5":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles","displayName":"PowerPoint 2007 and later presentations, shows, templates, themes and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"947a2859a414687f":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Publisher (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},"94a5c6ce415c6241":{"id":"user_vendor_msft_policy_config_remotedesktop_autosubscription","displayName":"Auto-subscription (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider"],"categoryId":"c14c2e8b-0081-46e0-89ac-48ade3b83408","categoryName":"Remote Desktop","options":null},"9486014f06456452":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"943bbf66fa78250f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors","displayName":"Table compare colors (User)","description":"This option determines the colors used for displaying the results of compared tables. Selecting ''none'' will track the changes, but they will not be colored in the resulting document (they will be listed in the reviewing pane).","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_1","displayName":"Enabled","description":null,"helpText":null}]},"948b316189d2d1ce":{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_status","displayName":"Status (User)","description":"Univeral Print printer status.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null}} \ No newline at end of file +{"94be7ba91f33be74":{"id":"ade_macos_awaitconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_macos_awaitconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_macos_awaitconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},"94323fb0c1cfc39f":{"id":"com.apple.domains_crosssitetrackingpreventionrelaxedapps","displayName":"Cross Site Tracking Prevention Relaxed Apps","description":"An array of up to 10 strings representing app bundle-ids. Apps matching the bundle-ids listed here have relaxed enforcement of cross-site tracking prevention for the domains listed in `CrossSiteTrackingPreventionRelaxedDomains`.\n\nAvailable in iOS 18 and later and macOS 15 and later.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},"94eb62d612016c33":{"id":"com.apple.extensiblesso_extensiondata_domainrealmmapping_generickey_kerberos_string","displayName":"Domain Realm Mapping","description":"An array of DNS Suffixes that map to the realm.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"94407b5a3740880d":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-curfew_enabled_true","displayName":"True","description":null,"helpText":null}]},"94f767af1900b116":{"id":"com.apple.managedclient.preferences_builtindnsclientenabled","displayName":"Use built-in DNS client","description":"Controls whether to use the built-in DNS client.\n\nThis does not affect which DNS servers are used; just the software stack which is used to communicate with them. For example if the operating system is configured to use an enterprise DNS server, that same server would be used by the built-in DNS client. It is however possible that the built-in DNS client will address servers in different ways by using more modern DNS-related protocols such as DNS-over-TLS.\n\nIf you enable this policy, the built-in DNS client is used, if it's available.\n\nIf you disable this policy, the client is never used.\n\nIf you don't configure this policy, the built-in DNS client is enabled by default on MacOS, and users can change whether to use the built-in DNS client by editing edge://flags or by specifying a command-line flag.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtindnsclientenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtindnsclientenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtindnsclientenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9468a2c47a6bc2aa":{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit","displayName":"Clear cached images and files when Microsoft Edge closes","description":"Microsoft Edge doesn't clear cached images and files by default when it closes.\n\nIf you enable this policy, cached images and files will be deleted each time Microsoft Edge closes.\n\nIf you disable this policy, users cannot configure the cached images and files option in edge://settings/clearBrowsingDataOnClose.\n\nIf you don't configure this policy, users can choose whether cached images and files are cleared on exit.\n\nIf you disable this policy, don't enable the \"ClearBrowsingDataOnExit\" policy, because they both deal with deleting data. If you configure both, the \"ClearBrowsingDataOnExit\" policy takes precedence and deletes all data when Microsoft Edge closes, regardless of how you configured \"ClearCachedImagesAndFilesOnExit\".","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#clearcachedimagesandfilesonexit"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_clearcachedimagesandfilesonexit_true","displayName":"Enabled","description":null,"helpText":null}]},"945a24e9bc6d5dea":{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Online revocation checks don't provide a significant security benefit and are disabled by default.\n\nIf you enable this policy, Microsoft Edge will perform soft-fail, online OCSP/CRL checks. \"Soft fail\" means that if the revocation server can't be reached, the certificate will be considered valid.\n\nIf you disable the policy or don't configure it, Microsoft Edge won't perform online revocation checks.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableonlinerevocationchecks"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableonlinerevocationchecks_true","displayName":"Enabled","description":null,"helpText":null}]},"94772d68177953d0":{"id":"com.apple.managedclient.preferences_showcasticonintoolbar","displayName":"Show the cast icon in the toolbar","description":"Set this policy to true to show the Cast toolbar icon on the toolbar or the overflow menu. Users won't be able to remove it.\n\nIf you don't configure this policy or if you disable it, users can pin or remove the icon by using its contextual menu.\n\nIf you've also set the \"EnableMediaRouter\" policy to false, then this policy is ignored, and the toolbar icon isn't shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showcasticonintoolbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showcasticonintoolbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showcasticonintoolbar_true","displayName":"Enabled","description":null,"helpText":null}]},"94c8f2a5ea0a455c":{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled","displayName":"Allow notifications to set Microsoft Edge as default PDF reader","description":"This policy setting lets you decide whether employees should receive recommendations to set Microsoft Edge as PDF handler.\n\nIf you enable or don't configure this setting, employees receive recommendations from Microsoft Edge to set itself as the default PDF handler.\n\nIf you disable this setting, employees will not receive any notifications from Microsoft Edge to set itself as the default PDF handler.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showpdfdefaultrecommendationsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showpdfdefaultrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"94f405df6c6640d4":{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentregex","displayName":"Password Content Regex","description":"A regular expression string that they system matches against the password to determine whether it complies with a policy. The regular expression uses the ICU syntax (). The string must not exceed 2048 characters in length.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"9469b554f948e3fe":{"id":"com.apple.mobiledevice.passwordpolicy_minutesuntilfailedloginreset","displayName":"Minutes Until Failed Login Reset","description":"The number of minutes before the login is reset after the maximum number of unsuccessful login attempts is reached. This key requires setting Max Failed Attempts. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"94b09153943a4ef1":{"id":"com.apple.tcc.configuration-profile-policy_services_listenevent","displayName":"Listen Event","description":"Allows the application to use CoreGraphics and HID APIs to listen to (receive) CGEvents and HID events from all processes. A profile can't grant access to these events; it can only deny it.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"9421a8f7bb9f7c2b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the Favorites check box is automatically selected in the Import browser data dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\nNote: This policy currently manages import from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importfavorites_true","displayName":"Enabled","description":null,"helpText":null}]},"941add0621c49882":{"id":"command_remotedesktop_remotedesktop","displayName":"Remote Desktop","description":"Enable/Disable Remote Desktop on the device","helpText":null,"infoUrls":[],"categoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","categoryName":"Remote Desktop","options":[{"id":"command_remotedesktop_remotedesktop_true","displayName":"Enable","description":null,"helpText":null},{"id":"command_remotedesktop_remotedesktop_false","displayName":"Disable","description":null,"helpText":null}]},"94b32346302c9b56":{"id":"contentcaching_allowpersonalcaching","displayName":"Allow Personal Caching","description":"If `true`, the system caches the user's iCloud data. Changes to this value don't have an immediate effect. Clients may take some time to react to changes.\n\n> Note:\n> At least one of the `AllowPersonalCaching` or `AllowSharedCaching` keys need to be `true`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_allowpersonalcaching_false","displayName":"Blocked","description":null,"helpText":null},{"id":"contentcaching_allowpersonalcaching_true","displayName":"Allowed","description":null,"helpText":null}]},"94929c29e026d4b2":{"id":"device_vendor_msft_email_emailserver","displayName":"Email Server","description":"The Exchange location (URL) of the email server to which the app you specified connects to get email.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/email2-csp"],"categoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","categoryName":"Email","options":null},"94bd17fb0a23ed8b":{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration","displayName":"Restrict delegation of credentials to remote servers","description":"When running in Restricted Admin or Remote Credential Guard mode, participating apps do not expose signed in or supplied credentials to a remote host. Restricted Admin limits access to resources located on other servers or networks from the remote host because credentials are not delegated. Remote Credential Guard does not limit access to resources because it redirects all requests back to the client device.\r\n\r\nParticipating apps:\r\nRemote Desktop Client\r\n\r\nIf you enable this policy setting, the following options are supported:\r\n \r\nRestrict credential delegation: Participating applications must use Restricted Admin or Remote Credential Guard to connect to remote hosts.\r\n \r\nRequire Remote Credential Guard: Participating applications must use Remote Credential Guard to connect to remote hosts.\r\n \r\nRequire Restricted Admin: Participating applications must use Restricted Admin to connect to remote hosts.\r\n\r\nIf you disable or do not configure this policy setting, Restricted Admin and Remote Credential Guard mode are not enforced and participating apps can delegate credentials to remote devices.\r\n\r\nNote: To disable most credential delegation, it may be sufficient to deny delegation in Credential Security Support Provider (CredSSP) by modifying Administrative template settings (located at Computer Configuration\\Administrative Templates\\System\\Credentials Delegation).\r\n\r\nNote: On Windows 8.1 and Windows Server 2012 R2, enabling this policy will enforce Restricted Administration mode, regardless of the mode chosen. These versions do not support Remote Credential Guard.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-restrictedremoteadministration"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_restrictedremoteadministration_1","displayName":"Enabled","description":null,"helpText":null}]},"94487dae2c4eb054":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1","displayName":"Configure log access","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable or do not configure this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nNote: If you enable this policy setting, some tools and APIs may ignore it. The same change should be made to the \"Configure log access (legacy)\" policy setting to enforce this change across all tools and APIs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_1_1","displayName":"Enabled","description":null,"helpText":null}]},"94b661923e479a70":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_assignaturedue_signatureupdate_assignaturedue","displayName":"Define the number of days before spyware security intelligence is considered out of date","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},"945d5696e356352d":{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse","displayName":"Allow users to browse for source while elevated","description":"This policy setting allows users to search for installation files during privileged installations.\r\n\r\nIf you enable this policy setting, the Browse button in the \"Use feature from\" dialog box is enabled. As a result, users can search for installation files even when the installation program is running with elevated system privileges.\r\n\r\nBecause the installation is running with elevated system privileges, users can browse through directories that their own permissions would not allow.\r\n\r\nThis policy setting does not affect installations that run in the user's security context. Also, see the \"Remove browse dialog box for new source\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, by default, only system administrators can browse during installations with elevated privileges, such as installations offered on the desktop or displayed in Add or Remove Programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-allowlockdownbrowse"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_allowlockdownbrowse_1","displayName":"Enabled","description":null,"helpText":null}]},"944981b389bb7a8d":{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers","displayName":"Specify permitted managers","description":"This policy setting determines the permitted list of hosts that can submit a query to the Simple Network Management (SNMP) agent running on the client computer.\r\n\r\nSimple Network Management Protocol is a protocol designed to give a user the capability to remotely manage a computer network by polling and setting terminal values and monitoring network events.\r\n\r\nThe manager is located on the host computer on the network. The manager's role is to poll the agents for certain requested information.\r\n\r\nIf you enable this policy setting, the SNMP agent only accepts requests from the list of permitted managers that you configure using this setting.\r\n\r\nIf you disable or do not configure this policy setting, SNMP service takes the permitted managers configured on the local computer instead.\r\n\r\nBest practice: For security purposes, it is recommended to restrict the HKLM\\SOFTWARE\\Policies\\SNMP\\Parameters\\PermittedManagers key to allow only the local admin group full control.\r\n\r\nNote: This policy setting has no effect if the SNMP agent is not installed on the client computer.\r\n\r\nAlso, see the other two SNMP policy settings: \"Specify trap configuration\" and \"Specify Community Name\".\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-snmp#admx-snmp-snmp-permittedmanagers"],"categoryId":"930d2960-3f70-48ca-9ead-b65a5a037c07","categoryName":"SNMP","options":[{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_snmp_snmp_permittedmanagers_1","displayName":"Enabled","description":null,"helpText":null}]},"944d2251a302b4f0":{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar","displayName":"Configure Favorites Bar","description":"The favorites bar shows your user's links to sites they have added to it. With this policy, you can specify whether to set the favorites bar to always be visible or hidden on any page. If enabled, favorites bar is always visible on any page, and the favorites bar toggle in Settings sets to On, but disabled preventing your users from making changes. An error message also shows at the top of the Settings pane indicating that your organization manages some settings. The show bar/hide bar option is hidden from the context menu. If disabled, the favorites bar is hidden, and the favorites bar toggle resets to Off, but disabled preventing your users from making changes. An error message also shows at the top of the Settings pane indicating that your organization manages some settings. If not configured, the favorites bar is hidden but is visible on the Start and New Tab pages, and the favorites bar toggle in Settings sets to Off but is enabled allowing the user to make changes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurefavoritesbar"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar_0","displayName":"Disabled","description":"Hide the favorites bar on all pages. Also, the favorites bar toggle, in Settings, is set to Off and disabled preventing users from making changes. Microsoft Edge also hides the “show bar/hide bar” option in the context menu.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurefavoritesbar_1","displayName":"Enabled","description":"Show the favorites bar on all pages. Also, the favorites bar toggle, in Settings, is set to On and disabled preventing users from making changes. Microsoft Edge also hides the “show bar/hide bar” option in the context menu.","helpText":null}]},"948e598a6fa69258":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins","displayName":"Allow running plugins that are outdated","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowoutdatedplugins_1","displayName":"Enabled","description":null,"helpText":null}]},"94307bc164142ce7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_newtabpagelocation","displayName":"New Tab page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},"94f94608211375d7":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings","displayName":"Enable automated password change","description":"This policy controls the availability of Google Chrome's automated password change feature.\r\n\r\nIf enabled, a user can trigger a process where the browser attempts to change their password on a website automatically. This process is managed by Generative AI. The new password is saved in the browser's password manager.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"94c549e462176368":{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats","displayName":"Remediation action for High severity threats","description":"","helpText":"","infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_clean","displayName":"Clean. Service tries to recover files and try to disinfect.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_quarantine","displayName":"Quarantine. Moves files to quarantine.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_remove","displayName":"Remove. Removes files from system.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_allow","displayName":"Allow. Allows file/does none of the above actions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_userdefined","displayName":"User defined. Requires user to make a decision on which action to take.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_highseveritythreats_block","displayName":"Block. Blocks file execution.","description":null,"helpText":null}]},"942926abbb33cfbb":{"id":"device_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing","displayName":"Turn off InPrivate Browsing","description":"This policy setting allows you to turn off the InPrivate Browsing feature.\n\nInPrivate Browsing prevents Internet Explorer from storing data about a user's browsing session. This includes cookies, temporary Internet files, history, and other data.\n\nIf you enable this policy setting, InPrivate Browsing is turned off.\n\nIf you disable this policy setting, InPrivate Browsing is available for use.\n\nIf you do not configure this policy setting, InPrivate Browsing can be turned on or off through the registry.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinprivatebrowsing"],"categoryId":"f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableinprivatebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},"943af4d0f08396ee":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver","displayName":"Include local path when user is uploading files to a server","description":"This policy setting controls whether or not local path information is sent when the user is uploading a file via an HTML form. If the local path information is sent, some information may be unintentionally revealed to the server. For instance, files sent from the user's desktop may contain the user name as a part of the path.\n\nIf you enable this policy setting, path information is sent when the user is uploading a file via an HTML form.\n\nIf you disable this policy setting, path information is removed when the user is uploading a file via an HTML form.\n\nIf you do not configure this policy setting, the user can choose whether path information is sent when he or she is uploading a file via an HTML form. By default, path information is sent.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneincludelocalpathwhenuploadingfilestoserver"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_1","displayName":"Enabled","description":null,"helpText":null}]},"94e23314dd589ce8":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001","displayName":"Download signed ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonedownloadsignedactivexcontrols_iz_partname1001_1","displayName":"Prompt","description":null,"helpText":null}]},"94c953ddec39957d":{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256","displayName":"PK Init Hash Algorithm SHA256","description":"Configure SHA-256 hash algorithm for certificate logon","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Kerberos#pkinithashalgorithmsha256"],"categoryId":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256_0","displayName":"Not Supported","description":"Not Supported","helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256_1","displayName":"Default","description":"Default","helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256_2","displayName":"Audited","description":"Audited","helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_pkinithashalgorithmsha256_3","displayName":"Supported","description":"Supported","helpText":null}]},"94adbfb519bcf352":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_shutdown_clearvirtualmemorypagefile","displayName":"Shutdown Clear Virtual Memory Page File","description":"Shutdown: Clear virtual memory pagefile This security setting determines whether the virtual memory pagefile is cleared when the system is shut down. Virtual memory support uses a system pagefile to swap pages of memory to disk when they are not used. On a running system, this pagefile is opened exclusively by the operating system, and it is well protected. However, systems that are configured to allow booting to other operating systems might have to make sure that the system pagefile is wiped clean when this system shuts down. This ensures that sensitive information from process memory that might go into the pagefile is not available to an unauthorized user who manages to directly access the pagefile. When this policy is enabled, it causes the system pagefile to be cleared upon clean shutdown. If you enable this security option, the hibernation file (hiberfil.sys) is also zeroed out when hibernation is disabled. Default: Disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#shutdown_clearvirtualmemorypagefile"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_shutdown_clearvirtualmemorypagefile_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_shutdown_clearvirtualmemorypagefile_0","displayName":"Disable","description":"Disable","helpText":null}]},"940d01cbe3b79b4d":{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc","displayName":"Local group","description":"This Setting allows an administrator to manage local groups on a Device. Possible settings: 1. Update Group Membership: Update a group and add and/or remove members though the 'U' action. When using Update, existing group members that are not specified in the policy remain untouched. 2. Replace Group Membership: Restrict a group by replacing group membership through the 'R' action. When using Replace, existing group membership is replaced by the list of members specified in the add member section. This option works in the same way as a Restricted Group and any group members that are not specified in the policy are removed. Caution: If the same group is configured with both Replace and Update, then Replace will win.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-localusersandgroups"],"categoryId":"b86100f0-e4ae-4f93-9dae-dd253a96726f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_administrators","displayName":"Administrators","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_users","displayName":"Users","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_guests","displayName":"Guests","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_powerusers","displayName":"Power Users","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_remotedesktopusers","displayName":"Remote Desktop Users","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_localusersandgroups_configure_groupconfiguration_accessgroup_desc_remotemanagementusers","displayName":"Remote Management Users","description":null,"helpText":null}]},"94ecb7c834ca277e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9494dbc7d110a4e6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"943d2daacbdaaaba":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled","displayName":"DataURL Whitespace Preservation for all media types","description":"This policy provides a temporary opt-out for changes to how Edge handles whitepsace in data URLS.\r\nPreviously, whitespace would be kept only if the top level media type was text or contained the media type string xml.\r\nNow, whitespace will be preserved in all data URLs, regardless of media type.\r\n\r\nIf this policy is left unset or is set to True, the new behavior is enabled.\r\n\r\nWhen this policy is set to False, the old behavior is enabled.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~network_dataurlwhitespacepreservationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"947aef90cc978eed":{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended","displayName":"Allow importing of extensions","description":"Allows users to import extensions from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Extensions** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, extensions aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, extensions are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports extensions on first run, but users can select or clear the **extensions** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_recommended_importextensions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"943f5fc34d4abbe6":{"id":"device_vendor_msft_policy_config_update_engagedrestarttransitionscheduleforfeatureupdates","displayName":"Engaged Restart Transition Schedule For Feature Updates","description":"For Feature Updates, this policy specifies the timing before transitioning from Auto restarts scheduled_outside of active hours to Engaged restart, which requires the user to schedule. The period can be set between 2 and 30 days from the time the restart becomes pending. Value type is integer. Default value is 7 days. Supported value range: 2 - 30. If you disable or do not configure this policy, the default behaviors will be used. If any of the following policies are configured, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installationsAlways automatically restart at scheduled timeSpecify deadline before auto-restart for update installation","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#engagedrestarttransitionscheduleforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"940648929e061a96":{"id":"device_vendor_msft_policy_config_wifi_wlanscanmode","displayName":"WLAN Scan Mode","description":"Allow an enterprise to control the WLAN scanning behavior and how aggressively devices should be actively scanning for Wi-Fi networks to get devices connected. Supported values are 0-500, where 100 = normal scan frequency and 500 = low scan frequency. The default value is 0. Supported operations are Add, Delete, Get, and Replace.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-wifi#wlanscanmode"],"categoryId":"0a803a48-789a-48b0-b928-e52d56ab17f1","categoryName":"Wi-Fi Settings","options":null},"94367dcab2dcceea":{"id":"device_vendor_msft_policy_config_windowslogon_enumeratelocalusersondomainjoinedcomputers","displayName":"Enumerate local users on domain-joined computers","description":"This policy setting allows local users to be enumerated on domain-joined computers. \n\nIf you enable this policy setting, Logon UI will enumerate all local users on domain-joined computers.\n\nIf you disable or do not configure this policy setting, the Logon UI will not enumerate local users on domain-joined computers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowslogon#windowslogon-enumeratelocalusersondomainjoinedcomputers"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_windowslogon_enumeratelocalusersondomainjoinedcomputers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowslogon_enumeratelocalusersondomainjoinedcomputers_1","displayName":"Enabled","description":null,"helpText":null}]},"94c64e0515a13f06":{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_internalname","displayName":"Internal name","description":null,"helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":null},"94f044c4209cfe37":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_minimumpinlength","displayName":"Minimum PIN Length (User)","description":"Minimum PIN length configures the minimum number of characters required for the PIN. The lowest number you can configure for this policy setting is 4. The largest number you can configure must be less than the number configured in the Maximum PIN length policy setting or the number 127, whichever is the lowest.\n\nIf you configure this policy setting, the PIN length must be greater than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be greater than or equal to 4.\n\nNOTE: If the above specified conditions for the minimum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"949e3e22509db916":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"6730f0be-a129-4b48-942f-e4ddf69fee66","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},"94b76b72647c6ec7":{"id":"user_vendor_msft_policy_config_admx_icm_shellremoveorderprints_1","displayName":"Turn off the \"Order Prints\" picture task (User)","description":"This policy setting specifies whether the \"Order Prints Online\" task is available from Picture Tasks in Windows folders.\r\n\r\nThe Order Prints Online Wizard is used to download a list of providers and allow users to order prints online.\r\n\r\nIf you enable this policy setting, the task \"Order Prints Online\" is removed from Picture Tasks in File Explorer folders.\r\n\r\nIf you disable or do not configure this policy setting, the task is displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremoveorderprints-1"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_icm_shellremoveorderprints_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_icm_shellremoveorderprints_1_1","displayName":"Enabled","description":null,"helpText":null}]},"94b576b4c8f7b10b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_tpmmanagement","displayName":"TPM Management (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-tpmmanagement"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_tpmmanagement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_tpmmanagement_1","displayName":"Enabled","description":null,"helpText":null}]},"9468ceae05b3d74e":{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity","displayName":"Turn off password security in Input Panel (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_4","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_1_passwordsecurity_5","displayName":"High","description":null,"helpText":null}]},"948e6700ad0da00b":{"id":"user_vendor_msft_policy_config_admx_wordwheel_customsearch_customsearch_nameprompt","displayName":"The string or DLL resource from which to load the string shown in the Instant Search menu. (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"72972c43-36a3-4034-8cc8-334c99087798","categoryName":"Instant Search","options":null},"940dd24fb5b2e7c5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended","displayName":"URLs to open on startup (User)","description":"If RestoreOnStartup is set to RestoreOnStartupIsURLs, then setting RestoreOnStartupURLs to a list of URLs specify which URLs open.\r\n\r\nIf not set, the New Tab page opens on start up.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nhttps://example.com\r\nhttps://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartupurls_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"94d75bf6116917b8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled","displayName":"Allow background tabs freeze (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"94950956db2b8555":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions. (User)","description":"Extensions that connect to one of these origins will be be kept running as long as the port is connected.\r\n\r\nIf unset, the policy's default values will be used. These are app origins that offer SDKs that are known to not offer the possibility to restart a closed connection to a previous state:\r\n- Smart Card Connector\r\n- Citrix Receiver (stable, beta, back-up)\r\n- VMware Horizon (stable, beta)\r\n\r\nIf set, the default value list is extended with the newly configured values. Both defaults and the policy-provided entries will grant the exception to the connecting extensions, as long as the port is connected.\r\n\r\nExample value:\r\n\r\nchrome-extension://abcdefghijklmnopabcdefghijklmnop/\r\nchrome-extension://bcdefghijklmnopabcdefghijklmnopa/","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_1","displayName":"Enabled","description":null,"helpText":null}]},"949887b17fef96a3":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist","displayName":"Blocklist for install types of extensions (User)","description":"The blocklist controls which extensions install types are disallowed.\r\n\r\nSetting \"command_line\" will block extension from being loaded from\r\ncommand line.\r\n\r\nExample value:\r\n\r\ncommand_line","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"941964004a0ebf5f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_descriptioncolon11","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"9486b1c592f6abf2":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay","displayName":"Enable four-digit year display (User)","description":"When this setting is not enabled, Excel follows the Short date style setting under Regional Settings in Control Panel. When this setting is enabled, Excel always displays four digits when you type a date that includes a four-digit year, which may override the Short date style setting under Regional Settings in Control Panel.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_enablefourdigityeardisplay_1","displayName":"Enabled","description":null,"helpText":null}]},"94e4ccb98e1aa62a":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"94ecdc4965163f72":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, users are queried whether to allow the control to be loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"94df499c1976e2bf":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled","displayName":"Allow users to configure Site safety services (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy is obselete as the feature is being removed after Microsoft Edge version 127.\r\n\r\nThis policy disables site safety services from showing top site info in the page info dialog.\r\n\r\nIf you enable this policy or don't configure it, the top site info will be shown.\r\n\r\nIf you disable this policy, the top site info will not be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_sitesafetyservicesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"94d2a2a7a99a9363":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (User)","description":"Configure the list of Edge Website Typo Protection trusted domains. This means:\r\nEdge Website Typo Protection won't check for potentially malicious typosquatting websites.\r\n\r\nIf you enable this policy, Edge Website Typo Protection trusts these domains.\r\nIf you disable or don't set this policy, default Edge Website Typo Protection protection is applied to all resources.\r\n\r\nThis will only take effect when TyposquattingCheckerEnabled policy is not set or set to enabled.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10/11 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.\r\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender for Endpoint. You must configure your allow and block lists in Microsoft 365 Defender portal using Indicators (Settings > Endpoints > Indicators).\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"949418eca1e75765":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_inprivatemodeurlallowlistdesc","displayName":"Allow access to a list of URLs in InPrivate mode. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"94874ff264204316":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsblockedforurls_sensorsblockedforurlsdesc","displayName":"Block access to sensors on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9431aab66afdd0ff":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"948e3b38ad1c1de7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy9_l_placesbarname225","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},"9429bef31725a164":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook","displayName":"Disallow in Outlook (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyoutlook_1","displayName":"True","description":null,"helpText":null}]},"9487cb822729fbae":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal","displayName":"Portuguese (Portugal) (User)","description":"Enables the editing language Portuguese (Portugal)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portugueseportugal_1","displayName":"Enabled","description":null,"helpText":null}]},"94a780bef4517999":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_datecolon251","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"94aaac4cf94cdb33":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc16_l_descriptioncolon300","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"94d231097dceade4":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit","displayName":"Limit the sync app upload speed to a fixed rate (User)","description":"This setting lets you configure the maximum speed at which the OneDrive sync app (OneDrive.exe) can upload files. This rate is a fixed value in kilobytes per second. The lower the rate, the slower the computer will upload files. The minimum rate that can be set is 1 KB/s and the maximum rate is 100000 KB/s. Any input lower than 50 KB/s will set the limit to 50 KB/s, even if the UI shows the inputted rate.\r\n\r\nIf you enable this setting, computers will use the maximum upload rate that you specify, and users will not be able to change it in OneDrive settings.\r\n\r\nIf you disable or do not configure this setting, users can choose to limit the upload rate to a fixed value (in KB/second), or set it to \"Adjust automatically\" which will use 70% of upload throughput to respond to increases and decreases in throughput.\r\n\r\nInstead of using this setting to limit the upload rate, we recommend enabling \"Limit the sync app upload rate to a percentage of throughput\" to set a limit that adjusts to changing conditions. You should not enable both settings at the same time.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_uploadbandwidthlimit_1","displayName":"Enabled","description":null,"helpText":null}]},"948d30673dfa656e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29","displayName":"\r\nSets which ActiveX controls to allow.\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_0","displayName":"Load only Outlook Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_1","displayName":"Allows only Safe Controls","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_allowactivexoneoffforms_v2_l_empty29_2","displayName":"Allows all ActiveX Controls","description":null,"helpText":null}]},"944efa42a0814953":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_draganddroptextediting_1","displayName":"Enabled","description":null,"helpText":null}]},"9404800fcbc32ef5":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles","displayName":"PowerPoint 2007 and later presentations, shows, templates, themes and add-in files (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_ppt~l_options~l_security~l_trustcenter~l_fileblocksettings_l_ppt2007andlaterpresentationsshowstemplatesthemesandaddinfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"947a2859a414687f":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath","displayName":"Personal templates path for Publisher (User)","description":"This policy setting specifies the location of a user's personal templates. \r\n\r\nIf you enable this policy setting, users will see any templates they have saved in the specified location in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will change to be the specified location. \r\n\r\nIf you disable or do not configure this policy setting, users will not see templates they have saved in the custom templates tab on the Office Start screen and in File | New and when saving a template their default folder will be their document save location.","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_personaltemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},"94a5c6ce415c6241":{"id":"user_vendor_msft_policy_config_remotedesktop_autosubscription","displayName":"Auto-subscription (User)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-configuration-service-provider"],"categoryId":"c14c2e8b-0081-46e0-89ac-48ade3b83408","categoryName":"Remote Desktop","options":null},"9486014f06456452":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_pathcolon","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"943bbf66fa78250f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors","displayName":"Table compare colors (User)","description":"This option determines the colors used for displaying the results of compared tables. Selecting ''none'' will track the changes, but they will not be colored in the resulting document (they will be listed in the reviewing pane).","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_1","displayName":"Enabled","description":null,"helpText":null}]},"948b316189d2d1ce":{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_status","displayName":"Status (User)","description":"Univeral Print printer status.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PrinterProvisioning-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/9a.json b/public/intune-definitions/9a.json index 83953fad1b1d..8af6907d7308 100644 --- a/public/intune-definitions/9a.json +++ b/public/intune-definitions/9a.json @@ -1 +1 @@ -{"9ae86dfef3b07c6b":{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing","displayName":"Allow Safari Private Browsing","description":"If `false`, the system disables the ability to use private browsing in Safari.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing_true","displayName":"True","description":null,"helpText":null}]},"9a1fb15a2cec417f":{"id":"com.apple.extensiblesso_hosts_kerberos","displayName":"Hosts","description":"One or more host or domain names for which the app extension performs SSO. Host or domain names are matched case-insensitively, and all the host/domain names of all installed Extensible SSO payloads must be unique. Hosts that begin with a “.” are wildcard suffixes and will match all subdomains, otherwise the host must be an exact match.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"9a1a7fc829eb8d47":{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_generickey","displayName":"ANY","description":"The key is an access right value, the value is the group to be associated with that access right.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"9a995e09e1ad4561":{"id":"com.apple.ldap.account_ldapaccountusessl","displayName":"LDAP Account Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":[{"id":"com.apple.ldap.account_ldapaccountusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapaccountusessl_true","displayName":"True","description":null,"helpText":null}]},"9a0c16c7dd468f2a":{"id":"com.apple.managedclient.preferences_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download","description":"This policy sets a list of file types that should be automatically opened on download. Note: The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\n\nBy default, these file types will be automatically opened on all URLs. You can use the \"AutoOpenAllowedForURLs\" policy to restrict the URLs for which these file types will be automatically opened on.\n\nFiles with types that should be automatically opened will still be subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks.\n\nFile types that a user has already specified to automatically be opened will continue to do so when downloaded. The user will continue to be able to specify other file types to be automatically opened.\n\nIf you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoopenfiletypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"9ae0b6d19c35b251":{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory","displayName":"Directory (selected) or file (not selected)","description":"Directory if selected, or file if not selected","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory_true","displayName":"Enabled","description":null,"helpText":null}]},"9ada55415adb85cc":{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"9a770ef8a463fa12":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_1","displayName":"Enabled","description":null,"helpText":null}]},"9a6bd73ec3230e93":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions","displayName":"Turn off Auto Exclusions","description":"\r\n Allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.\r\n\r\n Disabled (Default):\r\n Microsoft Defender will exclude pre-defined list of paths from the scan to improve performance.\r\n\r\n Enabled:\r\n Microsoft Defender will not exclude pre-defined list of paths from scans. This can impact machine performance in some scenarios.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableautoexclusions"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},"9a56fb6162483faf":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen","displayName":"Configure the 'Block at First Sight' feature","description":"This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check will not occur, which will lower the protection state of the device.\r\n Enabled – The Block at First Sight setting is turned on.\r\n Disabled – The Block at First Sight setting is turned off.\r\n \r\n This feature requires these Group Policy settings to be set as follows:\r\n MAPS -> The “Join Microsoft MAPS” must be enabled or the “Block at First Sight” feature will not function.\r\n MAPS -> The “Send file samples when further analysis is required” should be set to 1 (Send safe samples) or 3 (Send all samples). Setting to 0 (Always Prompt) will lower the protection state of the device. Setting to 2 (Never send) means the “Block at First Sight” feature will not function.\r\n Real-time Protection -> The “Scan all downloaded files and attachments” policy must be enabled or the “Block at First Sight” feature will not function.\r\n Real-time Protection -> Do not enable the “Turn off real-time protection” policy or the “Block at First Sight” feature will not function.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableblockatfirstseen"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen_1","displayName":"Enabled","description":null,"helpText":null}]},"9a4284fc456e4083":{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle","displayName":"Published State Check Interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_30","displayName":"30 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_60","displayName":"1 Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_240","displayName":"4 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_480","displayName":"8 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_720","displayName":"12 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_1440","displayName":"1 Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_4294967295","displayName":"Never","description":null,"helpText":null}]},"9a9979d9214b4bb7":{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"AppSync\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},"9adaa539265c4cc2":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013","displayName":"Microsoft Office 365 Visio 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013_1","displayName":"Enabled","description":null,"helpText":null}]},"9afcf8e605ecd8d6":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"9a36cea66b679c9a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings","description":"Configures browsing data lifetime settings for Google Chrome. This policy allows admins to configure (per data-type) when data is deleted by the browser. This is useful for customers that work with sensitive customer data. The policy will only take effect if SyncDisabled is set to true.\r\n\r\nThe available data types are 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\n\r\nThe browser will automatically remove data of selected types that is older than 'time_to_live_in_hours'. The minimum value that can be set is 1 hour.\r\n\r\nThe deletion of expired data will happen 15 seconds after the browser starts then every hour while the browser is running.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=BrowsingDataLifetime for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"time_to_live_in_hours\": 24,\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ]\r\n },\r\n {\r\n \"time_to_live_in_hours\": 12,\r\n \"data_types\": [\r\n \"password_signin\",\r\n \"autofill\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},"9ae9fd0a4f9efb15":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_javascriptallowedforurlsdesc","displayName":"Allow JavaScript on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"9ad0372e6854dae3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_homepagelocation","displayName":"Home page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},"9ab88701465d0acf":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_webhidallowalldevicesforurlsdesc","displayName":"Automatically grant permission to sites to connect to any HID device. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"9a428d737869269f":{"id":"device_vendor_msft_policy_config_deliveryoptimization_domaxuploadbandwidth","displayName":"DO Max Upload Bandwidth","description":"Specifies the minimum download QoS (Quality of Service or speed) in KiloBytes/sec for background downloads. This policy affects the blending of peer and HTTP sources. Delivery Optimization complements the download from the HTTP source to achieve the minimum QoS value set.","helpText":null,"infoUrls":[],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"9af1e0a35aca5653":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilessiddirectorynamepattern_profilessiddirectorynamepattern","displayName":"SID Directory Name Pattern (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":null},"9a6eab6e898835b4":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols","displayName":"Download signed ActiveX controls","description":"This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.\n\nIf you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.\n\nIf you disable the policy setting, signed controls cannot be downloaded.\n\nIf you do not configure this policy setting, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"9aeac1a001c96df5":{"id":"device_vendor_msft_policy_config_maps_enableofflinemapsautoupdate","displayName":"Enable Offline Maps Auto Update","description":"Disables the automatic download and update of map data. After the policy is applied, you can verify the settings in the user interface in System > Offline Maps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Maps#enableofflinemapsautoupdate"],"categoryId":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","categoryName":"Maps","options":[{"id":"device_vendor_msft_policy_config_maps_enableofflinemapsautoupdate_0","displayName":"Disabled. Force off auto-update.","description":"Disabled. Force off auto-update.","helpText":null},{"id":"device_vendor_msft_policy_config_maps_enableofflinemapsautoupdate_1","displayName":"Enabled. Force on auto-update.","description":"Enabled. Force on auto-update.","helpText":null},{"id":"device_vendor_msft_policy_config_maps_enableofflinemapsautoupdate_65535","displayName":"Not configured. User's choice.","description":"Not configured. User's choice.","helpText":null}]},"9af6f7a1d8cfd01f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting","displayName":"Default images setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting_1","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting_2","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},"9a70b1b069d4a854":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"9a50c2e3d5f67f21":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist_authserverallowlist","displayName":"Configure list of allowed authentication servers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},"9ae6fe3c3472a12d":{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled","displayName":"Guided Switch Enabled","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\r\n\r\nIf you enable this policy, you'll be prompted to switch to another account if the current profile doesn't work for the requesting link.\r\n\r\nIf you disable this policy, you won't be prompted to switch to another account when there's a profile and link mismatch.\r\n\r\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9a8d9c8f66f9e859":{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed","displayName":"Automatically open downloaded MHT or MHTML files from the web in Internet Explorer mode","description":"This policy controls whether MHT or MHTML files that are downloaded from the web are automatically opened in Internet Explorer mode.\r\n\r\nIf you enable this policy, the MHT or MHTML files that are downloaded from the web can be opened in both Microsoft Edge and Internet Explorer mode to provide the best user experience.\r\n\r\nIf you disable or don't configure this policy, MHT or MHTML files that are downloaded from the web won't automatically open in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"9ad8ff6f2411927d":{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended","displayName":"Enable tab preview on hover","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\r\n\r\nIf you disable this policy, tab previews will not be shown on hover.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9a7a351006783abf":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},"9a286d0de01faac1":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9ac17e76c52e9a23":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_licensingsettings_l_orgideduenabledcentennial","displayName":"Enable EDU Org ID Sign In in Office from Windows Store","description":"This policy setting controls whether Office product is activated with the student’s email account. By default, Org Id sign in is not allowed.\r\n\r\nIf you enable this policy setting, student’s email Id sign in will be used to activate the version of Office installed on the computer.\r\n\r\nIf you disable this policy setting, student’s email Id sign in won’t be used to activate the version of Office installed on the computer.\r\n\r\nEnabling or disabling this policy setting takes precedence over any setting that’s been configured by using the Office Deployment Tool or by manually editing the registry.\r\n\r\nIf you don’t configure this policy setting, student’s email Id sign in won’t be used to activate the version of Office installed on the computer unless you’ve enabled Org ID to sign in by manually editing the registry.\r\n ","helpText":"","infoUrls":[],"categoryId":"2e3f0407-6387-41b4-b6c2-ada4354be759","categoryName":"Licensing Settings","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_licensingsettings_l_orgideduenabledcentennial_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_licensingsettings_l_orgideduenabledcentennial_1","displayName":"Enabled","description":null,"helpText":null}]},"9a85d4d1e1da1919":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_miscellaneous_l_ageoutpolicy","displayName":"Age out documents older than n days","description":"This policy controls when locally cached Office documents are aged out of the Office Document Cache","helpText":"","infoUrls":[],"categoryId":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","categoryName":"Miscellaneous","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_miscellaneous_l_ageoutpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_miscellaneous_l_ageoutpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"9a1e5718708deeb6":{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_textbox","displayName":"Tenant ID: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"9acb6f286aa79148":{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlockmicrosoftidentityauthn","displayName":"Disconnect remote session on lock for Microsoft identity platform authentication","description":"This policy setting allows you to configure the user experience when the Remote Desktop session is locked by the user or by a policy. You can specify whether the remote session will show the remote lock screen or disconnect when the remote session is locked. Disconnecting the remote session ensures that a remote session cannot be left on the lock screen and cannot reconnect automatically due to loss of network connectivity.\n\nThis policy applies only when using an identity provider that uses the Microsoft identity platform, such as Microsoft Entra ID, to authenticate to the remote PC. This policy doesn't apply when using Legacy authentication which includes the NTLM, CredSSP, RDSTLS, TLS, and RDP basic authentication protocols.\n\nIf you enable or do not configure this policy setting, Remote Desktop connections using the Microsoft identity platform will disconnect the remote session when the remote session is locked. Users can reconnect when they're ready and can use passwordless authentication if configured.\n\nIf you disable this policy setting, Remote Desktop connections using the Microsoft identity platform will show the remote lock screen when the remote session is locked. Users can unlock the remote session using their username and password, or certificates.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-disconnectonlockmicrosoftidentityauthn"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlockmicrosoftidentityauthn_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlockmicrosoftidentityauthn_1","displayName":"Enabled","description":null,"helpText":null}]},"9a1429a713ed169e":{"id":"device_vendor_msft_policy_config_userrights_manageauditingandsecuritylog","displayName":"Manage Auditing And Security Log","description":"This user right determines which users can specify object access auditing options for individual resources, such as files, Active Directory objects, and registry keys. This security setting does not allow a user to enable file and object access auditing in general. You can view audited events in the security log of the Event Viewer. A user with this privilege can also view and clear the security log.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#manageauditingandsecuritylog"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"9abf4e980244a3f9":{"id":"device_vendor_msft_policy_privilegemanagement_elevationclientsettings_defaultelevationresponse_validation","displayName":"Validation","description":"","helpText":null,"infoUrls":[],"categoryId":"b750fe41-33c4-4293-8dfc-42285be35752","categoryName":null,"options":[{"id":"device_vendor_msft_policy_privilegemanagement_elevationclientsettings_defaultelevationresponse_validation_0","displayName":"Business justification","description":"Business Justification","helpText":null},{"id":"device_vendor_msft_policy_privilegemanagement_elevationclientsettings_defaultelevationresponse_validation_1","displayName":"Windows authentication","description":"Windows Authentication","helpText":null}]},"9a0fa340b9575acf":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders30","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders30_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders30_1","displayName":"True","description":null,"helpText":null}]},"9a230063e71c8da3":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_servermanager","displayName":"Server Manager (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-servermanager"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_servermanager_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_servermanager_1","displayName":"Enabled","description":null,"helpText":null}]},"9abd98d2a53e2535":{"id":"user_vendor_msft_policy_config_admx_startmenu_nocommongroups","displayName":"Remove common program groups from Start Menu (User)","description":"Removes items in the All Users profile from the Programs menu on the Start menu.\r\n\r\nBy default, the Programs menu contains items from the All Users profile and items from the user's profile. If you enable this setting, only items in the user's profile appear in the Programs menu.\r\n\r\nTip: To see the Program menu items in the All Users profile, on the system drive, go to ProgramData\\Microsoft\\Windows\\Start Menu\\Programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nocommongroups"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nocommongroups_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nocommongroups_1","displayName":"Enabled","description":null,"helpText":null}]},"9a97274ff16c6b2f":{"id":"user_vendor_msft_policy_config_admx_startmenu_notoolbarsontaskbar","displayName":"Do not display any custom toolbars in the taskbar (User)","description":"This setting affects the taskbar.\r\n\r\nThe taskbar includes the Start button, buttons for currently running tasks, custom toolbars, the notification area, and the system clock. Toolbars include Quick Launch, Address, Links, Desktop, and other custom toolbars created by the user or by an application.\r\n\r\nIf this setting is enabled, the taskbar does not display any custom toolbars, and the user cannot add any custom toolbars to the taskbar. Moreover, the \"Toolbars\" menu command and submenu are removed from the context menu. The taskbar displays only the Start button, taskbar buttons, the notification area, and the system clock.\r\n\r\nIf this setting is disabled or is not configured, the taskbar displays all toolbars. Users can add or remove custom toolbars, and the \"Toolbars\" command appears in the context menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notoolbarsontaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_notoolbarsontaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_notoolbarsontaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"9aec451dd072299b":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi","displayName":"VDI Configuration (User)","description":"This policy setting configures the synchronization of User Experience Virtualization (UE-V) rollback information for computers running in a non-persistent, pooled VDI environment. UE-V settings rollback data and checkpoints are normally stored only on the local computer. With this policy setting enabled, the rollback information is copied to the settings storage location when the user logs off or shuts down their VDI session. Enable this setting to register a VDI-specific settings location template and restore data on computers in pooled VDI environments that reset to a clean state on logout. With this policy enabled you can roll settings back to the state when UE-V was installed or to “last-known-good” configurations. Only enable this policy setting on computers running in a non-persistent VDI environment. The VDI Collection Name defines the name of the virtual desktop collection containing the virtual computers. \r\nIf you enable this policy setting, the UE-V rollback state is copied to the settings storage location on logout and restored on login.\r\nIf you disable this policy setting, no UE-V rollback state is copied to the settings storage location.\r\nIf you do not configure this policy, no UE-V rollback state is copied to the settings storage location.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-configurevdi"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_1","displayName":"Enabled","description":null,"helpText":null}]},"9a5bfa7613d70c1e":{"id":"user_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge","displayName":"Prevent Access To About Flags In Microsoft Edge (User)","description":"Prevent access to the about:flags page in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventaccesstoaboutflagsinmicrosoftedge"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge_0","displayName":"Disabled","description":"Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge_1","displayName":"Enabled","description":"Prevents users from accessing the about:flags page.","helpText":null}]},"9af6a558866c824b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Do not allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},"9a82686e0e513f53":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata","displayName":"Keep browsing data when creating enterprise profile by default (User)","description":"If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default.\r\n\r\nIf this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.\r\n\r\nRegardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile.\r\n\r\nThis policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata_1","displayName":"Enabled","description":null,"helpText":null}]},"9a1946caf617d3c6":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings","displayName":"Settings for Google's AI Mode integrations in the address bar and New Tab page search box. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings_0","displayName":"Allow AI Mode integrations.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings_1","displayName":"Do not allow AI Mode integrations.","description":null,"helpText":null}]},"9a3e8ab698fde814":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenableprotectedmode"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"9a407a37feb9a250":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended","displayName":"Allow importing of favorites (User)","description":"Allows users to import favorites from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9aa56cc612e17bb9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls","displayName":"Block the Adobe Flash plug-in on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from running Adobe Flash.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9ae9eb8e68162635":{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended","displayName":"Allow users to access the Outlook menu (User)","description":"This policy is used to manage access to the Outlook menu from Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, users can access the Outlook menu.\r\nIf you disable this policy, users can't access the Outlook menu.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9ad6f6c6fd3086c9":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_1","displayName":"Allow all websites to perform automatic downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_2","displayName":"Don't allow any website to perform automatic downloads","description":null,"helpText":null}]},"9acadcb57d89f8ab":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_idletimeout","displayName":"Delay before running idle actions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},"9a83b00170b9225a":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist","displayName":"Open local files in Internet Explorer mode file extension allow list (User)","description":"This policy limits which file:// URLs are allowed to be launched into Internet Explorer mode based on file extension.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nWhen a file:// URL is requested to launch in Internet Explorer mode, the file extension of the URL must be present in this list in order for the URL to be allowed to launch in Internet Explorer mode. A URL which is blocked from opening in Internet Explorer mode will instead open in Edge mode.\r\n\r\nIf you set this policy to the special value \"*\" or don't configure it, all file extensions are allowed.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\nExample value:\r\n\r\n.mht\r\n.pdf\r\n.vsdx","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"9aff65034b008212":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize_l_maximplicitcachesizedecimal","displayName":"Percent of disk space (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"9a4d66f25f703420":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceservername8","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"9aeb2592e2f3f2b9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint_1","displayName":"True","description":null,"helpText":null}]},"9ab9de5970bef1cd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"9a10eca271995ba3":{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook","displayName":"Running Outlook for Simple MAPI Mail Sending (User)","description":"This policy setting determines whether users can send mail through Simple MAPI when Outlook is not active.\r\n\r\nIf you enable this policy setting, users are required to have Outlook running to send mail through Simple MAPI. This will force users to open Outlook to send mail, ensuring that Outlook Add-ins run properly before the mail is sent. \r\n\r\nIf you disable this policy setting, users are allowed to send mail through Simple MAPI regardless of Outlook running.\r\n\r\nWhen this policy setting is not configured, it functions as if it has been disabled, allowing users to send mail through Simple MAPI without having Outlook running.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"9a1a62e14e6f228f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},"9a1282f1018ccc65":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"9ad4e9eacefd9552":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks","displayName":"Optional breaks (User)","description":"Determines whether the symbol used to represent optional breaks is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks_1","displayName":"Enabled","description":null,"helpText":null}]},"9aa3a16c03fd9e89":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]}} \ No newline at end of file +{"9ae86dfef3b07c6b":{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing","displayName":"Allow Safari Private Browsing","description":"If `false`, the system disables the ability to use private browsing in Safari.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowsafariprivatebrowsing_true","displayName":"True","description":null,"helpText":null}]},"9a1fb15a2cec417f":{"id":"com.apple.extensiblesso_hosts_kerberos","displayName":"Hosts","description":"One or more host or domain names for which the app extension performs SSO. Host or domain names are matched case-insensitively, and all the host/domain names of all installed Extensible SSO payloads must be unique. Hosts that begin with a “.” are wildcard suffixes and will match all subdomains, otherwise the host must be an exact match.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"9a1a7fc829eb8d47":{"id":"com.apple.extensiblesso_platformsso_authorizationgroups_generickey","displayName":"ANY","description":"The key is an access right value, the value is the group to be associated with that access right.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"9a995e09e1ad4561":{"id":"com.apple.ldap.account_ldapaccountusessl","displayName":"LDAP Account Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":[{"id":"com.apple.ldap.account_ldapaccountusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.ldap.account_ldapaccountusessl_true","displayName":"True","description":null,"helpText":null}]},"9a0c16c7dd468f2a":{"id":"com.apple.managedclient.preferences_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download","description":"This policy sets a list of file types that should be automatically opened on download. Note: The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\n\nBy default, these file types will be automatically opened on all URLs. You can use the \"AutoOpenAllowedForURLs\" policy to restrict the URLs for which these file types will be automatically opened on.\n\nFiles with types that should be automatically opened will still be subject to the enabled Microsoft Defender SmartScreen checks and won't be opened if they fail those checks.\n\nFile types that a user has already specified to automatically be opened will continue to do so when downloaded. The user will continue to be able to specify other file types to be automatically opened.\n\nIf you don't set this policy, only file types that a user has already specified to automatically be opened will do so when downloaded.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, Windows 10 Pro or Enterprise instances that enrolled for device management, or macOS instances that are that are managed via MDM or joined to a domain via MCX.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoopenfiletypes"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"9ae0b6d19c35b251":{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory","displayName":"Directory (selected) or file (not selected)","description":"Directory if selected, or file if not selected","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_isdirectory_true","displayName":"Enabled","description":null,"helpText":null}]},"9ada55415adb85cc":{"id":"com.apple.tcc.configuration-profile-policy_services_accessibility_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"9a770ef8a463fa12":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-1"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_1_1","displayName":"Enabled","description":null,"helpText":null}]},"9a6bd73ec3230e93":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions","displayName":"Turn off Auto Exclusions","description":"\r\n Allows an administrator to specify if Automatic Exclusions feature for Server SKUs should be turned off.\r\n\r\n Disabled (Default):\r\n Microsoft Defender will exclude pre-defined list of paths from the scan to improve performance.\r\n\r\n Enabled:\r\n Microsoft Defender will not exclude pre-defined list of paths from scans. This can impact machine performance in some scenarios.\r\n\r\n Not configured:\r\n Same as Disabled.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableautoexclusions"],"categoryId":"c805d788-1950-4ed1-adfb-771f12564a0c","categoryName":"Exclusions","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableautoexclusions_1","displayName":"Enabled","description":null,"helpText":null}]},"9a56fb6162483faf":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen","displayName":"Configure the 'Block at First Sight' feature","description":"This feature ensures the device checks in real time with the Microsoft Active Protection Service (MAPS) before allowing certain content to be run or accessed. If this feature is disabled, the check will not occur, which will lower the protection state of the device.\r\n Enabled – The Block at First Sight setting is turned on.\r\n Disabled – The Block at First Sight setting is turned off.\r\n \r\n This feature requires these Group Policy settings to be set as follows:\r\n MAPS -> The “Join Microsoft MAPS” must be enabled or the “Block at First Sight” feature will not function.\r\n MAPS -> The “Send file samples when further analysis is required” should be set to 1 (Send safe samples) or 3 (Send all samples). Setting to 0 (Always Prompt) will lower the protection state of the device. Setting to 2 (Never send) means the “Block at First Sight” feature will not function.\r\n Real-time Protection -> The “Scan all downloaded files and attachments” policy must be enabled or the “Block at First Sight” feature will not function.\r\n Real-time Protection -> Do not enable the “Turn off real-time protection” policy or the “Block at First Sight” feature will not function.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disableblockatfirstseen"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disableblockatfirstseen_1","displayName":"Enabled","description":null,"helpText":null}]},"9a4284fc456e4083":{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle","displayName":"Published State Check Interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_30","displayName":"30 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_60","displayName":"1 Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_240","displayName":"4 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_480","displayName":"8 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_720","displayName":"12 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_1440","displayName":"1 Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_verifypublishedstate_verifypublishedstatetitle_4294967295","displayName":"Never","description":null,"helpText":null}]},"9a9979d9214b4bb7":{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"AppSync\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disableappsyncsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},"9adaa539265c4cc2":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013","displayName":"Microsoft Office 365 Visio 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Visio 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Visio 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Visio 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Visio 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Visio 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365visio2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365visio2013_1","displayName":"Enabled","description":null,"helpText":null}]},"9afcf8e605ecd8d6":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"9a36cea66b679c9a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings","description":"Configures browsing data lifetime settings for Google Chrome. This policy allows admins to configure (per data-type) when data is deleted by the browser. This is useful for customers that work with sensitive customer data. The policy will only take effect if SyncDisabled is set to true.\r\n\r\nThe available data types are 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\n\r\nThe browser will automatically remove data of selected types that is older than 'time_to_live_in_hours'. The minimum value that can be set is 1 hour.\r\n\r\nThe deletion of expired data will happen 15 seconds after the browser starts then every hour while the browser is running.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=BrowsingDataLifetime for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"time_to_live_in_hours\": 24,\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ]\r\n },\r\n {\r\n \"time_to_live_in_hours\": 12,\r\n \"data_types\": [\r\n \"password_signin\",\r\n \"autofill\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},"9ae9fd0a4f9efb15":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptallowedforurls_javascriptallowedforurlsdesc","displayName":"Allow JavaScript on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"9ad0372e6854dae3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_homepagelocation","displayName":"Home page URL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":null},"9ab88701465d0acf":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_webhidallowalldevicesforurlsdesc","displayName":"Automatically grant permission to sites to connect to any HID device. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"9a428d737869269f":{"id":"device_vendor_msft_policy_config_deliveryoptimization_domaxuploadbandwidth","displayName":"DO Max Upload Bandwidth","description":"Specifies the minimum download QoS (Quality of Service or speed) in KiloBytes/sec for background downloads. This policy affects the blending of peer and HTTP sources. Delivery Optimization complements the download from the HTTP source to achieve the minimum QoS value set.","helpText":null,"infoUrls":[],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"9af1e0a35aca5653":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilessiddirectorynamepattern_profilessiddirectorynamepattern","displayName":"SID Directory Name Pattern (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":null},"9a6eab6e898835b4":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols","displayName":"Download signed ActiveX controls","description":"This policy setting allows you to manage whether users may download signed ActiveX controls from a page in the zone.\n\nIf you enable this policy, users can download signed controls without user intervention. If you select Prompt in the drop-down box, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.\n\nIf you disable the policy setting, signed controls cannot be downloaded.\n\nIf you do not configure this policy setting, users are queried whether to download controls signed by publishers who aren't trusted. Code signed by trusted publishers is silently downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedownloadsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"9aeac1a001c96df5":{"id":"device_vendor_msft_policy_config_maps_enableofflinemapsautoupdate","displayName":"Enable Offline Maps Auto Update","description":"Disables the automatic download and update of map data. After the policy is applied, you can verify the settings in the user interface in System > Offline Maps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Maps#enableofflinemapsautoupdate"],"categoryId":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","categoryName":"Maps","options":[{"id":"device_vendor_msft_policy_config_maps_enableofflinemapsautoupdate_0","displayName":"Disabled. Force off auto-update.","description":"Disabled. Force off auto-update.","helpText":null},{"id":"device_vendor_msft_policy_config_maps_enableofflinemapsautoupdate_1","displayName":"Enabled. Force on auto-update.","description":"Enabled. Force on auto-update.","helpText":null},{"id":"device_vendor_msft_policy_config_maps_enableofflinemapsautoupdate_65535","displayName":"Not configured. User's choice.","description":"Not configured. User's choice.","helpText":null}]},"9af6f7a1d8cfd01f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting","displayName":"Default images setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting_1","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultimagessetting_defaultimagessetting_2","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},"9a70b1b069d4a854":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallblocklist_extensioninstallblocklistdesc","displayName":"Extension IDs the user should be prevented from installing (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"9a50c2e3d5f67f21":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authserverallowlist_authserverallowlist","displayName":"Configure list of allowed authentication servers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},"9ae6fe3c3472a12d":{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled","displayName":"Guided Switch Enabled","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\r\n\r\nIf you enable this policy, you'll be prompted to switch to another account if the current profile doesn't work for the requesting link.\r\n\r\nIf you disable this policy, you won't be prompted to switch to another account when there's a profile and link mismatch.\r\n\r\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9a8d9c8f66f9e859":{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed","displayName":"Automatically open downloaded MHT or MHTML files from the web in Internet Explorer mode","description":"This policy controls whether MHT or MHTML files that are downloaded from the web are automatically opened in Internet Explorer mode.\r\n\r\nIf you enable this policy, the MHT or MHTML files that are downloaded from the web can be opened in both Microsoft Edge and Internet Explorer mode to provide the best user experience.\r\n\r\nIf you disable or don't configure this policy, MHT or MHTML files that are downloaded from the web won't automatically open in Internet Explorer mode.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_internetexplorerintegrationzoneidentifiermhtfileallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"9ad8ff6f2411927d":{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended","displayName":"Enable tab preview on hover","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\r\n\r\nIf you disable this policy, tab previews will not be shown on hover.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev141~policy~microsoft_edge_recommended_showtabpreviewenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9a7a351006783abf":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},"9a286d0de01faac1":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9ac17e76c52e9a23":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_licensingsettings_l_orgideduenabledcentennial","displayName":"Enable EDU Org ID Sign In in Office from Windows Store","description":"This policy setting controls whether Office product is activated with the student’s email account. By default, Org Id sign in is not allowed.\r\n\r\nIf you enable this policy setting, student’s email Id sign in will be used to activate the version of Office installed on the computer.\r\n\r\nIf you disable this policy setting, student’s email Id sign in won’t be used to activate the version of Office installed on the computer.\r\n\r\nEnabling or disabling this policy setting takes precedence over any setting that’s been configured by using the Office Deployment Tool or by manually editing the registry.\r\n\r\nIf you don’t configure this policy setting, student’s email Id sign in won’t be used to activate the version of Office installed on the computer unless you’ve enabled Org ID to sign in by manually editing the registry.\r\n ","helpText":"","infoUrls":[],"categoryId":"2e3f0407-6387-41b4-b6c2-ada4354be759","categoryName":"Licensing Settings","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_licensingsettings_l_orgideduenabledcentennial_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_licensingsettings_l_orgideduenabledcentennial_1","displayName":"Enabled","description":null,"helpText":null}]},"9a85d4d1e1da1919":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_miscellaneous_l_ageoutpolicy","displayName":"Age out documents older than n days","description":"This policy controls when locally cached Office documents are aged out of the Office Document Cache","helpText":"","infoUrls":[],"categoryId":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","categoryName":"Miscellaneous","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_miscellaneous_l_ageoutpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_miscellaneous_l_ageoutpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"9a1e5718708deeb6":{"id":"device_vendor_msft_policy_config_onedrivengscv2.updates~policy~onedrivengsc_kfmoptinnowizard_kfmoptinnowizard_textbox","displayName":"Tenant ID: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"9acb6f286aa79148":{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlockmicrosoftidentityauthn","displayName":"Disconnect remote session on lock for Microsoft identity platform authentication","description":"This policy setting allows you to configure the user experience when the Remote Desktop session is locked by the user or by a policy. You can specify whether the remote session will show the remote lock screen or disconnect when the remote session is locked. Disconnecting the remote session ensures that a remote session cannot be left on the lock screen and cannot reconnect automatically due to loss of network connectivity.\n\nThis policy applies only when using an identity provider that uses the Microsoft identity platform, such as Microsoft Entra ID, to authenticate to the remote PC. This policy doesn't apply when using Legacy authentication which includes the NTLM, CredSSP, RDSTLS, TLS, and RDP basic authentication protocols.\n\nIf you enable or do not configure this policy setting, Remote Desktop connections using the Microsoft identity platform will disconnect the remote session when the remote session is locked. Users can reconnect when they're ready and can use passwordless authentication if configured.\n\nIf you disable this policy setting, Remote Desktop connections using the Microsoft identity platform will show the remote lock screen when the remote session is locked. Users can unlock the remote session using their username and password, or certificates.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-disconnectonlockmicrosoftidentityauthn"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlockmicrosoftidentityauthn_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_disconnectonlockmicrosoftidentityauthn_1","displayName":"Enabled","description":null,"helpText":null}]},"9a1429a713ed169e":{"id":"device_vendor_msft_policy_config_userrights_manageauditingandsecuritylog","displayName":"Manage Auditing And Security Log","description":"This user right determines which users can specify object access auditing options for individual resources, such as files, Active Directory objects, and registry keys. This security setting does not allow a user to enable file and object access auditing in general. You can view audited events in the security log of the Event Viewer. A user with this privilege can also view and clear the security log.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#manageauditingandsecuritylog"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"9abf4e980244a3f9":{"id":"device_vendor_msft_policy_privilegemanagement_elevationclientsettings_defaultelevationresponse_validation","displayName":"Validation","description":"","helpText":null,"infoUrls":[],"categoryId":"b750fe41-33c4-4293-8dfc-42285be35752","categoryName":null,"options":[{"id":"device_vendor_msft_policy_privilegemanagement_elevationclientsettings_defaultelevationresponse_validation_0","displayName":"Business justification","description":"Business Justification","helpText":null},{"id":"device_vendor_msft_policy_privilegemanagement_elevationclientsettings_defaultelevationresponse_validation_1","displayName":"Windows authentication","description":"Windows Authentication","helpText":null}]},"9ada2e1013fa3fcf":{"id":"plugin_filter_sockets","displayName":"Sockets","description":"Settings that control the socket filter. If not present, the system doesn't use socket filtering.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"9a0fa340b9575acf":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders30","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders30_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_l_allowsubfolders30_1","displayName":"True","description":null,"helpText":null}]},"9a230063e71c8da3":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_servermanager","displayName":"Server Manager (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-servermanager"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_servermanager_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_servermanager_1","displayName":"Enabled","description":null,"helpText":null}]},"9abd98d2a53e2535":{"id":"user_vendor_msft_policy_config_admx_startmenu_nocommongroups","displayName":"Remove common program groups from Start Menu (User)","description":"Removes items in the All Users profile from the Programs menu on the Start menu.\r\n\r\nBy default, the Programs menu contains items from the All Users profile and items from the user's profile. If you enable this setting, only items in the user's profile appear in the Programs menu.\r\n\r\nTip: To see the Program menu items in the All Users profile, on the system drive, go to ProgramData\\Microsoft\\Windows\\Start Menu\\Programs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nocommongroups"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nocommongroups_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nocommongroups_1","displayName":"Enabled","description":null,"helpText":null}]},"9a97274ff16c6b2f":{"id":"user_vendor_msft_policy_config_admx_startmenu_notoolbarsontaskbar","displayName":"Do not display any custom toolbars in the taskbar (User)","description":"This setting affects the taskbar.\r\n\r\nThe taskbar includes the Start button, buttons for currently running tasks, custom toolbars, the notification area, and the system clock. Toolbars include Quick Launch, Address, Links, Desktop, and other custom toolbars created by the user or by an application.\r\n\r\nIf this setting is enabled, the taskbar does not display any custom toolbars, and the user cannot add any custom toolbars to the taskbar. Moreover, the \"Toolbars\" menu command and submenu are removed from the context menu. The taskbar displays only the Start button, taskbar buttons, the notification area, and the system clock.\r\n\r\nIf this setting is disabled or is not configured, the taskbar displays all toolbars. Users can add or remove custom toolbars, and the \"Toolbars\" command appears in the context menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notoolbarsontaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_notoolbarsontaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_notoolbarsontaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"9aec451dd072299b":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi","displayName":"VDI Configuration (User)","description":"This policy setting configures the synchronization of User Experience Virtualization (UE-V) rollback information for computers running in a non-persistent, pooled VDI environment. UE-V settings rollback data and checkpoints are normally stored only on the local computer. With this policy setting enabled, the rollback information is copied to the settings storage location when the user logs off or shuts down their VDI session. Enable this setting to register a VDI-specific settings location template and restore data on computers in pooled VDI environments that reset to a clean state on logout. With this policy enabled you can roll settings back to the state when UE-V was installed or to “last-known-good” configurations. Only enable this policy setting on computers running in a non-persistent VDI environment. The VDI Collection Name defines the name of the virtual desktop collection containing the virtual computers. \r\nIf you enable this policy setting, the UE-V rollback state is copied to the settings storage location on logout and restored on login.\r\nIf you disable this policy setting, no UE-V rollback state is copied to the settings storage location.\r\nIf you do not configure this policy, no UE-V rollback state is copied to the settings storage location.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-configurevdi"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configurevdi_1","displayName":"Enabled","description":null,"helpText":null}]},"9a5bfa7613d70c1e":{"id":"user_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge","displayName":"Prevent Access To About Flags In Microsoft Edge (User)","description":"Prevent access to the about:flags page in Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventaccesstoaboutflagsinmicrosoftedge"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge_0","displayName":"Disabled","description":"Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_preventaccesstoaboutflagsinmicrosoftedge_1","displayName":"Enabled","description":"Prevents users from accessing the about:flags page.","helpText":null}]},"9af6a558866c824b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Do not allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},"9a82686e0e513f53":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata","displayName":"Keep browsing data when creating enterprise profile by default (User)","description":"If this policy is Enabled, the option to keep any existing browsing data when creating an enterprise profile will be checked by default.\r\n\r\nIf this policy is unset or Disabled, the option to keep any existing browsing data when creating an enterprise profile will not be checked by default.\r\n\r\nRegardless of the value, the user will be able to decide whether or not to keep any existing browsing data when creating an enterprise profile.\r\n\r\nThis policy has no effect if the option to keep existing browsing data is not available; this happens if enterprise profile separation is strictly enforced, or if the data would be from an already managed profile.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilecreationkeepbrowsingdata_1","displayName":"Enabled","description":null,"helpText":null}]},"9a1946caf617d3c6":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings","displayName":"Settings for Google's AI Mode integrations in the address bar and New Tab page search box. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings_0","displayName":"Allow AI Mode integrations.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_aimodesettings_aimodesettings_1","displayName":"Do not allow AI Mode integrations.","description":null,"helpText":null}]},"9a3e8ab698fde814":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenableprotectedmode"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"9a407a37feb9a250":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended","displayName":"Allow importing of favorites (User)","description":"Allows users to import favorites from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (on macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importfavorites_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9aa56cc612e17bb9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls","displayName":"Block the Adobe Flash plug-in on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from running Adobe Flash.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultPluginsSetting' (Default Adobe Flash setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_pluginsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9ae9eb8e68162635":{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended","displayName":"Allow users to access the Outlook menu (User)","description":"This policy is used to manage access to the Outlook menu from Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, users can access the Outlook menu.\r\nIf you disable this policy, users can't access the Outlook menu.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev102~policy~microsoft_edge_recommended_outlookhubmenuenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9ad6f6c6fd3086c9":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting","displayName":"Default automatic downloads setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_1","displayName":"Allow all websites to perform automatic downloads","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_defaultautomaticdownloadssetting_defaultautomaticdownloadssetting_2","displayName":"Don't allow any website to perform automatic downloads","description":null,"helpText":null}]},"9acadcb57d89f8ab":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeout_idletimeout","displayName":"Delay before running idle actions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},"9a83b00170b9225a":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist","displayName":"Open local files in Internet Explorer mode file extension allow list (User)","description":"This policy limits which file:// URLs are allowed to be launched into Internet Explorer mode based on file extension.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nWhen a file:// URL is requested to launch in Internet Explorer mode, the file extension of the URL must be present in this list in order for the URL to be allowed to launch in Internet Explorer mode. A URL which is blocked from opening in Internet Explorer mode will instead open in Edge mode.\r\n\r\nIf you set this policy to the special value \"*\" or don't configure it, all file extensions are allowed.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\nExample value:\r\n\r\n.mht\r\n.pdf\r\n.vsdx","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileextensionallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"9aff65034b008212":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_maximplicitcachesize_l_maximplicitcachesizedecimal","displayName":"Percent of disk space (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"9a4d66f25f703420":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice08_l_broadcastserviceservername8","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"9aeb2592e2f3f2b9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicypowerpoint_1","displayName":"True","description":null,"helpText":null}]},"9ab9de5970bef1cd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc16_l_pathcolon16","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"9a10eca271995ba3":{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook","displayName":"Running Outlook for Simple MAPI Mail Sending (User)","description":"This policy setting determines whether users can send mail through Simple MAPI when Outlook is not active.\r\n\r\nIf you enable this policy setting, users are required to have Outlook running to send mail through Simple MAPI. This will force users to open Outlook to send mail, ensuring that Outlook Add-ins run properly before the mail is sent. \r\n\r\nIf you disable this policy setting, users are allowed to send mail through Simple MAPI regardless of Outlook running.\r\n\r\nWhen this policy setting is not configured, it functions as if it has been disabled, allowing users to send mail through Simple MAPI without having Outlook running.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v12~policy~l_microsoftofficeoutlook~l_miscellaneous_l_disablesimplemapisendwithoutoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"9a1a62e14e6f228f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"42ce9a9b-0574-4b5c-993b-7679de80be47","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_0","displayName":"Block files","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_l_setdocumentbehavioriffilevalidationfailsdropid_1","displayName":"Open in Protected View","description":null,"helpText":null}]},"9a1282f1018ccc65":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc07_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"9ad4e9eacefd9552":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks","displayName":"Optional breaks (User)","description":"Determines whether the symbol used to represent optional breaks is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalbreaks_1","displayName":"Enabled","description":null,"helpText":null}]},"9aa3a16c03fd9e89":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, Hyper-V Firewall rules from the local store are ignored and not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge_false","displayName":"AllowLocalPolicyMerge Off","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_domainprofile_allowlocalpolicymerge_true","displayName":"AllowLocalPolicyMerge On","description":"AllowLocalPolicyMerge On","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/9b.json b/public/intune-definitions/9b.json index 68c63d7e8ba4..725354cede66 100644 --- a/public/intune-definitions/9b.json +++ b/public/intune-definitions/9b.json @@ -1 +1 @@ -{"9b86f6590715b179":{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked","displayName":"Block outgoing calls","description":"If 'True', the device is prevented from making outgoing phone calls. If 'False', Intune doesn't change or update this setting. By default, the OS might allow outgoing calls. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked_true","displayName":"True","description":"True","helpText":null}]},"9bcfb99fc4712fca":{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked","displayName":"Block camera","description":"If 'True', prevents access to the camera during personal use. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using the camera in the personal profile. Available for corporate-owned work profile devices (at personal profile level).","helpText":null,"infoUrls":[],"categoryId":"990880db-3f64-4436-ab4a-d7d5181dfa5d","categoryName":"Personal Profile","options":[{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked_false","displayName":"False","description":"false","helpText":null}]},"9b5a8d88d575a28f":{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation","displayName":"Allow Background Security Improvement Installation (Deprecated)","description":"If false, Rapid Security Response will be disabled. ","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation_true","displayName":"True","description":null,"helpText":null}]},"9b950e2436e3c247":{"id":"com.apple.directoryservice.managed_adallowmultidomainauth","displayName":"AD Allow Multi Domain Auth","description":"If true, allows authentication from any domain in the namespace.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adallowmultidomainauth_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adallowmultidomainauth_true","displayName":"True","description":null,"helpText":null}]},"9bc46457f7e9a0bb":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled_true","displayName":"True","description":null,"helpText":null}]},"9be8453245d3fd3f":{"id":"com.apple.loginwindow_autologinpassword","displayName":"Autologin Password","description":"Optional user password when setting up auto login. If this key does not exist, and a user name was specified, auto login will be set up the next time the specified user logs in to the client.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},"9bc94757a694e4fb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled","displayName":"Discover feature In Microsoft Edge (Obsolete)","description":"This policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy lets you configure the Discover feature in Microsoft Edge.\n\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\n\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9b9493a5952bfee4":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled","displayName":"Control Microsoft Edge Safe Hosting Extension","description":"This policy controls whether the Microsoft Edge Safe Hosting component extension is installed automatically when users visit supported Microsoft services, such as Microsoft 365 Copilot app.\n\nThe Microsoft Edge Safe Hosting extension provides additional security capabilities for these services. When a user accesses a supported service, the extension installs automatically to enable those protections.\n\nIf you enable or don't configure this policy, the extension installs automatically and remains installed for 90 days after the user's last visit, then is removed if no further activity occurs.\n\nIf you disable this policy, the extension won't install automatically. If it’s already installed, it will be removed.\n\nNote: This policy controls only automatic installation. It doesn’t prevent users from manually installing other extensions from the Microsoft Edge Add-ons website.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9bbc943866716f04":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended","displayName":"Allow importing of search engine settings (users can override)","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"9b2825b3e988f26f":{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove","displayName":"Do not automatically encrypt files moved to encrypted folders","description":"This policy setting prevents File Explorer from encrypting files that are moved to an encrypted folder.\r\n\r\nIf you enable this policy setting, File Explorer will not automatically encrypt files that are moved to an encrypted folder.\r\n\r\nIf you disable or do not configure this policy setting, File Explorer automatically encrypts files that are moved to an encrypted folder.\r\n\r\nThis setting applies only to files moved within a volume. When files are moved to other volumes, or if you create a new file in an encrypted folder, File Explorer encrypts those files automatically.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-encryptfilesonmove#admx-encryptfilesonmove-noencryptonmove"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove_1","displayName":"Enabled","description":null,"helpText":null}]},"9b2b5e4b530dd093":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_netlogon_dnsttllabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},"9be1cab8b6892ee1":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup","displayName":"Common 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings which are common between the Microsoft Office Suite 2013 applications.\r\nMicrosoft Office Suite 2013 has user settings which are common between applications and are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific common Microsoft Office Suite 2013 applications.\r\nIf you enable this policy setting, certain user settings which are common between the Microsoft Office Suite 2013 applications will continue to be backed up.\r\nIf you disable this policy setting, certain user settings which are common between the Microsoft Office Suite 2013 applications will not be backed up. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013commonbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"9b7cf8531f00af99":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled","displayName":"Enable Bookmark Bar","description":"Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar.\r\n\r\nIf you set the policy, users can't change it. If not set, users decide whether to use this function.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9b90e0377428b875":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls","displayName":"Allow cookies on these sites","description":"Allows you to set a list of url patterns that specify sites which are allowed to set cookies.\r\n\r\nIf this policy is left not set the global default value will be used for all sites either from the DefaultCookiesSetting policy if it is set, or the user's personal configuration otherwise.\r\n\r\nSee also policies CookiesBlockedForUrls and CookiesSessionOnlyForUrls. Note that there must be no conflicting URL patterns between these three policies - it is unspecified which policy takes precedence.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9bae2c796c8dee80":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication","description":"If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\r\n\r\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9b7daf456ba984e8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on chrome://extensions.\r\n\r\nIf the policy is not set, users can turn on developer mode on extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\r\nIf the policy is set to Allow (0), users can turn on developer mode on extensions page.\r\nIf the policy is set to Disallow (1), users can not turn on developer mode on extensions page.\r\n\r\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"9b174973875be46f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability","displayName":"Manage the deprecated prefixed video fullscreen API's availability","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"9b043e47ae5fa1f9":{"id":"device_vendor_msft_policy_config_defender_allowemailscanning","displayName":"Allow Email Scanning","description":"Allows or disallows scanning of email.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_allowemailscanning_0","displayName":"Not allowed. Turns off email scanning.","description":"Not allowed. Turns off email scanning.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_allowemailscanning_1","displayName":"Allowed. Turns on email scanning.","description":"Allowed. Turns on email scanning.","helpText":null}]},"9b9c5eb2d2ebcbba":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesaccessnetworkascomputer","displayName":"Access Network as Computer Object","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nAttach as computer - folder must have permissions for computer objects\r\n\r\nCAUTION: Do not use this configuration setting unless your storage provider or architecture will NOT work with user-level permissions to the VHD(x) container locations. This setting will allow the virtual machine to access all the VHD(x) files on the storage provider creating a potential security risk.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\AccessNetworkAsComputerObject\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesaccessnetworkascomputer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesaccessnetworkascomputer_1","displayName":"Enabled","description":null,"helpText":null}]},"9b3ac120d1c4645b":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},"9b66c96838ad4be4":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"9b276aab901585da":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowfontdownloads"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"9bf9f12fc7a0f7cd":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips","displayName":"Allow Google Cast to connect to Cast devices on all IP addresses","description":"Enable this policy to let Google Cast connect to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses.\r\n\r\nDisable this policy to restrict Google Cast to Cast devices on RFC1918/RFC4193 private addresses.\r\n\r\nIf you don't configure this policy, Google Cast connects to Cast devices on RFC1918/RFC4193 private addresses only, unless you enable the CastAllowAllIPs feature.\r\n\r\nIf the 'EnableMediaRouter' (Enable Google Cast) policy is disabled, then this policy has no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips_1","displayName":"Enabled","description":null,"helpText":null}]},"9b8ea1c35b055ced":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\r\n\r\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\r\n\r\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.\r\n\r\nExample value: 10000-11999","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_1","displayName":"Enabled","description":null,"helpText":null}]},"9bdb31ce67362c70":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_1","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_2","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},"9b3429bd5c0f16fe":{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_geolocationblockedforurlsdesc","displayName":"Block geolocation on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"9b35923209fcd2dd":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_exprwdexe164","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_exprwdexe164_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_exprwdexe164_1","displayName":"True","description":null,"helpText":null}]},"9b26633672a99090":{"id":"device_vendor_msft_policy_config_settings_allowdatetime","displayName":"Allow Date Time","description":"Allows the user to change date and time settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#allowdatetime"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":[{"id":"device_vendor_msft_policy_config_settings_allowdatetime_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_settings_allowdatetime_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"9be49a91245424d2":{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync","displayName":"Do not sync accessibility settings","description":"\n Prevent the \"accessibility\" group from syncing to and from this PC. This turns off and disables the \"accessibility\" group on the \"Windows backup\" settings page in PC settings.\n\nIf you enable this policy setting, the \"accessibility\" group will not be synced.\n\nUse the option \"Allow users to turn accessibility syncing on\" so that syncing is turned off by default but not disabled.\n\nIf you do not set or disable this setting, syncing of the \"accessibility\" group is on by default and configurable by the user.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-settingssync#settingssync-disableaccessibilitysettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},"9ba8f67d0d7e0fb5":{"id":"device_vendor_msft_policy_config_update_allowautowindowsupdatedownloadovermeterednetwork","displayName":"Allow Auto Windows Update Download Over Metered Network","description":"Option to download updates automatically over metered connections (off by default). Value type is integer. A significant number of devices primarily use cellular data and do not have Wi-Fi access, which leads to a lower number of devices getting updates. Since a large number of devices have large data plans or unlimited data, this policy can unblock devices from getting updates. This policy is accessible through the Update setting in the user interface or Group Policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#allowautowindowsupdatedownloadovermeterednetwork"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_allowautowindowsupdatedownloadovermeterednetwork_0","displayName":"Not allowed","description":"Not allowed","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautowindowsupdatedownloadovermeterednetwork_1","displayName":"Allowed","description":"Allowed","helpText":null}]},"9b27dee7b0f9501a":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters","displayName":"Special Characters (User)","description":"Use this policy setting to configure the use of special characters in the Windows Hello for Business PIN gesture. Valid special characters for Windows Hello for Business PIN gestures include: ! \" # $ % & ' ( ) * + , - . / : ; < = > ? @ [ \\ ] ^ _ ` { | } ~ .\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one special character in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using special characters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use special characters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_0","displayName":"Allows the use of special characters in PIN.","description":"Allows the use of special characters in PIN.","helpText":null},{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_1","displayName":"Requires the use of at least one special characters in PIN.","description":"Requires the use of at least one special characters in PIN.","helpText":null},{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_2","displayName":"Does not allow the use of special characters in PIN.","description":"Does not allow the use of special characters in PIN.","helpText":null}]},"9b22604efcd5dcd5":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_toolssecurity~l_workgroupadministrator_l_pathtosharedworkgroupinformationfileforsecuredmdbfiles","displayName":"Path to shared Workgroup information file for secured MDB files (User)","description":"Specifies the default path and filename for the workgroup information file.","helpText":"","infoUrls":[],"categoryId":"a788a6e5-ab3f-41e5-96c8-ee59627dcb4d","categoryName":"Workgroup Administrator...","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_toolssecurity~l_workgroupadministrator_l_pathtosharedworkgroupinformationfileforsecuredmdbfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_toolssecurity~l_workgroupadministrator_l_pathtosharedworkgroupinformationfileforsecuredmdbfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"9bdb1c1c63f36a56":{"id":"user_vendor_msft_policy_config_admx_globalization_y2k_y2kyear","displayName":"Year (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"9b34969edfa111a4":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitytemplates","displayName":"Security Templates (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-securitytemplates"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitytemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitytemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"9b093624d69429a8":{"id":"user_vendor_msft_policy_config_browser_preventturningoffrequiredextensions","displayName":"Prevent Turning Off Required Extensions (User)","description":"You can define a list of extensions in Microsoft Edge that users cannot turn off. You must deploy extensions through any available enterprise deployment channel, such as Microsoft Intune. When you enable this policy, users cannot uninstall extensions from their computer, but they can configure options for extensions defined in this policy, such as allow for InPrivate browsing. Any additional permissions requested by future updates of the extension gets granted automatically. When you enable this policy, you must provide a semi-colon delimited list of extension package family names (PFNs). For example, adding Microsoft.OneNoteWebClipper_8wekyb3d8bbwe;Microsoft.OfficeOnline_8wekyb3d8bbwe prevents a user from turning off the OneNote Web Clipper and Office Online extension. When enabled, removing extensions from the list does not uninstall the extension from the user’s computer automatically. To uninstall the extension, use any available enterprise deployment channel. If you enable the Allow Developer Tools policy, then this policy does not prevent users from debugging and altering the logic on an extension. If disabled or not configured, extensions defined as part of this policy get ignored. Default setting: Disabled or not configured Related policies: Allow Developer Tools Related Documents: - Find a package family name (PFN) for per-app VPN (https://docs.microsoft.com/en-us/sccm/protect/deploy-use/find-a-pfn-for-per-app-vpn) - How to manage apps you purchased from the Microsoft Store for Business with Microsoft Intune (https://docs.microsoft.com/en-us/intune/windows-store-for-business) - How to assign apps to groups with Microsoft Intune (https://docs.microsoft.com/en-us/intune/apps-deploy) - Manage apps from the Microsoft Store for Business with System Center Configuration Manager (https://docs.microsoft.com/en-us/sccm/apps/deploy-use/manage-apps-from-the-windows-store-for-business) - How to add Windows line-of-business (LOB) apps to Microsoft Intune (https://docs.microsoft.com/en-us/intune/lob-apps-windows)","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventturningoffrequiredextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"9b1c8dc4b2d3e404":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory","displayName":"Import browsing history from default browser on first run (User)","description":"Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.\r\n\r\nUsers can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory_1","displayName":"Enabled","description":null,"helpText":null}]},"9bf8267f1e0fdc13":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended","displayName":"Import browsing history from default browser on first run (User)","description":"Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.\r\n\r\nUsers can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9bc8e4d7ae4ac57b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_defaultsearchprovidericonurl","displayName":"Default search provider icon (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"9ba525c383c0f7e5":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl","displayName":"WebRTC per URL IP Handling (User)","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection for each specific URL pattern.\r\n\r\nIt accepts a list of URL patterns and handling type pairs. The URL patterns are checked in order and the first match will configure which handling is used by WebRTC for the domain. When the URL of the current document is not matched against any entry, it uses the configuration set by the policy WebRtcIPHandling.\r\n\r\nFor detailed information on valid input patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nValid handling values:\r\n\r\n* default - WebRTC uses all network interfaces.\r\n\r\n* default_public_and_private_interfaces - WebRTC uses all public and private interfaces.\r\n\r\n* default_public_interface_only - WebRTC uses all public interfaces, but not private ones.\r\n\r\n* disable_non_proxied_udp - WebRTC uses either UDP SOCKS proxying or will fallback to TCP proxying.\r\n\r\nSee RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2) for a detailed description of all the handling values.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebRtcIPHandlingUrl for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.example.com\",\r\n \"handling\": \"default_public_and_private_interfaces\"\r\n },\r\n {\r\n \"url\": \"https://[*.]example.edu\",\r\n \"handling\": \"default_public_interface_only\"\r\n },\r\n {\r\n \"url\": \"*\",\r\n \"handling\": \"disable_non_proxied_udp\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_1","displayName":"Enabled","description":null,"helpText":null}]},"9b7cb73422c9278c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},"9b689a62c7695fd1":{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2","displayName":"Disable Internet Explorer 11 as a standalone browser (User)","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\n\nIf you enable this policy, it:\n- Prevents Internet Explorer 11 from launching as a standalone browser.\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\n- Redirects attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\n- Overrides any other policies that redirect to Internet Explorer 11.\n\nEven with this policy enabled launching Internet Explorer 11 using COM automation will still be allowed. To disable COM automation launches of Internet Explorer 11 use the \"Disable Internet Explorer 11 COM Automation\" group policy.\n\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"9b0d6e999485f21b":{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer places restrictions on each Web page it opens. The restrictions are dependent upon the location of the Web page (Internet, Intranet, Local Machine zone, etc.). Web pages on the local computer have the fewest security restrictions and reside in the Local Machine zone, making the Local Machine security zone a prime target for malicious users. Zone Elevation also disables JavaScript navigation if there is no security context.\n\nIf you enable this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.\n\nIf you disable this policy setting, no zone receives such protection for Internet Explorer processes.\n\nIf you do not configure this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-protectionfromzoneelevationinternetexplorerprocesses"],"categoryId":"3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","categoryName":"Protection From Zone Elevation","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},"9bfb4a76496ce4e9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin","displayName":"Control where security restrictions on insecure origins apply (User)","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*.contoso.com\") for which security restrictions on insecure origins don't apply.\r\n\r\nThis policy lets you specify allowed origins for legacy applications that can't deploy TLS or set up a staging server for internal web development so that developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled \"Not Secure\" in the omnibox.\r\n\r\nSetting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag.\r\n\r\nFor more information on secure contexts, see https://www.w3.org/TR/secure-contexts/.\r\n\r\nExample value:\r\n\r\nhttp://testserver.contoso.com/\r\n*.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_1","displayName":"Enabled","description":null,"helpText":null}]},"9bafb9f120a62148":{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled","displayName":"Enable QR Code Generator (User)","description":"This policy enables the QR Code generator feature in Microsoft Edge.\r\n\r\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\r\n\r\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9b2b5e8ae5fd0ad4":{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls","displayName":"Block idle detection on these sites (User)","description":"Allows you to specify a list of URL patterns for sites that are not allowed to use the Idle Detection API.\r\n\r\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported.\r\n\r\nFor detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9bb53ba8f8254a81":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory (User)","description":"This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings.\r\n\r\nIf you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.\r\n\r\nThis policy has no effect if the DownloadDirectory policy is set.\r\n\r\nFor a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars .\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9bf0fd916d64a028":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended","displayName":"Clear browsing data when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\r\n\r\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies)\r\n\r\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\r\n\r\nIf you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9bf625565192d587":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites (User)","description":"If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemWriteBlockedForUrls' (Block write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9b9906ccc5e95570":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian","displayName":"Indonesian (User)","description":"Enables the editing language Indonesian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian_1","displayName":"Enabled","description":null,"helpText":null}]},"9b5a1c11cf65637a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent","displayName":"Allow add-in usage data to be generated and collected by the Readiness Toolkit (User)","description":"This policy setting allows you to configure whether the Readiness Toolkit for Office generates and collects add-in usage data. The data generated and collected includes when the add-in is loaded and used, and if the add-in crashes. This information is available in reports provided by the Readiness Toolkit.\r\n\r\nIf you enable this policy setting, the Readiness Toolkit generates and collects add-in usage data.\r\n\r\nIf you disable or don't configure this policy setting, the Readiness Toolkit doesn't generate or collect add-in usage data.","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent_1","displayName":"Enabled","description":null,"helpText":null}]},"9b1139447088dbd2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon","displayName":"Load Controls in Forms3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_2","displayName":"2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_3","displayName":"3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_4","displayName":"4","description":null,"helpText":null}]},"9bd2aba86d265ecb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath","displayName":"User templates path (User)","description":"Specifies the location of user templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},"9b7845d50ca9c6fe":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires","displayName":"Legacy format signatures (User)","description":"This policy setting controls whether users can apply binary format digital signatures to Office 97-2003 documents. \r\n\r\nIf you enable this policy setting, Office 2016 applications use the Office 2003 binary format to apply digital signatures to Office 97-2003 binary documents so that they will be recognized by the Office 2003 release and earlier applications. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications use the XML--based XMLDSIG format to attach digital signatures to documents, including Office 97-2003 binary documents. XMLDSIG signatures are not recognized by Office 2003 applications or previous versions. If an Office 2003 user opens an Excel, PowerPoint, or Word binary document with an XMLDSIG signature attached, the signature will be lost.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires_1","displayName":"Enabled","description":null,"helpText":null}]},"9b11132d31e00819":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder","displayName":"Location of Backup Folder (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"9b985d8a46213687":{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_l_newoutlookautomigrationretryintervalsid","displayName":"New Outlook Auto Migration Retry Interval: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},"9bf1b7309efa0d02":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_0","displayName":"No conflicts are logged (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_1","displayName":"All conflicts logged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_2","displayName":"Unresolved conflicts logged only","description":null,"helpText":null}]},"9ba645e994a10283":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday_l_entertheurlofoutlooktodayswebpagemax129chars","displayName":"Enter the URL of Outlook Today's web page (max 129 chars): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":null},"9bebeb601f043bed":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages","displayName":"Send all signed messages as clear signed messages (User)","description":"This policy setting controls whether Outlook sends signed messages as clear text signed messages.\r\n\r\nIf you enable this policy setting, the \"Send clear text signed message when sending signed messages\" option is selected in the E-mail Security section of the Trust Center.\r\n\r\nIf you disable or do not configure this policy setting, when users sign e-mail messages with their digital signature and send them, Outlook uses the signature's private key to encrypt the digital signature but sends the messages as clear text, unless they are encrypted separately.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages_1","displayName":"Enabled","description":null,"helpText":null}]},"9be5baf433e50cfd":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption","displayName":"Enable RPC encryption (User) (Deprecated)","description":"This policy setting controls whether Outlook uses remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers. \r\n\r\nIf you enable this policy setting, Outlook uses RPC encryption when communicating with an Exchange server. Note - RPC encryption only encrypts the data from the Outlook client computer to the Exchange server. It does not encrypt the messages themselves as they traverse the Internet. \r\n\r\nIf you disable or do not configure this policy setting, RPC encryption is still used by default. This setting allows you to override the corresponding per-profile setting.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_1","displayName":"Enabled","description":null,"helpText":null}]},"9bd2703de5980a3d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10","displayName":"Days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_0","displayName":"d","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_1","displayName":"dy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_2","displayName":"day","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_4","displayName":"\r\n ","description":null,"helpText":null}]},"9b83fc9c5edc005a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits","displayName":"Work is entered in (User)","description":"Specifies the default unit of time (minutes, hours, days, weeks, or months) used in the Work field in the current project.\r\n\r\nIf you enable this setting, whenever Project displays work values, the unit you specified will be used.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_1","displayName":"Enabled","description":null,"helpText":null}]},"9bc7423de0ecc868":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"9b77001a91dd76f8":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"9b38005ae821970c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},"9bd398f954c1bba1":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits","displayName":"Show measurements in units of (User)","description":"Selects the default measurement unit for the horizontal ruler and for measurements in dialog boxes.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_1","displayName":"Enabled","description":null,"helpText":null}]},"9b662d86c1a278c4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"9b86f6590715b179":{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked","displayName":"Block outgoing calls","description":"If 'True', the device is prevented from making outgoing phone calls. If 'False', Intune doesn't change or update this setting. By default, the OS might allow outgoing calls. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"","infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.outgoingcallsblocked_true","displayName":"True","description":"True","helpText":null}]},"9bcfb99fc4712fca":{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked","displayName":"Block camera","description":"If 'True', prevents access to the camera during personal use. If 'False', Intune doesn't change or update this setting. By default, the OS might allow using the camera in the personal profile. Available for corporate-owned work profile devices (at personal profile level).","helpText":null,"infoUrls":[],"categoryId":"990880db-3f64-4436-ab4a-d7d5181dfa5d","categoryName":"Personal Profile","options":[{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked_true","displayName":"True","description":"true","helpText":null},{"id":"com.android.devicerestrictionpolicy.personalprofilecamerablocked_false","displayName":"False","description":"false","helpText":null}]},"9b5a8d88d575a28f":{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation","displayName":"Allow Background Security Improvement Installation (Deprecated)","description":"If false, Rapid Security Response will be disabled. ","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowrapidsecurityresponseinstallation_true","displayName":"True","description":null,"helpText":null}]},"9b950e2436e3c247":{"id":"com.apple.directoryservice.managed_adallowmultidomainauth","displayName":"AD Allow Multi Domain Auth","description":"If true, allows authentication from any domain in the namespace.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adallowmultidomainauth_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adallowmultidomainauth_true","displayName":"True","description":null,"helpText":null}]},"9bc46457f7e9a0bb":{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled","displayName":"Enabled","description":"If true, enable these settings. ","helpText":null,"infoUrls":[],"categoryId":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","categoryName":"Parental Controls Time Limits","options":[{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.timelimits.v2_time-limits_weekday-allowance_enabled_true","displayName":"True","description":null,"helpText":null}]},"9be8453245d3fd3f":{"id":"com.apple.loginwindow_autologinpassword","displayName":"Autologin Password","description":"Optional user password when setting up auto login. If this key does not exist, and a user name was specified, auto login will be set up the next time the specified user logs in to the client.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},"9bc94757a694e4fb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled","displayName":"Discover feature In Microsoft Edge (Obsolete)","description":"This policy doesn't work because Discover is now contained within the Edge Sidebar and can be managed using the \"HubsSidebarEnabled\" policy.\n\nThis policy lets you configure the Discover feature in Microsoft Edge.\n\nWorking in the background when enabled, this feature sends URLs to Microsoft Bing to search for related recommendations.\n\nIf you enable or don't configure this policy, you can use the Discover button on Microsoft Edge to start using this feature.\n\nIf you disable this policy, you can't use the Discover feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgediscoverenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9b9493a5952bfee4":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled","displayName":"Control Microsoft Edge Safe Hosting Extension","description":"This policy controls whether the Microsoft Edge Safe Hosting component extension is installed automatically when users visit supported Microsoft services, such as Microsoft 365 Copilot app.\n\nThe Microsoft Edge Safe Hosting extension provides additional security capabilities for these services. When a user accesses a supported service, the extension installs automatically to enable those protections.\n\nIf you enable or don't configure this policy, the extension installs automatically and remains installed for 90 days after the user's last visit, then is removed if no further activity occurs.\n\nIf you disable this policy, the extension won't install automatically. If it’s already installed, it will be removed.\n\nNote: This policy controls only automatic installation. It doesn’t prevent users from manually installing other extensions from the Microsoft Edge Add-ons website.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgesafehostingextensionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9bbc943866716f04":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended","displayName":"Allow importing of search engine settings (users can override)","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"9b0d9fc2f17fb7b2":{"id":"contentcaching_publicranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"9b2825b3e988f26f":{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove","displayName":"Do not automatically encrypt files moved to encrypted folders","description":"This policy setting prevents File Explorer from encrypting files that are moved to an encrypted folder.\r\n\r\nIf you enable this policy setting, File Explorer will not automatically encrypt files that are moved to an encrypted folder.\r\n\r\nIf you disable or do not configure this policy setting, File Explorer automatically encrypts files that are moved to an encrypted folder.\r\n\r\nThis setting applies only to files moved within a volume. When files are moved to other volumes, or if you create a new file in an encrypted folder, File Explorer encrypts those files automatically.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-encryptfilesonmove#admx-encryptfilesonmove-noencryptonmove"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_encryptfilesonmove_noencryptonmove_1","displayName":"Enabled","description":null,"helpText":null}]},"9b2b5e4b530dd093":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_netlogon_dnsttllabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},"9be1cab8b6892ee1":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup","displayName":"Common 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings which are common between the Microsoft Office Suite 2013 applications.\r\nMicrosoft Office Suite 2013 has user settings which are common between applications and are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific common Microsoft Office Suite 2013 applications.\r\nIf you enable this policy setting, certain user settings which are common between the Microsoft Office Suite 2013 applications will continue to be backed up.\r\nIf you disable this policy setting, certain user settings which are common between the Microsoft Office Suite 2013 applications will not be backed up. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013commonbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013commonbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"9b7cf8531f00af99":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled","displayName":"Enable Bookmark Bar","description":"Setting the policy to True displays a bookmark bar in Google Chrome. Setting the policy to False means users never see the bookmark bar.\r\n\r\nIf you set the policy, users can't change it. If not set, users decide whether to use this function.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_bookmarkbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9b90e0377428b875":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls","displayName":"Allow cookies on these sites","description":"Allows you to set a list of url patterns that specify sites which are allowed to set cookies.\r\n\r\nIf this policy is left not set the global default value will be used for all sites either from the DefaultCookiesSetting policy if it is set, or the user's personal configuration otherwise.\r\n\r\nSee also policies CookiesBlockedForUrls and CookiesSessionOnlyForUrls. Note that there must be no conflicting URL patterns between these three policies - it is unspecified which policy takes precedence.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9bae2c796c8dee80":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled","displayName":"Use user-added TLS certificates from platform trust stores for server authentication","description":"If enabled(or not set), user-added TLS certificates from platform trust stores will be used in path-building for TLS server authentication.\r\n\r\nIf disabled, user-added TLS certificates from platform trust stores will not be used in path-building for TLS server authentication.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_caplatformintegrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9b7daf456ba984e8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on chrome://extensions.\r\n\r\nIf the policy is not set, users can turn on developer mode on extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\r\nIf the policy is set to Allow (0), users can turn on developer mode on extensions page.\r\nIf the policy is set to Disallow (1), users can not turn on developer mode on extensions page.\r\n\r\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensiondevelopermodesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"9b174973875be46f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability","displayName":"Manage the deprecated prefixed video fullscreen API's availability","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_prefixedvideofullscreenapiavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"9b043e47ae5fa1f9":{"id":"device_vendor_msft_policy_config_defender_allowemailscanning","displayName":"Allow Email Scanning","description":"Allows or disallows scanning of email.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-defender"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_allowemailscanning_0","displayName":"Not allowed. Turns off email scanning.","description":"Not allowed. Turns off email scanning.","helpText":null},{"id":"device_vendor_msft_policy_config_defender_allowemailscanning_1","displayName":"Allowed. Turns on email scanning.","description":"Allowed. Turns on email scanning.","helpText":null}]},"9b9c5eb2d2ebcbba":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesaccessnetworkascomputer","displayName":"Access Network as Computer Object","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nAttach as computer - folder must have permissions for computer objects\r\n\r\nCAUTION: Do not use this configuration setting unless your storage provider or architecture will NOT work with user-level permissions to the VHD(x) container locations. This setting will allow the virtual machine to access all the VHD(x) files on the storage provider creating a potential security risk.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\AccessNetworkAsComputerObject\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesaccessnetworkascomputer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesaccessnetworkascomputer_1","displayName":"Enabled","description":null,"helpText":null}]},"9b3ac120d1c4645b":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407","displayName":"Allow paste operations via script","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowcopypasteviascript_iz_partname1407_1","displayName":"Prompt","description":null,"helpText":null}]},"9b66c96838ad4be4":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"9b276aab901585da":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowfontdownloads"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"9bf9f12fc7a0f7cd":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips","displayName":"Allow Google Cast to connect to Cast devices on all IP addresses","description":"Enable this policy to let Google Cast connect to Cast devices on all IP addresses, not just RFC1918/RFC4193 private addresses.\r\n\r\nDisable this policy to restrict Google Cast to Cast devices on RFC1918/RFC4193 private addresses.\r\n\r\nIf you don't configure this policy, Google Cast connects to Cast devices on RFC1918/RFC4193 private addresses only, unless you enable the CastAllowAllIPs feature.\r\n\r\nIf the 'EnableMediaRouter' (Enable Google Cast) policy is disabled, then this policy has no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_mediaroutercastallowallips_1","displayName":"Enabled","description":null,"helpText":null}]},"9b8ea1c35b055ced":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC","description":"Restricts the UDP port range used by WebRTC to a specified port interval (endpoints included).\r\n\r\nBy configuring this policy, you specify the range of local UDP ports that WebRTC can use.\r\n\r\nIf you don't configure this policy, or if you set it to an empty string or invalid port range, WebRTC can use any available local UDP port.\r\n\r\nExample value: 10000-11999","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtcudpportrange_1","displayName":"Enabled","description":null,"helpText":null}]},"9bdb31ce67362c70":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_1","displayName":"Enable advanced JavaScript optimizations on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_defaultjavascriptoptimizersetting_defaultjavascriptoptimizersetting_2","displayName":"Disable advanced JavaScript optimizations on all sites","description":null,"helpText":null}]},"9b3429bd5c0f16fe":{"id":"device_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge~contentsettings_geolocationblockedforurls_geolocationblockedforurlsdesc","displayName":"Block geolocation on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"9b35923209fcd2dd":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_exprwdexe164","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_exprwdexe164_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_savedfromurl_l_exprwdexe164_1","displayName":"True","description":null,"helpText":null}]},"9b26633672a99090":{"id":"device_vendor_msft_policy_config_settings_allowdatetime","displayName":"Allow Date Time","description":"Allows the user to change date and time settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#allowdatetime"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":[{"id":"device_vendor_msft_policy_config_settings_allowdatetime_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_settings_allowdatetime_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"9be49a91245424d2":{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync","displayName":"Do not sync accessibility settings","description":"\n Prevent the \"accessibility\" group from syncing to and from this PC. This turns off and disables the \"accessibility\" group on the \"Windows backup\" settings page in PC settings.\n\nIf you enable this policy setting, the \"accessibility\" group will not be synced.\n\nUse the option \"Allow users to turn accessibility syncing on\" so that syncing is turned off by default but not disabled.\n\nIf you do not set or disable this setting, syncing of the \"accessibility\" group is on by default and configurable by the user.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-settingssync#settingssync-disableaccessibilitysettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_settingssync_disableaccessibilitysettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},"9ba8f67d0d7e0fb5":{"id":"device_vendor_msft_policy_config_update_allowautowindowsupdatedownloadovermeterednetwork","displayName":"Allow Auto Windows Update Download Over Metered Network","description":"Option to download updates automatically over metered connections (off by default). Value type is integer. A significant number of devices primarily use cellular data and do not have Wi-Fi access, which leads to a lower number of devices getting updates. Since a large number of devices have large data plans or unlimited data, this policy can unblock devices from getting updates. This policy is accessible through the Update setting in the user interface or Group Policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#allowautowindowsupdatedownloadovermeterednetwork"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_allowautowindowsupdatedownloadovermeterednetwork_0","displayName":"Not allowed","description":"Not allowed","helpText":null},{"id":"device_vendor_msft_policy_config_update_allowautowindowsupdatedownloadovermeterednetwork_1","displayName":"Allowed","description":"Allowed","helpText":null}]},"9b27dee7b0f9501a":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters","displayName":"Special Characters (User)","description":"Use this policy setting to configure the use of special characters in the Windows Hello for Business PIN gesture. Valid special characters for Windows Hello for Business PIN gestures include: ! \" # $ % & ' ( ) * + , - . / : ; < = > ? @ [ \\ ] ^ _ ` { | } ~ .\n\nA value of 1 corresponds to “Required.” If you configure this policy setting to 1, Windows Hello for Business requires users to include at least one special character in their PIN.\n\nA value of 2 corresponds to “Disallow.” If you configure this policy setting to 2, Windows Hello for Business prevents users from using special characters in their PIN.\n\nIf you do not configure this policy setting, Windows Hello for Business does not allow users to use special characters in their PIN.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_0","displayName":"Allows the use of special characters in PIN.","description":"Allows the use of special characters in PIN.","helpText":null},{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_1","displayName":"Requires the use of at least one special characters in PIN.","description":"Requires the use of at least one special characters in PIN.","helpText":null},{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_specialcharacters_2","displayName":"Does not allow the use of special characters in PIN.","description":"Does not allow the use of special characters in PIN.","helpText":null}]},"9b22604efcd5dcd5":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_toolssecurity~l_workgroupadministrator_l_pathtosharedworkgroupinformationfileforsecuredmdbfiles","displayName":"Path to shared Workgroup information file for secured MDB files (User)","description":"Specifies the default path and filename for the workgroup information file.","helpText":"","infoUrls":[],"categoryId":"a788a6e5-ab3f-41e5-96c8-ee59627dcb4d","categoryName":"Workgroup Administrator...","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_toolssecurity~l_workgroupadministrator_l_pathtosharedworkgroupinformationfileforsecuredmdbfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_toolssecurity~l_workgroupadministrator_l_pathtosharedworkgroupinformationfileforsecuredmdbfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"9bdb1c1c63f36a56":{"id":"user_vendor_msft_policy_config_admx_globalization_y2k_y2kyear","displayName":"Year (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"9b34969edfa111a4":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitytemplates","displayName":"Security Templates (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-securitytemplates"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitytemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitytemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"9b093624d69429a8":{"id":"user_vendor_msft_policy_config_browser_preventturningoffrequiredextensions","displayName":"Prevent Turning Off Required Extensions (User)","description":"You can define a list of extensions in Microsoft Edge that users cannot turn off. You must deploy extensions through any available enterprise deployment channel, such as Microsoft Intune. When you enable this policy, users cannot uninstall extensions from their computer, but they can configure options for extensions defined in this policy, such as allow for InPrivate browsing. Any additional permissions requested by future updates of the extension gets granted automatically. When you enable this policy, you must provide a semi-colon delimited list of extension package family names (PFNs). For example, adding Microsoft.OneNoteWebClipper_8wekyb3d8bbwe;Microsoft.OfficeOnline_8wekyb3d8bbwe prevents a user from turning off the OneNote Web Clipper and Office Online extension. When enabled, removing extensions from the list does not uninstall the extension from the user’s computer automatically. To uninstall the extension, use any available enterprise deployment channel. If you enable the Allow Developer Tools policy, then this policy does not prevent users from debugging and altering the logic on an extension. If disabled or not configured, extensions defined as part of this policy get ignored. Default setting: Disabled or not configured Related policies: Allow Developer Tools Related Documents: - Find a package family name (PFN) for per-app VPN (https://docs.microsoft.com/en-us/sccm/protect/deploy-use/find-a-pfn-for-per-app-vpn) - How to manage apps you purchased from the Microsoft Store for Business with Microsoft Intune (https://docs.microsoft.com/en-us/intune/windows-store-for-business) - How to assign apps to groups with Microsoft Intune (https://docs.microsoft.com/en-us/intune/apps-deploy) - Manage apps from the Microsoft Store for Business with System Center Configuration Manager (https://docs.microsoft.com/en-us/sccm/apps/deploy-use/manage-apps-from-the-windows-store-for-business) - How to add Windows line-of-business (LOB) apps to Microsoft Intune (https://docs.microsoft.com/en-us/intune/lob-apps-windows)","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#preventturningoffrequiredextensions"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"9b1c8dc4b2d3e404":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory","displayName":"Import browsing history from default browser on first run (User)","description":"Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.\r\n\r\nUsers can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importhistory_1","displayName":"Enabled","description":null,"helpText":null}]},"9bf8267f1e0fdc13":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended","displayName":"Import browsing history from default browser on first run (User)","description":"Setting the policy to Enabled imports browsing history from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no browsing history is imported on first run.\r\n\r\nUsers can trigger an import dialog and the browsing history checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importhistory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9bc8e4d7ae4ac57b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidericonurl_defaultsearchprovidericonurl","displayName":"Default search provider icon (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"9ba525c383c0f7e5":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl","displayName":"WebRTC per URL IP Handling (User)","description":"This policy allows restricting which IP addresses and interfaces WebRTC uses when attempting to find the best available connection for each specific URL pattern.\r\n\r\nIt accepts a list of URL patterns and handling type pairs. The URL patterns are checked in order and the first match will configure which handling is used by WebRTC for the domain. When the URL of the current document is not matched against any entry, it uses the configuration set by the policy WebRtcIPHandling.\r\n\r\nFor detailed information on valid input patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. Wildcards, *, are allowed. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nValid handling values:\r\n\r\n* default - WebRTC uses all network interfaces.\r\n\r\n* default_public_and_private_interfaces - WebRTC uses all public and private interfaces.\r\n\r\n* default_public_interface_only - WebRTC uses all public interfaces, but not private ones.\r\n\r\n* disable_non_proxied_udp - WebRTC uses either UDP SOCKS proxying or will fallback to TCP proxying.\r\n\r\nSee RFC 8828 section 5.2 (https://tools.ietf.org/html/rfc8828.html#section-5.2) for a detailed description of all the handling values.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebRtcIPHandlingUrl for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.example.com\",\r\n \"handling\": \"default_public_and_private_interfaces\"\r\n },\r\n {\r\n \"url\": \"https://[*.]example.edu\",\r\n \"handling\": \"default_public_interface_only\"\r\n },\r\n {\r\n \"url\": \"*\",\r\n \"handling\": \"disable_non_proxied_udp\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtciphandlingurl_1","displayName":"Enabled","description":null,"helpText":null}]},"9b7cb73422c9278c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":null},"9b689a62c7695fd1":{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2","displayName":"Disable Internet Explorer 11 as a standalone browser (User)","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\n\nIf you enable this policy, it:\n- Prevents Internet Explorer 11 from launching as a standalone browser.\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\n- Redirects attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\n- Overrides any other policies that redirect to Internet Explorer 11.\n\nEven with this policy enabled launching Internet Explorer 11 using COM automation will still be allowed. To disable COM automation launches of Internet Explorer 11 use the \"Disable Internet Explorer 11 COM Automation\" group policy.\n\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"9b0d6e999485f21b":{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer places restrictions on each Web page it opens. The restrictions are dependent upon the location of the Web page (Internet, Intranet, Local Machine zone, etc.). Web pages on the local computer have the fewest security restrictions and reside in the Local Machine zone, making the Local Machine security zone a prime target for malicious users. Zone Elevation also disables JavaScript navigation if there is no security context.\n\nIf you enable this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.\n\nIf you disable this policy setting, no zone receives such protection for Internet Explorer processes.\n\nIf you do not configure this policy setting, any zone can be protected from zone elevation by Internet Explorer processes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-protectionfromzoneelevationinternetexplorerprocesses"],"categoryId":"3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","categoryName":"Protection From Zone Elevation","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_protectionfromzoneelevationinternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},"9bfb4a76496ce4e9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin","displayName":"Control where security restrictions on insecure origins apply (User)","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*.contoso.com\") for which security restrictions on insecure origins don't apply.\r\n\r\nThis policy lets you specify allowed origins for legacy applications that can't deploy TLS or set up a staging server for internal web development so that developers can test out features requiring secure contexts without having to deploy TLS on the staging server. This policy also prevents the origin from being labeled \"Not Secure\" in the omnibox.\r\n\r\nSetting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag.\r\n\r\nFor more information on secure contexts, see https://www.w3.org/TR/secure-contexts/.\r\n\r\nExample value:\r\n\r\nhttp://testserver.contoso.com/\r\n*.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_overridesecurityrestrictionsoninsecureorigin_1","displayName":"Enabled","description":null,"helpText":null}]},"9bafb9f120a62148":{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled","displayName":"Enable QR Code Generator (User)","description":"This policy enables the QR Code generator feature in Microsoft Edge.\r\n\r\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\r\n\r\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev125~policy~microsoft_edge_qrcodegeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9b2b5e8ae5fd0ad4":{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls","displayName":"Block idle detection on these sites (User)","description":"Allows you to specify a list of URL patterns for sites that are not allowed to use the Idle Detection API.\r\n\r\nOnly the origin of the URL is evaluated. Any path specified in a URL pattern is ignored. Wildcards, *, are supported.\r\n\r\nFor detailed information about valid URL pattern formats, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nIf you do not configure this policy, the default behavior applies to all sites. The default behavior is determined by the DefaultIdleDetectionSetting policy, if configured, or by the user’s personal settings otherwise.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~contentsettings_idledetectionblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9bb53ba8f8254a81":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory (User)","description":"This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings.\r\n\r\nIf you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.\r\n\r\nThis policy has no effect if the DownloadDirectory policy is set.\r\n\r\nFor a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars .\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9bf0fd916d64a028":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended","displayName":"Clear browsing data when Microsoft Edge closes (User)","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\r\n\r\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies)\r\n\r\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\r\n\r\nIf you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended_clearbrowsingdataonexit_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9bf625565192d587":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites (User)","description":"If you set this policy, you can list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nIf you don't set this policy, 'DefaultFileSystemWriteGuardSetting' (Control use of the File System API for writing) applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns can't conflict with 'FileSystemWriteBlockedForUrls' (Block write access to files and directories on these sites). Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemwriteaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9b9906ccc5e95570":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian","displayName":"Indonesian (User)","description":"Enables the editing language Indonesian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_indonesian_1","displayName":"Enabled","description":null,"helpText":null}]},"9b5a1c11cf65637a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent","displayName":"Allow add-in usage data to be generated and collected by the Readiness Toolkit (User)","description":"This policy setting allows you to configure whether the Readiness Toolkit for Office generates and collects add-in usage data. The data generated and collected includes when the add-in is loaded and used, and if the add-in crashes. This information is available in reports provided by the Readiness Toolkit.\r\n\r\nIf you enable this policy setting, the Readiness Toolkit generates and collects add-in usage data.\r\n\r\nIf you disable or don't configure this policy setting, the Readiness Toolkit doesn't generate or collect add-in usage data.","helpText":"","infoUrls":[],"categoryId":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","categoryName":"Readiness Toolkit","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_readinesstoolkit_l_officereadinesstoolkitenableusageagent_1","displayName":"Enabled","description":null,"helpText":null}]},"9b1139447088dbd2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon","displayName":"Load Controls in Forms3: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_1","displayName":"1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_2","displayName":"2","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_3","displayName":"3","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_loadcontrolsinforms3_l_loadcontrolsinforms3colon_4","displayName":"4","description":null,"helpText":null}]},"9bd2aba86d265ecb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath","displayName":"User templates path (User)","description":"Specifies the location of user templates.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_usertemplatespath_1","displayName":"Enabled","description":null,"helpText":null}]},"9b7845d50ca9c6fe":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires","displayName":"Legacy format signatures (User)","description":"This policy setting controls whether users can apply binary format digital signatures to Office 97-2003 documents. \r\n\r\nIf you enable this policy setting, Office 2016 applications use the Office 2003 binary format to apply digital signatures to Office 97-2003 binary documents so that they will be recognized by the Office 2003 release and earlier applications. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications use the XML--based XMLDSIG format to attach digital signatures to documents, including Office 97-2003 binary documents. XMLDSIG signatures are not recognized by Office 2003 applications or previous versions. If an Office 2003 user opens an Excel, PowerPoint, or Word binary document with an XMLDSIG signature attached, the signature will be lost.","helpText":"","infoUrls":[],"categoryId":"23c09e06-5bee-4b20-a391-36549bf0f620","categoryName":"Signing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_signing_l_legacyformatsignatires_1","displayName":"Enabled","description":null,"helpText":null}]},"9b11132d31e00819":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder","displayName":"Location of Backup Folder (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_locationofbackupfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"9b985d8a46213687":{"id":"user_vendor_msft_policy_config_outlk16v14~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_l_newoutlookautomigrationretryintervalsid","displayName":"New Outlook Auto Migration Retry Interval: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":null},"9bf1b7309efa0d02":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_0","displayName":"No conflicts are logged (default)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_1","displayName":"All conflicts logged","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_turnonloggingforallconflicts_l_turnonloggingforallconflictsdropid_2","displayName":"Unresolved conflicts logged only","description":null,"helpText":null}]},"9ba645e994a10283":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooktodaysettings_l_urlforcustomoutlooktoday_l_entertheurlofoutlooktodayswebpagemax129chars","displayName":"Enter the URL of Outlook Today's web page (max 129 chars): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"75ad885f-6118-4508-a2fd-bb26be931c3f","categoryName":"Outlook Today Settings","options":null},"9bebeb601f043bed":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages","displayName":"Send all signed messages as clear signed messages (User)","description":"This policy setting controls whether Outlook sends signed messages as clear text signed messages.\r\n\r\nIf you enable this policy setting, the \"Send clear text signed message when sending signed messages\" option is selected in the E-mail Security section of the Trust Center.\r\n\r\nIf you disable or do not configure this policy setting, when users sign e-mail messages with their digital signature and send them, Outlook uses the signature's private key to encrypt the digital signature but sends the messages as clear text, unless they are encrypted separately.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_sendallsignedmessagesasclearsignedmessages_1","displayName":"Enabled","description":null,"helpText":null}]},"9be5baf433e50cfd":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption","displayName":"Enable RPC encryption (User) (Deprecated)","description":"This policy setting controls whether Outlook uses remote procedure call (RPC) encryption to communicate with Microsoft Exchange servers. \r\n\r\nIf you enable this policy setting, Outlook uses RPC encryption when communicating with an Exchange server. Note - RPC encryption only encrypts the data from the Outlook client computer to the Exchange server. It does not encrypt the messages themselves as they traverse the Internet. \r\n\r\nIf you disable or do not configure this policy setting, RPC encryption is still used by default. This setting allows you to override the corresponding per-profile setting.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_enablerpcencryption_1","displayName":"Enabled","description":null,"helpText":null}]},"9bd2703de5980a3d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10","displayName":"Days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_0","displayName":"d","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_1","displayName":"dy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_2","displayName":"day","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjdays_l_pjdays10_4","displayName":"\r\n ","description":null,"helpText":null}]},"9b83fc9c5edc005a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits","displayName":"Work is entered in (User)","description":"Specifies the default unit of time (minutes, hours, days, weeks, or months) used in the Work field in the current project.\r\n\r\nIf you enable this setting, whenever Project displays work values, the unit you specified will be used.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjworkunits_1","displayName":"Enabled","description":null,"helpText":null}]},"9bc7423de0ecc868":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc06_l_descriptioncolon30","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"9b77001a91dd76f8":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_datecolon57","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"9b38005ae821970c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc15_l_allowsubfolders67_1","displayName":"True","description":null,"helpText":null}]},"9bd398f954c1bba1":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits","displayName":"Show measurements in units of (User)","description":"Selects the default measurement unit for the horizontal ruler and for measurements in dialog boxes.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_measurementunits_1","displayName":"Enabled","description":null,"helpText":null}]},"9b662d86c1a278c4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05","displayName":"Trusted Location #5 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/9c.json b/public/intune-definitions/9c.json index 918480a6f746..0b287f0eff6c 100644 --- a/public/intune-definitions/9c.json +++ b/public/intune-definitions/9c.json @@ -1 +1 @@ -{"9c79e0df0f4653d3":{"id":"com.android.devicerestrictionpolicy.passwordminimumuppercasecharacters","displayName":"Number of uppercase characters required","description":"Enter the number of uppercase characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"9c2a68784b565215":{"id":"com.apple.assetcache.managed_allowcachedelete","displayName":"Allow Cache Delete","description":"Allow the system to purge content from the cache automatically when it needs disk space for other apps (i.e. when free disk space runs low on the computer). Customers who want Content Caching to be as effective as possible should turn this setting off.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_allowcachedelete_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_allowcachedelete_true","displayName":"True","description":null,"helpText":null}]},"9c7e7a1b6c92255b":{"id":"com.apple.assetcache.managed_displayalerts","displayName":"Display Alerts","description":"If true, Content Caching displays exceptional conditions (alerts) as system notifications in the upper corner of the screen. Alerts were automatically displayed starting in macOS 10.13. In macOS 10.15 the alerts are off by default, but still available via this setting.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_displayalerts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_displayalerts_true","displayName":"True","description":null,"helpText":null}]},"9c077c4af5b63ba2":{"id":"com.apple.directoryservice.managed_clientid","displayName":"Client ID","description":"The client's identifier.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},"9cabacfb32493000":{"id":"com.apple.familycontrols.contentfilter_sitewhitelist_item_address","displayName":"Address","description":"The site prefix, including http(s) scheme.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},"9c0692a4c3275029":{"id":"com.apple.fileproviderd_managementremotesyncingallowlist","displayName":"Management Remote Syncing Allow List","description":"An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension synchronization. If present, and `ManagementAllowsRemoteSyncing` is set to `true`, the device allows only the apps in this list to use synchronization. This key is ignored if `ManagementAllowsRemoteSyncing` is set to `false`. If present, the other options will only be evaluated for the apps in this list. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},"9cf782eb2a6017c0":{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\n\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\n\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\n\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be well-supported in some paste destinations and/or websites. As such, if this policy is to be configured, then the plain URL option is recommended.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configurefriendlyurlformat"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_0","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_1","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_2","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},"9c766e26b0ac28c1":{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS","description":"Control the mode of the DNS-over-HTTPS resolver. Note that this policy will only set the default mode for each query. The mode can be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname.\n\nThe \"off\" mode will disable DNS-over-HTTPS.\n\nThe \"automatic\" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error.\n\nThe \"secure\" mode will only send DNS-over-HTTPS queries and will fail to resolve on error.\n\nIf you don't configure this policy, the browser might send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dnsoverhttpsmode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_0","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_1","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_2","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"9c8d7a267ab937c0":{"id":"com.apple.managedclient.preferences_extensioninstallallowlist","displayName":"Allow specific extensions to be installed","description":"By default, all extensions are allowed. However, if you block all extensions by setting the 'ExtensionInstallBlockList' policy to \"*,\" users can only install extensions defined in this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"9c875a16ac53f21b":{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout","displayName":"Specifies whether to opt out of Local Network Access restrictions","description":"This policy allows for opting out of restrictions on requests to local network endpoints.\n\nIf you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail.\n\nIf you disable or don't configure this policy, Local Network Access requests will follow the default handling behavior.\n\nFor more information about Local Network Access restrictions, see Local Network Access .\n\nTo allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy.\n\nNote: This opt-out policy is temporary and will be removed after Microsoft Edge version 152.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessrestrictionstemporaryoptout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout_true","displayName":"Enabled","description":null,"helpText":null}]},"9c01aa2215628706":{"id":"com.apple.mcx_com.apple.mcx-fdefilevaultoptions","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":null},"9cdb65333c7b840a":{"id":"com.apple.mcxmenuextras_ppp.menu","displayName":"PPP","description":"If true, enables the PPP menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ppp.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ppp.menu_true","displayName":"True","description":null,"helpText":null}]},"9c164e03bd195f5a":{"id":"com.apple.tcc.configuration-profile-policy_com.apple.tcc.configuration-profile-policy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"9c0fc341c988630c":{"id":"com.apple.universalaccess_stereoasmono","displayName":"Stereo as Mono","description":"If true, plays stereo audio as mono.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stereoasmono_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stereoasmono_true","displayName":"True","description":null,"helpText":null}]},"9c61e9fbf1ffe1a8":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type","displayName":"Type","description":"Defines the action for the removable storage groups in IncludedIDList\nEnforcement: Allow or Deny\nAudit: AuditAllowed or AuditDenied","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":[{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_allow","displayName":"Allow","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_deny","displayName":"Deny","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_auditallowed","displayName":"Audit Allowed","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_auditdenied","displayName":"Audit Denied","description":null,"helpText":null}]},"9c729ca46fc87989":{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid","displayName":"Always send compound authentication first","description":"This policy setting controls whether a device always sends a compound authentication request when the resource domain requests compound identity.\r\n\r\nNote: For a domain controller to request compound authentication, the policies \"KDC support for claims, compound authentication, and Kerberos armoring\" and \"Request compound authentication\" must be configured and enabled in the resource account domain. \r\n\r\nIf you enable this policy setting and the resource domain requests compound authentication, devices that support compound authentication always send a compound authentication request. \r\n\r\nIf you disable or do not configure this policy setting and the resource domain requests compound authentication, devices will send a non-compounded authentication request first then a compound authentication request when the service requests compound authentication.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-alwayssendcompoundid"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid_1","displayName":"Enabled","description":null,"helpText":null}]},"9c025b40badf7f68":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime","displayName":"Configure local setting override for scheduled scan time","description":"This policy setting configures a local override for the configuration of scheduled scan time. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescheduletime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},"9ca6572d6a2f8bfe":{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac","displayName":"Allow applications to prevent automatic sleep (plugged in)","description":"This policy setting allows applications and services to prevent automatic sleep.\r\n\r\nIf you enable this policy setting, any application, service, or device driver prevents Windows from automatically transitioning to sleep after a period of user inactivity.\r\n\r\nIf you disable or do not configure this policy setting, applications, services, or drivers do not prevent Windows from automatically transitioning to sleep. Only user input is used to determine if Windows should automatically sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystempowerrequestac"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac_1","displayName":"Enabled","description":null,"helpText":null}]},"9c9005f20b07f417":{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate","displayName":"Configure the refresh interval for Server Manager","description":"This policy setting allows you to set the refresh interval for Server Manager. Each refresh provides Server Manager with updated information about which roles and features are installed on servers that you are managing by using Server Manager. Server Manager also monitors the status of roles and features installed on managed servers.\r\n\r\nIf you enable this policy setting, Server Manager uses the refresh interval specified in the policy setting instead of the “Configure Refresh Interval” setting (in Windows Server 2008 and Windows Server 2008 R2), or the “Refresh the data shown in Server Manager every [x] [minutes/hours/days]” setting (in Windows Server 2012) that is configured in the Server Manager console.\r\n\r\nIf you disable this policy setting, Server Manager does not refresh automatically. If you do not configure this policy setting, Server Manager uses the refresh interval settings that are specified in the Server Manager console.\r\n\r\nNote: The default refresh interval for Server Manager is two minutes in Windows Server 2008 and Windows Server 2008 R2, or 10 minutes in Windows Server 2012.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-servermanagerautorefreshrate"],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_1","displayName":"Enabled","description":null,"helpText":null}]},"9c390cca6db9e595":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers","displayName":"Use the specified Remote Desktop license servers","description":"This policy setting allows you to specify the order in which an RD Session Host server attempts to locate Remote Desktop license servers.\r\n\r\nIf you enable this policy setting, an RD Session Host server first attempts to locate the specified license servers. If the specified license servers cannot be located, the RD Session Host server will attempt automatic license server discovery. In the automatic license server discovery process, an RD Session Host server in a Windows Server-based domain attempts to contact a license server in the following order:\r\n\r\n 1. Remote Desktop license servers that are published in Active Directory Domain Services.\r\n\r\n 2. Remote Desktop license servers that are installed on domain controllers in the same domain as the RD Session Host server.\r\n\r\nIf you disable or do not configure this policy setting, the RD Session Host server does not specify a license server at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-license-servers"],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_1","displayName":"Enabled","description":null,"helpText":null}]},"9ce844faf3e2cadf":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel","displayName":"Microsoft Excel 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Excel 2016.\r\nBy default, the user settings of Microsoft Excel 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Excel 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel_1","displayName":"Enabled","description":null,"helpText":null}]},"9cdf2fc1f1ba5bd8":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_ntpserver","displayName":"NtpServer","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},"9cd7ffd76cadb85e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on Shutdown: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"9c53356aaed09dfc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices.\r\n\r\nLeaving the policy unset lets sites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"9cc92c7434a3e058":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},"9c1f7a579904dec7":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication","description":"A list of TLS certificates that should be trusted by Google Chrome for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"9c2c04ecaf97a04f":{"id":"device_vendor_msft_policy_config_experience_showlockonusertile","displayName":"Show Lock On User Tile","description":"Shows or hides lock from the user tile menu. If you enable this policy setting, the lock option will be shown in the User Tile menu. If you disable this policy setting, the lock option will never be shown in the User Tile menu. If you do not configure this policy setting, users will be able to choose whether they want lock to show through the Power Options Control Panel.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#showlockonusertile"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_showlockonusertile_0","displayName":"Disabled","description":"The lock option is not displayed in the User Tile menu.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_showlockonusertile_1","displayName":"Enabled","description":"The lock option is displayed in the User Tile menu.","helpText":null}]},"9c53929332634521":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeskype","displayName":"Include Skype","description":"[ENABLED BY DEFAULT]\r\n\r\nSkype for Business GAL (Global Address List) data files will be included in the ODFC Container.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\IncludeSkype\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeskype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeskype_1","displayName":"Enabled","description":null,"helpText":null}]},"9c099bfa5a0abb47":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcodfcenabled","displayName":"Enabled","description":"Enables ODFC containers which changes the location of some Office based data.\r\n\r\nCAUTION: ODFC containers are designed to work with other roaming profie solutions. It is recommended to only use Profile containers when using FSLogix.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\Enabled\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcodfcenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcodfcenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9c9c27c1a33fde16":{"id":"device_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar","displayName":"Allow Microsoft services to provide enhanced suggestions as the user types in the Address bar","description":"This policy setting allows Internet Explorer to provide enhanced suggestions as the user types in the Address bar. To provide enhanced suggestions, the user's keystrokes are sent to Microsoft through Microsoft services.\n\nIf you enable this policy setting, users receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you disable this policy setting, users won't receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you don't configure this policy setting, users can change the Suggestions setting on the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedsuggestionsinaddressbar"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},"9c02504b60f8a0d2":{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2","displayName":"Disable Internet Explorer 11 as a standalone browser","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\n\nIf you enable this policy, it:\n- Prevents Internet Explorer 11 from launching as a standalone browser.\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\n- Redirects attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\n- Overrides any other policies that redirect to Internet Explorer 11.\n\nEven with this policy enabled launching Internet Explorer 11 using COM automation will still be allowed. To disable COM automation launches of Internet Explorer 11 use the \"Disable Internet Explorer 11 COM Automation\" group policy.\n\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"9c872a5ab7ba1827":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszonenavigatewindowsandframes"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"9ca7f6389d622ee8":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"9cc6931ea42be0fb":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_machineinactivitylimit_v2","displayName":"Interactive Logon Machine Inactivity Limit","description":"Interactive logon: Machine inactivity limit. Windows notices inactivity of a logon session, and if the amount of inactive time exceeds the inactivity limit, then the screen saver will run, locking the session. Default: not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_machineinactivitylimit"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"9c025f79f367ac44":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_microsoftnetworkserver_amountofidletimerequiredbeforesuspendingsession","displayName":"Microsoft Network Server Amount Of Idle Time Required Before Suspending Session","description":"Microsoft network server: Amount of idle time required before suspending a session This security setting determines the amount of continuous idle time that must pass in a Server Message Block (SMB) session before the session is suspended due to inactivity. Administrators can use this policy to control when a computer suspends an inactive SMB session. If client activity resumes, the session is automatically reestablished. For this policy setting, a value of 0 means to disconnect an idle session as quickly as is reasonably possible. The maximum value is 99999, which is 208 days; in effect, this value disables the policy. Default: This policy is not defined, which means that the system treats it as 15 minutes for servers and undefined for workstations.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#microsoftnetworkserver_amountofidletimerequiredbeforesuspendingsession"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"9c03d68b6ebd7137":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites","displayName":"Configure favorites","description":"Configures a list of managed favorites.\r\n\r\nThe policy creates a list of favorites. Each favorite contains the keys \"name\" and \"url,\" which hold the favorite's name and its target. You can configure a subfolder by defining a favorites without an \"url\" key but with an additional \"children\" key that contains a list of favorites as defined above (some of which may be folders again). Microsoft Edge amends incomplete URLs as if they were submitted via the Address Bar, for example \"microsoft.com\" becomes \"https://microsoft.com/\".\r\n\r\nThese favorites are placed in a folder that can't be modified by the user (but the user can choose to hide it from the favorites bar). By default the folder name is \"Managed favorites\" but you can change it by adding to the list of favorites a dictionary containing the key \"toplevel_name\" with the desired folder name as the value.\r\n\r\nManaged favorites are not synced to the user account and can't be modified by extensions.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"toplevel_name\": \"My managed favorites folder\"\r\n }, \r\n {\r\n \"url\": \"microsoft.com\", \r\n \"name\": \"Microsoft\"\r\n }, \r\n {\r\n \"url\": \"bing.com\", \r\n \"name\": \"Bing\"\r\n }, \r\n {\r\n \"name\": \"Microsoft Edge links\", \r\n \"children\": [\r\n {\r\n \"url\": \"www.microsoftedgeinsider.com\", \r\n \"name\": \"Microsoft Edge Insiders\"\r\n }, \r\n {\r\n \"url\": \"www.microsoft.com/windows/microsoft-edge\", \r\n \"name\": \"Microsoft Edge\"\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_1","displayName":"Enabled","description":null,"helpText":null}]},"9cefad5de282ea3b":{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9c96dbcc5ee9dfca":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on specified sites","description":"Create a list of URL patterns to specify sites that aren't allowed to display blockable (i.e. active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\r\n\r\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9c4cd990d944d370":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox","displayName":"New tab page search box experience (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox_redirect","displayName":"Address bar","description":null,"helpText":null}]},"9c58a14054188695":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls_serialblockedforurlsdesc","displayName":"Block the Serial API on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9c3c7856edc965b2":{"id":"device_vendor_msft_policy_config_mssecurityguide_turnonwindowsdefenderprotectionagainstpotentiallyunwantedapplications","displayName":"Turn on Windows Defender protection against Potentially Unwanted Applications (DEPRECATED)","description":"If this setting is enabled, Windows Defender protects against Potentially Unwanted Applications. For more information, see https://blogs.technet.microsoft.com/mmpc/2015/11/25/shields-up-on-potentially-unwanted-applications-in-your-enterprise/.\r\n\r\nIf this setting is disabled or not configured, Potentially Unwanted Application protection is disabled.\r\n\r\nBeginning with Windows 10 v1809 and Windows Server 2019, this functionality should instead be configured through the following Group Policy setting:\r\nComputer Configuration\\Administrative Templates\\Windows Components\\Windows Defender Antivirus, Configure detection for potentially unwanted applications.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-mssecurityguide#mssecurityguide-turnonwindowsdefenderprotectionagainstpotentiallyunwantedapplications"],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_mssecurityguide_turnonwindowsdefenderprotectionagainstpotentiallyunwantedapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_mssecurityguide_turnonwindowsdefenderprotectionagainstpotentiallyunwantedapplications_1","displayName":"Enabled","description":null,"helpText":null}]},"9c31c8ef9a60e1e4":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_excelexe127","displayName":"excel.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_excelexe127_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_excelexe127_1","displayName":"True","description":null,"helpText":null}]},"9cb32e549a5aaecf":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_msaccessexe67","displayName":"msaccess.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_msaccessexe67_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_msaccessexe67_1","displayName":"True","description":null,"helpText":null}]},"9c83bd987a1959ec":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_exprwdexe","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_exprwdexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_exprwdexe_1","displayName":"True","description":null,"helpText":null}]},"9c8f04e397dc9c71":{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum","displayName":"Select the driver signature mechanism for this computer:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_0","displayName":"Require inbox signed drivers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_1","displayName":"Allow inbox and Print Drivers Trusted Store signed drivers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_2","displayName":"Allow inbox, Print Drivers Trusted Store, and WHQL signed drivers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_3","displayName":"Allow inbox, Print Drivers Trusted Store, WHQL, and Trusted Publisher Store signed drivers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_4","displayName":"Allow all validly signed drivers","description":null,"helpText":null}]},"9c751dc68daab7b8":{"id":"device_vendor_msft_policy_config_remotemanagement_allowbasicauthentication_client","displayName":"Allow Basic authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) client uses Basic authentication.\n\nIf you enable this policy setting, the WinRM client uses Basic authentication. If WinRM is configured to use HTTP transport, the user name and password are sent over the network as clear text.\n\nIf you disable or do not configure this policy setting, the WinRM client does not use Basic authentication.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-allowbasicauthentication-client"],"categoryId":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","categoryName":"Win RM Client","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_allowbasicauthentication_client_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_allowbasicauthentication_client_1","displayName":"Enabled","description":null,"helpText":null}]},"9ceeadd5bcf9fcc7":{"id":"device_vendor_msft_policy_config_search_alwaysuseautolangdetection","displayName":"Always Use Auto Lang Detection","description":"Specifies whether to always use automatic language detection when indexing content and properties. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Search#alwaysuseautolangdetection"],"categoryId":"794337be-8833-4b9a-bb88-8a030141578d","categoryName":"Search","options":[{"id":"device_vendor_msft_policy_config_search_alwaysuseautolangdetection_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_search_alwaysuseautolangdetection_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"9ca7666bc91263cd":{"id":"device_vendor_msft_policy_config_timelanguagesettings_blockcleanupofunusedpreinstalledlangpacks","displayName":"Block Cleanup Of Unused Preinstalled Lang Packs","description":"This policy setting controls whether the LPRemove or Language Packs Uninstaller task will run to clean up language packs installed on a machine but are not used by any users on that machine.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TimeLanguageSettings#blockcleanupofunusedpreinstalledlangpacks"],"categoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","categoryName":"Time Language Settings","options":[{"id":"device_vendor_msft_policy_config_timelanguagesettings_blockcleanupofunusedpreinstalledlangpacks_0","displayName":"Block","description":"Not blocked.","helpText":null},{"id":"device_vendor_msft_policy_config_timelanguagesettings_blockcleanupofunusedpreinstalledlangpacks_1","displayName":"Allow","description":"Blocked.","helpText":null}]},"9cba151217b34f62":{"id":"passcode_maximumfailedattempts","displayName":"Maximum Number of Failed Attempts","description":"Specifies the number of failed passcode attempts that can be made before an iOS device is erased or a macOS device is locked. If you don’t change this setting, after six failed attempts, the device imposes a time delay before a passcode can be entered again. The time delay increases with each failed attempt. After the final failed attempt, all data and settings are securely erased from the iOS device. A macOS device locks after the final attempt. The passcode time delay begins after the sixth attempt, so if you set this value to six or lower, no time delay is imposed and the device is erased when the attempt limit is exceeded.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":null},"9c64c3769922b129":{"id":"safari_privacy_permissiondefaults","displayName":"Permission Defaults","description":"The dictionary of website permission defaults. Each key in the dictionary represents a single website, or a website and its sub-domains. The dictionary values represent the permission defaults that Safari applies for each website that matches the key.\n\nSafari supports the following patterns for the website key:\n\n- A specific domain such as \"example.com\" or \"www.example.com\". The permission defaults apply to that website only.\n- A wildcard domain that uses a single \"\\*\" character as a prefix for the domain, such as \"\\*example.com\". The permission defaults apply to both the exact domain \"example.com\", and any sub-domains such as \"www.example.com\". It won't match other domains with a similar string suffix such as \"myexample.com\".\n\nWhen multiple patterns match a website, Safari uses the most precise pattern. For example, for the website \"www.example.com\", if rules \"www.example.com\" and \"*example.com\" match, Safari uses the former.","helpText":null,"infoUrls":[],"categoryId":"e0ab6868-4b53-4310-b665-f7c979941db7","categoryName":"Safari Browser","options":null},"9cee781fdea3f194":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"9cb8c2815ec8a1e1":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_1","displayName":"Initial reminder balloon lifetime (User)","description":"Determines how long the first reminder balloon for a network status change is displayed.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the duration of the first reminder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderinittimeout-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_1_1","displayName":"Enabled","description":null,"helpText":null}]},"9c42b93f6545f55d":{"id":"user_vendor_msft_policy_config_admx_startmenu_nogamesfolderonstartmenu","displayName":"Remove Games link from Start Menu (User)","description":"If you enable this policy the start menu will not show a link to the Games folder.\r\n\r\nIf you disable or do not configure this policy, the start menu will show a link to the Games folder, unless the user chooses to remove it in the start menu control panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nogamesfolderonstartmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nogamesfolderonstartmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nogamesfolderonstartmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"9c4e9872cbba0817":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_ts_gateway_override","displayName":"Allow users to change this setting (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"a561e59a-09b7-4106-a6fa-0b82036a5b49","categoryName":"RD Gateway","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_ts_gateway_override_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_ts_gateway_override_1","displayName":"True","description":null,"helpText":null}]},"9cbfd7a81c946815":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist_browserswitcherurlgreylistdesc","displayName":"Websites that should never trigger a browser switch. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"9c69fd9bb161bc0a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"9c3d4feb5134337d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload_1","displayName":"Enabled","description":null,"helpText":null}]},"9c15633fd9d8159d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation","displayName":"Configure the home page URL (User)","description":"Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup.\r\n\r\nIf the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect.\r\n\r\n The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome.\r\n\r\nLeaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"9cd9695671baa8e2":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm (User)","description":"This feature enables the Happy Eyeballs V3 algorithm to make connection attempts. See https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3 for details.\r\n\r\nSetting the policy to Enabled means Google Chrome will use the Happy Eyeballs V3 algorithm for connection attempts.\r\n\r\nSetting the policy to Disabled turns off the Happy Eyeballs V3 algorithm.\r\n\r\nNot setting the policy, Google Chrome will turn on or off the Happy Eyeballs V3 algorithm based on chrome://flags/#happy-eyeballs-v3.\r\n\r\nThis policy supports dynamic refresh.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ce20d4415afc864":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled","displayName":"Control the new behavior of HTMLElement.offsetParent (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9c30e666b25fdafe":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally","displayName":"Always open PDF files externally (User)","description":"Disables the internal PDF viewer in Microsoft Edge.\r\n\r\nIf you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will open PDF files (unless the user disables it).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally_1","displayName":"Enabled","description":null,"helpText":null}]},"9cfeb39e58d15482":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting","displayName":"Configure cookies (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_1","displayName":"Let all sites create cookies","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_2","displayName":"Don't let any site create cookies","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_4","displayName":"Keep cookies for the duration of the session","description":null,"helpText":null}]},"9c10fe303d5d9dde":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy_applicationguardcontainerproxy","displayName":"Application Guard Container Proxy (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":null},"9c554978b4e5e536":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverinfo4","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"9c4fada10fee98ad":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles","displayName":"Do not upload media files (User)","description":"Disables/Enables uploading of media files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles_1","displayName":"Enabled","description":null,"helpText":null}]},"9c8ca48027e9bf99":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_pathcolon17","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"9c796133e855df2f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible","displayName":"Use long file names whenever possible (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible_1","displayName":"Enabled","description":null,"helpText":null}]},"9c42dc83e6b6803a":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption","displayName":"Disable Outlook send email to OneNote option (User)","description":"This policy disables the OneNote ''Send to OneNote'' add-in for Microsoft Outlook. By default OneNote installs an add-in on the Outlook toolbar which allows users to send emails to OneNote. The ''Send to OneNote'' button appears on the main mail module in Outlook as well as when viewing an email message. You may disable this feature with this policy.","helpText":"","infoUrls":[],"categoryId":"a87f9d6a-0c84-4cad-839f-e912c6006c12","categoryName":"Send to OneNote","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption_1","displayName":"Enabled","description":null,"helpText":null}]},"9c6bd23b453d28f6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts","displayName":"Do not allow Outlook object model scripts to run for shared folders (User) (Deprecated)","description":"This policy setting controls whether Outlook executes scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with shared folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_1","displayName":"Enabled","description":null,"helpText":null}]},"9cac66e91dae17c5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_l_endearlylongspinid","displayName":"Minutes to reduce meetings by: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},"9c734807a72db142":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert","displayName":"Do not display New Mail alert for users (User)","description":"By default, users receive an alert message on their desktops when new mail arrives. By enabling this setting, the alert is not displayed for new mail.","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},"9cabc0eac35e417b":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_l_autodiscoverredirectserverslist","displayName":"HTTPS server names: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},"9cee2efb8332bab3":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles","displayName":"Don’t allow the use of Live Subtitles (User)","description":"\r\nThis policy setting controls whether users can turn on Live Subtitles during a presentation. By default, Live Subtitles are off but can be turned on by users.\r\n\r\nIf you enable this policy setting, users can't turn on Live Subtitles during a presentation.\r\n\r\nIf you disable or don't configure this policy setting, users can turn on Live Subtitles.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles_1","displayName":"Enabled","description":null,"helpText":null}]},"9c197154836a360d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks","displayName":"New tasks (User)","description":"Specifies the default start date for new tasks as they are entered in the current project. For projects scheduled from the start date, the options are \"Start on Project Start Date\" and \"Start on Current Date.\" For projects scheduled from the finish date, the options are \"Finish on Project Finish Date\" and \"Start on Current Date.\"\r\n\r\nIf you enable this setting, new tasks will start on the date you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_1","displayName":"Enabled","description":null,"helpText":null}]},"9c38e8f0e9edc7a2":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting","displayName":"Enable connector splitting (User)","description":"When you place a shape on the line of a connector, it splits and each piece becomes a separate connector glued to the shape. Not all drawing types support connector splitting.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting_1","displayName":"Enabled","description":null,"helpText":null}]},"9c874d8cd4d721e0":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly","displayName":"Show white space between pages in Print Layout view (User)","description":"Determines whether the symbol used to represent white space between pages in Print view only is shown in the document.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly_1","displayName":"Enabled","description":null,"helpText":null}]},"9c7c0fe396237a3c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"9c79e0df0f4653d3":{"id":"com.android.devicerestrictionpolicy.passwordminimumuppercasecharacters","displayName":"Number of uppercase characters required","description":"Enter the number of uppercase characters the password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"9c2a68784b565215":{"id":"com.apple.assetcache.managed_allowcachedelete","displayName":"Allow Cache Delete","description":"Allow the system to purge content from the cache automatically when it needs disk space for other apps (i.e. when free disk space runs low on the computer). Customers who want Content Caching to be as effective as possible should turn this setting off.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_allowcachedelete_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_allowcachedelete_true","displayName":"True","description":null,"helpText":null}]},"9c7e7a1b6c92255b":{"id":"com.apple.assetcache.managed_displayalerts","displayName":"Display Alerts","description":"If true, Content Caching displays exceptional conditions (alerts) as system notifications in the upper corner of the screen. Alerts were automatically displayed starting in macOS 10.13. In macOS 10.15 the alerts are off by default, but still available via this setting.\r\nAvailable in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_displayalerts_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_displayalerts_true","displayName":"True","description":null,"helpText":null}]},"9c077c4af5b63ba2":{"id":"com.apple.directoryservice.managed_clientid","displayName":"Client ID","description":"The client's identifier.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},"9cabacfb32493000":{"id":"com.apple.familycontrols.contentfilter_sitewhitelist_item_address","displayName":"Address","description":"The site prefix, including http(s) scheme.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},"9c0692a4c3275029":{"id":"com.apple.fileproviderd_managementremotesyncingallowlist","displayName":"Management Remote Syncing Allow List","description":"An array of strings representing the composed identifiers of apps. The device allows the corresponding apps to use File Provider extension synchronization. If present, and `ManagementAllowsRemoteSyncing` is set to `true`, the device allows only the apps in this list to use synchronization. This key is ignored if `ManagementAllowsRemoteSyncing` is set to `false`. If present, the other options will only be evaluated for the apps in this list. The format of the app identifiers is \"Bundle-ID (Team-ID)\", for example `com.example.app (ABCD1234)`.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":null},"9cf782eb2a6017c0":{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\n\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\n\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\n\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be well-supported in some paste destinations and/or websites. As such, if this policy is to be configured, then the plain URL option is recommended.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#configurefriendlyurlformat"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_0","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_1","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_configurefriendlyurlformat_2","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},"9c766e26b0ac28c1":{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS","description":"Control the mode of the DNS-over-HTTPS resolver. Note that this policy will only set the default mode for each query. The mode can be overridden for special types of queries such as requests to resolve a DNS-over-HTTPS server hostname.\n\nThe \"off\" mode will disable DNS-over-HTTPS.\n\nThe \"automatic\" mode will send DNS-over-HTTPS queries first if a DNS-over-HTTPS server is available and may fallback to sending insecure queries on error.\n\nThe \"secure\" mode will only send DNS-over-HTTPS queries and will fail to resolve on error.\n\nIf you don't configure this policy, the browser might send DNS-over-HTTPS requests to a resolver associated with the user's configured system resolver.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#dnsoverhttpsmode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_0","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_1","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_dnsoverhttpsmode_2","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"9c8d7a267ab937c0":{"id":"com.apple.managedclient.preferences_extensioninstallallowlist","displayName":"Allow specific extensions to be installed","description":"By default, all extensions are allowed. However, if you block all extensions by setting the 'ExtensionInstallBlockList' policy to \"*,\" users can only install extensions defined in this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"9c875a16ac53f21b":{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout","displayName":"Specifies whether to opt out of Local Network Access restrictions","description":"This policy allows for opting out of restrictions on requests to local network endpoints.\n\nIf you enable this policy, Local Network Access requests will only display warnings in Edge DevTools when Local Network Access checks fail.\n\nIf you disable or don't configure this policy, Local Network Access requests will follow the default handling behavior.\n\nFor more information about Local Network Access restrictions, see Local Network Access .\n\nTo allow specific URL patterns that should automatically be granted Local Network Access permission, use the LocalNetworkAccessAllowedForUrls policy.\n\nNote: This opt-out policy is temporary and will be removed after Microsoft Edge version 152.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#localnetworkaccessrestrictionstemporaryoptout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_localnetworkaccessrestrictionstemporaryoptout_true","displayName":"Enabled","description":null,"helpText":null}]},"9c01aa2215628706":{"id":"com.apple.mcx_com.apple.mcx-fdefilevaultoptions","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","categoryName":"FileVault Options","options":null},"9cdb65333c7b840a":{"id":"com.apple.mcxmenuextras_ppp.menu","displayName":"PPP","description":"If true, enables the PPP menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_ppp.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_ppp.menu_true","displayName":"True","description":null,"helpText":null}]},"9c164e03bd195f5a":{"id":"com.apple.tcc.configuration-profile-policy_com.apple.tcc.configuration-profile-policy","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"9c0fc341c988630c":{"id":"com.apple.universalaccess_stereoasmono","displayName":"Stereo as Mono","description":"If true, plays stereo audio as mono.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":[{"id":"com.apple.universalaccess_stereoasmono_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.universalaccess_stereoasmono_true","displayName":"True","description":null,"helpText":null}]},"9c61e9fbf1ffe1a8":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type","displayName":"Type","description":"Defines the action for the removable storage groups in IncludedIDList\nEnforcement: Allow or Deny\nAudit: AuditAllowed or AuditDenied","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":[{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_allow","displayName":"Allow","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_deny","displayName":"Deny","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_auditallowed","displayName":"Audit Allowed","description":null,"helpText":null},{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_type_auditdenied","displayName":"Audit Denied","description":null,"helpText":null}]},"9c729ca46fc87989":{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid","displayName":"Always send compound authentication first","description":"This policy setting controls whether a device always sends a compound authentication request when the resource domain requests compound identity.\r\n\r\nNote: For a domain controller to request compound authentication, the policies \"KDC support for claims, compound authentication, and Kerberos armoring\" and \"Request compound authentication\" must be configured and enabled in the resource account domain. \r\n\r\nIf you enable this policy setting and the resource domain requests compound authentication, devices that support compound authentication always send a compound authentication request. \r\n\r\nIf you disable or do not configure this policy setting and the resource domain requests compound authentication, devices will send a non-compounded authentication request first then a compound authentication request when the service requests compound authentication.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-alwayssendcompoundid"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_alwayssendcompoundid_1","displayName":"Enabled","description":null,"helpText":null}]},"9c025b40badf7f68":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime","displayName":"Configure local setting override for scheduled scan time","description":"This policy setting configures a local override for the configuration of scheduled scan time. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-localsettingoverridescheduletime"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_localsettingoverridescheduletime_1","displayName":"Enabled","description":null,"helpText":null}]},"9ca6572d6a2f8bfe":{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac","displayName":"Allow applications to prevent automatic sleep (plugged in)","description":"This policy setting allows applications and services to prevent automatic sleep.\r\n\r\nIf you enable this policy setting, any application, service, or device driver prevents Windows from automatically transitioning to sleep after a period of user inactivity.\r\n\r\nIf you disable or do not configure this policy setting, applications, services, or drivers do not prevent Windows from automatically transitioning to sleep. Only user input is used to determine if Windows should automatically sleep.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-allowsystempowerrequestac"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_allowsystempowerrequestac_1","displayName":"Enabled","description":null,"helpText":null}]},"9c9005f20b07f417":{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate","displayName":"Configure the refresh interval for Server Manager","description":"This policy setting allows you to set the refresh interval for Server Manager. Each refresh provides Server Manager with updated information about which roles and features are installed on servers that you are managing by using Server Manager. Server Manager also monitors the status of roles and features installed on managed servers.\r\n\r\nIf you enable this policy setting, Server Manager uses the refresh interval specified in the policy setting instead of the “Configure Refresh Interval” setting (in Windows Server 2008 and Windows Server 2008 R2), or the “Refresh the data shown in Server Manager every [x] [minutes/hours/days]” setting (in Windows Server 2012) that is configured in the Server Manager console.\r\n\r\nIf you disable this policy setting, Server Manager does not refresh automatically. If you do not configure this policy setting, Server Manager uses the refresh interval settings that are specified in the Server Manager console.\r\n\r\nNote: The default refresh interval for Server Manager is two minutes in Windows Server 2008 and Windows Server 2008 R2, or 10 minutes in Windows Server 2012.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-servermanagerautorefreshrate"],"categoryId":"e042b102-b12c-48d1-86ef-f6d296da5b95","categoryName":"Server Manager","options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_servermanagerautorefreshrate_1","displayName":"Enabled","description":null,"helpText":null}]},"9c390cca6db9e595":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers","displayName":"Use the specified Remote Desktop license servers","description":"This policy setting allows you to specify the order in which an RD Session Host server attempts to locate Remote Desktop license servers.\r\n\r\nIf you enable this policy setting, an RD Session Host server first attempts to locate the specified license servers. If the specified license servers cannot be located, the RD Session Host server will attempt automatic license server discovery. In the automatic license server discovery process, an RD Session Host server in a Windows Server-based domain attempts to contact a license server in the following order:\r\n\r\n 1. Remote Desktop license servers that are published in Active Directory Domain Services.\r\n\r\n 2. Remote Desktop license servers that are installed on domain controllers in the same domain as the RD Session Host server.\r\n\r\nIf you disable or do not configure this policy setting, the RD Session Host server does not specify a license server at the Group Policy level.\r\n\r\n This setting is only available to Windows Insiders.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-license-servers"],"categoryId":"4b540860-0858-48f4-8830-18383bb1766f","categoryName":"Licensing","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_license_servers_1","displayName":"Enabled","description":null,"helpText":null}]},"9ce844faf3e2cadf":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel","displayName":"Microsoft Excel 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Excel 2016.\r\nBy default, the user settings of Microsoft Excel 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Excel 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016excel_1","displayName":"Enabled","description":null,"helpText":null}]},"9cdf2fc1f1ba5bd8":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_configure_ntpclient_w32time_ntpserver","displayName":"NtpServer","description":null,"helpText":"","infoUrls":[],"categoryId":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","categoryName":"Time Providers","options":null},"9cd7ffd76cadb85e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_fetchkeepalivedurationsecondsonshutdown_fetchkeepalivedurationsecondsonshutdown","displayName":"Fetch keepalive duration on Shutdown: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"9c53356aaed09dfc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Setting the policy to 3 lets websites ask for access to nearby Bluetooth devices. Setting the policy to 2 denies access to nearby Bluetooth devices.\r\n\r\nLeaving the policy unset lets sites ask for access, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultwebbluetoothguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"9cc92c7434a3e058":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~screencapture_windowcaptureallowedbyorigins_windowcaptureallowedbyoriginsdesc","displayName":"Allow Window and Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"4aa852ab-6269-4883-906f-0a0944fa1261","categoryName":"Allow or deny screen capture","options":null},"9c1f7a579904dec7":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication","description":"A list of TLS certificates that should be trusted by Google Chrome for server authentication.\r\nCertificates should be base64-encoded.\r\n\r\nExample value:\r\n\r\nMIICCTCCAY6gAwIBAgINAgPluILrIPglJ209ZjAKBggqhkjOPQQDAzBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwHhcNMTYwNjIyMDAwMDAwWhcNMzYwNjIyMDAwMDAwWjBHMQswCQYDVQQGEwJVUzEiMCAGA1UEChMZR29vZ2xlIFRydXN0IFNlcnZpY2VzIExMQzEUMBIGA1UEAxMLR1RTIFJvb3QgUjMwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQfTzOHMymKoYTey8chWEGJ6ladK0uFxh1MJ7x/JlFyb+Kf1qPKzEUURout736GjOyxfi//qXGdGIRFBEFVbivqJn+7kAHjSxm65FSWRQmx1WyRRK2EE46ajA2ADDL24CejQjBAMA4GA1UdDwEB/wQEAwIBhjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBTB8Sa6oC2uhYHP0/EqEr24Cmf9vDAKBggqhkjOPQQDAwNpADBmAjEA9uEglRR7VKOQFhG/hMjqb2sXnh5GmCCbn9MN2azTL818+FsuVbu/3ZL3pAzcMeGiAjEA/JdmZuVDFhOD3cffL74UOO0BzrEXGhF16b0DjyZ+hOXJYKaV11RZt+cRLInUue4X","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_1","displayName":"Enabled","description":null,"helpText":null}]},"9c2c04ecaf97a04f":{"id":"device_vendor_msft_policy_config_experience_showlockonusertile","displayName":"Show Lock On User Tile","description":"Shows or hides lock from the user tile menu. If you enable this policy setting, the lock option will be shown in the User Tile menu. If you disable this policy setting, the lock option will never be shown in the User Tile menu. If you do not configure this policy setting, users will be able to choose whether they want lock to show through the Power Options Control Panel.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#showlockonusertile"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_showlockonusertile_0","displayName":"Disabled","description":"The lock option is not displayed in the User Tile menu.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_showlockonusertile_1","displayName":"Enabled","description":"The lock option is displayed in the User Tile menu.","helpText":null}]},"9c53929332634521":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeskype","displayName":"Include Skype","description":"[ENABLED BY DEFAULT]\r\n\r\nSkype for Business GAL (Global Address List) data files will be included in the ODFC Container.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\IncludeSkype\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeskype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcincludeskype_1","displayName":"Enabled","description":null,"helpText":null}]},"9c099bfa5a0abb47":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcodfcenabled","displayName":"Enabled","description":"Enables ODFC containers which changes the location of some Office based data.\r\n\r\nCAUTION: ODFC containers are designed to work with other roaming profie solutions. It is recommended to only use Profile containers when using FSLogix.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\Enabled\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcodfcenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcodfcenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9c9c27c1a33fde16":{"id":"device_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar","displayName":"Allow Microsoft services to provide enhanced suggestions as the user types in the Address bar","description":"This policy setting allows Internet Explorer to provide enhanced suggestions as the user types in the Address bar. To provide enhanced suggestions, the user's keystrokes are sent to Microsoft through Microsoft services.\n\nIf you enable this policy setting, users receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you disable this policy setting, users won't receive enhanced suggestions while typing in the Address bar. In addition, users won't be able to change the Suggestions setting on the Settings charm.\n\nIf you don't configure this policy setting, users can change the Suggestions setting on the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowenhancedsuggestionsinaddressbar"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowenhancedsuggestionsinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},"9c02504b60f8a0d2":{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2","displayName":"Disable Internet Explorer 11 as a standalone browser","description":"This policy lets you restrict launching of Internet Explorer as a standalone browser.\n\nIf you enable this policy, it:\n- Prevents Internet Explorer 11 from launching as a standalone browser.\n- Restricts Internet Explorer's usage to Microsoft Edge's native 'Internet Explorer mode'.\n- Redirects attempts at launching Internet Explorer 11 to Microsoft Edge Stable Channel browser.\n- Overrides any other policies that redirect to Internet Explorer 11.\n\nEven with this policy enabled launching Internet Explorer 11 using COM automation will still be allowed. To disable COM automation launches of Internet Explorer 11 use the \"Disable Internet Explorer 11 COM Automation\" group policy.\n\nIf you disable, or don’t configure this policy, all sites are opened using the current active browser settings. Note: Microsoft Edge Stable Channel must be installed for this policy to take effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableinternetexplorerapp"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableinternetexplorerapp_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"9c872a5ab7ba1827":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszonenavigatewindowsandframes"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"9ca7f6389d622ee8":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"9cc6931ea42be0fb":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_interactivelogon_machineinactivitylimit_v2","displayName":"Interactive Logon Machine Inactivity Limit","description":"Interactive logon: Machine inactivity limit. Windows notices inactivity of a logon session, and if the amount of inactive time exceeds the inactivity limit, then the screen saver will run, locking the session. Default: not enforced.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#interactivelogon_machineinactivitylimit"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"9c025f79f367ac44":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_microsoftnetworkserver_amountofidletimerequiredbeforesuspendingsession","displayName":"Microsoft Network Server Amount Of Idle Time Required Before Suspending Session","description":"Microsoft network server: Amount of idle time required before suspending a session This security setting determines the amount of continuous idle time that must pass in a Server Message Block (SMB) session before the session is suspended due to inactivity. Administrators can use this policy to control when a computer suspends an inactive SMB session. If client activity resumes, the session is automatically reestablished. For this policy setting, a value of 0 means to disconnect an idle session as quickly as is reasonably possible. The maximum value is 99999, which is 208 days; in effect, this value disables the policy. Default: This policy is not defined, which means that the system treats it as 15 minutes for servers and undefined for workstations.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#microsoftnetworkserver_amountofidletimerequiredbeforesuspendingsession"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"9c03d68b6ebd7137":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites","displayName":"Configure favorites","description":"Configures a list of managed favorites.\r\n\r\nThe policy creates a list of favorites. Each favorite contains the keys \"name\" and \"url,\" which hold the favorite's name and its target. You can configure a subfolder by defining a favorites without an \"url\" key but with an additional \"children\" key that contains a list of favorites as defined above (some of which may be folders again). Microsoft Edge amends incomplete URLs as if they were submitted via the Address Bar, for example \"microsoft.com\" becomes \"https://microsoft.com/\".\r\n\r\nThese favorites are placed in a folder that can't be modified by the user (but the user can choose to hide it from the favorites bar). By default the folder name is \"Managed favorites\" but you can change it by adding to the list of favorites a dictionary containing the key \"toplevel_name\" with the desired folder name as the value.\r\n\r\nManaged favorites are not synced to the user account and can't be modified by extensions.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"toplevel_name\": \"My managed favorites folder\"\r\n }, \r\n {\r\n \"url\": \"microsoft.com\", \r\n \"name\": \"Microsoft\"\r\n }, \r\n {\r\n \"url\": \"bing.com\", \r\n \"name\": \"Bing\"\r\n }, \r\n {\r\n \"name\": \"Microsoft Edge links\", \r\n \"children\": [\r\n {\r\n \"url\": \"www.microsoftedgeinsider.com\", \r\n \"name\": \"Microsoft Edge Insiders\"\r\n }, \r\n {\r\n \"url\": \"www.microsoft.com/windows/microsoft-edge\", \r\n \"name\": \"Microsoft Edge\"\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_managedfavorites_1","displayName":"Enabled","description":null,"helpText":null}]},"9cefad5de282ea3b":{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_exemptfiletypedownloadwarnings_exemptfiletypedownloadwarnings","displayName":"Disable download file type extension-based warnings for specified file types on domains (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9c96dbcc5ee9dfca":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on specified sites","description":"Create a list of URL patterns to specify sites that aren't allowed to display blockable (i.e. active) mixed content (that is, HTTP content on HTTPS sites) and for which optionally blockable mixed content upgrades will be disabled.\r\n\r\nIf you don't configure this policy, blockable mixed content will be blocked and optionally blockable mixed content will be upgraded. However, users will be allowed to set exceptions to allow insecure mixed content for specific sites.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9c4cd990d944d370":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox","displayName":"New tab page search box experience (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox_bing","displayName":"Search box (Recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge~defaultsearchprovider_newtabpagesearchbox_newtabpagesearchbox_redirect","displayName":"Address bar","description":null,"helpText":null}]},"9c58a14054188695":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_serialblockedforurls_serialblockedforurlsdesc","displayName":"Block the Serial API on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9c3c7856edc965b2":{"id":"device_vendor_msft_policy_config_mssecurityguide_turnonwindowsdefenderprotectionagainstpotentiallyunwantedapplications","displayName":"Turn on Windows Defender protection against Potentially Unwanted Applications (DEPRECATED)","description":"If this setting is enabled, Windows Defender protects against Potentially Unwanted Applications. For more information, see https://blogs.technet.microsoft.com/mmpc/2015/11/25/shields-up-on-potentially-unwanted-applications-in-your-enterprise/.\r\n\r\nIf this setting is disabled or not configured, Potentially Unwanted Application protection is disabled.\r\n\r\nBeginning with Windows 10 v1809 and Windows Server 2019, this functionality should instead be configured through the following Group Policy setting:\r\nComputer Configuration\\Administrative Templates\\Windows Components\\Windows Defender Antivirus, Configure detection for potentially unwanted applications.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-mssecurityguide#mssecurityguide-turnonwindowsdefenderprotectionagainstpotentiallyunwantedapplications"],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_mssecurityguide_turnonwindowsdefenderprotectionagainstpotentiallyunwantedapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_mssecurityguide_turnonwindowsdefenderprotectionagainstpotentiallyunwantedapplications_1","displayName":"Enabled","description":null,"helpText":null}]},"9c31c8ef9a60e1e4":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_excelexe127","displayName":"excel.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_excelexe127_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_excelexe127_1","displayName":"True","description":null,"helpText":null}]},"9cb32e549a5aaecf":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_msaccessexe67","displayName":"msaccess.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_msaccessexe67_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_msaccessexe67_1","displayName":"True","description":null,"helpText":null}]},"9c83bd987a1959ec":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_exprwdexe","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_exprwdexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_exprwdexe_1","displayName":"True","description":null,"helpText":null}]},"9c8f04e397dc9c71":{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum","displayName":"Select the driver signature mechanism for this computer:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_0","displayName":"Require inbox signed drivers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_1","displayName":"Allow inbox and Print Drivers Trusted Store signed drivers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_2","displayName":"Allow inbox, Print Drivers Trusted Store, and WHQL signed drivers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_3","displayName":"Allow inbox, Print Drivers Trusted Store, WHQL, and Trusted Publisher Store signed drivers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configuredrivervalidationlevel_drivervalidationlevel_enum_4","displayName":"Allow all validly signed drivers","description":null,"helpText":null}]},"9c751dc68daab7b8":{"id":"device_vendor_msft_policy_config_remotemanagement_allowbasicauthentication_client","displayName":"Allow Basic authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) client uses Basic authentication.\n\nIf you enable this policy setting, the WinRM client uses Basic authentication. If WinRM is configured to use HTTP transport, the user name and password are sent over the network as clear text.\n\nIf you disable or do not configure this policy setting, the WinRM client does not use Basic authentication.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-allowbasicauthentication-client"],"categoryId":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","categoryName":"Win RM Client","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_allowbasicauthentication_client_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_allowbasicauthentication_client_1","displayName":"Enabled","description":null,"helpText":null}]},"9ceeadd5bcf9fcc7":{"id":"device_vendor_msft_policy_config_search_alwaysuseautolangdetection","displayName":"Always Use Auto Lang Detection","description":"Specifies whether to always use automatic language detection when indexing content and properties. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Search#alwaysuseautolangdetection"],"categoryId":"794337be-8833-4b9a-bb88-8a030141578d","categoryName":"Search","options":[{"id":"device_vendor_msft_policy_config_search_alwaysuseautolangdetection_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_search_alwaysuseautolangdetection_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"9ca7666bc91263cd":{"id":"device_vendor_msft_policy_config_timelanguagesettings_blockcleanupofunusedpreinstalledlangpacks","displayName":"Block Cleanup Of Unused Preinstalled Lang Packs","description":"This policy setting controls whether the LPRemove or Language Packs Uninstaller task will run to clean up language packs installed on a machine but are not used by any users on that machine.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TimeLanguageSettings#blockcleanupofunusedpreinstalledlangpacks"],"categoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","categoryName":"Time Language Settings","options":[{"id":"device_vendor_msft_policy_config_timelanguagesettings_blockcleanupofunusedpreinstalledlangpacks_0","displayName":"Block","description":"Not blocked.","helpText":null},{"id":"device_vendor_msft_policy_config_timelanguagesettings_blockcleanupofunusedpreinstalledlangpacks_1","displayName":"Allow","description":"Blocked.","helpText":null}]},"9c34402a674b4c3b":{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyschedule","displayName":"Maintenance Window Monthly Schedule","description":"If the maintenance window repeat schedule is set to monthly, configure whether to repeat on the same date each month (the 1st of every month), a day within a specific week (for example, the second Tuesday of every month), or on the last day of each month. 1=repeat on same date each month, 2=repeat on a day of a specific week, 3=repeat on the last day of each month.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowmonthlyschedule"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyschedule_1","displayName":"Date-based","description":"Date-based","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyschedule_2","displayName":"Week-based","description":"Week-based","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowmonthlyschedule_3","displayName":"Last day of the month","description":"Last day of the month","helpText":null}]},"9ce2569ea20b8bc7":{"id":"device_vendor_msft_policy_config_update_maintenancewindowweeklyfriday","displayName":"Maintenance Window Weekly Friday","description":"If the maintenance window repeat schedule is set to weekly, configure whether Friday is included in the weekly schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowweeklyfriday"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"9cba151217b34f62":{"id":"passcode_maximumfailedattempts","displayName":"Maximum Number of Failed Attempts","description":"Specifies the number of failed passcode attempts that can be made before an iOS device is erased or a macOS device is locked. If you don’t change this setting, after six failed attempts, the device imposes a time delay before a passcode can be entered again. The time delay increases with each failed attempt. After the final failed attempt, all data and settings are securely erased from the iOS device. A macOS device locks after the final attempt. The passcode time delay begins after the sixth attempt, so if you set this value to six or lower, no time delay is imposed and the device is erased when the attempt limit is exceeded.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":null},"9c64c3769922b129":{"id":"safari_privacy_permissiondefaults","displayName":"Permission Defaults","description":"The dictionary of website permission defaults. Each key in the dictionary represents a single website, or a website and its sub-domains. The dictionary values represent the permission defaults that Safari applies for each website that matches the key.\n\nSafari supports the following patterns for the website key:\n\n- A specific domain such as \"example.com\" or \"www.example.com\". The permission defaults apply to that website only.\n- A wildcard domain that uses a single \"\\*\" character as a prefix for the domain, such as \"\\*example.com\". The permission defaults apply to both the exact domain \"example.com\", and any sub-domains such as \"www.example.com\". It won't match other domains with a similar string suffix such as \"myexample.com\".\n\nWhen multiple patterns match a website, Safari uses the most precise pattern. For example, for the website \"www.example.com\", if rules \"www.example.com\" and \"*example.com\" match, Safari uses the former.","helpText":null,"infoUrls":[],"categoryId":"e0ab6868-4b53-4310-b665-f7c979941db7","categoryName":"Safari Browser","options":null},"9cee781fdea3f194":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"9cb8c2815ec8a1e1":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_1","displayName":"Initial reminder balloon lifetime (User)","description":"Determines how long the first reminder balloon for a network status change is displayed.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the duration of the first reminder.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderinittimeout-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderinittimeout_1_1","displayName":"Enabled","description":null,"helpText":null}]},"9c42b93f6545f55d":{"id":"user_vendor_msft_policy_config_admx_startmenu_nogamesfolderonstartmenu","displayName":"Remove Games link from Start Menu (User)","description":"If you enable this policy the start menu will not show a link to the Games folder.\r\n\r\nIf you disable or do not configure this policy, the start menu will show a link to the Games folder, unless the user chooses to remove it in the start menu control panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nogamesfolderonstartmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nogamesfolderonstartmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nogamesfolderonstartmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"9c4e9872cbba0817":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_ts_gateway_override","displayName":"Allow users to change this setting (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"a561e59a-09b7-4106-a6fa-0b82036a5b49","categoryName":"RD Gateway","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_ts_gateway_override_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_gateway_policy_auth_method_ts_gateway_override_1","displayName":"True","description":null,"helpText":null}]},"9cbfd7a81c946815":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurlgreylist_browserswitcherurlgreylistdesc","displayName":"Websites that should never trigger a browser switch. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"9c69fd9bb161bc0a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidername_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"9c3d4feb5134337d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload","displayName":"Allows a page to show popups during its unloading (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_allowpopupsduringpageunload_1","displayName":"Enabled","description":null,"helpText":null}]},"9c15633fd9d8159d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation","displayName":"Configure the home page URL (User)","description":"Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup.\r\n\r\nIf the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect.\r\n\r\n The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome.\r\n\r\nLeaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"9cd9695671baa8e2":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled","displayName":"Use the Happy Eyeballs V3 algorithm (User)","description":"This feature enables the Happy Eyeballs V3 algorithm to make connection attempts. See https://datatracker.ietf.org/doc/draft-pauly-happy-happyeyeballs-v3 for details.\r\n\r\nSetting the policy to Enabled means Google Chrome will use the Happy Eyeballs V3 algorithm for connection attempts.\r\n\r\nSetting the policy to Disabled turns off the Happy Eyeballs V3 algorithm.\r\n\r\nNot setting the policy, Google Chrome will turn on or off the Happy Eyeballs V3 algorithm based on chrome://flags/#happy-eyeballs-v3.\r\n\r\nThis policy supports dynamic refresh.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"fa2722a8-dcfd-4e14-a429-2b0041642c77","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~network_happyeyeballsv3enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ce20d4415afc864":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled","displayName":"Control the new behavior of HTMLElement.offsetParent (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9c30e666b25fdafe":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally","displayName":"Always open PDF files externally (User)","description":"Disables the internal PDF viewer in Microsoft Edge.\r\n\r\nIf you enable this policy Microsoft Edge treats PDF files as downloads and lets users open them with the default application.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will open PDF files (unless the user disables it).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_alwaysopenpdfexternally_1","displayName":"Enabled","description":null,"helpText":null}]},"9cfeb39e58d15482":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting","displayName":"Configure cookies (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_1","displayName":"Let all sites create cookies","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_2","displayName":"Don't let any site create cookies","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultcookiessetting_defaultcookiessetting_4","displayName":"Keep cookies for the duration of the session","description":null,"helpText":null}]},"9c10fe303d5d9dde":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge~applicationguard_applicationguardcontainerproxy_applicationguardcontainerproxy","displayName":"Application Guard Container Proxy (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","categoryName":"Application Guard settings","options":null},"9c554978b4e5e536":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverinfo4","displayName":"Information URL (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"9c4fada10fee98ad":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles","displayName":"Do not upload media files (User)","description":"Disables/Enables uploading of media files.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donotuploadmediafiles_1","displayName":"Enabled","description":null,"helpText":null}]},"9c8ca48027e9bf99":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc17_l_pathcolon17","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"9c796133e855df2f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible","displayName":"Use long file names whenever possible (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_uselongfilenameswheneverpossible_1","displayName":"Enabled","description":null,"helpText":null}]},"9c42dc83e6b6803a":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption","displayName":"Disable Outlook send email to OneNote option (User)","description":"This policy disables the OneNote ''Send to OneNote'' add-in for Microsoft Outlook. By default OneNote installs an add-in on the Outlook toolbar which allows users to send emails to OneNote. The ''Send to OneNote'' button appears on the main mail module in Outlook as well as when viewing an email message. You may disable this feature with this policy.","helpText":"","infoUrls":[],"categoryId":"a87f9d6a-0c84-4cad-839f-e912c6006c12","categoryName":"Send to OneNote","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_sendtoonenote_l_disableoutlooksendemailtoonenoteoption_1","displayName":"Enabled","description":null,"helpText":null}]},"9c6bd23b453d28f6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts","displayName":"Do not allow Outlook object model scripts to run for shared folders (User) (Deprecated)","description":"This policy setting controls whether Outlook executes scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with shared folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for shared folders. \r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscripts_1","displayName":"Enabled","description":null,"helpText":null}]},"9cac66e91dae17c5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_l_endearlylongspinid","displayName":"Minutes to reduce meetings by: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},"9c734807a72db142":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert","displayName":"Do not display New Mail alert for users (User)","description":"By default, users receive an alert message on their desktops when new mail arrives. By enabling this setting, the alert is not displayed for new mail.","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_newmaildesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},"9cabc0eac35e417b":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_l_autodiscoverredirectserverslist","displayName":"HTTPS server names: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":null},"9cee2efb8332bab3":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles","displayName":"Don’t allow the use of Live Subtitles (User)","description":"\r\nThis policy setting controls whether users can turn on Live Subtitles during a presentation. By default, Live Subtitles are off but can be turned on by users.\r\n\r\nIf you enable this policy setting, users can't turn on Live Subtitles during a presentation.\r\n\r\nIf you disable or don't configure this policy setting, users can turn on Live Subtitles.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_disablelivesubtitles_1","displayName":"Enabled","description":null,"helpText":null}]},"9c197154836a360d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks","displayName":"New tasks (User)","description":"Specifies the default start date for new tasks as they are entered in the current project. For projects scheduled from the start date, the options are \"Start on Project Start Date\" and \"Start on Current Date.\" For projects scheduled from the finish date, the options are \"Finish on Project Finish Date\" and \"Start on Current Date.\"\r\n\r\nIf you enable this setting, new tasks will start on the date you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtasks_1","displayName":"Enabled","description":null,"helpText":null}]},"9c38e8f0e9edc7a2":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting","displayName":"Enable connector splitting (User)","description":"When you place a shape on the line of a connector, it splits and each piece becomes a separate connector glued to the shape. Not all drawing types support connector splitting.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enalbeconnectorsplitting_1","displayName":"Enabled","description":null,"helpText":null}]},"9c874d8cd4d721e0":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly","displayName":"Show white space between pages in Print Layout view (User)","description":"Determines whether the symbol used to represent white space between pages in Print view only is shown in the document.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_whitespacebetweenpagesprintviewonly_1","displayName":"Enabled","description":null,"helpText":null}]},"9c7c0fe396237a3c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_datecolon49","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/9e.json b/public/intune-definitions/9e.json index 2e88a414c8ee..7b54f4570ec3 100644 --- a/public/intune-definitions/9e.json +++ b/public/intune-definitions/9e.json @@ -1 +1 @@ -{"9e9c3a82031c41d6":{"id":"ade_awaitconfiguration_basic","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_awaitconfiguration_basic_0","displayName":"No","description":null,"helpText":null},{"id":"ade_awaitconfiguration_basic_1","displayName":"Yes","description":null,"helpText":null}]},"9ed29841b64d1d7f":{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction","displayName":"Domain Action (Deprecated)","description":" The DNS settings behavior for the specified domains.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction_0","displayName":"Never Connect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction_1","displayName":"Connect If Needed","description":null,"helpText":null}]},"9e6c6b696905bd4a":{"id":"com.apple.managedclient.preferences_dailyconfiguration_timeofday","displayName":"Time of day","description":"Specifies the time of day, as the number of minutes after midnight, to perform a daily quick scan.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},"9e343e3f07b10e27":{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\n\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\n\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\n\nIf the \"SpellcheckEnabled\" policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsofteditorproofingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9e7cb281cc6c88a2":{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription_generickey","displayName":"Description","description":"A localized description.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"9ece6030042010da":{"id":"com.apple.systempolicy.control_enableassessment","displayName":"Enable Assessment","description":"If true, enables Gatekeeper.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_enableassessment_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_enableassessment_true","displayName":"True","description":null,"helpText":null}]},"9e3e5d19bfcae1c4":{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"9ec8ed00290485c7":{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"9ec0f711e0f07697":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"9ef9b18aae83463c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"This policy defines certificates that Microsoft Edge doesn't explicitly trust or distrust but may be used as hints during certificate path-building.\n\nThe specified certificates are considered as intermediates during path validation; the server's certificate still chain to a trusted root to be considered valid.\n\nCertificates must be base64-encoded.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},"9ed1be22753ba0aa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app","description":"This setting lets you enable reporting of sites that need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed in to Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\n\nIf you configure this policy, Microsoft Edge sends a report to the Microsoft 365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer (IE) engines several times. This indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report shows the URL of the site that's the redirect target, minus any query string or fragment. The user's identity isn't reported.\n\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the Microsoft 365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge still attempts to send reports if this step hasn't been completed. However, the reports aren't stored in the Site Lists app.\n\nIf you enable this policy, you must specify your Office 365 tenant ID. To learn more about finding your Office 365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668.\n\nIf you disable or don't configure this policy, Microsoft Edge never sends reports about misconfigured neutral sites to the Site Lists app.\n\nTo learn more about IE mode, see https://go.microsoft.com/fwlink/?linkid=2165707.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"9e7924279fb15c34":{"id":"com.microsoft.edge.mamedgeappconfigsettings.navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List","description":"Allows you to set a timeout, in seconds, for Microsoft Edge tabs waiting to navigate until the browser has downloaded the initial Enterprise Mode Site List.\n\nThis setting works in conjunction with: \"InternetExplorerIntegrationLevel\" is set to 'IEMode' and \"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry and \"DelayNavigationsForInitialSiteListDownload\" is set to \"All eligible navigations\" (1).\n\nTabs won't wait longer than this timeout for the Enterprise Mode Site List to download. If the browser hasn't finished downloading the Enterprise Mode Site List when the timeout expires, Microsoft Edge tabs continue navigating anyway. The value of the timeout should be no greater than 20 seconds and no fewer than 1 second.\n\nIf you set the timeout in this policy to a value greater than 2 seconds, an information bar is shown to the user after 2 seconds. The information bar contains a button that allows the user to quit waiting for the Enterprise Mode Site List download to complete.\n\nIf you don't configure this policy, the default timeout of 4 seconds is used. This default is subject to change in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"9eef656bc92cd218":{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (Obsolete)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed through a cloud service.\n\nIf you disable this policy, users can receive related matches in Find on Page on a limited set of sites. In this case, results are processed locally on the user's device.\n\nNote: This policy is obsolete. The associated cloud service is discontinued, so the feature and policy aren't supported on any versions of Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9e8caaec260a3ace":{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled","displayName":"Support device authentication using certificate","description":"Support for device authentication using certificate will require connectivity to a DC in the device account domain which supports certificate authentication for computer accounts. \r\n\r\nThis policy setting allows you to set support for Kerberos to attempt authentication using the certificate for the device to the domain.\r\n\r\nIf you enable this policy setting, the device’s credentials will be selected based on the following options:\r\n\r\nAutomatic: Device will attempt to authenticate using its certificate. If the DC does not support computer account authentication using certificates then authentication with password will be attempted.\r\n\r\nForce: Device will always authenticate using its certificate. If a DC cannot be found which support computer account authentication using certificates then authentication will fail.\r\n\r\nIf you disable this policy setting, certificates will never be used.\r\nIf you do not configure this policy setting, Automatic will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-devicepkinitenabled"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e5bc809ba10b71e":{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2","displayName":"Turn Off the hard disk (plugged in)","description":"This policy setting specifies the period of inactivity before Windows turns off the hard disk.\r\n\r\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows turns off the hard disk.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-diskacpowerdowntimeout-2"],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},"9e54f5d62a560adb":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings","displayName":"Themes","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings_1","displayName":"True","description":null,"helpText":null}]},"9ef4dd627513ef03":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync","displayName":"Microsoft Lync 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Lync 2010.\r\nBy default, the user settings of Microsoft Lync 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Lync 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync_1","displayName":"Enabled","description":null,"helpText":null}]},"9e7e7420b264026f":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},"9eb88f7d75989423":{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension","displayName":"Audit Security System Extension","description":"This policy setting allows you to audit events related to security system extensions or services such as the following: A security system extension, such as an authentication, notification, or security package is loaded and is registered with the Local Security Authority (LSA). It is used to authenticate logon attempts, submit logon requests, and any account or password changes. Examples of security system extensions are Kerberos and NTLM. A service is installed and registered with the Service Control Manager. The audit log contains information about the service name, binary, type, start type, and service account. If you configure this policy setting, an audit event is generated when an attempt is made to load a security system extension. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an attempt is made to load a security system extension.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditsecuritysystemextension"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"9e4ebaa725a3969d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Do not allow any site to run JavaScript","description":null,"helpText":null}]},"9edfddc9e200c845":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs.","description":"Setting the policy lets you list the URL patterns that specify which sites are automatically granted permission to access a USB device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the policy to be valid. Each item in the devices field can have a vendor_id and product_id field. Omitting the vendor_id field will create a policy matching any device. Omitting the product_id field will create a policy matching any device with the given vendor ID. A policy which has a product_id field without a vendor_id field is invalid.\r\n\r\nThe USB permission model will grant the specified URL permission to access the USB device as a top-level origin. If embedded frames need to access USB devices, the 'usb' feature-policy header should be used to grant access. The URL must be valid, otherwise the policy is ignored.\r\n\r\nDeprecated: The USB permission model used to support specifying both the requesting and embedding URLs. This is deprecated and only supported for backwards compatiblity in this manner: if both a requesting and embedding URL is specified, then the embedding URL will be granted the permission as top-level origin and the requsting URL will be ignored entirely.\r\n\r\nThis policy overrides DefaultWebUsbGuardSetting, WebUsbAskForUrls, WebUsbBlockedForUrls and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the WebUSB API. To grant access to USB devices through the Web Serial API see the SerialAllowUsbDevicesForUrls policy.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebUsbAllowDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234,\r\n \"product_id\": 5678\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://google.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9e2cb99a14a82802":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting","displayName":"Default mediastream setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting_2","displayName":"Do not allow any site to access the camera and microphone","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting_3","displayName":"Ask every time a site wants to access the camera and/or microphone","description":null,"helpText":null}]},"9ef06302a505be91":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting","displayName":"Control use of the File Handling API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"9e801abbd765f9fb":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended","displayName":"Enable Battery Saver Mode","description":"This policy enables or disables the Battery Saver Mode setting.\r\nOn Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance.\r\nOn ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off.\r\nThe different levels are:\r\nDisabled (0): Battery Saver Mode will be disabled.\r\nEnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low.\r\nEnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9e141311e73aaccf":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"9e01623cbe6cb1db":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowlocalsystemnullsessionfallback","displayName":"Network Security Allow Local System NULL Session Fallback","description":"Network security: Allow LocalSystem NULL session fallback Allow NTLM to fall back to NULL session when used with LocalSystem. The default is TRUE up to Windows Vista and FALSE in Windows 7.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_allowlocalsystemnullsessionfallback"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"9e51a39d409947bb":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended","displayName":"Set application locale","description":"Configures the application locale in Microsoft Edge and prevents users from changing the locale.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified locale. If the configured locale isn't supported, 'en-US' is used instead.\r\n\r\nIf you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'.\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9eae4aac3522b8ff":{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled","displayName":"Configure if the ads transparency feature is enabled","description":"Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the \"balanced\" mode of tracking prevention, and does not impact \"basic\" or \"strict\" modes. Your users' tracking prevention level can be configured using the 'TrackingPrevention' (Block tracking of users' web-browsing activity) policy. AdsTransparencyEnabled will only have an effect if 'TrackingPrevention' is set to TrackingPreventionBalanced or is not configured.\r\n\r\nIf you enable or don't configure this policy, transparency metadata provided by ads will be available to the user when the feature is active.\r\n\r\nWhen the feature is enabled, Tracking Prevention will enable exceptions for the associated ad providers that have met Microsoft's privacy standards.\r\n\r\nIf you disable this policy, Tracking Prevention will not adjust its behavior even when transparency metadata is provided by ads.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ea8951d083df9ad":{"id":"device_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled","displayName":"Enable Microsoft Bing trending suggestions in the address bar","description":"This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users click the address bar while on a New Tab Page.\r\n\r\nIf this policy is enabled or not configured, Microsoft Bing trending suggestions will appear in the address bar suggestion dropdown.\r\n\r\nIf this policy is disabled, Microsoft Edge will not display Microsoft Bing trending suggestions when users click the address bar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e97374c1e1eb8c9":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_maxconnectionsperproxyforwebsocket","displayName":"Maximum number of concurrent connections to the proxy server for WebSocket requests: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9e80b9060535c35b":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled","displayName":"Enable security warnings for command-line flags","description":"If disabled, this policy prevents security warnings from appearing when Microsoft Edge is launched with potentially dangerous command-line flags.\r\n\r\nIf enabled or unset, security warnings are displayed when these command-line flags are used to launch Microsoft Edge.\r\n\r\nFor example, the --disable-gpu-sandbox flag generates this warning: You're using an unsupported command-line flag: --disable-gpu-sandbox. This poses stability and security risks.\r\n\r\nOn Windows, this policy is only available on instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro (or Enterprise) instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e602199d9f013e5":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods","description":"Allows you to set whether websites can check if the user has payment methods saved.\r\n\r\nIf you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\r\n\r\nIf you enable this policy or don't set this policy, websites can check if the user has payment methods saved.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ea1fe7cc3551a4a":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled","displayName":"Allow users to get a strong password suggestion whenever they are creating an account online","description":"Configures the Password Generator Settings toggle that enables/disables the feature for users.\r\n\r\nIf you enable or don't configure this policy, then Password Generator will offer users a strong and unique password suggestion (via a dropdown) on Signup and Change Password pages.\r\n\r\nIf you disable this policy, users will no longer see strong password suggestions on Signup or Change Password pages.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e89f2f96b54509e":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_winprojexe76","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_winprojexe76_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_winprojexe76_1","displayName":"True","description":null,"helpText":null}]},"9e3e42fa4c0049c5":{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_trustedforest_chk","displayName":"Users can only point and print to machines in their forest","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_trustedforest_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_trustedforest_chk_1","displayName":"True","description":null,"helpText":null}]},"9e11f293b7aa9497":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesslocation","displayName":"Let Apps Access Location","description":"This policy setting specifies whether Windows apps can access location.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesslocation"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccesslocation_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesslocation_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesslocation_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"9ebc61b6770def99":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstasks_userincontroloftheseapps","displayName":"Let Apps Access Tasks User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the tasks privacy setting for the listed apps. This setting overrides the default LetAppsAccessTasks policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstasks_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"9e88b6a541a56d7f":{"id":"device_vendor_msft_policy_config_search_allowsearchhighlights","displayName":"Allow Search Highlights","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Search#allowsearchhighlights"],"categoryId":"794337be-8833-4b9a-bb88-8a030141578d","categoryName":"Search","options":null},"9ef8ad65cef33343":{"id":"device_vendor_msft_policy_config_update_scheduledinstallsecondweek","displayName":"Scheduled Install Second Week","description":"Enables the IT admin to schedule the update installation on the second week of the month. Value type is integer. Supported values:0 - no update in the schedule1 - update is scheduled every second week of the month","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduledinstallsecondweek"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_scheduledinstallsecondweek_0","displayName":"no update in the schedule","description":"no update in the schedule","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduledinstallsecondweek_1","displayName":"update is scheduled every second week of the month","description":"update is scheduled every second week of the month","helpText":null}]},"9e7ddf75a212a2e6":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_meteredupdatesmicrosoftedge_part_meteredupdatespolicy","displayName":"Metered Updates Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_meteredupdatesmicrosoftedge_part_meteredupdatespolicy_1","displayName":"Metered Disable updates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_meteredupdatesmicrosoftedge_part_meteredupdatespolicy_2","displayName":"Metered Updates Allowed","description":null,"helpText":null}]},"9e7fa73205765cf0":{"id":"linux_mdatp_managed_cloudservice_automaticdefinitionupdateenabled","displayName":"Automatic security intelligence updates","description":"Determines whether security intelligence updates are installed automatically:","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#enable--disable-automatic-security-intelligence-updates"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"linux_mdatp_managed_cloudservice_automaticdefinitionupdateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_cloudservice_automaticdefinitionupdateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9e521b55cdbafac4":{"id":"softwareupdate_deferrals","displayName":"Deferrals","description":"Controls the deferral of software updates. Rapid Security Responses are not considered within 'Major', 'Minor', or 'System' deferral mechanism. Only applicable on Supervised devices with iOS 18+ and MacOS 15++","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":null},"9e7dac0de88041ba":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_2007compatiblecachepolicy","displayName":"Use Access 2007 compatible cache (User)","description":"This policy setting allows you to force new and existing databases to use a cache compatible Access 2007.\r\n\r\nIf you enable this policy setting, new and existing databases will use caching compatible with Access 2007.\r\n\r\nIf you disable or do not configure this policy setting, new databases will default to use caching that is not compatible with Access 2007. Existing databases will use the caching mode that they were created with.\r\n","helpText":"","infoUrls":[],"categoryId":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_2007compatiblecachepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_2007compatiblecachepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"9e1e170518d0078f":{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffcustomdictionary","displayName":"Turn off custom dictionary (User)","description":"This policy setting allows you to turn off the ability to use a custom dictionary.\r\n\r\nIf you enable this policy setting, you cannot add, edit, and delete words in the custom dictionary either with GUI tools or APIs. A word registered in the custom dictionary before enabling this policy setting can continue to be used for conversion.\r\n\r\nIf you disable or do not configure this policy setting, the custom dictionary can be used by default.\r\n\r\nFor Japanese Microsoft IME, [Clear auto-tuning information] works, even if this policy setting is enabled, and it clears self-tuned words from the custom dictionary.\r\n\r\nThis policy setting is applied to Japanese Microsoft IME.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eaime#admx-eaime-l-turnoffcustomdictionary"],"categoryId":"7d331987-7e2d-4975-b23b-d99a5af26ddf","categoryName":"IME","options":[{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffcustomdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffcustomdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},"9e0e981dd03d99b6":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmypictures","displayName":"Remove Pictures icon from Start Menu (User)","description":"This policy setting allows you to remove the Pictures icon from Start Menu.\r\n\r\nIf you enable this policy setting, the Pictures icon is no longer available from Start Menu.\r\n\r\nIf you disable or do not configure this policy setting, the Pictures icon is available from Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosmmypictures"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmypictures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmypictures_1","displayName":"Enabled","description":null,"helpText":null}]},"9ec7c1337227d988":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedopensearch_opensearchlabel1","displayName":"Site Name 2 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"9e3907d40b84b1c1":{"id":"user_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior","displayName":"Set the default behavior for AutoRun (User)","description":"This policy setting sets the default behavior for Autorun commands.\n\n Autorun commands are generally stored in autorun.inf files. They often launch the installation program or other routines.\n\n Prior to Windows Vista, when media containing an autorun command is inserted, the system will automatically execute the program without user intervention.\n\n This creates a major security concern as code may be executed without user's knowledge. The default behavior starting with Windows Vista is to prompt the user whether autorun command is to be run. The autorun command is represented as a handler in the Autoplay dialog.\n\n If you enable this policy setting, an Administrator can change the default Windows Vista or later behavior for autorun to:\n\n a) Completely disable autorun commands, or\n b) Revert back to pre-Windows Vista behavior of automatically executing the autorun command.\n\n If you disable or not configure this policy setting, Windows Vista or later will prompt the user whether autorun command is to be run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-setdefaultautorunbehavior"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"user_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"9ec89a7f2b6d15d5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled","displayName":"Enable the default search provider (User)","description":"Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ef048898f02dbc7":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowaccesstodatasources"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"9e5565203cfa8374":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload","displayName":"Enable Domain Actions Download from Microsoft (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nAlthough this policy is used to enable/disable download of the domain actions list, it doesn't always achieve the desired state. The Experimentation and Configuration Service, which handles the download, has its own group policy to configure what is downloaded from the service. To avoid conflicting states, this policy is being deprecated and will be obsolete in milestone 85 onward. Please use the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy instead.\r\n\r\nIn Microsoft Edge, Domain Actions represent a series of compatibility features that help the browser work correctly on the web.\r\n\r\nMicrosoft keeps a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nWhen the browser starts up and then periodically afterwards, the browser will contact the Experimentation and Configuration Service that contains the most up to date list of compatibility actions to perform. This list is saved locally after it is first retrieved so that subsequent requests will only update the list if the server's copy has changed.\r\n\r\nIf you enable this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.\r\n\r\nIf you disable this policy, the list of Domain Actions will no longer be downloaded from the Experimentation and Configuration Service.\r\n\r\nIf you don't configure this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload_1","displayName":"Enabled","description":null,"helpText":null}]},"9ee17e37ab82a9cf":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification_1","displayName":"Recommended - Show a recurring prompt to the user indicating that a restart is recommended","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification_2","displayName":"Required - Show a recurring prompt to the user indicating that a restart is required","description":null,"helpText":null}]},"9ed88cc499136687":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content (User)","description":"If you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings -- either by the user or by enterprise policy -- will run. This includes content from other origins and/or small content.\r\n\r\nTo control which websites are allowed to run Adobe Flash, see the specifications in the 'DefaultPluginsSetting' (Default Adobe Flash setting), 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites), and 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) policies.\r\n\r\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (from sites that aren't specified in the three policies mentioned immediately above) or small content might be blocked.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode_1","displayName":"Enabled","description":null,"helpText":null}]},"9ed0e35ee071cf05":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup","displayName":"Action to take on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"9ee06353e878cbac":{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9ea5a683851b1b20":{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled","displayName":"Enable efficiency mode when the device is connected to a power source (User)","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\r\n\r\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\r\n\r\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ed3d3c4eacb5fc6":{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled","displayName":"Compose is enabled for writing on the web (User)","description":"This policy lets you configure Compose in Microsoft Edge. Compose provides help for writing with AI-generated text, which lets the user get ideas for writing. This includes elaborating on text, re-writing, changing tone, formatting the text, and more.\r\n\r\nIf you enable or don't configure this policy, Compose can provide text generation for eligible fields, which are text editable and don't have an autocomplete attribute.\r\n\r\nIf you disable this policy, Compose will not be able to provide text generation for eligible fields. Compose will still be available for prompt-based text generation through the sidebar and must be managed with either 'EdgeDiscoverEnabled' (Discover feature In Microsoft Edge) policy or 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e52548228005da7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors","displayName":"Stop reporting non-critical errors (User)","description":"This policy setting controls whether the application reports non-critical errors.\r\n\r\nIf you enable this policy, non-critical errors will not be reported.\r\n\r\nIf you disable or do not configure this policy setting, non-critical errors will be reported.","helpText":"","infoUrls":[],"categoryId":"33fb4f49-5c7f-472c-a0f3-e05646a55902","categoryName":"Improved Error Reporting","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors_1","displayName":"Enabled","description":null,"helpText":null}]},"9ec5fdeb124c939e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12","displayName":"Escrow Key #12 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_1","displayName":"Enabled","description":null,"helpText":null}]},"9e65fefc5e161362":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_pathcolon10","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"9e68c987afce333b":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},"9e498fed12bf2b13":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault","displayName":"Prompt the user if PowerPoint is not the default application for its file extensions (User)","description":"This policy setting specifies whether PowerPoint prompts users to change their file extension associations for any file types that are no longer associated with PowerPoint.\r\n\r\nIf you enable this policy setting, when users start PowerPoint, they are not prompted to change file extensions for any files that are no longer associated with PowerPoint. In addition, the checkbox on the user interface (UI) under File |Options | General | Start up options | Tell me is unchecked.\r\n\r\nIf you disable or do not configure this policy setting, when users start PowerPoint, they are prompted to change file extensions for any files that are no longer associated with PowerPoint. Users can change this behavior either by selecting the checkbox displayed in the prompt, or by selecting the UI checkbox under File |Options | General | Start up options | Tell me (which is selected by default).\r\n","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault_1","displayName":"Enabled","description":null,"helpText":null}]},"9e53e9c56392b966":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"9eca6bbc79433185":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"9ea2cbacad6e9429":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},"9e659283095785ae":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles","displayName":"Copy remotely stored files onto your computer, and update the remote file when saving (User)","description":"This policy setting allows you to set the \"Copy remotely stored files onto your computer, and update the remote file when saving\" option in Word Options | Advanced | Save.\r\n\r\nIf you enable this policy setting, \"Copy remotely stored files onto your computer, and update the remote file when saving\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Copy remotely stored files onto your computer, and update the remote file when saving\" will not be set.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"9eba5916210b1fca":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar","displayName":"Show vertical scroll bar (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},"9efbc7fa5036b901":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools_l_tools14","displayName":"Tools (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},"9e789b772d3ee190":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading","displayName":"Open e-mail attachments in Reading View (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"9e9c3a82031c41d6":{"id":"ade_awaitconfiguration_basic","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_awaitconfiguration_basic_0","displayName":"No","description":null,"helpText":null},{"id":"ade_awaitconfiguration_basic_1","displayName":"Yes","description":null,"helpText":null}]},"9ed29841b64d1d7f":{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction","displayName":"Domain Action (Deprecated)","description":" The DNS settings behavior for the specified domains.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction_0","displayName":"Never Connect","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_actionparameters_domainaction_1","displayName":"Connect If Needed","description":null,"helpText":null}]},"9e6c6b696905bd4a":{"id":"com.apple.managedclient.preferences_dailyconfiguration_timeofday","displayName":"Time of day","description":"Specifies the time of day, as the number of minutes after midnight, to perform a daily quick scan.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},"9e343e3f07b10e27":{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\n\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\n\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\n\nIf the \"SpellcheckEnabled\" policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#microsofteditorproofingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_microsofteditorproofingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9e7cb281cc6c88a2":{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription_generickey","displayName":"Description","description":"A localized description.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"9ece6030042010da":{"id":"com.apple.systempolicy.control_enableassessment","displayName":"Enable Assessment","description":"If true, enables Gatekeeper.","helpText":null,"infoUrls":[],"categoryId":"763525a0-8456-4336-a8d1-392253e8fdd8","categoryName":"System Policy Control","options":[{"id":"com.apple.systempolicy.control_enableassessment_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systempolicy.control_enableassessment_true","displayName":"True","description":null,"helpText":null}]},"9e3e5d19bfcae1c4":{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_coderequirement","displayName":"Code Requirement","description":"Obtained via the command \"codesign –display -r -\".","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"9ec8ed00290485c7":{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_postevent_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"9ec0f711e0f07697":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyallfiles_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"9ef9b18aae83463c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.cahintcertificates","displayName":"TLS certificates that are not trusted or distrusted but can be used in path-building for server authentication","description":"This policy defines certificates that Microsoft Edge doesn't explicitly trust or distrust but may be used as hints during certificate path-building.\n\nThe specified certificates are considered as intermediates during path validation; the server's certificate still chain to a trusted root to be considered valid.\n\nCertificates must be base64-encoded.","helpText":null,"infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},"9ed1be22753ba0aa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app","description":"This setting lets you enable reporting of sites that need to be configured as a neutral site on the Enterprise Mode Site List. The user must be signed in to Microsoft Edge with a valid work or school account for reports to be sent, and the user's account tenant must match the tenant specified by the policy.\n\nIf you configure this policy, Microsoft Edge sends a report to the Microsoft 365 Admin Center Site Lists app when a navigation appears stuck redirecting back and forth between the Microsoft Edge and Internet Explorer (IE) engines several times. This indicates that redirection to an authentication server is switching engines, which repeatedly fails in a loop. The report shows the URL of the site that's the redirect target, minus any query string or fragment. The user's identity isn't reported.\n\nFor this reporting to work correctly, you must have successfully visited the Microsoft Edge Site Lists app in the Microsoft 365 Admin Center at least once. This activates a per-tenant storage account used to store these reports. Microsoft Edge still attempts to send reports if this step hasn't been completed. However, the reports aren't stored in the Site Lists app.\n\nIf you enable this policy, you must specify your Office 365 tenant ID. To learn more about finding your Office 365 tenant ID, see https://go.microsoft.com/fwlink/?linkid=2185668.\n\nIf you disable or don't configure this policy, Microsoft Edge never sends reports about misconfigured neutral sites to the Site Lists app.\n\nTo learn more about IE mode, see https://go.microsoft.com/fwlink/?linkid=2165707.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"9e7924279fb15c34":{"id":"com.microsoft.edge.mamedgeappconfigsettings.navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List","description":"Allows you to set a timeout, in seconds, for Microsoft Edge tabs waiting to navigate until the browser has downloaded the initial Enterprise Mode Site List.\n\nThis setting works in conjunction with: \"InternetExplorerIntegrationLevel\" is set to 'IEMode' and \"InternetExplorerIntegrationSiteList\" policy where the list has at least one entry and \"DelayNavigationsForInitialSiteListDownload\" is set to \"All eligible navigations\" (1).\n\nTabs won't wait longer than this timeout for the Enterprise Mode Site List to download. If the browser hasn't finished downloading the Enterprise Mode Site List when the timeout expires, Microsoft Edge tabs continue navigating anyway. The value of the timeout should be no greater than 20 seconds and no fewer than 1 second.\n\nIf you set the timeout in this policy to a value greater than 2 seconds, an information bar is shown to the user after 2 seconds. The information bar contains a button that allows the user to quit waiting for the Enterprise Mode Site List download to complete.\n\nIf you don't configure this policy, the default timeout of 4 seconds is used. This default is subject to change in the future.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"9eef656bc92cd218":{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled","displayName":"Configure Related Matches in Find on Page (Obsolete)","description":"Specifies how the user receives related matches in Find on Page, which provides spellcheck, synonyms, and Q&A results in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can receive related matches in Find on Page on all sites. The results are processed through a cloud service.\n\nIf you disable this policy, users can receive related matches in Find on Page on a limited set of sites. In this case, results are processed locally on the user's device.\n\nNote: This policy is obsolete. The associated cloud service is discontinued, so the feature and policy aren't supported on any versions of Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.relatedmatchescloudserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9e9e73327783bc95":{"id":"contentcaching_peerlistenranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"9e8caaec260a3ace":{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled","displayName":"Support device authentication using certificate","description":"Support for device authentication using certificate will require connectivity to a DC in the device account domain which supports certificate authentication for computer accounts. \r\n\r\nThis policy setting allows you to set support for Kerberos to attempt authentication using the certificate for the device to the domain.\r\n\r\nIf you enable this policy setting, the device’s credentials will be selected based on the following options:\r\n\r\nAutomatic: Device will attempt to authenticate using its certificate. If the DC does not support computer account authentication using certificates then authentication with password will be attempted.\r\n\r\nForce: Device will always authenticate using its certificate. If a DC cannot be found which support computer account authentication using certificates then authentication will fail.\r\n\r\nIf you disable this policy setting, certificates will never be used.\r\nIf you do not configure this policy setting, Automatic will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-devicepkinitenabled"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_devicepkinitenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e5bc809ba10b71e":{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2","displayName":"Turn Off the hard disk (plugged in)","description":"This policy setting specifies the period of inactivity before Windows turns off the hard disk.\r\n\r\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows turns off the hard disk.\r\n\r\nIf you disable or do not configure this policy setting, users can see and change this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-diskacpowerdowntimeout-2"],"categoryId":"91c02e14-8848-485d-8844-b9933fa888ec","categoryName":"Hard Disk Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_diskacpowerdowntimeout_2_1","displayName":"Enabled","description":null,"helpText":null}]},"9e54f5d62a560adb":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings","displayName":"Themes","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_themesettings_1","displayName":"True","description":null,"helpText":null}]},"9ef4dd627513ef03":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync","displayName":"Microsoft Lync 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Lync 2010.\r\nBy default, the user settings of Microsoft Lync 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Lync 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010lync_1","displayName":"Enabled","description":null,"helpText":null}]},"9e7e7420b264026f":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver1_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},"9eb88f7d75989423":{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension","displayName":"Audit Security System Extension","description":"This policy setting allows you to audit events related to security system extensions or services such as the following: A security system extension, such as an authentication, notification, or security package is loaded and is registered with the Local Security Authority (LSA). It is used to authenticate logon attempts, submit logon requests, and any account or password changes. Examples of security system extensions are Kerberos and NTLM. A service is installed and registered with the Service Control Manager. The audit log contains information about the service name, binary, type, start type, and service account. If you configure this policy setting, an audit event is generated when an attempt is made to load a security system extension. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when an attempt is made to load a security system extension.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditsecuritysystemextension"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditsecuritysystemextension_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"9e4ebaa725a3969d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting","displayName":"Default JavaScript setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_1","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptsetting_defaultjavascriptsetting_2","displayName":"Do not allow any site to run JavaScript","description":null,"helpText":null}]},"9edfddc9e200c845":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls","displayName":"Automatically grant permission to these sites to connect to USB devices with the given vendor and product IDs.","description":"Setting the policy lets you list the URL patterns that specify which sites are automatically granted permission to access a USB device with the given vendor and product IDs. Each item in the list requires both devices and urls fields for the policy to be valid. Each item in the devices field can have a vendor_id and product_id field. Omitting the vendor_id field will create a policy matching any device. Omitting the product_id field will create a policy matching any device with the given vendor ID. A policy which has a product_id field without a vendor_id field is invalid.\r\n\r\nThe USB permission model will grant the specified URL permission to access the USB device as a top-level origin. If embedded frames need to access USB devices, the 'usb' feature-policy header should be used to grant access. The URL must be valid, otherwise the policy is ignored.\r\n\r\nDeprecated: The USB permission model used to support specifying both the requesting and embedding URLs. This is deprecated and only supported for backwards compatiblity in this manner: if both a requesting and embedding URL is specified, then the embedding URL will be granted the permission as top-level origin and the requsting URL will be ignored entirely.\r\n\r\nThis policy overrides DefaultWebUsbGuardSetting, WebUsbAskForUrls, WebUsbBlockedForUrls and the user's preferences.\r\n\r\nThis policy only affects access to USB devices through the WebUSB API. To grant access to USB devices through the Web Serial API see the SerialAllowUsbDevicesForUrls policy.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebUsbAllowDevicesForUrls for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234,\r\n \"product_id\": 5678\r\n }\r\n ],\r\n \"urls\": [\r\n \"https://google.com\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusballowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"9e2cb99a14a82802":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting","displayName":"Default mediastream setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting_2","displayName":"Do not allow any site to access the camera and microphone","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_defaultmediastreamsetting_defaultmediastreamsetting_3","displayName":"Ask every time a site wants to access the camera and/or microphone","description":null,"helpText":null}]},"9ef06302a505be91":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting","displayName":"Control use of the File Handling API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultfilehandlingguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"9e801abbd765f9fb":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended","displayName":"Enable Battery Saver Mode","description":"This policy enables or disables the Battery Saver Mode setting.\r\nOn Chrome, this setting makes it so that frame rate is throttled to lower power consumption. If this policy is unset, the end user can control this setting in chrome://settings/performance.\r\nOn ChromeOS, this setting makes it so that frame rate and CPU frequency are throttled, backlights are dimmed, and Android is put in Battery Saver Mode. On devices with multiple CPUs, some CPUs will be turned off.\r\nThe different levels are:\r\nDisabled (0): Battery Saver Mode will be disabled.\r\nEnabledBelowThreshold (1): Battery Saver Mode will be enabled when the device is on battery power and battery level is low.\r\nEnabledOnBattery (2): This value is deprecated as of M121. From M121 onwards, values will be treated as EnabledBelowThreshold.\r\n","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9e141311e73aaccf":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"9e01623cbe6cb1db":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networksecurity_allowlocalsystemnullsessionfallback","displayName":"Network Security Allow Local System NULL Session Fallback","description":"Network security: Allow LocalSystem NULL session fallback Allow NTLM to fall back to NULL session when used with LocalSystem. The default is TRUE up to Windows Vista and FALSE in Windows 7.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networksecurity_allowlocalsystemnullsessionfallback"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"9e51a39d409947bb":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended","displayName":"Set application locale","description":"Configures the application locale in Microsoft Edge and prevents users from changing the locale.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified locale. If the configured locale isn't supported, 'en-US' is used instead.\r\n\r\nIf you disable or don't configure this setting, Microsoft Edge uses either the user-specified preferred locale (if configured) or the fallback locale 'en-US'.\r\n\r\nExample value: en","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_applicationlocalevalue_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"9eae4aac3522b8ff":{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled","displayName":"Configure if the ads transparency feature is enabled","description":"Lets you decide whether the ads transparency feature is enabled. This behavior only applies to the \"balanced\" mode of tracking prevention, and does not impact \"basic\" or \"strict\" modes. Your users' tracking prevention level can be configured using the 'TrackingPrevention' (Block tracking of users' web-browsing activity) policy. AdsTransparencyEnabled will only have an effect if 'TrackingPrevention' is set to TrackingPreventionBalanced or is not configured.\r\n\r\nIf you enable or don't configure this policy, transparency metadata provided by ads will be available to the user when the feature is active.\r\n\r\nWhen the feature is enabled, Tracking Prevention will enable exceptions for the associated ad providers that have met Microsoft's privacy standards.\r\n\r\nIf you disable this policy, Tracking Prevention will not adjust its behavior even when transparency metadata is provided by ads.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev100~policy~microsoft_edge_adstransparencyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ea8951d083df9ad":{"id":"device_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled","displayName":"Enable Microsoft Bing trending suggestions in the address bar","description":"This policy controls whether Microsoft Bing trending suggestions appear in the address bar’s suggestion dropdown when users click the address bar while on a New Tab Page.\r\n\r\nIf this policy is enabled or not configured, Microsoft Bing trending suggestions will appear in the address bar suggestion dropdown.\r\n\r\nIf this policy is disabled, Microsoft Edge will not display Microsoft Bing trending suggestions when users click the address bar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev135~policy~microsoft_edge_addressbartrendingsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e97374c1e1eb8c9":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_maxconnectionsperproxyforwebsocket_maxconnectionsperproxyforwebsocket","displayName":"Maximum number of concurrent connections to the proxy server for WebSocket requests: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9e80b9060535c35b":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled","displayName":"Enable security warnings for command-line flags","description":"If disabled, this policy prevents security warnings from appearing when Microsoft Edge is launched with potentially dangerous command-line flags.\r\n\r\nIf enabled or unset, security warnings are displayed when these command-line flags are used to launch Microsoft Edge.\r\n\r\nFor example, the --disable-gpu-sandbox flag generates this warning: You're using an unsupported command-line flag: --disable-gpu-sandbox. This poses stability and security risks.\r\n\r\nOn Windows, this policy is only available on instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro (or Enterprise) instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_commandlineflagsecuritywarningsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e602199d9f013e5":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled","displayName":"Allow websites to query for available payment methods","description":"Allows you to set whether websites can check if the user has payment methods saved.\r\n\r\nIf you disable this policy, websites that use PaymentRequest.canMakePayment or PaymentRequest.hasEnrolledInstrument API will be informed that no payment methods are available.\r\n\r\nIf you enable this policy or don't set this policy, websites can check if the user has payment methods saved.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_paymentmethodqueryenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ea1fe7cc3551a4a":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled","displayName":"Allow users to get a strong password suggestion whenever they are creating an account online","description":"Configures the Password Generator Settings toggle that enables/disables the feature for users.\r\n\r\nIf you enable or don't configure this policy, then Password Generator will offer users a strong and unique password suggestion (via a dropdown) on Signup and Change Password pages.\r\n\r\nIf you disable this policy, users will no longer see strong password suggestions on Signup or Change Password pages.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~passwordmanager_passwordgeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e89f2f96b54509e":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_winprojexe76","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_winprojexe76_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_winprojexe76_1","displayName":"True","description":null,"helpText":null}]},"9e3e42fa4c0049c5":{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_trustedforest_chk","displayName":"Users can only point and print to machines in their forest","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_trustedforest_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_trustedforest_chk_1","displayName":"True","description":null,"helpText":null}]},"9e11f293b7aa9497":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesslocation","displayName":"Let Apps Access Location","description":"This policy setting specifies whether Windows apps can access location.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesslocation"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccesslocation_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesslocation_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesslocation_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"9ebc61b6770def99":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstasks_userincontroloftheseapps","displayName":"Let Apps Access Tasks User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the tasks privacy setting for the listed apps. This setting overrides the default LetAppsAccessTasks policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstasks_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"9e88b6a541a56d7f":{"id":"device_vendor_msft_policy_config_search_allowsearchhighlights","displayName":"Allow Search Highlights","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Search#allowsearchhighlights"],"categoryId":"794337be-8833-4b9a-bb88-8a030141578d","categoryName":"Search","options":null},"9ef8ad65cef33343":{"id":"device_vendor_msft_policy_config_update_scheduledinstallsecondweek","displayName":"Scheduled Install Second Week","description":"Enables the IT admin to schedule the update installation on the second week of the month. Value type is integer. Supported values:0 - no update in the schedule1 - update is scheduled every second week of the month","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduledinstallsecondweek"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_scheduledinstallsecondweek_0","displayName":"no update in the schedule","description":"no update in the schedule","helpText":null},{"id":"device_vendor_msft_policy_config_update_scheduledinstallsecondweek_1","displayName":"update is scheduled every second week of the month","description":"update is scheduled every second week of the month","helpText":null}]},"9e7ddf75a212a2e6":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_meteredupdatesmicrosoftedge_part_meteredupdatespolicy","displayName":"Metered Updates Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_meteredupdatesmicrosoftedge_part_meteredupdatespolicy_1","displayName":"Metered Disable updates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_meteredupdatesmicrosoftedge_part_meteredupdatespolicy_2","displayName":"Metered Updates Allowed","description":null,"helpText":null}]},"9e7fa73205765cf0":{"id":"linux_mdatp_managed_cloudservice_automaticdefinitionupdateenabled","displayName":"Automatic security intelligence updates","description":"Determines whether security intelligence updates are installed automatically:","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#enable--disable-automatic-security-intelligence-updates"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"linux_mdatp_managed_cloudservice_automaticdefinitionupdateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_cloudservice_automaticdefinitionupdateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"9e521b55cdbafac4":{"id":"softwareupdate_deferrals","displayName":"Deferrals","description":"Controls the deferral of software updates. Rapid Security Responses are not considered within 'Major', 'Minor', or 'System' deferral mechanism. Only applicable on Supervised devices with iOS 18+ and MacOS 15++","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":null},"9e7dac0de88041ba":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_2007compatiblecachepolicy","displayName":"Use Access 2007 compatible cache (User)","description":"This policy setting allows you to force new and existing databases to use a cache compatible Access 2007.\r\n\r\nIf you enable this policy setting, new and existing databases will use caching compatible with Access 2007.\r\n\r\nIf you disable or do not configure this policy setting, new databases will default to use caching that is not compatible with Access 2007. Existing databases will use the caching mode that they were created with.\r\n","helpText":"","infoUrls":[],"categoryId":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_2007compatiblecachepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_2007compatiblecachepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"9e1e170518d0078f":{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffcustomdictionary","displayName":"Turn off custom dictionary (User)","description":"This policy setting allows you to turn off the ability to use a custom dictionary.\r\n\r\nIf you enable this policy setting, you cannot add, edit, and delete words in the custom dictionary either with GUI tools or APIs. A word registered in the custom dictionary before enabling this policy setting can continue to be used for conversion.\r\n\r\nIf you disable or do not configure this policy setting, the custom dictionary can be used by default.\r\n\r\nFor Japanese Microsoft IME, [Clear auto-tuning information] works, even if this policy setting is enabled, and it clears self-tuned words from the custom dictionary.\r\n\r\nThis policy setting is applied to Japanese Microsoft IME.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eaime#admx-eaime-l-turnoffcustomdictionary"],"categoryId":"7d331987-7e2d-4975-b23b-d99a5af26ddf","categoryName":"IME","options":[{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffcustomdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoffcustomdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},"9e0e981dd03d99b6":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmypictures","displayName":"Remove Pictures icon from Start Menu (User)","description":"This policy setting allows you to remove the Pictures icon from Start Menu.\r\n\r\nIf you enable this policy setting, the Pictures icon is no longer available from Start Menu.\r\n\r\nIf you disable or do not configure this policy setting, the Pictures icon is available from Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosmmypictures"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmypictures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmypictures_1","displayName":"Enabled","description":null,"helpText":null}]},"9ec7c1337227d988":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedopensearch_opensearchlabel1","displayName":"Site Name 2 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"9e3907d40b84b1c1":{"id":"user_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior","displayName":"Set the default behavior for AutoRun (User)","description":"This policy setting sets the default behavior for Autorun commands.\n\n Autorun commands are generally stored in autorun.inf files. They often launch the installation program or other routines.\n\n Prior to Windows Vista, when media containing an autorun command is inserted, the system will automatically execute the program without user intervention.\n\n This creates a major security concern as code may be executed without user's knowledge. The default behavior starting with Windows Vista is to prompt the user whether autorun command is to be run. The autorun command is represented as a handler in the Autoplay dialog.\n\n If you enable this policy setting, an Administrator can change the default Windows Vista or later behavior for autorun to:\n\n a) Completely disable autorun commands, or\n b) Revert back to pre-Windows Vista behavior of automatically executing the autorun command.\n\n If you disable or not configure this policy setting, Windows Vista or later will prompt the user whether autorun command is to be run.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-setdefaultautorunbehavior"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"user_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_autoplay_setdefaultautorunbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"9ec89a7f2b6d15d5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled","displayName":"Enable the default search provider (User)","description":"Setting the policy to Enabled means a default search is performed when a user enters non-URL text in the address bar. To specify the default search provider, set the rest of the default search policies. If you leave those policies empty, the user can choose the default provider. Setting the policy to Disabled means there's no search when the user enters non-URL text in the address bar.\r\n\r\nIf you set the policy, users can't change it in Google Chrome. If not set, the default search provider is on, and users can set the search provider list.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ef048898f02dbc7":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneallowaccesstodatasources"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"9e5565203cfa8374":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload","displayName":"Enable Domain Actions Download from Microsoft (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nAlthough this policy is used to enable/disable download of the domain actions list, it doesn't always achieve the desired state. The Experimentation and Configuration Service, which handles the download, has its own group policy to configure what is downloaded from the service. To avoid conflicting states, this policy is being deprecated and will be obsolete in milestone 85 onward. Please use the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy instead.\r\n\r\nIn Microsoft Edge, Domain Actions represent a series of compatibility features that help the browser work correctly on the web.\r\n\r\nMicrosoft keeps a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nWhen the browser starts up and then periodically afterwards, the browser will contact the Experimentation and Configuration Service that contains the most up to date list of compatibility actions to perform. This list is saved locally after it is first retrieved so that subsequent requests will only update the list if the server's copy has changed.\r\n\r\nIf you enable this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.\r\n\r\nIf you disable this policy, the list of Domain Actions will no longer be downloaded from the Experimentation and Configuration Service.\r\n\r\nIf you don't configure this policy, the list of Domain Actions will continue to be downloaded from the Experimentation and Configuration Service.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_enabledomainactionsdownload_1","displayName":"Enabled","description":null,"helpText":null}]},"9ee17e37ab82a9cf":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification","displayName":"Notify a user that a browser restart is recommended or required for pending updates (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification_1","displayName":"Recommended - Show a recurring prompt to the user indicating that a restart is recommended","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_relaunchnotification_relaunchnotification_2","displayName":"Required - Show a recurring prompt to the user indicating that a restart is required","description":null,"helpText":null}]},"9ed88cc499136687":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode","displayName":"Extend Adobe Flash content setting to all content (User)","description":"If you enable this policy, all Adobe Flash content embedded in websites that are set to allow Adobe Flash in the content settings -- either by the user or by enterprise policy -- will run. This includes content from other origins and/or small content.\r\n\r\nTo control which websites are allowed to run Adobe Flash, see the specifications in the 'DefaultPluginsSetting' (Default Adobe Flash setting), 'PluginsAllowedForUrls' (Allow the Adobe Flash plug-in on specific sites), and 'PluginsBlockedForUrls' (Block the Adobe Flash plug-in on specific sites) policies.\r\n\r\nIf you disable this policy or don't configure it, Adobe Flash content from other origins (from sites that aren't specified in the three policies mentioned immediately above) or small content might be blocked.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_runallflashinallowmode_1","displayName":"Enabled","description":null,"helpText":null}]},"9ed0e35ee071cf05":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup","displayName":"Action to take on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"9ee06353e878cbac":{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_alloweddomainsforapps_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"9ea5a683851b1b20":{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled","displayName":"Enable efficiency mode when the device is connected to a power source (User)","description":"Allows efficiency mode to become active when the device is connected to a power source. On devices with no battery, this policy has no effect.\r\n\r\nIf you enable this policy, efficiency mode will become active when the device is connected to a power source.\r\n\r\nIf you disable or don't configure this policy, efficiency mode will never become active when the device is connected to a power source.\r\n\r\nThis policy has no effect if the 'EfficiencyModeEnabled' (Efficiency mode enabled) policy is disabled.\r\n\r\nLearn more about efficiency mode: https://go.microsoft.com/fwlink/?linkid=2173921","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev106~policy~microsoft_edge~performance_efficiencymodeonpowerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9ed3d3c4eacb5fc6":{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled","displayName":"Compose is enabled for writing on the web (User)","description":"This policy lets you configure Compose in Microsoft Edge. Compose provides help for writing with AI-generated text, which lets the user get ideas for writing. This includes elaborating on text, re-writing, changing tone, formatting the text, and more.\r\n\r\nIf you enable or don't configure this policy, Compose can provide text generation for eligible fields, which are text editable and don't have an autocomplete attribute.\r\n\r\nIf you disable this policy, Compose will not be able to provide text generation for eligible fields. Compose will still be available for prompt-based text generation through the sidebar and must be managed with either 'EdgeDiscoverEnabled' (Discover feature In Microsoft Edge) policy or 'HubsSidebarEnabled' (Show Hubs Sidebar) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_composeinlineenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"9e52548228005da7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors","displayName":"Stop reporting non-critical errors (User)","description":"This policy setting controls whether the application reports non-critical errors.\r\n\r\nIf you enable this policy, non-critical errors will not be reported.\r\n\r\nIf you disable or do not configure this policy setting, non-critical errors will be reported.","helpText":"","infoUrls":[],"categoryId":"33fb4f49-5c7f-472c-a0f3-e05646a55902","categoryName":"Improved Error Reporting","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_improvederrorreporting_l_stopreportingnoncriticalerrors_1","displayName":"Enabled","description":null,"helpText":null}]},"9ec5fdeb124c939e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12","displayName":"Escrow Key #12 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey12_1","displayName":"Enabled","description":null,"helpText":null}]},"9e65fefc5e161362":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_pathcolon10","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"9e68c987afce333b":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},"9e498fed12bf2b13":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault","displayName":"Prompt the user if PowerPoint is not the default application for its file extensions (User)","description":"This policy setting specifies whether PowerPoint prompts users to change their file extension associations for any file types that are no longer associated with PowerPoint.\r\n\r\nIf you enable this policy setting, when users start PowerPoint, they are not prompted to change file extensions for any files that are no longer associated with PowerPoint. In addition, the checkbox on the user interface (UI) under File |Options | General | Start up options | Tell me is unchecked.\r\n\r\nIf you disable or do not configure this policy setting, when users start PowerPoint, they are prompted to change file extensions for any files that are no longer associated with PowerPoint. Users can change this behavior either by selecting the checkbox displayed in the prompt, or by selecting the UI checkbox under File |Options | General | Start up options | Tell me (which is selected by default).\r\n","helpText":"","infoUrls":[],"categoryId":"f5007db5-6ee6-4bbd-a391-9727902aad6d","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionsgeneral_l_promptifpowerpointisnotdefault_1","displayName":"Enabled","description":null,"helpText":null}]},"9e53e9c56392b966":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_descriptioncolon14","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"9eca6bbc79433185":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon61","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"9ea2cbacad6e9429":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]},"9e659283095785ae":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles","displayName":"Copy remotely stored files onto your computer, and update the remote file when saving (User)","description":"This policy setting allows you to set the \"Copy remotely stored files onto your computer, and update the remote file when saving\" option in Word Options | Advanced | Save.\r\n\r\nIf you enable this policy setting, \"Copy remotely stored files onto your computer, and update the remote file when saving\" will be set.\r\n\r\nIf you disable or do not configure this policy setting, \"Copy remotely stored files onto your computer, and update the remote file when saving\" will not be set.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_copyremotelystoredfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"9eba5916210b1fca":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar","displayName":"Show vertical scroll bar (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_verticalscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},"9efbc7fa5036b901":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_tools_l_tools14","displayName":"Tools (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},"9e789b772d3ee190":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading","displayName":"Open e-mail attachments in Reading View (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_openattachmentsforfullscreenreading_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/a1.json b/public/intune-definitions/a1.json index bc63077f118e..2b61a730297e 100644 --- a/public/intune-definitions/a1.json +++ b/public/intune-definitions/a1.json @@ -1 +1 @@ -{"a10546c691801394":{"id":"ade_modernauth_awaitfinalconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_modernauth_awaitfinalconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_modernauth_awaitfinalconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},"a197940f77c982b1":{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing","displayName":"Data sharing between work and personal profile","description":"Choose if data can be shared between work and personal profiles. Available for corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_notconfigured","displayName":"Device default","description":"Not configured; this value defaults to CROSS_PROFILE_DATA_SHARING_UNSPECIFIED.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_crossprofiledatasharingblocked","displayName":"Block all sharing between profiles","description":"Data cannot be shared from both the personal profile to work profile and the work profile to the personal profile.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_datasharingfromworktopersonalblocked","displayName":"Block sharing from work to personal profile","description":"Prevents users from sharing data from the work profile to apps in the personal profile. Personal data can be shared with work apps.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_crossprofiledatasharingallowed","displayName":"No restrictions on sharing","description":"Data from either profile can be shared with the other profile.","helpText":null}]},"a13ad9b4e5deeee2":{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification","displayName":"Allow Default Browser Modification","description":"If false, disables default browser preference modification. The MDM Settings command to set the default browser preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification_true","displayName":"Enabled","description":null,"helpText":null}]},"a1b5b82f8ecb3bda":{"id":"com.apple.applicationaccess_allowesimmodification","displayName":"Allow ESIM Modification","description":"If false, disables modifications to carrier plan related settings (only available on select carriers). Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowesimmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowesimmodification_true","displayName":"True","description":null,"helpText":null}]},"a143ffcfe59edca8":{"id":"com.apple.dnssettings.managed_com.apple.dnssettings.managed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},"a1d93016cac72016":{"id":"com.apple.managedclient.preferences_defaultstolocalopensave","displayName":"Default to local files for open/save","description":"Prefer the local file system when accessing the Open and Save dialogs.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_defaultstolocalopensave_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultstolocalopensave_true","displayName":"True","description":null,"helpText":null}]},"a182238e37d855b6":{"id":"com.apple.managedclient.preferences_hidefirstrunexperience","displayName":"Hide the First-run experience and splash screen","description":"If you enable this policy, the First-run experience and the splash screen will not be shown to users when they run Microsoft Edge for the first time.\n\nFor the configuration options shown in the First Run Experience, the browser will default to the following:\n\n-On the New Tab Page, the feed type will be set to MSN News and the layout to Inspirational.\n\n-The user will still be automatically signed into Microsoft Edge if the Windows account is of AAD or MSA type.\n\n-Sync will not be enabled by default and users will be able to turn on sync from the sync settings.\n\nIf you disable or don't configure this policy, the First-run experience and the Splash screen will be shown.\n\nNote: The specific configuration options shown to the user in the First Run Experience, can also be managed by using other specific policies. You can use the HideFirstRunExperience policy in combination with these policies to configure a specific browser experience on your managed devices. Some of these other policies are:\n\n-\"AutoImportAtFirstRun\"\n\n-\"NewTabPageLocation\"\n\n-\"NewTabPageSetFeedType\"\n\n-\"SyncDisabled\"\n\n-\"BrowserSignin\"\n\n-\"NonRemovableProfileEnabled\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hidefirstrunexperience"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_hidefirstrunexperience_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidefirstrunexperience_true","displayName":"Enabled","description":null,"helpText":null}]},"a1a5b0feae8cd600":{"id":"com.apple.managedclient.preferences_kfmsilentoptin","displayName":"Automatically and silently enable the Folder Backup feature (Known Folder Move)","description":"Use this setting to redirect and move your users Documents and/or Desktop folders to OneDrive without any user interaction. Enter your Microsoft 365 tenant ID to enable this feature.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},"a1cbd44e78f7540f":{"id":"com.apple.mcx.filevault2_username","displayName":"Username","description":"The user name of the Open Directory user to be added to FileVault.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},"a1268dd97cded688":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting","displayName":"Default idle detection setting","description":"Setting this policy to 1 - AllowIdleDetection allows websites to use the Idle Detection API without requesting user permission.\n\nSetting this policy to 2 - BlockIdleDetection prevents websites from using the Idle Detection API.\n\nSetting this policy to 3 - AskIdleDetection requires websites to request user permission each time before using the Idle Detection API.\n\nIf you do not configure this policy, users can decide whether to allow the Idle Detection API and can change this setting themselves.\n\nPolicy options mapping:\n\n* AllowIdleDetection (1) = Allow sites to detect idle state without asking the user\n\n* BlockIdleDetection (2) = Do not allow any site to detect the user's idle state\n\n* AskIdleDetection (3) = Ask every time a site wants to detect the user's idle state\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_allowidledetection","displayName":"Allow sites to detect idle state without asking the user","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_blockidledetection","displayName":"Do not allow any site to detect the user's idle state","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_askidledetection","displayName":"Ask every time a site wants to detect the user's idle state","description":null,"helpText":null}]},"a1c0f6956d4e0c62":{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werminfreediskspace","displayName":"Minimum free disk space (MB):","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"a18b5081a99a24d0":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_proxybypass","displayName":"Define addresses to bypass proxy server","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},"a14308caa0225590":{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth","displayName":"Block all consumer Microsoft account user authentication","description":"This setting controls whether users can provide Microsoft accounts for authentication for applications or services. If this setting is enabled, all applications and services on the device are prevented from using Microsoft accounts for authentication. \r\nThis applies both to existing users of a device and new users who may be added. However, any application or service that has already authenticated a user will not be affected by enabling this setting until the authentication cache expires. \r\nIt is recommended to enable this setting before any user signs in to a device to prevent cached tokens from being present. If this setting is disabled or not configured, applications and services can use Microsoft accounts for authentication. \r\nBy default, this setting is Disabled. This setting does not affect whether users can sign in to devices by using Microsoft accounts, or the ability for users to provide Microsoft accounts via the browser for authentication with web-based applications. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msapolicy#admx-msapolicy-microsoftaccount-disableuserauth"],"categoryId":"60b898a9-0490-4599-b7f1-3cd451236266","categoryName":"Microsoft account","options":[{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth_1","displayName":"Enabled","description":null,"helpText":null}]},"a1ba55c27ce77865":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc","displayName":"Guaranteed service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_1","displayName":"Enabled","description":null,"helpText":null}]},"a1abb41d2f28f98c":{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_shutdownsessiontimeout_time","displayName":"Hung session timeout in Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":null},"a1c30a63f7ec41cf":{"id":"device_vendor_msft_policy_config_browser_allowdonottrack","displayName":"Allow Do Not Track","description":"This setting lets you decide whether employees can send Do Not Track headers to websites that request tracking info.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowdonottrack"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowdonottrack_0","displayName":"Block","description":"Never send tracking information.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowdonottrack_1","displayName":"Allow","description":"Send tracking information.","helpText":null}]},"a100efb6c5e6d039":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled","displayName":"Allow background tabs freeze","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a1160f62cae5a5c8":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvolumetypevhdorvhdx","displayName":"Volume Type (VHD or VHDX)","description":"Specifies the type of virtual disk to auto-create. The default is VHD which is the same as \"Not Configured\".\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\VolumeType\r\nType: REG_SZ\r\nValues: VHD, VHDX","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvolumetypevhdorvhdx_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvolumetypevhdorvhdx_1","displayName":"Enabled","description":null,"helpText":null}]},"a1403c35e0aece08":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesenabled","displayName":"Enabled","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nControls whether or not the Profiles feature is active\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\Enabled\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a11afc24bae248a2":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a","displayName":"Include local directory path when uploading files to a server","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_3","displayName":"Disable","description":null,"helpText":null}]},"a172c162dbef0383":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00","displayName":"Logon options","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},"a1fa777f89a29b87":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"a1d70a03f7d4f823":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},"a1be94fb5268526d":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},"a198d6acdc42664e":{"id":"device_vendor_msft_policy_config_secguidev22h2~policy~cat_secguide_pol_secguide_a001_block_flash","displayName":"Block Flash activation in Office documents","description":"This policy setting controls whether the Adobe Flash control can be activated by Office documents. Note that activation blocking applies only within Office processes.\r\n\r\nIf you enable this policy setting, you can choose from three options to control whether and how Flash is blocked from activation:\r\n\r\n1. \"Block all activation\" prevents the Flash control from being loaded, whether directly referenced by the document or indirectly by another embedded object.\r\n\r\n2. \"Block embedding/linking, allow other activation\" prevents the Flash control from being loaded when directly referenced by the document, but does not prevent activation through another object.\r\n\r\n3. \"Allow all activation\" restores Office's default behavior, allowing the Flash control to be activated.\r\n\r\nBecause this setting is not a true Group Policy setting and \"tattoos\" the registry, enabling the \"Allow all activation\" option is the only way to restore default behavior after either of the \"Block\" options has been applied. We do not recommend configuring this setting to \"Disabled,\" nor to \"Not Configured\" after it has been enabled.\r\n","helpText":"","infoUrls":[],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_secguidev22h2~policy~cat_secguide_pol_secguide_a001_block_flash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_secguidev22h2~policy~cat_secguide_pol_secguide_a001_block_flash_1","displayName":"Enabled","description":null,"helpText":null}]},"a120f34516af82ae":{"id":"device_vendor_msft_policy_config_system_disableonedrivefilesync","displayName":"Disable One Drive File Sync","description":"This policy setting lets you prevent apps and features from working with files on OneDrive. If you enable this policy setting: users can’t access OneDrive from the OneDrive app and file picker; Microsoft Store apps can’t access OneDrive using the WinRT API; OneDrive doesn’t appear in the navigation pane in File Explorer; OneDrive files aren’t kept in sync with the cloud; Users can’t automatically upload photos and videos from the camera roll folder. If you disable or do not configure this policy setting, apps and features can work with OneDrive file storage.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#disableonedrivefilesync"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_disableonedrivefilesync_0","displayName":"Sync enabled.","description":"Sync enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_disableonedrivefilesync_1","displayName":"Sync disabled.","description":"Sync disabled.","helpText":null}]},"a1e85a62a2331035":{"id":"device_vendor_msft_policy_config_system_limitdiagnosticlogcollection","displayName":"Limit Diagnostic Log Collection","description":"This policy setting specifies whether diagnostic log data can be collected when more information is needed to troubleshoot a problem. The diagnostic data logs are collected, only if we have permission to collect optional diagnostic data, and only if the device meets the criteria for additional data collection. If you disable or do not configure this policy setting, we may occasionally collect advanced diagnostic data if the user has opted to send optional diagnostic data.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#limitdiagnosticlogcollection"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_limitdiagnosticlogcollection_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_limitdiagnosticlogcollection_1","displayName":"Enabled.","description":"Enabled.","helpText":null}]},"a11387fb11cf1a97":{"id":"device_vendor_msft_policy_config_update_automaticmaintenancewakeup","displayName":"Automatic Maintenance Wake Up","description":"This policy setting allows you to configure Automatic Maintenance wake up policy. The maintenance wakeup policy specifies if Automatic Maintenance should make a wake request to the OS for the daily scheduled maintenance. Note, that if the OS power wake policy is explicitly disabled, then this setting has no effect. If you enable this policy setting, Automatic Maintenance will attempt to set OS wake policy and make a wake request for the daily scheduled time, if required. If you disable or do not configure this policy setting, the wake setting as specified in Security and Maintenance/Automatic Maintenance Control Panel will apply.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#automaticmaintenancewakeup"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_automaticmaintenancewakeup_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_update_automaticmaintenancewakeup_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"a1a38f79219eba54":{"id":"device_vendor_msft_policy_config_update_pausequalityupdates","displayName":"Pause Quality Updates","description":"Allows IT Admins to pause Quality Updates.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#pausequalityupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_pausequalityupdates_0","displayName":"Quality Updates are not paused.","description":"Quality Updates are not paused.","helpText":null},{"id":"device_vendor_msft_policy_config_update_pausequalityupdates_1","displayName":"Quality Updates are paused for 35 days or until value set back to 0, whichever is sooner.","description":"Quality Updates are paused for 35 days or until value set back to 0, whichever is sooner.","helpText":null}]},"a10e28a29889fd82":{"id":"device_vendor_msft_policy_config_webthreatdefense_notifypasswordreuse","displayName":"Notify Password Reuse","description":"Configures Enhanced Phishing Protection notifications for protecting passwords from reuse.","helpText":"","infoUrls":[],"categoryId":"20b71dc7-cf08-4534-9e52-d297dd071ca5","categoryName":"Enhanced Phishing Protection","options":[{"id":"device_vendor_msft_policy_config_webthreatdefense_notifypasswordreuse_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_webthreatdefense_notifypasswordreuse_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"a15d6f07cd4a4389":{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging","displayName":"Log script block invocation start / stop events:","description":"","helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging_1","displayName":"True","description":null,"helpText":null}]},"a1d370d8d714c5a5":{"id":"linux_mdatp_managed_edr_tags","displayName":"Device tags","description":null,"helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#add-tag-or-group-id-to-the-configuration-profile"],"categoryId":"22a2a407-0f28-481d-bdbe-1f9cb6d589c3","categoryName":" EDR preferences","options":null},"a1e7762c1a46994f":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_descriptioncolon25","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"a122af4975301059":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders58","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders58_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders58_1","displayName":"True","description":null,"helpText":null}]},"a15431203d52c1c4":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nocolorappearanceui","displayName":"Prevent changing color and appearance (User)","description":"Disables the Color (or Window Color) page in the Personalization Control Panel, or the Color Scheme dialog in the Display Control Panel on systems where the Personalization feature is not available.\r\n\r\nThis setting prevents users from using Control Panel to change the window border and taskbar color (on Windows 8), glass color (on Windows Vista and Windows 7), system colors, or color scheme of the desktop and windows.\r\n\r\nIf this setting is disabled or not configured, the Color (or Window Color) page or Color Scheme dialog is available in the Personalization or Display Control Panel.\r\n\r\nFor systems prior to Windows Vista, this setting hides the Appearance and Themes tabs in the in Display in Control Panel.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-nocolorappearanceui"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nocolorappearanceui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nocolorappearanceui_1","displayName":"Enabled","description":null,"helpText":null}]},"a16c9fcea64b5da3":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepincontacts","displayName":"Contacts (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepincontacts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepincontacts_1","displayName":"True","description":null,"helpText":null}]},"a144919816cc7357":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_1","displayName":"Reminder balloon frequency (User)","description":"Determines how often reminder balloon updates appear.\r\n\r\nIf you enable this setting, you can select how often reminder balloons updates appear and also prevent users from changing this setting.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the update interval.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To set reminder balloon frequency without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, and then click the Offline Files tab. This setting corresponds to the \"Display reminder balloons every ... minutes\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderfreq-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_1_1","displayName":"Enabled","description":null,"helpText":null}]},"a1fc307c89d2fbdc":{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist","displayName":"Remove pinned programs from the Taskbar (User)","description":"This policy setting allows you to remove pinned programs from the taskbar.\r\n\r\nIf you enable this policy setting, pinned programs are prevented from being shown on the Taskbar. Users cannot pin programs to the Taskbar.\r\n\r\nIf you disable or do not configure this policy setting, users can pin programs so that the program shortcuts stay on the Taskbar.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnopinnedlist"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist_1","displayName":"Enabled","description":null,"helpText":null}]},"a12daaad2bec2231":{"id":"user_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist","displayName":"Allow Microsoft Compatibility List (User)","description":"This policy setting lets you decide whether the Microsoft Compatibility List is enabled or disabled in Microsoft Edge. This feature uses a Microsoft-provided list to ensure that any sites with known compatibility issues are displayed correctly when a user navigates to them. By default, the Microsoft Compatibility List is enabled and can be viewed by navigating to about:compat. If you enable or don’t configure this setting, Microsoft Edge will periodically download the latest version of the list from Microsoft and will apply the configurations specified there during browser navigation. If a user visits a site on the Microsoft Compatibility List, he or she will be prompted to open the site in Internet Explorer 11. Once in Internet Explorer, the site will automatically be rendered as if the user is viewing it in the previous version of Internet Explorer it requires to display correctly. If you disable this setting, the Microsoft Compatibility List will not be used during browser navigation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowmicrosoftcompatibilitylist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"a10f6eb8a3ec0d42":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open New Tab Page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"a10cb670a0b04ce7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls","displayName":"Block notifications on these sites (User)","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't display notifications.\r\n\r\nLeaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"a120a7749577fa1e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon75","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"a15bf8ffc1c89331":{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate","displayName":"Trusted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_4","displayName":"High","description":null,"helpText":null}]},"a101767617d737d3":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols","displayName":"Download unsigned ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.\n\nIf you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.\n\nIf you disable this policy setting, users cannot run unsigned controls.\n\nIf you do not configure this policy setting, users cannot run unsigned controls.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadunsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"a17abc3e3f9264f2":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"a12165a19e2f6ef0":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"In Microsoft Edge, the Experimentation and Configuration Service is used to deploy Experimentation and Configuration payload.\r\n\r\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\r\n\r\nConfiguration payload consists of a list of settings that Microsoft wants to deploy to Microsoft Edge to optimize user experience. For example, configuration payload may specify how often Microsoft Edge sends requests to the Experimentation and Configuration Service to retrieve the newest payload.\r\n\r\nAdditionaly, configuration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nIf you set this policy to \"Retrieve configurations and experiments\" mode, the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\r\n\r\nIf you set this policy to \"Retrieve configurations only\" mode, only the configuration payload is delivered.\r\n\r\nIf you set this policy to \"Disable communication with the Experimentation and Configuration Service\" mode, the communication with the Experimentation and Configuration Service is stopped completely.\r\n\r\nIf you don't configure this policy, on a managed device on Stable and Beta channels the behavior is the same as the \"Retrieve configurations only\" mode.\r\n\r\nIf you don't configure this policy, on an unmanaged device the behavior is the same as the \"Retrieve configurations and experiments\" mode.\r\n\r\n* 0 = Disable communication with the Experimentation and Configuration Service\r\n\r\n* 1 = Retrieve configurations only\r\n\r\n* 2 = Retrieve configurations and experiments","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"a1fc2f7fb1f28b8e":{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting","displayName":"Configure browser process code integrity guard setting (User)","description":"This policy controls the use of code integrity guard in the browser process, which only allows Microsoft signed binaries to load.\r\n\r\nSetting this policy to Enabled will enable code integrity guard in the browser process.\r\n\r\nSetting this policy to Disabled, or if the policy is not set, will prevent the browser from enabling code integrity guard in the browser process.\r\n\r\nThe policy value Audit (1) is obsolete as of version 110. Setting this value is equivalent to the Disabled value.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro or Enterprise instances that enrolled for device management.\r\n\r\nThis policy will only take effect on Windows 10 RS2 and above.\r\n\r\nPolicy options mapping:\r\n\r\n* Disabled (0) = Do not enable code integrity guard in the browser process.\r\n\r\n* Audit (1) = Enable code integrity guard audit mode in the browser process.\r\n\r\n* Enabled (2) = Enable code integrity guard enforcement in the browser process.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_1","displayName":"Enabled","description":null,"helpText":null}]},"a1e0f5c26615718b":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended","displayName":"Suggest similar pages when a webpage can’t be found (User)","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"a15ae8d69ae4b55c":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled","displayName":"Enable startup boost (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.\r\n\r\nIf Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.\r\n\r\nIf you enable this policy, startup boost is turned on.\r\n\r\nIf you disable this policy, startup boost is turned off.\r\n\r\nIf you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a1db15eec03ef037":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"a13396e0a181b5e0":{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser","displayName":"Disable local training of the Adaptive Floatie feature for the user. (User)","description":"\r\nThis policy setting disables local training of the Adaptive Floatie feature for the user.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\nIf a higher priority policy setting is not configured, then:\r\n- If this policy setting is enabled, local training of the Adaptive Floatie feature is disabled for the user.\r\n- If this policy setting is disabled, local training of the Adaptive Floatie feature is enabled for the user.\r\n- If this policy setting is not configured, local training of the Adaptive Floatie feature is determined by lower priority policy settings.\r\n- If this policy setting is not configured and lower priority policy settings are also not configured, local training of the Adaptive Floatie feature is enabled for the user.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of the Adaptive Floatie feature for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of the Adaptive Floatie feature for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser_1","displayName":"Enabled","description":null,"helpText":null}]},"a149edfbfcfb6d30":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},"a13ce039c03455ff":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6","displayName":"Places Bar Location 6 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_1","displayName":"Enabled","description":null,"helpText":null}]},"a1d4869afbe00713":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador","displayName":"Spanish (Ecuador) (User)","description":"Enables the editing language Spanish (Ecuador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador_1","displayName":"Enabled","description":null,"helpText":null}]},"a13b286fd60fdfda":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowfriendly","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"a1c0d9825c58e500":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04","displayName":"Unsafe Location #4 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_1","displayName":"Enabled","description":null,"helpText":null}]},"a13bb38cf8a388c9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06_1","displayName":"True","description":null,"helpText":null}]},"a1b95b4bfeddc434":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword","displayName":"Word-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword_1","displayName":"True","description":null,"helpText":null}]},"a1337affbe74ffd7":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_l_allowedcomaddinslist","displayName":"Allowed COM/VSTO Add-ins: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},"a1e76d9610103f6b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks_1","displayName":"True","description":null,"helpText":null}]},"a1b7656115cc018e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders","displayName":"Do not allow Outlook object model scripts to run for public folders (User) (Deprecated)","description":"This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.\r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you do not configure this policy setting, Outlook will not run any scripts associated with public folders by default. Users can configure the setting in the Trust Center by selecting the “Allow script in public folders” check box.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"a1c53d3ae90467f5":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15","displayName":"Followed hyperlink color (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_16","displayName":"Automatic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_1","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_2","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_3","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_4","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_5","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_6","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_7","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_8","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_9","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_10","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_11","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_12","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_13","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_14","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_15","displayName":"Silver","description":null,"helpText":null}]},"a17e73eb44aa073b":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30","displayName":"Save Microsoft Project files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpp.12","displayName":"Project (*.mpp)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpt.12","displayName":"Template (*.mpt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpp.9","displayName":"Project 2000-2003 (*.mpp)","description":null,"helpText":null}]},"a141c3130d183109":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste","displayName":"Adjust table formatting and alignment on paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste_1","displayName":"Enabled","description":null,"helpText":null}]},"a1df9041a0ebf20c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]}} \ No newline at end of file +{"a10546c691801394":{"id":"ade_modernauth_awaitfinalconfiguration","displayName":"Await final configuration","description":"Keeps the device in Setup Assistant until the first sync between the device and Intune installs policies.","helpText":"","infoUrls":[],"categoryId":"75e27534-3163-45b1-b34e-ca79b077b286","categoryName":null,"options":[{"id":"ade_modernauth_awaitfinalconfiguration_0","displayName":"No","description":null,"helpText":null},{"id":"ade_modernauth_awaitfinalconfiguration_1","displayName":"Yes","description":null,"helpText":null}]},"a197940f77c982b1":{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing","displayName":"Data sharing between work and personal profile","description":"Choose if data can be shared between work and personal profiles. Available for corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_notconfigured","displayName":"Device default","description":"Not configured; this value defaults to CROSS_PROFILE_DATA_SHARING_UNSPECIFIED.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_crossprofiledatasharingblocked","displayName":"Block all sharing between profiles","description":"Data cannot be shared from both the personal profile to work profile and the work profile to the personal profile.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_datasharingfromworktopersonalblocked","displayName":"Block sharing from work to personal profile","description":"Prevents users from sharing data from the work profile to apps in the personal profile. Personal data can be shared with work apps.","helpText":null},{"id":"com.android.devicerestrictionpolicy.crossprofilepoliciesallowdatasharing_crossprofiledatasharingallowed","displayName":"No restrictions on sharing","description":"Data from either profile can be shared with the other profile.","helpText":null}]},"a13ad9b4e5deeee2":{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification","displayName":"Allow Default Browser Modification","description":"If false, disables default browser preference modification. The MDM Settings command to set the default browser preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultbrowsermodification_true","displayName":"Enabled","description":null,"helpText":null}]},"a1b5b82f8ecb3bda":{"id":"com.apple.applicationaccess_allowesimmodification","displayName":"Allow ESIM Modification","description":"If false, disables modifications to carrier plan related settings (only available on select carriers). Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowesimmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowesimmodification_true","displayName":"True","description":null,"helpText":null}]},"a143ffcfe59edca8":{"id":"com.apple.dnssettings.managed_com.apple.dnssettings.managed","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":null},"a1d93016cac72016":{"id":"com.apple.managedclient.preferences_defaultstolocalopensave","displayName":"Default to local files for open/save","description":"Prefer the local file system when accessing the Open and Save dialogs.","helpText":null,"infoUrls":["https://learn.microsoft.com/deployoffice/mac/preferences-office"],"categoryId":"b5169b74-41be-460a-9402-b13b6c22582b","categoryName":"Microsoft Office","options":[{"id":"com.apple.managedclient.preferences_defaultstolocalopensave_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultstolocalopensave_true","displayName":"True","description":null,"helpText":null}]},"a182238e37d855b6":{"id":"com.apple.managedclient.preferences_hidefirstrunexperience","displayName":"Hide the First-run experience and splash screen","description":"If you enable this policy, the First-run experience and the splash screen will not be shown to users when they run Microsoft Edge for the first time.\n\nFor the configuration options shown in the First Run Experience, the browser will default to the following:\n\n-On the New Tab Page, the feed type will be set to MSN News and the layout to Inspirational.\n\n-The user will still be automatically signed into Microsoft Edge if the Windows account is of AAD or MSA type.\n\n-Sync will not be enabled by default and users will be able to turn on sync from the sync settings.\n\nIf you disable or don't configure this policy, the First-run experience and the Splash screen will be shown.\n\nNote: The specific configuration options shown to the user in the First Run Experience, can also be managed by using other specific policies. You can use the HideFirstRunExperience policy in combination with these policies to configure a specific browser experience on your managed devices. Some of these other policies are:\n\n-\"AutoImportAtFirstRun\"\n\n-\"NewTabPageLocation\"\n\n-\"NewTabPageSetFeedType\"\n\n-\"SyncDisabled\"\n\n-\"BrowserSignin\"\n\n-\"NonRemovableProfileEnabled\"","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#hidefirstrunexperience"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_hidefirstrunexperience_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_hidefirstrunexperience_true","displayName":"Enabled","description":null,"helpText":null}]},"a1a5b0feae8cd600":{"id":"com.apple.managedclient.preferences_kfmsilentoptin","displayName":"Automatically and silently enable the Folder Backup feature (Known Folder Move)","description":"Use this setting to redirect and move your users Documents and/or Desktop folders to OneDrive without any user interaction. Enter your Microsoft 365 tenant ID to enable this feature.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#kfmsilentoptin"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},"a1cbd44e78f7540f":{"id":"com.apple.mcx.filevault2_username","displayName":"Username","description":"The user name of the Open Directory user to be added to FileVault.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":null},"a1268dd97cded688":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting","displayName":"Default idle detection setting","description":"Setting this policy to 1 - AllowIdleDetection allows websites to use the Idle Detection API without requesting user permission.\n\nSetting this policy to 2 - BlockIdleDetection prevents websites from using the Idle Detection API.\n\nSetting this policy to 3 - AskIdleDetection requires websites to request user permission each time before using the Idle Detection API.\n\nIf you do not configure this policy, users can decide whether to allow the Idle Detection API and can change this setting themselves.\n\nPolicy options mapping:\n\n* AllowIdleDetection (1) = Allow sites to detect idle state without asking the user\n\n* BlockIdleDetection (2) = Do not allow any site to detect the user's idle state\n\n* AskIdleDetection (3) = Ask every time a site wants to detect the user's idle state\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_allowidledetection","displayName":"Allow sites to detect idle state without asking the user","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_blockidledetection","displayName":"Do not allow any site to detect the user's idle state","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultidledetectionsetting_askidledetection","displayName":"Ask every time a site wants to detect the user's idle state","description":null,"helpText":null}]},"a1c0f6956d4e0c62":{"id":"device_vendor_msft_policy_config_admx_errorreporting_werqueue_2_werminfreediskspace","displayName":"Minimum free disk space (MB):","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"a18b5081a99a24d0":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_proxybypass_proxybypass","displayName":"Define addresses to bypass proxy server","description":null,"helpText":"","infoUrls":[],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":null},"a14308caa0225590":{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth","displayName":"Block all consumer Microsoft account user authentication","description":"This setting controls whether users can provide Microsoft accounts for authentication for applications or services. If this setting is enabled, all applications and services on the device are prevented from using Microsoft accounts for authentication. \r\nThis applies both to existing users of a device and new users who may be added. However, any application or service that has already authenticated a user will not be affected by enabling this setting until the authentication cache expires. \r\nIt is recommended to enable this setting before any user signs in to a device to prevent cached tokens from being present. If this setting is disabled or not configured, applications and services can use Microsoft accounts for authentication. \r\nBy default, this setting is Disabled. This setting does not affect whether users can sign in to devices by using Microsoft accounts, or the ability for users to provide Microsoft accounts via the browser for authentication with web-based applications. \r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msapolicy#admx-msapolicy-microsoftaccount-disableuserauth"],"categoryId":"60b898a9-0490-4599-b7f1-3cd451236266","categoryName":"Microsoft account","options":[{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msapolicy_microsoftaccount_disableuserauth_1","displayName":"Enabled","description":null,"helpText":null}]},"a1ba55c27ce77865":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc","displayName":"Guaranteed service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Guaranteed service type (ServiceTypeGuaranteed). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that do not conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Guaranteed service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypeguaranteed-nc"],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_1","displayName":"Enabled","description":null,"helpText":null}]},"a1abb41d2f28f98c":{"id":"device_vendor_msft_policy_config_admx_wininit_shutdowntimeouthungsessionsdescription_shutdownsessiontimeout_time","displayName":"Hung session timeout in Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","categoryName":"Shutdown Options","options":null},"a1c30a63f7ec41cf":{"id":"device_vendor_msft_policy_config_browser_allowdonottrack","displayName":"Allow Do Not Track","description":"This setting lets you decide whether employees can send Do Not Track headers to websites that request tracking info.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowdonottrack"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowdonottrack_0","displayName":"Block","description":"Never send tracking information.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowdonottrack_1","displayName":"Allow","description":"Send tracking information.","helpText":null}]},"a100efb6c5e6d039":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled","displayName":"Allow background tabs freeze","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabfreezingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a1160f62cae5a5c8":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvolumetypevhdorvhdx","displayName":"Volume Type (VHD or VHDX)","description":"Specifies the type of virtual disk to auto-create. The default is VHD which is the same as \"Not Configured\".\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\VolumeType\r\nType: REG_SZ\r\nValues: VHD, VHDX","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvolumetypevhdorvhdx_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcvolumetypevhdorvhdx_1","displayName":"Enabled","description":null,"helpText":null}]},"a1403c35e0aece08":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesenabled","displayName":"Enabled","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nControls whether or not the Profiles feature is active\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\Enabled\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a11afc24bae248a2":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a","displayName":"Include local directory path when uploading files to a server","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneincludelocalpathwhenuploadingfilestoserver_iz_partname160a_3","displayName":"Disable","description":null,"helpText":null}]},"a172c162dbef0383":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00","displayName":"Logon options","description":"","helpText":"","infoUrls":[],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},"a1fa777f89a29b87":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"a1d70a03f7d4f823":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},"a1be94fb5268526d":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},"a198d6acdc42664e":{"id":"device_vendor_msft_policy_config_secguidev22h2~policy~cat_secguide_pol_secguide_a001_block_flash","displayName":"Block Flash activation in Office documents","description":"This policy setting controls whether the Adobe Flash control can be activated by Office documents. Note that activation blocking applies only within Office processes.\r\n\r\nIf you enable this policy setting, you can choose from three options to control whether and how Flash is blocked from activation:\r\n\r\n1. \"Block all activation\" prevents the Flash control from being loaded, whether directly referenced by the document or indirectly by another embedded object.\r\n\r\n2. \"Block embedding/linking, allow other activation\" prevents the Flash control from being loaded when directly referenced by the document, but does not prevent activation through another object.\r\n\r\n3. \"Allow all activation\" restores Office's default behavior, allowing the Flash control to be activated.\r\n\r\nBecause this setting is not a true Group Policy setting and \"tattoos\" the registry, enabling the \"Allow all activation\" option is the only way to restore default behavior after either of the \"Block\" options has been applied. We do not recommend configuring this setting to \"Disabled,\" nor to \"Not Configured\" after it has been enabled.\r\n","helpText":"","infoUrls":[],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_secguidev22h2~policy~cat_secguide_pol_secguide_a001_block_flash_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_secguidev22h2~policy~cat_secguide_pol_secguide_a001_block_flash_1","displayName":"Enabled","description":null,"helpText":null}]},"a120f34516af82ae":{"id":"device_vendor_msft_policy_config_system_disableonedrivefilesync","displayName":"Disable One Drive File Sync","description":"This policy setting lets you prevent apps and features from working with files on OneDrive. If you enable this policy setting: users can’t access OneDrive from the OneDrive app and file picker; Microsoft Store apps can’t access OneDrive using the WinRT API; OneDrive doesn’t appear in the navigation pane in File Explorer; OneDrive files aren’t kept in sync with the cloud; Users can’t automatically upload photos and videos from the camera roll folder. If you disable or do not configure this policy setting, apps and features can work with OneDrive file storage.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#disableonedrivefilesync"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_disableonedrivefilesync_0","displayName":"Sync enabled.","description":"Sync enabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_disableonedrivefilesync_1","displayName":"Sync disabled.","description":"Sync disabled.","helpText":null}]},"a1e85a62a2331035":{"id":"device_vendor_msft_policy_config_system_limitdiagnosticlogcollection","displayName":"Limit Diagnostic Log Collection","description":"This policy setting specifies whether diagnostic log data can be collected when more information is needed to troubleshoot a problem. The diagnostic data logs are collected, only if we have permission to collect optional diagnostic data, and only if the device meets the criteria for additional data collection. If you disable or do not configure this policy setting, we may occasionally collect advanced diagnostic data if the user has opted to send optional diagnostic data.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#limitdiagnosticlogcollection"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_limitdiagnosticlogcollection_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_limitdiagnosticlogcollection_1","displayName":"Enabled.","description":"Enabled.","helpText":null}]},"a11387fb11cf1a97":{"id":"device_vendor_msft_policy_config_update_automaticmaintenancewakeup","displayName":"Automatic Maintenance Wake Up","description":"This policy setting allows you to configure Automatic Maintenance wake up policy. The maintenance wakeup policy specifies if Automatic Maintenance should make a wake request to the OS for the daily scheduled maintenance. Note, that if the OS power wake policy is explicitly disabled, then this setting has no effect. If you enable this policy setting, Automatic Maintenance will attempt to set OS wake policy and make a wake request for the daily scheduled time, if required. If you disable or do not configure this policy setting, the wake setting as specified in Security and Maintenance/Automatic Maintenance Control Panel will apply.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#automaticmaintenancewakeup"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_automaticmaintenancewakeup_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_update_automaticmaintenancewakeup_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"a1a38f79219eba54":{"id":"device_vendor_msft_policy_config_update_pausequalityupdates","displayName":"Pause Quality Updates","description":"Allows IT Admins to pause Quality Updates.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#pausequalityupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_pausequalityupdates_0","displayName":"Quality Updates are not paused.","description":"Quality Updates are not paused.","helpText":null},{"id":"device_vendor_msft_policy_config_update_pausequalityupdates_1","displayName":"Quality Updates are paused for 35 days or until value set back to 0, whichever is sooner.","description":"Quality Updates are paused for 35 days or until value set back to 0, whichever is sooner.","helpText":null}]},"a10e28a29889fd82":{"id":"device_vendor_msft_policy_config_webthreatdefense_notifypasswordreuse","displayName":"Notify Password Reuse","description":"Configures Enhanced Phishing Protection notifications for protecting passwords from reuse.","helpText":"","infoUrls":[],"categoryId":"20b71dc7-cf08-4534-9e52-d297dd071ca5","categoryName":"Enhanced Phishing Protection","options":[{"id":"device_vendor_msft_policy_config_webthreatdefense_notifypasswordreuse_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_webthreatdefense_notifypasswordreuse_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"a15d6f07cd4a4389":{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging","displayName":"Log script block invocation start / stop events:","description":"","helpText":"","infoUrls":[],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowspowershell_turnonpowershellscriptblocklogging_enablescriptblockinvocationlogging_1","displayName":"True","description":null,"helpText":null}]},"a1d370d8d714c5a5":{"id":"linux_mdatp_managed_edr_tags","displayName":"Device tags","description":null,"helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#add-tag-or-group-id-to-the-configuration-profile"],"categoryId":"22a2a407-0f28-481d-bdbe-1f9cb6d589c3","categoryName":" EDR preferences","options":null},"a1223a5050d2dd47":{"id":"plugin_filter_browsers_enabled","displayName":"Enabled","description":"If `true`, the system enables filtering WebKit traffic.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":[{"id":"plugin_filter_browsers_enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"plugin_filter_browsers_enabled_true","displayName":"Enabled","description":null,"helpText":null}]},"a1e7762c1a46994f":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_descriptioncolon25","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"a122af4975301059":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders58","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders58_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders58_1","displayName":"True","description":null,"helpText":null}]},"a15431203d52c1c4":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nocolorappearanceui","displayName":"Prevent changing color and appearance (User)","description":"Disables the Color (or Window Color) page in the Personalization Control Panel, or the Color Scheme dialog in the Display Control Panel on systems where the Personalization feature is not available.\r\n\r\nThis setting prevents users from using Control Panel to change the window border and taskbar color (on Windows 8), glass color (on Windows Vista and Windows 7), system colors, or color scheme of the desktop and windows.\r\n\r\nIf this setting is disabled or not configured, the Color (or Window Color) page or Color Scheme dialog is available in the Personalization or Display Control Panel.\r\n\r\nFor systems prior to Windows Vista, this setting hides the Appearance and Themes tabs in the in Display in Control Panel.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-nocolorappearanceui"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nocolorappearanceui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_nocolorappearanceui_1","displayName":"Enabled","description":null,"helpText":null}]},"a16c9fcea64b5da3":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepincontacts","displayName":"Contacts (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepincontacts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepincontacts_1","displayName":"True","description":null,"helpText":null}]},"a144919816cc7357":{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_1","displayName":"Reminder balloon frequency (User)","description":"Determines how often reminder balloon updates appear.\r\n\r\nIf you enable this setting, you can select how often reminder balloons updates appear and also prevent users from changing this setting.\r\n\r\nReminder balloons appear when the user's connection to a network file is lost or reconnected, and they are updated periodically. By default, the first reminder for an event is displayed for 30 seconds. Then, updates appear every 60 minutes and are displayed for 15 seconds. You can use this setting to change the update interval.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To set reminder balloon frequency without establishing a setting, in Windows Explorer, on the Tools menu, click Folder Options, and then click the Offline Files tab. This setting corresponds to the \"Display reminder balloons every ... minutes\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-reminderfreq-1"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_1_1","displayName":"Enabled","description":null,"helpText":null}]},"a1fc307c89d2fbdc":{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist","displayName":"Remove pinned programs from the Taskbar (User)","description":"This policy setting allows you to remove pinned programs from the taskbar.\r\n\r\nIf you enable this policy setting, pinned programs are prevented from being shown on the Taskbar. Users cannot pin programs to the Taskbar.\r\n\r\nIf you disable or do not configure this policy setting, users can pin programs so that the program shortcuts stay on the Taskbar.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnopinnedlist"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnopinnedlist_1","displayName":"Enabled","description":null,"helpText":null}]},"a12daaad2bec2231":{"id":"user_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist","displayName":"Allow Microsoft Compatibility List (User)","description":"This policy setting lets you decide whether the Microsoft Compatibility List is enabled or disabled in Microsoft Edge. This feature uses a Microsoft-provided list to ensure that any sites with known compatibility issues are displayed correctly when a user navigates to them. By default, the Microsoft Compatibility List is enabled and can be viewed by navigating to about:compat. If you enable or don’t configure this setting, Microsoft Edge will periodically download the latest version of the list from Microsoft and will apply the configurations specified there during browser navigation. If a user visits a site on the Microsoft Compatibility List, he or she will be prompted to open the site in Internet Explorer 11. Once in Internet Explorer, the site will automatically be rendered as if the user is viewing it in the previous version of Internet Explorer it requires to display correctly. If you disable this setting, the Microsoft Compatibility List will not be used during browser navigation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowmicrosoftcompatibilitylist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowmicrosoftcompatibilitylist_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"a10f6eb8a3ec0d42":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action on startup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","categoryName":"Startup Home page and New Tab page","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open New Tab Page","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"a10cb670a0b04ce7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls","displayName":"Block notifications on these sites (User)","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can't display notifications.\r\n\r\nLeaving the policy unset means DefaultNotificationsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"a120a7749577fa1e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_descriptioncolon75","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"a15bf8ffc1c89331":{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate","displayName":"Trusted Sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowtrustedsiteszonetemplate_iz_partnametrustedsiteszonetemplate_4","displayName":"High","description":null,"helpText":null}]},"a101767617d737d3":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols","displayName":"Download unsigned ActiveX controls (User)","description":"This policy setting allows you to manage whether users may download unsigned ActiveX controls from the zone. Such code is potentially harmful, especially when coming from an untrusted zone.\n\nIf you enable this policy setting, users can run unsigned controls without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to allow the unsigned control to run.\n\nIf you disable this policy setting, users cannot run unsigned controls.\n\nIf you do not configure this policy setting, users cannot run unsigned controls.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedownloadunsignedactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonedownloadunsignedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"a17abc3e3f9264f2":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"a12165a19e2f6ef0":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service (User)","description":"In Microsoft Edge, the Experimentation and Configuration Service is used to deploy Experimentation and Configuration payload.\r\n\r\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\r\n\r\nConfiguration payload consists of a list of settings that Microsoft wants to deploy to Microsoft Edge to optimize user experience. For example, configuration payload may specify how often Microsoft Edge sends requests to the Experimentation and Configuration Service to retrieve the newest payload.\r\n\r\nAdditionaly, configuration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nIf you set this policy to \"Retrieve configurations and experiments\" mode, the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\r\n\r\nIf you set this policy to \"Retrieve configurations only\" mode, only the configuration payload is delivered.\r\n\r\nIf you set this policy to \"Disable communication with the Experimentation and Configuration Service\" mode, the communication with the Experimentation and Configuration Service is stopped completely.\r\n\r\nIf you don't configure this policy, on a managed device on Stable and Beta channels the behavior is the same as the \"Retrieve configurations only\" mode.\r\n\r\nIf you don't configure this policy, on an unmanaged device the behavior is the same as the \"Retrieve configurations and experiments\" mode.\r\n\r\n* 0 = Disable communication with the Experimentation and Configuration Service\r\n\r\n* 1 = Retrieve configurations only\r\n\r\n* 2 = Retrieve configurations and experiments","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"a1fc2f7fb1f28b8e":{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting","displayName":"Configure browser process code integrity guard setting (User)","description":"This policy controls the use of code integrity guard in the browser process, which only allows Microsoft signed binaries to load.\r\n\r\nSetting this policy to Enabled will enable code integrity guard in the browser process.\r\n\r\nSetting this policy to Disabled, or if the policy is not set, will prevent the browser from enabling code integrity guard in the browser process.\r\n\r\nThe policy value Audit (1) is obsolete as of version 110. Setting this value is equivalent to the Disabled value.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, or Windows 10 Pro or Enterprise instances that enrolled for device management.\r\n\r\nThis policy will only take effect on Windows 10 RS2 and above.\r\n\r\nPolicy options mapping:\r\n\r\n* Disabled (0) = Do not enable code integrity guard in the browser process.\r\n\r\n* Audit (1) = Enable code integrity guard audit mode in the browser process.\r\n\r\n* Enabled (2) = Enable code integrity guard enforcement in the browser process.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_browsercodeintegritysetting_1","displayName":"Enabled","description":null,"helpText":null}]},"a1e0f5c26615718b":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended","displayName":"Suggest similar pages when a webpage can’t be found (User)","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"a15ae8d69ae4b55c":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled","displayName":"Enable startup boost (User)","description":"Allows Microsoft Edge processes to start at OS sign-in and restart in background after the last browser window is closed.\r\n\r\nIf Microsoft Edge is running in background mode, the browser might not close when the last window is closed and the browser won't be restarted in background when the window closes. See the 'BackgroundModeEnabled' (Continue running background apps after Microsoft Edge closes) policy for information about what happens after configuring Microsoft Edge background mode behavior.\r\n\r\nIf you enable this policy, startup boost is turned on.\r\n\r\nIf you disable this policy, startup boost is turned off.\r\n\r\nIf you don't configure this policy, startup boost may initially be off or on. The user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about startup boost: https://go.microsoft.com/fwlink/?linkid=2147018","helpText":"","infoUrls":[],"categoryId":"3edb2860-b77b-4240-af16-fb34d45d6ba1","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~performance_startupboostenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a1db15eec03ef037":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"a13396e0a181b5e0":{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser","displayName":"Disable local training of the Adaptive Floatie feature for the user. (User)","description":"\r\nThis policy setting disables local training of the Adaptive Floatie feature for the user.\r\n\r\nFor local training policy, feature-specific settings are prioritized over general settings and computer settings are prioritized over user settings.\r\n\r\nIf a higher priority policy setting is not configured, then:\r\n- If this policy setting is enabled, local training of the Adaptive Floatie feature is disabled for the user.\r\n- If this policy setting is disabled, local training of the Adaptive Floatie feature is enabled for the user.\r\n- If this policy setting is not configured, local training of the Adaptive Floatie feature is determined by lower priority policy settings.\r\n- If this policy setting is not configured and lower priority policy settings are also not configured, local training of the Adaptive Floatie feature is enabled for the user.\r\n\r\nFor this policy setting, the order of priority is:\r\n1. Disable local training of the Adaptive Floatie feature for the computer.\r\n2. Disable local training of all features for the computer.\r\n3. Disable local training of the Adaptive Floatie feature for the user.\r\n4. Disable local training of all features for the user.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v16~policy~l_microsoftofficesystem~l_miscellaneous437_l_disabletrainingofadaptivefloatieuser_1","displayName":"Enabled","description":null,"helpText":null}]},"a149edfbfcfb6d30":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},"a13ce039c03455ff":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6","displayName":"Places Bar Location 6 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy6_1","displayName":"Enabled","description":null,"helpText":null}]},"a1d4869afbe00713":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador","displayName":"Spanish (Ecuador) (User)","description":"Enables the editing language Spanish (Ecuador)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_spanishecuador_1","displayName":"Enabled","description":null,"helpText":null}]},"a13b286fd60fdfda":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowfriendly","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"a1c0d9825c58e500":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04","displayName":"Unsafe Location #4 (User)","description":"This policy setting allows you to specify a location containing files that should always open in Protected View.\r\n\r\nIf you enable this policy setting, you can specify a location containing files that always open in Protected View. If you check the \"Allow sub folders\" option, sub folders will also be included.\r\n\r\nIf you disable or do not configure this policy setting, only the \"Downloaded Program Files\" and \"Temporary Internet Files\" folders will be considered unsafe locations.","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc04_1","displayName":"Enabled","description":null,"helpText":null}]},"a13bb38cf8a388c9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc06_l_allowsubfolders06_1","displayName":"True","description":null,"helpText":null}]},"a1b95b4bfeddc434":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword","displayName":"Word-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsword_1","displayName":"True","description":null,"helpText":null}]},"a1337affbe74ffd7":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_securitysettings_l_allowedcomaddins_l_allowedcomaddinslist","displayName":"Allowed COM/VSTO Add-ins: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},"a1e76d9610103f6b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_turnoffinternetexplorersecuritychecks_1","displayName":"True","description":null,"helpText":null}]},"a1b7656115cc018e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders","displayName":"Do not allow Outlook object model scripts to run for public folders (User) (Deprecated)","description":"This policy setting controls whether Outlook executes scripts that are associated with custom forms or folder home pages for public folders.\r\n\r\nIf you enable this policy setting, Outlook cannot execute any scripts associated with public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you disable this policy setting, Outlook will automatically run any scripts associated with custom forms or folder home pages for public folders, overriding any configuration changes on users' computers. \r\n\r\nIf you do not configure this policy setting, Outlook will not run any scripts associated with public folders by default. Users can configure the setting in the Trust Center by selecting the “Allow script in public folders” check box.","helpText":"","infoUrls":[],"categoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced_l_disableoutlookobjectmodelscriptsforpublicfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"a1c53d3ae90467f5":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15","displayName":"Followed hyperlink color (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_16","displayName":"Automatic","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_0","displayName":"Black","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_1","displayName":"Red","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_2","displayName":"Yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_3","displayName":"Lime","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_4","displayName":"Aqua","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_5","displayName":"Blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_6","displayName":"Fuchsia","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_7","displayName":"White","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_8","displayName":"Maroon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_9","displayName":"Green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_10","displayName":"Olive","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_11","displayName":"Navy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_12","displayName":"Purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_13","displayName":"Teal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_14","displayName":"Gray","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjfollowedlinkcolour_l_pjfollowedlinkcolour15_15","displayName":"Silver","description":null,"helpText":null}]},"a17e73eb44aa073b":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30","displayName":"Save Microsoft Project files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpp.12","displayName":"Project (*.mpp)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpt.12","displayName":"Template (*.mpt)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave_l_pjfiletype_l_pjfiletype30_msproject.mpp.9","displayName":"Project 2000-2003 (*.mpp)","description":null,"helpText":null}]},"a141c3130d183109":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste","displayName":"Adjust table formatting and alignment on paste (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e63361ad-a54b-4557-acc7-02c272a3e58d","categoryName":"Smart cut and paste","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_smartcutandpaste_l_adjusttableformattingandalignmentonpaste_1","displayName":"Enabled","description":null,"helpText":null}]},"a1df9041a0ebf20c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_allowsubfolders87_1","displayName":"True","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/a2.json b/public/intune-definitions/a2.json index 945a0aa292b6..adbccb7524b6 100644 --- a/public/intune-definitions/a2.json +++ b/public/intune-definitions/a2.json @@ -1 +1 @@ -{"a2af011318eae547":{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice","displayName":"Allow selection of a preferential network service","description":"If 'True', the device will give priority to the specified network service over other available options (e.g., enterprise slice on 5G networks). If 'False', Intune doesn't change or update this setting. By default, the device connects using its default network selection process. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice_false","displayName":"False","description":"Preferential network service is disabled.","helpText":null},{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice_true","displayName":"True","description":"Preferential network service is enabled on the device.","helpText":null}]},"a237003e5db2329a":{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp","displayName":"Block Wi-Fi setting changes","description":"If 'True', prevents users from creating or changing any Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp_true","displayName":"True","description":"True","helpText":null}]},"a242d1db394b52f1":{"id":"com.apple.cellularprivatenetwork.managed_com.apple.cellularprivatenetwork.managed","displayName":"com.apple.cellularprivatenetwork.managed","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"a22aa39e7903d676":{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys","displayName":"Use Shared Device Keys","description":"If set to true, Platform SSO will use the same signing and encryption keys for all users.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys_true","displayName":"Enabled","description":null,"helpText":null}]},"a22df545a5ba5bb7":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_application id","displayName":"Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"a2e0beb5dda09fa7":{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting","displayName":"Default JavaScript setting","description":"Set whether websites can run JavaScript. You can allow it for all sites (1) or block it for all sites (2).\n\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\n\n* 1 = Allow all sites to run JavaScript\n\n* 2 = Don't allow any site to run JavaScript","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultjavascriptsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting_0","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting_1","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},"a22f3ce083383e7f":{"id":"com.apple.managedclient.preferences_importopentabs","displayName":"Allow importing of open tabs","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importopentabs"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importopentabs_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importopentabs_true","displayName":"Enabled","description":null,"helpText":null}]},"a2fca6d1105f16cb":{"id":"com.apple.managedclient.preferences_searchfiltersenabled","displayName":"Search Filters Enabled","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions will be shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown won't display the ribbon of available filters.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchfiltersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchfiltersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchfiltersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"a2989b89c4b1644b":{"id":"com.apple.mcxmenuextras_eject.menu","displayName":"Eject","description":"If true, enables the Eject menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_eject.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_eject.menu_true","displayName":"True","description":null,"helpText":null}]},"a25caec4d6bbe701":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information.\n\nIf you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available.\n\nIf you disable this policy, then \"EdgeAutofillMlEnabled\" is turned off.\n\nIf you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"a2571e1d51fc24e9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsettings","displayName":"Configure extension management settings","description":"Setting this policy controls extension management settings for Microsoft Edge, including those configured by other extension-related policies. This policy supersedes any legacy policies.\n\nThis policy maps an extension ID or update URL to a specific configuration. You can define a default configuration using the special ID \"*\", which applies to extensions without a custom configuration.\n\nNote that any per-ID extension setting from either \"ExtensionInstallForcelist\", \"ExtensionInstallAllowlist\", \"ExtensionInstallBlocklist\", or \"ExtensionSettings\" will only inherit 'installation_mode' and 'update_url' from the \"*\" defaults. It will not inherit any other properties. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest. If the 'override_update_url' flag is set to true, the extension is installed and updated using the update URL specified in the \"ExtensionInstallForcelist\" policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is the Edge Add-ons website update URL. For more details, check out the detailed guide to ExtensionSettings policy available at https://go.microsoft.com/fwlink/?linkid=2161555.\n\nTo block extensions from a particular third party store, you only need to block the update_url for that store. For example, if you want to block extensions from Chrome Web Store, you can use the following JSON.\n\n{\"update_url:https://clients2.google.com/service/update2/crx\":{\"installation_mode\":\"blocked\"}}\n\nNote that you can still use \"ExtensionInstallForcelist\" and \"ExtensionInstallAllowlist\" to allow / force install specific extensions even if the store is blocked using the JSON in the previous example.\n\nIf the 'sidebar_auto_open_blocked' flag is set to true in an extension's configuration, the hub-app (sidebar app) corresponding to the specified extension will be prevented from automatically opening.\n\nOn Windows instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be forced installed if the instance is joined to a Microsoft Active Directory domain or joined to Microsoft Azure Active Directory®.\n\nOn macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, joined to a domain via MCX.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"a214e8c781088cf7":{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled","displayName":"Enable Gamer Mode (Obsolete)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\n\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\nIf you disable this policy, Gamer Mode is disabled.\nNote: With Microsoft Edge version 141, this policy is obsolete because the Gamer Mode feature is removed.","helpText":null,"infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"a2294f356f9cd65b":{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption","displayName":"Allow Standard User Encryption","description":"Allows Admin to enforce \"RequireDeviceEncryption\" policy for scenarios where policy is pushed while current logged on user is non-admin/standard user.\n \"AllowStandardUserEncryption\" policy is tied to \"AllowWarningForOtherDiskEncryption\" policy being set to \"0\", i.e, Silent encryption is enforced.\n If \"AllowWarningForOtherDiskEncryption\" is not set, or is set to \"1\", \"RequireDeviceEncryption\" policy will not try to encrypt drive(s) if a standard user\n is the current logged on user in the system.\n\n The expected values for this policy are: \n\n 1 = \"RequireDeviceEncryption\" policy will try to enable encryption on all fixed drives even if a current logged in user is standard user.\n 0 = This is the default, when the policy is not set. If current logged on user is a standard user, \"RequireDeviceEncryption\" policy\n will not try to enable encryption on any drive.\n\n If you want to disable this policy use the following SyncML:\n 111./Device/Vendor/MSFT/BitLocker/AllowStandardUserEncryptionint0","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption_0","displayName":"Disabled","description":"This is the default, when the policy is not set. If current logged on user is a standard user, \"RequireDeviceEncryption\" policy will not try to enable encryption on any drive.","helpText":null},{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption_1","displayName":"Enabled","description":"\"RequireDeviceEncryption\" policy will try to enable encryption on all fixed drives even if a current logged in user is standard user.","helpText":null}]},"a2c5a4581ad86c38":{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name","displayName":"Configure TPM startup:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_2","displayName":"Allow TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_1","displayName":"Require TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_0","displayName":"Do not allow TPM","description":null,"helpText":null}]},"a2b3790e33bb40e1":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix_dns_primarydnssuffixbox","displayName":"Enter a primary DNS suffix:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},"a2047622bc2eba00":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist","displayName":"Process Mitigation Options","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},"a24dfd60b3e4072e":{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_friendlyname_control","displayName":"Friendly Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},"a2af5d71b06331fa":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace","displayName":"Microsoft SharePoint Workspace 2010","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Workspace 2010.\r\nBy default, the user settings of Microsoft SharePoint Workspace 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Workspace 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Workspace 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Workspace 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointworkspace"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_1","displayName":"Enabled","description":null,"helpText":null}]},"a2435091986bfbb6":{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect","displayName":"Enable Windows to soft-disconnect a computer from a network","description":"This policy setting determines whether Windows will soft-disconnect a computer from a network.\r\n\r\nIf this policy setting is enabled or not configured, Windows will soft-disconnect a computer from a network when it determines that the computer should no longer be connected to a network.\r\n\r\nIf this policy setting is disabled, Windows will disconnect a computer from a network immediately when it determines that the computer should no longer be connected to a network.\r\n\r\nWhen soft disconnect is enabled:\r\n- When Windows decides that the computer should no longer be connected to a network, it waits for traffic to settle on that network. The existing TCP session will continue uninterrupted.\r\n- Windows then checks the traffic level on the network periodically. If the traffic level is above a certain threshold, no further action is taken. The computer stays connected to the network and continues to use it. For example, if the network connection is currently being used to download files from the Internet, the files will continue to be downloaded using that network connection.\r\n- When the network traffic drops below this threshold, the computer will be disconnected from the network. Apps that keep a network connection active even when they’re not actively using it (for example, email apps) might lose their connection. If this happens, these apps should re-establish their connection over a different network. \r\n\r\nThis policy setting depends on other group policy settings. For example, if 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is disabled, Windows will not disconnect from any networks.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wcm#admx-wcm-wcm-enablesoftdisconnect"],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"a2cea7dd75fdd134":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot_streaming_package_installation_root_prompt","displayName":"Package Installation Root","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},"a20af9fa98b46f60":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_insecureprivatenetworkrequestsallowedforurlsdesc","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"a2e4e328e38a00d6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended","displayName":"Default search provider name","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"a246582111e02186":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled","displayName":"List of types that should be excluded from synchronization","description":"If this policy is set all specified data types will be excluded from synchronization both for Chrome Sync as well as for roaming profile synchronization. This can be beneficial to reduce the size of the roaming profile or limit the type of data uploaded to the Chrome Sync Servers.\r\n\r\nThe current data types for this policy are: \"bookmarks\", \"readingList\", \"preferences\", \"passwords\", \"autofill\", \"themes\", \"typedUrls\", \"extensions\", \"apps\", \"tabs\", \"wifiConfigurations\". Those names are case sensitive!\r\n\r\nExample value:\r\n\r\nbookmarks","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a2ec3d93955b2ece":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode","displayName":"Force YouTube Safety Mode","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode_1","displayName":"Enabled","description":null,"helpText":null}]},"a21989420ed4d9df":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcnoprofilecontainingfolder","displayName":"No Profile Containing Folder","description":"VHD(x) file is placed and used in the root VHDLocation rather than in a SID directory under VHDLocation\r\n\r\nNOTE: This setting will override ANY OTHER setting related to container folders.\r\n\r\n- SIDDIRNameMatch has NO EFFECT when used in conjunction with this setting.\r\n- SIDDIRNamePattern has NO EFFECT when used in conjunction with this setting.\r\n- FlipFlopProfileDirectoryName has NO EFFECT when used in conjunction with this setting.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\NoProfileContainingFolder\r\nType: DWORD\r\nValues: 0 = Disable, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"81eb92d0-acda-4ea2-8183-29ed5457276b","categoryName":"Container and Directory Naming","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcnoprofilecontainingfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcnoprofilecontainingfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"a22bd945ea382092":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},"a2d348b0f3f98a97":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_extensionallowedtypesdesc","displayName":"Types of extensions/apps that are allowed to be installed (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"a27073578f746b44":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist","displayName":"Control which native messaging hosts users can use","description":"List specific native messaging hosts that users can use in Microsoft Edge.\r\n\r\nBy default, all native messaging hosts are allowed. If you set the 'NativeMessagingBlocklist' (Configure native messaging block list) policy to *, all native messaging hosts are blocked, and only native messaging hosts listed in here are loaded.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"a2db63d9248470f4":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a201fe0cdf54b7cf":{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\r\n\r\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\r\n\r\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' is not provided, the URL is used as the default title. If 'pinned' is not provided, the default value is false.\r\n\r\nMicrosoft Edge presents these in the order listed, from left to right, with all pinned tiles displayed ahead of non-pinned tiles.\r\n\r\nIf the policy is set as mandatory, the 'pinned' field will be ignored and all tiles will be pinned. The tiles can't be deleted by the user and will always appear at the front of the quick links list.\r\n\r\nIf the policy is set as recommended, pinned tiles will remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying non-pinned links via this policy to an existing browser profile, the links may not appear at all, depending on how they rank compared to the user's browsing history.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"pinned\": true,\r\n \"title\": \"Contoso Portal\",\r\n \"url\": \"https://contoso.com\"\r\n },\r\n {\r\n \"title\": \"Fabrikam\",\r\n \"url\": \"https://fabrikam.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_1","displayName":"Enabled","description":null,"helpText":null}]},"a2bef20df192af63":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled","displayName":"Control use of the Headless Mode","description":"This policy setting lets you decide whether users can launch Microsoft Edge in headless mode.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge allows use of the headless mode.\r\n\r\nIf you disable this policy, Microsoft Edge denies use of the headless mode.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a206a389ce2d0366":{"id":"device_vendor_msft_policy_config_power_enableenergysaver","displayName":"Enable Energy Saver","description":"This policy will extend battery life and reduce energy consumption by enabling Energy Saver to always be on. Energy Saver will always be on for desktops as well as laptops regardless of battery level for both AC and DC. If you disable or don't configure this policy setting, then Energy Saver will turn on based on the EnergySaverBatteryThreshold group policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#enableenergysaver"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":[{"id":"device_vendor_msft_policy_config_power_enableenergysaver_0","displayName":"Disable energy saver policy","description":"Disable energy saver policy","helpText":null},{"id":"device_vendor_msft_policy_config_power_enableenergysaver_1","displayName":"Enable energy saver always-on mode.","description":"Enable energy saver always-on mode.","helpText":null}]},"a2b3d751b6464dd2":{"id":"linux_mdatp_managed_antivirusengine_allowedthreats","displayName":"Allowed threats","description":"List of threats (identified by their name) that are not blocked by the product and are instead allowed to run.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-preferences?view=o365-worldwide#allowed-threats"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"a2d38fd85b4ab726":{"id":"passcode_requirepasscode","displayName":"Require Passcode on Device","description":"Specifies whether the user is forced to set a passcode. Setting this value, without any other keys present, forces the user to enter a passcode, without imposing a length or quality. The presence of any of the other keys implicitly requires a passcode be present on the device, and this key is ignored.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":[{"id":"passcode_requirepasscode_false","displayName":"False","description":null,"helpText":null},{"id":"passcode_requirepasscode_true","displayName":"True","description":null,"helpText":null}]},"a2fc160b6488bd6f":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon37","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"a281f5760c8767e4":{"id":"user_vendor_msft_policy_config_admx_taskbar_enablelegacyballoonnotifications","displayName":"Disable showing balloon notifications as toasts. (User)","description":"This policy disables the functionality that converts balloons to toast notifications. \r\n\r\nIf you enable this policy setting, system and application notifications will render as balloons instead of toast notifications. \r\n\r\nEnable this policy setting if a specific app or system component that uses balloon notifications has compatibility issues with toast notifications. \r\n\r\nIf you disable or don’t configure this policy setting, all notifications will appear as toast notifications.\r\n\r\nA reboot is required for this policy setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-enablelegacyballoonnotifications"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_enablelegacyballoonnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_enablelegacyballoonnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"a237d990c7442c51":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016","displayName":"Microsoft Office 365 Project 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Project 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Project 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Project 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Project 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Project 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365project2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_1","displayName":"Enabled","description":null,"helpText":null}]},"a256bcb353e6a983":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_defaultprinterselection","displayName":"Default printer selection rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},"a201d39a6d2779c7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"a2868b5dd08b3ce6":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout","displayName":"Delay before running idle actions (User)","description":"Triggers an action when the computer is idle.\r\n\r\nIf this policy is set, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\r\n\r\nIf this policy is not set, no action will be ran.\r\n\r\nThe minimum threshold is 1 minute.\r\n\r\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"a202999556bad60a":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration","displayName":"Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices. (User)","description":"This policy specifies how long (in seconds) a cast device that was previously selected via an access code or QR code can be seen within the Google Cast menu of cast devices.\r\nThe lifetime of an entry starts at the time the access code was first entered or the QR code was first scanned.\r\nDuring this period the cast device will appear in the Google Cast menu's list of cast devices.\r\nAfter this period, in order to use the cast device again the access code must be reentered or the QR code must be rescanned.\r\nBy default, the period is zero seconds, so cast devices will not stay in the Google Cast menu, and so the access code must be reentered, or the QR code rescanned, in order to initiate a new casting session.\r\nNote that this policy only affects how long a cast devices appears in the Google Cast menu, and has no effect on any ongoing cast session which will continue even if the period expires.\r\nThis policy has no effect unless the AccessCodeCastEnabled policy is Enabled.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_1","displayName":"Enabled","description":null,"helpText":null}]},"a2cc0836427f3455":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks","displayName":"Internet and network paths as hyperlinks (User)","description":"This policy setting determines whether Excel automatically creates hyperlinks when users enter URL or UNC path information.\r\n \r\nIf you enable this policy setting, when users type a string of characters that Excel recognizes as a Uniform Resource Locator (URL) or Uniform Naming Convention (UNC) path to a resource on the Internet or a local network, Excel will automatically transform it into a hyperlink. Clicking the hyperlink opens it in the configured default Web browser or the appropriate application.\r\n \r\nIf you disable this policy setting, Excel will not transform URLs and UNC paths to hyperlinks.\r\n \r\nIf you do not configure this policy setting, Excel will automatically transform URLs and UNC paths to hyperlinks and users can change the behavior by selecting or deselecting the \"Internet and network paths as hyperlinks\" check box under File tab | Help | Options | Proofing | AutoCorrect Options... | AutoFormat as You Type tab | Replace as you type.","helpText":"","infoUrls":[],"categoryId":"67eb1dab-7805-41bb-af5a-798dc7e29f23","categoryName":"Autocorrect Options","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},"a2e0ffc1ea553610":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells","displayName":"Stop checking for merged cells (User)","description":"This policy setting allows you to configure whether Accessibility Checker will verify that tables do not have merged cells.\r\n\r\nIf you enable this policy setting, no check will be made.\r\n\r\nIf you disable or do not configure this policy setting, worksheets will be checked for merged cells and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells_1","displayName":"Enabled","description":null,"helpText":null}]},"a2fa62346a091251":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"a29437d05ad2364a":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},"a28f59d2cac28031":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker","displayName":"Use Pop-up Blocker (User)","description":"This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.\n\nIf you enable this policy setting, most unwanted pop-up windows are prevented from appearing.\n\nIf you disable this policy setting, pop-up windows are not prevented from appearing.\n\nIf you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneusepopupblocker"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_1","displayName":"Enabled","description":null,"helpText":null}]},"a24cecfb693cdb10":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist_urlblocklistdesc","displayName":"Block access to a list of URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"a2362cb8fac232d6":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces (User)","description":"This setting lets you to define groups of URLs, and apply specific Microsoft Edge Workspaces navigation settings to each group.\r\n\r\nIf this policy is configured, Microsoft Edge Workspaces will use the configured settings when deciding whether and how to share navigations among collaborators in a Microsoft Edge Workspace.\r\n\r\nIf this policy is not configured, Microsoft Edge Workspaces will use only default and internally configured navigation settings.\r\n\r\nFor more information about configuration options, see https://go.microsoft.com/fwlink/?linkid=2218655\r\n\r\nNote, format url_patterns according to https://go.microsoft.com/fwlink/?linkid=2095322. You can configure the url_regex_patterns in this policy to match multiple URLs using a Perl style regular expression for the pattern. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"navigation_options\": {\r\n \"do_not_send_to\": true,\r\n \"remove_all_query_parameters\": true\r\n },\r\n \"url_patterns\": [\r\n \"https://contoso.com\",\r\n \"https://www.fabrikam.com\",\r\n \".exact.hostname.com\"\r\n ]\r\n },\r\n {\r\n \"navigation_options\": {\r\n \"query_parameters_to_remove\": [\r\n \"username\",\r\n \"login_hint\"\r\n ]\r\n },\r\n \"url_patterns\": [\r\n \"https://adatum.com\"\r\n ]\r\n },\r\n {\r\n \"navigation_options\": {\r\n \"do_not_send_from\": true,\r\n \"prefer_initial_url\": true\r\n },\r\n \"url_regex_patterns\": [\r\n \"\\\\Ahttps://.*?tafe\\\\..*?trs.*?\\\\.fabrikam.com/Sts\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"a267c0ef0208bddf":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled","displayName":"Allow MAM enrollment when managed device has Purview DLP policy configured (User)","description":"Controls whether Microsoft Edge allows Mobile Application Management (MAM) enrollment on managed devices when Microsoft Purview Data Loss Prevention (DLP) is configured.\r\n\r\nIf you enable this policy, MAM enrollment is allowed even when Purview DLP is detected on the device.\r\n\r\nIf you disable or don't configure this policy, MAM enrollment is blocked when Purview DLP is detected on the device.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a2562c667649d8aa":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},"a2b078c69fc00b82":{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 103.\r\n\r\nThis policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content when it's found to be incompatible with the change to remove the U2F Security Key API. It doesn't work in Microsoft Edge after version 103.\r\n\r\nIf you enable this policy, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\r\n\r\nIf you disable this policy or don't configure it, the U2F Security Key API is disabled by default and can only be used by sites that register for and use the U2FSecurityKeyAPI origin trial which ended after Microsoft Edge version 103.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a2fb5f6f9cea4230":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy_l_evictserverversionspolicydecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"a243b6b86717f1d8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish","displayName":"Turkish (User)","description":"Enables the editing language Turkish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish_1","displayName":"Enabled","description":null,"helpText":null}]},"a2b2d4cc82808de1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowcachename483","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"a28a1e16d1d73b9e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowfriendly456","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"a2296356b0ae5e18":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"a2447fb5bc0c573a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_datecolon311","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"a2d4edefca29b759":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"a239f9b400ef646a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging","displayName":"Turn on telemetry data collection (User)","description":"This policy setting allows you to turn on the data collection features in Office that are used by Office Telemetry Dashboard and Office Telemetry Log.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent and Office applications will collect telemetry data, which includes Office application usage, most recently used Office documents (including file names) and solutions usage, compatibility issues, and critical errors that occur on the local computers. You can use Office Telemetry Dashboard to view this data remotely, and users can use Office Telemetry Log to view this data on their local computers.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent and Office applications do not generate or collect telemetry data.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging_1","displayName":"Enabled","description":null,"helpText":null}]},"a2e41ac3af7b1bda":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage","displayName":"Tasks Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Tasks Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"a24c769e46ea88ba":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint","displayName":"Legacy converters for PowerPoint (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"a207c136af448f3f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes","displayName":"Minutes (User)","description":"Sets the label for minutes.\r\n\r\nIf you enable this setting, minutes are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_1","displayName":"Enabled","description":null,"helpText":null}]},"a2ce060d505a0455":{"id":"user_vendor_msft_policy_config_start_hidecategoryview","displayName":"Hide Category View (User)","description":"This policy setting allows you to hide the category view in the Start Menu. If you enable this policy setting, the Start Menu will no longer show the category view as an option and will default to grid view.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidecategoryview"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidecategoryview_0","displayName":"Category view shown.","description":"Category view shown.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidecategoryview_1","displayName":"Category view hidden.","description":"Category view hidden.","helpText":null}]},"a245012642664872":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"a211bec1d7cdde04":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"a2926c405cae6e32":{"id":"vendor_msft_sharedpc_diskleveldeletion","displayName":"Disk Level Deletion","description":"Accounts will start being deleted when available disk space falls below this threshold, given as percent of total disk capacity. Accounts that have been inactive the longest will be deleted first. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null}} \ No newline at end of file +{"a2af011318eae547":{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice","displayName":"Allow selection of a preferential network service","description":"If 'True', the device will give priority to the specified network service over other available options (e.g., enterprise slice on 5G networks). If 'False', Intune doesn't change or update this setting. By default, the device connects using its default network selection process. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":null,"infoUrls":[],"categoryId":"929c169a-3480-467c-9f47-d1836b359ef7","categoryName":"Connectivity","options":[{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice_false","displayName":"False","description":"Preferential network service is disabled.","helpText":null},{"id":"com.android.devicerestrictionpolicy.preferentialnetworkservice_true","displayName":"True","description":"Preferential network service is enabled on the device.","helpText":null}]},"a237003e5db2329a":{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp","displayName":"Block Wi-Fi setting changes","description":"If 'True', prevents users from creating or changing any Wi-Fi configurations. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to change the Wi-Fi settings on the device.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.wifiblockeditconfigurationsaosp_true","displayName":"True","description":"True","helpText":null}]},"a242d1db394b52f1":{"id":"com.apple.cellularprivatenetwork.managed_com.apple.cellularprivatenetwork.managed","displayName":"com.apple.cellularprivatenetwork.managed","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"a22aa39e7903d676":{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys","displayName":"Use Shared Device Keys","description":"If set to true, Platform SSO will use the same signing and encryption keys for all users.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_useshareddevicekeys_true","displayName":"Enabled","description":null,"helpText":null}]},"a22df545a5ba5bb7":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_windows app.app_application id","displayName":"Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"a2e0beb5dda09fa7":{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting","displayName":"Default JavaScript setting","description":"Set whether websites can run JavaScript. You can allow it for all sites (1) or block it for all sites (2).\n\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\n\n* 1 = Allow all sites to run JavaScript\n\n* 2 = Don't allow any site to run JavaScript","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultjavascriptsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting_0","displayName":"Allow all sites to run JavaScript","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultjavascriptsetting_1","displayName":"Don't allow any site to run JavaScript","description":null,"helpText":null}]},"a22f3ce083383e7f":{"id":"com.apple.managedclient.preferences_importopentabs","displayName":"Allow importing of open tabs","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\n\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importopentabs"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importopentabs_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importopentabs_true","displayName":"Enabled","description":null,"helpText":null}]},"a2fca6d1105f16cb":{"id":"com.apple.managedclient.preferences_searchfiltersenabled","displayName":"Search Filters Enabled","description":"Lets you filter your autosuggestions by selecting a filter from the search filters ribbon. For example, if you select the \"Favorites\" filter, only favorites suggestions will be shown.\n\nIf you enable or don't configure this policy, the autosuggestion dropdown defaults to displaying the ribbon of available filters.\n\nIf you disable this policy, the autosuggestion dropdown won't display the ribbon of available filters.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#searchfiltersenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_searchfiltersenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_searchfiltersenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"a2989b89c4b1644b":{"id":"com.apple.mcxmenuextras_eject.menu","displayName":"Eject","description":"If true, enables the Eject menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_eject.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_eject.menu_true","displayName":"True","description":null,"helpText":null}]},"a25caec4d6bbe701":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled","displayName":"Enable AutoFill for addresses","description":"Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information.\n\nIf you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available.\n\nIf you disable this policy, then \"EdgeAutofillMlEnabled\" is turned off.\n\nIf you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"a2571e1d51fc24e9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensionsettings","displayName":"Configure extension management settings","description":"Setting this policy controls extension management settings for Microsoft Edge, including those configured by other extension-related policies. This policy supersedes any legacy policies.\n\nThis policy maps an extension ID or update URL to a specific configuration. You can define a default configuration using the special ID \"*\", which applies to extensions without a custom configuration.\n\nNote that any per-ID extension setting from either \"ExtensionInstallForcelist\", \"ExtensionInstallAllowlist\", \"ExtensionInstallBlocklist\", or \"ExtensionSettings\" will only inherit 'installation_mode' and 'update_url' from the \"*\" defaults. It will not inherit any other properties. With an update URL, configuration applies to extensions with the exact update URL stated in the extension manifest. If the 'override_update_url' flag is set to true, the extension is installed and updated using the update URL specified in the \"ExtensionInstallForcelist\" policy or in 'update_url' field in this policy. The flag 'override_update_url' is ignored if the 'update_url' is the Edge Add-ons website update URL. For more details, check out the detailed guide to ExtensionSettings policy available at https://go.microsoft.com/fwlink/?linkid=2161555.\n\nTo block extensions from a particular third party store, you only need to block the update_url for that store. For example, if you want to block extensions from Chrome Web Store, you can use the following JSON.\n\n{\"update_url:https://clients2.google.com/service/update2/crx\":{\"installation_mode\":\"blocked\"}}\n\nNote that you can still use \"ExtensionInstallForcelist\" and \"ExtensionInstallAllowlist\" to allow / force install specific extensions even if the store is blocked using the JSON in the previous example.\n\nIf the 'sidebar_auto_open_blocked' flag is set to true in an extension's configuration, the hub-app (sidebar app) corresponding to the specified extension will be prevented from automatically opening.\n\nOn Windows instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be forced installed if the instance is joined to a Microsoft Active Directory domain or joined to Microsoft Azure Active Directory®.\n\nOn macOS instances, apps and extensions from outside the Microsoft Edge Add-ons website can only be force installed if the instance is managed via MDM, joined to a domain via MCX.\n\nStarting in Microsoft Edge version 149, the \"Microsoft365CopilotChatIconEnabled\" policy controls the display of Copilot in the toolbar.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"a214e8c781088cf7":{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled","displayName":"Enable Gamer Mode (Obsolete)","description":"Microsoft Edge Gamer Mode allows gamers to personalize their browser with gaming themes and gives them the option of enabling Efficiency Mode for PC gaming, the Gaming feed on new tabs, sidebar apps for gamers, and more.\n\nIf you enable or don't configure this policy, users can opt into Gamer Mode.\nIf you disable this policy, Gamer Mode is disabled.\nNote: With Microsoft Edge version 141, this policy is obsolete because the Gamer Mode feature is removed.","helpText":null,"infoUrls":[],"categoryId":"81c518f1-522e-4957-b850-e8a66d2ab215","categoryName":"Games settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.gamermodeenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"a2294f356f9cd65b":{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption","displayName":"Allow Standard User Encryption","description":"Allows Admin to enforce \"RequireDeviceEncryption\" policy for scenarios where policy is pushed while current logged on user is non-admin/standard user.\n \"AllowStandardUserEncryption\" policy is tied to \"AllowWarningForOtherDiskEncryption\" policy being set to \"0\", i.e, Silent encryption is enforced.\n If \"AllowWarningForOtherDiskEncryption\" is not set, or is set to \"1\", \"RequireDeviceEncryption\" policy will not try to encrypt drive(s) if a standard user\n is the current logged on user in the system.\n\n The expected values for this policy are: \n\n 1 = \"RequireDeviceEncryption\" policy will try to enable encryption on all fixed drives even if a current logged in user is standard user.\n 0 = This is the default, when the policy is not set. If current logged on user is a standard user, \"RequireDeviceEncryption\" policy\n will not try to enable encryption on any drive.\n\n If you want to disable this policy use the following SyncML:\n 111./Device/Vendor/MSFT/BitLocker/AllowStandardUserEncryptionint0","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","categoryName":"BitLocker","options":[{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption_0","displayName":"Disabled","description":"This is the default, when the policy is not set. If current logged on user is a standard user, \"RequireDeviceEncryption\" policy will not try to enable encryption on any drive.","helpText":null},{"id":"device_vendor_msft_bitlocker_allowstandarduserencryption_1","displayName":"Enabled","description":"\"RequireDeviceEncryption\" policy will try to enable encryption on all fixed drives even if a current logged in user is standard user.","helpText":null}]},"a2c5a4581ad86c38":{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name","displayName":"Configure TPM startup:","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_2","displayName":"Allow TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_1","displayName":"Require TPM","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configuretpmusagedropdown_name_0","displayName":"Do not allow TPM","description":null,"helpText":null}]},"a2b3790e33bb40e1":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_primarydnssuffix_dns_primarydnssuffixbox","displayName":"Enter a primary DNS suffix:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},"a2047622bc2eba00":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_processmitigationoptionslist","displayName":"Process Mitigation Options","description":null,"helpText":"","infoUrls":[],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":null},"a24dfd60b3e4072e":{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_friendlyname_control","displayName":"Friendly Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":null},"a2af5d71b06331fa":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace","displayName":"Microsoft SharePoint Workspace 2010","description":"This policy setting configures the synchronization of user settings for Microsoft SharePoint Workspace 2010.\r\nBy default, the user settings of Microsoft SharePoint Workspace 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Workspace 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Workspace 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Workspace 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010sharepointworkspace"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010sharepointworkspace_1","displayName":"Enabled","description":null,"helpText":null}]},"a2435091986bfbb6":{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect","displayName":"Enable Windows to soft-disconnect a computer from a network","description":"This policy setting determines whether Windows will soft-disconnect a computer from a network.\r\n\r\nIf this policy setting is enabled or not configured, Windows will soft-disconnect a computer from a network when it determines that the computer should no longer be connected to a network.\r\n\r\nIf this policy setting is disabled, Windows will disconnect a computer from a network immediately when it determines that the computer should no longer be connected to a network.\r\n\r\nWhen soft disconnect is enabled:\r\n- When Windows decides that the computer should no longer be connected to a network, it waits for traffic to settle on that network. The existing TCP session will continue uninterrupted.\r\n- Windows then checks the traffic level on the network periodically. If the traffic level is above a certain threshold, no further action is taken. The computer stays connected to the network and continues to use it. For example, if the network connection is currently being used to download files from the Internet, the files will continue to be downloaded using that network connection.\r\n- When the network traffic drops below this threshold, the computer will be disconnected from the network. Apps that keep a network connection active even when they’re not actively using it (for example, email apps) might lose their connection. If this happens, these apps should re-establish their connection over a different network. \r\n\r\nThis policy setting depends on other group policy settings. For example, if 'Minimize the number of simultaneous connections to the Internet or a Windows Domain' is disabled, Windows will not disconnect from any networks.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wcm#admx-wcm-wcm-enablesoftdisconnect"],"categoryId":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","categoryName":"Windows Connection Manager","options":[{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wcm_wcm_enablesoftdisconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"a2cea7dd75fdd134":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowpackageinstallationroot_streaming_package_installation_root_prompt","displayName":"Package Installation Root","description":"","helpText":"","infoUrls":[],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":null},"a20af9fa98b46f60":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_insecureprivatenetworkrequestsallowedforurls_insecureprivatenetworkrequestsallowedforurlsdesc","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"a2e4e328e38a00d6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended","displayName":"Default search provider name","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"a246582111e02186":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled","displayName":"List of types that should be excluded from synchronization","description":"If this policy is set all specified data types will be excluded from synchronization both for Chrome Sync as well as for roaming profile synchronization. This can be beneficial to reduce the size of the roaming profile or limit the type of data uploaded to the Chrome Sync Servers.\r\n\r\nThe current data types for this policy are: \"bookmarks\", \"readingList\", \"preferences\", \"passwords\", \"autofill\", \"themes\", \"typedUrls\", \"extensions\", \"apps\", \"tabs\", \"wifiConfigurations\". Those names are case sensitive!\r\n\r\nExample value:\r\n\r\nbookmarks","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_synctypeslistdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a2ec3d93955b2ece":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode","displayName":"Force YouTube Safety Mode","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_forceyoutubesafetymode_1","displayName":"Enabled","description":null,"helpText":null}]},"a21989420ed4d9df":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcnoprofilecontainingfolder","displayName":"No Profile Containing Folder","description":"VHD(x) file is placed and used in the root VHDLocation rather than in a SID directory under VHDLocation\r\n\r\nNOTE: This setting will override ANY OTHER setting related to container folders.\r\n\r\n- SIDDIRNameMatch has NO EFFECT when used in conjunction with this setting.\r\n- SIDDIRNamePattern has NO EFFECT when used in conjunction with this setting.\r\n- FlipFlopProfileDirectoryName has NO EFFECT when used in conjunction with this setting.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\NoProfileContainingFolder\r\nType: DWORD\r\nValues: 0 = Disable, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"81eb92d0-acda-4ea2-8183-29ed5457276b","categoryName":"Container and Directory Naming","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcnoprofilecontainingfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcnoprofilecontainingfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"a22bd945ea382092":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},"a2d348b0f3f98a97":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensionallowedtypes_extensionallowedtypesdesc","displayName":"Types of extensions/apps that are allowed to be installed (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"a27073578f746b44":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist","displayName":"Control which native messaging hosts users can use","description":"List specific native messaging hosts that users can use in Microsoft Edge.\r\n\r\nBy default, all native messaging hosts are allowed. If you set the 'NativeMessagingBlocklist' (Configure native messaging block list) policy to *, all native messaging hosts are blocked, and only native messaging hosts listed in here are loaded.\r\n\r\nExample value:\r\n\r\ncom.native.messaging.host.name1\r\ncom.native.messaging.host.name2","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"a2db63d9248470f4":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a201fe0cdf54b7cf":{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links","description":"By default, Microsoft Edge displays quick links on the new tab page from user-added shortcuts and top sites based on browsing history. With this policy, you can configure up to three quick link tiles on the new tab page, expressed as a JSON object:\r\n\r\n[ { \"url\": \"https://www.contoso.com\", \"title\": \"Contoso Portal\", \"pinned\": true/false }, ... ]\r\n\r\nThe 'url' field is required; 'title' and 'pinned' are optional. If 'title' is not provided, the URL is used as the default title. If 'pinned' is not provided, the default value is false.\r\n\r\nMicrosoft Edge presents these in the order listed, from left to right, with all pinned tiles displayed ahead of non-pinned tiles.\r\n\r\nIf the policy is set as mandatory, the 'pinned' field will be ignored and all tiles will be pinned. The tiles can't be deleted by the user and will always appear at the front of the quick links list.\r\n\r\nIf the policy is set as recommended, pinned tiles will remain in the list but the user has the ability to edit and delete them. Quick link tiles that aren't pinned behave like default top sites and are pushed off the list if other websites are visited more frequently. When applying non-pinned links via this policy to an existing browser profile, the links may not appear at all, depending on how they rank compared to the user's browsing history.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"pinned\": true,\r\n \"title\": \"Contoso Portal\",\r\n \"url\": \"https://contoso.com\"\r\n },\r\n {\r\n \"title\": \"Fabrikam\",\r\n \"url\": \"https://fabrikam.com\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_1","displayName":"Enabled","description":null,"helpText":null}]},"a2bef20df192af63":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled","displayName":"Control use of the Headless Mode","description":"This policy setting lets you decide whether users can launch Microsoft Edge in headless mode.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge allows use of the headless mode.\r\n\r\nIf you disable this policy, Microsoft Edge denies use of the headless mode.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_headlessmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a206a389ce2d0366":{"id":"device_vendor_msft_policy_config_power_enableenergysaver","displayName":"Enable Energy Saver","description":"This policy will extend battery life and reduce energy consumption by enabling Energy Saver to always be on. Energy Saver will always be on for desktops as well as laptops regardless of battery level for both AC and DC. If you disable or don't configure this policy setting, then Energy Saver will turn on based on the EnergySaverBatteryThreshold group policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#enableenergysaver"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":[{"id":"device_vendor_msft_policy_config_power_enableenergysaver_0","displayName":"Disable energy saver policy","description":"Disable energy saver policy","helpText":null},{"id":"device_vendor_msft_policy_config_power_enableenergysaver_1","displayName":"Enable energy saver always-on mode.","description":"Enable energy saver always-on mode.","helpText":null}]},"a2b3d751b6464dd2":{"id":"linux_mdatp_managed_antivirusengine_allowedthreats","displayName":"Allowed threats","description":"List of threats (identified by their name) that are not blocked by the product and are instead allowed to run.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-preferences?view=o365-worldwide#allowed-threats"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"a2d38fd85b4ab726":{"id":"passcode_requirepasscode","displayName":"Require Passcode on Device","description":"Specifies whether the user is forced to set a passcode. Setting this value, without any other keys present, forces the user to enter a passcode, without imposing a length or quality. The presence of any of the other keys implicitly requires a passcode be present on the device, and this key is ignored.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":[{"id":"passcode_requirepasscode_false","displayName":"False","description":null,"helpText":null},{"id":"passcode_requirepasscode_true","displayName":"True","description":null,"helpText":null}]},"a2fc160b6488bd6f":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon37","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"a281f5760c8767e4":{"id":"user_vendor_msft_policy_config_admx_taskbar_enablelegacyballoonnotifications","displayName":"Disable showing balloon notifications as toasts. (User)","description":"This policy disables the functionality that converts balloons to toast notifications. \r\n\r\nIf you enable this policy setting, system and application notifications will render as balloons instead of toast notifications. \r\n\r\nEnable this policy setting if a specific app or system component that uses balloon notifications has compatibility issues with toast notifications. \r\n\r\nIf you disable or don’t configure this policy setting, all notifications will appear as toast notifications.\r\n\r\nA reboot is required for this policy setting to take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-enablelegacyballoonnotifications"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_enablelegacyballoonnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_enablelegacyballoonnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"a237d990c7442c51":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016","displayName":"Microsoft Office 365 Project 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Project 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Project 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Project 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Project 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Project 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365project2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_1","displayName":"Enabled","description":null,"helpText":null}]},"a256bcb353e6a983":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_defaultprinterselection","displayName":"Default printer selection rules (User)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":null},"a201d39a6d2779c7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"a2868b5dd08b3ce6":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout","displayName":"Delay before running idle actions (User)","description":"Triggers an action when the computer is idle.\r\n\r\nIf this policy is set, it specifies the length of time without user input (in minutes) before the browser runs actions configured via the IdleTimeoutActions policy.\r\n\r\nIf this policy is not set, no action will be ran.\r\n\r\nThe minimum threshold is 1 minute.\r\n\r\n\"User input\" is defined by Operating System APIs, and includes things like moving the mouse or typing on the keyboard.","helpText":"","infoUrls":[],"categoryId":"8c35f124-e249-43e3-9044-ecc0b0a5855a","categoryName":"Idle Browser Actions","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~browseridle_idletimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"a202999556bad60a":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration","displayName":"Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices. (User)","description":"This policy specifies how long (in seconds) a cast device that was previously selected via an access code or QR code can be seen within the Google Cast menu of cast devices.\r\nThe lifetime of an entry starts at the time the access code was first entered or the QR code was first scanned.\r\nDuring this period the cast device will appear in the Google Cast menu's list of cast devices.\r\nAfter this period, in order to use the cast device again the access code must be reentered or the QR code must be rescanned.\r\nBy default, the period is zero seconds, so cast devices will not stay in the Google Cast menu, and so the access code must be reentered, or the QR code rescanned, in order to initiate a new casting session.\r\nNote that this policy only affects how long a cast devices appears in the Google Cast menu, and has no effect on any ongoing cast session which will continue even if the period expires.\r\nThis policy has no effect unless the AccessCodeCastEnabled policy is Enabled.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_1","displayName":"Enabled","description":null,"helpText":null}]},"a2cc0836427f3455":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks","displayName":"Internet and network paths as hyperlinks (User)","description":"This policy setting determines whether Excel automatically creates hyperlinks when users enter URL or UNC path information.\r\n \r\nIf you enable this policy setting, when users type a string of characters that Excel recognizes as a Uniform Resource Locator (URL) or Uniform Naming Convention (UNC) path to a resource on the Internet or a local network, Excel will automatically transform it into a hyperlink. Clicking the hyperlink opens it in the configured default Web browser or the appropriate application.\r\n \r\nIf you disable this policy setting, Excel will not transform URLs and UNC paths to hyperlinks.\r\n \r\nIf you do not configure this policy setting, Excel will automatically transform URLs and UNC paths to hyperlinks and users can change the behavior by selecting or deselecting the \"Internet and network paths as hyperlinks\" check box under File tab | Help | Options | Proofing | AutoCorrect Options... | AutoFormat as You Type tab | Replace as you type.","helpText":"","infoUrls":[],"categoryId":"67eb1dab-7805-41bb-af5a-798dc7e29f23","categoryName":"Autocorrect Options","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_proofing~l_autocorrectoptions_l_internetandnetworkpathsashyperlinks_1","displayName":"Enabled","description":null,"helpText":null}]},"a2e0ffc1ea553610":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells","displayName":"Stop checking for merged cells (User)","description":"This policy setting allows you to configure whether Accessibility Checker will verify that tables do not have merged cells.\r\n\r\nIf you enable this policy setting, no check will be made.\r\n\r\nIf you disable or do not configure this policy setting, worksheets will be checked for merged cells and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"d9b5c806-099f-4be8-96e4-1152e99cbf26","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_filetab~l_checkaccessibility_l_stopcheckingformergedcells_1","displayName":"Enabled","description":null,"helpText":null}]},"a2fa62346a091251":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls (User)","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"a29437d05ad2364a":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406","displayName":"Access data sources across domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowaccesstodatasources_iz_partname1406_1","displayName":"Prompt","description":null,"helpText":null}]},"a28f59d2cac28031":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker","displayName":"Use Pop-up Blocker (User)","description":"This policy setting allows you to manage whether unwanted pop-up windows appear. Pop-up windows that are opened when the end user clicks a link are not blocked.\n\nIf you enable this policy setting, most unwanted pop-up windows are prevented from appearing.\n\nIf you disable this policy setting, pop-up windows are not prevented from appearing.\n\nIf you do not configure this policy setting, most unwanted pop-up windows are prevented from appearing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneusepopupblocker"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneusepopupblocker_1","displayName":"Enabled","description":null,"helpText":null}]},"a2542f9a827aa6ba":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled","displayName":"Enable Process Isolation (User)","description":"This policy controls Process Isolation in Microsoft Edge.\n\nWhen this policy is enabled, Microsoft Edge uses Process Isolation to help improve browser security by preventing authorized applications on the device from reading or modifying the contents of Microsoft Edge's running processes. This also helps prevent other applications from accessing encrypted data used by Microsoft Edge.\n\nEnabling Process Isolation may cause incompatibilities with third party applications that rely on being able to inject or tamper with Microsoft Edge's processes, such as antivirus, screen reader or window manager applications.\n\nSetting the policy to Enabled turns on process isolation in Microsoft Edge.\n\nSetting the policy to Disabled turns off process isolation in Microsoft Edge.\n\nIf this policy is unset, Microsoft Edge will follow the default rollout process for the Process Isolation feature, which means that the feature will be gradually rolled out to an increasing number of users.\n\nNote: This policy is applied when Microsoft Edge starts. If the policy is changed while Microsoft Edge is running, the new setting will take effect on the next restart.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_processisolationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a24cecfb693cdb10":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlblocklist_urlblocklistdesc","displayName":"Block access to a list of URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"a2362cb8fac232d6":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings","displayName":"Configure navigation settings per groups of URLs in Microsoft Edge Workspaces (User)","description":"This setting lets you to define groups of URLs, and apply specific Microsoft Edge Workspaces navigation settings to each group.\r\n\r\nIf this policy is configured, Microsoft Edge Workspaces will use the configured settings when deciding whether and how to share navigations among collaborators in a Microsoft Edge Workspace.\r\n\r\nIf this policy is not configured, Microsoft Edge Workspaces will use only default and internally configured navigation settings.\r\n\r\nFor more information about configuration options, see https://go.microsoft.com/fwlink/?linkid=2218655\r\n\r\nNote, format url_patterns according to https://go.microsoft.com/fwlink/?linkid=2095322. You can configure the url_regex_patterns in this policy to match multiple URLs using a Perl style regular expression for the pattern. Note that pattern matches are case sensitive. For more information about the regular expression rules that are used, refer to https://go.microsoft.com/fwlink/p/?linkid=2133903.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"navigation_options\": {\r\n \"do_not_send_to\": true,\r\n \"remove_all_query_parameters\": true\r\n },\r\n \"url_patterns\": [\r\n \"https://contoso.com\",\r\n \"https://www.fabrikam.com\",\r\n \".exact.hostname.com\"\r\n ]\r\n },\r\n {\r\n \"navigation_options\": {\r\n \"query_parameters_to_remove\": [\r\n \"username\",\r\n \"login_hint\"\r\n ]\r\n },\r\n \"url_patterns\": [\r\n \"https://adatum.com\"\r\n ]\r\n },\r\n {\r\n \"navigation_options\": {\r\n \"do_not_send_from\": true,\r\n \"prefer_initial_url\": true\r\n },\r\n \"url_regex_patterns\": [\r\n \"\\\\Ahttps://.*?tafe\\\\..*?trs.*?\\\\.fabrikam.com/Sts\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~edgeworkspaces_workspacesnavigationsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"a267c0ef0208bddf":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled","displayName":"Allow MAM enrollment when managed device has Purview DLP policy configured (User)","description":"Controls whether Microsoft Edge allows Mobile Application Management (MAM) enrollment on managed devices when Microsoft Purview Data Loss Prevention (DLP) is configured.\r\n\r\nIf you enable this policy, MAM enrollment is allowed even when Purview DLP is detected on the device.\r\n\r\nIf you disable or don't configure this policy, MAM enrollment is blocked when Purview DLP is detected on the device.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~manageability_mamwithdevicedlpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a2562c667649d8aa":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_1","displayName":"Allow any site to run JavaScript JIT","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_defaultjavascriptjitsetting_defaultjavascriptjitsetting_2","displayName":"Do not allow any site to run JavaScript JIT","description":null,"helpText":null}]},"a2b078c69fc00b82":{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled","displayName":"Allow using the deprecated U2F Security Key API (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 103.\r\n\r\nThis policy is obsolete because it was intended to be a short-term mechanism to give enterprises more time to update their web content when it's found to be incompatible with the change to remove the U2F Security Key API. It doesn't work in Microsoft Edge after version 103.\r\n\r\nIf you enable this policy, the deprecated U2F Security Key API can be used and the deprecation reminder prompt shown for U2F API requests is suppressed.\r\n\r\nIf you disable this policy or don't configure it, the U2F Security Key API is disabled by default and can only be used by sites that register for and use the U2FSecurityKeyAPI origin trial which ended after Microsoft Edge version 103.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_u2fsecuritykeyapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"a2fb5f6f9cea4230":{"id":"user_vendor_msft_policy_config_office16~policy~l_microsoftofficesystem~l_miscellaneous437_l_evictserverversionspolicy_l_evictserverversionspolicydecimal","displayName":"Number of days (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":null},"a243b6b86717f1d8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish","displayName":"Turkish (User)","description":"Enables the editing language Turkish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkish_1","displayName":"Enabled","description":null,"helpText":null}]},"a2b2d4cc82808de1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowcachename483","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"a28a1e16d1d73b9e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache6_l_workflowfriendly456","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"a2296356b0ae5e18":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey14_l_certhashcolon","displayName":"Certificate Hash: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":null},"a2447fb5bc0c573a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_datecolon311","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"a2d4edefca29b759":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog01_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"a239f9b400ef646a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging","displayName":"Turn on telemetry data collection (User)","description":"This policy setting allows you to turn on the data collection features in Office that are used by Office Telemetry Dashboard and Office Telemetry Log.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent and Office applications will collect telemetry data, which includes Office application usage, most recently used Office documents (including file names) and solutions usage, compatibility issues, and critical errors that occur on the local computers. You can use Office Telemetry Dashboard to view this data remotely, and users can use Office Telemetry Log to view this data on their local computers.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent and Office applications do not generate or collect telemetry data.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_enablelogging_1","displayName":"Enabled","description":null,"helpText":null}]},"a2e41ac3af7b1bda":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage","displayName":"Tasks Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Tasks Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_tasksfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"a24c769e46ea88ba":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint","displayName":"Legacy converters for PowerPoint (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save PowerPoint files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"4d69af55-f100-45fa-92e1-56d46434c647","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_fileblocksettings_l_legacyconvertersforpowerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"a207c136af448f3f":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes","displayName":"Minutes (User)","description":"Sets the label for minutes.\r\n\r\nIf you enable this setting, minutes are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjminutes_1","displayName":"Enabled","description":null,"helpText":null}]},"a2ce060d505a0455":{"id":"user_vendor_msft_policy_config_start_hidecategoryview","displayName":"Hide Category View (User)","description":"This policy setting allows you to hide the category view in the Start Menu. If you enable this policy setting, the Start Menu will no longer show the category view as an option and will default to grid view.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hidecategoryview"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"user_vendor_msft_policy_config_start_hidecategoryview_0","displayName":"Category view shown.","description":"Category view shown.","helpText":null},{"id":"user_vendor_msft_policy_config_start_hidecategoryview_1","displayName":"Category view hidden.","description":"Category view hidden.","helpText":null}]},"a245012642664872":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc07_l_pathcolon32","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"a211bec1d7cdde04":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments","displayName":"Turn off trusted documents (User)","description":"This policy setting allows you to turn off the trusted documents feature. The trusted documents feature allows users to always enable active content in documents such as macros, ActiveX controls, data connections, etc. so that they are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.\r\n\r\nIf you enable this policy setting, you will turn off the trusted documents feature. Users will receive a security prompt every time a document containing active content is opened.\r\n\r\nIf you disable or do not configure this policy setting, documents will be trusted when users enable content for a document, and users will not receive a security prompt.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_turnofftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"a2926c405cae6e32":{"id":"vendor_msft_sharedpc_diskleveldeletion","displayName":"Disk Level Deletion","description":"Accounts will start being deleted when available disk space falls below this threshold, given as percent of total disk capacity. Accounts that have been inactive the longest will be deleted first. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/ac.json b/public/intune-definitions/ac.json index 920fde2d1bd9..243fa5fb7637 100644 --- a/public/intune-definitions/ac.json +++ b/public/intune-definitions/ac.json @@ -1 +1 @@ -{"ac4e110c2611ae92":{"id":"com.apple.managedclient.preferences_proxymode","displayName":"Configure proxy server settings","description":"Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.\n\nIf you choose to never use a proxy server and to always connect directly, all other options are ignored.\n\nIf you choose to use system proxy settings, all other options are ignored.\n\nIf you choose to auto detect the proxy server, all other options are ignored.\n\nIf you choose fixed server proxy mode, you can specify further options in \"ProxyServer\" and 'Comma-separated list of proxy bypass rules'.\n\nIf you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.\n\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\n\nIf you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.\n\nIf you don't configure this policy users can choose their own proxy settings.\n\n* \"direct\" = Never use a proxy\n\n* \"auto_detect\" = Auto detect proxy settings\n\n* \"pac_script\" = Use a .pac proxy script\n\n* \"fixed_servers\" = Use fixed proxy servers\n\n* \"system\" = Use system proxy settings","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proxymode_0","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_1","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_2","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_3","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_4","displayName":"Use system proxy settings","description":null,"helpText":null}]},"ac0b6ab8ce28dc64":{"id":"com.apple.managedclient.preferences_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\n\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\n\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#verticaltabsallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_verticaltabsallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_verticaltabsallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"acaa194fc1482253":{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever","displayName":"Warn On Create Allow Never","description":"If true, allows the user to stop the prompts about mobile account creation every time the user logs in. This key is only valid if Warn On Create is set to true.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever_true","displayName":"True","description":null,"helpText":null}]},"ac9d0580aea387fa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings","displayName":"Print preview sticky settings","description":"Specifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages.\n\nIf you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages.\n\nIf you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF.\n\nThis policy is only available if you enable or don't configure the \"PrintingEnabled\" policy.\n\nPolicy options mapping:\n\n* EnableAll (0) = Enable sticky settings for PDF and Webpages\n\n* DisableAll (1) = Disable sticky settings for PDF and Webpages\n\n* DisablePdf (2) = Disable sticky settings for PDF\n\n* DisableWebpage (3) = Disable sticky settings for Webpages\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_enableall","displayName":"Enable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disableall","displayName":"Disable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disablepdf","displayName":"Disable sticky settings for PDF","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disablewebpage","displayName":"Disable sticky settings for Webpages","description":null,"helpText":null}]},"ac8878251bb29720":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_computersid","displayName":"Computer Sid","description":"Local computer Sid or computer Sid group or the Sid of the AD object, defines whether to apply this policy over a specific machine or machine group; one entry can have a maximum of one ComputerSid and an entry without any ComputerSid means applying the policy over the machine. If you want to apply an Entry to a specific user and specific machine, add both Sid and ComputerSid into the same Entry.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},"ac518b022cddf98b":{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_maximumattempts","displayName":"Maximum Attempts (Windows Insiders only)","description":"How many times profile download should be attempted before giving up. A value of 0 indicates unlimited retry attempts. When a value is not specified, it defaults to 50, which is equivalent to about a month of retry attempts.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},"ac93661e6689fdc3":{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_allowsavedcredentialswhenntlmonly_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},"ac0364a7bbedd330":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime","displayName":"Time (in seconds) to force reboot when required for policy changes to take effect","description":"This policy setting establishes the amount of time (in seconds) that the system will wait to reboot in order to enforce a change in device installation restriction policies.\r\n\r\nIf you enable this policy setting, set the amount of seconds you want the system to wait until a reboot.\r\n\r\nIf you disable or do not configure this policy setting, the system does not force a reboot.\r\n\r\nNote: If no reboot is forced, the device installation restriction right will not take effect until the system is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-policy-reboottime"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_1","displayName":"Enabled","description":null,"helpText":null}]},"aca5336ac6ccf19c":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel","displayName":"Primary DNS suffix devolution level","description":"Specifies if the devolution level that DNS clients will use if they perform primary DNS suffix devolution during the name resolution process.\r\n\r\nWith devolution, a DNS client creates queries by appending a single-label, unqualified domain name with the parent suffix of the primary DNS suffix name, and the parent of that suffix, and so on, stopping if the name is successfully resolved or at a level determined by devolution settings. Devolution can be used when a user or application submits a query for a single-label domain name.\r\n\r\nThe DNS client appends DNS suffixes to the single-label, unqualified domain name based on the state of the Append primary and connection specific DNS suffixes radio button and Append parent suffixes of the primary DNS suffix check box on the DNS tab in Advanced TCP/IP Settings for the Internet Protocol (TCP/IP) Properties dialog box.\r\n\r\nDevolution is not enabled if a global suffix search list is configured using Group Policy.\r\n\r\nIf a global suffix search list is not configured, and the Append primary and connection specific DNS suffixes radio button is selected, the DNS client appends the following names to a single-label name when it sends DNS queries:\r\n\r\nThe primary DNS suffix, as specified on the Computer Name tab of the System control panel.\r\n\r\nEach connection-specific DNS suffix, assigned either through DHCP or specified in the DNS suffix for this connection box on the DNS tab in the Advanced TCP/IP Settings dialog box for each connection.\r\n\r\nFor example, when a user submits a query for a single-label name such as \"example,\" the DNS client attaches a suffix such as \"microsoft.com\" resulting in the query \"example.microsoft.com,\" before sending the query to a DNS server.\r\n\r\nIf a DNS suffix search list is not specified, the DNS client attaches the primary DNS suffix to a single-label name. If this query fails, the connection-specific DNS suffix is attached for a new query. If none of these queries are resolved, the client devolves the primary DNS suffix of the computer (drops the leftmost label of the primary DNS suffix), attaches this devolved primary DNS suffix to the single-label name, and submits this new query to a DNS server.\r\n\r\nFor example, if the primary DNS suffix ooo.aaa.microsoft.com is attached to the non-dot-terminated single-label name \"example,\" and the DNS query for example.ooo.aaa.microsoft.com fails, the DNS client devolves the primary DNS suffix (drops the leftmost label) till the specified devolution level, and submits a query for example.aaa.microsoft.com. If this query fails, the primary DNS suffix is devolved further if it is under specified devolution level and the query example.microsoft.com is submitted. If this query fails, devolution continues if it is under specified devolution level and the query example.microsoft.com is submitted, corresponding to a devolution level of two. The primary DNS suffix cannot be devolved beyond a devolution level of two. The devolution level can be configured using this policy setting. The default devolution level is two.\r\n\r\nIf you enable this policy setting and DNS devolution is also enabled, DNS clients use the DNS devolution level that you specify.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, DNS clients use the default devolution level of two provided that DNS devolution is enabled.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-domainnamedevolutionlevel"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},"ac41f563baf255ce":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled","displayName":"Dynamic update","description":"Specifies if DNS dynamic update is enabled. Computers configured for DNS dynamic update automatically register and update their DNS resource records with a DNS server.\r\n\r\nIf you enable this policy setting, or you do not configure this policy setting, computers will attempt to use dynamic DNS registration on all network connections that have connection-specific dynamic DNS registration enabled. For a dynamic DNS registration to be enabled on a network connection, the connection-specific configuration must allow dynamic DNS registration, and this policy setting must not be disabled.\r\n\r\nIf you disable this policy setting, computers may not use dynamic DNS registration for any of their network connections, regardless of the configuration for individual network connections.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationenabled"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"acb2282b180bc80e":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions","displayName":"MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged","description":"MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxconnectresponseretransmissions"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_1","displayName":"Enabled","description":null,"helpText":null}]},"ac419ed79ad4e392":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod","displayName":"Use initial DC discovery retry setting for background callers","description":"This policy setting determines the amount of time (in seconds) to wait before the first retry for applications that perform periodic searches for domain controllers (DC) that are unable to find a DC.\r\n\r\nThe default value for this setting is 10 minutes (10*60). The maximum value for this setting is 49 days (0x49*24*60*60=4233600). The minimum value for this setting is 0.\r\n\r\nThis setting is relevant only to those callers of DsGetDcName that have specified the DS_BACKGROUND_ONLY flag.\r\n\r\nIf the value of this setting is less than the value specified in the NegativeCachePeriod subkey, the value in the NegativeCachePeriod subkey is used.\r\n\r\nWarning: If the value for this setting is too large, a client will not attempt to find any DCs that were initially unavailable. If the value set in this setting is very small and the DC is not available, the traffic caused by periodic DC discoveries may be excessive.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundretryinitialperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"acaa2fd9f07a28cb":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources","displayName":"Configure extension, app, and user script install sources","description":"Setting the policy specifies which URLs may install extensions, apps, and themes. Before Google Chrome 21, users could click on a link to a *.crx file, and Google Chrome would offer to install the file after a few warnings. Afterwards, such files must be downloaded and dragged to the Google Chrome settings page. This setting allows specific URLs to have the old, easier installation flow.\r\n\r\nEach item in this list is an extension-style match pattern (see https://developer.chrome.com/extensions/match_patterns). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (the referrer) must be allowed by these patterns.\r\n\r\nExtensionInstallBlocklist takes precedence over this policy. That is, an extension on the blocklist won't be installed, even if it happens from a site on this list.\r\n\r\nExample value:\r\n\r\nhttps://corp.mycompany.com/*","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_1","displayName":"Enabled","description":null,"helpText":null}]},"ac60a6b9095cf62a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_remoteaccesshostclipboardsizebytes","displayName":"The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},"acd4c008083620f6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled","displayName":"Enable sending downloads to Google for deep scanning for users enrolled in the Advanced Protection program","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"acd7b9f2da07c9a5":{"id":"device_vendor_msft_policy_config_dataprotection_allowdirectmemoryaccess","displayName":"Allow Direct Memory Access","description":"This policy setting allows you to block direct memory access (DMA) for all hot pluggable PCI downstream ports until a user logs into Windows. Once a user logs in, Windows will enumerate the PCI devices connected to the host plug PCI ports. Every time the user locks the machine, DMA will be blocked on hot plug PCI ports with no children devices until the user logs in again. Devices which were already enumerated when the machine was unlocked will continue to function until unplugged. This policy setting is only enforced when BitLocker Device Encryption is enabled. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-dataprotection#allowdirectmemoryaccess"],"categoryId":"22f2b16b-e1af-45fa-8d2f-687854b72c02","categoryName":"Data Protection","options":[{"id":"device_vendor_msft_policy_config_dataprotection_allowdirectmemoryaccess_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_dataprotection_allowdirectmemoryaccess_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"ac2142d835527d0d":{"id":"device_vendor_msft_policy_config_deliveryoptimization_doallowvpnpeercaching","displayName":"DO Allow VPN Peer Caching","description":"Specifies whether the device, with an active VPN connection, is allowed to participate in P2P or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#doallowvpnpeercaching"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":[{"id":"device_vendor_msft_policy_config_deliveryoptimization_doallowvpnpeercaching_0","displayName":"Not allowed","description":"Not allowed","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_doallowvpnpeercaching_1","displayName":"Allowed","description":"Allowed","helpText":null}]},"acbf1a9b0f15a725":{"id":"device_vendor_msft_policy_config_experience_donotshowfeedbacknotifications","displayName":"Do Not Show Feedback Notifications","description":"Prevents devices from showing feedback questions from Microsoft. If you enable this policy setting, users will no longer see feedback notifications through the Feedback hub app. If you disable or do not configure this policy setting, users may see notifications through the Feedback hub app asking users for feedback. If you disable or do not configure this policy setting, users can control how often they receive feedback questions.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#donotshowfeedbacknotifications"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_donotshowfeedbacknotifications_0","displayName":"Feedback notifications are not disabled. The actual state of feedback notifications on the device will then depend on what GP has configured or what the user has configured locally.","description":"Feedback notifications are not disabled. The actual state of feedback notifications on the device will then depend on what GP has configured or what the user has configured locally.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_donotshowfeedbacknotifications_1","displayName":"Feedback notifications are disabled.","description":"Feedback notifications are disabled.","helpText":null}]},"ac7880e379f377cc":{"id":"device_vendor_msft_policy_config_internetexplorer_disablecompatview","displayName":"Turn off Compatibility View","description":"This policy setting controls the Compatibility View feature, which allows the user to fix website display problems that he or she may encounter while browsing.\n\nIf you enable this policy setting, the user cannot use the Compatibility View button or manage the Compatibility View sites list.\n\nIf you disable or do not configure this policy setting, the user can use the Compatibility View button and manage the Compatibility View sites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecompatview"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablecompatview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablecompatview_1","displayName":"Enabled","description":null,"helpText":null}]},"ac63c2b8dae83b1c":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"ac4a0de2c4606e01":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"acd90ca8cd1c4dc8":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_downloaddirectory","displayName":"Set download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"ac5145f31623dbc0":{"id":"device_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_typosquattingallowlistdomainsdesc","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":null},"ac83470d05885a69":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays_internetexplorerintegrationlocalsitelistexpirationdays","displayName":"Specify the number of days that a site remains on the local IE mode site list: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"acebc1393f7615ff":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer_configureviewinfileexplorer","displayName":"Configure the View in File Explorer feature for SharePoint pages in Microsoft Edge (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"acb5061c89c6a6e0":{"id":"device_vendor_msft_policy_config_mssecurityguide_configuresmbv1server","displayName":"Configure SMB v1 server","description":"Disabling this setting disables server-side processing of the SMBv1 protocol. (Recommended.)\n\nEnabling this setting enables server-side processing of the SMBv1 protocol. (Default.)\n\nChanges to this setting require a reboot to take effect.\n\nFor more information, see https://support.microsoft.com/kb/2696547\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-mssecurityguide#mssecurityguide-configuresmbv1server"],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_mssecurityguide_configuresmbv1server_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_mssecurityguide_configuresmbv1server_1","displayName":"Enabled","description":null,"helpText":null}]},"ac78627bed84090b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_outlookexe190","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_outlookexe190_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_outlookexe190_1","displayName":"True","description":null,"helpText":null}]},"ac8fc9da39293b70":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_msaccessexe","displayName":"msaccess.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_msaccessexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_msaccessexe_1","displayName":"True","description":null,"helpText":null}]},"ac0cfe06c6b0e066":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_meteredupdatesmicrosoftedgedev_part_meteredupdatespolicy","displayName":"Metered Updates Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"13f62499-a266-42c8-a4dc-531efcea55cb","categoryName":"Microsoft Edge Dev","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_meteredupdatesmicrosoftedgedev_part_meteredupdatespolicy_1","displayName":"Metered Disable updates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_meteredupdatesmicrosoftedgedev_part_meteredupdatespolicy_2","displayName":"Metered Updates Allowed","description":null,"helpText":null}]},"ac77d05b84004d63":{"id":"device_vendor_msft_policy_config_userrights_changetimezone","displayName":"Change Time Zone","description":"This user right determines which users and groups can change the time zone used by the computer for displaying the local time, which is the computer's system time plus the time zone offset. System time itself is absolute and is not affected by a change in the time zone. \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#changetimezone"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"ac48173071041b1e":{"id":"device_vendor_msft_remoteremediation_cloudremediationsettings_networksettings_networkcredentials_networkpassword","displayName":"Network Password (Windows Insiders only)","description":"Refers to the password for the wifi network that the device will attempt to connect to during remediation. If a password is set without a SSID, then this will be ignored.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/RemoteRemediation-csp/"],"categoryId":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","categoryName":"Remote Remediation","options":null},"acae6102b4b53649":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon31","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"acf4871da8bca7a2":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},"acd9e99e6c61b8dc":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","categoryName":"Miscellaneous","options":null},"ac429b1e52a97e06":{"id":"user_vendor_msft_policy_config_admx_desktop_wallpaper_wallpapername","displayName":"Wallpaper Name: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":null},"ac4c46f5eac13ef6":{"id":"user_vendor_msft_policy_config_admx_eaime_l_restrictcharactercoderangeofconversion","displayName":"Restrict character code range of conversion (User)","description":"This policy setting allows you to restrict character code range of conversion by setting character filter.\r\n\r\nIf you enable this policy setting, then only the character code ranges specified by this policy setting are used for conversion of IME. You can specify multiple ranges by setting a value combined with a bitwise OR of following values:\r\n\r\n0x0001 // JIS208 area\r\n0x0002 // NEC special char code\r\n0x0004 // NEC selected IBM extended code\r\n0x0008 // IBM extended code\r\n0x0010 // Half width katakana code\r\n0x0100 // EUDC(GAIJI)\r\n0x0200 // S-JIS unmapped area\r\n0x0400 // Unicode char\r\n0x0800 // surrogate char\r\n0x1000 // IVS char\r\n0xFFFF // no definition.\r\n\r\nIf you disable or do not configure this policy setting, no range of characters are filtered by default.\r\n\r\nThis policy setting applies to Japanese Microsoft IME only.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eaime#admx-eaime-l-restrictcharactercoderangeofconversion"],"categoryId":"7d331987-7e2d-4975-b23b-d99a5af26ddf","categoryName":"IME","options":[{"id":"user_vendor_msft_policy_config_admx_eaime_l_restrictcharactercoderangeofconversion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_eaime_l_restrictcharactercoderangeofconversion_1","displayName":"Enabled","description":null,"helpText":null}]},"acfc06b6b332ccd5":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_devicemanager_2","displayName":"Device Manager (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-devicemanager-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_devicemanager_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_devicemanager_2_1","displayName":"Enabled","description":null,"helpText":null}]},"ac4e67392773816e":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_diskdefrag","displayName":"Disk Defragmenter (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-diskdefrag"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_diskdefrag_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_diskdefrag_1","displayName":"Enabled","description":null,"helpText":null}]},"acbfc14d267feda2":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word","displayName":"Microsoft Word 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Word 2016.\r\nBy default, the user settings of Microsoft Word 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word_1","displayName":"Enabled","description":null,"helpText":null}]},"aceb547fcb7f7c1c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT enabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"ac7d5302ee5a0841":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_remoteaccesshostclientdomainlistdesc","displayName":"Configure the required domain names for remote access clients (User)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},"ac9b6d663e30336d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_1","displayName":"Enabled","description":null,"helpText":null}]},"acff216b531b4768":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction","displayName":"Enable or disable the User-Agent Reduction. (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_1","displayName":"Enabled","description":null,"helpText":null}]},"ac6c8481b4984d7a":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation","displayName":"File tab | Options | Customize Ribbon | All Commands | Document Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation_1","displayName":"True","description":null,"helpText":null}]},"acf5b74abc6e60dc":{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles","displayName":"Always prevent untrusted Microsoft Query files from opening (User)","description":"This policy setting controls whether Microsoft Query files (.iqy, oqy, .dqy, and .rqy) in an untrusted location are prevented from opening.\r\n\r\nIf you enable this policy setting, Microsoft Query files in an untrusted location are prevented from opening. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nIf you disable or don’t configure this policy setting, Microsoft Query files in an untrusted location are not prevented from opening, unless users have changed this setting in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"acf8f84fc44bdaed":{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation","displayName":"Turn off browser geolocation (User)","description":"This policy setting allows you to disable browser geolocation support. This will prevent websites from requesting location data about the user.\n\nIf you enable this policy setting, browser geolocation support is turned off.\n\nIf you disable this policy setting, browser geolocation support is turned on.\n\nIf you do not configure this policy setting, browser geolocation support can be turned on or off in Internet Options on the Privacy tab.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablegeolocation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation_1","displayName":"Enabled","description":null,"helpText":null}]},"ac867124bd52dc4c":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture fingerprint of password (User)","description":"Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the fingerprint of passwords and use it for password reuse detection.\r\n\r\nIf you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs.\r\n\r\nIf you disable this policy or don't configure it, no password fingerprints are captured.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com/login.html\r\nhttps://login.contoso.com","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_1","displayName":"Enabled","description":null,"helpText":null}]},"ac7251379b1ccb39":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended","displayName":"Allow users to be alerted if their passwords are found to be unsafe (User)","description":"Allow Microsoft Edge to monitor user passwords.\r\n\r\nIf you enable this policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\r\n\r\nIf you disable this policy, users will not be asked for permission to enable this feature. Their passwords will not be scanned and they will not be alerted either.\r\n\r\nIf you don't configure the policy, users can turn this feature on or off.\r\n\r\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\r\n\r\nAdditional guidance:\r\n\r\nThis policy can be set as both Recommended as well as Mandatory, however with an important callout.\r\n\r\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\r\n\r\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\r\n\r\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"acf5dd5f9084833e":{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages","displayName":"Define an ordered list of preferred languages that websites should display in if the site supports the language (User)","description":"Configures the language variants that Microsoft Edge sends to websites as part of the Accept-Language request HTTP header and prevents users from adding, removing, or changing the order of preferred languages in Microsoft Edge settings. Users who want to change the languages Microsoft Edge displays in or offers to translate pages to will be limited to the languages configured in this policy.\r\n\r\nIf you enable this policy, websites will appear in the first language in the list that they support unless other site-specific logic is used to determine the display language. The language variants defined in this policy override the languages configured as part of the 'SpellcheckLanguage' (Enable specific spellcheck languages) policy.\r\n\r\nIf you don't configure or disable this policy, Microsoft Edge sends websites the user-specified preferred languages as part of the Accept-Language request HTTP header.\r\n\r\nFor detailed information on valid language variants, see https://go.microsoft.com/fwlink/?linkid=2148854.\r\n\r\nExample value: en-US,fr,es","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_1","displayName":"Enabled","description":null,"helpText":null}]},"acb4a1f53d4df4ff":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8","displayName":"Places Bar Location 8 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_1","displayName":"Enabled","description":null,"helpText":null}]},"ac91ab607d05efbf":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},"ac76a8e35d80cfef":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext","displayName":"Read e-mail as plain text (User)","description":"This policy setting determines whether Outlook renders all e-mail messages in plain text format for reading.Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. \r\n\r\nIf you enable this policy setting, the \"Read all standard mail in plain text\" check box option is selected in the \"E-mail Security\" section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays e-mail messages in whatever format they were received in.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext_1","displayName":"Enabled","description":null,"helpText":null}]},"ac4cc81f86cd6bb4":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour","displayName":"Hyperlink color (User)","description":"Specifies the color of hyperlinks that have not yet been followed.\r\n \r\nIf you enable this setting, hyperlinks that have not been followed are displayed in the color you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_1","displayName":"Enabled","description":null,"helpText":null}]},"ac3c654d2df2cd8a":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help_l_helpcolon","displayName":"Help: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},"ac7e7b626fc982ce":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc","displayName":"Disable Real Time Coauthoring for Word (User)","description":"This policy lets admins disable Real Time Coauthoring. They may want to do so if they have solutions that are not compatible with some elements of real time coauthoring, such as add-ins that would trigger too often due to Real Time Coauthoring causing the frequent saving of user content. \r\n\r\nIf you enable this policy setting, it will prevent Real Time Coauthoring. \r\n\r\nIf you disable or do not configure this policy setting, users will be able to experience Real Time Coauthoring feature.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc_1","displayName":"Enabled","description":null,"helpText":null}]},"ac30086d22210aef":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles","displayName":"Add Bi-Directional Marks when saving Text files (User)","description":"Checked: Add Bi-Directional Marks when saving Text files. | Unchecked: Do not add Bi-Directional Marks when saving Text files.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"aca00a0c1e025a7b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Word files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"ac256630aca9b908":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"aceded718d9d0f64":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_localuserauthorizedlist","displayName":"Local User Authorized List","description":"Specifies the list of authorized local users for this rule. A list of authorized users cannot be specified if the rule being authored is targeting a Windows service. If not specified, the default is all users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file +{"ac4e110c2611ae92":{"id":"com.apple.managedclient.preferences_proxymode","displayName":"Configure proxy server settings","description":"Specify the proxy server settings used by Microsoft Edge. If you enable this policy, users can't change the proxy settings.\n\nIf you choose to never use a proxy server and to always connect directly, all other options are ignored.\n\nIf you choose to use system proxy settings, all other options are ignored.\n\nIf you choose to auto detect the proxy server, all other options are ignored.\n\nIf you choose fixed server proxy mode, you can specify further options in \"ProxyServer\" and 'Comma-separated list of proxy bypass rules'.\n\nIf you choose to use a .pac proxy script, you must specify the URL to the script in 'URL to a proxy .pac file'.\n\nFor detailed examples, go to https://go.microsoft.com/fwlink/?linkid=2094936.\n\nIf you enable this policy, Microsoft Edge will ignore all proxy-related options specified from the command line.\n\nIf you don't configure this policy users can choose their own proxy settings.\n\n* \"direct\" = Never use a proxy\n\n* \"auto_detect\" = Auto detect proxy settings\n\n* \"pac_script\" = Use a .pac proxy script\n\n* \"fixed_servers\" = Use fixed proxy servers\n\n* \"system\" = Use system proxy settings","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#proxymode"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_proxymode_0","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_1","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_2","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_3","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_proxymode_4","displayName":"Use system proxy settings","description":null,"helpText":null}]},"ac0b6ab8ce28dc64":{"id":"com.apple.managedclient.preferences_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\n\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\n\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#verticaltabsallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_verticaltabsallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_verticaltabsallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"acaa194fc1482253":{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever","displayName":"Warn On Create Allow Never","description":"If true, allows the user to stop the prompts about mobile account creation every time the user logs in. This key is only valid if Warn On Create is set to true.","helpText":null,"infoUrls":[],"categoryId":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","categoryName":"Mobile Accounts","options":[{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_cachedaccounts.warnoncreate.allownever_true","displayName":"True","description":null,"helpText":null}]},"ac9d0580aea387fa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings","displayName":"Print preview sticky settings","description":"Specifies whether print preview should apply last used settings for Microsoft Edge PDF and webpages.\n\nIf you set this policy to 'EnableAll' or don't configure it, Microsoft Edge applies the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisableAll', Microsoft Edge doesn't apply the last used print preview settings for both PDF and webpages.\n\nIf you set this policy to 'DisablePdf', Microsoft Edge doesn't apply the last used print preview settings for PDF printing and retains it for webpages.\n\nIf you set this policy to 'DisableWebpage', Microsoft Edge doesn't apply the last used print preview settings for webpage printing and retain it for PDF.\n\nThis policy is only available if you enable or don't configure the \"PrintingEnabled\" policy.\n\nPolicy options mapping:\n\n* EnableAll (0) = Enable sticky settings for PDF and Webpages\n\n* DisableAll (1) = Disable sticky settings for PDF and Webpages\n\n* DisablePdf (2) = Disable sticky settings for PDF\n\n* DisableWebpage (3) = Disable sticky settings for Webpages\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_enableall","displayName":"Enable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disableall","displayName":"Disable sticky settings for PDF and Webpages","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disablepdf","displayName":"Disable sticky settings for PDF","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printstickysettings_disablewebpage","displayName":"Disable sticky settings for Webpages","description":null,"helpText":null}]},"ac8878251bb29720":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_entry_computersid","displayName":"Computer Sid","description":"Local computer Sid or computer Sid group or the Sid of the AD object, defines whether to apply this policy over a specific machine or machine group; one entry can have a maximum of one ComputerSid and an entry without any ComputerSid means applying the policy over the machine. If you want to apply an Entry to a specific user and specific machine, add both Sid and ComputerSid into the same Entry.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},"ac518b022cddf98b":{"id":"device_vendor_msft_euiccs_{euicc}_downloadservers_{servername}_maximumattempts","displayName":"Maximum Attempts (Windows Insiders only)","description":"How many times profile download should be attempted before giving up. A value of 0 indicates unlimited retry attempts. When a value is not specified, it defaults to 50, which is equivalent to about a month of retry attempts.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},"ac93661e6689fdc3":{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentialswhenntlmonly_allowsavedcredentialswhenntlmonly_name","displayName":"Add servers to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":null},"ac0364a7bbedd330":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime","displayName":"Time (in seconds) to force reboot when required for policy changes to take effect","description":"This policy setting establishes the amount of time (in seconds) that the system will wait to reboot in order to enforce a change in device installation restriction policies.\r\n\r\nIf you enable this policy setting, set the amount of seconds you want the system to wait until a reboot.\r\n\r\nIf you disable or do not configure this policy setting, the system does not force a reboot.\r\n\r\nNote: If no reboot is forced, the device installation restriction right will not take effect until the system is restarted.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-policy-reboottime"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_policy_reboottime_1","displayName":"Enabled","description":null,"helpText":null}]},"aca5336ac6ccf19c":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel","displayName":"Primary DNS suffix devolution level","description":"Specifies if the devolution level that DNS clients will use if they perform primary DNS suffix devolution during the name resolution process.\r\n\r\nWith devolution, a DNS client creates queries by appending a single-label, unqualified domain name with the parent suffix of the primary DNS suffix name, and the parent of that suffix, and so on, stopping if the name is successfully resolved or at a level determined by devolution settings. Devolution can be used when a user or application submits a query for a single-label domain name.\r\n\r\nThe DNS client appends DNS suffixes to the single-label, unqualified domain name based on the state of the Append primary and connection specific DNS suffixes radio button and Append parent suffixes of the primary DNS suffix check box on the DNS tab in Advanced TCP/IP Settings for the Internet Protocol (TCP/IP) Properties dialog box.\r\n\r\nDevolution is not enabled if a global suffix search list is configured using Group Policy.\r\n\r\nIf a global suffix search list is not configured, and the Append primary and connection specific DNS suffixes radio button is selected, the DNS client appends the following names to a single-label name when it sends DNS queries:\r\n\r\nThe primary DNS suffix, as specified on the Computer Name tab of the System control panel.\r\n\r\nEach connection-specific DNS suffix, assigned either through DHCP or specified in the DNS suffix for this connection box on the DNS tab in the Advanced TCP/IP Settings dialog box for each connection.\r\n\r\nFor example, when a user submits a query for a single-label name such as \"example,\" the DNS client attaches a suffix such as \"microsoft.com\" resulting in the query \"example.microsoft.com,\" before sending the query to a DNS server.\r\n\r\nIf a DNS suffix search list is not specified, the DNS client attaches the primary DNS suffix to a single-label name. If this query fails, the connection-specific DNS suffix is attached for a new query. If none of these queries are resolved, the client devolves the primary DNS suffix of the computer (drops the leftmost label of the primary DNS suffix), attaches this devolved primary DNS suffix to the single-label name, and submits this new query to a DNS server.\r\n\r\nFor example, if the primary DNS suffix ooo.aaa.microsoft.com is attached to the non-dot-terminated single-label name \"example,\" and the DNS query for example.ooo.aaa.microsoft.com fails, the DNS client devolves the primary DNS suffix (drops the leftmost label) till the specified devolution level, and submits a query for example.aaa.microsoft.com. If this query fails, the primary DNS suffix is devolved further if it is under specified devolution level and the query example.microsoft.com is submitted. If this query fails, devolution continues if it is under specified devolution level and the query example.microsoft.com is submitted, corresponding to a devolution level of two. The primary DNS suffix cannot be devolved beyond a devolution level of two. The devolution level can be configured using this policy setting. The default devolution level is two.\r\n\r\nIf you enable this policy setting and DNS devolution is also enabled, DNS clients use the DNS devolution level that you specify.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, DNS clients use the default devolution level of two provided that DNS devolution is enabled.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-domainnamedevolutionlevel"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_domainnamedevolutionlevel_1","displayName":"Enabled","description":null,"helpText":null}]},"ac41f563baf255ce":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled","displayName":"Dynamic update","description":"Specifies if DNS dynamic update is enabled. Computers configured for DNS dynamic update automatically register and update their DNS resource records with a DNS server.\r\n\r\nIf you enable this policy setting, or you do not configure this policy setting, computers will attempt to use dynamic DNS registration on all network connections that have connection-specific dynamic DNS registration enabled. For a dynamic DNS registration to be enabled on a network connection, the connection-specific configuration must allow dynamic DNS registration, and this policy setting must not be disabled.\r\n\r\nIf you disable this policy setting, computers may not use dynamic DNS registration for any of their network connections, regardless of the configuration for individual network connections.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registrationenabled"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registrationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"acb2282b180bc80e":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions","displayName":"MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged","description":"MSS: (TcpMaxConnectResponseRetransmissions) SYN-ACK retransmissions when a connection request is not acknowledged\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxconnectresponseretransmissions"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxconnectresponseretransmissions_1","displayName":"Enabled","description":null,"helpText":null}]},"ac419ed79ad4e392":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod","displayName":"Use initial DC discovery retry setting for background callers","description":"This policy setting determines the amount of time (in seconds) to wait before the first retry for applications that perform periodic searches for domain controllers (DC) that are unable to find a DC.\r\n\r\nThe default value for this setting is 10 minutes (10*60). The maximum value for this setting is 49 days (0x49*24*60*60=4233600). The minimum value for this setting is 0.\r\n\r\nThis setting is relevant only to those callers of DsGetDcName that have specified the DS_BACKGROUND_ONLY flag.\r\n\r\nIf the value of this setting is less than the value specified in the NegativeCachePeriod subkey, the value in the NegativeCachePeriod subkey is used.\r\n\r\nWarning: If the value for this setting is too large, a client will not attempt to find any DCs that were initially unavailable. If the value set in this setting is very small and the DC is not available, the traffic caused by periodic DC discoveries may be excessive.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-backgroundretryinitialperiod"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretryinitialperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"acaa2fd9f07a28cb":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources","displayName":"Configure extension, app, and user script install sources","description":"Setting the policy specifies which URLs may install extensions, apps, and themes. Before Google Chrome 21, users could click on a link to a *.crx file, and Google Chrome would offer to install the file after a few warnings. Afterwards, such files must be downloaded and dragged to the Google Chrome settings page. This setting allows specific URLs to have the old, easier installation flow.\r\n\r\nEach item in this list is an extension-style match pattern (see https://developer.chrome.com/extensions/match_patterns). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (the referrer) must be allowed by these patterns.\r\n\r\nExtensionInstallBlocklist takes precedence over this policy. That is, an extension on the blocklist won't be installed, even if it happens from a site on this list.\r\n\r\nExample value:\r\n\r\nhttps://corp.mycompany.com/*","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallsources_1","displayName":"Enabled","description":null,"helpText":null}]},"ac60a6b9095cf62a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_remoteaccesshostclipboardsizebytes","displayName":"The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},"acd4c008083620f6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled","displayName":"Enable sending downloads to Google for deep scanning for users enrolled in the Advanced Protection program","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_advancedprotectiondeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"acd7b9f2da07c9a5":{"id":"device_vendor_msft_policy_config_dataprotection_allowdirectmemoryaccess","displayName":"Allow Direct Memory Access","description":"This policy setting allows you to block direct memory access (DMA) for all hot pluggable PCI downstream ports until a user logs into Windows. Once a user logs in, Windows will enumerate the PCI devices connected to the host plug PCI ports. Every time the user locks the machine, DMA will be blocked on hot plug PCI ports with no children devices until the user logs in again. Devices which were already enumerated when the machine was unlocked will continue to function until unplugged. This policy setting is only enforced when BitLocker Device Encryption is enabled. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-dataprotection#allowdirectmemoryaccess"],"categoryId":"22f2b16b-e1af-45fa-8d2f-687854b72c02","categoryName":"Data Protection","options":[{"id":"device_vendor_msft_policy_config_dataprotection_allowdirectmemoryaccess_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_dataprotection_allowdirectmemoryaccess_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"ac2142d835527d0d":{"id":"device_vendor_msft_policy_config_deliveryoptimization_doallowvpnpeercaching","displayName":"DO Allow VPN Peer Caching","description":"Specifies whether the device, with an active VPN connection, is allowed to participate in P2P or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#doallowvpnpeercaching"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":[{"id":"device_vendor_msft_policy_config_deliveryoptimization_doallowvpnpeercaching_0","displayName":"Not allowed","description":"Not allowed","helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_doallowvpnpeercaching_1","displayName":"Allowed","description":"Allowed","helpText":null}]},"acbf1a9b0f15a725":{"id":"device_vendor_msft_policy_config_experience_donotshowfeedbacknotifications","displayName":"Do Not Show Feedback Notifications","description":"Prevents devices from showing feedback questions from Microsoft. If you enable this policy setting, users will no longer see feedback notifications through the Feedback hub app. If you disable or do not configure this policy setting, users may see notifications through the Feedback hub app asking users for feedback. If you disable or do not configure this policy setting, users can control how often they receive feedback questions.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#donotshowfeedbacknotifications"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_donotshowfeedbacknotifications_0","displayName":"Feedback notifications are not disabled. The actual state of feedback notifications on the device will then depend on what GP has configured or what the user has configured locally.","description":"Feedback notifications are not disabled. The actual state of feedback notifications on the device will then depend on what GP has configured or what the user has configured locally.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_donotshowfeedbacknotifications_1","displayName":"Feedback notifications are disabled.","description":"Feedback notifications are disabled.","helpText":null}]},"ac7880e379f377cc":{"id":"device_vendor_msft_policy_config_internetexplorer_disablecompatview","displayName":"Turn off Compatibility View","description":"This policy setting controls the Compatibility View feature, which allows the user to fix website display problems that he or she may encounter while browsing.\n\nIf you enable this policy setting, the user cannot use the Compatibility View button or manage the Compatibility View sites list.\n\nIf you disable or do not configure this policy setting, the user can use the Compatibility View button and manage the Compatibility View sites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecompatview"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablecompatview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablecompatview_1","displayName":"Enabled","description":null,"helpText":null}]},"ac63c2b8dae83b1c":{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"ac4a0de2c4606e01":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"acd90ca8cd1c4dc8":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_downloaddirectory","displayName":"Set download directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"ac5145f31623dbc0":{"id":"device_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_typosquattingallowlistdomainsdesc","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":null},"ac83470d05885a69":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationlocalsitelistexpirationdays_internetexplorerintegrationlocalsitelistexpirationdays","displayName":"Specify the number of days that a site remains on the local IE mode site list: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"acebc1393f7615ff":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_configureviewinfileexplorer_configureviewinfileexplorer","displayName":"Configure the View in File Explorer feature for SharePoint pages in Microsoft Edge (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"acb5061c89c6a6e0":{"id":"device_vendor_msft_policy_config_mssecurityguide_configuresmbv1server","displayName":"Configure SMB v1 server","description":"Disabling this setting disables server-side processing of the SMBv1 protocol. (Recommended.)\n\nEnabling this setting enables server-side processing of the SMBv1 protocol. (Default.)\n\nChanges to this setting require a reboot to take effect.\n\nFor more information, see https://support.microsoft.com/kb/2696547\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-mssecurityguide#mssecurityguide-configuresmbv1server"],"categoryId":"5371d50c-0aaa-425a-a075-2cb1c59968b9","categoryName":"MS Security Guide","options":[{"id":"device_vendor_msft_policy_config_mssecurityguide_configuresmbv1server_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_mssecurityguide_configuresmbv1server_1","displayName":"Enabled","description":null,"helpText":null}]},"ac78627bed84090b":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_outlookexe190","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_outlookexe190_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_outlookexe190_1","displayName":"True","description":null,"helpText":null}]},"ac8fc9da39293b70":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_msaccessexe","displayName":"msaccess.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_msaccessexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_msaccessexe_1","displayName":"True","description":null,"helpText":null}]},"acb2669b573266e5":{"id":"device_vendor_msft_policy_config_update_maintenancewindowrepeatscheduleoption","displayName":"Maintenance Window Repeat Schedule Option","description":"Configure whether and how often the maintenance window repeats, 1=no repeat, 2=daily, 3=weekly, 4=monthly. Daily/weekly/monthly schedule will be repeated every day/week/month.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowrepeatscheduleoption"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_maintenancewindowrepeatscheduleoption_1","displayName":"No repeat","description":"No repeat","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowrepeatscheduleoption_2","displayName":"Daily","description":"Daily","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowrepeatscheduleoption_3","displayName":"Weekly","description":"Weekly","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowrepeatscheduleoption_4","displayName":"Monthly","description":"Monthly","helpText":null}]},"ac0cfe06c6b0e066":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_meteredupdatesmicrosoftedgedev_part_meteredupdatespolicy","displayName":"Metered Updates Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"13f62499-a266-42c8-a4dc-531efcea55cb","categoryName":"Microsoft Edge Dev","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_meteredupdatesmicrosoftedgedev_part_meteredupdatespolicy_1","displayName":"Metered Disable updates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_meteredupdatesmicrosoftedgedev_part_meteredupdatespolicy_2","displayName":"Metered Updates Allowed","description":null,"helpText":null}]},"ac77d05b84004d63":{"id":"device_vendor_msft_policy_config_userrights_changetimezone","displayName":"Change Time Zone","description":"This user right determines which users and groups can change the time zone used by the computer for displaying the local time, which is the computer's system time plus the time zone offset. System time itself is absolute and is not affected by a change in the time zone. \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#changetimezone"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"ac48173071041b1e":{"id":"device_vendor_msft_remoteremediation_cloudremediationsettings_networksettings_networkcredentials_networkpassword","displayName":"Network Password (Windows Insiders only)","description":"Refers to the password for the wifi network that the device will attempt to connect to during remediation. If a password is set without a SSID, then this will be ignored.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/RemoteRemediation-csp/"],"categoryId":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","categoryName":"Remote Remediation","options":null},"acae6102b4b53649":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon31","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"acf4871da8bca7a2":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},"acd9e99e6c61b8dc":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","categoryName":"Miscellaneous","options":null},"ac429b1e52a97e06":{"id":"user_vendor_msft_policy_config_admx_desktop_wallpaper_wallpapername","displayName":"Wallpaper Name: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":null},"ac4c46f5eac13ef6":{"id":"user_vendor_msft_policy_config_admx_eaime_l_restrictcharactercoderangeofconversion","displayName":"Restrict character code range of conversion (User)","description":"This policy setting allows you to restrict character code range of conversion by setting character filter.\r\n\r\nIf you enable this policy setting, then only the character code ranges specified by this policy setting are used for conversion of IME. You can specify multiple ranges by setting a value combined with a bitwise OR of following values:\r\n\r\n0x0001 // JIS208 area\r\n0x0002 // NEC special char code\r\n0x0004 // NEC selected IBM extended code\r\n0x0008 // IBM extended code\r\n0x0010 // Half width katakana code\r\n0x0100 // EUDC(GAIJI)\r\n0x0200 // S-JIS unmapped area\r\n0x0400 // Unicode char\r\n0x0800 // surrogate char\r\n0x1000 // IVS char\r\n0xFFFF // no definition.\r\n\r\nIf you disable or do not configure this policy setting, no range of characters are filtered by default.\r\n\r\nThis policy setting applies to Japanese Microsoft IME only.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eaime#admx-eaime-l-restrictcharactercoderangeofconversion"],"categoryId":"7d331987-7e2d-4975-b23b-d99a5af26ddf","categoryName":"IME","options":[{"id":"user_vendor_msft_policy_config_admx_eaime_l_restrictcharactercoderangeofconversion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_eaime_l_restrictcharactercoderangeofconversion_1","displayName":"Enabled","description":null,"helpText":null}]},"acfc06b6b332ccd5":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_devicemanager_2","displayName":"Device Manager (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-devicemanager-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_devicemanager_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_devicemanager_2_1","displayName":"Enabled","description":null,"helpText":null}]},"ac4e67392773816e":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_diskdefrag","displayName":"Disk Defragmenter (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-diskdefrag"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_diskdefrag_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_diskdefrag_1","displayName":"Enabled","description":null,"helpText":null}]},"acbfc14d267feda2":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word","displayName":"Microsoft Word 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Word 2016.\r\nBy default, the user settings of Microsoft Word 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Word 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Word 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Word 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016word"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016word_1","displayName":"Enabled","description":null,"helpText":null}]},"aceb547fcb7f7c1c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.site.com will not correctly apply to site.com or subdomain.site.com since they both resolve to the same eTLD+1 (site.com) for which there is no policy. In this case, policy must be set on site.com to apply correctly for both site.com and subdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if site-one.com is listed in the JavaScriptJitAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript JIT enabled, but site-two.com will use the policy from DefaultJavaScriptJitSetting, if set, or default to JavaScript JIT enabled.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptJitSetting applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"ac7d5302ee5a0841":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_remoteaccesshostclientdomainlistdesc","displayName":"Configure the required domain names for remote access clients (User)","description":"","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":null},"ac9b6d663e30336d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_1","displayName":"Enabled","description":null,"helpText":null}]},"acff216b531b4768":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction","displayName":"Enable or disable the User-Agent Reduction. (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_useragentreduction_1","displayName":"Enabled","description":null,"helpText":null}]},"ac6c8481b4984d7a":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation","displayName":"File tab | Options | Customize Ribbon | All Commands | Document Location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fa63a9d-e22d-4fc8-8464-a13b56461115","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_officebuttonexceloptionscustomizedocumentlocation_1","displayName":"True","description":null,"helpText":null}]},"acf5b74abc6e60dc":{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles","displayName":"Always prevent untrusted Microsoft Query files from opening (User)","description":"This policy setting controls whether Microsoft Query files (.iqy, oqy, .dqy, and .rqy) in an untrusted location are prevented from opening.\r\n\r\nIf you enable this policy setting, Microsoft Query files in an untrusted location are prevented from opening. Users will not be able to change this setting under File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nIf you disable or don’t configure this policy setting, Microsoft Query files in an untrusted location are not prevented from opening, unless users have changed this setting in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_enableblockunsecurequeryfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"acf8f84fc44bdaed":{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation","displayName":"Turn off browser geolocation (User)","description":"This policy setting allows you to disable browser geolocation support. This will prevent websites from requesting location data about the user.\n\nIf you enable this policy setting, browser geolocation support is turned off.\n\nIf you disable this policy setting, browser geolocation support is turned on.\n\nIf you do not configure this policy setting, browser geolocation support can be turned on or off in Internet Options on the Privacy tab.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablegeolocation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablegeolocation_1","displayName":"Enabled","description":null,"helpText":null}]},"ac867124bd52dc4c":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls","displayName":"Configure the list of enterprise login URLs where password protection service should capture fingerprint of password (User)","description":"Configure the list of enterprise login URLs (HTTP and HTTPS schemes only) where Microsoft Edge should capture the fingerprint of passwords and use it for password reuse detection.\r\n\r\nIf you enable this policy, the password protection service captures fingerprints of passwords on the defined URLs.\r\n\r\nIf you disable this policy or don't configure it, no password fingerprints are captured.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value:\r\n\r\nhttps://contoso.com/login.html\r\nhttps://login.contoso.com","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionloginurls_1","displayName":"Enabled","description":null,"helpText":null}]},"ac7251379b1ccb39":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended","displayName":"Allow users to be alerted if their passwords are found to be unsafe (User)","description":"Allow Microsoft Edge to monitor user passwords.\r\n\r\nIf you enable this policy, the user will get alerted if any of their passwords stored in Microsoft Edge are found to be unsafe. Microsoft Edge will show an alert and this information will also be available in Settings > Passwords > Password Monitor.\r\n\r\nIf you disable this policy, users will not be asked for permission to enable this feature. Their passwords will not be scanned and they will not be alerted either.\r\n\r\nIf you don't configure the policy, users can turn this feature on or off.\r\n\r\nTo learn more about how Microsoft Edge finds unsafe passwords see https://go.microsoft.com/fwlink/?linkid=2133833\r\n\r\nAdditional guidance:\r\n\r\nThis policy can be set as both Recommended as well as Mandatory, however with an important callout.\r\n\r\nMandatory enabled: If the policy is set to Mandatory enabled, the UI in Settings will be disabled but remain in 'On' state, and a briefcase icon will be made visible next to it with this description displayed on hover - \"This setting is managed by your organization.\"\r\n\r\nRecommended enabled: If the policy is set to Recommended enabled, the UI in Settings will remain in 'Off' state, but a briefcase icon will be made visible next to it with this description displayed on hover - \"Your organization recommends a specific value for this setting and you have chosen a different value\"\r\n\r\nMandatory and Recommended disabled: Both these states will work the normal way, with the usual captions being shown to users.","helpText":"","infoUrls":[],"categoryId":"a877a2ff-f144-421f-814c-593e972a8a20","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_recommended~passwordmanager_recommended_passwordmonitorallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"acf5dd5f9084833e":{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages","displayName":"Define an ordered list of preferred languages that websites should display in if the site supports the language (User)","description":"Configures the language variants that Microsoft Edge sends to websites as part of the Accept-Language request HTTP header and prevents users from adding, removing, or changing the order of preferred languages in Microsoft Edge settings. Users who want to change the languages Microsoft Edge displays in or offers to translate pages to will be limited to the languages configured in this policy.\r\n\r\nIf you enable this policy, websites will appear in the first language in the list that they support unless other site-specific logic is used to determine the display language. The language variants defined in this policy override the languages configured as part of the 'SpellcheckLanguage' (Enable specific spellcheck languages) policy.\r\n\r\nIf you don't configure or disable this policy, Microsoft Edge sends websites the user-specified preferred languages as part of the Accept-Language request HTTP header.\r\n\r\nFor detailed information on valid language variants, see https://go.microsoft.com/fwlink/?linkid=2148854.\r\n\r\nExample value: en-US,fr,es","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge_definepreferredlanguages_1","displayName":"Enabled","description":null,"helpText":null}]},"acb4a1f53d4df4ff":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8","displayName":"Places Bar Location 8 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy8_1","displayName":"Enabled","description":null,"helpText":null}]},"ac91ab607d05efbf":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha1","displayName":"SHA1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha256","displayName":"SHA256","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha384","displayName":"SHA384","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturehashingalgorithm_l_selectdigitalsignaturehashingalgorithmdropid_sha512","displayName":"SHA512","description":null,"helpText":null}]},"ac76a8e35d80cfef":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext","displayName":"Read e-mail as plain text (User)","description":"This policy setting determines whether Outlook renders all e-mail messages in plain text format for reading.Outlook can display e-mail messages and other items in three formats: plain text, Rich Text Format (RTF), and HTML. \r\n\r\nIf you enable this policy setting, the \"Read all standard mail in plain text\" check box option is selected in the \"E-mail Security\" section of the Trust Center and users cannot change it. This option only changes the way e-mail messages are displayed; the original message is not converted to plain text format. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays e-mail messages in whatever format they were received in.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_reademailasplaintext_1","displayName":"Enabled","description":null,"helpText":null}]},"ac4cc81f86cd6bb4":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour","displayName":"Hyperlink color (User)","description":"Specifies the color of hyperlinks that have not yet been followed.\r\n \r\nIf you enable this setting, hyperlinks that have not been followed are displayed in the color you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3db7e884-6077-4b96-ace3-005a6b49ecc0","categoryName":"Hyperlink appearance in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjhyperlinkappear_l_pjhyperlinkcolour_1","displayName":"Enabled","description":null,"helpText":null}]},"ac3c654d2df2cd8a":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_help_l_helpcolon","displayName":"Help: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":null},"ac7e7b626fc982ce":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc","displayName":"Disable Real Time Coauthoring for Word (User)","description":"This policy lets admins disable Real Time Coauthoring. They may want to do so if they have solutions that are not compatible with some elements of real time coauthoring, such as add-ins that would trigger too often due to Real Time Coauthoring causing the frequent saving of user content. \r\n\r\nIf you enable this policy setting, it will prevent Real Time Coauthoring. \r\n\r\nIf you disable or do not configure this policy setting, users will be able to experience Real Time Coauthoring feature.","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablertc_1","displayName":"Enabled","description":null,"helpText":null}]},"ac30086d22210aef":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles","displayName":"Add Bi-Directional Marks when saving Text files (User)","description":"Checked: Add Bi-Directional Marks when saving Text files. | Unchecked: Do not add Bi-Directional Marks when saving Text files.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_addbidirectionalmarkswhensavingtextfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"aca00a0c1e025a7b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Word files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"ac256630aca9b908":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_l_datecolon","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"aceded718d9d0f64":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_localuserauthorizedlist","displayName":"Local User Authorized List","description":"Specifies the list of authorized local users for this rule. A list of authorized users cannot be specified if the rule being authored is targeting a Windows service. If not specified, the default is all users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/ad.json b/public/intune-definitions/ad.json index 8bc9d8c24a0e..3d53109d3c96 100644 --- a/public/intune-definitions/ad.json +++ b/public/intune-definitions/ad.json @@ -1 +1 @@ -{"ad0bda41e4bb5f32":{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock","displayName":"Required unlock frequency","description":"Select how long users have before they're required to unlock the device using a strong authentication method (password, PIN, or pattern). Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock_devicedefault","displayName":"Device default","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock_requiredpasswordunlockdailyoption","displayName":"24 hours since last PIN, password, or pattern unlock","description":null,"helpText":null}]},"ad3af61b4619ffc2":{"id":"com.apple.managedclient.preferences_disableicmpparsing","displayName":"Disable ICMP parsing","description":"Disables parsing of ICMP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disableicmpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableicmpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},"ad48388ea6259bc1":{"id":"com.apple.managedclient.preferences_forcebingsafesearch","displayName":"Enforce Bing SafeSearch","description":"Ensure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting.\n\nIf you configure this policy to \"Off\", SafeSearch in Bing search falls back to the bing.com value.\n\nIf you configure this policy to \"Moderate\", the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results.\n\nIf you configure this policy to \"Strict\", the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos.\n\nIf you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com.\n\n* 0 = Don't configure search restrictions in Bing\n\n* 1 = Configure moderate search restrictions in Bing\n\n* 2 = Configure strict search restrictions in Bing","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcebingsafesearch"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcebingsafesearch_0","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch_1","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch_2","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},"ad944bcc8fb9fa8d":{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default","displayName":"Is default","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default_true","displayName":"Enabled","description":null,"helpText":null}]},"adde5445f36750c1":{"id":"com.apple.security.firewall_applications_item_bundleid","displayName":"Bundle ID","description":"The bundle identifier for an app.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},"adabf83e33ae9137":{"id":"com.apple.systemconfiguration_proxies_ftpport","displayName":"FTP Port","description":"The FTP proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},"adc034b77446e56e":{"id":"com.apple.webcontent-filter_allowlistbookmarks_item_url","displayName":"URL","description":"The URL of the bookmark in the allow list.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},"adb76807b5297a25":{"id":"com.microsoft.edge.mamedgeappconfigsettings.webusbaskforurls","displayName":"Allow WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"WebUsbBlockedForUrls\" policy - you can't both allow and block a URL. For detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"ad7a7cf45ef0b13c":{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name","displayName":"Allow data recovery agent","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name_1","displayName":"True","description":null,"helpText":null}]},"ad15a989aec1129f":{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdvalue","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":null},"ad1632788dc5e4bc":{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage","displayName":"Restricts the UI language Windows uses for all logged users","description":"This policy setting restricts the Windows UI language for all users.\r\n\r\nThis is a policy setting for computers with more than one UI language installed.\r\n\r\nIf you enable this policy setting, the UI language of Windows menus and dialogs for systems with more than one language will follow the language specified by the administrator as the system UI languages. The UI language selected by the user will be ignored if it is different than any of the system UI languages.\r\n\r\nIf you disable or do not configure this policy setting, the user can specify which UI language is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-lockmachineuilanguage"],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_1","displayName":"Enabled","description":null,"helpText":null}]},"adb7468f612f9372":{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili","displayName":"Provide information about previous logons to client computers","description":"This policy setting controls whether the domain controller provides information about previous logons to client computers.\r\n\r\nIf you enable this policy setting, the domain controller provides the information message about previous logons.\r\n\r\nFor Windows Logon to leverage this feature, the \"Display information about previous logons during user logon\" policy setting located in the Windows Logon Options node under Windows Components also needs to be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the domain controller does not provide information about previous logons unless the \"Display information about previous logons during user logon\" policy setting is enabled.\r\n\r\nNote: Information about previous logons is provided only if the domain functional level is Windows Server 2008. In domains with a domain functional level of Windows Server 2003, Windows 2000 native, or Windows 2000 mixed, domain controllers cannot provide information about previous logons, and enabling this policy setting does not affect anything.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-emitlili"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili_1","displayName":"Enabled","description":null,"helpText":null}]},"adf69ed7c1325693":{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost_ncsi_corpdnsprobehostbox","displayName":"Corporate DNS Probe Hostname:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},"ad7461307539d7db":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod_netlogon_backgroundsuccessfulrefreshperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"add4df0c12cc9157":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncblockoutperiodstarttime","displayName":"Blockout Start Time (HHMM)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"ad71c2b031c0064c":{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent","displayName":"Set percentage of disk space used for client computer cache","description":"This policy setting specifies the default percentage of total disk space that is allocated for the BranchCache disk cache on client computers.\r\n\r\nIf you enable this policy setting, you can configure the percentage of total disk space to allocate for the cache.\r\n\r\nIf you disable or do not configure this policy setting, the cache is set to 5 percent of the total disk space on the client computer.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache client computer cache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to configure a BranchCache client computer cache setting on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache client computer cache settings on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the client computer cache setting that you use on individual client computers.\r\n\r\n- Enabled. With this selection, the BranchCache client computer cache setting is enabled for all client computers where the policy is applied. For example, if Set percentage of disk space used for client computer cache is enabled in domain Group Policy, the BranchCache client computer cache setting that you specify in the policy is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache client computers use the default client computer cache setting of five percent of the total disk space on the client computer.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Specify the percentage of total disk space allocated for the cache. Specifies an integer that is the percentage of total client computer disk space to use for the BranchCache client computer cache.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setcachepercent"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_1","displayName":"Enabled","description":null,"helpText":null}]},"ad93d644164ec631":{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2","displayName":"Turn off hardware buttons","description":"Turns off Tablet PC hardware buttons.\r\n\r\nIf you enable this policy, no actions will occur when the buttons are pressed, and the buttons tab in Tablet PC Control Panel will be removed.\r\n\r\nIf you disable this policy, user and OEM defined button actions will occur when the buttons are pressed.\r\n\r\nIf you do not configure this policy, user and OEM defined button actions will occur when the buttons are pressed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-turnoffbuttons-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2_1","displayName":"Enabled","description":null,"helpText":null}]},"adcc3e37956052bc":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013","displayName":"Microsoft Office 365 OneNote 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 OneNote 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 OneNote 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 OneNote 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 OneNote 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 OneNote 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365onenote2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013_1","displayName":"Enabled","description":null,"helpText":null}]},"ade8fca10f0fa41a":{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions_integration_roaming_registry_exclusions_prompt","displayName":"Roaming File Exclusions","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},"ad0e46d69b9f4cb5":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity","displayName":"Detailed Tracking Audit DPAPI Activity","description":"This policy setting allows you to audit events generated when encryption or decryption requests are made to the Data Protection application interface (DPAPI). DPAPI is used to protect secret information such as stored password and key information. For more information about DPAPI, see https://go.microsoft.com/fwlink/?LinkId=121720. If you configure this policy setting, an audit event is generated when an encryption or decryption request is made to DPAPI. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated when an encryption or decryption request is made to DPAPI.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditdpapiactivity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"ad26e187fa5b8d5b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended","displayName":"Import saved passwords from default browser on first run","description":"Setting the policy to Enabled imports saved passwords from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no saved passwords are imported on first run.\r\n\r\nUsers can trigger an import dialog and the saved passwords checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"adebde612f0a4ea2":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended","displayName":"Enable Live Translate","description":"Enable translation of live captions. Captions will be sent to Google for translation.\r\n\r\nIf this policy is set to Enabled, Live Translate will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Translate will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.\r\n\r\nIn LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"12142994-4b30-486c-bab1-9206528b2b96","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"ad78360932c527de":{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats","displayName":"Remediation action for Severe threats","description":"","helpText":"","infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_clean","displayName":"Clean. Service tries to recover files and try to disinfect.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_quarantine","displayName":"Quarantine. Moves files to quarantine.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_remove","displayName":"Remove. Removes files from system.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_allow","displayName":"Allow. Allows file/does none of the above actions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_userdefined","displayName":"User defined. Requires user to make a decision on which action to take.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_block","displayName":"Block. Blocks file execution.","description":null,"helpText":null}]},"adec7deb6ea755b1":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads","displayName":"Allow font downloads","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowfontdownloads"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"ade012b9592716ea":{"id":"device_vendor_msft_policy_config_lanmanserver_authratelimiterdelayinms","displayName":"Auth Rate Limiter Delay In Ms","description":"This policy controls whether the SMB server will use a default value in milliseconds for the invalid authentication delay. If you configure this policy setting, the authentication rate limiter will use the specified value for delaying invalid authentication attempts. If you do not configure this policy setting, the authentication rate limiter will use the default value obtained from either the software licensing service or the local registry.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanServer#authratelimiterdelayinms"],"categoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","categoryName":"Lanman Server","options":null},"ad0997f31b6255ce":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_leteveryonepermissionsapplytoanonymoususers","displayName":"Network Access Let Everyone Permissions Apply To Anonymous Users","description":"Network access: Let Everyone permissions apply to anonymous users This security setting determines what additional permissions are granted for anonymous connections to the computer. Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to grant access to users in a trusted domain that does not maintain a reciprocal trust. By Default, the Everyone security identifier (SID) is removed from the token created for anonymous connections. Therefore, permissions granted to the Everyone group do not apply to anonymous users. If this option is set, anonymous users can only access those resources for which the anonymous user has been explicitly given permission. If this policy is enabled, the Everyone SID is added to the token that is created for anonymous connections. In this case, anonymous users are able to access any resource for which the Everyone group has been given permissions. Default: Disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_leteveryonepermissionsapplytoanonymoususers"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"adf84fe920b464ce":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\r\n\r\nIf you enable, this policy, the option to import search engine settings is automatically selected.\r\n\r\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"adf857235a17a9ee":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_browsingwithcopilotblocklistdesc","displayName":"Browsing with Copilot Blocked URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"ad3b3c533bb7d1cc":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\r\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\r\nThis policy also applies to component extensions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ad500ba6a4061b2b":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"ad0780053442ff2f":{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\r\n\r\nPolicy options mapping:\r\n\r\n* any (any) = Allow printing with and without background graphics\r\n\r\n* enabled (enabled) = Allow printing only with background graphics\r\n\r\n* disabled (disabled) = Allow printing only without background graphics\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_1","displayName":"Enabled","description":null,"helpText":null}]},"adeae8e67395c32d":{"id":"device_vendor_msft_policy_config_system_disablesystemrestore","displayName":"Turn off System Restore","description":"Allows you to disable System Restore.\n\nThis policy setting allows you to turn off System Restore.\n\nSystem Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files. By default, System Restore is turned on for the boot volume.\n\nIf you enable this policy setting, System Restore is turned off, and the System Restore Wizard cannot be accessed. The option to configure System Restore or create a restore point through System Protection is also disabled.\n\nIf you disable or do not configure this policy setting, users can perform System Restore and configure System Restore settings through System Protection.\n\nAlso, see the \"Turn off System Restore configuration\" policy setting. If the \"Turn off System Restore\" policy setting is disabled or not configured, the \"Turn off System Restore configuration\" policy setting is used to determine whether the option to configure System Restore is available.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-system#system-disablesystemrestore"],"categoryId":"5c9a2f21-d3a8-4295-a803-e0535aa29489","categoryName":"System Restore","options":[{"id":"device_vendor_msft_policy_config_system_disablesystemrestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_system_disablesystemrestore_1","displayName":"Enabled","description":null,"helpText":null}]},"ad2d7fb4db58766b":{"id":"linux_mdatp_managed_antivirusengine_enablerealtimeprotection","displayName":"Enable real-time protection (deprecated)","description":"Locates and stops malware from installing or running on your device. You can turn off this setting for a short time before it turns back on automatically.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#enable--disable-real-time-protection"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_enablerealtimeprotection_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_enablerealtimeprotection_true","displayName":"Enabled","description":null,"helpText":null}]},"ad3d354ec91ad12b":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders50","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders50_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders50_1","displayName":"True","description":null,"helpText":null}]},"adf636ba2665a2ec":{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_1","displayName":"Do not allow window animations (User)","description":"This policy setting controls the appearance of window animations such as those found when restoring, minimizing, and maximizing windows. \r\n\r\nIf you enable this policy setting, window animations are turned off. \r\n\r\nIf you disable or do not configure this policy setting, window animations are turned on. \r\n\r\nChanging this policy setting requires a logoff for it to be applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdisallowanimations-1"],"categoryId":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","categoryName":"Desktop Window Manager","options":[{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_1_1","displayName":"Enabled","description":null,"helpText":null}]},"adb4614e401bf596":{"id":"user_vendor_msft_policy_config_admx_logon_run_1","displayName":"Run these programs at user logon (User)","description":"This policy setting specifies additional programs or documents that Windows starts automatically when a user logs on to the system.\r\n\r\nIf you enable this policy setting, you can specify which programs can run at the time the user logs on to this computer that has this policy applied.\r\n\r\nTo specify values for this policy setting, click Show. In the Show Contents dialog box in the Value column, type the name of the executable program (.exe) file or document file. To specify another name, press ENTER, and type the name. Unless the file is located in the %Systemroot% directory, you must specify the fully qualified path to the file.\r\n\r\nIf you disable or do not configure this policy setting, the user will have to start the appropriate programs after logon.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the system starts the programs specified in the Computer Configuration setting just before it starts the programs specified in the User Configuration setting.\r\n\r\nAlso, see the \"Do not process the legacy run list\" and the \"Do not process the run once list\" settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-run-1"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"user_vendor_msft_policy_config_admx_logon_run_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_logon_run_1_1","displayName":"Enabled","description":null,"helpText":null}]},"ada8d65a239fb504":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_hra","displayName":"Health Registration Authority (HRA) (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-hra"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_hra_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_hra_1","displayName":"Enabled","description":null,"helpText":null}]},"adbd13a30877062d":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitysettings_1","displayName":"Security Settings (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-securitysettings-1"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitysettings_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitysettings_1_1","displayName":"Enabled","description":null,"helpText":null}]},"ad2f24bd40918af2":{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremoterestore_1","displayName":"Prevent restoring remote previous versions (User)","description":"This setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a file on a file share.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a file on a file share.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a file on a file share. If the user clicks the Restore button, Windows attempts to restore the file from the file share.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a file on a file share.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disableremoterestore-1"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremoterestore_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremoterestore_1_1","displayName":"Enabled","description":null,"helpText":null}]},"ad7b68bb06ebe762":{"id":"user_vendor_msft_policy_config_admx_shellcommandpromptregedittools_disablecmd","displayName":"Prevent access to the command prompt (User)","description":"This policy setting prevents users from running the interactive command prompt, Cmd.exe. This policy setting also determines whether batch files (.cmd and .bat) can run on the computer.\r\n\r\nIf you enable this policy setting and the user tries to open a command window, the system displays a message explaining that a setting prevents the action.\r\n\r\nIf you disable this policy setting or do not configure it, users can run Cmd.exe and batch files normally.\r\n\r\nNote: Do not prevent the computer from running batch files if the computer uses logon, logoff, startup, or shutdown batch file scripts, or for users that use Remote Desktop Services.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-shellcommandpromptregedittools#admx-shellcommandpromptregedittools-disablecmd"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_shellcommandpromptregedittools_disablecmd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_shellcommandpromptregedittools_disablecmd_1","displayName":"Enabled","description":null,"helpText":null}]},"adabd09bf62e959e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"adf3034910cbe106":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled","displayName":"Enable Translate (User)","description":"Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features.\r\n\r\nIf you set the policy, users can't change this function. Leaving it unset lets them change the setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ad2e6b3c12e25c19":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter","displayName":"Print Headers and Footers (User)","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},"ad921f635a11436b":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_enterprisesearchaggregatorsettings","displayName":"Enterprise search aggregator settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"add4ce8d58f36d06":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist","displayName":"Enterprise profile separation secondary domain allowlist (User)","description":"If this policy is unset, account logins will not be required to create a new separate profile.\r\n\r\nIf this policy is set, account logins from the listed domains will not be required to create a new separate profile.\r\n\r\nThis policy can be set to an empty string so that all account logins are required to create a new separate profile.\r\n\r\nExample value:\r\n\r\ndomain.com\r\notherdomain.com","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_1","displayName":"Enabled","description":null,"helpText":null}]},"ad6e2b4f5b11eb64":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68_1","displayName":"True","description":null,"helpText":null}]},"adbed1906f004d56":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally","displayName":"Do not cache network files locally (User)","description":"This policy setting allows you to configure whether network files are locally cached when editing spreadsheets stored on network shares.\r\n\r\nIf you enable this policy setting, a file located on a network share may not be saved if the network connection was lost at any time while editing the file and the file contains a pivot table, VBE code or an embedded OLE object. \r\n\r\nIf you disable or do not configure this policy setting, network files are locally cached when editing spreadsheets stored on network shares. This may help prevent data loss during network failures.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally_1","displayName":"Enabled","description":null,"helpText":null}]},"adf213170d2a3416":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute signed managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute signed managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_1","displayName":"Enabled","description":null,"helpText":null}]},"ad68c634c206dbb8":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},"ad3630eaed7e5670":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverdescription4","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"ad1d2239509e9344":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview_l_empty388","displayName":"\r\nMax number of documents being reviewed using ad hoc review\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":null},"adf7d4bb67d0a33b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon","displayName":"French (Cameroon) (User)","description":"Enables the editing language French (Cameroon)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon_1","displayName":"Enabled","description":null,"helpText":null}]},"ad0f0805da71bed1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco","displayName":"French (Morocco) (User)","description":"Enables the editing language French (Morocco)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},"ad56e3e37801d095":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi","displayName":"Punjabi (User)","description":"Enables the editing language Punjabi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi_1","displayName":"Enabled","description":null,"helpText":null}]},"ad93e150e8351df3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil","displayName":"Tamil (User)","description":"Enables the editing language Tamil","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil_1","displayName":"Enabled","description":null,"helpText":null}]},"adb70214d30dfc76":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17","displayName":"Escrow Key #17 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_1","displayName":"Enabled","description":null,"helpText":null}]},"adfab9b5b93092d0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_l_setworkgrouppathforlabelpagesizeupdatefilesid","displayName":"Workgroup path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},"ad77b5f4623c4d24":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_freebusyupdatedontheservereveryxxxseconds","displayName":"Free/Busy updated on the server every xxx seconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},"ad3af6e25c71057c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_l_specifylistofsocialnetworkproviderstoloadid","displayName":"Separate ProgIDs with semi-colons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},"ad8da47f25677328":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay","displayName":"Do not display Folder Size button on folder properties dialog box (User)","description":"Retains/Removes the \"Folder Size\" button in the General tab of the Properties dialog box.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay_1","displayName":"Enabled","description":null,"helpText":null}]},"ad38d4aabdb6ea0f":{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink","displayName":"Disable Outlook Mobile Hyperlink (User)","description":"This policy setting determines if the Outlook Mobile Hyperlink is shown in Account Settings.\r\n\r\nIf you enable this policy setting, users will be unable to view the Outlook Mobile Hyperlink in Account Settings.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},"ad9d3c1c7504b403":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar","displayName":"Show all windows in the Taskbar (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"adf571bca93d09df":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel","displayName":"Publisher Automation Security Level (User)","description":"This policy setting controls whether macros opened programmatically by another application can run in Publisher.\r\n\r\nIf you enable this policy setting, you may choose an option for controlling macro behavior in Publisher when the application is opened programmatically:\r\n\r\n- Low (enabled): Macros can run in the programmatically opened application.\r\n- By UI (prompted): Macro functionality is determined by the setting in the \"Macro Settings\" section of the Trust Center.\r\n- High (disabled): All macros are disabled in the programmatically opened application.\r\n\r\nIf you disable or do not configure this policy setting, Publisher will use the default Macro setting in Trust Center.","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},"ad823a9ff74e8056":{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo","displayName":"Disable Click To Do (User)","description":"Click to Do lets people take action on content on their screens. When activated, it takes a screenshot of their screen and analyzes it to present actions. Click to Do ends when they exit it, and it can't take screenshots while closed. Screenshot analysis is always performed locally on their device. By default, Click to Do is enabled for users. This policy setting allows you to determine whether Click to Do is available for users on their device. When the policy is enabled, the Click to Do component and entry points will not be available to users. When the policy is disabled, users will have Click to Do available on their device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableclicktodo"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo_0","displayName":"Click to Do is enabled","description":"Click to Do is enabled","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo_1","displayName":"Click to Do is disabled.","description":"Click to Do is disabled.","helpText":null}]},"ad572ef2fcdf6490":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation_l_documents","displayName":"Documents (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},"adba08b65926c1fc":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens","displayName":"Optional hyphens (User)","description":"Determines whether the symbol used to represent optional hyphens is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"ad0bda41e4bb5f32":{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock","displayName":"Required unlock frequency","description":"Select how long users have before they're required to unlock the device using a strong authentication method (password, PIN, or pattern). Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":[{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock_devicedefault","displayName":"Device default","description":null,"helpText":null},{"id":"com.android.devicerestrictionpolicy.passwordrequireunlock_requiredpasswordunlockdailyoption","displayName":"24 hours since last PIN, password, or pattern unlock","description":null,"helpText":null}]},"ad3af61b4619ffc2":{"id":"com.apple.managedclient.preferences_disableicmpparsing","displayName":"Disable ICMP parsing","description":"Disables parsing of ICMP traffic","helpText":null,"infoUrls":[],"categoryId":"269c487f-8902-486a-88dd-db9b9b4454b8","categoryName":"Network protection","options":[{"id":"com.apple.managedclient.preferences_disableicmpparsing_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_disableicmpparsing_true","displayName":"Enabled","description":null,"helpText":null}]},"ad48388ea6259bc1":{"id":"com.apple.managedclient.preferences_forcebingsafesearch","displayName":"Enforce Bing SafeSearch","description":"Ensure that queries in Bing web search are done with SafeSearch set to the value specified. Users can't change this setting.\n\nIf you configure this policy to \"Off\", SafeSearch in Bing search falls back to the bing.com value.\n\nIf you configure this policy to \"Moderate\", the moderate setting is used in SafeSearch. The moderate setting filters adult videos and images but not text from search results.\n\nIf you configure this policy to \"Strict\", the strict setting in SafeSearch is used. The strict setting filters adult text, images, and videos.\n\nIf you disable this policy or don't configure it, SafeSearch in Bing search isn't enforced, and users can set the value they want on bing.com.\n\n* 0 = Don't configure search restrictions in Bing\n\n* 1 = Configure moderate search restrictions in Bing\n\n* 2 = Configure strict search restrictions in Bing","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#forcebingsafesearch"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_forcebingsafesearch_0","displayName":"Don't configure search restrictions in Bing","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch_1","displayName":"Configure moderate search restrictions in Bing","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_forcebingsafesearch_2","displayName":"Configure strict search restrictions in Bing","description":null,"helpText":null}]},"ad944bcc8fb9fa8d":{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default","displayName":"Is default","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_managedsearchengines_item_is_default_true","displayName":"Enabled","description":null,"helpText":null}]},"adde5445f36750c1":{"id":"com.apple.security.firewall_applications_item_bundleid","displayName":"Bundle ID","description":"The bundle identifier for an app.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":null},"adabf83e33ae9137":{"id":"com.apple.systemconfiguration_proxies_ftpport","displayName":"FTP Port","description":"The FTP proxy port.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},"adc034b77446e56e":{"id":"com.apple.webcontent-filter_allowlistbookmarks_item_url","displayName":"URL","description":"The URL of the bookmark in the allow list.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},"adb76807b5297a25":{"id":"com.microsoft.edge.mamedgeappconfigsettings.webusbaskforurls","displayName":"Allow WebUSB on specific sites","description":"Define a list of sites, based on URL patterns, that can ask the user for access to a USB device.\n\nIf you don't configure this policy, the global default value from the \"DefaultWebUsbGuardSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nThe URL patterns defined in this policy can't conflict with those configured in the \"WebUsbBlockedForUrls\" policy - you can't both allow and block a URL. For detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"ad1ffbe92989dd32":{"id":"contentcaching_logclientidentity","displayName":"Log Client Identity","description":"If `true`, the Content Cache logs the IP address and port number of the clients that request content.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_logclientidentity_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_logclientidentity_true","displayName":"Enabled","description":null,"helpText":null}]},"ad7a7cf45ef0b13c":{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name","displayName":"Allow data recovery agent","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvallowdra_name_1","displayName":"True","description":null,"helpText":null}]},"ad1fdce9d2033bbd":{"id":"device_vendor_msft_maintenancewindows_dayofmonth","displayName":"Day of month","description":"Specify the day of the month on which the maintenance window should run. Value must be between 1 and 28.","helpText":"1–28.","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":null},"ad15a989aec1129f":{"id":"device_vendor_msft_policy_config_admx_diskquota_dq_limit_dq_thresholdvalue","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","categoryName":"Disk Quotas","options":null},"ad1632788dc5e4bc":{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage","displayName":"Restricts the UI language Windows uses for all logged users","description":"This policy setting restricts the Windows UI language for all users.\r\n\r\nThis is a policy setting for computers with more than one UI language installed.\r\n\r\nIf you enable this policy setting, the UI language of Windows menus and dialogs for systems with more than one language will follow the language specified by the administrator as the system UI languages. The UI language selected by the user will be ignored if it is different than any of the system UI languages.\r\n\r\nIf you disable or do not configure this policy setting, the user can specify which UI language is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-lockmachineuilanguage"],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_globalization_lockmachineuilanguage_1","displayName":"Enabled","description":null,"helpText":null}]},"adb7468f612f9372":{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili","displayName":"Provide information about previous logons to client computers","description":"This policy setting controls whether the domain controller provides information about previous logons to client computers.\r\n\r\nIf you enable this policy setting, the domain controller provides the information message about previous logons.\r\n\r\nFor Windows Logon to leverage this feature, the \"Display information about previous logons during user logon\" policy setting located in the Windows Logon Options node under Windows Components also needs to be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the domain controller does not provide information about previous logons unless the \"Display information about previous logons during user logon\" policy setting is enabled.\r\n\r\nNote: Information about previous logons is provided only if the domain functional level is Windows Server 2008. In domains with a domain functional level of Windows Server 2003, Windows 2000 native, or Windows 2000 mixed, domain controllers cannot provide information about previous logons, and enabling this policy setting does not affect anything.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-emitlili"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_emitlili_1","displayName":"Enabled","description":null,"helpText":null}]},"adf69ed7c1325693":{"id":"device_vendor_msft_policy_config_admx_ncsi_ncsi_corpdnsprobehost_ncsi_corpdnsprobehostbox","displayName":"Corporate DNS Probe Hostname:","description":null,"helpText":"","infoUrls":[],"categoryId":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","categoryName":"Network Connectivity Status Indicator","options":null},"ad7461307539d7db":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundsuccessfulrefreshperiod_netlogon_backgroundsuccessfulrefreshperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"add4df0c12cc9157":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncblockoutperiodstarttime","displayName":"Blockout Start Time (HHMM)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"ad71c2b031c0064c":{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent","displayName":"Set percentage of disk space used for client computer cache","description":"This policy setting specifies the default percentage of total disk space that is allocated for the BranchCache disk cache on client computers.\r\n\r\nIf you enable this policy setting, you can configure the percentage of total disk space to allocate for the cache.\r\n\r\nIf you disable or do not configure this policy setting, the cache is set to 5 percent of the total disk space on the client computer.\r\n\r\nPolicy configuration\r\n\r\nSelect one of the following:\r\n\r\n- Not Configured. With this selection, BranchCache client computer cache settings are not applied to client computers by this policy. In the circumstance where client computers are domain members but you do not want to configure a BranchCache client computer cache setting on all client computers, you can specify Not Configured for this domain Group Policy setting, and then configure local computer policy to enable BranchCache client computer cache settings on individual client computers. Because the domain Group Policy setting is not configured, it will not over-write the client computer cache setting that you use on individual client computers.\r\n\r\n- Enabled. With this selection, the BranchCache client computer cache setting is enabled for all client computers where the policy is applied. For example, if Set percentage of disk space used for client computer cache is enabled in domain Group Policy, the BranchCache client computer cache setting that you specify in the policy is turned on for all domain member client computers to which the policy is applied.\r\n\r\n- Disabled. With this selection, BranchCache client computers use the default client computer cache setting of five percent of the total disk space on the client computer.\r\n\r\nIn circumstances where this setting is enabled, you can also select and configure the following option:\r\n\r\n- Specify the percentage of total disk space allocated for the cache. Specifies an integer that is the percentage of total client computer disk space to use for the BranchCache client computer cache.\r\n\r\n* This policy setting is supported on computers that are running Windows Vista Business, Enterprise, and Ultimate editions with Background Intelligent Transfer Service (BITS) 4.0 installed.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-peertopeercaching#admx-peertopeercaching-setcachepercent"],"categoryId":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","categoryName":"Branch Cache","options":[{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_peertopeercaching_setcachepercent_1","displayName":"Enabled","description":null,"helpText":null}]},"ad93d644164ec631":{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2","displayName":"Turn off hardware buttons","description":"Turns off Tablet PC hardware buttons.\r\n\r\nIf you enable this policy, no actions will occur when the buttons are pressed, and the buttons tab in Tablet PC Control Panel will be removed.\r\n\r\nIf you disable this policy, user and OEM defined button actions will occur when the buttons are pressed.\r\n\r\nIf you do not configure this policy, user and OEM defined button actions will occur when the buttons are pressed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-turnoffbuttons-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_turnoffbuttons_2_1","displayName":"Enabled","description":null,"helpText":null}]},"adcc3e37956052bc":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013","displayName":"Microsoft Office 365 OneNote 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 OneNote 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 OneNote 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 OneNote 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 OneNote 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 OneNote 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365onenote2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365onenote2013_1","displayName":"Enabled","description":null,"helpText":null}]},"ade8fca10f0fa41a":{"id":"device_vendor_msft_policy_config_appvirtualization_allowroamingregistryexclusions_integration_roaming_registry_exclusions_prompt","displayName":"Roaming File Exclusions","description":"","helpText":"","infoUrls":[],"categoryId":"ea9a092f-dd93-41d4-9bbb-118de1213578","categoryName":"Integration","options":null},"ad0e46d69b9f4cb5":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity","displayName":"Detailed Tracking Audit DPAPI Activity","description":"This policy setting allows you to audit events generated when encryption or decryption requests are made to the Data Protection application interface (DPAPI). DPAPI is used to protect secret information such as stored password and key information. For more information about DPAPI, see https://go.microsoft.com/fwlink/?LinkId=121720. If you configure this policy setting, an audit event is generated when an encryption or decryption request is made to DPAPI. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated when an encryption or decryption request is made to DPAPI.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditdpapiactivity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditdpapiactivity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"ad26e187fa5b8d5b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended","displayName":"Import saved passwords from default browser on first run","description":"Setting the policy to Enabled imports saved passwords from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no saved passwords are imported on first run.\r\n\r\nUsers can trigger an import dialog and the saved passwords checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_importsavedpasswords_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"adebde612f0a4ea2":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended","displayName":"Enable Live Translate","description":"Enable translation of live captions. Captions will be sent to Google for translation.\r\n\r\nIf this policy is set to Enabled, Live Translate will always be turned on.\r\n\r\nIf this policy is set to Disabled, Live Translate will always be turned off.\r\n\r\nIf you set this policy as mandatory, users cannot change or override it.\r\n\r\nIf this policy is left unset, Live Translate is disabled initially but can be enabled by the user anytime.\r\n\r\nIn LiveCaptionEnabled is set to Disabled, Live Translate will be disabled regardless of this policy setting.","helpText":"","infoUrls":[],"categoryId":"12142994-4b30-486c-bab1-9206528b2b96","categoryName":"Accessibility settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended~accessibility_recommended_livetranslateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"ad78360932c527de":{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats","displayName":"Remediation action for Severe threats","description":"","helpText":"","infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_clean","displayName":"Clean. Service tries to recover files and try to disinfect.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_quarantine","displayName":"Quarantine. Moves files to quarantine.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_remove","displayName":"Remove. Removes files from system.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_allow","displayName":"Allow. Allows file/does none of the above actions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_userdefined","displayName":"User defined. Requires user to make a decision on which action to take.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_severethreats_block","displayName":"Block. Blocks file execution.","description":null,"helpText":null}]},"adec7deb6ea755b1":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads","displayName":"Allow font downloads","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, HTML fonts can be downloaded automatically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowfontdownloads"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"ade012b9592716ea":{"id":"device_vendor_msft_policy_config_lanmanserver_authratelimiterdelayinms","displayName":"Auth Rate Limiter Delay In Ms","description":"This policy controls whether the SMB server will use a default value in milliseconds for the invalid authentication delay. If you configure this policy setting, the authentication rate limiter will use the specified value for delaying invalid authentication attempts. If you do not configure this policy setting, the authentication rate limiter will use the default value obtained from either the software licensing service or the local registry.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanServer#authratelimiterdelayinms"],"categoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","categoryName":"Lanman Server","options":null},"ad0997f31b6255ce":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_leteveryonepermissionsapplytoanonymoususers","displayName":"Network Access Let Everyone Permissions Apply To Anonymous Users","description":"Network access: Let Everyone permissions apply to anonymous users This security setting determines what additional permissions are granted for anonymous connections to the computer. Windows allows anonymous users to perform certain activities, such as enumerating the names of domain accounts and network shares. This is convenient, for example, when an administrator wants to grant access to users in a trusted domain that does not maintain a reciprocal trust. By Default, the Everyone security identifier (SID) is removed from the token created for anonymous connections. Therefore, permissions granted to the Everyone group do not apply to anonymous users. If this option is set, anonymous users can only access those resources for which the anonymous user has been explicitly given permission. If this policy is enabled, the Everyone SID is added to the token that is created for anonymous connections. In this case, anonymous users are able to access any resource for which the Everyone group has been given permissions. Default: Disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_leteveryonepermissionsapplytoanonymoususers"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"adf84fe920b464ce":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\r\n\r\nIf you enable, this policy, the option to import search engine settings is automatically selected.\r\n\r\nIf you disable this policy, search engine settings aren't imported at first run, and users can’t import them manually.\r\n\r\nIf you don’t configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\r\n\r\nYou can set this policy as a recommendation. This means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importsearchengine_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"adf857235a17a9ee":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotblocklist_browsingwithcopilotblocklistdesc","displayName":"Browsing with Copilot Blocked URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"ad3b3c533bb7d1cc":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled","displayName":"Allow managed extensions to use the Enterprise Hardware Platform API","description":"When this policy is set to enabled, extensions installed by enterprise policy are allowed to use the Enterprise Hardware Platform API.\r\nWhen this policy is set to disabled or isn't set, no extensions are allowed to use the Enterprise Hardware Platform API.\r\nThis policy also applies to component extensions.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_enterprisehardwareplatformapienabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ad500ba6a4061b2b":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_filesystemreadaskforurls_filesystemreadaskforurlsdesc","displayName":"Allow read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"ad0780053442ff2f":{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\r\n\r\nPolicy options mapping:\r\n\r\n* any (any) = Allow printing with and without background graphics\r\n\r\n* enabled (enabled) = Allow printing only with background graphics\r\n\r\n* disabled (disabled) = Allow printing only without background graphics\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev89~policy~microsoft_edge~printing_printingallowedbackgroundgraphicsmodes_1","displayName":"Enabled","description":null,"helpText":null}]},"adeae8e67395c32d":{"id":"device_vendor_msft_policy_config_system_disablesystemrestore","displayName":"Turn off System Restore","description":"Allows you to disable System Restore.\n\nThis policy setting allows you to turn off System Restore.\n\nSystem Restore enables users, in the event of a problem, to restore their computers to a previous state without losing personal data files. By default, System Restore is turned on for the boot volume.\n\nIf you enable this policy setting, System Restore is turned off, and the System Restore Wizard cannot be accessed. The option to configure System Restore or create a restore point through System Protection is also disabled.\n\nIf you disable or do not configure this policy setting, users can perform System Restore and configure System Restore settings through System Protection.\n\nAlso, see the \"Turn off System Restore configuration\" policy setting. If the \"Turn off System Restore\" policy setting is disabled or not configured, the \"Turn off System Restore configuration\" policy setting is used to determine whether the option to configure System Restore is available.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-system#system-disablesystemrestore"],"categoryId":"5c9a2f21-d3a8-4295-a803-e0535aa29489","categoryName":"System Restore","options":[{"id":"device_vendor_msft_policy_config_system_disablesystemrestore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_system_disablesystemrestore_1","displayName":"Enabled","description":null,"helpText":null}]},"ad2d7fb4db58766b":{"id":"linux_mdatp_managed_antivirusengine_enablerealtimeprotection","displayName":"Enable real-time protection (deprecated)","description":"Locates and stops malware from installing or running on your device. You can turn off this setting for a short time before it turns back on automatically.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#enable--disable-real-time-protection"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_enablerealtimeprotection_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_enablerealtimeprotection_true","displayName":"Enabled","description":null,"helpText":null}]},"ad3d354ec91ad12b":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders50","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders50_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_allowsubfolders50_1","displayName":"True","description":null,"helpText":null}]},"adf636ba2665a2ec":{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_1","displayName":"Do not allow window animations (User)","description":"This policy setting controls the appearance of window animations such as those found when restoring, minimizing, and maximizing windows. \r\n\r\nIf you enable this policy setting, window animations are turned off. \r\n\r\nIf you disable or do not configure this policy setting, window animations are turned on. \r\n\r\nChanging this policy setting requires a logoff for it to be applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdisallowanimations-1"],"categoryId":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","categoryName":"Desktop Window Manager","options":[{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_dwm_dwmdisallowanimations_1_1","displayName":"Enabled","description":null,"helpText":null}]},"adb4614e401bf596":{"id":"user_vendor_msft_policy_config_admx_logon_run_1","displayName":"Run these programs at user logon (User)","description":"This policy setting specifies additional programs or documents that Windows starts automatically when a user logs on to the system.\r\n\r\nIf you enable this policy setting, you can specify which programs can run at the time the user logs on to this computer that has this policy applied.\r\n\r\nTo specify values for this policy setting, click Show. In the Show Contents dialog box in the Value column, type the name of the executable program (.exe) file or document file. To specify another name, press ENTER, and type the name. Unless the file is located in the %Systemroot% directory, you must specify the fully qualified path to the file.\r\n\r\nIf you disable or do not configure this policy setting, the user will have to start the appropriate programs after logon.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the system starts the programs specified in the Computer Configuration setting just before it starts the programs specified in the User Configuration setting.\r\n\r\nAlso, see the \"Do not process the legacy run list\" and the \"Do not process the run once list\" settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-run-1"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"user_vendor_msft_policy_config_admx_logon_run_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_logon_run_1_1","displayName":"Enabled","description":null,"helpText":null}]},"ada8d65a239fb504":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_hra","displayName":"Health Registration Authority (HRA) (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-hra"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_hra_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_hra_1","displayName":"Enabled","description":null,"helpText":null}]},"adbd13a30877062d":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitysettings_1","displayName":"Security Settings (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-securitysettings-1"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitysettings_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_securitysettings_1_1","displayName":"Enabled","description":null,"helpText":null}]},"ad2f24bd40918af2":{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremoterestore_1","displayName":"Prevent restoring remote previous versions (User)","description":"This setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a file on a file share.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a file on a file share.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a file on a file share. If the user clicks the Restore button, Windows attempts to restore the file from the file share.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a file on a file share.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disableremoterestore-1"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremoterestore_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_previousversions_disableremoterestore_1_1","displayName":"Enabled","description":null,"helpText":null}]},"ad7b68bb06ebe762":{"id":"user_vendor_msft_policy_config_admx_shellcommandpromptregedittools_disablecmd","displayName":"Prevent access to the command prompt (User)","description":"This policy setting prevents users from running the interactive command prompt, Cmd.exe. This policy setting also determines whether batch files (.cmd and .bat) can run on the computer.\r\n\r\nIf you enable this policy setting and the user tries to open a command window, the system displays a message explaining that a setting prevents the action.\r\n\r\nIf you disable this policy setting or do not configure it, users can run Cmd.exe and batch files normally.\r\n\r\nNote: Do not prevent the computer from running batch files if the computer uses logon, logoff, startup, or shutdown batch file scripts, or for users that use Remote Desktop Services.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-shellcommandpromptregedittools#admx-shellcommandpromptregedittools-disablecmd"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_shellcommandpromptregedittools_disablecmd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_shellcommandpromptregedittools_disablecmd_1","displayName":"Enabled","description":null,"helpText":null}]},"adabd09bf62e959e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"adf3034910cbe106":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled","displayName":"Enable Translate (User)","description":"Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features.\r\n\r\nIf you set the policy, users can't change this function. Leaving it unset lets them change the setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ad2e6b3c12e25c19":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter","displayName":"Print Headers and Footers (User)","description":"Setting the policy to Enabled turns headers and footers on in print preview. Setting the policy to Disabled turns them off in print preview.\r\n\r\nIf you set the policy, users can't change it. If unset, users decides whether headers and footers appear.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printheaderfooter_1","displayName":"Enabled","description":null,"helpText":null}]},"ad921f635a11436b":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_enterprisesearchaggregatorsettings","displayName":"Enterprise search aggregator settings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"add4ce8d58f36d06":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist","displayName":"Enterprise profile separation secondary domain allowlist (User)","description":"If this policy is unset, account logins will not be required to create a new separate profile.\r\n\r\nIf this policy is set, account logins from the listed domains will not be required to create a new separate profile.\r\n\r\nThis policy can be set to an empty string so that all account logins are required to create a new separate profile.\r\n\r\nExample value:\r\n\r\ndomain.com\r\notherdomain.com","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_profileseparationdomainexceptionlist_1","displayName":"Enabled","description":null,"helpText":null}]},"ad6e2b4f5b11eb64":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders68_1","displayName":"True","description":null,"helpText":null}]},"adbed1906f004d56":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally","displayName":"Do not cache network files locally (User)","description":"This policy setting allows you to configure whether network files are locally cached when editing spreadsheets stored on network shares.\r\n\r\nIf you enable this policy setting, a file located on a network share may not be saved if the network connection was lost at any time while editing the file and the file contains a pivot table, VBE code or an embedded OLE object. \r\n\r\nIf you disable or do not configure this policy setting, network files are locally cached when editing spreadsheets stored on network shares. This may help prevent data loss during network failures.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_miscellaneous168_l_donotcachenetworkfileslocally_1","displayName":"Enabled","description":null,"helpText":null}]},"adf213170d2a3416":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode","displayName":"Run .NET Framework-reliant components signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute signed managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute signed managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute signed managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute signed managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonerunnetframeworkreliantcomponentssignedwithauthenticode_1","displayName":"Enabled","description":null,"helpText":null}]},"ad68c634c206dbb8":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended~startup_recommended_setntpdefaultfeedtab_recommended_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},"ad3630eaed7e5670":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice04_l_broadcastserviceserverdescription4","displayName":"Description (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"ad1d2239509e9344":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_maxnumberofdocumentsbeingreviewedusingadhocreview_l_empty388","displayName":"\r\nMax number of documents being reviewed using ad hoc review\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":null},"adf7d4bb67d0a33b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon","displayName":"French (Cameroon) (User)","description":"Enables the editing language French (Cameroon)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchcameroon_1","displayName":"Enabled","description":null,"helpText":null}]},"ad0f0805da71bed1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco","displayName":"French (Morocco) (User)","description":"Enables the editing language French (Morocco)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchmorocco_1","displayName":"Enabled","description":null,"helpText":null}]},"ad56e3e37801d095":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi","displayName":"Punjabi (User)","description":"Enables the editing language Punjabi","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabi_1","displayName":"Enabled","description":null,"helpText":null}]},"ad93e150e8351df3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil","displayName":"Tamil (User)","description":"Enables the editing language Tamil","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_tamil_1","displayName":"Enabled","description":null,"helpText":null}]},"adb70214d30dfc76":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17","displayName":"Escrow Key #17 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey17_1","displayName":"Enabled","description":null,"helpText":null}]},"adfab9b5b93092d0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setworkgrouppathforlabelpagesizeupdatefiles_l_setworkgrouppathforlabelpagesizeupdatefilesid","displayName":"Workgroup path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":null},"ad77b5f4623c4d24":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_freebusyupdatedontheservereveryxxxseconds","displayName":"Free/Busy updated on the server every xxx seconds: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},"ad3af6e25c71057c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_l_specifylistofsocialnetworkproviderstoloadid","displayName":"Separate ProgIDs with semi-colons (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},"ad8da47f25677328":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay","displayName":"Do not display Folder Size button on folder properties dialog box (User)","description":"Retains/Removes the \"Folder Size\" button in the General tab of the Properties dialog box.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_foldersizedisplay_1","displayName":"Enabled","description":null,"helpText":null}]},"ad38d4aabdb6ea0f":{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink","displayName":"Disable Outlook Mobile Hyperlink (User)","description":"This policy setting determines if the Outlook Mobile Hyperlink is shown in Account Settings.\r\n\r\nIf you enable this policy setting, users will be unable to view the Outlook Mobile Hyperlink in Account Settings.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableoutlookmobilehyperlink_1","displayName":"Enabled","description":null,"helpText":null}]},"ad9d3c1c7504b403":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar","displayName":"Show all windows in the Taskbar (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_windowsintaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"adf571bca93d09df":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel","displayName":"Publisher Automation Security Level (User)","description":"This policy setting controls whether macros opened programmatically by another application can run in Publisher.\r\n\r\nIf you enable this policy setting, you may choose an option for controlling macro behavior in Publisher when the application is opened programmatically:\r\n\r\n- Low (enabled): Macros can run in the programmatically opened application.\r\n- By UI (prompted): Macro functionality is determined by the setting in the \"Macro Settings\" section of the Trust Center.\r\n- High (disabled): All macros are disabled in the programmatically opened application.\r\n\r\nIf you disable or do not configure this policy setting, Publisher will use the default Macro setting in Trust Center.","helpText":"","infoUrls":[],"categoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security_l_publisherautomationsecuritylevel_1","displayName":"Enabled","description":null,"helpText":null}]},"ad823a9ff74e8056":{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo","displayName":"Disable Click To Do (User)","description":"Click to Do lets people take action on content on their screens. When activated, it takes a screenshot of their screen and analyzes it to present actions. Click to Do ends when they exit it, and it can't take screenshots while closed. Screenshot analysis is always performed locally on their device. By default, Click to Do is enabled for users. This policy setting allows you to determine whether Click to Do is available for users on their device. When the policy is enabled, the Click to Do component and entry points will not be available to users. When the policy is disabled, users will have Click to Do available on their device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableclicktodo"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo_0","displayName":"Click to Do is enabled","description":"Click to Do is enabled","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_disableclicktodo_1","displayName":"Click to Do is disabled.","description":"Click to Do is disabled.","helpText":null}]},"ad572ef2fcdf6490":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_defaultfilelocation_l_documents","displayName":"Documents (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},"adba08b65926c1fc":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens","displayName":"Optional hyphens (User)","description":"Determines whether the symbol used to represent optional hyphens is shown on the screen.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_optionalhyphens_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/af.json b/public/intune-definitions/af.json index 5346942afcb0..7dacff2d9da5 100644 --- a/public/intune-definitions/af.json +++ b/public/intune-definitions/af.json @@ -1 +1 @@ -{"af9832b72e000028":{"id":"com.apple.app.lock_com.apple.app.lock","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},"af3873b360e6ba21":{"id":"com.apple.applicationaccess_ratingappsfr","displayName":"Rating Apps - France","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_22","displayName":"All","description":null,"helpText":null}]},"afa2b92f99e2a550":{"id":"com.apple.appstore_restrict-store-disable-app-adoption","displayName":"Restrict-store-disable-app-adoption","description":"If true, disables app adoption by users. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":[{"id":"com.apple.appstore_restrict-store-disable-app-adoption_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.appstore_restrict-store-disable-app-adoption_true","displayName":"True","description":null,"helpText":null}]},"afb15859d603a0a6":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo_hash","displayName":"Hash","description":"The SHA-256 hash of the image.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"af55d259eb654593":{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it\nfails. Users' personal settings can allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and blocks matching origins\nfrom calling the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns are blocked.\nOrigins not specified by policy or user settings require a prior user\ngesture to call this API.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"afb99be11f01b71d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This setting limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\n\nPolicy options mapping:\n\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\n\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting_blockwindowmanagement","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting_askwindowmanagement","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},"af08156ee19cdf3f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar","description":"Set this policy to always show the Downloads button on the toolbar.\n\nIf you enable this policy, the Downloads button is pinned to the toolbar.\n\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},"afe222a03bec6524":{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended","displayName":"Configure sleeping tabs (users can override)","description":"This policy setting lets you configure whether to turn on sleeping tabs. Sleeping tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, sleeping tabs is turned on.\n\nIndividual sites may be blocked from being put to sleep by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nIf this policy is enabled, sleeping tabs are turned on.\n\nIf this policy is disabled, sleeping tabs are turned off. However, during moderate memory pressure, the system may freeze (sleep) tabs before discarding them.\n\nIf this policy is not configured, users can choose whether to enable sleeping tabs.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"afbf6ab2b551a3be":{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider","displayName":"Assign a default credential provider","description":"This policy setting allows the administrator to assign a specified credential provider as the default credential provider.\r\n\r\nIf you enable this policy setting, the specified credential provider is selected on other user tile.\r\n\r\nIf you disable or do not configure this policy setting, the system picks the default credential provider on other user tile.\r\n\r\nNote: A list of registered credential providers and their GUIDs can be found in the registry at HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Authentication\\Credential Providers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-defaultcredentialprovider"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_1","displayName":"Enabled","description":null,"helpText":null}]},"afd8d7746f97ce34":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay","displayName":"Configure Logon Script Delay","description":"\r\n Enter “0” to disable Logon Script Delay.\r\n\r\n This policy setting allows you to configure how long the Group Policy client waits after logon before running scripts.\r\n\r\n By default, the Group Policy client waits five minutes before running logon scripts. This helps create a responsive desktop environment by preventing disk contention.\r\n\r\n If you enable this policy setting, Group Policy will wait for the specified amount of time before running logon scripts.\r\n\r\n If you disable this policy setting, Group Policy will run scripts immediately after logon.\r\n\r\n If you do not configure this policy setting, Group Policy will wait five minutes before running logon scripts.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-logonscriptdelay"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"afde65f1a7738c6b":{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled","displayName":"Support authorization with client device information:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_1","displayName":"Automatic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_2","displayName":"Always","description":null,"helpText":null}]},"af0db70b22331a02":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_realtimeprotection_ioavmaxsize","displayName":"Define the maximum size of downloaded files and attachments to be scanned","description":null,"helpText":"","infoUrls":[],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":null},"af849ddcd8e25553":{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing","displayName":"Automatically publish new printers in Active Directory","description":"Determines whether the Add Printer Wizard automatically publishes the computer's shared printers in Active Directory.\r\n\r\n If you enable this setting or do not configure it, the Add Printer Wizard automatically publishes all shared printers.\r\n\r\n If you disable this setting, the Add Printer Wizard does not automatically publish printers. However, you can publish shared printers manually.\r\n\r\n The default behavior is to automatically publish shared printers in Active Directory.\r\n\r\n Note: This setting is ignored if the \"Allow printers to be published\" setting is disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-autopublishing"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing_1","displayName":"Enabled","description":null,"helpText":null}]},"afeb872d2388bfd3":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016","displayName":"Microsoft Office 365 Project 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Project 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Project 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Project 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Project 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Project 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365project2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_1","displayName":"Enabled","description":null,"helpText":null}]},"af4a0117c613fe4c":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music","displayName":"Music","description":"This policy setting configures the synchronization of user settings for the Music app.\r\nBy default, the user settings of Music sync between computers. Use the policy setting to prevent the user settings of Music from synchronizing between computers.\r\nIf you enable this policy setting, Music user settings continue to sync.\r\nIf you disable this policy setting, Music user settings are excluded from the synchronizing settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-music"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music_1","displayName":"Enabled","description":null,"helpText":null}]},"af8bb8b47d430ac2":{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration","displayName":"Disable or enable software Secure Attention Sequence","description":"This policy setting controls whether or not software can simulate the Secure Attention Sequence (SAS).\r\n\r\nIf you enable this policy setting, you have one of four options:\r\n\r\nIf you set this policy setting to \"None,\" user mode software cannot simulate the SAS.\r\nIf you set this policy setting to \"Services,\" services can simulate the SAS.\r\nIf you set this policy setting to \"Ease of Access applications,\" Ease of Access applications can simulate the SAS.\r\nIf you set this policy setting to \"Services and Ease of Access applications,\" both services and Ease of Access applications can simulate the SAS.\r\n\r\nIf you disable or do not configure this setting, only Ease of Access applications running on the secure desktop can simulate the SAS.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winlogon#admx-winlogon-softwaresasgeneration"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_1","displayName":"Enabled","description":null,"helpText":null}]},"af68a2f88097384d":{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps","displayName":"Select additional rules for trusting apps","description":"By default, any devices targeted with this App Control for Business policy will have the setting to Trust Windows components and Store apps enabled, in either audit or enforce mode based on your selection./nFurther, you can optionally add some additional rules to your policy, such as selecting Trust apps with good reputation to allow reputable apps as defined by the Microsoft Intelligent Security Graph to run./nSelect Trust apps from managed installers to allow apps deployed via authorized sources of application deployment (managed installers). The Intune management extension will be considered a managed installer if it has been set as such within your organization. Any apps not marked as coming from a managed installer will not be allowed to run./nAll other apps and files not specified by the rules in this App Control for Business policy will be audited only in local client logs (if Audit only is selected), or blocked (if Enforce is selected) from running on devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps_0","displayName":"Trust apps with good reputation","description":"Trust app with good reputation","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps_1","displayName":"Trust apps from managed installers","description":"Trust apps from managed installers","helpText":null}]},"af13f4d9a8028f47":{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse","displayName":"Privilege Use Audit Sensitive Privilege Use","description":"This policy setting allows you to audit events generated when sensitive privileges (user rights) are used such as the following: A privileged service is called. One of the following privileges are called: Act as part of the operating system. Back up files and directories. Create a token object. Debug programs. Enable computer and user accounts to be trusted for delegation. Generate security audits. Impersonate a client after authentication. Load and unload device drivers. Manage auditing and security log. Modify firmware environment values. Replace a process-level token. Restore files and directories. Take ownership of files or other objects. If you configure this policy setting, an audit event is generated when sensitive privilege requests are made. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated when sensitive privilege requests are made. ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#privilegeuse_auditsensitiveprivilegeuse"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"af0908c9352407b4":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions","description":"Setting the policy means users can't bypass download security decisions.\r\n\r\nThere are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked):\r\n\r\n* Malicious, as flagged by the Safe Browsing server\r\n* Uncommon or unwanted, as flagged by the Safe Browsing server\r\n* A dangerous file type (e.g. all SWF downloads and many EXE downloads)\r\n\r\nSetting the policy blocks different subsets of these, depending on it's value:\r\n\r\n0: No special restrictions. Default.\r\n\r\n1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n3: Blocks all downloads. Not recommended, except for special use cases.\r\n\r\n4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended.\r\n\r\nNote: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"afdf7f2bdb6384ea":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist","displayName":"Allow access to a list of URLs","description":"Setting the policy provides access to the listed URLs, as exceptions to URLBlocklist. See that policy's description for the format of entries of this list. For example, setting URLBlocklist to * will block all requests, and you can use this policy to allow access to a limited list of URLs. Use it to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths, using the format specified at ( https://www.chromium.org/administrators/url-blocklist-filter-format ). The most specific filter determines if a URL is blocked or allowed. The URLAllowlist policy takes precedence over URLBlocklist. This policy is limited to 1,000 entries.\r\n\r\nThis policy also allows enabling the automatic invocation by the browser of external application registered as protocol handlers for the listed protocols like \"tel:\" or \"ssh:\".\r\n\r\nLeaving the policy unset allows no exceptions to URLBlocklist.\r\n\r\nFrom Google Chrome version 92, this policy is also supported in the headless mode.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"af3de29cf0184988":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_urlwhitelistdesc","displayName":"Allow access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"af8c98af4a145019":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal","displayName":"Enable firewall traversal from remote access host","description":"Setting the policy to Enabled or leaving it unset allows the usage of STUN servers, letting remote clients discover and connect to this machine, even if separated by a firewall.\r\n\r\nSetting the policy to Disabled when outgoing UDP connections are filtered by the firewall means the machine only allows connections from client machines within the local network.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal_1","displayName":"Enabled","description":null,"helpText":null}]},"af779e260fcd6e16":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings","displayName":"Enable automated password change (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_0","displayName":"Allow feature use and improving AI models","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_1","displayName":"Allow feature use without improving AI models","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_2","displayName":"Do not allow feature","description":null,"helpText":null}]},"af218526565acdfe":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled","displayName":"Choose whether the Privacy Sandbox Site-suggested ads setting can be disabled","description":"A policy to control whether the Privacy Sandbox Site-suggested ads setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Site-suggested ads setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Site-suggested ads setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"af466a6627bf45ca":{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect","displayName":"Max Smb2 Dialect","description":"This policy controls the maximum version of SMB protocol. Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanWorkstation#maxsmb2dialect"],"categoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_514","displayName":"SMB 2.0.2","description":"SMB 2.0.2","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_528","displayName":"SMB 2.1.0","description":"SMB 2.1.0","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_768","displayName":"SMB 3.0.0","description":"SMB 3.0.0","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_770","displayName":"SMB 3.0.2","description":"SMB 3.0.2","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_785","displayName":"SMB 3.1.1","description":"SMB 3.1.1","helpText":null}]},"af039ec822060dd4":{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended","displayName":"Enables Microsoft Edge mini menu","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\r\n\r\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\r\n\r\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"afb2926227d11630":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"af68b60d024a07a4":{"id":"device_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"af9804388e1af42b":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags","description":"Configures users ability to override state of feature flags.\r\nIf you set this policy to 'CommandLineOverridesEnabled', users can override state of feature flags using command line arguments but not edge://flags page.\r\n\r\nIf you set this policy to 'OverridesEnabled', users can override state of feature flags using command line arguments or edge://flags page.\r\n\r\nIf you set this policy to 'OverridesDisabled', users can't override state of feature flags using command line arguments or edge://flags page.\r\n\r\nIf you don't configure this policy, the behavior is the same as the 'OverridesEnabled'.\r\n\r\nPolicy options mapping:\r\n\r\n* CommandLineOverridesEnabled (2) = Allow users to override feature flags using command line arguments only\r\n\r\n* OverridesEnabled (1) = Allow users to override feature flags\r\n\r\n* OverridesDisabled (0) = Prevent users from overriding feature flags\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"eb6409fc-fb52-413d-ae4b-eff017b52b30","categoryName":"Experimentation","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"af55d19706853f63":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls","displayName":"Automatically grant sites permission to connect all serial ports","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"afba9a770bc839d7":{"id":"device_vendor_msft_policy_config_networkisolation_neutralresources","displayName":"Neutral Resources","description":"List of domain names that can used for work or personal resource.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#neutralresources"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":null},"af30aa85f73a5404":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_visioexe","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_visioexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_visioexe_1","displayName":"True","description":null,"helpText":null}]},"afce13ffe27eb569":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_winprojexe6","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_winprojexe6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_winprojexe6_1","displayName":"True","description":null,"helpText":null}]},"af772f0aac63451e":{"id":"device_vendor_msft_policy_config_sudo_enablesudo","displayName":"Enable Sudo","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Sudo#enablesudo"],"categoryId":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","categoryName":"Sudo","options":[{"id":"device_vendor_msft_policy_config_sudo_enablesudo_0","displayName":"Sudo is disabled.","description":"Sudo is disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_sudo_enablesudo_1","displayName":"Sudo is allowed in 'force new window' mode.","description":"Sudo is allowed in 'force new window' mode.","helpText":null},{"id":"device_vendor_msft_policy_config_sudo_enablesudo_2","displayName":"Sudo is allowed in 'disable input' mode.","description":"Sudo is allowed in 'disable input' mode.","helpText":null},{"id":"device_vendor_msft_policy_config_sudo_enablesudo_3","displayName":"Sudo is allowed in 'inline' mode.","description":"Sudo is allowed in 'inline' mode.","helpText":null}]},"afde221e57160974":{"id":"device_vendor_msft_policy_config_system_allowlocation","displayName":"Allow Location","description":"Specifies whether to allow app access to the Location service. Most restricted value is 0. While the policy is set to 0 (Force Location Off) or 2 (Force Location On), any Location service call from an app would trigger the value set by this policy. When switching the policy back from 0 (Force Location Off) or 2 (Force Location On) to 1 (User Control), the app reverts to its original Location service setting. For example, an app's original Location setting is Off. The administrator then sets the AllowLocation policy to 2 (Force Location On. ) The Location service starts working for that app, overriding the original setting. Later, if the administrator switches the AllowLocation policy back to 1 (User Control), the app will revert to using its original setting of Off.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#allowlocation"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_allowlocation_0","displayName":"Force Location Off. All Location Privacy settings are toggled off and grayed out. Users cannot change the settings, and no apps are allowed access to the Location service, including Cortana and Search.","description":"Force Location Off. All Location Privacy settings are toggled off and grayed out. Users cannot change the settings, and no apps are allowed access to the Location service, including Cortana and Search.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowlocation_1","displayName":"Location service is allowed. The user has control and can change Location Privacy settings on or off.","description":"Location service is allowed. The user has control and can change Location Privacy settings on or off.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowlocation_2","displayName":"Force Location On. All Location Privacy settings are toggled on and grayed out. Users cannot change the settings and all consent permissions will be automatically suppressed.","description":"Force Location On. All Location Privacy settings are toggled on and grayed out. Users cannot change the settings and all consent permissions will be automatically suppressed.","helpText":null}]},"af8b958c9622fcd6":{"id":"device_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall","displayName":"Restrict Language Packs And Features Install","description":"This policy setting restricts the install of language packs and language features, such as spell checkers, on a device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TimeLanguageSettings#restrictlanguagepacksandfeaturesinstall"],"categoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","categoryName":"Time Language Settings","options":[{"id":"device_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall_0","displayName":"Disabled","description":"Not restricted.","helpText":null},{"id":"device_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall_1","displayName":"Enabled","description":"Restricted.","helpText":null}]},"afb664264ff8c23b":{"id":"device_vendor_msft_policy_config_virtualizationbasedtechnology_requireuefimemoryattributestable","displayName":"Require UEFI Memory Attributes Table","description":"Require UEFI Memory Attributes Table","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-VirtualizationBasedTechnology#requireuefimemoryattributestable"],"categoryId":"3588f84a-69de-4900-910c-09a5b69e5d99","categoryName":"Virtualization Based Technology","options":[{"id":"device_vendor_msft_policy_config_virtualizationbasedtechnology_requireuefimemoryattributestable_0","displayName":"Do not require UEFI Memory Attributes Table","description":"Do not require UEFI Memory Attributes Table","helpText":null},{"id":"device_vendor_msft_policy_config_virtualizationbasedtechnology_requireuefimemoryattributestable_1","displayName":"Require UEFI Memory Attributes Table","description":"Require UEFI Memory Attributes Table","helpText":null}]},"afb01718d4e8b177":{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode","displayName":"Update restriction:","description":"","helpText":"","infoUrls":[],"categoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","categoryName":"Windows App","options":[{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode_0","displayName":"Enable updates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode_1","displayName":"Disable updates from all locations","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode_2","displayName":"Disable updates from the Microsoft Store","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode_3","displayName":"Disable updates from non-store CDN location","description":null,"helpText":null}]},"afccff94ade87f21":{"id":"settings_item_voiceroaming","displayName":"Voice Roaming","description":"A dictionary that contains voice roaming settings. This setting requires the Network Information access right, and doesn't support user enrollment. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"1fbc29d7-0530-4208-b506-9df648a402e9","categoryName":"Voice Roaming","options":null},"afa6171bc3d58a5e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_datecolon48","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"af9ad64c2d5d10bf":{"id":"user_vendor_msft_policy_config_admx_taskbar_nopinningtotaskbar","displayName":"Do not allow pinning programs to the Taskbar (User)","description":"This policy setting allows you to control pinning programs to the Taskbar.\r\n\r\nIf you enable this policy setting, users cannot change the programs currently pinned to the Taskbar. If any programs are already pinned to the Taskbar, these programs continue to show in the Taskbar. However, users cannot unpin these programs already pinned to the Taskbar, and they cannot pin new programs to the Taskbar.\r\n\r\nIf you disable or do not configure this policy setting, users can change the programs currently pinned to the Taskbar.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-nopinningtotaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_nopinningtotaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_nopinningtotaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"afe73fe96212a685":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_hideprivacytab","displayName":"Hide Privacy Tab (User)","description":"This policy setting allows you to hide the Privacy tab in Windows Media Player.\r\n\r\nIf you enable this policy setting, the \"Update my music files (WMA and MP3 files) by retrieving missing media information from the Internet\" check box on the Media Library tab is available, even though the Privacy tab is hidden, unless the \"Prevent music file media information retrieval\" policy setting is enabled.\r\n\r\nThe default privacy settings are used for the options on the Privacy tab unless the user changed the settings previously.\r\n\r\nIf you disable or do not configure this policy setting, the Privacy tab is not hidden, and users can configure any privacy settings not configured by other polices.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-hideprivacytab"],"categoryId":"7f461268-0fb6-4247-b6db-52515d42a20e","categoryName":"User Interface","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_hideprivacytab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_hideprivacytab_1","displayName":"Enabled","description":null,"helpText":null}]},"aff20d6a7ceb466e":{"id":"user_vendor_msft_policy_config_attachmentmanager_hidezoneinfomechanism","displayName":"Hide mechanisms to remove zone information (User)","description":"This policy setting allows you to manage whether users can manually remove the zone information from saved file attachments by clicking the Unblock button in the file's property sheet or by using a check box in the security warning dialog. Removing the zone information allows users to open potentially dangerous file attachments that Windows has blocked users from opening.\n\nIf you enable this policy setting, Windows hides the check box and Unblock button.\n\nIf you disable this policy setting, Windows shows the check box and Unblock button.\n\nIf you do not configure this policy setting, Windows hides the check box and Unblock button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-attachmentmanager#attachmentmanager-hidezoneinfomechanism"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_attachmentmanager_hidezoneinfomechanism_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_attachmentmanager_hidezoneinfomechanism_1","displayName":"Enabled","description":null,"helpText":null}]},"af3eb1e53da57e2d":{"id":"user_vendor_msft_policy_config_browser_allowinprivate","displayName":"Allow InPrivate (User)","description":"This setting lets you decide whether employees can browse using InPrivate website browsing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowinprivate"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowinprivate_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowinprivate_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"af5f343e3e62e6d7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"af4410ff56481432":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled","displayName":"Allow download deep scanning for Safe Browsing-enabled users (User)","description":"When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives.\r\nWhen this policy is disabled, this scanning will not be performed.\r\nThis policy does not impact download content analysis configured by Chrome Enterprise Connectors.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"af58bea1aa08a0bc":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch","displayName":"Force file extension to match file type (User)","description":"This policy setting controls how Excel loads file types that do not match their extension. Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls (or any other file extension supported by Excel 2003 and earlier only), Excel can properly load it as a CSV file.\r\n\r\nIf you enable this policy setting, you can choose from three options for working with files that have non-matching extensions:\r\n\r\n- Allow different - Excel opens the files properly without warning users that the files have non-matching extensions. If users subsequently edit and save the files, Excel preserves both the true, underlying file format and the incorrect file extension.\r\n\r\n- Allow different, but warn - Excel opens the files properly, but warns users about the file type mismatch. This option is the default configuration in Excel.\r\n\r\n- Always match file type - Excel does not open any files that have non-matching extensions.\r\n\r\nIf you disable or do not configure this policy setting, if users attempt to open files with the wrong extension, Excel opens the file and displays a warning that the file type is not what Excel expected.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_1","displayName":"Enabled","description":null,"helpText":null}]},"af5ec78df43f17a9":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon18","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"af25bbf8951e007f":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c","displayName":"Only allow approved domains to use the TDC ActiveX control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_0","displayName":"Disable","description":null,"helpText":null}]},"af8c4928af2290f5":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},"af6cd91280695891":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowuserdatapersistence"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"afd1be537f647aac":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled","displayName":"Use hardware acceleration when available (User)","description":"Specify to use hardware acceleration, if it's available. If you enable this policy or don't configure it, hardware acceleration is enabled unless a GPU feature is explicitly blocked.\r\n\r\nIf you disable this policy, hardware acceleration is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"aff7ae81c5a18068":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":null},"af2e7df5d670e34a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph","displayName":"Do not display photograph (User)","description":"This policy setting lets you specify if the photograph is shown on the contact card, e-mail header, reading pane, fast search results, global address list (GAL) dialog, Backstage, and quick contacts. \r\n\r\nIf you enable this policy setting, photographs are not displayed in the locations listed above.\r\n\r\nIf you disable or do not configure this policy setting, photographs appear in the locations listed above.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph_1","displayName":"Enabled","description":null,"helpText":null}]},"af7e52b1d77c3278":{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow","displayName":"Current Channel (Preview) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow_1","displayName":"True","description":null,"helpText":null}]},"af5bbb500c1eb7fe":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot","displayName":"Load a notebook on first boot (User)","description":"Points to a folder containing a notebook that should be loaded on first boot.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_1","displayName":"Enabled","description":null,"helpText":null}]},"afe6c8e95bb2ab91":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook","displayName":"Do not promote InfoPath forms properties into Outlook properties (User)","description":"By default, InfoPath property promotion is enabled. This setting allows you to disable the ability to promote InfoPath forms properties into Outlook properties. This feature allows InfoPath forms to promote properties from the underlying data into named properties in Outlook. These properties are displayed in views on folders, and users can group, filter, and sort by them.","helpText":"","infoUrls":[],"categoryId":"e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","categoryName":"InfoPath Integration","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"af7bbc5ac382c8ef":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts","displayName":"Prevent users from adding POP3 e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts_1","displayName":"True","description":null,"helpText":null}]},"afceff80d2c8e4c7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace","displayName":"Disable Preview Place. (User)","description":"\r\n This policy setting determines whether the Preview Place feature is allowed. Enabling this setting will block the Preview Place feature from being available.\r\n Users will no longer be able to preview and provide feedback on upcoming changes in Outlook.\r\n\tNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_1","displayName":"Enabled","description":null,"helpText":null}]},"af4da0d6d73502ea":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode","displayName":"Disallow Download Full Items (User)","description":"This policy setting allows you to turn off the \"Download Full Items\" option.\r\n\r\nIf you enable this policy setting, you will turn off the \"Download Full Items\" option in the Download Preferences menu in the Send/Receive tab.\r\n\r\nIf you disable or do not configure this policy setting, you will allow the \"Download Full Items\" option in the Download Preferences menu in the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},"afb07877d433d009":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_l_entersecondstowaitbeforedownloaddefault30sec","displayName":"Enter seconds to wait before download(Default 30 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},"af9fd10f290faf70":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes","displayName":"Use Chinese font sizes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes_1","displayName":"Enabled","description":null,"helpText":null}]},"af0e5875d59e0aad":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection","displayName":"Use smart paragraph selection (User)","description":"This policy setting controls the \"Use smart paragraph selection\" option found under File tab | Options | Advanced | Editing options.\r\n\r\nIf you enable or do not configure this policy setting, Word will automatically select the paragraph mark at the end of a selected range of text.\r\n\r\nIf you disable this policy setting, Word will not automatically select the paragraph mark at the end of a selected range of text. However, a user can still select the paragraph mark manually.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"afcb77191b716d46":{"id":"ade_setupassistant_liquidglass","displayName":"Liquid Glass","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_liquidglass_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_liquidglass_1","displayName":"Show","description":null,"helpText":null}]},"af9832b72e000028":{"id":"com.apple.app.lock_com.apple.app.lock","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":null},"af3873b360e6ba21":{"id":"com.apple.applicationaccess_ratingappsfr","displayName":"Rating Apps - France","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsfr_22","displayName":"All","description":null,"helpText":null}]},"afa2b92f99e2a550":{"id":"com.apple.appstore_restrict-store-disable-app-adoption","displayName":"Restrict-store-disable-app-adoption","description":"If true, disables app adoption by users. Available in macOS 10.10 and later.","helpText":null,"infoUrls":[],"categoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","categoryName":"App Store","options":[{"id":"com.apple.appstore_restrict-store-disable-app-adoption_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.appstore_restrict-store-disable-app-adoption_true","displayName":"True","description":null,"helpText":null}]},"afb15859d603a0a6":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_light_logo_hash","displayName":"Hash","description":"The SHA-256 hash of the image.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"af55d259eb654593":{"id":"com.microsoft.edge.mamedgeappconfigsettings.automaticfullscreenblockedforurls","displayName":"Block automatic full screen on specified sites","description":"For security reasons, the\nrequestFullscreen() web API\nrequires a prior user gesture (\"transient activation\") to be called or it\nfails. Users' personal settings can allow certain origins to call this API\nwithout a prior user gesture.\n\nThis policy supersedes users' personal settings and blocks matching origins\nfrom calling the API without a prior user gesture.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\nWildcards (*) are allowed.\n\nOrigins matching both blocked and allowed policy patterns are blocked.\nOrigins not specified by policy or user settings require a prior user\ngesture to call this API.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"afb99be11f01b71d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting","displayName":"Default Window Management permission setting","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This setting limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\n\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\n\nPolicy options mapping:\n\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\n\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting_blockwindowmanagement","displayName":"Denies the Window Management permission on all sites by default","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwindowmanagementsetting_askwindowmanagement","displayName":"Ask every time a site wants obtain the Window Management permission","description":null,"helpText":null}]},"af08156ee19cdf3f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar","description":"Set this policy to always show the Downloads button on the toolbar.\n\nIf you enable this policy, the Downloads button is pinned to the toolbar.\n\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showdownloadstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},"afe222a03bec6524":{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended","displayName":"Configure sleeping tabs (users can override)","description":"This policy setting lets you configure whether to turn on sleeping tabs. Sleeping tabs reduces CPU, battery, and memory usage by putting idle background tabs to sleep. Microsoft Edge uses heuristics to avoid putting tabs to sleep that do useful work in the background, such as display notifications, play sound, and stream video. By default, sleeping tabs is turned on.\n\nIndividual sites may be blocked from being put to sleep by configuring the policy \"SleepingTabsBlockedForUrls\".\n\nIf this policy is enabled, sleeping tabs are turned on.\n\nIf this policy is disabled, sleeping tabs are turned off. However, during moderate memory pressure, the system may freeze (sleep) tabs before discarding them.\n\nIf this policy is not configured, users can choose whether to enable sleeping tabs.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabsenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"afbf6ab2b551a3be":{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider","displayName":"Assign a default credential provider","description":"This policy setting allows the administrator to assign a specified credential provider as the default credential provider.\r\n\r\nIf you enable this policy setting, the specified credential provider is selected on other user tile.\r\n\r\nIf you disable or do not configure this policy setting, the system picks the default credential provider on other user tile.\r\n\r\nNote: A list of registered credential providers and their GUIDs can be found in the registry at HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Authentication\\Credential Providers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credentialproviders#admx-credentialproviders-defaultcredentialprovider"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credentialproviders_defaultcredentialprovider_1","displayName":"Enabled","description":null,"helpText":null}]},"afd8d7746f97ce34":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay","displayName":"Configure Logon Script Delay","description":"\r\n Enter “0” to disable Logon Script Delay.\r\n\r\n This policy setting allows you to configure how long the Group Policy client waits after logon before running scripts.\r\n\r\n By default, the Group Policy client waits five minutes before running logon scripts. This helps create a responsive desktop environment by preventing disk contention.\r\n\r\n If you enable this policy setting, Group Policy will wait for the specified amount of time before running logon scripts.\r\n\r\n If you disable this policy setting, Group Policy will run scripts immediately after logon.\r\n\r\n If you do not configure this policy setting, Group Policy will wait five minutes before running logon scripts.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-logonscriptdelay"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"afde65f1a7738c6b":{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled","displayName":"Support authorization with client device information:","description":null,"helpText":"","infoUrls":[],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_0","displayName":"Never","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_1","displayName":"Automatic","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_compoundidenabled_2","displayName":"Always","description":null,"helpText":null}]},"af0db70b22331a02":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_realtimeprotection_ioavmaxsize","displayName":"Define the maximum size of downloaded files and attachments to be scanned","description":null,"helpText":"","infoUrls":[],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":null},"af849ddcd8e25553":{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing","displayName":"Automatically publish new printers in Active Directory","description":"Determines whether the Add Printer Wizard automatically publishes the computer's shared printers in Active Directory.\r\n\r\n If you enable this setting or do not configure it, the Add Printer Wizard automatically publishes all shared printers.\r\n\r\n If you disable this setting, the Add Printer Wizard does not automatically publish printers. However, you can publish shared printers manually.\r\n\r\n The default behavior is to automatically publish shared printers in Active Directory.\r\n\r\n Note: This setting is ignored if the \"Allow printers to be published\" setting is disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing2#admx-printing2-autopublishing"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_autopublishing_1","displayName":"Enabled","description":null,"helpText":null}]},"afeb872d2388bfd3":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016","displayName":"Microsoft Office 365 Project 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Project 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Project 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Project 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Project 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Project 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365project2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365project2016_1","displayName":"Enabled","description":null,"helpText":null}]},"af4a0117c613fe4c":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music","displayName":"Music","description":"This policy setting configures the synchronization of user settings for the Music app.\r\nBy default, the user settings of Music sync between computers. Use the policy setting to prevent the user settings of Music from synchronizing between computers.\r\nIf you enable this policy setting, Music user settings continue to sync.\r\nIf you disable this policy setting, Music user settings are excluded from the synchronizing settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-music"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_music_1","displayName":"Enabled","description":null,"helpText":null}]},"af8bb8b47d430ac2":{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration","displayName":"Disable or enable software Secure Attention Sequence","description":"This policy setting controls whether or not software can simulate the Secure Attention Sequence (SAS).\r\n\r\nIf you enable this policy setting, you have one of four options:\r\n\r\nIf you set this policy setting to \"None,\" user mode software cannot simulate the SAS.\r\nIf you set this policy setting to \"Services,\" services can simulate the SAS.\r\nIf you set this policy setting to \"Ease of Access applications,\" Ease of Access applications can simulate the SAS.\r\nIf you set this policy setting to \"Services and Ease of Access applications,\" both services and Ease of Access applications can simulate the SAS.\r\n\r\nIf you disable or do not configure this setting, only Ease of Access applications running on the secure desktop can simulate the SAS.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-winlogon#admx-winlogon-softwaresasgeneration"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_winlogon_softwaresasgeneration_1","displayName":"Enabled","description":null,"helpText":null}]},"af68a2f88097384d":{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps","displayName":"Select additional rules for trusting apps","description":"By default, any devices targeted with this App Control for Business policy will have the setting to Trust Windows components and Store apps enabled, in either audit or enforce mode based on your selection./nFurther, you can optionally add some additional rules to your policy, such as selecting Trust apps with good reputation to allow reputable apps as defined by the Microsoft Intelligent Security Graph to run./nSelect Trust apps from managed installers to allow apps deployed via authorized sources of application deployment (managed installers). The Intune management extension will be considered a managed installer if it has been set as such within your organization. Any apps not marked as coming from a managed installer will not be allowed to run./nAll other apps and files not specified by the rules in this App Control for Business policy will be audited only in local client logs (if Audit only is selected), or blocked (if Enforce is selected) from running on devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/security/threat-protection/windows-defender-application-control/select-types-of-rules-to-create"],"categoryId":"56b82fc9-c632-4c76-bb4f-dcf8757f003e","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps_0","displayName":"Trust apps with good reputation","description":"Trust app with good reputation","helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrol_built_in_controls_trust_apps_1","displayName":"Trust apps from managed installers","description":"Trust apps from managed installers","helpText":null}]},"af13f4d9a8028f47":{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse","displayName":"Privilege Use Audit Sensitive Privilege Use","description":"This policy setting allows you to audit events generated when sensitive privileges (user rights) are used such as the following: A privileged service is called. One of the following privileges are called: Act as part of the operating system. Back up files and directories. Create a token object. Debug programs. Enable computer and user accounts to be trusted for delegation. Generate security audits. Impersonate a client after authentication. Load and unload device drivers. Manage auditing and security log. Modify firmware environment values. Replace a process-level token. Restore files and directories. Take ownership of files or other objects. If you configure this policy setting, an audit event is generated when sensitive privilege requests are made. Success audits record successful requests and Failure audits record unsuccessful requests. If you do not configure this policy setting, no audit event is generated when sensitive privilege requests are made. ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#privilegeuse_auditsensitiveprivilegeuse"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_privilegeuse_auditsensitiveprivilegeuse_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"af0908c9352407b4":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions","description":"Setting the policy means users can't bypass download security decisions.\r\n\r\nThere are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked):\r\n\r\n* Malicious, as flagged by the Safe Browsing server\r\n* Uncommon or unwanted, as flagged by the Safe Browsing server\r\n* A dangerous file type (e.g. all SWF downloads and many EXE downloads)\r\n\r\nSetting the policy blocks different subsets of these, depending on it's value:\r\n\r\n0: No special restrictions. Default.\r\n\r\n1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n3: Blocks all downloads. Not recommended, except for special use cases.\r\n\r\n4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended.\r\n\r\nNote: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"afdf7f2bdb6384ea":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist","displayName":"Allow access to a list of URLs","description":"Setting the policy provides access to the listed URLs, as exceptions to URLBlocklist. See that policy's description for the format of entries of this list. For example, setting URLBlocklist to * will block all requests, and you can use this policy to allow access to a limited list of URLs. Use it to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths, using the format specified at ( https://www.chromium.org/administrators/url-blocklist-filter-format ). The most specific filter determines if a URL is blocked or allowed. The URLAllowlist policy takes precedence over URLBlocklist. This policy is limited to 1,000 entries.\r\n\r\nThis policy also allows enabling the automatic invocation by the browser of external application registered as protocol handlers for the listed protocols like \"tel:\" or \"ssh:\".\r\n\r\nLeaving the policy unset allows no exceptions to URLBlocklist.\r\n\r\nFrom Google Chrome version 92, this policy is also supported in the headless mode.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"af3de29cf0184988":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_urlwhitelistdesc","displayName":"Allow access to a list of URLs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"af8c98af4a145019":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal","displayName":"Enable firewall traversal from remote access host","description":"Setting the policy to Enabled or leaving it unset allows the usage of STUN servers, letting remote clients discover and connect to this machine, even if separated by a firewall.\r\n\r\nSetting the policy to Disabled when outgoing UDP connections are filtered by the firewall means the machine only allows connections from client machines within the local network.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostfirewalltraversal_1","displayName":"Enabled","description":null,"helpText":null}]},"af779e260fcd6e16":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings","displayName":"Enable automated password change (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_0","displayName":"Allow feature use and improving AI models","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_1","displayName":"Allow feature use without improving AI models","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_automatedpasswordchangesettings_automatedpasswordchangesettings_2","displayName":"Do not allow feature","description":null,"helpText":null}]},"af218526565acdfe":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled","displayName":"Choose whether the Privacy Sandbox Site-suggested ads setting can be disabled","description":"A policy to control whether the Privacy Sandbox Site-suggested ads setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Site-suggested ads setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Site-suggested ads setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxsiteenabledadsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"af466a6627bf45ca":{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect","displayName":"Max Smb2 Dialect","description":"This policy controls the maximum version of SMB protocol. Note: This group policy does not prevent use of SMB 1 if that component is still installed and enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LanmanWorkstation#maxsmb2dialect"],"categoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","categoryName":"Lanman Workstation","options":[{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_514","displayName":"SMB 2.0.2","description":"SMB 2.0.2","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_528","displayName":"SMB 2.1.0","description":"SMB 2.1.0","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_768","displayName":"SMB 3.0.0","description":"SMB 3.0.0","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_770","displayName":"SMB 3.0.2","description":"SMB 3.0.2","helpText":null},{"id":"device_vendor_msft_policy_config_lanmanworkstation_maxsmb2dialect_785","displayName":"SMB 3.1.1","description":"SMB 3.1.1","helpText":null}]},"af53c1663a0cd941":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled","displayName":"Enable clipboard suggestions in the address bar","description":"This policy controls whether suggestions based on clipboard content are shown in the address bar suggestion dropdown.\n\nIf you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown.\n\nIf you disable this policy, Microsoft Edge doesn't show suggestions based on clipboard content in the address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_addressbarclipboardsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"af039ec822060dd4":{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended","displayName":"Enables Microsoft Edge mini menu","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\r\n\r\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\r\n\r\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_quicksearchshowminimenu_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"afb2926227d11630":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"af68b60d024a07a4":{"id":"device_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_managedconfigurationperorigin_managedconfigurationperorigin","displayName":"Sets managed configuration values for websites to specific origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"af9804388e1af42b":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol","displayName":"Configure users ability to override feature flags","description":"Configures users ability to override state of feature flags.\r\nIf you set this policy to 'CommandLineOverridesEnabled', users can override state of feature flags using command line arguments but not edge://flags page.\r\n\r\nIf you set this policy to 'OverridesEnabled', users can override state of feature flags using command line arguments or edge://flags page.\r\n\r\nIf you set this policy to 'OverridesDisabled', users can't override state of feature flags using command line arguments or edge://flags page.\r\n\r\nIf you don't configure this policy, the behavior is the same as the 'OverridesEnabled'.\r\n\r\nPolicy options mapping:\r\n\r\n* CommandLineOverridesEnabled (2) = Allow users to override feature flags using command line arguments only\r\n\r\n* OverridesEnabled (1) = Allow users to override feature flags\r\n\r\n* OverridesDisabled (0) = Prevent users from overriding feature flags\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"eb6409fc-fb52-413d-ae4b-eff017b52b30","categoryName":"Experimentation","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~experimentation_featureflagoverridescontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"af55d19706853f63":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls","displayName":"Automatically grant sites permission to connect all serial ports","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available serial ports.\r\n\r\nThe URLs must be valid, or the policy is ignored. Only the origin (scheme, host, and port) of the URL is considered.\r\n\r\nThis policy overrides 'DefaultSerialGuardSetting' (Control use of the Serial API), 'SerialAskForUrls' (Allow the Serial API on specific sites), 'SerialBlockedForUrls' (Block the Serial API on specific sites) and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~contentsettings_serialallowallportsforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"afba9a770bc839d7":{"id":"device_vendor_msft_policy_config_networkisolation_neutralresources","displayName":"Neutral Resources","description":"List of domain names that can used for work or personal resource.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#neutralresources"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":null},"af30aa85f73a5404":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_visioexe","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_visioexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_visioexe_1","displayName":"True","description":null,"helpText":null}]},"afce13ffe27eb569":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_winprojexe6","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_winprojexe6_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_winprojexe6_1","displayName":"True","description":null,"helpText":null}]},"af772f0aac63451e":{"id":"device_vendor_msft_policy_config_sudo_enablesudo","displayName":"Enable Sudo","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Sudo#enablesudo"],"categoryId":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","categoryName":"Sudo","options":[{"id":"device_vendor_msft_policy_config_sudo_enablesudo_0","displayName":"Sudo is disabled.","description":"Sudo is disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_sudo_enablesudo_1","displayName":"Sudo is allowed in 'force new window' mode.","description":"Sudo is allowed in 'force new window' mode.","helpText":null},{"id":"device_vendor_msft_policy_config_sudo_enablesudo_2","displayName":"Sudo is allowed in 'disable input' mode.","description":"Sudo is allowed in 'disable input' mode.","helpText":null},{"id":"device_vendor_msft_policy_config_sudo_enablesudo_3","displayName":"Sudo is allowed in 'inline' mode.","description":"Sudo is allowed in 'inline' mode.","helpText":null}]},"afde221e57160974":{"id":"device_vendor_msft_policy_config_system_allowlocation","displayName":"Allow Location","description":"Specifies whether to allow app access to the Location service. Most restricted value is 0. While the policy is set to 0 (Force Location Off) or 2 (Force Location On), any Location service call from an app would trigger the value set by this policy. When switching the policy back from 0 (Force Location Off) or 2 (Force Location On) to 1 (User Control), the app reverts to its original Location service setting. For example, an app's original Location setting is Off. The administrator then sets the AllowLocation policy to 2 (Force Location On. ) The Location service starts working for that app, overriding the original setting. Later, if the administrator switches the AllowLocation policy back to 1 (User Control), the app will revert to using its original setting of Off.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#allowlocation"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_allowlocation_0","displayName":"Force Location Off. All Location Privacy settings are toggled off and grayed out. Users cannot change the settings, and no apps are allowed access to the Location service, including Cortana and Search.","description":"Force Location Off. All Location Privacy settings are toggled off and grayed out. Users cannot change the settings, and no apps are allowed access to the Location service, including Cortana and Search.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowlocation_1","displayName":"Location service is allowed. The user has control and can change Location Privacy settings on or off.","description":"Location service is allowed. The user has control and can change Location Privacy settings on or off.","helpText":null},{"id":"device_vendor_msft_policy_config_system_allowlocation_2","displayName":"Force Location On. All Location Privacy settings are toggled on and grayed out. Users cannot change the settings and all consent permissions will be automatically suppressed.","description":"Force Location On. All Location Privacy settings are toggled on and grayed out. Users cannot change the settings and all consent permissions will be automatically suppressed.","helpText":null}]},"af8b958c9622fcd6":{"id":"device_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall","displayName":"Restrict Language Packs And Features Install","description":"This policy setting restricts the install of language packs and language features, such as spell checkers, on a device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TimeLanguageSettings#restrictlanguagepacksandfeaturesinstall"],"categoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","categoryName":"Time Language Settings","options":[{"id":"device_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall_0","displayName":"Disabled","description":"Not restricted.","helpText":null},{"id":"device_vendor_msft_policy_config_timelanguagesettings_restrictlanguagepacksandfeaturesinstall_1","displayName":"Enabled","description":"Restricted.","helpText":null}]},"afb664264ff8c23b":{"id":"device_vendor_msft_policy_config_virtualizationbasedtechnology_requireuefimemoryattributestable","displayName":"Require UEFI Memory Attributes Table","description":"Require UEFI Memory Attributes Table","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-VirtualizationBasedTechnology#requireuefimemoryattributestable"],"categoryId":"3588f84a-69de-4900-910c-09a5b69e5d99","categoryName":"Virtualization Based Technology","options":[{"id":"device_vendor_msft_policy_config_virtualizationbasedtechnology_requireuefimemoryattributestable_0","displayName":"Do not require UEFI Memory Attributes Table","description":"Do not require UEFI Memory Attributes Table","helpText":null},{"id":"device_vendor_msft_policy_config_virtualizationbasedtechnology_requireuefimemoryattributestable_1","displayName":"Require UEFI Memory Attributes Table","description":"Require UEFI Memory Attributes Table","helpText":null}]},"afb01718d4e8b177":{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode","displayName":"Update restriction:","description":"","helpText":"","infoUrls":[],"categoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","categoryName":"Windows App","options":[{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode_0","displayName":"Enable updates","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode_1","displayName":"Disable updates from all locations","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode_2","displayName":"Disable updates from the Microsoft Store","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_updatepolicy_winapp_updatemode_3","displayName":"Disable updates from non-store CDN location","description":null,"helpText":null}]},"afccff94ade87f21":{"id":"settings_item_voiceroaming","displayName":"Voice Roaming","description":"A dictionary that contains voice roaming settings. This setting requires the Network Information access right, and doesn't support user enrollment. Available in iOS 5 and later.","helpText":null,"infoUrls":[],"categoryId":"1fbc29d7-0530-4208-b506-9df648a402e9","categoryName":"Voice Roaming","options":null},"afa6171bc3d58a5e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_datecolon48","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"af9ad64c2d5d10bf":{"id":"user_vendor_msft_policy_config_admx_taskbar_nopinningtotaskbar","displayName":"Do not allow pinning programs to the Taskbar (User)","description":"This policy setting allows you to control pinning programs to the Taskbar.\r\n\r\nIf you enable this policy setting, users cannot change the programs currently pinned to the Taskbar. If any programs are already pinned to the Taskbar, these programs continue to show in the Taskbar. However, users cannot unpin these programs already pinned to the Taskbar, and they cannot pin new programs to the Taskbar.\r\n\r\nIf you disable or do not configure this policy setting, users can change the programs currently pinned to the Taskbar.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-nopinningtotaskbar"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_nopinningtotaskbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_nopinningtotaskbar_1","displayName":"Enabled","description":null,"helpText":null}]},"afe73fe96212a685":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_hideprivacytab","displayName":"Hide Privacy Tab (User)","description":"This policy setting allows you to hide the Privacy tab in Windows Media Player.\r\n\r\nIf you enable this policy setting, the \"Update my music files (WMA and MP3 files) by retrieving missing media information from the Internet\" check box on the Media Library tab is available, even though the Privacy tab is hidden, unless the \"Prevent music file media information retrieval\" policy setting is enabled.\r\n\r\nThe default privacy settings are used for the options on the Privacy tab unless the user changed the settings previously.\r\n\r\nIf you disable or do not configure this policy setting, the Privacy tab is not hidden, and users can configure any privacy settings not configured by other polices.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-hideprivacytab"],"categoryId":"7f461268-0fb6-4247-b6db-52515d42a20e","categoryName":"User Interface","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_hideprivacytab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_hideprivacytab_1","displayName":"Enabled","description":null,"helpText":null}]},"aff20d6a7ceb466e":{"id":"user_vendor_msft_policy_config_attachmentmanager_hidezoneinfomechanism","displayName":"Hide mechanisms to remove zone information (User)","description":"This policy setting allows you to manage whether users can manually remove the zone information from saved file attachments by clicking the Unblock button in the file's property sheet or by using a check box in the security warning dialog. Removing the zone information allows users to open potentially dangerous file attachments that Windows has blocked users from opening.\n\nIf you enable this policy setting, Windows hides the check box and Unblock button.\n\nIf you disable this policy setting, Windows shows the check box and Unblock button.\n\nIf you do not configure this policy setting, Windows hides the check box and Unblock button.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-attachmentmanager#attachmentmanager-hidezoneinfomechanism"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_attachmentmanager_hidezoneinfomechanism_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_attachmentmanager_hidezoneinfomechanism_1","displayName":"Enabled","description":null,"helpText":null}]},"af3eb1e53da57e2d":{"id":"user_vendor_msft_policy_config_browser_allowinprivate","displayName":"Allow InPrivate (User)","description":"This setting lets you decide whether employees can browse using InPrivate website browsing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowinprivate"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowinprivate_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowinprivate_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"af5f343e3e62e6d7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_defaultsearchproviderencodingsdesc","displayName":"Default search provider encodings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"af4410ff56481432":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled","displayName":"Allow download deep scanning for Safe Browsing-enabled users (User)","description":"When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives.\r\nWhen this policy is disabled, this scanning will not be performed.\r\nThis policy does not impact download content analysis configured by Chrome Enterprise Connectors.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"af58bea1aa08a0bc":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch","displayName":"Force file extension to match file type (User)","description":"This policy setting controls how Excel loads file types that do not match their extension. Excel can load files with extensions that do not match the files' type. For example, if a comma-separated values (CSV) file named example.csv is renamed example.xls (or any other file extension supported by Excel 2003 and earlier only), Excel can properly load it as a CSV file.\r\n\r\nIf you enable this policy setting, you can choose from three options for working with files that have non-matching extensions:\r\n\r\n- Allow different - Excel opens the files properly without warning users that the files have non-matching extensions. If users subsequently edit and save the files, Excel preserves both the true, underlying file format and the incorrect file extension.\r\n\r\n- Allow different, but warn - Excel opens the files properly, but warns users about the file type mismatch. This option is the default configuration in Excel.\r\n\r\n- Always match file type - Excel does not open any files that have non-matching extensions.\r\n\r\nIf you disable or do not configure this policy setting, if users attempt to open files with the wrong extension, Excel opens the file and displays a warning that the file type is not what Excel expected.","helpText":"","infoUrls":[],"categoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security_l_forcefileextenstionstomatch_1","displayName":"Enabled","description":null,"helpText":null}]},"af5ec78df43f17a9":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon18","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"af25bbf8951e007f":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c","displayName":"Only allow approved domains to use the TDC ActiveX control (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_0","displayName":"Disable","description":null,"helpText":null}]},"af8c4928af2290f5":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},"af6cd91280695891":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowuserdatapersistence"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"afd1be537f647aac":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled","displayName":"Use hardware acceleration when available (User)","description":"Specify to use hardware acceleration, if it's available. If you enable this policy or don't configure it, hardware acceleration is enabled unless a GPU feature is explicitly blocked.\r\n\r\nIf you disable this policy, hardware acceleration is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_hardwareaccelerationmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"aff7ae81c5a18068":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~relatedwebsitesets_relatedwebsitesetsoverrides_relatedwebsitesetsoverrides","displayName":"Override Related Website Sets. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","categoryName":"Related Website Sets Settings","options":null},"af2e7df5d670e34a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph","displayName":"Do not display photograph (User)","description":"This policy setting lets you specify if the photograph is shown on the contact card, e-mail header, reading pane, fast search results, global address list (GAL) dialog, Backstage, and quick contacts. \r\n\r\nIf you enable this policy setting, photographs are not displayed in the locations listed above.\r\n\r\nIf you disable or do not configure this policy setting, photographs appear in the locations listed above.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_donotdisplayphotograph_1","displayName":"Enabled","description":null,"helpText":null}]},"af7e52b1d77c3278":{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow","displayName":"Current Channel (Preview) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v9~policy~l_microsoftofficesystem~l_miscellaneous437_l_updatechannelselectoruser_l_uc_insiderslow_1","displayName":"True","description":null,"helpText":null}]},"af5bbb500c1eb7fe":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot","displayName":"Load a notebook on first boot (User)","description":"Points to a folder containing a notebook that should be loaded on first boot.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_loadanotebookonfirstboot_1","displayName":"Enabled","description":null,"helpText":null}]},"afe6c8e95bb2ab91":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook","displayName":"Do not promote InfoPath forms properties into Outlook properties (User)","description":"By default, InfoPath property promotion is enabled. This setting allows you to disable the ability to promote InfoPath forms properties into Outlook properties. This feature allows InfoPath forms to promote properties from the underlying data into named properties in Outlook. These properties are displayed in views on folders, and users can group, filter, and sort by them.","helpText":"","infoUrls":[],"categoryId":"e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","categoryName":"InfoPath Integration","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_infopathintegration_l_disableinfopathpropertiespromotioninoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"af7bbc5ac382c8ef":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts","displayName":"Prevent users from adding POP3 e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingpop3emailaccounts_1","displayName":"True","description":null,"helpText":null}]},"afceff80d2c8e4c7":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace","displayName":"Disable Preview Place. (User)","description":"\r\n This policy setting determines whether the Preview Place feature is allowed. Enabling this setting will block the Preview Place feature from being available.\r\n Users will no longer be able to preview and provide feedback on upcoming changes in Outlook.\r\n\tNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablepreviewplace_1","displayName":"Enabled","description":null,"helpText":null}]},"af4da0d6d73502ea":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode","displayName":"Disallow Download Full Items (User)","description":"This policy setting allows you to turn off the \"Download Full Items\" option.\r\n\r\nIf you enable this policy setting, you will turn off the \"Download Full Items\" option in the Download Preferences menu in the Send/Receive tab.\r\n\r\nIf you disable or do not configure this policy setting, you will allow the \"Download Full Items\" option in the Download Preferences menu in the Send/Receive tab.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_disallowdownloadfullitemsfilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},"afb07877d433d009":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittodownloadchangesfromserver_l_entersecondstowaitbeforedownloaddefault30sec","displayName":"Enter seconds to wait before download(Default 30 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},"af9fd10f290faf70":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes","displayName":"Use Chinese font sizes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_usechinesefontsizes_1","displayName":"Enabled","description":null,"helpText":null}]},"af0e5875d59e0aad":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection","displayName":"Use smart paragraph selection (User)","description":"This policy setting controls the \"Use smart paragraph selection\" option found under File tab | Options | Advanced | Editing options.\r\n\r\nIf you enable or do not configure this policy setting, Word will automatically select the paragraph mark at the end of a selected range of text.\r\n\r\nIf you disable this policy setting, Word will not automatically select the paragraph mark at the end of a selected range of text. However, a user can still select the paragraph mark manually.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_usesmartparagraphselection_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/b2.json b/public/intune-definitions/b2.json index af72fc2b2102..b5928dfc92dc 100644 --- a/public/intune-definitions/b2.json +++ b/public/intune-definitions/b2.json @@ -1 +1 @@ -{"b217058b84de101d":{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP (User)","description":"If you enable this policy or leave it unset, Basic authentication challenges received over non-secure HTTP will be allowed.\r\n\r\nIf you disable this policy, non-secure HTTP requests from the Basic authentication scheme are blocked, and only secure HTTPS is allowed.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b202fed790d6e690":{"id":"com.apple.applicationaccess_allowlocalusercreation","displayName":"Allow Local User Creation","description":"If 'false', prevents creating new users in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlocalusercreation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlocalusercreation_true","displayName":"True","description":null,"helpText":null}]},"b2ab4cfb820506a6":{"id":"com.apple.applicationaccess_allowprintersharingmodification","displayName":"Allow Printer Sharing Modification","description":"If 'false', prevents modifying Printer Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowprintersharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowprintersharingmodification_true","displayName":"True","description":null,"helpText":null}]},"b28804e34caccab9":{"id":"com.apple.configurationprofile.identification_payloadidentification_promptmessage","displayName":"Prompt Message","description":"The additional descriptive text for the user prompt.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},"b233cd47843dcf93":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app","displayName":"Microsoft Teams (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"b24fa2fe390195b5":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_lcid","displayName":"Microsoft Word LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"b2b4d244b1e01da7":{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled","displayName":"Determines whether the built-in certificate verifier will be used to verify server certificates","description":"This policy is deprecated because it's intended to serve only as a short-term mechanism to give enterprises more time to update their environments and report issues if they are found to be incompatible with the built-in certificate verifier.\n\nThis policy is scheduled to be removed in Microsoft Edge for Mac OS X version 87, when support for the legacy certificate verifier on Mac OS X is planned to be removed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtincertificateverifierenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b23b92d738262437":{"id":"com.apple.managedclient.preferences_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nLeaving the policy unset means \"DefaultFileSystemReadGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemreadaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"b225e5ec80acdf57":{"id":"com.apple.managedclient.preferences_proxysettings_proxypacurl","displayName":"Proxy PAC URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"b2c56042bc6bb90e":{"id":"com.apple.managedclient.preferences_restoreonstartupurls","displayName":"Sites to open when the browser starts","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\n\nThis policy only works if you also set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4).\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartupurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"b230822f0c12f28b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users can still paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"b26f05e4a1341ebb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidername","displayName":"Default search provider name","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy isn't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"b27ff578fbf2c919":{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"b28dfdca7780b936":{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled","displayName":"Allow users to access the Microsoft Office menu (Deprecated)","description":"This policy is deprecated because the Microsoft Edge sidebar replaced it. Microsoft Office applications are now available in the sidebar, which are managed by HubsSidebarEnabled policy.\n\nWhen users can access the Microsoft Office menu, they can get access to Office applications such as Microsoft Word and Microsoft Excel.\n\nIf you enable or don't configure this policy, users can open the Microsoft Office menu.\n\nIf you disable this policy, users can't access the Microsoft Office menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b2392ce61c9cce4f":{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name","displayName":"Select the encryption type:","description":"","helpText":"","infoUrls":[],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_0","displayName":"Allow user to choose (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_1","displayName":"Full encryption","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_2","displayName":"Used Space Only encryption","description":null,"helpText":null}]},"b263e37b5deb9fb6":{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier","displayName":"Slot ID","description":"Node representing a SIM Slot. The node name is the Slot ID. SIM Slot ID format is \"0\", \"1\", etc., with exception of \"Embedded\" which represents the embedded Slot.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_embedded","displayName":"Embedded","description":"Embedded","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_0","displayName":"SIM Slot Id 0","description":"0","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_1","displayName":"SIM Slot Id 1","description":"1","helpText":null}]},"b2dbc136511fb2ee":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_nis_consumers_ips_sku_differentiation_signature_set_guidlist","displayName":"Specify additional definition sets for network traffic inspection","description":null,"helpText":"","infoUrls":[],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":null},"b2f29dcb92a0239d":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl","displayName":"Set TTL in the DC Locator DNS Records","description":"This policy setting specifies the value for the Time-To-Live (TTL) field in SRV resource records that are registered by the Net Logon service. These DNS records are dynamically registered, and they are used to locate the domain controller (DC).\r\n\r\nTo specify the TTL for DC Locator DNS records, click Enabled, and then enter a value in seconds (for example, the value \"900\" is 15 minutes).\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsttl"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_1","displayName":"Enabled","description":null,"helpText":null}]},"b25d42811448be2c":{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp_ee_enablepersistenttimestamp_desc4","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"b2fe3733ae708f6a":{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions","displayName":"Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands","description":"This policy setting prevents users from performing the following commands from the Windows security screen, the logon screen, and the Start menu: Shut Down, Restart, Sleep, and Hibernate. This policy setting does not prevent users from running Windows-based programs that perform these functions.\r\n\r\nIf you enable this policy setting, the shutdown, restart, sleep, and hibernate commands are removed from the Start menu. The Power button is also removed from the Windows Security screen, which appears when you press CTRL+ALT+DELETE, and from the logon screen.\r\n\r\nIf you disable or do not configure this policy setting, the Power button and the Shut Down, Restart, Sleep, and Hibernate commands are available on the Start menu. The Power button on the Windows Security and logon screens is also available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-hidepoweroptions"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions_1","displayName":"Enabled","description":null,"helpText":null}]},"b2fecff5ea25ba59":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint","displayName":"Microsoft PowerPoint 2010","description":"This policy setting configures the synchronization of user settings for Microsoft PowerPoint 2010.\r\nBy default, the user settings of Microsoft PowerPoint 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"b269fea508201e9e":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup","displayName":"Excel 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Excel 2013.\r\nMicrosoft Excel 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Excel 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Excel 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Excel 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013excelbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"b2edd151a093fbb6":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013","displayName":"Microsoft Office 365 Lync 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_1","displayName":"Enabled","description":null,"helpText":null}]},"b280808100cec1ee":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl","displayName":"Certificate Filter For Client SSL","description":"Specifies the path to a valid certificate in the certificate store.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowcertificatefilterforclient-ssl"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_1","displayName":"Enabled","description":null,"helpText":null}]},"b2ce9a8120e85c76":{"id":"device_vendor_msft_policy_config_bits_bandwidththrottlingstarttime","displayName":"Bandwidth Throttling Start Time","description":"This policy specifies the bandwidth throttling start time that Background Intelligent Transfer Service (BITS) uses for background transfers. This policy setting does not affect foreground transfers. This policy is based on the 24-hour clock. Value type is integer. Default value is 8 (8 am). Supported value range: 0 - 23You can specify a limit to use during a specific time interval and at all other times. For example, limit the use of network bandwidth to 10 Kbps from 8:00 A. M. to 5:00 P. M. , and use all available unused bandwidth the rest of the day's hours. Using the three policies together (BandwidthThrottlingStartTime, BandwidthThrottlingEndTime, BandwidthThrottlingTransferRate), BITS will limit its bandwidth usage to the specified values. You can specify the limit in kilobits per second (Kbps). If you specify a value less than 2 kilobits, BITS will continue to use approximately 2 kilobits. To prevent BITS transfers from occurring, specify a limit of 0. If you disable or do not configure this policy setting, BITS uses all available unused bandwidth. Note: You should base the limit on the speed of the network link, not the computer's network interface card (NIC). This policy setting does not affect peer caching transfers between peer computers (it does affect transfers from the origin server); the Limit the maximum network bandwidth used for Peercaching policy setting should be used for that purpose. Consider using this setting to prevent BITS transfers from competing for network bandwidth when the client computer has a fast network card (10Mbs), but is connected to the network via a slow link (56Kbs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#bandwidththrottlingstarttime"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},"b2c0dbfbe3142059":{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats","displayName":"Remediation action for Moderate severity threats","description":"","helpText":"","infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_clean","displayName":"Clean. Service tries to recover files and try to disinfect.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_quarantine","displayName":"Quarantine. Moves files to quarantine.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_remove","displayName":"Remove. Removes files from system.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_allow","displayName":"Allow. Allows file/does none of the above actions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_userdefined","displayName":"User defined. Requires user to make a decision on which action to take.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_block","displayName":"Block. Blocks file execution.","description":null,"helpText":null}]},"b26e8eee87a3269e":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesdiffdiskparentfolderpath_profilesdiffdiskparentfolderpath","displayName":"Diff Disk Parent Folder Path (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":null},"b289c564af5f053c":{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser","displayName":"First choice","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_","displayName":"","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},"b2218200e45f1a49":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402","displayName":"Scripting of Java applets","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_1","displayName":"Prompt","description":null,"helpText":null}]},"b2721c46b9ed21b0":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions","displayName":"Logon options","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon with current username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonelogonoptions"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"b241f95a9510d75d":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended_restoreonstartupurlsdesc","displayName":"Sites to open when the browser starts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},"b257e086fe8ef32e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings_proxysettings","displayName":"Proxy settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},"b256be49539da8bb":{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\r\n\r\nIf you enable or don't configure this policy, performance detector is turned on.\r\n\r\nIf you disable this policy, performance detector is turned off.\r\n\r\nThe user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"b2c354b669b4a88d":{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled","displayName":"Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nX.509 certificates may encode constraints, such as Name Constraints, in extensions in the certificate. RFC 5280 specifies that enforcing such constraints on trust anchor certificates is optional.\r\n\r\nStarting in Microsoft Edge 112, such constraints in certificates loaded from the platform certificate store will now be enforced.\r\n\r\nThis policy exists as a temporary opt-out in case an enterprise encounters issues with the constraints encoded in their private roots. In that case this policy may be used to temporarily disable enforcement of the constraints while correcting the certificate issues.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will enforce constraints encoded into trust anchors loaded from the platform trust store.\r\n\r\nIf you disable this policy, Microsoft Edge will not enforce constraints encoded into trust anchors loaded from the platform trust store.\r\n\r\nThis policy has no effect if the 'MicrosoftRootStoreEnabled' (Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates) policy is disabled.\r\n\r\nThis policy was removed in Microsoft Edge version 128. Starting with that version, constraints in trust anchors are always enforced.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b20d5fa17ef1f5bf":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\r\n\r\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\r\n\r\nIf this policy is disabled, users will not see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b255385aceaf18aa":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol and the protocol should be all lower case. For example, list \"skype\" instead of \"skype:\", \"skype://\" or \"Skype\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to launch an external application without prompting by policy if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ],\r\n \"protocol\": \"spotify\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ],\r\n \"protocol\": \"msteams\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"*\"\r\n ],\r\n \"protocol\": \"msoutlook\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"b2d64b3ed51e92b2":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject","displayName":"Bind to object","description":"Safe to bind to object","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_1","displayName":"Enabled","description":null,"helpText":null}]},"b2b20283f53857cf":{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_preferences_pol_autoupdatecheckperiod","displayName":"Auto-update check period override","description":"If enabled, this policy lets you set a value for the minimum number of minutes between automatic update checks. Otherwise, by default, auto-update checks for updates every 10 hours.\r\n\r\n If you want to disable all auto-update checks, set the value to 0 (not recommended).","helpText":"","infoUrls":[],"categoryId":"78497707-c3e4-400b-a6bc-1813c3689fdc","categoryName":"Preferences","options":[{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_preferences_pol_autoupdatecheckperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_preferences_pol_autoupdatecheckperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"b2971ea3afbeaf92":{"id":"device_vendor_msft_policy_config_windowsai_setdatalosspreventionprovider","displayName":"Set Data Loss Prevention Provider","description":"This policy allows an admin to specify a DLP provider, which Recall will use if the provider is properly installed. You will need to get the string for this from your provider. It will look something like 'key:HKEY_LOCAL_MACHINE\\Software\\Contoso\\DLP; value:InstallPath; binary:contosoDLP.dll' (without any quotes in the value). Important: This setting applies to Enterprise and Education client SKUs only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setdatalosspreventionprovider"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":null},"b2f6171ac670274d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_pathcolon51","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"b2c48d9de28108b5":{"id":"user_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_1","displayName":"Turn off the \"Publish to Web\" task for files and folders (User)","description":"This policy setting specifies whether the tasks \"Publish this file to the Web,\" \"Publish this folder to the Web,\" and \"Publish the selected items to the Web\" are available from File and Folder Tasks in Windows folders.\r\n\r\nThe Web Publishing Wizard is used to download a list of providers and allow users to publish content to the web.\r\n\r\nIf you enable this policy setting, these tasks are removed from the File and Folder tasks in Windows folders.\r\n\r\nIf you disable or do not configure this policy setting, the tasks are shown.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremovepublishtoweb-1"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_1_1","displayName":"Enabled","description":null,"helpText":null}]},"b2451a6ba5402ab6":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall","displayName":"Windows Firewall with Advanced Security (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-windowsfirewall"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_1","displayName":"Enabled","description":null,"helpText":null}]},"b217757922ee1a3b":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Excel files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"b2de6986dcd48e7e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36_1","displayName":"True","description":null,"helpText":null}]},"b27231d35fc7b648":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000","displayName":"Allow Binary and Script Behaviors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_65536","displayName":"Administrator approved","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_3","displayName":"Disable","description":null,"helpText":null}]},"b205b1664a0ee491":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended","displayName":"Configure the new tab page URL (User)","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"b2c69636ab24dadc":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC (User)","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\r\n\r\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\r\n\r\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\r\n\r\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\r\n\r\n * 'default' = Allow all interfaces. This exposes the local IP address.\r\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\r\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\r\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_1","displayName":"Enabled","description":null,"helpText":null}]},"b2d4322db890da9f":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"b2e787179f7c5544":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls","displayName":"Block notifications on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from displaying notifications.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultNotificationsSetting' (Default notification setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b27a7e862d2c2409":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled","displayName":"Enable 3DES cipher suites in TLS (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96.\r\n\r\n'This policy was removed in version 97 after 3DES was removed from Microsoft Edge.\r\n\r\nIf the policy is set to true, then 3DES cipher suites in TLS will be enabled. If it is set to false, they will be disabled. If the policy is unset, 3DES cipher suites are disabled by default. This policy may be used to temporarily retain compatibility with an outdated server. This is a stopgap measure and the server should be reconfigured.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b24ccd1538ac44ac":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in the 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins) policy.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"b2a3251e24b7832f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries","displayName":"Set maximum number of retries when synchronization fails (User)","description":"This policy setting allows you to specify the maximum number of times a failed synchronization operation can be retried.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of times a failed synchronization operation can be retried.\r\n\r\nIf you disable or do not configure this policy setting, then a default value of 50 times will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_1","displayName":"Enabled","description":null,"helpText":null}]},"b27b1d5087cdf8b1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations","displayName":"List of Approved Locations: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},"b2a1e1c98d060672":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw","displayName":"Disallow in SharePoint Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw_1","displayName":"True","description":null,"helpText":null}]},"b2d7174526b30399":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya","displayName":"Arabic (Libya) (User)","description":"Enables the editing language Arabic (Libya)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya_1","displayName":"Enabled","description":null,"helpText":null}]},"b2d97f43d618f804":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland","displayName":"French (Switzerland) (User)","description":"Enables the editing language French (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},"b2edf0c6a4a2b3d4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof","displayName":"Wolof (User)","description":"Enables the editing language Wolof","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof_1","displayName":"Enabled","description":null,"helpText":null}]},"b254e1978b1b5520":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion","displayName":"Active Directory timeout for querying one entry for group expansion (User)","description":"Specifies the timeout value for querying one Active Directory entry for group expansion.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_1","displayName":"Enabled","description":null,"helpText":null}]},"b2beff0e6d26419e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14","displayName":"Workflow Cache 14 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_1","displayName":"Enabled","description":null,"helpText":null}]},"b2cf35941ef4b3cb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications","displayName":"Office applications to exclude from Office Telemetry Agent reporting (User)","description":"This policy setting allows you to prevent telemetry data for Office applications from being reported to Office Telemetry Dashboard.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent does not upload telemetry data for the specified Office applications to Office Telemetry Dashboard.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data for all Office applications.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_1","displayName":"Enabled","description":null,"helpText":null}]},"b2c5ae4aafc36567":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote","displayName":"OneNote-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote_1","displayName":"True","description":null,"helpText":null}]},"b2e15519b2d70302":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments","displayName":"Allow OneNote e-mail attachments (User)","description":"Checks/Unchecks the option ''Attach a copy of the original notes as a OneNote file''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments_1","displayName":"Enabled","description":null,"helpText":null}]},"b2cb9d2f6261f4ae":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage","displayName":"Calendar Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Calendar Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"b2138b2f79e0e981":{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum","displayName":"When updating drivers for an existing connection: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum_1","displayName":"Show warning only","description":null,"helpText":null}]},"b289f839f154d30a":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword","displayName":"When selecting, automatically select entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword_1","displayName":"Enabled","description":null,"helpText":null}]},"b2ad1b5520162336":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom","displayName":"Center selection on zoom (User)","description":"Specifies that when you zoom in, whatever shape was selected appears in the center of the window.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom_1","displayName":"Enabled","description":null,"helpText":null}]},"b2edbea83ee26476":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},"b2f0a5392c84cc53":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo","displayName":"Save AutoRecover info (User)","description":"If you enable this policy setting, you can specify the number of minutes that Word will wait between saving AutoRecover information for the file. To prevent Word from ever saving AutoRecover information for the file, enable this policy and set the value to '0'.\r\n\r\nIf you disable or do not configure this policy setting, this policy will have no effect on the number of minutes that Word will wait between saving AutoRecover information for the file. By default, Word saves AutoRecover information for the file every 10 minutes.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_1","displayName":"Enabled","description":null,"helpText":null}]},"b288b5aefe020d04":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy","displayName":"Store random number to improve merge accuracy (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy_1","displayName":"Enabled","description":null,"helpText":null}]},"b2b2b1f56456704d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"b217058b84de101d":{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP (User)","description":"If you enable this policy or leave it unset, Basic authentication challenges received over non-secure HTTP will be allowed.\r\n\r\nIf you disable this policy, non-secure HTTP requests from the Basic authentication scheme are blocked, and only secure HTTPS is allowed.","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":[{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"3~policy~microsoft_edge~httpauthentication_basicauthoverhttpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b202fed790d6e690":{"id":"com.apple.applicationaccess_allowlocalusercreation","displayName":"Allow Local User Creation","description":"If 'false', prevents creating new users in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowlocalusercreation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowlocalusercreation_true","displayName":"True","description":null,"helpText":null}]},"b2ab4cfb820506a6":{"id":"com.apple.applicationaccess_allowprintersharingmodification","displayName":"Allow Printer Sharing Modification","description":"If 'false', prevents modifying Printer Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowprintersharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowprintersharingmodification_true","displayName":"True","description":null,"helpText":null}]},"b28804e34caccab9":{"id":"com.apple.configurationprofile.identification_payloadidentification_promptmessage","displayName":"Prompt Message","description":"The additional descriptive text for the user prompt.","helpText":null,"infoUrls":[],"categoryId":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","categoryName":"Identification (Deprecated)","options":null},"b233cd47843dcf93":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app","displayName":"Microsoft Teams (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"b24fa2fe390195b5":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft word.app_lcid","displayName":"Microsoft Word LCID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"b2b4d244b1e01da7":{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled","displayName":"Determines whether the built-in certificate verifier will be used to verify server certificates","description":"This policy is deprecated because it's intended to serve only as a short-term mechanism to give enterprises more time to update their environments and report issues if they are found to be incompatible with the built-in certificate verifier.\n\nThis policy is scheduled to be removed in Microsoft Edge for Mac OS X version 87, when support for the legacy certificate verifier on Mac OS X is planned to be removed.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#builtincertificateverifierenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_builtincertificateverifierenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b23b92d738262437":{"id":"com.apple.managedclient.preferences_filesystemreadaskforurls","displayName":"Allow read access via the File System API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them read access to files or directories in the host operating system's file system via the File System API.\n\nLeaving the policy unset means \"DefaultFileSystemReadGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemReadBlockedForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#filesystemreadaskforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"b225e5ec80acdf57":{"id":"com.apple.managedclient.preferences_proxysettings_proxypacurl","displayName":"Proxy PAC URL","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"b2c56042bc6bb90e":{"id":"com.apple.managedclient.preferences_restoreonstartupurls","displayName":"Sites to open when the browser starts","description":"Specify a list of websites to open automatically when the browser starts. If you don't configure this policy, no site is opened on startup.\n\nThis policy only works if you also set the \"RestoreOnStartup\" policy to 'Open a list of URLs' (4).\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#restoreonstartupurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"b230822f0c12f28b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\n\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users can still paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\n\nLeaving the policy unset means \"DefaultClipboardSetting\" applies for all sites if it's set. If it isn't set, the user's personal setting applies.\n\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"b26f05e4a1341ebb":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidername","displayName":"Default search provider name","description":"Specifies the name of the default search provider.\n\nIf you enable this policy, you set the name of the default search provider.\n\nIf you don't enable this policy or if you leave it empty, the host name specified by the search URL is used.\n\n'DefaultSearchProviderName' should be set to an organization-approved encrypted search provider that corresponds to the encrypted search provider set in DTBC-0008. This policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy isn't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"b27ff578fbf2c919":{"id":"com.microsoft.edge.mamedgeappconfigsettings.filesystemwriteblockedforurls","displayName":"Block write access to files and directories on these sites","description":"If you set this policy, you can list the URL patterns that specify which sites can't ask users to grant them write access to files or directories in the host operating system's file system.\n\nIf you don't set this policy, \"DefaultFileSystemWriteGuardSetting\" applies for all sites, if it's set. If not, users' personal settings apply.\n\nURL patterns can't conflict with \"FileSystemWriteAskForUrls\". Neither policy takes precedence if a URL matches with both.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"b28dfdca7780b936":{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled","displayName":"Allow users to access the Microsoft Office menu (Deprecated)","description":"This policy is deprecated because the Microsoft Edge sidebar replaced it. Microsoft Office applications are now available in the sidebar, which are managed by HubsSidebarEnabled policy.\n\nWhen users can access the Microsoft Office menu, they can get access to Office applications such as Microsoft Word and Microsoft Excel.\n\nIf you enable or don't configure this policy, users can open the Microsoft Office menu.\n\nIf you disable this policy, users can't access the Microsoft Office menu.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftofficemenuenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b2392ce61c9cce4f":{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name","displayName":"Select the encryption type:","description":"","helpText":"","infoUrls":[],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_0","displayName":"Allow user to choose (default)","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_1","displayName":"Full encryption","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesencryptiontype_fdvencryptiontypedropdown_name_2","displayName":"Used Space Only encryption","description":null,"helpText":null}]},"b23745a95812a669":{"id":"device_vendor_msft_maintenancewindows_updateaction","displayName":"Update action","description":"Select the update action to perform during the maintenance window.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_updateaction_1","displayName":"Download, install and restart","description":"Download, install and restart the device","helpText":null},{"id":"device_vendor_msft_maintenancewindows_updateaction_2","displayName":"Install and restart","description":"Install and restart the device","helpText":null},{"id":"device_vendor_msft_maintenancewindows_updateaction_3","displayName":"Restart only","description":"Restart the device only","helpText":null}]},"b263e37b5deb9fb6":{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier","displayName":"Slot ID","description":"Node representing a SIM Slot. The node name is the Slot ID. SIM Slot ID format is \"0\", \"1\", etc., with exception of \"Embedded\" which represents the embedded Slot.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_embedded","displayName":"Embedded","description":"Embedded","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_0","displayName":"SIM Slot Id 0","description":"0","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_identifier_1","displayName":"SIM Slot Id 1","description":"1","helpText":null}]},"b2dbc136511fb2ee":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_consumers_ips_sku_differentiation_signature_set_guid_nis_consumers_ips_sku_differentiation_signature_set_guidlist","displayName":"Specify additional definition sets for network traffic inspection","description":null,"helpText":"","infoUrls":[],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":null},"b2f29dcb92a0239d":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl","displayName":"Set TTL in the DC Locator DNS Records","description":"This policy setting specifies the value for the Time-To-Live (TTL) field in SRV resource records that are registered by the Net Logon service. These DNS records are dynamically registered, and they are used to locate the domain controller (DC).\r\n\r\nTo specify the TTL for DC Locator DNS records, click Enabled, and then enter a value in seconds (for example, the value \"900\" is 15 minutes).\r\n\r\nIf you do not configure this policy setting, it is not applied to any DCs, and DCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-dnsttl"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_dnsttl_1","displayName":"Enabled","description":null,"helpText":null}]},"b25d42811448be2c":{"id":"device_vendor_msft_policy_config_admx_reliability_ee_enablepersistenttimestamp_ee_enablepersistenttimestamp_desc4","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"b2fe3733ae708f6a":{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions","displayName":"Remove and prevent access to the Shut Down, Restart, Sleep, and Hibernate commands","description":"This policy setting prevents users from performing the following commands from the Windows security screen, the logon screen, and the Start menu: Shut Down, Restart, Sleep, and Hibernate. This policy setting does not prevent users from running Windows-based programs that perform these functions.\r\n\r\nIf you enable this policy setting, the shutdown, restart, sleep, and hibernate commands are removed from the Start menu. The Power button is also removed from the Windows Security screen, which appears when you press CTRL+ALT+DELETE, and from the logon screen.\r\n\r\nIf you disable or do not configure this policy setting, the Power button and the Shut Down, Restart, Sleep, and Hibernate commands are available on the Start menu. The Power button on the Windows Security and logon screens is also available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-hidepoweroptions"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_hidepoweroptions_1","displayName":"Enabled","description":null,"helpText":null}]},"b2fecff5ea25ba59":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint","displayName":"Microsoft PowerPoint 2010","description":"This policy setting configures the synchronization of user settings for Microsoft PowerPoint 2010.\r\nBy default, the user settings of Microsoft PowerPoint 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"b269fea508201e9e":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup","displayName":"Excel 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Excel 2013.\r\nMicrosoft Excel 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Excel 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Excel 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Excel 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013excelbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013excelbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"b2edd151a093fbb6":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013","displayName":"Microsoft Office 365 Lync 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2013_1","displayName":"Enabled","description":null,"helpText":null}]},"b280808100cec1ee":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl","displayName":"Certificate Filter For Client SSL","description":"Specifies the path to a valid certificate in the certificate store.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingallowcertificatefilterforclient-ssl"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingallowcertificatefilterforclient_ssl_1","displayName":"Enabled","description":null,"helpText":null}]},"b2ce9a8120e85c76":{"id":"device_vendor_msft_policy_config_bits_bandwidththrottlingstarttime","displayName":"Bandwidth Throttling Start Time","description":"This policy specifies the bandwidth throttling start time that Background Intelligent Transfer Service (BITS) uses for background transfers. This policy setting does not affect foreground transfers. This policy is based on the 24-hour clock. Value type is integer. Default value is 8 (8 am). Supported value range: 0 - 23You can specify a limit to use during a specific time interval and at all other times. For example, limit the use of network bandwidth to 10 Kbps from 8:00 A. M. to 5:00 P. M. , and use all available unused bandwidth the rest of the day's hours. Using the three policies together (BandwidthThrottlingStartTime, BandwidthThrottlingEndTime, BandwidthThrottlingTransferRate), BITS will limit its bandwidth usage to the specified values. You can specify the limit in kilobits per second (Kbps). If you specify a value less than 2 kilobits, BITS will continue to use approximately 2 kilobits. To prevent BITS transfers from occurring, specify a limit of 0. If you disable or do not configure this policy setting, BITS uses all available unused bandwidth. Note: You should base the limit on the speed of the network link, not the computer's network interface card (NIC). This policy setting does not affect peer caching transfers between peer computers (it does affect transfers from the origin server); the Limit the maximum network bandwidth used for Peercaching policy setting should be used for that purpose. Consider using this setting to prevent BITS transfers from competing for network bandwidth when the client computer has a fast network card (10Mbs), but is connected to the network via a slow link (56Kbs).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#bandwidththrottlingstarttime"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},"b2c0dbfbe3142059":{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats","displayName":"Remediation action for Moderate severity threats","description":"","helpText":"","infoUrls":[],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_clean","displayName":"Clean. Service tries to recover files and try to disinfect.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_quarantine","displayName":"Quarantine. Moves files to quarantine.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_remove","displayName":"Remove. Removes files from system.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_allow","displayName":"Allow. Allows file/does none of the above actions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_userdefined","displayName":"User defined. Requires user to make a decision on which action to take.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_threatseveritydefaultaction_moderateseveritythreats_block","displayName":"Block. Blocks file execution.","description":null,"helpText":null}]},"b26e8eee87a3269e":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesdiffdiskparentfolderpath_profilesdiffdiskparentfolderpath","displayName":"Diff Disk Parent Folder Path (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":null},"b289c564af5f053c":{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser","displayName":"First choice","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_","displayName":"","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},"b2218200e45f1a49":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402","displayName":"Scripting of Java applets","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_1","displayName":"Prompt","description":null,"helpText":null}]},"b2721c46b9ed21b0":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions","displayName":"Logon options","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon with current username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszonelogonoptions"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"b241f95a9510d75d":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartupurls_recommended_restoreonstartupurlsdesc","displayName":"Sites to open when the browser starts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":null},"b257e086fe8ef32e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~proxy_proxysettings_proxysettings","displayName":"Proxy settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},"b256be49539da8bb":{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended","displayName":"Performance Detector Enabled","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\r\n\r\nIf you enable or don't configure this policy, performance detector is turned on.\r\n\r\nIf you disable this policy, performance detector is turned off.\r\n\r\nThe user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"b2c354b669b4a88d":{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled","displayName":"Determines whether the built-in certificate verifier will enforce constraints encoded into trust anchors loaded from the platform trust store (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nX.509 certificates may encode constraints, such as Name Constraints, in extensions in the certificate. RFC 5280 specifies that enforcing such constraints on trust anchor certificates is optional.\r\n\r\nStarting in Microsoft Edge 112, such constraints in certificates loaded from the platform certificate store will now be enforced.\r\n\r\nThis policy exists as a temporary opt-out in case an enterprise encounters issues with the constraints encoded in their private roots. In that case this policy may be used to temporarily disable enforcement of the constraints while correcting the certificate issues.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will enforce constraints encoded into trust anchors loaded from the platform trust store.\r\n\r\nIf you disable this policy, Microsoft Edge will not enforce constraints encoded into trust anchors loaded from the platform trust store.\r\n\r\nThis policy has no effect if the 'MicrosoftRootStoreEnabled' (Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates) policy is disabled.\r\n\r\nThis policy was removed in Microsoft Edge version 128. Starting with that version, constraints in trust anchors are always enforced.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev114~policy~microsoft_edge_enforcelocalanchorconstraintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b20d5fa17ef1f5bf":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\r\n\r\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\r\n\r\nIf this policy is disabled, users will not see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge_addressbarworksearchresultsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b255385aceaf18aa":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol and the protocol should be all lower case. For example, list \"skype\" instead of \"skype:\", \"skype://\" or \"Skype\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to launch an external application without prompting by policy if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ],\r\n \"protocol\": \"spotify\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ],\r\n \"protocol\": \"msteams\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"*\"\r\n ],\r\n \"protocol\": \"msoutlook\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"b2d64b3ed51e92b2":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject","displayName":"Bind to object","description":"Safe to bind to object","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_1","displayName":"Enabled","description":null,"helpText":null}]},"b2b20283f53857cf":{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_preferences_pol_autoupdatecheckperiod","displayName":"Auto-update check period override","description":"If enabled, this policy lets you set a value for the minimum number of minutes between automatic update checks. Otherwise, by default, auto-update checks for updates every 10 hours.\r\n\r\n If you want to disable all auto-update checks, set the value to 0 (not recommended).","helpText":"","infoUrls":[],"categoryId":"78497707-c3e4-400b-a6bc-1813c3689fdc","categoryName":"Preferences","options":[{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_preferences_pol_autoupdatecheckperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_preferences_pol_autoupdatecheckperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"b2971ea3afbeaf92":{"id":"device_vendor_msft_policy_config_windowsai_setdatalosspreventionprovider","displayName":"Set Data Loss Prevention Provider","description":"This policy allows an admin to specify a DLP provider, which Recall will use if the provider is properly installed. You will need to get the string for this from your provider. It will look something like 'key:HKEY_LOCAL_MACHINE\\Software\\Contoso\\DLP; value:InstallPath; binary:contosoDLP.dll' (without any quotes in the value). Important: This setting applies to Enterprise and Education client SKUs only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setdatalosspreventionprovider"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":null},"b2f6171ac670274d":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_pathcolon51","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"b2c48d9de28108b5":{"id":"user_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_1","displayName":"Turn off the \"Publish to Web\" task for files and folders (User)","description":"This policy setting specifies whether the tasks \"Publish this file to the Web,\" \"Publish this folder to the Web,\" and \"Publish the selected items to the Web\" are available from File and Folder Tasks in Windows folders.\r\n\r\nThe Web Publishing Wizard is used to download a list of providers and allow users to publish content to the web.\r\n\r\nIf you enable this policy setting, these tasks are removed from the File and Folder tasks in Windows folders.\r\n\r\nIf you disable or do not configure this policy setting, the tasks are shown.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-shellremovepublishtoweb-1"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_icm_shellremovepublishtoweb_1_1","displayName":"Enabled","description":null,"helpText":null}]},"b2451a6ba5402ab6":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall","displayName":"Windows Firewall with Advanced Security (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-windowsfirewall"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_1","displayName":"Enabled","description":null,"helpText":null}]},"b217757922ee1a3b":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior","displayName":"Set default file block behavior (User)","description":"This policy setting allows you to determine if users can open, view, or edit Excel files.\r\n\r\nIf you enable this policy setting, you can set one of these options:\r\n- Blocked files are not opened\r\n- Blocked files open in Protected View and can not be edited\r\n- Blocked files open in Protected View and can be edited\r\n\r\nIf you disable or do not configure this policy setting, the behavior is the same as the \"Blocked files are not opened\" setting. Users will not be able to open blocked files.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_setdefaultfileblockbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"b2de6986dcd48e7e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders36_1","displayName":"True","description":null,"helpText":null}]},"b27231d35fc7b648":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000","displayName":"Allow Binary and Script Behaviors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_65536","displayName":"Administrator approved","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowbinaryandscriptbehaviors_iz_partname2000_3","displayName":"Disable","description":null,"helpText":null}]},"b23b52d50627d71a":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended","displayName":"Enable clipboard suggestions in the address bar (User)","description":"This policy controls whether suggestions based on clipboard content are shown in the address bar suggestion dropdown.\n\nIf you enable this policy or don't configure it, Microsoft Edge may show suggestions based on clipboard content in the address bar suggestion dropdown.\n\nIf you disable this policy, Microsoft Edge doesn't show suggestions based on clipboard content in the address bar suggestion dropdown.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_addressbarclipboardsuggestenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"b205b1664a0ee491":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended","displayName":"Configure the new tab page URL (User)","description":"Configures the default URL for the new tab page.\r\n\r\nThis policy determines the page that's opened when new tabs are created (including when new windows are opened). It also affects the startup page if that's set to open to the new tab page.\r\n\r\nThis policy doesn't determine which page opens on startup; that's controlled by the 'RestoreOnStartup' (Action to take on startup) policy. It also doesn’t affect the home page if that’s set to open to the new tab page.\r\n\r\nIf you don't configure this policy, the default new tab page is used.\r\n\r\nIf you configure this policy *and* the 'NewTabPageSetFeedType' (Configure the Microsoft Edge new tab page experience) policy, this policy has precedence.\r\n\r\nIf an invalid URL is provided, new tabs will open about://blank.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://www.fabrikam.com","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_newtabpagelocation_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"b2c69636ab24dadc":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC (User)","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\r\n\r\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\r\n\r\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\r\n\r\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\r\n\r\n * 'default' = Allow all interfaces. This exposes the local IP address.\r\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\r\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\r\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.\r\n\r\nExample value: default","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_webrtclocalhostiphandling_1","displayName":"Enabled","description":null,"helpText":null}]},"b2d4322db890da9f":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsallowedforurls_notificationsallowedforurlsdesc","displayName":"Allow notifications on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"b2e787179f7c5544":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls","displayName":"Block notifications on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are blocked from displaying notifications.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultNotificationsSetting' (Default notification setting) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b27a7e862d2c2409":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled","displayName":"Enable 3DES cipher suites in TLS (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96.\r\n\r\n'This policy was removed in version 97 after 3DES was removed from Microsoft Edge.\r\n\r\nIf the policy is set to true, then 3DES cipher suites in TLS will be enabled. If it is set to false, they will be disabled. If the policy is unset, 3DES cipher suites are disabled by default. This policy may be used to temporarily retain compatibility with an outdated server. This is a stopgap measure and the server should be reconfigured.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_tripledesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b24ccd1538ac44ac":{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins (User)","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\r\n\r\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\r\n\r\nThis policy is not considered if a site matches a URL pattern in the 'SameOriginTabCaptureAllowedByOrigins' (Allow Same Origin Tab capture by these origins) policy.\r\n\r\nIf a site matches a URL pattern in this policy, the following policies will not be considered: 'WindowCaptureAllowedByOrigins' (Allow Window and Tab capture by these origins), 'ScreenCaptureAllowedByOrigins' (Allow Desktop, Window, and Tab capture by these origins), 'ScreenCaptureAllowed' (Allow or deny screen capture).\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_tabcaptureallowedbyorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"b2a3251e24b7832f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries","displayName":"Set maximum number of retries when synchronization fails (User)","description":"This policy setting allows you to specify the maximum number of times a failed synchronization operation can be retried.\r\n\r\nIf you enable this policy setting, you may specify the maximum number of times a failed synchronization operation can be retried.\r\n\r\nIf you disable or do not configure this policy setting, then a default value of 50 times will be used.","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_1","displayName":"Enabled","description":null,"helpText":null}]},"b27b1d5087cdf8b1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_listofapprovedlocationspolicy_l_listofapprovedlocations","displayName":"List of Approved Locations: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":null},"b2a1e1c98d060672":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw","displayName":"Disallow in SharePoint Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuispw_1","displayName":"True","description":null,"helpText":null}]},"b2d7174526b30399":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya","displayName":"Arabic (Libya) (User)","description":"Enables the editing language Arabic (Libya)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiclibya_1","displayName":"Enabled","description":null,"helpText":null}]},"b2d97f43d618f804":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland","displayName":"French (Switzerland) (User)","description":"Enables the editing language French (Switzerland)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchswitzerland_1","displayName":"Enabled","description":null,"helpText":null}]},"b2edf0c6a4a2b3d4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof","displayName":"Wolof (User)","description":"Enables the editing language Wolof","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_wolof_1","displayName":"Enabled","description":null,"helpText":null}]},"b254e1978b1b5520":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion","displayName":"Active Directory timeout for querying one entry for group expansion (User)","description":"Specifies the timeout value for querying one Active Directory entry for group expansion.","helpText":"","infoUrls":[],"categoryId":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","categoryName":"Manage Restricted Permissions","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_managerestrictedpermissions_l_activedirectorytimeoutforqueryingoneentryforgroupexpansion_1","displayName":"Enabled","description":null,"helpText":null}]},"b2beff0e6d26419e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14","displayName":"Workflow Cache 14 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_1","displayName":"Enabled","description":null,"helpText":null}]},"b2cf35941ef4b3cb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications","displayName":"Office applications to exclude from Office Telemetry Agent reporting (User)","description":"This policy setting allows you to prevent telemetry data for Office applications from being reported to Office Telemetry Dashboard.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent does not upload telemetry data for the specified Office applications to Office Telemetry Dashboard.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data for all Office applications.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_1","displayName":"Enabled","description":null,"helpText":null}]},"b2c5ae4aafc36567":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote","displayName":"OneNote-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsonenote_1","displayName":"True","description":null,"helpText":null}]},"b2e15519b2d70302":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments","displayName":"Allow OneNote e-mail attachments (User)","description":"Checks/Unchecks the option ''Attach a copy of the original notes as a OneNote file''.","helpText":"","infoUrls":[],"categoryId":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_email_l_allowonenoteemailattachments_1","displayName":"Enabled","description":null,"helpText":null}]},"b2cb9d2f6261f4ae":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage","displayName":"Calendar Folder Home Page (User)","description":"This policy setting allows you to modify the \"Show home page by default for this folder\" in the Home Page tab of the Calendar Properties dialog box.\r\n\r\nIf you enable this policy setting, you will set the \"Show home page by default for this folder\" check box. You will also be able to enter a URL, which has a maximum limit of 129 characters.\r\n\r\nIf you disable or do not configure this policy setting, the \"Show home page by default for this folder\" check box will not be checked.","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_1","displayName":"Enabled","description":null,"helpText":null}]},"b2138b2f79e0e981":{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum","displayName":"When updating drivers for an existing connection: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationonupdate_enum_1","displayName":"Show warning only","description":null,"helpText":null}]},"b289f839f154d30a":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword","displayName":"When selecting, automatically select entire word (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_whenselectingautomaticallyselectentireword_1","displayName":"Enabled","description":null,"helpText":null}]},"b2ad1b5520162336":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom","displayName":"Center selection on zoom (User)","description":"Specifies that when you zoom in, whatever shape was selected appears in the center of the window.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_centerselectiononzoom_1","displayName":"Enabled","description":null,"helpText":null}]},"b2edbea83ee26476":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned","displayName":"Require that application add-ins are signed by Trusted Publisher (User)","description":"This policy setting controls whether add-ins for this applications must be digitally signed by a trusted publisher.\r\n \r\nIf you enable this policy setting, this application checks the digital signature for each add-in before loading it. If an add-in does not have a digital signature, or if the signature did not come from a trusted publisher, this application disables the add-in and notifies the user. Certificates must be added to the Trusted Publishers list if you require that all add-ins be signed by a trusted publisher. For detail on about obtaining and distributing certificates, see http://go.microsoft.com/fwlink/?LinkId=294922. Office 2016 stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Office 2016 still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store. Therefore, if you created a list of trusted publishers in a previous version of Office and you upgrade to Office 2016, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store. For more information about trusted publishers, see the Office Resource Kit.\r\n\r\nIf you disable or do not configure this policy setting, this application does not check the digital signature on application add-ins before opening them. If a dangerous add-in is loaded, it could harm users' computers or compromise data security.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_requirethatapplicationextensionsaresigned_1","displayName":"Enabled","description":null,"helpText":null}]},"b2f0a5392c84cc53":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo","displayName":"Save AutoRecover info (User)","description":"If you enable this policy setting, you can specify the number of minutes that Word will wait between saving AutoRecover information for the file. To prevent Word from ever saving AutoRecover information for the file, enable this policy and set the value to '0'.\r\n\r\nIf you disable or do not configure this policy setting, this policy will have no effect on the number of minutes that Word will wait between saving AutoRecover information for the file. By default, Word saves AutoRecover information for the file every 10 minutes.","helpText":"","infoUrls":[],"categoryId":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_save_l_saveautorecoverinfo_1","displayName":"Enabled","description":null,"helpText":null}]},"b288b5aefe020d04":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy","displayName":"Store random number to improve merge accuracy (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_storerandomnumbertoimprovemergeaccuracy_1","displayName":"Enabled","description":null,"helpText":null}]},"b2b2b1f56456704d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19","displayName":"Trusted Location #19 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/b5.json b/public/intune-definitions/b5.json index 6be22bdd3757..af908df105e5 100644 --- a/public/intune-definitions/b5.json +++ b/public/intune-definitions/b5.json @@ -1 +1 @@ -{"b5441b4e1f801627":{"id":"com.apple.dock_dblclickbehavior","displayName":"Double Click Behavior","description":"The behavior when the window's title bar is double-clicked.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_dblclickbehavior_0","displayName":"Minimize","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior_1","displayName":"Maximize","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior_2","displayName":"None","description":null,"helpText":null}]},"b5ef58db590d4cb3":{"id":"com.apple.dock_static-others_item_tile-data_url","displayName":"URL","description":"The URL string","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},"b5aafa32a261f984":{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\n\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\n\nIf this policy is disabled, users will not see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#addressbarworksearchresultsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b576def03ad9a7fa":{"id":"com.apple.managedclient.preferences_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to","description":"Configure the list of servers that Microsoft Edge can delegate to.\n\nSeparate multiple server names with commas. Wildcards (*) are allowed.\n\nIf you don't configure this policy Microsoft Edge won't delegate user credentials even if a server is detected as Intranet.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#authnegotiatedelegateallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"b5759a776d7ebe87":{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (Deprecated)","description":"This policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\n\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\n\nIf you disable this policy, the UI for the opt-out user experience is off.\n\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\n\nAfter careful evaluation, we have determined that this experimental opt-out UX is not required. As a result, this policy will be deprecated and stop working after Edge version 130.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeoptoutuxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b523ba37865416ad":{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar","description":"Set this policy to always show the Downloads button on the toolbar.\n\nIf you enable this policy, the Downloads button is pinned to the toolbar.\n\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showdownloadstoolbarbutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},"b57dcfc3b1627a1f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled","displayName":"Enhance images enabled (Obsolete)","description":"The enhance images feature is deprecated and starting in Microsoft Edge version 122, this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast.\n\nIf you enable this policy or don't configure the policy, Microsoft Edge automatically enhances images on specific web applications.\n\nIf you disable this policy, Microsoft Edge doesn't enhance images.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b5843e664861eedb":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-7"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_1","displayName":"Enabled","description":null,"helpText":null}]},"b5812dc11205d183":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc","displayName":"Set Group Policy refresh interval for domain controllers","description":"This policy setting specifies how often Group Policy is updated on domain controllers while they are running (in the background). The updates specified by this setting occur in addition to updates performed when the system starts.\r\n\r\nBy default, Group Policy on the domain controllers is updated every five minutes.\r\n\r\nIf you enable this setting, you can specify an update rate from 0 to 64,800 minutes (45 days). If you select 0 minutes, the domain controller tries to update Group Policy every 7 seconds. However, because updates might interfere with users' work and increase network traffic, very short update intervals are not appropriate for most installations.\r\n\r\nIf you disable or do not configure this setting, the domain controller updates Group Policy every 5 minutes (the default). To specify that Group Policies for users should never be updated while the computer is in use, select the \"Turn off background refresh of Group Policy\" setting.\r\n\r\nThis setting also lets you specify how much the actual update interval varies. To prevent domain controllers with the same update interval from requesting updates simultaneously, the system varies the update interval for each controller by a random number of minutes. The number you type in the random time box sets the upper limit for the range of variance. For example, if you type 30 minutes, the system selects a variance of 0 to 30 minutes. Typing a large number establishes a broad range and makes it less likely that update requests overlap. However, updates might be delayed significantly.\r\n\r\nNote: This setting is used only when you are establishing policy for a domain, site, organizational unit (OU), or customized group. If you are establishing policy for a local computer only, the system ignores this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-grouppolicyrefreshratedc"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_1","displayName":"Enabled","description":null,"helpText":null}]},"b5a4472ffef0cec6":{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2","displayName":"Do not display the Getting Started welcome screen at logon","description":"This policy setting hides the welcome screen that is displayed on Windows 2000 Professional each time the user logs on.\r\n\r\nIf you enable this policy setting, the welcome screen is hidden from the user logging on to a computer where this policy is applied.\r\n\r\nUsers can still display the welcome screen by selecting it on the Start menu or by typing \"Welcome\" in the Run dialog box.\r\n\r\nIf you disable or do not configure this policy, the welcome screen is displayed each time a user logs on to the computer.\r\n\r\nThis setting applies only to Windows 2000 Professional. It does not affect the \"Configure Your Server on a Windows 2000 Server\" screen on Windows 2000 Server.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To display the welcome screen, click Start, point to Programs, point to Accessories, point to System Tools, and then click \"Getting Started.\" To suppress the welcome screen without specifying a setting, clear the \"Show this screen at startup\" check box on the welcome screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-nowelcometips-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2_1","displayName":"Enabled","description":null,"helpText":null}]},"b5264486c8a52f6d":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_exploitguard_controlledfolderaccess_allowedapplications_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},"b592e37c26332395":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting","displayName":"Configure local setting override for reporting to Microsoft MAPS","description":"This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-spynet-localsettingoverridespynetreporting"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting_1","displayName":"Enabled","description":null,"helpText":null}]},"b5633303398dc31a":{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel","displayName":"Tool downloads allowed","description":null,"helpText":"","infoUrls":[],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel_1","displayName":"Remote troubleshooting only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel_2","displayName":"Local and remote troubleshooting","description":null,"helpText":null}]},"b52f5da9c0da2d03":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks","displayName":"MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)","description":"MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autosharewks"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks_1","displayName":"Enabled","description":null,"helpText":null}]},"b5316522002c51aa":{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_cleanupprofiles_days","displayName":"Delete user profiles older than (days)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},"b57d406c27e2c32a":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules","displayName":"Disable runtime file path rules","description":"Turning this off will disable FilePath rule protection of enforcing user-writeability and onlu allowing admin-writable locations.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules_enabled","displayName":"Enabled","description":null,"helpText":null}]},"b50ca977f8fd1b01":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes","displayName":"Microsoft Sticky Notes","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes_1","displayName":"True","description":null,"helpText":null}]},"b5857ab605fe5314":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist","displayName":"Enable CORS check mitigations in the new CORS implementation","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_1","displayName":"Enabled","description":null,"helpText":null}]},"b57e5dcf603d3187":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls","displayName":"Block key generation on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b56272b83d3a78c8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled","displayName":"Enable PDF Annotations","description":"Controls if the PDF viewer in Google Chrome can annotate PDFs.\r\n\r\nWhen this policy is not set, or is set to true, then the PDF viewer will be able to annotate PDFs.\r\n\r\nWhen this policy is set to false, then the PDF viewer will not be able to annotate PDFs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5ec9f5871b3784f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers","description":"Allows you to set whether Google Chrome\r\nwill run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\r\n\r\nDisabling JavaScript optimizations (by setting this policy's value to 2) will\r\nmean that Google Chrome may render web\r\ncontent more slowly.\r\n\r\nThis policy can be overridden for specific URL patterns using the JavaScriptOptimizerAllowedForSites and JavaScriptOptimizerBlockedForSites policies.\r\n\r\nIf this policy is left not set, JavaScript optimizations are enabled.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_1","displayName":"Enabled","description":null,"helpText":null}]},"b5d4a5b14cab8a70":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled","displayName":"Choose whether the Privacy Sandbox Ad topics setting can be disabled","description":"A policy to control whether the Privacy Sandbox Ad topics setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Ad topics setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Ad topics setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5abd367190081d0":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockrebootingmachineinsafemode_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"b5ec5ceab1fd73e7":{"id":"device_vendor_msft_policy_config_defender_schedulescanday","displayName":"Schedule Scan Day","description":"Selects the day that the Windows Defender scan should run. Note The scan type will depends on what scan type is selected in the Defender/ScanParameter setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#schedulescanday"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_schedulescanday_0","displayName":"Every day","description":"Every day","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_1","displayName":"Sunday","description":"Sunday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_2","displayName":"Monday","description":"Monday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_3","displayName":"Tuesday","description":"Tuesday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_4","displayName":"Wednesday","description":"Wednesday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_5","displayName":"Thursday","description":"Thursday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_6","displayName":"Friday","description":"Friday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_7","displayName":"Saturday","description":"Saturday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_8","displayName":"No scheduled scan","description":"No scheduled scan","helpText":null}]},"b553d239193373b2":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingdriverinterface","displayName":"Driver Interface","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging of the driver interface.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\DriverInterface\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingdriverinterface_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingdriverinterface_1","displayName":"Enabled","description":null,"helpText":null}]},"b5be0ea520a9bbad":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirectionxmlsourcefolder","displayName":"Redirection XML Source Folder","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies the path to a folder containing the XML file. If the folder contains a redirections.xml, it will be copied to the local profile and immediately used.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\RedirXMLSourceFolder\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirectionxmlsourcefolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirectionxmlsourcefolder_1","displayName":"Enabled","description":null,"helpText":null}]},"b51dbaaab2e7d9fd":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesclearcacheonforcedunregister","displayName":"Clear Cache on Forced Unregister","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nIf the desired behavior is for the local cache to be deleted, even if the data has not been flushed to a CCD Location, then Clear Cache On Forced Unregister should be set to Enabled. Setting Clear Cache On Forced Unregister to Enabled may result in user data saved in the registry to be lost during the current session. It is important to understand that this data isn't recoverable if the local cache is cleared in this scenario. Verify that you understand the implications of changing the default value of this setting prior to making changes.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ClearCacheOnForcedUnregister\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"719595d8-ab5d-4418-88aa-8cd55c2964ba","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesclearcacheonforcedunregister_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesclearcacheonforcedunregister_1","displayName":"Enabled","description":null,"helpText":null}]},"b56b65289da4e6da":{"id":"device_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode","displayName":"Turn on Internet Explorer Standards Mode for local intranet","description":"This policy setting controls how Internet Explorer displays local intranet content. Intranet content is defined as any webpage that belongs to the local intranet security zone.\n\nIf you enable this policy setting, Internet Explorer uses the current user agent string for local intranet content. Additionally, all local intranet Standards Mode pages appear in the Standards Mode available with the latest version of Internet Explorer. The user cannot change this behavior through the Compatibility View Settings dialog box.\n\nIf you disable this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. The user cannot change this behavior through the Compatibility View Settings dialog box.\n\nIf you do not configure this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. This option results in the greatest compatibility with existing webpages, but newer content written to common Internet standards may be displayed incorrectly. This option matches the default behavior of Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetexplorerstandardsmode"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode_1","displayName":"Enabled","description":null,"helpText":null}]},"b5d01de4e8210704":{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange","displayName":"Disable changing secondary home page settings","description":"Secondary home pages are the default Web pages that Internet Explorer loads in separate tabs from the home page whenever the browser is run. This policy setting allows you to set default secondary home pages.\n\nIf you enable this policy setting, you can specify which default home pages should load as secondary home pages. The user cannot set custom default secondary home pages.\n\nIf you disable or do not configure this policy setting, the user can add secondary home pages.\n\nNote: If the “Disable Changing Home Page Settings” policy is enabled, the user cannot add secondary home pages.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecondaryhomepagechange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_1","displayName":"Enabled","description":null,"helpText":null}]},"b5b82589596b466b":{"id":"device_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths","displayName":"Intranet Sites: Include all network paths (UNCs)","description":"This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone.\n\nIf you enable this policy setting, all network paths are mapped into the Intranet Zone.\n\nIf you disable this policy setting, network paths are not necessarily mapped into the Intranet Zone (other rules might map one there).\n\nIf you do not configure this policy setting, users choose whether network paths are mapped into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includeallnetworkpaths"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_1","displayName":"Enabled","description":null,"helpText":null}]},"b50b7c11bea7aec3":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneinitializeandscriptactivexcontrols"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"b508665d33d94f75":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_useadminapprovalmode","displayName":"User Account Control Use Admin Approval Mode","description":"User Account Control: Use Admin Approval Mode for the built-in Administrator account This policy setting controls the behavior of Admin Approval Mode for the built-in Administrator account. The options are: • Enabled: The built-in Administrator account uses Admin Approval Mode. By default, any operation that requires elevation of privilege will prompt the user to approve the operation. • Disabled: (Default) The built-in Administrator account runs all applications with full administrative privilege.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#useraccountcontrol_useadminapprovalmode"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_useadminapprovalmode_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_useadminapprovalmode_0","displayName":"Disable","description":"Disable","helpText":null}]},"b5b332676b1a54b0":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Disables saving browser history and prevents users from changing this setting.\r\n\r\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\r\n\r\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b550d51584f20f3e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it’s replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nSpecify Bing's Image Search URL Post Params as:\r\n'imageBin={google:imageThumbnailBase64}'.\r\n\r\nSpecify Google's Image Search URL Post Params as:\r\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\r\n\r\nIf you don’t set this policy, image search requests are sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},"b52bc44b2abd1641":{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\r\n\r\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\r\n\r\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5c10afda85329f5":{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled","displayName":"Controls whether the new HTML parser behavior for the element. This policy supports the old HTML parser behavior until M136.\r\n\r\nIf this policy is enabled or unset, the HTML parser will allow additional tags inside the element.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b53106ac7252aeed":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_idletimeoutactionsdesc","displayName":"Actions to run when the computer is idle (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},"b5b078d8c4b40c93":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation","displayName":"Protection From Zone Elevation","description":"Zone Elevation","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_1","displayName":"Enabled","description":null,"helpText":null}]},"b5bd77dfab9f7438":{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_insiderslow","displayName":"Current Channel (Preview) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","categoryName":"Miscellaneous","options":[{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_insiderslow_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_insiderslow_1","displayName":"True","description":null,"helpText":null}]},"b50da61e4d49e172":{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_trustedservers_edit","displayName":"Enter fully qualified server names separated by semicolons","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"b5bb6b0d4664319c":{"id":"device_vendor_msft_policy_config_update_engagedrestartsnoozescheduleforfeatureupdates","displayName":"Engaged Restart Snooze Schedule For Feature Updates","description":"For Feature Updates, this policy specifies the number of days a user can snooze Engaged restart reminder notifications. The snooze period can be set between 1 and 3 days. Value type is integer. Default is 3 days. Supported value range: 1 - 3. If you disable or do not configure this policy, the default behaviors will be used. If any of the following policies are configured, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installationsAlways automatically restart at scheduled timeSpecify deadline before auto-restart for update installation","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#engagedrestartsnoozescheduleforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"b592ca552fb7efe9":{"id":"device_vendor_msft_policy_config_update_pausefeatureupdatesstarttime","displayName":"Pause Feature Updates Start Time","description":"Specifies the date and time when the IT admin wants to start pausing the Feature Updates. Value type is string (yyyy-mm-dd, ex. 2018-10-28). Supported operations are Add, Get, Delete, and Replace.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#pausefeatureupdatesstarttime"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"b5342b5cdc13c090":{"id":"user_vendor_msft_pde_protectfolders_protectdesktop","displayName":"Protect Desktop (User)","description":"Allows the Admin to enable Personal Data Encryption on Desktop folder. Set to '1' to set this policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/personaldataencryption-csp/"],"categoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","categoryName":"Personal Data Encryption","options":[{"id":"user_vendor_msft_pde_protectfolders_protectdesktop_0","displayName":"Disable Personal Data Encryption on the folder. If the folder is currently protected by Personal Data Encryption, this will result in unprotecting the folder.","description":"Disable Personal Data Encryption on the folder. If the folder is currently protected by Personal Data Encryption, this will result in unprotecting the folder.","helpText":null},{"id":"user_vendor_msft_pde_protectfolders_protectdesktop_1","displayName":"Enable Personal Data Encryption on the folder.","description":"Enable Personal Data Encryption on the folder.","helpText":null}]},"b5190fcd617c7024":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders38","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders38_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders38_1","displayName":"True","description":null,"helpText":null}]},"b56ff5473a3f58d8":{"id":"user_vendor_msft_policy_config_admx_desktop_nointerneticon","displayName":"Hide Internet Explorer icon on desktop (User)","description":"Removes the Internet Explorer icon from the desktop and from the Quick Launch bar on the taskbar.\r\n\r\nThis setting does not prevent the user from starting Internet Explorer by using other methods.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-nointerneticon"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_desktop_nointerneticon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_nointerneticon_1","displayName":"Enabled","description":null,"helpText":null}]},"b51c71b9b7fe34eb":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls","displayName":"Limit cookies from matching URLs to the current session (User)","description":"Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults.\r\n\r\nWhile no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b5f78506f14eb0b9":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio (User)","description":"This policy controls whether the browser uses adaptive buffering for\r\nWeb Audio, which may decrease audio glitches but may increase\r\nlatency by a variable amount.\r\n\r\nSetting the policy to Enabled will always use adaptive buffering.\r\n\r\nSetting the policy to Disabled or not set will allow the browser\r\nfeature launch process to decide if adaptive buffering is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5fd4eb025afdb16":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"b5ae2d0b13891eac":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_allhttpauthschemesallowedfororiginsdesc","displayName":"List of origins allowing all HTTP authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},"b55e9ad85e2472d3":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled","displayName":"Choose whether the Privacy Sandbox ad measurement setting can be disabled (User)","description":"A policy to control whether the Privacy Sandbox Ad measurement setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Ad measurement setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Ad measurement setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b529fef3190a20b0":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize87","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":null},"b57a18d149d11331":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonelogonoptions"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"b5891fe7615a8b1c":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},"b5827eb57484120d":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_2","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_3","displayName":"Ask every time a site wants to obtain the Local Fonts permission","description":null,"helpText":null}]},"b57cc661ec5c593c":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled","displayName":"Search in Sidebar enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_0","displayName":"Enable search in sidebar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_1","displayName":"Disable search in sidebar for Kids Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_2","displayName":"Disable search in sidebar","description":null,"helpText":null}]},"b573d9cd08c8e0d8":{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_1","displayName":"Let third-party storage partitioning to be enabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_2","displayName":"Block third-party storage partitioning from being enabled.","description":null,"helpText":null}]},"b5fb8fe0431c75b1":{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled","displayName":"Configure Edge scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen (User)","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable this policy, Microsoft Edge will share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5f06301358a1d2c":{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm","displayName":"Encryption mode for Information Rights Management (IRM) (User)","description":"If you enable this policy setting, you can choose from two options for controlling the encryption mode that Excel, PowerPoint, Word, Visio, and Outlook applications use to protect content with Information Rights Management (IRM):\r\n\r\n- Electronic Codebook (ECB) – ECB mode is always used when applying IRM encryption.\r\n- Cipher Block Chaining (CBC) – CBC mode is always used when applying IRM encryption.\r\n\r\nIf you disable or don't configure this policy setting:\r\n\r\n- For Microsoft 365 Apps (Version 2304 or later): Cipher Block Chaining (CBC) mode is used.\r\n- For earlier Microsoft 365 Apps and Office LTSC 2021, 2019, and 2016: Electronic Codebook (ECB) mode is used.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_1","displayName":"Enabled","description":null,"helpText":null}]},"b55bb3094f2719a9":{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon","displayName":"IRM Encryption Mode: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon_1","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon_2","displayName":"Electronic Codebook (ECB)","description":null,"helpText":null}]},"b5d9a64a232bd2d1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"b5640c3a8f9e5f52":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04","displayName":"Trusted Catalog Location #4 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_1","displayName":"Enabled","description":null,"helpText":null}]},"b5b772bfc94a7125":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject","displayName":"Project-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject_1","displayName":"True","description":null,"helpText":null}]},"b58a8f45c682bc71":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes","displayName":"Disable web templates in File | New and on the Office Start screen (User)","description":"This policy setting controls whether users can download templates from Office.com from within the Office applications.\r\n\r\nIf you enable this policy setting, users will not see featured templates from Office.com in File | New and on the Office Start screen and will not be able to download templates from within Office applications.\r\n\r\nIf you disable or do not configure this policy setting, users will see featured templates from Office.com in File | New and on the Office Start screen and will be able to download templates from within Office applications.\r\n\r\nNote - Enabling this policy setting does not prevent users from downloading templates from Office.com using their Web browsers.","helpText":"","infoUrls":[],"categoryId":"2d5a483f-b408-426d-9234-2883eae20afb","categoryName":"Tools | Options | General | Web Options...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes_1","displayName":"Enabled","description":null,"helpText":null}]},"b59b8aa7e6c61a6a":{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser","displayName":"Default Office theme (User)","description":"This policy setting allows you to select the user interface (UI) theme used by Office, if the user has not already selected an Office theme.\r\n\r\nNote: This setting only applies to Version 1903 or later of Office.\r\n\r\nIf you enable this policy setting, you may choose the Office theme used in cases where the user has not selected an Office theme themselves.\r\n\r\nIf you disable or do not configure this policy setting, Office will use the Colorful theme in cases where the user has not selected an Office theme themselves.\r\n\r\nRegardless of how you configure this policy setting, users can change their Office theme by going to File > Account > Office Theme (or, in Outlook, by going to File > Office Account > Office Theme).\r\n\r\nNote: The “Default Office theme” policy setting located under Computer Configuration takes precedence over this policy setting.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_1","displayName":"Enabled","description":null,"helpText":null}]},"b5d1d5f9fdbffc9d":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval_l_empty15","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"b539f997a335b48c":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator","displayName":"Allow commas as address separator (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_1","displayName":"Enabled","description":null,"helpText":null}]},"b5428bfbc22197df":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring","displayName":"Do not download rights permission license information for IRM e-mail during Exchange folder sync (User)","description":"By default, IRM license information for e-mail messages is downloaded to the user's local cache when Outlook synchronizes with Exchange. By enabling this setting, you can change this behavior so that licence information is not cached locally and users must connect to the network to retreive license information in order to open rights-managed e-mail messages.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring_1","displayName":"Enabled","description":null,"helpText":null}]},"b501e43ec51ed3d8":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28","displayName":"\r\nSelect Add-In Trust Level:\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_0","displayName":"Trust all, or use Exchange settings if present","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_1","displayName":"Trust all loaded and installed COM addins","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_2","displayName":"Do NOT trust loaded and installed COM addins","description":null,"helpText":null}]},"b5d6b14aa47c2551":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel","displayName":"Security Level (User) (Deprecated)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_2","displayName":"Always warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_4","displayName":"Never warn, disable all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_3","displayName":"Warn for signed, disable unsigned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_1","displayName":"No security check","description":null,"helpText":null}]},"b53ebd8bbe58c565":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype","displayName":"Check spelling as you type (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},"b55157f30a467188":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_autorecoversavelocation","displayName":"AutoRecover save location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":null},"b55040275fcf60b3":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui","displayName":"Edits to work, units or duration (User)","description":"Specifies that the feedback triangle should appear in a corner of a Task Name field if you change the task's start date or finish date.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of the Task Name field if the user changes the task's start or finish date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui_1","displayName":"Enabled","description":null,"helpText":null}]},"b5372ec3f7ac5c38":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3","displayName":"Default Publisher direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3_0","displayName":"Left to right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3_1","displayName":"Right to left","description":null,"helpText":null}]},"b5a2e7662b8a5eac":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},"b5f175a4d61ef924":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles","displayName":"Prevent co-authoring on files with macros for Word (User)","description":"This policy controls whether users will be able to co-author Word documents with macros.\r\n\r\nEnabling this policy setting will turn off the ability to co-author Word documents with macros.\r\n\r\nIf you disable or don't configure this policy setting, the user will be able to co-author Word documents with macros.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"b5c4c93fe14fd98d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize97","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":null}} \ No newline at end of file +{"b5441b4e1f801627":{"id":"com.apple.dock_dblclickbehavior","displayName":"Double Click Behavior","description":"The behavior when the window's title bar is double-clicked.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_dblclickbehavior_0","displayName":"Minimize","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior_1","displayName":"Maximize","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior_2","displayName":"None","description":null,"helpText":null}]},"b5ef58db590d4cb3":{"id":"com.apple.dock_static-others_item_tile-data_url","displayName":"URL","description":"The URL string","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},"b5aafa32a261f984":{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled","displayName":"Enable Work Search suggestions in the address bar","description":"Enables the display of relevant workplace suggestions in the address bar’s suggestion dropdown when users type a query in the address bar.\n\nIf this policy is enabled or not configured, users can view internal work-related suggestions, such as bookmarks, files, and people results powered by Microsoft 365, in the Microsoft Edge address bar suggestion dropdown. To access these results, users must be signed into Microsoft Edge with their Entra ID account associated with that organization.\n\nIf this policy is disabled, users will not see internal workplace results in the Microsoft Edge address bar suggestion dropdown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#addressbarworksearchresultsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_addressbarworksearchresultsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b576def03ad9a7fa":{"id":"com.apple.managedclient.preferences_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to","description":"Configure the list of servers that Microsoft Edge can delegate to.\n\nSeparate multiple server names with commas. Wildcards (*) are allowed.\n\nIf you don't configure this policy Microsoft Edge won't delegate user credentials even if a server is detected as Intranet.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#authnegotiatedelegateallowlist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"b5759a776d7ebe87":{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (Deprecated)","description":"This policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\n\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\n\nIf you disable this policy, the UI for the opt-out user experience is off.\n\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\n\nAfter careful evaluation, we have determined that this experimental opt-out UX is not required. As a result, this policy will be deprecated and stop working after Edge version 130.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeoptoutuxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeoptoutuxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b523ba37865416ad":{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton","displayName":"Show Downloads button on the toolbar","description":"Set this policy to always show the Downloads button on the toolbar.\n\nIf you enable this policy, the Downloads button is pinned to the toolbar.\n\nIf you disable or don't configure the policy, the Downloads button isn't shown on the toolbar by default. Users can toggle the Downloads button in edge://settings/appearance.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showdownloadstoolbarbutton"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showdownloadstoolbarbutton_true","displayName":"Enabled","description":null,"helpText":null}]},"b57dcfc3b1627a1f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled","displayName":"Enhance images enabled (Obsolete)","description":"The enhance images feature is deprecated and starting in Microsoft Edge version 122, this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast.\n\nIf you enable this policy or don't configure the policy, Microsoft Edge automatically enhances images on specific web applications.\n\nIf you disable this policy, Microsoft Edge doesn't enhance images.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeenhanceimagesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"b5eaee2e5cbf10cf":{"id":"contentcaching_autoactivation","displayName":"Auto Activation","description":"If `true`, the system automatically activates the content cache when possible and prevents disabling it. If `allowContentCaching` is `false`, `AutoActivation` is also `false`.\n\nRemoving a profile that set `AutoActivation` to `true` doesn't deactivate the Content Cache.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_autoactivation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_autoactivation_true","displayName":"Enabled","description":null,"helpText":null}]},"b591f094a1f91103":{"id":"contentcaching_publicranges_item_type","displayName":"Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_publicranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"contentcaching_publicranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},"b5efd4ca38fb39b5":{"id":"device_vendor_msft_maintenancewindows_enablemaintenancewindows","displayName":"Enable Maintenance windows","description":"Configure when devices receive specific updates. During the maintenance window, the selected update action runs on the assigned devices.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_enablemaintenancewindows_0","displayName":"Off","description":"Maintenance windows are disabled","helpText":null},{"id":"device_vendor_msft_maintenancewindows_enablemaintenancewindows_1","displayName":"On","description":"Maintenance windows are enabled","helpText":null}]},"b5843e664861eedb":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7","displayName":"Configure log access (legacy)","description":"This policy setting specifies the security descriptor to use for the log using the Security Descriptor Definition Language (SDDL) string. You must set both \"configure log access\" policy settings for this log in order to affect the both modern and legacy tools.\r\n\r\nIf you enable this policy setting, only those users matching the security descriptor can access the log.\r\n\r\nIf you disable this policy setting, all authenticated users and system services can write, read, or clear this log.\r\n\r\nIf you do not configure this policy setting, the previous policy setting configuration remains in effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-log-filelogaccess-7"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_7_1","displayName":"Enabled","description":null,"helpText":null}]},"b5812dc11205d183":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc","displayName":"Set Group Policy refresh interval for domain controllers","description":"This policy setting specifies how often Group Policy is updated on domain controllers while they are running (in the background). The updates specified by this setting occur in addition to updates performed when the system starts.\r\n\r\nBy default, Group Policy on the domain controllers is updated every five minutes.\r\n\r\nIf you enable this setting, you can specify an update rate from 0 to 64,800 minutes (45 days). If you select 0 minutes, the domain controller tries to update Group Policy every 7 seconds. However, because updates might interfere with users' work and increase network traffic, very short update intervals are not appropriate for most installations.\r\n\r\nIf you disable or do not configure this setting, the domain controller updates Group Policy every 5 minutes (the default). To specify that Group Policies for users should never be updated while the computer is in use, select the \"Turn off background refresh of Group Policy\" setting.\r\n\r\nThis setting also lets you specify how much the actual update interval varies. To prevent domain controllers with the same update interval from requesting updates simultaneously, the system varies the update interval for each controller by a random number of minutes. The number you type in the random time box sets the upper limit for the range of variance. For example, if you type 30 minutes, the system selects a variance of 0 to 30 minutes. Typing a large number establishes a broad range and makes it less likely that update requests overlap. However, updates might be delayed significantly.\r\n\r\nNote: This setting is used only when you are establishing policy for a domain, site, organizational unit (OU), or customized group. If you are establishing policy for a local computer only, the system ignores this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-grouppolicyrefreshratedc"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshratedc_1","displayName":"Enabled","description":null,"helpText":null}]},"b5a4472ffef0cec6":{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2","displayName":"Do not display the Getting Started welcome screen at logon","description":"This policy setting hides the welcome screen that is displayed on Windows 2000 Professional each time the user logs on.\r\n\r\nIf you enable this policy setting, the welcome screen is hidden from the user logging on to a computer where this policy is applied.\r\n\r\nUsers can still display the welcome screen by selecting it on the Start menu or by typing \"Welcome\" in the Run dialog box.\r\n\r\nIf you disable or do not configure this policy, the welcome screen is displayed each time a user logs on to the computer.\r\n\r\nThis setting applies only to Windows 2000 Professional. It does not affect the \"Configure Your Server on a Windows 2000 Server\" screen on Windows 2000 Server.\r\n\r\nNote: This setting appears in the Computer Configuration and User Configuration folders. If both settings are configured, the setting in Computer Configuration takes precedence over the setting in User Configuration.\r\n\r\nTip: To display the welcome screen, click Start, point to Programs, point to Accessories, point to System Tools, and then click \"Getting Started.\" To suppress the welcome screen without specifying a setting, clear the \"Show this screen at startup\" check box on the welcome screen.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-nowelcometips-2"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_nowelcometips_2_1","displayName":"Enabled","description":null,"helpText":null}]},"b5264486c8a52f6d":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_allowedapplications_exploitguard_controlledfolderaccess_allowedapplications_value","displayName":"Value","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},"b592e37c26332395":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting","displayName":"Configure local setting override for reporting to Microsoft MAPS","description":"This policy setting configures a local override for the configuration to join Microsoft MAPS. This setting can only be set by Group Policy.\r\n\r\n If you enable this setting, the local preference setting will take priority over Group Policy.\r\n\r\n If you disable or do not configure this setting, Group Policy will take priority over the local preference setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-spynet-localsettingoverridespynetreporting"],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynet_localsettingoverridespynetreporting_1","displayName":"Enabled","description":null,"helpText":null}]},"b5633303398dc31a":{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel","displayName":"Tool downloads allowed","description":null,"helpText":"","infoUrls":[],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel_1","displayName":"Remote troubleshooting only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_msdttooldownloadpolicylevel_2","displayName":"Local and remote troubleshooting","description":null,"helpText":null}]},"b52f5da9c0da2d03":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks","displayName":"MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)","description":"MSS: (AutoShareWks) Enable Administrative Shares (recommended except for highly secure environments)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-autosharewks"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_autosharewks_1","displayName":"Enabled","description":null,"helpText":null}]},"b5316522002c51aa":{"id":"device_vendor_msft_policy_config_admx_userprofiles_cleanupprofiles_cleanupprofiles_days","displayName":"Delete user profiles older than (days)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},"b57d406c27e2c32a":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules","displayName":"Disable runtime file path rules","description":"Turning this off will disable FilePath rule protection of enforcing user-writeability and onlu allowing admin-writable locations.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_disableruntimefilepathrules_enabled","displayName":"Enabled","description":null,"helpText":null}]},"b50ca977f8fd1b01":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes","displayName":"Microsoft Sticky Notes","description":"","helpText":"","infoUrls":[],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_microsoftstickynotes_1","displayName":"True","description":null,"helpText":null}]},"b5857ab605fe5314":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist","displayName":"Enable CORS check mitigations in the new CORS implementation","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_1","displayName":"Enabled","description":null,"helpText":null}]},"b57e5dcf603d3187":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls","displayName":"Block key generation on these sites","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b56272b83d3a78c8":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled","displayName":"Enable PDF Annotations","description":"Controls if the PDF viewer in Google Chrome can annotate PDFs.\r\n\r\nWhen this policy is not set, or is set to true, then the PDF viewer will be able to annotate PDFs.\r\n\r\nWhen this policy is set to false, then the PDF viewer will not be able to annotate PDFs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfannotationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5ec9f5871b3784f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting","displayName":"Control use of JavaScript optimizers","description":"Allows you to set whether Google Chrome\r\nwill run the v8 JavaScript engine with more advanced JavaScript optimizations enabled.\r\n\r\nDisabling JavaScript optimizations (by setting this policy's value to 2) will\r\nmean that Google Chrome may render web\r\ncontent more slowly.\r\n\r\nThis policy can be overridden for specific URL patterns using the JavaScriptOptimizerAllowedForSites and JavaScriptOptimizerBlockedForSites policies.\r\n\r\nIf this policy is left not set, JavaScript optimizations are enabled.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultjavascriptoptimizersetting_1","displayName":"Enabled","description":null,"helpText":null}]},"b5d4a5b14cab8a70":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled","displayName":"Choose whether the Privacy Sandbox Ad topics setting can be disabled","description":"A policy to control whether the Privacy Sandbox Ad topics setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Ad topics setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Ad topics setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadtopicsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5abd367190081d0":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockrebootingmachineinsafemode_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"b5ec5ceab1fd73e7":{"id":"device_vendor_msft_policy_config_defender_schedulescanday","displayName":"Schedule Scan Day","description":"Selects the day that the Windows Defender scan should run. Note The scan type will depends on what scan type is selected in the Defender/ScanParameter setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#schedulescanday"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_schedulescanday_0","displayName":"Every day","description":"Every day","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_1","displayName":"Sunday","description":"Sunday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_2","displayName":"Monday","description":"Monday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_3","displayName":"Tuesday","description":"Tuesday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_4","displayName":"Wednesday","description":"Wednesday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_5","displayName":"Thursday","description":"Thursday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_6","displayName":"Friday","description":"Friday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_7","displayName":"Saturday","description":"Saturday","helpText":null},{"id":"device_vendor_msft_policy_config_defender_schedulescanday_8","displayName":"No scheduled scan","description":"No scheduled scan","helpText":null}]},"b553d239193373b2":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingdriverinterface","displayName":"Driver Interface","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging of the driver interface.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\DriverInterface\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingdriverinterface_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingdriverinterface_1","displayName":"Enabled","description":null,"helpText":null}]},"b5be0ea520a9bbad":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirectionxmlsourcefolder","displayName":"Redirection XML Source Folder","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSpecifies the path to a folder containing the XML file. If the folder contains a redirections.xml, it will be copied to the local profile and immediately used.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\RedirXMLSourceFolder\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirectionxmlsourcefolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirectionxmlsourcefolder_1","displayName":"Enabled","description":null,"helpText":null}]},"b51dbaaab2e7d9fd":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesclearcacheonforcedunregister","displayName":"Clear Cache on Forced Unregister","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nIf the desired behavior is for the local cache to be deleted, even if the data has not been flushed to a CCD Location, then Clear Cache On Forced Unregister should be set to Enabled. Setting Clear Cache On Forced Unregister to Enabled may result in user data saved in the registry to be lost during the current session. It is important to understand that this data isn't recoverable if the local cache is cleared in this scenario. Verify that you understand the implications of changing the default value of this setting prior to making changes.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ClearCacheOnForcedUnregister\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"719595d8-ab5d-4418-88aa-8cd55c2964ba","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesclearcacheonforcedunregister_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesclearcacheonforcedunregister_1","displayName":"Enabled","description":null,"helpText":null}]},"b56b65289da4e6da":{"id":"device_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode","displayName":"Turn on Internet Explorer Standards Mode for local intranet","description":"This policy setting controls how Internet Explorer displays local intranet content. Intranet content is defined as any webpage that belongs to the local intranet security zone.\n\nIf you enable this policy setting, Internet Explorer uses the current user agent string for local intranet content. Additionally, all local intranet Standards Mode pages appear in the Standards Mode available with the latest version of Internet Explorer. The user cannot change this behavior through the Compatibility View Settings dialog box.\n\nIf you disable this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. The user cannot change this behavior through the Compatibility View Settings dialog box.\n\nIf you do not configure this policy setting, Internet Explorer uses an Internet Explorer 7 user agent string (with an additional string appended) for local intranet content. Additionally, all local intranet Standards Mode pages appear in Internet Explorer 7 Standards Mode. This option results in the greatest compatibility with existing webpages, but newer content written to common Internet standards may be displayed incorrectly. This option matches the default behavior of Internet Explorer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowinternetexplorerstandardsmode"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowinternetexplorerstandardsmode_1","displayName":"Enabled","description":null,"helpText":null}]},"b5d01de4e8210704":{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange","displayName":"Disable changing secondary home page settings","description":"Secondary home pages are the default Web pages that Internet Explorer loads in separate tabs from the home page whenever the browser is run. This policy setting allows you to set default secondary home pages.\n\nIf you enable this policy setting, you can specify which default home pages should load as secondary home pages. The user cannot set custom default secondary home pages.\n\nIf you disable or do not configure this policy setting, the user can add secondary home pages.\n\nNote: If the “Disable Changing Home Page Settings” policy is enabled, the user cannot add secondary home pages.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecondaryhomepagechange"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecondaryhomepagechange_1","displayName":"Enabled","description":null,"helpText":null}]},"b5b82589596b466b":{"id":"device_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths","displayName":"Intranet Sites: Include all network paths (UNCs)","description":"This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone.\n\nIf you enable this policy setting, all network paths are mapped into the Intranet Zone.\n\nIf you disable this policy setting, network paths are not necessarily mapped into the Intranet Zone (other rules might map one there).\n\nIf you do not configure this policy setting, users choose whether network paths are mapped into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includeallnetworkpaths"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_1","displayName":"Enabled","description":null,"helpText":null}]},"b50b7c11bea7aec3":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzoneinitializeandscriptactivexcontrols"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"b508665d33d94f75":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_useadminapprovalmode","displayName":"User Account Control Use Admin Approval Mode","description":"User Account Control: Use Admin Approval Mode for the built-in Administrator account This policy setting controls the behavior of Admin Approval Mode for the built-in Administrator account. The options are: • Enabled: The built-in Administrator account uses Admin Approval Mode. By default, any operation that requires elevation of privilege will prompt the user to approve the operation. • Disabled: (Default) The built-in Administrator account runs all applications with full administrative privilege.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#useraccountcontrol_useadminapprovalmode"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_useadminapprovalmode_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_useraccountcontrol_useadminapprovalmode_0","displayName":"Disable","description":"Disable","helpText":null}]},"b5b332676b1a54b0":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled","displayName":"Disable saving browser history","description":"Disables saving browser history and prevents users from changing this setting.\r\n\r\nIf you enable this policy, browsing history isn't saved. This also disables tab syncing.\r\n\r\nIf you disable this policy or don't configure it, browsing history is saved.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_savingbrowserhistorydisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b550d51584f20f3e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it’s replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nSpecify Bing's Image Search URL Post Params as:\r\n'imageBin={google:imageThumbnailBase64}'.\r\n\r\nSpecify Google's Image Search URL Post Params as:\r\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\r\n\r\nIf you don’t set this policy, image search requests are sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},"b52bc44b2abd1641":{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled","displayName":"Get user confirmation before closing a browser window with multiple tabs","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\r\n\r\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\r\n\r\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_askbeforecloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5c10afda85329f5":{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled","displayName":"Controls whether the new HTML parser behavior for the element. This policy supports the old HTML parser behavior until M136.\r\n\r\nIf this policy is enabled or unset, the HTML parser will allow additional tags inside the element.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge_selectparserrelaxationenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b53106ac7252aeed":{"id":"device_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~browseridle_idletimeoutactions_idletimeoutactionsdesc","displayName":"Actions to run when the computer is idle (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"526e363a-84db-4256-a13c-e01c8c646e26","categoryName":"Idle Browser Actions","options":null},"b5b078d8c4b40c93":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation","displayName":"Protection From Zone Elevation","description":"Zone Elevation","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_1","displayName":"Enabled","description":null,"helpText":null}]},"b5bd77dfab9f7438":{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_insiderslow","displayName":"Current Channel (Preview) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","categoryName":"Miscellaneous","options":[{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_insiderslow_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_insiderslow_1","displayName":"True","description":null,"helpText":null}]},"b50da61e4d49e172":{"id":"device_vendor_msft_policy_config_printers_pointandprintrestrictions_pointandprint_trustedservers_edit","displayName":"Enter fully qualified server names separated by semicolons","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"b5bb6b0d4664319c":{"id":"device_vendor_msft_policy_config_update_engagedrestartsnoozescheduleforfeatureupdates","displayName":"Engaged Restart Snooze Schedule For Feature Updates","description":"For Feature Updates, this policy specifies the number of days a user can snooze Engaged restart reminder notifications. The snooze period can be set between 1 and 3 days. Value type is integer. Default is 3 days. Supported value range: 1 - 3. If you disable or do not configure this policy, the default behaviors will be used. If any of the following policies are configured, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installationsAlways automatically restart at scheduled timeSpecify deadline before auto-restart for update installation","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#engagedrestartsnoozescheduleforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"b592ca552fb7efe9":{"id":"device_vendor_msft_policy_config_update_pausefeatureupdatesstarttime","displayName":"Pause Feature Updates Start Time","description":"Specifies the date and time when the IT admin wants to start pausing the Feature Updates. Value type is string (yyyy-mm-dd, ex. 2018-10-28). Supported operations are Add, Get, Delete, and Replace.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#pausefeatureupdatesstarttime"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"b5342b5cdc13c090":{"id":"user_vendor_msft_pde_protectfolders_protectdesktop","displayName":"Protect Desktop (User)","description":"Allows the Admin to enable Personal Data Encryption on Desktop folder. Set to '1' to set this policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/personaldataencryption-csp/"],"categoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","categoryName":"Personal Data Encryption","options":[{"id":"user_vendor_msft_pde_protectfolders_protectdesktop_0","displayName":"Disable Personal Data Encryption on the folder. If the folder is currently protected by Personal Data Encryption, this will result in unprotecting the folder.","description":"Disable Personal Data Encryption on the folder. If the folder is currently protected by Personal Data Encryption, this will result in unprotecting the folder.","helpText":null},{"id":"user_vendor_msft_pde_protectfolders_protectdesktop_1","displayName":"Enable Personal Data Encryption on the folder.","description":"Enable Personal Data Encryption on the folder.","helpText":null}]},"b5190fcd617c7024":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders38","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders38_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders38_1","displayName":"True","description":null,"helpText":null}]},"b56ff5473a3f58d8":{"id":"user_vendor_msft_policy_config_admx_desktop_nointerneticon","displayName":"Hide Internet Explorer icon on desktop (User)","description":"Removes the Internet Explorer icon from the desktop and from the Quick Launch bar on the taskbar.\r\n\r\nThis setting does not prevent the user from starting Internet Explorer by using other methods.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-nointerneticon"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_desktop_nointerneticon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_nointerneticon_1","displayName":"Enabled","description":null,"helpText":null}]},"b51c71b9b7fe34eb":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls","displayName":"Limit cookies from matching URLs to the current session (User)","description":"Unless the RestoreOnStartup policy is set to permanently restore URLs from previous sessions, then setting CookiesSessionOnlyForUrls lets you make a list of URL patterns that specify sites that can and can't set cookies for one session.\r\n\r\nLeaving the policy unset results in the use of DefaultCookiesSetting for all sites, if it's set. If not, the user's personal setting applies. URLs not covered by the patterns specified also result in the use of defaults.\r\n\r\nWhile no specific policy takes precedence, see CookiesBlockedForUrls and CookiesAllowedForUrls. URL patterns among these 3 policies must not conflict.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiessessiononlyforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b5f78506f14eb0b9":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled","displayName":"Enable adaptive buffering for Web Audio (User)","description":"This policy controls whether the browser uses adaptive buffering for\r\nWeb Audio, which may decrease audio glitches but may increase\r\nlatency by a variable amount.\r\n\r\nSetting the policy to Enabled will always use adaptive buffering.\r\n\r\nSetting the policy to Disabled or not set will allow the browser\r\nfeature launch process to decide if adaptive buffering is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webaudiooutputbufferingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5fd4eb025afdb16":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensionextendedbackgroundlifetimeforportconnectionstourls_extensionextendedbackgroundlifetimeforportconnectionstourlsdesc","displayName":"Configure a list of origins that grant extended background lifetime to the connecting extensions. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"b5ae2d0b13891eac":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_allhttpauthschemesallowedfororiginsdesc","displayName":"List of origins allowing all HTTP authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":null},"b55e9ad85e2472d3":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled","displayName":"Choose whether the Privacy Sandbox ad measurement setting can be disabled (User)","description":"A policy to control whether the Privacy Sandbox Ad measurement setting can be disabled for your users.\r\n\r\nIf you set this policy to Disabled, then the Ad measurement setting will be turned off for your users.\r\nIf you set this policy to Enabled or keep it unset, your users will be able to turn on or off the Privacy Sandbox Ad measurement setting on their device.\r\n\r\nSetting this policy requires setting the PrivacySandboxPromptEnabled policy to Disabled.","helpText":"","infoUrls":[],"categoryId":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","categoryName":"Privacy Sandbox policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~privacysandbox_privacysandboxadmeasurementenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b529fef3190a20b0":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize87","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5b832259-c30b-43bb-b249-9d3ea4d5b028","categoryName":"Customizable Error Messages","options":null},"b57a18d149d11331":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions","displayName":"Logon options (User)","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonelogonoptions"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"b5891fe7615a8b1c":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},"b5827eb57484120d":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting","displayName":"Default Local Fonts permission setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_2","displayName":"Denies the Local Fonts permission on all sites by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultlocalfontssetting_defaultlocalfontssetting_3","displayName":"Ask every time a site wants to obtain the Local Fonts permission","description":null,"helpText":null}]},"b57cc661ec5c593c":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled","displayName":"Search in Sidebar enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_0","displayName":"Enable search in sidebar","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_1","displayName":"Disable search in sidebar for Kids Mode","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_searchinsidebarenabled_2","displayName":"Disable search in sidebar","description":null,"helpText":null}]},"b573d9cd08c8e0d8":{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting","displayName":"Default setting for third-party storage partitioning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_1","displayName":"Let third-party storage partitioning to be enabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge~contentsettings_defaultthirdpartystoragepartitioningsetting_defaultthirdpartystoragepartitioningsetting_2","displayName":"Block third-party storage partitioning from being enabled.","description":null,"helpText":null}]},"b5fb8fe0431c75b1":{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled","displayName":"Configure Edge scareware blocker to share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen (User)","description":"This policy controls whether Microsoft Edge shares URLs of sites that are detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable this policy, Microsoft Edge will share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will not share URLs of sites detected as potential tech scams with Microsoft Defender SmartScreen.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockersenddetectedsitestosmartscreenenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b5f06301358a1d2c":{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm","displayName":"Encryption mode for Information Rights Management (IRM) (User)","description":"If you enable this policy setting, you can choose from two options for controlling the encryption mode that Excel, PowerPoint, Word, Visio, and Outlook applications use to protect content with Information Rights Management (IRM):\r\n\r\n- Electronic Codebook (ECB) – ECB mode is always used when applying IRM encryption.\r\n- Cipher Block Chaining (CBC) – CBC mode is always used when applying IRM encryption.\r\n\r\nIf you disable or don't configure this policy setting:\r\n\r\n- For Microsoft 365 Apps (Version 2304 or later): Cipher Block Chaining (CBC) mode is used.\r\n- For earlier Microsoft 365 Apps and Office LTSC 2021, 2019, and 2016: Electronic Codebook (ECB) mode is used.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_1","displayName":"Enabled","description":null,"helpText":null}]},"b55bb3094f2719a9":{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon","displayName":"IRM Encryption Mode: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon_1","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v14~policy~l_microsoftofficesystem~l_securitysettings_l_encryptiontypeforirm_l_encryptiontypeforirmcolon_2","displayName":"Electronic Codebook (ECB)","description":null,"helpText":null}]},"b5d9a64a232bd2d1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog03_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"b5640c3a8f9e5f52":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04","displayName":"Trusted Catalog Location #4 (User)","description":"This policy setting sets the URL location of a Trusted SharePoint Catalog or Shared Folder Catalog. All web add-ins at this location are trusted so that users can work with these add-ins in their documents. However, the user cannot insert these add-ins into an Office document.\r\n\r\nIf you enable this policy setting and set the URL, users can work with web add-ins from the SharePoint Catalog or Shared Folder Catalog at that URL.\r\n\r\nIf you disable this policy setting, users will not be able to work with any web add-ins on Internet zone catalogs, and they will be prompted before they start web add-ins from any other catalogs.\r\n\r\nIf you do not configure this policy setting or any others in the Trusted Catalogs folder, users can set their own Trusted Sharepoint Catalog and Shared Folder Catalog locations.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_trustedcatalog04_1","displayName":"Enabled","description":null,"helpText":null}]},"b5b772bfc94a7125":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject","displayName":"Project-related solutions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedhostapplications_l_officeosmpreventedhostapplicationsproject_1","displayName":"True","description":null,"helpText":null}]},"b58a8f45c682bc71":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes","displayName":"Disable web templates in File | New and on the Office Start screen (User)","description":"This policy setting controls whether users can download templates from Office.com from within the Office applications.\r\n\r\nIf you enable this policy setting, users will not see featured templates from Office.com in File | New and on the Office Start screen and will not be able to download templates from within Office applications.\r\n\r\nIf you disable or do not configure this policy setting, users will see featured templates from Office.com in File | New and on the Office Start screen and will be able to download templates from within Office applications.\r\n\r\nNote - Enabling this policy setting does not prevent users from downloading templates from Office.com using their Web browsers.","helpText":"","infoUrls":[],"categoryId":"2d5a483f-b408-426d-9234-2883eae20afb","categoryName":"Tools | Options | General | Web Options...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions_l_disablehyperlinkstowebtemplatesinfilenewandtaskpanes_1","displayName":"Enabled","description":null,"helpText":null}]},"b59b8aa7e6c61a6a":{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser","displayName":"Default Office theme (User)","description":"This policy setting allows you to select the user interface (UI) theme used by Office, if the user has not already selected an Office theme.\r\n\r\nNote: This setting only applies to Version 1903 or later of Office.\r\n\r\nIf you enable this policy setting, you may choose the Office theme used in cases where the user has not selected an Office theme themselves.\r\n\r\nIf you disable or do not configure this policy setting, Office will use the Colorful theme in cases where the user has not selected an Office theme themselves.\r\n\r\nRegardless of how you configure this policy setting, users can change their Office theme by going to File > Account > Office Theme (or, in Outlook, by going to File > Office Account > Office Theme).\r\n\r\nNote: The “Default Office theme” policy setting located under Computer Configuration takes precedence over this policy setting.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_globaloptions~l_customize_l_defaultuithemeuser_1","displayName":"Enabled","description":null,"helpText":null}]},"b5d1d5f9fdbffc9d":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointsyncinterval_l_empty15","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"b539f997a335b48c":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator","displayName":"Allow commas as address separator (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_allowcommasasaddressseparator_1","displayName":"Enabled","description":null,"helpText":null}]},"b5428bfbc22197df":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring","displayName":"Do not download rights permission license information for IRM e-mail during Exchange folder sync (User)","description":"By default, IRM license information for e-mail messages is downloaded to the user's local cache when Outlook synchronizes with Exchange. By enabling this setting, you can change this behavior so that licence information is not cached locally and users must connect to the network to retreive license information in order to open rights-managed e-mail messages.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_donotdownloadpermissionlicenseforirmemailduring_1","displayName":"Enabled","description":null,"helpText":null}]},"b501e43ec51ed3d8":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28","displayName":"\r\nSelect Add-In Trust Level:\r\n","description":"","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_0","displayName":"Trust all, or use Exchange settings if present","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_1","displayName":"Trust all loaded and installed COM addins","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_configureaddintrustlevel_l_empty28_2","displayName":"Do NOT trust loaded and installed COM addins","description":null,"helpText":null}]},"b5d6b14aa47c2551":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel","displayName":"Security Level (User) (Deprecated)","description":"","helpText":"","infoUrls":[],"categoryId":"c3db5686-3bb2-437c-8906-60da1a1fa844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_2","displayName":"Always warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_4","displayName":"Never warn, disable all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_3","displayName":"Warn for signed, disable unsigned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_l_securitylevel_1","displayName":"No security check","description":null,"helpText":null}]},"b53ebd8bbe58c565":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype","displayName":"Check spelling as you type (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","categoryName":"Proofing","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_proofing_l_checkspellingasyoutype_1","displayName":"Enabled","description":null,"helpText":null}]},"b55157f30a467188":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_saveautorecoverinfo_l_autorecoversavelocation","displayName":"AutoRecover save location (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":null},"b55040275fcf60b3":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui","displayName":"Edits to work, units or duration (User)","description":"Specifies that the feedback triangle should appear in a corner of a Task Name field if you change the task's start date or finish date.\r\n\r\nIf you enable this setting, a feedback triangle is displayed in the corner of the Task Name field if the user changes the task's start or finish date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"fe7c8652-17d4-40a7-869c-f7cfc3454402","categoryName":"Show indicators and Option butons for","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjinterface~l_pjshowindicators_l_pjchangedurationooui_1","displayName":"Enabled","description":null,"helpText":null}]},"b5372ec3f7ac5c38":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3","displayName":"Default Publisher direction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"77b0357b-412e-4a81-9469-e20a5f1345fd","categoryName":"Complex scripts","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3_0","displayName":"Left to right","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced~l_complexscripts_l_defaultpublisherdirection_l_defaultpublisherdirection3_1","displayName":"Right to left","description":null,"helpText":null}]},"b5a2e7662b8a5eac":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned","displayName":"Disable Trust Bar Notification for unsigned application add-ins (User) (Deprecated)","description":"This policy setting controls whether the specified Office application notifies users when unsigned application add-ins are loaded or silently disable such add-ins without notification. This policy setting only applies if you enable the \"Require that application add-ins are signed by Trusted Publisher\" policy setting, which prevents users from changing this policy setting.\r\n\r\nIf you enable this policy setting, applications automatically disable unsigned add-ins without informing users.\r\n \r\nIf you disable this policy setting, if this application is configured to require that all add-ins be signed by a trusted publisher, any unsigned add-ins the application loads will be disabled and the application will display the Trust Bar at the top of the active window. The Trust Bar contains a message that informs users about the unsigned add-in.\r\n\r\nIf you do not configure this policy setting, the disable behavior applies, and in addition, users can configure this requirement themselves in the \"Add-ins\" category of the Trust Center for the application.","helpText":"","infoUrls":[],"categoryId":"30da5d88-cf03-41f4-ab55-51ead91b3844","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_security~l_trustcenter_l_disabletrustbarnotificationforunsigned_1","displayName":"Enabled","description":null,"helpText":null}]},"b5f175a4d61ef924":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles","displayName":"Prevent co-authoring on files with macros for Word (User)","description":"This policy controls whether users will be able to co-author Word documents with macros.\r\n\r\nEnabling this policy setting will turn off the ability to co-author Word documents with macros.\r\n\r\nIf you disable or don't configure this policy setting, the user will be able to co-author Word documents with macros.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"e522c142-5666-4090-a7f4-1da1487f5384","categoryName":"Co-authoring","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_collaborationsettings~l_coauthoring_l_disablecoauthoringondocmfiles_1","displayName":"Enabled","description":null,"helpText":null}]},"b5c4c93fe14fd98d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize97","displayName":"List of error messages to customize (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","categoryName":"Customizable Error Messages","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/b7.json b/public/intune-definitions/b7.json index a0a5eeb66d47..caf928a5fbb5 100644 --- a/public/intune-definitions/b7.json +++ b/public/intune-definitions/b7.json @@ -1 +1 @@ -{"b73a6a62e7db7b43":{"id":"com.apple.applicationaccess_allowimagewand","displayName":"Allow Image Wand (Deprecated)","description":"When false, prohibits the use of Image Wand.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowimagewand_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowimagewand_true","displayName":"True","description":null,"helpText":null}]},"b766bbda44723758":{"id":"com.apple.managedclient.preferences_weeklyconfiguration_timeofday","displayName":"Time of day","description":"Specifies the time of day, as the number of minutes after midnight, to perform a weekly scan.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},"b727998e78787458":{"id":"com.apple.security.firewall_enablelogging","displayName":"Enable Logging (Deprecated)","description":"If true, enables logging. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_enablelogging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_enablelogging_true","displayName":"True","description":null,"helpText":null}]},"b7285c5b899a9bb1":{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"b728d7fbfbfd2b22":{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials","displayName":"Deny delegating default credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's default credentials cannot be delegated (default credentials are those that you use when first logging on to Windows).\r\n\r\nIf you disable or do not configure (by default) this policy setting, this policy setting does not specify any server.\r\n\r\nNote: The \"Deny delegating default credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials cannot be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n\r\nThis policy setting can be used in combination with the \"Allow delegating default credentials\" policy setting to define exceptions for specific servers that are otherwise permitted when using wildcard characters in the \"Allow delegating default credentials\" server list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-denydefaultcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f4bbc9d8d0982c":{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r","displayName":"Remote Link to Remote Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r_1","displayName":"True","description":null,"helpText":null}]},"b73f2722b4ff4e86":{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider","displayName":"Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider","description":"This policy setting configures Microsoft Support Diagnostic Tool (MSDT) interactive communication with the support provider. MSDT gathers diagnostic data for analysis by support professionals.\r\n\r\nIf you enable this policy setting, users can use MSDT to collect and send diagnostic data to a support professional to resolve a problem.\r\n\r\nBy default, the support provider is set to Microsoft Corporation.\r\n\r\nIf you disable this policy setting, MSDT cannot run in support mode, and no data can be collected or sent to the support provider.\r\n\r\nIf you do not configure this policy setting, MSDT support mode is enabled by default.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-msdtsupportprovider"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider_1","displayName":"Enabled","description":null,"helpText":null}]},"b7661a20d2c13e7a":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate","displayName":"Set Teredo Refresh Rate","description":"This policy setting allows you to configure the Teredo refresh rate.\r\n\r\nNote: On a periodic basis (by default, every 30 seconds), Teredo clients send a single Router Solicitation packet to the Teredo server. The Teredo server sends a Router Advertisement Packet in response. This periodic packet refreshes the IP address and UDP port mapping in the translation table of the Teredo client's NAT device.\r\n\r\nIf you enable this policy setting, you can specify the refresh rate. If you choose a refresh rate longer than the port mapping in the Teredo client's NAT device, Teredo might stop working or connectivity might be intermittent.\r\n\r\nIf you disable or do not configure this policy setting, the refresh rate is configured using the local settings on the computer. The default refresh rate is 30 seconds.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-refresh-rate"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_1","displayName":"Enabled","description":null,"helpText":null}]},"b73369f90c55be5f":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates","displayName":"Replace the default Microsoft templates","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates_1","displayName":"True","description":null,"helpText":null}]},"b78047318d574676":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_id","displayName":"Rule Id","description":"The Id of the rule, leave this field blank, it will be filled in automatically.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},"b73c12695efe1c9f":{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps","displayName":"Disable Store Originated Apps","description":"Boolean value that disables the launch of all apps from Microsoft Store that came pre-installed or were downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#disablestoreoriginatedapps"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps_0","displayName":"Disabled","description":"Enable launch of apps.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps_1","displayName":"Enabled","description":"Disable launch of apps.","helpText":null}]},"b7b9271c508127cf":{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership","displayName":"Account Logon Logoff Audit Group Membership","description":"This policy allows you to audit the group memberhsip information in the user's logon token. Events in this subcategory are generated on the computer on which a logon session is created. For an interactive logon, the security audit event is generated on the computer that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the computer hosting the resource. When this setting is configured, one or more security audit events are generated for each successful logon. You must also enable the Audit Logon setting under Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff. Multiple events are generated if the group memberhsip information cannot fit in a single security audit event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditgroupmembership"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"b7b46d166c4a36fc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir","displayName":"Set user data directory","description":"Configures the directory that Google Chrome will use for storing user data.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory regardless whether the user has specified the '--user-data-dir' flag or not. To avoid data loss or other unexpected errors this policy should not be set to a directory used for other purposes, because Google Chrome manages its contents.\r\n\r\nSee https://support.google.com/chrome/a?p=Supported_directory_variables for a list of variables that can be used.\r\n\r\nIf this policy is left not set the default profile path will be used and the user will be able to override it with the '--user-data-dir' command line flag.\r\n\r\nExample value: ${users}/${user_name}/Chrome","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},"b7aea43354a40a86":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls","displayName":"Allow access to sensors on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can access sensors like motion and light sensors.\r\n\r\nLeaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nIf the same URL pattern exists in both this policy and the SensorsBlockedForUrls policy, the latter is prioritized and access to motion or light sensors will be blocked.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b7436cecdd3594de":{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout","displayName":"Set Max Connection Timeout","description":"IT admins can use this policy to set the max connection timeout. The connection timeout decides the max wait time for connecting to Cloud PC after sign in. The default max value is 5 min. For best user experience, it is recommended to continue with the default timeout of 5 min. Update only if it takes more than 5 min to connect to the Cloud PC in your organization.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-CloudDesktop#setmaxconnectiontimeout"],"categoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","categoryName":"Cloud Desktop","options":[{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_5","displayName":"5 min","description":"5 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_6","displayName":"6 min","description":"6 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_7","displayName":"7 min","description":"7 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_8","displayName":"8 min","description":"8 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_9","displayName":"9 min","description":"9 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_10","displayName":"10 min","description":"10 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_11","displayName":"11 min","description":"11 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_12","displayName":"12 min","description":"12 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_13","displayName":"13 min","description":"13 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_14","displayName":"14 min","description":"14 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_15","displayName":"15 min","description":"15 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_16","displayName":"16 min","description":"16 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_17","displayName":"17 min","description":"17 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_18","displayName":"18 min","description":"18 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_19","displayName":"19 min","description":"19 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_20","displayName":"20 min","description":"20 min","helpText":null}]},"b791b488d83c1ffa":{"id":"device_vendor_msft_policy_config_connectivity_prohibitinstallationandconfigurationofnetworkbridge","displayName":"Prohibit installation and configuration of Network Bridge on your DNS domain network","description":"Determines whether a user can install and configure the Network Bridge.\n\nImportant: This settings is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. If a computer is connected to a DNS domain network other than the one it was connected to when the setting was refreshed, this setting does not apply.\n\nThe Network Bridge allows users to create a layer 2 MAC bridge, enabling them to connect two or more network segements together. This connection appears in the Network Connections folder.\n\nIf you disable this setting or do not configure it, the user will be able to create and modify the configuration of a Network Bridge. Enabling this setting does not remove an existing Network Bridge from the user's computer.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-connectivity#connectivity-prohibitinstallationandconfigurationofnetworkbridge"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_connectivity_prohibitinstallationandconfigurationofnetworkbridge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_prohibitinstallationandconfigurationofnetworkbridge_1","displayName":"Enabled","description":null,"helpText":null}]},"b7d33e693c266f2c":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"b711f590da8ecd7d":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dopercentagemaxbackgroundbandwidth","displayName":"DO Percentage Max Background Bandwidth","description":"Specifies the maximum background download bandwidth that Delivery Optimization uses across all concurrent download activities as a percentage of available download bandwidth.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dopercentagemaxbackgroundbandwidth"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"b7b648c83c0bf101":{"id":"device_vendor_msft_policy_config_eventlogservice_controleventlogbehavior","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\n\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\n\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\n\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-eventlogservice#eventlogservice-controleventlogbehavior"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_eventlogservice_controleventlogbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_eventlogservice_controleventlogbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"b75aba3686faae08":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"b781f9f15341fa2c":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"b79cc5226f44591f":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"b7b1156671ac614c":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},"b7d1f7afb1a8230f":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled","displayName":"Automatically open Copilot side pane with contextual insights for links opened from Outlook","description":"This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open web links from Outlook emails sent from the same tenant.\r\n\r\nStarting in Microsoft Edge version 148, when users open eligible links from Outlook emails sent from the same tenant, Microsoft Edge automatically opens the Copilot side pane with contextual insights. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.\r\n\r\nIf you enable this policy or don't configure it, the Copilot side pane opens automatically when users open links from Outlook emails sent from the same tenant.\r\n\r\nIf you disable this policy, the Copilot side pane doesn't open automatically when users open links from Outlook emails sent from the same tenant.\r\n\r\nThis feature applies only to links opened from Outlook emails sent from the same tenant and requires Microsoft Copilot to be available for the user in Microsoft Edge.\r\n\r\nThis feature is disabled if the 'CopilotPageContext' (Control Copilot access to page context for Microsoft Entra ID profiles) policy or the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy is disabled, regardless of this policy's configuration. Copilot requires access to page content to provide contextual insights.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b786dc1ca975a2bc":{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended","displayName":"Visual search enabled","description":"Visual search lets you quickly explore more related content about entities in an image.\r\n\r\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\r\n\r\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\r\n\r\nNote: Visual Search in Web Capture is still managed by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge) policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f926040a0c5f4e":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremapplicationiduri","displayName":"Specify the Application ID URI for your Entra application for OIDC","description":"This setting allows you to specify an Application ID URI for your Entra application for OIDC if it is different from your SharePoint Server URL. To use this setting, you must also enable \"Enable the use of OIDC authentication for syncing content from a SharePoint Server\". This setting affects only OneDrive for Business sync functionality. It does not impact syncing team sites in SharePoint Online.\n\nIf you enable this setting and provide the Application ID URI, this value will be used for requests to the SharePoint Server.\n\nIf you disable or do not configure this setting, we will use the SharePoint Server URL as the Application ID URI instead.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremapplicationiduri_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremapplicationiduri_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f809333c51cdb4":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessaccountinfo_forceallowtheseapps","displayName":"Let Apps Access Account Info Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to account information. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessaccountinfo_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"b7025e1a955b9b0c":{"id":"device_vendor_msft_policy_config_remotedesktopservices_promptforpassworduponconnection","displayName":"Always prompt for password upon connection","description":"This policy setting specifies whether Remote Desktop Services always prompts the client for a password upon connection.\n\nYou can use this setting to enforce a password prompt for users logging on to Remote Desktop Services, even if they already provided the password in the Remote Desktop Connection client.\n\nBy default, Remote Desktop Services allows users to automatically log on by entering a password in the Remote Desktop Connection client.\n\nIf you enable this policy setting, users cannot automatically log on to Remote Desktop Services by supplying their passwords in the Remote Desktop Connection client. They are prompted for a password to log on.\n\nIf you disable this policy setting, users can always log on to Remote Desktop Services automatically by supplying their passwords in the Remote Desktop Connection client.\n\nIf you do not configure this policy setting, automatic logon is not specified at the Group Policy level.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-promptforpassworduponconnection"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_promptforpassworduponconnection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_promptforpassworduponconnection_1","displayName":"Enabled","description":null,"helpText":null}]},"b72279b186371df3":{"id":"device_vendor_msft_policy_config_start_forcestartsize","displayName":"Force Start Size","description":"Forces the start screen size. If there is policy configuration conflict, the latest configuration request is applied to the device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#forcestartsize"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_forcestartsize_0","displayName":"Do not force size of Start.","description":"Do not force size of Start.","helpText":null},{"id":"device_vendor_msft_policy_config_start_forcestartsize_1","displayName":"Force non-fullscreen size of Start.","description":"Force non-fullscreen size of Start.","helpText":null},{"id":"device_vendor_msft_policy_config_start_forcestartsize_2","displayName":"Force a fullscreen size of Start.","description":"Force a fullscreen size of Start.","helpText":null}]},"b7d2bc53de02000b":{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_hidewindowssecuritynotificationareacontrol","displayName":"Hide Windows Security Notification Area Control","description":"This policy setting hides the Windows Security notification area control. The user needs to either sign out and sign in or reboot the computer for this setting to take effect. Enabled:Windows Security notification area control will be hidden. Disabled:Windows Security notification area control will be shown. Not configured:Same as Disabled. Supported values:0 - Disabled (default)1 - Enabled","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsDefenderSecurityCenter#hidewindowssecuritynotificationareacontrol"],"categoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","categoryName":"Windows Defender Security Center","options":[{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_hidewindowssecuritynotificationareacontrol_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_hidewindowssecuritynotificationareacontrol_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"b799e1692d72c38f":{"id":"linux_mdatp_managed_advancedsettings_memoryscan","displayName":"Memory scan (preview) (Requires Behavior Monitoring for protection)","description":"Detects and blocks fileless and in-memory threats at runtime","helpText":null,"infoUrls":[],"categoryId":"1ae2f430-e0ca-4c68-ba28-aacbc6e33af3","categoryName":null,"options":[{"id":"linux_mdatp_managed_advancedsettings_memoryscan_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_advancedsettings_memoryscan_enabled","displayName":"Enabled","description":null,"helpText":null}]},"b75ebbf3d4cc77f1":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon20","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"b7e35dcb6b2f812a":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders62","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders62_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders62_1","displayName":"True","description":null,"helpText":null}]},"b78cb40c9363bc4d":{"id":"user_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation","displayName":"Block launching desktop apps associated with a file. (User)","description":"This policy setting lets you control whether Windows Store apps can open files using the default desktop app for a file type. Because desktop apps run at a higher integrity level than Windows Store apps, there is a risk that a Windows Store app might compromise the system by opening a file in the default desktop app for a file type.\r\n\r\nIf you enable this policy setting, Windows Store apps cannot open files in the default desktop app for a file type; they can open files only in other Windows Store apps.\r\n\r\nIf you disable or do not configure this policy setting, Windows Store apps can open files in the default desktop app for a file type.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeblockfileelevation"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"user_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation_1","displayName":"Enabled","description":null,"helpText":null}]},"b76d468e85f88859":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablecolorschemechoice","displayName":"Prevent changing color scheme (User)","description":"This setting forces the theme color scheme to be the default color scheme.\r\n\r\nIf you enable this setting, a user cannot change the color scheme of the current desktop theme.\r\n\r\nIf you disable or do not configure this setting, a user may change the color scheme of the current desktop theme.\r\n\r\nFor Windows 7 and later, use the \"Prevent changing color and appearance\" setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-disablecolorschemechoice"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablecolorschemechoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablecolorschemechoice_1","displayName":"Enabled","description":null,"helpText":null}]},"b755997a8e54a44e":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio","displayName":"Microsoft Visio 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft Visio 2010.\r\nBy default, the user settings of Microsoft Visio 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Visio 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Visio 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Visio 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010visio"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio_1","displayName":"Enabled","description":null,"helpText":null}]},"b758969c9a608843":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013","displayName":"Microsoft Office 365 Outlook 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_1","displayName":"Enabled","description":null,"helpText":null}]},"b7ddc691c742251c":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_sports","displayName":"Sports (User)","description":"This policy setting configures the synchronization of user settings for the Sports app.\r\nBy default, the user settings of Sports sync between computers. Use the policy setting to prevent the user settings of Sports from synchronizing between computers.\r\nIf you enable this policy setting, Sports user settings continue to sync.\r\nIf you disable this policy setting, Sports user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-sports"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_1","displayName":"Enabled","description":null,"helpText":null}]},"b764679832af0606":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"b79a0816c9421865":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode","displayName":"Control use of the Headless Mode (User)","description":"Setting this policy to Enabled or leaving the policy unset allows use of the headless mode. Setting this policy to Disabled denies use of the headless mode.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_1","displayName":"Enabled","description":null,"helpText":null}]},"b736ee93bfabfc20":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled","displayName":"Enable the Shared Clipboard Feature (User)","description":"Enable the Shared Clipboard feature which allows users to send text between Chrome Desktops and an Android device when Sync is enabled and the user is Signed-in.\r\n\r\nIf this policy is set to true, the capability of sending text, cross device, for chrome user is enabled.\r\n\r\nIf this policy is set to false, the capability of sending text, cross device, for chrome user is disabled.\r\n\r\nIf you set this policy, users cannot change or override it.\r\n\r\nIf this policy is left unset, the shared clipboard feature is enabled by default.\r\n\r\nIt is up to the admins to set policies in all platforms they care about. It's recommended to set this policy to one value in all platforms.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f4eea44be24d87":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters","displayName":"Command-line parameters for switching from the alternative browser. (User)","description":"Setting the policy to a list of strings means the strings are joined with spaces and passed from Internet Explorer® to Google Chrome as command-line parameters. If an parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line.\r\n\r\nEnvironment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable.\r\n\r\nLeaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter.\r\n\r\nNote: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect.\r\n\r\nExample value:\r\n\r\n--force-dark-mode","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f6ef61076e5000":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist","displayName":"Websites to open in alternative browser (User)","description":"Setting the policy controls the list of websites to open in an alternative browser. Each item is treated as a rule for something to open in an alternative browser. Google Chrome uses those rules when choosing if a URL should open in an alternative browser. When the Internet Explorer® add-in is on, Internet Explorer® switches back to Google Chrome when the rules don't match. If rules contradict each other, Google Chrome uses the most specific rule.\r\n\r\nLeaving the policy unset adds no websites to the list.\r\n\r\nNote: Elements can also be added to this list through the BrowserSwitcherUseIeSitelist and BrowserSwitcherExternalSitelistUrl policies.\r\n\r\nExample value:\r\n\r\nie.com\r\n!open-in-chrome.ie.com\r\nfoobar.com/ie-only/","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_1","displayName":"Enabled","description":null,"helpText":null}]},"b7d9b86b6a6940b1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls","displayName":"List of alternate URLs for the default search provider (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'.\r\n\r\nLeaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.\r\n\r\nExample value:\r\n\r\nhttps://search.my.company/suggest#q={searchTerms}\r\nhttps://search.my.company/suggest/search#q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b78978475ae466d9":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection","displayName":"Default printer selection rules (User)","description":"Setting the policy sets the rules for selecting the default printer in Google Chrome, overriding the default rules. Printer selection occurs the first time users try to print, when Google Chrome seeks a printer matching the specified attributes. In case of a less than perfect match, Google Chrome can be set to select any matching printer, depending on the order printers are discovered.\r\n\r\nLeaving the policy unset or set to attributes for which there's no match means the built-in PDF printer is the default. If there's no PDF printer, Google Chrome defaults to none.\r\n\r\nPrinters connected to Google Cloud Print are considered \"cloud\", the rest of the printers are classified as \"local\".\r\n\r\nNote: Omitting a field means all values match. For example, not specifying connectivity causes Print Preview to start discovery of all kinds of printers, \"local\" and \"cloud\". Regular expression patterns must follow the JavaScript RegExp syntax, and matches are case sensistive.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=DefaultPrinterSelection for more information about schema and formatting.\r\n\r\n\r\nExample value: { \"kind\": \"cloud\", \"idPattern\": \".*public\", \"namePattern\": \".*Color\" }","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_1","displayName":"Enabled","description":null,"helpText":null}]},"b755967e54abf681":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},"b79e5ad19de99067":{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch","displayName":"Don’t allow Dynamic Data Exchange (DDE) server launch in Excel (User)","description":"This policy setting allows you to control whether Dynamic Data Exchange (DDE) server launch is allowed.\r\n\r\nBy default, DDE server launch is turned off, but users can turn on DDE server launch by going to File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nFor security reasons, turning on DDE server launch is not recommended.\r\n\r\nNote: For DDE server launch to work, Dynamic Data Exchange (DDE) server lookup must be turned on. Be sure that the “Don’t allow Dynamic Data Exchange (DDE) server lookup” policy setting isn’t enabled, because enabling that policy setting turns off DDE server lookup.\r\n\r\nIf you enable this policy setting, DDE server launch isn’t allowed, and users can’t turn on DDE server launch in the Trust Center.\r\n\r\nIf you disable this policy setting, DDE server launch is allowed, and users cannot turn off DDE server launch in the Trust Center. For security reasons, this is not recommended.\r\n\r\nIf you don’t configure this policy setting, DDE server launch is turned off, but users can turn on DDE server launch in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},"b773a96581c8c79d":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowlessprivilegedsites"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"b771a13c69dba4c6":{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page (User)","description":"By default, the App Launcher is shown every time a user opens a new tab page.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and App Launcher is there for users.\r\n\r\nIf you disable this policy, App Launcher doesn't appear and users won't be able to launch M365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b7334ad81a2a6185":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls","displayName":"Block clipboard use on specific sites (User)","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b7bea2f8ac7e60b8":{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext","displayName":"Control Copilot with Commercial Data Protection access to page context for Microsoft Entra ID profiles (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132.\r\n\r\nThis policy has been obsoleted as of Edge 133. Instead of this obsolete policy, we recommend using 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane).\r\n\r\nThis policy controls access to page contents for Copilot with Commercial Data Protection in the Edge sidebar. This policy applies only to Microsoft Entra ID profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA profiles. This policy doesn't control access for Copilot without Commercial Data Protection. Access for Copilot without Commercial Data Protection is controlled by the policy CopilotPageContext.\r\n\r\nIf you enable this policy, Copilot with Commercial Data Protection will have access to page context.\r\n\r\nIf you don't configure this policy, a user can enable access to page context for Copilot with Commercial Data Protection using the setting toggle in Edge.\r\n\r\nIf you disable this policy, Copilot with Commercial Data Protection will not be able to access page context.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},"b7386dd640b71cb9":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings_exemptdomainfiletypepairsfromfiletypedownloadwarningsdesc","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"b7ab6e4af9520238":{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior","displayName":"Allow Basic Authentication prompts from network proxies (User)","description":"This policy setting controls whether network proxies are allowed to show Basic Authentication prompts.\r\n\r\nBy default, all Basic Authentication sign-in prompts are blocked, and the user is shown a message that the sign-in method isn’t allowed.\r\n\r\nIf you enable this policy setting, then network proxies will be allowed to show Basic Authentication prompts.\r\n\r\nWarning: Allowing Basic Authentication sign-in prompts isn’t recommended because it’s a security risk.\r\n\r\nIf you disable or don’t configure this policy setting, all Basic Authentication sign-in prompts from network proxes will be blocked, and the user will be shown a message that the sign-in method isn’t allowed.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2199001.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"b74c7d1dcb1c5a9e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},"b777ee6da9fd8e34":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceminorversion9","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"b71cd1a2b23afe47":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_l_setupdateintervalforoutlookglobaladdresslistdictionaryspinid","displayName":"(in minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},"b7da79986f16191b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant","displayName":"Set password hash format as ISO-compliant (User)","description":"This policy setting allows you create ISO-compliant modification password records.\r\n\r\nIf you enable this policy setting, then passwords created will be ISO-compliant.\r\n\r\nIf you disable or do not configure this policy setting, the default will be ECMA-style records.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant_1","displayName":"Enabled","description":null,"helpText":null}]},"b7a775636fb04621":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles","displayName":"Set User path for the label page size update files (User)","description":"This policy setting allows you to override the User path for the label page size update files. \r\n\r\nIf you enable this policy setting, you may enter the path to the PSX update files and override the User path.\r\n\r\nIf you disable or do not configure this policy setting, the User path for the label page size update files remains valid.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"b791fd725bac742d":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize","displayName":"Default Font Size (User)","description":"Specifies the value in the option ''Size''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_1","displayName":"Enabled","description":null,"helpText":null}]},"b7cd3e58bbae2e7f":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass","displayName":"Disallows add-ons access to password protected sections (User)","description":"This option disallows extensibility add-ons the ability to access password protected sections if they are unlocked.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass_1","displayName":"Enabled","description":null,"helpText":null}]},"b70151fd552547dd":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},"b74b3212d8f993ad":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec","displayName":"Specify duration of Desktop Alert on mouse over (in milliseconds) (User)","description":"Specify duration of Desktop Alert on mouse over (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},"b72748e2f87f124b":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"b726325de9fbb34d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript","displayName":"Ordinals with superscript (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript_1","displayName":"Enabled","description":null,"helpText":null}]},"b77dd600ee2fc763":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"b7f11e08291ebd33":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline","displayName":"Tools | Compare and Merge Documents, Legal blackline (User)","description":"If you enable this policy setting, a comparison between two documents automatically generates a new Legal Blackline document, leaving the original documents unchanged.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f6895c5c193540":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools_l_delaybeforestartingbackgroundgrammarchecker3","displayName":"Milliseconds (e.g. 5000 milliseconds = 5 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":null},"b791e810196fc3b5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols","displayName":"Symbol characters (--) with symbols (User)","description":"Checks/unchecks the option ''Hyphens (--) with dash (-)''.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols_1","displayName":"Enabled","description":null,"helpText":null}]},"b794583a0a166949":{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections","displayName":"Enable Log Success Connections","description":"This value is used as an on/off switch. If this value is on, the firewall logs all successful inbound connections. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections_false","displayName":"Disable Logging Of Successful Connections","description":"Disable Logging Of Successful Connections","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections_true","displayName":"Enable Logging Of Successful Connections","description":"Enable Logging Of Successful Connections","helpText":null}]}} \ No newline at end of file +{"b73a6a62e7db7b43":{"id":"com.apple.applicationaccess_allowimagewand","displayName":"Allow Image Wand (Deprecated)","description":"When false, prohibits the use of Image Wand.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowimagewand_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowimagewand_true","displayName":"True","description":null,"helpText":null}]},"b766bbda44723758":{"id":"com.apple.managedclient.preferences_weeklyconfiguration_timeofday","displayName":"Time of day","description":"Specifies the time of day, as the number of minutes after midnight, to perform a weekly scan.","helpText":null,"infoUrls":[],"categoryId":"64c8233f-3057-4485-b902-d71a312318d7","categoryName":"Scheduled scan configuration","options":null},"b727998e78787458":{"id":"com.apple.security.firewall_enablelogging","displayName":"Enable Logging (Deprecated)","description":"If true, enables logging. Available in macOS 12 and later.","helpText":null,"infoUrls":[],"categoryId":"70b5da13-9c31-4857-890d-b7eb223729c3","categoryName":"Firewall","options":[{"id":"com.apple.security.firewall_enablelogging_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.security.firewall_enablelogging_true","displayName":"True","description":null,"helpText":null}]},"b7285c5b899a9bb1":{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed","displayName":"Allowed","description":"If true, access is granted; otherwise, the process doesn't have access. The user isn't prompted and can't change this value.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_microphone_item_allowed_true","displayName":"True","description":null,"helpText":null}]},"b728d7fbfbfd2b22":{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials","displayName":"Deny delegating default credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's default credentials cannot be delegated (default credentials are those that you use when first logging on to Windows).\r\n\r\nIf you disable or do not configure (by default) this policy setting, this policy setting does not specify any server.\r\n\r\nNote: The \"Deny delegating default credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials cannot be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in .humanresources.fabrikam.com\r\n\r\nThis policy setting can be used in combination with the \"Allow delegating default credentials\" policy setting to define exceptions for specific servers that are otherwise permitted when using wildcard characters in the \"Allow delegating default credentials\" server list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-denydefaultcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_denydefaultcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f4bbc9d8d0982c":{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r","displayName":"Remote Link to Remote Target","description":null,"helpText":"","infoUrls":[],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_symlinkevaluation_symlinkclassr2r_1","displayName":"True","description":null,"helpText":null}]},"b73f2722b4ff4e86":{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider","displayName":"Microsoft Support Diagnostic Tool: Turn on MSDT interactive communication with support provider","description":"This policy setting configures Microsoft Support Diagnostic Tool (MSDT) interactive communication with the support provider. MSDT gathers diagnostic data for analysis by support professionals.\r\n\r\nIf you enable this policy setting, users can use MSDT to collect and send diagnostic data to a support professional to resolve a problem.\r\n\r\nBy default, the support provider is set to Microsoft Corporation.\r\n\r\nIf you disable this policy setting, MSDT cannot run in support mode, and no data can be collected or sent to the support provider.\r\n\r\nIf you do not configure this policy setting, MSDT support mode is enabled by default.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-msdtsupportprovider"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdtsupportprovider_1","displayName":"Enabled","description":null,"helpText":null}]},"b7661a20d2c13e7a":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate","displayName":"Set Teredo Refresh Rate","description":"This policy setting allows you to configure the Teredo refresh rate.\r\n\r\nNote: On a periodic basis (by default, every 30 seconds), Teredo clients send a single Router Solicitation packet to the Teredo server. The Teredo server sends a Router Advertisement Packet in response. This periodic packet refreshes the IP address and UDP port mapping in the translation table of the Teredo client's NAT device.\r\n\r\nIf you enable this policy setting, you can specify the refresh rate. If you choose a refresh rate longer than the port mapping in the Teredo client's NAT device, Teredo might stop working or connectivity might be intermittent.\r\n\r\nIf you disable or do not configure this policy setting, the refresh rate is configured using the local settings on the computer. The default refresh rate is 30 seconds.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-refresh-rate"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_1","displayName":"Enabled","description":null,"helpText":null}]},"b73369f90c55be5f":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates","displayName":"Replace the default Microsoft templates","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_overridemstemplates_1","displayName":"True","description":null,"helpText":null}]},"b78047318d574676":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_id","displayName":"Rule Id","description":"The Id of the rule, leave this field blank, it will be filled in automatically.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},"b73c12695efe1c9f":{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps","displayName":"Disable Store Originated Apps","description":"Boolean value that disables the launch of all apps from Microsoft Store that came pre-installed or were downloaded.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#disablestoreoriginatedapps"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps_0","displayName":"Disabled","description":"Enable launch of apps.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_disablestoreoriginatedapps_1","displayName":"Enabled","description":"Disable launch of apps.","helpText":null}]},"b7b9271c508127cf":{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership","displayName":"Account Logon Logoff Audit Group Membership","description":"This policy allows you to audit the group memberhsip information in the user's logon token. Events in this subcategory are generated on the computer on which a logon session is created. For an interactive logon, the security audit event is generated on the computer that the user logged on to. For a network logon, such as accessing a shared folder on the network, the security audit event is generated on the computer hosting the resource. When this setting is configured, one or more security audit events are generated for each successful logon. You must also enable the Audit Logon setting under Advanced Audit Policy Configuration\\System Audit Policies\\Logon/Logoff. Multiple events are generated if the group memberhsip information cannot fit in a single security audit event.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditgroupmembership"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditgroupmembership_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"b7b46d166c4a36fc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir","displayName":"Set user data directory","description":"Configures the directory that Google Chrome will use for storing user data.\r\n\r\nIf you set this policy, Google Chrome will use the provided directory regardless whether the user has specified the '--user-data-dir' flag or not. To avoid data loss or other unexpected errors this policy should not be set to a directory used for other purposes, because Google Chrome manages its contents.\r\n\r\nSee https://support.google.com/chrome/a?p=Supported_directory_variables for a list of variables that can be used.\r\n\r\nIf this policy is left not set the default profile path will be used and the user will be able to override it with the '--user-data-dir' command line flag.\r\n\r\nExample value: ${users}/${user_name}/Chrome","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},"b7aea43354a40a86":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls","displayName":"Allow access to sensors on these sites","description":"Setting the policy lets you set a list of URL patterns that specify the sites that can access sensors like motion and light sensors.\r\n\r\nLeaving the policy unset means DefaultSensorsSetting applies for all sites, if it's set. If not, the user's personal setting applies.\r\n\r\nIf the same URL pattern exists in both this policy and the SensorsBlockedForUrls policy, the latter is prioritized and access to motion or light sensors will be blocked.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_sensorsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b7436cecdd3594de":{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout","displayName":"Set Max Connection Timeout","description":"IT admins can use this policy to set the max connection timeout. The connection timeout decides the max wait time for connecting to Cloud PC after sign in. The default max value is 5 min. For best user experience, it is recommended to continue with the default timeout of 5 min. Update only if it takes more than 5 min to connect to the Cloud PC in your organization.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-CloudDesktop#setmaxconnectiontimeout"],"categoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","categoryName":"Cloud Desktop","options":[{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_5","displayName":"5 min","description":"5 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_6","displayName":"6 min","description":"6 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_7","displayName":"7 min","description":"7 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_8","displayName":"8 min","description":"8 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_9","displayName":"9 min","description":"9 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_10","displayName":"10 min","description":"10 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_11","displayName":"11 min","description":"11 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_12","displayName":"12 min","description":"12 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_13","displayName":"13 min","description":"13 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_14","displayName":"14 min","description":"14 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_15","displayName":"15 min","description":"15 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_16","displayName":"16 min","description":"16 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_17","displayName":"17 min","description":"17 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_18","displayName":"18 min","description":"18 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_19","displayName":"19 min","description":"19 min","helpText":null},{"id":"device_vendor_msft_policy_config_clouddesktop_setmaxconnectiontimeout_20","displayName":"20 min","description":"20 min","helpText":null}]},"b791b488d83c1ffa":{"id":"device_vendor_msft_policy_config_connectivity_prohibitinstallationandconfigurationofnetworkbridge","displayName":"Prohibit installation and configuration of Network Bridge on your DNS domain network","description":"Determines whether a user can install and configure the Network Bridge.\n\nImportant: This settings is location aware. It only applies when a computer is connected to the same DNS domain network it was connected to when the setting was refreshed on that computer. If a computer is connected to a DNS domain network other than the one it was connected to when the setting was refreshed, this setting does not apply.\n\nThe Network Bridge allows users to create a layer 2 MAC bridge, enabling them to connect two or more network segements together. This connection appears in the Network Connections folder.\n\nIf you disable this setting or do not configure it, the user will be able to create and modify the configuration of a Network Bridge. Enabling this setting does not remove an existing Network Bridge from the user's computer.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-connectivity#connectivity-prohibitinstallationandconfigurationofnetworkbridge"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"device_vendor_msft_policy_config_connectivity_prohibitinstallationandconfigurationofnetworkbridge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_prohibitinstallationandconfigurationofnetworkbridge_1","displayName":"Enabled","description":null,"helpText":null}]},"b7d33e693c266f2c":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"b711f590da8ecd7d":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dopercentagemaxbackgroundbandwidth","displayName":"DO Percentage Max Background Bandwidth","description":"Specifies the maximum background download bandwidth that Delivery Optimization uses across all concurrent download activities as a percentage of available download bandwidth.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dopercentagemaxbackgroundbandwidth"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"b7b648c83c0bf101":{"id":"device_vendor_msft_policy_config_eventlogservice_controleventlogbehavior","displayName":"Control Event Log behavior when the log file reaches its maximum size","description":"This policy setting controls Event Log behavior when the log file reaches its maximum size.\n\nIf you enable this policy setting and a log file reaches its maximum size, new events are not written to the log and are lost.\n\nIf you disable or do not configure this policy setting and a log file reaches its maximum size, new events overwrite old events.\n\nNote: Old events may or may not be retained according to the \"Backup log automatically when full\" policy setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-eventlogservice#eventlogservice-controleventlogbehavior"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_eventlogservice_controleventlogbehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_eventlogservice_controleventlogbehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"b75aba3686faae08":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c","displayName":"Don't run antimalware programs against ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_iz_partname270c_0","displayName":"Disable","description":null,"helpText":null}]},"b781f9f15341fa2c":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"b79cc5226f44591f":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"b7b1156671ac614c":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100","displayName":"Enable MIME Sniffing","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablemimesniffing_iz_partname2100_3","displayName":"Disable","description":null,"helpText":null}]},"b7d1f7afb1a8230f":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled","displayName":"Automatically open Copilot side pane with contextual insights for links opened from Outlook","description":"This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open web links from Outlook emails sent from the same tenant.\r\n\r\nStarting in Microsoft Edge version 148, when users open eligible links from Outlook emails sent from the same tenant, Microsoft Edge automatically opens the Copilot side pane with contextual insights. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.\r\n\r\nIf you enable this policy or don't configure it, the Copilot side pane opens automatically when users open links from Outlook emails sent from the same tenant.\r\n\r\nIf you disable this policy, the Copilot side pane doesn't open automatically when users open links from Outlook emails sent from the same tenant.\r\n\r\nThis feature applies only to links opened from Outlook emails sent from the same tenant and requires Microsoft Copilot to be available for the user in Microsoft Edge.\r\n\r\nThis feature is disabled if the 'CopilotPageContext' (Control Copilot access to page context for Microsoft Entra ID profiles) policy or the 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane) policy is disabled, regardless of this policy's configuration. Copilot requires access to page content to provide contextual insights.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_m365linksautoopencopilotenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b786dc1ca975a2bc":{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended","displayName":"Visual search enabled","description":"Visual search lets you quickly explore more related content about entities in an image.\r\n\r\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\r\n\r\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\r\n\r\nNote: Visual Search in Web Capture is still managed by 'WebCaptureEnabled' (Enable the Screenshot (previously named Web Capture) feature in Microsoft Edge) policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_recommended_visualsearchenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f926040a0c5f4e":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremapplicationiduri","displayName":"Specify the Application ID URI for your Entra application for OIDC","description":"This setting allows you to specify an Application ID URI for your Entra application for OIDC if it is different from your SharePoint Server URL. To use this setting, you must also enable \"Enable the use of OIDC authentication for syncing content from a SharePoint Server\". This setting affects only OneDrive for Business sync functionality. It does not impact syncing team sites in SharePoint Online.\n\nIf you enable this setting and provide the Application ID URI, this value will be used for requests to the SharePoint Server.\n\nIf you disable or do not configure this setting, we will use the SharePoint Server URL as the Application ID URI instead.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremapplicationiduri_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremapplicationiduri_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f809333c51cdb4":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessaccountinfo_forceallowtheseapps","displayName":"Let Apps Access Account Info Force Allow These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are allowed access to account information. This setting overrides the default LetAppsAccessAccountInfo policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessaccountinfo_forceallowtheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"b7025e1a955b9b0c":{"id":"device_vendor_msft_policy_config_remotedesktopservices_promptforpassworduponconnection","displayName":"Always prompt for password upon connection","description":"This policy setting specifies whether Remote Desktop Services always prompts the client for a password upon connection.\n\nYou can use this setting to enforce a password prompt for users logging on to Remote Desktop Services, even if they already provided the password in the Remote Desktop Connection client.\n\nBy default, Remote Desktop Services allows users to automatically log on by entering a password in the Remote Desktop Connection client.\n\nIf you enable this policy setting, users cannot automatically log on to Remote Desktop Services by supplying their passwords in the Remote Desktop Connection client. They are prompted for a password to log on.\n\nIf you disable this policy setting, users can always log on to Remote Desktop Services automatically by supplying their passwords in the Remote Desktop Connection client.\n\nIf you do not configure this policy setting, automatic logon is not specified at the Group Policy level.\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-promptforpassworduponconnection"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_promptforpassworduponconnection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_promptforpassworduponconnection_1","displayName":"Enabled","description":null,"helpText":null}]},"b72279b186371df3":{"id":"device_vendor_msft_policy_config_start_forcestartsize","displayName":"Force Start Size","description":"Forces the start screen size. If there is policy configuration conflict, the latest configuration request is applied to the device.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#forcestartsize"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_forcestartsize_0","displayName":"Do not force size of Start.","description":"Do not force size of Start.","helpText":null},{"id":"device_vendor_msft_policy_config_start_forcestartsize_1","displayName":"Force non-fullscreen size of Start.","description":"Force non-fullscreen size of Start.","helpText":null},{"id":"device_vendor_msft_policy_config_start_forcestartsize_2","displayName":"Force a fullscreen size of Start.","description":"Force a fullscreen size of Start.","helpText":null}]},"b7d2bc53de02000b":{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_hidewindowssecuritynotificationareacontrol","displayName":"Hide Windows Security Notification Area Control","description":"This policy setting hides the Windows Security notification area control. The user needs to either sign out and sign in or reboot the computer for this setting to take effect. Enabled:Windows Security notification area control will be hidden. Disabled:Windows Security notification area control will be shown. Not configured:Same as Disabled. Supported values:0 - Disabled (default)1 - Enabled","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsDefenderSecurityCenter#hidewindowssecuritynotificationareacontrol"],"categoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","categoryName":"Windows Defender Security Center","options":[{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_hidewindowssecuritynotificationareacontrol_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_hidewindowssecuritynotificationareacontrol_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"b799e1692d72c38f":{"id":"linux_mdatp_managed_advancedsettings_memoryscan","displayName":"Memory scan (preview) (Requires Behavior Monitoring for protection)","description":"Detects and blocks fileless and in-memory threats at runtime","helpText":null,"infoUrls":[],"categoryId":"9d7352fe-a881-456d-a3cd-2b76fc6519f3","categoryName":null,"options":[{"id":"linux_mdatp_managed_advancedsettings_memoryscan_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_advancedsettings_memoryscan_enabled","displayName":"Enabled","description":null,"helpText":null}]},"b75ebbf3d4cc77f1":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_datecolon20","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"b7e35dcb6b2f812a":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders62","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders62_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders62_1","displayName":"True","description":null,"helpText":null}]},"b78cb40c9363bc4d":{"id":"user_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation","displayName":"Block launching desktop apps associated with a file. (User)","description":"This policy setting lets you control whether Windows Store apps can open files using the default desktop app for a file type. Because desktop apps run at a higher integrity level than Windows Store apps, there is a risk that a Windows Store app might compromise the system by opening a file in the default desktop app for a file type.\r\n\r\nIf you enable this policy setting, Windows Store apps cannot open files in the default desktop app for a file type; they can open files only in other Windows Store apps.\r\n\r\nIf you disable or do not configure this policy setting, Windows Store apps can open files in the default desktop app for a file type.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appxruntime#admx-appxruntime-appxruntimeblockfileelevation"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"user_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_appxruntime_appxruntimeblockfileelevation_1","displayName":"Enabled","description":null,"helpText":null}]},"b76d468e85f88859":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablecolorschemechoice","displayName":"Prevent changing color scheme (User)","description":"This setting forces the theme color scheme to be the default color scheme.\r\n\r\nIf you enable this setting, a user cannot change the color scheme of the current desktop theme.\r\n\r\nIf you disable or do not configure this setting, a user may change the color scheme of the current desktop theme.\r\n\r\nFor Windows 7 and later, use the \"Prevent changing color and appearance\" setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-disablecolorschemechoice"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablecolorschemechoice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_disablecolorschemechoice_1","displayName":"Enabled","description":null,"helpText":null}]},"b755997a8e54a44e":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio","displayName":"Microsoft Visio 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft Visio 2010.\r\nBy default, the user settings of Microsoft Visio 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Visio 2010 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Visio 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Visio 2010 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010visio"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010visio_1","displayName":"Enabled","description":null,"helpText":null}]},"b758969c9a608843":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013","displayName":"Microsoft Office 365 Outlook 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_1","displayName":"Enabled","description":null,"helpText":null}]},"b7ddc691c742251c":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_sports","displayName":"Sports (User)","description":"This policy setting configures the synchronization of user settings for the Sports app.\r\nBy default, the user settings of Sports sync between computers. Use the policy setting to prevent the user settings of Sports from synchronizing between computers.\r\nIf you enable this policy setting, Sports user settings continue to sync.\r\nIf you disable this policy setting, Sports user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-sports"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_1","displayName":"Enabled","description":null,"helpText":null}]},"b764679832af0606":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_alloweddomainsforapps_alloweddomainsforapps","displayName":"Define domains allowed to access Google Workspace (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"b79a0816c9421865":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode","displayName":"Control use of the Headless Mode (User)","description":"Setting this policy to Enabled or leaving the policy unset allows use of the headless mode. Setting this policy to Disabled denies use of the headless mode.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_headlessmode_1","displayName":"Enabled","description":null,"helpText":null}]},"b736ee93bfabfc20":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled","displayName":"Enable the Shared Clipboard Feature (User)","description":"Enable the Shared Clipboard feature which allows users to send text between Chrome Desktops and an Android device when Sync is enabled and the user is Signed-in.\r\n\r\nIf this policy is set to true, the capability of sending text, cross device, for chrome user is enabled.\r\n\r\nIf this policy is set to false, the capability of sending text, cross device, for chrome user is disabled.\r\n\r\nIf you set this policy, users cannot change or override it.\r\n\r\nIf this policy is left unset, the shared clipboard feature is enabled by default.\r\n\r\nIt is up to the admins to set policies in all platforms they care about. It's recommended to set this policy to one value in all platforms.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sharedclipboardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f4eea44be24d87":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters","displayName":"Command-line parameters for switching from the alternative browser. (User)","description":"Setting the policy to a list of strings means the strings are joined with spaces and passed from Internet Explorer® to Google Chrome as command-line parameters. If an parameter contains ${url}, ${url} is replaced with the URL of the page to open. If no parameter contains ${url}, the URL is appended at the end of the command line.\r\n\r\nEnvironment variables are expanded. On Microsoft® Windows®, %ABC% is replaced with the value of the ABC environment variable.\r\n\r\nLeaving the policy unset means Internet Explorer® only passes the URL to Google Chrome as a command-line parameter.\r\n\r\nNote: If the Legacy Browser Support add-in for Internet Explorer® isn't installed, this policy has no effect.\r\n\r\nExample value:\r\n\r\n--force-dark-mode","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f6ef61076e5000":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist","displayName":"Websites to open in alternative browser (User)","description":"Setting the policy controls the list of websites to open in an alternative browser. Each item is treated as a rule for something to open in an alternative browser. Google Chrome uses those rules when choosing if a URL should open in an alternative browser. When the Internet Explorer® add-in is on, Internet Explorer® switches back to Google Chrome when the rules don't match. If rules contradict each other, Google Chrome uses the most specific rule.\r\n\r\nLeaving the policy unset adds no websites to the list.\r\n\r\nNote: Elements can also be added to this list through the BrowserSwitcherUseIeSitelist and BrowserSwitcherExternalSitelistUrl policies.\r\n\r\nExample value:\r\n\r\nie.com\r\n!open-in-chrome.ie.com\r\nfoobar.com/ie-only/","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherurllist_1","displayName":"Enabled","description":null,"helpText":null}]},"b7d9b86b6a6940b1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls","displayName":"List of alternate URLs for the default search provider (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderAlternateURLs specifies a list of alternate URLs for extracting search terms from the search engine. The URLs should include the string '{searchTerms}'.\r\n\r\nLeaving DefaultSearchProviderAlternateURLs unset means no alternate URLs are used to extract search terms.\r\n\r\nExample value:\r\n\r\nhttps://search.my.company/suggest#q={searchTerms}\r\nhttps://search.my.company/suggest/search#q={searchTerms}","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovideralternateurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b78978475ae466d9":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection","displayName":"Default printer selection rules (User)","description":"Setting the policy sets the rules for selecting the default printer in Google Chrome, overriding the default rules. Printer selection occurs the first time users try to print, when Google Chrome seeks a printer matching the specified attributes. In case of a less than perfect match, Google Chrome can be set to select any matching printer, depending on the order printers are discovered.\r\n\r\nLeaving the policy unset or set to attributes for which there's no match means the built-in PDF printer is the default. If there's no PDF printer, Google Chrome defaults to none.\r\n\r\nPrinters connected to Google Cloud Print are considered \"cloud\", the rest of the printers are classified as \"local\".\r\n\r\nNote: Omitting a field means all values match. For example, not specifying connectivity causes Print Preview to start discovery of all kinds of printers, \"local\" and \"cloud\". Regular expression patterns must follow the JavaScript RegExp syntax, and matches are case sensistive.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=DefaultPrinterSelection for more information about schema and formatting.\r\n\r\n\r\nExample value: { \"kind\": \"cloud\", \"idPattern\": \".*public\", \"namePattern\": \".*Color\" }","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_defaultprinterselection_1","displayName":"Enabled","description":null,"helpText":null}]},"b755967e54abf681":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},"b79e5ad19de99067":{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch","displayName":"Don’t allow Dynamic Data Exchange (DDE) server launch in Excel (User)","description":"This policy setting allows you to control whether Dynamic Data Exchange (DDE) server launch is allowed.\r\n\r\nBy default, DDE server launch is turned off, but users can turn on DDE server launch by going to File > Options > Trust Center > Trust Center Settings > External Content.\r\n\r\nFor security reasons, turning on DDE server launch is not recommended.\r\n\r\nNote: For DDE server launch to work, Dynamic Data Exchange (DDE) server lookup must be turned on. Be sure that the “Don’t allow Dynamic Data Exchange (DDE) server lookup” policy setting isn’t enabled, because enabling that policy setting turns off DDE server lookup.\r\n\r\nIf you enable this policy setting, DDE server launch isn’t allowed, and users can’t turn on DDE server launch in the Trust Center.\r\n\r\nIf you disable this policy setting, DDE server launch is allowed, and users cannot turn off DDE server launch in the Trust Center. For security reasons, this is not recommended.\r\n\r\nIf you don’t configure this policy setting, DDE server launch is turned off, but users can turn on DDE server launch in the Trust Center.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.","helpText":"","infoUrls":[],"categoryId":"e36863b6-3232-4a29-be02-32ee67cc48b9","categoryName":"External Content","options":[{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v3~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_externalcontent_l_disableddeserverlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},"b773a96581c8c79d":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowlessprivilegedsites"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"b771a13c69dba4c6":{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page (User)","description":"By default, the App Launcher is shown every time a user opens a new tab page.\r\n\r\nIf you enable or don't configure this policy, there is no change on the Microsoft Edge new tab page and App Launcher is there for users.\r\n\r\nIf you disable this policy, App Launcher doesn't appear and users won't be able to launch M365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge~startup_newtabpageapplauncherenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"b7334ad81a2a6185":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls","displayName":"Block clipboard use on specific sites (User)","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"b7bea2f8ac7e60b8":{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext","displayName":"Control Copilot with Commercial Data Protection access to page context for Microsoft Entra ID profiles (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 132.\r\n\r\nThis policy has been obsoleted as of Edge 133. Instead of this obsolete policy, we recommend using 'EdgeEntraCopilotPageContext' (Control Copilot access to Microsoft Edge page content for Entra account user profiles when using Copilot in the Microsoft Edge sidepane).\r\n\r\nThis policy controls access to page contents for Copilot with Commercial Data Protection in the Edge sidebar. This policy applies only to Microsoft Entra ID profiles. To summarize pages and interact with text selections, it needs to be able to access the page contents. This policy does not apply to MSA profiles. This policy doesn't control access for Copilot without Commercial Data Protection. Access for Copilot without Commercial Data Protection is controlled by the policy CopilotPageContext.\r\n\r\nIf you enable this policy, Copilot with Commercial Data Protection will have access to page context.\r\n\r\nIf you don't configure this policy, a user can enable access to page context for Copilot with Commercial Data Protection using the setting toggle in Edge.\r\n\r\nIf you disable this policy, Copilot with Commercial Data Protection will not be able to access page context.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_copilotcdppagecontext_1","displayName":"Enabled","description":null,"helpText":null}]},"b7386dd640b71cb9":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_exemptdomainfiletypepairsfromfiletypedownloadwarnings_exemptdomainfiletypepairsfromfiletypedownloadwarningsdesc","displayName":"Disable download file type extension-based warnings for specified file types on domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"b7ab6e4af9520238":{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior","displayName":"Allow Basic Authentication prompts from network proxies (User)","description":"This policy setting controls whether network proxies are allowed to show Basic Authentication prompts.\r\n\r\nBy default, all Basic Authentication sign-in prompts are blocked, and the user is shown a message that the sign-in method isn’t allowed.\r\n\r\nIf you enable this policy setting, then network proxies will be allowed to show Basic Authentication prompts.\r\n\r\nWarning: Allowing Basic Authentication sign-in prompts isn’t recommended because it’s a security risk.\r\n\r\nIf you disable or don’t configure this policy setting, all Basic Authentication sign-in prompts from network proxes will be blocked, and the user will be shown a message that the sign-in method isn’t allowed.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2199001.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_securitysettings_l_basicauthproxybehavior_1","displayName":"Enabled","description":null,"helpText":null}]},"b74c7d1dcb1c5a9e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_0","displayName":"Use AutoSave Default Setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_1","displayName":"AutoSave Is On By Default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffpowerpoint_l_autosavedefaultsettingenum_2","displayName":"AutoSave Is Off By Default","description":null,"helpText":null}]},"b777ee6da9fd8e34":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice09_l_broadcastserviceminorversion9","displayName":"Server Minor Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"b71cd1a2b23afe47":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_l_setupdateintervalforoutlookglobaladdresslistdictionaryspinid","displayName":"(in minutes) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},"b7da79986f16191b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant","displayName":"Set password hash format as ISO-compliant (User)","description":"This policy setting allows you create ISO-compliant modification password records.\r\n\r\nIf you enable this policy setting, then passwords created will be ISO-compliant.\r\n\r\nIf you disable or do not configure this policy setting, the default will be ECMA-style records.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_setpasswordhashformatasisocompliant_1","displayName":"Enabled","description":null,"helpText":null}]},"b7a775636fb04621":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles","displayName":"Set User path for the label page size update files (User)","description":"This policy setting allows you to override the User path for the label page size update files. \r\n\r\nIf you enable this policy setting, you may enter the path to the PSX update files and override the User path.\r\n\r\nIf you disable or do not configure this policy setting, the User path for the label page size update files remains valid.","helpText":"","infoUrls":[],"categoryId":"7a8b936d-b4b0-408f-bec5-3c97050730f8","categoryName":"Shared paths","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_sharedpaths_l_setuserpathforthelabelpagesizeupdatefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"b791fd725bac742d":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize","displayName":"Default Font Size (User)","description":"Specifies the value in the option ''Size''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_defaultfontsize_1","displayName":"Enabled","description":null,"helpText":null}]},"b7cd3e58bbae2e7f":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass","displayName":"Disallows add-ons access to password protected sections (User)","description":"This option disallows extensibility add-ons the ability to access password protected sections if they are unlocked.","helpText":"","infoUrls":[],"categoryId":"1979a12b-2a72-438d-9de7-320d1b38e777","categoryName":"Password","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_password_l_disallowsaddonsaccesstopass_1","displayName":"Enabled","description":null,"helpText":null}]},"b70151fd552547dd":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_specifycngrandomnumbergeneratoralgorithm_l_specifycngrandomnumbergeneratoralgorithmid","displayName":"Random number generator: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},"b74b3212d8f993ad":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec","displayName":"Specify duration of Desktop Alert on mouse over (in milliseconds) (User)","description":"Specify duration of Desktop Alert on mouse over (in milliseconds)","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydurationofdesktopalertonmouseoverinmillisec_1","displayName":"Enabled","description":null,"helpText":null}]},"b72748e2f87f124b":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"b726325de9fbb34d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript","displayName":"Ordinals with superscript (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"af9b2941-29f9-4ee5-ae09-215f4e242943","categoryName":"AutoCorrect Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_proofing~l_autocorrectoptions_l_ordinalswithsuperscript_1","displayName":"Enabled","description":null,"helpText":null}]},"b77dd600ee2fc763":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_pathcolon36","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"b7f11e08291ebd33":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline","displayName":"Tools | Compare and Merge Documents, Legal blackline (User)","description":"If you enable this policy setting, a comparison between two documents automatically generates a new Legal Blackline document, leaving the original documents unchanged.","helpText":"","infoUrls":[],"categoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_miscellaneous178_l_toolscompareandmergedocumentslegalblackline_1","displayName":"Enabled","description":null,"helpText":null}]},"b7f6895c5c193540":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing_l_delaybeforestartingotherproofingtools_l_delaybeforestartingbackgroundgrammarchecker3","displayName":"Milliseconds (e.g. 5000 milliseconds = 5 seconds) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dc049161-17c6-411e-906b-a871b33651cd","categoryName":"Proofing","options":null},"b791e810196fc3b5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols","displayName":"Symbol characters (--) with symbols (User)","description":"Checks/unchecks the option ''Hyphens (--) with dash (-)''.","helpText":"","infoUrls":[],"categoryId":"b6cafb2c-81be-40cf-90d8-788f713f7099","categoryName":"Replace as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_replaceasyoutype_l_symbolcharacterswithsymbols_1","displayName":"Enabled","description":null,"helpText":null}]},"b794583a0a166949":{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections","displayName":"Enable Log Success Connections","description":"This value is used as an on/off switch. If this value is on, the firewall logs all successful inbound connections. The merge law for this option is to let \"on\" values win.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections_false","displayName":"Disable Logging Of Successful Connections","description":"Disable Logging Of Successful Connections","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablelogsuccessconnections_true","displayName":"Enable Logging Of Successful Connections","description":"Enable Logging Of Successful Connections","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/ba.json b/public/intune-definitions/ba.json index 536af05530f3..7e1adec2467c 100644 --- a/public/intune-definitions/ba.json +++ b/public/intune-definitions/ba.json @@ -1 +1 @@ -{"ba1800ed684874e2":{"id":"com.android.devicerestrictionpolicy.bluetoothblocked","displayName":"Block Bluetooth","description":"If 'True', disables Bluetooth entirely on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow Bluetooth to be used. Available for fully managed, dedicated, and corporate-owned work profile devices. In comparison, Bluetooth configuration disables the user from making changes to the Bluetooth toggle. As a result, it might be either 'On' or 'Off' depending on the state of Bluetooth prior to applying a policy with Bluetooth configuration enabled.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblocked_true","displayName":"True","description":"True","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblocked_false","displayName":"False","description":"false","helpText":null}]},"ba203356254b5a62":{"id":"com.apple.app.lock_app_options_enablespeakselection","displayName":"Enable Speak Selection","description":"If true, enables Speak Selection.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablespeakselection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablespeakselection_true","displayName":"True","description":null,"helpText":null}]},"ba62402b783327cf":{"id":"com.apple.applicationaccess_ratingappsnz","displayName":"Rating Apps - New Zealand","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsnz_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_22","displayName":"All","description":null,"helpText":null}]},"bae33027ca684c61":{"id":"com.apple.dock_show-recents","displayName":"Show Recents","description":"If true, enables \"Show recent items.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_show-recents_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_show-recents_true","displayName":"True","description":null,"helpText":null}]},"ba4343ed0898d62c":{"id":"com.apple.domains_crosssitetrackingpreventionrelaxeddomains","displayName":"Cross Site Tracking Prevention Relaxed Domains","description":"Specify an array of up to ten domains \r\nwhen cross-site tracking is required for functionality.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},"baf792f5df4e5f75":{"id":"com.apple.extensiblesso_ignored_kerberos_$typepicker","displayName":"IGNORED","description":null,"helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_ignored_kerberos_0","displayName":"Array","description":null,"helpText":null}},"ba62c638ee838256":{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress","displayName":"Allow S/MIME certificates without a matching email address","description":"Allow users to decrypt and encrypt S/MIME messages when the S/MIME certificate does not match the email address.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-smime-certificates-without-a-matching-email-address"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress_true","displayName":"True","description":null,"helpText":null}]},"ba210359023742d9":{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page","description":"By default, the Microsoft Edge new tab page includes three Bing Chat entry points: one inside the search box, one in the Bing autosuggest dropdown when users click or begin typing in the box, and one as a suggested prompt below the box.\n\nIf you enable or don't configure this policy, these Bing Chat entry points continue to appear on the new tab page.\n\nIf you disable this policy, all Bing Chat entry points are removed from the new tab page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagebingchatenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"baddf3cff77bfee5":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo_hash","displayName":"Hash","description":"The SHA-256 hash of the image.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"ba85355a980f93db":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page.","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\n\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\n\nIf this policy is not configured, the default neutralStrokeActive (#cecece) color will be used as the backplate color.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagecompanylogobackplatecolor"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"baa8d4e0882538c4":{"id":"com.apple.systemconfiguration_proxies","displayName":"Proxies","description":"The dictionary containing all the proxies for this device.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},"ba5cc988cf5ccbc3":{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"ba8c76ee75fe0645":{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled","displayName":"Super Drag Drop Enabled","description":"This policy lets you configure the Super Drag Drop feature in Microsoft Edge.\n\nWith this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine.\n\nIf you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.\n\nIf you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"ba9ae0583f874e07":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata","displayName":"Policy rule","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},"ba1b8b4aef334808":{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly","displayName":"Allow delegating fresh credentials with NTLM-only server authentication","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via NTLM.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials can be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of fresh credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of fresh credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating fresh credentials with NTLM-only server authentication\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowfreshcredentialswhenntlmonly"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_1","displayName":"Enabled","description":null,"helpText":null}]},"ba74dc1cc490e5c9":{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification","displayName":"Disable delete notifications on all volumes","description":"Delete notification is a feature that notifies the underlying storage device of clusters that are freed due to a file delete operation.\r\n\r\nA value of 0, the default, will enable delete notifications for all volumes. \r\nA value of 1 will disable delete notifications for all volumes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-disabledeletenotification"],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification_1","displayName":"Enabled","description":null,"helpText":null}]},"bacc4029b5d384ee":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_asyncscriptdelay1","displayName":"minute:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"baf1240af71fbf03":{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp","displayName":"Turn off Active Help","description":"This policy setting specifies whether active content links in trusted assistance content are rendered. By default, the Help viewer renders trusted assistance content with active elements such as ShellExecute links and Guided Help links.\r\n\r\nIf you enable this policy setting, active content links are not rendered. The text is displayed, but there are no clickable links for these elements.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior applies (Help viewer renders trusted assistance content with active elements).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-helpandsupport#admx-helpandsupport-activehelp"],"categoryId":"5be35eeb-62e9-4317-8804-018a9dd31149","categoryName":"Online Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp_1","displayName":"Enabled","description":null,"helpText":null}]},"bab477d735237fb4":{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy","displayName":"Always wait for the network at computer startup and logon","description":"This policy setting determines whether Group Policy processing is synchronous (that is, whether computers wait for the network to be fully initialized during computer startup and user logon). By default, on client computers, Group Policy processing is not synchronous; client computers typically do not wait for the network to be fully initialized at startup and logon. Existing users are logged on using cached credentials, which results in shorter logon times. Group Policy is applied in the background after the network becomes available. \r\n\r\nNote that because this is a background refresh, extensions such as Software Installation and Folder Redirection take two logons to apply changes. To be able to operate safely, these extensions require that no users be logged on. Therefore, they must be processed in the foreground before users are actively using the computer. In addition, changes that are made to the user object, such as adding a roaming profile path, home directory, or user object logon script, may take up to two logons to be detected.\r\n\r\nIf a user with a roaming profile, home directory, or user object logon script logs on to a computer, computers always wait for the network to be initialized before logging the user on. If a user has never logged on to this computer before, computers always wait for the network to be initialized.\r\n\r\nIf you enable this policy setting, computers wait for the network to be fully initialized before users are logged on. Group Policy is applied in the foreground, synchronously. \r\n\r\nOn servers running Windows Server 2008 or later, this policy setting is ignored during Group Policy processing at computer startup and Group Policy processing will be synchronous (these servers wait for the network to be initialized during computer startup). \r\n\r\nIf the server is configured as follows, this policy setting takes effect during Group Policy processing at user logon:\r\n• The server is configured as a terminal server (that is, the Terminal Server role service is installed and configured on the server); and\r\n• The “Allow asynchronous user Group Policy processing when logging on through Terminal Services” policy setting is enabled. This policy setting is located under Computer Configuration\\Policies\\Administrative templates\\System\\Group Policy\\.\r\n\r\nIf this configuration is not implemented on the server, this policy setting is ignored. In this case, Group Policy processing at user logon is synchronous (these servers wait for the network to be initialized during user logon).\r\n\r\nIf you disable or do not configure this policy setting and users log on to a client computer or a server running Windows Server 2008 or later and that is configured as described earlier, the computer typically does not wait for the network to be fully initialized. In this case, users are logged on with cached credentials. Group Policy is applied asynchronously in the background.\r\n\r\nNotes: \r\n-If you want to guarantee the application of Folder Redirection, Software Installation, or roaming user profile settings in just one logon, enable this policy setting to ensure that Windows waits for the network to be available before applying policy. \r\n-If Folder Redirection policy will apply during the next logon, security policies will be applied asynchronously during the next update cycle, if network connectivity is available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-syncforegroundpolicy"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"baf6e64a5975a1c1":{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2","displayName":"Critical battery notification action","description":"This policy setting specifies the action that Windows takes when battery capacity reaches the critical battery notification level.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Take no action\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargeaction0-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_1","displayName":"Enabled","description":null,"helpText":null}]},"bad4a5aa0af60869":{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2","displayName":"For tablet pen input, don’t show the Input Panel icon","description":"Prevents the Tablet PC Input Panel icon from appearing next to any text entry area in applications where this behavior is available. This policy applies only when using a tablet pen as an input device.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will never appear next to text entry areas when using a tablet pen as an input device. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will appear next to any text entry area in applications where this behavior is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-iptiptarget-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2_1","displayName":"Enabled","description":null,"helpText":null}]},"ba735cadebe13666":{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval","displayName":"Set 6to4 Relay Name Resolution Interval","description":"This policy setting allows you to specify the interval at which the relay name is resolved. The 6to4 relay name resolution interval setting has no effect if 6to4 connectivity is not available on the host.\r\n\r\nIf you enable this policy setting, you can specify the value for the duration at which the relay name is resolved periodically.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-6to4-router-name-resolution-interval"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_1","displayName":"Enabled","description":null,"helpText":null}]},"ba571c74cc7de9b2":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics","displayName":"Optimize visual experience when using RemoteFX","description":"This policy setting allows you to specify the visual experience that remote users will have in Remote Desktop Connection (RDC) connections that use RemoteFX. You can use this policy to balance the network bandwidth usage with the type of graphics experience that is delivered.\r\n\r\nDepending on the requirements of your users, you can reduce network bandwidth usage by reducing the screen capture rate. You can also reduce network bandwidth usage by reducing the image quality (increasing the amount of image compression that is performed).\r\n\r\nIf you have a higher than average bandwidth network, you can maximize the utilization of bandwidth by selecting the highest setting for screen capture rate and the highest setting for image quality.\r\n\r\nBy default, Remote Desktop Connection sessions that use RemoteFX are optimized for a balanced experience over LAN conditions. If you disable or do not configure this policy setting, Remote Desktop Connection sessions that use RemoteFX will be the same as if the medium screen capture rate and the medium image compression settings were selected (the default behavior). \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-remotedesktopvirtualgraphics"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},"bac840b559233ca3":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chaindisable","displayName":"ChainDisable","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"baf0a0af988624e9":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxpollinterval","displayName":"MaxPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"bab974adc2bb8ac9":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users cannot preview items or get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-restricted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted_1","displayName":"Enabled","description":null,"helpText":null}]},"baf39e9f13a6cc51":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo","displayName":"Microsoft To Do (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo_1","displayName":"True","description":null,"helpText":null}]},"ba1fbac5b6339356":{"id":"device_vendor_msft_policy_config_bits_jobinactivitytimeout","displayName":"Job Inactivity Timeout","description":"This policy setting specifies the number of days a pending BITS job can remain inactive before the job is considered abandoned. By default BITS will wait 90 days before considering an inactive job abandoned. After a job is determined to be abandoned, the job is deleted from BITS and any downloaded files for the job are deleted from the disk. NoteAny property changes to the job or any successful download action will reset this timeout. Value type is integer. Default is 90 days. Supported values range: 0 - 999Consider increasing the timeout value if computers tend to stay offline for a long period of time and still have pending jobs. Consider decreasing this value if you are concerned about orphaned jobs occupying disk space. If you disable or do not configure this policy setting, the default value of 90 (days) will be used for the inactive job timeout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#jobinactivitytimeout"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},"baa8c734077a11a4":{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising","displayName":"Allow Advertising","description":"Specifies whether the device can send out Bluetooth advertisements. If this is not set or it is deleted, the default value of 1 (Allow) is used. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowadvertising"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising_0","displayName":"Block","description":"Not allowed. When set to 0, the device will not send out advertisements. To verify, use any Bluetooth LE app and enable it to do advertising. Then, verify that the advertisement is not received by the peripheral.","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising_1","displayName":"Allow","description":"Allowed. When set to 1, the device will send out advertisements. To verify, use any Bluetooth LE app and enable it to do advertising. Then, verify that the advertisement is received by the peripheral.","helpText":null}]},"ba7c44e6ef1b601a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled","displayName":"Enable the network service sandbox","description":"This policy controls whether or not the network service process runs sandboxed.\r\nIf this policy is enabled, the network service process will run sandboxed.\r\nIf this policy is disabled, the network service process will run unsandboxed. This leaves users open to additional security risks related to running the network service unsandboxed.\r\nIf this policy is not set, the default configuration for the network sandbox will be used. This may vary depending on Google Chrome release, currently running field trials, and platform.\r\nThis policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ba1fc1c9b9869ff3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on these sites","description":"Cookies set for domains matching these patterns will revert to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute, and skips the scheme comparison when evaluating if two sites are same-site. See https://www.chromium.org/administrators/policy-list-3/cookie-legacy-samesite-policies for full description.\r\n\r\nFor cookies on domains not covered by the patterns specified here, or for all cookies if this policy is not set, the global default value will be the user's personal configuration.\r\n\r\nFor detailed information on valid patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nNote that patterns you list here are treated as domains, not URLs, so you should not specify a scheme or port.\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},"ba7f5117717deeb7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls_webusbblockedforurlsdesc","displayName":"Block WebUSB on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"ba289bc043b45888":{"id":"device_vendor_msft_policy_config_handwriting_paneldefaultmodedocked","displayName":"Panel Default Mode Docked","description":"Specifies whether the handwriting panel comes up floating near the text box or attached to the bottom of the screen","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Handwriting#paneldefaultmodedocked"],"categoryId":"4e8db19c-cb8e-4361-8849-1d435d50bb66","categoryName":"Handwriting","options":[{"id":"device_vendor_msft_policy_config_handwriting_paneldefaultmodedocked_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_handwriting_paneldefaultmodedocked_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"baf33cbaef24e25b":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended","displayName":"Allow importing of browsing history","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\r\n\r\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"ba3d4e61daa10fc6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended","displayName":"Register protocol handlers","description":"Register a list of protocol handlers. Set the protocol property to the scheme (like 'mailto') and the url property to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which will be replaced by the handled URL.\r\n\r\nYou can recommend a specific value for this policy, but you can't require that your users use it.\r\n\r\nThe protocol handlers registered by policy are merged with any handlers registered by the user, and both are available for use. The user can override the protocol handlers installed by policy by installing a new default handler, but they can't remove a protocol handler registered by policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://mail.contoso.com/mail/?extsrc=mailto&url=%s\", \r\n \"default\": true, \r\n \"protocol\": \"mailto\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"ba565c838991547a":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices","description":"Allows you to set a list of urls that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs. Each item in the list must contain both devices and urls in order for the policy to be valid. Each item in devices can contain a vendor ID and product ID field. Any ID that is omitted is treated as a wildcard with one exception, and that exception is that a product ID cannot be specified without a vendor ID also being specified. Otherwise, the policy will not be valid and will be ignored.\r\n\r\nThe USB permission model uses the URL of the requesting site (\"requesting URL\") and the URL of the top-level frame site (\"embedding URL\") to grant permission to the requesting URL to access the USB device. The requesting URL may be different than the embedding URL when the requesting site is loaded in an iframe. Therefore, the \"urls\" field can contain up to two URL strings delimited by a comma to specify the requesting and embedding URL respectively. If only one URL is specified, then access to the corresponding USB devices will be granted when the requesting site's URL matches this URL regardless of embedding status. The URLs in \"urls\" must be valid URLs, otherwise the policy will be ignored.\r\n\r\nIf this policy is left not set, the global default value will be used for all sites either from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy if it is set, or the user's personal configuration otherwise.\r\n\r\nURL patterns in this policy should not clash with the ones configured via 'WebUsbBlockedForUrls' (Block WebUSB on specific sites). If there is a clash, this policy will take precedence over 'WebUsbBlockedForUrls' and 'WebUsbAskForUrls' (Allow WebUSB on specific sites).\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://contoso.com\", \r\n \"https://fabrikam.com\"\r\n ], \r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234, \r\n \"product_id\": 5678\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"ba977e1a53355ae2":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when:\r\n- The 'Passwords' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy ClearBrowsingDataOnExit is enabled\r\n\r\nIf you enable this policy, passwords won't be cleared when the browser closes.\r\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ba9bc2d4979c2fad":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_allowtokenbindingforurlsdesc","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"ba471280b192bbb3":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_winprojexe104","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_winprojexe104_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_winprojexe104_1","displayName":"True","description":null,"helpText":null}]},"bac646968a8fc393":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory","displayName":"Let Apps Access Call History","description":"This policy setting specifies whether Windows apps can access call history.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscallhistory"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"baceb321b6172664":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture","displayName":"Disables send-a-smile's screenshot capability","description":"This policy disables the screenshot capability in the send-a-smile feature.","helpText":"","infoUrls":[],"categoryId":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","categoryName":"Feedback Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture_1","displayName":"Enabled","description":null,"helpText":null}]},"bacd7219fa058a77":{"id":"settings_item_accessibilitysettings_textsize","displayName":"Text Size","description":"The accessibility text size apps that support dynamic text use. 0 is the smallest value, and 11 is the largest available.","helpText":null,"infoUrls":[],"categoryId":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","categoryName":"Accessibility Settings","options":[{"id":"settings_item_accessibilitysettings_textsize_0","displayName":"0","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_1","displayName":"1","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_2","displayName":"2","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_3","displayName":"3","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_4","displayName":"4","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_5","displayName":"5","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_6","displayName":"6","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_7","displayName":"7","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_8","displayName":"8","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_9","displayName":"9","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_10","displayName":"10","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_11","displayName":"11","description":null,"helpText":null}]},"badf14b08b0b8c56":{"id":"softwareupdate_automaticactions_installosupdates","displayName":"Install OS Updates","description":"Specifies whether automatic install of available OS updates can be controlled by the user:\n* \"Allowed\" - the user can enable or disable automatic installs.\n* \"AlwaysOn\". - automatic installs are always enabled. This option requires automatic downloads to be turned on.\n* \"AlwaysOff\" - automatic installs are always disabled.","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":[{"id":"softwareupdate_automaticactions_installosupdates_0","displayName":"Allowed","description":null,"helpText":null},{"id":"softwareupdate_automaticactions_installosupdates_1","displayName":"Always On","description":null,"helpText":null},{"id":"softwareupdate_automaticactions_installosupdates_2","displayName":"Always Off","description":null,"helpText":null}]},"ba36ebe2fe193a9a":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iis","displayName":"Internet Information Services (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-iis"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iis_1","displayName":"Enabled","description":null,"helpText":null}]},"ba999e7863c309ae":{"id":"user_vendor_msft_policy_config_admx_msi_disablemedia","displayName":"Prevent removable media source for any installation (User)","description":"This policy setting prevents users from installing any programs from removable media.\r\n\r\nIf you enable this policy setting, if a user tries to install a program from removable media, such as CD-ROMs, floppy disks, and DVDs, a message appears stating that the feature cannot be found.\r\n\r\nThis policy setting applies even when the installation is running in the user's security context.\r\n\r\nIf you disable or do not configure this policy setting, users can install from removable media when the installation is running in their own security context, but only system administrators can use removable media when an installation is running with elevated system privileges, such as installations offered on the desktop or in Add or Remove Programs.\r\n\r\nAlso, see the \"Enable user to use media source while elevated\" and \"Hide the 'Add a program from CD-ROM or floppy disk' option\" policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablemedia"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"user_vendor_msft_policy_config_admx_msi_disablemedia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_msi_disablemedia_1","displayName":"Enabled","description":null,"helpText":null}]},"ba40e0cc3e81ae19":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup","displayName":"InfoPath 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft InfoPath 2013.\r\nMicrosoft InfoPath 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft InfoPath 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft InfoPath 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft InfoPath 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013infopathbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"ba4d098ec94a101a":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup","displayName":"Visio 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Visio 2013.\r\nMicrosoft Visio 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Visio 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Visio 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Visio 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013visiobackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup_1","displayName":"Enabled","description":null,"helpText":null}]},"ba75f125fcbad1a3":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-localmachinelockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"babed335d3dca491":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes (User)","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with\r\nthe \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome makes srcdoc iframes\r\nwith \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\r\n\r\nSetting the policy to Disabled leaves the srcdoc iframe not controlled by\r\nServiceWorker.\r\n\r\nThis policy is intended to be temporary and will be removed in 2026.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ba932e52c82d1e1e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill","displayName":"Automatically Flash Fill (User)","description":"This policy setting controls the \"Automatically Flash Fill\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will enable automatic Flash Fill. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will turn off the Automatic Flash Fill feature.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill_1","displayName":"Enabled","description":null,"helpText":null}]},"baba7d773ce6982c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_descriptioncolon59","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"badf9e49689871f4":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_descriptioncolon71","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"baecc2a1d404d6d8":{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths","displayName":"Intranet Sites: Include all network paths (UNCs) (User)","description":"This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone.\n\nIf you enable this policy setting, all network paths are mapped into the Intranet Zone.\n\nIf you disable this policy setting, network paths are not necessarily mapped into the Intranet Zone (other rules might map one there).\n\nIf you do not configure this policy setting, users choose whether network paths are mapped into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includeallnetworkpaths"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_1","displayName":"Enabled","description":null,"helpText":null}]},"bad9c288b4e1d28e":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},"baf4aad25201f182":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"ba05b374376d6003":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled","displayName":"Enable Copilot address bar suggestions (User)","description":"This policy controls whether Copilot chat suggestions appear in the address bar of Microsoft Edge.\n\nIf you enable this policy or don't configure it, Copilot chat suggestions appear in the address bar.\n\nIf you disable this policy, Copilot chat suggestions don't appear in the address bar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ba01c00ed204ae11":{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended","displayName":"Get user confirmation before closing a browser window with multiple tabs (User)","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\r\n\r\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\r\n\r\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"baf264e219a85087":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load blockable mixed content","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow blockable mixed content","description":null,"helpText":null}]},"ba90f7318a3d8daf":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean","displayName":"Korean (User)","description":"Enables the editing language Korean","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean_1","displayName":"Enabled","description":null,"helpText":null}]},"ba9dcdf709736863":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_pathcolon290","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"bab190c8b2bf514f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps","displayName":"Allow Unsecure web add-ins and Catalogs (User)","description":"This policy setting allows users to run unsecure web add-in, which are add-ins that have web page or catalog locations that are not SSL-secured (https://), and are not in users' Internet zones.\r\n\r\nIf you enable this policy setting, users can run unsecure apps. To enable specific unsecure web add-ins, you must also configure the Trusted Web add-in Catalog policy settings to trust the catalogs that contains those Add-ins.\r\n\r\nIf you disable or do not configure this policy setting, unsecure web add-ins are not allowed.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps_1","displayName":"Enabled","description":null,"helpText":null}]},"ba96a6dcc408f3e8":{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey","displayName":"Allow users to receive and respond to in-product surveys from Microsoft (User)","description":"This policy setting allows you to control whether your users can receive and respond to in-product surveys in Microsoft 365 products. Microsoft will use this feedback to improve the product experience for users. The ability to receive and respond to in-product surveys is enabled by default.\r\n\r\nIf you enable this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nIf you disable this policy setting, Microsoft will not survey your users while they are using Microsoft 365 products.\r\n\r\nIf you don't configure this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This data will be considered \"Feedback\" under your Microsoft 365 agreement, including information that would otherwise be considered \"Customer Data\" or \"Personal Data\".\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_1","displayName":"Enabled","description":null,"helpText":null}]},"ba7eff8d4a2afbe2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded_l_preventmapiservicesfrombeingaddedpart","displayName":"Enter MAPI services to disable (semi-colon delimited) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},"ba4a8546ee3810a5":{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage","displayName":"Disable the Support tab under the File menu in Outlook (User)","description":"This policy setting determines whether the Support tab will be displayed under the File menu in Outlook.\r\n\r\nIf you enable this policy setting, then the Support tab will not be displayed under the File menu in Outlook.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage_1","displayName":"Enabled","description":null,"helpText":null}]},"ba27b01aeb26c2de":{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_l_equivalentcomaddin2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},"baa32f5c4d67e561":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":null},"ba31f757695490be":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},"ba957ac9f7b4de61":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":null},"ba6fea8ca7e8cb0e":{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode","displayName":"Disable Stealth Mode","description":"This value is an on/off switch. When this option is false, the server operates in stealth mode. The firewall rules used to enforce stealth mode are implementation-specific. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode_false","displayName":"False","description":"Use Stealth Mode","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode_true","displayName":"True","description":"Disable Stealth Mode","helpText":null}]}} \ No newline at end of file +{"ba1800ed684874e2":{"id":"com.android.devicerestrictionpolicy.bluetoothblocked","displayName":"Block Bluetooth","description":"If 'True', disables Bluetooth entirely on the device. If 'False', Intune doesn't change or update this setting. By default, the OS might allow Bluetooth to be used. Available for fully managed, dedicated, and corporate-owned work profile devices. In comparison, Bluetooth configuration disables the user from making changes to the Bluetooth toggle. As a result, it might be either 'On' or 'Off' depending on the state of Bluetooth prior to applying a policy with Bluetooth configuration enabled.","helpText":null,"infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.bluetoothblocked_true","displayName":"True","description":"True","helpText":null},{"id":"com.android.devicerestrictionpolicy.bluetoothblocked_false","displayName":"False","description":"false","helpText":null}]},"ba203356254b5a62":{"id":"com.apple.app.lock_app_options_enablespeakselection","displayName":"Enable Speak Selection","description":"If true, enables Speak Selection.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_options_enablespeakselection_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_options_enablespeakselection_true","displayName":"True","description":null,"helpText":null}]},"ba62402b783327cf":{"id":"com.apple.applicationaccess_ratingappsnz","displayName":"Rating Apps - New Zealand","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsnz_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsnz_22","displayName":"All","description":null,"helpText":null}]},"bae33027ca684c61":{"id":"com.apple.dock_show-recents","displayName":"Show Recents","description":"If true, enables \"Show recent items.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_show-recents_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_show-recents_true","displayName":"True","description":null,"helpText":null}]},"ba4343ed0898d62c":{"id":"com.apple.domains_crosssitetrackingpreventionrelaxeddomains","displayName":"Cross Site Tracking Prevention Relaxed Domains","description":"Specify an array of up to ten domains \r\nwhen cross-site tracking is required for functionality.","helpText":null,"infoUrls":[],"categoryId":"224dc683-c0e0-4783-8ba8-8f02c76d161d","categoryName":"Domains","options":null},"baf792f5df4e5f75":{"id":"com.apple.extensiblesso_ignored_kerberos_$typepicker","displayName":"IGNORED","description":null,"helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":{"id":"com.apple.extensiblesso_ignored_kerberos_0","displayName":"Array","description":null,"helpText":null}},"ba62c638ee838256":{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress","displayName":"Allow S/MIME certificates without a matching email address","description":"Allow users to decrypt and encrypt S/MIME messages when the S/MIME certificate does not match the email address.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-smime-certificates-without-a-matching-email-address"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowcertswithoutmatchingemailaddress_true","displayName":"True","description":null,"helpText":null}]},"ba210359023742d9":{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled","displayName":"Disable Bing chat entry-points on Microsoft Edge Enterprise new tab page","description":"By default, the Microsoft Edge new tab page includes three Bing Chat entry points: one inside the search box, one in the Bing autosuggest dropdown when users click or begin typing in the box, and one as a suggested prompt below the box.\n\nIf you enable or don't configure this policy, these Bing Chat entry points continue to appear on the new tab page.\n\nIf you disable this policy, all Bing Chat entry points are removed from the new tab page.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagebingchatenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_newtabpagebingchatenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"baddf3cff77bfee5":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogo_default_logo_hash","displayName":"Hash","description":"The SHA-256 hash of the image.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"ba85355a980f93db":{"id":"com.apple.managedclient.preferences_newtabpagecompanylogobackplatecolor","displayName":"Set the company logo backplate color on the new tab page.","description":"By default, the new tab page sets the company logo backplate color to the neutralStrokeActive (#cecece) constant.\n\nYou can configure this policy with a color hex code to change the company logo backplate color on the new tab page.\n\nIf this policy is not configured, the default neutralStrokeActive (#cecece) color will be used as the backplate color.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#newtabpagecompanylogobackplatecolor"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"baa8d4e0882538c4":{"id":"com.apple.systemconfiguration_proxies","displayName":"Proxies","description":"The dictionary containing all the proxies for this device.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":null},"ba5cc988cf5ccbc3":{"id":"com.apple.tcc.configuration-profile-policy_services_bluetoothalways_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"ba8c76ee75fe0645":{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled","displayName":"Super Drag Drop Enabled","description":"This policy lets you configure the Super Drag Drop feature in Microsoft Edge.\n\nWith this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine.\n\nIf you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.\n\nIf you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.superdragdropenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"ba9ae0583f874e07":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata","displayName":"Policy rule","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},"ba1b8b4aef334808":{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly","displayName":"Allow delegating fresh credentials with NTLM-only server authentication","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via NTLM.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's fresh credentials can be delegated (fresh credentials are those that you are prompted for when executing the application).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of fresh credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of fresh credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating fresh credentials with NTLM-only server authentication\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowfreshcredentialswhenntlmonly"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowfreshcredentialswhenntlmonly_1","displayName":"Enabled","description":null,"helpText":null}]},"ba74dc1cc490e5c9":{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification","displayName":"Disable delete notifications on all volumes","description":"Delete notification is a feature that notifies the underlying storage device of clusters that are freed due to a file delete operation.\r\n\r\nA value of 0, the default, will enable delete notifications for all volumes. \r\nA value of 1 will disable delete notifications for all volumes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-filesys#admx-filesys-disabledeletenotification"],"categoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","categoryName":"Filesystem","options":[{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_filesys_disabledeletenotification_1","displayName":"Enabled","description":null,"helpText":null}]},"bacc4029b5d384ee":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_logonscriptdelay_asyncscriptdelay1","displayName":"minute:","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"baf1240af71fbf03":{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp","displayName":"Turn off Active Help","description":"This policy setting specifies whether active content links in trusted assistance content are rendered. By default, the Help viewer renders trusted assistance content with active elements such as ShellExecute links and Guided Help links.\r\n\r\nIf you enable this policy setting, active content links are not rendered. The text is displayed, but there are no clickable links for these elements.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior applies (Help viewer renders trusted assistance content with active elements).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-helpandsupport#admx-helpandsupport-activehelp"],"categoryId":"5be35eeb-62e9-4317-8804-018a9dd31149","categoryName":"Online Assistance","options":[{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_helpandsupport_activehelp_1","displayName":"Enabled","description":null,"helpText":null}]},"bab477d735237fb4":{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy","displayName":"Always wait for the network at computer startup and logon","description":"This policy setting determines whether Group Policy processing is synchronous (that is, whether computers wait for the network to be fully initialized during computer startup and user logon). By default, on client computers, Group Policy processing is not synchronous; client computers typically do not wait for the network to be fully initialized at startup and logon. Existing users are logged on using cached credentials, which results in shorter logon times. Group Policy is applied in the background after the network becomes available. \r\n\r\nNote that because this is a background refresh, extensions such as Software Installation and Folder Redirection take two logons to apply changes. To be able to operate safely, these extensions require that no users be logged on. Therefore, they must be processed in the foreground before users are actively using the computer. In addition, changes that are made to the user object, such as adding a roaming profile path, home directory, or user object logon script, may take up to two logons to be detected.\r\n\r\nIf a user with a roaming profile, home directory, or user object logon script logs on to a computer, computers always wait for the network to be initialized before logging the user on. If a user has never logged on to this computer before, computers always wait for the network to be initialized.\r\n\r\nIf you enable this policy setting, computers wait for the network to be fully initialized before users are logged on. Group Policy is applied in the foreground, synchronously. \r\n\r\nOn servers running Windows Server 2008 or later, this policy setting is ignored during Group Policy processing at computer startup and Group Policy processing will be synchronous (these servers wait for the network to be initialized during computer startup). \r\n\r\nIf the server is configured as follows, this policy setting takes effect during Group Policy processing at user logon:\r\n• The server is configured as a terminal server (that is, the Terminal Server role service is installed and configured on the server); and\r\n• The “Allow asynchronous user Group Policy processing when logging on through Terminal Services” policy setting is enabled. This policy setting is located under Computer Configuration\\Policies\\Administrative templates\\System\\Group Policy\\.\r\n\r\nIf this configuration is not implemented on the server, this policy setting is ignored. In this case, Group Policy processing at user logon is synchronous (these servers wait for the network to be initialized during user logon).\r\n\r\nIf you disable or do not configure this policy setting and users log on to a client computer or a server running Windows Server 2008 or later and that is configured as described earlier, the computer typically does not wait for the network to be fully initialized. In this case, users are logged on with cached credentials. Group Policy is applied asynchronously in the background.\r\n\r\nNotes: \r\n-If you want to guarantee the application of Folder Redirection, Software Installation, or roaming user profile settings in just one logon, enable this policy setting to ensure that Windows waits for the network to be available before applying policy. \r\n-If Folder Redirection policy will apply during the next logon, security policies will be applied asynchronously during the next update cycle, if network connectivity is available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-logon#admx-logon-syncforegroundpolicy"],"categoryId":"439f715e-5511-44fd-9a0f-644ba7cc6baf","categoryName":"Logon","options":[{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_logon_syncforegroundpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"baf6e64a5975a1c1":{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2","displayName":"Critical battery notification action","description":"This policy setting specifies the action that Windows takes when battery capacity reaches the critical battery notification level.\r\n\r\nIf you enable this policy setting, select one of the following actions:\r\n-Take no action\r\n-Sleep\r\n-Hibernate\r\n-Shut down\r\n\r\nIf you disable or do not configure this policy setting, users control this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-power#admx-power-dcbatterydischargeaction0-2"],"categoryId":"7226f8a2-c542-471a-8d9e-e0df527325d3","categoryName":"Notification Settings","options":[{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_power_dcbatterydischargeaction0_2_1","displayName":"Enabled","description":null,"helpText":null}]},"bad4a5aa0af60869":{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2","displayName":"For tablet pen input, don’t show the Input Panel icon","description":"Prevents the Tablet PC Input Panel icon from appearing next to any text entry area in applications where this behavior is available. This policy applies only when using a tablet pen as an input device.\r\n\r\nTablet PC Input Panel is a Tablet PC accessory that enables you to use handwriting or an on-screen keyboard to enter text, symbols, numbers, or keyboard shortcuts.\r\n\r\nIf you enable this policy, Input Panel will never appear next to text entry areas when using a tablet pen as an input device. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you disable this policy, Input Panel will appear next to any text entry area in applications where this behavior is available. Users will not be able to configure this setting in the Input Panel Options dialog box.\r\n\r\nIf you do not configure this policy, Input Panel will appear next to text entry areas in applications where this behavior is available. Users will be able to configure this setting on the Opening tab in Input Panel Options.\r\n\r\nCaution: If you enable both the “Prevent Input Panel from appearing next to text entry areas” policy and the “Prevent Input Panel tab from appearing” policy, and disable the “Show Input Panel taskbar icon” policy, the user will then have no way to access Input Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletpcinputpanel#admx-tabletpcinputpanel-iptiptarget-2"],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_iptiptarget_2_1","displayName":"Enabled","description":null,"helpText":null}]},"ba735cadebe13666":{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval","displayName":"Set 6to4 Relay Name Resolution Interval","description":"This policy setting allows you to specify the interval at which the relay name is resolved. The 6to4 relay name resolution interval setting has no effect if 6to4 connectivity is not available on the host.\r\n\r\nIf you enable this policy setting, you can specify the value for the duration at which the relay name is resolved periodically.\r\n\r\nIf you disable or do not configure this policy setting, the local host setting is used.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-6to4-router-name-resolution-interval"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_6to4_router_name_resolution_interval_1","displayName":"Enabled","description":null,"helpText":null}]},"ba571c74cc7de9b2":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics","displayName":"Optimize visual experience when using RemoteFX","description":"This policy setting allows you to specify the visual experience that remote users will have in Remote Desktop Connection (RDC) connections that use RemoteFX. You can use this policy to balance the network bandwidth usage with the type of graphics experience that is delivered.\r\n\r\nDepending on the requirements of your users, you can reduce network bandwidth usage by reducing the screen capture rate. You can also reduce network bandwidth usage by reducing the image quality (increasing the amount of image compression that is performed).\r\n\r\nIf you have a higher than average bandwidth network, you can maximize the utilization of bandwidth by selecting the highest setting for screen capture rate and the highest setting for image quality.\r\n\r\nBy default, Remote Desktop Connection sessions that use RemoteFX are optimized for a balanced experience over LAN conditions. If you disable or do not configure this policy setting, Remote Desktop Connection sessions that use RemoteFX will be the same as if the medium screen capture rate and the medium image compression settings were selected (the default behavior). \r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-remotedesktopvirtualgraphics"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_remotedesktopvirtualgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},"bac840b559233ca3":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_chaindisable","displayName":"ChainDisable","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"baf0a0af988624e9":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_maxpollinterval","displayName":"MaxPollInterval","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"bab974adc2bb8ac9":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users cannot preview items or get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-restricted"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_restricted_1","displayName":"Enabled","description":null,"helpText":null}]},"baf39e9f13a6cc51":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo","displayName":"Microsoft To Do (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_todo_1","displayName":"True","description":null,"helpText":null}]},"ba1fbac5b6339356":{"id":"device_vendor_msft_policy_config_bits_jobinactivitytimeout","displayName":"Job Inactivity Timeout","description":"This policy setting specifies the number of days a pending BITS job can remain inactive before the job is considered abandoned. By default BITS will wait 90 days before considering an inactive job abandoned. After a job is determined to be abandoned, the job is deleted from BITS and any downloaded files for the job are deleted from the disk. NoteAny property changes to the job or any successful download action will reset this timeout. Value type is integer. Default is 90 days. Supported values range: 0 - 999Consider increasing the timeout value if computers tend to stay offline for a long period of time and still have pending jobs. Consider decreasing this value if you are concerned about orphaned jobs occupying disk space. If you disable or do not configure this policy setting, the default value of 90 (days) will be used for the inactive job timeout.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#jobinactivitytimeout"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":null},"baa8c734077a11a4":{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising","displayName":"Allow Advertising","description":"Specifies whether the device can send out Bluetooth advertisements. If this is not set or it is deleted, the default value of 1 (Allow) is used. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#allowadvertising"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":[{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising_0","displayName":"Block","description":"Not allowed. When set to 0, the device will not send out advertisements. To verify, use any Bluetooth LE app and enable it to do advertising. Then, verify that the advertisement is not received by the peripheral.","helpText":null},{"id":"device_vendor_msft_policy_config_bluetooth_allowadvertising_1","displayName":"Allow","description":"Allowed. When set to 1, the device will send out advertisements. To verify, use any Bluetooth LE app and enable it to do advertising. Then, verify that the advertisement is received by the peripheral.","helpText":null}]},"ba7c44e6ef1b601a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled","displayName":"Enable the network service sandbox","description":"This policy controls whether or not the network service process runs sandboxed.\r\nIf this policy is enabled, the network service process will run sandboxed.\r\nIf this policy is disabled, the network service process will run unsandboxed. This leaves users open to additional security risks related to running the network service unsandboxed.\r\nIf this policy is not set, the default configuration for the network sandbox will be used. This may vary depending on Google Chrome release, currently running field trials, and platform.\r\nThis policy is intended to give enterprises flexibility to disable the network sandbox if they use third party software that interferes with the network service sandbox.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkservicesandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ba1fc1c9b9869ff3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist","displayName":"Revert to legacy SameSite behavior for cookies on these sites","description":"Cookies set for domains matching these patterns will revert to legacy SameSite behavior. Reverting to legacy behavior causes cookies that don't specify a SameSite attribute to be treated as if they were \"SameSite=None\", removes the requirement for \"SameSite=None\" cookies to carry the \"Secure\" attribute, and skips the scheme comparison when evaluating if two sites are same-site. See https://www.chromium.org/administrators/policy-list-3/cookie-legacy-samesite-policies for full description.\r\n\r\nFor cookies on domains not covered by the patterns specified here, or for all cookies if this policy is not set, the global default value will be the user's personal configuration.\r\n\r\nFor detailed information on valid patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\n\r\nNote that patterns you list here are treated as domains, not URLs, so you should not specify a scheme or port.\r\n\r\nExample value:\r\n\r\nwww.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_legacysamesitecookiebehaviorenabledfordomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},"ba7f5117717deeb7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_webusbblockedforurls_webusbblockedforurlsdesc","displayName":"Block WebUSB on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"ba289bc043b45888":{"id":"device_vendor_msft_policy_config_handwriting_paneldefaultmodedocked","displayName":"Panel Default Mode Docked","description":"Specifies whether the handwriting panel comes up floating near the text box or attached to the bottom of the screen","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Handwriting#paneldefaultmodedocked"],"categoryId":"4e8db19c-cb8e-4361-8849-1d435d50bb66","categoryName":"Handwriting","options":[{"id":"device_vendor_msft_policy_config_handwriting_paneldefaultmodedocked_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_handwriting_paneldefaultmodedocked_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"baf33cbaef24e25b":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended","displayName":"Allow importing of browsing history","description":"Allows users to import their browsing history from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Browsing history** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, browsing history data isn't imported at first run, and users can’t import this data manually.\r\n\r\nIf you don’t configure this policy, browsing history data is imported at first run, and users can choose whether to import it manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports browsing history on first run, but users can select or clear the **history** option during manual import.\r\n\r\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS), Mozilla Firefox (on Windows 7, 8, and 10 and on macOS), and Apple Safari (macOS) browsers.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_importhistory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"ba3d4e61daa10fc6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended","displayName":"Register protocol handlers","description":"Register a list of protocol handlers. Set the protocol property to the scheme (like 'mailto') and the url property to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which will be replaced by the handled URL.\r\n\r\nYou can recommend a specific value for this policy, but you can't require that your users use it.\r\n\r\nThe protocol handlers registered by policy are merged with any handlers registered by the user, and both are available for use. The user can override the protocol handlers installed by policy by installing a new default handler, but they can't remove a protocol handler registered by policy.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://mail.contoso.com/mail/?extsrc=mailto&url=%s\", \r\n \"default\": true, \r\n \"protocol\": \"mailto\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"ba565c838991547a":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls","displayName":"Grant access to specific sites to connect to specific USB devices","description":"Allows you to set a list of urls that specify which sites will automatically be granted permission to access a USB device with the given vendor and product IDs. Each item in the list must contain both devices and urls in order for the policy to be valid. Each item in devices can contain a vendor ID and product ID field. Any ID that is omitted is treated as a wildcard with one exception, and that exception is that a product ID cannot be specified without a vendor ID also being specified. Otherwise, the policy will not be valid and will be ignored.\r\n\r\nThe USB permission model uses the URL of the requesting site (\"requesting URL\") and the URL of the top-level frame site (\"embedding URL\") to grant permission to the requesting URL to access the USB device. The requesting URL may be different than the embedding URL when the requesting site is loaded in an iframe. Therefore, the \"urls\" field can contain up to two URL strings delimited by a comma to specify the requesting and embedding URL respectively. If only one URL is specified, then access to the corresponding USB devices will be granted when the requesting site's URL matches this URL regardless of embedding status. The URLs in \"urls\" must be valid URLs, otherwise the policy will be ignored.\r\n\r\nIf this policy is left not set, the global default value will be used for all sites either from the 'DefaultWebUsbGuardSetting' (Control use of the WebUSB API) policy if it is set, or the user's personal configuration otherwise.\r\n\r\nURL patterns in this policy should not clash with the ones configured via 'WebUsbBlockedForUrls' (Block WebUSB on specific sites). If there is a clash, this policy will take precedence over 'WebUsbBlockedForUrls' and 'WebUsbAskForUrls' (Allow WebUSB on specific sites).\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://contoso.com\", \r\n \"https://fabrikam.com\"\r\n ], \r\n \"devices\": [\r\n {\r\n \"vendor_id\": 1234, \r\n \"product_id\": 5678\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_webusballowdevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"ba977e1a53355ae2":{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when:\r\n- The 'Passwords' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy ClearBrowsingDataOnExit is enabled\r\n\r\nIf you enable this policy, passwords won't be cleared when the browser closes.\r\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~passwordmanager_passworddeleteonbrowsercloseenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ba9bc2d4979c2fad":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_allowtokenbindingforurlsdesc","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"ba471280b192bbb3":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_winprojexe104","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_winprojexe104_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_winprojexe104_1","displayName":"True","description":null,"helpText":null}]},"bac646968a8fc393":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory","displayName":"Let Apps Access Call History","description":"This policy setting specifies whether Windows apps can access call history.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscallhistory"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"baceb321b6172664":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture","displayName":"Disables send-a-smile's screenshot capability","description":"This policy disables the screenshot capability in the send-a-smile feature.","helpText":"","infoUrls":[],"categoryId":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","categoryName":"Feedback Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~feedbacksettings_disablescreenshotcapture_1","displayName":"Enabled","description":null,"helpText":null}]},"ba641affd3bbc99f":{"id":"plugin_organization","displayName":"Organization","description":"The organization string to pass to the third-party plug-in.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"bacd7219fa058a77":{"id":"settings_item_accessibilitysettings_textsize","displayName":"Text Size","description":"The accessibility text size apps that support dynamic text use. 0 is the smallest value, and 11 is the largest available.","helpText":null,"infoUrls":[],"categoryId":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","categoryName":"Accessibility Settings","options":[{"id":"settings_item_accessibilitysettings_textsize_0","displayName":"0","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_1","displayName":"1","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_2","displayName":"2","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_3","displayName":"3","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_4","displayName":"4","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_5","displayName":"5","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_6","displayName":"6","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_7","displayName":"7","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_8","displayName":"8","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_9","displayName":"9","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_10","displayName":"10","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_textsize_11","displayName":"11","description":null,"helpText":null}]},"badf14b08b0b8c56":{"id":"softwareupdate_automaticactions_installosupdates","displayName":"Install OS Updates","description":"Specifies whether automatic install of available OS updates can be controlled by the user:\n* \"Allowed\" - the user can enable or disable automatic installs.\n* \"AlwaysOn\". - automatic installs are always enabled. This option requires automatic downloads to be turned on.\n* \"AlwaysOff\" - automatic installs are always disabled.","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":[{"id":"softwareupdate_automaticactions_installosupdates_0","displayName":"Allowed","description":null,"helpText":null},{"id":"softwareupdate_automaticactions_installosupdates_1","displayName":"Always On","description":null,"helpText":null},{"id":"softwareupdate_automaticactions_installosupdates_2","displayName":"Always Off","description":null,"helpText":null}]},"ba36ebe2fe193a9a":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iis","displayName":"Internet Information Services (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-iis"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_iis_1","displayName":"Enabled","description":null,"helpText":null}]},"ba999e7863c309ae":{"id":"user_vendor_msft_policy_config_admx_msi_disablemedia","displayName":"Prevent removable media source for any installation (User)","description":"This policy setting prevents users from installing any programs from removable media.\r\n\r\nIf you enable this policy setting, if a user tries to install a program from removable media, such as CD-ROMs, floppy disks, and DVDs, a message appears stating that the feature cannot be found.\r\n\r\nThis policy setting applies even when the installation is running in the user's security context.\r\n\r\nIf you disable or do not configure this policy setting, users can install from removable media when the installation is running in their own security context, but only system administrators can use removable media when an installation is running with elevated system privileges, such as installations offered on the desktop or in Add or Remove Programs.\r\n\r\nAlso, see the \"Enable user to use media source while elevated\" and \"Hide the 'Add a program from CD-ROM or floppy disk' option\" policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disablemedia"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"user_vendor_msft_policy_config_admx_msi_disablemedia_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_msi_disablemedia_1","displayName":"Enabled","description":null,"helpText":null}]},"ba40e0cc3e81ae19":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup","displayName":"InfoPath 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft InfoPath 2013.\r\nMicrosoft InfoPath 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft InfoPath 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft InfoPath 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft InfoPath 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013infopathbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"ba4d098ec94a101a":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup","displayName":"Visio 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Visio 2013.\r\nMicrosoft Visio 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Visio 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Visio 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Visio 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013visiobackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013visiobackup_1","displayName":"Enabled","description":null,"helpText":null}]},"ba75f125fcbad1a3":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-localmachinelockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_localmachinelockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"babed335d3dca491":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled","displayName":"Allow ServiceWorker to control srcdoc iframes (User)","description":"https://github.com/w3c/ServiceWorker/issues/765 asks srcdoc iframe with\r\nthe \"allow-same-origin\" sandbox attribute to be under ServiceWorker control.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome makes srcdoc iframes\r\nwith \"allow-same-origin\" sandbox attributes to be under ServiceWorker control.\r\n\r\nSetting the policy to Disabled leaves the srcdoc iframe not controlled by\r\nServiceWorker.\r\n\r\nThis policy is intended to be temporary and will be removed in 2026.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkertocontrolsrcdociframeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ba932e52c82d1e1e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill","displayName":"Automatically Flash Fill (User)","description":"This policy setting controls the \"Automatically Flash Fill\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will enable automatic Flash Fill. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will turn off the Automatic Flash Fill feature.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_automaticallyflashfill_1","displayName":"Enabled","description":null,"helpText":null}]},"baba7d773ce6982c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_descriptioncolon59","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"badf9e49689871f4":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_descriptioncolon71","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"baecc2a1d404d6d8":{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths","displayName":"Intranet Sites: Include all network paths (UNCs) (User)","description":"This policy setting controls whether URLs representing UNCs are mapped into the local Intranet security zone.\n\nIf you enable this policy setting, all network paths are mapped into the Intranet Zone.\n\nIf you disable this policy setting, network paths are not necessarily mapped into the Intranet Zone (other rules might map one there).\n\nIf you do not configure this policy setting, users choose whether network paths are mapped into the Intranet Zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-includeallnetworkpaths"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_includeallnetworkpaths_1","displayName":"Enabled","description":null,"helpText":null}]},"bad9c288b4e1d28e":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},"baf4aad25201f182":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301","displayName":"Use SmartScreen Filter (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowsmartscreenie_iz_partname2301_3","displayName":"Disable","description":null,"helpText":null}]},"ba05b374376d6003":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled","displayName":"Enable Copilot address bar suggestions (User)","description":"This policy controls whether Copilot chat suggestions appear in the address bar of Microsoft Edge.\n\nIf you enable this policy or don't configure it, Copilot chat suggestions appear in the address bar.\n\nIf you disable this policy, Copilot chat suggestions don't appear in the address bar.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_copilotaddressbarsuggestionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ba01c00ed204ae11":{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended","displayName":"Get user confirmation before closing a browser window with multiple tabs (User)","description":"This policy lets you configure whether users see a confirmation dialog before closing a browser window with multiple tabs. This dialog asks users to confirm that the browser window can be closed.\r\n\r\nIf you enable this policy, users will be presented with a confirmation dialog when closing a browser window with multiple tabs.\r\n\r\nIf you disable or don't configure this policy, a browser window with multiple tabs will close immediately without user confirmation.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_recommended_askbeforecloseenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"baf264e219a85087":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load blockable mixed content","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow blockable mixed content","description":null,"helpText":null}]},"ba90f7318a3d8daf":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean","displayName":"Korean (User)","description":"Enables the editing language Korean","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_korean_1","displayName":"Enabled","description":null,"helpText":null}]},"ba9dcdf709736863":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc14_l_pathcolon290","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"bab190c8b2bf514f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps","displayName":"Allow Unsecure web add-ins and Catalogs (User)","description":"This policy setting allows users to run unsecure web add-in, which are add-ins that have web page or catalog locations that are not SSL-secured (https://), and are not in users' Internet zones.\r\n\r\nIf you enable this policy setting, users can run unsecure apps. To enable specific unsecure web add-ins, you must also configure the Trusted Web add-in Catalog policy settings to trust the catalogs that contains those Add-ins.\r\n\r\nIf you disable or do not configure this policy setting, unsecure web add-ins are not allowed.","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_allowunsecureapps_1","displayName":"Enabled","description":null,"helpText":null}]},"ba96a6dcc408f3e8":{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey","displayName":"Allow users to receive and respond to in-product surveys from Microsoft (User)","description":"This policy setting allows you to control whether your users can receive and respond to in-product surveys in Microsoft 365 products. Microsoft will use this feedback to improve the product experience for users. The ability to receive and respond to in-product surveys is enabled by default.\r\n\r\nIf you enable this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nIf you disable this policy setting, Microsoft will not survey your users while they are using Microsoft 365 products.\r\n\r\nIf you don't configure this policy setting, your users will be able to receive and respond to in-product surveys about their experience using Microsoft 365 products.\r\n\r\nComing soon, you will be able to view and manage feedback from your org in the Microsoft 365 admin center.\r\n\r\nNote: This data will be considered \"Feedback\" under your Microsoft 365 agreement, including information that would otherwise be considered \"Customer Data\" or \"Personal Data\".\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise, and to subscription versions of Project and Visio.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2142253","helpText":"","infoUrls":[],"categoryId":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7.updates~policy~l_microsoftofficesystem~l_privacy~l_trustcenter_l_sendsurvey_1","displayName":"Enabled","description":null,"helpText":null}]},"ba7eff8d4a2afbe2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventmapiservicesfrombeingadded_l_preventmapiservicesfrombeingaddedpart","displayName":"Enter MAPI services to disable (semi-colon delimited) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},"ba4a8546ee3810a5":{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage","displayName":"Disable the Support tab under the File menu in Outlook (User)","description":"This policy setting determines whether the Support tab will be displayed under the File menu in Outlook.\r\n\r\nIf you enable this policy setting, then the Support tab will not be displayed under the File menu in Outlook.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablesupportbackstage_1","displayName":"Enabled","description":null,"helpText":null}]},"ba27b01aeb26c2de":{"id":"user_vendor_msft_policy_config_outlk16v9~policy~l_microsoftofficeoutlook~l_miscellaneous_l_equivalentcomaddin_l_equivalentcomaddin2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":null},"baa32f5c4d67e561":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":null},"ba31f757695490be":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet","displayName":"Block macros from running in Office files from the Internet (User)","description":"\r\n This policy setting allows you to block macros from running in Office files that come from the Internet.\r\n\r\n If you enable this policy setting, macros are blocked from running, even if “Enable all macros” is selected in the Macro Settings section of the Trust Center. Also, instead of having the choice to “Enable Content,” users will receive a notification that macros are blocked from running. If the Office file is saved to a trusted location or was previously trusted by the user, macros will be allowed to run.\r\n\r\n If you disable or don’t configure this policy setting, the settings configured in the Macro Settings section of the Trust Center determine whether macros run in Office files that come from the Internet.\r\n ","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_blockmacroexecutionfrominternet_1","displayName":"Enabled","description":null,"helpText":null}]},"ba957ac9f7b4de61":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_setmaximumnumberoftrustrecordstopreserve_l_setmaximumnumberoftrustrecordstopreservespinid","displayName":"Maximum to preserve: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":null},"ba6fea8ca7e8cb0e":{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode","displayName":"Disable Stealth Mode","description":"This value is an on/off switch. When this option is false, the server operates in stealth mode. The firewall rules used to enforce stealth mode are implementation-specific. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode_false","displayName":"False","description":"Use Stealth Mode","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disablestealthmode_true","displayName":"True","description":"Disable Stealth Mode","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/bb.json b/public/intune-definitions/bb.json index 08e596356b30..1870bb6a4457 100644 --- a/public/intune-definitions/bb.json +++ b/public/intune-definitions/bb.json @@ -1 +1 @@ -{"bbed53d6befdd102":{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice","displayName":"Allow Proximity Setup To New Device","description":"If false, disables the prompt to set up new devices that are nearby. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice_true","displayName":"True","description":null,"helpText":null}]},"bb7644f4db51009b":{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing","displayName":"Management Allows Known Folder Syncing","description":"If `false`, the device prevents the File Provider extension from using desktop and documents synchronization in any app. This doesn't impact the ability for apps to utilize the File Provider extension for file and folder syncing with remote storage.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing_true","displayName":"Allowed","description":null,"helpText":null}]},"bb4115b4f2d5b238":{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled","displayName":"JavaScript setTimeout will not be clamped until a higher nesting threshold is set (deprecated)","description":"This policy is deprecated because it is a temporary policy for web standards compliance. It won't work in Microsoft Edge as soon as version 107.\nIf you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will not be clamped. This improves short horizon performance, but websites abusing the API will still eventually have their setTimeout usages clamped.\nIf you disable or don't configure policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will be clamped.\n\nThis is a web standards compliancy feature that may change task ordering on a web page, leading to unexpected behavior on sites that are dependent on a certain ordering.\nIt also may affect sites with a lot of usage of a timeout of 0ms for setTimeout. For example, increasing CPU load.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#unthrottlednestedtimeoutenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"bbf4516bfbb16180":{"id":"com.apple.proxy.http.global_proxypacfallbackallowed","displayName":"Proxy PAC Fallback Allowed","description":"If true, allows connecting directly to the destination if the proxy autoconfiguration (PAC) file is unreachable. ","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxypacfallbackallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxypacfallbackallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"bb59e64ad018663d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended","displayName":"Allow importing of autofill form data (users can override)","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import autofill data is automatically selected.\n\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports autofill data on first run, but users can select or clear autofill data option during manual import.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"bbd2f22add47f7d3":{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer","displayName":"Configure Corporate Windows Error Reporting","description":"This policy setting specifies a corporate server to which Windows Error Reporting sends reports (if you do not want to send error reports to Microsoft).\r\n\r\nIf you enable this policy setting, you can specify the name or IP address of an error report destination server on your organization’s network. You can also select Connect using SSL to transmit error reports over a Secure Sockets Layer (SSL) connection, and specify a port number on the destination server for transmission.\r\n\r\nIf you disable or do not configure this policy setting, Windows Error Reporting sends error reports to Microsoft.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-wercer"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_1","displayName":"Enabled","description":null,"helpText":null}]},"bb5152d0a590c061":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes","displayName":"Randomize scheduled task times","description":"This policy setting allows you to enable or disable randomization of the scheduled scan start time and the scheduled security intelligence update start time. This setting is used to distribute the resource impact of scanning. For example, it could be used in guest virtual machines sharing a host, to prevent multiple guest virtual machines from undertaking a disk-intensive operation at the same time.\r\n\r\n If you enable or do not configure this setting, scheduled tasks will begin at a random time within an interval of 4 hours after the specified start time.\r\n\r\n If you disable this setting, scheduled tasks will begin at the specified start time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-randomizescheduletasktimes"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes_1","displayName":"Enabled","description":null,"helpText":null}]},"bb9c5d334219a90d":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting","displayName":"Join Microsoft MAPS","description":null,"helpText":"","infoUrls":[],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_1","displayName":"Basic MAPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_2","displayName":"Advanced MAPS","description":null,"helpText":null}]},"bbcab1046cb15e33":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag_netlogon_debugflaglabel","displayName":"Level:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"bbc6a9aca306f16c":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay","displayName":"Specify expected dial-up delay on logon","description":"This policy setting specifies the additional time for the computer to wait for the domain controller’s (DC) response when logging on to the network.\r\n\r\nTo specify the expected dial-up delay at logon, click Enabled, and then enter the desired value in seconds (for example, the value \"60\" is 1 minute).\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-expecteddialupdelay"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"bb198e82092ef77b":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},"bb432146839f2e15":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports","displayName":"Sports","description":"This policy setting configures the synchronization of user settings for the Sports app.\r\nBy default, the user settings of Sports sync between computers. Use the policy setting to prevent the user settings of Sports from synchronizing between computers.\r\nIf you enable this policy setting, Sports user settings continue to sync.\r\nIf you disable this policy setting, Sports user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-sports"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3622ceb2bd43cc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled","displayName":"Enables the concept of policy atomic groups","description":"Setting the policy to Enabled means policies coming from an atomic group that don't share the source with the highest priority from that group get ignored.\r\n\r\nSetting the policy to Disabled means no policy is ignored because of its source. Policies are ignored only if there's a conflict, and the policy doesn't have the highest priority.\r\n\r\nIf this policy is set from a cloud source, it can't target a specific user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bb5cd58ddaf7571a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default popups setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},"bba7952c777e15f3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes_chromeframecontenttypesdesc","displayName":"Allow Google Chrome Frame to handle the listed content types (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"bbe7c65763e8e6cc":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings","displayName":"Enterprise search aggregator settings","description":"This policy allows administrators to set a designated enterprise search aggregator that will provide search recommendations and results within the omnibox (address bar) and the search box on the New Tab page.\r\n\r\nBy default, enterprise search suggestions will be blended and shown alongside regular Google Chrome recommendations. Users can explicitly scope their search to just the enterprise search aggregator by typing the keyword specified in the shortcut field with or without the @ prefix (e.g. @work) followed by Space or Tab in the omnibox. Scoped enterprise searches (triggered by a keyword) are currently only supported in the omnibox and not in the search box on the New Tab page.\r\n\r\nThe following fields are required: name, shortcut, search_url, suggest_url.\r\n\r\nThe name field corresponds to the search engine name shown to the user in the address bar.\r\n\r\nThe shortcut field corresponds to the keyword that the user enters to trigger the search. The shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must be unique.\r\n\r\nThe search_url field specifies the URL on which to search. Enter the web address for the search engine's results page, and use '{searchTerms}' in place of the query.\r\n\r\nThe suggest_url field specifies the URL that provides search suggestions. A POST request will be made and the user's query will be passed in the POST params under key 'query'.\r\n\r\nThe icon_url field specifies the URL to an image that will be used on the search suggestions. A default icon will be used when this field is not set. It's recommended to use a favicon (example https://www.google.com/favicon.ico). Supported image file formats: JPEG, PNG, and ICO.\r\n\r\nThe require_shortcut field specifies whether the address bar shortcut is required to see search recommendations. If required, suggestions will not be shown in the search box on the New Tab page, but will continue to be shown in the omnibox (address bar) in scoped search mode. If this field is not set, the address bar shortcut is not required.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=EnterpriseSearchAggregatorSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"name\": \"My Search Aggregator\",\r\n \"shortcut\": \"work\",\r\n \"search_url\": \"https://www.aggregator.com/search?q={searchTerms}\",\r\n \"suggest_url\": \"https://www.aggregator.com/suggest\",\r\n \"icon_url\": \"https://www.google.com/favicon.ico\",\r\n \"require_shortcut\": true\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"bbab2bcf8c6e18c9":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdmaxcachesizeinmbs_odfcccdmaxcachesizeinmbs","displayName":"CCD Max Cache Size in MBs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":null},"bbb94e3005e467fd":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesattachedvhdsddl_profilesattachedvhdsddl","displayName":"Attached VHD SDDL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"bbafbbdd38cbbe4f":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzonenavigatewindowsandframes"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3cfb33b0f1b486":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenablecrosssitescriptingfilter"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},"bbed5ecbf8ecdb49":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions","displayName":"Logon options","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Prompt for username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonelogonoptions"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"bbac19db30f9caad":{"id":"device_vendor_msft_policy_config_internetexplorer_securityzonesuseonlymachinesettings","displayName":"Security Zones: Use only machine settings ","description":"Applies security zone information to all users of the same computer. A security zone is a group of Web sites with the same security level.\n\nIf you enable this policy, changes that the user makes to a security zone will apply to all users of that computer.\n\nIf you disable this policy or do not configure it, users of the same computer can establish their own security zone settings.\n\nThis policy is intended to ensure that security zone settings apply uniformly to the same computer and do not vary from user to user.\n\nAlso, see the \"Security zones: Do not allow users to change policies\" policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-securityzonesuseonlymachinesettings"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_securityzonesuseonlymachinesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_securityzonesuseonlymachinesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3f177e6670f44c":{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseproxyserversareauthoritative","displayName":"Enterprise Proxy Servers Are Authoritative","description":"Boolean value that tells the client to accept the configured list of proxies and not try to detect other work proxies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterpriseproxyserversareauthoritative"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":[{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseproxyserversareauthoritative_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseproxyserversareauthoritative_0","displayName":"Disable","description":"Disable","helpText":null}]},"bb5d1b4b3286c143":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_exprwdexe80","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_exprwdexe80_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_exprwdexe80_1","displayName":"True","description":null,"helpText":null}]},"bb5ff2145cfc6fde":{"id":"device_vendor_msft_policy_config_taskscheduler_enablexboxgamesavetask","displayName":"Enable Xbox Game Save Task","description":"This setting determines whether the specific task is enabled (1) or disabled (0). Default: Enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TaskScheduler#enablexboxgamesavetask"],"categoryId":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","categoryName":"Task Scheduler","options":[{"id":"device_vendor_msft_policy_config_taskscheduler_enablexboxgamesavetask_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_taskscheduler_enablexboxgamesavetask_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"bbc214a6769d60aa":{"id":"device_vendor_msft_policy_config_updatev87~policy~cat_edgeupdate~cat_webview_pol_updatepolicymicrosoftedgewebview_part_updatepolicy","displayName":"Update Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"46eaa2b7-341b-4e39-be21-c3ea09dd5778","categoryName":"Microsoft Edge Web View2 Runtime","options":[{"id":"device_vendor_msft_policy_config_updatev87~policy~cat_edgeupdate~cat_webview_pol_updatepolicymicrosoftedgewebview_part_updatepolicy_1","displayName":"Always allow updates (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev87~policy~cat_edgeupdate~cat_webview_pol_updatepolicymicrosoftedgewebview_part_updatepolicy_0","displayName":"Updates disabled","description":null,"helpText":null}]},"bb0a87f9a8aec1a8":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~livesharesettings_livesharedomainname","displayName":"Allow only company domain accounts","description":"Prevents users from being able to share their session with any guests who are not part of their company or any other company that has been given access. Users must be logged in with their company email to access Live Share. If this policy is disabled, any user from any organization can access a shared Live Share session. Use ; to separate out multiple domains. For example, set the domain name as contoso.com or contoso.com;foo.com \r\nFor more information, see: https://aka.ms/vsls-policies ","helpText":"","infoUrls":[],"categoryId":"d9d5f333-9402-4459-8ef1-e29330cac8be","categoryName":"Live Share Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~livesharesettings_livesharedomainname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~livesharesettings_livesharedomainname_1","displayName":"Enabled","description":null,"helpText":null}]},"bb60f86d70db2267":{"id":"device_vendor_msft_policy_config_windowsai_disableremoteagentconnectors","displayName":"Disable Remote Agent Connectors (Windows Insiders only)","description":"Enable or Disable Remote Agent Connectors.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableremoteagentconnectors"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_disableremoteagentconnectors_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableremoteagentconnectors_1","displayName":"Force Enable.","description":"Force Enable.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableremoteagentconnectors_2","displayName":"Force Disable.","description":"Force Disable.","helpText":null}]},"bbc6eed66a8a3243":{"id":"setrecoverylock_enablerecoverylockpassword","displayName":"Enable Recovery Lock Password","description":"Set a recovery lock password that will be required to access RecoveryOS on Mac devices. Available for Apple silicon devices running macOS 11.5 and later.","helpText":null,"infoUrls":[],"categoryId":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","categoryName":"Recovery Lock Password","options":{"id":"setrecoverylock_enablerecoverylockpassword_true","displayName":"Enabled","description":null,"helpText":null}},"bbe22685fed29022":{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_sethighriskinclusion_am_instructhighriskinclusionlist","displayName":"Specify high risk extensions (include a leading period, e.g. .cmd;.exe;). (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":null},"bbda222cf56cbfb3":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access","displayName":"Microsoft Access 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft Access 2010.\r\nBy default, the user settings of Microsoft Access 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Access 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access_1","displayName":"Enabled","description":null,"helpText":null}]},"bb0da7e6ea6c34ac":{"id":"user_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_1","displayName":"Prohibit access of the Windows Connect Now wizards (User)","description":"This policy setting prohibits access to Windows Connect Now (WCN) wizards. \r\n\r\nIf you enable this policy setting, the wizards are turned off and users have no access to any of the wizard tasks. All the configuration related tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device\" are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can access the wizard tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device.\" The default for this policy setting allows users to access all WCN wizards.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsconnectnow#admx-windowsconnectnow-wcn-disablewcnui-1"],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"user_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_1_1","displayName":"Enabled","description":null,"helpText":null}]},"bb753eff93969503":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary","displayName":"Pin Libraries or Search Connectors to the \"Search again\" links and the Start menu (User)","description":"This policy setting allows up to five Libraries or Search Connectors to be pinned to the \"Search again\" links and the Start menu links. The \"Search again\" links at the bottom of the Search Results view allow the user to reconduct a search but in a different location. To add a Library or Search Connector link, specify the path of the .Library-ms or .searchConnector-ms file in the \"Location\" text box (for example, \"C:\\sampleLibrary.Library-ms\" for the Documents library, or \"C:\\sampleSearchConnector.searchConnector-ms\" for a Search Connector). The pinned link will only work if this path is valid and the location contains the specified .Library-ms or .searchConnector-ms file.\r\n\r\nYou can add up to five additional links to the \"Search again\" links at the bottom of results returned in File Explorer after a search is executed. These links will be shared between Internet search sites and Search Connectors/Libraries. Search Connector/Library links take precedence over Internet search links.\r\n\r\nThe first several links will also be pinned to the Start menu. A total of four links can be included on the Start menu. The \"See more results\" link will be pinned first by default, unless it is disabled via Group Policy. The \"Search the Internet\" link is pinned second, if it is pinned via Group Policy (though this link is disabled by default). If a custom Internet search link is pinned using the \"Custom Internet search provider\" Group Policy, this link will be pinned third on the Start menu. The remaining link(s) will be shared between pinned Search Connectors/Libraries and pinned Internet/intranet search links. Search Connector/Library links take precedence over Internet/intranet search links.\r\n\r\nIf you enable this policy setting, the specified Libraries or Search Connectors will appear in the \"Search again\" links and the Start menu links.\r\n\r\nIf you disable or do not configure this policy setting, no Libraries or Search Connectors will appear in the \"Search again\" links or the Start menu links.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-tryharderpinnedlibrary"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3e8f7d4f8f9f80":{"id":"user_vendor_msft_policy_config_browser_clearbrowsingdataonexit","displayName":"Clear Browsing Data On Exit (User)","description":"Specifies whether to always clear browsing history on exiting Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#clearbrowsingdataonexit"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_clearbrowsingdataonexit_0","displayName":"Disabled","description":"Prevented/not allowed. Users can configure the 'Clear browsing data' option in Settings.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_clearbrowsingdataonexit_1","displayName":"Enabled","description":"Allowed. Clear the browsing data upon exit automatically.","helpText":null}]},"bb6ddb81fb623c92":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (User)","description":"Allows you to set whether Google Chrome will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\r\n\r\nDisabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration.\r\n\r\nThis policy can be overridden for specific URL patterns using the JavaScriptJitAllowedForSites and JavaScriptJitBlockedForSites policies.\r\n\r\nIf this policy is left not set, JavaScript JIT is enabled.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"bb476473c4bad07a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3d0e269dbf3cb8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies","displayName":"Policy overrides for Debug builds of the remote access host (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},"bb4233e133561329":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins_webauthenticationremotedesktopallowedoriginsdesc","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"bbb1ef1321ccf2d0":{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight","displayName":"Allow Windows Spotlight (User)","description":"Specifies whether to turn off all Windows spotlight features at once. If you enable this policy setting, Windows spotlight on lock screen, Windows Tips, Microsoft consumer features and other related features will be turned off. You should enable this policy setting if your goal is to minimize network traffic from target devices. If you disable or do not configure this policy setting, Windows spotlight features are allowed and may be controlled individually using their corresponding policy settings. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlight"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"bbc3f3613810f008":{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate","displayName":"Intranet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowintranetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"bbfd05394a4a13d8":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"bb2416e9949c5899":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"bbb13062b0aa9c73":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfontdownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"bb2928824d905909":{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice","displayName":"Specify use of ActiveX Installer Service for installation of ActiveX controls (User)","description":"This policy setting allows you to specify how ActiveX controls are installed.\n\nIf you enable this policy setting, ActiveX controls are installed only if the ActiveX Installer Service is present and has been configured to allow the installation of ActiveX controls.\n\nIf you disable or do not configure this policy setting, ActiveX controls, including per-user controls, are installed through the standard installation process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-specifyuseofactivexinstallerservice"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice_1","displayName":"Enabled","description":null,"helpText":null}]},"bb8bc3e3d179a948":{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled","displayName":"TLS Encrypted ClientHello Enabled (User)","description":"Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy.\r\n\r\nIf ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status.\r\n\r\nIf you enable or do not configure this policy, Microsoft Edge will follow the default rollout process for ECH.\r\n\r\nIf this policy is disabled, Microsoft Edge will not enable ECH.\r\n\r\nBecause ECH is an evolving protocol, Microsoft Edge's implementation is subject to change.\r\n\r\nAs such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bb39c8b20703298a":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support (User)","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will accept web contents using the compression dictionary transport feature.\r\n\r\nIf you disable this policy, Microsoft Edge will turn off the compression dictionary transport feature.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bb06401f7dfa2ba7":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (User)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"bbf7a4cb3b8e15f7":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"bb4cba0f1f442343":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicesharednotescustomurl2","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"bbac4de1ca029d5f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland","displayName":"Sami, Skolt (Finland) (User)","description":"Enables the editing language \"Sami, Skolt (Finland)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland_1","displayName":"Enabled","description":null,"helpText":null}]},"bb4570af2146d4f1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel","displayName":"Set the Automation Security level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_3","displayName":"Disable macros by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_2","displayName":"Use application macro security level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_1","displayName":"Macros enabled (default)","description":null,"helpText":null}]},"bb5dbf3870df8d09":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter","displayName":"Specify filtering for certificate issuers (User)","description":"This policy setting allows you to configure Office to only allow certificates from a specific issuer when creating a digital signature.\r\n \r\nIf you enable this policy setting, Office only displays certificates that contain the string you set in the policy. This setting is case-sensitive.\r\n\r\nFor example, a setting of \"MyCA\" would match an issuer of \"MyCA 1\"and \"MyCA 2\", but not \"MYCA 3\".\r\n\r\nIf you disable or don’t configure this setting, then signing certificates from any issuer can be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_1","displayName":"Enabled","description":null,"helpText":null}]},"bb5b28cc073ad6f2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog","displayName":"Display alternative certificate providers (User)","description":"This policy setting allows you to configure whether Office displays a link to get a certificate from a Microsoft partner when there are no usable signing certificates.\r\n\r\nIf you enable this policy setting, the link won’t be displayed.\r\n\r\nIf you disable or don’t configure this policy setting, the link is displayed.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog_1","displayName":"Enabled","description":null,"helpText":null}]},"bbd77a254ff10d91":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":null},"bb1fe2a377955165":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout","displayName":"Set the time-out interval for Outlook people search (User)","description":"This policy setting controls the time-out interval of Outlook people search. Outlook returns as many people search results as possible before the time-out interval lapses. If the search results are incomplete, Outlook displays a message at the bottom of the results list.\r\n\r\nIf you enable this policy setting, you can specify the time-out interval in milliseconds.\r\n\r\nIf you disable or do not configure this policy setting, the time-out interval is 60,000 milliseconds (60 seconds).","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"bb69f64cbaffc3dd":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults","displayName":"Calendar item defaults (User)","description":"Sets the value in the option \"Default reminder\".","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_1","displayName":"Enabled","description":null,"helpText":null}]},"bb1367fe80e6b3ec":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions","displayName":"Do not allow users to change permissions on folders (User)","description":"This policy setting prevents users from changing their mail folder permissions. \r\n\r\nIf you enable this policy setting, Outlook users cannot change permissions on folders; the settings on the Permissions tab are disabled. Enabling this policy setting does not affect existing permissions, and users can still change permissions by sending a sharing message.\r\n\r\nIf you disable or do not configure this policy setting, Outlook users can change the permissions for folders under their control by using the Permissions tab of the Properties dialog box for the folder.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions_1","displayName":"Enabled","description":null,"helpText":null}]},"bb6f6478082f60ba":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting","displayName":"Print in background (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting_1","displayName":"Enabled","description":null,"helpText":null}]},"bb66589decdfa6d7":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd","displayName":"Disable Package For CD (User)","description":"Check to Disable Package for CD; Uncheck to Enable Package for CD. Shows or hides the File tab | Save & Send | Package Presentation for CD command. Package for CD allows the user to package and burn presentations onto CD for portable viewing even when PowerPoint is not installed.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd_1","displayName":"Enabled","description":null,"helpText":null}]},"bbf265da4f8c2164":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},"bbb2fd412dd857f2":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime_l_pjdefaultendtime2","displayName":"Default end time (Minutes after 12am * 10) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},"bb5353c5c3dc8b0c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3","displayName":"Rulers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3_1","displayName":"True","description":null,"helpText":null}]},"bb9084e2fd771f61":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect","displayName":"Enable AutoConnect (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"bb41409fba61d09b":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"bba454ce15712781":{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook","displayName":"Allow Advanced Typography features for Outlook (User)","description":"This policy setting sets the “Advanced Typography” options found under Outlook’s File tab | Outlook Options | Mail | Editor Options | Advanced | Advanced Typography.\r\n\r\nIf you enable or do not configure this policy setting, Advanced Typography features will be applied. This is the default behavior.\r\n\r\nIf you disable this policy setting, Advanced Typography features will not be applied.\r\n ","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"bbb248f7ae103099":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},"bb36f9dd32842ab0":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"bb5d15f46de014d1":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]},"bb836551ae698b1b":{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications","displayName":"Disable Inbound Notifications","description":"This value is an on/off switch. If this value is false, the firewall MAY display a notification to the user when an application is blocked from listening on a port. If this value is on, the firewall MUST NOT display such a notification. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications_false","displayName":"False","description":"Firewall May Display Notification","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications_true","displayName":"True","description":"Firewall Must Not Display Notification","helpText":null}]}} \ No newline at end of file +{"bbed53d6befdd102":{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice","displayName":"Allow Proximity Setup To New Device","description":"If false, disables the prompt to set up new devices that are nearby. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowproximitysetuptonewdevice_true","displayName":"True","description":null,"helpText":null}]},"bb7644f4db51009b":{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing","displayName":"Management Allows Known Folder Syncing","description":"If `false`, the device prevents the File Provider extension from using desktop and documents synchronization in any app. This doesn't impact the ability for apps to utilize the File Provider extension for file and folder syncing with remote storage.","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsknownfoldersyncing_true","displayName":"Allowed","description":null,"helpText":null}]},"bb4115b4f2d5b238":{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled","displayName":"JavaScript setTimeout will not be clamped until a higher nesting threshold is set (deprecated)","description":"This policy is deprecated because it is a temporary policy for web standards compliance. It won't work in Microsoft Edge as soon as version 107.\nIf you enable this policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will not be clamped. This improves short horizon performance, but websites abusing the API will still eventually have their setTimeout usages clamped.\nIf you disable or don't configure policy, the JavaScript setTimeout and setInterval, with an interval smaller than 4ms, will be clamped.\n\nThis is a web standards compliancy feature that may change task ordering on a web page, leading to unexpected behavior on sites that are dependent on a certain ordering.\nIt also may affect sites with a lot of usage of a timeout of 0ms for setTimeout. For example, increasing CPU load.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#unthrottlednestedtimeoutenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_unthrottlednestedtimeoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"bbf4516bfbb16180":{"id":"com.apple.proxy.http.global_proxypacfallbackallowed","displayName":"Proxy PAC Fallback Allowed","description":"If true, allows connecting directly to the destination if the proxy autoconfiguration (PAC) file is unreachable. ","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":[{"id":"com.apple.proxy.http.global_proxypacfallbackallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.proxy.http.global_proxypacfallbackallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"bb59e64ad018663d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended","displayName":"Allow importing of autofill form data (users can override)","description":"Allows users to import autofill form data from another browser into Microsoft Edge.\n\nIf you enable this policy, the option to manually import autofill data is automatically selected.\n\nIf you disable this policy, autofill form data isn't imported at first run, and users can't import it manually.\n\nIf you don't configure this policy, autofill data is imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This means that Microsoft Edge imports autofill data on first run, but users can select or clear autofill data option during manual import.\n\nNote: This policy currently manages import from Google Chrome (on Windows 7, 8, and 10 and on macOS) and Mozilla Firefox (on Windows 7, 8, and 10 and on macOS) browsers.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importautofillformdata_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"bbd2f22add47f7d3":{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer","displayName":"Configure Corporate Windows Error Reporting","description":"This policy setting specifies a corporate server to which Windows Error Reporting sends reports (if you do not want to send error reports to Microsoft).\r\n\r\nIf you enable this policy setting, you can specify the name or IP address of an error report destination server on your organization’s network. You can also select Connect using SSL to transmit error reports over a Secure Sockets Layer (SSL) connection, and specify a port number on the destination server for transmission.\r\n\r\nIf you disable or do not configure this policy setting, Windows Error Reporting sends error reports to Microsoft.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-wercer"],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_wercer_1","displayName":"Enabled","description":null,"helpText":null}]},"bb5152d0a590c061":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes","displayName":"Randomize scheduled task times","description":"This policy setting allows you to enable or disable randomization of the scheduled scan start time and the scheduled security intelligence update start time. This setting is used to distribute the resource impact of scanning. For example, it could be used in guest virtual machines sharing a host, to prevent multiple guest virtual machines from undertaking a disk-intensive operation at the same time.\r\n\r\n If you enable or do not configure this setting, scheduled tasks will begin at a random time within an interval of 4 hours after the specified start time.\r\n\r\n If you disable this setting, scheduled tasks will begin at the specified start time.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-randomizescheduletasktimes"],"categoryId":"c9a65baa-de10-4818-97a2-b61babb28060","categoryName":"Microsoft Defender Antivirus","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_randomizescheduletasktimes_1","displayName":"Enabled","description":null,"helpText":null}]},"bb9c5d334219a90d":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting","displayName":"Join Microsoft MAPS","description":null,"helpText":"","infoUrls":[],"categoryId":"09c02465-dc11-457e-9eac-19fc542e4cda","categoryName":"MAPS","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_1","displayName":"Basic MAPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_spynetreporting_spynetreporting_2","displayName":"Advanced MAPS","description":null,"helpText":null}]},"bbcab1046cb15e33":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_debugflag_netlogon_debugflaglabel","displayName":"Level:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"bbc6a9aca306f16c":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay","displayName":"Specify expected dial-up delay on logon","description":"This policy setting specifies the additional time for the computer to wait for the domain controller’s (DC) response when logging on to the network.\r\n\r\nTo specify the expected dial-up delay at logon, click Enabled, and then enter the desired value in seconds (for example, the value \"60\" is 1 minute).\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-expecteddialupdelay"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"bb198e82092ef77b":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},"bb432146839f2e15":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports","displayName":"Sports","description":"This policy setting configures the synchronization of user settings for the Sports app.\r\nBy default, the user settings of Sports sync between computers. Use the policy setting to prevent the user settings of Sports from synchronizing between computers.\r\nIf you enable this policy setting, Sports user settings continue to sync.\r\nIf you disable this policy setting, Sports user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-sports"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_sports_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3622ceb2bd43cc":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled","displayName":"Enables the concept of policy atomic groups","description":"Setting the policy to Enabled means policies coming from an atomic group that don't share the source with the highest priority from that group get ignored.\r\n\r\nSetting the policy to Disabled means no policy is ignored because of its source. Policies are ignored only if there's a conflict, and the policy doesn't have the highest priority.\r\n\r\nIf this policy is set from a cloud source, it can't target a specific user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bb5cd58ddaf7571a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting","displayName":"Default popups setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting_1","displayName":"Allow all sites to show pop-ups","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultpopupssetting_defaultpopupssetting_2","displayName":"Do not allow any site to show popups","description":null,"helpText":null}]},"bba7952c777e15f3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframecontenttypes_chromeframecontenttypesdesc","displayName":"Allow Google Chrome Frame to handle the listed content types (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"bbe7c65763e8e6cc":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings","displayName":"Enterprise search aggregator settings","description":"This policy allows administrators to set a designated enterprise search aggregator that will provide search recommendations and results within the omnibox (address bar) and the search box on the New Tab page.\r\n\r\nBy default, enterprise search suggestions will be blended and shown alongside regular Google Chrome recommendations. Users can explicitly scope their search to just the enterprise search aggregator by typing the keyword specified in the shortcut field with or without the @ prefix (e.g. @work) followed by Space or Tab in the omnibox. Scoped enterprise searches (triggered by a keyword) are currently only supported in the omnibox and not in the search box on the New Tab page.\r\n\r\nThe following fields are required: name, shortcut, search_url, suggest_url.\r\n\r\nThe name field corresponds to the search engine name shown to the user in the address bar.\r\n\r\nThe shortcut field corresponds to the keyword that the user enters to trigger the search. The shortcut can include plain words and characters, but cannot include spaces or start with the @ symbol. Shortcuts must be unique.\r\n\r\nThe search_url field specifies the URL on which to search. Enter the web address for the search engine's results page, and use '{searchTerms}' in place of the query.\r\n\r\nThe suggest_url field specifies the URL that provides search suggestions. A POST request will be made and the user's query will be passed in the POST params under key 'query'.\r\n\r\nThe icon_url field specifies the URL to an image that will be used on the search suggestions. A default icon will be used when this field is not set. It's recommended to use a favicon (example https://www.google.com/favicon.ico). Supported image file formats: JPEG, PNG, and ICO.\r\n\r\nThe require_shortcut field specifies whether the address bar shortcut is required to see search recommendations. If required, suggestions will not be shown in the search box on the New Tab page, but will continue to be shown in the omnibox (address bar) in scoped search mode. If this field is not set, the address bar shortcut is not required.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=EnterpriseSearchAggregatorSettings for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"name\": \"My Search Aggregator\",\r\n \"shortcut\": \"work\",\r\n \"search_url\": \"https://www.aggregator.com/search?q={searchTerms}\",\r\n \"suggest_url\": \"https://www.aggregator.com/suggest\",\r\n \"icon_url\": \"https://www.google.com/favicon.ico\",\r\n \"require_shortcut\": true\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterprisesearchaggregatorsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"bbab2bcf8c6e18c9":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfcccdmaxcachesizeinmbs_odfcccdmaxcachesizeinmbs","displayName":"CCD Max Cache Size in MBs (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":null},"bbb94e3005e467fd":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesattachedvhdsddl_profilesattachedvhdsddl","displayName":"Attached VHD SDDL (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"bbafbbdd38cbbe4f":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownintranetzonenavigatewindowsandframes"],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownintranetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3cfb33b0f1b486":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenablecrosssitescriptingfilter"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},"bbed5ecbf8ecdb49":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions","displayName":"Logon options","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Prompt for username and password.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonelogonoptions"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"bbac19db30f9caad":{"id":"device_vendor_msft_policy_config_internetexplorer_securityzonesuseonlymachinesettings","displayName":"Security Zones: Use only machine settings ","description":"Applies security zone information to all users of the same computer. A security zone is a group of Web sites with the same security level.\n\nIf you enable this policy, changes that the user makes to a security zone will apply to all users of that computer.\n\nIf you disable this policy or do not configure it, users of the same computer can establish their own security zone settings.\n\nThis policy is intended to ensure that security zone settings apply uniformly to the same computer and do not vary from user to user.\n\nAlso, see the \"Security zones: Do not allow users to change policies\" policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-securityzonesuseonlymachinesettings"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_securityzonesuseonlymachinesettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_securityzonesuseonlymachinesettings_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3f177e6670f44c":{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseproxyserversareauthoritative","displayName":"Enterprise Proxy Servers Are Authoritative","description":"Boolean value that tells the client to accept the configured list of proxies and not try to detect other work proxies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterpriseproxyserversareauthoritative"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":[{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseproxyserversareauthoritative_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_networkisolation_enterpriseproxyserversareauthoritative_0","displayName":"Disable","description":"Disable","helpText":null}]},"bb5d1b4b3286c143":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_exprwdexe80","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_exprwdexe80_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_objectcachingprotection_l_exprwdexe80_1","displayName":"True","description":null,"helpText":null}]},"bb5ff2145cfc6fde":{"id":"device_vendor_msft_policy_config_taskscheduler_enablexboxgamesavetask","displayName":"Enable Xbox Game Save Task","description":"This setting determines whether the specific task is enabled (1) or disabled (0). Default: Enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TaskScheduler#enablexboxgamesavetask"],"categoryId":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","categoryName":"Task Scheduler","options":[{"id":"device_vendor_msft_policy_config_taskscheduler_enablexboxgamesavetask_0","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_policy_config_taskscheduler_enablexboxgamesavetask_1","displayName":"Enabled","description":"Enabled","helpText":null}]},"bbc214a6769d60aa":{"id":"device_vendor_msft_policy_config_updatev87~policy~cat_edgeupdate~cat_webview_pol_updatepolicymicrosoftedgewebview_part_updatepolicy","displayName":"Update Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"46eaa2b7-341b-4e39-be21-c3ea09dd5778","categoryName":"Microsoft Edge Web View2 Runtime","options":[{"id":"device_vendor_msft_policy_config_updatev87~policy~cat_edgeupdate~cat_webview_pol_updatepolicymicrosoftedgewebview_part_updatepolicy_1","displayName":"Always allow updates (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev87~policy~cat_edgeupdate~cat_webview_pol_updatepolicymicrosoftedgewebview_part_updatepolicy_0","displayName":"Updates disabled","description":null,"helpText":null}]},"bb0a87f9a8aec1a8":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~livesharesettings_livesharedomainname","displayName":"Allow only company domain accounts","description":"Prevents users from being able to share their session with any guests who are not part of their company or any other company that has been given access. Users must be logged in with their company email to access Live Share. If this policy is disabled, any user from any organization can access a shared Live Share session. Use ; to separate out multiple domains. For example, set the domain name as contoso.com or contoso.com;foo.com \r\nFor more information, see: https://aka.ms/vsls-policies ","helpText":"","infoUrls":[],"categoryId":"d9d5f333-9402-4459-8ef1-e29330cac8be","categoryName":"Live Share Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~livesharesettings_livesharedomainname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~livesharesettings_livesharedomainname_1","displayName":"Enabled","description":null,"helpText":null}]},"bb60f86d70db2267":{"id":"device_vendor_msft_policy_config_windowsai_disableremoteagentconnectors","displayName":"Disable Remote Agent Connectors (Windows Insiders only)","description":"Enable or Disable Remote Agent Connectors.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#disableremoteagentconnectors"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"device_vendor_msft_policy_config_windowsai_disableremoteagentconnectors_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableremoteagentconnectors_1","displayName":"Force Enable.","description":"Force Enable.","helpText":null},{"id":"device_vendor_msft_policy_config_windowsai_disableremoteagentconnectors_2","displayName":"Force Disable.","description":"Force Disable.","helpText":null}]},"bbc6eed66a8a3243":{"id":"setrecoverylock_enablerecoverylockpassword","displayName":"Enable Recovery Lock Password","description":"Set a recovery lock password that will be required to access RecoveryOS on Mac devices. Available for Apple silicon devices running macOS 11.5 and later.","helpText":null,"infoUrls":[],"categoryId":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","categoryName":"Recovery Lock Password","options":{"id":"setrecoverylock_enablerecoverylockpassword_true","displayName":"Enabled","description":null,"helpText":null}},"bbe22685fed29022":{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_sethighriskinclusion_am_instructhighriskinclusionlist","displayName":"Specify high risk extensions (include a leading period, e.g. .cmd;.exe;). (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":null},"bbda222cf56cbfb3":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access","displayName":"Microsoft Access 2010 (User)","description":"This policy setting configures the synchronization of user settings for Microsoft Access 2010.\r\nBy default, the user settings of Microsoft Access 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Access 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Access 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Access 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010access"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010access_1","displayName":"Enabled","description":null,"helpText":null}]},"bb0da7e6ea6c34ac":{"id":"user_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_1","displayName":"Prohibit access of the Windows Connect Now wizards (User)","description":"This policy setting prohibits access to Windows Connect Now (WCN) wizards. \r\n\r\nIf you enable this policy setting, the wizards are turned off and users have no access to any of the wizard tasks. All the configuration related tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device\" are disabled. \r\n\r\nIf you disable or do not configure this policy setting, users can access the wizard tasks, including \"Set up a wireless router or access point\" and \"Add a wireless device.\" The default for this policy setting allows users to access all WCN wizards.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsconnectnow#admx-windowsconnectnow-wcn-disablewcnui-1"],"categoryId":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","categoryName":"Windows Connect Now","options":[{"id":"user_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsconnectnow_wcn_disablewcnui_1_1","displayName":"Enabled","description":null,"helpText":null}]},"bb753eff93969503":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary","displayName":"Pin Libraries or Search Connectors to the \"Search again\" links and the Start menu (User)","description":"This policy setting allows up to five Libraries or Search Connectors to be pinned to the \"Search again\" links and the Start menu links. The \"Search again\" links at the bottom of the Search Results view allow the user to reconduct a search but in a different location. To add a Library or Search Connector link, specify the path of the .Library-ms or .searchConnector-ms file in the \"Location\" text box (for example, \"C:\\sampleLibrary.Library-ms\" for the Documents library, or \"C:\\sampleSearchConnector.searchConnector-ms\" for a Search Connector). The pinned link will only work if this path is valid and the location contains the specified .Library-ms or .searchConnector-ms file.\r\n\r\nYou can add up to five additional links to the \"Search again\" links at the bottom of results returned in File Explorer after a search is executed. These links will be shared between Internet search sites and Search Connectors/Libraries. Search Connector/Library links take precedence over Internet search links.\r\n\r\nThe first several links will also be pinned to the Start menu. A total of four links can be included on the Start menu. The \"See more results\" link will be pinned first by default, unless it is disabled via Group Policy. The \"Search the Internet\" link is pinned second, if it is pinned via Group Policy (though this link is disabled by default). If a custom Internet search link is pinned using the \"Custom Internet search provider\" Group Policy, this link will be pinned third on the Start menu. The remaining link(s) will be shared between pinned Search Connectors/Libraries and pinned Internet/intranet search links. Search Connector/Library links take precedence over Internet/intranet search links.\r\n\r\nIf you enable this policy setting, the specified Libraries or Search Connectors will appear in the \"Search again\" links and the Start menu links.\r\n\r\nIf you disable or do not configure this policy setting, no Libraries or Search Connectors will appear in the \"Search again\" links or the Start menu links.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-tryharderpinnedlibrary"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3e8f7d4f8f9f80":{"id":"user_vendor_msft_policy_config_browser_clearbrowsingdataonexit","displayName":"Clear Browsing Data On Exit (User)","description":"Specifies whether to always clear browsing history on exiting Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#clearbrowsingdataonexit"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_clearbrowsingdataonexit_0","displayName":"Disabled","description":"Prevented/not allowed. Users can configure the 'Clear browsing data' option in Settings.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_clearbrowsingdataonexit_1","displayName":"Enabled","description":"Allowed. Clear the browsing data upon exit automatically.","helpText":null}]},"bb6ddb81fb623c92":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting","displayName":"Control use of JavaScript JIT (User)","description":"Allows you to set whether Google Chrome will run the v8 JavaScript engine with JIT (Just In Time) compiler enabled or not.\r\n\r\nDisabling the JavaScript JIT will mean that Google Chrome may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Google Chrome to render web content in a more secure configuration.\r\n\r\nThis policy can be overridden for specific URL patterns using the JavaScriptJitAllowedForSites and JavaScriptJitBlockedForSites policies.\r\n\r\nIf this policy is left not set, JavaScript JIT is enabled.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultjavascriptjitsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"bb476473c4bad07a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttp://testserver.example.com/\r\n*.example.org","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_1","displayName":"Enabled","description":null,"helpText":null}]},"bb3d0e269dbf3cb8":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies","displayName":"Policy overrides for Debug builds of the remote access host (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostdebugoverridepolicies_1","displayName":"Enabled","description":null,"helpText":null}]},"bb4233e133561329":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_webauthenticationremotedesktopallowedorigins_webauthenticationremotedesktopallowedoriginsdesc","displayName":"Allowed Origins for Proxied WebAuthn Requests from Remote Desktop Applications. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"bbb1ef1321ccf2d0":{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight","displayName":"Allow Windows Spotlight (User)","description":"Specifies whether to turn off all Windows spotlight features at once. If you enable this policy setting, Windows spotlight on lock screen, Windows Tips, Microsoft consumer features and other related features will be turned off. You should enable this policy setting if your goal is to minimize network traffic from target devices. If you disable or do not configure this policy setting, Windows spotlight features are allowed and may be controlled individually using their corresponding policy settings. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowwindowsspotlight"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_experience_allowwindowsspotlight_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"bbc3f3613810f008":{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate","displayName":"Intranet Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowintranetzonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"bbfd05394a4a13d8":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"bb2416e9949c5899":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallowautomaticpromptingforfiledownloads"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"bbb13062b0aa9c73":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads","displayName":"Allow font downloads (User)","description":"This policy setting allows you to manage whether pages of the zone may download HTML fonts.\n\nIf you enable this policy setting, HTML fonts can be downloaded automatically. If you enable this policy setting and Prompt is selected in the drop-down box, users are queried whether to allow HTML fonts to download.\n\nIf you disable this policy setting, HTML fonts are prevented from downloading.\n\nIf you do not configure this policy setting, users are queried whether to allow HTML fonts to download.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowfontdownloads"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowfontdownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"bb2928824d905909":{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice","displayName":"Specify use of ActiveX Installer Service for installation of ActiveX controls (User)","description":"This policy setting allows you to specify how ActiveX controls are installed.\n\nIf you enable this policy setting, ActiveX controls are installed only if the ActiveX Installer Service is present and has been configured to allow the installation of ActiveX controls.\n\nIf you disable or do not configure this policy setting, ActiveX controls, including per-user controls, are installed through the standard installation process.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-specifyuseofactivexinstallerservice"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_specifyuseofactivexinstallerservice_1","displayName":"Enabled","description":null,"helpText":null}]},"bb8bc3e3d179a948":{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled","displayName":"TLS Encrypted ClientHello Enabled (User)","description":"Encrypted ClientHello (ECH) is an extension to TLS that encrypts the sensitive fields of ClientHello to improve privacy.\r\n\r\nIf ECH is enabled, Microsoft Edge might or might not use ECH depending on server support, the availability of the HTTPS DNS record, or the rollout status.\r\n\r\nIf you enable or do not configure this policy, Microsoft Edge will follow the default rollout process for ECH.\r\n\r\nIf this policy is disabled, Microsoft Edge will not enable ECH.\r\n\r\nBecause ECH is an evolving protocol, Microsoft Edge's implementation is subject to change.\r\n\r\nAs such, this policy is a temporary measure to control the initial experimental implementation. It will be replaced with final controls as the protocol finalizes.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_encryptedclienthelloenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bb39c8b20703298a":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled","displayName":"Enable compression dictionary transport support (User)","description":"This feature enables the use of dictionary-specific content encodings in the Accept-Encoding request header (\"sbr\" and \"zst-d\") when dictionaries are available for use.\r\n\r\nIf you enable this policy or don't configure it, Microsoft Edge will accept web contents using the compression dictionary transport feature.\r\n\r\nIf you disable this policy, Microsoft Edge will turn off the compression dictionary transport feature.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~network_compressiondictionarytransportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bb06401f7dfa2ba7":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge. (User)","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?LinkId=2341535.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"bbf7a4cb3b8e15f7":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpstemplates_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"bb4cba0f1f442343":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicesharednotescustomurl2","displayName":"Shared Notes Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"bbac4de1ca029d5f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland","displayName":"Sami, Skolt (Finland) (User)","description":"Enables the editing language \"Sami, Skolt (Finland)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_samiskoltfinland_1","displayName":"Enabled","description":null,"helpText":null}]},"bb4570af2146d4f1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel","displayName":"Set the Automation Security level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_3","displayName":"Disable macros by default","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_2","displayName":"Use application macro security level","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_automationsecurity_l_settheautomationsecuritylevel_1","displayName":"Macros enabled (default)","description":null,"helpText":null}]},"bb5dbf3870df8d09":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter","displayName":"Specify filtering for certificate issuers (User)","description":"This policy setting allows you to configure Office to only allow certificates from a specific issuer when creating a digital signature.\r\n \r\nIf you enable this policy setting, Office only displays certificates that contain the string you set in the policy. This setting is case-sensitive.\r\n\r\nFor example, a setting of \"MyCA\" would match an issuer of \"MyCA 1\"and \"MyCA 2\", but not \"MYCA 3\".\r\n\r\nIf you disable or don’t configure this setting, then signing certificates from any issuer can be used.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_specifyissuerfilter_1","displayName":"Enabled","description":null,"helpText":null}]},"bb5b28cc073ad6f2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog","displayName":"Display alternative certificate providers (User)","description":"This policy setting allows you to configure whether Office displays a link to get a certificate from a Microsoft partner when there are no usable signing certificates.\r\n\r\nIf you enable this policy setting, the link won’t be displayed.\r\n\r\nIf you disable or don’t configure this policy setting, the link is displayed.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_suppressnocertdialog_1","displayName":"Enabled","description":null,"helpText":null}]},"bbd77a254ff10d91":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys39_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8184df77-410e-41a6-b687-88de05769977","categoryName":"Custom","options":null},"bb1fe2a377955165":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout","displayName":"Set the time-out interval for Outlook people search (User)","description":"This policy setting controls the time-out interval of Outlook people search. Outlook returns as many people search results as possible before the time-out interval lapses. If the search results are incomplete, Outlook displays a message at the bottom of the results list.\r\n\r\nIf you enable this policy setting, you can specify the time-out interval in milliseconds.\r\n\r\nIf you disable or do not configure this policy setting, the time-out interval is 60,000 milliseconds (60 seconds).","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_specifyoutlookpeoplesearchtimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"bb69f64cbaffc3dd":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults","displayName":"Calendar item defaults (User)","description":"Sets the value in the option \"Default reminder\".","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_1","displayName":"Enabled","description":null,"helpText":null}]},"bb1367fe80e6b3ec":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions","displayName":"Do not allow users to change permissions on folders (User)","description":"This policy setting prevents users from changing their mail folder permissions. \r\n\r\nIf you enable this policy setting, Outlook users cannot change permissions on folders; the settings on the Permissions tab are disabled. Enabling this policy setting does not affect existing permissions, and users can still change permissions by sending a sharing message.\r\n\r\nIf you disable or do not configure this policy setting, Outlook users can change the permissions for folders under their control by using the Permissions tab of the Properties dialog box for the folder.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_disablechangingfolderpermissions_1","displayName":"Enabled","description":null,"helpText":null}]},"bb6f6478082f60ba":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting","displayName":"Print in background (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_backgroundprinting_1","displayName":"Enabled","description":null,"helpText":null}]},"bb66589decdfa6d7":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd","displayName":"Disable Package For CD (User)","description":"Check to Disable Package for CD; Uncheck to Enable Package for CD. Shows or hides the File tab | Save & Send | Package Presentation for CD command. Package for CD allows the user to package and burn presentations onto CD for portable viewing even when PowerPoint is not installed.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_disablepackageforcd_1","displayName":"Enabled","description":null,"helpText":null}]},"bbf265da4f8c2164":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders75_1","displayName":"True","description":null,"helpText":null}]},"bbb2fd412dd857f2":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalendar_l_pjdefaultendtime_l_pjdefaultendtime2","displayName":"Default end time (Minutes after 12am * 10) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"9ecb05b7-e942-4b60-9040-d612385f5c67","categoryName":"Calendar","options":null},"bb5353c5c3dc8b0c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3","displayName":"Rulers (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_specifyscreentipstoappear_l_specifyscreentipstoappearboolid3_1","displayName":"True","description":null,"helpText":null}]},"bb9084e2fd771f61":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect","displayName":"Enable AutoConnect (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_enableautoconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"bb41409fba61d09b":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"bba454ce15712781":{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook","displayName":"Allow Advanced Typography features for Outlook (User)","description":"This policy setting sets the “Advanced Typography” options found under Outlook’s File tab | Outlook Options | Mail | Editor Options | Advanced | Advanced Typography.\r\n\r\nIf you enable or do not configure this policy setting, Advanced Typography features will be applied. This is the default behavior.\r\n\r\nIf you disable this policy setting, Advanced Typography features will not be applied.\r\n ","helpText":"","infoUrls":[],"categoryId":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v14~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_emailoptions_l_advancedtypographyoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"bbb248f7ae103099":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},"bb36f9dd32842ab0":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"bb5d15f46de014d1":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_publicprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]},"bb836551ae698b1b":{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications","displayName":"Disable Inbound Notifications","description":"This value is an on/off switch. If this value is false, the firewall MAY display a notification to the user when an application is blocked from listening on a port. If this value is on, the firewall MUST NOT display such a notification. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications_false","displayName":"False","description":"Firewall May Display Notification","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_disableinboundnotifications_true","displayName":"True","description":"Firewall Must Not Display Notification","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/be.json b/public/intune-definitions/be.json index 63fca55cdca8..422bb7190159 100644 --- a/public/intune-definitions/be.json +++ b/public/intune-definitions/be.json @@ -1 +1 @@ -{"be42a8b3df67021b":{"id":"com.apple.assetcache.managed_parentselectionpolicy","displayName":"Parent Selection Policy","description":"The policy to implement when choosing among more than one configured parent content cache. With every policy, parent caches that are temporarily unavailable are skipped.\r\nfirst-available: Always use the first available parent in the Parents list. Use this policy to designate permanent primary, secondary, and subsequent parents.\r\n\r\nurl-path-hash: Hash the path part of the requested URL so that the same parent is always used for the same URL. This is useful for maximizing the size of the combined caches of the parents.\r\n\r\nrandom: Choose a parent at random. Use this policy for load balancing.\r\n\r\nround-robin: Rotate through the parents in order. Use this policy for load balancing.\r\n\r\nsticky-available: Use the first available parent that is available in the Parents list until it becomes unavailable, then advance to the next one. Use this policy for designating floating primary, secondary, and subsequent parents. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_parentselectionpolicy_0","displayName":"first-available","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_1","displayName":"url-path-hash","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_2","displayName":"random","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_3","displayName":"round-robin","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_4","displayName":"sticky-available","description":null,"helpText":null}]},"be90a95d3f6fefbc":{"id":"com.apple.associated-domains_configuration","displayName":"Configuration","description":"Map apps to their associated domains.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},"be39367f7f5f50ee":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_application id","displayName":"Microsoft Teams (work or school) Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"bea2a037e95ae5c5":{"id":"com.apple.managedclient.preferences_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"A list of URLs to which \"AutoOpenFileTypes\" will apply to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\n\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in \"AutoOpenFileTypes\". If either condition is false, the download won't automatically open by policy.\n\nIf you don't set this policy, all downloads where the file type is in \"AutoOpenFileTypes\" will automatically open.\n\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoopenallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"be74af32f0a2669a":{"id":"com.apple.managedclient.preferences_extensioninstallblocklist","displayName":"Control which extensions cannot be installed","description":"List specific extensions that users can NOT install in Microsoft Edge. When you deploy this policy, any extensions on this list that were previously installed will be disabled, and the user won't be able to enable them. If you remove an item from the list of blocked extensions, that extension is automatically re-enabled anywhere it was previously installed.\n\nUse \"*\" to block all extensions that aren't explicitly listed in the allow list.\n\nIf you don't configure this policy, users can install any extension in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"beff107f7e33a4d8":{"id":"com.apple.managedclient.preferences_importfavorites","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\n\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS) and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importfavorites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importfavorites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importfavorites_true","displayName":"Enabled","description":null,"helpText":null}]},"be7734474c7ba77e":{"id":"com.apple.managedclient.preferences_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sleepingtabstimeout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_0","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_1","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_2","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_3","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_4","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_5","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_6","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_7","displayName":"12 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_8","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"be22953feb606444":{"id":"com.apple.mcxprinting_userprinterlist","displayName":"User Printer List","description":"The printers available to a user.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},"becbc88b0571480e":{"id":"com.apple.screensaver.user_modulepath","displayName":"Module Path","description":"A full path to the screen saver module to use.","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},"be4a57f03b645d62":{"id":"com.apple.softwareupdate_automaticallyinstallappupdates","displayName":"Automatically Install App Updates (Deprecated)","description":"If false, deselects the \"Install app updates from the App Store\" option and prevents the user from changing the option. ","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticallyinstallappupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticallyinstallappupdates_true","displayName":"True","description":null,"helpText":null}]},"be9c7a9e4e3c717a":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"be0ea24cec57c12b":{"id":"com.apple.universalaccess_contrast","displayName":"Contrast","description":"The contrast value in the Display options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},"beb185a34f30655d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurl_recommended","displayName":"Specifies the search-by-image feature for the default search provider (users can override)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\n\nThis policy is optional. If you don't configure it, image search isn't available.\n\nSpecify Bing's Image Search URL as:\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\n\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\n\nSee \"DefaultSearchProviderImageURLPostParams\" policy to finish configuring image search.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"be8aa86c17b36332":{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy","displayName":"Turn off solid state mode","description":"This policy setting turns off the solid state mode for the hybrid hard disks. \r\n\r\nIf you enable this policy setting, frequently written files such as the file system metadata and registry may not be stored in the NV cache.\r\n\r\nIf you disable this policy setting, the system will store frequently written data into the non-volatile (NV) cache. This allows the system to exclusively run out of the NV cache and power down the disk for longer periods to save power. Note that this can cause increased wear of the NV cache.\r\n\r\nIf you do not configure this policy setting, the default behavior of the system is observed and frequently written files will be stored in the NV cache.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-solidstatepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"be3ff4b6bf0e958e":{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound","displayName":"Support compound authentication","description":"This policy setting controls configuring the device's Active Directory account for compound authentication.\r\n\r\nSupport for providing compound authentication which is used for access control will require enough domain controllers in the resource account domains to support the requests. The Domain Administrator must configure the policy \"Support Dynamic Access Control and Kerberos armoring\" on all the domain controllers to support this policy.\r\n\r\nIf you enable this policy setting, the device's Active Directory account will be configured for compound authentication by the following options:\r\n\r\nNever: Compound authentication is never provided for this computer account.\r\n\r\nAutomatic: Compound authentication is provided for this computer account when one or more applications are configured for Dynamic Access Control.\r\n\r\nAlways: Compound authentication is always provided for this computer account.\r\n\r\nIf you disable this policy setting, Never will be used.\r\nIf you do not configure this policy setting, Automatic will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-serveracceptscompound"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_1","displayName":"Enabled","description":null,"helpText":null}]},"be2eed2fb51ba808":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist","displayName":"Files and Folders:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"be4bfb86d259606d":{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name","displayName":"Enable Device Health Attestation Monitoring and Reporting","description":"This group policy enables Device Health Attestation reporting (DHA-report) on supported devices. It enables supported devices to send Device Health Attestation related information (device boot logs, PCR values, TPM certificate, etc.) to Device Health Attestation Service (DHA-Service) every time a device starts. Device Health Attestation Service validates the security state and health of the devices, and makes the findings accessible to enterprise administrators via a cloud based reporting portal. This policy is independent of DHA reports that are initiated by device manageability solutions (like MDM or SCCM), and will not interfere with their workflows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-optintodsha-name"],"categoryId":"99b4ac32-50b5-4659-a7a1-94bc708ae71a","categoryName":"Device Health Attestation Service","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name_1","displayName":"Enabled","description":null,"helpText":null}]},"be27544cd979c635":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common","displayName":"Microsoft Office 2010 Common Settings","description":"This policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2010 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2010 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2010 applications from synchronization between computers. \r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2010 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2010 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2010 applications are enabled, this policy setting should not be disabled \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common_1","displayName":"Enabled","description":null,"helpText":null}]},"beb811a4476ec944":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel","displayName":"Microsoft Excel 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Excel 2010.\r\nBy default, the user settings of Microsoft Excel 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Excel 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel_1","displayName":"Enabled","description":null,"helpText":null}]},"be7cf8c3ee8bdfbb":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes","displayName":"Microsoft Sticky Notes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes_1","displayName":"True","description":null,"helpText":null}]},"be0f2f9cf26865cb":{"id":"device_vendor_msft_policy_config_browser_enterprisesitelistserviceurl","displayName":"Enterprise Site List Service Url","description":"Important. Discontinued in Windows 10, version 1511. Use the Browser/EnterpriseModeSiteList policy instead.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisesitelistserviceurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"be0a6b49d1b060fc":{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton","displayName":"Unlock Home Button","description":"By default, when enabling Configure Home Button or Set Home Button URL, the home button is locked down to prevent your users from changing what page loads when clicking the home button. Use this policy to let users change the home button even when Configure Home Button or Set Home Button URL are enabled. If enabled, the UI settings for the home button are enabled allowing your users to make changes, including hiding and showing the home button as well as configuring a custom URL. If disabled or not configured, the UI settings for the home button are disabled preventing your users from making changes. Default setting: Disabled or not configured Related policy: -Configure Home Button -Set Home Button URL","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#unlockhomebutton"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton_0","displayName":"Disabled","description":"Lock down and prevent users from making changes to the settings.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton_1","displayName":"Enabled","description":"Let users make changes.","helpText":null}]},"be8bd9b236ee2ed1":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates.","description":"Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"be0ae3d94bd87c72":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},"be2a2e6a66f04e3e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled","displayName":"Configure tab lifecycles","description":"The tab lifecycles feature reclaims CPU and memory associated with running tabs that haven't been used in a long time, by first throttling, then freezing, and finally discarding them.\r\n\r\nIf you disable this policy, the tab lifecycles feature is disabled, and all tabs are left running normally.\r\n\r\nIf you enable or don't configure this policy, the tab lifecycles feature is enabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"be6aca540fad65e5":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"bef1f8de3aca5a99":{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled","displayName":"Enable upload files from mobile in Microsoft Edge desktop","description":"This policy lets you configure the \"Upload from mobile\" feature in Microsoft Edge.\r\n\r\nUpload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"be32d0b23772b599":{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites","description":"Lets you configure a list of site url patterns that specify sites which will automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"be126f8b5475e809":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled","displayName":"Enhance images enabled (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 121.\r\n\r\nThe enhance images feature is deprecated and starting in 122 this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast.\r\n\r\nIf you enable this policy or don't configure the policy, Microsoft Edge will automatically enhance images on specific web applications.\r\n\r\nIf you disable this policy, Microsoft Edge will not enhance images.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bee32165a678f032":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_visioexe47","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_visioexe47_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_visioexe47_1","displayName":"True","description":null,"helpText":null}]},"be184f571c3b9763":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_outlookexe106","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_outlookexe106_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_outlookexe106_1","displayName":"True","description":null,"helpText":null}]},"be67fa33da780e80":{"id":"device_vendor_msft_policy_config_search_disablebackoff","displayName":"Disable Backoff","description":"If enabled, the search indexer backoff feature will be disabled. Indexing will continue at full speed even when system activity is high. If disabled, backoff logic will be used to throttle back indexing activity when system activity is high. Default is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Search#disablebackoff"],"categoryId":"794337be-8833-4b9a-bb88-8a030141578d","categoryName":"Search","options":[{"id":"device_vendor_msft_policy_config_search_disablebackoff_0","displayName":"Disable.","description":"Disable.","helpText":null},{"id":"device_vendor_msft_policy_config_search_disablebackoff_1","displayName":"Enable.","description":"Enable.","helpText":null}]},"be2a23c1d641ec20":{"id":"enrollment_autopilot_dpp_allowedscriptids","displayName":"Allowed scripts","description":"Select up to 10 Windows PowerShell scripts to install during this deployment. These scripts should be already assigned to the device group selected earlier. You can check the installation status for these scripts in the Autopilot device preparation deployment report.","helpText":"","infoUrls":[],"categoryId":"db9fc5b8-fb50-437b-aceb-87d9d380def0","categoryName":null,"options":null},"be9e155d243c0949":{"id":"linux_mdatp_managed_cloudservice_diagnosticlevel","displayName":"Diagnostic data collection level","description":"We encourage you to share your diagnostic and usage data with us to help improve Microsoft products and services.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#diagnostic-collection-level"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"linux_mdatp_managed_cloudservice_diagnosticlevel_0","displayName":"optional","description":null,"helpText":null},{"id":"linux_mdatp_managed_cloudservice_diagnosticlevel_1","displayName":"required","description":null,"helpText":null}]},"be1ddcc733379825":{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnonotification","displayName":"Turn off all balloon notifications (User)","description":"This policy setting allows you to turn off all notification balloons.\r\n\r\nIf you enable this policy setting, no notification balloons are shown to the user.\r\n\r\nIf you disable or do not configure this policy setting, notification balloons are shown to the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnonotification"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnonotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnonotification_1","displayName":"Enabled","description":null,"helpText":null}]},"bef96af7ffc41c4d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled","displayName":"Continue running background apps when Google Chrome is closed (User)","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"be33b7de3b8d355d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins","displayName":"Specify a list of disabled plugins (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_1","displayName":"Enabled","description":null,"helpText":null}]},"bec37f20eef84044":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor","displayName":"Enable two-factor authentication for remote access hosts (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor_1","displayName":"Enabled","description":null,"helpText":null}]},"bedc2f58e272b027":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which\r\nadvanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Google Chrome may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site\r\ngranularity (eTLD+1). A policy set for only subdomain.site.com will not\r\ncorrectly apply to site.com or subdomain.site.com since they both resolve to\r\nthe same eTLD+1 (site.com) for which there is no policy. In this case, policy\r\nmust be set on site.com to apply correctly for both site.com and\r\nsubdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level\r\norigin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerBlockedForSites policy but site-one.com loads a frame\r\ncontaining site-two.com then site-one.com will have JavaScript optimizations\r\ndisabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript\r\noptimizations enabled. Blocklist entries have higher priority than allowlist\r\nentries, which in turn have higher priority than the configured default value.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise\r\nJavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"bed1c920c79607b6":{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting (User)","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\r\n\r\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"bebf4370f7973a35":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_browsingwithcopilotallowlistdesc","displayName":"Browsing with Copilot Allowed URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"be5ca2a81e9f5bb0":{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended","displayName":"Single sign-on for work or school sites using this profile enabled (User)","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"be8677bba91c9358":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled","displayName":"Enable renderer in app container (User)","description":"Launches Renderer processes into an App Container for\r\nadditional security benefits.\r\n\r\nIf you don't configure this policy, Microsoft Edge will launch the renderer process in an app\r\ncontainer in a future update.\r\n\r\nIf you enable this policy, Microsoft Edge will launch the renderer process in an app container.\r\n\r\nIf you disable this policy, Microsoft Edge will not launch the renderer process in an app container.\r\n\r\nOnly turn off the policy if there are compatibility issues with\r\nthird-party software that must run inside Microsoft Edge's renderer processes.\r\n\r\nThis policy will only take effect on Windows 10 RS5 and above.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"be4b0e191c1a8277":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_l_maxretriesdecimal","displayName":"Maximum number of retries (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},"be13e7b63524aeee":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail","displayName":"Replace AD - E-mail (User)","description":"This policy setting allows you to customize the 1st value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"email address\" of line 1.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 1 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},"be3ba3f3d191c6e5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian","displayName":"Albanian (User)","description":"Enables the editing language Albanian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian_1","displayName":"Enabled","description":null,"helpText":null}]},"be89612c2544d488":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt","displayName":"Block opening of pre-release versions of file formats new to PowerPoint 2016 through the Compatibility Pack for Office 2016 and PowerPoint 2016 Converter (User)","description":"This policy setting controls whether users with the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2016 File Formats installed can open Office Open XML files saved with pre-release versions of PowerPoint 2016. PowerPoint Open XML files usually have the following extensions: .pptx, .pptm, .potx, .potm, .ppsx, .ppsm, .ppam, .thmx, .xml. \r\n\r\nIf you enable this policy setting, users of the Compatibility Pack will not be able to open Office Open XML files created in pre-release versions of PowerPoint 2016. \r\n\r\nIf you disable this policy setting, users with the Compatibility Pack installed can open files saved by some pre-release versions of PowerPoint, but not by others, which can lead to inconsistent file opening functionality.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled","helpText":"","infoUrls":[],"categoryId":"8b0e5a63-c309-430b-8521-7bd21e715b90","categoryName":"Office 2016 Converters","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt_1","displayName":"Enabled","description":null,"helpText":null}]},"be3b081c0e89294e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_pathcolon250","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"bed11f2c92d615b3":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages","displayName":"Always use TNEF formatting in S/MIME messages (User)","description":"This policy setting allows you to specify the formatting when sending S/MIME messages.\r\n\r\nIf you enable this policy setting, Outlook always uses TNEF formatting when sending S/MIME messages.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the format specified by the user when sending e-mail messages, including when sending S/MIME messages.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages_1","displayName":"Enabled","description":null,"helpText":null}]},"beee78bcc2c5df77":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption","displayName":"Save Active Project only (User)","description":"Saves only the active project at the interval you specify. This setting is only used by Project if Auto Save is turned on.\r\n\r\nIf you enable this setting, Project will only save the active project at specified intervals.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption_1","displayName":"Enabled","description":null,"helpText":null}]},"be7a96057ec15160":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile_l_cachesizeperprofile38","displayName":"Local Project Cache Size Limit in MB (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":null},"becbab450390c4c8":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar","displayName":"Scroll Bars (User)","description":"Displays scrollbars for views.\r\n \r\nIf you enable this setting, scrollbars are displayed in the views.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},"be0a3fd80bd6f1d4":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"be3d3d69fbc7231c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"befaae035147dd3c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"be4b76fc50f19fe5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies","displayName":"Mark formatting inconsistencies (User)","description":"Defines color to use for marking formatting inconsistencies.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_1","displayName":"Enabled","description":null,"helpText":null}]},"be98fdf410b4c04b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"be42a8b3df67021b":{"id":"com.apple.assetcache.managed_parentselectionpolicy","displayName":"Parent Selection Policy","description":"The policy to implement when choosing among more than one configured parent content cache. With every policy, parent caches that are temporarily unavailable are skipped.\r\nfirst-available: Always use the first available parent in the Parents list. Use this policy to designate permanent primary, secondary, and subsequent parents.\r\n\r\nurl-path-hash: Hash the path part of the requested URL so that the same parent is always used for the same URL. This is useful for maximizing the size of the combined caches of the parents.\r\n\r\nrandom: Choose a parent at random. Use this policy for load balancing.\r\n\r\nround-robin: Rotate through the parents in order. Use this policy for load balancing.\r\n\r\nsticky-available: Use the first available parent that is available in the Parents list until it becomes unavailable, then advance to the next one. Use this policy for designating floating primary, secondary, and subsequent parents. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_parentselectionpolicy_0","displayName":"first-available","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_1","displayName":"url-path-hash","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_2","displayName":"random","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_3","displayName":"round-robin","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_parentselectionpolicy_4","displayName":"sticky-available","description":null,"helpText":null}]},"be90a95d3f6fefbc":{"id":"com.apple.associated-domains_configuration","displayName":"Configuration","description":"Map apps to their associated domains.","helpText":null,"infoUrls":[],"categoryId":"8efd284f-5a56-4da8-8821-f51984ff954d","categoryName":"Associated Domains","options":null},"be39367f7f5f50ee":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams (work or school).app_application id","displayName":"Microsoft Teams (work or school) Application ID","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"bea2a037e95ae5c5":{"id":"com.apple.managedclient.preferences_autoopenallowedforurls","displayName":"URLs where AutoOpenFileTypes can apply","description":"A list of URLs to which \"AutoOpenFileTypes\" will apply to. This policy has no impact on automatically open values set by users via the download shelf ... > \"Always open files of this type\" menu entry.\n\nIf you set URLs in this policy, files will only automatically open by policy if the URL is part of this set and the file type is listed in \"AutoOpenFileTypes\". If either condition is false, the download won't automatically open by policy.\n\nIf you don't set this policy, all downloads where the file type is in \"AutoOpenFileTypes\" will automatically open.\n\nA URL pattern has to be formatted according to https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autoopenallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"be74af32f0a2669a":{"id":"com.apple.managedclient.preferences_extensioninstallblocklist","displayName":"Control which extensions cannot be installed","description":"List specific extensions that users can NOT install in Microsoft Edge. When you deploy this policy, any extensions on this list that were previously installed will be disabled, and the user won't be able to enable them. If you remove an item from the list of blocked extensions, that extension is automatically re-enabled anywhere it was previously installed.\n\nUse \"*\" to block all extensions that aren't explicitly listed in the allow list.\n\nIf you don't configure this policy, users can install any extension in Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensioninstallblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"beff107f7e33a4d8":{"id":"com.apple.managedclient.preferences_importfavorites","displayName":"Allow importing of favorites","description":"Allows users to import favorites from another browser into Microsoft Edge.\n\nIf you enable this policy, the **Favorites** check box is automatically selected in the **Import browser data** dialog box.\n\nIf you disable this policy, favorites aren't imported at first run, and users can’t import them manually.\n\nIf you don’t configure this policy, favorites are imported at first run, and users can choose whether to import them manually during later browsing sessions.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports favorites on first run, but users can select or clear the **favorites** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10), Google Chrome (on Windows 7, 8, and 10 and on macOS) and Apple Safari (on macOS) browsers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importfavorites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importfavorites_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importfavorites_true","displayName":"Enabled","description":null,"helpText":null}]},"be7734474c7ba77e":{"id":"com.apple.managedclient.preferences_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if Sleeping Tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or is not configured and the user has enabled the Sleeping Tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sleepingtabstimeout"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_0","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_1","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_2","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_3","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_4","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_5","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_6","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_7","displayName":"12 hours of inactivity","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sleepingtabstimeout_8","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"be22953feb606444":{"id":"com.apple.mcxprinting_userprinterlist","displayName":"User Printer List","description":"The printers available to a user.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},"becbc88b0571480e":{"id":"com.apple.screensaver.user_modulepath","displayName":"Module Path","description":"A full path to the screen saver module to use.","helpText":null,"infoUrls":[],"categoryId":"11c4cf0f-a03d-4309-93b2-011be4c410d5","categoryName":"Screensaver User","options":null},"be4a57f03b645d62":{"id":"com.apple.softwareupdate_automaticallyinstallappupdates","displayName":"Automatically Install App Updates (Deprecated)","description":"If false, deselects the \"Install app updates from the App Store\" option and prevents the user from changing the option. ","helpText":null,"infoUrls":[],"categoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","categoryName":"Software Update","options":[{"id":"com.apple.softwareupdate_automaticallyinstallappupdates_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.softwareupdate_automaticallyinstallappupdates_true","displayName":"True","description":null,"helpText":null}]},"be9c7a9e4e3c717a":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype","displayName":"Identifier Type","description":"The type of identifier value. Application bundles must be identified by bundle ID. Nonbundled binaries must be identified by installation path. Helper tools embedded within an application bundle automatically inherit the permissions of their enclosing app bundle.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype_0","displayName":"bundle ID","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_identifiertype_1","displayName":"path","description":null,"helpText":null}]},"be0ea24cec57c12b":{"id":"com.apple.universalaccess_contrast","displayName":"Contrast","description":"The contrast value in the Display options.","helpText":null,"infoUrls":[],"categoryId":"c00d6468-cac3-429c-ada5-ba3adf4982a8","categoryName":"Accessibility","options":null},"beb185a34f30655d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchproviderimageurl_recommended","displayName":"Specifies the search-by-image feature for the default search provider (users can override)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\n\nThis policy is optional. If you don't configure it, image search isn't available.\n\nSpecify Bing's Image Search URL as:\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\n\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\n\nSee \"DefaultSearchProviderImageURLPostParams\" policy to finish configuring image search.\n\nThis policy is applied only if you enable the \"DefaultSearchProviderEnabled\" and \"DefaultSearchProviderSearchURL\" policies.\n\nStarting in Microsoft Edge version 84, you can set this policy as a recommended policy. If the user set a default search provider, the default search provider configured by this recommended policy can't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"be8aa86c17b36332":{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy","displayName":"Turn off solid state mode","description":"This policy setting turns off the solid state mode for the hybrid hard disks. \r\n\r\nIf you enable this policy setting, frequently written files such as the file system metadata and registry may not be stored in the NV cache.\r\n\r\nIf you disable this policy setting, the system will store frequently written data into the non-volatile (NV) cache. This allows the system to exclusively run out of the NV cache and power down the disk for longer periods to save power. Note that this can cause increased wear of the NV cache.\r\n\r\nIf you do not configure this policy setting, the default behavior of the system is observed and frequently written files will be stored in the NV cache.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-solidstatepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_solidstatepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"be3ff4b6bf0e958e":{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound","displayName":"Support compound authentication","description":"This policy setting controls configuring the device's Active Directory account for compound authentication.\r\n\r\nSupport for providing compound authentication which is used for access control will require enough domain controllers in the resource account domains to support the requests. The Domain Administrator must configure the policy \"Support Dynamic Access Control and Kerberos armoring\" on all the domain controllers to support this policy.\r\n\r\nIf you enable this policy setting, the device's Active Directory account will be configured for compound authentication by the following options:\r\n\r\nNever: Compound authentication is never provided for this computer account.\r\n\r\nAutomatic: Compound authentication is provided for this computer account when one or more applications are configured for Dynamic Access Control.\r\n\r\nAlways: Compound authentication is always provided for this computer account.\r\n\r\nIf you disable this policy setting, Never will be used.\r\nIf you do not configure this policy setting, Automatic will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-serveracceptscompound"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_serveracceptscompound_1","displayName":"Enabled","description":null,"helpText":null}]},"be2eed2fb51ba808":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist","displayName":"Files and Folders:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"be4bfb86d259606d":{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name","displayName":"Enable Device Health Attestation Monitoring and Reporting","description":"This group policy enables Device Health Attestation reporting (DHA-report) on supported devices. It enables supported devices to send Device Health Attestation related information (device boot logs, PCR values, TPM certificate, etc.) to Device Health Attestation Service (DHA-Service) every time a device starts. Device Health Attestation Service validates the security state and health of the devices, and makes the findings accessible to enterprise administrators via a cloud based reporting portal. This policy is independent of DHA reports that are initiated by device manageability solutions (like MDM or SCCM), and will not interfere with their workflows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tpm#admx-tpm-optintodsha-name"],"categoryId":"99b4ac32-50b5-4659-a7a1-94bc708ae71a","categoryName":"Device Health Attestation Service","options":[{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tpm_optintodsha_name_1","displayName":"Enabled","description":null,"helpText":null}]},"be27544cd979c635":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common","displayName":"Microsoft Office 2010 Common Settings","description":"This policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2010 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2010 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2010 applications from synchronization between computers. \r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2010 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2010 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2010 applications are enabled, this policy setting should not be disabled \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010common_1","displayName":"Enabled","description":null,"helpText":null}]},"beb811a4476ec944":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel","displayName":"Microsoft Excel 2010","description":"This policy setting configures the synchronization of user settings for Microsoft Excel 2010.\r\nBy default, the user settings of Microsoft Excel 2010 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Excel 2010 from synchronization between computers. \r\nIf you enable this policy setting, Microsoft Excel 2010 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Excel 2010 user settings are excluded from the synchronization settings. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2010excel"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2010excel_1","displayName":"Enabled","description":null,"helpText":null}]},"be7cf8c3ee8bdfbb":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes","displayName":"Microsoft Sticky Notes (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_2_microsoftstickynotes_1","displayName":"True","description":null,"helpText":null}]},"be0f2f9cf26865cb":{"id":"device_vendor_msft_policy_config_browser_enterprisesitelistserviceurl","displayName":"Enterprise Site List Service Url","description":"Important. Discontinued in Windows 10, version 1511. Use the Browser/EnterpriseModeSiteList policy instead.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisesitelistserviceurl"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"be0a6b49d1b060fc":{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton","displayName":"Unlock Home Button","description":"By default, when enabling Configure Home Button or Set Home Button URL, the home button is locked down to prevent your users from changing what page loads when clicking the home button. Use this policy to let users change the home button even when Configure Home Button or Set Home Button URL are enabled. If enabled, the UI settings for the home button are enabled allowing your users to make changes, including hiding and showing the home button as well as configuring a custom URL. If disabled or not configured, the UI settings for the home button are disabled preventing your users from making changes. Default setting: Disabled or not configured Related policy: -Configure Home Button -Set Home Button URL","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#unlockhomebutton"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton_0","displayName":"Disabled","description":"Lock down and prevent users from making changes to the settings.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_unlockhomebutton_1","displayName":"Enabled","description":"Let users make changes.","helpText":null}]},"be8bd9b236ee2ed1":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed","displayName":"Allow users to manage installed CA certificates.","description":"Setting the policy to All (0) or leaving it unset lets users edit trust settings for all CA certificates, remove user-imported certificates, and import certificates using Certificate Manager. Setting the policy to UserOnly (1) lets users manage only user-imported certificates, but not change trust settings of built-in certificates. Setting it to None (2) lets users view (not manage) CA certificates.","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificatemanagementallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"be0ae3d94bd87c72":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v2~policy~microsoft_edge_webview2_httpallowlist_httpallowlistdesc","displayName":"HTTP Allowlist (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c945edd8-c865-4932-806d-83752e3f46ad","categoryName":"Microsoft Edge Web View2","options":null},"be2a2e6a66f04e3e":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled","displayName":"Configure tab lifecycles","description":"The tab lifecycles feature reclaims CPU and memory associated with running tabs that haven't been used in a long time, by first throttling, then freezing, and finally discarding them.\r\n\r\nIf you disable this policy, the tab lifecycles feature is disabled, and all tabs are left running normally.\r\n\r\nIf you enable or don't configure this policy, the tab lifecycles feature is enabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"be6aca540fad65e5":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls","displayName":"Allow clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify which sites can use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"bef1f8de3aca5a99":{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled","displayName":"Enable upload files from mobile in Microsoft Edge desktop","description":"This policy lets you configure the \"Upload from mobile\" feature in Microsoft Edge.\r\n\r\nUpload from mobile lets users select file from mobile devices to desktop when user upload file in a webpage in Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, you can use the Upload from mobile feature in Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Upload from mobile feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_uploadfromphoneenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"be32d0b23772b599":{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls","displayName":"Block Window Management permission on specified sites","description":"Lets you configure a list of site url patterns that specify sites which will automatically deny the window management permission. This limits the ability of sites to see information about the device's screens. This information can be used to open and place windows or request fullscreen on specific screens.\r\n\r\nFor detailed information on valid site url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed. This policy only matches based on site origin, so any path in the URL pattern is ignored.\r\n\r\nIf this policy isn't configured for a site, then the policy from 'DefaultWindowManagementSetting' (Default Window Management permission setting) applies to the site, if configured. Otherwise the permission will follow the browser's defaults and let users choose this permission per site.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_windowmanagementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"be126f8b5475e809":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled","displayName":"Enhance images enabled (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 121.\r\n\r\nThe enhance images feature is deprecated and starting in 122 this policy will be removed. Set whether Microsoft Edge can automatically enhance images to show you sharper images with better color, lighting, and contrast.\r\n\r\nIf you enable this policy or don't configure the policy, Microsoft Edge will automatically enhance images on specific web applications.\r\n\r\nIf you disable this policy, Microsoft Edge will not enhance images.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge_edgeenhanceimagesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bee32165a678f032":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_visioexe47","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_visioexe47_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_consistentmimehandling_l_visioexe47_1","displayName":"True","description":null,"helpText":null}]},"be184f571c3b9763":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_outlookexe106","displayName":"outlook.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_outlookexe106_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_outlookexe106_1","displayName":"True","description":null,"helpText":null}]},"be67fa33da780e80":{"id":"device_vendor_msft_policy_config_search_disablebackoff","displayName":"Disable Backoff","description":"If enabled, the search indexer backoff feature will be disabled. Indexing will continue at full speed even when system activity is high. If disabled, backoff logic will be used to throttle back indexing activity when system activity is high. Default is disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Search#disablebackoff"],"categoryId":"794337be-8833-4b9a-bb88-8a030141578d","categoryName":"Search","options":[{"id":"device_vendor_msft_policy_config_search_disablebackoff_0","displayName":"Disable.","description":"Disable.","helpText":null},{"id":"device_vendor_msft_policy_config_search_disablebackoff_1","displayName":"Enable.","description":"Enable.","helpText":null}]},"be4e61b8a653bb6c":{"id":"device_vendor_msft_policy_config_update_maintenancewindowweeklysaturday","displayName":"Maintenance Window Weekly Saturday","description":"If the maintenance window repeat schedule is set to weekly, configure whether Saturday is included in the weekly schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowweeklysaturday"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"be2a23c1d641ec20":{"id":"enrollment_autopilot_dpp_allowedscriptids","displayName":"Allowed scripts","description":"Select up to 10 Windows PowerShell scripts to install during this deployment. These scripts should be already assigned to the device group selected earlier. You can check the installation status for these scripts in the Autopilot device preparation deployment report.","helpText":"","infoUrls":[],"categoryId":"db9fc5b8-fb50-437b-aceb-87d9d380def0","categoryName":null,"options":null},"be9e155d243c0949":{"id":"linux_mdatp_managed_cloudservice_diagnosticlevel","displayName":"Diagnostic data collection level","description":"We encourage you to share your diagnostic and usage data with us to help improve Microsoft products and services.","helpText":null,"infoUrls":["https://docs.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#diagnostic-collection-level"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":[{"id":"linux_mdatp_managed_cloudservice_diagnosticlevel_0","displayName":"optional","description":null,"helpText":null},{"id":"linux_mdatp_managed_cloudservice_diagnosticlevel_1","displayName":"required","description":null,"helpText":null}]},"be1ddcc733379825":{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnonotification","displayName":"Turn off all balloon notifications (User)","description":"This policy setting allows you to turn off all notification balloons.\r\n\r\nIf you enable this policy setting, no notification balloons are shown to the user.\r\n\r\nIf you disable or do not configure this policy setting, notification balloons are shown to the user.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-taskbar#admx-taskbar-taskbarnonotification"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnonotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_taskbar_taskbarnonotification_1","displayName":"Enabled","description":null,"helpText":null}]},"bef96af7ffc41c4d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled","displayName":"Continue running background apps when Google Chrome is closed (User)","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_backgroundmodeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"be33b7de3b8d355d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins","displayName":"Specify a list of disabled plugins (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disabledplugins_1","displayName":"Enabled","description":null,"helpText":null}]},"bec37f20eef84044":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor","displayName":"Enable two-factor authentication for remote access hosts (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_remoteaccesshostrequiretwofactor_1","displayName":"Enabled","description":null,"helpText":null}]},"bedc2f58e272b027":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which\r\nadvanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Google Chrome may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site\r\ngranularity (eTLD+1). A policy set for only subdomain.site.com will not\r\ncorrectly apply to site.com or subdomain.site.com since they both resolve to\r\nthe same eTLD+1 (site.com) for which there is no policy. In this case, policy\r\nmust be set on site.com to apply correctly for both site.com and\r\nsubdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level\r\norigin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerBlockedForSites policy but site-one.com loads a frame\r\ncontaining site-two.com then site-one.com will have JavaScript optimizations\r\ndisabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript\r\noptimizations enabled. Blocklist entries have higher priority than allowlist\r\nentries, which in turn have higher priority than the configured default value.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise\r\nJavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"bed1c920c79607b6":{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting","displayName":"Default Window Management permission setting (User)","description":"Setting the policy to \"BlockWindowManagement\" (value 2) automatically denies the window management permission to sites by default. This limits the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nSetting the policy to \"AskWindowManagement\" (value 3) by default prompts the user when the window management permission is requested. If users allow the permission, it extends the ability of sites to see information about the device's screens and use that information to open and place windows or request fullscreen on specific screens.\r\n\r\nNot configuring the policy means the \"AskWindowManagement\" policy applies, but users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockWindowManagement (2) = Denies the Window Management permission on all sites by default\r\n\r\n* AskWindowManagement (3) = Ask every time a site wants obtain the Window Management permission\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev123~policy~microsoft_edge~contentsettings_defaultwindowmanagementsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"bebf4370f7973a35":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_browsingwithcopilotallowlist_browsingwithcopilotallowlistdesc","displayName":"Browsing with Copilot Allowed URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"be5ca2a81e9f5bb0":{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended","displayName":"Single sign-on for work or school sites using this profile enabled (User)","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\r\n\r\nIf you disable this policy, non-AAD profiles will not be able to use SSO using other credentials present on the machine. This will also ensure that 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' is turned off.\r\n\r\nIf you enable this policy or don't configure it, non-AAD profiles will be able to use SSO using other credentials present on the machine and 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will continue working.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_aadwebsitessousingthisprofileenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"be8677bba91c9358":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled","displayName":"Enable renderer in app container (User)","description":"Launches Renderer processes into an App Container for\r\nadditional security benefits.\r\n\r\nIf you don't configure this policy, Microsoft Edge will launch the renderer process in an app\r\ncontainer in a future update.\r\n\r\nIf you enable this policy, Microsoft Edge will launch the renderer process in an app container.\r\n\r\nIf you disable this policy, Microsoft Edge will not launch the renderer process in an app container.\r\n\r\nOnly turn off the policy if there are compatibility issues with\r\nthird-party software that must run inside Microsoft Edge's renderer processes.\r\n\r\nThis policy will only take effect on Windows 10 RS5 and above.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_rendererappcontainerenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"be4b0e191c1a8277":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_businessdata~l_synchronization_l_maxretries_l_maxretriesdecimal","displayName":"Maximum number of retries (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","categoryName":"Synchronization","options":null},"be13e7b63524aeee":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail","displayName":"Replace AD - E-mail (User)","description":"This policy setting allows you to customize the 1st value of the Contact Tab.\r\n\r\nIf you enable this policy setting, you can change or remove the default value - \"email address\" of line 1.\r\n\r\nIf you disable or do not configure this policy setting, the default value for line 1 is displayed.\r\n\r\nImportant:\r\nIt is recommended that you specify a Messaging Application Programming Interface (MAPI) property and a corresponding Active Directory attribute (AD attribute). The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in this format: ADAttribute. Any properties entered which are binary or list box, cannot be displayed and are ignored.\r\n\r\nExample:\r\nTo display the Assistant on the Contact Card, enter the AD attribute: Ms-exch-assistant-name.\r\n\r\nTo remove the value, enter: null.\r\n\r\nNote: \r\nThe Location and Calendar values for a default Contact Card are not MAPI Properties or AD Attributes. \r\n\r\nRelated policy settings: \r\nReplace MAPI property n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_1","displayName":"Enabled","description":null,"helpText":null}]},"be3ba3f3d191c6e5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian","displayName":"Albanian (User)","description":"Enables the editing language Albanian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_albanian_1","displayName":"Enabled","description":null,"helpText":null}]},"be89612c2544d488":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt","displayName":"Block opening of pre-release versions of file formats new to PowerPoint 2016 through the Compatibility Pack for Office 2016 and PowerPoint 2016 Converter (User)","description":"This policy setting controls whether users with the Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2016 File Formats installed can open Office Open XML files saved with pre-release versions of PowerPoint 2016. PowerPoint Open XML files usually have the following extensions: .pptx, .pptm, .potx, .potm, .ppsx, .ppsm, .ppam, .thmx, .xml. \r\n\r\nIf you enable this policy setting, users of the Compatibility Pack will not be able to open Office Open XML files created in pre-release versions of PowerPoint 2016. \r\n\r\nIf you disable this policy setting, users with the Compatibility Pack installed can open files saved by some pre-release versions of PowerPoint, but not by others, which can lead to inconsistent file opening functionality.\r\n\r\nIf you do not configure this policy setting, the behavior is the equivalent of setting the policy to Enabled","helpText":"","infoUrls":[],"categoryId":"8b0e5a63-c309-430b-8521-7bd21e715b90","categoryName":"Office 2016 Converters","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_officeconverters_l_blockopeningofprereleaseppt_1","displayName":"Enabled","description":null,"helpText":null}]},"be3b081c0e89294e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_pathcolon250","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"bed11f2c92d615b3":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages","displayName":"Always use TNEF formatting in S/MIME messages (User)","description":"This policy setting allows you to specify the formatting when sending S/MIME messages.\r\n\r\nIf you enable this policy setting, Outlook always uses TNEF formatting when sending S/MIME messages.\r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the format specified by the user when sending e-mail messages, including when sending S/MIME messages.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_outlooktnefinsmimemessages_1","displayName":"Enabled","description":null,"helpText":null}]},"beee78bcc2c5df77":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption","displayName":"Save Active Project only (User)","description":"Saves only the active project at the interval you specify. This setting is only used by Project if Auto Save is turned on.\r\n\r\nIf you enable this setting, Project will only save the active project at specified intervals.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjautomaticsaveoption_1","displayName":"Enabled","description":null,"helpText":null}]},"be7a96057ec15160":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjcache_l_cachesizeperprofile_l_cachesizeperprofile38","displayName":"Local Project Cache Size Limit in MB (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e13ec567-e29c-4ca0-b599-e8c43587f10a","categoryName":"Tools | Local Project Cache","options":null},"becbab450390c4c8":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar","displayName":"Scroll Bars (User)","description":"Displays scrollbars for views.\r\n \r\nIf you enable this setting, scrollbars are displayed in the views.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},"be0a3fd80bd6f1d4":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc01_l_descriptioncolon","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"be3d3d69fbc7231c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc02_l_pathcolon12","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"befaae035147dd3c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy","displayName":"VBA Macro Notification Settings (User)","description":"This policy setting controls how the specified applications warn users when Visual Basic for Applications (VBA) macros are present.\r\n\r\nIf you enable this policy setting, you can choose from four options for determining how the specified applications will warn the user about macros:\r\n \r\n- Disable all with notification: The application displays the Trust Bar for all macros, whether signed or unsigned. This option enforces the default configuration in Office.\r\n \r\n- Disable all except digitally signed macros: The application displays the Trust Bar for digitally signed macros, allowing users to enable them or leave them disabled. Any unsigned macros are disabled, and users are not notified.\r\n \r\n- Disable all without notification: The application disables all macros, whether signed or unsigned, and does not notify users.\r\n \r\n- Enable all macros (not recommended): All macros are enabled, whether signed or unsigned. This option can significantly reduce security by allowing dangerous code to run undetected.\r\n \r\nIf you disable this policy setting, \"Disable all with notification\" will be the default setting.\r\n \r\nIf you do not configure this policy setting, when users open files in the specified applications that contain VBA macros, the applications open the files with the macros disabled and display the Trust Bar with a warning that macros are present and have been disabled. Users can inspect and edit the files if appropriate, but cannot use any disabled functionality until they enable it by clicking \"Enable Content\" on the Trust Bar. If the user clicks \"Enable Content\", then the document is added as a trusted document.\r\n \r\nImportant: If \"Disable all except digitally signed macros\" is selected, users will not be able to open unsigned Access databases.\r\n \r\nAlso, note that Microsoft Office stores certificates for trusted publishers in the Internet Explorer trusted publisher store. Earlier versions of Microsoft Office stored trusted publisher certificate information (specifically, the certificate thumbprint) in a special Office trusted publisher store. Microsoft Office still reads trusted publisher certificate information from the Office trusted publisher store, but it does not write information to this store.\r\n \r\nTherefore, if you created a list of trusted publishers in a previous version of Microsoft Office and you upgrade to Office, your trusted publisher list will still be recognized. However, any trusted publisher certificates that you add to the list will be stored in the Internet Explorer trusted publisher store.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_vbawarningspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"be4b76fc50f19fe5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies","displayName":"Mark formatting inconsistencies (User)","description":"Defines color to use for marking formatting inconsistencies.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_markformattinginconsistencies_1","displayName":"Enabled","description":null,"helpText":null}]},"be98fdf410b4c04b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13","displayName":"Trusted Location #13 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/bf.json b/public/intune-definitions/bf.json index ef25dbf9375b..823faf6b49c7 100644 --- a/public/intune-definitions/bf.json +++ b/public/intune-definitions/bf.json @@ -1 +1 @@ -{"bff0c17cf8ce0938":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_application id","displayName":"Microsoft Defender ATP Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"bff7270142ad5424":{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy","displayName":"Microsoft Edge management service policy overrides platform policy.","description":"If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy.\n\nIf you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.\n\nThis mandatory policy affects machine scope cloud-based Microsoft Edge management policies.\n\nMachine policies apply to all edge browser instances regardless of the user who is logged in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementpolicyoverridesplatformpolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy_true","displayName":"Enabled","description":null,"helpText":null}]},"bfa69bb7f6d0c65d":{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader","description":"Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration isn't available.\n\nWhen enabled, Microsoft Edge uses SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines.\n\nStarting in Microsoft Edge version 144, SwiftShader has been deprecated due to security concerns. As a result, WebGL context creation fails in scenarios where SwiftShader would have been used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader.\n\nIf you disable or don't configure this policy, WebGL context creation may fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it doesn't handle context creation failures.\n\nNote: This policy is temporary and scheduled for removal in a future release. Microsoft does not guarantee the security of environments where this policy is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableunsafeswiftshader"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader_true","displayName":"Enabled","description":null,"helpText":null}]},"bfd65eb242a4f467":{"id":"com.apple.managedclient.preferences_screencaptureallowed","displayName":"Allow or deny screen capture","description":"If you enable this policy, or don't configure this policy, a web page can use screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\nIf you disable this policy, calls to screen-share APIs will fail. For example, if you're using a web-based online meeting, video or screen sharing will not work.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencaptureallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_screencaptureallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_screencaptureallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"bf029460664d9e15":{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\n\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\n\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\n\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sendsiteinfotoimproveservices"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices_true","displayName":"Enabled","description":null,"helpText":null}]},"bf82ad0173e32ef0":{"id":"com.apple.managedclient.preferences_sharepointonpremtenantname","displayName":"SharePoint Server Tenant Name","description":"Specifies the name of the folder created for syncing the SharePoint Server 2019 files specified in the Front Door URL.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremtenantname"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},"bf8ae0dbefabae1e":{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked","displayName":"Printer Locked","description":"If true, locks the printer.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked_true","displayName":"True","description":null,"helpText":null}]},"bf5efbb151a67984":{"id":"com.apple.system-extension-policy_removablesystemextensions_generickey","displayName":"Removable System Extensions","description":"The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"bfcc8dab78c092f1":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled","displayName":"Enable Workspaces","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\n\nIf you enable or don't configure this policy, users can access the Microsoft Edge Workspaces feature.\nIf you disable this policy, users won't be able to access the Microsoft Edge Workspaces feature.\n\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":null,"infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"bf38c7b2c41d5bff":{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled","displayName":"Automatically open Copilot side pane with contextual insights for links opened from Outlook","description":"This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open eligible web links from Outlook emails sent from the same tenant.\n\nStarting in Microsoft Edge version 148, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.\n\nIf you enable this policy or don't configure it, the Copilot side pane opens automatically when users open eligible links from Outlook emails sent from the same tenant.\n\nIf you disable this policy, the Copilot side pane doesn't open automatically for those links.\n\nThis policy is not yet supported. When support becomes available, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"bf0cc20172be8ae0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled","displayName":"Microsoft Edge Insider Promotion Enabled","description":"Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page.\n\nIf you enable or don't configure this policy, the Microsoft Edge Insider promotion content is shown on the About Microsoft Edge page.\n\nIf you disable this policy, the Microsoft Edge Insider promotion content isn't shown on the About Microsoft Edge page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"bfe14d406f9f2872":{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry","displayName":"Turn off Application Telemetry","description":"The policy controls the state of the Application Telemetry engine in the system.\r\n\r\nApplication Telemetry is a mechanism that tracks anonymous usage of specific Windows system components by applications.\r\n\r\nTurning Application Telemetry off by selecting \"enable\" will stop the collection of usage data.\r\n\r\nIf the customer Experience Improvement program is turned off, Application Telemetry will be turned off regardless of how this policy is set.\r\n\r\nDisabling telemetry will take effect on any newly launched applications. To ensure that telemetry collection has stopped for all applications, please reboot your machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffapplicationimpacttelemetry"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry_1","displayName":"Enabled","description":null,"helpText":null}]},"bf416a660ec1c16e":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_6","displayName":"Saturday","description":null,"helpText":null}]},"bf4e09afdfb92cb5":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_dumppath_edit","displayName":"Corporate upload file path:","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":null},"bfb4b723d488f273":{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters","displayName":"Events.asp program command line parameters","description":"This specifies the command line parameters that will be passed to the events.asp program\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventviewer#admx-eventviewer-eventviewer-redirectionprogramcommandlineparameters"],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":[{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_1","displayName":"Enabled","description":null,"helpText":null}]},"bfb55a1b6e1916c7":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation","displayName":"Define security intelligence location for VDI clients.","description":"This policy setting allows you to define the security intelligence location for VDI-configured computers. \r\n\r\n If you disable or do not configure this setting, security intelligence will be referred from the default local source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-sharedsignatureslocation"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_1","displayName":"Enabled","description":null,"helpText":null}]},"bfc7ede8be82f64d":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},"bfc0b6ec6842571c":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_teredorefreshratebox","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},"bf49a26973509975":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings","displayName":"Roaming Credentials","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_1","displayName":"True","description":null,"helpText":null}]},"bff47700a4e48455":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync","displayName":"Microsoft Lync 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Lync 2016.\r\nBy default, the user settings of Microsoft Lync 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Lync 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync_1","displayName":"Enabled","description":null,"helpText":null}]},"bfe1c15a5d650521":{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2","displayName":"Prohibit installing or uninstalling color profiles","description":"This policy setting affects the ability of users to install or uninstall color profiles.\r\n\r\nIf you enable this policy setting, users cannot install new color profiles or uninstall previously installed color profiles.\r\n\r\nIf you disable or do not configure this policy setting, all users can install new color profiles. Standard users can uninstall color profiles that they previously installed. Administrators will be able to uninstall all color profiles.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowscolorsystem#admx-windowscolorsystem-prohibitchanginginstalledprofilelist-2"],"categoryId":"444409a4-8b03-402d-91d0-1cd9565fb0fb","categoryName":"Windows Color System","options":[{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2_1","displayName":"Enabled","description":null,"helpText":null}]},"bf8bb70e14103ba4":{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation","displayName":"Account Logon Audit Credential Validation","description":"This policy setting allows you to audit events generated by validation tests on user account logon credentials. Events in this subcategory occur only on the computer that is authoritative for those credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditcredentialvalidation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"bf6117579eb279a6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability","displayName":"Control where Developer Tools can be used","description":"Setting the policy to 0 (the default) means you can access the developer tools and the JavaScript console, but not in the context of extensions installed by enterprise policy. Setting the policy to 1 means you can access the developer tools and the JavaScript console in all contexts, including that of extensions installed by enterprise policy. Setting the policy to 2 means you can't acess developer tools, and you can't inspect website elements.\r\n\r\nThis setting also turns off keyboard shortcuts and menu or context menu entries to open developer tools or the JavaScript console.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"bf05436998fb70df":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":null},"bf7e868191c6de9e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo","displayName":"Prevent app promotions from appearing on the new tab page","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo_1","displayName":"Enabled","description":null,"helpText":null}]},"bf9ae0385b3b8535":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability","displayName":"Enable Battery Saver Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_0","displayName":"Battery Saver Mode will be disabled.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_1","displayName":"Battery Saver Mode will be enabled when the device is on battery power and battery level is low.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_2","displayName":"This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.","description":null,"helpText":null}]},"bfd3450b2cfb0ba4":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockcredentialstealingfromwindowslocalsecurityauthoritysubsystem_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"bfdddad172cccab5":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},"bfec044fd47d56bb":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\r\n\r\nIf you don't configure this policy, no app is forced to be shown in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be shown.\r\n\r\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"bf897f08e60ad615":{"id":"device_vendor_msft_policy_config_microsoft_edgev88.0.705.23~policy~microsoft_edge_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 102.\r\n\r\nIf you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel=\"opener\".\r\n\r\nIf you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88.0.705.23~policy~microsoft_edge_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88.0.705.23~policy~microsoft_edge_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},"bf6a36562f3eadc2":{"id":"device_vendor_msft_policy_config_mixedreality_autologonuser","displayName":"Auto Logon User","description":"This policy controls whether a user will be automatically logged on. When the policy is set to a non-empty value, it specifies the email address of the auto-logon user. The specified user must logon to the device at least once to enable auto-logon.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#autologonuser"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":null},"bf481c79a9fe93c4":{"id":"device_vendor_msft_policy_config_mixedreality_disallownetworkconnectivitypassivepolling","displayName":"Disallow Network Connectivity Passive Polling","description":"Network Connection Status Indicator (NCSI) detects Internet connectivity and corporate network connectivity status. This policy allows IT admins to disable NCSI passive polling. Value type is integer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#disallownetworkconnectivitypassivepolling"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_disallownetworkconnectivitypassivepolling_0","displayName":"Allowed.","description":"Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_disallownetworkconnectivitypassivepolling_1","displayName":"Not allowed.","description":"Not allowed.","helpText":null}]},"bf389003e00896eb":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_msaccessexe137","displayName":"msaccess.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_msaccessexe137_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_msaccessexe137_1","displayName":"True","description":null,"helpText":null}]},"bfef0102257573e9":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_visioexe61","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_visioexe61_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_visioexe61_1","displayName":"True","description":null,"helpText":null}]},"bf694ed81efdd39f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_visioexe103","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_visioexe103_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_visioexe103_1","displayName":"True","description":null,"helpText":null}]},"bf7fb99c2a7807b6":{"id":"device_vendor_msft_policy_config_start_allowpinnedfoldersettings","displayName":"Allow Pinned Folder Settings","description":"This policy controls the visibility of the Settings shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#allowpinnedfoldersettings"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_allowpinnedfoldersettings_0","displayName":"The shortcut is hidden and disables the setting in the Settings app.","description":"The shortcut is hidden and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfoldersettings_1","displayName":"The shortcut is visible and disables the setting in the Settings app.","description":"The shortcut is visible and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfoldersettings_65535","displayName":"There is no enforced configuration and the setting can be changed by the user.","description":"There is no enforced configuration and the setting can be changed by the user.","helpText":null}]},"bf4e70fc10692e6e":{"id":"keyboardsettings_allowdefinitionlookup","displayName":"Allow Definition Lookup","description":"If `false`, disables definition lookup.","helpText":null,"infoUrls":[],"categoryId":"dba26132-cba6-4178-93c3-f02476532f08","categoryName":"Keyboard Settings","options":[{"id":"keyboardsettings_allowdefinitionlookup_false","displayName":"False","description":null,"helpText":null},{"id":"keyboardsettings_allowdefinitionlookup_true","displayName":"True","description":null,"helpText":null}]},"bf20d692245720fe":{"id":"linux_mdatp_managed_exclusionsettings_exclusions_item_isdirectory","displayName":"Is directory","description":"Directory if selected, or file if not selected","helpText":null,"infoUrls":[],"categoryId":"d2191717-e304-46f7-bcc0-55e6477026c9","categoryName":"Exclusion Settings","options":[{"id":"linux_mdatp_managed_exclusionsettings_exclusions_item_isdirectory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_exclusionsettings_exclusions_item_isdirectory_true","displayName":"Enabled","description":null,"helpText":null}]},"bf8d5947b262791e":{"id":"mathsettings_calculator_basicmode","displayName":"Basic Mode","description":"If present, configures the basic mode of the calculator. Basic mode is always enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":null},"bf45a84940835961":{"id":"passcode_maximumpasscodeageindays","displayName":"Maximum Passcode Age In Days","description":"Specifies the maximum number of days that the passcode can remain unchanged. After this number of days, the system forces the user to change the passcode before it unlocks the device.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":null},"bf39478e38e5ae0d":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting","displayName":"Turn on PowerShell Transcription (User)","description":"\r\n This policy setting lets you capture the input and output of Windows PowerShell commands into text-based transcripts.\r\n\r\n If you enable this policy setting, Windows PowerShell will enable transcripting for Windows PowerShell, the Windows PowerShell ISE, and any other\r\n applications that leverage the Windows PowerShell engine. By default, Windows PowerShell will record transcript output to each users' My Documents\r\n directory, with a file name that includes 'PowerShell_transcript', along with the computer name and time started. Enabling this policy is equivalent\r\n to calling the Start-Transcript cmdlet on each Windows PowerShell session.\r\n\r\n If you disable this policy setting, transcripting of PowerShell-based applications is disabled by default, although transcripting can still be enabled\r\n through the Start-Transcript cmdlet.\r\n \r\n If you use the OutputDirectory setting to enable transcript logging to a shared location, be sure to limit access to that directory to prevent users\r\n from viewing the transcripts of other users or computers.\r\n\r\n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enabletranscripting"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_1","displayName":"Enabled","description":null,"helpText":null}]},"bffe2d17cf04c030":{"id":"user_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_packagepointandprintserverlist_edit","displayName":"Enter fully qualified server names (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},"bfde8e6ef82b1247":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_1","displayName":"Allow .rdp files from unknown publishers (User)","description":"This policy setting allows you to specify whether users can run unsigned Remote Desktop Protocol (.rdp) files and .rdp files from unknown publishers on the client computer.\r\n\r\nIf you enable or do not configure this policy setting, users can run unsigned .rdp files and .rdp files from unknown publishers on the client computer. Before a user starts an RDP session, the user receives a warning message and is asked to confirm whether they want to connect.\r\n\r\nIf you disable this policy setting, users cannot run unsigned .rdp files and .rdp files from unknown publishers on the client computer. If the user tries to start an RDP session, the user receives a message that the publisher has been blocked.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-allow-unsigned-files-1"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_1_1","displayName":"Enabled","description":null,"helpText":null}]},"bfe7b953e416d6ec":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_enforceshellextensionsecurity","displayName":"Allow only per user or approved shell extensions (User)","description":"This setting is designed to ensure that shell extensions can operate on a per-user basis. If you enable this setting, Windows is directed to only run those shell extensions that have either been approved by an administrator or that will not impact other users of the machine.\r\n\r\nA shell extension only runs if there is an entry in at least one of the following locations in registry.\r\n\r\nFor shell extensions that have been approved by the administrator and are available to all users of the computer, there must be an entry at HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved.\r\n\r\nFor shell extensions to run on a per-user basis, there must be an entry at HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enforceshellextensionsecurity"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_enforceshellextensionsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_enforceshellextensionsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},"bfa28e4e139e0251":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nocachethumbnailpictures","displayName":"Turn off caching of thumbnail pictures (User)","description":"This policy setting allows you to turn off caching of thumbnail pictures.\r\n\r\nIf you enable this policy setting, thumbnail views are not cached.\r\n\r\nIf you disable or do not configure this policy setting, thumbnail views are cached.\r\n\r\nNote: For shared corporate workstations or computers where security is a top concern, you should enable this policy setting to turn off the thumbnail view cache, because the thumbnail cache can be read by everyone.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nocachethumbnailpictures"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nocachethumbnailpictures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nocachethumbnailpictures_1","displayName":"Enabled","description":null,"helpText":null}]},"bf3a4d88eacbf20e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled","displayName":"Enable Media Recommendations (User)","description":"By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bf5bf82f810705a2":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_keygenblockedforurlsdesc","displayName":"Block key generation on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"bf4933e0b73cdf7b":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled","displayName":"Control new behavior for the cancel dialog produced by the beforeunload event (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bf0462d468ff2de8":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission (User)","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices. Note, however, that the pattern \"*\", which matches any URL, is not supported by this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com/\r\nhttps://[*.]contoso.edu/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},"bf6ce8deb3f63fb8":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist","displayName":"Allow access to a list of URLs in InPrivate mode. (User)","description":"This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.). See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322).\r\n\r\nIf both this policy and 'InPrivateModeUrlBlocklist' are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs).\r\n\r\nIf this policy is configured and 'InPrivateModeUrlBlocklist' is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked.\r\n\r\nIf 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist.\r\n\r\nIf this policy is not configured, no exceptions are applied to 'InPrivateModeUrlBlocklist' or 'InPrivateModeAvailability'.\r\n\r\nThis policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the 'URLAllowlist' policy.\r\n\r\nThis policy supports up to 1000 entries.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"bf7c77643b922b3f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink","displayName":"With just a simple Web discussions link (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},"bf2e47c817c8dbce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_l_withjustasimplewebdiscussionslink377","displayName":"With just a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},"bf1c13797736fae8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_l_defaultsaveprompttext352","displayName":"Default save prompt text (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},"bfbbd69913e08e50":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance","displayName":"French (France) (User)","description":"Enables the editing language French (France)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance_1","displayName":"Enabled","description":null,"helpText":null}]},"bfe64488038416c4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime","displayName":"Do not track document editing time (User)","description":"Checked: Do not calculate the total editing time while a document is open. | Unchecked: Track the editing time while a document is open.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime_1","displayName":"Enabled","description":null,"helpText":null}]},"bff89231caece242":{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals","displayName":"Interval between new Outlook migration attempts (User)","description":"This policy setting controls the interval between new Outlook migration attempts.\r\n\r\nIf you don't set this or set this to 0 (default value), classic Outlook will stop executing \"New Outlook auto migration\" after the user toggles back to classic Outlook for Windows.\r\n\r\nIf you set this to 1, classic Outlook will show a blocking prompt on each app launch, which will attempt to switch the user to the new Outlook app.\r\n\r\nIf you set this to N (2 - 9900) value, \"New Outlook auto migration\" will be re-initiated N days after the user toggles back to classic Outlook.\r\n\r\nNote: This policy only applies to subscription-based Microsoft 365 Apps.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_1","displayName":"Enabled","description":null,"helpText":null}]},"bf91ab960ec301a3":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance","displayName":"Set importance: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_2","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_1","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_0","displayName":"Low","description":null,"helpText":null}]},"bf962de95770b904":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear","displayName":"First week of year (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_1","displayName":"Enabled","description":null,"helpText":null}]},"bff3264da68d1d4b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"bf03a574136d1205":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts","displayName":"Allow embedded TrueType fonts to be sent in messages (User)","description":"\r\n This policy setting controls whether embedded TrueType fonts can be sent in messages.\r\n\r\n By default, embedded TrueType fonts aren't allowed in messages. Allowing embedded TrueType fonts Isn't recommended because of security concerns.\r\n\r\n If you enable this policy setting, embedded TrueType fonts can be sent in messages.\r\n\r\n If you disable or don’t configure this policy setting, embedded TrueType fonts can't be sent in messages.\r\n ","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"bff0c17cf8ce0938":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft defender atp.app_application id","displayName":"Microsoft Defender ATP Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"bff7270142ad5424":{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy","displayName":"Microsoft Edge management service policy overrides platform policy.","description":"If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy.\n\nIf you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.\n\nThis mandatory policy affects machine scope cloud-based Microsoft Edge management policies.\n\nMachine policies apply to all edge browser instances regardless of the user who is logged in.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementpolicyoverridesplatformpolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementpolicyoverridesplatformpolicy_true","displayName":"Enabled","description":null,"helpText":null}]},"bfa69bb7f6d0c65d":{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader","displayName":"Allow software WebGL fallback using SwiftShader","description":"Controls whether SwiftShader is used as a fallback for WebGL when hardware GPU acceleration isn't available.\n\nWhen enabled, Microsoft Edge uses SwiftShader to support WebGL on systems without GPU acceleration, such as headless environments or virtual machines.\n\nStarting in Microsoft Edge version 144, SwiftShader has been deprecated due to security concerns. As a result, WebGL context creation fails in scenarios where SwiftShader would have been used. Enabling this policy allows organizations to temporarily defer the deprecation and continue using SwiftShader.\n\nIf you disable or don't configure this policy, WebGL context creation may fail on systems without hardware acceleration. This could cause web content relying on WebGL to function incorrectly if it doesn't handle context creation failures.\n\nNote: This policy is temporary and scheduled for removal in a future release. Microsoft does not guarantee the security of environments where this policy is enabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableunsafeswiftshader"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableunsafeswiftshader_true","displayName":"Enabled","description":null,"helpText":null}]},"bfd65eb242a4f467":{"id":"com.apple.managedclient.preferences_screencaptureallowed","displayName":"Allow or deny screen capture","description":"If you enable this policy, or don't configure this policy, a web page can use screen-share APIs (for example, getDisplayMedia() or the Desktop Capture extension API) for a screen capture.\nIf you disable this policy, calls to screen-share APIs will fail. For example, if you're using a web-based online meeting, video or screen sharing will not work.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencaptureallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_screencaptureallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_screencaptureallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"bf029460664d9e15":{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\n\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\n\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\n\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\n\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#sendsiteinfotoimproveservices"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sendsiteinfotoimproveservices_true","displayName":"Enabled","description":null,"helpText":null}]},"bf82ad0173e32ef0":{"id":"com.apple.managedclient.preferences_sharepointonpremtenantname","displayName":"SharePoint Server Tenant Name","description":"Specifies the name of the folder created for syncing the SharePoint Server 2019 files specified in the Front Door URL.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremtenantname"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},"bf8ae0dbefabae1e":{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked","displayName":"Printer Locked","description":"If true, locks the printer.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":[{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxprinting_userprinterlist_printer_printerlocked_true","displayName":"True","description":null,"helpText":null}]},"bf5efbb151a67984":{"id":"com.apple.system-extension-policy_removablesystemextensions_generickey","displayName":"Removable System Extensions","description":"The dictionary maps team identifiers (keys) to arrays of bundle identifiers, where the bundle identifier defines the system extension.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"bfcc8dab78c092f1":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled","displayName":"Enable Workspaces","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\n\nIf you enable or don't configure this policy, users can access the Microsoft Edge Workspaces feature.\nIf you disable this policy, users won't be able to access the Microsoft Edge Workspaces feature.\n\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":null,"infoUrls":[],"categoryId":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","categoryName":"Edge Workspaces settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgeworkspacesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"bf38c7b2c41d5bff":{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled","displayName":"Automatically open Copilot side pane with contextual insights for links opened from Outlook","description":"This policy controls whether Microsoft Edge automatically opens the Microsoft Copilot side pane when users open eligible web links from Outlook emails sent from the same tenant.\n\nStarting in Microsoft Edge version 148, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane. Copilot can use the originating Outlook email as context to surface relevant insights and suggested next steps alongside the web content.\n\nIf you enable this policy or don't configure it, the Copilot side pane opens automatically when users open eligible links from Outlook emails sent from the same tenant.\n\nIf you disable this policy, the Copilot side pane doesn't open automatically for those links.\n\nThis policy is not yet supported. When support becomes available, eligible links from Outlook emails sent from the same tenant can open with the Copilot side pane.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365linksautoopencopilotenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"bf0cc20172be8ae0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled","displayName":"Microsoft Edge Insider Promotion Enabled","description":"Shows content promoting the Microsoft Edge Insider channels on the About Microsoft Edge settings page.\n\nIf you enable or don't configure this policy, the Microsoft Edge Insider promotion content is shown on the About Microsoft Edge page.\n\nIf you disable this policy, the Microsoft Edge Insider promotion content isn't shown on the About Microsoft Edge page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.microsoftedgeinsiderpromotionenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"bf9d6b02c12ee01f":{"id":"contentcaching_localsubnetsonly","displayName":"Local Subnets Only","description":"If `true`, the content cache offers content to clients only on the same immediate local network only. The content cache offers no content to clients on other networks reachable by the content cache. If `LocalSubnetsOnly` is `true`, the system ignores `ListenRanges`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_localsubnetsonly_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_localsubnetsonly_true","displayName":"Enabled","description":null,"helpText":null}]},"bfe14d406f9f2872":{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry","displayName":"Turn off Application Telemetry","description":"The policy controls the state of the Application Telemetry engine in the system.\r\n\r\nApplication Telemetry is a mechanism that tracks anonymous usage of specific Windows system components by applications.\r\n\r\nTurning Application Telemetry off by selecting \"enable\" will stop the collection of usage data.\r\n\r\nIf the customer Experience Improvement program is turned off, Application Telemetry will be turned off regardless of how this policy is set.\r\n\r\nDisabling telemetry will take effect on any newly launched applications. To ensure that telemetry collection has stopped for all applications, please reboot your machine.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffapplicationimpacttelemetry"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffapplicationimpacttelemetry_1","displayName":"Enabled","description":null,"helpText":null}]},"bf416a660ec1c16e":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto","displayName":"To","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_0","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_1","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_4","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_5","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_maintenance_bits_maintenancedaysto_6","displayName":"Saturday","description":null,"helpText":null}]},"bf4e09afdfb92cb5":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_dumppath_edit","displayName":"Corporate upload file path:","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":null},"bfb4b723d488f273":{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters","displayName":"Events.asp program command line parameters","description":"This specifies the command line parameters that will be passed to the events.asp program\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventviewer#admx-eventviewer-eventviewer-redirectionprogramcommandlineparameters"],"categoryId":"3453c694-bc38-4082-9d3d-886e385df927","categoryName":"Event Viewer","options":[{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventviewer_eventviewer_redirectionprogramcommandlineparameters_1","displayName":"Enabled","description":null,"helpText":null}]},"bfb55a1b6e1916c7":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation","displayName":"Define security intelligence location for VDI clients.","description":"This policy setting allows you to define the security intelligence location for VDI-configured computers. \r\n\r\n If you disable or do not configure this setting, security intelligence will be referred from the default local source.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-sharedsignatureslocation"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_sharedsignatureslocation_1","displayName":"Enabled","description":null,"helpText":null}]},"bfc7ede8be82f64d":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypecontrolledload_c_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":null},"bfc0b6ec6842571c":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_refresh_rate_teredorefreshratebox","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},"bf49a26973509975":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings","displayName":"Roaming Credentials","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_disablewindowsossettings_roamingcredentialsettings_1","displayName":"True","description":null,"helpText":null}]},"bff47700a4e48455":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync","displayName":"Microsoft Lync 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Lync 2016.\r\nBy default, the user settings of Microsoft Lync 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft Lync 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft Lync 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft Lync 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016lync"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016lync_1","displayName":"Enabled","description":null,"helpText":null}]},"bfe1c15a5d650521":{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2","displayName":"Prohibit installing or uninstalling color profiles","description":"This policy setting affects the ability of users to install or uninstall color profiles.\r\n\r\nIf you enable this policy setting, users cannot install new color profiles or uninstall previously installed color profiles.\r\n\r\nIf you disable or do not configure this policy setting, all users can install new color profiles. Standard users can uninstall color profiles that they previously installed. Administrators will be able to uninstall all color profiles.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowscolorsystem#admx-windowscolorsystem-prohibitchanginginstalledprofilelist-2"],"categoryId":"444409a4-8b03-402d-91d0-1cd9565fb0fb","categoryName":"Windows Color System","options":[{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_2_1","displayName":"Enabled","description":null,"helpText":null}]},"bf8bb70e14103ba4":{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation","displayName":"Account Logon Audit Credential Validation","description":"This policy setting allows you to audit events generated by validation tests on user account logon credentials. Events in this subcategory occur only on the computer that is authoritative for those credentials. For domain accounts, the domain controller is authoritative. For local accounts, the local computer is authoritative.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogon_auditcredentialvalidation"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogon_auditcredentialvalidation_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"bf6117579eb279a6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability","displayName":"Control where Developer Tools can be used","description":"Setting the policy to 0 (the default) means you can access the developer tools and the JavaScript console, but not in the context of extensions installed by enterprise policy. Setting the policy to 1 means you can access the developer tools and the JavaScript console in all contexts, including that of extensions installed by enterprise policy. Setting the policy to 2 means you can't acess developer tools, and you can't inspect website elements.\r\n\r\nThis setting also turns off keyboard shortcuts and menu or context menu entries to open developer tools or the JavaScript console.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_developertoolsavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"bf05436998fb70df":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_defaultsearchproviderinstanturlpostparams_recommended_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":null},"bf7e868191c6de9e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo","displayName":"Prevent app promotions from appearing on the new tab page","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_hidewebstorepromo_1","displayName":"Enabled","description":null,"helpText":null}]},"bf9ae0385b3b8535":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability","displayName":"Enable Battery Saver Mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_0","displayName":"Battery Saver Mode will be disabled.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_1","displayName":"Battery Saver Mode will be enabled when the device is on battery power and battery level is low.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_recommended_batterysavermodeavailability_recommended_batterysavermodeavailability_2","displayName":"This value is deprecated as of M121. In M121 and after, values will be treated as EnabledBelowThreshold.","description":null,"helpText":null}]},"bfd3450b2cfb0ba4":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockcredentialstealingfromwindowslocalsecurityauthoritysubsystem_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"bfdddad172cccab5":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~nativemessaging_nativemessagingblocklist_nativemessagingblocklistdesc","displayName":"Names of the forbidden native messaging hosts (or * for all) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":null},"bfec044fd47d56bb":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\r\n\r\nIf you don't configure this policy, no app is forced to be shown in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be shown.\r\n\r\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"bf897f08e60ad615":{"id":"device_vendor_msft_policy_config_microsoft_edgev88.0.705.23~policy~microsoft_edge_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 102.\r\n\r\nIf you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel=\"opener\".\r\n\r\nIf you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88.0.705.23~policy~microsoft_edge_targetblankimpliesnoopener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88.0.705.23~policy~microsoft_edge_targetblankimpliesnoopener_1","displayName":"Enabled","description":null,"helpText":null}]},"bf6a36562f3eadc2":{"id":"device_vendor_msft_policy_config_mixedreality_autologonuser","displayName":"Auto Logon User","description":"This policy controls whether a user will be automatically logged on. When the policy is set to a non-empty value, it specifies the email address of the auto-logon user. The specified user must logon to the device at least once to enable auto-logon.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#autologonuser"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":null},"bf481c79a9fe93c4":{"id":"device_vendor_msft_policy_config_mixedreality_disallownetworkconnectivitypassivepolling","displayName":"Disallow Network Connectivity Passive Polling","description":"Network Connection Status Indicator (NCSI) detects Internet connectivity and corporate network connectivity status. This policy allows IT admins to disable NCSI passive polling. Value type is integer.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#disallownetworkconnectivitypassivepolling"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_disallownetworkconnectivitypassivepolling_0","displayName":"Allowed.","description":"Allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_disallownetworkconnectivitypassivepolling_1","displayName":"Not allowed.","description":"Not allowed.","helpText":null}]},"bf389003e00896eb":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_msaccessexe137","displayName":"msaccess.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_msaccessexe137_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_disableusernameandpassword_l_msaccessexe137_1","displayName":"True","description":null,"helpText":null}]},"bfef0102257573e9":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_visioexe61","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_visioexe61_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_visioexe61_1","displayName":"True","description":null,"helpText":null}]},"bf694ed81efdd39f":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_visioexe103","displayName":"visio.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_visioexe103_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_visioexe103_1","displayName":"True","description":null,"helpText":null}]},"bf7fb99c2a7807b6":{"id":"device_vendor_msft_policy_config_start_allowpinnedfoldersettings","displayName":"Allow Pinned Folder Settings","description":"This policy controls the visibility of the Settings shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#allowpinnedfoldersettings"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_allowpinnedfoldersettings_0","displayName":"The shortcut is hidden and disables the setting in the Settings app.","description":"The shortcut is hidden and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfoldersettings_1","displayName":"The shortcut is visible and disables the setting in the Settings app.","description":"The shortcut is visible and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfoldersettings_65535","displayName":"There is no enforced configuration and the setting can be changed by the user.","description":"There is no enforced configuration and the setting can be changed by the user.","helpText":null}]},"bf4e70fc10692e6e":{"id":"keyboardsettings_allowdefinitionlookup","displayName":"Allow Definition Lookup","description":"If `false`, disables definition lookup.","helpText":null,"infoUrls":[],"categoryId":"dba26132-cba6-4178-93c3-f02476532f08","categoryName":"Keyboard Settings","options":[{"id":"keyboardsettings_allowdefinitionlookup_false","displayName":"False","description":null,"helpText":null},{"id":"keyboardsettings_allowdefinitionlookup_true","displayName":"True","description":null,"helpText":null}]},"bf20d692245720fe":{"id":"linux_mdatp_managed_exclusionsettings_exclusions_item_isdirectory","displayName":"Is directory","description":"Directory if selected, or file if not selected","helpText":null,"infoUrls":[],"categoryId":"d2191717-e304-46f7-bcc0-55e6477026c9","categoryName":"Exclusion Settings","options":[{"id":"linux_mdatp_managed_exclusionsettings_exclusions_item_isdirectory_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_exclusionsettings_exclusions_item_isdirectory_true","displayName":"Enabled","description":null,"helpText":null}]},"bf8d5947b262791e":{"id":"mathsettings_calculator_basicmode","displayName":"Basic Mode","description":"If present, configures the basic mode of the calculator. Basic mode is always enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":null},"bf45a84940835961":{"id":"passcode_maximumpasscodeageindays","displayName":"Maximum Passcode Age In Days","description":"Specifies the maximum number of days that the passcode can remain unchanged. After this number of days, the system forces the user to change the passcode before it unlocks the device.","helpText":null,"infoUrls":[],"categoryId":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","categoryName":"Passcode","options":null},"bf39478e38e5ae0d":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting","displayName":"Turn on PowerShell Transcription (User)","description":"\r\n This policy setting lets you capture the input and output of Windows PowerShell commands into text-based transcripts.\r\n\r\n If you enable this policy setting, Windows PowerShell will enable transcripting for Windows PowerShell, the Windows PowerShell ISE, and any other\r\n applications that leverage the Windows PowerShell engine. By default, Windows PowerShell will record transcript output to each users' My Documents\r\n directory, with a file name that includes 'PowerShell_transcript', along with the computer name and time started. Enabling this policy is equivalent\r\n to calling the Start-Transcript cmdlet on each Windows PowerShell session.\r\n\r\n If you disable this policy setting, transcripting of PowerShell-based applications is disabled by default, although transcripting can still be enabled\r\n through the Start-Transcript cmdlet.\r\n \r\n If you use the OutputDirectory setting to enable transcript logging to a shared location, be sure to limit access to that directory to prevent users\r\n from viewing the transcripts of other users or computers.\r\n\r\n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enabletranscripting"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enabletranscripting_1","displayName":"Enabled","description":null,"helpText":null}]},"bffe2d17cf04c030":{"id":"user_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_packagepointandprintserverlist_edit","displayName":"Enter fully qualified server names (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":null},"bfde8e6ef82b1247":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_1","displayName":"Allow .rdp files from unknown publishers (User)","description":"This policy setting allows you to specify whether users can run unsigned Remote Desktop Protocol (.rdp) files and .rdp files from unknown publishers on the client computer.\r\n\r\nIf you enable or do not configure this policy setting, users can run unsigned .rdp files and .rdp files from unknown publishers on the client computer. Before a user starts an RDP session, the user receives a warning message and is asked to confirm whether they want to connect.\r\n\r\nIf you disable this policy setting, users cannot run unsigned .rdp files and .rdp files from unknown publishers on the client computer. If the user tries to start an RDP session, the user receives a message that the publisher has been blocked.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-allow-unsigned-files-1"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_allow_unsigned_files_1_1","displayName":"Enabled","description":null,"helpText":null}]},"bfe7b953e416d6ec":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_enforceshellextensionsecurity","displayName":"Allow only per user or approved shell extensions (User)","description":"This setting is designed to ensure that shell extensions can operate on a per-user basis. If you enable this setting, Windows is directed to only run those shell extensions that have either been approved by an administrator or that will not impact other users of the machine.\r\n\r\nA shell extension only runs if there is an entry in at least one of the following locations in registry.\r\n\r\nFor shell extensions that have been approved by the administrator and are available to all users of the computer, there must be an entry at HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved.\r\n\r\nFor shell extensions to run on a per-user basis, there must be an entry at HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enforceshellextensionsecurity"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_enforceshellextensionsecurity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_enforceshellextensionsecurity_1","displayName":"Enabled","description":null,"helpText":null}]},"bfa28e4e139e0251":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nocachethumbnailpictures","displayName":"Turn off caching of thumbnail pictures (User)","description":"This policy setting allows you to turn off caching of thumbnail pictures.\r\n\r\nIf you enable this policy setting, thumbnail views are not cached.\r\n\r\nIf you disable or do not configure this policy setting, thumbnail views are cached.\r\n\r\nNote: For shared corporate workstations or computers where security is a top concern, you should enable this policy setting to turn off the thumbnail view cache, because the thumbnail cache can be read by everyone.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nocachethumbnailpictures"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nocachethumbnailpictures_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nocachethumbnailpictures_1","displayName":"Enabled","description":null,"helpText":null}]},"bf3a4d88eacbf20e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled","displayName":"Enable Media Recommendations (User)","description":"By default the browser will show media recommendations that are personalized to the user. Setting this policy to Disabled will result in these recommendations being hidden from the user. Setting this policy to Enabled or leaving it unset will result in the media recommendations being shown to the user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_mediarecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bf5bf82f810705a2":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_keygenblockedforurls_keygenblockedforurlsdesc","displayName":"Block key generation on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"bf4933e0b73cdf7b":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled","displayName":"Control new behavior for the cancel dialog produced by the beforeunload event (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_beforeunloadeventcancelbypreventdefaultenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"bf0462d468ff2de8":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission (User)","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices. Note, however, that the pattern \"*\", which matches any URL, is not supported by this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com/\r\nhttps://[*.]contoso.edu/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_audiocaptureallowedurls_1","displayName":"Enabled","description":null,"helpText":null}]},"bf6ce8deb3f63fb8":{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist","displayName":"Allow access to a list of URLs in InPrivate mode. (User)","description":"This policy allows administrators to specify a list of URL patterns that are permitted to open in InPrivate mode. It can be used to create exceptions for URL patterns defined in 'InPrivateModeUrlBlocklist' (Block access to a list of URLs in InPrivate mode.). See how to format a URL pattern (https://go.microsoft.com/fwlink/?linkid=2095322).\r\n\r\nIf both this policy and 'InPrivateModeUrlBlocklist' are configured, the allowlist takes precedence. URLs that match a pattern on this allowlist are allowed. URLs that match the blocklist but not this allowlist are blocked. URLs that match neither list fall back to 'URLBlocklist' (Block access to a list of URLs) and 'URLAllowlist' (Define a list of allowed URLs).\r\n\r\nIf this policy is configured and 'InPrivateModeUrlBlocklist' is not configured, only the URLs specified in this allowlist can be opened in InPrivate mode. All other URLs are blocked.\r\n\r\nIf 'InPrivateModeAvailability' (Configure InPrivate mode availability) is set to disallow (value 1) but this policy is configured, InPrivate mode is available only for URLs that match the allowlist.\r\n\r\nIf this policy is not configured, no exceptions are applied to 'InPrivateModeUrlBlocklist' or 'InPrivateModeAvailability'.\r\n\r\nThis policy applies only to InPrivate mode. To allow URLs across all browsing modes and profiles, use the 'URLAllowlist' policy.\r\n\r\nThis policy supports up to 1000 entries.\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/bad_path\r\nhttps://server:8080/path\r\n.exact.hostname.com\r\nfile://*\r\ncustom_scheme:*\r\n*","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_inprivatemodeurlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"bf7c77643b922b3f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink","displayName":"With just a simple Web discussions link (User)","description":"Defines the default message body text used in a reply to an email request for review when the reply contains a simple Web discussions link. ","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},"bf2e47c817c8dbce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareply_l_withjustasimplewebdiscussionslink_l_withjustasimplewebdiscussionslink377","displayName":"With just a simple Web discussions link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","categoryName":"Default message text for a reply...","options":null},"bf1c13797736fae8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_defaultsaveprompttext_l_defaultsaveprompttext352","displayName":"Default save prompt text (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},"bfbbd69913e08e50":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance","displayName":"French (France) (User)","description":"Enables the editing language French (France)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_frenchfrance_1","displayName":"Enabled","description":null,"helpText":null}]},"bfe64488038416c4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime","displayName":"Do not track document editing time (User)","description":"Checked: Do not calculate the total editing time while a document is open. | Unchecked: Track the editing time while a document is open.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_donottrackdocumenteditingtime_1","displayName":"Enabled","description":null,"helpText":null}]},"bff89231caece242":{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals","displayName":"Interval between new Outlook migration attempts (User)","description":"This policy setting controls the interval between new Outlook migration attempts.\r\n\r\nIf you don't set this or set this to 0 (default value), classic Outlook will stop executing \"New Outlook auto migration\" after the user toggles back to classic Outlook for Windows.\r\n\r\nIf you set this to 1, classic Outlook will show a blocking prompt on each app launch, which will attempt to switch the user to the new Outlook app.\r\n\r\nIf you set this to N (2 - 9900) value, \"New Outlook auto migration\" will be re-initiated N days after the user toggles back to classic Outlook.\r\n\r\nNote: This policy only applies to subscription-based Microsoft 365 Apps.\r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v14.1~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_newoutlookautomigrationretryintervals_1","displayName":"Enabled","description":null,"helpText":null}]},"bf91ab960ec301a3":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance","displayName":"Set importance: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_2","displayName":"High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_1","displayName":"Normal","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setimportance_l_setimportance_0","displayName":"Low","description":null,"helpText":null}]},"bf962de95770b904":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear","displayName":"First week of year (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstweekofyear_1","displayName":"Enabled","description":null,"helpText":null}]},"bff3264da68d1d4b":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode","displayName":"Configure CNG cipher chaining mode (User)","description":"This policy setting allows you to configure the cipher chaining mode used.\r\n\r\nIf you enable this policy setting, the cipher chaining mode specified will be applied.\r\n\r\nIf you disable or do not configure this policy setting, Cipher Block Chaining (CBC) will be the default CNG cipher chaining mode used.","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_configurecngcipherchainingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"bf03a574136d1205":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts","displayName":"Allow embedded TrueType fonts to be sent in messages (User)","description":"\r\n This policy setting controls whether embedded TrueType fonts can be sent in messages.\r\n\r\n By default, embedded TrueType fonts aren't allowed in messages. Allowing embedded TrueType fonts Isn't recommended because of security concerns.\r\n\r\n If you enable this policy setting, embedded TrueType fonts can be sent in messages.\r\n\r\n If you disable or don’t configure this policy setting, embedded TrueType fonts can't be sent in messages.\r\n ","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowwordmailloadembeddedfonts_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/c4.json b/public/intune-definitions/c4.json index 568f3e9290f4..ef2dd19340bf 100644 --- a/public/intune-definitions/c4.json +++ b/public/intune-definitions/c4.json @@ -1 +1 @@ -{"c4640e6ea1d0d58f":{"id":"ade_setupassistant_osshowcase","displayName":"OS showcase","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_osshowcase_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_osshowcase_1","displayName":"Show","description":null,"helpText":null}]},"c4b2f85ce916f1ff":{"id":"com.android.devicerestrictionpolicy.passwordminimumlength","displayName":"Minimum password length","description":"Enter the minimum number of digits or characters the password must have, between 4 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"c432bea332124cde":{"id":"com.apple.applicationaccess_allowremotescreenobservation","displayName":"Allow Remote Screen Observation","description":"If false, disables remote screen observation by the Classroom app. If Allow Screen Shot is set to false, the Classroom app doesn't observe remote screens. Required a supervised device until iOS 13 and macOS 10.15. Available in iOS 12 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowremotescreenobservation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowremotescreenobservation_true","displayName":"True","description":null,"helpText":null}]},"c48ef45ad6b2e35a":{"id":"com.apple.extensiblesso_platformsso_unlockpolicy","displayName":"Unlock Policy","description":"The policy to apply when using Platform SSO at screensaver unlock. Applies when 'AuthenticationMethod' is `Password`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"c418104abfd92987":{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing","displayName":"Management Allows External Volume Syncing","description":"If `false`, the device only allows File Provider extension volume synchronization for the system \"home\" volume and any data separated volume, and prevents synchronization with any other volumes. If `true``, the device allows File Provider extension volume synchronization for the system \"home\" volume, any data separated volume, and any encrypted APFS volumes (on either internal or external media).","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing_true","displayName":"Allowed","description":null,"helpText":null}]},"c4289e3307b3cd4a":{"id":"com.apple.managedclient.preferences_blockexternalsync","displayName":"Block external sync","description":"Prevents the sync app from syncing libraries and folders shared from other organizations.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#blockexternalsync"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_blockexternalsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockexternalsync_true","displayName":"True","description":null,"helpText":null}]},"c43ecd241d05c784":{"id":"com.apple.managedclient.preferences_channelname","displayName":"Update channel","description":"Specifies the channel to receive updates. The most stable channel is the Current Channel, which is recommended for the majority of your fleet. Users subscribed to the Preview Channel will receive production-quality updates a week before Current Channel users. Users subscribed to the Beta Channel will receive unsupported nightly builds that are designed for testing.","helpText":null,"infoUrls":["https://support.microsoft.com/office/update-office-for-mac-automatically-bfd1e497-c24d-4754-92ab-910a4074d7c1"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_2","displayName":"Current Channel (Deferred)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_3","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_4","displayName":"Current Channel (Monthly)","description":null,"helpText":null}]},"c497a377f1ea1808":{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled","displayName":"Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge","description":"This policy lets you manage whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is turned on.\n\nIf you enable or don't configure this policy, the indicator UI is on.\n\nIf you disable this policy, the indicator UI is off.\n\nNote: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeindicatoruienabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled_true","displayName":"Enabled","description":null,"helpText":null}]},"c47faf40deb76450":{"id":"com.apple.managedclient.preferences_exclusions_item_name","displayName":"Name","description":"Process name, either or full path or file name, wildcards supported","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"c4580bf2c06cac64":{"id":"com.apple.managedclient.preferences_importshortcuts","displayName":"Allow importing of shortcuts","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\n\nIf you disable this policy, Shortcuts aren't imported on first run.\n\nIf you don’t configure this policy, Shortcuts are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\n\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importshortcuts"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importshortcuts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importshortcuts_true","displayName":"Enabled","description":null,"helpText":null}]},"c4e7b98d975bacc6":{"id":"com.apple.managedclient.preferences_precisegeolocationallowedforurls","displayName":"Allow precise geolocation on these sites","description":"This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission.\n\nIf you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used.\n\nFor information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#precisegeolocationallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"c4cfada71245bf2c":{"id":"com.apple.mcx.filevault2_userentersmissinginfo","displayName":"User Enters Missing Info","description":"If true, enables a prompt for missing user name or password fields.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_userentersmissinginfo_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_userentersmissinginfo_true","displayName":"True","description":null,"helpText":null}]},"c4b05234c4395faf":{"id":"device_vendor_msft_pkcscertificate_subjectnameformat","displayName":"Subject name format","description":"CN={{UserName}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US\\nor\\nCN={{AAD_Device_ID}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},"c44e72622a47f467":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3_1","displayName":"True","description":null,"helpText":null}]},"c47636e41a6ce2b5":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions","displayName":"Process Mitigation Options","description":"\r\n This security feature provides a means to override individual process MitigationOptions settings. This can be used to enforce a number of security policies specific to applications. The application name is specified as the Value name, including extension. The Value is specified as a bit field with a series of flags in particular positions. Bits can be set to either 0 (setting is forced off), 1 (setting is forced on), or ? (setting retains its existing value prior to GPO evaluation). The recognized bit locations are:\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE (0x00000001)\r\n Enables data execution prevention (DEP) for the child process\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ATL_THUNK_ENABLE (0x00000002)\r\n Enables DEP-ATL thunk emulation for the child process. DEP-ATL thunk emulation causes the system to intercept NX faults that originate from the Active Template Library (ATL) thunk layer.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_SEHOP_ENABLE (0x00000004)\r\n Enables structured exception handler overwrite protection (SEHOP) for the child process. SEHOP blocks exploits that use the structured exception handler (SEH) overwrite technique.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON (0x00000100)\r\n The force Address Space Layout Randomization (ASLR) policy forcibly rebases images that are not dynamic base compatible by acting as though an image base collision happened at load time. If relocations are required, images that do not have a base relocation section will not be loaded.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_ON (0x00010000)\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF (0x00020000)\r\n The bottom-up randomization policy, which includes stack randomization options, causes a random location to be used as the lowest user address.\r\n\r\n For instance, to enable PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE and PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON, disable PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF, and to leave all other options at their default values, specify a value of:\r\n ???????????????0???????1???????1\r\n\r\n Setting flags not specified here to any value other than ? results in undefined behavior.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-processmitigationoptions"],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"c4a840f7b6de0485":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode","displayName":"Use urgent mode when pinging domain controllers","description":"This policy setting configures whether the computers to which this setting is applied are more aggressive when trying to locate a domain controller (DC).\r\n\r\nWhen an environment has a large number of DCs running both old and new operating systems, the default DC locator discovery behavior may be insufficient to find DCs running a newer operating system. This policy setting can be enabled to configure DC locator to be more aggressive about trying to locate a DC in such an environment, by pinging DCs at a higher frequency. Enabling this setting may result in additional network traffic and increased load on DCs. You should disable this setting once all DCs are running the same OS version.\r\n\r\nThe allowable values for this setting result in the following behaviors:\r\n\r\n1 - Computers will ping DCs at the normal frequency.\r\n2 - Computers will ping DCs at the higher frequency.\r\n\r\nTo specify this behavior, click Enabled and then enter a value. The range of values is from 1 to 2.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-pingurgencymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_1","displayName":"Enabled","description":null,"helpText":null}]},"c489002d0df2f716":{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2","displayName":"Prevent restoring local previous versions","description":"This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a local file.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a local file. If the user clicks the Restore button, Windows attempts to restore the file from the local disk.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a local file.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablelocalrestore-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2_1","displayName":"Enabled","description":null,"helpText":null}]},"c423638f25f4bad7":{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded","displayName":"Allow user name hint","description":"This policy setting lets you determine whether an optional field will be displayed during logon and elevation that allows a user to enter his or her user name or user name and domain, thereby associating a certificate with that user.\r\n\r\nIf you enable this policy setting then an optional field that allows a user to enter their user name or user name and domain will be displayed.\r\n\r\nIf you disable or do not configure this policy setting, an optional field that allows users to enter their user name or user name and domain will not be displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-x509hintsneeded"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded_1","displayName":"Enabled","description":null,"helpText":null}]},"c42c08161f83b64f":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_ts_workdir","displayName":"Working Directory","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},"c494e7f6ed8b4f7c":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_clockadjustmentauditlimit","displayName":"ClockAdjustmentAuditLimit","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"c4ed3dd7b48e8a28":{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_forcedenytheseapps","displayName":"Let Apps Access Cellular Data Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_forcedenytheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},"c4141fda1b815e74":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Setting the policy to True means online OCSP/CRL checks are performed.\r\n\r\nSetting the policy to False or leaving it unset means Google Chrome won't perform online revocation checks in Google Chrome 19 and later.\r\n\r\nNote: OCSP/CRL checks provide no effective security benefit.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks_1","displayName":"Enabled","description":null,"helpText":null}]},"c4639146bba0d91d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy_maxconnectionsperproxy","displayName":"Maximal number of concurrent connections to the proxy server: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"c4caeec544eb3be0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled","displayName":"Enable showing full-tab promotional content","description":"Setting the policy to True or leaving it unset lets Google Chrome show users product information as full-tab content.\r\n\r\nSetting the policy to False prevents Google Chrome from showing product information as full-tab content.\r\n\r\nSetting the policy controls the presentation of the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c427a90fa545f426":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow","displayName":"Set the time interval for relaunch","description":"Specify a target time window for the end of the relaunch notification period.\r\n\r\nUsers are notified of the need for a browser relaunch or device restart based on the RelaunchNotification and RelaunchNotificationPeriod policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the RelaunchNotification policy is set to 'Required'. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window.\r\n\r\nIf this policy is not set, the default target time window for Google Chrome OS is between 2 AM and 4 AM. The default target time window for Google Chrome is the whole day (i.e., the end of the notification period is never deferred).\r\n\r\nNote: Though the policy can accept multiple items in entries, all but the first item are ignored.\r\nWarning: Setting this policy may delay application of software updates.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=RelaunchWindow for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"entries\": [\r\n {\r\n \"start\": {\r\n \"hour\": 2,\r\n \"minute\": 15\r\n },\r\n \"duration_mins\": 240\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_1","displayName":"Enabled","description":null,"helpText":null}]},"c401819246ab133d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting","displayName":"Default notification setting","description":"Setting the policy to 1 lets websites display desktop notifications. Setting the policy to 2 denies desktop notifications.\r\n\r\nLeaving it unset means AskNotifications applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"c4a4e2c7fa0c3352":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin","displayName":"Minimum TLS version to fallback to","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_1","displayName":"Enabled","description":null,"helpText":null}]},"c4f739e3c4848615":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins_fileordirectorypickerwithoutgestureallowedfororiginsdesc","displayName":"Allow file or directory picker APIs to be called without prior user gesture (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"c458e3e771b6009e":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto","displayName":"To:","description":"","helpText":"","infoUrls":[],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":[{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_23","displayName":"11 PM","description":null,"helpText":null}]},"c458be2408fe45d0":{"id":"device_vendor_msft_policy_config_deviceguard_configuresystemguardlaunch","displayName":"Configure System Guard Launch","description":"Secure Launch configuration: 0 - Unmanaged, configurable by Administrative user, 1 - Enables Secure Launch if supported by hardware, 2 - Disables Secure Launch.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#configuresystemguardlaunch"],"categoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","categoryName":"Device Guard","options":[{"id":"device_vendor_msft_policy_config_deviceguard_configuresystemguardlaunch_0","displayName":"Unmanaged Configurable by Administrative user","description":"Unmanaged Configurable by Administrative user","helpText":null},{"id":"device_vendor_msft_policy_config_deviceguard_configuresystemguardlaunch_1","displayName":"Unmanaged Enables Secure Launch if supported by hardware","description":"Unmanaged Enables Secure Launch if supported by hardware","helpText":null},{"id":"device_vendor_msft_policy_config_deviceguard_configuresystemguardlaunch_2","displayName":"Unmanaged Disables Secure Launch","description":"Unmanaged Disables Secure Launch","helpText":null}]},"c469500ea51376ea":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol","displayName":"Allow only approved domains to use the TDC ActiveX control","description":"This policy setting controls whether or not the user is allowed to run the TDC ActiveX control on websites.\n\nIf you enable this policy setting, the TDC ActiveX control will not run from websites in this zone.\n\nIf you disable this policy setting, the TDC Active X control will run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"c4525141bf78def3":{"id":"device_vendor_msft_policy_config_maps_allowofflinemapsdownloadovermeteredconnection","displayName":"Allow Offline Maps Download Over Metered Connection","description":"Allows the download and update of map data over metered connections. After the policy is applied, you can verify the settings in the user interface in System > Offline Maps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Maps#allowofflinemapsdownloadovermeteredconnection"],"categoryId":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","categoryName":"Maps","options":[{"id":"device_vendor_msft_policy_config_maps_allowofflinemapsdownloadovermeteredconnection_0","displayName":"Disabled. Force disable auto-update over metered connection.","description":"Disabled. Force disable auto-update over metered connection.","helpText":null},{"id":"device_vendor_msft_policy_config_maps_allowofflinemapsdownloadovermeteredconnection_1","displayName":"Enabled. Force enable auto-update over metered connection.","description":"Enabled. Force enable auto-update over metered connection.","helpText":null},{"id":"device_vendor_msft_policy_config_maps_allowofflinemapsdownloadovermeteredconnection_65535","displayName":"Not configured. User's choice.","description":"Not configured. User's choice.","helpText":null}]},"c49f9cce5719c710":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action to take on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"c41b63827df92745":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_roamingprofilelocation","displayName":"Set the roaming profile directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"c4460de19b7519af":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Don't allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},"c49b64d9632a3ec3":{"id":"device_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for sleeping tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or is not configured and the user has enabled the sleeping tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 30Seconds (30) = 30 seconds of inactivity\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"c4e29556c4376d22":{"id":"device_vendor_msft_policy_config_power_energysaverbatterythresholdpluggedin","displayName":"Energy Saver Battery Threshold Plugged In","description":"This policy setting allows you to specify battery charge level at which Energy Saver is turned on. If you enable this policy setting, you must provide a percent value, indicating the battery charge level. Energy Saver will be automatically turned on at (and below) the specified level. If you disable or do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#energysaverbatterythresholdpluggedin"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":null},"c4bc1270aeffa578":{"id":"device_vendor_msft_policy_config_power_standbytimeoutpluggedin","displayName":"Specify the system sleep timeout (plugged in)","description":"This policy setting allows you to specify the period of inactivity before Windows transitions the system to sleep.\n\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows transitions to sleep.\n\nIf you disable or do not configure this policy setting, users control this setting.\n\nIf the user has configured a slide show to run on the lock screen when the machine is locked, this can prevent the sleep transition from occuring. The \"Prevent enabling lock screen slide show\" policy setting can be used to disable the slide show feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-standbytimeoutpluggedin"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_standbytimeoutpluggedin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_standbytimeoutpluggedin_1","displayName":"Enabled","description":null,"helpText":null}]},"c406c902a776d3a5":{"id":"device_vendor_msft_policy_config_system_limitdumpcollection","displayName":"Limit Dump Collection","description":"This policy setting limits the type of dumps that can be collected when more information is needed to troubleshoot a problem. These dumps are not sent unless we have permission to collect optional diagnostic data. By enabling this policy setting, Windows Error Reporting is limited to sending kernel mini dumps and user mode triage dumps only. If you disable or do not configure this policy setting, we may occasionally collect full or heap dumps if the user has opted to send optional diagnostic data.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#limitdumpcollection"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_limitdumpcollection_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_limitdumpcollection_1","displayName":"Enabled.","description":"Enabled.","helpText":null}]},"c43ac44c5e98d7ba":{"id":"device_vendor_msft_scepcertificate_scepserverurls","displayName":"SCEP Server URLs","description":"Add one or more URLs for the NDES Server that issues certificates through SCEP.","helpText":"","infoUrls":[],"categoryId":"66c92e07-234b-4992-a081-9afe4c113ba3","categoryName":"SCEP certificate","options":null},"c47feb58e294763d":{"id":"device_vendor_msft_windowsadvancedthreatprotection_onboarding","displayName":"Onboarding (Device)","description":"Set Windows Defender Advanced Threat Protection Onboarding blob and initiate onboarding to Windows Defender Advanced Threat Protection","helpText":null,"infoUrls":[],"categoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","categoryName":"Microsoft Defender for Endpoint","options":null},"c49047876e95470a":{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_certificatethumbprints","displayName":"Certificate Thumbprints","description":"This policy setting allows certain device level Root Certificates to be shared with the Microsoft Defender Application Guard container. If you enable this setting, certificates with a thumbprint matching the ones specified will be transferred into the container. Multiple certificates can be specified by using a comma to separate the thumbprints for each certificate you want to transfer. Here's an example: b4e72779a8a362c860c36a6461f31e3aa7e58c14,1b1d49f06d2a697a544a1059bd59a7b058cda924. If you disable or don’t configure this setting, certificates are not shared with the Microsoft Defender Application Guard container.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsDefenderApplicationGuard-csp/"],"categoryId":"cd55f347-a417-4fe9-83ee-8f1f40ac5eb0","categoryName":null,"options":null},"c4d3a1651bd3f538":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirdomtrusts","displayName":"Active Directory Domains and Trusts (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-activedirdomtrusts"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirdomtrusts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirdomtrusts_1","displayName":"Enabled","description":null,"helpText":null}]},"c4b3af0d2946dc63":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_logicalmappeddrives","displayName":"Logical and Mapped Drives (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-logicalmappeddrives"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_logicalmappeddrives_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_logicalmappeddrives_1","displayName":"Enabled","description":null,"helpText":null}]},"c4db74a8252f2c3d":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_gp","displayName":"Windows Firewall with Advanced Security (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-windowsfirewall-gp"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_gp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_gp_1","displayName":"Enabled","description":null,"helpText":null}]},"c4717253841b929e":{"id":"user_vendor_msft_policy_config_admx_touchinput_touchinputoff_1","displayName":"Turn off Tablet PC touch input (User)","description":"Turn off Tablet PC touch input\r\n\r\nTurns off touch input, which allows the user to interact with their computer using their finger.\r\n\r\nIf you enable this setting, the user will not be able to produce input with touch. They will not be able to use touch input or touch gestures such as tap and double tap, the touch pointer, and other touch-specific features.\r\n\r\nIf you disable this setting, the user can produce input with touch, by using gestures, the touch pointer, and other-touch specific features.\r\n\r\nIf you do not configure this setting, touch input is on by default.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-touchinput#admx-touchinput-touchinputoff-1"],"categoryId":"abf781d7-1179-4f24-8d01-5611db14eddc","categoryName":"Touch Input","options":[{"id":"user_vendor_msft_policy_config_admx_touchinput_touchinputoff_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_touchinput_touchinputoff_1_1","displayName":"Enabled","description":null,"helpText":null}]},"c4c1562dd628d595":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedopensearch_opensearchlabel4","displayName":"Site Name 5 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"c469faf284d62445":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP (User)","description":"Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP.\r\n\r\nSetting the policy to Disabled forbids non-secure HTTP requests from using the Basic authentication scheme; only secure HTTPS is allowed.\r\n\r\nThis policy setting is ignored (and Basic is always forbidden) if the AuthSchemes policy is set and does not include Basic.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c4861f7356a47fda":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability","displayName":"Print PDF as Image Available (User)","description":"Controls how Google Chrome makes the Print as image option available on Microsoft® Windows® and macOS when printing PDFs.\r\n\r\nWhen printing a PDF on Microsoft® Windows® or macOS, sometimes print jobs need to be rasterized to an image for certain printers to get correct looking output.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will make the Print as image option available in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome the Print as image option will not be available to users in Print Preview and PDFs will be printed as usual without being rasterized to an image before being sent to the destination.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"c4f31ee71fd9a3c6":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},"c412f32723fe5c5b":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"c404bd95265bc6e7":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory","displayName":"Set download directory (User)","description":"Configures the directory to use when downloading files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified one or chosen to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\r\n\r\nIf you set an invalid path, Microsoft Edge will default to the user's default download directory.\r\n\r\nIf the folder specified by the path doesn't exist, the download will trigger a prompt that asks the user where they want to save their download.\r\n\r\nExample value: \r\n Linux-based OSes (including Mac): /home/${user_name}/Downloads\r\n Windows: C:\\Users\\${user_name}\\Downloads","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_1","displayName":"Enabled","description":null,"helpText":null}]},"c4fee312b00a8ae9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_imagesallowedforurlsdesc","displayName":"Allow images on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"c441049bb892ff5b":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls_localnetworkblockedforurlsdesc","displayName":"Block sites from making network requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"c4596af6f9b6b89d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration","displayName":"Turn off presence integration (User)","description":"This policy setting allows you to turn off instant messaging (IM) presence integration for Microsoft Office applications. \r\n\r\nIf you enable this policy, setting IM presence icons will not be displayed and presence integration will be turned off for Office applications.\r\n\r\nIf you disable or do not configure this policy setting, IM presence icons will be displayed and presence integration will be turned on for Office applications.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration_1","displayName":"Enabled","description":null,"helpText":null}]},"c42862472ddaaaee":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_l_placesbarname217","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},"c4d37e5d59db5c55":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd","displayName":"Disallow in SharePoint Designer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd_1","displayName":"True","description":null,"helpText":null}]},"c4bac41be0103137":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowpath","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"c4c0cb43fadbb0be":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave","displayName":"Web Add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave_1","displayName":"True","description":null,"helpText":null}]},"c4627cc14d612b27":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard","displayName":"Don't use Application Guard with Office. (User)","description":"This policy setting allows you to control whether Office apps use Application Guard to isolate untrusted documents.\r\n\r\nIf you enable this policy setting, Office apps won't use Application Guard to isolate untrusted documents even if the device is configured to use Application Guard. Instead, Office will use Protected View to isolate untrusted documents.\r\n\r\nNote: You should consider enabling this policy setting if you want to stop Office apps from using Application Guard without impacting the use of Application Guard with other applications.\r\n\r\nIf you disable or don't configure this policy settings, Office apps will use Application Guard to isolate untrusted documents. The device must be configured to use Application Guard and the user must be licensed to use Application Guard.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},"c40c590dbe20554d":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea","displayName":"Add OneNote icon to notification area (User)","description":"Checks/Unchecks the option ''Place OneNote icon in the notification area of the taskbar''.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea_1","displayName":"Enabled","description":null,"helpText":null}]},"c49ffc5aebf8dd9e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray","displayName":"Show an envelope icon in the system tray (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray_1","displayName":"True","description":null,"helpText":null}]},"c4353180abfc011f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation","displayName":"Stop checking for alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},"c4e7c3e414afafbf":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing","displayName":"Show slide animation while browsing (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},"c4a2b0d573fdbc49":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},"c40250ce3a2e1956":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},"c4f2ff4d1c793bbf":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength","displayName":"Most Recently Used Template List Length (User)","description":"This setting determines the length of the recently used templates list in the New Document task pane (File New...). The maximum value is 9 and the minimum value is 0. This setting applies only applies to Project.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_1","displayName":"Enabled","description":null,"helpText":null}]},"c40a6b0784335d48":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"8e48532a-ff0e-4422-82e2-6956b6786005","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"c48fab7289be8989":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels","displayName":"Undo Levels (User)","description":"Limits the number of actions (1-99) that a user can undo. If you enable this setting, you can set a limit on the number of actions (1-99) a user is can undo. If you disable this setting or do not configure it, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_1","displayName":"Enabled","description":null,"helpText":null}]},"c4bb86619a16d4e3":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"c4dc984023a4bd82":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"c413b32cfbc4bcea":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"c49ab3a2941246d4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},"c44567ba0f978e5d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"c4ebcf9ed13fba8e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]}} \ No newline at end of file +{"c4640e6ea1d0d58f":{"id":"ade_setupassistant_osshowcase","displayName":"OS showcase","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_osshowcase_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_osshowcase_1","displayName":"Show","description":null,"helpText":null}]},"c4b2f85ce916f1ff":{"id":"com.android.devicerestrictionpolicy.passwordminimumlength","displayName":"Minimum password length","description":"Enter the minimum number of digits or characters the password must have, between 4 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (4-16)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"c432bea332124cde":{"id":"com.apple.applicationaccess_allowremotescreenobservation","displayName":"Allow Remote Screen Observation","description":"If false, disables remote screen observation by the Classroom app. If Allow Screen Shot is set to false, the Classroom app doesn't observe remote screens. Required a supervised device until iOS 13 and macOS 10.15. Available in iOS 12 and later, and macOS 10.14.4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowremotescreenobservation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowremotescreenobservation_true","displayName":"True","description":null,"helpText":null}]},"c48ef45ad6b2e35a":{"id":"com.apple.extensiblesso_platformsso_unlockpolicy","displayName":"Unlock Policy","description":"The policy to apply when using Platform SSO at screensaver unlock. Applies when 'AuthenticationMethod' is `Password`.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"c418104abfd92987":{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing","displayName":"Management Allows External Volume Syncing","description":"If `false`, the device only allows File Provider extension volume synchronization for the system \"home\" volume and any data separated volume, and prevents synchronization with any other volumes. If `true``, the device allows File Provider extension volume synchronization for the system \"home\" volume, any data separated volume, and any encrypted APFS volumes (on either internal or external media).","helpText":null,"infoUrls":[],"categoryId":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","categoryName":"File Provider","options":[{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.fileproviderd_managementallowsexternalvolumesyncing_true","displayName":"Allowed","description":null,"helpText":null}]},"c4289e3307b3cd4a":{"id":"com.apple.managedclient.preferences_blockexternalsync","displayName":"Block external sync","description":"Prevents the sync app from syncing libraries and folders shared from other organizations.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#blockexternalsync"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_blockexternalsync_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_blockexternalsync_true","displayName":"True","description":null,"helpText":null}]},"c43ecd241d05c784":{"id":"com.apple.managedclient.preferences_channelname","displayName":"Update channel","description":"Specifies the channel to receive updates. The most stable channel is the Current Channel, which is recommended for the majority of your fleet. Users subscribed to the Preview Channel will receive production-quality updates a week before Current Channel users. Users subscribed to the Beta Channel will receive unsupported nightly builds that are designed for testing.","helpText":null,"infoUrls":["https://support.microsoft.com/office/update-office-for-mac-automatically-bfd1e497-c24d-4754-92ab-910a4074d7c1"],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_2","displayName":"Current Channel (Deferred)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_3","displayName":"Beta Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_channelname_4","displayName":"Current Channel (Monthly)","description":null,"helpText":null}]},"c497a377f1ea1808":{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled","displayName":"Manage the indicator UI of the Enhanced Security Mode (ESM) feature in Microsoft Edge","description":"This policy lets you manage whether the indicator User Interface (UI) for enhanced security mode is shown or not when ESM is turned on.\n\nIf you enable or don't configure this policy, the indicator UI is on.\n\nIf you disable this policy, the indicator UI is off.\n\nNote: If this policy is used, only the indicator User Interface experience is supressed - ESM is still turned on. For more information, see the \"EnhanceSecurityMode\" policy.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enhancesecuritymodeindicatoruienabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enhancesecuritymodeindicatoruienabled_true","displayName":"Enabled","description":null,"helpText":null}]},"c47faf40deb76450":{"id":"com.apple.managedclient.preferences_exclusions_item_name","displayName":"Name","description":"Process name, either or full path or file name, wildcards supported","helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"c4580bf2c06cac64":{"id":"com.apple.managedclient.preferences_importshortcuts","displayName":"Allow importing of shortcuts","description":"Allows users to import Shortcuts from another browser into Microsoft Edge.\n\nIf you disable this policy, Shortcuts aren't imported on first run.\n\nIf you don’t configure this policy, Shortcuts are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Shortcuts on first run.\n\n**Note**: This policy currently manages importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#importshortcuts"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_importshortcuts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_importshortcuts_true","displayName":"Enabled","description":null,"helpText":null}]},"c4e7b98d975bacc6":{"id":"com.apple.managedclient.preferences_precisegeolocationallowedforurls","displayName":"Allow precise geolocation on these sites","description":"This policy lets you specify a list of URL patterns for sites that are allowed to access the user's high-accuracy geolocation without prompting for permission.\n\nIf you leave this policy unset, DefaultGeolocationSetting applies to all sites (if configured). Otherwise, the user's personal setting is used.\n\nFor information about valid url patterns, see https://learn.microsoft.com/deployedge/edge-learnmmore-url-list-filter%20format. Wildcards (*) are supported.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#precisegeolocationallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"c4cfada71245bf2c":{"id":"com.apple.mcx.filevault2_userentersmissinginfo","displayName":"User Enters Missing Info","description":"If true, enables a prompt for missing user name or password fields.","helpText":null,"infoUrls":[],"categoryId":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","categoryName":"FileVault","options":[{"id":"com.apple.mcx.filevault2_userentersmissinginfo_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx.filevault2_userentersmissinginfo_true","displayName":"True","description":null,"helpText":null}]},"c400bef6f9992484":{"id":"contentcaching_publicranges_item_first","displayName":"First","description":"The first IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"c4b05234c4395faf":{"id":"device_vendor_msft_pkcscertificate_subjectnameformat","displayName":"Subject name format","description":"CN={{UserName}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US\\nor\\nCN={{AAD_Device_ID}},E={{EmailAddress}},OU=EnterpriseUsers,O=Contoso Corporation,L=Redmond,ST=WA,C=US","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/mem/intune/protect/certificates-pfx-configure"],"categoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","categoryName":"PKCS certificate","options":null},"c44e72622a47f467":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_efsrecovery_cse_nochanges3_1","displayName":"True","description":null,"helpText":null}]},"c47636e41a6ce2b5":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions","displayName":"Process Mitigation Options","description":"\r\n This security feature provides a means to override individual process MitigationOptions settings. This can be used to enforce a number of security policies specific to applications. The application name is specified as the Value name, including extension. The Value is specified as a bit field with a series of flags in particular positions. Bits can be set to either 0 (setting is forced off), 1 (setting is forced on), or ? (setting retains its existing value prior to GPO evaluation). The recognized bit locations are:\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE (0x00000001)\r\n Enables data execution prevention (DEP) for the child process\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_DEP_ATL_THUNK_ENABLE (0x00000002)\r\n Enables DEP-ATL thunk emulation for the child process. DEP-ATL thunk emulation causes the system to intercept NX faults that originate from the Active Template Library (ATL) thunk layer.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_SEHOP_ENABLE (0x00000004)\r\n Enables structured exception handler overwrite protection (SEHOP) for the child process. SEHOP blocks exploits that use the structured exception handler (SEH) overwrite technique.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON (0x00000100)\r\n The force Address Space Layout Randomization (ASLR) policy forcibly rebases images that are not dynamic base compatible by acting as though an image base collision happened at load time. If relocations are required, images that do not have a base relocation section will not be loaded.\r\n\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_ON (0x00010000)\r\n PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF (0x00020000)\r\n The bottom-up randomization policy, which includes stack randomization options, causes a random location to be used as the lowest user address.\r\n\r\n For instance, to enable PROCESS_CREATION_MITIGATION_POLICY_DEP_ENABLE and PROCESS_CREATION_MITIGATION_POLICY_FORCE_RELOCATE_IMAGES_ALWAYS_ON, disable PROCESS_CREATION_MITIGATION_POLICY_BOTTOM_UP_ASLR_ALWAYS_OFF, and to leave all other options at their default values, specify a value of:\r\n ???????????????0???????1???????1\r\n\r\n Setting flags not specified here to any value other than ? results in undefined behavior.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-processmitigationoptions"],"categoryId":"5dcea340-0469-4f43-b270-a49ed0597201","categoryName":"Mitigation Options","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_processmitigationoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"c4a840f7b6de0485":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode","displayName":"Use urgent mode when pinging domain controllers","description":"This policy setting configures whether the computers to which this setting is applied are more aggressive when trying to locate a domain controller (DC).\r\n\r\nWhen an environment has a large number of DCs running both old and new operating systems, the default DC locator discovery behavior may be insufficient to find DCs running a newer operating system. This policy setting can be enabled to configure DC locator to be more aggressive about trying to locate a DC in such an environment, by pinging DCs at a higher frequency. Enabling this setting may result in additional network traffic and increased load on DCs. You should disable this setting once all DCs are running the same OS version.\r\n\r\nThe allowable values for this setting result in the following behaviors:\r\n\r\n1 - Computers will ping DCs at the normal frequency.\r\n2 - Computers will ping DCs at the higher frequency.\r\n\r\nTo specify this behavior, click Enabled and then enter a value. The range of values is from 1 to 2.\r\n\r\nIf you do not configure this policy setting, it is not applied to any computers, and computers use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-pingurgencymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_pingurgencymode_1","displayName":"Enabled","description":null,"helpText":null}]},"c489002d0df2f716":{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2","displayName":"Prevent restoring local previous versions","description":"This policy setting lets you suppress the Restore button in the previous versions property page when the user has selected a previous version of a local file.\r\n\r\nIf you enable this policy setting, the Restore button is disabled when the user selects a previous version corresponding to a local file.\r\n\r\nIf you disable this policy setting, the Restore button remains active for a previous version corresponding to a local file. If the user clicks the Restore button, Windows attempts to restore the file from the local disk.\r\n\r\nIf you do not configure this policy setting, it is disabled by default. The Restore button is active when the previous version is of a local file.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-previousversions#admx-previousversions-disablelocalrestore-2"],"categoryId":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","categoryName":"Previous Versions","options":[{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_previousversions_disablelocalrestore_2_1","displayName":"Enabled","description":null,"helpText":null}]},"c423638f25f4bad7":{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded","displayName":"Allow user name hint","description":"This policy setting lets you determine whether an optional field will be displayed during logon and elevation that allows a user to enter his or her user name or user name and domain, thereby associating a certificate with that user.\r\n\r\nIf you enable this policy setting then an optional field that allows a user to enter their user name or user name and domain will be displayed.\r\n\r\nIf you disable or do not configure this policy setting, an optional field that allows users to enter their user name or user name and domain will not be displayed.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-smartcard#admx-smartcard-x509hintsneeded"],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_x509hintsneeded_1","displayName":"Enabled","description":null,"helpText":null}]},"c42c08161f83b64f":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_ts_workdir","displayName":"Working Directory","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},"c494e7f6ed8b4f7c":{"id":"device_vendor_msft_policy_config_admx_w32time_w32time_policy_config_w32time_clockadjustmentauditlimit","displayName":"ClockAdjustmentAuditLimit","description":null,"helpText":"","infoUrls":[],"categoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","categoryName":"Windows Time Service","options":null},"c4ed3dd7b48e8a28":{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_forcedenytheseapps","displayName":"Let Apps Access Cellular Data Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied access to cellular data. This setting overrides the default LetAppsAccessCellularData policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata_forcedenytheseapps"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":null},"c4141fda1b815e74":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks","displayName":"Enable online OCSP/CRL checks","description":"Setting the policy to True means online OCSP/CRL checks are performed.\r\n\r\nSetting the policy to False or leaving it unset means Google Chrome won't perform online revocation checks in Google Chrome 19 and later.\r\n\r\nNote: OCSP/CRL checks provide no effective security benefit.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableonlinerevocationchecks_1","displayName":"Enabled","description":null,"helpText":null}]},"c4639146bba0d91d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_maxconnectionsperproxy_maxconnectionsperproxy","displayName":"Maximal number of concurrent connections to the proxy server: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"c4caeec544eb3be0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled","displayName":"Enable showing full-tab promotional content","description":"Setting the policy to True or leaving it unset lets Google Chrome show users product information as full-tab content.\r\n\r\nSetting the policy to False prevents Google Chrome from showing product information as full-tab content.\r\n\r\nSetting the policy controls the presentation of the welcome pages that help users sign in to Google Chrome, set Google Chrome as users' default browser, or otherwise inform them of product features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_promotionaltabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c427a90fa545f426":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow","displayName":"Set the time interval for relaunch","description":"Specify a target time window for the end of the relaunch notification period.\r\n\r\nUsers are notified of the need for a browser relaunch or device restart based on the RelaunchNotification and RelaunchNotificationPeriod policy settings. Browsers and devices are forcibly restarted at the end of the notification period when the RelaunchNotification policy is set to 'Required'. This RelaunchWindow policy can be used to defer the end of the notification period so that it falls within a specific time window.\r\n\r\nIf this policy is not set, the default target time window for Google Chrome OS is between 2 AM and 4 AM. The default target time window for Google Chrome is the whole day (i.e., the end of the notification period is never deferred).\r\n\r\nNote: Though the policy can accept multiple items in entries, all but the first item are ignored.\r\nWarning: Setting this policy may delay application of software updates.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=RelaunchWindow for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"entries\": [\r\n {\r\n \"start\": {\r\n \"hour\": 2,\r\n \"minute\": 15\r\n },\r\n \"duration_mins\": 240\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchwindow_1","displayName":"Enabled","description":null,"helpText":null}]},"c401819246ab133d":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting","displayName":"Default notification setting","description":"Setting the policy to 1 lets websites display desktop notifications. Setting the policy to 2 denies desktop notifications.\r\n\r\nLeaving it unset means AskNotifications applies, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultnotificationssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"c4a4e2c7fa0c3352":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin","displayName":"Minimum TLS version to fallback to","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_sslversionfallbackmin_1","displayName":"Enabled","description":null,"helpText":null}]},"c4f739e3c4848615":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_fileordirectorypickerwithoutgestureallowedfororigins_fileordirectorypickerwithoutgestureallowedfororiginsdesc","displayName":"Allow file or directory picker APIs to be called without prior user gesture (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"c458e3e771b6009e":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto","displayName":"To:","description":"","helpText":"","infoUrls":[],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":[{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitbackgrounddownloadbandwidth_sethourstolimitbackgrounddownloadbandwidthto_23","displayName":"11 PM","description":null,"helpText":null}]},"c458be2408fe45d0":{"id":"device_vendor_msft_policy_config_deviceguard_configuresystemguardlaunch","displayName":"Configure System Guard Launch","description":"Secure Launch configuration: 0 - Unmanaged, configurable by Administrative user, 1 - Enables Secure Launch if supported by hardware, 2 - Disables Secure Launch.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceguard#configuresystemguardlaunch"],"categoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","categoryName":"Device Guard","options":[{"id":"device_vendor_msft_policy_config_deviceguard_configuresystemguardlaunch_0","displayName":"Unmanaged Configurable by Administrative user","description":"Unmanaged Configurable by Administrative user","helpText":null},{"id":"device_vendor_msft_policy_config_deviceguard_configuresystemguardlaunch_1","displayName":"Unmanaged Enables Secure Launch if supported by hardware","description":"Unmanaged Enables Secure Launch if supported by hardware","helpText":null},{"id":"device_vendor_msft_policy_config_deviceguard_configuresystemguardlaunch_2","displayName":"Unmanaged Disables Secure Launch","description":"Unmanaged Disables Secure Launch","helpText":null}]},"c469500ea51376ea":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol","displayName":"Allow only approved domains to use the TDC ActiveX control","description":"This policy setting controls whether or not the user is allowed to run the TDC ActiveX control on websites.\n\nIf you enable this policy setting, the TDC ActiveX control will not run from websites in this zone.\n\nIf you disable this policy setting, the TDC Active X control will run from all sites in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"c4525141bf78def3":{"id":"device_vendor_msft_policy_config_maps_allowofflinemapsdownloadovermeteredconnection","displayName":"Allow Offline Maps Download Over Metered Connection","description":"Allows the download and update of map data over metered connections. After the policy is applied, you can verify the settings in the user interface in System > Offline Maps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Maps#allowofflinemapsdownloadovermeteredconnection"],"categoryId":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","categoryName":"Maps","options":[{"id":"device_vendor_msft_policy_config_maps_allowofflinemapsdownloadovermeteredconnection_0","displayName":"Disabled. Force disable auto-update over metered connection.","description":"Disabled. Force disable auto-update over metered connection.","helpText":null},{"id":"device_vendor_msft_policy_config_maps_allowofflinemapsdownloadovermeteredconnection_1","displayName":"Enabled. Force enable auto-update over metered connection.","description":"Enabled. Force enable auto-update over metered connection.","helpText":null},{"id":"device_vendor_msft_policy_config_maps_allowofflinemapsdownloadovermeteredconnection_65535","displayName":"Not configured. User's choice.","description":"Not configured. User's choice.","helpText":null}]},"c49f9cce5719c710":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup","displayName":"Action to take on startup (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_5","displayName":"Open a new tab","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_1","displayName":"Restore the last session","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_restoreonstartup_4","displayName":"Open a list of URLs","description":null,"helpText":null}]},"c41b63827df92745":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_roamingprofilelocation","displayName":"Set the roaming profile directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"c4460de19b7519af":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Don't allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},"c49b64d9632a3ec3":{"id":"device_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended","displayName":"Set the background tab inactivity timeout for sleeping tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs will be automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\r\n\r\nTabs are only put to sleep automatically when the policy 'SleepingTabsEnabled' (Configure sleeping tabs) is enabled or is not configured and the user has enabled the sleeping tabs setting.\r\n\r\nIf you don't configure this policy, users can choose the timeout value.\r\n\r\nPolicy options mapping:\r\n\r\n* 30Seconds (30) = 30 seconds of inactivity\r\n\r\n* 5Minutes (300) = 5 minutes of inactivity\r\n\r\n* 15Minutes (900) = 15 minutes of inactivity\r\n\r\n* 30Minutes (1800) = 30 minutes of inactivity\r\n\r\n* 1Hour (3600) = 1 hour of inactivity\r\n\r\n* 2Hours (7200) = 2 hours of inactivity\r\n\r\n* 3Hours (10800) = 3 hours of inactivity\r\n\r\n* 6Hours (21600) = 6 hours of inactivity\r\n\r\n* 12Hours (43200) = 12 hours of inactivity\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88.1~policy~microsoft_edge_recommended_sleepingtabstimeout_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"c4e29556c4376d22":{"id":"device_vendor_msft_policy_config_power_energysaverbatterythresholdpluggedin","displayName":"Energy Saver Battery Threshold Plugged In","description":"This policy setting allows you to specify battery charge level at which Energy Saver is turned on. If you enable this policy setting, you must provide a percent value, indicating the battery charge level. Energy Saver will be automatically turned on at (and below) the specified level. If you disable or do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#energysaverbatterythresholdpluggedin"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":null},"c4bc1270aeffa578":{"id":"device_vendor_msft_policy_config_power_standbytimeoutpluggedin","displayName":"Specify the system sleep timeout (plugged in)","description":"This policy setting allows you to specify the period of inactivity before Windows transitions the system to sleep.\n\nIf you enable this policy setting, you must provide a value, in seconds, indicating how much idle time should elapse before Windows transitions to sleep.\n\nIf you disable or do not configure this policy setting, users control this setting.\n\nIf the user has configured a slide show to run on the lock screen when the machine is locked, this can prevent the sleep transition from occuring. The \"Prevent enabling lock screen slide show\" policy setting can be used to disable the slide show feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-power#power-standbytimeoutpluggedin"],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":[{"id":"device_vendor_msft_policy_config_power_standbytimeoutpluggedin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_power_standbytimeoutpluggedin_1","displayName":"Enabled","description":null,"helpText":null}]},"c406c902a776d3a5":{"id":"device_vendor_msft_policy_config_system_limitdumpcollection","displayName":"Limit Dump Collection","description":"This policy setting limits the type of dumps that can be collected when more information is needed to troubleshoot a problem. These dumps are not sent unless we have permission to collect optional diagnostic data. By enabling this policy setting, Windows Error Reporting is limited to sending kernel mini dumps and user mode triage dumps only. If you disable or do not configure this policy setting, we may occasionally collect full or heap dumps if the user has opted to send optional diagnostic data.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#limitdumpcollection"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_limitdumpcollection_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_limitdumpcollection_1","displayName":"Enabled.","description":"Enabled.","helpText":null}]},"c43ac44c5e98d7ba":{"id":"device_vendor_msft_scepcertificate_scepserverurls","displayName":"SCEP Server URLs","description":"Add one or more URLs for the NDES Server that issues certificates through SCEP.","helpText":"","infoUrls":[],"categoryId":"66c92e07-234b-4992-a081-9afe4c113ba3","categoryName":"SCEP certificate","options":null},"c47feb58e294763d":{"id":"device_vendor_msft_windowsadvancedthreatprotection_onboarding","displayName":"Onboarding (Device)","description":"Set Windows Defender Advanced Threat Protection Onboarding blob and initiate onboarding to Windows Defender Advanced Threat Protection","helpText":null,"infoUrls":[],"categoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","categoryName":"Microsoft Defender for Endpoint","options":null},"c49047876e95470a":{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_certificatethumbprints","displayName":"Certificate Thumbprints","description":"This policy setting allows certain device level Root Certificates to be shared with the Microsoft Defender Application Guard container. If you enable this setting, certificates with a thumbprint matching the ones specified will be transferred into the container. Multiple certificates can be specified by using a comma to separate the thumbprints for each certificate you want to transfer. Here's an example: b4e72779a8a362c860c36a6461f31e3aa7e58c14,1b1d49f06d2a697a544a1059bd59a7b058cda924. If you disable or don’t configure this setting, certificates are not shared with the Microsoft Defender Application Guard container.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsDefenderApplicationGuard-csp/"],"categoryId":"cd55f347-a417-4fe9-83ee-8f1f40ac5eb0","categoryName":null,"options":null},"c4d3a1651bd3f538":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirdomtrusts","displayName":"Active Directory Domains and Trusts (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-activedirdomtrusts"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirdomtrusts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_activedirdomtrusts_1","displayName":"Enabled","description":null,"helpText":null}]},"c4b3af0d2946dc63":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_logicalmappeddrives","displayName":"Logical and Mapped Drives (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-logicalmappeddrives"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_logicalmappeddrives_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_logicalmappeddrives_1","displayName":"Enabled","description":null,"helpText":null}]},"c4db74a8252f2c3d":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_gp","displayName":"Windows Firewall with Advanced Security (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-windowsfirewall-gp"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_gp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_windowsfirewall_gp_1","displayName":"Enabled","description":null,"helpText":null}]},"c4717253841b929e":{"id":"user_vendor_msft_policy_config_admx_touchinput_touchinputoff_1","displayName":"Turn off Tablet PC touch input (User)","description":"Turn off Tablet PC touch input\r\n\r\nTurns off touch input, which allows the user to interact with their computer using their finger.\r\n\r\nIf you enable this setting, the user will not be able to produce input with touch. They will not be able to use touch input or touch gestures such as tap and double tap, the touch pointer, and other touch-specific features.\r\n\r\nIf you disable this setting, the user can produce input with touch, by using gestures, the touch pointer, and other-touch specific features.\r\n\r\nIf you do not configure this setting, touch input is on by default.\r\n\r\nNote: Changes to this setting will not take effect until the user logs off.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-touchinput#admx-touchinput-touchinputoff-1"],"categoryId":"abf781d7-1179-4f24-8d01-5611db14eddc","categoryName":"Touch Input","options":[{"id":"user_vendor_msft_policy_config_admx_touchinput_touchinputoff_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_touchinput_touchinputoff_1_1","displayName":"Enabled","description":null,"helpText":null}]},"c4c1562dd628d595":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedopensearch_opensearchlabel4","displayName":"Site Name 5 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"c469faf284d62445":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled","displayName":"Allow Basic authentication for HTTP (User)","description":"Setting the policy to Enabled or leaving it unset will allow Basic authentication challenges received over non-secure HTTP.\r\n\r\nSetting the policy to Disabled forbids non-secure HTTP requests from using the Basic authentication scheme; only secure HTTPS is allowed.\r\n\r\nThis policy setting is ignored (and Basic is always forbidden) if the AuthSchemes policy is set and does not include Basic.","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_basicauthoverhttpenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c4861f7356a47fda":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability","displayName":"Print PDF as Image Available (User)","description":"Controls how Google Chrome makes the Print as image option available on Microsoft® Windows® and macOS when printing PDFs.\r\n\r\nWhen printing a PDF on Microsoft® Windows® or macOS, sometimes print jobs need to be rasterized to an image for certain printers to get correct looking output.\r\n\r\nWhen this policy is set to Enabled, Google Chrome will make the Print as image option available in the Print Preview when printing a PDF.\r\n\r\nWhen this policy is set to Disabled or not set Google Chrome the Print as image option will not be available to users in Print Preview and PDFs will be printed as usual without being rasterized to an image before being sent to the destination.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printpdfasimageavailability_1","displayName":"Enabled","description":null,"helpText":null}]},"c4f31ee71fd9a3c6":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},"c412f32723fe5c5b":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads (User)","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, users will receive a file download dialog for automatic download attempts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"c404bd95265bc6e7":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory","displayName":"Set download directory (User)","description":"Configures the directory to use when downloading files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified one or chosen to be prompted for download location every time. See https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nIf you disable or don't configure this policy, the default download directory is used, and the user can change it.\r\n\r\nIf you set an invalid path, Microsoft Edge will default to the user's default download directory.\r\n\r\nIf the folder specified by the path doesn't exist, the download will trigger a prompt that asks the user where they want to save their download.\r\n\r\nExample value: \r\n Linux-based OSes (including Mac): /home/${user_name}/Downloads\r\n Windows: C:\\Users\\${user_name}\\Downloads","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_downloaddirectory_1","displayName":"Enabled","description":null,"helpText":null}]},"c4fee312b00a8ae9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_imagesallowedforurls_imagesallowedforurlsdesc","displayName":"Allow images on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"c441049bb892ff5b":{"id":"user_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_localnetworkblockedforurls_localnetworkblockedforurlsdesc","displayName":"Block sites from making network requests to local network endpoints. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"c4596af6f9b6b89d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration","displayName":"Turn off presence integration (User)","description":"This policy setting allows you to turn off instant messaging (IM) presence integration for Microsoft Office applications. \r\n\r\nIf you enable this policy, setting IM presence icons will not be displayed and presence integration will be turned off for Office applications.\r\n\r\nIf you disable or do not configure this policy setting, IM presence icons will be displayed and presence integration will be turned on for Office applications.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_turnoffpresenceintegration_1","displayName":"Enabled","description":null,"helpText":null}]},"c42862472ddaaaee":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_l_placesbarname217","displayName":"Name: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":null},"c4d37e5d59db5c55":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd","displayName":"Disallow in SharePoint Designer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyspd_1","displayName":"True","description":null,"helpText":null}]},"c4bac41be0103137":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowpath","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"c4c0cb43fadbb0be":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave","displayName":"Web Add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmpreventedsolutiontypes_l_officeosmpreventedsolutiontypesagave_1","displayName":"True","description":null,"helpText":null}]},"c4627cc14d612b27":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard","displayName":"Don't use Application Guard with Office. (User)","description":"This policy setting allows you to control whether Office apps use Application Guard to isolate untrusted documents.\r\n\r\nIf you enable this policy setting, Office apps won't use Application Guard to isolate untrusted documents even if the device is configured to use Application Guard. Instead, Office will use Protected View to isolate untrusted documents.\r\n\r\nNote: You should consider enabling this policy setting if you want to stop Office apps from using Application Guard without impacting the use of Application Guard with other applications.\r\n\r\nIf you disable or don't configure this policy settings, Office apps will use Application Guard to isolate untrusted documents. The device must be configured to use Application Guard and the user must be licensed to use Application Guard.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffofficeinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},"c40c590dbe20554d":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea","displayName":"Add OneNote icon to notification area (User)","description":"Checks/Unchecks the option ''Place OneNote icon in the notification area of the taskbar''.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_addonenoteicontonotificationarea_1","displayName":"Enabled","description":null,"helpText":null}]},"c49ffc5aebf8dd9e":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray","displayName":"Show an envelope icon in the system tray (User)","description":"","helpText":"","infoUrls":[],"categoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","categoryName":"Advanced E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions_l_whennewitemsarrive_l_showanenvelopeiconinthesystemtray_1","displayName":"True","description":null,"helpText":null}]},"c4353180abfc011f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation","displayName":"Stop checking for alt text accessibility information (User)","description":"This policy setting prevents the Accessibility Checker from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that objects such as images and shapes contain alt text.\r\n\r\nIf you disable or do not configure this policy setting, objects will be checked for alternative text and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"f5babdb3-c718-4675-b977-6c7bc7e6f886","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_filetab~l_checkaccessibility_l_stopcheckingalttextaccessibilityinformation_1","displayName":"Enabled","description":null,"helpText":null}]},"c4e7c3e414afafbf":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing","displayName":"Show slide animation while browsing (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_showslideanimationwhilebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},"c4a2b0d573fdbc49":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation","displayName":"Turn off file validation (User)","description":"This policy setting allows you turn off the file validation feature.\r\n\r\nIf you enable this policy setting, file validation will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, file validation will be turned on. Office Binary Documents (97-2003) are checked to see if they conform against the file format schema before they are opened.","helpText":"","infoUrls":[],"categoryId":"85810387-3320-4056-bae2-953beeb246f7","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security_l_turnofffilevalidation_1","displayName":"Enabled","description":null,"helpText":null}]},"c40250ce3a2e1956":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders79_1","displayName":"True","description":null,"helpText":null}]},"c4f2ff4d1c793bbf":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength","displayName":"Most Recently Used Template List Length (User)","description":"This setting determines the length of the recently used templates list in the New Document task pane (File New...). The maximum value is 9 and the minimum value is 0. This setting applies only applies to Project.","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_mrutemplatelistlength_1","displayName":"Enabled","description":null,"helpText":null}]},"c40a6b0784335d48":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"8e48532a-ff0e-4422-82e2-6956b6786005","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"c48fab7289be8989":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels","displayName":"Undo Levels (User)","description":"Limits the number of actions (1-99) that a user can undo. If you enable this setting, you can set a limit on the number of actions (1-99) a user is can undo. If you disable this setting or do not configure it, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjgeneral_l_undolevels_1","displayName":"Enabled","description":null,"helpText":null}]},"c4bb86619a16d4e3":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc13_l_pathcolon56","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"c4dc984023a4bd82":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc17_l_pathcolon72","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"c413b32cfbc4bcea":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_pathcolon76","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"c49ab3a2941246d4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngpasswordspincount_l_setcngpasswordspincountspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},"c44567ba0f978e5d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word6pt0binarydocumentsandtemplates_l_word6pt0binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"c4ebcf9ed13fba8e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/c6.json b/public/intune-definitions/c6.json index 1e5b62ca7e25..f24cc9ebb200 100644 --- a/public/intune-definitions/c6.json +++ b/public/intune-definitions/c6.json @@ -1 +1 @@ -{"c631d22b247c8980":{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation","displayName":"Force Classroom Unprompted Screen Observation","description":"If `true` and `ScreenObservationPermissionModificationAllowed` is also `true` in the Education payload, a student enrolled in a managed course through the Classroom app automatically gives permission to that course teacher's requests to observe the student's screen without prompting the student.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation_true","displayName":"Enabled","description":null,"helpText":null}]},"c6c62a8faf7a4868":{"id":"com.apple.directoryservice.managed_adusewindowsuncpath","displayName":"AD Use Windows UNC Path","description":"If true, uses the UNC path from Active Directory to derive the network home location.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adusewindowsuncpath_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adusewindowsuncpath_true","displayName":"True","description":null,"helpText":null}]},"c6277898ce9f6b9e":{"id":"com.apple.dock_contents-immutable","displayName":"Contents Immutable","description":"If true, disables changes to the dock.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_contents-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_contents-immutable_true","displayName":"True","description":null,"helpText":null}]},"c6d9cab047c52a26":{"id":"com.apple.loginwindow_adminhostinfo","displayName":"Admin Host Info","description":"If this key is included in the payload, its value is displayed in the login window as additional computer information. Before macOS 10.10, this string could contain only certain information (host name, system version, or IP address). After macOS 10.10, setting this key to any value allows the user to click the time area of the menu bar to toggle through various computer information values.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},"c66d13c35a5f0034":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_lcid","displayName":"Microsoft Edge Canary LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"c6d3d9d24e291607":{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step","displayName":"Dynamic Power Step","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step_1","displayName":"True","description":null,"helpText":null}]},"c67594988a0d619c":{"id":"com.apple.system-extension-policy_nonremovablesystemextensions_generickey","displayName":"ANY","description":"System extension bundle identifiers","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"c6f8ba7edfcc1f15":{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},"c61660b0901bf69a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting","displayName":"Control use of the WebUSB API","description":"Set whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices.\n\nYou can override this policy for specific URL patterns by using the \"WebUsbAskForUrls\" and \"WebUsbBlockedForUrls\" policies.\n\nIf you don't configure this policy, sites can ask users whether they can access the connected USB devices ('AskWebUsb') by default, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockWebUsb (2) = Do not allow any site to request access to USB devices via the WebUSB API\n\n* AskWebUsb (3) = Allow sites to ask the user to grant access to a connected USB device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting_blockwebusb","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting_askwebusb","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},"c6a5066b866532e4":{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Defines a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\n\nIf you don't configure this policy, \"DefaultJavaScriptSetting\" applies for all sites, if it's set. If not, the user's personal setting applies.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nThis policy blocks JavaScript based on whether the origin of the top-level document (usually the page URL that's also displayed in the address bar) matches any of the patterns. Therefore, this policy isn't appropriate for mitigating web supply-chain attacks. For example, supplying the pattern `https://[*.]foo.com/` doesn't prevent a page hosted on, say, `https://contoso.com`, from running a script loaded from `https://www.foo.com/example.js`. Furthermore, supplying the pattern `https://contoso.com/` doesn't prevent a document from `https://contoso.com` from running scripts if it isn't the top-level document, but embedded as a subframe into a page hosted on another origin, say, `https://www.fabrikam.com`.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"c68c060af48ecf89":{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery","displayName":"Enable Pin Recovery","description":"If the user forgets their PIN, it can be changed to a new PIN using the Windows Hello for Business PIN recovery service. This cloud service encrypts a recovery secret which is stored locally on the client, but which can only be decrypted by the cloud service.\n\nIf you enable this policy setting, the PIN recovery secret will be stored on the device and the user will be able to change to a new PIN in case their PIN is forgotten.\n\nIf you disable or do not configure this policy setting, the PIN recovery secret will not be created or stored. If the user's PIN is forgotten, the only way to get a new PIN is by deleting the existing PIN and creating a new one, which will require the user to re-register with any services the old PIN provided access to.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery_true","displayName":"true","description":"Enabled","helpText":null}]},"c6108d7ed62a09cb":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk","displayName":"Force queue mode for application errors","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk_1","displayName":"True","description":null,"helpText":null}]},"c645450649161c3b":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring","displayName":"Turn on behavior monitoring","description":"This policy setting allows you to configure behavior monitoring.\r\n\r\n If you enable or do not configure this setting, behavior monitoring will be enabled.\r\n\r\n If you disable this setting, behavior monitoring will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablebehaviormonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},"c60391fb45993091":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt","displayName":"NoDefaultExempt","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_0","displayName":"Allow all exemptions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_1","displayName":"Multicast, broadcast, & ISAKMP exempt.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_2","displayName":"RSVP, Kerberos, and ISAKMP are exempt.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_3","displayName":"Only ISAKMP is exempt.","description":null,"helpText":null}]},"c6b8bc83c90ea816":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages","displayName":"Remove Default Microsoft Store packages from the system.","description":"Removes Default Microsoft Store packages from the system.\n\nIf you enable this policy, the selected Microsoft Store apps in the provided list will be uninstalled from the system. You can make adjustments to the default settings.\n\nUnselected apps in the list will not be removed.\n\nDefault is 'disabled' (key not present).\n\nIf the policy is disabled or not configured, no Default Microsoft Store packages will be removed from the system.\n\n* This is a headless app (no UI)\n\n** This app is the default handler for a common file type or protocol. Removing this app might result in a degraded user experience. We do not recommend removing this app.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-applicationmanagement#applicationmanagement-removedefaultmicrosoftstorepackages"],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_1","displayName":"Enabled","description":null,"helpText":null}]},"c681a0da531ab25a":{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange","displayName":"Audit Changes to Audit Policy","description":"This policy setting allows you to audit changes in the security audit policy settings such as the following: Settings permissions and audit settings on the Audit Policy object. Changes to the system audit policy. Registration of security event sources. De-registration of security event sources. Changes to the per-user audit settings. Changes to the value of CrashOnAuditFail. Changes to the system access control list on a file system or registry object. Changes to the Special Groups list. Note: System access control list (SACL) change auditing is done when a SACL for an object changes and the policy change category is enabled. Discretionary access control list (DACL) and ownership changes are audited when object access auditing is enabled and the object's SACL is configured for auditing of DACL/Owner change.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"c687b20a55cc3981":{"id":"device_vendor_msft_policy_config_bluetooth_setminimumencryptionkeysize","displayName":"Set Minimum Encryption Key Size","description":"There are multiple levels of encryption strength when pairing Bluetooth devices. This policy helps prevent weaker devices cryptographically being used in high security environments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#setminimumencryptionkeysize"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":null},"c6aa8b26700fa897":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed","displayName":"Allow media autoplay","description":"Setting the policy to True lets Google Chrome autoplay media. Setting the policy to False stops Google Chrome from autoplaying media.\r\n\r\n By default, Google Chrome doesn't autoplay media. But, for certain URL patterns, you can use the AutoplayAllowlist policy to change this setting.\r\n\r\nIf this policy changes while Google Chrome is running, it only applies to newly opened tabs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"c6369ac25a3401c2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_enableexperimentalpoliciesdesc","displayName":"Enables experimental policies (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"c6a7a3e42f2f4a9f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl","displayName":"URL of an XML file that contains URLs to load in an alternative browser.","description":"Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlList policy.\r\n\r\nLeaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for switching browsers.\r\n\r\nNote: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode)\r\n\r\nExample value: http://example.com/sitelist.xml","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_1","displayName":"Enabled","description":null,"helpText":null}]},"c614dd663284bce8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block popups on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"c6bc55507aa2a9a2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled","displayName":"Enable Safe Browsing","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c637bf889adc2667":{"id":"device_vendor_msft_policy_config_deliveryoptimization_docachehostsource","displayName":"DO Cache Host Source","description":"Specifies how your client(s) can discover Microsoft Connected Cache servers dynamically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#docachehostsource"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"c6f7be2c6e1dd710":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdwritecachedirectory_ccdwritecachedirectory","displayName":"Write Cache Directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f2d139ed-a314-48b7-b700-4d11adfcc309","categoryName":"Cloud Cache Service","options":null},"c6a49d4fa948d978":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_devices_allowedtoformatandejectremovablemedia","displayName":"Devices Allowed To Format And Eject Removable Media","description":"Devices: Allowed to format and eject removable media This security setting determines who is allowed to format and eject removable NTFS media. This capability can be given to: Administrators Administrators and Interactive Users Default: This policy is not defined and only Administrators have this ability.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#devices_allowedtoformatandejectremovablemedia"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"c677d9d30b69ca20":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc","displayName":"Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"c6de42e35fe92b0d":{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications","displayName":"Allows system notifications","description":"Lets you use system notifications instead of Microsoft Edge's embedded Message Center on Windows and Linux.\r\n\r\nIf set to True or not set, Microsoft Edge is allowed to use system notifications.\r\n\r\nIf set to False, Microsoft Edge will not use system notifications. Microsoft Edge's embedded Message Center will be used as a fallback.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"c6625090a39c8c1c":{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy","displayName":"Microsoft Edge management service policy overrides platform policy.","description":"If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy.\r\n\r\nIf you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.\r\n\r\nThis mandatory policy affects machine scope cloud-based Microsoft Edge management policies.\r\n\r\nMachine policies apply to all edge browser instances regardless of the user who is logged in.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"c65404fe9317bbc4":{"id":"device_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"c64a5cfa1114f9f8":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled","displayName":"Enable the extended lifetime option for SharedWorkers","description":"Controls whether Microsoft Edge allows SharedWorkers to use the extendedLifetime option.\r\n\r\nIf you enable or don't configure this policy, SharedWorkers can use the extended lifetime option in the SharedWorker constructor.\r\n\r\nIf you disable this policy, the extended lifetime option is ignored, even if it is requested by the page.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c6df38ad75dda8d4":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall","displayName":"Prevent install of the BHO to redirect incompatible sites from Internet Explorer to Microsoft Edge","description":"This setting lets you specify whether to block the install of the Browser Helper Object (BHO) that enables redirecting incompatible sites from Internet Explorer to Microsoft Edge for sites that require a modern browser.\r\n\r\nIf you enable this policy, the BHO will not be installed. If it is already installed it will be uninstalled on the next Microsoft Edge update.\r\n\r\nIf this policy is not configured or is disabled, the BHO will be installed.\r\n\r\nThe BHO is required for incompatible site redirection to occur, however whether redirection occurs or not is also controlled by 'RedirectSitesFromInternetExplorerRedirectMode' (Redirect incompatible sites from Internet Explorer to Microsoft Edge).\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},"c68828c66ce454c2":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\r\n\r\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise JavaScript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"c62f81f7f1544b38":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended","displayName":"Show Hubs Sidebar","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"c6327b92f64acb15":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_spdesignexe","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_spdesignexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_spdesignexe_1","displayName":"True","description":null,"helpText":null}]},"c69a40a617c3f2b0":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_scriptedwindowsecurityrestrictions_l_winprojexe90","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_scriptedwindowsecurityrestrictions_l_winprojexe90_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_scriptedwindowsecurityrestrictions_l_winprojexe90_1","displayName":"True","description":null,"helpText":null}]},"c605f3a504fd557e":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_sharepointonpremoidc_dropdown","displayName":"Allow OIDC authentication:","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_sharepointonpremoidc_dropdown_0","displayName":"Disable OIDC Authentication","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_sharepointonpremoidc_dropdown_1","displayName":"Enable OIDC Authentication","description":null,"helpText":null}]},"c6276fecb1212a89":{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery","displayName":"Select Lid Close Action On Battery","description":"This policy setting specifies the action that Windows takes when a user closes the lid on a mobile PC. Possible actions include: 0 - Take no action 1 - Sleep 2 - Hibernate 3 - Shut down If you enable this policy setting, you must select the desired action. If you disable this policy setting or do not configure it, users can see and change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#selectlidcloseactiononbattery"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":[{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery_0","displayName":"Take no action","description":"Take no action","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery_1","displayName":"Sleep","description":"Sleep","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery_2","displayName":"System hibernate sleep state","description":"System hibernate sleep state","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery_3","displayName":"System shutdown","description":"System shutdown","helpText":null}]},"c680b66deb983eec":{"id":"device_vendor_msft_policy_config_privacy_allowautoacceptpairingandprivacyconsentprompts","displayName":"Allow Auto Accept Pairing And Privacy Consent Prompts","description":"Allows or disallows the automatic acceptance of the pairing and privacy user consent dialog when launching apps. NoteThere were issues reported with the previous release of this policy and a fix was Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#allowautoacceptpairingandprivacyconsentprompts"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_allowautoacceptpairingandprivacyconsentprompts_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_allowautoacceptpairingandprivacyconsentprompts_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"c6c0b8f407497195":{"id":"device_vendor_msft_policy_config_update_configuredeadlineforfeatureupdates","displayName":"Configure Deadline For Feature Updates","description":"Number of days before feature updates are installed on devices automatically regardless of active hours. Before the deadline passes, users will be able to schedule restarts, and automatic restarts can happen outside of active hours. When set to 0, updates will download and install immediately, but might not finish within the day due to device availability and network connectivity.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlineforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"c6dd9bfe408028a4":{"id":"device_vendor_msft_policy_config_windowslogon_allowautomaticrestartsignon","displayName":"Sign-in and lock last interactive user automatically after a restart","description":"This policy setting controls whether a device will automatically sign in and lock the last interactive user after the system restarts or after a shutdown and cold boot.\n\nThis only occurs if the last interactive user didn’t sign out before the restart or shutdown.​\n\nIf the device is joined to Active Directory or Azure Active Directory, this policy only applies to Windows Update restarts. Otherwise, this will apply to both Windows Update restarts and user-initiated restarts and shutdowns.​\n\nIf you don’t configure this policy setting, it is enabled by default. When the policy is enabled, the user is automatically signed in and the session is automatically locked with all lock screen apps configured for that user after the device boots.​\n\nAfter enabling this policy, you can configure its settings through the ConfigAutomaticRestartSignOn policy, which configures the mode of automatically signing in and locking the last interactive user after a restart or cold boot​.\n\nIf you disable this policy setting, the device does not configure automatic sign in. The user’s lock screen apps are not restarted after the system restarts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowslogon#windowslogon-allowautomaticrestartsignon"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_windowslogon_allowautomaticrestartsignon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowslogon_allowautomaticrestartsignon_1","displayName":"Enabled","description":null,"helpText":null}]},"c6b1a702313b777f":{"id":"diskmanagement_restrictions_networkstorage","displayName":"Network Storage","description":"Specifies the mount policy for network storage:\n* Allowed - network storage that is read-write or read-only will be mounted.\n* ReadOnly - only network storage that is read-only will be mounted. Note that network storage that is read-write will not be mounted read-only.\n* Disallowed - no network storage will be mounted.","helpText":null,"infoUrls":[],"categoryId":"83febe72-a64f-4051-9071-1efae1ea9a15","categoryName":"Disk Management","options":[{"id":"diskmanagement_restrictions_networkstorage_0","displayName":"Allowed","description":null,"helpText":null},{"id":"diskmanagement_restrictions_networkstorage_1","displayName":"ReadOnly","description":null,"helpText":null},{"id":"diskmanagement_restrictions_networkstorage_2","displayName":"Disallowed","description":null,"helpText":null}]},"c65841855f2e24a2":{"id":"softwareupdate_beta_offerprograms_item_description","displayName":"Description","description":"A human readable description of the beta program.","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":null},"c6940834f54ddd93":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_newgpodisplayname_newgpodisplaynameheading","displayName":"GPO Name: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"c671e3c0ea51768b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_routing","displayName":"Routing (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-routing"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_routing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_routing_1","displayName":"Enabled","description":null,"helpText":null}]},"c694bb73d9a0a65d":{"id":"user_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled","displayName":"Pin Apps to Start when installed (User)","description":"This policy setting allows pinning apps to Start by default, when they are included by AppID on the list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-startpinappswheninstalled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_1","displayName":"Enabled","description":null,"helpText":null}]},"c6273d2f8cd7dc46":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled","displayName":"Enable First-Party Sets. (User)","description":"This policy is provided as a way to opt-out of the First-Party Sets feature.\r\n\r\nWhen this policy is unset or set to Enabled, the First-Party Sets feature is enabled.\r\n\r\nWhen this policy is set to Disabled, the First-Party Sets feature is disabled.\r\n\r\nIt controls whether Chrome supports First-Party Sets related integrations.\r\n\r\nThis is the equivalent of the RelatedWebsiteSetsEnabled policy.\r\nEither policy may be used, but this one will be deprecated soon so the RelatedWebsiteSetsEnabled policy is preferred.\r\nThey both have the same effect on the browser's behavior.","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c61c041416eb6ed4":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"c62cd8829b53ffe7":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"c6b2cfb0d080c064":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowscriptlets"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"c6940fe2516e67c3":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowuserdatapersistence"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"c65249d46ee223b0":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},"c6f49540019d60b0":{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled","displayName":"Guided Switch Enabled (User)","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\r\n\r\nIf you enable this policy, you'll be prompted to switch to another account if the current profile doesn't work for the requesting link.\r\n\r\nIf you disable this policy, you won't be prompted to switch to another account when there's a profile and link mismatch.\r\n\r\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c6640da3b17b7c3f":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended","displayName":"Performance Detector Enabled (User)","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\r\n\r\nIf you enable or don't configure this policy, performance detector is turned on.\r\n\r\nIf you disable this policy, performance detector is turned off.\r\n\r\nThe user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"c67d5ea2f44dc085":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed (User)","description":"This policy determines whether Microsoft Edge handles interactions with printer drivers through a separate service process.\r\n\r\nUsing a service process for tasks like querying available printers, retrieving print driver settings, and submitting documents to local printers improves browser stability and prevents UI freezing during Print Preview.\r\n\r\nEnabled or Not Set: Microsoft Edge will use a separate service process for these printing tasks.\r\n\r\nDisabled: Microsoft Edge will perform these printing tasks within the browser process.\r\n\r\nNote: This policy will be deprecated in the future once the transition to out-of-process print drivers is fully implemented.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"c622a3127bf9041b":{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended","displayName":"Configure Edge scareware blocker to block sites detected as potential tech scams (User)","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will block sites detected as potential tech scams.\r\n\r\nIf you disable this policy, Microsoft Edge will not block sites detected as potential tech scams.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"c6f583891f3f84a0":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps (User)","description":"Specifies a list of websites that are installed silently, without user interaction, and which can't be uninstalled or disabled by the user.\r\n\r\nEach list item of the policy is an object with the following members:\r\n - \"url\", which is mandatory. \"url\" should be the URL of the web app to install.\r\n\r\nValues for the optional members are:\r\n - \"launch_container\" should be either \"window\" or \"tab\" to indicate how the Web App will be opened after it's installed.\r\n - \"create_desktop_shortcut\" should be true if a desktop shortcut should be created on Windows.\r\n\r\nIf \"default_launch_container\" is omitted, the app will open in a tab by default. Regardless of the value of \"default_launch_container\", users can change which container the app will open in. If \"create_desktop_shortcuts\" is omitted, no desktop shortcuts will be created.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.contoso.com/maps\", \r\n \"create_desktop_shortcut\": true, \r\n \"default_launch_container\": \"window\"\r\n }, \r\n {\r\n \"url\": \"https://app.contoso.edu\", \r\n \"default_launch_container\": \"tab\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"c662ef62c21657f4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish","displayName":"Danish (User)","description":"Enables the editing language Danish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish_1","displayName":"Enabled","description":null,"helpText":null}]},"c666933fd90935d0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian","displayName":"Georgian (User)","description":"Enables the editing language Georgian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian_1","displayName":"Enabled","description":null,"helpText":null}]},"c69334009075c061":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature","displayName":"Trust legacy VBA signatures (User)","description":"This policy setting allows you to control how Office loads and verifies legacy Visual Basic for Applications (VBA) signatures.\r\n\r\nIf you enable or do not configure this policy setting, Office applications can load and verify legacy VBA signatures.\r\n\r\nIf you disable this policy setting, Office applications can’t load or verify legacy VBA signatures. They can only load and verify agile VBA signatures.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature_1","displayName":"Enabled","description":null,"helpText":null}]},"c61e2ad13f90b5f1":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup","displayName":"Check to enable automatic backup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup_1","displayName":"True","description":null,"helpText":null}]},"c6ee67048fd04bca":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_urladdressofassociatedwebpage49","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"c6187e758892ccac":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls","displayName":"Missing CRLs (User)","description":"This policy setting controls whether Outlook considers a missing certificate revocation list (CRL) a warning or an error. Digital certificates contain an attribute that shows where the corresponding CRL is located. CRLs contain lists of digital certificates that have been revoked by their controlling certification authorities (CAs), typically because the certificates were issued improperly or their associated private keys were compromised. If a CRL is missing or unavailable, Outlook cannot determine whether a certificate has been revoked. Therefore, an improperly issued certificate or one that has been compromised might be used to gain access to data. \r\n\r\nIf you enable this policy setting, you can choose between two options that determine how Outlook functions when a CRL is missing: \r\n\r\n- Warning. This option is the default configuration in Outlook and ensures that Outlook displays a warning message when a CRL is missing. \r\n\r\n- Error. This option ensures that Outlook displays an error message when a CRL is missing. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays a warning message when a CRL is not available.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_1","displayName":"Enabled","description":null,"helpText":null}]},"c6c220fae21986b1":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold","displayName":"Cached Exchange low bandwidth threshold (User)","description":"Specifies the bit rate threshold value. If the bit rate of the active network connection is below this value, Outlook identifies the network connection as a \"slow\" connection and operates accordingly (for example, downloading headers instead of full messages).","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_1","displayName":"Enabled","description":null,"helpText":null}]},"c6bc0fd8a39388d4":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_descriptioncolon86","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"c6d561513f7bbb4e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"c62dda0116e019e6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"c6de6288216e86fa":{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_printersharedid","displayName":"Shared ID (User)","description":"Universal Print printer shared id","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/UPPrinterInstalls-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},"c6711f76eb2245a1":{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected","displayName":"Stay Connected (Windows Insiders only)","description":"When set to 0: Default network discovery behavior is applied. When set to 1: Once connected, the device will always stay connected to this network. This means the device will not attempt to discover or switch to other higher priority networks until it first loses connectivity to this network.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected_0","displayName":"Default network discovery behavior.","description":"Default network discovery behavior.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected_1","displayName":"Once connected to this network, try to stay connected.","description":"Once connected to this network, try to stay connected.","helpText":null}]}} \ No newline at end of file +{"c631d22b247c8980":{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation","displayName":"Force Classroom Unprompted Screen Observation","description":"If `true` and `ScreenObservationPermissionModificationAllowed` is also `true` in the Education payload, a student enrolled in a managed course through the Classroom app automatically gives permission to that course teacher's requests to observe the student's screen without prompting the student.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.applicationaccess_forceclassroomunpromptedscreenobservation_true","displayName":"Enabled","description":null,"helpText":null}]},"c6c62a8faf7a4868":{"id":"com.apple.directoryservice.managed_adusewindowsuncpath","displayName":"AD Use Windows UNC Path","description":"If true, uses the UNC path from Active Directory to derive the network home location.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adusewindowsuncpath_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adusewindowsuncpath_true","displayName":"True","description":null,"helpText":null}]},"c6277898ce9f6b9e":{"id":"com.apple.dock_contents-immutable","displayName":"Contents Immutable","description":"If true, disables changes to the dock.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_contents-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_contents-immutable_true","displayName":"True","description":null,"helpText":null}]},"c6d9cab047c52a26":{"id":"com.apple.loginwindow_adminhostinfo","displayName":"Admin Host Info","description":"If this key is included in the payload, its value is displayed in the login window as additional computer information. Before macOS 10.10, this string could contain only certain information (host name, system version, or IP address). After macOS 10.10, setting this key to any value allows the user to click the time area of the menu bar to toggle through various computer information values.","helpText":null,"infoUrls":[],"categoryId":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","categoryName":"Login Window Behavior","options":null},"c66d13c35a5f0034":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_lcid","displayName":"Microsoft Edge Canary LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"c6d3d9d24e291607":{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step","displayName":"Dynamic Power Step","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.desktop.acpower_dynamic power step_1","displayName":"True","description":null,"helpText":null}]},"c67594988a0d619c":{"id":"com.apple.system-extension-policy_nonremovablesystemextensions_generickey","displayName":"ANY","description":"System extension bundle identifiers","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"c6f8ba7edfcc1f15":{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization","displayName":"Authorization","description":"The Authorization key is an optional replacement for the Allowed key. Every payload must specify either Authorization or Allowed, but not both.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_0","displayName":"Allow","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_1","displayName":"Deny","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_photos_item_authorization_2","displayName":"Allow Standard User To Set System Service","description":null,"helpText":null}]},"c61660b0901bf69a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting","displayName":"Control use of the WebUSB API","description":"Set whether websites can access connected USB devices. You can completely block access or ask the user each time a website wants to get access to connected USB devices.\n\nYou can override this policy for specific URL patterns by using the \"WebUsbAskForUrls\" and \"WebUsbBlockedForUrls\" policies.\n\nIf you don't configure this policy, sites can ask users whether they can access the connected USB devices ('AskWebUsb') by default, and users can change this setting.\n\nPolicy options mapping:\n\n* BlockWebUsb (2) = Do not allow any site to request access to USB devices via the WebUSB API\n\n* AskWebUsb (3) = Allow sites to ask the user to grant access to a connected USB device\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting_blockwebusb","displayName":"Do not allow any site to request access to USB devices via the WebUSB API","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultwebusbguardsetting_askwebusb","displayName":"Allow sites to ask the user to grant access to a connected USB device","description":null,"helpText":null}]},"c6a5066b866532e4":{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Defines a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\n\nIf you don't configure this policy, \"DefaultJavaScriptSetting\" applies for all sites, if it's set. If not, the user's personal setting applies.\n\nFor detailed information on valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nThis policy blocks JavaScript based on whether the origin of the top-level document (usually the page URL that's also displayed in the address bar) matches any of the patterns. Therefore, this policy isn't appropriate for mitigating web supply-chain attacks. For example, supplying the pattern `https://[*.]foo.com/` doesn't prevent a page hosted on, say, `https://contoso.com`, from running a script loaded from `https://www.foo.com/example.js`. Furthermore, supplying the pattern `https://contoso.com/` doesn't prevent a document from `https://contoso.com` from running scripts if it isn't the top-level document, but embedded as a subframe into a page hosted on another origin, say, `https://www.fabrikam.com`.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"c6e4ef1a6b8b8398":{"id":"contentcaching_listenwithpeersandparents","displayName":"Listen With Peers And Parents","description":"If `true`, the content cache provides content to the clients in the union of the `ListenRanges`, `PeerListenRanges` and `Parents`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_listenwithpeersandparents_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_listenwithpeersandparents_true","displayName":"Enabled","description":null,"helpText":null}]},"c68c060af48ecf89":{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery","displayName":"Enable Pin Recovery","description":"If the user forgets their PIN, it can be changed to a new PIN using the Windows Hello for Business PIN recovery service. This cloud service encrypts a recovery secret which is stored locally on the client, but which can only be decrypted by the cloud service.\n\nIf you enable this policy setting, the PIN recovery secret will be stored on the device and the user will be able to change to a new PIN in case their PIN is forgotten.\n\nIf you disable or do not configure this policy setting, the PIN recovery secret will not be created or stored. If the user's PIN is forgotten, the only way to get a new PIN is by deleting the existing PIN and creating a new one, which will require the user to re-register with any services the old PIN provided access to.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery_false","displayName":"false","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_enablepinrecovery_true","displayName":"true","description":"Enabled","helpText":null}]},"c6108d7ed62a09cb":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk","displayName":"Force queue mode for application errors","description":null,"helpText":"","infoUrls":[],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_configurereport_pch_forceq_chk_1","displayName":"True","description":null,"helpText":null}]},"c645450649161c3b":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring","displayName":"Turn on behavior monitoring","description":"This policy setting allows you to configure behavior monitoring.\r\n\r\n If you enable or do not configure this setting, behavior monitoring will be enabled.\r\n\r\n If you disable this setting, behavior monitoring will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablebehaviormonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablebehaviormonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},"c60391fb45993091":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt","displayName":"NoDefaultExempt","description":null,"helpText":"","infoUrls":[],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_0","displayName":"Allow all exemptions.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_1","displayName":"Multicast, broadcast, & ISAKMP exempt.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_2","displayName":"RSVP, Kerberos, and ISAKMP are exempt.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_nodefaultexempt_nodefaultexempt_3","displayName":"Only ISAKMP is exempt.","description":null,"helpText":null}]},"c6b8bc83c90ea816":{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages","displayName":"Remove Default Microsoft Store packages from the system.","description":"Removes Default Microsoft Store packages from the system.\n\nIf you enable this policy, the selected Microsoft Store apps in the provided list will be uninstalled from the system. You can make adjustments to the default settings.\n\nUnselected apps in the list will not be removed.\n\nDefault is 'disabled' (key not present).\n\nIf the policy is disabled or not configured, no Default Microsoft Store packages will be removed from the system.\n\n* This is a headless app (no UI)\n\n** This app is the default handler for a common file type or protocol. Removing this app might result in a degraded user experience. We do not recommend removing this app.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-applicationmanagement#applicationmanagement-removedefaultmicrosoftstorepackages"],"categoryId":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","categoryName":"App Package Deployment","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_removedefaultmicrosoftstorepackages_1","displayName":"Enabled","description":null,"helpText":null}]},"c681a0da531ab25a":{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange","displayName":"Audit Changes to Audit Policy","description":"This policy setting allows you to audit changes in the security audit policy settings such as the following: Settings permissions and audit settings on the Audit Policy object. Changes to the system audit policy. Registration of security event sources. De-registration of security event sources. Changes to the per-user audit settings. Changes to the value of CrashOnAuditFail. Changes to the system access control list on a file system or registry object. Changes to the Special Groups list. Note: System access control list (SACL) change auditing is done when a SACL for an object changes and the policy change category is enabled. Discretionary access control list (DACL) and ownership changes are audited when object access auditing is enabled and the object's SACL is configured for auditing of DACL/Owner change.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"c687b20a55cc3981":{"id":"device_vendor_msft_policy_config_bluetooth_setminimumencryptionkeysize","displayName":"Set Minimum Encryption Key Size","description":"There are multiple levels of encryption strength when pairing Bluetooth devices. This policy helps prevent weaker devices cryptographically being used in high security environments.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Bluetooth#setminimumencryptionkeysize"],"categoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","categoryName":"Bluetooth","options":null},"c6aa8b26700fa897":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed","displayName":"Allow media autoplay","description":"Setting the policy to True lets Google Chrome autoplay media. Setting the policy to False stops Google Chrome from autoplaying media.\r\n\r\n By default, Google Chrome doesn't autoplay media. But, for certain URL patterns, you can use the AutoplayAllowlist policy to change this setting.\r\n\r\nIf this policy changes while Google Chrome is running, it only applies to newly opened tabs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"c6369ac25a3401c2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_enableexperimentalpolicies_enableexperimentalpoliciesdesc","displayName":"Enables experimental policies (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"c6a7a3e42f2f4a9f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl","displayName":"URL of an XML file that contains URLs to load in an alternative browser.","description":"Setting the policy to a valid URL has Google Chrome download the site list from that URL and apply the rules as if they were set up with the BrowserSwitcherUrlList policy.\r\n\r\nLeaving it unset (or set to a invalid URL) means Google Chrome doesn't use the policy as a source of rules for switching browsers.\r\n\r\nNote: This policy points to an XML file in the same format as Internet Explorer®'s SiteList policy. This loads rules from an XML file, without sharing those rules with Internet Explorer®. Read more on Internet Explorer®'s SiteList policy ( https://docs.microsoft.com/internet-explorer/ie11-deploy-guide/what-is-enterprise-mode)\r\n\r\nExample value: http://example.com/sitelist.xml","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_1","displayName":"Enabled","description":null,"helpText":null}]},"c614dd663284bce8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_popupsblockedforurls_popupsblockedforurlsdesc","displayName":"Block popups on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"c6bc55507aa2a9a2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled","displayName":"Enable Safe Browsing","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c637bf889adc2667":{"id":"device_vendor_msft_policy_config_deliveryoptimization_docachehostsource","displayName":"DO Cache Host Source","description":"Specifies how your client(s) can discover Microsoft Connected Cache servers dynamically.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#docachehostsource"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"c6f7be2c6e1dd710":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~ccd_ccdwritecachedirectory_ccdwritecachedirectory","displayName":"Write Cache Directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f2d139ed-a314-48b7-b700-4d11adfcc309","categoryName":"Cloud Cache Service","options":null},"c6a49d4fa948d978":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_devices_allowedtoformatandejectremovablemedia","displayName":"Devices Allowed To Format And Eject Removable Media","description":"Devices: Allowed to format and eject removable media This security setting determines who is allowed to format and eject removable NTFS media. This capability can be given to: Administrators Administrators and Interactive Users Default: This policy is not defined and only Administrators have this ability.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#devices_allowedtoformatandejectremovablemedia"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"c677d9d30b69ca20":{"id":"device_vendor_msft_policy_config_microsoft_edge_webview2v1~policy~microsoft_edge_webview2~webview2loaderoverridesettings_browserexecutablefolder_browserexecutablefolderdesc","displayName":"Set value name to the Application User Model ID or the executable file name. You can use the \"*\" wildcard as value name to apply to all applications. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"13cc3b63-a150-4cf2-8d76-309975603c8e","categoryName":"Loader Override Settings","options":null},"c6de42e35fe92b0d":{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications","displayName":"Allows system notifications","description":"Lets you use system notifications instead of Microsoft Edge's embedded Message Center on Windows and Linux.\r\n\r\nIf set to True or not set, Microsoft Edge is allowed to use system notifications.\r\n\r\nIf set to False, Microsoft Edge will not use system notifications. Microsoft Edge's embedded Message Center will be used as a fallback.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev117~policy~microsoft_edge_allowsystemnotifications_1","displayName":"Enabled","description":null,"helpText":null}]},"c6625090a39c8c1c":{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy","displayName":"Microsoft Edge management service policy overrides platform policy.","description":"If you enable this policy, the cloud-based Microsoft Edge management service policy takes precedence if it conflicts with platform policy.\r\n\r\nIf you disable or don't configure this policy, platform policy takes precedence if it conflicts with the cloud-based Microsoft Edge management service policy.\r\n\r\nThis mandatory policy affects machine scope cloud-based Microsoft Edge management policies.\r\n\r\nMachine policies apply to all edge browser instances regardless of the user who is logged in.","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev119~policy~microsoft_edge~manageability_edgemanagementpolicyoverridesplatformpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"c65404fe9317bbc4":{"id":"device_vendor_msft_policy_config_microsoft_edgev137~policy~microsoft_edge_onprintenterpriseconnector_onprintenterpriseconnector","displayName":"Configuration policy for print for Microsoft Edge for Business Data Loss Prevention Connectors (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"c64a5cfa1114f9f8":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled","displayName":"Enable the extended lifetime option for SharedWorkers","description":"Controls whether Microsoft Edge allows SharedWorkers to use the extendedLifetime option.\r\n\r\nIf you enable or don't configure this policy, SharedWorkers can use the extended lifetime option in the SharedWorker constructor.\r\n\r\nIf you disable this policy, the extended lifetime option is ignored, even if it is requested by the page.\r\n\r\nThis policy is temporary and will be removed in a future release.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_sharedworkerextendedlifetimeenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c6df38ad75dda8d4":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall","displayName":"Prevent install of the BHO to redirect incompatible sites from Internet Explorer to Microsoft Edge","description":"This setting lets you specify whether to block the install of the Browser Helper Object (BHO) that enables redirecting incompatible sites from Internet Explorer to Microsoft Edge for sites that require a modern browser.\r\n\r\nIf you enable this policy, the BHO will not be installed. If it is already installed it will be uninstalled on the next Microsoft Edge update.\r\n\r\nIf this policy is not configured or is disabled, the BHO will be installed.\r\n\r\nThe BHO is required for incompatible site redirection to occur, however whether redirection occurs or not is also controlled by 'RedirectSitesFromInternetExplorerRedirectMode' (Redirect incompatible sites from Internet Explorer to Microsoft Edge).\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerpreventbhoinstall_1","displayName":"Enabled","description":null,"helpText":null}]},"c68828c66ce454c2":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites","displayName":"Block JavaScript from using JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are not allowed to run JavaScript JIT (Just In Time) compiler enabled.\r\n\r\nDisabling the JavaScript JIT will mean that Microsoft Edge may render web content more slowly, and may also disable parts of JavaScript including WebAssembly. Disabling the JavaScript JIT may allow Microsoft Edge to render web content in a more secure configuration.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitBlockedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise JavaScript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"c62f81f7f1544b38":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended","displayName":"Show Hubs Sidebar","description":"Shows a launcher bar on the right side of Microsoft Edge's screen.\r\n\r\nEnable this policy to always show the Sidebar.\r\nDisable this policy to never show the Sidebar.\r\n\r\nIf you don't configure the policy, users can choose whether to show the Sidebar.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_recommended_hubssidebarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"c6327b92f64acb15":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_spdesignexe","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_spdesignexe_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictactivexinstall_l_spdesignexe_1","displayName":"True","description":null,"helpText":null}]},"c69a40a617c3f2b0":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_scriptedwindowsecurityrestrictions_l_winprojexe90","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_scriptedwindowsecurityrestrictions_l_winprojexe90_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_scriptedwindowsecurityrestrictions_l_winprojexe90_1","displayName":"True","description":null,"helpText":null}]},"c605f3a504fd557e":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_sharepointonpremoidc_dropdown","displayName":"Allow OIDC authentication:","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_sharepointonpremoidc_dropdown_0","displayName":"Disable OIDC Authentication","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_sharepointonpremoidc_sharepointonpremoidc_dropdown_1","displayName":"Enable OIDC Authentication","description":null,"helpText":null}]},"c6276fecb1212a89":{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery","displayName":"Select Lid Close Action On Battery","description":"This policy setting specifies the action that Windows takes when a user closes the lid on a mobile PC. Possible actions include: 0 - Take no action 1 - Sleep 2 - Hibernate 3 - Shut down If you enable this policy setting, you must select the desired action. If you disable this policy setting or do not configure it, users can see and change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#selectlidcloseactiononbattery"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":[{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery_0","displayName":"Take no action","description":"Take no action","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery_1","displayName":"Sleep","description":"Sleep","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery_2","displayName":"System hibernate sleep state","description":"System hibernate sleep state","helpText":null},{"id":"device_vendor_msft_policy_config_power_selectlidcloseactiononbattery_3","displayName":"System shutdown","description":"System shutdown","helpText":null}]},"c680b66deb983eec":{"id":"device_vendor_msft_policy_config_privacy_allowautoacceptpairingandprivacyconsentprompts","displayName":"Allow Auto Accept Pairing And Privacy Consent Prompts","description":"Allows or disallows the automatic acceptance of the pairing and privacy user consent dialog when launching apps. NoteThere were issues reported with the previous release of this policy and a fix was Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#allowautoacceptpairingandprivacyconsentprompts"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_allowautoacceptpairingandprivacyconsentprompts_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_allowautoacceptpairingandprivacyconsentprompts_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"c6c0b8f407497195":{"id":"device_vendor_msft_policy_config_update_configuredeadlineforfeatureupdates","displayName":"Configure Deadline For Feature Updates","description":"Number of days before feature updates are installed on devices automatically regardless of active hours. Before the deadline passes, users will be able to schedule restarts, and automatic restarts can happen outside of active hours. When set to 0, updates will download and install immediately, but might not finish within the day due to device availability and network connectivity.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlineforfeatureupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"c6dd9bfe408028a4":{"id":"device_vendor_msft_policy_config_windowslogon_allowautomaticrestartsignon","displayName":"Sign-in and lock last interactive user automatically after a restart","description":"This policy setting controls whether a device will automatically sign in and lock the last interactive user after the system restarts or after a shutdown and cold boot.\n\nThis only occurs if the last interactive user didn’t sign out before the restart or shutdown.​\n\nIf the device is joined to Active Directory or Azure Active Directory, this policy only applies to Windows Update restarts. Otherwise, this will apply to both Windows Update restarts and user-initiated restarts and shutdowns.​\n\nIf you don’t configure this policy setting, it is enabled by default. When the policy is enabled, the user is automatically signed in and the session is automatically locked with all lock screen apps configured for that user after the device boots.​\n\nAfter enabling this policy, you can configure its settings through the ConfigAutomaticRestartSignOn policy, which configures the mode of automatically signing in and locking the last interactive user after a restart or cold boot​.\n\nIf you disable this policy setting, the device does not configure automatic sign in. The user’s lock screen apps are not restarted after the system restarts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-windowslogon#windowslogon-allowautomaticrestartsignon"],"categoryId":"43eca758-22c0-4625-8f12-85a8a34ea8b1","categoryName":"Windows Logon Options","options":[{"id":"device_vendor_msft_policy_config_windowslogon_allowautomaticrestartsignon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowslogon_allowautomaticrestartsignon_1","displayName":"Enabled","description":null,"helpText":null}]},"c6b1a702313b777f":{"id":"diskmanagement_restrictions_networkstorage","displayName":"Network Storage","description":"Specifies the mount policy for network storage:\n* Allowed - network storage that is read-write or read-only will be mounted.\n* ReadOnly - only network storage that is read-only will be mounted. Note that network storage that is read-write will not be mounted read-only.\n* Disallowed - no network storage will be mounted.","helpText":null,"infoUrls":[],"categoryId":"83febe72-a64f-4051-9071-1efae1ea9a15","categoryName":"Disk Management","options":[{"id":"diskmanagement_restrictions_networkstorage_0","displayName":"Allowed","description":null,"helpText":null},{"id":"diskmanagement_restrictions_networkstorage_1","displayName":"ReadOnly","description":null,"helpText":null},{"id":"diskmanagement_restrictions_networkstorage_2","displayName":"Disallowed","description":null,"helpText":null}]},"c65841855f2e24a2":{"id":"softwareupdate_beta_offerprograms_item_description","displayName":"Description","description":"A human readable description of the beta program.","helpText":null,"infoUrls":[],"categoryId":"b382d980-7459-4850-a45e-75dd99488972","categoryName":"Software Update Settings","options":null},"c6940834f54ddd93":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_newgpodisplayname_newgpodisplaynameheading","displayName":"GPO Name: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"c671e3c0ea51768b":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_routing","displayName":"Routing (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-routing"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_routing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_routing_1","displayName":"Enabled","description":null,"helpText":null}]},"c694bb73d9a0a65d":{"id":"user_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled","displayName":"Pin Apps to Start when installed (User)","description":"This policy setting allows pinning apps to Start by default, when they are included by AppID on the list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-startpinappswheninstalled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_1","displayName":"Enabled","description":null,"helpText":null}]},"c6273d2f8cd7dc46":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled","displayName":"Enable First-Party Sets. (User)","description":"This policy is provided as a way to opt-out of the First-Party Sets feature.\r\n\r\nWhen this policy is unset or set to Enabled, the First-Party Sets feature is enabled.\r\n\r\nWhen this policy is set to Disabled, the First-Party Sets feature is disabled.\r\n\r\nIt controls whether Chrome supports First-Party Sets related integrations.\r\n\r\nThis is the equivalent of the RelatedWebsiteSetsEnabled policy.\r\nEither policy may be used, but this one will be deprecated soon so the RelatedWebsiteSetsEnabled policy is preferred.\r\nThey both have the same effect on the browser's behavior.","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c61c041416eb6ed4":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209","displayName":"Scriptlets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"c62cd8829b53ffe7":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls (User)","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"c6b2cfb0d080c064":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowscriptlets"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"c6940fe2516e67c3":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownrestrictedsiteszoneallowuserdatapersistence"],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"c65249d46ee223b0":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},"c6f49540019d60b0":{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled","displayName":"Guided Switch Enabled (User)","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\r\n\r\nIf you enable this policy, you'll be prompted to switch to another account if the current profile doesn't work for the requesting link.\r\n\r\nIf you disable this policy, you won't be prompted to switch to another account when there's a profile and link mismatch.\r\n\r\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge~identity_guidedswitchenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"c6640da3b17b7c3f":{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended","displayName":"Performance Detector Enabled (User)","description":"The performance detector detects tab performance issues and recommends actions to fix the performance issues.\r\n\r\nIf you enable or don't configure this policy, performance detector is turned on.\r\n\r\nIf you disable this policy, performance detector is turned off.\r\n\r\nThe user can configure its behavior in edge://settings/system.\r\n\r\nLearn more about performance detector: https://aka.ms/EdgePerformanceDetector","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev107~policy~microsoft_edge_recommended~performance_recommended_performancedetectorenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"c67d5ea2f44dc085":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed (User)","description":"This policy determines whether Microsoft Edge handles interactions with printer drivers through a separate service process.\r\n\r\nUsing a service process for tasks like querying available printers, retrieving print driver settings, and submitting documents to local printers improves browser stability and prevents UI freezing during Print Preview.\r\n\r\nEnabled or Not Set: Microsoft Edge will use a separate service process for these printing tasks.\r\n\r\nDisabled: Microsoft Edge will perform these printing tasks within the browser process.\r\n\r\nNote: This policy will be deprecated in the future once the transition to out-of-process print drivers is fully implemented.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"c622a3127bf9041b":{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended","displayName":"Configure Edge scareware blocker to block sites detected as potential tech scams (User)","description":"This policy controls whether Microsoft Edge blocks sites that are detected as potential tech scams.\r\n\r\nThis policy only takes effect if ScarewareBlockerProtectionEnabled is enabled.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge will block sites detected as potential tech scams.\r\n\r\nIf you disable this policy, Microsoft Edge will not block sites detected as potential tech scams.","helpText":"","infoUrls":[],"categoryId":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge_recommended~scarewareblocker_recommended_scarewareblockerblocksdetectedsitesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"c6f583891f3f84a0":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps (User)","description":"Specifies a list of websites that are installed silently, without user interaction, and which can't be uninstalled or disabled by the user.\r\n\r\nEach list item of the policy is an object with the following members:\r\n - \"url\", which is mandatory. \"url\" should be the URL of the web app to install.\r\n\r\nValues for the optional members are:\r\n - \"launch_container\" should be either \"window\" or \"tab\" to indicate how the Web App will be opened after it's installed.\r\n - \"create_desktop_shortcut\" should be true if a desktop shortcut should be created on Windows.\r\n\r\nIf \"default_launch_container\" is omitted, the app will open in a tab by default. Regardless of the value of \"default_launch_container\", users can change which container the app will open in. If \"create_desktop_shortcuts\" is omitted, no desktop shortcuts will be created.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.contoso.com/maps\", \r\n \"create_desktop_shortcut\": true, \r\n \"default_launch_container\": \"window\"\r\n }, \r\n {\r\n \"url\": \"https://app.contoso.edu\", \r\n \"default_launch_container\": \"tab\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"c662ef62c21657f4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish","displayName":"Danish (User)","description":"Enables the editing language Danish","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_danish_1","displayName":"Enabled","description":null,"helpText":null}]},"c666933fd90935d0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian","displayName":"Georgian (User)","description":"Enables the editing language Georgian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_georgian_1","displayName":"Enabled","description":null,"helpText":null}]},"c69334009075c061":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature","displayName":"Trust legacy VBA signatures (User)","description":"This policy setting allows you to control how Office loads and verifies legacy Visual Basic for Applications (VBA) signatures.\r\n\r\nIf you enable or do not configure this policy setting, Office applications can load and verify legacy VBA signatures.\r\n\r\nIf you disable this policy setting, Office applications can’t load or verify legacy VBA signatures. They can only load and verify agile VBA signatures.","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustlegacysignature_1","displayName":"Enabled","description":null,"helpText":null}]},"c61e2ad13f90b5f1":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup","displayName":"Check to enable automatic backup (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c02141e6-0725-4f6f-9138-83d10c6bc104","categoryName":"Backup","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_backup_l_automaticallybackupmynotebook_l_checktoenableautomaticbackup_1","displayName":"True","description":null,"helpText":null}]},"c6ee67048fd04bca":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_deleteditemsfolderhomepage_l_urladdressofassociatedwebpage49","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"c6187e758892ccac":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls","displayName":"Missing CRLs (User)","description":"This policy setting controls whether Outlook considers a missing certificate revocation list (CRL) a warning or an error. Digital certificates contain an attribute that shows where the corresponding CRL is located. CRLs contain lists of digital certificates that have been revoked by their controlling certification authorities (CAs), typically because the certificates were issued improperly or their associated private keys were compromised. If a CRL is missing or unavailable, Outlook cannot determine whether a certificate has been revoked. Therefore, an improperly issued certificate or one that has been compromised might be used to gain access to data. \r\n\r\nIf you enable this policy setting, you can choose between two options that determine how Outlook functions when a CRL is missing: \r\n\r\n- Warning. This option is the default configuration in Outlook and ensures that Outlook displays a warning message when a CRL is missing. \r\n\r\n- Error. This option ensures that Outlook displays an error message when a CRL is missing. \r\n\r\nIf you disable or do not configure this policy setting, Outlook displays a warning message when a CRL is not available.","helpText":"","infoUrls":[],"categoryId":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","categoryName":"Signature Status dialog box","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography~l_signaturestatusdialog_l_missingcrls_1","displayName":"Enabled","description":null,"helpText":null}]},"c6c220fae21986b1":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold","displayName":"Cached Exchange low bandwidth threshold (User)","description":"Specifies the bit rate threshold value. If the bit rate of the active network connection is below this value, Outlook identifies the network connection as a \"slow\" connection and operates accordingly (for example, downloading headers instead of full messages).","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_cachedexchangelowbandwidththreshold_1","displayName":"Enabled","description":null,"helpText":null}]},"c6bc0fd8a39388d4":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_descriptioncolon86","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"c6d561513f7bbb4e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon53","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"c62dda0116e019e6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_descriptioncolon70","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"c6de6288216e86fa":{"id":"user_vendor_msft_printerprovisioning_upprinterinstalls_{printersharedid}_printersharedid","displayName":"Shared ID (User)","description":"Universal Print printer shared id","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/UPPrinterInstalls-csp/"],"categoryId":"56c54112-2991-4bda-9e01-e6868bd07726","categoryName":"Printer Provisioning","options":null},"c6711f76eb2245a1":{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected","displayName":"Stay Connected (Windows Insiders only)","description":"When set to 0: Default network discovery behavior is applied. When set to 1: Once connected, the device will always stay connected to this network. This means the device will not attempt to discover or switch to other higher priority networks until it first loses connectivity to this network.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WirelessNetworkPreference-csp/"],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":[{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected_0","displayName":"Default network discovery behavior.","description":"Default network discovery behavior.","helpText":null},{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}_stayconnected_1","displayName":"Once connected to this network, try to stay connected.","description":"Once connected to this network, try to stay connected.","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/cb.json b/public/intune-definitions/cb.json index 47b2ab321d4d..1757ab831b94 100644 --- a/public/intune-definitions/cb.json +++ b/public/intune-definitions/cb.json @@ -1 +1 @@ -{"cb63454b27c8806d":{"id":"com.apple.managedclient.preferences_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\n\nThis policy is not considered if a site matches a URL pattern in any of the following policies: \"WindowCaptureAllowedByOrigins\", \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the \"ScreenCaptureAllowed\" will not be considered.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cb6066fbcceed873":{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder","displayName":"Set the order in which S/MIME certificates are considered","description":"Set the order in which certificates will be used to decrypt and encrypt S/MIME messages.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#set-the-order-in-which-smime-certificates-are-considered"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_0","displayName":"Contacts","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_1","displayName":"Global Address List","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_2","displayName":"Device","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_3","displayName":"LDAP","description":null,"helpText":null}]},"cba799a2e9441706":{"id":"com.apple.mcx.timemachine_backupdesturl","displayName":"Backup Destination URL","description":"The URL of the backup destination.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},"cb9746560b40de8d":{"id":"com.apple.mcxprinting_userprinterlist_printer_displayname","displayName":"Display Name","description":"The display name.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},"cb49bc3b53bd11cf":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses (users can override)","description":"Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information.\n\nIf you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available.\n\nIf you disable this policy, then \"EdgeAutofillMlEnabled\" is turned off.\n\nIf you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"cb3eff8e7c8ee42c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled","displayName":"Enable CryptoWallet feature (Obsolete)","description":"This policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There's no replacement for this policy.\n Enables CryptoWallet feature in Microsoft Edge.\n\n If you enable this policy or don't configure it, users can use CryptoWallet feature that allows users to securely store, manage, and transact digital assets such as Bitcoin, Ethereum, and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature.\n\n If you disable this policy, users can't use CryptoWallet feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"cb0591ef064dc596":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_true","displayName":"Enabled","description":null,"helpText":null}]},"cb474b21a8dc8fd7":{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans","displayName":"Disable Cpu Throttle On Idle Scans","description":"Indicates whether the CPU will be throttled for scheduled scans while the device is idle. This feature is enabled by default and will not throttle the CPU for scheduled scans performed when the device is otherwise idle, regardless of what ScanAvgCPULoadFactor is set to. For all other scheduled scans this flag will have no impact and normal throttling will occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans_1","displayName":"Disable CPU Throttle on idle scans","description":"Disable CPU Throttle on idle scans","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans_0","displayName":"Enable CPU Throttle on idle scans","description":"Enable CPU Throttle on idle scans","helpText":null}]},"cbef763691201602":{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2","displayName":"Redirect folders on primary computers only","description":"This policy setting controls whether folders are redirected on a user's primary computers only. This policy setting is useful to improve logon performance and to increase security for user data on computers where the user might not want to download private data, such as on a meeting room computer or on a computer in a remote office.\r\n\r\nTo designate a user's primary computers, an administrator must use management software or a script to add primary computer attributes to the user's account in Active Directory Domain Services (AD DS). This policy setting also requires the Windows Server 2012 version of the Active Directory schema to function.\r\n\r\nIf you enable this policy setting and the user has redirected folders, such as the Documents and Pictures folders, the folders are redirected on the user's primary computer only.\r\n\r\nIf you disable or do not configure this policy setting and the user has redirected folders, the folders are redirected on every computer that the user logs on to.\r\n\r\nNote: If you enable this policy setting in Computer Configuration and User Configuration, the Computer Configuration policy setting takes precedence.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-primarycomputer-fr-2"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2_1","displayName":"Enabled","description":null,"helpText":null}]},"cb3e71ecba453fb0":{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2","displayName":"Turn off the Windows Messenger Customer Experience Improvement Program","description":"This policy setting specifies whether Windows Messenger collects anonymous information about how Windows Messenger software and service is used.\r\n\r\nWith the Customer Experience Improvement program, users can allow Microsoft to collect anonymous information about how the product is used. This information is used to improve the product in future releases.\r\n\r\nIf you enable this policy setting, Windows Messenger does not collect usage information, and the user settings to enable the collection of usage information are not shown.\r\n\r\nIf you disable this policy setting, Windows Messenger collects anonymous usage information, and the setting is not shown.\r\n\r\nIf you do not configure this policy setting, users have the choice to opt in and allow information to be collected.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-winmsg-noinstrumentation-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2_1","displayName":"Enabled","description":null,"helpText":null}]},"cbaa95a0a6bd6340":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring","displayName":"Turn off real-time protection","description":"This policy setting turns off real-time protection prompts for known malware detection.\r\n\r\n Microsoft Defender Antivirus alerts you when malware or potentially unwanted software attempts to install itself or to run on your computer.\r\n\r\n If you enable this policy setting, Microsoft Defender Antivirus will not prompt users to take actions on malware detections.\r\n\r\n If you disable or do not configure this policy setting, Microsoft Defender Antivirus will prompt users to take actions on malware detections.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disablerealtimemonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},"cb480318251f29c3":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_exploitguard_controlledfolderaccess_protectedfolders","displayName":"Enter the folders that should be guarded:","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},"cb75dc3dbd93fd7b":{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown","displayName":"Prohibit use of Restart Manager","description":"This policy setting controls Windows Installer's interaction with the Restart Manager. The Restart Manager API can eliminate or reduce the number of system restarts that are required to complete an installation or update.\r\n\r\nIf you enable this policy setting, you can use the options in the Prohibit Use of Restart Manager box to control file in use detection behavior.\r\n\r\n-- The \"Restart Manager On\" option instructs Windows Installer to use Restart Manager to detect files in use and mitigate a system restart, when possible.\r\n\r\n-- The \"Restart Manager Off\" option turns off Restart Manager for file in use detection and the legacy file in use behavior is used.\r\n\r\n-- The \"Restart Manager Off for Legacy App Setup\" option applies to packages that were created for Windows Installer versions lesser than 4.0. This option lets those packages display the legacy files in use UI while still using Restart Manager for detection.\r\n\r\nIf you disable or do not configure this policy setting, Windows Installer will use Restart Manager to detect files in use and mitigate a system restart, when possible.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disableautomaticapplicationshutdown"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},"cbb5d72316da5645":{"id":"device_vendor_msft_policy_config_admx_nca_dtes","displayName":"IPsec Tunnel Endpoints","description":"Specifies the IPv6 addresses of the endpoints of the Internet Protocol security (IPsec) tunnels that enable DirectAccess. NCA attempts to access the resources that are specified in the Corporate Resources setting through these configured tunnel endpoints. \r\n\r\nBy default, NCA uses the same DirectAccess server that the DirectAccess client computer connection is using. In default configurations of DirectAccess, there are typically two IPsec tunnel endpoints: one for the infrastructure tunnel and one for the intranet tunnel. You should configure one endpoint for each tunnel. \r\n\t \r\nEach entry consists of the text PING: followed by the IPv6 address of an IPsec tunnel endpoint. Example: PING:2002:836b:1::836b:1.\r\n\r\nYou must configure this setting to have complete NCA functionality.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-dtes"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_dtes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_dtes_1","displayName":"Enabled","description":null,"helpText":null}]},"cb653f0d48c55d10":{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity","displayName":"Turn off password security in Input Panel","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_1","displayName":"Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_4","displayName":"Medium High","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_5","displayName":"High","description":null,"helpText":null}]},"cb9b243dd5ae4246":{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional","displayName":"Allow Microsoft accounts to be optional","description":"This policy setting lets you control whether Microsoft accounts are optional for packaged Microsoft Store apps that require an account to sign in. This policy only affects packaged Microsoft Store apps that support it.\n\nIf you enable this policy setting, packaged Microsoft Store apps that typically require a Microsoft account to sign in will allow users to sign in with an enterprise account instead.\n\nIf you disable or do not configure this policy setting, users will need to sign in with a Microsoft account.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-appruntime#appruntime-allowmicrosoftaccountstobeoptional"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional_1","displayName":"Enabled","description":null,"helpText":null}]},"cb4a185105c3e49e":{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading","displayName":"Allow Tab Preloading","description":"Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowtabpreloading"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading_1","displayName":"Allow","description":"Allowed. Preload Start and New tab pages.","helpText":null}]},"cbeea55439d957c5":{"id":"device_vendor_msft_policy_config_browser_configurekioskmode","displayName":"Configure Kiosk Mode","description":"Configure how Microsoft Edge behaves when it’s running in kiosk mode with assigned access, either as a single app or as one of multiple apps running on the kiosk device. You can control whether Microsoft Edge runs InPrivate full screen, InPrivate multi-tab with limited functionality, or normal Microsoft Edge. You need to configure Microsoft Edge in assigned access for this policy to take effect; otherwise, these settings are ignored. To learn more about assigned access and kiosk configuration, see “Configure kiosk and shared devices running Windows desktop editions” (https://aka.ms/E489vw). If enabled and set to 0 (Default or not configured): - If it’s a single app, it runs InPrivate full screen for digital signage or interactive displays. - If it’s one of many apps, Microsoft Edge runs as normal. If enabled and set to 1: - If it’s a single app, it runs a limited multi-tab version of InPrivate and is the only app available for public browsing. Users can’t minimize, close, or open windows or customize Microsoft Edge, but can clear browsing data and downloads and restart by clicking “End session.” You can configure Microsoft Edge to restart after a period of inactivity by using the “Configure kiosk reset after idle timeout” policy. - If it’s one of many apps, it runs in a limited multi-tab version of InPrivate for public browsing with other apps. Users can minimize, close, and open multiple InPrivate windows, but they can’t customize Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurekioskmode"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurekioskmode_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurekioskmode_0","displayName":"Disable","description":"Disable","helpText":null}]},"cb1bea77e210521e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended","displayName":"Parameter providing search-by-image feature for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.)\r\n\r\nLeaving DefaultSearchProviderImageURL unset means no image search is used.\r\n\r\nExample value: https://search.my.company/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cb47bf512f070684":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback.","description":"Following each major version update, Chrome will create a snapshot of certain portions of the user's browsing data for use in case of a later emergency version rollback. If an emergency rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This allows users to retain such settings as bookmarks and autofill data.\r\n\r\nIf this policy is not set, the default value of 3 is used\r\n\r\nIf the policy is set, old snapshots are deleted as needed to respect the limit. If the policy is set to 0, no snapshots will be taken","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_1","displayName":"Enabled","description":null,"helpText":null}]},"cb6a6f6b00dd0850":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},"cb47ecea631692fd":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitforegrounddownloadbandwidth","displayName":"Set Business Hours to Limit Foreground Download Bandwidth","description":"Specifies the maximum foreground download bandwidth that Delivery Optimization uses during and outside business hours across all concurrent download activities as a percentage of available download bandwidth.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-deliveryoptimization#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":[{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitforegrounddownloadbandwidth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitforegrounddownloadbandwidth_1","displayName":"Enabled","description":null,"helpText":null}]},"cba65f76c3d0295a":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesprofiledirectorysddl","displayName":"Profile Directory SDDL","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSDDL string representing the ACLs to use when creating the profile directory.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ProfileDirSDDL\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesprofiledirectorysddl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesprofiledirectorysddl_1","displayName":"Enabled","description":null,"helpText":null}]},"cb7cee7e659c8d44":{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck","displayName":"Turn off the Security Settings Check feature","description":"This policy setting turns off the Security Settings Check feature, which checks Internet Explorer security settings to determine when the settings put Internet Explorer at risk.\n\nIf you enable this policy setting, the feature is turned off.\n\nIf you disable or do not configure this policy setting, the feature is turned on.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecuritysettingscheck"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck_1","displayName":"Enabled","description":null,"helpText":null}]},"cbd66c36add43cf3":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},"cb49688b4e2c2caa":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cb26312d9471f842":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting","displayName":"Default geolocation setting","description":"Set whether websites can track users' physical locations. You can allow tracking by default (1), deny it by default (2), or ask the user each time a website requests their location (3).\r\n\r\nIf you don't configure this policy, 'AskGeolocation' policy is used and the user can change it.\r\n\r\n* 1 = Allow sites to track users' physical location\r\n\r\n* 2 = Don't allow any site to track users' physical location\r\n\r\n* 3 = Ask whenever a site wants to track users' physical location","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"cb6e0553d0ea5aa2":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},"cbf153204615ecd6":{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_2","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},"cb223167164c06f8":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\r\n\r\nIf you enable this policy, services and export targets that match the given list are blocked.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\r\n\r\nPolicy options mapping:\r\n\r\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\npinterest_suggestions","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"cb9857f5c6a66b44":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_winprojexe146","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_winprojexe146_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_winprojexe146_1","displayName":"True","description":null,"helpText":null}]},"cb6395e34e34468d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_powerpntexe171","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_powerpntexe171_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_powerpntexe171_1","displayName":"True","description":null,"helpText":null}]},"cbe58cc8dc76dc0b":{"id":"device_vendor_msft_policy_config_printers_configurerpcauthnlevelprivacyenabled","displayName":"Configure RPC packet level privacy setting for incoming connections","description":"\nThis policy setting controls whether packet level privacy is enabled for RPC for incoming connections.\n\nBy default packet level privacy is enabled for RPC for incoming connections.\n\nIf you enable or do not configure this policy setting, packet level privacy is enabled for RPC for incoming connections.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-configurerpcauthnlevelprivacyenabled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configurerpcauthnlevelprivacyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpcauthnlevelprivacyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cbb39c48c7371ed8":{"id":"device_vendor_msft_policy_config_start_hideusertile","displayName":"Hide User Tile","description":"Enabling this policy hides the user tile from appearing in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hideusertile"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hideusertile_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hideusertile_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"cb36b389fac2d927":{"id":"device_vendor_msft_policy_config_windowssandbox_allowvgpu","displayName":"Allow VGPU","description":"Allow vGPU sharing for Windows Sandbox","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsSandbox#allowvgpu"],"categoryId":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","categoryName":"Windows Sandbox","options":[{"id":"device_vendor_msft_policy_config_windowssandbox_allowvgpu_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_windowssandbox_allowvgpu_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"cb979f6eea8adaab":{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_filepath","displayName":"File path","description":null,"helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":null},"cb10216383b06b49":{"id":"safari_acceptcookies","displayName":"Accept Cookies","description":"The policy Safari uses for managing cookies:\n\n- `Never`: Safari always blocks cookies.\n- `CurrentWebsite`: Safari allows cookies only from the current website.\n- `VisitedWebsites`: Safari allows cookies only from visited websites.\n- `Always`: Safari always allows cookies.","helpText":null,"infoUrls":[],"categoryId":"e0ab6868-4b53-4310-b665-f7c979941db7","categoryName":"Safari Browser","options":[{"id":"safari_acceptcookies_0","displayName":"Never","description":null,"helpText":null},{"id":"safari_acceptcookies_1","displayName":"CurrentWebsite","description":null,"helpText":null},{"id":"safari_acceptcookies_2","displayName":"VisitedWebsites","description":null,"helpText":null},{"id":"safari_acceptcookies_3","displayName":"Always","description":null,"helpText":null}]},"cba4dabd0a236f0f":{"id":"user_vendor_msft_policy_config_admx_startmenu_disableglobalsearchonappsview","displayName":"Search just apps from the Apps view (User)","description":"This policy setting prevents the user from searching apps, files, settings (and the web if enabled) when the user searches from the Apps view.\r\n\r\nThis policy setting is only applied when the Apps view is set as the default view for Start.\r\n\r\nIf you enable this policy setting, searching from the Apps view will only search the list of installed apps.\r\n\r\nIf you disable or don’t configure this policy setting, the user can configure this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-disableglobalsearchonappsview"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_disableglobalsearchonappsview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_disableglobalsearchonappsview_1","displayName":"Enabled","description":null,"helpText":null}]},"cb7eac4ba5d9b91a":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_library1","displayName":"Location 2 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"cba0c2e9d8cdc73e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed","displayName":"Allow QUIC protocol (User)","description":"Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome.\r\n\r\nSetting the policy to Disabled disallows the use of QUIC protocol.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"cbdc10d64dee3a7e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},"cb686a65b08c0a31":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist","displayName":"Configure the required domain names for remote access clients (User)","description":"Setting the policy specifies the client domain names that are imposed on remote access clients, and users can't change them. Only clients from one of the specified domains can connect to the host.\r\n\r\nSetting the policy to an empty list or leaving it unset applies the default policy for the connection type. For remote assistance, this allows clients from any domain to connect to the host. For anytime remote access, only the host owner can connect.\r\n\r\nSee also RemoteAccessHostDomainList.\r\n\r\nNote: This setting overrides RemoteAccessHostClientDomain, if present.\r\n\r\nExample value:\r\n\r\nmy-awesome-domain.com\r\nmy-auxiliary-domain.com","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},"cbf3a8ed78b49a0e":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled","displayName":"Allow the shopping list feature to be enabled (User)","description":"This policy controls the availability of the shopping list feature.\r\nIf enabled, users will be presented with UI to track the price of the product displayed on the current page. The tracked product will be shown in the bookmarks side panel.\r\nIf this policy is set to Enabled or not set, the shopping list feature will be available to users.\r\nIf this policy is set to Disabled, the shopping list feature will be unavailable.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cb92f18bf8bd700f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement","displayName":"Cursor movement (User)","description":"Determines how the insertion point moves through bi-directional text. Possible values are Logical or Visual and the default is Logical.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_1","displayName":"Enabled","description":null,"helpText":null}]},"cb047b0173294f04":{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions","displayName":"Select SmartScreen Filter mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions_0","displayName":"Off","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions_1","displayName":"On","description":null,"helpText":null}]},"cbec1d13b0099abc":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_0","displayName":"Enable both Work and Discover tabs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_1","displayName":"Enable only Work tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_2","displayName":"Enable only Discover tab","description":null,"helpText":null}]},"cb5d8a8043ad1d14":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"cb751efda3612967":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions","displayName":"Blocks external extensions from being installed (User)","description":"Control the installation of external extensions.\r\n\r\nIf you enable this setting, external extensions are blocked from being installed.\r\n\r\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\r\n\r\nExternal extensions and their installation are documented at [Alternate extension distribution methods](/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options).","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"cb507cece7518117":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject_1","displayName":"True","description":null,"helpText":null}]},"cb2aa65497611cbd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11","displayName":"Escrow Key #11 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_1","displayName":"Enabled","description":null,"helpText":null}]},"cb80a7f9dd5d482d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"cbe212a0fa6a2112":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize37_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":null},"cb9b273acc5dc264":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_urladdressofassociatedwebpage43","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"cb439a51ad5b4487":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender","displayName":"Accept Categories assigned to incoming mail by the sender (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender_1","displayName":"True","description":null,"helpText":null}]},"cb9622bd66efc3cf":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_automaticallywraptextatxcharacters","displayName":"Automatically wrap text at characters. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":null},"cba6fea0a716616c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert","displayName":"Specify default location of Desktop Alert (User)","description":"You can change the default location of the Desktop Alert. In the Corner field, select a number corresponding to a quadrant of the user's screen: 0 = upper left, 1 = upper right, 2 = lower left, 3 = lower right (the default). In the XOffset field, enter a number representing the horizontal distance from the corner you've specified (the default is 44). In the YOffset field, enter a number representing the vertical distance from the corner you've specified (the default is 42).","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},"cb3cc585c1e2bf26":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval","displayName":"Save Interval (User)","description":"Specifies how often Project should automatically save your projects. This setting is only used by Project if Auto Save has been turned on.\r\n\r\nIf you enable this setting, Project will save users projects at the specified interval.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"cb6b9161166cb2e0":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips","displayName":"Project Screentips (User)","description":"Displays tips for Gantt bars and field headings, including dates for timescale units, and the full cell contents if a cell is too narrow to completely display the text in sheet and Network Diagram views.\r\n\r\nIf you enable this setting, tips are displayed fro Gantt bars and field headings.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},"cba7df6ec3c868f9":{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy","displayName":"Restrict sign in to Teams to accounts in specific tenants (User)","description":"This policy setting allows you to control the accounts that can be used in Teams on managed devices running Windows. \r\n\r\nIf you enable this policy setting, users will only be allowed to sign in with accounts from Azure Active Directory (Azure AD) tenants that you specify. You can enter a comma separated list of tenant IDs. \r\n \r\nThe policy setting applies to all ways that the user signs in, including first and additional accounts on versions of Teams that support multiple accounts side by side. \r\n\r\nThe policy setting is also enforced when users sign out and sign back in. \r\n\r\nIf you disable or don't configure this policy setting, Teams will continue to allow users to sign in with work or school accounts, or personal Microsoft accounts. \r\n\r\nImportant: This policy setting only restricts which users can sign in. It does not restrict the ability for users to be invited as a guest in other Azure AD tenants, or switch to tenants they were invited to.\r\n\r\nNote: This policy does not apply to Teams web app.","helpText":"","infoUrls":[],"categoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","categoryName":"Microsoft Teams","options":[{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_1","displayName":"Enabled","description":null,"helpText":null}]},"cb98d474a25753e2":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"cb70b46275f86a11":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"cb9e4209f0df9952":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar","displayName":"Show horizontal scroll bar (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},"cb321aae55935ad6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors","displayName":"Object anchors (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors_1","displayName":"Enabled","description":null,"helpText":null}]},"cb62a499c3d18cdb":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid","displayName":"Dynamic Data Exchange setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid_1","displayName":"Limited Dynamic Data Exchange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid_2","displayName":"Allow Dynamic Data Exchange","description":null,"helpText":null}]},"cb33a99fc9a683b7":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},"cb0d0ffc17eccf2a":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1","displayName":"Color for inserted cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_8","displayName":"Gray","description":null,"helpText":null}]},"cb8ec33758893956":{"id":"vendor_msft_sharedpc_maxpagefilesizemb","displayName":"Max Page File Size MB","description":"Maximum size of the paging file in MB. Applies only to systems with less than 32 GB storage and at least 3 GB of RAM. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/SharedPC-csp/"],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null}} \ No newline at end of file +{"cb63454b27c8806d":{"id":"com.apple.managedclient.preferences_screencaptureallowedbyorigins","displayName":"Allow Desktop, Window, and Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Desktop, Window, and Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of Capture.\n\nThis policy is not considered if a site matches a URL pattern in any of the following policies: \"WindowCaptureAllowedByOrigins\", \"TabCaptureAllowedByOrigins\", \"SameOriginTabCaptureAllowedByOrigins\".\n\nIf a site matches a URL pattern in this policy, the \"ScreenCaptureAllowed\" will not be considered.\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cb6066fbcceed873":{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder","displayName":"Set the order in which S/MIME certificates are considered","description":"Set the order in which certificates will be used to decrypt and encrypt S/MIME messages.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#set-the-order-in-which-smime-certificates-are-considered"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_0","displayName":"Contacts","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_1","displayName":"Global Address List","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_2","displayName":"Device","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_smimecertificateslookuporder_3","displayName":"LDAP","description":null,"helpText":null}]},"cba799a2e9441706":{"id":"com.apple.mcx.timemachine_backupdesturl","displayName":"Backup Destination URL","description":"The URL of the backup destination.","helpText":null,"infoUrls":[],"categoryId":"361859d9-1382-47c3-b9ec-9251a62fbb25","categoryName":"Time Machine","options":null},"cb9746560b40de8d":{"id":"com.apple.mcxprinting_userprinterlist_printer_displayname","displayName":"Display Name","description":"The display name.","helpText":null,"infoUrls":[],"categoryId":"174ffe92-3770-4688-aa21-85b7535cf374","categoryName":"Printing","options":null},"cb49bc3b53bd11cf":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses (users can override)","description":"Enables the AutoFill feature and allows users to autocomplete address information in web forms through previously stored information.\n\nIf you have enabled or not configured this policy, users manage AutoFill for addresses in Microsoft Edge settings. AutoFill allows users to complete address fields in web forms using previously saved information.\n\nIf you have disabled this policy, Microsoft Edge doesn't suggest, fill in, or save address information. AutoFill is also disabled for all web forms except payment and password fields, and previously saved addresses aren't available.\n\nIf you disable this policy, then \"EdgeAutofillMlEnabled\" is turned off.\n\nIf you disable this policy, all activities for all web forms are stopped, except payment and password forms. No further entries are saved, and Microsoft Edge doesn't suggest or AutoFill any previous entries.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.autofilladdressenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"cb3eff8e7c8ee42c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled","displayName":"Enable CryptoWallet feature (Obsolete)","description":"This policy is obsoleted because this feature will no longer be supported, starting in Microsoft Edge 128. There's no replacement for this policy.\n Enables CryptoWallet feature in Microsoft Edge.\n\n If you enable this policy or don't configure it, users can use CryptoWallet feature that allows users to securely store, manage, and transact digital assets such as Bitcoin, Ethereum, and other cryptocurrencies. Therefore, Microsoft Edge may access Microsoft servers to communicate with the web3 world during the use of the CryptoWallet feature.\n\n If you disable this policy, users can't use CryptoWallet feature.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.cryptowalletenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"cb0591ef064dc596":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine","displayName":"Allow importing of search engine settings","description":"Allows users to import search engine settings from another browser into Microsoft Edge.\n\nIf you enable, this policy, the option to import search engine settings is automatically selected.\n\nIf you disable this policy, search engine settings aren't imported at first run, and users can't import them manually.\n\nIf you don't configure this policy, search engine settings are imported at first run, and users can choose whether to import this data manually during later browsing sessions.\n\nYou can set this policy as a recommendation. This option means that Microsoft Edge imports search engine settings on first run, but users can select or clear the **search engine** option during manual import.\n\n**Note**: This policy currently manages importing from Internet Explorer (on Windows 7, 8, and 10).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importsearchengine_true","displayName":"Enabled","description":null,"helpText":null}]},"cbf274f323dcde96":{"id":"contentcaching_listenranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"cb474b21a8dc8fd7":{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans","displayName":"Disable Cpu Throttle On Idle Scans","description":"Indicates whether the CPU will be throttled for scheduled scans while the device is idle. This feature is enabled by default and will not throttle the CPU for scheduled scans performed when the device is otherwise idle, regardless of what ScanAvgCPULoadFactor is set to. For all other scheduled scans this flag will have no impact and normal throttling will occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans_1","displayName":"Disable CPU Throttle on idle scans","description":"Disable CPU Throttle on idle scans","helpText":null},{"id":"device_vendor_msft_defender_configuration_disablecputhrottleonidlescans_0","displayName":"Enable CPU Throttle on idle scans","description":"Enable CPU Throttle on idle scans","helpText":null}]},"cbef763691201602":{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2","displayName":"Redirect folders on primary computers only","description":"This policy setting controls whether folders are redirected on a user's primary computers only. This policy setting is useful to improve logon performance and to increase security for user data on computers where the user might not want to download private data, such as on a meeting room computer or on a computer in a remote office.\r\n\r\nTo designate a user's primary computers, an administrator must use management software or a script to add primary computer attributes to the user's account in Active Directory Domain Services (AD DS). This policy setting also requires the Windows Server 2012 version of the Active Directory schema to function.\r\n\r\nIf you enable this policy setting and the user has redirected folders, such as the Documents and Pictures folders, the folders are redirected on the user's primary computer only.\r\n\r\nIf you disable or do not configure this policy setting and the user has redirected folders, the folders are redirected on every computer that the user logs on to.\r\n\r\nNote: If you enable this policy setting in Computer Configuration and User Configuration, the Computer Configuration policy setting takes precedence.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-primarycomputer-fr-2"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_folderredirection_primarycomputer_fr_2_1","displayName":"Enabled","description":null,"helpText":null}]},"cb3e71ecba453fb0":{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2","displayName":"Turn off the Windows Messenger Customer Experience Improvement Program","description":"This policy setting specifies whether Windows Messenger collects anonymous information about how Windows Messenger software and service is used.\r\n\r\nWith the Customer Experience Improvement program, users can allow Microsoft to collect anonymous information about how the product is used. This information is used to improve the product in future releases.\r\n\r\nIf you enable this policy setting, Windows Messenger does not collect usage information, and the user settings to enable the collection of usage information are not shown.\r\n\r\nIf you disable this policy setting, Windows Messenger collects anonymous usage information, and the setting is not shown.\r\n\r\nIf you do not configure this policy setting, users have the choice to opt in and allow information to be collected.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-winmsg-noinstrumentation-2"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_winmsg_noinstrumentation_2_1","displayName":"Enabled","description":null,"helpText":null}]},"cbaa95a0a6bd6340":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring","displayName":"Turn off real-time protection","description":"This policy setting turns off real-time protection prompts for known malware detection.\r\n\r\n Microsoft Defender Antivirus alerts you when malware or potentially unwanted software attempts to install itself or to run on your computer.\r\n\r\n If you enable this policy setting, Microsoft Defender Antivirus will not prompt users to take actions on malware detections.\r\n\r\n If you disable or do not configure this policy setting, Microsoft Defender Antivirus will prompt users to take actions on malware detections.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-disablerealtimemonitoring"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_disablerealtimemonitoring_1","displayName":"Enabled","description":null,"helpText":null}]},"cb480318251f29c3":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_controlledfolderaccess_protectedfolders_exploitguard_controlledfolderaccess_protectedfolders","displayName":"Enter the folders that should be guarded:","description":null,"helpText":"","infoUrls":[],"categoryId":"72f61c7d-e5d2-4170-baf3-c953c1082e19","categoryName":"Controlled Folder Access","options":null},"cb75dc3dbd93fd7b":{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown","displayName":"Prohibit use of Restart Manager","description":"This policy setting controls Windows Installer's interaction with the Restart Manager. The Restart Manager API can eliminate or reduce the number of system restarts that are required to complete an installation or update.\r\n\r\nIf you enable this policy setting, you can use the options in the Prohibit Use of Restart Manager box to control file in use detection behavior.\r\n\r\n-- The \"Restart Manager On\" option instructs Windows Installer to use Restart Manager to detect files in use and mitigate a system restart, when possible.\r\n\r\n-- The \"Restart Manager Off\" option turns off Restart Manager for file in use detection and the legacy file in use behavior is used.\r\n\r\n-- The \"Restart Manager Off for Legacy App Setup\" option applies to packages that were created for Windows Installer versions lesser than 4.0. This option lets those packages display the legacy files in use UI while still using Restart Manager for detection.\r\n\r\nIf you disable or do not configure this policy setting, Windows Installer will use Restart Manager to detect files in use and mitigate a system restart, when possible.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-disableautomaticapplicationshutdown"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_disableautomaticapplicationshutdown_1","displayName":"Enabled","description":null,"helpText":null}]},"cbb5d72316da5645":{"id":"device_vendor_msft_policy_config_admx_nca_dtes","displayName":"IPsec Tunnel Endpoints","description":"Specifies the IPv6 addresses of the endpoints of the Internet Protocol security (IPsec) tunnels that enable DirectAccess. NCA attempts to access the resources that are specified in the Corporate Resources setting through these configured tunnel endpoints. \r\n\r\nBy default, NCA uses the same DirectAccess server that the DirectAccess client computer connection is using. In default configurations of DirectAccess, there are typically two IPsec tunnel endpoints: one for the infrastructure tunnel and one for the intranet tunnel. You should configure one endpoint for each tunnel. \r\n\t \r\nEach entry consists of the text PING: followed by the IPv6 address of an IPsec tunnel endpoint. Example: PING:2002:836b:1::836b:1.\r\n\r\nYou must configure this setting to have complete NCA functionality.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-dtes"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_dtes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_dtes_1","displayName":"Enabled","description":null,"helpText":null}]},"cb653f0d48c55d10":{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity","displayName":"Turn off password security in Input Panel","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_1","displayName":"Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_3","displayName":"Medium","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_4","displayName":"Medium High","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_passwordsecurity_2_passwordsecurity_5","displayName":"High","description":null,"helpText":null}]},"cb9b243dd5ae4246":{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional","displayName":"Allow Microsoft accounts to be optional","description":"This policy setting lets you control whether Microsoft accounts are optional for packaged Microsoft Store apps that require an account to sign in. This policy only affects packaged Microsoft Store apps that support it.\n\nIf you enable this policy setting, packaged Microsoft Store apps that typically require a Microsoft account to sign in will allow users to sign in with an enterprise account instead.\n\nIf you disable or do not configure this policy setting, users will need to sign in with a Microsoft account.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-appruntime#appruntime-allowmicrosoftaccountstobeoptional"],"categoryId":"e972d9fe-a9b7-4a65-a88f-0958fab19584","categoryName":"App runtime","options":[{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appruntime_allowmicrosoftaccountstobeoptional_1","displayName":"Enabled","description":null,"helpText":null}]},"cb4a185105c3e49e":{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading","displayName":"Allow Tab Preloading","description":"Prevent Microsoft Edge from starting and loading the Start and New Tab page at Windows startup and each time Microsoft Edge is closed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowtabpreloading"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowtabpreloading_1","displayName":"Allow","description":"Allowed. Preload Start and New tab pages.","helpText":null}]},"cbeea55439d957c5":{"id":"device_vendor_msft_policy_config_browser_configurekioskmode","displayName":"Configure Kiosk Mode","description":"Configure how Microsoft Edge behaves when it’s running in kiosk mode with assigned access, either as a single app or as one of multiple apps running on the kiosk device. You can control whether Microsoft Edge runs InPrivate full screen, InPrivate multi-tab with limited functionality, or normal Microsoft Edge. You need to configure Microsoft Edge in assigned access for this policy to take effect; otherwise, these settings are ignored. To learn more about assigned access and kiosk configuration, see “Configure kiosk and shared devices running Windows desktop editions” (https://aka.ms/E489vw). If enabled and set to 0 (Default or not configured): - If it’s a single app, it runs InPrivate full screen for digital signage or interactive displays. - If it’s one of many apps, Microsoft Edge runs as normal. If enabled and set to 1: - If it’s a single app, it runs a limited multi-tab version of InPrivate and is the only app available for public browsing. Users can’t minimize, close, or open windows or customize Microsoft Edge, but can clear browsing data and downloads and restart by clicking “End session.” You can configure Microsoft Edge to restart after a period of inactivity by using the “Configure kiosk reset after idle timeout” policy. - If it’s one of many apps, it runs in a limited multi-tab version of InPrivate for public browsing with other apps. Users can minimize, close, and open multiple InPrivate windows, but they can’t customize Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#configurekioskmode"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_configurekioskmode_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_browser_configurekioskmode_0","displayName":"Disable","description":"Disable","helpText":null}]},"cb1bea77e210521e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended","displayName":"Parameter providing search-by-image feature for the default search provider","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderImageURL specifies the URL of the search engine used for image search. (If DefaultSearchProviderImageURLPostParams is set, then image search requests use the POST method instead.)\r\n\r\nLeaving DefaultSearchProviderImageURL unset means no image search is used.\r\n\r\nExample value: https://search.my.company/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cb47bf512f070684":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback.","description":"Following each major version update, Chrome will create a snapshot of certain portions of the user's browsing data for use in case of a later emergency version rollback. If an emergency rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This allows users to retain such settings as bookmarks and autofill data.\r\n\r\nIf this policy is not set, the default value of 3 is used\r\n\r\nIf the policy is set, old snapshots are deleted as needed to respect the limit. If the policy is set to 0, no snapshots will be taken","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_userdatasnapshotretentionlimit_1","displayName":"Enabled","description":null,"helpText":null}]},"cb6a6f6b00dd0850":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_enabled","displayName":"Enable background graphics printing mode by default","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_printingbackgroundgraphicsdefault_disabled","displayName":"Disable background graphics printing mode by default","description":null,"helpText":null}]},"cb47ecea631692fd":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitforegrounddownloadbandwidth","displayName":"Set Business Hours to Limit Foreground Download Bandwidth","description":"Specifies the maximum foreground download bandwidth that Delivery Optimization uses during and outside business hours across all concurrent download activities as a percentage of available download bandwidth.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-deliveryoptimization#deliveryoptimization-dosethourstolimitforegrounddownloadbandwidth"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":[{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitforegrounddownloadbandwidth_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deliveryoptimization_dosethourstolimitforegrounddownloadbandwidth_1","displayName":"Enabled","description":null,"helpText":null}]},"cba65f76c3d0295a":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesprofiledirectorysddl","displayName":"Profile Directory SDDL","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nSDDL string representing the ACLs to use when creating the profile directory.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ProfileDirSDDL\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesprofiledirectorysddl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesprofiledirectorysddl_1","displayName":"Enabled","description":null,"helpText":null}]},"cb7cee7e659c8d44":{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck","displayName":"Turn off the Security Settings Check feature","description":"This policy setting turns off the Security Settings Check feature, which checks Internet Explorer security settings to determine when the settings put Internet Explorer at risk.\n\nIf you enable this policy setting, the feature is turned off.\n\nIf you disable or do not configure this policy setting, the feature is turned on.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablesecuritysettingscheck"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disablesecuritysettingscheck_1","displayName":"Enabled","description":null,"helpText":null}]},"cbd66c36add43cf3":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00","displayName":"Java permissions","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_65536","displayName":"High safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_131072","displayName":"Medium safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_196608","displayName":"Low safety","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_8388608","displayName":"Custom","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonejavapermissions_iz_partname1c00_0","displayName":"Disable Java","description":null,"helpText":null}]},"cb49688b4e2c2caa":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended","displayName":"Enable favorites bar","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_favoritesbarenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cb26312d9471f842":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting","displayName":"Default geolocation setting","description":"Set whether websites can track users' physical locations. You can allow tracking by default (1), deny it by default (2), or ask the user each time a website requests their location (3).\r\n\r\nIf you don't configure this policy, 'AskGeolocation' policy is used and the user can change it.\r\n\r\n* 1 = Allow sites to track users' physical location\r\n\r\n* 2 = Don't allow any site to track users' physical location\r\n\r\n* 3 = Ask whenever a site wants to track users' physical location","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultgeolocationsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"cb6e0553d0ea5aa2":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~httpauthentication_authnegotiatedelegateallowlist_authnegotiatedelegateallowlist","displayName":"Specifies a list of servers that Microsoft Edge can delegate user credentials to (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","categoryName":"HTTP authentication","options":null},"cbf153204615ecd6":{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_2","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_downloadrestrictions_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},"cb223167164c06f8":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\r\n\r\nIf you enable this policy, services and export targets that match the given list are blocked.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\r\n\r\nPolicy options mapping:\r\n\r\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\npinterest_suggestions","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"cb9857f5c6a66b44":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_winprojexe146","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_winprojexe146_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_winprojexe146_1","displayName":"True","description":null,"helpText":null}]},"cb6395e34e34468d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_powerpntexe171","displayName":"powerpnt.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_powerpntexe171_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_powerpntexe171_1","displayName":"True","description":null,"helpText":null}]},"cbe58cc8dc76dc0b":{"id":"device_vendor_msft_policy_config_printers_configurerpcauthnlevelprivacyenabled","displayName":"Configure RPC packet level privacy setting for incoming connections","description":"\nThis policy setting controls whether packet level privacy is enabled for RPC for incoming connections.\n\nBy default packet level privacy is enabled for RPC for incoming connections.\n\nIf you enable or do not configure this policy setting, packet level privacy is enabled for RPC for incoming connections.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-printers#printers-configurerpcauthnlevelprivacyenabled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_printers_configurerpcauthnlevelprivacyenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_printers_configurerpcauthnlevelprivacyenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cbb39c48c7371ed8":{"id":"device_vendor_msft_policy_config_start_hideusertile","displayName":"Hide User Tile","description":"Enabling this policy hides the user tile from appearing in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hideusertile"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hideusertile_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hideusertile_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"cb36b389fac2d927":{"id":"device_vendor_msft_policy_config_windowssandbox_allowvgpu","displayName":"Allow VGPU","description":"Allow vGPU sharing for Windows Sandbox","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsSandbox#allowvgpu"],"categoryId":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","categoryName":"Windows Sandbox","options":[{"id":"device_vendor_msft_policy_config_windowssandbox_allowvgpu_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_windowssandbox_allowvgpu_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"cb979f6eea8adaab":{"id":"device_vendor_msft_policy_privilegemanagement_elevationrules_{elevationrulename}_filepath","displayName":"File path","description":null,"helpText":null,"infoUrls":[],"categoryId":"4f3a6fca-a74c-448d-95b1-9d6d7a5d4449","categoryName":null,"options":null},"cb10216383b06b49":{"id":"safari_acceptcookies","displayName":"Accept Cookies","description":"The policy Safari uses for managing cookies:\n\n- `Never`: Safari always blocks cookies.\n- `CurrentWebsite`: Safari allows cookies only from the current website.\n- `VisitedWebsites`: Safari allows cookies only from visited websites.\n- `Always`: Safari always allows cookies.","helpText":null,"infoUrls":[],"categoryId":"e0ab6868-4b53-4310-b665-f7c979941db7","categoryName":"Safari Browser","options":[{"id":"safari_acceptcookies_0","displayName":"Never","description":null,"helpText":null},{"id":"safari_acceptcookies_1","displayName":"CurrentWebsite","description":null,"helpText":null},{"id":"safari_acceptcookies_2","displayName":"VisitedWebsites","description":null,"helpText":null},{"id":"safari_acceptcookies_3","displayName":"Always","description":null,"helpText":null}]},"cba4dabd0a236f0f":{"id":"user_vendor_msft_policy_config_admx_startmenu_disableglobalsearchonappsview","displayName":"Search just apps from the Apps view (User)","description":"This policy setting prevents the user from searching apps, files, settings (and the web if enabled) when the user searches from the Apps view.\r\n\r\nThis policy setting is only applied when the Apps view is set as the default view for Start.\r\n\r\nIf you enable this policy setting, searching from the Apps view will only search the list of installed apps.\r\n\r\nIf you disable or don’t configure this policy setting, the user can configure this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-disableglobalsearchonappsview"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_disableglobalsearchonappsview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_disableglobalsearchonappsview_1","displayName":"Enabled","description":null,"helpText":null}]},"cb7eac4ba5d9b91a":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_library1","displayName":"Location 2 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"cba0c2e9d8cdc73e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed","displayName":"Allow QUIC protocol (User)","description":"Setting the policy to Enabled or leaving it unset allows the use of QUIC protocol in Google Chrome.\r\n\r\nSetting the policy to Disabled disallows the use of QUIC protocol.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_quicallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"cbdc10d64dee3a7e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},"cb686a65b08c0a31":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist","displayName":"Configure the required domain names for remote access clients (User)","description":"Setting the policy specifies the client domain names that are imposed on remote access clients, and users can't change them. Only clients from one of the specified domains can connect to the host.\r\n\r\nSetting the policy to an empty list or leaving it unset applies the default policy for the connection type. For remote assistance, this allows clients from any domain to connect to the host. For anytime remote access, only the host owner can connect.\r\n\r\nSee also RemoteAccessHostDomainList.\r\n\r\nNote: This setting overrides RemoteAccessHostClientDomain, if present.\r\n\r\nExample value:\r\n\r\nmy-awesome-domain.com\r\nmy-auxiliary-domain.com","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclientdomainlist_1","displayName":"Enabled","description":null,"helpText":null}]},"cbf3a8ed78b49a0e":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled","displayName":"Allow the shopping list feature to be enabled (User)","description":"This policy controls the availability of the shopping list feature.\r\nIf enabled, users will be presented with UI to track the price of the product displayed on the current page. The tracked product will be shown in the bookmarks side panel.\r\nIf this policy is set to Enabled or not set, the shopping list feature will be available to users.\r\nIf this policy is set to Disabled, the shopping list feature will be unavailable.\r\n","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_shoppinglistenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cb92f18bf8bd700f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement","displayName":"Cursor movement (User)","description":"Determines how the insertion point moves through bi-directional text. Possible values are Logical or Visual and the default is Logical.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_cursormovement_1","displayName":"Enabled","description":null,"helpText":null}]},"cb047b0173294f04":{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions","displayName":"Select SmartScreen Filter mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions_0","displayName":"Off","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_preventmanagingsmartscreenfilter_ie9safetyfilteroptions_1","displayName":"On","description":null,"helpText":null}]},"cbec1d13b0099abc":{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_0","displayName":"Enable both Work and Discover tabs","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_1","displayName":"Enable only Work tab","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_configurentpfeedtabvisibility_configurentpfeedtabvisibility_2","displayName":"Enable only Discover tab","description":null,"helpText":null}]},"cb5d8a8043ad1d14":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderimageurlpostparams_recommended_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"cb751efda3612967":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions","displayName":"Blocks external extensions from being installed (User)","description":"Control the installation of external extensions.\r\n\r\nIf you enable this setting, external extensions are blocked from being installed.\r\n\r\nIf you disable this setting or leave it unset, external extensions are allowed to be installed.\r\n\r\nExternal extensions and their installation are documented at [Alternate extension distribution methods](/microsoft-edge/extensions-chromium/developer-guide/alternate-distribution-options).","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge~extensions_blockexternalextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"cb507cece7518117":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiproject_1","displayName":"True","description":null,"helpText":null}]},"cb2aa65497611cbd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11","displayName":"Escrow Key #11 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey11_1","displayName":"Enabled","description":null,"helpText":null}]},"cb80a7f9dd5d482d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_trustedcatalogs_l_defaultfilesharecatalog_l_url","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"24f6d328-64e7-4490-be38-452ac3b61f6f","categoryName":"Trusted Catalogs","options":null},"cbe212a0fa6a2112":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize37_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":null},"cb9b273acc5dc264":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_urladdressofassociatedwebpage43","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"cb439a51ad5b4487":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender","displayName":"Accept Categories assigned to incoming mail by the sender (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_managingcategoriesduringe_mailexchanges_l_acceptcategoriesassignedtoincomingmailbythesender_1","displayName":"True","description":null,"helpText":null}]},"cb9622bd66efc3cf":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_plaintextoptions_l_automaticallywraptextatxcharacters","displayName":"Automatically wrap text at characters. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":null},"cba6fea0a716616c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert","displayName":"Specify default location of Desktop Alert (User)","description":"You can change the default location of the Desktop Alert. In the Corner field, select a number corresponding to a quadrant of the user's screen: 0 = upper left, 1 = upper right, 2 = lower left, 3 = lower right (the default). In the XOffset field, enter a number representing the horizontal distance from the corner you've specified (the default is 44). In the YOffset field, enter a number representing the vertical distance from the corner you've specified (the default is 42).","helpText":"","infoUrls":[],"categoryId":"35f245bd-8d1f-424c-83de-a80be27a6a4e","categoryName":"Desktop Alert","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_desktopalert_l_specifydefaultlocationofdesktopalert_1","displayName":"Enabled","description":null,"helpText":null}]},"cb3cc585c1e2bf26":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval","displayName":"Save Interval (User)","description":"Specifies how often Project should automatically save your projects. This setting is only used by Project if Auto Save has been turned on.\r\n\r\nIf you enable this setting, Project will save users projects at the specified interval.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dfd5d749-c68c-448f-ab3f-851c09f09df4","categoryName":"Auto Save Options","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjsave~l_pjautosave_l_pjsaveinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"cb6b9161166cb2e0":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips","displayName":"Project Screentips (User)","description":"Displays tips for Gantt bars and field headings, including dates for timescale units, and the full cell contents if a cell is too narrow to completely display the text in sheet and Network Diagram views.\r\n\r\nIf you enable this setting, tips are displayed fro Gantt bars and field headings.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"251c6873-bf5b-4d85-8185-3c4973b6f33c","categoryName":"Show","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview~l_pjshow_l_pjprojectscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},"cba7df6ec3c868f9":{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy","displayName":"Restrict sign in to Teams to accounts in specific tenants (User)","description":"This policy setting allows you to control the accounts that can be used in Teams on managed devices running Windows. \r\n\r\nIf you enable this policy setting, users will only be allowed to sign in with accounts from Azure Active Directory (Azure AD) tenants that you specify. You can enter a comma separated list of tenant IDs. \r\n \r\nThe policy setting applies to all ways that the user signs in, including first and additional accounts on versions of Teams that support multiple accounts side by side. \r\n\r\nThe policy setting is also enforced when users sign out and sign back in. \r\n\r\nIf you disable or don't configure this policy setting, Teams will continue to allow users to sign in with work or school accounts, or personal Microsoft accounts. \r\n\r\nImportant: This policy setting only restricts which users can sign in. It does not restrict the ability for users to be invited as a guest in other Azure AD tenants, or switch to tenants they were invited to.\r\n\r\nNote: This policy does not apply to Teams web app.","helpText":"","infoUrls":[],"categoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","categoryName":"Microsoft Teams","options":[{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_teamsv3~policy~l_teams_string_teams_signinrestriction_policy_1","displayName":"Enabled","description":null,"helpText":null}]},"cb98d474a25753e2":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc03_l_descriptioncolon18","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"cb70b46275f86a11":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc05_l_datecolon25","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"cb9e4209f0df9952":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar","displayName":"Show horizontal scroll bar (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_horizontalscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},"cb321aae55935ad6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors","displayName":"Object anchors (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_objectanchors_1","displayName":"Enabled","description":null,"helpText":null}]},"cb62a499c3d18cdb":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid","displayName":"Dynamic Data Exchange setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid_1","displayName":"Limited Dynamic Data Exchange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_allowdde_l_allowddedropid_2","displayName":"Allow Dynamic Data Exchange","description":null,"helpText":null}]},"cb33a99fc9a683b7":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09","displayName":"Trusted Location #9 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_1","displayName":"Enabled","description":null,"helpText":null}]},"cb0d0ffc17eccf2a":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1","displayName":"Color for inserted cells: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_1","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_0","displayName":"By Author","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_2","displayName":"Pink","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_3","displayName":"Light blue","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_4","displayName":"Light yellow","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_5","displayName":"Light purple","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_6","displayName":"Light Orange","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_7","displayName":"Light green","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_tablecomparecolors_l_tablecomparecolorspart1_8","displayName":"Gray","description":null,"helpText":null}]},"cb8ec33758893956":{"id":"vendor_msft_sharedpc_maxpagefilesizemb","displayName":"Max Page File Size MB","description":"Maximum size of the paging file in MB. Applies only to systems with less than 32 GB storage and at least 3 GB of RAM. If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/SharedPC-csp/"],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/cd.json b/public/intune-definitions/cd.json index 01aee7e21014..3f6ad8eede1d 100644 --- a/public/intune-definitions/cd.json +++ b/public/intune-definitions/cd.json @@ -1 +1 @@ -{"cd18f99f5c8f68d2":{"id":"com.apple.assetcache.managed_com.apple.assetcache.managed","displayName":"Top Level Setting Group Collection","description":"com.apple.AssetCache.managed","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},"cdffcacb7204fd98":{"id":"com.apple.managedclient.preferences_automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticdownloadsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cd316ff7e79f1949":{"id":"com.apple.managedclient.preferences_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\n\nIf you don't configure this policy, no app is forced to be shown in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used and no sidebar can be shown.\n\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarappurlhostforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cd7d0b41c42f65e6":{"id":"com.apple.managedclient.preferences_exclusions_item_$type","displayName":"Type","description":null,"helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusions_item_$type_0","displayName":"Path","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type_1","displayName":"File extension","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type_2","displayName":"File name","description":null,"helpText":null}]},"cd3e1e4fd14bff9f":{"id":"com.apple.managedclient.preferences_javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\n\nIf you don't configure this policy, the global default value from the \"DefaultJavaScriptSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cdc3070b1b872a1e":{"id":"com.apple.networkusagerules_applicationrules_item_appidentifiermatches","displayName":"App Identifier Matches","description":"A list of managed app identifiers, as strings, that must follow the associated rules. If this key is missing, the rules apply to all managed apps on the device. Each string in the AppIdentifierMatches array may either be an exact app identifier match (for example, com.mycompany.myapp) or it may specify a prefix match for the bundle ID by using the * wildcard character. If used, this character must appear after a period (.) and may only appear once, at the end of the string; for example, com.mycompany.*.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},"cd17f28492f68f7a":{"id":"com.apple.xsan_sanauthmethod","displayName":"San Auth Method","description":"The authentication method for the SAN. This key is required for all Xsan SANs. It's optional for StorNext SANs but should be set if the StorNext SAN uses an auth_secret file. Only one value is accepted: auth_secret","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":{"id":"com.apple.xsan_sanauthmethod_0","displayName":"auth_secret","description":null,"helpText":null}},"cde3091c389e0d56":{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptallowedforurls","displayName":"Allow JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to run JavaScript.\n\nIf you don't configure this policy, \"DefaultJavaScriptSetting\" applies for all sites, when the setting is enabled. If not, the user's personal setting applies.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"cd56425bb66ba808":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled","displayName":"Allow feature recommendations and browser assistance notifications from Microsoft Edge","description":"This setting controls the in-browser assistance notifications that are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance, Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management.\n\nDisabling this policy stops this message from appearing again even if the user has too many tabs open.\nAny features that have been disabled by a management policy aren't suggested to users.\nIf you enable or don't configure this setting, users receive recommendations or notifications from Microsoft Edge.\nIf you disable this setting, users won't receive any recommendations or notifications from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"cd9b49756cd5809d":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser","displayName":"Allow non-administrators to install drivers for these device setup classes","description":"This policy setting specifies a list of device setup class GUIDs describing driver packages that non-administrator members of the built-in Users group may install on the system.\n\nIf you enable this policy setting, members of the Users group may install new drivers for the specified device setup classes. The drivers must be signed according to Windows Driver Signing Policy, or be signed by publishers already in the TrustedPublisher store.\n\nIf you disable or do not configure this policy setting, only members of the Administrators group are allowed to install new driver packages on the system.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-driverinstall-classes-allowuser"],"categoryId":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","categoryName":"Driver Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_1","displayName":"Enabled","description":null,"helpText":null}]},"cdaf815fd13f7e85":{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown","displayName":"Select search order:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_1","displayName":"Always search Windows Update","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_2","displayName":"Search Windows Update only if needed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_0","displayName":"Do not search Windows Update","description":null,"helpText":null}]},"cd0935078c811ed0":{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid","displayName":"Request compound authentication","description":"This policy setting allows you to configure a domain controller to request compound authentication.\r\n\r\nNote: For a domain controller to request compound authentication, the policy \"KDC support for claims, compound authentication, and Kerberos armoring\" must be configured and enabled. \r\n\r\nIf you enable this policy setting, domain controllers will request compound authentication. The returned service ticket will contain compound authentication only when the account is explicitly configured. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain. \r\n\r\nIf you disable or do not configure this policy setting, domain controllers will return service tickets that contain compound authentication any time the client sends a compound authentication request regardless of the account configuration.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-requestcompoundid"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid_1","displayName":"Enabled","description":null,"helpText":null}]},"cd04603f327eadd4":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint","displayName":"Create a system restore point","description":"This policy setting allows you to create a system restore point on the computer on a daily basis prior to cleaning. \r\n\r\n If you enable this setting, a system restore point will be created.\r\n\r\n If you disable or do not configure this setting, a system restore point will not be created.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablerestorepoint"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint_1","displayName":"Enabled","description":null,"helpText":null}]},"cdead83823db97ca":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_netlogon_expecteddialupdelaylabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"cdcc0e2b25294697":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_lbl_defcachesizespin","displayName":"Default cache size:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"cd177e75327a18bf":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},"cd06d9f0f27345e9":{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings","displayName":"Options for handling ROCA-vulnerable WHfB keys:","description":"","helpText":"","infoUrls":[],"categoryId":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","categoryName":"Security Account Manager","options":[{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_0","displayName":"Ignore ROCA-vulnerable WHfB keys","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_1","displayName":"Audit ROCA-vulnerable WHfB keys on use","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_2","displayName":"Block ROCA-vulnerable WHfB keys on use","description":null,"helpText":null}]},"cdf179e8e6aa0535":{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2","displayName":"Turn off location scripting","description":"\r\n This policy setting turns off scripting for the location feature.\r\n\r\n If you enable this policy setting, scripts for the location feature will not run.\r\n\r\n If you disable or do not configure this policy setting, all location scripts will run.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sensors#admx-sensors-disablelocationscripting-2"],"categoryId":"b40cfb22-8f17-4317-bcbb-c1c871497446","categoryName":"Location and Sensors","options":[{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2_1","displayName":"Enabled","description":null,"helpText":null}]},"cd4287741debb8ec":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver","displayName":"Use WDDM graphics display driver for Remote Desktop Connections","description":"This policy setting lets you enable WDDM graphics display driver for Remote Desktop Connections.\r\n\r\nIf you enable or do not configure this policy setting, Remote Desktop Connections will use WDDM graphics display driver.\r\n\r\nIf you disable this policy setting, Remote Desktop Connections will NOT use WDDM graphics display driver. In this case, the Remote Desktop Connections will use XDDM graphics display driver.\r\n\r\nFor this change to take effect, you must restart Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-wddm-graphics-driver"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver_1","displayName":"Enabled","description":null,"helpText":null}]},"cd8ca1efd05c0135":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016","displayName":"Microsoft Office 365 Lync 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_1","displayName":"Enabled","description":null,"helpText":null}]},"cd19f7eb420082d0":{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy","displayName":"Diagnostics: Configure scenario retention","description":"This policy setting determines the data retention limit for Diagnostic Policy Service (DPS) scenario data.\r\n\r\nIf you enable this policy setting, you must enter the maximum size of scenario data that should be retained in megabytes. Detailed troubleshooting data related to scenarios will be retained until this limit is reached.\r\n\r\nIf you disable or do not configure this policy setting, the DPS deletes scenario data once it exceeds 128 megabytes in size.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenario data will not be deleted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wdi#admx-wdi-wdidpsscenariodatasizelimitpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"cd45dc6d61eca193":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown","displayName":"Pick one of the following settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown_block","displayName":"Warn and prevent bypass","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown_warn","displayName":"Warn","description":null,"helpText":null}]},"cd1f38f30f5e08dd":{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority","displayName":"Costed Network Behavior Background Priority","description":"This policy setting defines the default behavior that the Background Intelligent Transfer Service (BITS) uses for background transfers when the system is connected to a costed network (3G, etc. ). Download behavior policies further limit the network usage of background transfers. If you enable this policy setting, you can define a default download policy for each BITS job priority. This setting does not override a download policy explicitly configured by the application that created the BITS job, but does apply to jobs that are created by specifying only a priority. For example, you can specify that background jobs are by default to transfer only when on uncosted network connections, but foreground jobs should proceed only when not roaming. The values that can be assigned are:1 - Always transfer2 - Transfer unless roaming3 - Transfer unless surcharge applies (when not roaming or overcap)4 - Transfer unless nearing limit (when not roaming or nearing cap)5 - Transfer only if unconstrained","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#costednetworkbehaviorbackgroundpriority"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":[{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_1","displayName":"Always transfer","description":"Always transfer","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_2","displayName":"Transfer unless roaming","description":"Transfer unless roaming","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_3","displayName":"Transfer unless surcharge applies (when not roaming or over cap)","description":"Transfer unless surcharge applies (when not roaming or over cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_4","displayName":"Transfer unless nearing limit (when not roaming or nearing cap)","description":"Transfer unless nearing limit (when not roaming or nearing cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_5","displayName":"Transfer only if unconstrained","description":"Transfer only if unconstrained","helpText":null}]},"cd058cb13d49cf8a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load mixed content","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow mixed content","description":null,"helpText":null}]},"cd04c014122e6d24":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode","displayName":"Choose how to specify proxy server settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_direct","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_auto_detect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_pac_script","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_fixed_servers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_system","displayName":"Use system proxy settings","description":null,"helpText":null}]},"cd06ce06d4d1e790":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode","description":"Overrides default background graphics printing mode.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},"cd0d218e197b7f7b":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled","description":"Configure the list of domains where Google Chrome should disable the Password Manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\r\n\r\nIf a domain is present in the list, the Password Manager will be disabled for it.\r\n\r\nIf a domain is not present in the list, the Password Manager will be available for it.\r\n\r\nIf the policy is unset, the Password Manager will be available for all domains.\r\n\r\nExample value:\r\n\r\nexample.com\r\nlogin.example.com","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"cdb3f28878b0be2b":{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel","displayName":"Configure which channel of Microsoft Edge to use for opening redirected sites","description":"Enables you to configure up to three versions of Microsoft Edge to open a redirected site (in order of preference). Use this policy if your environment is configured to redirect sites from Internet Explorer 11 to Microsoft Edge. If any of the chosen versions are not installed on the device, that preference will be bypassed.\n\nIf both the Windows Update for the next version of Microsoft Edge* and Microsoft Edge Stable channel are installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge Stable channel is used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\nIf the Windows Update for the next version of Microsoft Edge* or Microsoft Edge Stable channel are not installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge version 45 or earlier is automatically used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 0 = Microsoft Edge version 45 or earlier\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\n*For more information about the Windows update for the next version of Microsoft Edge including how to disable it, see https://go.microsoft.com/fwlink/?linkid=2102115. This update applies only to Windows 10 version 1709 and higher.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-configureedgeredirectchannel"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_1","displayName":"Enabled","description":null,"helpText":null}]},"cd65c8956f7c700e":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowsmartscreenie"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"cdcb4824116877a8":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer","displayName":"Allow VBScript to run in Internet Explorer","description":"This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.\n\nIf you selected Enable in the drop-down box, VBScript can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.\n\nIf you selected Disable in the drop-down box, VBScript is prevented from running.\n\nIf you do not configure or disable this policy setting, VBScript is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowvbscripttorunininternetexplorer"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"cd90c79b81ccdb1f":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_sharingandsecuritymodelforlocalaccounts","displayName":"Network Access Sharing And Security Model For Local Accounts","description":"Network access: Sharing and security model for local accounts This security setting determines how network logons that use local accounts are authenticated. If this setting is set to Classic, network logons that use local account credentials authenticate by using those credentials. The Classic model allows fine control over access to resources. By using the Classic model, you can grant different types of access to different users for the same resource. If this setting is set to Guest only, network logons that use local accounts are automatically mapped to the Guest account. By using the Guest model, you can have all users treated equally. All users authenticate as Guest, and they all receive the same level of access to a given resource, which can be either Read-only or Modify. Default on domain computers: Classic. Default on stand-alone computers: Guest only Important With the Guest only model, any user who can access your computer over the network (including anonymous Internet users) can access your shared resources. You must use the Windows Firewall or another similar device to protect your computer from unauthorized access. Similarly, with the Classic model, local accounts must be password protected; otherwise, those user accounts can be used by anyone to access shared system resources. Note: This setting does not affect interactive logons that are performed remotely by using such services as Telnet or Remote Desktop Services. Remote Desktop Services was called Terminal Services in previous versions of Windows Server. This policy will have no impact on computers running Windows 2000. When the computer is not joined to a domain, this setting also modifies the Sharing and Security tabs in File Explorer to correspond to the sharing and security model that is being used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_sharingandsecuritymodelforlocalaccounts"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"cd136a85eb14c780":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability","displayName":"Control where developer tools can be used (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_0","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_1","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_2","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},"cdc378318f3ffc42":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch","displayName":"Enforce Google SafeSearch","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\r\n\r\nIf you enable this policy, SafeSearch in Google Search is always active.\r\n\r\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},"cd9316a70bee57bd":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls","displayName":"Block clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"cd10a1a57916349d":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If you enable this policy, Microsoft Edge will allow Web Authentication requests on websites that have TLS certificates with errors (i.e. websites considered not secure).\r\n\r\nIf you disable or don't configure this policy, the default behavior of blocking such requests will apply.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts_1","displayName":"Enabled","description":null,"helpText":null}]},"cd8a369372ea1781":{"id":"device_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nLocal Network Access restrictions prevent public websites from making\r\nrequests to devices on a user's local network without explicit user permission.\r\n\r\nIf you enable this policy, Microsoft Edge will\r\nblock any request that would otherwise trigger a DevTools warning\r\ndue to Local Network Access checks.\r\nThese requests will be denied without prompting the user.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will handle\r\nthese requests using the default behavior, which may include showing warnings in DevTools\r\nand allowing the request to proceed depending on the context.\r\n\r\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\r\nunless explicitly granted by the user.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cdb26434709f86cf":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge.","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_1","displayName":"Enabled","description":null,"helpText":null}]},"cd4beeaa5ec0087f":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu","displayName":"Show context menu to open a link in Internet Explorer mode","description":"This policy controls the visibility of the 'Open link in new Internet Explorer mode tab' option on the context menu for file:// links.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, the 'Open link in new Internet Explorer mode tab' context menu item will be available for file:// links.\r\n\r\nIf you set this policy to false or don't configure it, the context menu item will not be added.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"cd6df22dc1f844a8":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_sameorigintabcaptureallowedbyoriginsdesc","displayName":"Allow Same Origin Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"cd3901fdc62022a5":{"id":"device_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_disablenewaccountdetection","displayName":"Disable a toast and activity center message to encourage a user to sign in OneDrive using an existing credential that is made available to Microsoft applications","description":"If admins enable this setting (value 1), the user won't see the toast and the activity center message about new accounts that can be used to sign-in with OneDrive.\r\n\r\nIf admins disable (value 0) or do not configure this setting, the user will see the toast and the activity center message when OneDrive detects a new account on the device.\r\n ","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_disablenewaccountdetection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_disablenewaccountdetection_1","displayName":"Enabled","description":null,"helpText":null}]},"cdbc6b0ecdf59d18":{"id":"device_vendor_msft_policy_config_remotemanagement_disallownegotiateauthenticationservice","displayName":"Disallow Negotiate authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) service accepts Negotiate authentication from a remote client.\n\n If you enable this policy setting, the WinRM service does not accept Negotiate authentication from a remote client.\n\n If you disable or do not configure this policy setting, the WinRM service accepts Negotiate authentication from a remote client.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-disallownegotiateauthenticationservice"],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_disallownegotiateauthenticationservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_disallownegotiateauthenticationservice_1","displayName":"Enabled","description":null,"helpText":null}]},"cd0fc0475f1a88bc":{"id":"device_vendor_msft_policy_config_system_enableonesettingsauditing","displayName":"Enable One Settings Auditing","description":"This policy setting controls whether Windows records attempts to connect with the OneSettings service to the EventLog. If you enable this policy, Windows will record attempts to connect with the OneSettings service to the Microsoft\\Windows\\Privacy-Auditing\\Operational EventLog channel. If you disable or don't configure this policy setting, Windows will not record attempts to connect with the OneSettings service to the EventLog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#enableonesettingsauditing"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_enableonesettingsauditing_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_enableonesettingsauditing_1","displayName":"Enabled.","description":"Enabled.","helpText":null}]},"cd9219c7d67816c2":{"id":"device_vendor_msft_policy_config_update_requiredeferupgrade","displayName":"Require Defer Upgrade","description":"NoteDon't use this policy in Windows 10, version 1607 devices, instead use the new policies listed in Changes in Windows 10, version 1607 for update management. You can continue to use RequireDeferUpgrade for Windows 10, version 1511 devices. Allows the IT admin to set a device to Semi-Annual Channel train.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#requiredeferupgrade"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_requiredeferupgrade_0","displayName":"User gets upgrades from Semi-Annual Channel (Targeted).","description":"User gets upgrades from Semi-Annual Channel (Targeted).","helpText":null},{"id":"device_vendor_msft_policy_config_update_requiredeferupgrade_1","displayName":"User gets upgrades from Semi-Annual Channel.","description":"User gets upgrades from Semi-Annual Channel.","helpText":null}]},"cda38d7a1d27f02c":{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_createdesktopshortcutmicrosoftedge","displayName":"Prevent Desktop Shortcut creation upon install","description":"If you enable this policy a desktop shortcut is created when Microsoft Edge is installed.\r\n If you disable this policy, no desktop shortcut will be created when Microsoft Edge is installed.\r\n If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. \r\n If Microsoft Edge is already installed, this policy will have no effect.\r\n\r\n If you don't configure this policy for a channel, the 'CreateDesktopShortcut default' policy configuration determines shortcut creation when Microsoft Edge is installed.","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_createdesktopshortcutmicrosoftedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_createdesktopshortcutmicrosoftedge_1","displayName":"Enabled","description":null,"helpText":null}]},"cdd54ed2f8c33b7a":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders78","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders78_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders78_1","displayName":"True","description":null,"helpText":null}]},"cd220bb4ce4c9704":{"id":"user_vendor_msft_policy_config_admx_desktop_nodesktop","displayName":"Hide and disable all items on the desktop (User)","description":"Removes icons, shortcuts, and other default and user-defined items from the desktop, including Briefcase, Recycle Bin, Computer, and Network Locations.\r\n\r\nRemoving icons and shortcuts does not prevent the user from using another method to start the programs or opening the items they represent.\r\n\r\nAlso, see \"Items displayed in Places Bar\" in User Configuration\\Administrative Templates\\Windows Components\\Common Open File Dialog to remove the Desktop icon from the Places Bar. This will help prevent users from saving data to the Desktop.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-nodesktop"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_desktop_nodesktop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_nodesktop_1","displayName":"Enabled","description":null,"helpText":null}]},"cd992c0133e574a2":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_napsnap_gp","displayName":"NAP Client Configuration (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-napsnap-gp"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_napsnap_gp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_napsnap_gp_1","displayName":"Enabled","description":null,"helpText":null}]},"cd9ec96948964377":{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvesearch","displayName":"Do not use the search-based method when resolving shell shortcuts (User)","description":"This policy setting prevents the system from conducting a comprehensive search of the target drive to resolve a shortcut.\r\n\r\nIf you enable this policy setting, the system does not conduct the final drive search. It just displays a message explaining that the file is not found.\r\n\r\nIf you disable or do not configure this policy setting, by default, when the system cannot find the target file for a shortcut (.lnk), it searches all paths associated with the shortcut. If the target file is located on an NTFS partition, the system then uses the target's file ID to find a path. If the resulting path is not correct, it conducts a comprehensive search of the target drive in an attempt to find the file.\r\n\r\nNote: This policy setting only applies to target files on NTFS partitions. FAT partitions do not have this ID tracking and search capability.\r\n\r\nAlso, see the \"Do not track Shell shortcuts during roaming\" and the \"Do not use the tracking-based method when resolving shell shortcuts\" policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-noresolvesearch"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvesearch_1","displayName":"Enabled","description":null,"helpText":null}]},"cd8aeac7aeb85160":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_password_saving_1","displayName":"Do not allow passwords to be saved (User)","description":"Controls whether a user can save passwords using Remote Desktop Connection.\r\n\r\nIf you enable this setting the credential saving checkbox in Remote Desktop Connection will be disabled and users will no longer be able to save passwords. When a user opens an RDP file using Remote Desktop Connection and saves his settings, any password that previously existed in the RDP file will be deleted.\r\n\r\nIf you disable this setting or leave it not configured, the user will be able to save passwords using Remote Desktop Connection\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-disable-password-saving-1"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_password_saving_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_password_saving_1_1","displayName":"Enabled","description":null,"helpText":null}]},"cd29267ab02feeb4":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable","displayName":"Enable notification (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable_1","displayName":"True","description":null,"helpText":null}]},"cd5ed3b9a0e7d836":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability","displayName":"Incognito mode availability (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_0","displayName":"Incognito mode available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_1","displayName":"Incognito mode disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_2","displayName":"Incognito mode forced","description":null,"helpText":null}]},"cde9de45da44ffe9":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cd0f171f2b0d2638":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended","displayName":"Enable network prediction (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cdc691fa8fe6dce3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled","displayName":"Enable URL-keyed anonymized data collection (User)","description":"Setting the policy to Enabled means URL-keyed anonymized data collection, which sends URLs of pages the user visits to Google to make searches and browsing better, is always active.\r\n\r\nSetting the policy to Disabled results in no URL-keyed anonymized data collection.\r\n\r\nIf you set the policy, users can't change. If not set, then URL-keyed anonymized data collection at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cdb95f6418d55982":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled","displayName":"Enable Safe Browsing (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cd51d8aa93664d96":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"cd4f795f5df9f9d8":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_pathcolon9","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"cda090cc28256d4f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16_1","displayName":"True","description":null,"helpText":null}]},"cddb369d051fb067":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallownetframeworkreliantcomponents"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"cd09fab64b103fd0":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled","displayName":"DNS interception checks enabled (User)","description":"This policy configures a local switch that can be used to disable DNS interception checks. These checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nThis detection might not be necessary in an enterprise environment where the network configuration is known. It can be disabled to avoid additional DNS and HTTP traffic on start-up and each DNS configuration change.\r\n\r\nIf you enable or don’t set this policy, the DNS interception checks are performed.\r\n\r\nIf you disable this policy, DNS interception checks aren’t performed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cd8c9d5e499c19df":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"cdacc40500da7a62":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_0","displayName":"Off (Not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_1","displayName":"Required data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_2","displayName":"Optional data","description":null,"helpText":null}]},"cdcfed24ede01ac1":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled","displayName":"Enable the User-Agent Client Hints feature (obsolete) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it's only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it's found to be incompatible with the User-Agent Client Hints feature. It won't work in Microsoft Edge version 89.\r\n\r\nWhen enabled the User-Agent Client Hints feature sends granular request headers that provide information about the user browser (for example, the browser version) and environment (for example, the system architecture).\r\n\r\nThis is an additive feature, but the new headers may break some websites that restrict the characters that requests may contain.\r\n\r\nIf you enable or don't configure this policy, the User-Agent Client Hints feature is enabled. If you disable this policy, this feature is unavailable.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cd213bb53e16f060":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser (User)","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\r\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\r\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\r\n\r\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\r\n\r\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"cd698cb02853e161":{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_0","displayName":"Automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_1","displayName":"With device password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_2","displayName":"With custom primary password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_3","displayName":"Autofill off","description":null,"helpText":null}]},"cd28cb35c4fec307":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing","displayName":"Activate Restricted Browsing (User)","description":"When Restricted Browsing is activated the save as dialog box will be restricted such that the user will only be able to navigate to those locations and the children of those locations specified in the \"Restricted Browsing\\Approve Locations\" policy setting. If you want to enable the \"Approve Locations\" policy setting, you must first enable the \"Approve Locations\" policy setting first.","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},"cde102480fc93ac3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips","displayName":"Show shortcut keys in ScreenTips (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},"cdcc0da00b2d480a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowdescrip445","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"cd6173c546a6b14c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06","displayName":"Escrow Key #6 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_1","displayName":"Enabled","description":null,"helpText":null}]},"cdbd7025ce1dd824":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10_1","displayName":"True","description":null,"helpText":null}]},"cd0e64f184a7adfa":{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart","displayName":"Block OrgChart (User)","description":"This policy setting allows you to control whether Organization Chart (OrgChart) Add-in for Microsoft Office programs runs in Microsoft 365 apps.\r\n\r\nIf you enable this policy setting, OrgChart will not run in any Microsoft 365 app. Instead, a static image will render in its place.\r\n\r\nIf you disable this policy setting, OrgChart will run in Microsoft 365 apps.\r\n\r\nIf you don't configure this policy setting, OrgChart will run in Microsoft 365 apps.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart_1","displayName":"Enabled","description":null,"helpText":null}]},"cdcbe1abfd2d4fd1":{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_0","displayName":"Display automatically when MailTips apply","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_1","displayName":"Display at all times","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_2","displayName":"Never display MailTips","description":null,"helpText":null}]},"cda05e04b6a81f62":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver_l_entersecondstowaitbeforeuploaddefault15sec","displayName":"Enter seconds to wait before upload(Default 15 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},"cd66e16ac3d49930":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions","displayName":"Do not roam users' RSS Feeds (User)","description":"This policy setting allows you to change the default delivery location of RSS Feeds to a local PST.\r\n\r\nIf you enable this setting, the default delivery location will be changed to a local PST. When RSS Feeds are delivered to a local PST, they will not roam from client to client and will only be available on the computer where the user originally subscribed to the RSS Feed.\r\n\r\nIf you disable or do not configure this policy setting, subscriptions to RSS Feeds are delivered to the user's mailbox and roam from client to client via Exchange. This setting does not affect RSS Feeds that were subscribed before the policy setting was enabled. This setting also does not prevent the user from manually directing an RSS Feed to deliver to the user's mailbox, which allows the RSS Feed to roam from client to client.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions_1","displayName":"Enabled","description":null,"helpText":null}]},"cdf05fa1ff5f532f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"cd7b549bbc9b0d7f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"cd1e8d46ca6c2751":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"cdbe00964676f013":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},"cd6aec662cb5097a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"cdcdd0ded796b0de":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab","displayName":"Default tab to show in Publisher on the Office Start screen and in File | New (User)","description":"This policy setting controls what displays as the default tab in Publisher on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, you can choose one of two options to become the default tab on the Office Start screen and in File | New:\r\n\r\n* Built-in – Users will the see built-in templates tab as the default tab in Publisher on the Office Start screen and in File | New.\r\n\r\n* Custom – Users will the see custom templates tab as the default tab in Publisher on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Publisher on the Office Start screen and in File | New","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_1","displayName":"Enabled","description":null,"helpText":null}]},"cd437741ee26ebcb":{"id":"user_vendor_msft_policy_config_start_configurestartpins","displayName":"Configure Start Pins (User)","description":"Allows admin to override the default items pinned to Start.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#configurestartpins"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":null},"cd608d514333a15f":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},"cd21594ac622cae5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_1","displayName":"Enabled","description":null,"helpText":null}]},"cd06d020eb19ed08":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu","displayName":"Match hyu/iyu, byu/vyu (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu_1","displayName":"Enabled","description":null,"helpText":null}]},"cd07d93597a967ec":{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt","displayName":"IPsec Exceptions","description":"This value configures IPsec exceptions and MUST be a combination of the valid flags that are defined in IPSEC_EXEMPT_VALUES; therefore, the maximum value MUST always be IPSEC_EXEMPT_MAX-1 for servers supporting a schema version of 0x0201 and IPSEC_EXEMPT_MAX_V2_0-1 for servers supporting a schema version of 0x0200. If the maximum value is exceeded when the method RRPC_FWSetGlobalConfig (Opnum 4) is called, the method returns ERROR_INVALID_PARAMETER. This error code is returned if no other preceding error is discovered. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_0","displayName":"FWGLOBALCONFIGIPSECEXEMPTNONE: No IPsec exemptions.","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_NONE: No IPsec exemptions.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_1","displayName":"Exempt neighbor discover IPv6 ICMP type-codes from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_NEIGHBOR_DISC: Exempt neighbor discover IPv6 ICMP type-codes from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_2","displayName":"Exempt ICMP from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_ICMP: Exempt ICMP from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_4","displayName":"Exempt router discover IPv6 ICMP type-codes from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_ROUTER_DISC: Exempt router discover IPv6 ICMP type-codes from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_8","displayName":"Exempt both IPv4 and IPv6 DHCP traffic from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_DHCP: Exempt both IPv4 and IPv6 DHCP traffic from IPsec.","helpText":null}]}} \ No newline at end of file +{"cd18f99f5c8f68d2":{"id":"com.apple.assetcache.managed_com.apple.assetcache.managed","displayName":"Top Level Setting Group Collection","description":"com.apple.AssetCache.managed","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},"cdffcacb7204fd98":{"id":"com.apple.managedclient.preferences_automaticdownloadsblockedforurls","displayName":"Block multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, where multiple successive automatic downloads aren't allowed.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticdownloadsblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cd316ff7e79f1949":{"id":"com.apple.managedclient.preferences_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\n\nIf you don't configure this policy, no app is forced to be shown in sidebar.\n\nIf the \"HubsSidebarEnabled\" policy is disabled, this list isn't used and no sidebar can be shown.\n\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\n\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgesidebarappurlhostforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cd7d0b41c42f65e6":{"id":"com.apple.managedclient.preferences_exclusions_item_$type","displayName":"Type","description":null,"helpText":null,"infoUrls":[],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_exclusions_item_$type_0","displayName":"Path","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type_1","displayName":"File extension","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_exclusions_item_$type_2","displayName":"File name","description":null,"helpText":null}]},"cd3e1e4fd14bff9f":{"id":"com.apple.managedclient.preferences_javascriptblockedforurls","displayName":"Block JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to run JavaScript.\n\nIf you don't configure this policy, the global default value from the \"DefaultJavaScriptSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptblockedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cdc3070b1b872a1e":{"id":"com.apple.networkusagerules_applicationrules_item_appidentifiermatches","displayName":"App Identifier Matches","description":"A list of managed app identifiers, as strings, that must follow the associated rules. If this key is missing, the rules apply to all managed apps on the device. Each string in the AppIdentifierMatches array may either be an exact app identifier match (for example, com.mycompany.myapp) or it may specify a prefix match for the bundle ID by using the * wildcard character. If used, this character must appear after a period (.) and may only appear once, at the end of the string; for example, com.mycompany.*.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},"cd17f28492f68f7a":{"id":"com.apple.xsan_sanauthmethod","displayName":"San Auth Method","description":"The authentication method for the SAN. This key is required for all Xsan SANs. It's optional for StorNext SANs but should be set if the StorNext SAN uses an auth_secret file. Only one value is accepted: auth_secret","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":{"id":"com.apple.xsan_sanauthmethod_0","displayName":"auth_secret","description":null,"helpText":null}},"cde3091c389e0d56":{"id":"com.microsoft.edge.mamedgeappconfigsettings.javascriptallowedforurls","displayName":"Allow JavaScript on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to run JavaScript.\n\nIf you don't configure this policy, \"DefaultJavaScriptSetting\" applies for all sites, when the setting is enabled. If not, the user's personal setting applies.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"cd56425bb66ba808":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled","displayName":"Allow feature recommendations and browser assistance notifications from Microsoft Edge","description":"This setting controls the in-browser assistance notifications that are intended to help users get the most out of Microsoft Edge. This is done by recommending features and by helping them use browser features. These notifications take the form of dialog boxes, flyouts, coach marks and banners in the browser. An example of an assistance notification would be when a user has many tabs opened in the browser. In this instance, Microsoft Edge may prompt the user to try out the vertical tabs feature which is designed to give better browser tab management.\n\nDisabling this policy stops this message from appearing again even if the user has too many tabs open.\nAny features that have been disabled by a management policy aren't suggested to users.\nIf you enable or don't configure this setting, users receive recommendations or notifications from Microsoft Edge.\nIf you disable this setting, users won't receive any recommendations or notifications from Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showrecommendationsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"cd9b49756cd5809d":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser","displayName":"Allow non-administrators to install drivers for these device setup classes","description":"This policy setting specifies a list of device setup class GUIDs describing driver packages that non-administrator members of the built-in Users group may install on the system.\n\nIf you enable this policy setting, members of the Users group may install new drivers for the specified device setup classes. The drivers must be signed according to Windows Driver Signing Policy, or be signed by publishers already in the TrustedPublisher store.\n\nIf you disable or do not configure this policy setting, only members of the Administrators group are allowed to install new driver packages on the system.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-driverinstall-classes-allowuser"],"categoryId":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","categoryName":"Driver Installation","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_1","displayName":"Enabled","description":null,"helpText":null}]},"cdaf815fd13f7e85":{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown","displayName":"Select search order:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_1","displayName":"Always search Windows Update","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_2","displayName":"Search Windows Update only if needed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_devicesetup_driversearchplaces_searchorderconfiguration_driversearchplaces_searchorderconfiguration_dropdown_0","displayName":"Do not search Windows Update","description":null,"helpText":null}]},"cd0935078c811ed0":{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid","displayName":"Request compound authentication","description":"This policy setting allows you to configure a domain controller to request compound authentication.\r\n\r\nNote: For a domain controller to request compound authentication, the policy \"KDC support for claims, compound authentication, and Kerberos armoring\" must be configured and enabled. \r\n\r\nIf you enable this policy setting, domain controllers will request compound authentication. The returned service ticket will contain compound authentication only when the account is explicitly configured. This policy should be applied to all domain controllers to ensure consistent application of this policy in the domain. \r\n\r\nIf you disable or do not configure this policy setting, domain controllers will return service tickets that contain compound authentication any time the client sends a compound authentication request regardless of the account configuration.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kdc#admx-kdc-requestcompoundid"],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_requestcompoundid_1","displayName":"Enabled","description":null,"helpText":null}]},"cd04603f327eadd4":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint","displayName":"Create a system restore point","description":"This policy setting allows you to create a system restore point on the computer on a daily basis prior to cleaning. \r\n\r\n If you enable this setting, a system restore point will be created.\r\n\r\n If you disable or do not configure this setting, a system restore point will not be created.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disablerestorepoint"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disablerestorepoint_1","displayName":"Enabled","description":null,"helpText":null}]},"cdead83823db97ca":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_expecteddialupdelay_netlogon_expecteddialupdelaylabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"cdcc0e2b25294697":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_lbl_defcachesizespin","displayName":"Default cache size:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"cd177e75327a18bf":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_nc_qosdscpvalue","displayName":"DSCP value:","description":null,"helpText":"","infoUrls":[],"categoryId":"cf968979-f316-47cb-a207-bf9ef28cd1aa","categoryName":"DSCP value of non-conforming packets","options":null},"cd06d9f0f27345e9":{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings","displayName":"Options for handling ROCA-vulnerable WHfB keys:","description":"","helpText":"","infoUrls":[],"categoryId":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","categoryName":"Security Account Manager","options":[{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_0","displayName":"Ignore ROCA-vulnerable WHfB keys","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_1","displayName":"Audit ROCA-vulnerable WHfB keys on use","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sam_samngckeyrocavalidation_samngckeyrocavalidation_settings_2","displayName":"Block ROCA-vulnerable WHfB keys on use","description":null,"helpText":null}]},"cdf179e8e6aa0535":{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2","displayName":"Turn off location scripting","description":"\r\n This policy setting turns off scripting for the location feature.\r\n\r\n If you enable this policy setting, scripts for the location feature will not run.\r\n\r\n If you disable or do not configure this policy setting, all location scripts will run.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sensors#admx-sensors-disablelocationscripting-2"],"categoryId":"b40cfb22-8f17-4317-bcbb-c1c871497446","categoryName":"Location and Sensors","options":[{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_sensors_disablelocationscripting_2_1","displayName":"Enabled","description":null,"helpText":null}]},"cd4287741debb8ec":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver","displayName":"Use WDDM graphics display driver for Remote Desktop Connections","description":"This policy setting lets you enable WDDM graphics display driver for Remote Desktop Connections.\r\n\r\nIf you enable or do not configure this policy setting, Remote Desktop Connections will use WDDM graphics display driver.\r\n\r\nIf you disable this policy setting, Remote Desktop Connections will NOT use WDDM graphics display driver. In this case, the Remote Desktop Connections will use XDDM graphics display driver.\r\n\r\nFor this change to take effect, you must restart Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-wddm-graphics-driver"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_wddm_graphics_driver_1","displayName":"Enabled","description":null,"helpText":null}]},"cd8ca1efd05c0135":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016","displayName":"Microsoft Office 365 Lync 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_1","displayName":"Enabled","description":null,"helpText":null}]},"cd19f7eb420082d0":{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy","displayName":"Diagnostics: Configure scenario retention","description":"This policy setting determines the data retention limit for Diagnostic Policy Service (DPS) scenario data.\r\n\r\nIf you enable this policy setting, you must enter the maximum size of scenario data that should be retained in megabytes. Detailed troubleshooting data related to scenarios will be retained until this limit is reached.\r\n\r\nIf you disable or do not configure this policy setting, the DPS deletes scenario data once it exceeds 128 megabytes in size.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect: changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service is in the running state. When the service is stopped or disabled, diagnostic scenario data will not be deleted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wdi#admx-wdi-wdidpsscenariodatasizelimitpolicy"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wdi_wdidpsscenariodatasizelimitpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"cd45dc6d61eca193":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown","displayName":"Pick one of the following settings:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown_block","displayName":"Warn and prevent bypass","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enablesmartscreen_enablesmartscreendropdown_warn","displayName":"Warn","description":null,"helpText":null}]},"cd1f38f30f5e08dd":{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority","displayName":"Costed Network Behavior Background Priority","description":"This policy setting defines the default behavior that the Background Intelligent Transfer Service (BITS) uses for background transfers when the system is connected to a costed network (3G, etc. ). Download behavior policies further limit the network usage of background transfers. If you enable this policy setting, you can define a default download policy for each BITS job priority. This setting does not override a download policy explicitly configured by the application that created the BITS job, but does apply to jobs that are created by specifying only a priority. For example, you can specify that background jobs are by default to transfer only when on uncosted network connections, but foreground jobs should proceed only when not roaming. The values that can be assigned are:1 - Always transfer2 - Transfer unless roaming3 - Transfer unless surcharge applies (when not roaming or overcap)4 - Transfer unless nearing limit (when not roaming or nearing cap)5 - Transfer only if unconstrained","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-BITS#costednetworkbehaviorbackgroundpriority"],"categoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","categoryName":"BITS","options":[{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_1","displayName":"Always transfer","description":"Always transfer","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_2","displayName":"Transfer unless roaming","description":"Transfer unless roaming","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_3","displayName":"Transfer unless surcharge applies (when not roaming or over cap)","description":"Transfer unless surcharge applies (when not roaming or over cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_4","displayName":"Transfer unless nearing limit (when not roaming or nearing cap)","description":"Transfer unless nearing limit (when not roaming or nearing cap)","helpText":null},{"id":"device_vendor_msft_policy_config_bits_costednetworkbehaviorbackgroundpriority_5","displayName":"Transfer only if unconstrained","description":"Transfer only if unconstrained","helpText":null}]},"cd058cb13d49cf8a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting","displayName":"Control use of insecure content exceptions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_2","displayName":"Do not allow any site to load mixed content","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultinsecurecontentsetting_defaultinsecurecontentsetting_3","displayName":"Allow users to add exceptions to allow mixed content","description":null,"helpText":null}]},"cd04c014122e6d24":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode","displayName":"Choose how to specify proxy server settings (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_direct","displayName":"Never use a proxy","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_auto_detect","displayName":"Auto detect proxy settings","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_pac_script","displayName":"Use a .pac proxy script","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_fixed_servers","displayName":"Use fixed proxy servers","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxymode_proxymode_system","displayName":"Use system proxy settings","description":null,"helpText":null}]},"cd06ce06d4d1e790":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode","description":"Overrides default background graphics printing mode.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},"cd0d218e197b7f7b":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled","description":"Configure the list of domains where Google Chrome should disable the Password Manager. This means that Save and Fill workflows will be disabled, ensuring that passwords for those websites can't be saved or auto filled into web forms.\r\n\r\nIf a domain is present in the list, the Password Manager will be disabled for it.\r\n\r\nIf a domain is not present in the list, the Password Manager will be available for it.\r\n\r\nIf the policy is unset, the Password Manager will be available for all domains.\r\n\r\nExample value:\r\n\r\nexample.com\r\nlogin.example.com","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"cdb3f28878b0be2b":{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel","displayName":"Configure which channel of Microsoft Edge to use for opening redirected sites","description":"Enables you to configure up to three versions of Microsoft Edge to open a redirected site (in order of preference). Use this policy if your environment is configured to redirect sites from Internet Explorer 11 to Microsoft Edge. If any of the chosen versions are not installed on the device, that preference will be bypassed.\n\nIf both the Windows Update for the next version of Microsoft Edge* and Microsoft Edge Stable channel are installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge Stable channel is used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\nIf the Windows Update for the next version of Microsoft Edge* or Microsoft Edge Stable channel are not installed, the following behaviors occur:\n- If you disable or don't configure this policy, Microsoft Edge version 45 or earlier is automatically used. This is the default behavior.\n- If you enable this policy, you can configure redirected sites to open in up to three of the following channels where:\n 0 = Microsoft Edge version 45 or earlier\n 1 = Microsoft Edge Stable\n 2 = Microsoft Edge Beta version 77 or later\n 3 = Microsoft Edge Dev version 77 or later\n 4 = Microsoft Edge Canary version 77 or later\n\n*For more information about the Windows update for the next version of Microsoft Edge including how to disable it, see https://go.microsoft.com/fwlink/?linkid=2102115. This update applies only to Windows 10 version 1709 and higher.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-configureedgeredirectchannel"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_1","displayName":"Enabled","description":null,"helpText":null}]},"cd65c8956f7c700e":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowsmartscreenie"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"cdcb4824116877a8":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer","displayName":"Allow VBScript to run in Internet Explorer","description":"This policy setting allows you to manage whether VBScript can be run on pages from the specified zone in Internet Explorer.\n\nIf you selected Enable in the drop-down box, VBScript can run without user intervention.\n\nIf you selected Prompt in the drop-down box, users are asked to choose whether to allow VBScript to run.\n\nIf you selected Disable in the drop-down box, VBScript is prevented from running.\n\nIf you do not configure or disable this policy setting, VBScript is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowvbscripttorunininternetexplorer"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowvbscripttorunininternetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"cd90c79b81ccdb1f":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_sharingandsecuritymodelforlocalaccounts","displayName":"Network Access Sharing And Security Model For Local Accounts","description":"Network access: Sharing and security model for local accounts This security setting determines how network logons that use local accounts are authenticated. If this setting is set to Classic, network logons that use local account credentials authenticate by using those credentials. The Classic model allows fine control over access to resources. By using the Classic model, you can grant different types of access to different users for the same resource. If this setting is set to Guest only, network logons that use local accounts are automatically mapped to the Guest account. By using the Guest model, you can have all users treated equally. All users authenticate as Guest, and they all receive the same level of access to a given resource, which can be either Read-only or Modify. Default on domain computers: Classic. Default on stand-alone computers: Guest only Important With the Guest only model, any user who can access your computer over the network (including anonymous Internet users) can access your shared resources. You must use the Windows Firewall or another similar device to protect your computer from unauthorized access. Similarly, with the Classic model, local accounts must be password protected; otherwise, those user accounts can be used by anyone to access shared system resources. Note: This setting does not affect interactive logons that are performed remotely by using such services as Telnet or Remote Desktop Services. Remote Desktop Services was called Terminal Services in previous versions of Windows Server. This policy will have no impact on computers running Windows 2000. When the computer is not joined to a domain, this setting also modifies the Sharing and Security tabs in File Explorer to correspond to the sharing and security model that is being used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_sharingandsecuritymodelforlocalaccounts"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"cd136a85eb14c780":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability","displayName":"Control where developer tools can be used (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_0","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_1","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_developertoolsavailability_developertoolsavailability_2","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},"cdc378318f3ffc42":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch","displayName":"Enforce Google SafeSearch","description":"Forces queries in Google Web Search to be performed with SafeSearch set to active, and prevents users from changing this setting.\r\n\r\nIf you enable this policy, SafeSearch in Google Search is always active.\r\n\r\nIf you disable this policy or don't configure it, SafeSearch in Google Search isn't enforced.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forcegooglesafesearch_1","displayName":"Enabled","description":null,"helpText":null}]},"cd9316a70bee57bd":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls","displayName":"Block clipboard use on specific sites","description":"Configure the list of URL patterns that specify which sites can use the clipboard site permission.\r\n\r\nSetting the policy lets you create a list of URL patterns that specify sites that can't use the clipboard site permission. This doesn't include all clipboard operations on origins that match the patterns. For example, users will still be able to paste using keyboard shortcuts because this isn't controlled by the clipboard site permission.\r\n\r\nLeaving the policy unset means 'DefaultClipboardSetting' (Default clipboard site permission) applies for all sites if it's set. If it isn't set, the user's personal setting applies.\r\n\r\nFor more information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_clipboardblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"cd10a1a57916349d":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts","displayName":"Allow Web Authentication requests on sites with broken TLS certificates.","description":"If you enable this policy, Microsoft Edge will allow Web Authentication requests on websites that have TLS certificates with errors (i.e. websites considered not secure).\r\n\r\nIf you disable or don't configure this policy, the default behavior of blocking such requests will apply.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_allowwebauthnwithbrokentlscerts_1","displayName":"Enabled","description":null,"helpText":null}]},"cd8a369372ea1781":{"id":"device_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled","displayName":"Specifies whether to block requests from public websites to devices on a user's local network. (deprecated)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nLocal Network Access restrictions prevent public websites from making\r\nrequests to devices on a user's local network without explicit user permission.\r\n\r\nIf you enable this policy, Microsoft Edge will\r\nblock any request that would otherwise trigger a DevTools warning\r\ndue to Local Network Access checks.\r\nThese requests will be denied without prompting the user.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will handle\r\nthese requests using the default behavior, which may include showing warnings in DevTools\r\nand allowing the request to proceed depending on the context.\r\n\r\nNote: This feature improves local network security by deprecating direct access to private IP addresses from public websites\r\nunless explicitly granted by the user.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev138~policy~microsoft_edge~network_localnetworkaccessrestrictionsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cdb26434709f86cf":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge.","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?LinkId=2341535.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_allowbrowsingwithcopilot_1","displayName":"Enabled","description":null,"helpText":null}]},"cd4beeaa5ec0087f":{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu","displayName":"Show context menu to open a link in Internet Explorer mode","description":"This policy controls the visibility of the 'Open link in new Internet Explorer mode tab' option on the context menu for file:// links.\r\n\r\nThis setting works in conjunction with:\r\n'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) is set to 'IEMode'.\r\n\r\nIf you set this policy to true, the 'Open link in new Internet Explorer mode tab' context menu item will be available for file:// links.\r\n\r\nIf you set this policy to false or don't configure it, the context menu item will not be added.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_internetexplorerintegrationlocalfileshowcontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"cd6df22dc1f844a8":{"id":"device_vendor_msft_policy_config_microsoft_edgev97~policy~microsoft_edge~screencapture_sameorigintabcaptureallowedbyorigins_sameorigintabcaptureallowedbyoriginsdesc","displayName":"Allow Same Origin Tab capture by these origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"05811ceb-2954-426c-8afa-2a53f02480cc","categoryName":"Permit or deny screen capture","options":null},"cd3901fdc62022a5":{"id":"device_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_disablenewaccountdetection","displayName":"Disable a toast and activity center message to encourage a user to sign in OneDrive using an existing credential that is made available to Microsoft applications","description":"If admins enable this setting (value 1), the user won't see the toast and the activity center message about new accounts that can be used to sign-in with OneDrive.\r\n\r\nIf admins disable (value 0) or do not configure this setting, the user will see the toast and the activity center message when OneDrive detects a new account on the device.\r\n ","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_disablenewaccountdetection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv7~policy~onedrivengsc_disablenewaccountdetection_1","displayName":"Enabled","description":null,"helpText":null}]},"cdbc6b0ecdf59d18":{"id":"device_vendor_msft_policy_config_remotemanagement_disallownegotiateauthenticationservice","displayName":"Disallow Negotiate authentication","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) service accepts Negotiate authentication from a remote client.\n\n If you enable this policy setting, the WinRM service does not accept Negotiate authentication from a remote client.\n\n If you disable or do not configure this policy setting, the WinRM service accepts Negotiate authentication from a remote client.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-disallownegotiateauthenticationservice"],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_disallownegotiateauthenticationservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_disallownegotiateauthenticationservice_1","displayName":"Enabled","description":null,"helpText":null}]},"cd0fc0475f1a88bc":{"id":"device_vendor_msft_policy_config_system_enableonesettingsauditing","displayName":"Enable One Settings Auditing","description":"This policy setting controls whether Windows records attempts to connect with the OneSettings service to the EventLog. If you enable this policy, Windows will record attempts to connect with the OneSettings service to the Microsoft\\Windows\\Privacy-Auditing\\Operational EventLog channel. If you disable or don't configure this policy setting, Windows will not record attempts to connect with the OneSettings service to the EventLog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-System#enableonesettingsauditing"],"categoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_system_enableonesettingsauditing_0","displayName":"Disabled.","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_system_enableonesettingsauditing_1","displayName":"Enabled.","description":"Enabled.","helpText":null}]},"cd9219c7d67816c2":{"id":"device_vendor_msft_policy_config_update_requiredeferupgrade","displayName":"Require Defer Upgrade","description":"NoteDon't use this policy in Windows 10, version 1607 devices, instead use the new policies listed in Changes in Windows 10, version 1607 for update management. You can continue to use RequireDeferUpgrade for Windows 10, version 1511 devices. Allows the IT admin to set a device to Semi-Annual Channel train.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#requiredeferupgrade"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_requiredeferupgrade_0","displayName":"User gets upgrades from Semi-Annual Channel (Targeted).","description":"User gets upgrades from Semi-Annual Channel (Targeted).","helpText":null},{"id":"device_vendor_msft_policy_config_update_requiredeferupgrade_1","displayName":"User gets upgrades from Semi-Annual Channel.","description":"User gets upgrades from Semi-Annual Channel.","helpText":null}]},"cda38d7a1d27f02c":{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_createdesktopshortcutmicrosoftedge","displayName":"Prevent Desktop Shortcut creation upon install","description":"If you enable this policy a desktop shortcut is created when Microsoft Edge is installed.\r\n If you disable this policy, no desktop shortcut will be created when Microsoft Edge is installed.\r\n If you don’t configure this policy a desktop shortcut to Microsoft Edge will be created during installation. \r\n If Microsoft Edge is already installed, this policy will have no effect.\r\n\r\n If you don't configure this policy for a channel, the 'CreateDesktopShortcut default' policy configuration determines shortcut creation when Microsoft Edge is installed.","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_createdesktopshortcutmicrosoftedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev83diff~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_createdesktopshortcutmicrosoftedge_1","displayName":"Enabled","description":null,"helpText":null}]},"cdd54ed2f8c33b7a":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders78","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders78_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc19_l_allowsubfolders78_1","displayName":"True","description":null,"helpText":null}]},"cd220bb4ce4c9704":{"id":"user_vendor_msft_policy_config_admx_desktop_nodesktop","displayName":"Hide and disable all items on the desktop (User)","description":"Removes icons, shortcuts, and other default and user-defined items from the desktop, including Briefcase, Recycle Bin, Computer, and Network Locations.\r\n\r\nRemoving icons and shortcuts does not prevent the user from using another method to start the programs or opening the items they represent.\r\n\r\nAlso, see \"Items displayed in Places Bar\" in User Configuration\\Administrative Templates\\Windows Components\\Common Open File Dialog to remove the Desktop icon from the Places Bar. This will help prevent users from saving data to the Desktop.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-nodesktop"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_desktop_nodesktop_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_nodesktop_1","displayName":"Enabled","description":null,"helpText":null}]},"cd992c0133e574a2":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_napsnap_gp","displayName":"NAP Client Configuration (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-napsnap-gp"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_napsnap_gp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_napsnap_gp_1","displayName":"Enabled","description":null,"helpText":null}]},"cd9ec96948964377":{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvesearch","displayName":"Do not use the search-based method when resolving shell shortcuts (User)","description":"This policy setting prevents the system from conducting a comprehensive search of the target drive to resolve a shortcut.\r\n\r\nIf you enable this policy setting, the system does not conduct the final drive search. It just displays a message explaining that the file is not found.\r\n\r\nIf you disable or do not configure this policy setting, by default, when the system cannot find the target file for a shortcut (.lnk), it searches all paths associated with the shortcut. If the target file is located on an NTFS partition, the system then uses the target's file ID to find a path. If the resulting path is not correct, it conducts a comprehensive search of the target drive in an attempt to find the file.\r\n\r\nNote: This policy setting only applies to target files on NTFS partitions. FAT partitions do not have this ID tracking and search capability.\r\n\r\nAlso, see the \"Do not track Shell shortcuts during roaming\" and the \"Do not use the tracking-based method when resolving shell shortcuts\" policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-noresolvesearch"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvesearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvesearch_1","displayName":"Enabled","description":null,"helpText":null}]},"cd8aeac7aeb85160":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_password_saving_1","displayName":"Do not allow passwords to be saved (User)","description":"Controls whether a user can save passwords using Remote Desktop Connection.\r\n\r\nIf you enable this setting the credential saving checkbox in Remote Desktop Connection will be disabled and users will no longer be able to save passwords. When a user opens an RDP file using Remote Desktop Connection and saves his settings, any password that previously existed in the RDP file will be deleted.\r\n\r\nIf you disable this setting or leave it not configured, the user will be able to save passwords using Remote Desktop Connection\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-disable-password-saving-1"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_password_saving_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_password_saving_1_1","displayName":"Enabled","description":null,"helpText":null}]},"cd29267ab02feeb4":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable","displayName":"Enable notification (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_configuresyncmethod_settingsimportnotification_enable_1","displayName":"True","description":null,"helpText":null}]},"cd5ed3b9a0e7d836":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability","displayName":"Incognito mode availability (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_0","displayName":"Incognito mode available","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_1","displayName":"Incognito mode disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_incognitomodeavailability_incognitomodeavailability_2","displayName":"Incognito mode forced","description":null,"helpText":null}]},"cde9de45da44ffe9":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cd0f171f2b0d2638":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended","displayName":"Enable network prediction (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cdc691fa8fe6dce3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled","displayName":"Enable URL-keyed anonymized data collection (User)","description":"Setting the policy to Enabled means URL-keyed anonymized data collection, which sends URLs of pages the user visits to Google to make searches and browsing better, is always active.\r\n\r\nSetting the policy to Disabled results in no URL-keyed anonymized data collection.\r\n\r\nIf you set the policy, users can't change. If not set, then URL-keyed anonymized data collection at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_urlkeyedanonymizeddatacollectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cdb95f6418d55982":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled","displayName":"Enable Safe Browsing (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_safebrowsingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cd51d8aa93664d96":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturl_defaultsearchproviderinstanturl","displayName":"Default search provider instant URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"cd4f795f5df9f9d8":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc03_l_pathcolon9","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"cda090cc28256d4f":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_allowsubfolders16_1","displayName":"True","description":null,"helpText":null}]},"cddb369d051fb067":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzoneallownetframeworkreliantcomponents"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"cd09fab64b103fd0":{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled","displayName":"DNS interception checks enabled (User)","description":"This policy configures a local switch that can be used to disable DNS interception checks. These checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\r\n\r\nThis detection might not be necessary in an enterprise environment where the network configuration is known. It can be disabled to avoid additional DNS and HTTP traffic on start-up and each DNS configuration change.\r\n\r\nIf you enable or don’t set this policy, the DNS interception checks are performed.\r\n\r\nIf you disable this policy, DNS interception checks aren’t performed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_dnsinterceptionchecksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cd8c9d5e499c19df":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"cdacc40500da7a62":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_0","displayName":"Off (Not recommended)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_1","displayName":"Required data","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_diagnosticdata_diagnosticdata_2","displayName":"Optional data","description":null,"helpText":null}]},"cdcfed24ede01ac1":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled","displayName":"Enable the User-Agent Client Hints feature (obsolete) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy is deprecated because it's only intended to be a short-term mechanism to give enterprises more time to update their web content if and when it's found to be incompatible with the User-Agent Client Hints feature. It won't work in Microsoft Edge version 89.\r\n\r\nWhen enabled the User-Agent Client Hints feature sends granular request headers that provide information about the user browser (for example, the browser version) and environment (for example, the system architecture).\r\n\r\nThis is an additive feature, but the new headers may break some websites that restrict the characters that requests may contain.\r\n\r\nIf you enable or don't configure this policy, the User-Agent Client Hints feature is enabled. If you disable this policy, this feature is unavailable.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_useragentclienthintsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cd213bb53e16f060":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed","displayName":"Configures availability of a vertical layout for tabs on the side of the browser (User)","description":"Configures whether a user can access an alternative layout where tabs are vertically aligned on the side of the browser instead of at the top.\r\nWhen there are several tabs open, this layout provides better tab viewing and management. There's better visibility of the site titles,\r\nit's easier to scan aligned icons, and there's more space to manage and close tabs.\r\n\r\nIf you disable this policy, then the vertical tab layout will not be available as an option for users.\r\n\r\nIf you enable or don't configure this policy, the tab layout will still be at the top, but a user has the option to turn on vertical tabs on the side.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_verticaltabsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"cd698cb02853e161":{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting","displayName":"Configures a setting that asks users to enter their device password while using password autofill (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_0","displayName":"Automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_1","displayName":"With device password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_2","displayName":"With custom primary password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93.1~policy~microsoft_edge~passwordmanager_primarypasswordsetting_primarypasswordsetting_3","displayName":"Autofill off","description":null,"helpText":null}]},"cd28cb35c4fec307":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing","displayName":"Activate Restricted Browsing (User)","description":"When Restricted Browsing is activated the save as dialog box will be restricted such that the user will only be able to navigate to those locations and the children of those locations specified in the \"Restricted Browsing\\Approve Locations\" policy setting. If you want to enable the \"Approve Locations\" policy setting, you must first enable the \"Approve Locations\" policy setting first.","helpText":"","infoUrls":[],"categoryId":"8b7e662c-0410-4e33-ae11-edb7c717d914","categoryName":"Restricted Browsing","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_restrictedbrowsing_l_activaterestrictedbrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},"cde102480fc93ac3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips","displayName":"Show shortcut keys in ScreenTips (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_showshortcutkeysinscreentips_1","displayName":"Enabled","description":null,"helpText":null}]},"cdcc0da00b2d480a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowdescrip445","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"cd6173c546a6b14c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06","displayName":"Escrow Key #6 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey06_1","displayName":"Enabled","description":null,"helpText":null}]},"cdbd7025ce1dd824":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc10_l_allowsubfolders10_1","displayName":"True","description":null,"helpText":null}]},"cd0e64f184a7adfa":{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart","displayName":"Block OrgChart (User)","description":"This policy setting allows you to control whether Organization Chart (OrgChart) Add-in for Microsoft Office programs runs in Microsoft 365 apps.\r\n\r\nIf you enable this policy setting, OrgChart will not run in any Microsoft 365 app. Instead, a static image will render in its place.\r\n\r\nIf you disable this policy setting, OrgChart will run in Microsoft 365 apps.\r\n\r\nIf you don't configure this policy setting, OrgChart will run in Microsoft 365 apps.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v23~policy~l_microsoftofficesystem~l_securitysettings_l_blockorgchart_1","displayName":"Enabled","description":null,"helpText":null}]},"cdcbe1abfd2d4fd1":{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_0","displayName":"Display automatically when MailTips apply","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_1","displayName":"Display at all times","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v15~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_mailtipsbardisplayoption_l_mailtipsbardisplayoptions_2","displayName":"Never display MailTips","description":null,"helpText":null}]},"cda05e04b6a81f62":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_entersecondstowaittouploadchangestoserver_l_entersecondstowaitbeforeuploaddefault15sec","displayName":"Enter seconds to wait before upload(Default 15 sec.) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":null},"cd66e16ac3d49930":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions","displayName":"Do not roam users' RSS Feeds (User)","description":"This policy setting allows you to change the default delivery location of RSS Feeds to a local PST.\r\n\r\nIf you enable this setting, the default delivery location will be changed to a local PST. When RSS Feeds are delivered to a local PST, they will not roam from client to client and will only be available on the computer where the user originally subscribed to the RSS Feed.\r\n\r\nIf you disable or do not configure this policy setting, subscriptions to RSS Feeds are delivered to the user's mailbox and roam from client to client via Exchange. This setting does not affect RSS Feeds that were subscribed before the policy setting was enabled. This setting also does not prevent the user from manually directing an RSS Feed to deliver to the user's mailbox, which allows the RSS Feed to roam from client to client.","helpText":"","infoUrls":[],"categoryId":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","categoryName":"RSS Feeds","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_rsssubscriptions_l_disableroamingofrsssubscriptions_1","displayName":"Enabled","description":null,"helpText":null}]},"cdf05fa1ff5f532f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"cd7b549bbc9b0d7f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_datecolon37","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"cd1e8d46ca6c2751":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"cdbe00964676f013":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_cryptography_l_specifycngsaltlength_l_specifycngsaltlengthspinid","displayName":"Number of bytes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1671dfc3-a1dd-4178-9093-10fb6b62586a","categoryName":"Cryptography","options":null},"cd6aec662cb5097a":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc08_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"cdcdd0ded796b0de":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab","displayName":"Default tab to show in Publisher on the Office Start screen and in File | New (User)","description":"This policy setting controls what displays as the default tab in Publisher on the Office Start screen and in File | New. \r\n\r\nIf you enable this policy setting, you can choose one of two options to become the default tab on the Office Start screen and in File | New:\r\n\r\n* Built-in – Users will the see built-in templates tab as the default tab in Publisher on the Office Start screen and in File | New.\r\n\r\n* Custom – Users will the see custom templates tab as the default tab in Publisher on the Office Start screen and in File | New when templates exist (this can include Custom XML programmed templates, templates in the Workgroup templates path, templates in the Personal templates path, or SharePoint templates).\r\n\r\nIf you disable or do not configure this policy setting, users will see the Featured templates tab as the default tab in Publisher on the Office Start screen and in File | New","helpText":"","infoUrls":[],"categoryId":"c6c1120b-988c-4581-a21c-b9786a821242","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_miscellaneous_l_defaultbuiltintab_1","displayName":"Enabled","description":null,"helpText":null}]},"cd437741ee26ebcb":{"id":"user_vendor_msft_policy_config_start_configurestartpins","displayName":"Configure Start Pins (User)","description":"Allows admin to override the default items pinned to Start.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#configurestartpins"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":null},"cd608d514333a15f":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2_key","displayName":"Name","description":"","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":null},"cd21594ac622cae5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175","displayName":"Disable shortcut keys (User)","description":"This policy setting allows you to disable any shortcut key by using its virtual key code ID, including shortcut keys that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter a virtual key code ID number to disable a specific shortcut key.\r\n\r\nIf you disable or do not configure this policy setting, all default shortcut keys are enabled for users.","helpText":"","infoUrls":[],"categoryId":"0f42fc50-66c8-4b70-9904-64f8d662c930","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys175_1","displayName":"Enabled","description":null,"helpText":null}]},"cd06d020eb19ed08":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu","displayName":"Match hyu/iyu, byu/vyu (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchhyuiyubyuvyu_1","displayName":"Enabled","description":null,"helpText":null}]},"cd07d93597a967ec":{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt","displayName":"IPsec Exceptions","description":"This value configures IPsec exceptions and MUST be a combination of the valid flags that are defined in IPSEC_EXEMPT_VALUES; therefore, the maximum value MUST always be IPSEC_EXEMPT_MAX-1 for servers supporting a schema version of 0x0201 and IPSEC_EXEMPT_MAX_V2_0-1 for servers supporting a schema version of 0x0200. If the maximum value is exceeded when the method RRPC_FWSetGlobalConfig (Opnum 4) is called, the method returns ERROR_INVALID_PARAMETER. This error code is returned if no other preceding error is discovered. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, use the local store value.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_0","displayName":"FWGLOBALCONFIGIPSECEXEMPTNONE: No IPsec exemptions.","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_NONE: No IPsec exemptions.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_1","displayName":"Exempt neighbor discover IPv6 ICMP type-codes from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_NEIGHBOR_DISC: Exempt neighbor discover IPv6 ICMP type-codes from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_2","displayName":"Exempt ICMP from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_ICMP: Exempt ICMP from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_4","displayName":"Exempt router discover IPv6 ICMP type-codes from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_ROUTER_DISC: Exempt router discover IPv6 ICMP type-codes from IPsec.","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_ipsecexempt_8","displayName":"Exempt both IPv4 and IPv6 DHCP traffic from IPsec","description":"FW_GLOBAL_CONFIG_IPSEC_EXEMPT_DHCP: Exempt both IPv4 and IPv6 DHCP traffic from IPsec.","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/cf.json b/public/intune-definitions/cf.json index 55a4c6468edc..e8fbc55f0800 100644 --- a/public/intune-definitions/cf.json +++ b/public/intune-definitions/cf.json @@ -1 +1 @@ -{"cf769417e208f0dd":{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"13f62499-a266-42c8-a4dc-531efcea55cb","categoryName":"Microsoft Edge Dev","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_1","displayName":"Enabled","description":null,"helpText":null}]},"cfd7a64d57226835":{"id":"com.apple.directoryservice.managed_admapgidattributeflag","displayName":"AD Map GID Attribute Flag","description":"If true, enables the AD Map GID Attribute key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapgidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapgidattributeflag_true","displayName":"True","description":null,"helpText":null}]},"cf5317e09a39a075":{"id":"com.apple.dock_static-only","displayName":"Static Only","description":"If true, uses the Static Apps and Static Others dictionaries for the dock and ignores any items in the Persistent Apps and Persistent Others dictionaries. If false, the contents are merged with the static items listed first.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-only_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_static-only_true","displayName":"True","description":null,"helpText":null}]},"cf9049c69261a4a7":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app","displayName":"Microsoft PowerPoint","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"cf57ca665b56a987":{"id":"com.apple.managedclient.preferences_defaultsearchprovidersearchurl","displayName":"Default search provider search URL","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidersearchurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cf4318d0793df93f":{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\n\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\n\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\n\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\n\n * 'default' = Allow all interfaces. This exposes the local IP address.\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtclocalhostiphandling"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_0","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_1","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_2","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_3","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},"cfc5a5d3772a1315":{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl","displayName":"Account Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":[{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl_true","displayName":"True","description":null,"helpText":null}]},"cfbce7cea690d9d0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled","displayName":"Allow M365 authentication popups in work profiles","description":"This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles.\n\nWhen users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in.\n\nIf you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.\n\nIf you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"cf0dfe226ff30595":{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup","displayName":"Action to take on Microsoft Edge startup","description":"Specify how Microsoft Edge behaves when it starts.\n\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\n\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session is restored as it was. This option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\n\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\n\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\n\nDisabling this setting is the same as leaving it not configured. Users can change it in Microsoft Edge.\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\n\nPolicy options mapping:\n\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\n\n* RestoreOnStartupIsLastSession (1) = Restore the last session\n\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\n\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupisnewtabpage","displayName":"Open a new tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupislastsession","displayName":"Restore the last session","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupisurls","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupislastsessionandurls","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},"cfb3b7aae64a887d":{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock","displayName":"Dynamic Lock","description":"Enables/Disables Dyanamic Lock","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock_true","displayName":"Enabled","description":"Enabled","helpText":null}]},"cff6d25c6425901a":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_23","displayName":"11 PM","description":null,"helpText":null}]},"cf6b5924b5d6658b":{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2","displayName":"Specify a default color","description":"This policy setting controls the default color for window frames when the user does not specify a color. \r\n\r\nIf you enable this policy setting and specify a default color, this color is used in glass window frames, if the user does not specify a color. \r\n\r\nIf you disable or do not configure this policy setting, the default internal color is used, if the user does not specify a color. \r\n\r\nNote: This policy setting can be used in conjunction with the \"Prevent color changes of window frames\" setting, to enforce a specific color for window frames that cannot be changed by users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdefaultcolorizationcolor-2"],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":[{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_1","displayName":"Enabled","description":null,"helpText":null}]},"cff31e04b16b895e":{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl","displayName":"Set a support web page link","description":"Sets the target of the More Information link that will be displayed when the user attempts to run a program that is blocked by policy.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-admininfourl"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_1","displayName":"Enabled","description":null,"helpText":null}]},"cffb37067a483846":{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2_allowableuserlocaletaglist","displayName":"User Locales","description":null,"helpText":"","infoUrls":[],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":null},"cfe6a459e80569ca":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder","displayName":"Define the order of sources for downloading security intelligence updates","description":"This policy setting allows you to define the order in which different security intelligence update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources in order. Possible values are: “InternalDefinitionUpdateServer”, “MicrosoftUpdateServer”, “MMPC”, and “FileShares”\r\n\r\n For example: { InternalDefinitionUpdateServer | MicrosoftUpdateServer | MMPC }\r\n\r\n If you enable this setting, security intelligence update sources will be contacted in the order specified. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.\r\n\r\n If you disable or do not configure this setting, security intelligence update sources will be contacted in a default order.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-fallbackorder"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_1","displayName":"Enabled","description":null,"helpText":null}]},"cfb5344f5efe4295":{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy","displayName":"Microsoft Support Diagnostic Tool: Restrict tool download","description":"This policy setting restricts the tool download policy for Microsoft Support Diagnostic Tool.\r\n\r\nMicrosoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals. For some problems, MSDT may prompt the user to download additional tools for troubleshooting.\r\n\r\nThese tools are required to completely troubleshoot the problem. If tool download is restricted, it may not be possible to find the root cause of the problem.\r\n\r\nIf you enable this policy setting for remote troubleshooting, MSDT prompts the user to download additional tools to diagnose problems on remote computers only. If you enable this policy setting for local and remote troubleshooting, MSDT always prompts for additional tool downloading.\r\n\r\nIf you disable this policy setting, MSDT never downloads tools, and is unable to diagnose problems on remote computers.\r\n\r\nIf you do not configure this policy setting, MSDT prompts the user before downloading any additional tools.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\nThis policy setting will take effect only when MSDT is enabled.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-msdttooldownloadpolicy"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"cf2aaa08056c9312":{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall","displayName":"Prohibit removal of updates","description":"This policy setting controls the ability for users or administrators to remove Windows Installer based updates.\r\n\r\nThis policy setting should be used if you need to maintain a tight control over updates. One example is a lockdown environment where you want to ensure that updates once installed cannot be removed by users or administrators.\r\n\r\nIf you enable this policy setting, updates cannot be removed from the computer by a user or an administrator. The Windows Installer can still remove an update that is no longer applicable to the product.\r\n\r\nIf you disable or do not configure this policy setting, a user can remove an update from the computer only if the user has been granted privileges to remove the update. This can depend on whether the user is an administrator, whether \"Disable Windows Installer\" and \"Always install with elevated privileges\" policy settings are set, and whether the update was installed in a per-user managed, per-user unmanaged, or per-machine context.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disablepatchuninstall"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall_1","displayName":"Enabled","description":null,"helpText":null}]},"cfba66f95ce1ecd3":{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules","displayName":"Enforce upgrade component rules","description":"This policy setting causes the Windows Installer to enforce strict rules for component upgrades.\r\n\r\nIf you enable this policy setting, strict upgrade rules will be enforced by the Windows Installer which may cause some upgrades to fail. Upgrades can fail if they attempt to do one of the following:\r\n\r\n(1) Remove a component from a feature.\r\nThis can also occur if you change the GUID of a component. The component identified by the original GUID appears to be removed and the component as identified by the new GUID appears as a new component.\r\n\r\n(2) Add a new feature to the top or middle of an existing feature tree.\r\nThe new feature must be added as a new leaf feature to an existing feature tree.\r\n\r\nIf you disable or do not configure this policy setting, the Windows Installer will use less restrictive rules for component upgrades.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-enforceupgradecomponentrules"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules_1","displayName":"Enabled","description":null,"helpText":null}]},"cf82fa053f2c327d":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize","displayName":"Default cache size","description":"Limits the percentage of the computer's disk space that can be used to store automatically cached offline files.\r\n\r\nThis setting also disables the \"Amount of disk space to use for temporary offline files\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nAutomatic caching can be set on any network share. When a user opens a file on the share, the system automatically stores a copy of the file on the user's computer.\r\n\r\nThis setting does not limit the disk space available for files that user's make available offline manually.\r\n\r\nIf you enable this setting, you can specify an automatic-cache disk space limit.\r\n\r\nIf you disable this setting, the system limits the space that automatically cached files occupy to 10 percent of the space on the system drive.\r\n\r\nIf you do not configure this setting, disk space for automatically cached files is limited to 10 percent of the system drive by default, but users can change it.\r\n\r\nTip: To change the amount of disk space used for automatic caching without specifying a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then use the slider bar associated with the \"Amount of disk space to use for temporary offline files\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-defcachesize"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"cf122c8de8e2686b":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_lbl_onlinecachingsettingslist","displayName":"Enter network latency value in milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"cf0e22084481b7ba":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10","displayName":"Internet Explorer 10","description":"This policy setting configures the synchronization of user settings of Internet Explorer 10.\r\nBy default, the user settings of Internet Explorer 10 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 10 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 10 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 10 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer10"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_1","displayName":"Enabled","description":null,"helpText":null}]},"cf3f89b4cb5ea982":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended","displayName":"Block third party cookies","description":"Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting.\r\n\r\nLeaving it unset turns third-party cookies on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cfbcb6dc4cf9bf0e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls_imagesblockedforurlsdesc","displayName":"Block images on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"cf4e5090f921bfa3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled","displayName":"Enable Incognito mode","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cfbd83c502c6943a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist","displayName":"Allow access to a list of URLs","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},"cf147db5ef40da55":{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardataroaming","displayName":"Allow Cellular Data Roaming","description":"Allows or disallows cellular data roaming on the device. Device reboot is not required to enforce the policy. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-connectivity#allowcellulardataroaming"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardataroaming_0","displayName":"Do not allow cellular data roaming. The user cannot turn it on. This value is not supported in Windows 10, version 1511.","description":"Do not allow cellular data roaming. The user cannot turn it on. This value is not supported in Windows 10, version 1511.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardataroaming_1","displayName":"Allow cellular data roaming.","description":"Allow cellular data roaming.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardataroaming_2","displayName":"Allow cellular data roaming on. The user cannot turn it off.","description":"Allow cellular data roaming on. The user cannot turn it off.","helpText":null}]},"cf3cfeda363943a8":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockexecutablefilesrunningunlesstheymeetprevalenceagetrustedlistcriterion_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"cf73b4c93c5046ec":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses","displayName":"Block Office applications from injecting code into other processes","description":"This rule blocks code injection attempts from Office apps into other processes.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_warn","displayName":"Warn","description":null,"helpText":null}]},"cf2a72cd27eb9214":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware","displayName":"Use advanced protection against ransomware","description":"This rule provides an extra layer of protection against ransomware. It scans executable files entering the system to determine whether they're trustworthy. If the files closely resemble ransomware, this rule blocks them from running, unless they're in a trusted list or an exclusion list.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware_warn","displayName":"Warn","description":null,"helpText":null}]},"cf48192abf4a707f":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingprocessstart","displayName":"Process Start","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging of the Start Process component.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\ProcessStart\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingprocessstart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingprocessstart_1","displayName":"Enabled","description":null,"helpText":null}]},"cfa7dbcbc4b0fb85":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager","description":"This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager.\r\n\r\nIf the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect.\r\n\r\nIf this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.\r\n\r\nIf this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cf5b6fa5e64b373e":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download’s reputation regardless of source.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen doesn’t check the download’s reputation when downloading from a trusted source.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cf20ab18925ec085":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode","description":"This policy allows users to reload unconfigured sites (that are not configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge and a site requires Internet Explorer for compatibility.\r\n\r\nAfter a site has been reloaded in Internet Explorer mode, \"in-page\" navigations will stay in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge will automatically exit from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\r\n\r\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice will be remembered for a length of time managed by the 'InternetExplorerIntegrationLocalSiteListExpirationDays' (Specify the number of days that a site remains on the local IE mode site list) policy.\r\n\r\nIf the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy is set to 'IEMode', then sites explicitly configured by the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy's site list to use Microsoft Edge can't be reloaded in Internet Explorer mode, and sites configured by the site list or by the 'SendIntranetToInternetExplorer' (Send all intranet sites to Internet Explorer) policy to use Internet Explorer mode can't exit from Internet Explorer mode.\r\n\r\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nNote that if you enable this policy, it takes precedence over how you configured the 'InternetExplorerIntegrationTestingAllowed' (Allow Internet Explorer mode testing) policy, and that policy will be disabled.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"cfc349a90428174a":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_winprojexe118","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_winprojexe118_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_winprojexe118_1","displayName":"True","description":null,"helpText":null}]},"cf666967820b9f95":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_grooveexe28","displayName":"groove.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_grooveexe28_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_grooveexe28_1","displayName":"True","description":null,"helpText":null}]},"cf74c66fbf700edc":{"id":"device_vendor_msft_policy_config_remoteassistance_solicitedremoteassistance_ra_solicit_control_list","displayName":"Permit remote control of this computer:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_remoteassistance_solicitedremoteassistance_ra_solicit_control_list_1","displayName":"Allow helpers to remotely control the computer","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remoteassistance_solicitedremoteassistance_ra_solicit_control_list_0","displayName":"Allow helpers to only view the computer","description":null,"helpText":null}]},"cfdff2416072a89e":{"id":"device_vendor_msft_policy_config_remotemanagement_allowunencryptedtraffic_service","displayName":"Allow unencrypted traffic","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) service sends and receives unencrypted messages over the network.\n\nIf you enable this policy setting, the WinRM client sends and receives unencrypted messages over the network.\n\nIf you disable or do not configure this policy setting, the WinRM client sends or receives only encrypted messages over the network.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-allowunencryptedtraffic-service"],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_allowunencryptedtraffic_service_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_allowunencryptedtraffic_service_1","displayName":"Enabled","description":null,"helpText":null}]},"cf3483917b082c8c":{"id":"device_vendor_msft_policy_config_start_hideswitchaccount","displayName":"Hide Switch Account","description":"Enabling this policy hides \"Switch account\" from appearing in the user tile in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hideswitchaccount"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hideswitchaccount_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hideswitchaccount_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"cfa54dc57cb7a5d1":{"id":"device_vendor_msft_wifi_profile_{ssid}_proxywpad","displayName":"Connect to this network, even when its not broadcasting its SSID","description":"The presence of the field enables WPAD for proxy lookup.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/wifi-csp"],"categoryId":"c4e48b1b-6d88-434f-a717-d5bab28eb245","categoryName":"Wi-Fi Connection","options":null},"cf85c88bdb46b5c3":{"id":"sirisettings_sirisettings","displayName":"com.apple.configuration.siri.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b85d9c04-4923-4fdf-a425-424686d47859","categoryName":"Siri Settings","options":null},"cf7a7ffe7c633205":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas_certificatetransparencyenforcementdisabledforcasdesc","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"cf750589c6ee70a4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay","displayName":"Delay before launching alternative browser (milliseconds) (User)","description":"Setting the policy to a number has Google Chrome show a message for that number of milliseconds, then it opens an alternative browser.\r\n\r\nLeaving the policy unset or set to 0 means navigating to a designated URL immediately opens it in an alternative browser.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"cf37e0c7969d6755":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist","displayName":"Always render the following URL patterns in the host browser (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_1","displayName":"Enabled","description":null,"helpText":null}]},"cf0e0d6905517a9f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings. (User)","description":"Setting the policy to Enabled means Safe Browsing will trust the domains you designate. It won't check them for dangerous resources such as phishing, malware, or unwanted software. Safe Browsing's download protection service won't check downloads hosted on these domains. Its password protection service won't check for password reuse.\r\n\r\nLeaving the policy unset means default Safe Browsing protection applies to all resources.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"cfafb4a3e55e55b9":{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts","displayName":"Disable Office Scripts in Excel for Windows Desktop (User)","description":"This policy setting controls whether Office Scripts (including the relevant commands on the Automate tab) are available for use.\r\n\r\nIf you enable this policy setting, Office Scripts will not be available for use on the installed Excel app on a desktop.\r\n\r\nIf you disable or don't configure this policy setting, Office Scripts will be available for use provided all other prerequisites are met, including the applicable Microsoft 365 subscription license.\r\n\r\nNote: This policy setting is independent of Office Scripts settings available to administrators in the Microsoft 365 Admin Center. Admin Center settings are always honored by the Excel app regardless of the state of this policy; however, turning on this policy will also hide Office Scripts-related entry points.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts_1","displayName":"Enabled","description":null,"helpText":null}]},"cf4b2ec5e4c29141":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"cf5310d90c938c34":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},"cf63a3a780832c82":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},"cf539f14c465cd6f":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Microsoft Edge may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise JavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"cf96e507fb2e74cb":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled","displayName":"Configure Edge Scareware Blocker Protection (User)","description":"This policy setting allows administrators to control whether Microsoft Edge enables the Scareware Blocker, an AI-powered feature that provides warning messages to help protect users from potential tech scams.\r\n\r\nIf this policy is enabled, Edge Scareware Blocker will warn users of potential tech scams.\r\n\r\nIf this policy is disabled, Edge Scareware Blocker will not warn users of potential tech scams.\r\n\r\nIf this policy is not configured, Edge Scareware Blocker will not warn users of potential tech scams, but users can choose warnings in settings.\r\n\r\nBy configuring this policy, administrators determine whether users receive proactive scam warnings or must manually enable them.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cf54bef3627504b7":{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled","displayName":"Enable Silent Printing (User)","description":"This policy controls whether Microsoft Edge uses silent printing.\r\n\r\nIf you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder.\r\n\r\nIf you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cf0660124b6bd98d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceservercapabilities1","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"cf7dd9989fb1f970":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06","displayName":"Configure presentation service in PowerPoint and Word 7 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_1","displayName":"Enabled","description":null,"helpText":null}]},"cfbef0936417d307":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_l_emailadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"cf65dc77f17d1ea7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7","displayName":"Places Bar Location 7 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_1","displayName":"Enabled","description":null,"helpText":null}]},"cfc4baf7be25bee6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont","displayName":"List font names in their font (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont_1","displayName":"Enabled","description":null,"helpText":null}]},"cf3095e3ee54285a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication","displayName":"Open Office document directly in Office application (User)","description":"This policy setting allows you to choose whether Office documents located on web servers open directly in the registered application or through the web browser. \r\n\r\nIf you enable this policy setting, files will open directly in the associated Office application, bypassing the web browser.\r\n\r\nIf you disable this policy setting files will open through the web browser.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication_1","displayName":"Enabled","description":null,"helpText":null}]},"cfc061559cc497cc":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj","displayName":"Display OLE package objects (User)","description":"By default, OLE package objects are not displayed in e-mail messages. You can change this behavior so that the package appears in the body of the e-mail message as an icon that represents an embedded or linked OLE object. When users double-click the icon representing the package, the program used to create the object either plays the object or opens and displays it. Be aware that the icon for OLE package objects can be easily changed and used to disguise malicious files.\r\n\r\nTo set Exchange Security Form settings by using Group Policy, note that this policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj_1","displayName":"Enabled","description":null,"helpText":null}]},"cf2c57e5d96398ea":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist","displayName":"Number of entries in the Recent Drawings list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Drawings list that appears when users click Open on the File tab in Backstage view. \r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Drawings list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Drawings list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},"cfd0a24ae9f11e51":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"2764869c-54a3-462b-bc72-c580621ab6bb","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"cfc7b2a69c962b56":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar","displayName":"Left scroll bar (User)","description":"Checks/unchecks the corresponding UI option. This option is only available if support for right-to-left languages is enabled through Microsoft Office Language Preferences. This setting also sets Right ruler (Print view only).","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},"cf7e451314257a33":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages","displayName":"Check if Word is the default editor for all other Web pages (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"d804205d-6c12-4f40-86a0-aa5a5355370f","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages_1","displayName":"Enabled","description":null,"helpText":null}]},"cfac92ffe2cc86ce":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"cf26815f5e62e034":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},"cf3ff74a20ff8da5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart","displayName":"Document used for result of compare: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_0","displayName":"Original Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_1","displayName":"Revised Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_2","displayName":"New document","description":null,"helpText":null}]},"cfbd1cb6f091a7c6":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_icmptypesandcodes","displayName":"ICMP Types And Codes","description":"\n String value. Multiple ICMP type+code pairs can be included in the string by separating each value with a \",\". If more than one ICMP type+code pair is specified, the strings must be separated by a comma.\n To specify all ICMP types and codes, use the \"*\" character. For specific ICMP types and codes, use the \":\" to separate the type and code.\n The following are valid examples: 3:4 or 1:*. The \"*\" character can be used to represent any code. The \"*\" character can't be used to specify any type, examples such as \"*:4\" or \"*:*\" are invalid.\n When setting this field in a firewall rule, the protocol field must also be set, to either 1 (ICMP) or 58 (IPv6-ICMP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file +{"cf769417e208f0dd":{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"13f62499-a266-42c8-a4dc-531efcea55cb","categoryName":"Microsoft Edge Dev","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgedev_pol_targetversionprefixmicrosoftedgedev_1","displayName":"Enabled","description":null,"helpText":null}]},"cfd7a64d57226835":{"id":"com.apple.directoryservice.managed_admapgidattributeflag","displayName":"AD Map GID Attribute Flag","description":"If true, enables the AD Map GID Attribute key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapgidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapgidattributeflag_true","displayName":"True","description":null,"helpText":null}]},"cf5317e09a39a075":{"id":"com.apple.dock_static-only","displayName":"Static Only","description":"If true, uses the Static Apps and Static Others dictionaries for the dock and ignores any items in the Persistent Apps and Persistent Others dictionaries. If false, the contents are merged with the static items listed first.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_static-only_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_static-only_true","displayName":"True","description":null,"helpText":null}]},"cf9049c69261a4a7":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft powerpoint.app","displayName":"Microsoft PowerPoint","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"cf57ca665b56a987":{"id":"com.apple.managedclient.preferences_defaultsearchprovidersearchurl","displayName":"Default search provider search URL","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidersearchurl"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"cf4318d0793df93f":{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling","displayName":"Restrict exposure of local IP address by WebRTC","description":"Allows you to set whether or not WebRTC exposes the user's local IP address.\n\nIf you set this policy to \"AllowAllInterfaces\" ('default') or \"AllowPublicAndPrivateInterfaces\" ('default_public_and_private_interfaces'), WebRTC exposes the local IP address.\n\nIf you set this policy to \"AllowPublicInterfaceOnly\" ('default_public_interface_only') or \"DisableNonProxiedUdp\" ('disable_non_proxied_udp'), WebRTC doesn't expose the local IP address.\n\nIf you don't set this policy, or if you disable it, WebRTC exposes the local IP address.\n\n * 'default' = Allow all interfaces. This exposes the local IP address.\n * 'default_public_and_private_interfaces' = Allow public and private interfaces over http default route. This exposes the local IP address.\n * 'default_public_interface_only' = Allow public interface over http default route. This doesn't expose the local IP address.\n * 'disable_non_proxied_udp' = Use TCP unless proxy server supports UDP. This doesn't expose the local IP address.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webrtclocalhostiphandling"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_0","displayName":"Allow all interfaces. This exposes the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_1","displayName":"Allow public and private interfaces over http default route. This exposes the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_2","displayName":"Allow public interface over http default route. This doesn't expose the local IP address","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webrtclocalhostiphandling_3","displayName":"Use TCP unless proxy server supports UDP. This doesn't expose the local IP address","description":null,"helpText":null}]},"cfc5a5d3772a1315":{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl","displayName":"Account Use SSL","description":"If true, enables SSL.","helpText":null,"infoUrls":[],"categoryId":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","categoryName":"Subscribed Calendars","options":[{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.subscribedcalendar.account_subcalaccountusessl_true","displayName":"True","description":null,"helpText":null}]},"cfbce7cea690d9d0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled","displayName":"Allow M365 authentication popups in work profiles","description":"This policy controls whether Microsoft Edge allows Microsoft 365 authentication pop-ups to bypass the pop-up blocker in work profiles.\n\nWhen users are signed in with a work account, some Microsoft 365 sites (for example, microsoft.com, cloud.microsoft, and visualstudio.com) may open authentication pop-ups to login.microsoftonline.com, login.live.com, or login.microsoft.com. These pop-ups are required to complete sign-in.\n\nIf you enable this policy or don't configure it, Microsoft 365 authentication pop-ups are allowed in work profiles.\n\nIf you disable this policy, Microsoft 365 authentication pop-ups follow the default settings like other pop-ups.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.m365authpopupsinworkenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"cf0dfe226ff30595":{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup","displayName":"Action to take on Microsoft Edge startup","description":"Specify how Microsoft Edge behaves when it starts.\n\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\n\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session is restored as it was. This option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\n\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\n\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\n\nDisabling this setting is the same as leaving it not configured. Users can change it in Microsoft Edge.\n\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\n\nPolicy options mapping:\n\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\n\n* RestoreOnStartupIsLastSession (1) = Restore the last session\n\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\n\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupisnewtabpage","displayName":"Open a new tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupislastsession","displayName":"Restore the last session","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupisurls","displayName":"Open a list of URLs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.restoreonstartup_restoreonstartupislastsessionandurls","displayName":"Open a list of URLs and restore the last session","description":null,"helpText":null}]},"cf65773f9619e4de":{"id":"contentcaching_datapath","displayName":"Data Path","description":"The path to the directory used to store cached content. Changing this setting manually doesn't automatically move cached content from the old location to the new one. To move content automatically, use the Sharing preference's Content Caching pane. The value must be (or end with) `/Library/Application Support/Apple/AssetCache/Data`.\n\nThe system creates a directory and its intermediates for the given data path if it doesn't already exist. The directory is owned by `_assetcache:_assetcache` and has mode 0750. Its immediate parent directory (`.../Library/Application Support/Apple/AssetCache`) is owned by `_assetcache:_assetcache` and has mode `0755`.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"cfb3b7aae64a887d":{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock","displayName":"Dynamic Lock","description":"Enables/Disables Dyanamic Lock","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":[{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock_false","displayName":"Disabled","description":"Disabled","helpText":null},{"id":"device_vendor_msft_passportforwork_dynamiclock_dynamiclock_true","displayName":"Enabled","description":"Enabled","helpText":null}]},"cff6d25c6425901a":{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom","displayName":"From","description":null,"helpText":"","infoUrls":[],"categoryId":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","categoryName":"Background Intelligent Transfer Service BITS","options":[{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_0","displayName":"12 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_1","displayName":"1 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_2","displayName":"2 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_3","displayName":"3 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_4","displayName":"4 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_5","displayName":"5 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_6","displayName":"6 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_7","displayName":"7 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_8","displayName":"8 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_9","displayName":"9 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_10","displayName":"10 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_11","displayName":"11 AM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_12","displayName":"12 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_13","displayName":"1 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_14","displayName":"2 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_15","displayName":"3 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_16","displayName":"4 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_17","displayName":"5 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_18","displayName":"6 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_19","displayName":"7 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_20","displayName":"8 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_21","displayName":"9 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_22","displayName":"10 PM","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_bits_bits_maxbandwidthv2_work_bits_workhoursfrom_23","displayName":"11 PM","description":null,"helpText":null}]},"cf6b5924b5d6658b":{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2","displayName":"Specify a default color","description":"This policy setting controls the default color for window frames when the user does not specify a color. \r\n\r\nIf you enable this policy setting and specify a default color, this color is used in glass window frames, if the user does not specify a color. \r\n\r\nIf you disable or do not configure this policy setting, the default internal color is used, if the user does not specify a color. \r\n\r\nNote: This policy setting can be used in conjunction with the \"Prevent color changes of window frames\" setting, to enforce a specific color for window frames that cannot be changed by users.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dwm#admx-dwm-dwmdefaultcolorizationcolor-2"],"categoryId":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","categoryName":"Window Frame Coloring","options":[{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dwm_dwmdefaultcolorizationcolor_2_1","displayName":"Enabled","description":null,"helpText":null}]},"cff31e04b16b895e":{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl","displayName":"Set a support web page link","description":"Sets the target of the More Information link that will be displayed when the user attempts to run a program that is blocked by policy.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-explorer#admx-explorer-admininfourl"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_explorer_admininfourl_1","displayName":"Enabled","description":null,"helpText":null}]},"cffb37067a483846":{"id":"device_vendor_msft_policy_config_admx_globalization_localeuserrestrict_2_allowableuserlocaletaglist","displayName":"User Locales","description":null,"helpText":"","infoUrls":[],"categoryId":"edd1e620-09e1-47ea-abc8-1e241a174ed9","categoryName":"Locale Services","options":null},"cfe6a459e80569ca":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder","displayName":"Define the order of sources for downloading security intelligence updates","description":"This policy setting allows you to define the order in which different security intelligence update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the security intelligence update sources in order. Possible values are: “InternalDefinitionUpdateServer”, “MicrosoftUpdateServer”, “MMPC”, and “FileShares”\r\n\r\n For example: { InternalDefinitionUpdateServer | MicrosoftUpdateServer | MMPC }\r\n\r\n If you enable this setting, security intelligence update sources will be contacted in the order specified. Once security intelligence updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted.\r\n\r\n If you disable or do not configure this setting, security intelligence update sources will be contacted in a default order.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-signatureupdate-fallbackorder"],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_fallbackorder_1","displayName":"Enabled","description":null,"helpText":null}]},"cfb5344f5efe4295":{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy","displayName":"Microsoft Support Diagnostic Tool: Restrict tool download","description":"This policy setting restricts the tool download policy for Microsoft Support Diagnostic Tool.\r\n\r\nMicrosoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals. For some problems, MSDT may prompt the user to download additional tools for troubleshooting.\r\n\r\nThese tools are required to completely troubleshoot the problem. If tool download is restricted, it may not be possible to find the root cause of the problem.\r\n\r\nIf you enable this policy setting for remote troubleshooting, MSDT prompts the user to download additional tools to diagnose problems on remote computers only. If you enable this policy setting for local and remote troubleshooting, MSDT always prompts for additional tool downloading.\r\n\r\nIf you disable this policy setting, MSDT never downloads tools, and is unable to diagnose problems on remote computers.\r\n\r\nIf you do not configure this policy setting, MSDT prompts the user before downloading any additional tools.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\nThis policy setting will take effect only when MSDT is enabled.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios are not executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-msdttooldownloadpolicy"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_msdttooldownloadpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"cf2aaa08056c9312":{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall","displayName":"Prohibit removal of updates","description":"This policy setting controls the ability for users or administrators to remove Windows Installer based updates.\r\n\r\nThis policy setting should be used if you need to maintain a tight control over updates. One example is a lockdown environment where you want to ensure that updates once installed cannot be removed by users or administrators.\r\n\r\nIf you enable this policy setting, updates cannot be removed from the computer by a user or an administrator. The Windows Installer can still remove an update that is no longer applicable to the product.\r\n\r\nIf you disable or do not configure this policy setting, a user can remove an update from the computer only if the user has been granted privileges to remove the update. This can depend on whether the user is an administrator, whether \"Disable Windows Installer\" and \"Always install with elevated privileges\" policy settings are set, and whether the update was installed in a per-user managed, per-user unmanaged, or per-machine context.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-disablepatchuninstall"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_disablepatchuninstall_1","displayName":"Enabled","description":null,"helpText":null}]},"cfba66f95ce1ecd3":{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules","displayName":"Enforce upgrade component rules","description":"This policy setting causes the Windows Installer to enforce strict rules for component upgrades.\r\n\r\nIf you enable this policy setting, strict upgrade rules will be enforced by the Windows Installer which may cause some upgrades to fail. Upgrades can fail if they attempt to do one of the following:\r\n\r\n(1) Remove a component from a feature.\r\nThis can also occur if you change the GUID of a component. The component identified by the original GUID appears to be removed and the component as identified by the new GUID appears as a new component.\r\n\r\n(2) Add a new feature to the top or middle of an existing feature tree.\r\nThe new feature must be added as a new leaf feature to an existing feature tree.\r\n\r\nIf you disable or do not configure this policy setting, the Windows Installer will use less restrictive rules for component upgrades.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msi#admx-msi-msi-enforceupgradecomponentrules"],"categoryId":"156f2e6a-6638-4749-9f43-e7acc4aba762","categoryName":"Windows Installer","options":[{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msi_msi_enforceupgradecomponentrules_1","displayName":"Enabled","description":null,"helpText":null}]},"cf82fa053f2c327d":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize","displayName":"Default cache size","description":"Limits the percentage of the computer's disk space that can be used to store automatically cached offline files.\r\n\r\nThis setting also disables the \"Amount of disk space to use for temporary offline files\" option on the Offline Files tab. This prevents users from trying to change the option while a setting controls it.\r\n\r\nAutomatic caching can be set on any network share. When a user opens a file on the share, the system automatically stores a copy of the file on the user's computer.\r\n\r\nThis setting does not limit the disk space available for files that user's make available offline manually.\r\n\r\nIf you enable this setting, you can specify an automatic-cache disk space limit.\r\n\r\nIf you disable this setting, the system limits the space that automatically cached files occupy to 10 percent of the space on the system drive.\r\n\r\nIf you do not configure this setting, disk space for automatically cached files is limited to 10 percent of the system drive by default, but users can change it.\r\n\r\nTip: To change the amount of disk space used for automatic caching without specifying a setting, in Windows Explorer, on the Tools menu, click Folder Options, click the Offline Files tab, and then use the slider bar associated with the \"Amount of disk space to use for temporary offline files\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-defcachesize"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_defcachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"cf122c8de8e2686b":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_lbl_onlinecachingsettingslist","displayName":"Enter network latency value in milliseconds","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"cf0e22084481b7ba":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10","displayName":"Internet Explorer 10","description":"This policy setting configures the synchronization of user settings of Internet Explorer 10.\r\nBy default, the user settings of Internet Explorer 10 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 10 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 10 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 10 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer10"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_1","displayName":"Enabled","description":null,"helpText":null}]},"cf3f89b4cb5ea982":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended","displayName":"Block third party cookies","description":"Setting the policy to Enabled prevents webpage elements that aren't from the domain that's in the browser's address bar from setting cookies. Setting the policy to Disabled lets those elements set cookies and prevents users from changing this setting.\r\n\r\nLeaving it unset turns third-party cookies on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_blockthirdpartycookies_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cfbcb6dc4cf9bf0e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_imagesblockedforurls_imagesblockedforurlsdesc","displayName":"Block images on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"cf4e5090f921bfa3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled","displayName":"Enable Incognito mode","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_incognitoenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cfbd83c502c6943a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist","displayName":"Allow access to a list of URLs","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nexample.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_urlwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},"cf147db5ef40da55":{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardataroaming","displayName":"Allow Cellular Data Roaming","description":"Allows or disallows cellular data roaming on the device. Device reboot is not required to enforce the policy. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-connectivity#allowcellulardataroaming"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardataroaming_0","displayName":"Do not allow cellular data roaming. The user cannot turn it on. This value is not supported in Windows 10, version 1511.","description":"Do not allow cellular data roaming. The user cannot turn it on. This value is not supported in Windows 10, version 1511.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardataroaming_1","displayName":"Allow cellular data roaming.","description":"Allow cellular data roaming.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardataroaming_2","displayName":"Allow cellular data roaming on. The user cannot turn it off.","description":"Allow cellular data roaming on. The user cannot turn it off.","helpText":null}]},"cf3cfeda363943a8":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockexecutablefilesrunningunlesstheymeetprevalenceagetrustedlistcriterion_perruleexclusions","displayName":"ASR Only Per Rule Exclusions","description":"Apply ASR only per rule exclusions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"cf73b4c93c5046ec":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses","displayName":"Block Office applications from injecting code into other processes","description":"This rule blocks code injection attempts from Office apps into other processes.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockofficeapplicationsfrominjectingcodeintootherprocesses_warn","displayName":"Warn","description":null,"helpText":null}]},"cf2a72cd27eb9214":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware","displayName":"Use advanced protection against ransomware","description":"This rule provides an extra layer of protection against ransomware. It scans executable files entering the system to determine whether they're trustworthy. If the files closely resemble ransomware, this rule blocks them from running, unless they're in a trusted list or an exclusion list.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_useadvancedprotectionagainstransomware_warn","displayName":"Warn","description":null,"helpText":null}]},"cf48192abf4a707f":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingprocessstart","displayName":"Process Start","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging of the Start Process component.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\ProcessStart\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingprocessstart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingprocessstart_1","displayName":"Enabled","description":null,"helpText":null}]},"cfa7dbcbc4b0fb85":{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager","description":"This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager.\r\n\r\nIf the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect.\r\n\r\nIf this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.\r\n\r\nIf this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cf5b6fa5e64b373e":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended","displayName":"Force Microsoft Defender SmartScreen checks on downloads from trusted sources","description":"This policy setting lets you configure whether Microsoft Defender SmartScreen checks download reputation from a trusted source.\r\n\r\nIf you enable or don't configure this setting, Microsoft Defender SmartScreen checks the download’s reputation regardless of source.\r\n\r\nIf you disable this setting, Microsoft Defender SmartScreen doesn’t check the download’s reputation when downloading from a trusted source.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenfortrusteddownloadsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"cf20ab18925ec085":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed","displayName":"Allow unconfigured sites to be reloaded in Internet Explorer mode","description":"This policy allows users to reload unconfigured sites (that are not configured in the Enterprise Mode Site List) in Internet Explorer mode when browsing in Microsoft Edge and a site requires Internet Explorer for compatibility.\r\n\r\nAfter a site has been reloaded in Internet Explorer mode, \"in-page\" navigations will stay in Internet Explorer mode (for example, a link, script, or form on the page, or a server-side redirect from another \"in-page\" navigation). Users can choose to exit from Internet Explorer mode, or Microsoft Edge will automatically exit from Internet Explorer mode when a navigation that isn't \"in-page\" occurs (for example, using the address bar, the back button, or a favorite link).\r\n\r\nUsers can also optionally tell Microsoft Edge to use Internet Explorer mode for the site in the future. This choice will be remembered for a length of time managed by the 'InternetExplorerIntegrationLocalSiteListExpirationDays' (Specify the number of days that a site remains on the local IE mode site list) policy.\r\n\r\nIf the 'InternetExplorerIntegrationLevel' (Configure Internet Explorer integration) policy is set to 'IEMode', then sites explicitly configured by the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) policy's site list to use Microsoft Edge can't be reloaded in Internet Explorer mode, and sites configured by the site list or by the 'SendIntranetToInternetExplorer' (Send all intranet sites to Internet Explorer) policy to use Internet Explorer mode can't exit from Internet Explorer mode.\r\n\r\nIf you enable this policy, users are allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nIf you disable this policy, users aren't allowed to reload unconfigured sites in Internet Explorer mode.\r\n\r\nNote that if you enable this policy, it takes precedence over how you configured the 'InternetExplorerIntegrationTestingAllowed' (Allow Internet Explorer mode testing) policy, and that policy will be disabled.\r\n\r\nTo learn more about Internet Explorer mode, see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_internetexplorerintegrationreloadiniemodeallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"cfc349a90428174a":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_winprojexe118","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_winprojexe118_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_winprojexe118_1","displayName":"True","description":null,"helpText":null}]},"cf666967820b9f95":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_grooveexe28","displayName":"groove.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_grooveexe28_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_grooveexe28_1","displayName":"True","description":null,"helpText":null}]},"cf74c66fbf700edc":{"id":"device_vendor_msft_policy_config_remoteassistance_solicitedremoteassistance_ra_solicit_control_list","displayName":"Permit remote control of this computer:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":[{"id":"device_vendor_msft_policy_config_remoteassistance_solicitedremoteassistance_ra_solicit_control_list_1","displayName":"Allow helpers to remotely control the computer","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remoteassistance_solicitedremoteassistance_ra_solicit_control_list_0","displayName":"Allow helpers to only view the computer","description":null,"helpText":null}]},"cfdff2416072a89e":{"id":"device_vendor_msft_policy_config_remotemanagement_allowunencryptedtraffic_service","displayName":"Allow unencrypted traffic","description":"This policy setting allows you to manage whether the Windows Remote Management (WinRM) service sends and receives unencrypted messages over the network.\n\nIf you enable this policy setting, the WinRM client sends and receives unencrypted messages over the network.\n\nIf you disable or do not configure this policy setting, the WinRM client sends or receives only encrypted messages over the network.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-allowunencryptedtraffic-service"],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_allowunencryptedtraffic_service_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_allowunencryptedtraffic_service_1","displayName":"Enabled","description":null,"helpText":null}]},"cf3483917b082c8c":{"id":"device_vendor_msft_policy_config_start_hideswitchaccount","displayName":"Hide Switch Account","description":"Enabling this policy hides \"Switch account\" from appearing in the user tile in the start menu.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#hideswitchaccount"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_hideswitchaccount_0","displayName":"Disabled","description":"Do not hide.","helpText":null},{"id":"device_vendor_msft_policy_config_start_hideswitchaccount_1","displayName":"Enabled","description":"Hide.","helpText":null}]},"cfa54dc57cb7a5d1":{"id":"device_vendor_msft_wifi_profile_{ssid}_proxywpad","displayName":"Connect to this network, even when its not broadcasting its SSID","description":"The presence of the field enables WPAD for proxy lookup.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/wifi-csp"],"categoryId":"c4e48b1b-6d88-434f-a717-d5bab28eb245","categoryName":"Wi-Fi Connection","options":null},"cf85c88bdb46b5c3":{"id":"sirisettings_sirisettings","displayName":"com.apple.configuration.siri.settings","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"b85d9c04-4923-4fdf-a425-424686d47859","categoryName":"Siri Settings","options":null},"cf7a7ffe7c633205":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforcas_certificatetransparencyenforcementdisabledforcasdesc","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"cf750589c6ee70a4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay","displayName":"Delay before launching alternative browser (milliseconds) (User)","description":"Setting the policy to a number has Google Chrome show a message for that number of milliseconds, then it opens an alternative browser.\r\n\r\nLeaving the policy unset or set to 0 means navigating to a designated URL immediately opens it in an alternative browser.","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherdelay_1","displayName":"Enabled","description":null,"helpText":null}]},"cf37e0c7969d6755":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist","displayName":"Always render the following URL patterns in the host browser (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_1","displayName":"Enabled","description":null,"helpText":null}]},"cf0e0d6905517a9f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains","displayName":"Configure the list of domains on which Safe Browsing will not trigger warnings. (User)","description":"Setting the policy to Enabled means Safe Browsing will trust the domains you designate. It won't check them for dangerous resources such as phishing, malware, or unwanted software. Safe Browsing's download protection service won't check downloads hosted on these domains. Its password protection service won't check for password reuse.\r\n\r\nLeaving the policy unset means default Safe Browsing protection applies to all resources.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~safebrowsing_safebrowsingallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"cfafb4a3e55e55b9":{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts","displayName":"Disable Office Scripts in Excel for Windows Desktop (User)","description":"This policy setting controls whether Office Scripts (including the relevant commands on the Automate tab) are available for use.\r\n\r\nIf you enable this policy setting, Office Scripts will not be available for use on the installed Excel app on a desktop.\r\n\r\nIf you disable or don't configure this policy setting, Office Scripts will be available for use provided all other prerequisites are met, including the applicable Microsoft 365 subscription license.\r\n\r\nNote: This policy setting is independent of Office Scripts settings available to administrators in the Microsoft 365 Admin Center. Admin Center settings are always honored by the Excel app regardless of the state of this policy; however, turning on this policy will also hide Office Scripts-related entry points.","helpText":"","infoUrls":[],"categoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v7~policy~l_microsoftofficeexcel~l_miscellaneous168_l_exceldisableofficescripts_1","displayName":"Enabled","description":null,"helpText":null}]},"cf4b2ec5e4c29141":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneinitializeandscriptactivexcontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"cf5310d90c938c34":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},"cf63a3a780832c82":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin","displayName":"Minimum SSL version enabled (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1","displayName":"TLS 1.0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1.1","displayName":"TLS 1.1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_sslversionmin_tls1.2","displayName":"TLS 1.2","description":null,"helpText":null}]},"cf539f14c465cd6f":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites","displayName":"Block JavaScript optimizations on these sites (User)","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are disabled.\r\n\r\nDisabling JavaScript optimizations will mean that Microsoft Edge may render web content more slowly.\r\n\r\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the 'JavaScriptOptimizerBlockedForSites' (Block JavaScript optimizations on these sites) policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations disabled, but fabrikam.com will use the policy from 'DefaultJavaScriptOptimizerSetting' (Control use of JavaScript optimizers), if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptOptimizerSetting' applies to the site, if set, otherwise JavaScript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~contentsettings_javascriptoptimizerblockedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"cf96e507fb2e74cb":{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled","displayName":"Configure Edge Scareware Blocker Protection (User)","description":"This policy setting allows administrators to control whether Microsoft Edge enables the Scareware Blocker, an AI-powered feature that provides warning messages to help protect users from potential tech scams.\r\n\r\nIf this policy is enabled, Edge Scareware Blocker will warn users of potential tech scams.\r\n\r\nIf this policy is disabled, Edge Scareware Blocker will not warn users of potential tech scams.\r\n\r\nIf this policy is not configured, Edge Scareware Blocker will not warn users of potential tech scams, but users can choose warnings in settings.\r\n\r\nBy configuring this policy, administrators determine whether users receive proactive scam warnings or must manually enable them.","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev134~policy~microsoft_edge~scarewareblocker_scarewareblockerprotectionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cf54bef3627504b7":{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled","displayName":"Enable Silent Printing (User)","description":"This policy controls whether Microsoft Edge uses silent printing.\r\n\r\nIf you enable this policy, Edge automatically closes the print preview window and prints to the default printer using its default settings. If the default printer is Save as PDF, the file is saved to the user's Downloads folder.\r\n\r\nIf you disable or don't configure this policy, silent printing is disabled. The print preview window stays open and the user must choose print settings as usual.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev144~policy~microsoft_edge_silentprintingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"cf0660124b6bd98d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastserviceservercapabilities1","displayName":"Server Capabilities flags: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"cf7dd9989fb1f970":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06","displayName":"Configure presentation service in PowerPoint and Word 7 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice06_1","displayName":"Enabled","description":null,"helpText":null}]},"cfbef0936417d307":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceemail_l_emailadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"cf65dc77f17d1ea7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7","displayName":"Places Bar Location 7 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy7_1","displayName":"Enabled","description":null,"helpText":null}]},"cfc4baf7be25bee6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont","displayName":"List font names in their font (User)","description":"Checks/Unchecks the corresponding UI option. This option only applies to CommandBars UI.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_listfontnamesintheirfont_1","displayName":"Enabled","description":null,"helpText":null}]},"cf3095e3ee54285a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication","displayName":"Open Office document directly in Office application (User)","description":"This policy setting allows you to choose whether Office documents located on web servers open directly in the registered application or through the web browser. \r\n\r\nIf you enable this policy setting, files will open directly in the associated Office application, bypassing the web browser.\r\n\r\nIf you disable this policy setting files will open through the web browser.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentdirectlyinofficeapplication_1","displayName":"Enabled","description":null,"helpText":null}]},"cfc061559cc497cc":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj","displayName":"Display OLE package objects (User)","description":"By default, OLE package objects are not displayed in e-mail messages. You can change this behavior so that the package appears in the body of the e-mail message as an icon that represents an embedded or linked OLE object. When users double-click the icon representing the package, the program used to create the object either plays the object or opens and displays it. Be aware that the icon for OLE package objects can be easily changed and used to disguise malicious files.\r\n\r\nTo set Exchange Security Form settings by using Group Policy, note that this policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_showolepackageobj_1","displayName":"Enabled","description":null,"helpText":null}]},"cf2c57e5d96398ea":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist","displayName":"Number of entries in the Recent Drawings list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Drawings list that appears when users click Open on the File tab in Backstage view. \r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Drawings list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Drawings list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},"cfd0a24ae9f11e51":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"2764869c-54a3-462b-bc72-c580621ab6bb","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"cfc7b2a69c962b56":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar","displayName":"Left scroll bar (User)","description":"Checks/unchecks the corresponding UI option. This option is only available if support for right-to-left languages is enabled through Microsoft Office Language Preferences. This setting also sets Right ruler (Print view only).","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_leftscrollbar_1","displayName":"Enabled","description":null,"helpText":null}]},"cf7e451314257a33":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages","displayName":"Check if Word is the default editor for all other Web pages (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"d804205d-6c12-4f40-86a0-aa5a5355370f","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_weboptions~l_files_l_checkifwordisthedefaulteditorforallotherwebpages_1","displayName":"Enabled","description":null,"helpText":null}]},"cfac92ffe2cc86ce":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc05_l_descriptioncolon34","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"cf26815f5e62e034":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},"cf3ff74a20ff8da5":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart","displayName":"Document used for result of compare: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2f6205e9-8680-4b8f-97f3-be12e252e038","categoryName":"Track changes and compare","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_0","displayName":"Original Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_1","displayName":"Revised Document","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_trackchangesandcompare_l_compareresultingdocument_l_compareresultingdocumentpart_2","displayName":"New document","description":null,"helpText":null}]},"cfbd1cb6f091a7c6":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_icmptypesandcodes","displayName":"ICMP Types And Codes","description":"\n String value. Multiple ICMP type+code pairs can be included in the string by separating each value with a \",\". If more than one ICMP type+code pair is specified, the strings must be separated by a comma.\n To specify all ICMP types and codes, use the \"*\" character. For specific ICMP types and codes, use the \":\" to separate the type and code.\n The following are valid examples: 3:4 or 1:*. The \"*\" character can be used to represent any code. The \"*\" character can't be used to specify any type, examples such as \"*:4\" or \"*:*\" are invalid.\n When setting this field in a firewall rule, the protocol field must also be set, to either 1 (ICMP) or 58 (IPv6-ICMP).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/d4.json b/public/intune-definitions/d4.json index eeb290bf193a..aa1cce6c6018 100644 --- a/public/intune-definitions/d4.json +++ b/public/intune-definitions/d4.json @@ -1 +1 @@ -{"d422ab19b5f3a39e":{"id":"com.android.devicerestrictionpolicy.workprofilepasswordexpirationdays","displayName":"Number of days until password expires","description":"Enter the number of days, until the work profile password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. If the value is blank, Intune doesn't change or update this setting. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-365)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},"d41fcc76d3e46e8b":{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype","displayName":"Required password type","description":"Set the work profile password’s complexity requirements. Additional password requirements will become available based on your selection. Available for corporate-owned work profile devices (at work profile level). For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-fx#device-password:~:text=owned%20work%20profiles.-,Required%20password%20type%3A,-Enter%20the%20required"],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":[{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},"d4e33452d0a1f98d":{"id":"com.apple.cellularprivatenetwork.managed_csgnetworkidentifier","displayName":"Csg Network Identifier","description":"A string using the 3GPP \"CSG_ID\" format (defined in 3GPP 23.003, Section 4.7). The device uses this value to match a SIM present on the device.\n\nAll combinations of `NetworkIdentifier` and `CsgNetworkIdentifier` must be unique across all profiles installed on the device.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"d45920003a810a75":{"id":"com.apple.dock_dblclickbehavior-immutable","displayName":"Double Click Behavior Immutable","description":"If true, locks \"Double-click a window's title bar.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_dblclickbehavior-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior-immutable_true","displayName":"True","description":null,"helpText":null}]},"d41ba5f14c82cbd3":{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\n\nIf you enable or disable this policy, 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will be turned off.\n\nIf you don't configure this policy, users can control whether to use SSO using other credentials present on the machine in edge://settings/profiles/multiProfileSettings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#aadwebsitessousingthisprofileenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d4ecfaf7ad38d725":{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery","displayName":"Disable DIAL protocol for cast device discovery","description":"Enable this policy to disable the DIAL (Discovery And Launch) protocol for cast device discovery. (If EnableMediaRouter is disabled, this policy will have no effect).\n\nEnable this policy to disable DIAL protocol.\n\nBy default, Cast device discovery will use DIAL protocol.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgedisabledialprotocolforcastdiscovery"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery_true","displayName":"Enabled","description":null,"helpText":null}]},"d497b796354a9b55":{"id":"com.apple.managedclient.preferences_enableodignore","displayName":"Ignore named files","description":"This setting lets you enter keywords to prevent the OneDrive sync app from uploading certain files to OneDrive or SharePoint. You can enter complete names, such as setup.bin or use the asterisk (*) as a wildcard character to represent a series of characters, such as *.eml. Keywords aren't case-sensitive.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-only-corporate-mailboxes-to-be-added"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},"d4004f4579115f2c":{"id":"com.apple.managedclient.preferences_threattypesettings","displayName":"Threat type settings","description":"The threatTypeSettings preference in the antivirus engine is used to control how certain threat types are handled by the product.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#threat-type-settings"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"d497b66b4122bdb1":{"id":"com.apple.managedclient.preferences_webappinstallforcelist","displayName":"Web App Install Force List","description":"Specifies a list of websites that are installed silently, without user interaction, and which can't be uninstalled or disabled by the user.\n\nEach list item of the policy is an object with the following members:\n - \"url\", which is mandatory. \"url\" should be the URL of the web app to install.\n\nValues for the optional members are:\n - \"launch_container\" should be either \"window\" or \"tab\" to indicate how the Web App will be opened after it's installed.\n - \"create_desktop_shortcut\" should be true if a desktop shortcut should be created on Windows.\n\nIf \"default_launch_container\" is omitted, the app will open in a tab by default. Regardless of the value of \"default_launch_container\", users can change which container the app will open in. If \"create_desktop_shortcuts\" is omitted, no desktop shortcuts will be created.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webappinstallforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"d452bbd10349a068":{"id":"com.apple.systemconfiguration_proxies_ftppassive","displayName":"FTP Passive","description":"If true, enables passive FTP mode. ","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_ftppassive_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_ftppassive_1","displayName":"True","description":null,"helpText":null}]},"d4064101f74cd349":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding","displayName":"Turn off IDN encoding","description":"Specifies whether the DNS client should convert internationalized domain names (IDNs) to Punycode when the computer is on non-domain networks with no WINS servers configured.\r\n\r\nIf this policy setting is enabled, IDNs are not converted to Punycode.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, IDNs are converted to Punycode when the computer is on non-domain networks with no WINS servers configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-idnencoding"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding_1","displayName":"Enabled","description":null,"helpText":null}]},"d4858cfe7758e5f1":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable","displayName":"Turn on process scanning whenever real-time protection is enabled","description":"This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off.\r\n\r\n If you enable or do not configure this setting, a process scan will be initiated when real-time protection is turned on.\r\n\r\n If you disable this setting, a process scan will not be initiated when real-time protection is turned on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablescanonrealtimeenable"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable_1","displayName":"Enabled","description":null,"helpText":null}]},"d490207f73690800":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod_netlogon_backgroundretrymaximumperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"d40c73613c880cd1":{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_wsdprinters","displayName":"Number of Web Services Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"d46f3224942e19d5":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name","displayName":"Set Teredo Server Name","description":"This policy setting allows you to specify the name of the Teredo server. This server name will be used on the Teredo client computer where this policy setting is applied.\r\n\r\nIf you enable this policy setting, you can specify a Teredo server name that applies to a Teredo client.\r\n\r\nIf you disable or do not configure this policy setting, the local settings on the computer are used to determine the Teredo server name.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-server-name"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_1","displayName":"Enabled","description":null,"helpText":null}]},"d468d3d9773a47b7":{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2","displayName":"Turn off the offer to update to the latest version of Windows","description":"Enables or disables the Store offer to update to the latest version of Windows.\r\n\r\nIf you enable this setting, the Store application will not offer updates to the latest version of Windows.\r\n\r\nIf you disable or do not configure this setting the Store application will offer updates to the latest version of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-disableosupgrade-2"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2_1","displayName":"Enabled","description":null,"helpText":null}]},"d469490e837df0df":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_certificatetransparencyenforcementdisabledforlegacycasdesc","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"d416aa60be8580cf":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_browserswitcherchromeparametersdesc","displayName":"Command-line parameters for switching from the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"d4e47e4b05d046d2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printers of types placed on the deny list will be disabled from being discovered or having their capabilities fetched.\r\n\r\nPlacing all printer types on the deny list effectively disables printing, as there would be no available destinations to send a document for printing.\r\n\r\nIncluding cloud on the deny list has the same effect as setting the CloudPrintSubmitEnabled policy to false. In order to keep Google Cloud Print destinations discoverable, the CloudPrintSubmitEnabled policy must be set to true and cloud must not be on the deny list.\r\n\r\nIf the policy is not set, or is set to an empty list, all printer types will be available for discovery.\r\n\r\nExtension printers are also known as print provider destinations, and include any destination that belongs to a Google Chrome extension.\r\n\r\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\r\n\r\nExample value:\r\n\r\ncloud\r\nprivet","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},"d4f4cc54c8688c6f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings","displayName":"Default HTML renderer for Google Chrome Frame","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_1","displayName":"Enabled","description":null,"helpText":null}]},"d4e07c4433b6fe57":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation","displayName":"Configure the New Tab page URL","description":"Setting the policy configures the default New Tab page URL and prevents users from changing it.\r\n\r\nThe New Tab page opens with new tabs and windows.\r\n\r\nThis policy doesn't decide which pages open on start up. Those are controlled by the RestoreOnStartup policies. This policy does affect the homepage, if that's set to open the New Tab page, as well as the startup page if it's set to open the New Tab page.\r\n\r\nIt is a best practice to provide fully canonicalized URL, if the URL is not fully canonicalized Google Chrome will default to https://.\r\n\r\nLeaving the policy unset or empty puts the default New Tab page in use.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"d434704e64b2d818":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site url patterns that specify sites for which\r\nadvanced JavaScript optimizations are enabled.\r\n\r\nFor detailed information on valid site url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site\r\ngranularity (eTLD+1). A policy set for only subdomain.site.com will not\r\ncorrectly apply to site.com or subdomain.site.com since they both resolve to\r\nthe same eTLD+1 (site.com) for which there is no policy. In this case, policy\r\nmust be set on site.com to apply correctly for both site.com and\r\nsubdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level\r\norigin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript optimizations\r\nenabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript\r\noptimizations enabled. Blocklist entries have higher priority than allowlist\r\nentries, which in turn have higher priority than the configured default value.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise\r\nJavascript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"d4cfe35b9da20836":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_firstpartysetsoverrides","displayName":"Override First-Party Sets. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":null},"d432da3bac9a5a99":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_accesscodecastdeviceduration","displayName":"Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices.: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":null},"d43a35b3379eb54a":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcroamsearch_odfcroamsearch","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcroamsearch_odfcroamsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcroamsearch_odfcroamsearch_1","displayName":"Single-user Search","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcroamsearch_odfcroamsearch_2","displayName":"Multi-user Search","description":null,"helpText":null}]},"d4b24076adb9961f":{"id":"device_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit","displayName":"Allow deleting browsing history on exit","description":"This policy setting allows the automatic deletion of specified items when the last browser window closes. The preferences selected in the Delete Browsing History dialog box (such as deleting temporary Internet files, cookies, history, form data, and passwords) are applied, and those items are deleted.\n\nIf you enable this policy setting, deleting browsing history on exit is turned on.\n\nIf you disable this policy setting, deleting browsing history on exit is turned off.\n\nIf you do not configure this policy setting, it can be configured on the General tab in Internet Options.\n\nIf the \"Prevent access to Delete Browsing History\" policy setting is enabled, this policy setting has no effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowdeletingbrowsinghistoryonexit"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"d46dd6d785a11164":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions","displayName":"Logon options","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonelogonoptions"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"d42f974844ea9578":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_remotelyaccessibleregistrypaths","displayName":"Network Access Remotely Accessible Registry Paths","description":"Network access: Remotely accessible registry paths This security setting determines which registry keys can be accessed over the network, regardless of the users or groups listed in the access control list (ACL) of the winreg registry key. Default: System\\CurrentControlSet\\Control\\ProductOptions System\\CurrentControlSet\\Control\\Server Applications Software\\Microsoft\\Windows NT\\CurrentVersion Caution Incorrectly editing the registry may severely damage your system. Before making changes to the registry, you should back up any valued data on the computer. Note: This security setting is not available on earlier versions of Windows. The security setting that appears on computers running Windows XP, "Network access: Remotely accessible registry paths" corresponds to the "Network access: Remotely accessible registry paths and subpaths" security option on members of the Windows Server 2003 family. For more information, see Network access: Remotely accessible registry paths and subpaths.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_remotelyaccessibleregistrypaths"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"d43823f9ddc13690":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting","displayName":"Default notification setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_1","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_2","displayName":"Don't allow any site to show desktop notifications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_3","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},"d4b9d3e1871f420c":{"id":"device_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\r\n\r\nRequired diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\r\n\r\nUp to version 121, this policy is not supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nFor version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection.\r\n\r\nUse one of the following settings to configure this policy:\r\n\r\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\r\n\r\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\r\n\r\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\r\n\r\nPolicy options mapping:\r\n\r\n* Off (0) = Off (Not recommended)\r\n\r\n* RequiredData (1) = Required data\r\n\r\n* OptionalData (2) = Optional data\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_1","displayName":"Enabled","description":null,"helpText":null}]},"d4b1048564449f2a":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"d4387c21faaea0db":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_winprojexe188","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_winprojexe188_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_winprojexe188_1","displayName":"True","description":null,"helpText":null}]},"d4e1573062d39977":{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_saepreview","displayName":"Semi-Annual Enterprise Channel (Preview) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","categoryName":"Miscellaneous","options":[{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_saepreview_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_saepreview_1","displayName":"True","description":null,"helpText":null}]},"d4df85ba33ba4f4d":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_addedfolderunmountonpermissionsloss","displayName":"Hard-delete the contents of an added folder when user loses permissions to the folder","description":"This setting determines the behavior of the Sync client when the user loses permissions to an added folder.\n\nIf admins enable this setting (value 1), when the Sync client detects that the user lost permissions to an Added Folder, the Sync client will hard-delete all the contents of the folder and the folder itself.\n\nIf admins disable (value 0) or do not configure this setting, Sync will by default mark the folder in error and prompt the user to remove it. When the user confirms the removals, the contents of the folder are moved to the recycle-bin.\n ","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_addedfolderunmountonpermissionsloss_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_addedfolderunmountonpermissionsloss_1","displayName":"Enabled","description":null,"helpText":null}]},"d41895d0b73bfc1d":{"id":"device_vendor_msft_policy_config_onedrivengscv3~policy~onedrivengsc_warningmindiskspacelimitinmb","displayName":"Warn users who are low on disk space","description":"This setting lets you specify a minimum amount of available disk space and warn users when the OneDrive sync app (OneDrive.exe) downloads a file that causes them to have less than this amount.\r\n\r\nUsers will be prompted with options to help free up space.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv3~policy~onedrivengsc_warningmindiskspacelimitinmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv3~policy~onedrivengsc_warningmindiskspacelimitinmb_1","displayName":"Enabled","description":null,"helpText":null}]},"d412709e3fd36067":{"id":"device_vendor_msft_policy_config_remoteshell_specifymaxmemory","displayName":"Specify maximum amount of memory in MB per Shell","description":"This policy setting configures the maximum total amount of memory in megabytes that can be allocated by any active remote shell and all its child processes.\n\nAny value from 0 to 0x7FFFFFFF can be set, where 0 equals unlimited memory, which means the ability of remote operations to allocate memory is only limited by the available virtual memory.\n\nIf you enable this policy setting, the remote operation is terminated when a new allocation exceeds the specified quota.\n\nIf you disable or do not configure this policy setting, the value 150 is used by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remoteshell#remoteshell-specifymaxmemory"],"categoryId":"f69e6993-2e88-4938-bfe5-cea9ab21a858","categoryName":"Windows Remote Shell","options":[{"id":"device_vendor_msft_policy_config_remoteshell_specifymaxmemory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remoteshell_specifymaxmemory_1","displayName":"Enabled","description":null,"helpText":null}]},"d4f5e7df9fa85084":{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_allowedfilesystemdirectories_accesslevel","displayName":"Access level","description":"Level of filesystem access granted for this directory. Subdirectories inherit the same access level unless they have their own rule.","helpText":"","infoUrls":[],"categoryId":"ea5fabb0-6eec-4c3e-8c6d-7523739207c3","categoryName":null,"options":[{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_allowedfilesystemdirectories_accesslevel_0","displayName":"Read","description":"Read-only access","helpText":null},{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_allowedfilesystemdirectories_accesslevel_1","displayName":"Read/Write","description":"Read and write access","helpText":null}]},"d4b0e3dead89936a":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"d457b47741d0468e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},"d496edbe1950c3fa":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders70","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders70_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders70_1","displayName":"True","description":null,"helpText":null}]},"d436fdd58e19cd01":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_nocomponents","displayName":"Disable all items (User)","description":"Removes Active Desktop content and prevents users from adding Active Desktop content. \r\n\r\nThis setting removes all Active Desktop items from the desktop. It also removes the Web tab from Display in Control Panel. As a result, users cannot add Web pages or pictures from the Internet or an intranet to the desktop.\r\n\r\nNote: This setting does not disable Active Desktop. Users can still use image formats, such as JPEG and GIF, for their desktop wallpaper.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-sz-atc-nocomponents"],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_nocomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_nocomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"d433304882a18c23":{"id":"user_vendor_msft_policy_config_admx_sharedfolders_publishsharedfolders","displayName":"Allow shared folders to be published (User)","description":"This policy setting determines whether the user can publish shared folders in Active Directory Domain Services (AD DS).\r\n\r\nIf you enable or do not configure this policy setting, users can use the \"Publish in Active Directory\" option in the Shared Folders snap-in to publish shared folders in AD DS.\r\n\r\nIf you disable this policy setting, users cannot publish shared folders in AD DS, and the \"Publish in Active Directory\" option is disabled. Note: The default is to allow shared folders to be published when this setting is not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sharedfolders#admx-sharedfolders-publishsharedfolders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_sharedfolders_publishsharedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_sharedfolders_publishsharedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"d45dc9b3c1546db0":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmymusic","displayName":"Remove Music icon from Start Menu (User)","description":"This policy setting allows you to remove the Music icon from Start Menu.\r\n\r\nIf you enable this policy setting, the Music icon is no longer available from Start Menu.\r\n\r\nIf you disable or do not configure this policy setting, the Music icon is available from Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosmmymusic"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmymusic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmymusic_1","displayName":"Enabled","description":null,"helpText":null}]},"d4cde5e67accb1f8":{"id":"user_vendor_msft_policy_config_admx_startmenu_notraycontextmenu","displayName":"Remove access to the context menus for the taskbar (User)","description":"This policy setting allows you to remove access to the context menus for the taskbar.\r\n\r\nIf you enable this policy setting, the menus that appear when you right-click the taskbar and items on the taskbar are hidden, such as the Start button, the clock, and the taskbar buttons.\r\n\r\nIf you disable or do not configure this policy setting, the context menus for the taskbar are available.\r\n\r\nThis policy setting does not prevent users from using other methods to issue the commands that appear on these menus.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notraycontextmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_notraycontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_notraycontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"d47f962abad404cd":{"id":"user_vendor_msft_policy_config_admx_startmenu_showstartondisplaywithforegroundonwinkey","displayName":"Show Start on the display the user is using when they press the Windows logo key (User)","description":"This policy setting allows the Start screen to appear on the display the user is using when they press the Windows logo key. This setting only applies to users who are using multiple displays.\r\n\r\nIf you enable this policy setting, the Start screen will appear on the display the user is using when they press the Windows logo key.\r\n\r\nIf you disable or don't configure this policy setting, the Start screen will always appear on the main display when the user presses the Windows logo key. Users will still be able to open Start on other displays by pressing the Start button on that display. Also, the user will be able to configure this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-showstartondisplaywithforegroundonwinkey"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_showstartondisplaywithforegroundonwinkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_showstartondisplaywithforegroundonwinkey_1","displayName":"Enabled","description":null,"helpText":null}]},"d482612a2d82d9ed":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_maxrecentdocs_maxrecentdocs","displayName":"Maximum number of recent documents (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"d4b5502cc75546f1":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nonetconnectdisconnect","displayName":"Remove \"Map Network Drive\" and \"Disconnect Network Drive\" (User)","description":"Prevents users from using File Explorer or Network Locations to map or disconnect network drives.\r\n\r\nIf you enable this setting, the system removes the Map Network Drive and Disconnect Network Drive commands from the toolbar and Tools menus in File Explorer and Network Locations and from menus that appear when you right-click the File Explorer or Network Locations icons.\r\n\r\nThis setting does not prevent users from connecting to another computer by typing the name of a shared folder in the Run dialog box.\r\n\r\nNote:\r\n\r\nThis setting was documented incorrectly on the Explain tab in Group Policy for Windows 2000. The Explain tab states incorrectly that this setting prevents users from connecting and disconnecting drives.\r\n\r\nNote: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nonetconnectdisconnect"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nonetconnectdisconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nonetconnectdisconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"d47a938c0872b072":{"id":"user_vendor_msft_policy_config_browser_allowpopups","displayName":"Allow Popups (User)","description":"This setting lets you decide whether to turn on Pop-up Blocker and whether to allow pop-ups to appear in secondary windows.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowpopups"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowpopups_0","displayName":"Block","description":"Turn off Pop-up Blocker letting pop-up windows open.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowpopups_1","displayName":"Allow","description":"Turn on Pop-up Blocker stopping pop-up windows from opening.","helpText":null}]},"d4c1e0ebf47756e4":{"id":"user_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar","displayName":"Allow Search Suggestionsin Address Bar (User)","description":"This setting lets you decide whether search suggestions should appear in the Address bar of Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsearchsuggestionsinaddressbar"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar_0","displayName":"Block","description":"Prevented/Not allowed. Hide the search suggestions.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar_1","displayName":"Allow","description":"Allowed. Show the search suggestions.","helpText":null}]},"d4b8fa330efb7a80":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer","displayName":"Restrict CPU core sharing for renderer process (User)","description":"This policy mitigates side-channel cross process memory attacks by isolating the renderer process on the CPU core and preventing other processes from sharing the same core. The mitigation is supported on Microsoft® Windows® 11 24H2 and above. If the OS does not have the required scheduling support, this policy will have no effect. This policy may slow down performance in some demanding scenarios similar to disabling hyperthreading. For more information refer https://learn.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy\r\nIf this policy is enabled, all other processes will not be scheduled on the same CPU core when the renderer process is running.\r\nIf this policy is disabled, all other processes can be scheduled on the same CPU core if a renderer process is running on it.\r\nIf this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core. This may vary depending on Google Chrome release, currently running field trials, and platform.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_1","displayName":"Enabled","description":null,"helpText":null}]},"d4ab6a4f03cfb390":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_webhidallowalldevicesforurlsdesc","displayName":"Automatically grant permission to sites to connect to any HID device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"d486988eef3f6941":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled","displayName":"Bind Google credentials to a device (User)","description":"Controls the state of the Device Bound Session Credentials feature.\r\n\r\nDevice Bound Session Credentials protects Google authentication cookies against cookie theft by regularly providing a cryptographic proof of device possession to Google servers.\r\n\r\nIf this policy is set to false, Device Bound Session Credentials feature will be disabled.\r\n\r\nIf this policy is set to true, Device Bound Session Credentials feature will be enabled.\r\n\r\nIf this policy is unset, Google Chrome will follow the default rollout process for the Device Bound Session Credentials feature, which means that the feature will be gradually rolled out to an increasing number of users.","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d45bc92be5b4f619":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon62","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"d43d7d7bd9dd5d54":{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname","displayName":"Disable displaying organization name in the buttons to create PivotTables from Power BI datasets (User)","description":"\r\n This policy setting allows you to prevent the organization name from being displayed in the buttons in the Excel ribbon used to create PivotTables from Power BI datasets. By default, the organization name will be shown in the ribbon if it is available from Graph.\r\n\r\n If you enable this policy setting, the organization name will not be shown.\r\n\r\n If you disable or don’t configure this policy setting, the organization name will be shown.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","categoryName":"Power BI","options":[{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname_1","displayName":"Enabled","description":null,"helpText":null}]},"d4d4a6eef6e0c480":{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms","displayName":"Check for signatures on downloaded programs (User)","description":"This policy setting allows you to manage whether Internet Explorer checks for digital signatures (which identifies the publisher of signed software and verifies it hasn't been modified or tampered with) on user computers before downloading executable programs.\n\nIf you enable this policy setting, Internet Explorer will check the digital signatures of executable programs and display their identities before downloading them to user computers.\n\nIf you disable this policy setting, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.\n\nIf you do not configure this policy, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checksignaturesondownloadedprograms"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"d4eeb0d3d3f654d1":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows","displayName":"Enable dragging of content from different domains across windows (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when both the source and destination are in different windows. Users cannot change this setting.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy or do not configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_1","displayName":"Enabled","description":null,"helpText":null}]},"d4c3f9b2783272aa":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},"d4364118ca8f01e5":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether Internet Explorer will redirect navigations to sites that require a modern browser to Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Sitelist', beginning in M87, Internet Explorer will redirect sites that require a modern browser to Microsoft Edge.\r\n\r\nMicrosoft provides a list of public sites that require such redirection, such as https://mail.yahoo.com.\r\n\r\nWhen a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that began loading that site is closed if it had no prior content. Otherwise, it is navigated to a Microsoft help page explaining why the site was redirected to Microsoft Edge.\r\n\r\nWhen Microsoft Edge is launched to load a site from IE, an information bar is shown to the user explaining that the site works best in a modern browser.\r\n\r\nIf you set this policy to 'Disable', Internet Explorer will not redirect any traffic to Microsoft Edge.\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable\r\n\r\n* Sitelist (1) = Redirect sites based on the incompatible sites sitelist\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d41273dbacbd99a1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword","displayName":"Turn off AutoSave by default in Word (User)","description":"This policy setting allows you to turn off AutoSave by default in PowerPoint. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in PowerPoint. But, the user can enable AutoSave for PowerPoint by going to File > Options > Save. Or, the user can enable AutoSave for a specific PowerPoint file by using the AutoSave toggle in the title bar.\r\n \r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n \r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_1","displayName":"Enabled","description":null,"helpText":null}]},"d44534b68ef97f54":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicenotesdefaulturl5","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"d4bfe90ae2d4e7a3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_0","displayName":"Enable 'send for review'","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_2","displayName":"Exclude author's e-mail in documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_1","displayName":"Disable 'send for review'","description":null,"helpText":null}]},"d4dfb8f7c259c1b2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany","displayName":"Replace Label - Company (User)","description":"This policy setting allows you to change or remove the 12th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},"d480a5d43261a54e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile","displayName":"Replace Label - Mobile (User)","description":"This policy setting allows you to change or remove the 5th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_1","displayName":"Enabled","description":null,"helpText":null}]},"d4d94a56a3d67d02":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog","displayName":"Suppress recommended settings dialog (User)","description":"This policy setting controls the Recommended Settings dialog on first run of Office.\r\n\r\nIf you enable this policy setting, the recommended settings dialog will not be displayed on first run of Office.\r\n\r\nIf you disable or do not configure this policy setting, the recommended settings will provide choices to the user to opt into services such as such as Microsoft Update, new software notifications, Customer Experience Improvement Program, Office Diagnostics (Automatically receive small updates to improve reliability) Online Help (Online content options) and Online Search Relevancy that will help improve their Office experience.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog_1","displayName":"Enabled","description":null,"helpText":null}]},"d4cef577f139c7b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes","displayName":"Arabic modes (User)","description":"Specifies the spelling rules to use for checking spelling of Arabic text. This option is available only if you are using a right-to-left language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for the language, and have enabled support for the language through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_1","displayName":"Enabled","description":null,"helpText":null}]},"d4bc6fc4b9d075fb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},"d4b2c06229473890":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose","displayName":"Disable Reading Pane Compose (User)","description":"This policy setting allows you to control whether user’s responses to emails are composed inline on the reading pane or in a new window.\r\n\r\nIf you enable this policy setting, responses to emails are composed in new windows.\r\n\r\nIf you disable or do not configure this policy setting, responses to emails are composed inline in the reading pane.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose_1","displayName":"Enabled","description":null,"helpText":null}]},"d4790f1ab83e9bd7":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesgallerytitle","displayName":"Enterprise themes category title (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},"d48ded2b10c8fedb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},"d450fa0777195f20":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual","displayName":"Default fixed costs accrual (User)","description":"Specifies how Project sets the fixed cost accrual for new tasks.\r\n\r\nIf you enable this setting, new tasks will accrue fixed cost according to the specification you made.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_1","displayName":"Enabled","description":null,"helpText":null}]},"d493ba0d878fb8a3":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f9e53433-d8d9-4eaf-bdf3-d32de60d686e","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"d4c8d9d1ad990721":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"d422ab19b5f3a39e":{"id":"com.android.devicerestrictionpolicy.workprofilepasswordexpirationdays","displayName":"Number of days until password expires","description":"Enter the number of days, until the work profile password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. If the value is blank, Intune doesn't change or update this setting. Available for corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-365)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},"d41fcc76d3e46e8b":{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype","displayName":"Required password type","description":"Set the work profile password’s complexity requirements. Additional password requirements will become available based on your selection. Available for corporate-owned work profile devices (at work profile level). For more details, see the information provided in the ‘Learn More’ section below.","helpText":"","infoUrls":["https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-fx#device-password:~:text=owned%20work%20profiles.-,Required%20password%20type%3A,-Enter%20the%20required"],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":[{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_devicedefault","displayName":"Device default","description":"Device default value, no intent.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_required","displayName":"Password required, no restrictions","description":"There must be a password set, but there are no restrictions on type.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_lowsecuritybiometric","displayName":"Weak Biometric","description":"Low security biometrics based password required.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_numeric","displayName":"Numeric","description":"At least numeric.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_numericcomplex","displayName":"Numeric Complex","description":"At least numeric with no repeating or ordered sequences.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphabetic","displayName":"Alphabetic","description":"At least alphabetic password.","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphanumeric","displayName":"Alphanumeric","description":"At least alphanumeric password","helpText":null},{"id":"com.android.devicerestrictionpolicy.workprofilepasswordrequiredtype_alphanumericwithsymbols","displayName":"Alphanumeric with symbols","description":"At least alphanumeric with symbols.","helpText":null}]},"d4e33452d0a1f98d":{"id":"com.apple.cellularprivatenetwork.managed_csgnetworkidentifier","displayName":"Csg Network Identifier","description":"A string using the 3GPP \"CSG_ID\" format (defined in 3GPP 23.003, Section 4.7). The device uses this value to match a SIM present on the device.\n\nAll combinations of `NetworkIdentifier` and `CsgNetworkIdentifier` must be unique across all profiles installed on the device.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"d45920003a810a75":{"id":"com.apple.dock_dblclickbehavior-immutable","displayName":"Double Click Behavior Immutable","description":"If true, locks \"Double-click a window's title bar.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_dblclickbehavior-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_dblclickbehavior-immutable_true","displayName":"True","description":null,"helpText":null}]},"d41ba5f14c82cbd3":{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled","displayName":"Single sign-on for work or school sites using this profile enabled","description":"'Allow single sign-on for work or school sites using this profile' option allows non-AAD profiles to be able to use single sign-on for work or school sites using work or school credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-AAD profiles only.\n\nIf you enable or disable this policy, 'Intelligent enablement of Single sign-on (SSO) for all Windows Azure Active Directory (Azure AD) accounts for users with a single non-Azure AD Microsoft Edge profile' will be turned off.\n\nIf you don't configure this policy, users can control whether to use SSO using other credentials present on the machine in edge://settings/profiles/multiProfileSettings.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#aadwebsitessousingthisprofileenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_aadwebsitessousingthisprofileenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d4ecfaf7ad38d725":{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery","displayName":"Disable DIAL protocol for cast device discovery","description":"Enable this policy to disable the DIAL (Discovery And Launch) protocol for cast device discovery. (If EnableMediaRouter is disabled, this policy will have no effect).\n\nEnable this policy to disable DIAL protocol.\n\nBy default, Cast device discovery will use DIAL protocol.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgedisabledialprotocolforcastdiscovery"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgedisabledialprotocolforcastdiscovery_true","displayName":"Enabled","description":null,"helpText":null}]},"d497b796354a9b55":{"id":"com.apple.managedclient.preferences_enableodignore","displayName":"Ignore named files","description":"This setting lets you enter keywords to prevent the OneDrive sync app from uploading certain files to OneDrive or SharePoint. You can enter complete names, such as setup.bin or use the asterisk (*) as a wildcard character to represent a series of characters, such as *.eml. Keywords aren't case-sensitive.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#allow-only-corporate-mailboxes-to-be-added"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":null},"d4004f4579115f2c":{"id":"com.apple.managedclient.preferences_threattypesettings","displayName":"Threat type settings","description":"The threatTypeSettings preference in the antivirus engine is used to control how certain threat types are handled by the product.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#threat-type-settings"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"d497b66b4122bdb1":{"id":"com.apple.managedclient.preferences_webappinstallforcelist","displayName":"Web App Install Force List","description":"Specifies a list of websites that are installed silently, without user interaction, and which can't be uninstalled or disabled by the user.\n\nEach list item of the policy is an object with the following members:\n - \"url\", which is mandatory. \"url\" should be the URL of the web app to install.\n\nValues for the optional members are:\n - \"launch_container\" should be either \"window\" or \"tab\" to indicate how the Web App will be opened after it's installed.\n - \"create_desktop_shortcut\" should be true if a desktop shortcut should be created on Windows.\n\nIf \"default_launch_container\" is omitted, the app will open in a tab by default. Regardless of the value of \"default_launch_container\", users can change which container the app will open in. If \"create_desktop_shortcuts\" is omitted, no desktop shortcuts will be created.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#webappinstallforcelist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"d452bbd10349a068":{"id":"com.apple.systemconfiguration_proxies_ftppassive","displayName":"FTP Passive","description":"If true, enables passive FTP mode. ","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_ftppassive_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_ftppassive_1","displayName":"True","description":null,"helpText":null}]},"d4ad2862462b4e39":{"id":"contentcaching_peerfilterranges_item_last","displayName":"Last","description":"The last IP address in the range.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"d4064101f74cd349":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding","displayName":"Turn off IDN encoding","description":"Specifies whether the DNS client should convert internationalized domain names (IDNs) to Punycode when the computer is on non-domain networks with no WINS servers configured.\r\n\r\nIf this policy setting is enabled, IDNs are not converted to Punycode.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, IDNs are converted to Punycode when the computer is on non-domain networks with no WINS servers configured.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-idnencoding"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnencoding_1","displayName":"Enabled","description":null,"helpText":null}]},"d4858cfe7758e5f1":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable","displayName":"Turn on process scanning whenever real-time protection is enabled","description":"This policy setting allows you to configure process scanning when real-time protection is turned on. This helps to catch malware which could start when real-time protection is turned off.\r\n\r\n If you enable or do not configure this setting, a process scan will be initiated when real-time protection is turned on.\r\n\r\n If you disable this setting, a process scan will not be initiated when real-time protection is turned on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-disablescanonrealtimeenable"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_disablescanonrealtimeenable_1","displayName":"Enabled","description":null,"helpText":null}]},"d490207f73690800":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_backgroundretrymaximumperiod_netlogon_backgroundretrymaximumperiodlabel","displayName":"Seconds:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"d40c73613c880cd1":{"id":"device_vendor_msft_policy_config_admx_printing_domainprinters_wsdprinters","displayName":"Number of Web Services Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"d46f3224942e19d5":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name","displayName":"Set Teredo Server Name","description":"This policy setting allows you to specify the name of the Teredo server. This server name will be used on the Teredo client computer where this policy setting is applied.\r\n\r\nIf you enable this policy setting, you can specify a Teredo server name that applies to a Teredo client.\r\n\r\nIf you disable or do not configure this policy setting, the local settings on the computer are used to determine the Teredo server name.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-server-name"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_1","displayName":"Enabled","description":null,"helpText":null}]},"d468d3d9773a47b7":{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2","displayName":"Turn off the offer to update to the latest version of Windows","description":"Enables or disables the Store offer to update to the latest version of Windows.\r\n\r\nIf you enable this setting, the Store application will not offer updates to the latest version of Windows.\r\n\r\nIf you disable or do not configure this setting the Store application will offer updates to the latest version of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsstore#admx-windowsstore-disableosupgrade-2"],"categoryId":"be9bdbec-b52e-4174-9c5b-cf765dee855b","categoryName":"Store","options":[{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsstore_disableosupgrade_2_1","displayName":"Enabled","description":null,"helpText":null}]},"d469490e837df0df":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_certificatetransparencyenforcementdisabledforlegacycas_certificatetransparencyenforcementdisabledforlegacycasdesc","displayName":"Disable Certificate Transparency enforcement for a list of Legacy Certificate Authorities (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"d416aa60be8580cf":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromeparameters_browserswitcherchromeparametersdesc","displayName":"Command-line parameters for switching from the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"d4e47e4b05d046d2":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist","displayName":"Disable printer types on the deny list","description":"The printers of types placed on the deny list will be disabled from being discovered or having their capabilities fetched.\r\n\r\nPlacing all printer types on the deny list effectively disables printing, as there would be no available destinations to send a document for printing.\r\n\r\nIncluding cloud on the deny list has the same effect as setting the CloudPrintSubmitEnabled policy to false. In order to keep Google Cloud Print destinations discoverable, the CloudPrintSubmitEnabled policy must be set to true and cloud must not be on the deny list.\r\n\r\nIf the policy is not set, or is set to an empty list, all printer types will be available for discovery.\r\n\r\nExtension printers are also known as print provider destinations, and include any destination that belongs to a Google Chrome extension.\r\n\r\nLocal printers are also known as native printing destinations, and include destinations available to the local machine and shared network printers.\r\n\r\nExample value:\r\n\r\ncloud\r\nprivet","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printertypedenylist_1","displayName":"Enabled","description":null,"helpText":null}]},"d4f4cc54c8688c6f":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings","displayName":"Default HTML renderer for Google Chrome Frame","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_chromeframerenderersettings_1","displayName":"Enabled","description":null,"helpText":null}]},"d4e07c4433b6fe57":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation","displayName":"Configure the New Tab page URL","description":"Setting the policy configures the default New Tab page URL and prevents users from changing it.\r\n\r\nThe New Tab page opens with new tabs and windows.\r\n\r\nThis policy doesn't decide which pages open on start up. Those are controlled by the RestoreOnStartup policies. This policy does affect the homepage, if that's set to open the New Tab page, as well as the startup page if it's set to open the New Tab page.\r\n\r\nIt is a best practice to provide fully canonicalized URL, if the URL is not fully canonicalized Google Chrome will default to https://.\r\n\r\nLeaving the policy unset or empty puts the default New Tab page in use.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_newtabpagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"d434704e64b2d818":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site url patterns that specify sites for which\r\nadvanced JavaScript optimizations are enabled.\r\n\r\nFor detailed information on valid site url patterns, please see\r\nhttps://cloud.google.com/docs/chrome-enterprise/policies/url-patterns.\r\nWildcards, *, are allowed.\r\n\r\nJavaScript optimization policy exceptions will only be enforced at a site\r\ngranularity (eTLD+1). A policy set for only subdomain.site.com will not\r\ncorrectly apply to site.com or subdomain.site.com since they both resolve to\r\nthe same eTLD+1 (site.com) for which there is no policy. In this case, policy\r\nmust be set on site.com to apply correctly for both site.com and\r\nsubdomain.site.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level\r\norigin url alone, so e.g. if site-one.com is listed in the JavaScriptOptimizerAllowedForSites policy but site-one.com loads a frame containing site-two.com then site-one.com will have JavaScript optimizations\r\nenabled, but site-two.com will use the policy from DefaultJavaScriptOptimizerSetting, if set, or default to JavaScript\r\noptimizations enabled. Blocklist entries have higher priority than allowlist\r\nentries, which in turn have higher priority than the configured default value.\r\n\r\nIf this policy is not set for a site then the policy from DefaultJavaScriptOptimizerSetting applies to the site, if set, otherwise\r\nJavascript optimization is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"d4cfe35b9da20836":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_firstpartysetsoverrides","displayName":"Override First-Party Sets. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":null},"d432da3bac9a5a99":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~googlecast_accesscodecastdeviceduration_accesscodecastdeviceduration","displayName":"Specifies how long (in seconds) a cast device selected with an access code or QR code stays in the Google Cast menu's list of cast devices.: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":null},"d43a35b3379eb54a":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcroamsearch_odfcroamsearch","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcroamsearch_odfcroamsearch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcroamsearch_odfcroamsearch_1","displayName":"Single-user Search","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcroamsearch_odfcroamsearch_2","displayName":"Multi-user Search","description":null,"helpText":null}]},"d4b24076adb9961f":{"id":"device_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit","displayName":"Allow deleting browsing history on exit","description":"This policy setting allows the automatic deletion of specified items when the last browser window closes. The preferences selected in the Delete Browsing History dialog box (such as deleting temporary Internet files, cookies, history, form data, and passwords) are applied, and those items are deleted.\n\nIf you enable this policy setting, deleting browsing history on exit is turned on.\n\nIf you disable this policy setting, deleting browsing history on exit is turned off.\n\nIf you do not configure this policy setting, it can be configured on the General tab in Internet Options.\n\nIf the \"Prevent access to Delete Browsing History\" policy setting is enabled, this policy setting has no effect.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowdeletingbrowsinghistoryonexit"],"categoryId":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","categoryName":"Delete Browsing History","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowdeletingbrowsinghistoryonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"d46dd6d785a11164":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions","displayName":"Logon options","description":"This policy setting allows you to manage settings for logon options.\n\nIf you enable this policy setting, you can choose from the following logon options.\n\nAnonymous logon to disable HTTP authentication and use the guest account only for the Common Internet File System (CIFS) protocol.\n\nPrompt for user name and password to query users for user IDs and passwords. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon only in Intranet zone to query users for user IDs and passwords in other zones. After a user is queried, these values can be used silently for the remainder of the session.\n\nAutomatic logon with current user name and password to attempt logon using Windows NT Challenge Response (also known as NTLM authentication). If Windows NT Challenge Response is supported by the server, the logon uses the user's network user name and password for logon. If Windows NT Challenge Response is not supported by the server, the user is queried to provide the user name and password.\n\nIf you disable this policy setting, logon is set to Automatic logon only in Intranet zone.\n\nIf you do not configure this policy setting, logon is set to Automatic logon only in Intranet zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonelogonoptions"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonelogonoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"d42f974844ea9578":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_remotelyaccessibleregistrypaths","displayName":"Network Access Remotely Accessible Registry Paths","description":"Network access: Remotely accessible registry paths This security setting determines which registry keys can be accessed over the network, regardless of the users or groups listed in the access control list (ACL) of the winreg registry key. Default: System\\CurrentControlSet\\Control\\ProductOptions System\\CurrentControlSet\\Control\\Server Applications Software\\Microsoft\\Windows NT\\CurrentVersion Caution Incorrectly editing the registry may severely damage your system. Before making changes to the registry, you should back up any valued data on the computer. Note: This security setting is not available on earlier versions of Windows. The security setting that appears on computers running Windows XP, "Network access: Remotely accessible registry paths" corresponds to the "Network access: Remotely accessible registry paths and subpaths" security option on members of the Windows Server 2003 family. For more information, see Network access: Remotely accessible registry paths and subpaths.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_remotelyaccessibleregistrypaths"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":null},"d43823f9ddc13690":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting","displayName":"Default notification setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_1","displayName":"Allow sites to show desktop notifications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_2","displayName":"Don't allow any site to show desktop notifications","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultnotificationssetting_defaultnotificationssetting_3","displayName":"Ask every time a site wants to show desktop notifications","description":null,"helpText":null}]},"d4b9d3e1871f420c":{"id":"device_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata","displayName":"Send required and optional diagnostic data about browser usage","description":"This policy controls sending required and optional diagnostic data about browser usage to Microsoft.\r\n\r\nRequired diagnostic data is collected to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\nOptional diagnostic data includes data about how you use the browser, websites you visit and crash reports to Microsoft for product and service improvement.\r\n\r\nUp to version 121, this policy is not supported on Windows 10 devices. To control this data collection on Windows 10 for 121 and previous, IT admins must use the Windows diagnostic data group policy. This policy will either be 'Allow Telemetry' or 'Allow Diagnostic Data', depending on the version of Windows. Learn more about Windows 10 diagnostic data collection: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nFor version 122 and later, this policy is supported on Windows 10 devices to allow controlling Microsoft Edge data collection separately from Windows 10 diagnostics data collection.\r\n\r\nUse one of the following settings to configure this policy:\r\n\r\n'Off' turns off required and optional diagnostic data collection. This option is not recommended.\r\n\r\n'RequiredData' sends required diagnostic data but turns off optional diagnostic data collection. Microsoft Edge will send required diagnostic data to keep Microsoft Edge secure, up to date and performing as expected.\r\n\r\n'OptionalData' sends optional diagnostic data includes data about browser usage, websites that are visited, crash reports sent to Microsoft for product and service improvement.\r\n\r\nOn Windows 7/macOS, this policy controls sending required and optional data to Microsoft.\r\n\r\nIf you don't configure this policy or disable it, Microsoft Edge will default to the user's preference.\r\n\r\nPolicy options mapping:\r\n\r\n* Off (0) = Off (Not recommended)\r\n\r\n* RequiredData (1) = Required data\r\n\r\n* OptionalData (2) = Optional data\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86.1~policy~microsoft_edge_diagnosticdata_1","displayName":"Enabled","description":null,"helpText":null}]},"d4b1048564449f2a":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_internetexplorerintegrationcloudneutralsitesreporting_internetexplorerintegrationcloudneutralsitesreporting","displayName":"Configure reporting of potentially misconfigured neutral site URLs to the M365 Admin Center Site Lists app (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"d4387c21faaea0db":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_winprojexe188","displayName":"winproj.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_winprojexe188_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_winprojexe188_1","displayName":"True","description":null,"helpText":null}]},"d4e1573062d39977":{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_saepreview","displayName":"Semi-Annual Enterprise Channel (Preview) (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","categoryName":"Miscellaneous","options":[{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_saepreview_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v9~policy~l_microsoftofficemachine~l_miscellaneous_l_updatechannelselectormachine_l_uc_saepreview_1","displayName":"True","description":null,"helpText":null}]},"d4df85ba33ba4f4d":{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_addedfolderunmountonpermissionsloss","displayName":"Hard-delete the contents of an added folder when user loses permissions to the folder","description":"This setting determines the behavior of the Sync client when the user loses permissions to an added folder.\n\nIf admins enable this setting (value 1), when the Sync client detects that the user lost permissions to an Added Folder, the Sync client will hard-delete all the contents of the folder and the folder itself.\n\nIf admins disable (value 0) or do not configure this setting, Sync will by default mark the folder in error and prompt the user to remove it. When the user confirms the removals, the contents of the folder are moved to the recycle-bin.\n ","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_addedfolderunmountonpermissionsloss_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengsc~policy~onedrivengsc_addedfolderunmountonpermissionsloss_1","displayName":"Enabled","description":null,"helpText":null}]},"d41895d0b73bfc1d":{"id":"device_vendor_msft_policy_config_onedrivengscv3~policy~onedrivengsc_warningmindiskspacelimitinmb","displayName":"Warn users who are low on disk space","description":"This setting lets you specify a minimum amount of available disk space and warn users when the OneDrive sync app (OneDrive.exe) downloads a file that causes them to have less than this amount.\r\n\r\nUsers will be prompted with options to help free up space.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv3~policy~onedrivengsc_warningmindiskspacelimitinmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv3~policy~onedrivengsc_warningmindiskspacelimitinmb_1","displayName":"Enabled","description":null,"helpText":null}]},"d412709e3fd36067":{"id":"device_vendor_msft_policy_config_remoteshell_specifymaxmemory","displayName":"Specify maximum amount of memory in MB per Shell","description":"This policy setting configures the maximum total amount of memory in megabytes that can be allocated by any active remote shell and all its child processes.\n\nAny value from 0 to 0x7FFFFFFF can be set, where 0 equals unlimited memory, which means the ability of remote operations to allocate memory is only limited by the available virtual memory.\n\nIf you enable this policy setting, the remote operation is terminated when a new allocation exceeds the specified quota.\n\nIf you disable or do not configure this policy setting, the value 150 is used by default.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remoteshell#remoteshell-specifymaxmemory"],"categoryId":"f69e6993-2e88-4938-bfe5-cea9ab21a858","categoryName":"Windows Remote Shell","options":[{"id":"device_vendor_msft_policy_config_remoteshell_specifymaxmemory_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remoteshell_specifymaxmemory_1","displayName":"Enabled","description":null,"helpText":null}]},"d4f5e7df9fa85084":{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_allowedfilesystemdirectories_accesslevel","displayName":"Access level","description":"Level of filesystem access granted for this directory. Subdirectories inherit the same access level unless they have their own rule.","helpText":"","infoUrls":[],"categoryId":"ea5fabb0-6eec-4c3e-8c6d-7523739207c3","categoryName":null,"options":[{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_allowedfilesystemdirectories_accesslevel_0","displayName":"Read","description":"Read-only access","helpText":null},{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_allowedfilesystemdirectories_accesslevel_1","displayName":"Read/Write","description":"Read and write access","helpText":null}]},"d4b0e3dead89936a":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngcipheralgorithm","displayName":"Set CNG cipher algorithm (User)","description":"This policy setting allows you to configure the CNG cipher algorithm that is used.\r\n\r\nIf you enable this policy setting, then the cipher provided will be used if it is a supported algorithm.\r\n\r\nIf you disable or do not configure this policy setting, AES will be used.","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngcipheralgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_setcngcipheralgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"d457b47741d0468e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07","displayName":"Trusted Location #7 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc07_1","displayName":"Enabled","description":null,"helpText":null}]},"d496edbe1950c3fa":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders70","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders70_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc17_l_allowsubfolders70_1","displayName":"True","description":null,"helpText":null}]},"d436fdd58e19cd01":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_nocomponents","displayName":"Disable all items (User)","description":"Removes Active Desktop content and prevents users from adding Active Desktop content. \r\n\r\nThis setting removes all Active Desktop items from the desktop. It also removes the Web tab from Display in Control Panel. As a result, users cannot add Web pages or pictures from the Internet or an intranet to the desktop.\r\n\r\nNote: This setting does not disable Active Desktop. Users can still use image formats, such as JPEG and GIF, for their desktop wallpaper.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-sz-atc-nocomponents"],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_nocomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_nocomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"d433304882a18c23":{"id":"user_vendor_msft_policy_config_admx_sharedfolders_publishsharedfolders","displayName":"Allow shared folders to be published (User)","description":"This policy setting determines whether the user can publish shared folders in Active Directory Domain Services (AD DS).\r\n\r\nIf you enable or do not configure this policy setting, users can use the \"Publish in Active Directory\" option in the Shared Folders snap-in to publish shared folders in AD DS.\r\n\r\nIf you disable this policy setting, users cannot publish shared folders in AD DS, and the \"Publish in Active Directory\" option is disabled. Note: The default is to allow shared folders to be published when this setting is not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-sharedfolders#admx-sharedfolders-publishsharedfolders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_sharedfolders_publishsharedfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_sharedfolders_publishsharedfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"d45dc9b3c1546db0":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmymusic","displayName":"Remove Music icon from Start Menu (User)","description":"This policy setting allows you to remove the Music icon from Start Menu.\r\n\r\nIf you enable this policy setting, the Music icon is no longer available from Start Menu.\r\n\r\nIf you disable or do not configure this policy setting, the Music icon is available from Start Menu.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosmmymusic"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmymusic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosmmymusic_1","displayName":"Enabled","description":null,"helpText":null}]},"d4cde5e67accb1f8":{"id":"user_vendor_msft_policy_config_admx_startmenu_notraycontextmenu","displayName":"Remove access to the context menus for the taskbar (User)","description":"This policy setting allows you to remove access to the context menus for the taskbar.\r\n\r\nIf you enable this policy setting, the menus that appear when you right-click the taskbar and items on the taskbar are hidden, such as the Start button, the clock, and the taskbar buttons.\r\n\r\nIf you disable or do not configure this policy setting, the context menus for the taskbar are available.\r\n\r\nThis policy setting does not prevent users from using other methods to issue the commands that appear on these menus.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notraycontextmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_notraycontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_notraycontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"d47f962abad404cd":{"id":"user_vendor_msft_policy_config_admx_startmenu_showstartondisplaywithforegroundonwinkey","displayName":"Show Start on the display the user is using when they press the Windows logo key (User)","description":"This policy setting allows the Start screen to appear on the display the user is using when they press the Windows logo key. This setting only applies to users who are using multiple displays.\r\n\r\nIf you enable this policy setting, the Start screen will appear on the display the user is using when they press the Windows logo key.\r\n\r\nIf you disable or don't configure this policy setting, the Start screen will always appear on the main display when the user presses the Windows logo key. Users will still be able to open Start on other displays by pressing the Start button on that display. Also, the user will be able to configure this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-showstartondisplaywithforegroundonwinkey"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_showstartondisplaywithforegroundonwinkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_showstartondisplaywithforegroundonwinkey_1","displayName":"Enabled","description":null,"helpText":null}]},"d482612a2d82d9ed":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_maxrecentdocs_maxrecentdocs","displayName":"Maximum number of recent documents (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"d4b5502cc75546f1":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nonetconnectdisconnect","displayName":"Remove \"Map Network Drive\" and \"Disconnect Network Drive\" (User)","description":"Prevents users from using File Explorer or Network Locations to map or disconnect network drives.\r\n\r\nIf you enable this setting, the system removes the Map Network Drive and Disconnect Network Drive commands from the toolbar and Tools menus in File Explorer and Network Locations and from menus that appear when you right-click the File Explorer or Network Locations icons.\r\n\r\nThis setting does not prevent users from connecting to another computer by typing the name of a shared folder in the Run dialog box.\r\n\r\nNote:\r\n\r\nThis setting was documented incorrectly on the Explain tab in Group Policy for Windows 2000. The Explain tab states incorrectly that this setting prevents users from connecting and disconnecting drives.\r\n\r\nNote: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nonetconnectdisconnect"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nonetconnectdisconnect_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nonetconnectdisconnect_1","displayName":"Enabled","description":null,"helpText":null}]},"d47a938c0872b072":{"id":"user_vendor_msft_policy_config_browser_allowpopups","displayName":"Allow Popups (User)","description":"This setting lets you decide whether to turn on Pop-up Blocker and whether to allow pop-ups to appear in secondary windows.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowpopups"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowpopups_0","displayName":"Block","description":"Turn off Pop-up Blocker letting pop-up windows open.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowpopups_1","displayName":"Allow","description":"Turn on Pop-up Blocker stopping pop-up windows from opening.","helpText":null}]},"d4c1e0ebf47756e4":{"id":"user_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar","displayName":"Allow Search Suggestionsin Address Bar (User)","description":"This setting lets you decide whether search suggestions should appear in the Address bar of Microsoft Edge.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowsearchsuggestionsinaddressbar"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar_0","displayName":"Block","description":"Prevented/Not allowed. Hide the search suggestions.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowsearchsuggestionsinaddressbar_1","displayName":"Allow","description":"Allowed. Show the search suggestions.","helpText":null}]},"d4b8fa330efb7a80":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer","displayName":"Restrict CPU core sharing for renderer process (User)","description":"This policy mitigates side-channel cross process memory attacks by isolating the renderer process on the CPU core and preventing other processes from sharing the same core. The mitigation is supported on Microsoft® Windows® 11 24H2 and above. If the OS does not have the required scheduling support, this policy will have no effect. This policy may slow down performance in some demanding scenarios similar to disabling hyperthreading. For more information refer https://learn.microsoft.com/en-us/windows/win32/api/winnt/ns-winnt-process_mitigation_side_channel_isolation_policy\r\nIf this policy is enabled, all other processes will not be scheduled on the same CPU core when the renderer process is running.\r\nIf this policy is disabled, all other processes can be scheduled on the same CPU core if a renderer process is running on it.\r\nIf this policy is not set, all other processes can be scheduled on the same CPU core if a renderer process is running on the core. This may vary depending on Google Chrome release, currently running field trials, and platform.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_restrictcoresharingonrenderer_1","displayName":"Enabled","description":null,"helpText":null}]},"d4ab6a4f03cfb390":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_webhidallowalldevicesforurlsdesc","displayName":"Automatically grant permission to sites to connect to any HID device. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"d486988eef3f6941":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled","displayName":"Bind Google credentials to a device (User)","description":"Controls the state of the Device Bound Session Credentials feature.\r\n\r\nDevice Bound Session Credentials protects Google authentication cookies against cookie theft by regularly providing a cryptographic proof of device possession to Google servers.\r\n\r\nIf this policy is set to false, Device Bound Session Credentials feature will be disabled.\r\n\r\nIf this policy is set to true, Device Bound Session Credentials feature will be enabled.\r\n\r\nIf this policy is unset, Google Chrome will follow the default rollout process for the Device Bound Session Credentials feature, which means that the feature will be gradually rolled out to an increasing number of users.","helpText":"","infoUrls":[],"categoryId":"f00e9baf-9bbf-48e4-aaac-57410730f016","categoryName":"Sign-in settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~signin_boundsessioncredentialsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d45bc92be5b4f619":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc16_l_datecolon62","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"d43d7d7bd9dd5d54":{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname","displayName":"Disable displaying organization name in the buttons to create PivotTables from Power BI datasets (User)","description":"\r\n This policy setting allows you to prevent the organization name from being displayed in the buttons in the Excel ribbon used to create PivotTables from Power BI datasets. By default, the organization name will be shown in the ribbon if it is available from Graph.\r\n\r\n If you enable this policy setting, the organization name will not be shown.\r\n\r\n If you disable or don’t configure this policy setting, the organization name will be shown.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","categoryName":"Power BI","options":[{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v4~policy~l_microsoftofficeexcel~l_powerbi_l_disablefrompowerbidatasetorganizationname_1","displayName":"Enabled","description":null,"helpText":null}]},"d4d4a6eef6e0c480":{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms","displayName":"Check for signatures on downloaded programs (User)","description":"This policy setting allows you to manage whether Internet Explorer checks for digital signatures (which identifies the publisher of signed software and verifies it hasn't been modified or tampered with) on user computers before downloading executable programs.\n\nIf you enable this policy setting, Internet Explorer will check the digital signatures of executable programs and display their identities before downloading them to user computers.\n\nIf you disable this policy setting, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.\n\nIf you do not configure this policy, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checksignaturesondownloadedprograms"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"d4eeb0d3d3f654d1":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows","displayName":"Enable dragging of content from different domains across windows (User)","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in different windows.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when both the source and destination are in different windows. Users cannot change this setting.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in different windows. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy or do not configure it, users can drag content from one domain to a different domain when the source and destination are in different windows. Users cannot change this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainsacrosswindows_1","displayName":"Enabled","description":null,"helpText":null}]},"d4c3f9b2783272aa":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},"d4364118ca8f01e5":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge (User)","description":"This setting lets you specify whether Internet Explorer will redirect navigations to sites that require a modern browser to Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Sitelist', beginning in M87, Internet Explorer will redirect sites that require a modern browser to Microsoft Edge.\r\n\r\nMicrosoft provides a list of public sites that require such redirection, such as https://mail.yahoo.com.\r\n\r\nWhen a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that began loading that site is closed if it had no prior content. Otherwise, it is navigated to a Microsoft help page explaining why the site was redirected to Microsoft Edge.\r\n\r\nWhen Microsoft Edge is launched to load a site from IE, an information bar is shown to the user explaining that the site works best in a modern browser.\r\n\r\nIf you set this policy to 'Disable', Internet Explorer will not redirect any traffic to Microsoft Edge.\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable\r\n\r\n* Sitelist (1) = Redirect sites based on the incompatible sites sitelist\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_recommended_redirectsitesfrominternetexplorerredirectmode_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d41273dbacbd99a1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword","displayName":"Turn off AutoSave by default in Word (User)","description":"This policy setting allows you to turn off AutoSave by default in PowerPoint. AutoSave automatically saves all changes a user makes to files that are stored in OneDrive, OneDrive for Business, or SharePoint Online.\r\n\r\nIf you enable this policy setting, AutoSave is off by default in PowerPoint. But, the user can enable AutoSave for PowerPoint by going to File > Options > Save. Or, the user can enable AutoSave for a specific PowerPoint file by using the AutoSave toggle in the title bar.\r\n \r\nIf you disable or don’t configure this policy setting, AutoSave is on by default, but the user can disable AutoSave by going to File > Options > Save or by using the AutoSave toggle.\r\n \r\nNote: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"9865907f-b775-4d36-9578-a016c5105dfe","categoryName":"AutoSave","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_autosave_l_autosavedefaultoffword_1","displayName":"Enabled","description":null,"helpText":null}]},"d44534b68ef97f54":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice05_l_broadcastservicenotesdefaulturl5","displayName":"Shared Notes Default Url (optional): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"d4bfe90ae2d4e7a3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_0","displayName":"Enable 'send for review'","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_2","displayName":"Exclude author's e-mail in documents","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_outlooksendforreview_l_empty399_1","displayName":"Disable 'send for review'","description":null,"helpText":null}]},"d4dfb8f7c259c1b2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany","displayName":"Replace Label - Company (User)","description":"This policy setting allows you to change or remove the 12th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},"d480a5d43261a54e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile","displayName":"Replace Label - Mobile (User)","description":"This policy setting allows you to change or remove the 5th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacemobile_1","displayName":"Enabled","description":null,"helpText":null}]},"d4d94a56a3d67d02":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog","displayName":"Suppress recommended settings dialog (User)","description":"This policy setting controls the Recommended Settings dialog on first run of Office.\r\n\r\nIf you enable this policy setting, the recommended settings dialog will not be displayed on first run of Office.\r\n\r\nIf you disable or do not configure this policy setting, the recommended settings will provide choices to the user to opt into services such as such as Microsoft Update, new software notifications, Customer Experience Improvement Program, Office Diagnostics (Automatically receive small updates to improve reliability) Online Help (Online content options) and Online Search Relevancy that will help improve their Office experience.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_suppressrecommendedsettingsdialog_1","displayName":"Enabled","description":null,"helpText":null}]},"d4cef577f139c7b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes","displayName":"Arabic modes (User)","description":"Specifies the spelling rules to use for checking spelling of Arabic text. This option is available only if you are using a right-to-left language version of Microsoft Office or have installed Microsoft Office 2016 proofing tools or the Microsoft Office Single Language Pack 2016 for the language, and have enabled support for the language through Microsoft Office 2016 Language Preferences.","helpText":"","infoUrls":[],"categoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","categoryName":"Tools | Options | Spelling","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsspelling_l_arabicmodes_1","displayName":"Enabled","description":null,"helpText":null}]},"d4bc6fc4b9d075fb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize","displayName":"List of error messages to customize (User)","description":"Defines a list of custom error messages to activate.","helpText":"","infoUrls":[],"categoryId":"ee62e9fc-14c8-4f24-aa7e-89524087a802","categoryName":"Customizable Error Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_customizableerrormessages_l_listoferrormessagestocustomize_1","displayName":"Enabled","description":null,"helpText":null}]},"d4b2c06229473890":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose","displayName":"Disable Reading Pane Compose (User)","description":"This policy setting allows you to control whether user’s responses to emails are composed inline on the reading pane or in a new window.\r\n\r\nIf you enable this policy setting, responses to emails are composed in new windows.\r\n\r\nIf you disable or do not configure this policy setting, responses to emails are composed inline in the reading pane.","helpText":"","infoUrls":[],"categoryId":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","categoryName":"Compose Messages","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mail~l_composemessages_l_disablereadingpanecompose_1","displayName":"Enabled","description":null,"helpText":null}]},"d4790f1ab83e9bd7":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_displayenterprisethemes_l_displayenterprisethemesgallerytitle","displayName":"Enterprise themes category title (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":null},"d48ded2b10c8fedb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc","displayName":"Disable all trusted locations (User)","description":"This policy setting allows administrators to disable all trusted locations in the specified applications. Trusted locations specified in the Trust Center are used to define file locations that are assumed to be safe. Content, code, and add-ins are allowed to load from trusted locations with a minimal amount of security, without prompting the users for permission. If a dangerous file is opened from a trusted location, it will not be subject to standard security measures and could harm users' computers or data.\r\n \r\nIf you enable this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are ignored, including any trusted locations established by Office 2016 during setup, deployed to users using Group Policy, or added by users themselves. Users will be prompted again when opening files from trusted locations.\r\n\r\nIf you disable or do not configure this policy setting, all trusted locations (those specified in the Trust Center) in the specified applications are assumed to be safe.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_disabletrustedloc_1","displayName":"Enabled","description":null,"helpText":null}]},"d450fa0777195f20":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual","displayName":"Default fixed costs accrual (User)","description":"Specifies how Project sets the fixed cost accrual for new tasks.\r\n\r\nIf you enable this setting, new tasks will accrue fixed cost according to the specification you made.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjdefaultfixedaccrual_1","displayName":"Enabled","description":null,"helpText":null}]},"d493ba0d878fb8a3":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f9e53433-d8d9-4eaf-bdf3-d32de60d686e","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"d4c8d9d1ad990721":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_pathcolon48","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/d6.json b/public/intune-definitions/d6.json index 4fdc07ba11ad..270cc45ed832 100644 --- a/public/intune-definitions/d6.json +++ b/public/intune-definitions/d6.json @@ -1 +1 @@ -{"d66412d0068cf7e8":{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation","displayName":"Allow Marketplace App Installation","description":"When 'false', the device prevents installation of alternative marketplace apps from the web, and prevents any installed alternative marketplace apps from installing apps.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation_true","displayName":"True","description":null,"helpText":null}]},"d6d84f522a1cde15":{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_latitude","displayName":"Latitude","description":"The latitude of the geofence.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"d6872183336c45bd":{"id":"com.apple.directoryservice.managed_adforcehomelocalflag","displayName":"AD Force Home Local Flag","description":"If true, enables the AD Force Home Local key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adforcehomelocalflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adforcehomelocalflag_true","displayName":"True","description":null,"helpText":null}]},"d68f2a7f1a1213e2":{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek","displayName":"Specify first day of the week","description":"Set the first day of week in calendar view.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-calendar-first-day-of-week"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_0","displayName":"Sunday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_1","displayName":"Monday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_4","displayName":"Thursday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_5","displayName":"Friday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_6","displayName":"Saturday","description":null,"helpText":null}]},"d64bde42699d5ef5":{"id":"com.apple.managedclient.preferences_passivemode","displayName":"Enable passive mode (deprecated)","description":"Whether the antivirus engine runs in passive mode or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-passive-mode"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_passivemode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passivemode_true","displayName":"Enabled","description":null,"helpText":null}]},"d61ea4cbbc8edd72":{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\n​\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\n\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scrolltotextfragmentenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d6e446db0c9886e5":{"id":"com.apple.system-extension-policy_allowedsystemextensions_generickey","displayName":"Allowed System Extensions","description":"The mapping of team identifiers to arrays of bundle identifiers, where the bundle identifier defines the system extension to install.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"d6ed36395f7eba54":{"id":"com.apple.webcontent-filter_userdefinedname","displayName":"User Defined Name","description":"The display name for this filtering configuration.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},"d61cf110ab56b92c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (users can override)","description":"If FriendlyURLs are enabled, Microsoft Edge computes more representations of the URL and places them on the clipboard.\n\nThis policy configures what format is pasted when the user pastes in external applications or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf you configure this policy, it makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu won't be available.\n\n* Not configured = The users are able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats are stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge, and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature is disabled.\n\n* 3 = The user gets a friendly URL whenever they paste into surfaces that accept rich text. The plain URL is still available for nonrich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\n\nThe recommended policy is available in Microsoft Edge 105 or later.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_plaintext","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_titledhyperlink","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_webpreview","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},"d645d31bc1400155":{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords aren't cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d60387657445896e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled","displayName":"Enable tab preview on hover","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\n\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\n\nIf you disable this policy, tab previews aren't shown on hover.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d6c98ef887b3bcdd":{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction","displayName":"Enable or disable the User-Agent Reduction (Obsolete)","description":"The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch\n\nIf you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.\n\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins.\n\nSet this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header.\n\nTo learn more about the User-Agent string, read here:\n\nhttps://go.microsoft.com/fwlink/?linkid=2186267\n\nPolicy options mapping:\n\n* Default (0) = Reduced User Agent, or controlled by experimentation.\n\n* ForceDisabled (1) = Full (legacy) User Agent.\n\n* ForceEnabled (2) = Reduced User Agent.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_default","displayName":"Reduced User Agent, or controlled by experimentation.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_forcedisabled","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_forceenabled","displayName":"Reduced User Agent.","description":null,"helpText":null}]},"d689331bcdd6d4dc":{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions","displayName":"Choose how BitLocker-protected fixed drives can be recovered","description":"This policy setting allows you to control how BitLocker-protected fixed data drives are recovered in the absence of the required credentials. This policy setting is applied when you turn on BitLocker.\n\nThe \"Allow data recovery agent\" check box is used to specify whether a data recovery agent can be used with BitLocker-protected fixed data drives. Before a data recovery agent can be used it must be added from the Public Key Policies item in either the Group Policy Management Console or the Local Group Policy Editor. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about adding data recovery agents.\n\nIn \"Configure user storage of BitLocker recovery information\" select whether users are allowed, required, or not allowed to generate a 48-digit recovery password or a 256-bit recovery key.\n\nSelect \"Omit recovery options from the BitLocker setup wizard\" to prevent users from specifying recovery options when they turn on BitLocker on a drive. This means that you will not be able to specify which recovery option to use when you turn on BitLocker, instead BitLocker recovery options for the drive are determined by the policy setting.\n\nIn \"Save BitLocker recovery information to Active Directory Domain Services\" choose which BitLocker recovery information to store in AD DS for fixed data drives. If you select \"Backup recovery password and key package\", both the BitLocker recovery password and key package are stored in AD DS. Storing the key package supports recovering data from a drive that has been physically corrupted. If you select \"Backup recovery password only,\" only the recovery password is stored in AD DS.\n\nSelect the \"Do not enable BitLocker until recovery information is stored in AD DS for fixed data drives\" check box if you want to prevent users from enabling BitLocker unless the computer is connected to the domain and the backup of BitLocker recovery information to AD DS succeeds.\n\nNote: If the \"Do not enable BitLocker until recovery information is stored in AD DS for fixed data drives\" check box is selected, a recovery password is automatically generated.\n\nIf you enable this policy setting, you can control the methods available to users to recover data from BitLocker-protected fixed data drives.\n\nIf this policy setting is not configured or disabled, the default recovery options are supported for BitLocker recovery. By default a DRA is allowed, the recovery options can be specified by the user including the recovery password and recovery key, and recovery information is not backed up to AD DS\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"d617db9b57141f42":{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_history","displayName":"PIN History","description":"This policy specifies the number of past PINs that can be stored in the history that can’t be used. Valid values are 0 to 50 inclusive. If this policy is set to 0, then storage of previous PINs is not required. PIN history is not preserved through PIN reset.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"d624110eb8c46e0d":{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord","displayName":"Turn off Steps Recorder","description":"This policy setting controls the state of Steps Recorder.\r\n\r\nSteps Recorder keeps a record of steps taken by the user. The data generated by Steps Recorder can be used in feedback systems such as Windows Error Reporting to help developers understand and fix problems. The data includes user actions such as keyboard input and mouse input, user interface data, and screen shots. Steps Recorder includes an option to turn on and off data collection.\r\n\r\nIf you enable this policy setting, Steps Recorder will be disabled.\r\n\r\nIf you disable or do not configure this policy setting, Steps Recorder will be enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffuseractionrecord"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord_1","displayName":"Enabled","description":null,"helpText":null}]},"d606ab9f172e4ca1":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2","displayName":"Configure Group Policy slow link detection","description":"This policy setting defines a slow connection for purposes of applying and updating Group Policy.\r\n\r\nIf the rate at which data is transferred from the domain controller providing a policy update to the computers in this group is slower than the rate specified by this setting, the system considers the connection to be slow.\r\n\r\nThe system's response to a slow policy connection varies among policies. The program implementing the policy can specify the response to a slow link. Also, the policy processing settings in this folder lets you override the programs' specified responses to slow links.\r\n\r\nIf you enable this setting, you can, in the \"Connection speed\" box, type a decimal number between 0 and 4,294,967,200, indicating a transfer rate in kilobits per second. Any connection slower than this rate is considered to be slow. If you type 0, all connections are considered to be fast.\r\n\r\nIf you disable this setting or do not configure it, the system uses the default value of 500 kilobits per second.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. The setting in Computer Configuration defines a slow link for policies in the Computer Configuration folder. The setting in User Configuration defines a slow link for settings in the User Configuration folder.\r\n\r\nAlso, see the \"Do not detect slow network connections\" and related policies in Computer Configuration\\Administrative Templates\\System\\User Profile. Note: If the profile server has IP connectivity, the connection speed setting is used. If the profile server does not have IP connectivity, the SMB timing is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-gptransferrate-2"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_1","displayName":"Enabled","description":null,"helpText":null}]},"d6c85c126cf6ca2d":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning","displayName":"Turn on e-mail scanning","description":"This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac).\r\n\r\n If you enable this setting, e-mail scanning will be enabled.\r\n\r\n If you disable or do not configure this setting, e-mail scanning will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disableemailscanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning_1","displayName":"Enabled","description":null,"helpText":null}]},"d636b05c3d2537f3":{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy","displayName":"Microsoft Support Diagnostic Tool: Configure execution level","description":"This policy setting determines the execution level for Microsoft Support Diagnostic Tool.\r\n\r\nMicrosoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals.\r\n\r\nIf you enable this policy setting, administrators can use MSDT to collect and send diagnostic data to a support professional to resolve a problem.\r\n\r\nIf you disable this policy setting, MSDT cannot gather diagnostic data.\r\n\r\nIf you do not configure this policy setting, MSDT is turned on by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-wdiscenarioexecutionpolicy"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"d6a43df760f3ae0a":{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy","displayName":"Configure MSI Corrupted File Recovery behavior","description":"This policy setting allows you to configure the recovery behavior for corrupted MSI files to one of three states:\r\n\r\nPrompt for Resolution: Detection, troubleshooting, and recovery of corrupted MSI applications will be turned on. Windows will prompt the user with a dialog box when application reinstallation is required. This is the default recovery behavior on Windows client.\r\n\r\nSilent: Detection, troubleshooting, and notification of MSI application to reinstall will occur with no UI. Windows will log an event when corruption is determined and will suggest the application that should be re-installed. This behavior is recommended for headless operation and is the default recovery behavior on Windows server.\r\n\r\nTroubleshooting Only: Detection and verification of file corruption will be performed without UI. Recovery is not attempted.\r\n\r\nIf you enable this policy setting, the recovery behavior for corrupted files is set to either the Prompt For Resolution (default on Windows client), Silent (default on Windows server), or Troubleshooting Only. \r\n\r\nIf you disable this policy setting, the troubleshooting and recovery behavior for corrupted files will be disabled. No troubleshooting or resolution will be attempted.\r\n\r\nIf you do not configure this policy setting, the recovery behavior for corrupted files will be set to the default recovery behavior.\r\n\r\nNo system or service restarts are required for changes to this policy setting to take immediate effect after a Group Policy refresh.\r\n\r\nNote: This policy setting will take effect only when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, system file recovery will not be attempted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msifilerecovery#admx-msifilerecovery-wdiscenarioexecutionpolicy"],"categoryId":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","categoryName":"MSI Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"d6f1f38cbaacc80e":{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction","displayName":"User management of sharing user name, account picture, and domain information with apps (not desktop apps)","description":"This setting prevents users from managing the ability to allow apps to access the user name, account picture, and domain information.\r\n\r\nIf you enable this policy setting, sharing of user name, picture and domain information may be controlled by setting one of the following options:\r\n\r\n\"Always on\" - users will not be able to change this setting and the user's name and account picture will be shared with apps (not desktop apps). In addition apps (not desktop apps) that have the enterprise authentication capability will also be able to retrieve the user's UPN, SIP/URI, and DNS.\r\n\r\n\"Always off\" - users will not be able to change this setting and the user's name and account picture will not be shared with apps (not desktop apps). In addition apps (not desktop apps) that have the enterprise authentication capability will not be able to retrieve the user's UPN, SIP/URI, and DNS. Selecting this option may have a negative impact on certain enterprise software and/or line of business apps that depend on the domain information protected by this setting to connect with network resources.\r\n\r\nIf you do not configure or disable this policy the user will have full control over this setting and can turn it off and on. Selecting this option may have a negative impact on certain enterprise software and/or line of business apps that depend on the domain information protected by this setting to connect with network resources if users choose to turn the setting off.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-userinfoaccessaction"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_1","displayName":"Enabled","description":null,"helpText":null}]},"d62814665c8d0521":{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver","displayName":"System Audit I Psec Driver","description":"This policy setting allows you to audit events generated by the IPsec filter driver such as the following: Startup and shutdown of the IPsec services. Network packets dropped due to integrity check failure. Network packets dropped due to replay check failure. Network packets dropped due to being in plaintext. Network packets received with incorrect Security Parameter Index (SPI). This may indicate that either the network card is not working correctly or the driver needs to be updated. Inability to process IPsec filters. If you configure this policy setting, an audit event is generated on an IPsec filter driver operation. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated on an IPSec filter driver operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditipsecdriver"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"d643379ad51eb7d8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir","displayName":"Set disk cache directory","description":"Setting the policy has Google Chrome use the directory you provide for storing cached files on the disk—whether or not users specify the --disk-cache-dir flag.\r\n\r\nIf not set, Google Chrome uses the default cache directory, but users can change that setting with the --disk-cache-dir command line flag.\r\n\r\nGoogle Chrome manages the contents of a volume's root directory. So to avoid data loss or other errors, do not set this policy to the root directory or any directory used for other purposes. See the variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: ${user_home}/Chrome_cache","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},"d69797aa4971376e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains","displayName":"Suppress lookalike domain warnings on domains","description":"This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Google Chrome believes might be trying to spoof another site the user is familiar with.\r\n\r\nIf the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain.\r\n\r\nIf the policy is not set, or set to an empty list, warnings may appear on any site the user visits.\r\n\r\nA hostname can be allowed with a complete host match, or any domain match. For example, a URL like \"https://foo.example.com/bar\" may have warnings suppressed if this list includes either \"foo.example.com\" or \"example.com\".\r\n\r\nExample value:\r\n\r\nfoo.example.com\r\nexample.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"d619659d03ded868":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs","displayName":"Suppress JavaScript Dialogs triggered from different origin subframes","description":"As described in https://www.chromestatus.com/feature/5148698084376576 , JavaScript modal dialogs, triggered by window.alert, window.confirm, and window.prompt, will be blocked in Google Chrome if triggered from a subframe whose origin is different from the main frame origin.\r\nThis policy allows overriding that change.\r\nIf the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked.\r\nIf the policy is set to disabled, JavaScript dialogs triggered from a different origin subframe will not be blocked.\r\n\r\nThis policy will be removed in Google Chrome version 95.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"d67dbb7799ee5c1e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},"d6e6c3eedb715d84":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes","displayName":"The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization","description":"If this policy is set, clipboard data sent to and from the host will be truncated to the limit set by this policy.\r\n\r\nIf a value of 0 is set, then clipboard sync is disabled.\r\n\r\nThis policy affects both remote access and remote support scenarios.\r\n\r\nThis policy has no effect if it is not set.\r\n\r\nSetting the policy to a value that is not within the min/max range may prevent the host from starting.\r\n\r\nPlease note that the actual upper bound for the clipboard size is based on the maximum WebRTC data channel message size which this policy does not control.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_1","displayName":"Enabled","description":null,"helpText":null}]},"d64c1560b29d554a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_1","displayName":"Enabled","description":null,"helpText":null}]},"d63ff05285a95943":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"d6296a09c42dbfae":{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardata","displayName":"Allow Cellular Data","description":"Allows the cellular data channel on the device. Device reboot is not required to enforce the policy.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-connectivity#allowcellulardata"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardata_0","displayName":"Do not allow the cellular data channel. The user cannot turn it on. This value is not supported in Windows 10, version 1511.","description":"Do not allow the cellular data channel. The user cannot turn it on. This value is not supported in Windows 10, version 1511.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardata_1","displayName":"Allow the cellular data channel. The user can turn it off.","description":"Allow the cellular data channel. The user can turn it off.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardata_2","displayName":"Allow the cellular data channel. The user cannot turn it off.","description":"Allow the cellular data channel. The user cannot turn it off.","helpText":null}]},"d64e222fe5aed53e":{"id":"device_vendor_msft_policy_config_defender_signatureupdatefallbackorder","displayName":"Signature Update Fallback Order","description":"This policy setting allows you to define the order in which different definition update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the definition update sources in order. Possible values are:InternalDefinitionUpdateServerMicrosoftUpdateServerMMPCFileSharesFor example: InternalDefinitionUpdateServer | MicrosoftUpdateServer | MMPCIf you enable this setting, definition update sources will be contacted in the order specified. Once definition updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted. If you disable or do not configure this setting, definition update sources will be contacted in a default order. OMA-URI Path: . /Vendor/MSFT/Policy/Config/Defender/SignatureUpdateFallbackOrder","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#signatureupdatefallbackorder"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"d68be06f14dbbf61":{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesecuritylog","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\n\nIf you enable this policy setting, you can configure the maximum log file size to be between 20 megabytes (20480 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\n\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 20 megabytes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-eventlogservice#eventlogservice-specifymaximumfilesizesecuritylog"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesecuritylog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesecuritylog_1","displayName":"Enabled","description":null,"helpText":null}]},"d605f0d685b27d33":{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesystemlog","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\n\nIf you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\n\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 1 megabyte.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-eventlogservice#eventlogservice-specifymaximumfilesizesystemlog"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesystemlog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesystemlog_1","displayName":"Enabled","description":null,"helpText":null}]},"d66b046695063a9e":{"id":"device_vendor_msft_policy_config_feeds_feedsenabled","displayName":"Enable News and interests","description":"This policy setting specifies whether News and interests is allowed on the device.","helpText":"","infoUrls":[],"categoryId":"b260992a-8216-4bfa-b60a-4eeea1f356c9","categoryName":"News and interests","options":[{"id":"device_vendor_msft_policy_config_feeds_feedsenabled_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_feeds_feedsenabled_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"d6a71d2843718a26":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff","displayName":"Shutdown On User Logoff","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nShuts down the machine when a user logs off\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ShutdownOnUserLogoff\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Any user, 2 = Any FSLogix Profile user","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"d6a13ba3f6c90e34":{"id":"device_vendor_msft_policy_config_kioskbrowser_blockedurlexceptions","displayName":"Blocked Url Exceptions","description":"List of exceptions to the blocked website URLs (with wildcard support). This is used to configure URLs kiosk browsers are allowed to navigate to, which are a subset of the blocked URLs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#blockedurlexceptions"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},"d631b9dbffb950bb":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_2","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_3","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},"d62f54b23aab8132":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings","description":"Configure the list of Microsoft Defender SmartScreen trusted domains. This means:\r\nMicrosoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\r\nThe Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\r\n\r\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\r\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender Advanced Threat Protection. You must configure your allow and block lists in Microsoft Defender Security Center instead.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"d65b72fb0a89bbf7":{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\r\n\r\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d604b3a702759293":{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"d6d537234a1e0549":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_exprwdexe38","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_exprwdexe38_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_exprwdexe38_1","displayName":"True","description":null,"helpText":null}]},"d62e7b88da8d5e99":{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_globaloptionsmachine~l_customizemachine_l_defaultuithememachine","displayName":"Default Office theme","description":"This policy setting allows you to select the user interface (UI) theme used by Office, if the user has not already selected an Office theme.\r\n\r\nNote: This setting only applies to Version 1903 or later of Office.\r\n\r\nIf you enable this policy setting, you may choose the Office theme used in cases where the user has not selected an Office theme themselves.\r\n\r\nIf you disable or do not configure this policy setting, Office will use the Colorful theme in cases where the user has not selected an Office theme themselves.\r\n\r\nRegardless of how you configure this policy setting, users can change their Office theme by going to File > Account > Office Theme (or, in Outlook, by going to File > Office Account > Office Theme).\r\n\r\nNote: This policy setting takes precedence over the “Default Office theme” policy setting located under User Configuration.","helpText":"","infoUrls":[],"categoryId":"5d8272e2-1ed3-4a8d-9555-9a87fa13d078","categoryName":"Customize","options":[{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_globaloptionsmachine~l_customizemachine_l_defaultuithememachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_globaloptionsmachine~l_customizemachine_l_defaultuithememachine_1","displayName":"Enabled","description":null,"helpText":null}]},"d6699f145db15d9f":{"id":"device_vendor_msft_policy_config_systemservices_configurehomegroupproviderservicestartupmode","displayName":"Configure Home Group Provider Service Startup Mode","description":"This setting determines whether the service's start type is Automatic(2), Manual(3), Disabled(4). Default: Manual.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-SystemServices#configurehomegroupproviderservicestartupmode"],"categoryId":"4f29ef5c-6ca0-4b09-893f-01755a670877","categoryName":"System Services","options":null},"d6c28299cc6c9d45":{"id":"device_vendor_msft_policy_config_updateupdates.1~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_allowinstallationmicrosoftedgecanary_part_installpolicy","displayName":"Install Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"device_vendor_msft_policy_config_updateupdates.1~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_allowinstallationmicrosoftedgecanary_part_installpolicy_1","displayName":"Always allow Installs (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updateupdates.1~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_allowinstallationmicrosoftedgecanary_part_installpolicy_0","displayName":"Installs disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updateupdates.1~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_allowinstallationmicrosoftedgecanary_part_installpolicy_6","displayName":"Force Installs (Per-User)","description":null,"helpText":null}]},"d6eae8f04cd491c3":{"id":"linux_mdatp_managed_antivirusengine_scanarchives","displayName":"Enable scanning of archives","description":"Specifies whether to scan archives during on-demand antivirus scans.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-preferences?view=o365-worldwide#scan-archives-on-demand-antivirus-scans-only"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_scanarchives_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scanarchives_true","displayName":"Enabled","description":null,"helpText":null}]},"d6e32f468ba3bdff":{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution","displayName":"Allow agent execution in container","description":"Controls whether agent tools and loops can execute. The specific behavior depends on the selected agent.","helpText":"","infoUrls":[],"categoryId":"ea5fabb0-6eec-4c3e-8c6d-7523739207c3","categoryName":null,"options":[{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_0","displayName":"Don't allow","description":"Agent tool execution is not allowed","helpText":null},{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_1","displayName":"Allow","description":"Agent tool execution is allowed with configured resource policies","helpText":null}]},"d6cacda81d93b758":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme","displayName":"Load a specific theme (User)","description":"Specifies which theme file is applied to the computer the first time a user logs on.\r\n\r\nIf you enable this setting, the theme that you specify will be applied when a new user logs on for the first time. This policy does not prevent the user from changing the theme or any of the theme elements such as the desktop background, color, sounds, or screen saver after the first logon.\r\n\r\nIf you disable or do not configure this setting, the default theme will be applied at the first logon.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-settheme"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_1","displayName":"Enabled","description":null,"helpText":null}]},"d63e2bafecbbe772":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werarchive_1_wermaxarchivecount","displayName":"Maximum number of reports to store: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"d6429638c54aa8e4":{"id":"user_vendor_msft_policy_config_admx_globalization_turnoffoffertextpredictions","displayName":"Turn off offer text predictions as I type (User)","description":"\r\n This policy turns off the offer text predictions as I type option. This does not, however, prevent the user or an application from changing the setting programmatically.\r\n\r\n The offer text predictions as I type option controls whether or not text prediction suggestions will be presented to the user on the on-screen keyboard.\r\n\r\n If the policy is Enabled, then the option will be locked to not offer text predictions.\r\n\r\n If the policy is Disabled or Not Configured, then the user will be free to change the setting according to their preference.\r\n\r\n Note that the availability and function of this setting is dependent on supported languages being enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-turnoffoffertextpredictions"],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"user_vendor_msft_policy_config_admx_globalization_turnoffoffertextpredictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_turnoffoffertextpredictions_1","displayName":"Enabled","description":null,"helpText":null}]},"d672cc15d9eac32a":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_gpdcoptions","displayName":"Configure Group Policy domain controller selection (User)","description":"This policy setting determines which domain controller the Group Policy Object Editor snap-in uses.\r\n\r\nIf you enable this setting, you can which domain controller is used according to these options:\r\n\r\n\"Use the Primary Domain Controller\" indicates that the Group Policy Object Editor snap-in reads and writes changes to the domain controller designated as the PDC Operations Master for the domain.\r\n\r\n\"Inherit from Active Directory Snap-ins\" indicates that the Group Policy Object Editor snap-in reads and writes changes to the domain controller that Active Directory Users and Computers or Active Directory Sites and Services snap-ins use.\r\n\r\n\"Use any available domain controller\" indicates that the Group Policy Object Editor snap-in can read and write changes to any available domain controller.\r\n\r\nIf you disable this setting or do not configure it, the Group Policy Object Editor snap-in uses the domain controller designated as the PDC Operations Master for the domain.\r\n\r\nNote: To change the PDC Operations Master for a domain, in Active Directory Users and Computers, right-click a domain, and then click \"Operations Masters.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-gpdcoptions"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"user_vendor_msft_policy_config_admx_grouppolicy_gpdcoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_grouppolicy_gpdcoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"d6227f4120d79cd6":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup","displayName":"Visio 2016 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Visio 2016.\r\nMicrosoft Visio 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Visio 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Visio 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Visio 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016visiobackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup_1","displayName":"Enabled","description":null,"helpText":null}]},"d66e88b5b3fb9721":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled","displayName":"Enable search suggestions (User)","description":"Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions.\r\n\r\nIf you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d63462458a764f03":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess","displayName":"Require Site Isolation for every site (User)","description":"Since Google Chrome 67, site isolation has been enabled by default on all Desktop platforms, causing every site to run in its own process. A site is a scheme plus eTLD+1 (e.g., https://example.com). Setting this policy to Enabled does not change that behavior; it only prevents users from opting out (for example, using Disable site isolation in chrome://flags). Since Google Chrome 76, setting the policy to Disabled or leaving it unset doesn't turn off site isolation, but instead allows users to opt out.\r\n\r\nIsolateOrigins might also be useful for isolating specific origins at a finer granularity than site (e.g., https://a.example.com).\r\n\r\nOn Google Chrome OS version 76 and earlier, set the DeviceLoginScreenSitePerProcess device policy to the same value. (If the values don't match, a delay can occur when entering a user session.)\r\n\r\nNote: For Android, use the SitePerProcessAndroid policy instead.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess_1","displayName":"Enabled","description":null,"helpText":null}]},"d6a7d4a9e584246b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting","displayName":"Default images setting (User)","description":"Setting the policy to 1 lets all websites display images. Setting the policy to 2 denies image display.\r\n\r\nLeaving it unset allows images, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_1","displayName":"Enabled","description":null,"helpText":null}]},"d6fe7cec3f9179e7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes","displayName":"Maximum session duration allowed for remote access connections (User)","description":"If this policy is set, remote access connections will automatically disconnect after the number of minutes defined in the policy have elapsed. This does not prevent the client from reconnecting after the maximum session duration has been reached. Setting the policy to a value that is not within the min/max range may prevent the host from starting. This policy does not affect remote support scenarios.\r\n\r\nThis policy has no effect if it is not set. In this case, remote access connections will have no maximum duration on this machine.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_1","displayName":"Enabled","description":null,"helpText":null}]},"d6f3d8401f2f233c":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_cacertificatesdesc","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"d6cef70af89f0080":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled","displayName":"Re-enable the deprecated async interface for FileSystemSyncAccessHandle in File System Access API (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d67ca5c802180898":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview","displayName":"Show Formula bar in Normal View (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show formula bar\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview_1","displayName":"Enabled","description":null,"helpText":null}]},"d696fc2394e61d2e":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},"d6092a4908124c58":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it’s replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nSpecify Bing's Image Search URL Post Params as:\r\n'imageBin={google:imageThumbnailBase64}'.\r\n\r\nSpecify Google's Image Search URL Post Params as:\r\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\r\n\r\nIf you don’t set this policy, image search requests are sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},"d600562be6a3dd42":{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs (User)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d64d52928037896f":{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled","displayName":"Enables DALL-E themes generation (User)","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the AI generated themes will be enabled.\r\n\r\nIf you disable this policy, the AI generated themes will be disabled for your organization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d6f70b8502d14050":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled","displayName":"Allow users to configure Family safety (User)","description":"This policy disables and completely hides the Family safety page in Settings. Navigation to edge://settings/familysafety will also be blocked. The Family safety page describes what features are available for family groups and how to join a family group. Learn more about family safety here: (https://go.microsoft.com/fwlink/?linkid=2098432).\r\n\r\nIf you enable this policy or don't configure it, the Family safety page will be shown.\r\n\r\nIf you disable this policy, the Family safety page will not be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d65022d5248ad5bb":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (User)","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol and the protocol should be all lower case. For example, list \"skype\" instead of \"skype:\", \"skype://\" or \"Skype\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to launch an external application without prompting by policy if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ],\r\n \"protocol\": \"spotify\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ],\r\n \"protocol\": \"msteams\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"*\"\r\n ],\r\n \"protocol\": \"msoutlook\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"d6890fd4597b1b06":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"d67f9562b6a6e607":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00","displayName":"Configure presentation service in PowerPoint and Word 1 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_1","displayName":"Enabled","description":null,"helpText":null}]},"d6975678bdf7bc21":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicemajorversion1","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"d63a7e15b87c998e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_0","displayName":"Display all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_1","displayName":"Display some","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_2","displayName":"Display none","description":null,"helpText":null}]},"d662df46e887bbe3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome_l_homeadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"d628d9f9a77f946d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother","displayName":"Replace Label - Other (User)","description":"This policy setting allows you to change or remove the 8th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_1","displayName":"Enabled","description":null,"helpText":null}]},"d6741f3dd0ec5c19":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary_l_setcommentfieldsforoutlookcontactsdictionaryid","displayName":"Field identification letters: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},"d6ebfbee263c231f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin","displayName":"Display help in (User)","description":"Sets the default language of online Help. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_1","displayName":"Enabled","description":null,"helpText":null}]},"d60140b7d88f24f4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1","displayName":"Workflow Cache 1 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_1","displayName":"Enabled","description":null,"helpText":null}]},"d61405f1bffd4cdc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowfriendly501","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"d64248bb5d1179a3":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence","displayName":"Notebook Presence (User)","description":"This policy setting enables or disables the Notebook Presence feature in OneNote, which broadcasts user presence within a notebook and enables real-time synchronization for users who are editing the same page. Note: Any change to this policy does not take effect until OneNote is restarted.\r\n\r\nIf you enable or do not configure this policy setting, users are notified when they are editing the same page in a notebook as another user. OneNote also enters real-time sync when it discovers multiple users editing the same page. \r\n\r\nIf you disable this policy setting, users are not notified when they are editing the same page in a notebook as another user. OneNote does not enter real-time sync when multiple users are editing the same page.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence_1","displayName":"Enabled","description":null,"helpText":null}]},"d6f7819670e985f6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook","displayName":"Do not display \"Open this task\" button for workflow tasks (User)","description":"As part of E-mail notification of workflow tasks, users can edit a task by clicking the \"Open this task\" button to display the task dialog box for the workflow task. When this setting is enabled, the \"Open this task\" button is not displayed.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"d6d2472b47a4b06f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars","displayName":"Access to published calendars (User)","description":"This policy setting determines what restrictions apply to users who publish their calendars on Office.com or third-party World Wide Web Distributed Authoring and Versioning (WebDAV) servers. \r\n\r\nIf you enable or disable this policy setting, calendars that are published on Office.com must have restricted access (users other than the calendar owner/publisher who wish to view the calendar can only do so if they receive invitations from the calendar owner), and users cannot publish their calendars to third-party DAV servers. \r\n\r\nIf you do not configure this policy setting, users can share their calendars with others by publishing them to the Office.com Calendar Sharing Services and to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Office.com allows users to choose whether to restrict access to their calendars to people they invite, or allow unrestricted access to anyone who knows the URL to reach the calendar. DAV access restrictions can only be achieved through server and folder permissions, and might require the assistance of a server administrator to set up and maintain.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars_1","displayName":"Enabled","description":null,"helpText":null}]},"d6e7852ed112429b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity","displayName":"Disable Office connections to social networks (User)","description":"This policy setting prevents users from connecting Office to social networks (including SharePoint), and prevents Office from displaying contacts and feeds from their social networks.\r\n\r\nIf you enable this policy setting, users cannot connect Office to social networks.\r\n\r\nIf you disable or you do not configure this policy setting, users can connect Office to social networks.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity_1","displayName":"Enabled","description":null,"helpText":null}]},"d666d4797651c204":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval","displayName":"Set GAL contact synchronization interval (User)","description":"This policy setting controls how often contact information is synchronized between Outlook and connected social networks (in minutes). \r\n\r\nIf you enable this policy setting, you may specify the specified interval (in minutes) in which contact information is synchronized.\r\n\r\nIf you disable or you do not configure this policy setting, contact information is synchronized at the default interval (once every 4 days, or 5760 minutes).","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"d62cef91811bfdee":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport","displayName":"Turn off contact export (User)","description":"This policy setting controls the ability of users to export contact information from the address book.\r\n\r\nIf you enable this policy setting, the \"Add to Contacts\" menu is not configurable in the address book.\r\n\r\nIf you disable or do not configure this policy setting, the \"Add to Contacts\" menu is configurable.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport_1","displayName":"Enabled","description":null,"helpText":null}]},"d6406c479098ae4e":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"d645c851273ac9f6":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3","displayName":"Date Format (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_0","displayName":"1/31/00 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_1","displayName":"1/31/00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_20","displayName":"1/31/2000","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_2","displayName":"January 31, 2000 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_3","displayName":"January 31, 2000","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_4","displayName":"Jan 31 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_5","displayName":"Jan 31 '00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_6","displayName":"January 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_7","displayName":"Jan 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_8","displayName":"Mon 1/31/00 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_9","displayName":"Mon 1/31/00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_10","displayName":"Mon Jan 31, '00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_11","displayName":"Mon 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_15","displayName":"Mon Jan 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_16","displayName":"Mon 1/31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_17","displayName":"Mon 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_12","displayName":"1/31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_13","displayName":"31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_14","displayName":"12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_18","displayName":"W1/1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_19","displayName":"W1/1/00 12:33 PM","description":null,"helpText":null}]},"d65c4fbc66612617":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio","displayName":"Disable the Office Start screen for Visio (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Visio.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Visio.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Visio.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio_1","displayName":"Enabled","description":null,"helpText":null}]},"d6d2184fd4a2bdc7":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"d6d7156ed4ea464d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable some specific commands in Microsoft Word. Commands are buttons, menus, or other items that can be added to the Quick Access Toolbar or to the Ribbon under File tab | Options | Quick Access Toolbar or via File | Options | Customize Ribbon, respectively.\r\n\r\nIf you enable this policy setting then you can specify what commands in the user interface for Word are disabled.\r\n\r\nIf you disable or do not configure this policy setting, the commands in the predefined list are all enabled in Word.","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"d66a9e100bfbe057":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields","displayName":"Update fields before printing (User)","description":"This policy setting allows you to configure the \"Update fields before printing\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will update fields in the document before the document is printed.\r\n\r\nIf you disable or do not configure this policy setting, Word will not update fields in the document before the document is printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields_1","displayName":"Enabled","description":null,"helpText":null}]},"d6d330b009c1032c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings","displayName":"Headings (User)","description":"Checks/unchecks the option ''Built in Heading styles''.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"d66412d0068cf7e8":{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation","displayName":"Allow Marketplace App Installation","description":"When 'false', the device prevents installation of alternative marketplace apps from the web, and prevents any installed alternative marketplace apps from installing apps.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowmarketplaceappinstallation_true","displayName":"True","description":null,"helpText":null}]},"d6d84f522a1cde15":{"id":"com.apple.cellularprivatenetwork.managed_geofences_item_latitude","displayName":"Latitude","description":"The latitude of the geofence.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":null},"d6872183336c45bd":{"id":"com.apple.directoryservice.managed_adforcehomelocalflag","displayName":"AD Force Home Local Flag","description":"If true, enables the AD Force Home Local key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_adforcehomelocalflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_adforcehomelocalflag_true","displayName":"True","description":null,"helpText":null}]},"d68f2a7f1a1213e2":{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek","displayName":"Specify first day of the week","description":"Set the first day of week in calendar view.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-calendar-first-day-of-week"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":[{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_0","displayName":"Sunday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_1","displayName":"Monday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_4","displayName":"Thursday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_5","displayName":"Friday","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_calendarfirstdayofweek_6","displayName":"Saturday","description":null,"helpText":null}]},"d64bde42699d5ef5":{"id":"com.apple.managedclient.preferences_passivemode","displayName":"Enable passive mode (deprecated)","description":"Whether the antivirus engine runs in passive mode or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#enable--disable-passive-mode"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_passivemode_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_passivemode_true","displayName":"Enabled","description":null,"helpText":null}]},"d61ea4cbbc8edd72":{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\n​\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\n\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#scrolltotextfragmentenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scrolltotextfragmentenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d6e446db0c9886e5":{"id":"com.apple.system-extension-policy_allowedsystemextensions_generickey","displayName":"Allowed System Extensions","description":"The mapping of team identifiers to arrays of bundle identifiers, where the bundle identifier defines the system extension to install.","helpText":null,"infoUrls":[],"categoryId":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","categoryName":"System Extensions","options":null},"d6ed36395f7eba54":{"id":"com.apple.webcontent-filter_userdefinedname","displayName":"User Defined Name","description":"The display name for this filtering configuration.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},"d61cf110ab56b92c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users (users can override)","description":"If FriendlyURLs are enabled, Microsoft Edge computes more representations of the URL and places them on the clipboard.\n\nThis policy configures what format is pasted when the user pastes in external applications or inside Microsoft Edge without the 'Paste as' context menu item.\n\nIf you configure this policy, it makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu won't be available.\n\n* Not configured = The users are able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\n\n* 1 = No additional formats are stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge, and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature is disabled.\n\n* 3 = The user gets a friendly URL whenever they paste into surfaces that accept rich text. The plain URL is still available for nonrich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\n\n* 4 = (Not currently used)\n\nThe richer formats may not be supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\n\nThe recommended policy is available in Microsoft Edge 105 or later.\n\nPolicy options mapping:\n\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\n\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.\n\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_plaintext","displayName":"The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_titledhyperlink","displayName":"Titled Hyperlink: A hyperlink that points to the copied URL but whose visible text is the title of the destination page. This is the Friendly URL format.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurefriendlyurlformat_recommended_webpreview","displayName":"Coming soon. If set, behaves the same as 'Plain URL'.","description":null,"helpText":null}]},"d645d31bc1400155":{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled","displayName":"Prevent passwords from being deleted if any Edge settings is enabled to delete browsing data when Microsoft Edge closes","description":"When this policy is enabled, the passwords saved with Edge Password Manager are exempted from deletion when the browser closes. This policy is only effective when the \"ClearBrowsingDataOnExit\" policy is enabled.\n\nIf you enable this policy, passwords aren't cleared when the browser closes.\nIf you disable or don't configure this policy, the user's personal configuration is used.","helpText":null,"infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.passworddeleteonbrowsercloseenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d60387657445896e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled","displayName":"Enable tab preview on hover","description":"This policy controls whether Microsoft Edge displays a preview of the tab content when the user hovers over a tab.\n\nIf you enable or don't configure this policy, Microsoft Edge shows a tab preview when the user hovers over a tab.\n\nIf you disable this policy, tab previews aren't shown on hover.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showtabpreviewenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d6c98ef887b3bcdd":{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction","displayName":"Enable or disable the User-Agent Reduction (Obsolete)","description":"The User-Agent HTTP request header has been reduced by default since Microsoft Edge version 119. To continue receiving detailed platform information, migrate to User-Agent Client Hints, which replace the deprecated detailed User-Agent header. For more information, visit: https://web.dev/articles/migrate-to-ua-ch\n\nIf you don't configure this policy or set it to Default, the User-Agent header will be reduced and controlled by experimentation.\n\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header for all origins.\n\nSet this policy to 'ForceDisabled' to always use the full (legacy) User-Agent header.\n\nTo learn more about the User-Agent string, read here:\n\nhttps://go.microsoft.com/fwlink/?linkid=2186267\n\nPolicy options mapping:\n\n* Default (0) = Reduced User Agent, or controlled by experimentation.\n\n* ForceDisabled (1) = Full (legacy) User Agent.\n\n* ForceEnabled (2) = Reduced User Agent.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_default","displayName":"Reduced User Agent, or controlled by experimentation.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_forcedisabled","displayName":"Full (legacy) User Agent.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.useragentreduction_forceenabled","displayName":"Reduced User Agent.","description":null,"helpText":null}]},"d6d7271ae95c675c":{"id":"contentcaching_port","displayName":"Port","description":"The TCP port number on which the content cache accepts requests for uploads or downloads. Set to `0` to pick a random, available port.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"d689331bcdd6d4dc":{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions","displayName":"Choose how BitLocker-protected fixed drives can be recovered","description":"This policy setting allows you to control how BitLocker-protected fixed data drives are recovered in the absence of the required credentials. This policy setting is applied when you turn on BitLocker.\n\nThe \"Allow data recovery agent\" check box is used to specify whether a data recovery agent can be used with BitLocker-protected fixed data drives. Before a data recovery agent can be used it must be added from the Public Key Policies item in either the Group Policy Management Console or the Local Group Policy Editor. Consult the BitLocker Drive Encryption Deployment Guide on Microsoft TechNet for more information about adding data recovery agents.\n\nIn \"Configure user storage of BitLocker recovery information\" select whether users are allowed, required, or not allowed to generate a 48-digit recovery password or a 256-bit recovery key.\n\nSelect \"Omit recovery options from the BitLocker setup wizard\" to prevent users from specifying recovery options when they turn on BitLocker on a drive. This means that you will not be able to specify which recovery option to use when you turn on BitLocker, instead BitLocker recovery options for the drive are determined by the policy setting.\n\nIn \"Save BitLocker recovery information to Active Directory Domain Services\" choose which BitLocker recovery information to store in AD DS for fixed data drives. If you select \"Backup recovery password and key package\", both the BitLocker recovery password and key package are stored in AD DS. Storing the key package supports recovering data from a drive that has been physically corrupted. If you select \"Backup recovery password only,\" only the recovery password is stored in AD DS.\n\nSelect the \"Do not enable BitLocker until recovery information is stored in AD DS for fixed data drives\" check box if you want to prevent users from enabling BitLocker unless the computer is connected to the domain and the backup of BitLocker recovery information to AD DS succeeds.\n\nNote: If the \"Do not enable BitLocker until recovery information is stored in AD DS for fixed data drives\" check box is selected, a recovery password is automatically generated.\n\nIf you enable this policy setting, you can control the methods available to users to recover data from BitLocker-protected fixed data drives.\n\nIf this policy setting is not configured or disabled, the default recovery options are supported for BitLocker recovery. By default a DRA is allowed, the recovery options can be specified by the user including the recovery password and recovery key, and recovery information is not backed up to AD DS\n\n","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"d617db9b57141f42":{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_history","displayName":"PIN History","description":"This policy specifies the number of past PINs that can be stored in the history that can’t be used. Valid values are 0 to 50 inclusive. If this policy is set to 0, then storage of previous PINs is not required. PIN history is not preserved through PIN reset.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"d624110eb8c46e0d":{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord","displayName":"Turn off Steps Recorder","description":"This policy setting controls the state of Steps Recorder.\r\n\r\nSteps Recorder keeps a record of steps taken by the user. The data generated by Steps Recorder can be used in feedback systems such as Windows Error Reporting to help developers understand and fix problems. The data includes user actions such as keyboard input and mouse input, user interface data, and screen shots. Steps Recorder includes an option to turn on and off data collection.\r\n\r\nIf you enable this policy setting, Steps Recorder will be disabled.\r\n\r\nIf you disable or do not configure this policy setting, Steps Recorder will be enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-appcompat#admx-appcompat-appcompatturnoffuseractionrecord"],"categoryId":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","categoryName":"Application Compatibility","options":[{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_appcompat_appcompatturnoffuseractionrecord_1","displayName":"Enabled","description":null,"helpText":null}]},"d606ab9f172e4ca1":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2","displayName":"Configure Group Policy slow link detection","description":"This policy setting defines a slow connection for purposes of applying and updating Group Policy.\r\n\r\nIf the rate at which data is transferred from the domain controller providing a policy update to the computers in this group is slower than the rate specified by this setting, the system considers the connection to be slow.\r\n\r\nThe system's response to a slow policy connection varies among policies. The program implementing the policy can specify the response to a slow link. Also, the policy processing settings in this folder lets you override the programs' specified responses to slow links.\r\n\r\nIf you enable this setting, you can, in the \"Connection speed\" box, type a decimal number between 0 and 4,294,967,200, indicating a transfer rate in kilobits per second. Any connection slower than this rate is considered to be slow. If you type 0, all connections are considered to be fast.\r\n\r\nIf you disable this setting or do not configure it, the system uses the default value of 500 kilobits per second.\r\n\r\nThis setting appears in the Computer Configuration and User Configuration folders. The setting in Computer Configuration defines a slow link for policies in the Computer Configuration folder. The setting in User Configuration defines a slow link for settings in the User Configuration folder.\r\n\r\nAlso, see the \"Do not detect slow network connections\" and related policies in Computer Configuration\\Administrative Templates\\System\\User Profile. Note: If the profile server has IP connectivity, the connection speed setting is used. If the profile server does not have IP connectivity, the SMB timing is used.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-gptransferrate-2"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_gptransferrate_2_1","displayName":"Enabled","description":null,"helpText":null}]},"d6c85c126cf6ca2d":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning","displayName":"Turn on e-mail scanning","description":"This policy setting allows you to configure e-mail scanning. When e-mail scanning is enabled, the engine will parse the mailbox and mail files, according to their specific format, in order to analyze the mail bodies and attachments. Several e-mail formats are currently supported, for example: pst (Outlook), dbx, mbx, mime (Outlook Express), binhex (Mac).\r\n\r\n If you enable this setting, e-mail scanning will be enabled.\r\n\r\n If you disable or do not configure this setting, e-mail scanning will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-scan-disableemailscanning"],"categoryId":"428f107c-2167-4bc2-9293-8f1d6728a0c5","categoryName":"Scan","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_scan_disableemailscanning_1","displayName":"Enabled","description":null,"helpText":null}]},"d636b05c3d2537f3":{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy","displayName":"Microsoft Support Diagnostic Tool: Configure execution level","description":"This policy setting determines the execution level for Microsoft Support Diagnostic Tool.\r\n\r\nMicrosoft Support Diagnostic Tool (MSDT) gathers diagnostic data for analysis by support professionals.\r\n\r\nIf you enable this policy setting, administrators can use MSDT to collect and send diagnostic data to a support professional to resolve a problem.\r\n\r\nIf you disable this policy setting, MSDT cannot gather diagnostic data.\r\n\r\nIf you do not configure this policy setting, MSDT is turned on by default.\r\n\r\nThis policy setting takes effect only if the diagnostics-wide scenario execution policy is not configured.\r\n\r\nNo reboots or service restarts are required for this policy setting to take effect. Changes take effect immediately.\r\n\r\nThis policy setting will only take effect when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, diagnostic scenarios will not be executed. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msdt#admx-msdt-wdiscenarioexecutionpolicy"],"categoryId":"f926f6e3-1bd6-4259-ae7c-e14108568882","categoryName":"Microsoft Support Diagnostic Tool","options":[{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msdt_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"d6a43df760f3ae0a":{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy","displayName":"Configure MSI Corrupted File Recovery behavior","description":"This policy setting allows you to configure the recovery behavior for corrupted MSI files to one of three states:\r\n\r\nPrompt for Resolution: Detection, troubleshooting, and recovery of corrupted MSI applications will be turned on. Windows will prompt the user with a dialog box when application reinstallation is required. This is the default recovery behavior on Windows client.\r\n\r\nSilent: Detection, troubleshooting, and notification of MSI application to reinstall will occur with no UI. Windows will log an event when corruption is determined and will suggest the application that should be re-installed. This behavior is recommended for headless operation and is the default recovery behavior on Windows server.\r\n\r\nTroubleshooting Only: Detection and verification of file corruption will be performed without UI. Recovery is not attempted.\r\n\r\nIf you enable this policy setting, the recovery behavior for corrupted files is set to either the Prompt For Resolution (default on Windows client), Silent (default on Windows server), or Troubleshooting Only. \r\n\r\nIf you disable this policy setting, the troubleshooting and recovery behavior for corrupted files will be disabled. No troubleshooting or resolution will be attempted.\r\n\r\nIf you do not configure this policy setting, the recovery behavior for corrupted files will be set to the default recovery behavior.\r\n\r\nNo system or service restarts are required for changes to this policy setting to take immediate effect after a Group Policy refresh.\r\n\r\nNote: This policy setting will take effect only when the Diagnostic Policy Service (DPS) is in the running state. When the service is stopped or disabled, system file recovery will not be attempted. The DPS can be configured with the Services snap-in to the Microsoft Management Console.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-msifilerecovery#admx-msifilerecovery-wdiscenarioexecutionpolicy"],"categoryId":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","categoryName":"MSI Corrupted File Recovery","options":[{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_msifilerecovery_wdiscenarioexecutionpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"d6f1f38cbaacc80e":{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction","displayName":"User management of sharing user name, account picture, and domain information with apps (not desktop apps)","description":"This setting prevents users from managing the ability to allow apps to access the user name, account picture, and domain information.\r\n\r\nIf you enable this policy setting, sharing of user name, picture and domain information may be controlled by setting one of the following options:\r\n\r\n\"Always on\" - users will not be able to change this setting and the user's name and account picture will be shared with apps (not desktop apps). In addition apps (not desktop apps) that have the enterprise authentication capability will also be able to retrieve the user's UPN, SIP/URI, and DNS.\r\n\r\n\"Always off\" - users will not be able to change this setting and the user's name and account picture will not be shared with apps (not desktop apps). In addition apps (not desktop apps) that have the enterprise authentication capability will not be able to retrieve the user's UPN, SIP/URI, and DNS. Selecting this option may have a negative impact on certain enterprise software and/or line of business apps that depend on the domain information protected by this setting to connect with network resources.\r\n\r\nIf you do not configure or disable this policy the user will have full control over this setting and can turn it off and on. Selecting this option may have a negative impact on certain enterprise software and/or line of business apps that depend on the domain information protected by this setting to connect with network resources if users choose to turn the setting off.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userprofiles#admx-userprofiles-userinfoaccessaction"],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userprofiles_userinfoaccessaction_1","displayName":"Enabled","description":null,"helpText":null}]},"d62814665c8d0521":{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver","displayName":"System Audit I Psec Driver","description":"This policy setting allows you to audit events generated by the IPsec filter driver such as the following: Startup and shutdown of the IPsec services. Network packets dropped due to integrity check failure. Network packets dropped due to replay check failure. Network packets dropped due to being in plaintext. Network packets received with incorrect Security Parameter Index (SPI). This may indicate that either the network card is not working correctly or the driver needs to be updated. Inability to process IPsec filters. If you configure this policy setting, an audit event is generated on an IPsec filter driver operation. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated on an IPSec filter driver operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#system_auditipsecdriver"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_system_auditipsecdriver_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"d643379ad51eb7d8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir","displayName":"Set disk cache directory","description":"Setting the policy has Google Chrome use the directory you provide for storing cached files on the disk—whether or not users specify the --disk-cache-dir flag.\r\n\r\nIf not set, Google Chrome uses the default cache directory, but users can change that setting with the --disk-cache-dir command line flag.\r\n\r\nGoogle Chrome manages the contents of a volume's root directory. So to avoid data loss or other errors, do not set this policy to the root directory or any directory used for other purposes. See the variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: ${user_home}/Chrome_cache","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_diskcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},"d69797aa4971376e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains","displayName":"Suppress lookalike domain warnings on domains","description":"This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Google Chrome believes might be trying to spoof another site the user is familiar with.\r\n\r\nIf the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain.\r\n\r\nIf the policy is not set, or set to an empty list, warnings may appear on any site the user visits.\r\n\r\nA hostname can be allowed with a complete host match, or any domain match. For example, a URL like \"https://foo.example.com/bar\" may have warnings suppressed if this list includes either \"foo.example.com\" or \"example.com\".\r\n\r\nExample value:\r\n\r\nfoo.example.com\r\nexample.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"d619659d03ded868":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs","displayName":"Suppress JavaScript Dialogs triggered from different origin subframes","description":"As described in https://www.chromestatus.com/feature/5148698084376576 , JavaScript modal dialogs, triggered by window.alert, window.confirm, and window.prompt, will be blocked in Google Chrome if triggered from a subframe whose origin is different from the main frame origin.\r\nThis policy allows overriding that change.\r\nIf the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked.\r\nIf the policy is set to disabled, JavaScript dialogs triggered from a different origin subframe will not be blocked.\r\n\r\nThis policy will be removed in Google Chrome version 95.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"d67dbb7799ee5c1e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams","displayName":"Parameters for search URL which uses POST","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderSearchURLPostParams specifies the parameters when searching a URL with POST. It consists of comma-separated, name-value pairs. If a value is a template parameter, such as '{searchTerms}', real search terms data replaces it.\r\n\r\nLeaving DefaultSearchProviderSearchURLPostParams unset means search requests are sent using the GET method.\r\n\r\nExample value: q={searchTerms},ie=utf-8,oe=utf-8","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},"d6e6c3eedb715d84":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes","displayName":"The maximum size, in bytes, that can be transferred between client and host via clipboard synchronization","description":"If this policy is set, clipboard data sent to and from the host will be truncated to the limit set by this policy.\r\n\r\nIf a value of 0 is set, then clipboard sync is disabled.\r\n\r\nThis policy affects both remote access and remote support scenarios.\r\n\r\nThis policy has no effect if it is not set.\r\n\r\nSetting the policy to a value that is not within the min/max range may prevent the host from starting.\r\n\r\nPlease note that the actual upper bound for the clipboard size is based on the maximum WebRTC data channel message size which this policy does not control.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostclipboardsizebytes_1","displayName":"Enabled","description":null,"helpText":null}]},"d64c1560b29d554a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey","displayName":"Parameter controlling search term placement for the default search provider","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchprovidersearchtermsreplacementkey_1","displayName":"Enabled","description":null,"helpText":null}]},"d63ff05285a95943":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"d6296a09c42dbfae":{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardata","displayName":"Allow Cellular Data","description":"Allows the cellular data channel on the device. Device reboot is not required to enforce the policy.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-connectivity#allowcellulardata"],"categoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","categoryName":"Connectivity","options":[{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardata_0","displayName":"Do not allow the cellular data channel. The user cannot turn it on. This value is not supported in Windows 10, version 1511.","description":"Do not allow the cellular data channel. The user cannot turn it on. This value is not supported in Windows 10, version 1511.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardata_1","displayName":"Allow the cellular data channel. The user can turn it off.","description":"Allow the cellular data channel. The user can turn it off.","helpText":null},{"id":"device_vendor_msft_policy_config_connectivity_allowcellulardata_2","displayName":"Allow the cellular data channel. The user cannot turn it off.","description":"Allow the cellular data channel. The user cannot turn it off.","helpText":null}]},"d64e222fe5aed53e":{"id":"device_vendor_msft_policy_config_defender_signatureupdatefallbackorder","displayName":"Signature Update Fallback Order","description":"This policy setting allows you to define the order in which different definition update sources should be contacted. The value of this setting should be entered as a pipe-separated string enumerating the definition update sources in order. Possible values are:InternalDefinitionUpdateServerMicrosoftUpdateServerMMPCFileSharesFor example: InternalDefinitionUpdateServer | MicrosoftUpdateServer | MMPCIf you enable this setting, definition update sources will be contacted in the order specified. Once definition updates have been successfully downloaded from one specified source, the remaining sources in the list will not be contacted. If you disable or do not configure this setting, definition update sources will be contacted in a default order. OMA-URI Path: . /Vendor/MSFT/Policy/Config/Defender/SignatureUpdateFallbackOrder","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Defender#signatureupdatefallbackorder"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"d68be06f14dbbf61":{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesecuritylog","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\n\nIf you enable this policy setting, you can configure the maximum log file size to be between 20 megabytes (20480 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\n\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 20 megabytes.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-eventlogservice#eventlogservice-specifymaximumfilesizesecuritylog"],"categoryId":"a28dd311-46e8-4868-89ab-d3745c0bca21","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesecuritylog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesecuritylog_1","displayName":"Enabled","description":null,"helpText":null}]},"d605f0d685b27d33":{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesystemlog","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\n\nIf you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\n\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 1 megabyte.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-eventlogservice#eventlogservice-specifymaximumfilesizesystemlog"],"categoryId":"55a61bb8-e023-4741-8213-99995c5902e5","categoryName":"System","options":[{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesystemlog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizesystemlog_1","displayName":"Enabled","description":null,"helpText":null}]},"d66b046695063a9e":{"id":"device_vendor_msft_policy_config_feeds_feedsenabled","displayName":"Enable News and interests","description":"This policy setting specifies whether News and interests is allowed on the device.","helpText":"","infoUrls":[],"categoryId":"b260992a-8216-4bfa-b60a-4eeea1f356c9","categoryName":"News and interests","options":[{"id":"device_vendor_msft_policy_config_feeds_feedsenabled_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_feeds_feedsenabled_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"d6a71d2843718a26":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff","displayName":"Shutdown On User Logoff","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nShuts down the machine when a user logs off\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\ShutdownOnUserLogoff\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Any user, 2 = Any FSLogix Profile user","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesshutdownonuserlogoff_1","displayName":"Enabled","description":null,"helpText":null}]},"d6a13ba3f6c90e34":{"id":"device_vendor_msft_policy_config_kioskbrowser_blockedurlexceptions","displayName":"Blocked Url Exceptions","description":"List of exceptions to the blocked website URLs (with wildcard support). This is used to configure URLs kiosk browsers are allowed to navigate to, which are a subset of the blocked URLs.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#blockedurlexceptions"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},"d631b9dbffb950bb":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_2","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultwebbluetoothguardsetting_defaultwebbluetoothguardsetting_3","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},"d62f54b23aab8132":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings","description":"Configure the list of Microsoft Defender SmartScreen trusted domains. This means:\r\nMicrosoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\r\nThe Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\r\n\r\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\r\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender Advanced Threat Protection. You must configure your allow and block lists in Microsoft Defender Security Center instead.\r\n\r\nExample value:\r\n\r\nmydomain.com\r\nmyuniversity.edu","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_smartscreenallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"d65b72fb0a89bbf7":{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled","displayName":"Spell checking provided by Microsoft Editor","description":"The Microsoft Editor service provides enhanced spell and grammar checking for editable text fields on web pages.\r\n\r\nIf you enable or don't configure this policy, Microsoft Editor spell check can be used for eligible text fields.\r\n\r\nIf you disable this policy, spell check can only be provided by local engines that use platform or Hunspell services. The results from these engines might be less informative than the results Microsoft Editor can provide.\r\n\r\nIf the 'SpellcheckEnabled' (Enable spellcheck) policy is set to disabled, or the user disables spell checking in the settings page, this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_microsofteditorproofingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d604b3a702759293":{"id":"device_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge~startup_newtabpagemanagedquicklinks_newtabpagemanagedquicklinks","displayName":"Set new tab page quick links (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":null},"d6d537234a1e0549":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_exprwdexe38","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_exprwdexe38_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_localmachinezonelockdownsecurity_l_exprwdexe38_1","displayName":"True","description":null,"helpText":null}]},"d62e7b88da8d5e99":{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_globaloptionsmachine~l_customizemachine_l_defaultuithememachine","displayName":"Default Office theme","description":"This policy setting allows you to select the user interface (UI) theme used by Office, if the user has not already selected an Office theme.\r\n\r\nNote: This setting only applies to Version 1903 or later of Office.\r\n\r\nIf you enable this policy setting, you may choose the Office theme used in cases where the user has not selected an Office theme themselves.\r\n\r\nIf you disable or do not configure this policy setting, Office will use the Colorful theme in cases where the user has not selected an Office theme themselves.\r\n\r\nRegardless of how you configure this policy setting, users can change their Office theme by going to File > Account > Office Theme (or, in Outlook, by going to File > Office Account > Office Theme).\r\n\r\nNote: This policy setting takes precedence over the “Default Office theme” policy setting located under User Configuration.","helpText":"","infoUrls":[],"categoryId":"5d8272e2-1ed3-4a8d-9555-9a87fa13d078","categoryName":"Customize","options":[{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_globaloptionsmachine~l_customizemachine_l_defaultuithememachine_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_globaloptionsmachine~l_customizemachine_l_defaultuithememachine_1","displayName":"Enabled","description":null,"helpText":null}]},"d6699f145db15d9f":{"id":"device_vendor_msft_policy_config_systemservices_configurehomegroupproviderservicestartupmode","displayName":"Configure Home Group Provider Service Startup Mode","description":"This setting determines whether the service's start type is Automatic(2), Manual(3), Disabled(4). Default: Manual.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-SystemServices#configurehomegroupproviderservicestartupmode"],"categoryId":"4f29ef5c-6ca0-4b09-893f-01755a670877","categoryName":"System Services","options":null},"d6c28299cc6c9d45":{"id":"device_vendor_msft_policy_config_updateupdates.1~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_allowinstallationmicrosoftedgecanary_part_installpolicy","displayName":"Install Policy (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"device_vendor_msft_policy_config_updateupdates.1~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_allowinstallationmicrosoftedgecanary_part_installpolicy_1","displayName":"Always allow Installs (recommended)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updateupdates.1~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_allowinstallationmicrosoftedgecanary_part_installpolicy_0","displayName":"Installs disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updateupdates.1~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_allowinstallationmicrosoftedgecanary_part_installpolicy_6","displayName":"Force Installs (Per-User)","description":null,"helpText":null}]},"d6eae8f04cd491c3":{"id":"linux_mdatp_managed_antivirusengine_scanarchives","displayName":"Enable scanning of archives","description":"Specifies whether to scan archives during on-demand antivirus scans.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-preferences?view=o365-worldwide#scan-archives-on-demand-antivirus-scans-only"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_scanarchives_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_scanarchives_true","displayName":"Enabled","description":null,"helpText":null}]},"d6e32f468ba3bdff":{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution","displayName":"Allow agent execution in container","description":"Controls whether agent tools and loops can execute. The specific behavior depends on the selected agent.","helpText":"","infoUrls":[],"categoryId":"ea5fabb0-6eec-4c3e-8c6d-7523739207c3","categoryName":null,"options":[{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_0","displayName":"Don't allow","description":"Agent tool execution is not allowed","helpText":null},{"id":"user_vendor_msft_agentgovernance_{profileid}_resourcepolicy_allowagenttoolexecution_1","displayName":"Allow","description":"Agent tool execution is allowed with configured resource policies","helpText":null}]},"d6cacda81d93b758":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme","displayName":"Load a specific theme (User)","description":"Specifies which theme file is applied to the computer the first time a user logs on.\r\n\r\nIf you enable this setting, the theme that you specify will be applied when a new user logs on for the first time. This policy does not prevent the user from changing the theme or any of the theme elements such as the desktop background, color, sounds, or screen saver after the first logon.\r\n\r\nIf you disable or do not configure this setting, the default theme will be applied at the first logon.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-settheme"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_settheme_1","displayName":"Enabled","description":null,"helpText":null}]},"d63e2bafecbbe772":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werarchive_1_wermaxarchivecount","displayName":"Maximum number of reports to store: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":null},"d6429638c54aa8e4":{"id":"user_vendor_msft_policy_config_admx_globalization_turnoffoffertextpredictions","displayName":"Turn off offer text predictions as I type (User)","description":"\r\n This policy turns off the offer text predictions as I type option. This does not, however, prevent the user or an application from changing the setting programmatically.\r\n\r\n The offer text predictions as I type option controls whether or not text prediction suggestions will be presented to the user on the on-screen keyboard.\r\n\r\n If the policy is Enabled, then the option will be locked to not offer text predictions.\r\n\r\n If the policy is Disabled or Not Configured, then the user will be free to change the setting according to their preference.\r\n\r\n Note that the availability and function of this setting is dependent on supported languages being enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-turnoffoffertextpredictions"],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"user_vendor_msft_policy_config_admx_globalization_turnoffoffertextpredictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_turnoffoffertextpredictions_1","displayName":"Enabled","description":null,"helpText":null}]},"d672cc15d9eac32a":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_gpdcoptions","displayName":"Configure Group Policy domain controller selection (User)","description":"This policy setting determines which domain controller the Group Policy Object Editor snap-in uses.\r\n\r\nIf you enable this setting, you can which domain controller is used according to these options:\r\n\r\n\"Use the Primary Domain Controller\" indicates that the Group Policy Object Editor snap-in reads and writes changes to the domain controller designated as the PDC Operations Master for the domain.\r\n\r\n\"Inherit from Active Directory Snap-ins\" indicates that the Group Policy Object Editor snap-in reads and writes changes to the domain controller that Active Directory Users and Computers or Active Directory Sites and Services snap-ins use.\r\n\r\n\"Use any available domain controller\" indicates that the Group Policy Object Editor snap-in can read and write changes to any available domain controller.\r\n\r\nIf you disable this setting or do not configure it, the Group Policy Object Editor snap-in uses the domain controller designated as the PDC Operations Master for the domain.\r\n\r\nNote: To change the PDC Operations Master for a domain, in Active Directory Users and Computers, right-click a domain, and then click \"Operations Masters.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-gpdcoptions"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"user_vendor_msft_policy_config_admx_grouppolicy_gpdcoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_grouppolicy_gpdcoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"d6227f4120d79cd6":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup","displayName":"Visio 2016 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Visio 2016.\r\nMicrosoft Visio 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Visio 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Visio 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Visio 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016visiobackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016visiobackup_1","displayName":"Enabled","description":null,"helpText":null}]},"d66e88b5b3fb9721":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled","displayName":"Enable search suggestions (User)","description":"Setting the policy to True turns on search suggestions in Google Chrome's address bar. Setting the policy to False turns off these search suggestions.\r\n\r\nIf you set the policy, users can't change it. If not set, search suggestions are on at first, but users can turn them off any time.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_searchsuggestenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d63462458a764f03":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess","displayName":"Require Site Isolation for every site (User)","description":"Since Google Chrome 67, site isolation has been enabled by default on all Desktop platforms, causing every site to run in its own process. A site is a scheme plus eTLD+1 (e.g., https://example.com). Setting this policy to Enabled does not change that behavior; it only prevents users from opting out (for example, using Disable site isolation in chrome://flags). Since Google Chrome 76, setting the policy to Disabled or leaving it unset doesn't turn off site isolation, but instead allows users to opt out.\r\n\r\nIsolateOrigins might also be useful for isolating specific origins at a finer granularity than site (e.g., https://a.example.com).\r\n\r\nOn Google Chrome OS version 76 and earlier, set the DeviceLoginScreenSitePerProcess device policy to the same value. (If the values don't match, a delay can occur when entering a user session.)\r\n\r\nNote: For Android, use the SitePerProcessAndroid policy instead.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_siteperprocess_1","displayName":"Enabled","description":null,"helpText":null}]},"d6a7d4a9e584246b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting","displayName":"Default images setting (User)","description":"Setting the policy to 1 lets all websites display images. Setting the policy to 2 denies image display.\r\n\r\nLeaving it unset allows images, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultimagessetting_1","displayName":"Enabled","description":null,"helpText":null}]},"d6fe7cec3f9179e7":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes","displayName":"Maximum session duration allowed for remote access connections (User)","description":"If this policy is set, remote access connections will automatically disconnect after the number of minutes defined in the policy have elapsed. This does not prevent the client from reconnecting after the maximum session duration has been reached. Setting the policy to a value that is not within the min/max range may prevent the host from starting. This policy does not affect remote support scenarios.\r\n\r\nThis policy has no effect if it is not set. In this case, remote access connections will have no maximum duration on this machine.","helpText":"","infoUrls":[],"categoryId":"098942c3-afe3-40c8-823f-37f0b5b13ad4","categoryName":"Remote access","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~remoteaccess_remoteaccesshostmaximumsessiondurationminutes_1","displayName":"Enabled","description":null,"helpText":null}]},"d6f3d8401f2f233c":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificates_cacertificatesdesc","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"d6cef70af89f0080":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled","displayName":"Re-enable the deprecated async interface for FileSystemSyncAccessHandle in File System Access API (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d67ca5c802180898":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview","displayName":"Show Formula bar in Normal View (User)","description":"Enabling this setting selects the Advanced (Display) user option to \"Show formula bar\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_showformulabarinnormalview_1","displayName":"Enabled","description":null,"helpText":null}]},"d696fc2394e61d2e":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_networkpredictionoptions_networkpredictionoptions_2","displayName":"Don't predict network actions on any network connection","description":null,"helpText":null}]},"d6092a4908124c58":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams","displayName":"Parameters for an image URL that uses POST (User)","description":"If you enable this policy, it specifies the parameters used when an image search that uses POST is performed. The policy consists of comma-separated name/value pairs. If a value is a template parameter, like {imageThumbnail} in the preceding example, it’s replaced with real image thumbnail data. This policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nSpecify Bing's Image Search URL Post Params as:\r\n'imageBin={google:imageThumbnailBase64}'.\r\n\r\nSpecify Google's Image Search URL Post Params as:\r\n'encoded_image={google:imageThumbnail},image_url={google:imageURL},sbisrc={google:imageSearchSource},original_width={google:imageOriginalWidth},original_height={google:imageOriginalHeight}'.\r\n\r\nIf you don’t set this policy, image search requests are sent using the GET method.\r\n\r\nExample value: content={imageThumbnail},url={imageURL},sbisrc={SearchSource}","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurlpostparams_1","displayName":"Enabled","description":null,"helpText":null}]},"d600562be6a3dd42":{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled","displayName":"Configure auto discard sleeping tabs (User)","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~sleepingtabs_autodiscardsleepingtabsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d64d52928037896f":{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled","displayName":"Enables DALL-E themes generation (User)","description":"This policy lets you generate browser themes using DALL-E and apply them to Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the AI generated themes will be enabled.\r\n\r\nIf you disable this policy, the AI generated themes will be disabled for your organization.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_aigenthemesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d6f70b8502d14050":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled","displayName":"Allow users to configure Family safety (User)","description":"This policy disables and completely hides the Family safety page in Settings. Navigation to edge://settings/familysafety will also be blocked. The Family safety page describes what features are available for family groups and how to join a family group. Learn more about family safety here: (https://go.microsoft.com/fwlink/?linkid=2098432).\r\n\r\nIf you enable this policy or don't configure it, the Family safety page will be shown.\r\n\r\nIf you disable this policy, the Family safety page will not be shown.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_familysafetysettingsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d65022d5248ad5bb":{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins","displayName":"Define a list of protocols that can launch an external application from listed origins without prompting the user (User)","description":"Allows you to set a list of protocols, and for each protocol an associated list of allowed origin patterns, that can launch an external application without prompting the user. The trailing separator should not be included when listing the protocol and the protocol should be all lower case. For example, list \"skype\" instead of \"skype:\", \"skype://\" or \"Skype\".\r\n\r\nIf you configure this policy, a protocol will only be permitted to launch an external application without prompting by policy if:\r\n\r\n- the protocol is listed\r\n\r\n- the origin of the site trying to launch the protocol matches one of the origin patterns in that protocol's allowed_origins list.\r\n\r\nIf either condition is false, the external protocol launch prompt will not be omitted by policy.\r\n\r\nIf you don't configure this policy, no protocols can launch without a prompt. Users can opt out of prompts on a per-protocol/per-site basis unless the 'ExternalProtocolDialogShowAlwaysOpenCheckbox' (Show an \"Always open\" checkbox in external protocol dialog) policy is set to Disabled. This policy has no impact on per-protocol/per-site prompt exemptions set by users.\r\n\r\nThe origin matching patterns use a similar format to those for the 'URLBlocklist' (Block access to a list of URLs) policy, which are documented at https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nHowever, origin matching patterns for this policy cannot contain \"/path\" or \"@query\" elements. Any pattern that does contain a \"/path\" or \"@query\" element will be ignored.\r\n\r\nThis policy does not work as expected with file://* wildcards.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"allowed_origins\": [\r\n \"example.com\",\r\n \"http://www.example.com:8080\"\r\n ],\r\n \"protocol\": \"spotify\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"https://example.com\",\r\n \"https://.mail.example.com\"\r\n ],\r\n \"protocol\": \"msteams\"\r\n },\r\n {\r\n \"allowed_origins\": [\r\n \"*\"\r\n ],\r\n \"protocol\": \"msoutlook\"\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_autolaunchprotocolsfromorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"d6890fd4597b1b06":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"d67f9562b6a6e607":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00","displayName":"Configure presentation service in PowerPoint and Word 1 (User)","description":"This policy setting allows you to add a presentation service to the list of online presentation services in PowerPoint and Word. This list appears when a user selects the More services link under Present Online on the Share tab in Backstage view in PowerPoint and Word and in the ribbon in PowerPoint.\r\n\r\nIf you enable this policy setting, you can add a presentation service to the list of online presentation services in PowerPoint and Word. For each service you add, you must specify a name and URL. Optionally, you can specify a description, the URL of a web page with more information about the service, and the URL of a web page with service terms that the user can display by selecting the Service Agreement link. \r\n\r\nIf you disable or do not configure this policy setting, the More services link displays only services that are manually added by users.","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_1","displayName":"Enabled","description":null,"helpText":null}]},"d6975678bdf7bc21":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice01_l_broadcastservicemajorversion1","displayName":"Server Major Version: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":null},"d63a7e15b87c998e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_0","displayName":"Display all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_1","displayName":"Display some","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_configurepresenceicons_l_configurepresenceiconsdropid_2","displayName":"Display none","description":null,"helpText":null}]},"d662df46e887bbe3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplacehome_l_homeadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"d628d9f9a77f946d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother","displayName":"Replace Label - Other (User)","description":"This policy setting allows you to change or remove the 8th label on the Contact Tab, which is on the Contact Card. The default values for the Contact Tab labels are Email (email address), Work (work phone), Work2 (work phone 2), WorkFax (work fax), Mobile (mobile phone), Home (home phone), Home2 (home phone 2), Other (other phone), IM (IM address), Profile (profile), Office (office location), Company (company), WorkAdd (work address), HomeAdd (home address), OtherAdd (other address), Birthday (birthday) . \r\n\r\nIf you enable this policy setting, you can change or remove the labels on their Contact Tab by entering a new text string in the text box below. \r\n\r\nIf you disable or do not configure this policy setting, the default label is displayed.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplaceother_1","displayName":"Enabled","description":null,"helpText":null}]},"d6741f3dd0ec5c19":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setcommentfieldsforoutlookcontactsdictionary_l_setcommentfieldsforoutlookcontactsdictionaryid","displayName":"Field identification letters: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":null},"d6ebfbee263c231f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin","displayName":"Display help in (User)","description":"Sets the default language of online Help. In addition to configuring this setting, consider enabling the same language in the 'Enabled Editing Languages' policy node.","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_displayhelpin_1","displayName":"Enabled","description":null,"helpText":null}]},"d60140b7d88f24f4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1","displayName":"Workflow Cache 1 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_1","displayName":"Enabled","description":null,"helpText":null}]},"d61405f1bffd4cdc":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowfriendly501","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"d64248bb5d1179a3":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence","displayName":"Notebook Presence (User)","description":"This policy setting enables or disables the Notebook Presence feature in OneNote, which broadcasts user presence within a notebook and enables real-time synchronization for users who are editing the same page. Note: Any change to this policy does not take effect until OneNote is restarted.\r\n\r\nIf you enable or do not configure this policy setting, users are notified when they are editing the same page in a notebook as another user. OneNote also enters real-time sync when it discovers multiple users editing the same page. \r\n\r\nIf you disable this policy setting, users are not notified when they are editing the same page in a notebook as another user. OneNote does not enter real-time sync when multiple users are editing the same page.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_notebookpresence_1","displayName":"Enabled","description":null,"helpText":null}]},"d6f7819670e985f6":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook","displayName":"Do not display \"Open this task\" button for workflow tasks (User)","description":"As part of E-mail notification of workflow tasks, users can edit a task by clicking the \"Open this task\" button to display the task dialog box for the workflow task. When this setting is enabled, the \"Open this task\" button is not displayed.","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_workflowtasksinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"d6d2472b47a4b06f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars","displayName":"Access to published calendars (User)","description":"This policy setting determines what restrictions apply to users who publish their calendars on Office.com or third-party World Wide Web Distributed Authoring and Versioning (WebDAV) servers. \r\n\r\nIf you enable or disable this policy setting, calendars that are published on Office.com must have restricted access (users other than the calendar owner/publisher who wish to view the calendar can only do so if they receive invitations from the calendar owner), and users cannot publish their calendars to third-party DAV servers. \r\n\r\nIf you do not configure this policy setting, users can share their calendars with others by publishing them to the Office.com Calendar Sharing Services and to a server that supports the World Wide Web Distributed Authoring and Versioning (WebDAV) protocol. Office.com allows users to choose whether to restrict access to their calendars to people they invite, or allow unrestricted access to anyone who knows the URL to reach the calendar. DAV access restrictions can only be achieved through server and folder permissions, and might require the assistance of a server administrator to set up and maintain.","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_accesstopublishedcalendars_1","displayName":"Enabled","description":null,"helpText":null}]},"d6e7852ed112429b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity","displayName":"Disable Office connections to social networks (User)","description":"This policy setting prevents users from connecting Office to social networks (including SharePoint), and prevents Office from displaying contacts and feeds from their social networks.\r\n\r\nIf you enable this policy setting, users cannot connect Office to social networks.\r\n\r\nIf you disable or you do not configure this policy setting, users can connect Office to social networks.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_preventsocialnetworkconnectivity_1","displayName":"Enabled","description":null,"helpText":null}]},"d666d4797651c204":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval","displayName":"Set GAL contact synchronization interval (User)","description":"This policy setting controls how often contact information is synchronized between Outlook and connected social networks (in minutes). \r\n\r\nIf you enable this policy setting, you may specify the specified interval (in minutes) in which contact information is synchronized.\r\n\r\nIf you disable or you do not configure this policy setting, contact information is synchronized at the default interval (once every 4 days, or 5760 minutes).","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_setgalcontactsynchronizationinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"d62cef91811bfdee":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport","displayName":"Turn off contact export (User)","description":"This policy setting controls the ability of users to export contact information from the address book.\r\n\r\nIf you enable this policy setting, the \"Add to Contacts\" menu is not configurable in the address book.\r\n\r\nIf you disable or do not configure this policy setting, the \"Add to Contacts\" menu is configurable.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_turnoffcontactexport_1","displayName":"Enabled","description":null,"helpText":null}]},"d6406c479098ae4e":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc11_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"d645c851273ac9f6":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3","displayName":"Date Format (User)","description":"","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_0","displayName":"1/31/00 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_1","displayName":"1/31/00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_20","displayName":"1/31/2000","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_2","displayName":"January 31, 2000 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_3","displayName":"January 31, 2000","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_4","displayName":"Jan 31 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_5","displayName":"Jan 31 '00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_6","displayName":"January 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_7","displayName":"Jan 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_8","displayName":"Mon 1/31/00 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_9","displayName":"Mon 1/31/00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_10","displayName":"Mon Jan 31, '00","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_11","displayName":"Mon 12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_15","displayName":"Mon Jan 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_16","displayName":"Mon 1/31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_17","displayName":"Mon 31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_12","displayName":"1/31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_13","displayName":"31","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_14","displayName":"12:33 PM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_18","displayName":"W1/1","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_l_pjdateformat3_19","displayName":"W1/1/00 12:33 PM","description":null,"helpText":null}]},"d65c4fbc66612617":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio","displayName":"Disable the Office Start screen for Visio (User)","description":"This policy setting controls whether the Office Start screen appears on boot for Visio.\r\n\r\nIf you enable this policy setting, users will not see the Office Start screen when they boot Visio.\r\n\r\nIf you disable or do not configure this policy setting, users will see the Office Start screen when they boot Visio.\r\n\r\nNote: This policy setting is overridden by the policy setting \"Microsoft Office 2016 > Miscellaneous > Disable the Office Start screen for all Office applications\" if that policy setting is set.","helpText":"","infoUrls":[],"categoryId":"e6f727b7-f474-4010-b214-83149ffdac2b","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_miscellaneous_l_disableofficestartvisio_1","displayName":"Enabled","description":null,"helpText":null}]},"d6d2184fd4a2bdc7":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"d6d7156ed4ea464d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems","displayName":"Disable commands (User)","description":"This policy setting allows you to disable some specific commands in Microsoft Word. Commands are buttons, menus, or other items that can be added to the Quick Access Toolbar or to the Ribbon under File tab | Options | Quick Access Toolbar or via File | Options | Customize Ribbon, respectively.\r\n\r\nIf you enable this policy setting then you can specify what commands in the user interface for Word are disabled.\r\n\r\nIf you disable or do not configure this policy setting, the commands in the predefined list are all enabled in Word.","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_1","displayName":"Enabled","description":null,"helpText":null}]},"d66a9e100bfbe057":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields","displayName":"Update fields before printing (User)","description":"This policy setting allows you to configure the \"Update fields before printing\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will update fields in the document before the document is printed.\r\n\r\nIf you disable or do not configure this policy setting, Word will not update fields in the document before the document is printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatefields_1","displayName":"Enabled","description":null,"helpText":null}]},"d6d330b009c1032c":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings","displayName":"Headings (User)","description":"Checks/unchecks the option ''Built in Heading styles''.","helpText":"","infoUrls":[],"categoryId":"62492a4c-fd70-4275-ae5e-d60e200e3553","categoryName":"Apply as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_applyasyoutype_l_headings_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/d7.json b/public/intune-definitions/d7.json index 5cb99e7263ed..1ca06de760ed 100644 --- a/public/intune-definitions/d7.json +++ b/public/intune-definitions/d7.json @@ -1 +1 @@ -{"d7d85fa56029d924":{"id":"com.apple.applicationaccess_allowbluetoothmodification","displayName":"Allow Bluetooth Modification","description":"If false, prevents modification of Bluetooth settings. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbluetoothmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbluetoothmodification_true","displayName":"True","description":null,"helpText":null}]},"d781aeb1efc4b08f":{"id":"com.apple.assetcache.managed_publicranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_publicranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_publicranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},"d76941b42180069e":{"id":"com.apple.finder_com.apple.finder","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":null},"d7eb5149bf24d4c8":{"id":"com.apple.managedclient.preferences_audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiocaptureallowedurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"d7c50faec4bfed34":{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy","displayName":"Allow cloud-based Microsoft Edge management service user policies to override local user policies.","description":"If you enable this policy, cloud-based Microsoft Edge management service user policies takes precedence if it conflicts with local user policy.\n\nIf you disable or don't configure this policy, Microsoft Edge management service user policies will take precedence.\n\nThe policy can be combined with \"EdgeManagementPolicyOverridesPlatformPolicy\". If both policies are enabled, all cloud-based Microsoft Edge management service policies will take precedence over conflicting local service policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementuserpolicyoverridescloudmachinepolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy_true","displayName":"Enabled","description":null,"helpText":null}]},"d7f3cad41314ef81":{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (Deprecated)","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Private Network Access checks.\n\nIf this policy is not set, this policy behaves as if set to the empty list.\n\nFor origins not covered by the patterns specified here, the global default value will be used either from the \"InsecurePrivateNetworkRequestsAllowed\" policy, if it is set, or the user's personal configuration otherwise.\n\nFor detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecureprivatenetworkrequestsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"d7ba047cbfd2fb0a":{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank","description":"If you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel=\"opener\".\n\nIf you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.\n\nThis policy will be obsoleted in Microsoft Edge version 95.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#targetblankimpliesnoopener"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener_true","displayName":"Enabled","description":null,"helpText":null}]},"d7ec6a3ecdaadbd4":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"d79f33d501224fc9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled","displayName":"Enable Standardized Browser Zoom Behavior","description":"Configures whether the CSS \"zoom\" property follows the current CSS specification or legacy behavior.\n\nWhen this policy is enabled or not configured, the CSS \"zoom\" property follows the current specification defined by the CSS Working Group:\nhttps://drafts.csswg.org/css-viewport/#zoom-property\n\nWhen this policy is disabled, the CSS \"zoom\" property uses its legacy, pre-standardized behavior.\n\nThis policy is temporary and is intended to provide time for organizations to migrate web content to the updated behavior. In a future Microsoft Edge release, this policy will be removed and the standardized behavior will be enforced by default.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d7a5201c88f366ad":{"id":"device_vendor_msft_defender_configuration_archivemaxsize","displayName":"Archive Max Size","description":"Specify the maximum size, in KB, of archive files to be extracted and scanned. If this configuration is off or not set, the default value (0) is applied, and all archives are extracted and scanned regardless of size.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"d7e49f121dce5465":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout_reporting_recentlycleanedtimeout","displayName":"Configure time out for detections in recently remediated state","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},"d731d9fa930327b5":{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy","displayName":"Notify blocked drivers","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectblockeddriverspolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"d7b1dc00e81b0056":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_ts_program_name","displayName":"Program path and file name","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},"d7fa2deef68ae3ff":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote","displayName":"Microsoft OneNote 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2016.\r\nBy default, the user settings of Microsoft OneNote 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_1","displayName":"Enabled","description":null,"helpText":null}]},"d73bd790f9a31a24":{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly","displayName":"Require Private Store Only","description":"Allows disabling of the retail catalog and only enables the Private store. Most restricted value is 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#requireprivatestoreonly"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly_0","displayName":"Allow both public and Private store.","description":"Allow both public and Private store.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly_1","displayName":"Only Private store is enabled.","description":"Only Private store is enabled.","helpText":null}]},"d790396fcb19c63e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended","displayName":"Enable network prediction","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d7827f00e36a2b49":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification","displayName":"Notify a user that a browser relaunch or device restart is recommended or required","description":"Notify users that Google Chrome must be relaunched or Google Chrome OS must be restarted to apply a pending update.\r\n\r\nThis policy setting enables notifications to inform the user that a browser relaunch or device restart is recommended or required. If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google Chrome OS indicates such via a notification in the system tray. If set to 'Recommended', a recurring warning will be shown to the user that a relaunch is recommended. The user can dismiss this warning to defer the relaunch. If set to 'Required', a recurring warning will be shown to the user indicating that a browser relaunch will be forced once the notification period passes. The default period is seven days for Google Chrome and four days for Google Chrome OS, and may be configured via the RelaunchNotificationPeriod policy setting.\r\n\r\nThe user's session is restored following the relaunch/restart.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"d7e098dac63ca01c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Do not allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},"d73984e8ca8023ab":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled","displayName":"Enable Instant","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d7ed1bf32dc95adc":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls","displayName":"Automatically grant permission to sites to connect to any HID device.","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available devices.\r\n\r\nThe URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered.\r\n\r\nOn ChromeOS, this policy only applies to affiliated users.\r\n\r\nThis policy overrides DefaultWebHidGuardSetting, WebHidAskForUrls, WebHidBlockedForUrls and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"d7976fdbc0e50c61":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled","displayName":"Determines whether the Chrome Root Store and built-in certificate verifier will be used to verify server certificates","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d729891ad271f8c6":{"id":"device_vendor_msft_policy_config_deviceinstallation_preventdevicemetadatafromnetwork","displayName":"Prevent automatic download of applications associated with device metadata","description":"This policy setting allows you to prevent Windows from downloading applications associated with device metadata.\n\nIf you enable this policy setting, Windows does not download applications associated with device metadata for installed devices. This policy setting overrides the setting in the Device Installation Settings dialog box (Control Panel > System and Security > System > Advanced System Settings > Hardware tab).\n\nIf you disable or do not configure this policy setting, the setting in the Device Installation Settings dialog box controls whether Windows downloads applications associated with device metadata.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_deviceinstallation_preventdevicemetadatafromnetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deviceinstallation_preventdevicemetadatafromnetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"d706340c73b9416d":{"id":"device_vendor_msft_policy_config_humanpresence_forceinstantlock","displayName":"Force Instant Lock","description":"Determines whether Lock on Leave is forced on/off by the MDM policy. The user will not be able to change this setting and the toggle in the UI will be greyed out.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-HumanPresence#forceinstantlock"],"categoryId":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","categoryName":"Human Presence","options":[{"id":"device_vendor_msft_policy_config_humanpresence_forceinstantlock_2","displayName":"Forced Off.","description":"ForcedOff.","helpText":null},{"id":"device_vendor_msft_policy_config_humanpresence_forceinstantlock_1","displayName":"Forced On.","description":"ForcedOn.","helpText":null},{"id":"device_vendor_msft_policy_config_humanpresence_forceinstantlock_0","displayName":"Default To User Choice.","description":"DefaultToUserChoice.","helpText":null}]},"d756c14e606ac76b":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzonenavigatewindowsandframes"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"d7826d719b2fa053":{"id":"device_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons","displayName":"Enable Navigation Buttons","description":"Enable/disable kiosk browser's navigation buttons (forward/back).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enablenavigationbuttons"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"device_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons_0","displayName":"Disable","description":"Disable","helpText":null}]},"d72717aadcb7b577":{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},"d747e1d9af066414":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended","displayName":"Configure auto discard sleeping tabs","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d7e59a7375d157ec":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\r\n\r\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\r\n\r\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\r\n\r\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\r\n\r\nIf you enable this policy, the Copilot new tab page is turned on.\r\n\r\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d7ef8107907e5a55":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\r\n​\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d764eb3285f84b05":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_mspubexe16","displayName":"mspub.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_mspubexe16_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_mspubexe16_1","displayName":"True","description":null,"helpText":null}]},"d77628513db90d26":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups","displayName":"Block popups","description":"Block popups","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_1","displayName":"Enabled","description":null,"helpText":null}]},"d716186af9b278b4":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites","displayName":"Configure team site libraries to sync automatically","description":"This setting lets you specify SharePoint team site libraries to sync automatically the next time users sign in to the OneDrive sync app (OneDrive.exe). It may take up to 8 hours after a users signs in before the library begins to sync. To use the setting, you must enable OneDrive Files On-Demand, and the setting applies only for users on computers running Windows 10 (1709) Fall Creators Update or later. Do not enable this setting for the same library to more than 1,000 devices. To ensure a good sync experience, avoid enabling this feature on large libraries sets (For the most up to date guidance see https://docs.microsoft.com/en-us/onedrive/use-group-policy#AutoMountTeamSites). This feature is not enabled for on-premises SharePoint sites.\r\n \r\nIf you enable this setting, the OneDrive sync app will automatically download the contents of the libraries you specified as online-only files the next time the user signs in. The user won't be able to stop syncing the libraries.\r\n \r\nIf you disable this setting, team site libraries that you've specified won't be automatically synced for new users. Existing users can choose to stop syncing the libraries, but the libraries won't stop syncing automatically.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_1","displayName":"Enabled","description":null,"helpText":null}]},"d790c8737cba459b":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstasks","displayName":"Let Apps Access Tasks","description":"This policy setting specifies whether Windows apps can access tasks.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstasks"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"d76109f54941679b":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_enforcefirewall","displayName":"Enable firewall protection of Microsoft endpoints","description":"","helpText":"","infoUrls":[],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":[{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_enforcefirewall_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_enforcefirewall_1","displayName":"True","description":null,"helpText":null}]},"d7db3edf5658892e":{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_v2","displayName":"Auto Restart Notification Schedule","description":"Allows the IT Admin to specify the period for auto-restart reminder notifications. The default value is 15 (minutes).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#autorestartnotificationschedule"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_15","displayName":"15 Minutes","description":"15 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_30","displayName":"30 Minutes","description":"30 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_60","displayName":"60 Minutes","description":"60 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_120","displayName":"120 Minutes","description":"120 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_240","displayName":"240 Minutes","description":"240 Minutes","helpText":null}]},"d716655af6137cbb":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_removedesktopshortcutmicrosoftedgecanary","displayName":"Remove Desktop Shortcuts upon update","description":"If you set this policy to \"Force delete system-level Desktop Shortcuts\" (1), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots.\r\n If you set this policy to \"Force delete system-level and user-level Desktop Shortcuts\" (2), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots and any existing user-level desktop shortcuts will be deleted when the browser updates. This includes user-level desktop shortcuts that users might have made themselves.\r\n If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts.\r\n\r\n If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_removedesktopshortcutmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_removedesktopshortcutmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},"d7fcb1d9ee46e6eb":{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_rollbacktotargetversionmicrosoftedgebeta","displayName":"Rollback to Target version","description":"Specifies that Microsoft Edge Update should rollback installations of Microsoft Edge to the version indicated in 'Target version override'.\r\n\r\nThis policy has no effect unless 'Target version override' is set and 'Update policy override' is set to one of the ON states (Always allow updates, Automatic silent updates only, Manual updates only).\r\n\r\nIf you disable this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is.\r\n\r\nIf you enable this policy, installs that have a current version higher than specified by the 'Target version override' will be downgraded to the target version.\r\n\r\nWe recommend that users install the latest version of the Microsoft Edge browser to ensure protection by the latest security updates. Rollback to an earlier version risks exposure to known security issues. This policy is meant to be used as a temporary fix to address issues in a Microsoft Edge browser update.\r\n\r\nBefore temporarily rolling back your browser version, we recommend that you turn on Sync (https://go.microsoft.com/fwlink/?linkid=2133032) for all users in your organization. If you don't turn on Sync, there is a risk of permanent browsing data loss. Use this policy at your own risk.\r\n\r\nNote: All versions available for rollback can be viewed here https://aka.ms/EdgeEnterprise.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.\r\n\r\nThis policy applies to Microsoft Edge version 86 or later.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2133918 for more information. This policy is meant to serve as temporary measure when Enterprise Administrators need to downgrade for business reasons. To ensure users are protected by the latest security updates, the most recent version should be used. When versions are downgraded to older versions, there could be incompatibilities.","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":[{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_rollbacktotargetversionmicrosoftedgebeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_rollbacktotargetversionmicrosoftedgebeta_1","displayName":"Enabled","description":null,"helpText":null}]},"d7da18c7fc6577f3":{"id":"device_vendor_msft_policy_config_userrights_enabledelegation","displayName":"Enable Delegation","description":"This user right determines which users can set the Trusted for Delegation setting on a user or computer object. The user or object that is granted this privilege must have write access to the account control flags on the user or computer object. A server process running on a computer (or under a user context) that is trusted for delegation can access resources on another computer using delegated credentials of a client, as long as the client account does not have the Account cannot be delegated account control flag set. Caution: Misuse of this user right, or of the Trusted for Delegation setting, could make the network vulnerable to sophisticated attacks using Trojan horse programs that impersonate incoming clients and use their credentials to gain access to network resources.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#enabledelegation"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"d7ddf3071fed4be0":{"id":"user_vendor_msft_policy_config_admx_controlpanel_disallowcpls_disallowcplslist","displayName":"List of disallowed Control Panel items (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"d70ae96b6527b163":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_1","displayName":"Do not throttle additional data (User)","description":"This policy setting determines whether Windows Error Reporting (WER) sends additional, second-level report data even if a CAB file containing data about the same event types has already been uploaded to the server.\r\n\r\nIf you enable this policy setting, WER does not throttle data; that is, WER uploads additional CAB files that can contain data about the same event types as an earlier uploaded report.\r\n\r\nIf you disable or do not configure this policy setting, WER throttles data by default; that is, WER does not upload more than one CAB file for a report that contains data about the same event types.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassdatathrottling-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_1_1","displayName":"Enabled","description":null,"helpText":null}]},"d72eefb6239a9e09":{"id":"user_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_1","displayName":"Floppy Drives: Deny read access (User)","description":"This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denyread-access-1"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"user_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_1_1","displayName":"Enabled","description":null,"helpText":null}]},"d7c95ba6e0953692":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8","displayName":"Internet Explorer 8 (User)","description":"This policy setting configures the synchronization of user settings for Internet Explorer 8.\r\nBy default, the user settings of Internet Explorer 8 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 8 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 8 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 8 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer8"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8_1","displayName":"Enabled","description":null,"helpText":null}]},"d770f001895e2516":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup","displayName":"Access 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Access 2013.\r\nMicrosoft Access 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Access 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Access 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Access 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013accessbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"d76a6a33d6a2557b":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-internet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet_1","displayName":"Enabled","description":null,"helpText":null}]},"d70676bf2d32b2a8":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown","displayName":"Allow OpenSearch queries in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-internetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"d7cf738bb02fe5fc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d7a2b2bb89befad4":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls","displayName":"Block Window Placement permission on these sites (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"d7986e6e5cf1031f":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"d758f950007f7900":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe","displayName":"Launching applications and files in an IFRAME (User)","description":"This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.\n\nIf you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.\n\nIf you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.\n\nIf you do not configure this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonelaunchingapplicationsandfilesiniframe"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_1","displayName":"Enabled","description":null,"helpText":null}]},"d7223e7ce16ef127":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled","displayName":"Enable favorites bar (User)","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d74cf98090f0e546":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\r\n\r\nThis policy is optional. If you don't configure it, image search isn't available.\r\n\r\nSpecify Bing's Image Search URL as:\r\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\r\n\r\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\r\n\r\nSee 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_1","displayName":"Enabled","description":null,"helpText":null}]},"d7729f62e8ec8128":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled","displayName":"Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 114.\r\n\r\nWhen this policy is set to enabled, Microsoft Edge will perform verification of server certificates using the built-in certificate verifier with the Microsoft Root Store as the source of public trust.\r\n\r\nWhen this policy is set to disabled, Microsoft Edge will use the system certificate verifier and system root certificates.\r\n\r\nWhen this policy is not set, the Microsoft Root Store or system provided roots may be used.\r\n\r\nThis policy is planned to be removed in Microsoft Edge version\r\n121 for Android devices when support for using the platform supplied roots is planned to be removed.\r\n\r\nThis policy was removed in Microsoft Edge version 115 for\r\nMicrosoft Windows and macOS,\r\nMicrosoft Edge version 120 for\r\nLinux, and\r\nMicrosoft Edge version 121 for\r\nAndroid\r\nwhen support for using the platform supplied certificate verifier and roots was removed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d76ee11b4db3df47":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2_1","displayName":"True","description":null,"helpText":null}]},"d7bb06e9aa5146c0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor","displayName":"Prompt for sending reviewed document to author (User)","description":"\"Never ask user\": Do not ask users if they want to send back changes to the author. | \"Prompt for 'send for review\"': Ask users if they want to send back changes to the author only if the document was sent using Send For Review and not with ad-hoc review. | \"Always prompt\": Ask users if they want to send back changes to the author for documents sent using either Send For Review or ad-hoc review.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_1","displayName":"Enabled","description":null,"helpText":null}]},"d7732b1276b559e9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly","displayName":"Italian (Italy) (User)","description":"Enables the editing language Italian (Italy)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly_1","displayName":"Enabled","description":null,"helpText":null}]},"d738ab2b0f965f37":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache","displayName":"Delete files from Office Document Cache (User)","description":"This policy setting determines whether or not documents opened in Office are deleted from the Office Document Cache when they are closed.\r\n\r\nIf you enable this policy setting documents are deleted from the Office Document Cache when they are closed. \r\n\r\nIf you disable or do not configure this policy setting, documents are not deleted from the Office Document Cache when they are closed.\r\n\r\nNote: This policy setting does not apply to documents in SharePoint Workspace. Documents in SharePoint Workspace will not be deleted from the Office Document cache when they are closed. Sharepoint Workspace will not work correctly if this Group Policy is enabled.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache_1","displayName":"Enabled","description":null,"helpText":null}]},"d72f56a773ad1f54":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs","displayName":"Disable web view in the Office file dialog boxes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"d7b64b6f2d45d0ec":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowcachename433","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"d7e3476238bb1262":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowfriendly446","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"d7f75625700fe816":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage_1","displayName":"True","description":null,"helpText":null}]},"d7a598ce91610b91":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency","displayName":"Weather Bar Update Frequency (User)","description":"This policy setting allows you to set the update frequency (in minutes) for the Weather Bar. \r\n\r\nIf you enable this policy setting, Outlook sets the update frequency to the specified value. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default value of 120 minutes.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_1","displayName":"Enabled","description":null,"helpText":null}]},"d7395482976d107a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting","displayName":"Do not display hit highlights in search results (User)","description":"By default, hit highlights are included in search results. Enable this setting to turn off search hit highlighting.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting_1","displayName":"Enabled","description":null,"helpText":null}]},"d7896bd758feba19":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones","displayName":"Do not permit download of content from safe zones (User)","description":"This policy setting controls whether Outlook automatically downloads content from safe zones when displaying messages. \r\n\r\nIf you enable this policy setting content from safe zones will be downloaded automatically. \r\n\r\nIf you disable this policy Outlook will not automatically download content from safe zones. Recipients can choose to download external content from untrusted senders on a message-by-message basis. \r\n\r\nIf you do not configure this policy setting, Outlook automatically downloads content from sites that are considered \"safe,\" as defined in the Security tab of the Internet Options dialog box in Internet Explorer. \r\n\r\nImportant - Note that this policy setting is \"backward.\" Despite the name, disabling the policy setting prevents the download of content from safe zones and enabling the policy setting allows it.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones_1","displayName":"Enabled","description":null,"helpText":null}]},"d7ebd52066ba11ce":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt_1","displayName":"True","description":null,"helpText":null}]},"d73eef78949e8d55":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp","displayName":"Suppress file format compatibility dialog box for OpenDocument Presentation format (User)","description":"This policy setting allows you to enable or disable the file format compatibility dialog box when saving a file as an OpenDocument presentation file in Microsoft PowerPoint.\r\n\r\nIf you enable this policy, the file format compatibility dialog is displayed whenever you save as an OpenDocument presentation file in PowerPoint.\r\n\r\nIf you disable this policy, the file format compatibility dialog is not displayed when you save as an OpenDocument presentation file in PowerPoint.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp_1","displayName":"Enabled","description":null,"helpText":null}]},"d7dabcc1d7edaf47":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon4","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"d7c0bef7d7961352":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor","displayName":"Search for: (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_1","displayName":"Enabled","description":null,"helpText":null}]},"d7fe55a1b6e66831":{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots","displayName":"Set Maximum Storage Duration For Recall Snapshots (User)","description":"This policy setting allows you to control the maximum amount of time (in days) that Windows saves snapshots for Recall. The default value for this setting is '0' which doesn't set a time frame to delete snapshots. When the default is used, snapshots aren't deleted until the maximum storage allocation for Recall is reached and the oldest snapshots are deleted first. You can configure the maximum storage duration to be 30, 60, 90, or 180 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragedurationforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_0","displayName":"Let the OS define the maximum amount of time the snapshots will be saved","description":"Let the OS define the maximum amount of time the snapshots will be saved","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_30","displayName":"30 days","description":"30 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_60","displayName":"60 days","description":"60 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_90","displayName":"90 days","description":"90 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_180","displayName":"180 days","description":"180 days","helpText":null}]},"d78859a1e3974e00":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano","displayName":"Match ia/iya (piano/piyano) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano_1","displayName":"Enabled","description":null,"helpText":null}]},"d71e655d28c4f280":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_localportranges","displayName":"Local Port Ranges","description":"Comma Separated list of ranges for eg. 100-120,200,300-320. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file +{"d79d28e74677ad2e":{"id":"com.android.devicerestrictionpolicy.maxdayswithworkoff","displayName":"Maximum days to turn off work profile","description":"Set the maximum number of days a work profile can be turned off before the work profile is removed. Value of 0 means no limit. Available for corporate-owned work profile (COPE) devices running Android 11+.","helpText":"Enter a number (0-365). 0 means no limit.","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":null},"d7d85fa56029d924":{"id":"com.apple.applicationaccess_allowbluetoothmodification","displayName":"Allow Bluetooth Modification","description":"If false, prevents modification of Bluetooth settings. Requires a supervised device. Available in iOS 11 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowbluetoothmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowbluetoothmodification_true","displayName":"True","description":null,"helpText":null}]},"d781aeb1efc4b08f":{"id":"com.apple.assetcache.managed_publicranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_publicranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_publicranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},"d76941b42180069e":{"id":"com.apple.finder_com.apple.finder","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":null},"d7eb5149bf24d4c8":{"id":"com.apple.managedclient.preferences_audiocaptureallowedurls","displayName":"Sites that can access audio capture devices without requesting permission","description":"Specify websites, based on URL patterns, that can use audio capture devices without asking the user for permission. Patterns in this list are matched against the security origin of the requesting URL. If they match, the site is automatically granted access to audio capture devices.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiocaptureallowedurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"d7c50faec4bfed34":{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy","displayName":"Allow cloud-based Microsoft Edge management service user policies to override local user policies.","description":"If you enable this policy, cloud-based Microsoft Edge management service user policies takes precedence if it conflicts with local user policy.\n\nIf you disable or don't configure this policy, Microsoft Edge management service user policies will take precedence.\n\nThe policy can be combined with \"EdgeManagementPolicyOverridesPlatformPolicy\". If both policies are enabled, all cloud-based Microsoft Edge management service policies will take precedence over conflicting local service policies.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgemanagementuserpolicyoverridescloudmachinepolicy"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgemanagementuserpolicyoverridescloudmachinepolicy_true","displayName":"Enabled","description":null,"helpText":null}]},"d7f3cad41314ef81":{"id":"com.apple.managedclient.preferences_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (Deprecated)","description":"List of URL patterns. Requests initiated from websites served by matching origins are not subject to Private Network Access checks.\n\nIf this policy is not set, this policy behaves as if set to the empty list.\n\nFor origins not covered by the patterns specified here, the global default value will be used either from the \"InsecurePrivateNetworkRequestsAllowed\" policy, if it is set, or the user's personal configuration otherwise.\n\nFor detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format).","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#insecureprivatenetworkrequestsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"d7ba047cbfd2fb0a":{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener","displayName":"Do not set window.opener for links targeting _blank","description":"If you enable this policy or leave it unset, the window.opener property is set to null unless the anchor specifies rel=\"opener\".\n\nIf you disable this policy, popups that target _blank are permitted to access (via JavaScript) the page that requested to open the popup.\n\nThis policy will be obsoleted in Microsoft Edge version 95.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#targetblankimpliesnoopener"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_targetblankimpliesnoopener_true","displayName":"Enabled","description":null,"helpText":null}]},"d7ec6a3ecdaadbd4":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode","displayName":"Static Code","description":"If true, statically validate the code requirement. Used only if the process invalidates its dynamic code signature.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":[{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicyremovablevolumes_item_staticcode_true","displayName":"True","description":null,"helpText":null}]},"d79f33d501224fc9":{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled","displayName":"Enable Standardized Browser Zoom Behavior","description":"Configures whether the CSS \"zoom\" property follows the current CSS specification or legacy behavior.\n\nWhen this policy is enabled or not configured, the CSS \"zoom\" property follows the current specification defined by the CSS Working Group:\nhttps://drafts.csswg.org/css-viewport/#zoom-property\n\nWhen this policy is disabled, the CSS \"zoom\" property uses its legacy, pre-standardized behavior.\n\nThis policy is temporary and is intended to provide time for organizations to migrate web content to the updated behavior. In a future Microsoft Edge release, this policy will be removed and the standardized behavior will be enforced by default.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.standardizedbrowserzoomenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"d7a5201c88f366ad":{"id":"device_vendor_msft_defender_configuration_archivemaxsize","displayName":"Archive Max Size","description":"Specify the maximum size, in KB, of archive files to be extracted and scanned. If this configuration is off or not set, the default value (0) is applied, and all archives are extracted and scanned regardless of size.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"d7e49f121dce5465":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_reporting_recentlycleanedtimeout_reporting_recentlycleanedtimeout","displayName":"Configure time out for detections in recently remediated state","description":null,"helpText":"","infoUrls":[],"categoryId":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","categoryName":"Reporting","options":null},"d731d9fa930327b5":{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy","displayName":"Notify blocked drivers","description":"This setting exists only for backward compatibility, and is not valid for this version of Windows. To configure the Program Compatibility Assistant, use the 'Turn off Program Compatibility Assistant' setting under Computer Configuration\\Administrative Templates\\Windows Components\\Application Compatibility.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-pca#admx-pca-detectblockeddriverspolicy"],"categoryId":"76c53aab-0288-4ac1-b399-0104e04c6457","categoryName":"Application Compatibility Diagnostics","options":[{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_pca_detectblockeddriverspolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"d7b1dc00e81b0056":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_ts_program_name","displayName":"Program path and file name","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},"d7fa2deef68ae3ff":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote","displayName":"Microsoft OneNote 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2016.\r\nBy default, the user settings of Microsoft OneNote 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_1","displayName":"Enabled","description":null,"helpText":null}]},"d73bd790f9a31a24":{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly","displayName":"Require Private Store Only","description":"Allows disabling of the retail catalog and only enables the Private store. Most restricted value is 1.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-ApplicationManagement#requireprivatestoreonly"],"categoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","categoryName":"Microsoft App Store","options":[{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly_0","displayName":"Allow both public and Private store.","description":"Allow both public and Private store.","helpText":null},{"id":"device_vendor_msft_policy_config_applicationmanagement_requireprivatestoreonly_1","displayName":"Only Private store is enabled.","description":"Only Private store is enabled.","helpText":null}]},"d790396fcb19c63e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended","displayName":"Enable network prediction","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"bce24fbf-4caf-449f-a210-5dd31a368b22","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~removedpolicies_recommended_dnsprefetchingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d7827f00e36a2b49":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification","displayName":"Notify a user that a browser relaunch or device restart is recommended or required","description":"Notify users that Google Chrome must be relaunched or Google Chrome OS must be restarted to apply a pending update.\r\n\r\nThis policy setting enables notifications to inform the user that a browser relaunch or device restart is recommended or required. If not set, Google Chrome indicates to the user that a relaunch is needed via subtle changes to its menu, while Google Chrome OS indicates such via a notification in the system tray. If set to 'Recommended', a recurring warning will be shown to the user that a relaunch is recommended. The user can dismiss this warning to defer the relaunch. If set to 'Required', a recurring warning will be shown to the user indicating that a browser relaunch will be forced once the notification period passes. The default period is seven days for Google Chrome and four days for Google Chrome OS, and may be configured via the RelaunchNotificationPeriod policy setting.\r\n\r\nThe user's session is restored following the relaunch/restart.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"d7e098dac63ca01c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting","displayName":"Control use of the File System API for reading (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_2","displayName":"Do not allow any site to request read access to files and directories via the File System API","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_defaultfilesystemreadguardsetting_defaultfilesystemreadguardsetting_3","displayName":"Allow sites to ask the user to grant read access to files and directories via the File System API","description":null,"helpText":null}]},"d73984e8ca8023ab":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled","displayName":"Enable Instant","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_instantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d7ed1bf32dc95adc":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls","displayName":"Automatically grant permission to sites to connect to any HID device.","description":"Setting the policy allows you to list sites which are automatically granted permission to access all available devices.\r\n\r\nThe URLs must be valid, otherwise the policy is ignored. Only the origin (scheme, host and port) of the URL is considered.\r\n\r\nOn ChromeOS, this policy only applies to affiliated users.\r\n\r\nThis policy overrides DefaultWebHidGuardSetting, WebHidAskForUrls, WebHidBlockedForUrls and the user's preferences.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidallowalldevicesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"d7976fdbc0e50c61":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled","displayName":"Determines whether the Chrome Root Store and built-in certificate verifier will be used to verify server certificates","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromerootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d729891ad271f8c6":{"id":"device_vendor_msft_policy_config_deviceinstallation_preventdevicemetadatafromnetwork","displayName":"Prevent automatic download of applications associated with device metadata","description":"This policy setting allows you to prevent Windows from downloading applications associated with device metadata.\n\nIf you enable this policy setting, Windows does not download applications associated with device metadata for installed devices. This policy setting overrides the setting in the Device Installation Settings dialog box (Control Panel > System and Security > System > Advanced System Settings > Hardware tab).\n\nIf you disable or do not configure this policy setting, the setting in the Device Installation Settings dialog box controls whether Windows downloads applications associated with device metadata.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_deviceinstallation_preventdevicemetadatafromnetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_deviceinstallation_preventdevicemetadatafromnetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"d706340c73b9416d":{"id":"device_vendor_msft_policy_config_humanpresence_forceinstantlock","displayName":"Force Instant Lock","description":"Determines whether Lock on Leave is forced on/off by the MDM policy. The user will not be able to change this setting and the toggle in the UI will be greyed out.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-HumanPresence#forceinstantlock"],"categoryId":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","categoryName":"Human Presence","options":[{"id":"device_vendor_msft_policy_config_humanpresence_forceinstantlock_2","displayName":"Forced Off.","description":"ForcedOff.","helpText":null},{"id":"device_vendor_msft_policy_config_humanpresence_forceinstantlock_1","displayName":"Forced On.","description":"ForcedOn.","helpText":null},{"id":"device_vendor_msft_policy_config_humanpresence_forceinstantlock_0","displayName":"Default To User Choice.","description":"DefaultToUserChoice.","helpText":null}]},"d756c14e606ac76b":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzonenavigatewindowsandframes"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"d7826d719b2fa053":{"id":"device_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons","displayName":"Enable Navigation Buttons","description":"Enable/disable kiosk browser's navigation buttons (forward/back).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#enablenavigationbuttons"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":[{"id":"device_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_kioskbrowser_enablenavigationbuttons_0","displayName":"Disable","description":"Disable","helpText":null}]},"d72717aadcb7b577":{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block malicious downloads and dangerous file types","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block potentially dangerous or unwanted downloads and dangerous file types","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgeupdates.2~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_4","displayName":"Block malicious downloads","description":null,"helpText":null}]},"d747e1d9af066414":{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended","displayName":"Configure auto discard sleeping tabs","description":"Setting this policy enables inactive (sleeping) tabs to be automatically discarded after 1.5 days of inactivity. This is done to save memory. When the user switches back to a discarded tab, the tab will need to be reloaded.\r\n\r\nIf the 'SleepingTabsEnabled' (Configure sleeping tabs) policy is enabled, then this feature will be enabled by default.\r\n\r\nIf the 'SleepingTabsEnabled' is disabled, then this feature will be disabled by default and cannot be enabled.\r\n\r\nIf enabled, idle background tabs will be discarded after 1.5 days.\r\n\r\nIf disabled, idle background tab will not be discarded after 1.5 days. Tabs can still be discarded for other reasons if this policy is disabled.","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge_recommended~sleepingtabs_recommended_autodiscardsleepingtabsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d7e59a7375d157ec":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended","displayName":"Enable the Copilot new tab page","description":"This policy configures the availability of the Copilot new tab page in Microsoft Edge for Business.\r\n\r\nThe Copilot new tab page combines search and chat into a single input box and includes personalized cards that provide quick access to relevant files, calendar events, and suggested Copilot prompts. Users who do not have a Microsoft 365 Copilot license might experience limited relevance in Copilot prompt card content.\r\n\r\nMost policies that customize the New Tab Page are supported on the Copilot new tab page. For a complete list of supported and unsupported policies, see https://go.microsoft.com/fwlink/?linkid=2330462.\r\n\r\nThis policy applies only to Microsoft Entra ID profiles and controls the Copilot new tab page experience in Microsoft Edge for Business. This policy does not apply to the Copilot new tab page on MSA profiles.\r\n\r\nIf you enable this policy, the Copilot new tab page is turned on.\r\n\r\nIf you disable or don't configure this policy, the Copilot new tab page is turned off. When the policy is not configured, users can turn it on via user settings.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_copilotnewtabpageenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d7ef8107907e5a55":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled","displayName":"Enable scrolling to text specified in URL fragments","description":"This feature lets hyperlink and address bar URL navigations target specific text on a web page, which will be scrolled to after the web page finishes loading.\r\n​\r\nIf you enable or don't configure this policy, web page scrolling to specific text fragments via a URL will be enabled.​\r\n\r\nIf you disable this policy, web page scrolling to specific text fragments via a URL will be disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_scrolltotextfragmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d764eb3285f84b05":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_mspubexe16","displayName":"mspub.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_mspubexe16_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_addonmanagement_l_mspubexe16_1","displayName":"True","description":null,"helpText":null}]},"d77628513db90d26":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups","displayName":"Block popups","description":"Block popups","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_1","displayName":"Enabled","description":null,"helpText":null}]},"d716186af9b278b4":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites","displayName":"Configure team site libraries to sync automatically","description":"This setting lets you specify SharePoint team site libraries to sync automatically the next time users sign in to the OneDrive sync app (OneDrive.exe). It may take up to 8 hours after a users signs in before the library begins to sync. To use the setting, you must enable OneDrive Files On-Demand, and the setting applies only for users on computers running Windows 10 (1709) Fall Creators Update or later. Do not enable this setting for the same library to more than 1,000 devices. To ensure a good sync experience, avoid enabling this feature on large libraries sets (For the most up to date guidance see https://docs.microsoft.com/en-us/onedrive/use-group-policy#AutoMountTeamSites). This feature is not enabled for on-premises SharePoint sites.\r\n \r\nIf you enable this setting, the OneDrive sync app will automatically download the contents of the libraries you specified as online-only files the next time the user signs in. The user won't be able to stop syncing the libraries.\r\n \r\nIf you disable this setting, team site libraries that you've specified won't be automatically synced for new users. Existing users can choose to stop syncing the libraries, but the libraries won't stop syncing automatically.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_1","displayName":"Enabled","description":null,"helpText":null}]},"d790c8737cba459b":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesstasks","displayName":"Let Apps Access Tasks","description":"This policy setting specifies whether Windows apps can access tasks.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesstasks"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"d76109f54941679b":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_enforcefirewall","displayName":"Enable firewall protection of Microsoft endpoints","description":"","helpText":"","infoUrls":[],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":[{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_enforcefirewall_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_enforcefirewall_1","displayName":"True","description":null,"helpText":null}]},"d7db3edf5658892e":{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_v2","displayName":"Auto Restart Notification Schedule","description":"Allows the IT Admin to specify the period for auto-restart reminder notifications. The default value is 15 (minutes).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#autorestartnotificationschedule"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_15","displayName":"15 Minutes","description":"15 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_30","displayName":"30 Minutes","description":"30 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_60","displayName":"60 Minutes","description":"60 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_120","displayName":"120 Minutes","description":"120 Minutes","helpText":null},{"id":"device_vendor_msft_policy_config_update_autorestartnotificationschedule_240","displayName":"240 Minutes","description":"240 Minutes","helpText":null}]},"d716655af6137cbb":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_removedesktopshortcutmicrosoftedgecanary","displayName":"Remove Desktop Shortcuts upon update","description":"If you set this policy to \"Force delete system-level Desktop Shortcuts\" (1), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots.\r\n If you set this policy to \"Force delete system-level and user-level Desktop Shortcuts\" (2), any existing system-level Microsoft Edge desktop shortcuts will be deleted when the browser updates or the machine reboots and any existing user-level desktop shortcuts will be deleted when the browser updates. This includes user-level desktop shortcuts that users might have made themselves.\r\n If you don't configure this policy or disable it (0), nothing will happen to existing Microsoft Edge desktop shortcuts.\r\n\r\n If you don't configure this policy for a channel, the 'Remove Desktop Shortcuts upon update default' policy configuration determines desktop shortcut removal.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_removedesktopshortcutmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_removedesktopshortcutmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},"d7fcb1d9ee46e6eb":{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_rollbacktotargetversionmicrosoftedgebeta","displayName":"Rollback to Target version","description":"Specifies that Microsoft Edge Update should rollback installations of Microsoft Edge to the version indicated in 'Target version override'.\r\n\r\nThis policy has no effect unless 'Target version override' is set and 'Update policy override' is set to one of the ON states (Always allow updates, Automatic silent updates only, Manual updates only).\r\n\r\nIf you disable this policy or don't configure it, installs that have a version higher than that specified by 'Target version override' will be left as-is.\r\n\r\nIf you enable this policy, installs that have a current version higher than specified by the 'Target version override' will be downgraded to the target version.\r\n\r\nWe recommend that users install the latest version of the Microsoft Edge browser to ensure protection by the latest security updates. Rollback to an earlier version risks exposure to known security issues. This policy is meant to be used as a temporary fix to address issues in a Microsoft Edge browser update.\r\n\r\nBefore temporarily rolling back your browser version, we recommend that you turn on Sync (https://go.microsoft.com/fwlink/?linkid=2133032) for all users in your organization. If you don't turn on Sync, there is a risk of permanent browsing data loss. Use this policy at your own risk.\r\n\r\nNote: All versions available for rollback can be viewed here https://aka.ms/EdgeEnterprise.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain.\r\n\r\nThis policy applies to Microsoft Edge version 86 or later.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2133918 for more information. This policy is meant to serve as temporary measure when Enterprise Administrators need to downgrade for business reasons. To ensure users are protected by the latest security updates, the most recent version should be used. When versions are downgraded to older versions, there could be incompatibilities.","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":[{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_rollbacktotargetversionmicrosoftedgebeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev86~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_rollbacktotargetversionmicrosoftedgebeta_1","displayName":"Enabled","description":null,"helpText":null}]},"d7da18c7fc6577f3":{"id":"device_vendor_msft_policy_config_userrights_enabledelegation","displayName":"Enable Delegation","description":"This user right determines which users can set the Trusted for Delegation setting on a user or computer object. The user or object that is granted this privilege must have write access to the account control flags on the user or computer object. A server process running on a computer (or under a user context) that is trusted for delegation can access resources on another computer using delegated credentials of a client, as long as the client account does not have the Account cannot be delegated account control flag set. Caution: Misuse of this user right, or of the Trusted for Delegation setting, could make the network vulnerable to sophisticated attacks using Trojan horse programs that impersonate incoming clients and use their credentials to gain access to network resources.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#enabledelegation"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"d7ddf3071fed4be0":{"id":"user_vendor_msft_policy_config_admx_controlpanel_disallowcpls_disallowcplslist","displayName":"List of disallowed Control Panel items (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"d70ae96b6527b163":{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_1","displayName":"Do not throttle additional data (User)","description":"This policy setting determines whether Windows Error Reporting (WER) sends additional, second-level report data even if a CAB file containing data about the same event types has already been uploaded to the server.\r\n\r\nIf you enable this policy setting, WER does not throttle data; that is, WER uploads additional CAB files that can contain data about the same event types as an earlier uploaded report.\r\n\r\nIf you disable or do not configure this policy setting, WER throttles data by default; that is, WER does not upload more than one CAB file for a report that contains data about the same event types.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-errorreporting#admx-errorreporting-werbypassdatathrottling-1"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_errorreporting_werbypassdatathrottling_1_1","displayName":"Enabled","description":null,"helpText":null}]},"d72eefb6239a9e09":{"id":"user_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_1","displayName":"Floppy Drives: Deny read access (User)","description":"This policy setting denies read access to the Floppy Drives removable storage class, including USB Floppy Drives.\r\n\r\nIf you enable this policy setting, read access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, read access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-floppydrives-denyread-access-1"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"user_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_removablestorage_floppydrives_denyread_access_1_1","displayName":"Enabled","description":null,"helpText":null}]},"d7c95ba6e0953692":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8","displayName":"Internet Explorer 8 (User)","description":"This policy setting configures the synchronization of user settings for Internet Explorer 8.\r\nBy default, the user settings of Internet Explorer 8 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 8 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 8 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 8 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer8"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer8_1","displayName":"Enabled","description":null,"helpText":null}]},"d770f001895e2516":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup","displayName":"Access 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Access 2013.\r\nMicrosoft Access 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Access 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Access 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Access 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013accessbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013accessbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"d76a6a33d6a2557b":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet","displayName":"Allow previewing and custom thumbnails of OpenSearch query results in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether a user may preview an item from this zone or display custom thumbnails in the preview pane in File Explorer. While this policy setting usually applies to items returned by OpenSearch queries using Search Connectors (which allow rich searching of remote sources from within the File Explorer), it might affect other items as well that are marked from this zone. For example, some application-specific items such as MAPI (Messaging Application Programming Interface) items that are returned as search results in File Explorer will be affected. MAPI items reside in the Internet zone, so disabling this policy for the Internet zone will prevent the previewing of these items in File Explorer. For the case of custom thumbnails, it is the zone of the thumbnail that is checked, not the zone of item. Typically these are the same but a source is able to define a specific location of a thumbnail that is different than the location of the item.\r\n\r\nIf you enable this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you disable this policy setting, users will be prevented from previewing items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nIf you do not configure this policy setting, users can preview items and get custom thumbnails from OpenSearch query results in this zone using File Explorer.\r\n\r\nChanges to this setting may not be applied until the user logs off from Windows.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchpreview-internet"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchpreview_internet_1","displayName":"Enabled","description":null,"helpText":null}]},"d70676bf2d32b2a8":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown","displayName":"Allow OpenSearch queries in File Explorer (User)","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-internetlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_internetlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"d7cf738bb02fe5fc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_webcomponentsv0enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d7a2b2bb89befad4":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls","displayName":"Block Window Placement permission on these sites (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"d7986e6e5cf1031f":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"d758f950007f7900":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe","displayName":"Launching applications and files in an IFRAME (User)","description":"This policy setting allows you to manage whether applications may be run and files may be downloaded from an IFRAME reference in the HTML of the pages in this zone.\n\nIf you enable this policy setting, users can run applications and download files from IFRAMEs on the pages in this zone without user intervention. If you select Prompt in the drop-down box, users are queried to choose whether to run applications and download files from IFRAMEs on the pages in this zone.\n\nIf you disable this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.\n\nIf you do not configure this policy setting, users are prevented from running applications and downloading files from IFRAMEs on the pages in this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonelaunchingapplicationsandfilesiniframe"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelaunchingapplicationsandfilesiniframe_1","displayName":"Enabled","description":null,"helpText":null}]},"d7223e7ce16ef127":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled","displayName":"Enable favorites bar (User)","description":"Enables or disables the favorites bar.\r\n\r\nIf you enable this policy, users will see the favorites bar.\r\n\r\nIf you disable this policy, users won't see the favorites bar.\r\n\r\nIf this policy is not configured, then the user can decide to use the favorites bar or not.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_favoritesbarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d74cf98090f0e546":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl","displayName":"Specifies the search-by-image feature for the default search provider (User)","description":"Specifies the URL to the search engine used for image search. Search requests are sent using the GET method.\r\n\r\nThis policy is optional. If you don't configure it, image search isn't available.\r\n\r\nSpecify Bing's Image Search URL as:\r\n'{bing:baseURL}images/detail/search?iss=sbiupload&FORM=ANCMS1#enterInsights'.\r\n\r\nSpecify Google's Image Search URL as: '{google:baseURL}searchbyimage/upload'.\r\n\r\nSee 'DefaultSearchProviderImageURLPostParams' (Parameters for an image URL that uses POST) policy to finish configuring image search.\r\n\r\nThis policy is applied only if you enable the 'DefaultSearchProviderEnabled' (Enable the default search provider) and 'DefaultSearchProviderSearchURL' (Default search provider search URL) policies.\r\n\r\nExample value: https://search.contoso.com/searchbyimage/upload","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderimageurl_1","displayName":"Enabled","description":null,"helpText":null}]},"d7729f62e8ec8128":{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled","displayName":"Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 114.\r\n\r\nWhen this policy is set to enabled, Microsoft Edge will perform verification of server certificates using the built-in certificate verifier with the Microsoft Root Store as the source of public trust.\r\n\r\nWhen this policy is set to disabled, Microsoft Edge will use the system certificate verifier and system root certificates.\r\n\r\nWhen this policy is not set, the Microsoft Root Store or system provided roots may be used.\r\n\r\nThis policy is planned to be removed in Microsoft Edge version\r\n121 for Android devices when support for using the platform supplied roots is planned to be removed.\r\n\r\nThis policy was removed in Microsoft Edge version 115 for\r\nMicrosoft Windows and macOS,\r\nMicrosoft Edge version 120 for\r\nLinux, and\r\nMicrosoft Edge version 121 for\r\nAndroid\r\nwhen support for using the platform supplied certificate verifier and roots was removed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d76ee11b4db3df47":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice02_l_broadcastservicecreatesharednotes2_1","displayName":"True","description":null,"helpText":null}]},"d7bb06e9aa5146c0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor","displayName":"Prompt for sending reviewed document to author (User)","description":"\"Never ask user\": Do not ask users if they want to send back changes to the author. | \"Prompt for 'send for review\"': Ask users if they want to send back changes to the author only if the document was sent using Send For Review and not with ad-hoc review. | \"Always prompt\": Ask users if they want to send back changes to the author for documents sent using either Send For Review or ad-hoc review.","helpText":"","infoUrls":[],"categoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","categoryName":"Collaboration Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings_l_promptforsendingrevieweddocumenttoauthor_1","displayName":"Enabled","description":null,"helpText":null}]},"d7732b1276b559e9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly","displayName":"Italian (Italy) (User)","description":"Enables the editing language Italian (Italy)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_italianitaly_1","displayName":"Enabled","description":null,"helpText":null}]},"d738ab2b0f965f37":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache","displayName":"Delete files from Office Document Cache (User)","description":"This policy setting determines whether or not documents opened in Office are deleted from the Office Document Cache when they are closed.\r\n\r\nIf you enable this policy setting documents are deleted from the Office Document Cache when they are closed. \r\n\r\nIf you disable or do not configure this policy setting, documents are not deleted from the Office Document Cache when they are closed.\r\n\r\nNote: This policy setting does not apply to documents in SharePoint Workspace. Documents in SharePoint Workspace will not be deleted from the Office Document cache when they are closed. Sharepoint Workspace will not work correctly if this Group Policy is enabled.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_deletefilesfromofficedocumentcache_1","displayName":"Enabled","description":null,"helpText":null}]},"d72f56a773ad1f54":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs","displayName":"Disable web view in the Office file dialog boxes (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disablewebviewintheofficefiledialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"d7b64b6f2d45d0ec":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache2_l_workflowcachename433","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"d7e3476238bb1262":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache4_l_workflowfriendly446","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"d7f75625700fe816":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage","displayName":"Turn off Windows Internet Explorer security checks for this web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_turnoffinternetexplorersecuritychecksforthiswebpage_1","displayName":"True","description":null,"helpText":null}]},"d7a598ce91610b91":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency","displayName":"Weather Bar Update Frequency (User)","description":"This policy setting allows you to set the update frequency (in minutes) for the Weather Bar. \r\n\r\nIf you enable this policy setting, Outlook sets the update frequency to the specified value. \r\n\r\nIf you disable or do not configure this policy setting, Outlook uses the default value of 120 minutes.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_weatherupdatefrequency_1","displayName":"Enabled","description":null,"helpText":null}]},"d7395482976d107a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting","displayName":"Do not display hit highlights in search results (User)","description":"By default, hit highlights are included in search results. Enable this setting to turn off search hit highlighting.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disablehithighlighting_1","displayName":"Enabled","description":null,"helpText":null}]},"d7896bd758feba19":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones","displayName":"Do not permit download of content from safe zones (User)","description":"This policy setting controls whether Outlook automatically downloads content from safe zones when displaying messages. \r\n\r\nIf you enable this policy setting content from safe zones will be downloaded automatically. \r\n\r\nIf you disable this policy Outlook will not automatically download content from safe zones. Recipients can choose to download external content from untrusted senders on a message-by-message basis. \r\n\r\nIf you do not configure this policy setting, Outlook automatically downloads content from sites that are considered \"safe,\" as defined in the Security tab of the Internet Options dialog box in Internet Explorer. \r\n\r\nImportant - Note that this policy setting is \"backward.\" Despite the name, disabling the policy setting prevents the download of content from safe zones and enabling the policy setting allows it.","helpText":"","infoUrls":[],"categoryId":"a321fc04-d0cb-45ec-a6bf-51d60249922d","categoryName":"Automatic Picture Download Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_automaticpicturedownloadsettings_l_permitdownloadofcontentfromsafezones_1","displayName":"Enabled","description":null,"helpText":null}]},"d7ebd52066ba11ce":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt","displayName":"Ctrl+K (Insert | Links | Hyperlink) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_ctrlkinserthyperlinkppt_1","displayName":"True","description":null,"helpText":null}]},"d73eef78949e8d55":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp","displayName":"Suppress file format compatibility dialog box for OpenDocument Presentation format (User)","description":"This policy setting allows you to enable or disable the file format compatibility dialog box when saving a file as an OpenDocument presentation file in Microsoft PowerPoint.\r\n\r\nIf you enable this policy, the file format compatibility dialog is displayed whenever you save as an OpenDocument presentation file in PowerPoint.\r\n\r\nIf you disable this policy, the file format compatibility dialog is not displayed when you save as an OpenDocument presentation file in PowerPoint.","helpText":"","infoUrls":[],"categoryId":"c3b5e77d-c00d-4578-84c9-289362ad0b00","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_save_l_turnofffileformatcompatiblitydialogforodp_1","displayName":"Enabled","description":null,"helpText":null}]},"d7dabcc1d7edaf47":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_l_pathcolon4","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"d7c0bef7d7961352":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor","displayName":"Search for: (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"98cefd27-a980-4070-ba45-3696b623810d","categoryName":"Shape Search","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_shapesearch_l_searchfor_1","displayName":"Enabled","description":null,"helpText":null}]},"d7fe55a1b6e66831":{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots","displayName":"Set Maximum Storage Duration For Recall Snapshots (User)","description":"This policy setting allows you to control the maximum amount of time (in days) that Windows saves snapshots for Recall. The default value for this setting is '0' which doesn't set a time frame to delete snapshots. When the default is used, snapshots aren't deleted until the maximum storage allocation for Recall is reached and the oldest snapshots are deleted first. You can configure the maximum storage duration to be 30, 60, 90, or 180 days.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsAI#setmaximumstoragedurationforrecallsnapshots"],"categoryId":"33a43c22-104b-4683-995b-5652cfd5b490","categoryName":"Windows AI","options":[{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_0","displayName":"Let the OS define the maximum amount of time the snapshots will be saved","description":"Let the OS define the maximum amount of time the snapshots will be saved","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_30","displayName":"30 days","description":"30 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_60","displayName":"60 days","description":"60 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_90","displayName":"90 days","description":"90 days","helpText":null},{"id":"user_vendor_msft_policy_config_windowsai_setmaximumstoragedurationforrecallsnapshots_180","displayName":"180 days","description":"180 days","helpText":null}]},"d78859a1e3974e00":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano","displayName":"Match ia/iya (piano/piyano) (User)","description":"This policy setting allows you to check or uncheck the corresponding UI option in the \"Japanese Find\" dialog. The \"Japanese Find\" dialog may be accessed from the Find dialog, under Home tab | Editing | Find | Go To... | Search Options | Options.... It could also be found under the Navigation Pane, under Home tab | Editing | Find | < down arrow > | Options... | Sounds Like (Japanese) | Options. The \"Sounds like (Japanese)\" checkbox and the \"Options...\" button may be hidden in Word until certain editing languages are enabled.\r\n\r\nIf you enable this policy setting, you will check the corresponding UI option as specified in this policy setting's title.\r\n\r\nIf you disable or do not configure this policy setting, the corresponding UI option will be unchecked.\r\n","helpText":"","infoUrls":[],"categoryId":"b8adcde1-500a-430f-8636-f97eaae2a2c6","categoryName":"Japanese Find","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_japanesefind_l_matchiaiyapianopiyano_1","displayName":"Enabled","description":null,"helpText":null}]},"d71e655d28c4f280":{"id":"vendor_msft_firewall_mdmstore_hypervfirewallrules_{firewallrulename}_localportranges","displayName":"Local Port Ranges","description":"Comma Separated list of ranges for eg. 100-120,200,300-320. If not specified the default is All.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/d8.json b/public/intune-definitions/d8.json index 8eb989e93999..2707d03e81cf 100644 --- a/public/intune-definitions/d8.json +++ b/public/intune-definitions/d8.json @@ -1 +1 @@ -{"d889958f7482bbe5":{"id":"ade_setupassistant_camerabutton","displayName":"Camera button","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_camerabutton_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_camerabutton_1","displayName":"Show","description":null,"helpText":null}]},"d8c4305ba8e489eb":{"id":"com.apple.applicationaccess_ratingtvshowsde","displayName":"Rating TV Shows - Germany","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsde_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_1","displayName":"Ab 0 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_2","displayName":"Ab 6 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_3","displayName":"Ab 12 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_4","displayName":"Ab 16 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_5","displayName":"Ab 18 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_7","displayName":"All","description":null,"helpText":null}]},"d8ea3111502ec861":{"id":"com.apple.asam_allowedapplications_item_teamidentifier","displayName":"Team Identifier","description":"The developer's team identifier, used when the app was signed.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},"d892a4fa7075c07b":{"id":"com.apple.familycontrols.contentfilter_whitelistenabled","displayName":"Allowlist Enabled","description":"If true, enables web content filters.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":[{"id":"com.apple.familycontrols.contentfilter_whitelistenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.contentfilter_whitelistenabled_true","displayName":"True","description":null,"helpText":null}]},"d82f92982cd6f28a":{"id":"com.apple.shareddeviceconfiguration_assettaginformation","displayName":"Asset Tag Information","description":"The asset tag information for the device, displayed in the Login Window and Lock Screen.","helpText":null,"infoUrls":[],"categoryId":"dec8381a-0a61-406b-842b-fc6ae9930795","categoryName":"Lock Screen Message","options":null},"d8502c3d5bc99018":{"id":"com.microsoft.edge.mamedgeappconfigsettings.cookiesallowedforurls","displayName":"Allow cookies on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies. URL patterns can be a single URL indicating that the site can use cookies on all top-level sites. Patterns can also be two URLs delimited by a comma. The first specifies the site that should be allowed to use cookies. The second specifies the top-level site that the first value should be applied on. If you use a pair of URLs, the first value in the pair supports *, but the second value doesn't. Using * for the first value indicates that all sites can use cookies when the second URL is the top-level site.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor more information, see the \"CookiesBlockedForUrls\" and \"CookiesSessionOnlyForUrls\" policies.\n\nNote there can't be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- CookiesAllowedForUrls\n\n- \"CookiesSessionOnlyForUrls\"\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.\n\nTo allow third-party cookies to be set, specify a pair of URL patterns delimited by a comma. The first value in the pair specifies the third-party site that should be allowed to use cookies. The second value in the pair specifies the top-level site that the first value should be applied on. The first value in the pair supports * but the second value doesn't.\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"d86e13ef62ceaf02":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\n\nIf you set this policy to 'StandardMode', the enhanced mode is turned off, and Microsoft Edge falls back to its standard security mode.\n\nIf you set this policy to 'BalancedMode', the security state is in balanced mode.\n\nIf you set this policy to 'StrictMode', the security state is in strict mode.\n\nIf you set this policy to 'BasicMode', the security state is in basic mode.\n\nNote: Sites that use WebAssembly (WASM) aren't supported on 32-bit systems when \"EnhanceSecurityMode\" is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\n\nStarting from Microsoft Edge version 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It doesn't work in Microsoft Edge version 116.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\n\nPolicy options mapping:\n\n* StandardMode (0) = Standard mode\n\n* BalancedMode (1) = Balanced mode\n\n* StrictMode (2) = Strict mode\n\n* BasicMode (3) = (Deprecated) Basic mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_standardmode","displayName":"Standard mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_balancedmode","displayName":"Balanced mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_strictmode","displayName":"Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_basicmode","displayName":"(Deprecated) Basic mode","description":null,"helpText":null}]},"d8c04e6b4bf04847":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (users can override)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\n\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\n\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"d834d5a0a924981c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.securitykeypermitattestation","displayName":"Websites or domains that don't need permission to use direct Security Key attestation","description":"Specifies the WebAuthn RP IDs that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use enterprise attestation. Without this policy, users are prompted each time a site requests attestation of security keys.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"d858c8add1c36d78":{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowedfororigins","displayName":"Allow users to proceed from the HTTPS warning page for specific origins","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure the \"SSLErrorOverrideAllowed\" policy, this policy does nothing.\n\nIf you disable the \"SSLErrorOverrideAllowed\" policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list.\n\nIf you don't configure this policy, the \"SSLErrorOverrideAllowed\" policy applies for all sites.\n\nFor detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"d80682e47695a24b":{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordlength","displayName":"Password Length","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":null},"d87856bbfd78513c":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings","displayName":"Enable Transparent Caching","description":"This policy setting controls whether files read from file shares over a slow network are transparently cached in the Offline Files cache for future reads. When a user tries to access a file that has been transparently cached, Windows reads from the cached copy after verifying its integrity. This improves end-user response times and decreases bandwidth consumption over WAN links.\r\n\r\nThe cached files are temporary and are not available to the user when offline. The cached files are not kept in sync with the version on the server, and the most current version from the server is always available for subsequent reads.\r\n\r\nThis policy setting is triggered by the configured round trip network latency value. We recommend using this policy setting when the network connection to the server is slow. For example, you can configure a value of 60 ms as the round trip latency of the network above which files should be transparently cached in the Offline Files cache. If the round trip latency of the network is less than 60ms, reads to remote files will not be cached.\r\n\r\nIf you enable this policy setting, transparent caching is enabled and configurable.\r\n\r\nIf you disable or do not configure this policy setting, remote files will be not be transparently cached on client computers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-onlinecachingsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"d8c3fe2353c7f7d3":{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page","displayName":"Do not display Manage Your Server page at logon","description":"This policy setting allows you to turn off the automatic display of the Manage Your Server page. \r\n\r\nIf you enable this policy setting, the Manage Your Server page is not displayed each time an administrator logs on to the server. \r\n\r\nIf you disable or do not configure this policy setting, the Manage Your Server page is displayed each time an administrator logs on to the server. However, if the administrator has selected the \"Don’t display this page at logon\" option at the bottom of the Manage Your Server page, the page is not displayed.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-do-not-display-manage-your-server-page"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page_1","displayName":"Enabled","description":null,"helpText":null}]},"d859fa7c25994f49":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode","displayName":"Do not allow hardware accelerated decoding","description":"This policy setting specifies whether the Remote Desktop Connection can use hardware acceleration if supported hardware is available. If you use this setting, the Remote Desktop Client will use only software decoding. For example, if you have a problem that you suspect may be related to hardware acceleration, use this setting to disable the acceleration; then, if the problem still occurs, you will know that there are additional issues to investigate. If you disable this setting or leave it not configured, the Remote Desktop client will use hardware accelerated decoding if supported hardware is available.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-disable-hardware-mode"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode_1","displayName":"Enabled","description":null,"helpText":null}]},"d8294684159b3e47":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_overridesecurityrestrictionsoninsecureorigindesc","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"d890256a3a4de03e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses","description":"Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.\r\n\r\nSetting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d86c3f101b98ade9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended","displayName":"Enable leak detection for entered credentials","description":"Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.\r\n\r\nThis behavior will not trigger if Safe Browsing is disabled (either by policy or by the user). In order to force Safe Browsing on, use the SafeBrowsingEnabled policy or the SafeBrowsingProtectionLevel policy.","helpText":"","infoUrls":[],"categoryId":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d811984ef305aa0c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled","displayName":"Enable signin interception","description":"This settings enables or disables signin interception.\r\n\r\nWhen this policy not set or is set to True, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile.\r\n\r\nWhen this is set to False, the signin interception dialog does not trigger.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d8b4b0f05bba3106":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"d8ce4b97c72a312c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"https://github.com/WICG/service-worker-auto-preload\r\nThe ServiceWorkerAutoPreload feature dispatches a network request for a main resource at the same time it begins the ServiceWorker bootstrap process.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome enables ServiceWorkerAutoPreload. The navigation request is automatically dispatched while starting the ServiceWorker in some scenarios, e.g. ServiceWorker is not running,\r\n\r\nIf it is disabled, Google Chrome will not enable ServiceWorkerAutoPreload. The navigation request is dispatched always after starting the ServiceWorker.\r\n\r\nThis policy is a temporary measure to control the feature and will be removed in M144.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d87846f5cef64e5c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings","displayName":"Settings for Help Me Write (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_0","displayName":"Allow Help Me Write and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_1","displayName":"Allow Help Me Write without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_2","displayName":"Do not allow Help Me Write.","description":null,"helpText":null}]},"d8eb80faa3b5debb":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own and, if fixing them is possible, it usually requires complex user actions.\r\n\r\nSetting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\r\n\r\nSetting the policy to Disabled means users will leave their password manager data untouched, but will experience a broken password manager functionality.\r\n\r\nIf the policy is set, users can't change it in Google Chrome.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d8d44d203305e32e":{"id":"device_vendor_msft_policy_config_devicelock_passwordhistorysize","displayName":"Password History Size","description":"Enforce password history This security setting determines the number of unique new passwords that have to be associated with a user account before an old password can be reused. The value must be between 0 and 24 passwords. This policy enables administrators to enhance security by ensuring that old passwords are not reused continually. Default: 24 on domain controllers. 0 on stand-alone servers. Note: By default, member computers follow the configuration of their domain controllers. To maintain the effectiveness of the password history, do not allow passwords to be changed immediately after they were just changed by also enabling the Minimum password age security policy setting. For information about the minimum password age security policy setting, see Minimum password age.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeviceLock#passwordhistorysize"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":null},"d8ad7ec32e95260d":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezonenavigatewindowsandframes"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"d88320e5527cee4f":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b","displayName":"Only allow approved domains to use ActiveX controls without prompt","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_0","displayName":"Disable","description":null,"helpText":null}]},"d8e36e82b6671422":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, a warning is issued to the user that potentially risky navigation is about to occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowlessprivilegedsites"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"d87461e0e63c9742":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service","description":"In Microsoft Edge, the Experimentation and Configuration Service is used to deploy Experimentation and Configuration payload.\r\n\r\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\r\n\r\nConfiguration payload consists of a list of settings that Microsoft wants to deploy to Microsoft Edge to optimize user experience. For example, configuration payload may specify how often Microsoft Edge sends requests to the Experimentation and Configuration Service to retrieve the newest payload.\r\n\r\nAdditionaly, configuration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nIf you set this policy to \"Retrieve configurations and experiments\" mode, the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\r\n\r\nIf you set this policy to \"Retrieve configurations only\" mode, only the configuration payload is delivered.\r\n\r\nIf you set this policy to \"Disable communication with the Experimentation and Configuration Service\" mode, the communication with the Experimentation and Configuration Service is stopped completely.\r\n\r\nIf you don't configure this policy, on a managed device on Stable and Beta channels the behavior is the same as the \"Retrieve configurations only\" mode.\r\n\r\nIf you don't configure this policy, on an unmanaged device the behavior is the same as the \"Retrieve configurations and experiments\" mode.\r\n\r\n* 0 = Disable communication with the Experimentation and Configuration Service\r\n\r\n* 1 = Retrieve configurations only\r\n\r\n* 2 = Retrieve configurations and experiments","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"d84fffa62423f1fd":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended","displayName":"Enable resolution of navigation errors using a web service","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\r\n\r\nIf you enable this policy, a web service is used for network connectivity tests.\r\n\r\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\r\n\r\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d80da6f9aa452f17":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates_cadistrustedcertificatesdesc","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},"d82b853ed73bf7e9":{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory","description":"This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings.\r\n\r\nIf you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.\r\n\r\nThis policy has no effect if the DownloadDirectory policy is set.\r\n\r\nFor a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars .\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d83a85634c91f783":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback","description":"Following each major version update, Microsoft Edge will create a snapshot of parts of the user's browsing data to use in case of a later emergency that requires a temporary version rollback. If a temporary rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This lets users keep settings such as bookmarks and autofill data.\r\n\r\nIf you don't set this policy, the default value of 3 snapshots is used.\r\n\r\nIf you set this policy, old snapshots are deleted as needed to respect the limit you set. If you set this policy to 0, no snapshots are taken.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_1","displayName":"Enabled","description":null,"helpText":null}]},"d84bc2b708ff28b1":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"d8a51356f603437a":{"id":"device_vendor_msft_policy_config_mixedreality_eyetrackingcalibrationprompt","displayName":"Eye Tracking Calibration Prompt","description":"This policy controls when a new person uses Hololens device, if Hololens should automatically ask to run eye calibration.","helpText":"","infoUrls":[],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_eyetrackingcalibrationprompt_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_eyetrackingcalibrationprompt_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"d860aa7889c83c1f":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessgraphicscaptureprogrammatic_forcedenytheseapps","displayName":"Let Apps Access Graphics Capture Programmatic Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied the use of screen capture on arbitrary windows or displays. This setting overrides the default LetAppsAccessGraphicsCaptureWithoutBorder policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessgraphicscaptureprogrammatic_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"d835d3cb3e69db35":{"id":"device_vendor_msft_policy_config_storage_configstoragesenserecyclebincleanupthreshold","displayName":"Config Storage Sense Recycle Bin Cleanup Threshold","description":"When Storage Sense runs, it can delete files in the user’s Recycle Bin if they have been there for over a certain amount of days. If the Storage/AllowStorageSenseGlobal policy is disabled, then this policy does not have any effect. If you enable this policy setting, you must provide the minimum age threshold (in days) of a file in the Recycle Bin before Storage Sense will delete it. Supported values are: 0–365. If you set this value to zero, Storage Sense will not delete files in the user’s Recycle Bin. The default is 30 days. If you disable or do not configure this policy setting, Storage Sense will delete files in the user’s Recycle Bin that have been there for over 30 days by default. Users can configure this setting in Storage settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Storage#configstoragesenserecyclebincleanupthreshold"],"categoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","categoryName":"Storage","options":null},"d80d3f0e8c7a2c9e":{"id":"extensionsettings_managedextensions_generickey_state","displayName":"State","description":"Controls whether an extension is allowed.\n* Allowed - The user is allowed to turn the extension on or off\n* AlwaysOn - The extension will always be on\n* AlwaysOff - The extension will always be off","helpText":null,"infoUrls":[],"categoryId":"7d9e5b9b-84e7-473c-b6ca-a1629448df55","categoryName":"Safari Extension Settings","options":[{"id":"extensionsettings_managedextensions_generickey_state_0","displayName":"Allowed","description":null,"helpText":null},{"id":"extensionsettings_managedextensions_generickey_state_1","displayName":"Always On","description":null,"helpText":null},{"id":"extensionsettings_managedextensions_generickey_state_2","displayName":"Always Off","description":null,"helpText":null}]},"d8c0984d8eec1d87":{"id":"linux_mdatp_managed_antivirusengine_enablefilehashcomputation","displayName":"Enable file hash computation","description":"Whether the antivirus engine computes hashes for the files it scans or not.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-preferences?view=o365-worldwide#configure-file-hash-computation-feature"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_enablefilehashcomputation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_enablefilehashcomputation_true","displayName":"Enabled","description":null,"helpText":null}]},"d879e3ddc3409c17":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpin","displayName":"Do not automatically make all redirected folders available offline (User)","description":"This policy setting allows you to control whether all redirected shell folders, such as Contacts, Documents, Desktop, Favorites, Music, Pictures, Videos, Start Menu, and AppData\\Roaming, are available offline by default.\r\n\r\nIf you enable this policy setting, users must manually select the files they wish to make available offline. \r\n\r\nIf you disable or do not configure this policy setting, redirected shell folders are automatically made available offline. All subfolders within the redirected folders are also made available offline. \r\n\r\nNote: This policy setting does not prevent files from being automatically cached if the network share is configured for \"Automatic Caching\", nor does it affect the availability of the \"Always available offline\" menu option in the user interface. \r\n\r\nNote: Do not enable this policy setting if users will need access to their redirected files if the network or server holding the redirected files becomes unavailable.\r\n\r\nNote: If one or more valid folder GUIDs are specified in the policy setting \"Do not automatically make specific redirected folders available offline\", that setting will override the configured value of \"Do not automatically make all redirected folders available offline\".\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-disablefradminpin"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpin_1","displayName":"Enabled","description":null,"helpText":null}]},"d84c517a46aed4c7":{"id":"user_vendor_msft_policy_config_admx_startmenu_intellimenus","displayName":"Turn off personalized menus (User)","description":"Disables personalized menus.\r\n\r\nWindows personalizes long menus by moving recently used items to the top of the menu and hiding items that have not been used recently. Users can display the hidden items by clicking an arrow to extend the menu.\r\n\r\nIf you enable this setting, the system does not personalize menus. All menu items appear and remain in standard order. Also, this setting removes the \"Use Personalized Menus\" option so users do not try to change the setting while a setting is in effect.\r\n\r\nNote: Personalized menus require user tracking. If you enable the \"Turn off user tracking\" setting, the system disables user tracking and personalized menus and ignores this setting.\r\n\r\nTip: To Turn off personalized menus without specifying a setting, click Start, click Settings, click Taskbar and Start Menu, and then, on the General tab, clear the \"Use Personalized Menus\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-intellimenus"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_intellimenus_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_intellimenus_1","displayName":"Enabled","description":null,"helpText":null}]},"d8e748aa364ec6d4":{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_1","displayName":"Prevent press and hold (User)","description":"Prevents press and hold actions on hardware buttons, so that only one action is available per button.\r\n\r\nIf you enable this policy, press and hold actions are unavailable, and the button configuration dialog will display the following text: \"Some settings are controlled by Group Policy. If a setting is unavailable, contact your system administrator.\"\r\n\r\nIf you disable this policy, press and hold actions for buttons will be available.\r\n\r\nIf you do not configure this policy, press and hold actions will be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventpressandhold-1"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_1_1","displayName":"Enabled","description":null,"helpText":null}]},"d8295901722e256a":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10","displayName":"Internet Explorer 10 (User)","description":"This policy setting configures the synchronization of user settings of Internet Explorer 10.\r\nBy default, the user settings of Internet Explorer 10 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 10 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 10 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 10 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer10"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_1","displayName":"Enabled","description":null,"helpText":null}]},"d8b2aae39b571c42":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedopensearch_opensearchlabel2","displayName":"Site Name 3 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"d8c6e819dbc9b128":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_bypassproxylocal","displayName":"Bypass proxy for local addresses (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_bypassproxylocal_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_bypassproxylocal_1","displayName":"True","description":null,"helpText":null}]},"d80d36f4cb0170da":{"id":"user_vendor_msft_policy_config_browser_allowprinting","displayName":"Allow Printing (User)","description":"With this policy, you can restrict whether printing web content in Microsoft Edge is allowed. If enabled, printing is allowed. If disabled, printing is not allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowprinting"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowprinting_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowprinting_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"d84717b8f8d68b44":{"id":"user_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer","displayName":"Show Message When Opening Sites In Internet Explorer (User)","description":"You can configure Microsoft Edge to open a site automatically in Internet Explorer 11 and choose to display a notification before the site opens. If you want to display a notification, you must enable Configure the Enterprise Mode Site List or Send all intranets sites to Internet Explorer 11 or both. If enabled, the notification appears on a new page. If you want users to continue in Microsoft Edge, select the Show Keep going in Microsoft Edge option from the drop-down list under Options. If disabled or not configured, the default app behavior occurs and no additional page displays. Default setting: Disabled or not configured Related policies: -Configure the Enterprise Mode Site List -Send all intranet sites to Internet Explorer 11","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#showmessagewhenopeningsitesininternetexplorer"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_0","displayName":"No additional message displays.","description":"No additional message displays.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_1","displayName":"Show an additional message stating that a site has opened in IE11.","description":"Show an additional message stating that a site has opened in IE11.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_2","displayName":"Show an additional message with a \"Keep going in Microsoft Edge\" link.","description":"Show an additional message with a \"Keep going in Microsoft Edge\" link.","helpText":null}]},"d895de5940d62c95":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords","displayName":"Import saved passwords from default browser on first run (User)","description":"Setting the policy to Enabled imports saved passwords from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no saved passwords are imported on first run.\r\n\r\nUsers can trigger an import dialog and the saved passwords checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords_1","displayName":"Enabled","description":null,"helpText":null}]},"d83fe12e95b0841b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended","displayName":"Enable alternate error pages (User)","description":"Setting the policy to True means Google Chrome uses alternate error pages built into (such as \"page not found\"). Setting the policy to False means Google Chrome never uses alternate error pages.\r\n\r\nIf you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d8e0b1184a971b47":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox (User)","description":"Setting the policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services whenever the system configuration supports it.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security as services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn off the policy if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d857e93ad08b449c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells","displayName":"Alert before overwriting cells (User)","description":"This policy setting sets the \"Alert before overwriting cells\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will give a warning if cells are about to be overwritten. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will suppress the warning that cells are about to be overwritten.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells_1","displayName":"Enabled","description":null,"helpText":null}]},"d8ca1fcecc39d389":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptlets"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"d8da7b5f5e8575a0":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallownetframeworkreliantcomponents"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"d8a9f413cec76050":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"d8e3e421daa7a9f7":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols","displayName":"Allow scripting of Internet Explorer WebBrowser controls (User)","description":"This policy setting determines whether a page can control embedded WebBrowser controls via script.\n\nIf you enable this policy setting, script access to the WebBrowser control is allowed.\n\nIf you disable this policy setting, script access to the WebBrowser control is not allowed.\n\nIf you do not configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"d8cd49b14a850480":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneturnonprotectedmode"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"d86ffd1b1de92b8e":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_urlallowlistdesc","displayName":"Define a list of allowed URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"d899c7e9df0d0de5":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL (User)","description":"Configures the change password URL (HTTP and HTTPS schemes only).\r\n\r\nPassword protection service will send users to this URL to change their password after seeing a warning in the browser.\r\n\r\nIf you enable this policy, then password protection service sends users to this URL to change their password.\r\n\r\nIf you disable this policy or don't configure it, then password protection service will not redirect users to a change password URL.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://contoso.com/change_password.html","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_1","displayName":"Enabled","description":null,"helpText":null}]},"d83a5a3fd8b5946d":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled","displayName":"Choose whether users can receive customized background images and text, suggestions, notifications,\r\nand tips for Microsoft services (User)","description":"Choose whether users can receive customized background images and text, suggestions, notifications, and tips for Microsoft services.\r\n\r\nIf you enable or don't configure this setting, spotlight experiences and recommendations are turned on.\r\n\r\nIf you disable this setting, spotlight experiences and recommendations are turned off.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d8b07997f66e8a1e":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended","displayName":"Allow single sign-on for Microsoft personal sites using this profile (User)","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\r\n\r\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\r\n\r\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d805a65889064dca":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint_1","displayName":"True","description":null,"helpText":null}]},"d8b183acfa4931f4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein","displayName":"German (Liechtenstein) (User)","description":"Enables the editing language German (Liechtenstein)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein_1","displayName":"Enabled","description":null,"helpText":null}]},"d8e821eaaf67aae5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowfriendly491","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"d8b1dcf766e9b057":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_urladdressofassociatedwebpage41","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"d81cf45fe6b26ab2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57_1","displayName":"True","description":null,"helpText":null}]},"d87c2e1e640509eb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts","displayName":"Prevent users from adding Exchange e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts_1","displayName":"True","description":null,"helpText":null}]},"d8264c637409a9eb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards","displayName":"On replies and forwards (User)","description":"Sets the values in the corresponding UI options.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_1","displayName":"Enabled","description":null,"helpText":null}]},"d8582e85dd6f9869":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},"d8854651eeff343d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles","displayName":"Show more handles on hover (User)","description":"This policy setting allows you to show more shape handles when hovering over a selected shape.\r\n\r\nIf you enable this policy setting, more shape handles will be shown after a brief delay.\r\n\r\nIf you disable or do not configure this policy setting, more shape handles will not be shown.\r\n","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles_1","displayName":"Enabled","description":null,"helpText":null}]},"d81a396cee190c1c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings","displayName":"Drawings (User)","description":"Displays the additional location of drawings. When you add a location here, it becomes the default save location.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_1","displayName":"Enabled","description":null,"helpText":null}]},"d832c318d015c14a":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles_l_autorecoverfiles13","displayName":"AutoRecover files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},"d873428cb5cc8db2":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]}} \ No newline at end of file +{"d889958f7482bbe5":{"id":"ade_setupassistant_camerabutton","displayName":"Camera button","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_camerabutton_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_camerabutton_1","displayName":"Show","description":null,"helpText":null}]},"d8c4305ba8e489eb":{"id":"com.apple.applicationaccess_ratingtvshowsde","displayName":"Rating TV Shows - Germany","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsde_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_1","displayName":"Ab 0 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_2","displayName":"Ab 6 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_3","displayName":"Ab 12 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_4","displayName":"Ab 16 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_5","displayName":"Ab 18 Jahren","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsde_7","displayName":"All","description":null,"helpText":null}]},"d8ea3111502ec861":{"id":"com.apple.asam_allowedapplications_item_teamidentifier","displayName":"Team Identifier","description":"The developer's team identifier, used when the app was signed.","helpText":null,"infoUrls":[],"categoryId":"daa2ea69-8026-465a-942c-75eb0396d5b9","categoryName":"Autonomous Single App Mode","options":null},"d892a4fa7075c07b":{"id":"com.apple.familycontrols.contentfilter_whitelistenabled","displayName":"Allowlist Enabled","description":"If true, enables web content filters.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":[{"id":"com.apple.familycontrols.contentfilter_whitelistenabled_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.familycontrols.contentfilter_whitelistenabled_true","displayName":"True","description":null,"helpText":null}]},"d82f92982cd6f28a":{"id":"com.apple.shareddeviceconfiguration_assettaginformation","displayName":"Asset Tag Information","description":"The asset tag information for the device, displayed in the Login Window and Lock Screen.","helpText":null,"infoUrls":[],"categoryId":"dec8381a-0a61-406b-842b-fc6ae9930795","categoryName":"Lock Screen Message","options":null},"d8502c3d5bc99018":{"id":"com.microsoft.edge.mamedgeappconfigsettings.cookiesallowedforurls","displayName":"Allow cookies on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to set cookies. URL patterns can be a single URL indicating that the site can use cookies on all top-level sites. Patterns can also be two URLs delimited by a comma. The first specifies the site that should be allowed to use cookies. The second specifies the top-level site that the first value should be applied on. If you use a pair of URLs, the first value in the pair supports *, but the second value doesn't. Using * for the first value indicates that all sites can use cookies when the second URL is the top-level site.\n\nIf you don't configure this policy, the global default value from the \"DefaultCookiesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor more information, see the \"CookiesBlockedForUrls\" and \"CookiesSessionOnlyForUrls\" policies.\n\nNote there can't be conflicting URL patterns set between these three policies:\n\n- \"CookiesBlockedForUrls\"\n\n- CookiesAllowedForUrls\n\n- \"CookiesSessionOnlyForUrls\"\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * isn't an accepted value for this policy.\n\nTo allow third-party cookies to be set, specify a pair of URL patterns delimited by a comma. The first value in the pair specifies the third-party site that should be allowed to use cookies. The second value in the pair specifies the top-level site that the first value should be applied on. The first value in the pair supports * but the second value doesn't.\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"d86e13ef62ceaf02":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\n\nIf you set this policy to 'StandardMode', the enhanced mode is turned off, and Microsoft Edge falls back to its standard security mode.\n\nIf you set this policy to 'BalancedMode', the security state is in balanced mode.\n\nIf you set this policy to 'StrictMode', the security state is in strict mode.\n\nIf you set this policy to 'BasicMode', the security state is in basic mode.\n\nNote: Sites that use WebAssembly (WASM) aren't supported on 32-bit systems when \"EnhanceSecurityMode\" is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\n\nStarting from Microsoft Edge version 113, 'BasicMode' is deprecated and is treated the same as 'BalancedMode'. It doesn't work in Microsoft Edge version 116.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\n\nPolicy options mapping:\n\n* StandardMode (0) = Standard mode\n\n* BalancedMode (1) = Balanced mode\n\n* StrictMode (2) = Strict mode\n\n* BasicMode (3) = (Deprecated) Basic mode\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_standardmode","displayName":"Standard mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_balancedmode","displayName":"Balanced mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_strictmode","displayName":"Strict mode","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymode_basicmode","displayName":"(Deprecated) Basic mode","description":null,"helpText":null}]},"d8c04e6b4bf04847":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended","displayName":"Microsoft Edge built-in PDF reader powered by Adobe Acrobat enabled (users can override)","description":"The policy lets Microsoft Edge launch the new version of the built-in PDF reader that's powered by Adobe Acrobat's PDF rendering engine. The new PDF reader ensures that there's no loss of functionality and delivers an enhanced PDF experience. This experience includes richer rendering, improved performance, strong security for PDF handling, and greater accessibility.\n\nIf you enable this policy, Microsoft Edge will use the new Adobe Acrobat powered built-in PDF reader to open all PDF files.\n\nIf you disable or don't configure this policy, Microsoft Edge will use the existing PDF reader to open all PDF files.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newpdfreaderenabled_recommended_true","displayName":"Enabled","description":null,"helpText":null}]},"d834d5a0a924981c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.securitykeypermitattestation","displayName":"Websites or domains that don't need permission to use direct Security Key attestation","description":"Specifies the WebAuthn RP IDs that don't need explicit user permission when attestation certificates from security keys are requested. Additionally, a signal is sent to the security key indicating that it can use enterprise attestation. Without this policy, users are prompted each time a site requests attestation of security keys.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"d858c8add1c36d78":{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowedfororigins","displayName":"Allow users to proceed from the HTTPS warning page for specific origins","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure the \"SSLErrorOverrideAllowed\" policy, this policy does nothing.\n\nIf you disable the \"SSLErrorOverrideAllowed\" policy, configuring this policy lets you configure a list of origin patterns for sites where users can continue to click through SSL error pages. Users can't click through SSL error pages on origins that are not on this list.\n\nIf you don't configure this policy, the \"SSLErrorOverrideAllowed\" policy applies for all sites.\n\nFor detailed information about valid origin patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy. This policy only matches based on origin, so any path or query in the URL pattern is ignored.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"d80682e47695a24b":{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_elm_admpwd_passwordlength","displayName":"Password Length","description":"","helpText":"","infoUrls":[],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":null},"d87856bbfd78513c":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings","displayName":"Enable Transparent Caching","description":"This policy setting controls whether files read from file shares over a slow network are transparently cached in the Offline Files cache for future reads. When a user tries to access a file that has been transparently cached, Windows reads from the cached copy after verifying its integrity. This improves end-user response times and decreases bandwidth consumption over WAN links.\r\n\r\nThe cached files are temporary and are not available to the user when offline. The cached files are not kept in sync with the version on the server, and the most current version from the server is always available for subsequent reads.\r\n\r\nThis policy setting is triggered by the configured round trip network latency value. We recommend using this policy setting when the network connection to the server is slow. For example, you can configure a value of 60 ms as the round trip latency of the network above which files should be transparently cached in the Offline Files cache. If the round trip latency of the network is less than 60ms, reads to remote files will not be cached.\r\n\r\nIf you enable this policy setting, transparent caching is enabled and configurable.\r\n\r\nIf you disable or do not configure this policy setting, remote files will be not be transparently cached on client computers.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-offlinefiles#admx-offlinefiles-pol-onlinecachingsettings"],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_onlinecachingsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"d8c3fe2353c7f7d3":{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page","displayName":"Do not display Manage Your Server page at logon","description":"This policy setting allows you to turn off the automatic display of the Manage Your Server page. \r\n\r\nIf you enable this policy setting, the Manage Your Server page is not displayed each time an administrator logs on to the server. \r\n\r\nIf you disable or do not configure this policy setting, the Manage Your Server page is displayed each time an administrator logs on to the server. However, if the administrator has selected the \"Don’t display this page at logon\" option at the bottom of the Manage Your Server page, the page is not displayed.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-servermanager#admx-servermanager-do-not-display-manage-your-server-page"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_servermanager_do_not_display_manage_your_server_page_1","displayName":"Enabled","description":null,"helpText":null}]},"d859fa7c25994f49":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode","displayName":"Do not allow hardware accelerated decoding","description":"This policy setting specifies whether the Remote Desktop Connection can use hardware acceleration if supported hardware is available. If you use this setting, the Remote Desktop Client will use only software decoding. For example, if you have a problem that you suspect may be related to hardware acceleration, use this setting to disable the acceleration; then, if the problem still occurs, you will know that there are additional issues to investigate. If you disable this setting or leave it not configured, the Remote Desktop client will use hardware accelerated decoding if supported hardware is available.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-client-disable-hardware-mode"],"categoryId":"4c604a0e-9339-4c01-9536-b689bd0abe5f","categoryName":"Remote Desktop Connection Client","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_client_disable_hardware_mode_1","displayName":"Enabled","description":null,"helpText":null}]},"d8294684159b3e47":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_overridesecurityrestrictionsoninsecureorigin_overridesecurityrestrictionsoninsecureorigindesc","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"d890256a3a4de03e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended","displayName":"Enable AutoFill for addresses","description":"Setting the policy to True or leaving it unset gives users control of Autofill for addresses in the UI.\r\n\r\nSetting the policy to False means Autofill never suggests or fills address information, nor does it save additional address information that users submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_autofilladdressenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d86c3f101b98ade9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended","displayName":"Enable leak detection for entered credentials","description":"Setting the policy to Enabled lets users have Google Chrome check whether usernames and passwords entered were part of a leak.\r\n\r\nIf the policy is set, users can't change it in Google Chrome. If not set, credential leak checking is allowed, but the user can turn it off.\r\n\r\nThis behavior will not trigger if Safe Browsing is disabled (either by policy or by the user). In order to force Safe Browsing on, use the SafeBrowsingEnabled policy or the SafeBrowsingProtectionLevel policy.","helpText":"","infoUrls":[],"categoryId":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~passwordmanager_recommended_passwordleakdetectionenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d811984ef305aa0c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled","displayName":"Enable signin interception","description":"This settings enables or disables signin interception.\r\n\r\nWhen this policy not set or is set to True, the signin interception dialog triggers when a Google account is added on the web, and the user may benefit from moving this account to another (new or existing) profile.\r\n\r\nWhen this is set to False, the signin interception dialog does not trigger.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_signininterceptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d8b4b0f05bba3106":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webrtcudpportrange_webrtcudpportrange","displayName":"Restrict the range of local UDP ports used by WebRTC (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"d8ce4b97c72a312c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled","displayName":"Allow ServiceWorker to dispatch navigation requests without waiting for its startup","description":"https://github.com/WICG/service-worker-auto-preload\r\nThe ServiceWorkerAutoPreload feature dispatches a network request for a main resource at the same time it begins the ServiceWorker bootstrap process.\r\n\r\nSetting the policy to Enabled or leaving it unset means\r\nGoogle Chrome enables ServiceWorkerAutoPreload. The navigation request is automatically dispatched while starting the ServiceWorker in some scenarios, e.g. ServiceWorker is not running,\r\n\r\nIf it is disabled, Google Chrome will not enable ServiceWorkerAutoPreload. The navigation request is dispatched always after starting the ServiceWorker.\r\n\r\nThis policy is a temporary measure to control the feature and will be removed in M144.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_serviceworkerautopreloadenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d87846f5cef64e5c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings","displayName":"Settings for Help Me Write (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_0","displayName":"Allow Help Me Write and improve AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_1","displayName":"Allow Help Me Write without improving AI models.","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_2","displayName":"Do not allow Help Me Write.","description":null,"helpText":null}]},"d8eb80faa3b5debb":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own and, if fixing them is possible, it usually requires complex user actions.\r\n\r\nSetting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\r\n\r\nSetting the policy to Disabled means users will leave their password manager data untouched, but will experience a broken password manager functionality.\r\n\r\nIf the policy is set, users can't change it in Google Chrome.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d8d44d203305e32e":{"id":"device_vendor_msft_policy_config_devicelock_passwordhistorysize","displayName":"Password History Size","description":"Enforce password history This security setting determines the number of unique new passwords that have to be associated with a user account before an old password can be reused. The value must be between 0 and 24 passwords. This policy enables administrators to enhance security by ensuring that old passwords are not reused continually. Default: 24 on domain controllers. 0 on stand-alone servers. Note: By default, member computers follow the configuration of their domain controllers. To maintain the effectiveness of the password history, do not allow passwords to be changed immediately after they were just changed by also enabling the Minimum password age security policy setting. For information about the minimum password age security policy setting, see Minimum password age.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeviceLock#passwordhistorysize"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":null},"d8ad7ec32e95260d":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes","displayName":"Navigate windows and frames across different domains","description":"This policy setting allows you to manage the opening of windows and frames and access of applications across different domains.\n\nIf you enable this policy setting, users can open windows and frames from othe domains and access applications from other domains. If you select Prompt in the drop-down box, users are queried whether to allow windows and frames to access applications from other domains.\n\nIf you disable this policy setting, users cannot open windows and frames to access applications from different domains.\n\nIf you do not configure this policy setting, users can open windows and frames from othe domains and access applications from other domains.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezonenavigatewindowsandframes"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezonenavigatewindowsandframes_1","displayName":"Enabled","description":null,"helpText":null}]},"d88320e5527cee4f":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b","displayName":"Only allow approved domains to use ActiveX controls without prompt","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_0","displayName":"Disable","description":null,"helpText":null}]},"d8e36e82b6671422":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Restricted Sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, a warning is issued to the user that potentially risky navigation is about to occur.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-trustedsiteszoneallowlessprivilegedsites"],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"d87461e0e63c9742":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol","displayName":"Control communication with the Experimentation and Configuration Service","description":"In Microsoft Edge, the Experimentation and Configuration Service is used to deploy Experimentation and Configuration payload.\r\n\r\nExperimentation payload consists of a list of early in development features that Microsoft is enabling for testing and feedback.\r\n\r\nConfiguration payload consists of a list of settings that Microsoft wants to deploy to Microsoft Edge to optimize user experience. For example, configuration payload may specify how often Microsoft Edge sends requests to the Experimentation and Configuration Service to retrieve the newest payload.\r\n\r\nAdditionaly, configuration payload may also contain a list of actions to take on certain domains for compatibility reasons. For example, the browser may override the User Agent string on a website if that website is broken due to the new User Agent string on Microsoft Edge. Each of these actions is intended to be temporary while Microsoft tries to resolve the issue with the site owner.\r\n\r\nIf you set this policy to \"Retrieve configurations and experiments\" mode, the full payload is downloaded from the Experimentation and Configuration Service. This includes both the experimentation and configuration payloads.\r\n\r\nIf you set this policy to \"Retrieve configurations only\" mode, only the configuration payload is delivered.\r\n\r\nIf you set this policy to \"Disable communication with the Experimentation and Configuration Service\" mode, the communication with the Experimentation and Configuration Service is stopped completely.\r\n\r\nIf you don't configure this policy, on a managed device on Stable and Beta channels the behavior is the same as the \"Retrieve configurations only\" mode.\r\n\r\nIf you don't configure this policy, on an unmanaged device the behavior is the same as the \"Retrieve configurations and experiments\" mode.\r\n\r\n* 0 = Disable communication with the Experimentation and Configuration Service\r\n\r\n* 1 = Retrieve configurations only\r\n\r\n* 2 = Retrieve configurations and experiments","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_experimentationandconfigurationservicecontrol_1","displayName":"Enabled","description":null,"helpText":null}]},"d84fffa62423f1fd":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended","displayName":"Enable resolution of navigation errors using a web service","description":"Allow Microsoft Edge to issue a dataless connection to a web service to probe networks for connectivity in cases like hotel and airport Wi-Fi.\r\n\r\nIf you enable this policy, a web service is used for network connectivity tests.\r\n\r\nIf you disable this policy, Microsoft Edge uses native APIs to try to resolve network connectivity and navigation issues.\r\n\r\n**Note**: Except on Windows 8 and later versions of Windows, Microsoft Edge *always* uses native APIs to resolve connectivity issues.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Use a web service to help resolve navigation errors** toggle, which the user can switch on or off. Be aware that if you have enabled this policy (ResolveNavigationErrorsUseWebService), the **Use a web service to help resolve navigation errors** setting is turned on, but the user can't change the setting by using the toggle. If you have disabled this policy, the **Use a web service to help resolve navigation errors** setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_resolvenavigationerrorsusewebservice_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d80da6f9aa452f17":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cadistrustedcertificates_cadistrustedcertificatesdesc","displayName":"TLS certificates that should be distrusted by Microsoft Edge for server authentication (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},"d82b853ed73bf7e9":{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory","description":"This policy sets the default directory that Microsoft Edge uses to download files. Users can change the directory through browser settings.\r\n\r\nIf you don't configure this policy, Microsoft Edge uses the platform-specific default download directory.\r\n\r\nThis policy has no effect if the DownloadDirectory policy is set.\r\n\r\nFor a list of supported variables, see https://learn.microsoft.com/en-us/deployedge/edge-learnmore-create-user-directory-vars .\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_recommended~downloads_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d83a85634c91f783":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit","displayName":"Limits the number of user data snapshots retained for use in case of emergency rollback","description":"Following each major version update, Microsoft Edge will create a snapshot of parts of the user's browsing data to use in case of a later emergency that requires a temporary version rollback. If a temporary rollback is performed to a version for which a user has a corresponding snapshot, the data in the snapshot is restored. This lets users keep settings such as bookmarks and autofill data.\r\n\r\nIf you don't set this policy, the default value of 3 snapshots is used.\r\n\r\nIf you set this policy, old snapshots are deleted as needed to respect the limit you set. If you set this policy to 0, no snapshots are taken.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_userdatasnapshotretentionlimit_1","displayName":"Enabled","description":null,"helpText":null}]},"d84bc2b708ff28b1":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites","displayName":"Allow JavaScript to use JIT on these sites","description":"Allows you to set a list of site url patterns that specify sites which are allowed to run JavaScript with JIT (Just In Time) compiler enabled.\r\n\r\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\r\n\r\nJavaScript JIT policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\r\n\r\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the JavaScriptJitAllowedForSites policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript JIT enabled, but fabrikam.com will use the policy from 'DefaultJavaScriptJitSetting' (Control use of JavaScript JIT), if set, or default to JavaScript JIT enabled.\r\n\r\nIf you don't configure this policy for a site then the policy from 'DefaultJavaScriptJitSetting' applies to the site, if set, otherwise Javascript JIT is enabled for the site.\r\n\r\nExample value:\r\n\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~contentsettings_javascriptjitallowedforsites_1","displayName":"Enabled","description":null,"helpText":null}]},"d8a51356f603437a":{"id":"device_vendor_msft_policy_config_mixedreality_eyetrackingcalibrationprompt","displayName":"Eye Tracking Calibration Prompt","description":"This policy controls when a new person uses Hololens device, if Hololens should automatically ask to run eye calibration.","helpText":"","infoUrls":[],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_eyetrackingcalibrationprompt_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_eyetrackingcalibrationprompt_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"d860aa7889c83c1f":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessgraphicscaptureprogrammatic_forcedenytheseapps","displayName":"Let Apps Access Graphics Capture Programmatic Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. Listed apps are denied the use of screen capture on arbitrary windows or displays. This setting overrides the default LetAppsAccessGraphicsCaptureWithoutBorder policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessgraphicscaptureprogrammatic_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"d835d3cb3e69db35":{"id":"device_vendor_msft_policy_config_storage_configstoragesenserecyclebincleanupthreshold","displayName":"Config Storage Sense Recycle Bin Cleanup Threshold","description":"When Storage Sense runs, it can delete files in the user’s Recycle Bin if they have been there for over a certain amount of days. If the Storage/AllowStorageSenseGlobal policy is disabled, then this policy does not have any effect. If you enable this policy setting, you must provide the minimum age threshold (in days) of a file in the Recycle Bin before Storage Sense will delete it. Supported values are: 0–365. If you set this value to zero, Storage Sense will not delete files in the user’s Recycle Bin. The default is 30 days. If you disable or do not configure this policy setting, Storage Sense will delete files in the user’s Recycle Bin that have been there for over 30 days by default. Users can configure this setting in Storage settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Storage#configstoragesenserecyclebincleanupthreshold"],"categoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","categoryName":"Storage","options":null},"d8d4b39501114879":{"id":"device_vendor_msft_policy_config_update_maintenancewindowweeklymonday","displayName":"Maintenance Window Weekly Monday","description":"SIf the maintenance window repeat schedule is set to weekly, configure whether Monday is included in the weekly schedule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowweeklymonday"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"d80d3f0e8c7a2c9e":{"id":"extensionsettings_managedextensions_generickey_state","displayName":"State","description":"Controls whether an extension is allowed.\n* Allowed - The user is allowed to turn the extension on or off\n* AlwaysOn - The extension will always be on\n* AlwaysOff - The extension will always be off","helpText":null,"infoUrls":[],"categoryId":"7d9e5b9b-84e7-473c-b6ca-a1629448df55","categoryName":"Safari Extension Settings","options":[{"id":"extensionsettings_managedextensions_generickey_state_0","displayName":"Allowed","description":null,"helpText":null},{"id":"extensionsettings_managedextensions_generickey_state_1","displayName":"Always On","description":null,"helpText":null},{"id":"extensionsettings_managedextensions_generickey_state_2","displayName":"Always Off","description":null,"helpText":null}]},"d8c0984d8eec1d87":{"id":"linux_mdatp_managed_antivirusengine_enablefilehashcomputation","displayName":"Enable file hash computation","description":"Whether the antivirus engine computes hashes for the files it scans or not.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-preferences?view=o365-worldwide#configure-file-hash-computation-feature"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"linux_mdatp_managed_antivirusengine_enablefilehashcomputation_false","displayName":"Disabled","description":null,"helpText":null},{"id":"linux_mdatp_managed_antivirusengine_enablefilehashcomputation_true","displayName":"Enabled","description":null,"helpText":null}]},"d879e3ddc3409c17":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpin","displayName":"Do not automatically make all redirected folders available offline (User)","description":"This policy setting allows you to control whether all redirected shell folders, such as Contacts, Documents, Desktop, Favorites, Music, Pictures, Videos, Start Menu, and AppData\\Roaming, are available offline by default.\r\n\r\nIf you enable this policy setting, users must manually select the files they wish to make available offline. \r\n\r\nIf you disable or do not configure this policy setting, redirected shell folders are automatically made available offline. All subfolders within the redirected folders are also made available offline. \r\n\r\nNote: This policy setting does not prevent files from being automatically cached if the network share is configured for \"Automatic Caching\", nor does it affect the availability of the \"Always available offline\" menu option in the user interface. \r\n\r\nNote: Do not enable this policy setting if users will need access to their redirected files if the network or server holding the redirected files becomes unavailable.\r\n\r\nNote: If one or more valid folder GUIDs are specified in the policy setting \"Do not automatically make specific redirected folders available offline\", that setting will override the configured value of \"Do not automatically make all redirected folders available offline\".\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-disablefradminpin"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpin_1","displayName":"Enabled","description":null,"helpText":null}]},"d84c517a46aed4c7":{"id":"user_vendor_msft_policy_config_admx_startmenu_intellimenus","displayName":"Turn off personalized menus (User)","description":"Disables personalized menus.\r\n\r\nWindows personalizes long menus by moving recently used items to the top of the menu and hiding items that have not been used recently. Users can display the hidden items by clicking an arrow to extend the menu.\r\n\r\nIf you enable this setting, the system does not personalize menus. All menu items appear and remain in standard order. Also, this setting removes the \"Use Personalized Menus\" option so users do not try to change the setting while a setting is in effect.\r\n\r\nNote: Personalized menus require user tracking. If you enable the \"Turn off user tracking\" setting, the system disables user tracking and personalized menus and ignores this setting.\r\n\r\nTip: To Turn off personalized menus without specifying a setting, click Start, click Settings, click Taskbar and Start Menu, and then, on the General tab, clear the \"Use Personalized Menus\" option.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-intellimenus"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_intellimenus_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_intellimenus_1","displayName":"Enabled","description":null,"helpText":null}]},"d8e748aa364ec6d4":{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_1","displayName":"Prevent press and hold (User)","description":"Prevents press and hold actions on hardware buttons, so that only one action is available per button.\r\n\r\nIf you enable this policy, press and hold actions are unavailable, and the button configuration dialog will display the following text: \"Some settings are controlled by Group Policy. If a setting is unavailable, contact your system administrator.\"\r\n\r\nIf you disable this policy, press and hold actions for buttons will be available.\r\n\r\nIf you do not configure this policy, press and hold actions will be available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventpressandhold-1"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_tabletshell_preventpressandhold_1_1","displayName":"Enabled","description":null,"helpText":null}]},"d8295901722e256a":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10","displayName":"Internet Explorer 10 (User)","description":"This policy setting configures the synchronization of user settings of Internet Explorer 10.\r\nBy default, the user settings of Internet Explorer 10 synchronize between computers. Use the policy setting to prevent the user settings for Internet Explorer 10 from synchronization between computers. \r\nIf you enable this policy setting, the Internet Explorer 10 user settings continue to synchronize. \r\nIf you disable this policy setting, Internet Explorer 10 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-internetexplorer10"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_internetexplorer10_1","displayName":"Enabled","description":null,"helpText":null}]},"d8b2aae39b571c42":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedopensearch_opensearchlabel2","displayName":"Site Name 3 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"d8c6e819dbc9b128":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_bypassproxylocal","displayName":"Bypass proxy for local addresses (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_bypassproxylocal_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurehttpproxysettings_bypassproxylocal_1","displayName":"True","description":null,"helpText":null}]},"d80d36f4cb0170da":{"id":"user_vendor_msft_policy_config_browser_allowprinting","displayName":"Allow Printing (User)","description":"With this policy, you can restrict whether printing web content in Microsoft Edge is allowed. If enabled, printing is allowed. If disabled, printing is not allowed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowprinting"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowprinting_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowprinting_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"d84717b8f8d68b44":{"id":"user_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer","displayName":"Show Message When Opening Sites In Internet Explorer (User)","description":"You can configure Microsoft Edge to open a site automatically in Internet Explorer 11 and choose to display a notification before the site opens. If you want to display a notification, you must enable Configure the Enterprise Mode Site List or Send all intranets sites to Internet Explorer 11 or both. If enabled, the notification appears on a new page. If you want users to continue in Microsoft Edge, select the Show Keep going in Microsoft Edge option from the drop-down list under Options. If disabled or not configured, the default app behavior occurs and no additional page displays. Default setting: Disabled or not configured Related policies: -Configure the Enterprise Mode Site List -Send all intranet sites to Internet Explorer 11","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#showmessagewhenopeningsitesininternetexplorer"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_0","displayName":"No additional message displays.","description":"No additional message displays.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_1","displayName":"Show an additional message stating that a site has opened in IE11.","description":"Show an additional message stating that a site has opened in IE11.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_showmessagewhenopeningsitesininternetexplorer_2","displayName":"Show an additional message with a \"Keep going in Microsoft Edge\" link.","description":"Show an additional message with a \"Keep going in Microsoft Edge\" link.","helpText":null}]},"d895de5940d62c95":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords","displayName":"Import saved passwords from default browser on first run (User)","description":"Setting the policy to Enabled imports saved passwords from the previous default browser on first run. Setting the policy to Disabled or leaving it unset means no saved passwords are imported on first run.\r\n\r\nUsers can trigger an import dialog and the saved passwords checkbox will be checked or unchecked to match this policy's value.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_importsavedpasswords_1","displayName":"Enabled","description":null,"helpText":null}]},"d83fe12e95b0841b":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended","displayName":"Enable alternate error pages (User)","description":"Setting the policy to True means Google Chrome uses alternate error pages built into (such as \"page not found\"). Setting the policy to False means Google Chrome never uses alternate error pages.\r\n\r\nIf you set the policy, users can't change it. If not set, the policy is on, but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d8e0b1184a971b47":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled","displayName":"Enable Printing LPAC Sandbox (User)","description":"Setting the policy to Enabled or leaving it unset enables the LPAC Sandbox for printing services whenever the system configuration supports it.\r\n\r\nSetting the policy to Disabled has a detrimental effect on Google Chrome's security as services used for printing might run in a weaker sandbox configuration.\r\n\r\nOnly turn off the policy if there are compatibility issues with third party software that prevent printing services from operating correctly inside the LPAC Sandbox.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_printinglpacsandboxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d857e93ad08b449c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells","displayName":"Alert before overwriting cells (User)","description":"This policy setting sets the \"Alert before overwriting cells\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will give a warning if cells are about to be overwritten. This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will suppress the warning that cells are about to be overwritten.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_alertbeforeoverwritingcells_1","displayName":"Enabled","description":null,"helpText":null}]},"d8ca1fcecc39d389":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets","displayName":"Allow scriptlets (User)","description":"This policy setting allows you to manage whether the user can run scriptlets.\n\nIf you enable this policy setting, the user can run scriptlets.\n\nIf you disable this policy setting, the user cannot run scriptlets.\n\nIf you do not configure this policy setting, the user can enable or disable scriptlets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneallowscriptlets"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneallowscriptlets_1","displayName":"Enabled","description":null,"helpText":null}]},"d8da7b5f5e8575a0":{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallownetframeworkreliantcomponents"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_localmachinezoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"d8a9f413cec76050":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"d8e3e421daa7a9f7":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols","displayName":"Allow scripting of Internet Explorer WebBrowser controls (User)","description":"This policy setting determines whether a page can control embedded WebBrowser controls via script.\n\nIf you enable this policy setting, script access to the WebBrowser control is allowed.\n\nIf you disable this policy setting, script access to the WebBrowser control is not allowed.\n\nIf you do not configure this policy setting, the user can enable or disable script access to the WebBrowser control. By default, script access to the WebBrowser control is allowed only in the Local Machine and Intranet zones.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptingofinternetexplorerwebbrowsercontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"d8cd49b14a850480":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode","displayName":"Turn on Protected Mode (User)","description":"This policy setting allows you to turn on Protected Mode. Protected Mode helps protect Internet Explorer from exploited vulnerabilities by reducing the locations that Internet Explorer can write to in the registry and the file system.\n\nIf you enable this policy setting, Protected Mode is turned on. The user cannot turn off Protected Mode.\n\nIf you disable this policy setting, Protected Mode is turned off. The user cannot turn on Protected Mode.\n\nIf you do not configure this policy setting, the user can turn on or turn off Protected Mode.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneturnonprotectedmode"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneturnonprotectedmode_1","displayName":"Enabled","description":null,"helpText":null}]},"d86ffd1b1de92b8e":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_urlallowlistdesc","displayName":"Define a list of allowed URLs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"d899c7e9df0d0de5":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl","displayName":"Configure the change password URL (User)","description":"Configures the change password URL (HTTP and HTTPS schemes only).\r\n\r\nPassword protection service will send users to this URL to change their password after seeing a warning in the browser.\r\n\r\nIf you enable this policy, then password protection service sends users to this URL to change their password.\r\n\r\nIf you disable this policy or don't configure it, then password protection service will not redirect users to a change password URL.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances that are enrolled for device management.\r\n\r\nExample value: https://contoso.com/change_password.html","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~passwordmanager_passwordprotectionchangepasswordurl_1","displayName":"Enabled","description":null,"helpText":null}]},"d83a5a3fd8b5946d":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled","displayName":"Choose whether users can receive customized background images and text, suggestions, notifications,\r\nand tips for Microsoft services (User)","description":"Choose whether users can receive customized background images and text, suggestions, notifications, and tips for Microsoft services.\r\n\r\nIf you enable or don't configure this setting, spotlight experiences and recommendations are turned on.\r\n\r\nIf you disable this setting, spotlight experiences and recommendations are turned off.","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge~contentsettings_spotlightexperiencesandrecommendationsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"d8b07997f66e8a1e":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended","displayName":"Allow single sign-on for Microsoft personal sites using this profile (User)","description":"'Allow single sign-on for Microsoft personal sites using this profile' option allows non-MSA profiles to be able to use single sign-on for Microsoft sites using MSA credentials present on the machine. This option shows up for end-users as a toggle in Settings -> Profiles -> Profile Preferences for non-MSA profiles only.\r\n\r\nIf you disable this policy, non-MSA profiles will not be able to use single sign-on for Microsoft sites using MSA credentials present on the machine.\r\n\r\nIf you enable this policy or don't configure it, users will be able to use the Settings option to ensure non-MSA profiles are able to use single sign-on for Microsoft sites using MSA credentials present on the machine provided only a single MSA account exists on the machine.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_recommended_msawebsitessousingthisprofileallowed_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"d805a65889064dca":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint","displayName":"Disallow in PowerPoint (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicypowerpoint_1","displayName":"True","description":null,"helpText":null}]},"d8b183acfa4931f4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein","displayName":"German (Liechtenstein) (User)","description":"Enables the editing language German (Liechtenstein)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_germanliechtenstein_1","displayName":"Enabled","description":null,"helpText":null}]},"d8e821eaaf67aae5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache13_l_workflowfriendly491","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"d8b1dcf766e9b057":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_inboxfolderhomepage_l_urladdressofassociatedwebpage41","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"d81cf45fe6b26ab2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_notesfolderhomepage_l_showassociatedwebpage57_1","displayName":"True","description":null,"helpText":null}]},"d87c2e1e640509eb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts","displayName":"Prevent users from adding Exchange e-mail accounts (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f5a1a387-6665-4527-b532-88a64a76e732","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_miscellaneous_l_preventusersfromaddingemailaccounttypes_l_preventusersfromaddingexchangeemailaccounts_1","displayName":"True","description":null,"helpText":null}]},"d8264c637409a9eb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards","displayName":"On replies and forwards (User)","description":"Sets the values in the corresponding UI options.","helpText":"","infoUrls":[],"categoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","categoryName":"E-mail Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions_l_onrepliesandforwards_1","displayName":"Enabled","description":null,"helpText":null}]},"d8582e85dd6f9869":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc09_l_allowsubfolders35_1","displayName":"True","description":null,"helpText":null}]},"d8854651eeff343d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles","displayName":"Show more handles on hover (User)","description":"This policy setting allows you to show more shape handles when hovering over a selected shape.\r\n\r\nIf you enable this policy setting, more shape handles will be shown after a brief delay.\r\n\r\nIf you disable or do not configure this policy setting, more shape handles will not be shown.\r\n","helpText":"","infoUrls":[],"categoryId":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","categoryName":"Editing Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_editingoptions_l_showmorehandles_1","displayName":"Enabled","description":null,"helpText":null}]},"d81a396cee190c1c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings","displayName":"Drawings (User)","description":"Displays the additional location of drawings. When you add a location here, it becomes the default save location.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_drawings_1","displayName":"Enabled","description":null,"helpText":null}]},"d832c318d015c14a":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced~l_filelocations_l_autorecoverfiles_l_autorecoverfiles13","displayName":"AutoRecover files (User)","description":"","helpText":"","infoUrls":[],"categoryId":"bc65521d-e48a-4e95-899f-49df827808ca","categoryName":"File Locations","options":null},"d873428cb5cc8db2":{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction","displayName":"Default Inbound Action","description":"This value is the action that the Hyper-V Firewall does by default (and evaluates at the very end) on inbound connections. The allow action is represented by 0x00000000; 0x00000001 represents a block action. Default value is 1 [Block].","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction_0","displayName":"Allow Inbound By Default","description":"Allow Inbound By Default","helpText":null},{"id":"vendor_msft_firewall_mdmstore_hypervvmsettings_{vmcreatorid}_privateprofile_defaultinboundaction_1","displayName":"Block Inbound By Default","description":"Block Inbound By Default","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/da.json b/public/intune-definitions/da.json index 47cbbf876fd4..b7951bc6da78 100644 --- a/public/intune-definitions/da.json +++ b/public/intune-definitions/da.json @@ -1 +1 @@ -{"da50247a9d50121a":{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":null},"da7fd05295158886":{"id":"com.apple.directoryservice.managed_admapggidattributeflag","displayName":"AD Map GGID Attribute Flag","description":"If true, enables the AD Map GGID Attribute Flag key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapggidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapggidattributeflag_true","displayName":"True","description":null,"helpText":null}]},"da4445dc766f18a5":{"id":"com.apple.ldap.account_ldapaccountpassword","displayName":"LDAP Account Password","description":"The user’s password. The password is enabled only with encrypted profiles.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},"dae804ba649f4ad5":{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled","displayName":"Save and fill memberships","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autofillmembershipsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"dae1118b0a8dbe88":{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeassetdeliveryserviceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"da8d17aae6f600f4":{"id":"com.apple.managedclient.preferences_relaunchnotificationperiod","displayName":"Set the time period for update notifications","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\n\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the \"RelaunchNotification\" policy follow this same schedule.\n\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relaunchnotificationperiod"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"da1c98953a3cb17e":{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning","description":"Suppresses the warning that appears when Microsoft Edge is running on a computer or operating system that is no longer supported.\n\nIf this policy is false or unset, the warnings will appear on such unsupported computers or operating systems.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#suppressunsupportedoswarning"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning_true","displayName":"Enabled","description":null,"helpText":null}]},"da41e733414f89ec":{"id":"com.apple.servicemanagement_com.apple.servicemanagement","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},"dada2d2db97173f2":{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions)","description":"If you set this policy to Enabled or leave it unset, Microsoft Edge can use native messaging hosts installed at the user level.\n\nIf you set this policy to Disabled, Microsoft Edge can only use these hosts if they're installed at the system level.","helpText":null,"infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts_true","displayName":"Enabled","description":null,"helpText":null}]},"da213314a513d832":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_includedidlist","displayName":"Included Devices","description":"The group(s) that the policy will be applied to. If multiple groups are added, the policy will be applied to any media in all those groups.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},"da5f4063d5e728be":{"id":"device_vendor_msft_laps_policies_passwordagedays","displayName":"Password Age Days ","description":"Use this policy to configure the maximum password age of the managed local administrator account.\n\nIf not specified, this setting will default to 30 days\n\nThis setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Microsoft Entra ID..\n\nThis setting has a maximum allowed value of 365 days.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},"dae04d376a3d5ef4":{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected","displayName":"Is Selected","description":"Indicates whether this Slot is selected or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected_false","displayName":"Not selected","description":"Not selected","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected_true","displayName":"Selected","description":"Selected","helpText":null}]},"da00ac77dfa5efec":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_driverinstall_classes_allowuser_list","displayName":"Allow Users to install driver packages for these classes:","description":"","helpText":"","infoUrls":[],"categoryId":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","categoryName":"Driver Installation","options":null},"daf8082b471e7558":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage_netlogon_ndncsitecoveragelabel","displayName":"Sites:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},"da58514f9f44d57a":{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation","displayName":"Isolate print drivers from applications","description":"Determines if print driver components are isolated from applications instead of normally loading them into applications. Isolating print drivers greatly reduces the risk of a print driver failure causing an application crash.\r\n\r\nNot all applications support driver isolation. By default, Microsoft Excel 2007, Excel 2010, Word 2007, Word 2010 and certain other applications are configured to support it. Other applications may also be capable of isolating print drivers, depending on whether they are configured for it.\r\n\r\nIf you enable or do not configure this policy setting, then applications that are configured to support driver isolation will be isolated.\r\n\r\nIf you disable this policy setting, then print drivers will be loaded within all associated application processes.\r\n\r\nNotes:\r\n-This policy setting applies only to applications opted into isolation.\r\n-This policy setting applies only to print drivers loaded by applications. Print drivers loaded by the print spooler are not affected.\r\n-This policy setting is only checked once during the lifetime of a process. After changing the policy, a running application must be relaunched before settings take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-applicationdriverisolation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation_1","displayName":"Enabled","description":null,"helpText":null}]},"daca37529aa6836a":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy","displayName":"Require use of specific security layer for remote (RDP) connections","description":"This policy setting specifies whether to require the use of a specific security layer to secure communications between clients and RD Session Host servers during Remote Desktop Protocol (RDP) connections.\r\n\r\nIf you enable this policy setting, all communications between clients and RD Session Host servers during remote connections must use the security method specified in this setting. The following security methods are available:\r\n\r\n* Negotiate: The Negotiate method enforces the most secure method that is supported by the client. If Transport Layer Security (TLS) version 1.0 is supported, it is used to authenticate the RD Session Host server. If TLS is not supported, native Remote Desktop Protocol (RDP) encryption is used to secure communications, but the RD Session Host server is not authenticated. Native RDP encryption (as opposed to SSL encryption) is not recommended.\r\n\r\n* RDP: The RDP method uses native RDP encryption to secure communications between the client and RD Session Host server. If you select this setting, the RD Session Host server is not authenticated. Native RDP encryption (as opposed to SSL encryption) is not recommended.\r\n\r\n* SSL (TLS 1.0): The SSL method requires the use of TLS 1.0 to authenticate the RD Session Host server. If TLS is not supported, the connection fails. This is the recommended setting for this policy.\r\n\r\nIf you disable or do not configure this policy setting, the security method to be used for remote connections to RD Session Host servers is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-security-layer-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_1","displayName":"Enabled","description":null,"helpText":null}]},"dab42d9e895b77e2":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint","displayName":"Microsoft PowerPoint 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft PowerPoint 2013.\r\nBy default, the user settings of Microsoft PowerPoint 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"da3f0009c95304dd":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-trustedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"da495ae0e056baca":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation","displayName":"Trust apps with good reputation","description":"When enabled, applications with known good reputation as defined by the Microsoft's Intelligent Security Graph (ISG) are white listed.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation_enabled","displayName":"Enabled","description":null,"helpText":null}]},"da2def72028eaab5":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"daca404d7a3c17a6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request headers support","description":"Configures support of CORS non-wildcard request headers.\r\n\r\nGoogle Chrome version 97 introduces support for CORS non-wildcard request headers. When scripts make a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://www.chromest atus.com/feature/5768642492891136 for more detail.\r\n\r\nIf this policy is not set, or set to True, Google Chrome will support the CORS non-wildcard request headers and behave as described above.\r\n\r\nWhen this policy is set to False, chrome will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\r\n\r\nThis Enterprise policy is temporary; it's intended to be removed after Google Chrome version 103.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport_1","displayName":"Enabled","description":null,"helpText":null}]},"da40b3d232fd04c6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"da307ed1b9127516":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled","displayName":"Allow download deep scanning for Safe Browsing-enabled users","description":"When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives.\r\nWhen this policy is disabled, this scanning will not be performed.\r\nThis policy does not impact download content analysis configured by Chrome Enterprise Connectors.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"da5a1a1f8ddad48e":{"id":"device_vendor_msft_policy_config_devicehealthmonitoring_configdevicehealthmonitoringscope","displayName":"[Deprecated] Config Device Health Monitoring Scope","description":"If the device is not opted-in to the DeviceHealthMonitoring service via the AllowDeviceHealthMonitoring then this policy has no meaning. For devices which are opted in, the value of this policy modifies which types of events are monitored.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeviceHealthMonitoring#configdevicehealthmonitoringscope"],"categoryId":"55c888df-44ff-49d1-808e-ad9cb8429aff","categoryName":"Device Health Monitoring","options":null},"dadc6106aa7143c7":{"id":"device_vendor_msft_policy_config_devicelock_devicepasswordenabled","displayName":"Device Password Enabled","description":"Specifies whether device lock is enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#devicepasswordenabled"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":[{"id":"device_vendor_msft_policy_config_devicelock_devicepasswordenabled_0","displayName":"Enabled","description":"Enabled","helpText":null},{"id":"device_vendor_msft_policy_config_devicelock_devicepasswordenabled_1","displayName":"Disabled","description":"Disabled","helpText":null}]},"da2e7688dc797065":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"da95842b3be4abd5":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"da39bd88c35db328":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null}]},"da839c0470735877":{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override","description":"This policy enables an override of the IPv6 reachability check. When overridden, the\r\nsystem will always query AAAA records when resolving host names. It applies to\r\nall users and interfaces on the device.\r\n\r\nIf you enable this policy, the IPv6 reachability check will be overridden.\r\n\r\nIf you disable or don't configure this policy, the IPv6 reachability check will not be overridden.\r\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"da78d643a45be68c":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge.","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?linkid=2346300.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"dad150e8c7f640c4":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"da36c210d67dc34c":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb","displayName":"Set limit on megabytes of memory a single Microsoft Edge instance can use.","description":"Configures the amount of memory that a single Microsoft Edge instance can use before tabs start getting discarded to save memory. The memory used by the tab will be freed and the tab will have to be reloaded when switched to.\r\n\r\nIf you enable this policy, the browser will start to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024.\r\n\r\nIf you don't set this policy, the browser will only attempt to save memory when it has detected that the amount of physical memory on its machine is low.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_1","displayName":"Enabled","description":null,"helpText":null}]},"daf5e1733ce6ad35":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting","displayName":"Default sensors setting","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\r\n\r\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies access to sensors.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SensorsAllowedForUrls' (Allow access to sensors on specific sites) and 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policies.\r\n\r\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This is the global default for 'SensorsAllowedForUrls' and 'SensorsBlockedForUrls'.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowSensors (1) = Allow sites to access sensors\r\n\r\n* BlockSensors (2) = Do not allow any site to access sensors\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"da00dd677ab1a84f":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction","displayName":"Enable or disable the User-Agent Reduction","description":"The User-Agent HTTP request header is scheduled to be reduced. To facilitate testing and compatibility, this policy can enable the reduction feature for all websites, or disable the ability for origin trials, or field trials to enable the feature.\r\n\r\nIf you don't configure this policy or set it to Default, User-Agent will be controlled by experimentation.\r\n\r\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header.\r\n\r\nSet this policy to 'ForceDisabled' to force the full version of the User-Agent request header.\r\n\r\nTo learn more about the User-Agent string, read here:\r\n\r\nhttps://docs.microsoft.com/en-us/microsoft-edge/web-platform/user-agent-guidance.\r\n\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = User-Agent reduction will be controllable via Experimentation\r\n\r\n* ForceDisabled (1) = User-Agent reduction diabled, and not enabled by Experimentation\r\n\r\n* ForceEnabled (2) = User-Agent reduction will be enabled for all origins\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_1","displayName":"Enabled","description":null,"helpText":null}]},"dad1d0816353bac5":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_excelexe113","displayName":"excel.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_excelexe113_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_excelexe113_1","displayName":"True","description":null,"helpText":null}]},"dad94d186177146d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_spdesignexe177","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_spdesignexe177_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_spdesignexe177_1","displayName":"True","description":null,"helpText":null}]},"da0e9d4920d079f0":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mspubexe2","displayName":"mspub.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mspubexe2_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mspubexe2_1","displayName":"True","description":null,"helpText":null}]},"dae5251ca587082b":{"id":"device_vendor_msft_policy_config_start_disableeditingquicksettings","displayName":"Disable Editing Quick Settings","description":"Allows admin to disable editing Quick Settings, such as by accessing the 'Edit quick settings' context through right-clicking on Quick Settings buttons.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#disableeditingquicksettings"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_disableeditingquicksettings_0","displayName":"Enable editing Quick Settings.","description":"Enable editing Quick Settings.","helpText":null},{"id":"device_vendor_msft_policy_config_start_disableeditingquicksettings_1","displayName":"Disable editing Quick Settings.","description":"Disable editing Quick Settings.","helpText":null}]},"da78772d811250a6":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},"dad5447aa5d22744":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems85","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"dba1a547-e288-45ac-8553-27a3b564699e","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems85_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems85_1","displayName":"Enabled","description":null,"helpText":null}]},"da9969b8e3dbee83":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensaverissecure","displayName":"Password protect the screen saver (User)","description":"Determines whether screen savers used on the computer are password protected.\r\n\r\nIf you enable this setting, all screen savers are password protected. If you disable this setting, password protection cannot be set on any screen saver.\r\n\r\nThis setting also disables the \"Password protected\" checkbox on the Screen Saver dialog in the Personalization or Display Control Panel, preventing users from changing the password protection setting.\r\n\r\nIf you do not configure this setting, users can choose whether or not to set password protection on each screen saver.\r\n\r\nTo ensure that a computer will be password protected, enable the \"Enable Screen Saver\" setting and specify a timeout via the \"Screen Saver timeout\" setting.\r\n\r\nNote: To remove the Screen Saver dialog, use the \"Prevent changing Screen Saver\" setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-screensaverissecure"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensaverissecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensaverissecure_1","displayName":"Enabled","description":null,"helpText":null}]},"da140b73224b7579":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_dwp_nohtmlpaper","displayName":"Allow only bitmapped wallpaper (User)","description":"Permits only bitmap images for wallpaper. This setting limits the desktop background (\"wallpaper\") to bitmap (.bmp) files. If users select files with other image formats, such as JPEG, GIF, PNG, or HTML, through the Browse button on the Desktop tab, the wallpaper does not load. Files that are autoconverted to a .bmp format, such as JPEG, GIF, and PNG, can be set as Wallpaper by right-clicking the image and selecting \"Set as Wallpaper\".\r\n\r\nAlso, see the \"Desktop Wallpaper\" and the \"Prevent changing wallpaper\" (in User Configuration\\Administrative Templates\\Control Panel\\Display) settings.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-sz-dwp-nohtmlpaper"],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_sz_dwp_nohtmlpaper_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_sz_dwp_nohtmlpaper_1","displayName":"Enabled","description":null,"helpText":null}]},"da82244d6eebcd09":{"id":"user_vendor_msft_policy_config_admx_globalization_hidelanguageselection","displayName":"Hide the select language group options (User)","description":"This policy setting removes the option to change the user's menus and dialogs (UI) language from the Language and Regional Options control panel.\r\n\r\nThis policy setting is used only to simplify the Regional Options control panel.\r\n\r\nIf you enable this policy setting, the user does not see the option for changing the UI language. This does not prevent the user or an application from changing the UI language programmatically.\r\n\r\nIf you disable or do not configure this policy setting, the user sees the option for changing the UI language.\r\n\r\nNote: Even if a user can see the option to change the UI language, other policy settings can prevent them from changing their UI language.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-hidelanguageselection"],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"user_vendor_msft_policy_config_admx_globalization_hidelanguageselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_hidelanguageselection_1","displayName":"Enabled","description":null,"helpText":null}]},"da5a692febb53b56":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_raschangeproperties","displayName":"Prohibit access to properties of components of a remote access connection (User)","description":"Determines whether users can view and change the properties of components used by a private or all-user remote access connection.\r\n\r\nThis setting determines whether the Properties button for components used by a private or all-user remote access connection is enabled.\r\n\r\nIf you enable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), the Properties button is disabled for all users (including administrators).\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting does not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you disable this setting or do not configure it, the Properties button is enabled for all users.\r\n\r\nThe Networking tab of the Remote Access Connection Properties dialog box includes a list of the network components that the connection uses. To view or change the properties of a component, click the name of the component, and then click the Properties button beneath the component list.\r\n\r\nNote: Not all network components have configurable properties. For components that are not configurable, the Properties button is always disabled.\r\n\r\nNote: When the \"Ability to change properties of an all user remote access connection\" or \"Prohibit changing properties of a private remote access connection\" settings are set to deny access to the Remote Access Connection Properties dialog box, the Properties button for remote access connection components is blocked.\r\n\r\nNote: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-raschangeproperties"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_raschangeproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_raschangeproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"dac9596dc86862d6":{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown","displayName":"Choose one of the following actions (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_3","displayName":"Collapse","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_2","displayName":"Collapse and disable setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_1","displayName":"Remove and disable setting","description":null,"helpText":null}]},"daf0ccabd77f216a":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosearchfilesinstartmenu","displayName":"Do not search for files (User)","description":"If you enable this policy setting the Start menu search box will not search for files.\r\n\r\nIf you disable or do not configure this policy setting, the Start menu will search for files, unless the user chooses not to do so directly in Control Panel. If you enable this policy, a \"See more results\" / \"Search Everywhere\" link will not be shown when the user performs a search in the start menu search box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosearchfilesinstartmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosearchfilesinstartmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosearchfilesinstartmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"dad2b580b272659e":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit","displayName":"Active session limit : (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_0","displayName":"Never","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_432000000","displayName":"5 days","description":null,"helpText":null}]},"dab5c39eeda6c25a":{"id":"user_vendor_msft_policy_config_admx_wpn_nocallsduringquiethours","displayName":"Turn off calls during Quiet Hours (User)","description":"\r\n This policy setting blocks voice and video calls during Quiet Hours.\r\n\r\n If you enable this policy setting, voice and video calls will be blocked during the designated Quiet Hours time window each day, and users will not be able to customize any other Quiet Hours settings.\r\n\r\n If you disable this policy setting, voice and video calls will be allowed during Quiet Hours, and users will not be able to customize this or any other Quiet Hours settings.\r\n\r\n If you do not configure this policy setting, voice and video calls will be allowed during Quiet Hours by default. Adminstrators and users will be able to modify this setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-nocallsduringquiethours"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_admx_wpn_nocallsduringquiethours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_wpn_nocallsduringquiethours_1","displayName":"Enabled","description":null,"helpText":null}]},"dab384129130d402":{"id":"user_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary","displayName":"Allow Configuration Update For Books Library (User)","description":"This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowconfigurationupdateforbookslibrary"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary_1","displayName":"Allow","description":"Allowed. Microsoft Edge updates the configuration data for the Books Library automatically.","helpText":null}]},"da82b406a0e29bd3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed","displayName":"Enable additional protections for users enrolled in the Advanced Protection program (User)","description":"This policy controls whether users enrolled in the Advanced Protection program receive extra protections. Some of these features may involve the sharing of data with Google (for example, Advanced Protection users will be able to send their downloads to Google for malware scanning). If set to True or not set, enrolled users will receive extra protections. If set to False, Advanced Protection users will receive only the standard consumer features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"da2984d9ba17b49f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_proxyserver","displayName":"Address or URL of proxy server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"daba080aefae59d8":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_javascriptoptimizerallowedforsitesdesc","displayName":"Allow JavaScript optimization on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"da69a74f23fdd60b":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":null},"daed9f8215843abc":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"da5896a8d6efd92c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets","displayName":"Web pages and Excel 2003 XML spreadsheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_1","displayName":"Enabled","description":null,"helpText":null}]},"dafabcad433ce2ec":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"da60aa66630454b8":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script (User)","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script cannot perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowcopypasteviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"da3f21cd4c67e26b":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"da9ae5da8137e0d2":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"daa503f4ad3724af":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},"da6a6bbb88391e91":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting","displayName":"Control use of the Serial API (User)","description":"\r\nSet whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\r\n\r\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SerialAskForUrls' (Allow the Serial API on specific sites) and 'SerialBlockedForUrls' (Block the Serial API on specific sites) policies.\r\n\r\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\r\n\r\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"da76047d57ca58cd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7_1","displayName":"True","description":null,"helpText":null}]},"dad6676d88e8a3ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath_1","displayName":"True","description":null,"helpText":null}]},"da9ac954082f3ae4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm","displayName":"Configure legacy hashing algorithm (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as legacy when it contains specific hash algorithms.\r\n\r\nIf you enable this policy setting, you can specify the weakest hash algorithm that Office treats as legacy. You can specify any of the following algorithms:\r\n- MD5\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n\r\nIf you don’t configure this policy setting, Office treats digital signatures containing SHA1 or better as valid.\r\n\r\nFor example, if you set SHA256 as the legacy hashing algorithm, Office treats SHA384 signatures as valid.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"dae8cfca3d0fb0d4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_pathcolon310","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"dad1e80dc39c84c8":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard","displayName":"Don't allow copy and paste from Office documents opened in Application Guard. (User)","description":"This policy setting allows you to control whether users can copy and paste content from Office to and from documents opened in Application Guard.\r\nNote: Application Guard only allows copying text and images and doesn’t allow copying of rich content.\r\n\r\nIf you enable this policy setting, users can't copy and paste content to and from documents opened in Application Guard to other locations outside Application Guard.\r\n\r\nIf you disable or don't configure this policy setting, users can copy and paste content to and from documents opened in Application Guard to other locations outside Application Guard.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},"daf5c55bcc86b40b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber","displayName":"Use UserIssuerSerialNumber (User)","description":"This policy setting determines whether Outlook uses IssuerSerialNumber as the SignerIdentifier, which enables third-party email client software applications to read encrypted Outlook email messages. For more information about Cryptographic Message Syntax, refer to the RFC 5652 specification.\r\n\r\nIf you enable or do not configure this policy setting, Outlook uses the IssuerSerialNumber as the SignerIdentifier.\r\n\r\nIf you disable this policy setting, Outlook uses SubjectKeyIdentifier for the SignerIdentifier, which might prevent third-party email client software applications from reading encrypted Outlook email messages.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber_1","displayName":"Enabled","description":null,"helpText":null}]},"da34dc4f0a385bb2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel","displayName":"Security Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_2","displayName":"Always warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_4","displayName":"Never warn, disable all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_3","displayName":"Warn for signed, disable unsigned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_1","displayName":"No security check","description":null,"helpText":null}]},"da3ad3be2107faad":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},"da44bf3e215dd5fb":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat","displayName":"Date Format (User)","description":"Specifies the format for displaying dates. Some information, such as time formats and the date separator, is set through the Control Panel.\r\n \r\nIf you enable this setting, dates are displayed in the format you set.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_1","displayName":"Enabled","description":null,"helpText":null}]},"dac162f1c652e885":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"dad2a08542daf8fd":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},"da7b59d60e89859a":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch","displayName":"Prevent showing New screen on launch (User)","description":"This policy setting allows you to prevent the New screen to be shown on launch of Visio.\r\n\r\nIf you enable this policy setting, the New screen will not be shown on launch.\r\n\r\nIf you disable or do not configure this policy setting, the New screen, including a catalog of templates, is shown when you open Visio.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},"daa9d3c0f4e70731":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject","displayName":"Enable Microsoft Visual Basic for Applications project creation (User)","description":"Enables creations of VBA projects when you open (or create) a document that does not already contain a project. If you clear this check box, you will not be able to create a macro in a document that does not already contain a project.","helpText":"","infoUrls":[],"categoryId":"253fda23-118b-48c7-b24a-27b8c93df41a","categoryName":"Macro Security","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject_1","displayName":"Enabled","description":null,"helpText":null}]},"da3d92deaaa1a6b4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"da097dea613c3955":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"da50247a9d50121a":{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgebeta_pol_targetversionprefixmicrosoftedgebeta_part_targetversionprefix","displayName":"Target version (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","categoryName":"Microsoft Edge Beta","options":null},"da7fd05295158886":{"id":"com.apple.directoryservice.managed_admapggidattributeflag","displayName":"AD Map GGID Attribute Flag","description":"If true, enables the AD Map GGID Attribute Flag key.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":[{"id":"com.apple.directoryservice.managed_admapggidattributeflag_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.directoryservice.managed_admapggidattributeflag_true","displayName":"True","description":null,"helpText":null}]},"da4445dc766f18a5":{"id":"com.apple.ldap.account_ldapaccountpassword","displayName":"LDAP Account Password","description":"The user’s password. The password is enabled only with encrypted profiles.","helpText":null,"infoUrls":[],"categoryId":"9ba1b877-865a-4104-8376-b43a0c75b04b","categoryName":"LDAP","options":null},"dae804ba649f4ad5":{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled","displayName":"Save and fill memberships","description":"This policy lets you decide whether users can have their membership info (for example, program name and membership number) automatically saved and used to fill form fields while using Microsoft Edge. By default, users can choose whether to enable it or not.\n\nIf you enable this policy, users can only have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you don't configure this policy, users can choose whether to have their membership info automatically saved and used to fill form fields while using Microsoft Edge.\n\nIf you disable this policy, users can't have their membership info automatically saved and used to fill form fields while using Microsoft Edge.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#autofillmembershipsenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_autofillmembershipsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"dae1118b0a8dbe88":{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled","displayName":"Allow features to download assets from the Asset Delivery Service","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\nThese assets can be config files or Machine Learning models that power the features that use this service.\n\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\n\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeassetdeliveryserviceenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeassetdeliveryserviceenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"da8d17aae6f600f4":{"id":"com.apple.managedclient.preferences_relaunchnotificationperiod","displayName":"Set the time period for update notifications","description":"Allows you to set the time period, in milliseconds, over which users are notified that Microsoft Edge must be relaunched or that a Microsoft Edge OS device must be restarted to apply a pending update.\n\nOver this time period, the user will be repeatedly informed of the need for an update. For Microsoft Edge OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Microsoft Edge browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the \"RelaunchNotification\" policy follow this same schedule.\n\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#relaunchnotificationperiod"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"da1c98953a3cb17e":{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning","displayName":"Suppress the unsupported OS warning","description":"Suppresses the warning that appears when Microsoft Edge is running on a computer or operating system that is no longer supported.\n\nIf this policy is false or unset, the warnings will appear on such unsupported computers or operating systems.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#suppressunsupportedoswarning"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_suppressunsupportedoswarning_true","displayName":"Enabled","description":null,"helpText":null}]},"da41e733414f89ec":{"id":"com.apple.servicemanagement_com.apple.servicemanagement","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"9859957e-34f1-4669-9f95-2b7c79fff052","categoryName":"Service Management - Managed Login Items","options":null},"dada2d2db97173f2":{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts","displayName":"Allow user-level native messaging hosts (installed without admin permissions)","description":"If you set this policy to Enabled or leave it unset, Microsoft Edge can use native messaging hosts installed at the user level.\n\nIf you set this policy to Disabled, Microsoft Edge can only use these hosts if they're installed at the system level.","helpText":null,"infoUrls":[],"categoryId":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","categoryName":"Native Messaging","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.nativemessaginguserlevelhosts_true","displayName":"Enabled","description":null,"helpText":null}]},"da213314a513d832":{"id":"device_vendor_msft_defender_configuration_devicecontrol_policyrules_{ruleid}_ruledata_includedidlist","displayName":"Included Devices","description":"The group(s) that the policy will be applied to. If multiple groups are added, the policy will be applied to any media in all those groups.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/device-control-removable-storage-access-control"],"categoryId":"5ed18ca1-36d1-4375-bfd6-fd67801c2659","categoryName":null,"options":null},"da5f4063d5e728be":{"id":"device_vendor_msft_laps_policies_passwordagedays","displayName":"Password Age Days ","description":"Use this policy to configure the maximum password age of the managed local administrator account.\n\nIf not specified, this setting will default to 30 days\n\nThis setting has a minimum allowed value of 1 day when backing the password to onpremises Active Directory, and 7 days when backing the password to Microsoft Entra ID..\n\nThis setting has a maximum allowed value of 365 days.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},"dae04d376a3d5ef4":{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected","displayName":"Is Selected","description":"Indicates whether this Slot is selected or not.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/MultiSIM-csp/"],"categoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","categoryName":"Multi SIM","options":[{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected_false","displayName":"Not selected","description":"Not selected","helpText":null},{"id":"device_vendor_msft_multisim_{modemid}_slots_{slotid}_isselected_true","displayName":"Selected","description":"Selected","helpText":null}]},"da00ac77dfa5efec":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_driverinstall_classes_allowuser_driverinstall_classes_allowuser_list","displayName":"Allow Users to install driver packages for these classes:","description":"","helpText":"","infoUrls":[],"categoryId":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","categoryName":"Driver Installation","options":null},"daf8082b471e7558":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_ndncsitecoverage_netlogon_ndncsitecoveragelabel","displayName":"Sites:","description":null,"helpText":"","infoUrls":[],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":null},"da58514f9f44d57a":{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation","displayName":"Isolate print drivers from applications","description":"Determines if print driver components are isolated from applications instead of normally loading them into applications. Isolating print drivers greatly reduces the risk of a print driver failure causing an application crash.\r\n\r\nNot all applications support driver isolation. By default, Microsoft Excel 2007, Excel 2010, Word 2007, Word 2010 and certain other applications are configured to support it. Other applications may also be capable of isolating print drivers, depending on whether they are configured for it.\r\n\r\nIf you enable or do not configure this policy setting, then applications that are configured to support driver isolation will be isolated.\r\n\r\nIf you disable this policy setting, then print drivers will be loaded within all associated application processes.\r\n\r\nNotes:\r\n-This policy setting applies only to applications opted into isolation.\r\n-This policy setting applies only to print drivers loaded by applications. Print drivers loaded by the print spooler are not affected.\r\n-This policy setting is only checked once during the lifetime of a process. After changing the policy, a running application must be relaunched before settings take effect.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-applicationdriverisolation"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_applicationdriverisolation_1","displayName":"Enabled","description":null,"helpText":null}]},"daca37529aa6836a":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy","displayName":"Require use of specific security layer for remote (RDP) connections","description":"This policy setting specifies whether to require the use of a specific security layer to secure communications between clients and RD Session Host servers during Remote Desktop Protocol (RDP) connections.\r\n\r\nIf you enable this policy setting, all communications between clients and RD Session Host servers during remote connections must use the security method specified in this setting. The following security methods are available:\r\n\r\n* Negotiate: The Negotiate method enforces the most secure method that is supported by the client. If Transport Layer Security (TLS) version 1.0 is supported, it is used to authenticate the RD Session Host server. If TLS is not supported, native Remote Desktop Protocol (RDP) encryption is used to secure communications, but the RD Session Host server is not authenticated. Native RDP encryption (as opposed to SSL encryption) is not recommended.\r\n\r\n* RDP: The RDP method uses native RDP encryption to secure communications between the client and RD Session Host server. If you select this setting, the RD Session Host server is not authenticated. Native RDP encryption (as opposed to SSL encryption) is not recommended.\r\n\r\n* SSL (TLS 1.0): The SSL method requires the use of TLS 1.0 to authenticate the RD Session Host server. If TLS is not supported, the connection fails. This is the recommended setting for this policy.\r\n\r\nIf you disable or do not configure this policy setting, the security method to be used for remote connections to RD Session Host servers is not specified at the Group Policy level.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-security-layer-policy"],"categoryId":"579d6272-8708-4b22-a352-89cbd705ca82","categoryName":"Security","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_security_layer_policy_1","displayName":"Enabled","description":null,"helpText":null}]},"dab42d9e895b77e2":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint","displayName":"Microsoft PowerPoint 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft PowerPoint 2013.\r\nBy default, the user settings of Microsoft PowerPoint 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft PowerPoint 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft PowerPoint 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft PowerPoint 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013powerpoint"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpoint_1","displayName":"Enabled","description":null,"helpText":null}]},"da3f0009c95304dd":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown","displayName":"Allow OpenSearch queries in File Explorer","description":"\r\nThis policy setting allows you to manage whether OpenSearch queries in this zone can be performed using Search Connectors in File Explorer. Search Connectors allow rich searching of remote sources from within File Explorer. Search results will be returned in File Explorer and can be acted upon like local files.\r\n\r\nIf you enable this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you disable this policy setting, users are prevented from performing OpenSearch queries in this zone using Search Connectors.\r\n\r\nIf you do not configure this policy setting, users can perform OpenSearch queries in this zone using Search Connectors.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-iz-policy-opensearchquery-trustedlockdown"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_iz_policy_opensearchquery_trustedlockdown_1","displayName":"Enabled","description":null,"helpText":null}]},"da495ae0e056baca":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation","displayName":"Trust apps with good reputation","description":"When enabled, applications with known good reputation as defined by the Microsoft's Intelligent Security Graph (ISG) are white listed.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":[{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation_disabled","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_trustappswithgoodreputation_enabled","displayName":"Enabled","description":null,"helpText":null}]},"da2def72028eaab5":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_refresh_interval_prompt","displayName":"User Publishing Refresh Interval","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"daca404d7a3c17a6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport","displayName":"CORS non-wildcard request headers support","description":"Configures support of CORS non-wildcard request headers.\r\n\r\nGoogle Chrome version 97 introduces support for CORS non-wildcard request headers. When scripts make a cross-origin network request via fetch() and XMLHttpRequest with a script-added Authorization header, the header must be explicitly allowed by the Access-Control-Allow-Headers header in the CORS preflight response. \"Explicitly\" here means that the wild card symbol \"*\" doesn't cover the Authorization header. See https://www.chromest atus.com/feature/5768642492891136 for more detail.\r\n\r\nIf this policy is not set, or set to True, Google Chrome will support the CORS non-wildcard request headers and behave as described above.\r\n\r\nWhen this policy is set to False, chrome will allow the wildcard symbol (\"*\") in the Access-Control-Allow-Headers header in the CORS preflight response to cover the Authorization header.\r\n\r\nThis Enterprise policy is temporary; it's intended to be removed after Google Chrome version 103.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_corsnonwildcardrequestheaderssupport_1","displayName":"Enabled","description":null,"helpText":null}]},"da40b3d232fd04c6":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderimageurlpostparams_defaultsearchproviderimageurlpostparams","displayName":"Parameters for image URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"da307ed1b9127516":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled","displayName":"Allow download deep scanning for Safe Browsing-enabled users","description":"When this policy is enabled or left unset, Google Chrome can send suspicious downloads from Safe Browsing-enabled users to Google to scan for malware, or prompt users to provide a password for encrypted archives.\r\nWhen this policy is disabled, this scanning will not be performed.\r\nThis policy does not impact download content analysis configured by Chrome Enterprise Connectors.","helpText":"","infoUrls":[],"categoryId":"b485695b-0fae-41ae-861c-3030769b28df","categoryName":"Safe Browsing settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~safebrowsing_safebrowsingdeepscanningenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"da5a1a1f8ddad48e":{"id":"device_vendor_msft_policy_config_devicehealthmonitoring_configdevicehealthmonitoringscope","displayName":"[Deprecated] Config Device Health Monitoring Scope","description":"If the device is not opted-in to the DeviceHealthMonitoring service via the AllowDeviceHealthMonitoring then this policy has no meaning. For devices which are opted in, the value of this policy modifies which types of events are monitored.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeviceHealthMonitoring#configdevicehealthmonitoringscope"],"categoryId":"55c888df-44ff-49d1-808e-ad9cb8429aff","categoryName":"Device Health Monitoring","options":null},"dadc6106aa7143c7":{"id":"device_vendor_msft_policy_config_devicelock_devicepasswordenabled","displayName":"Device Password Enabled","description":"Specifies whether device lock is enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#devicepasswordenabled"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":[{"id":"device_vendor_msft_policy_config_devicelock_devicepasswordenabled_0","displayName":"Enabled","description":"Enabled","helpText":null},{"id":"device_vendor_msft_policy_config_devicelock_devicepasswordenabled_1","displayName":"Disabled","description":"Disabled","helpText":null}]},"da2e7688dc797065":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"da95842b3be4abd5":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"da39bd88c35db328":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions","displayName":"Download restrictions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_0","displayName":"No special restrictions","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_1","displayName":"Block dangerous downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_2","displayName":"Block potentially dangerous downloads","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_downloadrestrictions_3","displayName":"Block all downloads","description":null,"helpText":null}]},"da839c0470735877":{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled","displayName":"Enable IPv6 reachability check override","description":"This policy enables an override of the IPv6 reachability check. When overridden, the\r\nsystem will always query AAAA records when resolving host names. It applies to\r\nall users and interfaces on the device.\r\n\r\nIf you enable this policy, the IPv6 reachability check will be overridden.\r\n\r\nIf you disable or don't configure this policy, the IPv6 reachability check will not be overridden.\r\nThe system only queries AAAA records when it is reachable to a global IPv6 host.","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev132~policy~microsoft_edge~network_ipv6reachabilityoverrideenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"da78d643a45be68c":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended","displayName":"Controls the availability of browsing with Copilot in Microsoft Edge.","description":"When browsing with Copilot is enabled, users can explicitly invoke it for a query. It isn't invoked automatically.\r\n\r\nBrowsing with Copilot is available only on domains specified in the 'BrowsingWithCopilotAllowList' (Browsing with Copilot Allowed URLs) policy and is blocked on domains specified in the 'BrowsingWithCopilotBlockList' (Browsing with Copilot Blocked URLs) policy. If no domains are configured in the allow list, browsing with Copilot is effectively disabled.\r\n\r\nThis feature is available only to users with an active Microsoft 365 Copilot subscription.\r\n\r\nFor more information about configuring browsing with Copilot, see https://go.microsoft.com/fwlink/?LinkId=2341535.\r\n\r\nIf you enable this policy, browsing with Copilot is turned on for all users who receive the policy, and users can't turn it off.\r\n\r\nIf you disable this policy, browsing with Copilot is turned off for all users who receive the policy, and users can't turn it on.\r\n\r\nIf you don't configure this policy, browsing with Copilot is off by default, and users can turn it on.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge_recommended_allowbrowsingwithcopilot_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"dad150e8c7f640c4":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended~smartscreen_recommended_smartscreenpuaenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"da36c210d67dc34c":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb","displayName":"Set limit on megabytes of memory a single Microsoft Edge instance can use.","description":"Configures the amount of memory that a single Microsoft Edge instance can use before tabs start getting discarded to save memory. The memory used by the tab will be freed and the tab will have to be reloaded when switched to.\r\n\r\nIf you enable this policy, the browser will start to discard tabs to save memory once the limitation is exceeded. However, there is no guarantee that the browser is always running under the limit. Any value under 1024 will be rounded up to 1024.\r\n\r\nIf you don't set this policy, the browser will only attempt to save memory when it has detected that the amount of physical memory on its machine is low.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_totalmemorylimitmb_1","displayName":"Enabled","description":null,"helpText":null}]},"daf5e1733ce6ad35":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting","displayName":"Default sensors setting","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\r\n\r\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies access to sensors.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SensorsAllowedForUrls' (Allow access to sensors on specific sites) and 'SensorsBlockedForUrls' (Block access to sensors on specific sites) policies.\r\n\r\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This is the global default for 'SensorsAllowedForUrls' and 'SensorsBlockedForUrls'.\r\n\r\nPolicy options mapping:\r\n\r\n* AllowSensors (1) = Allow sites to access sensors\r\n\r\n* BlockSensors (2) = Do not allow any site to access sensors\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_1","displayName":"Enabled","description":null,"helpText":null}]},"da00dd677ab1a84f":{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction","displayName":"Enable or disable the User-Agent Reduction","description":"The User-Agent HTTP request header is scheduled to be reduced. To facilitate testing and compatibility, this policy can enable the reduction feature for all websites, or disable the ability for origin trials, or field trials to enable the feature.\r\n\r\nIf you don't configure this policy or set it to Default, User-Agent will be controlled by experimentation.\r\n\r\nSet this policy to 'ForceEnabled' to force the reduced version of the User-Agent request header.\r\n\r\nSet this policy to 'ForceDisabled' to force the full version of the User-Agent request header.\r\n\r\nTo learn more about the User-Agent string, read here:\r\n\r\nhttps://docs.microsoft.com/en-us/microsoft-edge/web-platform/user-agent-guidance.\r\n\r\n\r\nPolicy options mapping:\r\n\r\n* Default (0) = User-Agent reduction will be controllable via Experimentation\r\n\r\n* ForceDisabled (1) = User-Agent reduction diabled, and not enabled by Experimentation\r\n\r\n* ForceEnabled (2) = User-Agent reduction will be enabled for all origins\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_useragentreduction_1","displayName":"Enabled","description":null,"helpText":null}]},"dad1d0816353bac5":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_excelexe113","displayName":"excel.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_excelexe113_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_excelexe113_1","displayName":"True","description":null,"helpText":null}]},"dad94d186177146d":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_spdesignexe177","displayName":"spDesign.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_spdesignexe177_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_spdesignexe177_1","displayName":"True","description":null,"helpText":null}]},"da0e9d4920d079f0":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mspubexe2","displayName":"mspub.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mspubexe2_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_restrictfiledownload_l_mspubexe2_1","displayName":"True","description":null,"helpText":null}]},"dae5251ca587082b":{"id":"device_vendor_msft_policy_config_start_disableeditingquicksettings","displayName":"Disable Editing Quick Settings","description":"Allows admin to disable editing Quick Settings, such as by accessing the 'Edit quick settings' context through right-clicking on Quick Settings buttons.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#disableeditingquicksettings"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_disableeditingquicksettings_0","displayName":"Enable editing Quick Settings.","description":"Enable editing Quick Settings.","helpText":null},{"id":"device_vendor_msft_policy_config_start_disableeditingquicksettings_1","displayName":"Disable editing Quick Settings.","description":"Disable editing Quick Settings.","helpText":null}]},"da78772d811250a6":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"7eaa5e09-e5ab-4051-b557-64a124ae497c","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecbc","displayName":"Cipher Block Chaining (CBC)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_cryptography_l_configurecngcipherchainingmode_l_configurecngcipherchainingmodedropid_chainingmodecfb","displayName":"Cipher Feedback (CFB)","description":null,"helpText":null}]},"dad5447aa5d22744":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems85","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. The ID number needs to be in decimal (not hexadecimal). Multiple values should be separated by commas.\r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"dba1a547-e288-45ac-8553-27a3b564699e","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems85_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems85_1","displayName":"Enabled","description":null,"helpText":null}]},"da9969b8e3dbee83":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensaverissecure","displayName":"Password protect the screen saver (User)","description":"Determines whether screen savers used on the computer are password protected.\r\n\r\nIf you enable this setting, all screen savers are password protected. If you disable this setting, password protection cannot be set on any screen saver.\r\n\r\nThis setting also disables the \"Password protected\" checkbox on the Screen Saver dialog in the Personalization or Display Control Panel, preventing users from changing the password protection setting.\r\n\r\nIf you do not configure this setting, users can choose whether or not to set password protection on each screen saver.\r\n\r\nTo ensure that a computer will be password protected, enable the \"Enable Screen Saver\" setting and specify a timeout via the \"Screen Saver timeout\" setting.\r\n\r\nNote: To remove the Screen Saver dialog, use the \"Prevent changing Screen Saver\" setting.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-screensaverissecure"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensaverissecure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensaverissecure_1","displayName":"Enabled","description":null,"helpText":null}]},"da140b73224b7579":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_dwp_nohtmlpaper","displayName":"Allow only bitmapped wallpaper (User)","description":"Permits only bitmap images for wallpaper. This setting limits the desktop background (\"wallpaper\") to bitmap (.bmp) files. If users select files with other image formats, such as JPEG, GIF, PNG, or HTML, through the Browse button on the Desktop tab, the wallpaper does not load. Files that are autoconverted to a .bmp format, such as JPEG, GIF, and PNG, can be set as Wallpaper by right-clicking the image and selecting \"Set as Wallpaper\".\r\n\r\nAlso, see the \"Desktop Wallpaper\" and the \"Prevent changing wallpaper\" (in User Configuration\\Administrative Templates\\Control Panel\\Display) settings.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-sz-dwp-nohtmlpaper"],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_sz_dwp_nohtmlpaper_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_sz_dwp_nohtmlpaper_1","displayName":"Enabled","description":null,"helpText":null}]},"da82244d6eebcd09":{"id":"user_vendor_msft_policy_config_admx_globalization_hidelanguageselection","displayName":"Hide the select language group options (User)","description":"This policy setting removes the option to change the user's menus and dialogs (UI) language from the Language and Regional Options control panel.\r\n\r\nThis policy setting is used only to simplify the Regional Options control panel.\r\n\r\nIf you enable this policy setting, the user does not see the option for changing the UI language. This does not prevent the user or an application from changing the UI language programmatically.\r\n\r\nIf you disable or do not configure this policy setting, the user sees the option for changing the UI language.\r\n\r\nNote: Even if a user can see the option to change the UI language, other policy settings can prevent them from changing their UI language.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-globalization#admx-globalization-hidelanguageselection"],"categoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","categoryName":"Regional and Language Options","options":[{"id":"user_vendor_msft_policy_config_admx_globalization_hidelanguageselection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_globalization_hidelanguageselection_1","displayName":"Enabled","description":null,"helpText":null}]},"da5a692febb53b56":{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_raschangeproperties","displayName":"Prohibit access to properties of components of a remote access connection (User)","description":"Determines whether users can view and change the properties of components used by a private or all-user remote access connection.\r\n\r\nThis setting determines whether the Properties button for components used by a private or all-user remote access connection is enabled.\r\n\r\nIf you enable this setting (and enable the \"Enable Network Connections settings for Administrators\" setting), the Properties button is disabled for all users (including administrators).\r\n\r\nImportant: If the \"Enable Network Connections settings for Administrators\" is disabled or not configured, this setting does not apply to administrators on post-Windows 2000 computers.\r\n\r\nIf you disable this setting or do not configure it, the Properties button is enabled for all users.\r\n\r\nThe Networking tab of the Remote Access Connection Properties dialog box includes a list of the network components that the connection uses. To view or change the properties of a component, click the name of the component, and then click the Properties button beneath the component list.\r\n\r\nNote: Not all network components have configurable properties. For components that are not configurable, the Properties button is always disabled.\r\n\r\nNote: When the \"Ability to change properties of an all user remote access connection\" or \"Prohibit changing properties of a private remote access connection\" settings are set to deny access to the Remote Access Connection Properties dialog box, the Properties button for remote access connection components is blocked.\r\n\r\nNote: This setting does not prevent users from using other programs, such as Internet Explorer, to bypass this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-networkconnections#admx-networkconnections-nc-raschangeproperties"],"categoryId":"d982a1ef-84be-4832-99d4-8b71a4644b74","categoryName":"Network Connections","options":[{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_raschangeproperties_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_networkconnections_nc_raschangeproperties_1","displayName":"Enabled","description":null,"helpText":null}]},"dac9596dc86862d6":{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown","displayName":"Choose one of the following actions (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_0","displayName":"None","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_3","displayName":"Collapse","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_2","displayName":"Collapse and disable setting","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nomoreprogramslist_nomoreprogramslistdropdown_1","displayName":"Remove and disable setting","description":null,"helpText":null}]},"daf0ccabd77f216a":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosearchfilesinstartmenu","displayName":"Do not search for files (User)","description":"If you enable this policy setting the Start menu search box will not search for files.\r\n\r\nIf you disable or do not configure this policy setting, the Start menu will search for files, unless the user chooses not to do so directly in Control Panel. If you enable this policy, a \"See more results\" / \"Search Everywhere\" link will not be shown when the user performs a search in the start menu search box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosearchfilesinstartmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosearchfilesinstartmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosearchfilesinstartmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"dad2b580b272659e":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit","displayName":"Active session limit : (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","categoryName":"Session Time Limits","options":[{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_0","displayName":"Never","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_60000","displayName":"1 minute","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_300000","displayName":"5 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_600000","displayName":"10 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_900000","displayName":"15 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_1800000","displayName":"30 minutes","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_3600000","displayName":"1 hour","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_7200000","displayName":"2 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_10800000","displayName":"3 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_21600000","displayName":"6 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_28800000","displayName":"8 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_43200000","displayName":"12 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_57600000","displayName":"16 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_64800000","displayName":"18 hours","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_86400000","displayName":"1 day","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_172800000","displayName":"2 days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_259200000","displayName":"3 days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_345600000","displayName":"4 days","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_sessions_limits_1_ts_sessions_activelimit_432000000","displayName":"5 days","description":null,"helpText":null}]},"dab5c39eeda6c25a":{"id":"user_vendor_msft_policy_config_admx_wpn_nocallsduringquiethours","displayName":"Turn off calls during Quiet Hours (User)","description":"\r\n This policy setting blocks voice and video calls during Quiet Hours.\r\n\r\n If you enable this policy setting, voice and video calls will be blocked during the designated Quiet Hours time window each day, and users will not be able to customize any other Quiet Hours settings.\r\n\r\n If you disable this policy setting, voice and video calls will be allowed during Quiet Hours, and users will not be able to customize this or any other Quiet Hours settings.\r\n\r\n If you do not configure this policy setting, voice and video calls will be allowed during Quiet Hours by default. Adminstrators and users will be able to modify this setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-nocallsduringquiethours"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_admx_wpn_nocallsduringquiethours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_wpn_nocallsduringquiethours_1","displayName":"Enabled","description":null,"helpText":null}]},"dab384129130d402":{"id":"user_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary","displayName":"Allow Configuration Update For Books Library (User)","description":"This policy setting lets you decide whether Microsoft Edge can automatically update the configuration data for the Books Library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowconfigurationupdateforbookslibrary"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"user_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_browser_allowconfigurationupdateforbookslibrary_1","displayName":"Allow","description":"Allowed. Microsoft Edge updates the configuration data for the Books Library automatically.","helpText":null}]},"da82b406a0e29bd3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed","displayName":"Enable additional protections for users enrolled in the Advanced Protection program (User)","description":"This policy controls whether users enrolled in the Advanced Protection program receive extra protections. Some of these features may involve the sharing of data with Google (for example, Advanced Protection users will be able to send their downloads to Google for malware scanning). If set to True or not set, enrolled users will receive extra protections. If set to False, Advanced Protection users will receive only the standard consumer features.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_advancedprotectionallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"da2984d9ba17b49f":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_proxyserver_proxyserver","displayName":"Address or URL of proxy server (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"daba080aefae59d8":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_javascriptoptimizerallowedforsites_javascriptoptimizerallowedforsitesdesc","displayName":"Allow JavaScript optimization on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"da69a74f23fdd60b":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_disableitemsinuserinterface~l_custom_l_disableshortcutkeys166_l_enterakeyandmodifiertodisable","displayName":"Enter a key and modifier to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3b7e16e7-171f-4169-8904-c8483b06700d","categoryName":"Custom","options":null},"daed9f8215843abc":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_l_excel4workbooksdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"da5896a8d6efd92c":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets","displayName":"Web pages and Excel 2003 XML spreadsheets (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_webpagesandexcel2003xmlspreadsheets_1","displayName":"Enabled","description":null,"helpText":null}]},"dafabcad433ce2ec":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"da60aa66630454b8":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript","displayName":"Allow cut, copy or paste operations from the clipboard via script (User)","description":"This policy setting allows you to manage whether scripts can perform a clipboard operation (for example, cut, copy, and paste) in a specified region.\n\nIf you enable this policy setting, a script can perform a clipboard operation.\n\nIf you select Prompt in the drop-down box, users are queried as to whether to perform clipboard operations.\n\nIf you disable this policy setting, a script cannot perform a clipboard operation.\n\nIf you do not configure this policy setting, a script cannot perform a clipboard operation.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowcopypasteviascript"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowcopypasteviascript_1","displayName":"Enabled","description":null,"helpText":null}]},"da3f21cd4c67e26b":{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606","displayName":"Userdata persistence (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowuserdatapersistence_iz_partname1606_3","displayName":"Disable","description":null,"helpText":null}]},"da9ae5da8137e0d2":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchprovidername_defaultsearchprovidername","displayName":"Default search provider name (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"daa503f4ad3724af":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Microsoft Edge for server authentication with constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","categoryName":"Certificate management settings","options":null},"da6a6bbb88391e91":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting","displayName":"Control use of the Serial API (User)","description":"\r\nSet whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\r\n\r\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SerialAskForUrls' (Allow the Serial API on specific sites) and 'SerialBlockedForUrls' (Block the Serial API on specific sites) policies.\r\n\r\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\r\n\r\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"da76047d57ca58cd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice07_l_broadcastservicecreatesharednotes7_1","displayName":"True","description":null,"helpText":null}]},"dad6676d88e8a3ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath","displayName":"Disallow in InfoPath (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiinfopath_1","displayName":"True","description":null,"helpText":null}]},"da9ac954082f3ae4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm","displayName":"Configure legacy hashing algorithm (User)","description":"This policy setting allows you to configure whether Office displays a digital signature as legacy when it contains specific hash algorithms.\r\n\r\nIf you enable this policy setting, you can specify the weakest hash algorithm that Office treats as legacy. You can specify any of the following algorithms:\r\n- MD5\r\n- SHA1\r\n- SHA256\r\n- SHA384\r\n\r\nIf you don’t configure this policy setting, Office treats digital signatures containing SHA1 or better as valid.\r\n\r\nFor example, if you set SHA256 as the legacy hashing algorithm, Office treats SHA384 signatures as valid.","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacyhashingalgorithm_1","displayName":"Enabled","description":null,"helpText":null}]},"dae8cfca3d0fb0d4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc19_l_pathcolon310","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"dad1e80dc39c84c8":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard","displayName":"Don't allow copy and paste from Office documents opened in Application Guard. (User)","description":"This policy setting allows you to control whether users can copy and paste content from Office to and from documents opened in Application Guard.\r\nNote: Application Guard only allows copying text and images and doesn’t allow copying of rich content.\r\n\r\nIf you enable this policy setting, users can't copy and paste content to and from documents opened in Application Guard to other locations outside Application Guard.\r\n\r\nIf you disable or don't configure this policy setting, users can copy and paste content to and from documents opened in Application Guard to other locations outside Application Guard.\r\n\r\nNote: This policy setting only applies to Microsoft 365 Apps for enterprise.","helpText":"","infoUrls":[],"categoryId":"517e55f5-729f-4b4d-9555-33baa95a0e5a","categoryName":"Application Guard","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_applicationguard_l_turnoffclipboardaccessinapplicationguard_1","displayName":"Enabled","description":null,"helpText":null}]},"daf5c55bcc86b40b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber","displayName":"Use UserIssuerSerialNumber (User)","description":"This policy setting determines whether Outlook uses IssuerSerialNumber as the SignerIdentifier, which enables third-party email client software applications to read encrypted Outlook email messages. For more information about Cryptographic Message Syntax, refer to the RFC 5652 specification.\r\n\r\nIf you enable or do not configure this policy setting, Outlook uses the IssuerSerialNumber as the SignerIdentifier.\r\n\r\nIf you disable this policy setting, Outlook uses SubjectKeyIdentifier for the SignerIdentifier, which might prevent third-party email client software applications from reading encrypted Outlook email messages.","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_smimeuseissuerserialnumber_1","displayName":"Enabled","description":null,"helpText":null}]},"da34dc4f0a385bb2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel","displayName":"Security Level (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_2","displayName":"Always warn","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_4","displayName":"Never warn, disable all","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_3","displayName":"Warn for signed, disable unsigned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_trustcenter_l_securityleveloutlook_v2_l_securitylevel_1","displayName":"No security check","description":null,"helpText":null}]},"da3ad3be2107faad":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc10_l_allowsubfolders39_1","displayName":"True","description":null,"helpText":null}]},"da44bf3e215dd5fb":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat","displayName":"Date Format (User)","description":"Specifies the format for displaying dates. Some information, such as time formats and the date separator, is set through the Control Panel.\r\n \r\nIf you enable this setting, dates are displayed in the format you set.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","categoryName":"View","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjview_l_pjdateformat_1","displayName":"Enabled","description":null,"helpText":null}]},"dac162f1c652e885":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc10_l_datecolon45","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"dad2a08542daf8fd":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12","displayName":"Trusted Location #12 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc12_1","displayName":"Enabled","description":null,"helpText":null}]},"da7b59d60e89859a":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch","displayName":"Prevent showing New screen on launch (User)","description":"This policy setting allows you to prevent the New screen to be shown on launch of Visio.\r\n\r\nIf you enable this policy setting, the New screen will not be shown on launch.\r\n\r\nIf you disable or do not configure this policy setting, the New screen, including a catalog of templates, is shown when you open Visio.","helpText":"","infoUrls":[],"categoryId":"f59804be-7fc6-43c3-9baa-942aab85be84","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_display_l_preventshowingnewscreenonlaunch_1","displayName":"Enabled","description":null,"helpText":null}]},"daa9d3c0f4e70731":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject","displayName":"Enable Microsoft Visual Basic for Applications project creation (User)","description":"Enables creations of VBA projects when you open (or create) a document that does not already contain a project. If you clear this check box, you will not be able to create a macro in a document that does not already contain a project.","helpText":"","infoUrls":[],"categoryId":"253fda23-118b-48c7-b24a-27b8c93df41a","categoryName":"Macro Security","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_macrosecurity_l_enablemicrosoftvisualbasicforapplicationsproject_1","displayName":"Enabled","description":null,"helpText":null}]},"da3d92deaaa1a6b4":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions","displayName":"Disable all application add-ins (User)","description":"This policy setting disables all add-ins for the specified Office 2016 applications.\r\n \r\nIf you enable this policy setting, all add-ins for the specified Office 2016 applications are disabled.\r\n\r\nIf you disable or do not configure this policy setting, all add-ins for the specified Office 2016 applications are allowed to run without notifying the users, except if application add-ins are required to be signed by Trusted Publishers.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_disableallapplicationextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"da097dea613c3955":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork","displayName":"Turn off Trusted Documents on the network (User)","description":"This policy setting allows you to turn off the trusted documents feature for documents opened from the network.\r\n\r\nIf you enable this policy setting, users will always see security notifications for active content such as macros, ActiveX controls, data connections, etc. for documents opened from the network.\r\n\r\nIf you disable or do not configure this policy setting, the trusted documents feature allows users to always allow active content in documents such as macros, ActiveX controls, data connections, etc. so that users are not prompted the next time they open the documents. Trusted documents are exempt from security notifications.","helpText":"","infoUrls":[],"categoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter_l_turnofftrusteddocumentsonthenetwork_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/e6.json b/public/intune-definitions/e6.json index 71102cc20ee5..e94883a4afd3 100644 --- a/public/intune-definitions/e6.json +++ b/public/intune-definitions/e6.json @@ -1 +1 @@ -{"e62a3df1c05207af":{"id":"app_privacy_permissiondefaults_generickey_dictation","displayName":"Dictation","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of dictation.\n* `Allow`: The app privacy permission default is set to allow use of dictation.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_dictation_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_dictation_1","displayName":"Allow","description":null,"helpText":null}]},"e62fa8a60fd54ac6":{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification","displayName":"Allow Remote Apple Events Modification","description":"If 'false', prevents modifying Remote Apple Events Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification_true","displayName":"True","description":null,"helpText":null}]},"e6d1afb73aebef04":{"id":"com.apple.applicationaccess_ratingtvshowsau","displayName":"Rating TV Shows - Australia","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_1","displayName":"P","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_2","displayName":"C","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_3","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_4","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_5","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_6","displayName":"MA15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_7","displayName":"AV15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_8","displayName":"All","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_9","displayName":"All","description":null,"helpText":null}]},"e6ee5577286560f4":{"id":"com.apple.caldav.account_caldavaccountdescription","displayName":"Cal DAV Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},"e674c1d43ec820c5":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_application id","displayName":"Microsoft Teams Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"e6a6b660af1fa73c":{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Control whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device.\n\nIf you don't configure this policy, the default value (3, meaning users are asked each time) is used and users can change it.\n\n* 2 = Don't allow any site to request access to Bluetooth devices by using the Web Bluetooth API\n\n* 3 = Allow sites to ask the user to grant access to a nearby Bluetooth device","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwebbluetoothguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting_0","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting_1","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},"e6680bf62e316386":{"id":"com.apple.managedclient.preferences_scanarchives","displayName":"Scanning inside archive files","description":"If true, Defender will unpack archives and scan files inside them. Otherwise archive content will be skipped, that will improve scanning performance.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#scan-archives-on-demand-antivirus-scans-only"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_scanarchives_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scanarchives_true","displayName":"True","description":null,"helpText":null}]},"e6db8347c571e579":{"id":"com.apple.managedclient.preferences_scanhistorymaximumitems","displayName":"Scan history size","description":"Specify the maximum number of entries to keep in the scan history. Entries include all on-demand scans performed in the past and all antivirus detections.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#maximum-number-of-items-in-the-antivirus-scan-history"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"e693691724e1b2b3":{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy","displayName":"SharePoint Prioritization","description":"For hybrid scenarios where the email is the same for both SharePoint Server on-premises and SharePoint Online, determines whether or not the client should set up sync for SharePoint Server or SharePoint Online first during the first-run scenario.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremprioritizationpolicy"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy_0","displayName":"Prioritize SharePoint Online","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy_1","displayName":"Prioritize SharePoint Server","description":null,"helpText":null}]},"e65934226c6c518a":{"id":"com.apple.managedclient.preferences_smartactionsblocklist","displayName":"Block smart actions for a list of services","description":"List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\n\nIf you enable the policy:\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\n\nIf you disable or don't configure this policy:\n - The smart action in the mini and full context menu will be enabled for all profiles.\n - Users will see the smart action in the mini and full context menu on text selection.\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\n\nPolicy options mapping:\n\n* smart_actions (smart_actions) = Smart actions in pdfs and on websites\n\n* smart_actions_website (smart_actions_website) = Smart actions on websites\n\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartactionsblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"e6dc8205bc368f9a":{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription","displayName":"Password Content Description","description":"Contains a dictionary of keys for supported OS language IDs (for example, \"en-US\"), and whose values represent a localized description of the policy enforced by the regular expression. Use the special `default` key can for languages that aren't contained in the dictionary.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"e68242be1dc0cc2d":{"id":"com.apple.proxy.http.global_proxyusername","displayName":"Proxy Username","description":"The user name used to authenticate to the proxy server.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},"e6f175ebc087497e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page.","description":"This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled.\n\nIf you set this policy to 'EnableBothWorkDiscover' (0) or do not configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.\n\nIf you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the new tab page.\n\nIf you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the new tab page.\n\nThis policy works with the SetNTPDefaultFeedTab policy, which controls which feed tab is selected by default when both tabs are available.\n\nPolicy options mapping:\n\n* EnableBothWorkDiscover (0) = Enable both Work and Discover tabs\n\n* EnableOnlyWork (1) = Enable only Work tab\n\n* EnableOnlyDiscover (2) = Enable only Discover tab\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enablebothworkdiscover","displayName":"Enable both Work and Discover tabs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enableonlywork","displayName":"Enable only Work tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enableonlydiscover","displayName":"Enable only Discover tab","description":null,"helpText":null}]},"e6439af96b72b120":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallsources","displayName":"Configure extension and user script install sources","description":"Define URLs that can install extensions and themes.\n\nDefine URLs that can install extensions and themes directly without having to drag and drop the packages to the edge://extensions page.\n\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns. Don't host the files at a location that requires authentication.\n\nThe \"ExtensionInstallBlocklist\" policy takes precedence over this policy. Any extensions that's on the blocklist won't be installed, even if it comes from a site on this list.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"e60ecb4052c61d51":{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled","displayName":"Origin-keyed agent clustering enabled by default","description":"The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This functionality has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled.\n\nIf you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header are assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor isn't settable.\n\nIf you disable this policy, documents without the Origin-Agent-Cluster: header are assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor is settable.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2191896.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"e65ab229c4c71d9d":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext","displayName":"Display a custom message title when device installation is prevented by a policy setting","description":"This policy setting allows you to display a custom message title in a notification when a device installation is attempted and a policy setting prevents the installation.\r\n\r\nIf you enable this policy setting, Windows displays the text you type in the Main Text box as the title text of a notification when a policy setting prevents device installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows displays a default title in a notification when a policy setting prevents device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-deniedpolicy-simpletext"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_1","displayName":"Enabled","description":null,"helpText":null}]},"e66c590710772362":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername","displayName":"Register DNS records with connection-specific DNS suffix","description":"Specifies if a computer performing dynamic DNS registration will register A and PTR resource records with a concatenation of its computer name and a connection-specific DNS suffix, in addition to registering these records with a concatenation of its computer name and the primary DNS suffix.\r\n\r\nBy default, a DNS client performing dynamic DNS registration registers A and PTR resource records with a concatenation of its computer name and the primary DNS suffix. For example, a computer name of mycomputer and a primary DNS suffix of microsoft.com will be registered as: mycomputer.microsoft.com.\r\n\r\nIf you enable this policy setting, a computer will register A and PTR resource records with its connection-specific DNS suffix, in addition to the primary DNS suffix. This applies to all network connections used by computers that receive this policy setting.\r\n\r\nFor example, with a computer name of mycomputer, a primary DNS suffix of microsoft.com, and a connection specific DNS suffix of VPNconnection, a computer will register A and PTR resource records for mycomputer.VPNconnection and mycomputer.microsoft.com when this policy setting is enabled.\r\n\r\nImportant: This policy setting is ignored on a DNS client computer if dynamic DNS registration is disabled.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, a DNS client computer will not register any A and PTR resource records using a connection-specific DNS suffix.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registeradaptername"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername_1","displayName":"Enabled","description":null,"helpText":null}]},"e68fce46a245caac":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\r\n\r\nIf you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\r\n\r\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 1 megabyte.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logmaxsize-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_1","displayName":"Enabled","description":null,"helpText":null}]},"e64597fc8200e2c8":{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_startpinappswheninstalled_name","displayName":"Add AppIDs to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"e6603d2949c4d042":{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout","displayName":"Turn off tolerant and Z-shaped scratch-out gestures","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_1","displayName":"All","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_2","displayName":"Tolerant","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_3","displayName":"None","description":null,"helpText":null}]},"e6e4396e0c5751aa":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_teredoservernamebox","displayName":"Enter a Teredo server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},"e6587481f8368123":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016","displayName":"Microsoft Office 365 Excel 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Excel 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Excel 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Excel 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Excel 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Excel 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365excel2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016_1","displayName":"Enabled","description":null,"helpText":null}]},"e6f3dd604f3589fa":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath","displayName":"Settings template catalog path","description":"This policy setting configures where custom settings location templates are stored and if the catalog will be used to replace the default Microsoft templates installed with the UE-V Agent.\r\nIf you enable this policy setting, the UE-V Agent checks the specified location once each day and updates its synchronization behavior based on the templates in this location. Settings location templates added or updated since the last check are registered by the UE-V Agent. The UE-V Agent deregisters templates that were removed from this location.\r\nIf you specify a UNC path and leave the option to replace the default Microsoft templates unchecked, the UE-V Agent will use the default Microsoft templates installed by the UE-V Agent and custom templates in the settings template catalog. If there are custom templates in the settings template catalog which use the same ID as the default Microsoft templates, they will be ignored.\r\nIf you specify a UNC path and check the option to replace the default Microsoft templates, all of the default Microsoft templates installed by the UE-V Agent will be deleted from the computer and only the templates located in the settings template catalog will be used.\r\nIf you disable this policy setting, the UE-V Agent will not use the custom settings location templates. If you disable this policy setting after it has been enabled, the UE-V Agent will not restore the default Microsoft templates. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-settingstemplatecatalogpath"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_1","displayName":"Enabled","description":null,"helpText":null}]},"e6a4cbf23514aa7f":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},"e691144e182aa25a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_browserswitcherexternalsitelisturl","displayName":"URL of an XML file that contains URLs to load in an alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"e6007fc82542bf83":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls_serialallowusbdevicesforurls","displayName":"Automatically grant permission to sites to connect to USB serial devices. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"e680f8813f469ae2":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts","displayName":"Setting shortcuts on the New Tab Page (Beta)","description":"In development: for early preview only.\r\n\r\nSetting the policy pre-configures up to 10 custom shortcuts on the Google Chrome New Tab page.\r\n\r\nIf set, users will see these shortcuts by default and users can toggle between “My shortcuts,\" \"Most visited sites\" or \"My organization's shortcuts\" on the \"Customize Chrome\" panel. If empty or unset, the user will only be able to toggle between “My shortcuts\" or \"Most visited sites\" on the \"Customize Chrome\" panel.\r\n\r\nShortcut URLs must be unique.\r\n\r\nIf allow_user_edit is set to true, users can change the name of the shortcut. If set to false or unset, users cannot edit the name.\r\n\r\nIf allow_user_delete is set to true, users can remove the shortcut. If set to false or unset, users cannot remove the shortcut.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=NTPShortcuts for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"name\": \"Google\",\r\n \"url\": \"https://www.google.com\"\r\n },\r\n {\r\n \"name\": \"YouTube\",\r\n \"url\": \"https://www.youtube.com\"\r\n },\r\n {\r\n \"name\": \"Google Drive\",\r\n \"url\": \"https://www.drive.google.com\",\r\n \"allow_user_edit\": true,\r\n \"allow_user_delete\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"e61f537479199805":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed","description":"Controls if Google Chrome interacts with printer drivers from a separate service process. Platform printing calls to query available printers, get print driver settings, and submit documents for printing to local printers are made from a service process. Moving such calls out of the browser process helps improve stability and reduce frozen UI behavior in Print Preview.\r\n\r\nWhen this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks.\r\n\r\nWhen this policy is set to Disabled, Google Chrome will use the browser process for platform printing tasks.\r\n\r\nThis policy will be removed in the future, after the out-of-process print drivers feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"e65bd4bb60ac4204":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e65813067ac60742":{"id":"device_vendor_msft_policy_config_devicelock_allowsimpledevicepassword","displayName":"Allow Simple Device Password","description":"Specifies whether PINs or passwords such as 1111 or 1234 are allowed. For the desktop, it also controls the use of picture passwords.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#allowsimpledevicepassword"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":[{"id":"device_vendor_msft_policy_config_devicelock_allowsimpledevicepassword_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_devicelock_allowsimpledevicepassword_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"e6a0a4835b97c4a3":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingnetwork","displayName":"Network","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging of the Network component.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\Network\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingnetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingnetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"e667563090d49d00":{"id":"device_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms","displayName":"Check for signatures on downloaded programs","description":"This policy setting allows you to manage whether Internet Explorer checks for digital signatures (which identifies the publisher of signed software and verifies it hasn't been modified or tampered with) on user computers before downloading executable programs.\n\nIf you enable this policy setting, Internet Explorer will check the digital signatures of executable programs and display their identities before downloading them to user computers.\n\nIf you disable this policy setting, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.\n\nIf you do not configure this policy, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checksignaturesondownloadedprograms"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"e6d8a1f81d49ac98":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"e62b3fdeb4d8c2c0":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls","displayName":"Block cookies on specific sites","description":"Define a list of sites, based on URL patterns, that can't set cookies.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nSee the 'CookiesAllowedForUrls' (Allow cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- CookiesBlockedForUrls\r\n\r\n- 'CookiesAllowedForUrls'\r\n\r\n- 'CookiesSessionOnlyForUrls'\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"e69562e9bba93c18":{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\r\n\r\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\r\n\r\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\r\n\r\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\r\n\r\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\r\n\r\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\r\n\r\n* 4 = (Not currently used)\r\n\r\nThe richer formats may not be well-supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\r\n\r\nThe recommended policy is available in Microsoft Edge 105 or later.\r\n\r\nPolicy options mapping:\r\n\r\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\r\n\r\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\r\n\r\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e682453a6f77ab38":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e6bc1b225aef69ca":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"e6ab2e1736f52e32":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_exprwdexe108","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_exprwdexe108_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_exprwdexe108_1","displayName":"True","description":null,"helpText":null}]},"e6022aa8f079c407":{"id":"device_vendor_msft_policy_config_remotemanagement_turnoncompatibilityhttplistener","displayName":"Turn On Compatibility HTTP Listener","description":"This policy setting turns on or turns off an HTTP listener created for backward compatibility purposes in the Windows Remote Management (WinRM) service.\n\n If you enable this policy setting, the HTTP listener always appears.\n\n If you disable or do not configure this policy setting, the HTTP listener never appears.\n\n When certain port 80 listeners are migrated to WinRM 2.0, the listener port number changes to 5985.\n\n A listener might be automatically created on port 80 to ensure backward compatibility.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-turnoncompatibilityhttplistener"],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_turnoncompatibilityhttplistener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_turnoncompatibilityhttplistener_1","displayName":"Enabled","description":null,"helpText":null}]},"e6fe1d092d3cdfa2":{"id":"device_vendor_msft_policy_config_systemservices_configurexboxliveauthmanagerservicestartupmode","displayName":"Configure Xbox Live Auth Manager Service Startup Mode","description":"This setting determines whether the service's start type is Automatic(2), Manual(3), Disabled(4). Default: Manual.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-SystemServices#configurexboxliveauthmanagerservicestartupmode"],"categoryId":"4f29ef5c-6ca0-4b09-893f-01755a670877","categoryName":"System Services","options":[{"id":"device_vendor_msft_policy_config_systemservices_configurexboxliveauthmanagerservicestartupmode_2","displayName":"Automatic","description":"Automatic","helpText":null},{"id":"device_vendor_msft_policy_config_systemservices_configurexboxliveauthmanagerservicestartupmode_3","displayName":"Manual","description":"Manual","helpText":null},{"id":"device_vendor_msft_policy_config_systemservices_configurexboxliveauthmanagerservicestartupmode_4","displayName":"Disabled","description":"Disabled","helpText":null}]},"e6976e9293865bc0":{"id":"device_vendor_msft_policy_config_update_configuredeadlineforqualityupdates","displayName":"Quality Update Deadline Period (Days)","description":"Number of days before quality updates are installed on devices automatically regardless of active hours. Before the deadline passes, users will be able to schedule restarts, and automatic restarts can happen outside of active hours. When set to 0, updates will download and install immediately, but might not finish within the day due to device availability and network connectivity.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlineforqualityupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"e65722a7c90b8a7b":{"id":"device_vendor_msft_policy_config_userrights_denyaccessfromnetwork","displayName":"Deny Access From Network","description":"This user right determines which users are prevented from accessing a computer over the network. This policy setting supersedes the Access this computer from the network policy setting if a user account is subject to both policies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#denyaccessfromnetwork"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"e630db2cfa41586b":{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setlowriskinclusion","displayName":"Inclusion list for low file types (User)","description":"This policy setting allows you to configure the list of low-risk file types. If the attachment is in the list of low-risk file types, Windows will not prompt the user before accessing the file, regardless of the file's zone information. This inclusion list overrides the list of high-risk file types built into Windows and has a lower precedence than the high-risk or medium-risk inclusion lists (where an extension is listed in more than one inclusion list).\r\n\r\nIf you enable this policy setting, you can specify file types that pose a low risk.\r\n\r\nIf you disable this policy setting, Windows uses its default trust logic.\r\n\r\nIf you do not configure this policy setting, Windows uses its default trust logic.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-attachmentmanager#admx-attachmentmanager-am-setlowriskinclusion"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setlowriskinclusion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setlowriskinclusion_1","displayName":"Enabled","description":null,"helpText":null}]},"e6e25ba4ba14300b":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrateuser_gprefreshrate3","displayName":"Minutes: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"e60f9a3d3eb06e2f":{"id":"user_vendor_msft_policy_config_admx_printing_packagepointandprintonly","displayName":"Only use Package Point and print (User)","description":"This policy restricts clients computers to use package point and print only.\r\n\r\nIf this setting is enabled, users will only be able to point and print to printers that use package-aware drivers. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.\r\n\r\nIf this setting is disabled, or not configured, users will not be restricted to package-aware point and print only.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-packagepointandprintonly"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_admx_printing_packagepointandprintonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_printing_packagepointandprintonly_1","displayName":"Enabled","description":null,"helpText":null}]},"e62a7ac462075755":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled","displayName":"Enables the concept of policy atomic groups (User)","description":"Setting the policy to Enabled means policies coming from an atomic group that don't share the source with the highest priority from that group get ignored.\r\n\r\nSetting the policy to Disabled means no policy is ignored because of its source. Policies are ignored only if there's a conflict, and the policy doesn't have the highest priority.\r\n\r\nIf this policy is set from a cloud source, it can't target a specific user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e6596bcc7866cbc5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory (User)","description":"Setting the policy changes the default directory that Chrome downloads files to, but users can change the directory.\r\n\r\nLeaving the policy unset means Chrome uses its platform-specific default directory.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e6a8a9d3434856af":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended","displayName":"Default search provider name (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e646eca508de10e9":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"e6d6d1c4f4c0717c":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides","displayName":"Override First-Party Sets. (User)","description":"This policy provides a way to override the list of sets the browser uses for First-Party Sets features.\r\n\r\nEach set in the browser's list of First-Party Sets must meet the requirements of a First-Party Set.\r\nA First-Party Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all of its ccTLD variants.\r\nSee https://github.com/WICG/first-party-sets for more information on First-Party Sets are used by Google Chrome.\r\n\r\nAll sites in a First-Party Set must be a registrable domain served over HTTPS. Each site in a First-Party Set must also be unique,\r\nmeaning a site cannot be listed more than once in a First-Party Set.\r\n\r\nWhen this policy is given an empty dictionary, the browser uses the public list of First-Party Sets.\r\n\r\nFor all sites in a First-Party Set from the replacements list, if a site is also present\r\non a First-Party Set in the browser's list, then that site will be removed from the browser's First-Party Set.\r\nAfter this, the policy's First-Party Set will be added to the browser's list of First-Party Sets.\r\n\r\nFor all sites in a First-Party Set from the additions list, if a site is also present\r\non a First-Party Set in the browser's list, then the browser's First-Party Set will be updated so that the\r\nnew First-Party Set can be added to the browser's list. After the browser's list has been updated,\r\nthe policy's First-Party Set will be added to the browser's list of First-Party Sets.\r\n\r\nThe browser's list of First-Party Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site cannot be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) are not supported as a policy value, nor within any First-Party Set in these lists.\r\n\r\nAll sets provided by the policy must be valid First-Party Sets, if they aren't then an\r\nappropriate error will be outputted.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nThis is the equivalent of the RelatedWebsiteSetsOverrides policy.\r\nEither policy may be used, but this one will be deprecated soon so the RelatedWebsiteSetsOverrides policy is preferred.\r\nThey both have the same effect on the browser's behavior.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=FirstPartySetsOverrides for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},"e62172543f2c7c44":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection","displayName":"Default sheet direction (User)","description":"This setting controls the default sheet direction, which is either \"Left to Right\" or \"Right to Left\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_1","displayName":"Enabled","description":null,"helpText":null}]},"e68216e20a2f9eb2":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell","displayName":"Edit directly in cell (User)","description":"This policy setting sets the \"Edit directly in cell\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will allow editing directly in the cell This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not allow editing to be done directly in the cell.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell_1","displayName":"Enabled","description":null,"helpText":null}]},"e6e08667ba434b29":{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},"e645a7da080eae9e":{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation","displayName":"Check for server certificate revocation (User)","description":"This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates. Certificates are revoked when they have been compromised or are no longer valid, and this option protects users from submitting confidential data to a site that may be fraudulent or not secure.\n\nIf you enable this policy setting, Internet Explorer will check to see if server certificates have been revoked.\n\nIf you disable this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.\n\nIf you do not configure this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checkservercertificaterevocation"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_1","displayName":"Enabled","description":null,"helpText":null}]},"e60c97447f1b19ef":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"e66aa37cee63f4b1":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist","displayName":"Define a list of allowed URLs (User)","description":"Allow access to the listed URLs, as exceptions to the URL block list.\r\n\r\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nYou can use this policy to open exceptions to restrictive block lists. For example, you can include '*' in the block list to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\r\n\r\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the block list.\r\n\r\nThis policy is limited to 1000 entries; subsequent entries are ignored.\r\n\r\nIf you don't configure this policy, there are no exceptions to the block list in the 'URLBlocklist' (Block access to a list of URLs) policy.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"e67c8cac8f58ee92":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},"e6fc06e128801643":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday_l_birthdaymapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"e616e0ca8909d396":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject_1","displayName":"True","description":null,"helpText":null}]},"e67a7aaa665bd6bb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries","displayName":"Turn off Outlook name dictionaries update (User)","description":"This policy setting allows you to turn off updating for Outlook name dictionaries of Microsoft IME (Input Method Editor). This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, all Outlook name dictionaries are not updated.\r\nOutlook name dictionaries that were added before enabling this policy setting are used for conversion.\r\n\r\nIf you disable or do not configure this policy setting, Outlook name dictionaries are generated, updated and used for conversion.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries_1","displayName":"Enabled","description":null,"helpText":null}]},"e66070f5e05a8df6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite_l_changeordeletelinktolanguagepackdownloadsiteid","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":null},"e640a4d44a2363c6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari","displayName":"Dari (User)","description":"Enables the editing language Dari","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari_1","displayName":"Enabled","description":null,"helpText":null}]},"e63dcc460e98671f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers","displayName":"Disable Clipboard Toolbar triggers (User)","description":"Checked: Prevents the Office Clipboard from automatically appearing when multiple Copy commands are performed in any of the Office programs. | Unchecked: Permits the Office Clipboard to appear automatically when multiple Copy commands are performed in Office programs.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers_1","displayName":"Enabled","description":null,"helpText":null}]},"e6a87cd298ffee6e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12","displayName":"Workflow Cache 12 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_1","displayName":"Enabled","description":null,"helpText":null}]},"e6148b8c87cf7a47":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowcachename498","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"e6dbb5adf8e2a508":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_pathcolon08","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"e685c71017f40b7f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons","displayName":"Show AutoCorrect Options buttons (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},"e6bd8c8a4c1adffa":{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan","displayName":"Force Runtime AV Scan (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365. \r\n\r\nThis policy setting controls when Office files are scanned at runtime by an installed Anti-Virus software.\r\n\r\nNote, files will only be scanned if the Anti-Virus software registers as a provider for runtime scanning.\r\n\r\nIf you enable this policy setting, Office applications will submit all files for a runtime scan by Antivirus.\r\n\r\nIf you disable or do not configure this policy setting, Office will selectively submit certain files, for example encrypted files, for a runtime scan by Antivirus.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan_1","displayName":"Enabled","description":null,"helpText":null}]},"e6f1879c689f4904":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot","displayName":"Prevent users from changing the location of their OneDrive folder (User)","description":"This setting lets you block users from changing the location of their OneDrive - {organization name} folder during setup of the OneDrive sync app.\r\n\r\nIf you enable this setting, the \"Change location\" link is hidden in OneDrive Setup. The OneDrive folder will be created in the default location, or in the custom location you specified if you enabled the \"Set the default location for the OneDrive folder\" setting.\r\n\r\nIf you disable or do not configure this setting, users can click the \"Change location\" link to change the location of their OneDrive folder in OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_1","displayName":"Enabled","description":null,"helpText":null}]},"e668a8b6103b6d3d":{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_l_empty17","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"e66383c95e0acc63":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart","displayName":"Configure form regions permissions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_0","displayName":"All form regions are allowed to run","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_1","displayName":"Allow only those registered in HKLM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_2","displayName":"No form regions are allowed to run","description":null,"helpText":null}]},"e681828e539440b3":{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice","displayName":"Prevent Outlook from interacting with the account settings detection service (User)","description":"This policy setting determines whether Outlook can interact with the account settings detection service to gather information about a user's account settings.\r\n\r\nIf you enable this policy setting, users will need to manually configure their account settings.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice_1","displayName":"Enabled","description":null,"helpText":null}]},"e6f689a4500c6c26":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers","displayName":"Don’t show redirect warnings for Autodiscover for the specified HTTPS server names (User)","description":"This policy setting allows you to specify HTTPS server names for which Autodiscover won’t show a warning message when redirecting from HTTP to HTTPS.\r\n\r\nBy default, when an Autodiscover operation redirects from HTTP to HTTPS, you may be shown a warning message about the redirection.\r\n\r\nIf you enable this policy setting, you need to specify HTTPS server names, and for those server names, you won’t be shown a warning message. For example, if you enter contoso.com, you won’t be shown a warning message when Autodiscover redirects to https://contoso.com.\r\n\r\nIf you disable or don’t configure this policy setting, you may be shown a warning message when an Autodiscover operation redirects from HTTP to HTTPS.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_1","displayName":"Enabled","description":null,"helpText":null}]},"e6b63b039ff7721f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist","displayName":"Number of presentations in the Recent Presentations list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Presentations list that appears when users click Open on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Presentations list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Presentations list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},"e69d54881d429549":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},"e68e0ae7bb1e9832":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9","displayName":"Hours (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_0","displayName":"h","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_1","displayName":"hr","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_2","displayName":"hour","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_4","displayName":"\r\n ","description":null,"helpText":null}]},"e6364c90710f7d6e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation","displayName":"Provide feedback with animation (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"e62a3df1c05207af":{"id":"app_privacy_permissiondefaults_generickey_dictation","displayName":"Dictation","description":"Controls whether an app privacy permission default is set.\n* `None`: No app privacy permission default is set for use of dictation.\n* `Allow`: The app privacy permission default is set to allow use of dictation.","helpText":null,"infoUrls":[],"categoryId":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","categoryName":"App Settings","options":[{"id":"app_privacy_permissiondefaults_generickey_dictation_0","displayName":"None","description":null,"helpText":null},{"id":"app_privacy_permissiondefaults_generickey_dictation_1","displayName":"Allow","description":null,"helpText":null}]},"e62fa8a60fd54ac6":{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification","displayName":"Allow Remote Apple Events Modification","description":"If 'false', prevents modifying Remote Apple Events Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowremoteappleeventsmodification_true","displayName":"True","description":null,"helpText":null}]},"e6d1afb73aebef04":{"id":"com.apple.applicationaccess_ratingtvshowsau","displayName":"Rating TV Shows - Australia","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsau_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_1","displayName":"P","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_2","displayName":"C","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_3","displayName":"G","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_4","displayName":"PG","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_5","displayName":"M","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_6","displayName":"MA15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_7","displayName":"AV15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_8","displayName":"All","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsau_9","displayName":"All","description":null,"helpText":null}]},"e6ee5577286560f4":{"id":"com.apple.caldav.account_caldavaccountdescription","displayName":"Cal DAV Account Description","description":"The description of the account.","helpText":null,"infoUrls":[],"categoryId":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","categoryName":"Caldav","options":null},"e674c1d43ec820c5":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft teams.app_application id","displayName":"Microsoft Teams Application ID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"e6a6b660af1fa73c":{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting","displayName":"Control use of the Web Bluetooth API","description":"Control whether websites can access nearby Bluetooth devices. You can completely block access or require the site to ask the user each time it wants to access a Bluetooth device.\n\nIf you don't configure this policy, the default value (3, meaning users are asked each time) is used and users can change it.\n\n* 2 = Don't allow any site to request access to Bluetooth devices by using the Web Bluetooth API\n\n* 3 = Allow sites to ask the user to grant access to a nearby Bluetooth device","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultwebbluetoothguardsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting_0","displayName":"Do not allow any site to request access to Bluetooth devices via the Web Bluetooth API","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultwebbluetoothguardsetting_1","displayName":"Allow sites to ask the user to grant access to a nearby Bluetooth device","description":null,"helpText":null}]},"e6680bf62e316386":{"id":"com.apple.managedclient.preferences_scanarchives","displayName":"Scanning inside archive files","description":"If true, Defender will unpack archives and scan files inside them. Otherwise archive content will be skipped, that will improve scanning performance.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/mac-preferences?view=o365-worldwide#scan-archives-on-demand-antivirus-scans-only"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_scanarchives_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_scanarchives_true","displayName":"True","description":null,"helpText":null}]},"e6db8347c571e579":{"id":"com.apple.managedclient.preferences_scanhistorymaximumitems","displayName":"Scan history size","description":"Specify the maximum number of entries to keep in the scan history. Entries include all on-demand scans performed in the past and all antivirus detections.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#maximum-number-of-items-in-the-antivirus-scan-history"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"e693691724e1b2b3":{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy","displayName":"SharePoint Prioritization","description":"For hybrid scenarios where the email is the same for both SharePoint Server on-premises and SharePoint Online, determines whether or not the client should set up sync for SharePoint Server or SharePoint Online first during the first-run scenario.","helpText":null,"infoUrls":["https://learn.microsoft.com/sharepoint/deploy-and-configure-on-macos#sharepointonpremprioritizationpolicy"],"categoryId":"19ba782c-3594-45da-b829-72b54f6d45c7","categoryName":"Microsoft OneDrive","options":[{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy_0","displayName":"Prioritize SharePoint Online","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_sharepointonpremprioritizationpolicy_1","displayName":"Prioritize SharePoint Server","description":null,"helpText":null}]},"e65934226c6c518a":{"id":"com.apple.managedclient.preferences_smartactionsblocklist","displayName":"Block smart actions for a list of services","description":"List specific services, such as PDFs, and websites that don't show smart actions. (Smart actions are actions like \"define\" which are available in full and mini context menus in Microsoft Edge.)\n\nIf you enable the policy:\n - The smart action in the mini and full context menu will be disabled for all profiles for services that match the given list.\n - Users will not see the smart action in the mini and full context menu on text selection for services that match the given list.\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be disabled for services that match the given list.\n\nIf you disable or don't configure this policy:\n - The smart action in the mini and full context menu will be enabled for all profiles.\n - Users will see the smart action in the mini and full context menu on text selection.\n - In Microsoft Edge settings, the smart action in the mini and full context menu will be enabled.\n\nPolicy options mapping:\n\n* smart_actions (smart_actions) = Smart actions in pdfs and on websites\n\n* smart_actions_website (smart_actions_website) = Smart actions on websites\n\n* smart_actions_pdf (smart_actions_pdf) = Smart actions in PDF\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartactionsblocklist"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"e6dc8205bc368f9a":{"id":"com.apple.mobiledevice.passwordpolicy_customregex_passwordcontentdescription","displayName":"Password Content Description","description":"Contains a dictionary of keys for supported OS language IDs (for example, \"en-US\"), and whose values represent a localized description of the policy enforced by the regular expression. Use the special `default` key can for languages that aren't contained in the dictionary.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"e68242be1dc0cc2d":{"id":"com.apple.proxy.http.global_proxyusername","displayName":"Proxy Username","description":"The user name used to authenticate to the proxy server.","helpText":null,"infoUrls":[],"categoryId":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","categoryName":"Global HTTP Proxy","options":null},"e6f175ebc087497e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility","displayName":"Configure whether the Discover or Work feed tabs are shown on the New Tab Page.","description":"This policy configures whether the Discover or Work feed tabs are shown on the New Tab Page. By default, both Work and Discover tabs are enabled.\n\nIf you set this policy to 'EnableBothWorkDiscover' (0) or do not configure this policy, Microsoft Edge shows both the Work and Discover feed tabs on the new tab page.\n\nIf you set this policy to 'EnableOnlyWork' (1), Microsoft Edge shows only the Work feed tab on the new tab page.\n\nIf you set this policy to 'EnableOnlyDiscover' (2), Microsoft Edge shows only the Discover feed tab on the new tab page.\n\nThis policy works with the SetNTPDefaultFeedTab policy, which controls which feed tab is selected by default when both tabs are available.\n\nPolicy options mapping:\n\n* EnableBothWorkDiscover (0) = Enable both Work and Discover tabs\n\n* EnableOnlyWork (1) = Enable only Work tab\n\n* EnableOnlyDiscover (2) = Enable only Discover tab\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enablebothworkdiscover","displayName":"Enable both Work and Discover tabs","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enableonlywork","displayName":"Enable only Work tab","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.configurentpfeedtabvisibility_enableonlydiscover","displayName":"Enable only Discover tab","description":null,"helpText":null}]},"e6439af96b72b120":{"id":"com.microsoft.edge.mamedgeappconfigsettings.extensioninstallsources","displayName":"Configure extension and user script install sources","description":"Define URLs that can install extensions and themes.\n\nDefine URLs that can install extensions and themes directly without having to drag and drop the packages to the edge://extensions page.\n\nEach item in this list is an extension-style match pattern (see https://go.microsoft.com/fwlink/?linkid=2095039). Users can easily install items from any URL that matches an item in this list. Both the location of the *.crx file and the page where the download is started from (in other words, the referrer) must be allowed by these patterns. Don't host the files at a location that requires authentication.\n\nThe \"ExtensionInstallBlocklist\" policy takes precedence over this policy. Any extensions that's on the blocklist won't be installed, even if it comes from a site on this list.","helpText":null,"infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"e60ecb4052c61d51":{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled","displayName":"Origin-keyed agent clustering enabled by default","description":"The Origin-Agent-Cluster: HTTP header controls whether a document is isolated in an origin-keyed agent cluster or in a site-keyed agent cluster. This functionality has security implications because an origin-keyed agent cluster allows isolating documents by origin. The consequence of this for developers is that the document.domain accessor can no longer be set when origin-keyed agent clustering is enabled.\n\nIf you enable or don't configure this policy, documents without the Origin-Agent-Cluster: header are assigned to origin-keyed agent clustering by default. On these documents, the document.domain accessor isn't settable.\n\nIf you disable this policy, documents without the Origin-Agent-Cluster: header are assigned to site-keyed agent clusters by default. On these documents, the document.domain accessor is settable.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2191896.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.originagentclusterdefaultenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"e64f274756c413aa":{"id":"contentcaching_peerfilterranges","displayName":"Peer Filter Ranges","description":"An array of dictionaries describing a range of peer IP addresses that the content cache uses to filter its list of peers to query for content. The content cache only queries peers in `PeerFilterRanges`. When `PeerFilterRanges` is an empty array, the content cache doesn't query any peers.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"e692f609a8661b78":{"id":"contentcaching_publicranges","displayName":"Public Ranges","description":"An array of dictionaries describing a range of public IP addresses that the cloud servers should use for matching clients to content caches.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"e65ab229c4c71d9d":{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext","displayName":"Display a custom message title when device installation is prevented by a policy setting","description":"This policy setting allows you to display a custom message title in a notification when a device installation is attempted and a policy setting prevents the installation.\r\n\r\nIf you enable this policy setting, Windows displays the text you type in the Main Text box as the title text of a notification when a policy setting prevents device installation.\r\n\r\nIf you disable or do not configure this policy setting, Windows displays a default title in a notification when a policy setting prevents device installation.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-deviceinstallation#admx-deviceinstallation-deviceinstall-deniedpolicy-simpletext"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":[{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_deviceinstallation_deviceinstall_deniedpolicy_simpletext_1","displayName":"Enabled","description":null,"helpText":null}]},"e66c590710772362":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername","displayName":"Register DNS records with connection-specific DNS suffix","description":"Specifies if a computer performing dynamic DNS registration will register A and PTR resource records with a concatenation of its computer name and a connection-specific DNS suffix, in addition to registering these records with a concatenation of its computer name and the primary DNS suffix.\r\n\r\nBy default, a DNS client performing dynamic DNS registration registers A and PTR resource records with a concatenation of its computer name and the primary DNS suffix. For example, a computer name of mycomputer and a primary DNS suffix of microsoft.com will be registered as: mycomputer.microsoft.com.\r\n\r\nIf you enable this policy setting, a computer will register A and PTR resource records with its connection-specific DNS suffix, in addition to the primary DNS suffix. This applies to all network connections used by computers that receive this policy setting.\r\n\r\nFor example, with a computer name of mycomputer, a primary DNS suffix of microsoft.com, and a connection specific DNS suffix of VPNconnection, a computer will register A and PTR resource records for mycomputer.VPNconnection and mycomputer.microsoft.com when this policy setting is enabled.\r\n\r\nImportant: This policy setting is ignored on a DNS client computer if dynamic DNS registration is disabled.\r\n\r\nIf you disable this policy setting, or if you do not configure this policy setting, a DNS client computer will not register any A and PTR resource records using a connection-specific DNS suffix.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-registeradaptername"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_registeradaptername_1","displayName":"Enabled","description":null,"helpText":null}]},"e68fce46a245caac":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\r\n\r\nIf you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\r\n\r\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 1 megabyte.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logmaxsize-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logmaxsize_3_1","displayName":"Enabled","description":null,"helpText":null}]},"e64597fc8200e2c8":{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_startpinappswheninstalled_name","displayName":"Add AppIDs to the list:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"e6603d2949c4d042":{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout","displayName":"Turn off tolerant and Z-shaped scratch-out gestures","description":null,"helpText":"","infoUrls":[],"categoryId":"395a548d-737b-41fe-8449-c68c51e3a349","categoryName":"Input Panel","options":[{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_1","displayName":"All","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_2","displayName":"Tolerant","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletpcinputpanel_scratchout_2_scratchout_3","displayName":"None","description":null,"helpText":null}]},"e6e4396e0c5751aa":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_server_name_teredoservernamebox","displayName":"Enter a Teredo server name:","description":null,"helpText":"","infoUrls":[],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":null},"e6587481f8368123":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016","displayName":"Microsoft Office 365 Excel 2016","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Excel 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Excel 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Excel 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Excel 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Excel 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365excel2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365excel2016_1","displayName":"Enabled","description":null,"helpText":null}]},"e6f3dd604f3589fa":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath","displayName":"Settings template catalog path","description":"This policy setting configures where custom settings location templates are stored and if the catalog will be used to replace the default Microsoft templates installed with the UE-V Agent.\r\nIf you enable this policy setting, the UE-V Agent checks the specified location once each day and updates its synchronization behavior based on the templates in this location. Settings location templates added or updated since the last check are registered by the UE-V Agent. The UE-V Agent deregisters templates that were removed from this location.\r\nIf you specify a UNC path and leave the option to replace the default Microsoft templates unchecked, the UE-V Agent will use the default Microsoft templates installed by the UE-V Agent and custom templates in the settings template catalog. If there are custom templates in the settings template catalog which use the same ID as the default Microsoft templates, they will be ignored.\r\nIf you specify a UNC path and check the option to replace the default Microsoft templates, all of the default Microsoft templates installed by the UE-V Agent will be deleted from the computer and only the templates located in the settings template catalog will be used.\r\nIf you disable this policy setting, the UE-V Agent will not use the custom settings location templates. If you disable this policy setting after it has been enabled, the UE-V Agent will not restore the default Microsoft templates. \r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-settingstemplatecatalogpath"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_settingstemplatecatalogpath_1","displayName":"Enabled","description":null,"helpText":null}]},"e6a4cbf23514aa7f":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options","displayName":"User Publishing Refresh","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver4_user_publishing_refresh_options_1","displayName":"True","description":null,"helpText":null}]},"e691144e182aa25a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherexternalsitelisturl_browserswitcherexternalsitelisturl","displayName":"URL of an XML file that contains URLs to load in an alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"e6007fc82542bf83":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_serialallowusbdevicesforurls_serialallowusbdevicesforurls","displayName":"Automatically grant permission to sites to connect to USB serial devices. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"e680f8813f469ae2":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts","displayName":"Setting shortcuts on the New Tab Page (Beta)","description":"In development: for early preview only.\r\n\r\nSetting the policy pre-configures up to 10 custom shortcuts on the Google Chrome New Tab page.\r\n\r\nIf set, users will see these shortcuts by default and users can toggle between “My shortcuts,\" \"Most visited sites\" or \"My organization's shortcuts\" on the \"Customize Chrome\" panel. If empty or unset, the user will only be able to toggle between “My shortcuts\" or \"Most visited sites\" on the \"Customize Chrome\" panel.\r\n\r\nShortcut URLs must be unique.\r\n\r\nIf allow_user_edit is set to true, users can change the name of the shortcut. If set to false or unset, users cannot edit the name.\r\n\r\nIf allow_user_delete is set to true, users can remove the shortcut. If set to false or unset, users cannot remove the shortcut.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=NTPShortcuts for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"name\": \"Google\",\r\n \"url\": \"https://www.google.com\"\r\n },\r\n {\r\n \"name\": \"YouTube\",\r\n \"url\": \"https://www.youtube.com\"\r\n },\r\n {\r\n \"name\": \"Google Drive\",\r\n \"url\": \"https://www.drive.google.com\",\r\n \"allow_user_edit\": true,\r\n \"allow_user_delete\": true\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_ntpshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"e61f537479199805":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed","displayName":"Out-of-process print drivers allowed","description":"Controls if Google Chrome interacts with printer drivers from a separate service process. Platform printing calls to query available printers, get print driver settings, and submit documents for printing to local printers are made from a service process. Moving such calls out of the browser process helps improve stability and reduce frozen UI behavior in Print Preview.\r\n\r\nWhen this policy is set to Enabled or not set, Google Chrome will use a separate service process for platform printing tasks.\r\n\r\nWhen this policy is set to Disabled, Google Chrome will use the browser process for platform printing tasks.\r\n\r\nThis policy will be removed in the future, after the out-of-process print drivers feature has fully rolled out.","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~printing_oopprintdriversallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"e65bd4bb60ac4204":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled","displayName":"Force WebSQL in non-secure contexts to be enabled.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_websqlnonsecurecontextenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e65813067ac60742":{"id":"device_vendor_msft_policy_config_devicelock_allowsimpledevicepassword","displayName":"Allow Simple Device Password","description":"Specifies whether PINs or passwords such as 1111 or 1234 are allowed. For the desktop, it also controls the use of picture passwords.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#allowsimpledevicepassword"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":[{"id":"device_vendor_msft_policy_config_devicelock_allowsimpledevicepassword_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_devicelock_allowsimpledevicepassword_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"e6a0a4835b97c4a3":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingnetwork","displayName":"Network","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging of the Network component.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\Network\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingnetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingnetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"e667563090d49d00":{"id":"device_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms","displayName":"Check for signatures on downloaded programs","description":"This policy setting allows you to manage whether Internet Explorer checks for digital signatures (which identifies the publisher of signed software and verifies it hasn't been modified or tampered with) on user computers before downloading executable programs.\n\nIf you enable this policy setting, Internet Explorer will check the digital signatures of executable programs and display their identities before downloading them to user computers.\n\nIf you disable this policy setting, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.\n\nIf you do not configure this policy, Internet Explorer will not check the digital signatures of executable programs or display their identities before downloading them to user computers.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checksignaturesondownloadedprograms"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_checksignaturesondownloadedprograms_1","displayName":"Enabled","description":null,"helpText":null}]},"e6d8a1f81d49ac98":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"e62b3fdeb4d8c2c0":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls","displayName":"Block cookies on specific sites","description":"Define a list of sites, based on URL patterns, that can't set cookies.\r\n\r\nIf you don't configure this policy, the global default value from the 'DefaultCookiesSetting' (Configure cookies) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nSee the 'CookiesAllowedForUrls' (Allow cookies on specific sites) and 'CookiesSessionOnlyForUrls' (Limit cookies from specific websites to the current session) policies for more information.\r\n\r\nNote there cannot be conflicting URL patterns set between these three policies:\r\n\r\n- CookiesBlockedForUrls\r\n\r\n- 'CookiesAllowedForUrls'\r\n\r\n- 'CookiesSessionOnlyForUrls'\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"e69562e9bba93c18":{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended","displayName":"Configure the default paste format of URLs copied from Microsoft Edge, and determine if additional formats will be available to users","description":"If FriendlyURLs are enabled, Microsoft Edge will compute additional representations of the URL and place them on the clipboard.\r\n\r\nThis policy configures what format will be pasted when the user pastes in external applications, or inside Microsoft Edge without the 'Paste as' context menu item.\r\n\r\nIf configured, this policy makes a choice on behalf of the user. The options in edge://settings/shareCopyPaste will be grayed out, and the options in the 'Paste As' context menu will not be available.\r\n\r\n* Not configured = The user will be able to choose their preferred paste format. By default, this is set to the friendly URL format. The 'Paste As' menu will be available in Microsoft Edge.\r\n\r\n* 1 = No additional formats will be stored on the clipboard. There will be no 'Paste as' context menu item in Microsoft Edge and the only format available to paste will be the plain text URL format. Effectively, the friendly URL feature will be disabled.\r\n\r\n* 3 = The user will get a friendly URL whenever they paste into surfaces that accept rich text. The plain URL will still be available for non-rich surfaces. There will be no 'Paste As' menu in Microsoft Edge.\r\n\r\n* 4 = (Not currently used)\r\n\r\nThe richer formats may not be well-supported in some paste destinations and/or websites. In these scenarios, the plain URL option is recommended when configuring this policy.\r\n\r\nThe recommended policy is available in Microsoft Edge 105 or later.\r\n\r\nPolicy options mapping:\r\n\r\n* PlainText (1) = The plain URL without any extra information, such as the page's title. This is the recommended option when this policy is configured. For more information, see the description.\r\n\r\n* TitledHyperlink (3) = Titled Hyperlink: A hyperlink that points to the copied URL, but whose visible text is the title of the destination page. This is the Friendly URL format.\r\n\r\n* WebPreview (4) = Coming soon. If set, behaves the same as 'Plain URL'.\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev105~policy~microsoft_edge_recommended_configurefriendlyurlformat_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e682453a6f77ab38":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled","displayName":"Configure Microsoft Defender SmartScreen to block potentially unwanted apps","description":"This policy setting lets you configure whether to turn on blocking for potentially unwanted apps with Microsoft Defender SmartScreen. Potentially unwanted app blocking with Microsoft Defender SmartScreen provides warning messages to help protect users from adware, coin miners, bundleware, and other low-reputation apps that are hosted by websites. Potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off by default.\r\n\r\nIf you enable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned on.\r\n\r\nIf you disable this setting, potentially unwanted app blocking with Microsoft Defender SmartScreen is turned off.\r\n\r\nIf you don't configure this setting, users can choose whether to use potentially unwanted app blocking with Microsoft Defender SmartScreen.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge~smartscreen_smartscreenpuaenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e6bc1b225aef69ca":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode","displayName":"Control the mode of DNS-over-HTTPS (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_off","displayName":"Disable DNS-over-HTTPS","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_automatic","displayName":"Enable DNS-over-HTTPS with insecure fallback","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_dnsoverhttpsmode_dnsoverhttpsmode_secure","displayName":"Enable DNS-over-HTTPS without insecure fallback","description":null,"helpText":null}]},"e6ab2e1736f52e32":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_exprwdexe108","displayName":"exprwd.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_exprwdexe108_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_exprwdexe108_1","displayName":"True","description":null,"helpText":null}]},"e6022aa8f079c407":{"id":"device_vendor_msft_policy_config_remotemanagement_turnoncompatibilityhttplistener","displayName":"Turn On Compatibility HTTP Listener","description":"This policy setting turns on or turns off an HTTP listener created for backward compatibility purposes in the Windows Remote Management (WinRM) service.\n\n If you enable this policy setting, the HTTP listener always appears.\n\n If you disable or do not configure this policy setting, the HTTP listener never appears.\n\n When certain port 80 listeners are migrated to WinRM 2.0, the listener port number changes to 5985.\n\n A listener might be automatically created on port 80 to ensure backward compatibility.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotemanagement#remotemanagement-turnoncompatibilityhttplistener"],"categoryId":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","categoryName":"Win RM Service","options":[{"id":"device_vendor_msft_policy_config_remotemanagement_turnoncompatibilityhttplistener_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotemanagement_turnoncompatibilityhttplistener_1","displayName":"Enabled","description":null,"helpText":null}]},"e6fe1d092d3cdfa2":{"id":"device_vendor_msft_policy_config_systemservices_configurexboxliveauthmanagerservicestartupmode","displayName":"Configure Xbox Live Auth Manager Service Startup Mode","description":"This setting determines whether the service's start type is Automatic(2), Manual(3), Disabled(4). Default: Manual.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-SystemServices#configurexboxliveauthmanagerservicestartupmode"],"categoryId":"4f29ef5c-6ca0-4b09-893f-01755a670877","categoryName":"System Services","options":[{"id":"device_vendor_msft_policy_config_systemservices_configurexboxliveauthmanagerservicestartupmode_2","displayName":"Automatic","description":"Automatic","helpText":null},{"id":"device_vendor_msft_policy_config_systemservices_configurexboxliveauthmanagerservicestartupmode_3","displayName":"Manual","description":"Manual","helpText":null},{"id":"device_vendor_msft_policy_config_systemservices_configurexboxliveauthmanagerservicestartupmode_4","displayName":"Disabled","description":"Disabled","helpText":null}]},"e6976e9293865bc0":{"id":"device_vendor_msft_policy_config_update_configuredeadlineforqualityupdates","displayName":"Quality Update Deadline Period (Days)","description":"Number of days before quality updates are installed on devices automatically regardless of active hours. Before the deadline passes, users will be able to schedule restarts, and automatic restarts can happen outside of active hours. When set to 0, updates will download and install immediately, but might not finish within the day due to device availability and network connectivity.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#configuredeadlineforqualityupdates"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"e65722a7c90b8a7b":{"id":"device_vendor_msft_policy_config_userrights_denyaccessfromnetwork","displayName":"Deny Access From Network","description":"This user right determines which users are prevented from accessing a computer over the network. This policy setting supersedes the Access this computer from the network policy setting if a user account is subject to both policies.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#denyaccessfromnetwork"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"e630db2cfa41586b":{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setlowriskinclusion","displayName":"Inclusion list for low file types (User)","description":"This policy setting allows you to configure the list of low-risk file types. If the attachment is in the list of low-risk file types, Windows will not prompt the user before accessing the file, regardless of the file's zone information. This inclusion list overrides the list of high-risk file types built into Windows and has a lower precedence than the high-risk or medium-risk inclusion lists (where an extension is listed in more than one inclusion list).\r\n\r\nIf you enable this policy setting, you can specify file types that pose a low risk.\r\n\r\nIf you disable this policy setting, Windows uses its default trust logic.\r\n\r\nIf you do not configure this policy setting, Windows uses its default trust logic.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-attachmentmanager#admx-attachmentmanager-am-setlowriskinclusion"],"categoryId":"634e4243-284b-4cb7-a7e6-08ca7e262937","categoryName":"Attachment Manager","options":[{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setlowriskinclusion_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_attachmentmanager_am_setlowriskinclusion_1","displayName":"Enabled","description":null,"helpText":null}]},"e6e25ba4ba14300b":{"id":"user_vendor_msft_policy_config_admx_grouppolicy_grouppolicyrefreshrateuser_gprefreshrate3","displayName":"Minutes: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":null},"e60f9a3d3eb06e2f":{"id":"user_vendor_msft_policy_config_admx_printing_packagepointandprintonly","displayName":"Only use Package Point and print (User)","description":"This policy restricts clients computers to use package point and print only.\r\n\r\nIf this setting is enabled, users will only be able to point and print to printers that use package-aware drivers. When using package point and print, client computers will check the driver signature of all drivers that are downloaded from print servers.\r\n\r\nIf this setting is disabled, or not configured, users will not be restricted to package-aware point and print only.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-packagepointandprintonly"],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_admx_printing_packagepointandprintonly_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_printing_packagepointandprintonly_1","displayName":"Enabled","description":null,"helpText":null}]},"e62a7ac462075755":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled","displayName":"Enables the concept of policy atomic groups (User)","description":"Setting the policy to Enabled means policies coming from an atomic group that don't share the source with the highest priority from that group get ignored.\r\n\r\nSetting the policy to Disabled means no policy is ignored because of its source. Policies are ignored only if there's a conflict, and the policy doesn't have the highest priority.\r\n\r\nIf this policy is set from a cloud source, it can't target a specific user.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyatomicgroupsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e6596bcc7866cbc5":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended","displayName":"Set default download directory (User)","description":"Setting the policy changes the default directory that Chrome downloads files to, but users can change the directory.\r\n\r\nLeaving the policy unset means Chrome uses its platform-specific default directory.\r\n\r\nNote: See a list of variables you can use ( https://www.chromium.org/administrators/policy-list-3/user-data-directory-variables ).\r\n\r\nExample value: /home/${user_name}/Downloads","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_defaultdownloaddirectory_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e6a8a9d3434856af":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended","displayName":"Default search provider name (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderName specifies the default search provider's name.\r\n\r\nLeaving DefaultSearchProviderName unset means the hostname specified by the search URL is used.\r\n\r\nExample value: My Intranet Search","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidername_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e646eca508de10e9":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~certificatemanagement_cacertificateswithconstraints_cacertificateswithconstraints","displayName":"TLS certificates that should be trusted by Google Chrome for server authentication with constraints (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1d6d392c-8b32-459b-b114-af964a4bbbc5","categoryName":"Certificate management settings","options":null},"e6d6d1c4f4c0717c":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides","displayName":"Override First-Party Sets. (User)","description":"This policy provides a way to override the list of sets the browser uses for First-Party Sets features.\r\n\r\nEach set in the browser's list of First-Party Sets must meet the requirements of a First-Party Set.\r\nA First-Party Set must contain a primary site and one or more member sites.\r\nA set can also contain a list of service sites that it owns, as well as a map from a site to all of its ccTLD variants.\r\nSee https://github.com/WICG/first-party-sets for more information on First-Party Sets are used by Google Chrome.\r\n\r\nAll sites in a First-Party Set must be a registrable domain served over HTTPS. Each site in a First-Party Set must also be unique,\r\nmeaning a site cannot be listed more than once in a First-Party Set.\r\n\r\nWhen this policy is given an empty dictionary, the browser uses the public list of First-Party Sets.\r\n\r\nFor all sites in a First-Party Set from the replacements list, if a site is also present\r\non a First-Party Set in the browser's list, then that site will be removed from the browser's First-Party Set.\r\nAfter this, the policy's First-Party Set will be added to the browser's list of First-Party Sets.\r\n\r\nFor all sites in a First-Party Set from the additions list, if a site is also present\r\non a First-Party Set in the browser's list, then the browser's First-Party Set will be updated so that the\r\nnew First-Party Set can be added to the browser's list. After the browser's list has been updated,\r\nthe policy's First-Party Set will be added to the browser's list of First-Party Sets.\r\n\r\nThe browser's list of First-Party Sets requires that for all sites in its list, no site is in\r\nmore than one set. This is also required for both the replacements list\r\nand the additions list. Similarly, a site cannot be in both the\r\nreplacements list and the additions list.\r\n\r\nWildcards (*) are not supported as a policy value, nor within any First-Party Set in these lists.\r\n\r\nAll sets provided by the policy must be valid First-Party Sets, if they aren't then an\r\nappropriate error will be outputted.\r\n\r\nOn Microsoft® Windows®, this policy is only available on instances that are joined to a Microsoft® Active Directory® domain, joined to Microsoft® Azure® Active Directory® or enrolled in Chrome Enterprise Core.\r\n\r\nOn macOS, this policy is only available on instances that are managed via MDM, joined to a domain via MCX or enrolled in Chrome Enterprise Core.\r\n\r\nThis is the equivalent of the RelatedWebsiteSetsOverrides policy.\r\nEither policy may be used, but this one will be deprecated soon so the RelatedWebsiteSetsOverrides policy is preferred.\r\nThey both have the same effect on the browser's behavior.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=FirstPartySetsOverrides for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n{\r\n \"additions\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate2.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate2.test\": [\r\n \"https://associate2.com\"\r\n ]\r\n },\r\n \"primary\": \"https://primary2.test\",\r\n \"serviceSites\": [\r\n \"https://associate2-content.test\"\r\n ]\r\n }\r\n ],\r\n \"replacements\": [\r\n {\r\n \"associatedSites\": [\r\n \"https://associate1.test\"\r\n ],\r\n \"ccTLDs\": {\r\n \"https://associate1.test\": [\r\n \"https://associate1.co.uk\"\r\n ]\r\n },\r\n \"primary\": \"https://primary1.test\",\r\n \"serviceSites\": [\r\n \"https://associate1-content.test\"\r\n ]\r\n }\r\n ]\r\n}","helpText":"","infoUrls":[],"categoryId":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","categoryName":"First- Party Sets Settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~firstpartysets_firstpartysetsoverrides_1","displayName":"Enabled","description":null,"helpText":null}]},"e62172543f2c7c44":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection","displayName":"Default sheet direction (User)","description":"This setting controls the default sheet direction, which is either \"Left to Right\" or \"Right to Left\".","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_defaultdirection_1","displayName":"Enabled","description":null,"helpText":null}]},"e68216e20a2f9eb2":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell","displayName":"Edit directly in cell (User)","description":"This policy setting sets the \"Edit directly in cell\" option found under File tab | Options | Advanced | Editing Options.\r\n\r\nIf you enable or do not configure this policy setting, Excel will allow editing directly in the cell This is the default behavior.\r\n\r\nIf you disable this policy setting, Excel will not allow editing to be done directly in the cell.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_editdirectlyincell_1","displayName":"Enabled","description":null,"helpText":null}]},"e6e08667ba434b29":{"id":"user_vendor_msft_policy_config_internetexplorer_allowsitetozoneassignmentlist_iz_zonemapprompt_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":null},"e645a7da080eae9e":{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation","displayName":"Check for server certificate revocation (User)","description":"This policy setting allows you to manage whether Internet Explorer will check revocation status of servers' certificates. Certificates are revoked when they have been compromised or are no longer valid, and this option protects users from submitting confidential data to a site that may be fraudulent or not secure.\n\nIf you enable this policy setting, Internet Explorer will check to see if server certificates have been revoked.\n\nIf you disable this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.\n\nIf you do not configure this policy setting, Internet Explorer will not check server certificates to see if they have been revoked.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-checkservercertificaterevocation"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_checkservercertificaterevocation_1","displayName":"Enabled","description":null,"helpText":null}]},"e60c97447f1b19ef":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004","displayName":"Run .NET Framework-reliant components not signed with Authenticode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallownetframeworkreliantcomponents_iz_partname2004_1","displayName":"Prompt","description":null,"helpText":null}]},"e66aa37cee63f4b1":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist","displayName":"Define a list of allowed URLs (User)","description":"Allow access to the listed URLs, as exceptions to the URL block list.\r\n\r\nFormat the URL pattern according to https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nYou can use this policy to open exceptions to restrictive block lists. For example, you can include '*' in the block list to block all requests, and then use this policy to allow access to a limited list of URLs. You can use this policy to open exceptions to certain schemes, subdomains of other domains, ports, or specific paths.\r\n\r\nThe most specific filter determines if a URL is blocked or allowed. The allowed list takes precedence over the block list.\r\n\r\nThis policy is limited to 1000 entries; subsequent entries are ignored.\r\n\r\nIf you don't configure this policy, there are no exceptions to the block list in the 'URLBlocklist' (Block access to a list of URLs) policy.\r\n\r\nExample value:\r\n\r\ncontoso.com\r\nhttps://ssl.server.com\r\nhosting.com/good_path\r\nhttps://server:8080/path\r\n.exact.hostname.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_urlallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"e67c8cac8f58ee92":{"id":"user_vendor_msft_policy_config_microsoft_edgev118~policy~microsoft_edge~smartscreen_exemptsmartscreendownloadwarnings_exemptsmartscreendownloadwarnings","displayName":"Disable SmartScreen AppRep based warnings for specified file types on specified domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":null},"e6fc06e128801643":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacebirthday_l_birthdaymapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"e616e0ca8909d396":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject","displayName":"Disallow in Project (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_nousercustomizationpolicy_l_nousercustomizationpolicyproject_1","displayName":"True","description":null,"helpText":null}]},"e67a7aaa665bd6bb":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries","displayName":"Turn off Outlook name dictionaries update (User)","description":"This policy setting allows you to turn off updating for Outlook name dictionaries of Microsoft IME (Input Method Editor). This policy setting applies to Japanese Microsoft IME only.\r\n\r\nIf you enable this policy setting, all Outlook name dictionaries are not updated.\r\nOutlook name dictionaries that were added before enabling this policy setting are used for conversion.\r\n\r\nIf you disable or do not configure this policy setting, Outlook name dictionaries are generated, updated and used for conversion.","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_turnoffoutlooknamedictionaries_1","displayName":"Enabled","description":null,"helpText":null}]},"e66070f5e05a8df6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_displaylanguage_l_changeordeletelinktolanguagepackdownloadsite_l_changeordeletelinktolanguagepackdownloadsiteid","displayName":"URL: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0f6020d9-278b-4284-894a-bc4a70c8cf32","categoryName":"Display Language","options":null},"e640a4d44a2363c6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari","displayName":"Dari (User)","description":"Enables the editing language Dari","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_dari_1","displayName":"Enabled","description":null,"helpText":null}]},"e63dcc460e98671f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers","displayName":"Disable Clipboard Toolbar triggers (User)","description":"Checked: Prevents the Office Clipboard from automatically appearing when multiple Copy commands are performed in any of the Office programs. | Unchecked: Permits the Office Clipboard to appear automatically when multiple Copy commands are performed in Office programs.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_disableclipboardtoolbartriggers_1","displayName":"Enabled","description":null,"helpText":null}]},"e6a87cd298ffee6e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12","displayName":"Workflow Cache 12 (User)","description":"The values entered will be used by the client to provide the user with a workflow to be made available to the user for all of their documents. The url should be a full path, such as 'http://localsharepointsite/Shared%20Documents'. Some workflows require that the user sign a document with an in-document signature, workflows indicated as such will only be shown the the user as an option in applications that support in-document signatures. \r\n\r\nThis workflow must also be made available on the document library (setting these values only lets the client know about the workflow).","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_1","displayName":"Enabled","description":null,"helpText":null}]},"e6148b8c87cf7a47":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache15_l_workflowcachename498","displayName":"Name of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"e6dbb5adf8e2a508":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc08_l_pathcolon08","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"e685c71017f40b7f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons","displayName":"Show AutoCorrect Options buttons (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"8084033c-156a-4d1b-ab0b-159541810459","categoryName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsautocorrectoptionsexcelpowerpointandaccess_l_showautocorrectoptionsbuttons_1","displayName":"Enabled","description":null,"helpText":null}]},"e6bd8c8a4c1adffa":{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan","displayName":"Force Runtime AV Scan (User)","description":"This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus or Visio Pro for Office 365. \r\n\r\nThis policy setting controls when Office files are scanned at runtime by an installed Anti-Virus software.\r\n\r\nNote, files will only be scanned if the Anti-Virus software registers as a provider for runtime scanning.\r\n\r\nIf you enable this policy setting, Office applications will submit all files for a runtime scan by Antivirus.\r\n\r\nIf you disable or do not configure this policy setting, Office will selectively submit certain files, for example encrypted files, for a runtime scan by Antivirus.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v3~policy~l_microsoftofficesystem~l_securitysettings_l_forceruntimeavscan_1","displayName":"Enabled","description":null,"helpText":null}]},"e6f1879c689f4904":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot","displayName":"Prevent users from changing the location of their OneDrive folder (User)","description":"This setting lets you block users from changing the location of their OneDrive - {organization name} folder during setup of the OneDrive sync app.\r\n\r\nIf you enable this setting, the \"Change location\" link is hidden in OneDrive Setup. The OneDrive folder will be created in the default location, or in the custom location you specified if you enabled the \"Set the default location for the OneDrive folder\" setting.\r\n\r\nIf you disable or do not configure this setting, users can click the \"Change location\" link to change the location of their OneDrive folder in OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablecustomroot_1","displayName":"Enabled","description":null,"helpText":null}]},"e668a8b6103b6d3d":{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_l_empty17","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"e66383c95e0acc63":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart","displayName":"Configure form regions permissions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e0e10e94-325c-49e6-ab48-4f146254395f","categoryName":"Form Region Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_0","displayName":"All form regions are allowed to run","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_1","displayName":"Allow only those registered in HKLM","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_formregionsettings_l_disableformregions_l_disableformregionspart_2","displayName":"No form regions are allowed to run","description":null,"helpText":null}]},"e681828e539440b3":{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice","displayName":"Prevent Outlook from interacting with the account settings detection service (User)","description":"This policy setting determines whether Outlook can interact with the account settings detection service to gather information about a user's account settings.\r\n\r\nIf you enable this policy setting, users will need to manually configure their account settings.","helpText":"","infoUrls":[],"categoryId":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","categoryName":"E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v4~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_accountsettingsemail_disableaccountsettingsdetectionservice_1","displayName":"Enabled","description":null,"helpText":null}]},"e6f689a4500c6c26":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers","displayName":"Don’t show redirect warnings for Autodiscover for the specified HTTPS server names (User)","description":"This policy setting allows you to specify HTTPS server names for which Autodiscover won’t show a warning message when redirecting from HTTP to HTTPS.\r\n\r\nBy default, when an Autodiscover operation redirects from HTTP to HTTPS, you may be shown a warning message about the redirection.\r\n\r\nIf you enable this policy setting, you need to specify HTTPS server names, and for those server names, you won’t be shown a warning message. For example, if you enter contoso.com, you won’t be shown a warning message when Autodiscover redirects to https://contoso.com.\r\n\r\nIf you disable or don’t configure this policy setting, you may be shown a warning message when an Autodiscover operation redirects from HTTP to HTTPS.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_autodiscoverredirectservers_1","displayName":"Enabled","description":null,"helpText":null}]},"e6b63b039ff7721f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist","displayName":"Number of presentations in the Recent Presentations list (User)","description":"This policy setting specifies the number of entries displayed in the Recent Presentations list that appears when users click Open on the File tab in Backstage view.\r\n\r\nIf you enable this policy setting, you can specify the number of entries to be between 0 and 50. If you set the number to 0, all pinned and unpinned entries are hidden.\r\n\r\nIf you disable or do not configure this policy setting, a maximum of 25 items will be displayed in the Recent Presentations list.\r\n\r\nNote: If you want to prevent items from being added to the Recent Presentations list entirely, you can enable the \"Do not keep history of recently opened documents\" Windows policy setting.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_recentlyusedfilelist_1","displayName":"Enabled","description":null,"helpText":null}]},"e69d54881d429549":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_miscellaneous_l_listofmanagedaddins_l_listofmanagedaddins2","displayName":"List of managed add-ins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"e344b25a-2046-4e70-a3b9-1a418613861f","categoryName":"Miscellaneous","options":null},"e68e0ae7bb1e9832":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9","displayName":"Hours (User)","description":"","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_0","displayName":"h","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_1","displayName":"hr","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_2","displayName":"hour","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_3","displayName":"\r\n ","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_l_pjhours9_4","displayName":"\r\n ","description":null,"helpText":null}]},"e6364c90710f7d6e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation","displayName":"Provide feedback with animation (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_providefeedbackwithanimation_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/e7.json b/public/intune-definitions/e7.json index 676ba6e3d554..fe39b6ff7feb 100644 --- a/public/intune-definitions/e7.json +++ b/public/intune-definitions/e7.json @@ -1 +1 @@ -{"e779d4f500a983f5":{"id":"ade_setupassistant_actionbutton","displayName":"Action Button","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_actionbutton_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_actionbutton_1","displayName":"Show","description":null,"helpText":null}]},"e7c7647bfea0c97d":{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults","displayName":"Allow Personalized Handwriting Results (Deprecated)","description":"If false, prevents the system from generating text in the user's handwriting.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_true","displayName":"True","description":null,"helpText":null}]},"e7ae92161c369aa1":{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled","displayName":"Enable Workspaces","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\n\nIf you enable or don't configure this policy, users will be able to access the Microsoft Edge Workspaces feature.\nIf you disable this policy, users will not be able to access the Microsoft Edge Workspaces feature.\n\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeworkspacesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"e7659689bc7e0235":{"id":"com.apple.managedclient.preferences_screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture","description":"For security reasons, the\ngetDisplayMedia() web API requires\na prior user gesture (\"transient activation\") to be called or the API will\nfail.\n\nWhen this policy is configured, admins can specify origins on which this API\ncan be called without prior user gesture.\n\nFor detailed information on valid url patterns, see\nhttps://go.microsoft.com/fwlink/?linkid=2095322. Note: * is not an accepted\nvalue for this policy.\n\nIf this policy is not configured, all origins require a prior user gesture to\ncall this API.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencapturewithoutgestureallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"e7ff3a96fdb12050":{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable","displayName":"Enable Hotspot Authentication","description":"This policy setting defines whether WLAN hotspots are probed for Wireless Internet Service Provider roaming (WISPr) protocol support.\r\n\r\nIf a WLAN hotspot supports the WISPr protocol, users can submit credentials when manually connecting to the network. If authentication is successful, users will be connected automatically on subsequent attempts. Credentials can also be configured by network operators.\r\n\r\nIf you enable this policy setting, or if you do not configure this policy setting, WLAN hotspots are automatically probed for WISPR protocol support.\r\n\r\nIf you disable this policy setting, WLAN hotspots are not probed for WISPr protocol support, and users can only authenticate with WLAN hotspots using a web browser.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-hotspotauth#admx-hotspotauth-hotspotauth-enable"],"categoryId":"6d4184ab-a66c-47f1-b54e-af55f654e2a5","categoryName":"Hotspot Authentication","options":[{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable_1","displayName":"Enabled","description":null,"helpText":null}]},"e78fe5a92169bfb9":{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2","displayName":"Turn off Windows Mobility Center","description":"This policy setting turns off Windows Mobility Center.\r\n\r\nIf you enable this policy setting, the user is unable to invoke Windows Mobility Center. The Windows Mobility Center UI is removed from all shell entry points and the .exe file does not launch it.\r\n\r\nIf you disable this policy setting, the user is able to invoke Windows Mobility Center and the .exe file launches it.\r\n\r\nIf you do not configure this policy setting, Windows Mobility Center is on by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mobilepcmobilitycenter#admx-mobilepcmobilitycenter-mobilitycenterenable-2"],"categoryId":"1ed9f90e-d8b6-413f-bfc2-face955141bc","categoryName":"Windows Mobility Center","options":[{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2_1","displayName":"Enabled","description":null,"helpText":null}]},"e77706a40be2c191":{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"start layout\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},"e79b0a2ac5ca44f2":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup","displayName":"InfoPath 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft InfoPath 2013.\r\nMicrosoft InfoPath 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft InfoPath 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft InfoPath 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft InfoPath 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013infopathbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"e75e34a3d4a4ba2b":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common","displayName":"Microsoft Office 2016 Common Settings","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2016 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2016 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2016 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2016 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_1","displayName":"Enabled","description":null,"helpText":null}]},"e733a4106d5e05ad":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption","displayName":"Show hibernate in the power options menu","description":"Shows or hides hibernate from the power options menu.\r\n\r\nIf you enable this policy setting, the hibernate option will be shown in the Power Options menu (as long as it is supported by the machine's hardware).\r\n\r\nIf you disable this policy setting, the hibernate option will never be shown in the Power Options menu.\r\n\r\nIf you do not configure this policy setting, users will be able to choose whether they want hibernate to show through the Power Options Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-showhibernateoption"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption_1","displayName":"Enabled","description":null,"helpText":null}]},"e7865ef0d2268dbf":{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon","displayName":"Audit Special Logon","description":"This policy setting allows you to audit events generated by special logons such as the following : The use of a special logon, which is a logon that has administrator-equivalent privileges and can be used to elevate a process to a higher level. A logon by a member of a Special Group. Special Groups enable you to audit events generated when a member of a certain group has logged on to your network. You can configure a list of group security identifiers (SIDs) in the registry. If any of those SIDs are added to a token during logon and the subcategory is enabled, an event is logged. For more information about this feature, see article 947223 in the Microsoft Knowledge Base (https://go.microsoft.com/fwlink/?LinkId=121697).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditspeciallogon"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"e78ae22c8f1904fd":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents","displayName":"Object Access Audit Other Object Access Events","description":"This policy setting allows you to audit events generated by the management of task scheduler jobs or COM+ objects. For scheduler jobs, the following are audited: Job created. Job deleted. Job enabled. Job disabled. Job updated. For COM+ objects, the following are audited: Catalog object added. Catalog object updated. Catalog object deleted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditotherobjectaccessevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"e7acac091a7ee8b5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed","displayName":"Allow or deny audio capture","description":"Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the AudioCaptureAllowedUrls list, users get prompted for audio capture access.\r\n\r\nSetting the policy to Disabled turns off prompts, and audio capture is only available to URLs set in the AudioCaptureAllowedUrls list.\r\n\r\nNote: The policy affects all audio input (not just the built-in microphone).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"e73353c8c4abe4ff":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy","displayName":"Google Chrome cloud policy overrides Platform policy.","description":"Setting the policy to Enabled means cloud policy takes precedence if it conflicts with platform policy.\r\n\r\nSetting the policy to Disabled or leaving it unset means platform policy takes precedence if it conflicts with cloud policy.\r\n\r\nThis mandatory policy affects machine scope cloud policies.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"e791021f6b027b3b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_registeredprotocolhandlers","displayName":"Register protocol handlers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"962a2377-ad9a-4654-a526-a77c14152fd7","categoryName":"Content settings","options":null},"e70e3cfa15c9c4e9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e7f7dbedebee6246":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation","displayName":"URLs/domains automatically permitted direct Security Key attestation","description":"Setting the policy specifies URLs and domains for which no prompt appears when attestation certificates from Security Keys are requested. A signal is also sent to the Security Key indicating that individual attestation may be used. Without this, when sites request attestation of Security Keys, users are prompted in Google Chrome version 65 and later.\r\n\r\nURLs will only match as U2F appIDs. Domains only match as webauthn RP IDs. So to cover both U2F and webauthn APIs, list the appID URL and domain for a given site.\r\n\r\nExample value:\r\n\r\nhttps://example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_1","displayName":"Enabled","description":null,"helpText":null}]},"e7738ba147c01fbf":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls","displayName":"Allow Window Placement permission on these sites","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"e760a7450c7f64d5":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_extensioninstalltypeblocklistdesc","displayName":"Blocklist for install types of extensions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"e7c52f95a5a7e82c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled","displayName":"Control the URL parameter filter feature","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e70fb8a8d51dcda8":{"id":"device_vendor_msft_policy_config_datausage_setcost4g_cost4g_dropdownlist","displayName":"Please select a 4G connection cost value to set:","description":"","helpText":"","infoUrls":[],"categoryId":"edf3754c-b22d-4946-a744-4773240a5883","categoryName":"WWAN Media Cost","options":[{"id":"device_vendor_msft_policy_config_datausage_setcost4g_cost4g_dropdownlist_1","displayName":"Unrestricted","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_datausage_setcost4g_cost4g_dropdownlist_2","displayName":"Fixed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_datausage_setcost4g_cost4g_dropdownlist_3","displayName":"Variable","description":null,"helpText":null}]},"e789b449803c83a1":{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizeapplicationlog","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\n\nIf you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\n\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 1 megabyte.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-eventlogservice#eventlogservice-specifymaximumfilesizeapplicationlog"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizeapplicationlog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizeapplicationlog_1","displayName":"Enabled","description":null,"helpText":null}]},"e7f35e83d93f6786":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvhdlocations_profilesvhdlocations","displayName":"VHD Locations (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"e792423bff0ad661":{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_preventteamsinstall","displayName":"Don’t install Microsoft Teams with new installations or updates of Office","description":"This policy setting allows you to control whether Microsoft Teams is installed with a new installation of Office or when an existing installation of Office is updated.\r\n\r\nNote: This policy setting only applies to versions of Office, such as Office 365 ProPlus, where Teams is installed with a new installation or an update of Office.\r\n\r\nIf you enable this policy setting, Teams won’t be installed with a new installation or an update of Office.\r\n\r\nIf you disable or don’t configure this policy setting, Teams will be installed as part of a new installation or an update of Office, unless you have used some other method, such as the Office Deployment Tool, to exclude the installation of Teams.","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_preventteamsinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_preventteamsinstall_1","displayName":"Enabled","description":null,"helpText":null}]},"e70695f43f0f33f8":{"id":"device_vendor_msft_policy_config_remoteassistance_unsolicitedremoteassistance_ra_unsolicit_dacl_edit","displayName":"Helpers:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":null},"e77646441b1dbaff":{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection","displayName":"Restrict clipboard transfer from server to client","description":"This policy setting allows you to restrict clipboard data transfers from server to client.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from server to client.\r\n\r\n- Allow plain text copying from server to client.\r\n\r\n- Allow plain text and images copying from server to client.\r\n\r\n- Allow plain text, images and Rich Text Format copying from server to client.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from server to client.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from server to client if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitservertoclientclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},"e7c2162e29614c47":{"id":"device_vendor_msft_policy_config_storage_removablediskdenywriteaccess","displayName":"Removable Disk Deny Write Access","description":"If you enable this policy setting, write access is denied to this removable storage class. If you disable or do not configure this policy setting, write access is allowed to this removable storage class. Note: To require that users write data to BitLocker-protected storage, enable the policy setting \"Deny write access to drives not protected by BitLocker,\" which is located in \"Computer Configuration\\Administrative Templates\\Windows Components\\BitLocker Drive Encryption\\Removable Data Drives.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Storage#removablediskdenywriteaccess"],"categoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","categoryName":"Storage","options":[{"id":"device_vendor_msft_policy_config_storage_removablediskdenywriteaccess_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_storage_removablediskdenywriteaccess_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"e785022220a74023":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_meteredupdatesmicrosoftedgecanary","displayName":"Let users update on metered connections","description":"Specifies whether Microsoft Edge Update will update on connections marked as metered, such as cellular connections or others where data usage is controlled for the Microsoft Edge browser. \r\n\r\nIf you don't enable and configure this policy, updates occur based the 'Download Updates over metered connections' toggle in the About Page of the Microsoft Edge browser. If a user doesn't make a choice, the Windows setting is used. You can find out more about the Windows setting here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update#allowautowindowsupdatedownloadovermeterednetwork\r\n\r\nAlways allow updates (2): Updates are always downloaded when found, either by automatic update check or by a manual update check.\r\n\r\nDisable updates (1): Updates are not downloaded when using a metered connection.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_meteredupdatesmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_meteredupdatesmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},"e7613a36a127c710":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders54","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders54_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders54_1","displayName":"True","description":null,"helpText":null}]},"e74b4bf9927f2792":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosetfolders","displayName":"Remove programs on Settings menu (User)","description":"This policy setting allows you to remove programs on Settings menu.\r\n\r\nIf you enable this policy setting, the Control Panel, Printers, and Network and Connection folders are removed from Settings on the Start menu, and from Computer and File Explorer. It also prevents the programs represented by these folders (such as Control.exe) from running.\r\n\r\nHowever, users can still start Control Panel items by using other methods, such as right-clicking the desktop to start Display or right-clicking Computer to start System.\r\n\r\nIf you disable or do not configure this policy setting, the Control Panel, Printers, and Network and Connection folders from Settings are available on the Start menu, and from Computer and File Explorer.\r\n\r\nAlso, see the \"Disable Control Panel,\" \"Disable Display in Control Panel,\" and \"Remove Network Connections from Start Menu\" policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosetfolders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosetfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosetfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"e79607bcb7b62b28":{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskbarclock","displayName":"Remove Clock from the system notification area (User)","description":"Prevents the clock in the system notification area from being displayed.\r\n\r\nIf you enable this setting, the clock will not be displayed in the system notification area.\r\n\r\nIf you disable or do not configure this setting, the default behavior of the clock appearing in the notification area will occur.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notaskbarclock"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskbarclock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskbarclock_1","displayName":"Enabled","description":null,"helpText":null}]},"e74d5b3ef41bf8a5":{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskgrouping","displayName":"Prevent grouping of taskbar items (User)","description":"This setting affects the taskbar buttons used to switch between running programs.\r\n\r\nTaskbar grouping consolidates similar applications when there is no room on the taskbar. It kicks in when the user's taskbar is full.\r\n\r\nIf you enable this setting, it prevents the taskbar from grouping items that share the same program name. By default, this setting is always enabled.\r\n\r\nIf you disable or do not configure it, items on the taskbar that share the same program are grouped together. The users have the option to disable grouping if they choose.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notaskgrouping"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskgrouping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskgrouping_1","displayName":"Enabled","description":null,"helpText":null}]},"e761e44b9276a07c":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming","displayName":"Sync settings over metered connections even when roaming (User)","description":"This policy setting defines whether the User Experience Virtualization (UE-V) Agent synchronizes settings over metered connections outside of the home provider network, for example when connected via a roaming connection.\r\nBy default, the UE-V Agent does not synchronize settings over a metered connection that is roaming.\r\nWith this setting enabled, the UE-V Agent synchronizes settings over a metered connection that is roaming.\r\nWith this setting disabled, the UE-V Agent will not synchronize settings over a metered connection that is roaming.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncovermeterednetworkwhenroaming"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming_1","displayName":"Enabled","description":null,"helpText":null}]},"e71b2c825649dca5":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noentirenetwork","displayName":"No Entire Network in Network Locations (User)","description":"Removes all computers outside of the user's workgroup or local domain from lists of network resources in File Explorer and Network Locations.\r\n\r\nIf you enable this setting, the system removes the Entire Network option and the icons representing networked computers from Network Locations and from the browser associated with the Map Network Drive option.\r\n\r\nThis setting does not prevent users from viewing or connecting to computers in their workgroup or domain. It also does not prevent users from connecting to remote computers by other commonly used methods, such as by typing the share name in the Run dialog box or the Map Network Drive dialog box.\r\n\r\nTo remove computers in the user's workgroup or domain from lists of network resources, use the \"No Computers Near Me in Network Locations\" setting.\r\n\r\nNote: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-noentirenetwork"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noentirenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noentirenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"e7cbbb0f7127c779":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions","displayName":"Allow download restrictions (User)","description":"Setting the policy means users can't bypass download security decisions.\r\n\r\nThere are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked):\r\n\r\n* Malicious, as flagged by the Safe Browsing server\r\n* Uncommon or unwanted, as flagged by the Safe Browsing server\r\n* A dangerous file type (e.g. all SWF downloads and many EXE downloads)\r\n\r\nSetting the policy blocks different subsets of these, depending on it's value:\r\n\r\n0: No special restrictions. Default.\r\n\r\n1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n3: Blocks all downloads. Not recommended, except for special use cases.\r\n\r\n4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended.\r\n\r\nNote: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},"e7cc5bb4b202dcc3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"e790505c8e4faca4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist","displayName":"Configure extension installation whitelist (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},"e7741cd7645325b1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes","displayName":"Supported authentication schemes (User)","description":"Setting the policy specifies which HTTP authentication schemes Google Chrome supports.\r\n\r\nLeaving the policy unset employs all 4 schemes.\r\n\r\nValid values:\r\n\r\n* basic\r\n\r\n* digest\r\n\r\n* ntlm\r\n\r\n* negotiate\r\n\r\nNote: Separate multiple values with commas.\r\n\r\nExample value: basic,digest,ntlm,negotiate","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_1","displayName":"Enabled","description":null,"helpText":null}]},"e76c3d0232c37a78":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins_enabledpluginsdesc","displayName":"List of enabled plugins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"e73a3b6a57248bde":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowaccesstodatasources"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"e73f27d483e74aee":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b","displayName":"Only allow approved domains to use ActiveX controls without prompt (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_0","displayName":"Disable","description":null,"helpText":null}]},"e7a0fd6bde08309c":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},"e7e58b53bc15f0f0":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1","displayName":"Disable HTTP fallback for SIP connection (User)","description":"Prevents from HTTP being used for SIP connection in case TLS or TCP fail.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1_1","displayName":"Enabled","description":null,"helpText":null}]},"e7a02cefc42b9da5":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1","displayName":"Allow storage of user passwords (User)","description":"\r\nAllows Microsoft Lync to store user passwords.\r\n\r\nIf you enable this policy setting, Microsoft Lync can store a password on request from the user.\r\n\r\nIf you disable this policy setting, Microsoft Lync cannot store a password.\r\n\r\nIf you do not configure this policy setting and the user logs on to a domain, Microsoft Lync does not store the password. If you do not configure this policy setting and the user does not log on to a domain (for example, if the user logs on to a workgroup), Microsoft Lync can store the password.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1_1","displayName":"Enabled","description":null,"helpText":null}]},"e75c37368f1d6297":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots","displayName":"Disable taking screenshots (User)","description":"Controls if users can take screenshots of the browser page.\r\n\r\nIf enabled, user can't take screenshots by using keyboard shortcuts or extension APIs.\r\n\r\nIf disabled or don't configure this policy, users can take screenshots.\r\n\r\nPlease note this policy controls screenshots taken from within the browser itself. Even if you enable this policy, users might still be able to take screenshots using some method outside of the browser (like using an operating system feature or another application).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots_1","displayName":"Enabled","description":null,"helpText":null}]},"e79f20741c7a9525":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_isolateorigins","displayName":"Enable site isolation for specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"e7613d3e18593064":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended_downloaddirectory","displayName":"Set download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},"e7f419ae705614ce":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e7cbd0d9920942e9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir","displayName":"Set the user data directory (User)","description":"Set the directory to use for storing user data.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified directory regardless of whether the user has set the '--user-data-dir' command-line flag.\r\n\r\nIf you don't enable this policy, the default profile path is used, but the user can override it by using the '--user-data-dir' flag. Users can find the directory for the profile at edge://version/ under profile path.\r\n\r\nTo avoid data loss or other errors, don't configure this policy to a volume's root directory or to a directory that's used for other purposes, because Microsoft Edge manages its contents.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nExample value: ${users}/${user_name}/Edge","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},"e7131aa6dba572b6":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention","displayName":"Block tracking of users' web-browsing activity (User)","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\r\n\r\nIf you enable this policy, you have the following options for setting the level of tracking prevention:\r\n\r\n* 0 = Off (no tracking prevention)\r\n\r\n* 1 = Basic (blocks harmful trackers, content and ads will be personalized)\r\n\r\n* 2 = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\r\n\r\n* 3 = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\r\n\r\nIf you disable this policy or don't configure it, users can set their own level of tracking prevention.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_1","displayName":"Enabled","description":null,"helpText":null}]},"e7fa1975c68de0d3":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs","displayName":"Allow importing of open tabs (User)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs_1","displayName":"Enabled","description":null,"helpText":null}]},"e713ef0e1144e4b4":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache (User)","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\r\n\r\nIf you disable or don’t set this policy, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\r\n\r\nIf you enable this policy HTTP auth credentials entered in the context of one site will automatically be used in the context of another site.\r\n\r\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\r\n\r\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e77a371be5d8aa35":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting","displayName":"Default sensors setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting_1","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting_2","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},"e7fddc94938d8176":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic","displayName":"Greenlandic (User)","description":"Enables the editing language Greenlandic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic_1","displayName":"Enabled","description":null,"helpText":null}]},"e72a752fa615b0b8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowfriendly466","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"e73984a861015e40":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_descriptioncolon252","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"e7d265b23ea4a733":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot","displayName":"Notebook Root (User)","description":"To change to where new notebooks are defaulted, enter a path to a folder relative to your documents.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_1","displayName":"Enabled","description":null,"helpText":null}]},"e7f6afd07e29d01c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_l_showremindersxminutesbeforetheeventstarts","displayName":"Show reminders minutes before the event starts: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},"e7620289d66ce75b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30","displayName":"Signature Warning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_0","displayName":"Let user decide if they want to be warned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_1","displayName":"Always warn about invalid signatures","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_2","displayName":"Never warn about invalid signatures","description":null,"helpText":null}]},"e79c5b98242df65b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy","displayName":"Remove file extensions blocked as Level 1 (User) (Deprecated)","description":"This policy setting controls which types of attachments (determined by file extension) Outlook prevents from being delivered. \r\n\r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify the removal of file type extensions as that Outlook classifies as Level 1--that is, to be blocked from delivery--by entering them in the text field provided separated by semicolons. \r\n\r\nIf you disable or do not configure this policy setting, Outlook classifies a number of potentially harmful file types (such as those with .exe, .reg, and .vbs extensions) as Level 1 and blocks files with those extensions from being delivered. \r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"e704275c692bcb87":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder","displayName":"Turn off audio recording for screen recording (User)","description":"This policy setting allows you to control the initial audio recording setting for a screen recording in PowerPoint. By default, audio is recorded during a screen recording.\r\n \r\nIf you enable this policy setting, audio isn’t recorded during a screen recording. But, the user can choose to turn on audio recording manually in the UI.\r\n \r\nIf you disable or don’t configure this policy setting, audio is recorded during a screen recording. The user can choose to turn off audio recording manually in the UI.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder_1","displayName":"Enabled","description":null,"helpText":null}]},"e77a7ed6490bc5fb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f66fb7e4-a968-4969-b627-f99aaad0dfc3","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"e77bc2495bc4fdc1":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"e7cb3e11c6ae44f5":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline","displayName":"Baseline for Earned Value calculations (User)","description":"Specifies the baseline that is used to measure project performance using earned value analysis.\r\n\r\nIf you enable this setting, Project will calculate earned value using the baseline you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_1","displayName":"Enabled","description":null,"helpText":null}]},"e74110f741db985e":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. \r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"907fd656-2a80-4f34-8615-a3acb11a2b95","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_1","displayName":"Enabled","description":null,"helpText":null}]},"e7f614e5fbcf0a07":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality","displayName":"Turn off CAD/DWG functionality (User)","description":"This policy setting allows you to turn off all entry points related to CAD/DWG files.\r\n\r\nIf you enable this policy setting, CAD/DWG functionality will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, CAD/DWG functionality will be turned on.","helpText":"","infoUrls":[],"categoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality_1","displayName":"Enabled","description":null,"helpText":null}]},"e7bd389fd168d93b":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"e7432753376cec8d":{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon","displayName":"Allow the use of SharePoint eSignature for Microsoft Word (User)","description":"This policy setting allows you to control whether users can request eSignatures directly from Word in tenants that have enabled Microsoft's native eSignature service.\r\n\r\nIf you enable this policy setting, users can request eSignatures from within Word. This policy setting applies only to subscription versions of Word.\r\n\r\nIf you disable this policy setting, users cannot request eSignatures from within Word.\r\n\r\nIf you don't configure this policy setting, users cannot request eSignatures from within Word.","helpText":"","infoUrls":[],"categoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","categoryName":"Microsoft Word 2016","options":[{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon_1","displayName":"Enabled","description":null,"helpText":null}]},"e7af63a59f9d66ec":{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption","displayName":"Allow Startup Boost feature (User)","description":"This policy setting configures the \"Startup Boost\" checkbox found under File tab | Options | General. Startup Boost improves Word's boot time by prewarming the app on user login.\r\n\r\nIf you enable or do not configure this policy, users will be able to use the Startup Boost feature. The Startup Boost checkbox will be enabled and checked by default.\r\n\r\nIf you disable this policy setting, the Startup Boost feature will not be available. The Startup Boost checkbox will be disabled and unchecked.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption_1","displayName":"Enabled","description":null,"helpText":null}]},"e777b60efd87817c":{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption","displayName":"Disable Stealth Mode Ipsec Secured Packet Exemption","description":"This value is an on/off switch. This option is ignored if DisableStealthMode is on. Otherwise, when this option is true, the firewall's stealth mode rules MUST NOT prevent the host computer from responding to unsolicited network traffic if that traffic is secured by IPsec. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption_true","displayName":"True","description":"TRUE","helpText":null}]}} \ No newline at end of file +{"e779d4f500a983f5":{"id":"ade_setupassistant_actionbutton","displayName":"Action Button","description":null,"helpText":null,"infoUrls":[],"categoryId":"0d23daec-d948-4eee-8ee5-89ab1c59e440","categoryName":null,"options":[{"id":"ade_setupassistant_actionbutton_0","displayName":"Hide","description":null,"helpText":null},{"id":"ade_setupassistant_actionbutton_1","displayName":"Show","description":null,"helpText":null}]},"e71f65b9453849e8":{"id":"com.android.devicerestrictionpolicy.unifiedlocksettings","displayName":"Require separate work lock","description":"If 'True', requires a separate lock for the work profile, preventing use of a unified lock for both device and work profile. If set to 'False', Intune doesn't change or update this setting. By default, the OS might allow a common lock for the device and the work profile. Available for corporate-owned work profile devices (at work profile level).","helpText":null,"infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":[{"id":"com.android.devicerestrictionpolicy.unifiedlocksettings_false","displayName":"False","description":"A common lock for the device and the work profile is allowed.","helpText":null},{"id":"com.android.devicerestrictionpolicy.unifiedlocksettings_true","displayName":"True","description":"A separate lock for the work profile is required.","helpText":null}]},"e7c7647bfea0c97d":{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults","displayName":"Allow Personalized Handwriting Results (Deprecated)","description":"If false, prevents the system from generating text in the user's handwriting.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowpersonalizedhandwritingresults_true","displayName":"True","description":null,"helpText":null}]},"e7ae92161c369aa1":{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled","displayName":"Enable Workspaces","description":"Microsoft Edge Workspaces helps improve productivity for users in your organization.\n\nIf you enable or don't configure this policy, users will be able to access the Microsoft Edge Workspaces feature.\nIf you disable this policy, users will not be able to access the Microsoft Edge Workspaces feature.\n\nTo learn more about the feature, see https://go.microsoft.com/fwlink/?linkid=2209950","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#edgeworkspacesenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_edgeworkspacesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"e7659689bc7e0235":{"id":"com.apple.managedclient.preferences_screencapturewithoutgestureallowedfororigins","displayName":"Allow screen capture without prior user gesture","description":"For security reasons, the\ngetDisplayMedia() web API requires\na prior user gesture (\"transient activation\") to be called or the API will\nfail.\n\nWhen this policy is configured, admins can specify origins on which this API\ncan be called without prior user gesture.\n\nFor detailed information on valid url patterns, see\nhttps://go.microsoft.com/fwlink/?linkid=2095322. Note: * is not an accepted\nvalue for this policy.\n\nIf this policy is not configured, all origins require a prior user gesture to\ncall this API.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#screencapturewithoutgestureallowedfororigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"e7ff3a96fdb12050":{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable","displayName":"Enable Hotspot Authentication","description":"This policy setting defines whether WLAN hotspots are probed for Wireless Internet Service Provider roaming (WISPr) protocol support.\r\n\r\nIf a WLAN hotspot supports the WISPr protocol, users can submit credentials when manually connecting to the network. If authentication is successful, users will be connected automatically on subsequent attempts. Credentials can also be configured by network operators.\r\n\r\nIf you enable this policy setting, or if you do not configure this policy setting, WLAN hotspots are automatically probed for WISPR protocol support.\r\n\r\nIf you disable this policy setting, WLAN hotspots are not probed for WISPr protocol support, and users can only authenticate with WLAN hotspots using a web browser.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-hotspotauth#admx-hotspotauth-hotspotauth-enable"],"categoryId":"6d4184ab-a66c-47f1-b54e-af55f654e2a5","categoryName":"Hotspot Authentication","options":[{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_hotspotauth_hotspotauth_enable_1","displayName":"Enabled","description":null,"helpText":null}]},"e78fe5a92169bfb9":{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2","displayName":"Turn off Windows Mobility Center","description":"This policy setting turns off Windows Mobility Center.\r\n\r\nIf you enable this policy setting, the user is unable to invoke Windows Mobility Center. The Windows Mobility Center UI is removed from all shell entry points and the .exe file does not launch it.\r\n\r\nIf you disable this policy setting, the user is able to invoke Windows Mobility Center and the .exe file launches it.\r\n\r\nIf you do not configure this policy setting, Windows Mobility Center is on by default.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mobilepcmobilitycenter#admx-mobilepcmobilitycenter-mobilitycenterenable-2"],"categoryId":"1ed9f90e-d8b6-413f-bfc2-face955141bc","categoryName":"Windows Mobility Center","options":[{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mobilepcmobilitycenter_mobilitycenterenable_2_1","displayName":"Enabled","description":null,"helpText":null}]},"e77706a40be2c191":{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride","displayName":"Allow users to turn \"start layout\" syncing on.","description":null,"helpText":"","infoUrls":[],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disablestartlayoutsettingsync_checkbox_useroverride_1","displayName":"True","description":null,"helpText":null}]},"e79b0a2ac5ca44f2":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup","displayName":"InfoPath 2013 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft InfoPath 2013.\r\nMicrosoft InfoPath 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft InfoPath 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft InfoPath 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft InfoPath 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013infopathbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013infopathbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"e75e34a3d4a4ba2b":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common","displayName":"Microsoft Office 2016 Common Settings","description":"\r\nThis policy setting configures the synchronization of user settings which are common between the Microsoft Office Suite 2016 applications.\r\nBy default, the user settings which are common between the Microsoft Office Suite 2016 applications synchronize between computers. Use the policy setting to prevent the user settings which are common between the Microsoft Office Suite 2016 applications from synchronization between computers.\r\nIf you enable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications continue to synchronize.\r\nIf you disable this policy setting, the user settings which are common between the Microsoft Office Suite 2016 applications are excluded from the synchronization settings. If any of the Microsoft Office Suite 2016 applications are enabled, this policy setting should not be disabled.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016common"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016common_1","displayName":"Enabled","description":null,"helpText":null}]},"e733a4106d5e05ad":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption","displayName":"Show hibernate in the power options menu","description":"Shows or hides hibernate from the power options menu.\r\n\r\nIf you enable this policy setting, the hibernate option will be shown in the Power Options menu (as long as it is supported by the machine's hardware).\r\n\r\nIf you disable this policy setting, the hibernate option will never be shown in the Power Options menu.\r\n\r\nIf you do not configure this policy setting, users will be able to choose whether they want hibernate to show through the Power Options Control Panel.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-showhibernateoption"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_showhibernateoption_1","displayName":"Enabled","description":null,"helpText":null}]},"e7865ef0d2268dbf":{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon","displayName":"Audit Special Logon","description":"This policy setting allows you to audit events generated by special logons such as the following : The use of a special logon, which is a logon that has administrator-equivalent privileges and can be used to elevate a process to a higher level. A logon by a member of a Special Group. Special Groups enable you to audit events generated when a member of a certain group has logged on to your network. You can configure a list of group security identifiers (SIDs) in the registry. If any of those SIDs are added to a token during logon and the subcategory is enabled, an event is logged. For more information about this feature, see article 947223 in the Microsoft Knowledge Base (https://go.microsoft.com/fwlink/?LinkId=121697).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#accountlogonlogoff_auditspeciallogon"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_accountlogonlogoff_auditspeciallogon_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"e78ae22c8f1904fd":{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents","displayName":"Object Access Audit Other Object Access Events","description":"This policy setting allows you to audit events generated by the management of task scheduler jobs or COM+ objects. For scheduler jobs, the following are audited: Job created. Job deleted. Job enabled. Job disabled. Job updated. For COM+ objects, the following are audited: Catalog object added. Catalog object updated. Catalog object deleted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#objectaccess_auditotherobjectaccessevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_objectaccess_auditotherobjectaccessevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"e7acac091a7ee8b5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed","displayName":"Allow or deny audio capture","description":"Setting the policy to Enabled or leaving it unset means that, with the exception of URLs set in the AudioCaptureAllowedUrls list, users get prompted for audio capture access.\r\n\r\nSetting the policy to Disabled turns off prompts, and audio capture is only available to URLs set in the AudioCaptureAllowedUrls list.\r\n\r\nNote: The policy affects all audio input (not just the built-in microphone).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_audiocaptureallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"e73353c8c4abe4ff":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy","displayName":"Google Chrome cloud policy overrides Platform policy.","description":"Setting the policy to Enabled means cloud policy takes precedence if it conflicts with platform policy.\r\n\r\nSetting the policy to Disabled or leaving it unset means platform policy takes precedence if it conflicts with cloud policy.\r\n\r\nThis mandatory policy affects machine scope cloud policies.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cloudpolicyoverridesplatformpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"e791021f6b027b3b":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~contentsettings_recommended_registeredprotocolhandlers_recommended_registeredprotocolhandlers","displayName":"Register protocol handlers (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"962a2377-ad9a-4654-a526-a77c14152fd7","categoryName":"Content settings","options":null},"e70e3cfa15c9c4e9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended","displayName":"Default search provider keyword","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e7f7dbedebee6246":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation","displayName":"URLs/domains automatically permitted direct Security Key attestation","description":"Setting the policy specifies URLs and domains for which no prompt appears when attestation certificates from Security Keys are requested. A signal is also sent to the Security Key indicating that individual attestation may be used. Without this, when sites request attestation of Security Keys, users are prompted in Google Chrome version 65 and later.\r\n\r\nURLs will only match as U2F appIDs. Domains only match as webauthn RP IDs. So to cover both U2F and webauthn APIs, list the appID URL and domain for a given site.\r\n\r\nExample value:\r\n\r\nhttps://example.com","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_securitykeypermitattestation_1","displayName":"Enabled","description":null,"helpText":null}]},"e7738ba147c01fbf":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls","displayName":"Allow Window Placement permission on these sites","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~deprecatedpolicies_windowplacementallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"e760a7450c7f64d5":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~extensions_extensioninstalltypeblocklist_extensioninstalltypeblocklistdesc","displayName":"Blocklist for install types of extensions (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":null},"e7c52f95a5a7e82c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled","displayName":"Control the URL parameter filter feature","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_urlparamfilterenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e70fb8a8d51dcda8":{"id":"device_vendor_msft_policy_config_datausage_setcost4g_cost4g_dropdownlist","displayName":"Please select a 4G connection cost value to set:","description":"","helpText":"","infoUrls":[],"categoryId":"edf3754c-b22d-4946-a744-4773240a5883","categoryName":"WWAN Media Cost","options":[{"id":"device_vendor_msft_policy_config_datausage_setcost4g_cost4g_dropdownlist_1","displayName":"Unrestricted","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_datausage_setcost4g_cost4g_dropdownlist_2","displayName":"Fixed","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_datausage_setcost4g_cost4g_dropdownlist_3","displayName":"Variable","description":null,"helpText":null}]},"e789b449803c83a1":{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizeapplicationlog","displayName":"Specify the maximum log file size (KB)","description":"This policy setting specifies the maximum size of the log file in kilobytes.\n\nIf you enable this policy setting, you can configure the maximum log file size to be between 1 megabyte (1024 kilobytes) and 2 terabytes (2147483647 kilobytes), in kilobyte increments.\n\nIf you disable or do not configure this policy setting, the maximum size of the log file will be set to the locally configured value. This value can be changed by the local administrator using the Log Properties dialog, and it defaults to 1 megabyte.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-eventlogservice#eventlogservice-specifymaximumfilesizeapplicationlog"],"categoryId":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","categoryName":"Application","options":[{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizeapplicationlog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_eventlogservice_specifymaximumfilesizeapplicationlog_1","displayName":"Enabled","description":null,"helpText":null}]},"e7f35e83d93f6786":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesvhdlocations_profilesvhdlocations","displayName":"VHD Locations (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"e792423bff0ad661":{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_preventteamsinstall","displayName":"Don’t install Microsoft Teams with new installations or updates of Office","description":"This policy setting allows you to control whether Microsoft Teams is installed with a new installation of Office or when an existing installation of Office is updated.\r\n\r\nNote: This policy setting only applies to versions of Office, such as Office 365 ProPlus, where Teams is installed with a new installation or an update of Office.\r\n\r\nIf you enable this policy setting, Teams won’t be installed with a new installation or an update of Office.\r\n\r\nIf you disable or don’t configure this policy setting, Teams will be installed as part of a new installation or an update of Office, unless you have used some other method, such as the Office Deployment Tool, to exclude the installation of Teams.","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_preventteamsinstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v3~policy~l_microsoftofficemachine~l_updates_l_preventteamsinstall_1","displayName":"Enabled","description":null,"helpText":null}]},"e70695f43f0f33f8":{"id":"device_vendor_msft_policy_config_remoteassistance_unsolicitedremoteassistance_ra_unsolicit_dacl_edit","displayName":"Helpers:","description":"","helpText":"","infoUrls":[],"categoryId":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","categoryName":"Remote Assistance","options":null},"e77646441b1dbaff":{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection","displayName":"Restrict clipboard transfer from server to client","description":"This policy setting allows you to restrict clipboard data transfers from server to client.\r\n\r\nIf you enable this policy setting, you must choose from the following behaviors:\r\n\r\n- Disable clipboard transfers from server to client.\r\n\r\n- Allow plain text copying from server to client.\r\n\r\n- Allow plain text and images copying from server to client.\r\n\r\n- Allow plain text, images and Rich Text Format copying from server to client.\r\n\r\n- Allow plain text, images, Rich Text Format and HTML copying from server to client.\r\n\r\nIf you disable or do not configure this policy setting, users can copy arbitrary contents from server to client if clipboard redirection is enabled.\r\n\r\nNote: This policy setting appears in both Computer Configuration and User Configuration. If both policy settings are configured, the stricter restriction will be used.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-limitservertoclientclipboardredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_limitservertoclientclipboardredirection_1","displayName":"Enabled","description":null,"helpText":null}]},"e7c2162e29614c47":{"id":"device_vendor_msft_policy_config_storage_removablediskdenywriteaccess","displayName":"Removable Disk Deny Write Access","description":"If you enable this policy setting, write access is denied to this removable storage class. If you disable or do not configure this policy setting, write access is allowed to this removable storage class. Note: To require that users write data to BitLocker-protected storage, enable the policy setting \"Deny write access to drives not protected by BitLocker,\" which is located in \"Computer Configuration\\Administrative Templates\\Windows Components\\BitLocker Drive Encryption\\Removable Data Drives.\"","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Storage#removablediskdenywriteaccess"],"categoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","categoryName":"Storage","options":[{"id":"device_vendor_msft_policy_config_storage_removablediskdenywriteaccess_0","displayName":"Disabled","description":"Disabled.","helpText":null},{"id":"device_vendor_msft_policy_config_storage_removablediskdenywriteaccess_1","displayName":"Enabled","description":"Enabled.","helpText":null}]},"e785022220a74023":{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_meteredupdatesmicrosoftedgecanary","displayName":"Let users update on metered connections","description":"Specifies whether Microsoft Edge Update will update on connections marked as metered, such as cellular connections or others where data usage is controlled for the Microsoft Edge browser. \r\n\r\nIf you don't enable and configure this policy, updates occur based the 'Download Updates over metered connections' toggle in the About Page of the Microsoft Edge browser. If a user doesn't make a choice, the Windows setting is used. You can find out more about the Windows setting here: https://learn.microsoft.com/en-us/windows/client-management/mdm/policy-csp-update#allowautowindowsupdatedownloadovermeterednetwork\r\n\r\nAlways allow updates (2): Updates are always downloaded when found, either by automatic update check or by a manual update check.\r\n\r\nDisable updates (1): Updates are not downloaded when using a metered connection.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_meteredupdatesmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev127~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_meteredupdatesmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},"e7613a36a127c710":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders54","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders54_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc13_l_allowsubfolders54_1","displayName":"True","description":null,"helpText":null}]},"e74b4bf9927f2792":{"id":"user_vendor_msft_policy_config_admx_startmenu_nosetfolders","displayName":"Remove programs on Settings menu (User)","description":"This policy setting allows you to remove programs on Settings menu.\r\n\r\nIf you enable this policy setting, the Control Panel, Printers, and Network and Connection folders are removed from Settings on the Start menu, and from Computer and File Explorer. It also prevents the programs represented by these folders (such as Control.exe) from running.\r\n\r\nHowever, users can still start Control Panel items by using other methods, such as right-clicking the desktop to start Display or right-clicking Computer to start System.\r\n\r\nIf you disable or do not configure this policy setting, the Control Panel, Printers, and Network and Connection folders from Settings are available on the Start menu, and from Computer and File Explorer.\r\n\r\nAlso, see the \"Disable Control Panel,\" \"Disable Display in Control Panel,\" and \"Remove Network Connections from Start Menu\" policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nosetfolders"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nosetfolders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nosetfolders_1","displayName":"Enabled","description":null,"helpText":null}]},"e79607bcb7b62b28":{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskbarclock","displayName":"Remove Clock from the system notification area (User)","description":"Prevents the clock in the system notification area from being displayed.\r\n\r\nIf you enable this setting, the clock will not be displayed in the system notification area.\r\n\r\nIf you disable or do not configure this setting, the default behavior of the clock appearing in the notification area will occur.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notaskbarclock"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskbarclock_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskbarclock_1","displayName":"Enabled","description":null,"helpText":null}]},"e74d5b3ef41bf8a5":{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskgrouping","displayName":"Prevent grouping of taskbar items (User)","description":"This setting affects the taskbar buttons used to switch between running programs.\r\n\r\nTaskbar grouping consolidates similar applications when there is no room on the taskbar. It kicks in when the user's taskbar is full.\r\n\r\nIf you enable this setting, it prevents the taskbar from grouping items that share the same program name. By default, this setting is always enabled.\r\n\r\nIf you disable or do not configure it, items on the taskbar that share the same program are grouped together. The users have the option to disable grouping if they choose.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-notaskgrouping"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskgrouping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_notaskgrouping_1","displayName":"Enabled","description":null,"helpText":null}]},"e761e44b9276a07c":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming","displayName":"Sync settings over metered connections even when roaming (User)","description":"This policy setting defines whether the User Experience Virtualization (UE-V) Agent synchronizes settings over metered connections outside of the home provider network, for example when connected via a roaming connection.\r\nBy default, the UE-V Agent does not synchronize settings over a metered connection that is roaming.\r\nWith this setting enabled, the UE-V Agent synchronizes settings over a metered connection that is roaming.\r\nWith this setting disabled, the UE-V Agent will not synchronize settings over a metered connection that is roaming.\r\nIf you do not configure this policy setting, any defined values are deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-syncovermeterednetworkwhenroaming"],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_syncovermeterednetworkwhenroaming_1","displayName":"Enabled","description":null,"helpText":null}]},"e71b2c825649dca5":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noentirenetwork","displayName":"No Entire Network in Network Locations (User)","description":"Removes all computers outside of the user's workgroup or local domain from lists of network resources in File Explorer and Network Locations.\r\n\r\nIf you enable this setting, the system removes the Entire Network option and the icons representing networked computers from Network Locations and from the browser associated with the Map Network Drive option.\r\n\r\nThis setting does not prevent users from viewing or connecting to computers in their workgroup or domain. It also does not prevent users from connecting to remote computers by other commonly used methods, such as by typing the share name in the Run dialog box or the Map Network Drive dialog box.\r\n\r\nTo remove computers in the user's workgroup or domain from lists of network resources, use the \"No Computers Near Me in Network Locations\" setting.\r\n\r\nNote: It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-noentirenetwork"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noentirenetwork_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noentirenetwork_1","displayName":"Enabled","description":null,"helpText":null}]},"e7cbbb0f7127c779":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions","displayName":"Allow download restrictions (User)","description":"Setting the policy means users can't bypass download security decisions.\r\n\r\nThere are many types of download warnings within Chrome, which roughly break down into these categories (learn more about Safe Browsing verdicts https://support.google.com/chrome/?p=ib_download_blocked):\r\n\r\n* Malicious, as flagged by the Safe Browsing server\r\n* Uncommon or unwanted, as flagged by the Safe Browsing server\r\n* A dangerous file type (e.g. all SWF downloads and many EXE downloads)\r\n\r\nSetting the policy blocks different subsets of these, depending on it's value:\r\n\r\n0: No special restrictions. Default.\r\n\r\n1: Blocks malicious files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n2: Blocks malicious files flagged by the Safe Browsing server AND Blocks uncommon or unwanted files flagged by the Safe Browsing server AND Blocks all dangerous file types. Only recommended for OUs/browsers/users that have a high tolerance for False Positives.\r\n\r\n3: Blocks all downloads. Not recommended, except for special use cases.\r\n\r\n4: Blocks malicious files flagged by the Safe Browsing server, does not block dangerous file types. Recommended.\r\n\r\nNote: These restrictions apply to downloads triggered from webpage content, as well as the Download link... menu option. They don't apply to the download of the currently displayed page or to saving as PDF from the printing options. Read more about Safe Browsing ( https://developers.google.com/safe-browsing ).","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_downloadrestrictions_1","displayName":"Enabled","description":null,"helpText":null}]},"e7cc5bb4b202dcc3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"e790505c8e4faca4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist","displayName":"Configure extension installation whitelist (User)","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500\r\n\r\nExample value:\r\n\r\nextension_id1\r\nextension_id2","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_extensioninstallwhitelist_1","displayName":"Enabled","description":null,"helpText":null}]},"e7741cd7645325b1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes","displayName":"Supported authentication schemes (User)","description":"Setting the policy specifies which HTTP authentication schemes Google Chrome supports.\r\n\r\nLeaving the policy unset employs all 4 schemes.\r\n\r\nValid values:\r\n\r\n* basic\r\n\r\n* digest\r\n\r\n* ntlm\r\n\r\n* negotiate\r\n\r\nNote: Separate multiple values with commas.\r\n\r\nExample value: basic,digest,ntlm,negotiate","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~httpauthentication_authschemes_1","displayName":"Enabled","description":null,"helpText":null}]},"e76c3d0232c37a78":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_enabledplugins_enabledpluginsdesc","displayName":"List of enabled plugins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"e73a3b6a57248bde":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources","displayName":"Access data sources across domains (User)","description":"This policy setting allows you to manage whether Internet Explorer can access data from another security zone using the Microsoft XML Parser (MSXML) or ActiveX Data Objects (ADO).\n\nIf you enable this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone. If you select Prompt in the drop-down box, users are queried to choose whether to allow a page to be loaded in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you disable this policy setting, users cannot load a page in the zone that uses MSXML or ADO to access data from another site in the zone.\n\nIf you do not configure this policy setting, users can load a page in the zone that uses MSXML or ADO to access data from another site in the zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowaccesstodatasources"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowaccesstodatasources_1","displayName":"Enabled","description":null,"helpText":null}]},"e73f27d483e74aee":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b","displayName":"Only allow approved domains to use ActiveX controls without prompt (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_3","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstouseactivexcontrols_iz_partname120b_0","displayName":"Disable","description":null,"helpText":null}]},"e7a0fd6bde08309c":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00","displayName":"Logon options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_196608","displayName":"Anonymous logon","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_131072","displayName":"Automatic logon only in Intranet zone","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_0","displayName":"Automatic logon with current username and password","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonelogonoptions_iz_partname1a00_65536","displayName":"Prompt for user name and password","description":null,"helpText":null}]},"e7e58b53bc15f0f0":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1","displayName":"Disable HTTP fallback for SIP connection (User)","description":"Prevents from HTTP being used for SIP connection in case TLS or TCP fail.","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisablehttpconnect_1_1","displayName":"Enabled","description":null,"helpText":null}]},"e7a02cefc42b9da5":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1","displayName":"Allow storage of user passwords (User)","description":"\r\nAllows Microsoft Lync to store user passwords.\r\n\r\nIf you enable this policy setting, Microsoft Lync can store a password on request from the user.\r\n\r\nIf you disable this policy setting, Microsoft Lync cannot store a password.\r\n\r\nIf you do not configure this policy setting and the user logs on to a domain, Microsoft Lync does not store the password. If you do not configure this policy setting and the user does not log on to a domain (for example, if the user logs on to a workgroup), Microsoft Lync can store the password.\r\n\r\nNote: You can configure this policy setting under both Computer Configuration and User Configuration, but the policy setting under Computer Configuration takes precedence.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policysavepassword_1_1","displayName":"Enabled","description":null,"helpText":null}]},"e75c37368f1d6297":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots","displayName":"Disable taking screenshots (User)","description":"Controls if users can take screenshots of the browser page.\r\n\r\nIf enabled, user can't take screenshots by using keyboard shortcuts or extension APIs.\r\n\r\nIf disabled or don't configure this policy, users can take screenshots.\r\n\r\nPlease note this policy controls screenshots taken from within the browser itself. Even if you enable this policy, users might still be able to take screenshots using some method outside of the browser (like using an operating system feature or another application).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_disablescreenshots_1","displayName":"Enabled","description":null,"helpText":null}]},"e79f20741c7a9525":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_isolateorigins","displayName":"Enable site isolation for specific origins (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"e7613d3e18593064":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloaddirectory_recommended_downloaddirectory","displayName":"Set download directory (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},"e7f419ae705614ce":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended","displayName":"Allow download restrictions (User)","description":"Configures the type of downloads that Microsoft Edge completely blocks, without letting users override the security decision.\r\n\r\nSet 'Block dangerous downloads' (1) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings.\r\n\r\nSet 'Block potentially dangerous downloads' (2) to allow all downloads except for those that carry Microsoft Defender SmartScreen warnings of potentially dangerous downloads.\r\n\r\nSet 'Block all downloads' (3) to block all downloads.\r\n\r\nIf you don't configure this policy or set the 'No special restrictions' (0) option, the downloads go through the usual security restrictions based on Microsoft Defender SmartScreen analysis results.\r\n\r\nNote that these restrictions apply to downloads from web page content, as well as the 'download link...' context menu option. These restrictions don't apply to saving or downloading the currently displayed page, nor do they apply to the Save as PDF option from the printing options.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2094934 for more info on Microsoft Defender SmartScreen.\r\n\r\n* 0 = No special restrictions\r\n\r\n* 1 = Block dangerous downloads\r\n\r\n* 2 = Block potentially dangerous downloads\r\n\r\n* 3 = Block all downloads","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_downloadrestrictions_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e7cbd0d9920942e9":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir","displayName":"Set the user data directory (User)","description":"Set the directory to use for storing user data.\r\n\r\nIf you enable this policy, Microsoft Edge uses the specified directory regardless of whether the user has set the '--user-data-dir' command-line flag.\r\n\r\nIf you don't enable this policy, the default profile path is used, but the user can override it by using the '--user-data-dir' flag. Users can find the directory for the profile at edge://version/ under profile path.\r\n\r\nTo avoid data loss or other errors, don't configure this policy to a volume's root directory or to a directory that's used for other purposes, because Microsoft Edge manages its contents.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables that can be used.\r\n\r\nExample value: ${users}/${user_name}/Edge","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_userdatadir_1","displayName":"Enabled","description":null,"helpText":null}]},"e7131aa6dba572b6":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention","displayName":"Block tracking of users' web-browsing activity (User)","description":"Lets you decide whether to block websites from tracking users' web-browsing activity.\r\n\r\nIf you enable this policy, you have the following options for setting the level of tracking prevention:\r\n\r\n* 0 = Off (no tracking prevention)\r\n\r\n* 1 = Basic (blocks harmful trackers, content and ads will be personalized)\r\n\r\n* 2 = Balanced (blocks harmful trackers and trackers from sites user has not visited; content and ads will be less personalized)\r\n\r\n* 3 = Strict (blocks harmful trackers and majority of trackers from all sites; content and ads will have minimal personalization. Some parts of sites might not work)\r\n\r\nIf you disable this policy or don't configure it, users can set their own level of tracking prevention.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_trackingprevention_1","displayName":"Enabled","description":null,"helpText":null}]},"e7fa1975c68de0d3":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs","displayName":"Allow importing of open tabs (User)","description":"Allows users to import open and pinned tabs from another browser into Microsoft Edge.\r\n\r\nIf you enable this policy, the **Open tabs** check box is automatically selected in the **Import browser data** dialog box.\r\n\r\nIf you disable this policy, open tabs aren't imported at first run, and users can't import them manually.\r\n\r\nIf you don't configure this policy, open tabs are imported at first run, and users can choose whether to import them manually during later browsing sessions.\r\n\r\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports open tabs on first run, but users can select or clear the **Open tabs** option during manual import.\r\n\r\n**Note**: This policy currently only supports importing from Google Chrome (on Windows 7, 8, and 10 and on macOS).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_importopentabs_1","displayName":"Enabled","description":null,"helpText":null}]},"e713ef0e1144e4b4":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled","displayName":"Enable globally scoped HTTP auth cache (User)","description":"This policy configures a single global per profile cache with HTTP server authentication credentials.\r\n\r\nIf you disable or don’t set this policy, the browser will use the default behavior of cross-site auth, which as of version 80, will be to scope HTTP server authentication credentials by top-level site. So, if two sites use resources from the same authenticating domain, credentials will need to be provided independently in the context of both sites. Cached proxy credentials will be reused across sites.\r\n\r\nIf you enable this policy HTTP auth credentials entered in the context of one site will automatically be used in the context of another site.\r\n\r\nEnabling this policy leaves sites open to some types of cross-site attacks, and allows users to be tracked across sites even without cookies by adding entries to the HTTP auth cache using credentials embedded in URLs.\r\n\r\nThis policy is intended to give enterprises depending on the legacy behavior a chance to update their login procedures and will be removed in the future.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_globallyscopehttpauthcacheenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e77a371be5d8aa35":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting","displayName":"Default sensors setting (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting_1","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultsensorssetting_defaultsensorssetting_2","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},"e7fddc94938d8176":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic","displayName":"Greenlandic (User)","description":"Enables the editing language Greenlandic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_greenlandic_1","displayName":"Enabled","description":null,"helpText":null}]},"e72a752fa615b0b8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache8_l_workflowfriendly466","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"e73984a861015e40":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc04_l_descriptioncolon252","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"e7d265b23ea4a733":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot","displayName":"Notebook Root (User)","description":"To change to where new notebooks are defaulted, enter a path to a folder relative to your documents.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_notebookroot_1","displayName":"Enabled","description":null,"helpText":null}]},"e7f6afd07e29d01c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_calendaritemdefaults_l_showremindersxminutesbeforetheeventstarts","displayName":"Show reminders minutes before the event starts: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":null},"e7620289d66ce75b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30","displayName":"Signature Warning (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_0","displayName":"Let user decide if they want to be warned","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_1","displayName":"Always warn about invalid signatures","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_signaturewarning_l_signaturewarning30_2","displayName":"Never warn about invalid signatures","description":null,"helpText":null}]},"e79c5b98242df65b":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy","displayName":"Remove file extensions blocked as Level 1 (User) (Deprecated)","description":"This policy setting controls which types of attachments (determined by file extension) Outlook prevents from being delivered. \r\n\r\nOutlook uses two levels of security to restrict users' access to files attached to e-mail messages or other items. Files with specific extensions can be categorized as Level 1 (users cannot view the file) or Level 2 (users can open the file after saving it to disk). Users can freely open files of types that are not categorized as Level 1 or Level 2. \r\n\r\nIf you enable this policy setting, you can specify the removal of file type extensions as that Outlook classifies as Level 1--that is, to be blocked from delivery--by entering them in the text field provided separated by semicolons. \r\n\r\nIf you disable or do not configure this policy setting, Outlook classifies a number of potentially harmful file types (such as those with .exe, .reg, and .vbs extensions) as Level 1 and blocks files with those extensions from being delivered. \r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level1removefilepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"e704275c692bcb87":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder","displayName":"Turn off audio recording for screen recording (User)","description":"This policy setting allows you to control the initial audio recording setting for a screen recording in PowerPoint. By default, audio is recorded during a screen recording.\r\n \r\nIf you enable this policy setting, audio isn’t recorded during a screen recording. But, the user can choose to turn on audio recording manually in the UI.\r\n \r\nIf you disable or don’t configure this policy setting, audio is recorded during a screen recording. The user can choose to turn off audio recording manually in the UI.","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_defaultmuteaudioinscreenrecorder_1","displayName":"Enabled","description":null,"helpText":null}]},"e77a7ed6490bc5fb":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab","displayName":"Display Developer tab in the Ribbon (User)","description":"This policy setting controls whether the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you enable this policy setting, the Developer tab will be displayed in the Ribbon.\r\n\r\nIf you disable this policy setting, the Developer tab will not be displayed in the Ribbon.\r\n\r\nIf you do not configure this policy setting, the Developer tab will not be displayed in the Ribbon, but its visibility can be changed via a setting in the application Options dialog box.","helpText":"","infoUrls":[],"categoryId":"f66fb7e4-a968-4969-b627-f99aaad0dfc3","categoryName":"Customize Ribbon","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_optionscustomizeribbon_l_displaydevelopertab_1","displayName":"Enabled","description":null,"helpText":null}]},"e77bc2495bc4fdc1":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon69","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":null},"e7cb3e11c6ae44f5":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline","displayName":"Baseline for Earned Value calculations (User)","description":"Specifies the baseline that is used to measure project performance using earned value analysis.\r\n\r\nIf you enable this setting, Project will calculate earned value using the baseline you specified.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"acbc106b-796a-4ba3-ab5f-c130530ad455","categoryName":"Earned Value options for Project1","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile~l_pjev_l_pjevbaseline_1","displayName":"Enabled","description":null,"helpText":null}]},"e74110f741db985e":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2","displayName":"Disable commands (User)","description":"This policy setting allows you to disable any command bar button and menu item with a command bar ID, including command bar buttons and menu items that are not in the predefined lists.\r\n\r\nIf you enable this policy setting, you can enter an ID number to disable a specific command bar button or menu item. \r\n\r\nIf you disable or do not configure this policy setting, all default command bar buttons or menu items are available to users.","helpText":"","infoUrls":[],"categoryId":"907fd656-2a80-4f34-8615-a3acb11a2b95","categoryName":"Custom","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems2_1","displayName":"Enabled","description":null,"helpText":null}]},"e7f614e5fbcf0a07":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality","displayName":"Turn off CAD/DWG functionality (User)","description":"This policy setting allows you to turn off all entry points related to CAD/DWG files.\r\n\r\nIf you enable this policy setting, CAD/DWG functionality will be turned off.\r\n\r\nIf you disable or do not configure this policy setting, CAD/DWG functionality will be turned on.","helpText":"","infoUrls":[],"categoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_save_l_turnoffcaddwgfunctionality_1","displayName":"Enabled","description":null,"helpText":null}]},"e7bd389fd168d93b":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc11_l_descriptioncolon50","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"e7432753376cec8d":{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon","displayName":"Allow the use of SharePoint eSignature for Microsoft Word (User)","description":"This policy setting allows you to control whether users can request eSignatures directly from Word in tenants that have enabled Microsoft's native eSignature service.\r\n\r\nIf you enable this policy setting, users can request eSignatures from within Word. This policy setting applies only to subscription versions of Word.\r\n\r\nIf you disable this policy setting, users cannot request eSignatures from within Word.\r\n\r\nIf you don't configure this policy setting, users cannot request eSignatures from within Word.","helpText":"","infoUrls":[],"categoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","categoryName":"Microsoft Word 2016","options":[{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword_l_showesignribbon_1","displayName":"Enabled","description":null,"helpText":null}]},"e7af63a59f9d66ec":{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption","displayName":"Allow Startup Boost feature (User)","description":"This policy setting configures the \"Startup Boost\" checkbox found under File tab | Options | General. Startup Boost improves Word's boot time by prewarming the app on user login.\r\n\r\nIf you enable or do not configure this policy, users will be able to use the Startup Boost feature. The Startup Boost checkbox will be enabled and checked by default.\r\n\r\nIf you disable this policy setting, the Startup Boost feature will not be available. The Startup Boost checkbox will be disabled and unchecked.\r\n\r\nNote: This policy setting only applies to subscription versions of Office, such as Microsoft 365 Apps for enterprise.\r\n ","helpText":"","infoUrls":[],"categoryId":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v13~policy~l_microsoftofficeword~l_wordoptions~l_optionsgeneral_l_startupboostoption_1","displayName":"Enabled","description":null,"helpText":null}]},"e777b60efd87817c":{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption","displayName":"Disable Stealth Mode Ipsec Secured Packet Exemption","description":"This value is an on/off switch. This option is ignored if DisableStealthMode is on. Otherwise, when this option is true, the firewall's stealth mode rules MUST NOT prevent the host computer from responding to unsolicited network traffic if that traffic is secured by IPsec. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_disablestealthmodeipsecsecuredpacketexemption_true","displayName":"True","description":"TRUE","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/e9.json b/public/intune-definitions/e9.json index c8d85f2a3c42..0527274b9361 100644 --- a/public/intune-definitions/e9.json +++ b/public/intune-definitions/e9.json @@ -1 +1 @@ -{"e976443d26a6166c":{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification","displayName":"Allow Default Messaging App Modification","description":"If false, disables default messaging app preference modification. The MDM Settings command to set the default messaging app preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification_true","displayName":"True","description":null,"helpText":null}]},"e99e3fe2d26d6594":{"id":"com.apple.applicationaccess_allowfilesharingmodification","displayName":"Allow File Sharing Modification","description":"If 'false', prevents modifying File Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesharingmodification_true","displayName":"True","description":null,"helpText":null}]},"e9c9b4d974cc7e76":{"id":"com.apple.applicationaccess_ratingtvshowsjp","displayName":"Rating TV Shows - Japan","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsjp_1","displayName":"Explicit Allowed","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsjp_2","displayName":"All","description":null,"helpText":null}]},"e9716fc61a5d2c20":{"id":"com.apple.dock_launchanim-immutable","displayName":"Launch Animation Immutable","description":"If true, locks \"Animate opening applications.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_launchanim-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_launchanim-immutable_true","displayName":"True","description":null,"helpText":null}]},"e92b8ca5f118c120":{"id":"com.apple.familycontrols.contentfilter_filterblacklist","displayName":"Filter Blocklist (Deprecated)","description":"The array of URLs that defines a deny list. When Restrict Web and Use Content Filter are enabled, no URLs in the deny list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},"e9e80c49a463e57d":{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on edge://extensions.\n\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\nIf the policy is set to Disallow (1), users cannot turn on developer mode on the extensions page.\n\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\n\nPolicy options mapping:\n\n* Allow (0) = Allow the usage of developer mode on extensions page\n\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensiondevelopermodesettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},"e993fb6cfe68d24c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame","displayName":"Allow surf game","description":"If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf.\n\nIf you enable or don't configure this policy, users can play the surf game.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame_true","displayName":"Enabled","description":null,"helpText":null}]},"e945ece0942b43fa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended","displayName":"Configure Automatic HTTPS (Obsolete) (users can override)","description":"This policy lets you manage settings for \"AutomaticHttpsDefault\", which switches connections from HTTP to HTTPS.\n\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\n\nMicrosoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to \"AlwaysUpgrade\" or left unset, this feature is enabled by default.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nThis policy is obsolete, and is replaced with the policy \"HttpsUpgradesEnabled\".\n\nPolicy options mapping:\n\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\n\n* UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\n\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_disableautomatichttps","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_upgradecapabledomains","displayName":"(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_alwaysupgrade","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},"e9f328a6c94fb106":{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\n\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured \"DefaultCookiesSetting\"\n\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\n\nIf you enable this policy, don't configure the \"AllowDeletingBrowserHistory\" or the \"ClearCachedImagesAndFilesOnExit\" policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured \"AllowDeletingBrowserHistory\" or \"ClearCachedImagesAndFilesOnExit\".\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.\nTo exclude passwords from being deleted on exit, configure the \"PasswordDeleteOnBrowserCloseEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_true","displayName":"Enabled","description":null,"helpText":null}]},"e9bec20488048504":{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\n\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"e9b7a9766ddf1dc6":{"id":"com.microsoft.edge.mamedgeappconfigsettings.scarewareblockerallowlistdomains","displayName":"Configure the list of domains where Microsoft Edge Scareware blockers don't run","description":"This policy configures the list of trusted domains for Microsoft Edge Scareware blocker. When a website's source URL matches any domain in this list, Microsoft Edge Scareware blocker doesn't analyze that site.\n\nThis policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled.\n\nIf you enable this policy, Microsoft Edge Scareware blocker trusts the specified domains.\n\nIf you disable or don't configure this policy, Microsoft Edge Scareware blocker analyzes all sites.","helpText":null,"infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},"e95ffc376ec4203e":{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials","displayName":"Allow delegating saved credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's saved credentials can be delegated (saved credentials are those that you elect to save/remember using the Windows credential manager).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of saved credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of saved credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating saved credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowsavedcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},"e941570d520f0457":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list","displayName":"Default:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list_1","displayName":"Report all application errors","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list_0","displayName":"Do not report any application errors","description":null,"helpText":null}]},"e98455e77f1cdb0a":{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate","displayName":"Allow hibernate (S4) when starting from a Windows To Go workspace","description":"\r\n\r\nSpecifies whether the PC can use the hibernation sleep state (S4) when started from a Windows To Go workspace.\r\n\r\nIf you enable this setting, Windows, when started from a Windows To Go workspace, can hibernate the PC.\r\n\r\nIf you disable or don't configure this setting, Windows, when started from a Windows To Go workspace, can't hibernate the PC.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-externalboot#admx-externalboot-portableoperatingsystem-hibernate"],"categoryId":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","categoryName":"Portable Operating System","options":[{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate_1","displayName":"Enabled","description":null,"helpText":null}]},"e9bc0bc74be4d299":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup","displayName":"Allow cross-forest user policy and roaming user profiles","description":"This policy setting allows user-based policy processing, roaming user profiles, and user object logon scripts for interactive logons across forests.\r\n\r\nThis policy setting affects all user accounts that interactively log on to a computer in a different forest when a trust across forests or a two-way forest trust exists.\r\n\r\nIf you do not configure this policy setting:\r\n- No user-based policy settings are applied from the user's forest.\r\n- Users do not receive their roaming profiles; they receive a local profile on the computer from the local forest. A warning message appears to the user, and an event log message (1529) is posted.\r\n- Loopback Group Policy processing is applied, using the Group Policy Objects (GPOs) that are scoped to the computer.\r\n- An event log message (1109) is posted, stating that loopback was invoked in Replace mode.\r\n\r\nIf you enable this policy setting, the behavior is exactly the same as in Windows 2000: user policy is applied, and a roaming user profile is allowed from the trusted forest.\r\n\r\nIf you disable this policy setting, the behavior is the same as if it is not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-allowx-forestpolicy-and-rup"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup_1","displayName":"Enabled","description":null,"helpText":null}]},"e97e0a0eca5e3489":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue_signatureupdate_avsignaturedue","displayName":"Define the number of days before virus security intelligence is considered out of date","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},"e94f33991307eee4":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_netlogon_sitenamelabel","displayName":"Site:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"e9f9d94da4d1b9b6":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},"e9df70dc29ff777a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},"e903be92a940a7a5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_cookiesallowedforurlsdesc","displayName":"Allow cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"e9764b3622e58608":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses","displayName":"Block all Office applications from creating child processes","description":"This rule blocks Office apps from creating child processes. This includes Word, Excel, PowerPoint, OneNote, and Access.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses_warn","displayName":"Warn","description":null,"helpText":null}]},"e9c76e72eb16b1c0":{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdeviceids_deviceinstall_ids_allow_list","displayName":"Allowed device IDs","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},"e93baaedafdba279":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions","displayName":"Java permissions","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzonejavapermissions"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},"e9ea652ce7c22e94":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"e95c9f12939de5ed":{"id":"device_vendor_msft_policy_config_kioskbrowser_restartonidletime","displayName":"Restart On Idle Time","description":"Amount of time in minutes the session is idle until the kiosk browser restarts in a fresh state.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#restartonidletime"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},"e9a3581d3a1a7620":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_allowanonymoussidornametranslation","displayName":"Network Access Allow Anonymous SID Or Name Translation","description":"Network access: Allow anonymous SID/name translation This policy setting determines whether an anonymous user can request security identifier (SID) attributes for another user. If this policy is enabled, an anonymous user can request the SID attribute for another user. An anonymous user with knowledge of an administrator's SID could contact a computer that has this policy enabled and use the SID to get the administrator's name. This setting affects both the SID-to-name translation as well as the name-to-SID translation. If this policy setting is disabled, an anonymous user cannot request the SID attribute for another user. Default on workstations and member servers: Disabled. Default on domain controllers running Windows Server 2008 or later: Disabled. Default on domain controllers running Windows Server 2003 R2 or earlier: Enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_allowanonymoussidornametranslation"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_allowanonymoussidornametranslation_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_allowanonymoussidornametranslation_0","displayName":"Disable","description":"Disable","helpText":null}]},"e9d9cc6e44177203":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes","description":"Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.\r\n\r\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed to still be used for Enterprise hosts.\r\n\r\nTo disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met:\r\n1. The hash is of the server certificate's subjectPublicKeyInfo.\r\n2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute.\r\n3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\r\n\r\nA subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\r\n\r\nIf you disable this policy or don't configure it, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it's not disclosed according to the Certificate Transparency policy.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_1","displayName":"Enabled","description":null,"helpText":null}]},"e9d1cfb8e31ab809":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended","displayName":"Enable Translate","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\r\n\r\nDisable this policy to disable all built-in translate features.\r\n\r\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e970a787b0cb784c":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_cookiesblockedforurlsdesc","displayName":"Block cookies on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"e9950bc52c8f9df2":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_notificationsblockedforurlsdesc","displayName":"Block notifications on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"e9aa66d2b71b6abc":{"id":"device_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":null},"e9261f61e1bd673a":{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended","displayName":"Enable insecure download warnings","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\r\n\r\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\r\n\r\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e98816c5d41b2b0e":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\nExample value: https://internal.contoso.com/sitelist.xml","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},"e9e1909ffd4593eb":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit","displayName":"Save cookies when Microsoft Edge closes","description":"When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when:\r\n- The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) is enabled or\r\n- The policy 'DefaultCookiesSetting' (Configure cookies) is set to 'Keep cookies for the duration of the session'.\r\n\r\nYou can define a list of sites, based on URL patterns, that will have their cookies preserved across sessions.\r\n\r\nNote: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that have been added by an Admin.\r\n\r\nIf you enable this policy, the list of cookies won't be cleared when the browser closes.\r\n\r\nIf you disable or don't configure this policy, the user's personal configuration is used.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"e9ab1be4ff0e292f":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit","displayName":"Delete files downloaded as part of kiosk session when Microsoft Edge closes","description":"This policy only applies to Microsoft Edge kiosk mode.\r\n\r\nIf you enable this policy, files downloaded as part of the kiosk session are deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy or don't configure it, files downloaded as part of the kiosk session are not deleted when Microsoft Edge closes.\r\n\r\nFor detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":"","infoUrls":[],"categoryId":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","categoryName":"Kiosk Mode settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"e9f52de0ba205cda":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablepasswordcaching","displayName":"Disable Password Caching","description":"This policy lets you control whether passwords can be stored in Microsoft Office 2016 files. \r\n\r\nIf you enable this policy setting, Office 2016 users are prevented from storing passwords in Office 2016 files.\r\n\r\nIf you disable or do not configure this policy setting, users can store passwords in Office 2016 files.","helpText":"","infoUrls":[],"categoryId":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","categoryName":"Security Settings","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablepasswordcaching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablepasswordcaching_1","displayName":"Enabled","description":null,"helpText":null}]},"e9ce4df4611ad0ce":{"id":"device_vendor_msft_policy_config_power_energysaverbatterythresholdonbattery","displayName":"Energy Saver Battery Threshold On Battery","description":"This policy setting allows you to specify battery charge level at which Energy Saver is turned on. If you enable this policy setting, you must provide a percent value, indicating the battery charge level. Energy Saver will be automatically turned on at (and below) the specified level. If you disable or do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#energysaverbatterythresholdonbattery"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":null},"e9706b5cc430a473":{"id":"device_vendor_msft_policy_config_remotedesktopservices_donotallowdriveredirection","displayName":"Do not allow drive redirection","description":"This policy setting specifies whether to prevent the mapping of client drives in a Remote Desktop Services session (drive redirection).\r\n\r\nBy default, an RD Session Host server maps client drives automatically upon connection. Mapped drives appear in the session folder tree in File Explorer or Computer in the format on . You can use this policy setting to override this behavior.\r\n\r\nIf you enable this policy setting, client drive redirection is not allowed in Remote Desktop Services sessions, and Clipboard file copy redirection is not allowed on computers running Windows Server 2003, Windows 8, and Windows XP.\r\n\r\nIf you disable this policy setting, client drive redirection is always allowed. In addition, Clipboard file copy redirection is always allowed if Clipboard redirection is allowed.\r\n\r\nIf you do not configure this policy setting, client drive redirection and Clipboard file copy redirection are not specified at the Group Policy level.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-donotallowdriveredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_donotallowdriveredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_donotallowdriveredirection_1","displayName":"Enabled","description":null,"helpText":null}]},"e9a7a35df74962b1":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditoracc","displayName":"Alt+F11 (Database Tools | Macro | Visual Basic) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditoracc_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditoracc_1","displayName":"True","description":null,"helpText":null}]},"e9e06c7d3a033482":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensavertimeout","displayName":"Screen saver timeout (User)","description":"Specifies how much user idle time must elapse before the screen saver is launched.\r\n\r\nWhen configured, this idle time can be set from a minimum of 1 second to a maximum of 86,400 seconds, or 24 hours. If set to zero, the screen saver will not be started.\r\n\r\nThis setting has no effect under any of the following circumstances:\r\n\r\n - The setting is disabled or not configured.\r\n\r\n - The wait time is set to zero.\r\n\r\n - The \"Enable Screen Saver\" setting is disabled.\r\n\r\n - Neither the \"Screen saver executable name\" setting nor the Screen Saver dialog of the client computer's Personalization or Display Control Panel specifies a valid existing screen saver program on the client.\r\n\r\nWhen not configured, whatever wait time is set on the client through the Screen Saver dialog in the Personalization or Display Control Panel is used. The default is 15 minutes.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-screensavertimeout"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensavertimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensavertimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"e92e4b81c33fd16c":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_video","displayName":"Video (User)","description":"This policy setting configures the synchronization of user settings for the Video app.\r\nBy default, the user settings of Video sync between computers. Use the policy setting to prevent the user settings of Video from synchronizing between computers.\r\nIf you enable this policy setting, Video user settings continue to sync.\r\nIf you disable this policy setting, Video user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-video"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_video_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_video_1","displayName":"Enabled","description":null,"helpText":null}]},"e98d09b2e42408de":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_library3","displayName":"Location 4 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"e9e3a4da9c3687b5":{"id":"user_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices","displayName":"Disallow Autoplay for non-volume devices (User)","description":"This policy setting disallows AutoPlay for MTP devices like cameras or phones.\n\n If you enable this policy setting, AutoPlay is not allowed for MTP devices like cameras or phones.\n\n If you disable or do not configure this policy setting, AutoPlay is enabled for non-volume devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-disallowautoplayfornonvolumedevices"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"user_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices_1","displayName":"Enabled","description":null,"helpText":null}]},"e9d06ce9c37e0690":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains","displayName":"Suppress lookalike domain warnings on domains (User)","description":"This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Google Chrome believes might be trying to spoof another site the user is familiar with.\r\n\r\nIf the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain.\r\n\r\nIf the policy is not set, or set to an empty list, warnings may appear on any site the user visits.\r\n\r\nA hostname can be allowed with a complete host match, or any domain match. For example, a URL like \"https://foo.example.com/bar\" may have warnings suppressed if this list includes either \"foo.example.com\" or \"example.com\".\r\n\r\nExample value:\r\n\r\nfoo.example.com\r\nexample.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"e96f399c868357de":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled","displayName":"Enable reporting of usage and crash-related data (User)","description":"When this policy is enabled, anonymous reporting of usage and crash-related data about Chrome to Google is enabled by default. Users will still be able to change this setting in the Chrome settings.\r\n\r\nWhen this policy is disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting.\r\n\r\nWhen this policy isn't set, users can choose the anonymous reporting behavior at installation or first run, and can later change the setting in the Chrome settings.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain or Windows 10 Pro or Enterprise instances that are enrolled for device management, and macOS instances that are managed via MDM or joined to a domain via MCX.\r\n\r\n(For Chrome OS, see DeviceMetricsReportingEnabled.)","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e974090aca0ce2c3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings","displayName":"Default search provider encodings (User)","description":"If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\r\n\r\nLeaving DefaultSearchProviderEncodings unset puts UTF-8 in use.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_1","displayName":"Enabled","description":null,"helpText":null}]},"e9f4d686583ec883":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings","displayName":"Change Memory Saver Mode Savings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_0","displayName":"Moderate memory savings.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_1","displayName":"Balanced memory savings.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_2","displayName":"Maximum memory savings.","description":null,"helpText":null}]},"e9f24996528decd4":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks","displayName":"Excel 95 workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_1","displayName":"Enabled","description":null,"helpText":null}]},"e98a052ef96e0b51":{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode","displayName":"Reset zoom to default for HTML dialogs in Internet Explorer mode (User)","description":"This policy setting lets admins reset zoom to default for HTML dialogs in Internet Explorer mode.\n\nIf you enable this policy, the zoom of an HTML dialog in Internet Explorer mode will not get propagated from its parent page.\n\nIf you disable, or don't configure this policy, the zoom of an HTML dialog in Internet Explorer mode will be set based on the zoom of it's parent page.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2220107","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-resetzoomfordialoginiemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode_1","displayName":"Enabled","description":null,"helpText":null}]},"e90742c2d4d037b4":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services (User)","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\r\n\r\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\r\n\r\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\r\n\r\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_1","displayName":"Enabled","description":null,"helpText":null}]},"e993b5fccf0fa0a7":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_extensioninstallallowlistdesc","displayName":"Extension IDs to exempt from the block list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"e96c946c4babb7df":{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended","displayName":"Pin browser essentials toolbar button (User)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e9f27301333a9fdc":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_sensorsallowedforurlsdesc","displayName":"Allow access to sensors on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"e960bd3d519e25f2":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes_forcesynctypesdesc","displayName":"Configure the list of types that are included for synchronization (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"e9c72f2c77e40036":{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"e9bbc45a26cd90b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog","displayName":"Display legacy GAL dialog (User)","description":"This policy setting allows you to specify the way contact information is displayed.\r\n\r\nIf you enable this policy setting the global address list (GAL) dialog is displayed instead of the Contact Card when users double click a contact in Outlook. \r\n\r\nIf you disable or do not configure this policy setting the Contact Card is displayed when users double click a contact in Outlook.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog_1","displayName":"Enabled","description":null,"helpText":null}]},"e9a7465fa77dcb6a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany","displayName":"Replace MAPI - Company (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"company\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"company\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},"e9d3f2f9d418dfac":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_l_empty421","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":null},"e99686580335e212":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy","displayName":"Disable UI extending from documents and templates (User)","description":"This policy setting controls whether Office 2016 applications load any custom user interface (UI) code included with a document or template. Office 2016 allows developers to extend the UI with customization code that is included in a document or template. \r\n\r\nIf you enable this policy setting, Office 2016 applications cannot load any UI customization code included with documents and templates. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications load any UI customization code included with a document or template when opening it.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"e9cf9692e8ab1190":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary","displayName":"Set update interval for Outlook Global Address List Dictionary (User)","description":"This policy setting allows you to specify the update interval for the Outlook Global Address List Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\n\r\nIf you enable this policy setting, you can specify the update interval in minutes. For example, if you specify \"720,\" the Outlook Global Address List Dictionary is updated every 720 minutes.\r\n\r\nIf you do not configure this policy setting, the Outlook Global Address List Dictionary is updated every 1440 minutes (24 hours).","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},"e9763ba1de38589e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic","displayName":"Amharic (User)","description":"Enables the editing language Amharic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic_1","displayName":"Enabled","description":null,"helpText":null}]},"e9b49d070caf3f7e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil","displayName":"Portuguese (Brazil) (User)","description":"Enables the editing language Portuguese (Brazil)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil_1","displayName":"Enabled","description":null,"helpText":null}]},"e9286079496b600d":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions","displayName":"Disable 3D Model File Formats List (User)","description":"This policy setting allows you to specify a list of 3D model file formats that will be blocked from being loaded in Office applications.\r\n\r\nIf you enable this policy setting, you can specify a list of 3D Model file format that Office applications will block on insert or load. You should specify the list of 3D model file formats to block in a list of files extensions. For example, to block the FBX extension, enter the string “FBX”. To block the FBX and OBJ extensions, enter the string “FBX; OBJ”.\r\n\r\nIf you disable or do not configure this policy setting, Office applications do not restrict any 3D model file formats.\r\n","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"e99e7529b1c70ff9":{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics","displayName":"Turn off support diagnostics in OneNote (User)","description":"This policy setting controls whether OneNote sends client information to support services on failure.\r\n\r\nSending client information to support services on failure can help diagnose the issue, provide resolution steps, or show contextual error messaging to the user.\r\n\r\nIf you enable this policy setting, OneNote won’t send client information to support services on failure.\r\n\r\nIf you disable or don’t configure this policy setting, OneNote will send client information to support services on failure.\r\n\r\nNote: This policy setting only applies to Version 2207 and later of OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},"e96354a24b944c68":{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels","displayName":"Enable OneNote Sensitivity Labels (User)","description":"This policy setting controls whether Purview Sensitivity Label capabilities can be enabled for OneNote Sections.\r\n\r\nIf you enable this policy, users can use supported Purview features, such as manual labeling, label removal, or default labels, to apply sensitivity labels to OneNote sections and help protect sensitive information. At this time, mandatory labels, auto labeling, and dynamic watermarking are not supported.\r\n\r\nIf you disable this policy, users won't be able to apply, change or remove Sensitivity Labels in OneNote Sections.\r\n\r\nIf you do not configure this policy setting, users won't be able to apply, change or remove Sensitivity Labels in OneNote Sections.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels_1","displayName":"Enabled","description":null,"helpText":null}]},"e9dad70d93d99140":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges","displayName":"Mark item as read when selection changes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges_1","displayName":"True","description":null,"helpText":null}]},"e9ccf839dd9ef6ab":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_monthsoffreebusyinformationpublished","displayName":"Months of Free/Busy information published: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},"e941d7bf6ab48e21":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival","displayName":"Process requests and responses on arrival (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival_1","displayName":"True","description":null,"helpText":null}]},"e9d9b9eacfa2a97d":{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart","displayName":"Disable the Outlook crash notification when Outlook restarts. (User)","description":"This policy setting determines if the Outlook crash notification on restart is allowed. Enabling this setting will block Outlook crash notification on restart.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart_1","displayName":"Enabled","description":null,"helpText":null}]},"e9c8ea21a6448197":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},"e98e706ad678f72d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"e94fa2b29908d64a":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon85","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"e976443d26a6166c":{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification","displayName":"Allow Default Messaging App Modification","description":"If false, disables default messaging app preference modification. The MDM Settings command to set the default messaging app preference will still work when this is applied.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowdefaultmessagingappmodification_true","displayName":"True","description":null,"helpText":null}]},"e99e3fe2d26d6594":{"id":"com.apple.applicationaccess_allowfilesharingmodification","displayName":"Allow File Sharing Modification","description":"If 'false', prevents modifying File Sharing setting in System Settings.\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowfilesharingmodification_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowfilesharingmodification_true","displayName":"True","description":null,"helpText":null}]},"e9c9b4d974cc7e76":{"id":"com.apple.applicationaccess_ratingtvshowsjp","displayName":"Rating TV Shows - Japan","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsjp_1","displayName":"Explicit Allowed","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsjp_2","displayName":"All","description":null,"helpText":null}]},"e9716fc61a5d2c20":{"id":"com.apple.dock_launchanim-immutable","displayName":"Launch Animation Immutable","description":"If true, locks \"Animate opening applications.\"","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_launchanim-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_launchanim-immutable_true","displayName":"True","description":null,"helpText":null}]},"e92b8ca5f118c120":{"id":"com.apple.familycontrols.contentfilter_filterblacklist","displayName":"Filter Blocklist (Deprecated)","description":"The array of URLs that defines a deny list. When Restrict Web and Use Content Filter are enabled, no URLs in the deny list are available to the user.","helpText":null,"infoUrls":[],"categoryId":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","categoryName":"Parental Controls Content Filter","options":null},"e9e80c49a463e57d":{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings","displayName":"Control the availability of developer mode on extensions page","description":"Control if users can turn on Developer Mode on edge://extensions.\n\nIf the policy isn't set, users can turn on developer mode on the extension page unless DeveloperToolsAvailability policy is set to DeveloperToolsDisallowed (2).\nIf the policy is set to Allow (0), users can turn on developer mode on the extensions page.\nIf the policy is set to Disallow (1), users cannot turn on developer mode on the extensions page.\n\nIf this policy is set, DeveloperToolsAvailability can no longer control extensions developer mode.\n\nPolicy options mapping:\n\n* Allow (0) = Allow the usage of developer mode on extensions page\n\n* Disallow (1) = Do not allow the usage of developer mode on extensions page\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#extensiondevelopermodesettings"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings_0","displayName":"Allow the usage of developer mode on extensions page","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_extensiondevelopermodesettings_1","displayName":"Do not allow the usage of developer mode on extensions page","description":null,"helpText":null}]},"e993fb6cfe68d24c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame","displayName":"Allow surf game","description":"If you disable this policy, users won't be able to play the surf game when the device is offline or if the user navigates to edge://surf.\n\nIf you enable or don't configure this policy, users can play the surf game.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.allowsurfgame_true","displayName":"Enabled","description":null,"helpText":null}]},"e945ece0942b43fa":{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended","displayName":"Configure Automatic HTTPS (Obsolete) (users can override)","description":"This policy lets you manage settings for \"AutomaticHttpsDefault\", which switches connections from HTTP to HTTPS.\n\nThis feature helps protect against man-in-the-middle attacks by enforcing more secure connections, but users might experience more connection errors.\n\nMicrosoft Edge attempts to upgrade some navigations from HTTP to HTTPS, when possible. This policy can be used to disable this behavior. If set to \"AlwaysUpgrade\" or left unset, this feature is enabled by default.\n\nThe separate HttpAllowlist policy can be used to exempt specific hostnames or hostname patterns from being upgraded to HTTPS by this feature.\n\nThis policy is obsolete, and is replaced with the policy \"HttpsUpgradesEnabled\".\n\nPolicy options mapping:\n\n* DisableAutomaticHttps (0) = Automatic HTTPS functionality is disabled.\n\n* UpgradeCapableDomains (1) = (Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.\n\n* AlwaysUpgrade (2) = All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_disableautomatichttps","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_upgradecapabledomains","displayName":"(Deprecated) Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.automatichttpsdefault_recommended_alwaysupgrade","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},"e9f328a6c94fb106":{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\n\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured \"DefaultCookiesSetting\"\n\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\n\nIf you enable this policy, don't configure the \"AllowDeletingBrowserHistory\" or the \"ClearCachedImagesAndFilesOnExit\" policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured \"AllowDeletingBrowserHistory\" or \"ClearCachedImagesAndFilesOnExit\".\n\nTo exclude cookies from being deleted on exit, configure the \"SaveCookiesOnExit\" policy.\nTo exclude passwords from being deleted on exit, configure the \"PasswordDeleteOnBrowserCloseEnabled\" policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.clearbrowsingdataonexit_true","displayName":"Enabled","description":null,"helpText":null}]},"e9bec20488048504":{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled","displayName":"Allows users to edit favorites","description":"Enable this policy to let users add, remove, and modify favorites. This is the default behavior if you don't configure the policy.\n\nDisable this policy to stop users from adding, removing, or modifying favorites. They can still use existing favorites.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.editfavoritesenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"e9b7a9766ddf1dc6":{"id":"com.microsoft.edge.mamedgeappconfigsettings.scarewareblockerallowlistdomains","displayName":"Configure the list of domains where Microsoft Edge Scareware blockers don't run","description":"This policy configures the list of trusted domains for Microsoft Edge Scareware blocker. When a website's source URL matches any domain in this list, Microsoft Edge Scareware blocker doesn't analyze that site.\n\nThis policy takes effect only if the ScarewareBlockerProtectionEnabled policy is enabled.\n\nIf you enable this policy, Microsoft Edge Scareware blocker trusts the specified domains.\n\nIf you disable or don't configure this policy, Microsoft Edge Scareware blocker analyzes all sites.","helpText":null,"infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},"e95ffc376ec4203e":{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials","displayName":"Allow delegating saved credentials","description":"This policy setting applies to applications using the Cred SSP component (for example: Remote Desktop Connection).\r\n\r\nThis policy setting applies when server authentication was achieved via a trusted X509 certificate or Kerberos.\r\n\r\nIf you enable this policy setting, you can specify the servers to which the user's saved credentials can be delegated (saved credentials are those that you elect to save/remember using the Windows credential manager).\r\n\r\nIf you do not configure (by default) this policy setting, after proper mutual authentication, delegation of saved credentials is permitted to Remote Desktop Session Host running on any machine (TERMSRV/*).\r\n\r\nIf you disable this policy setting, delegation of saved credentials is not permitted to any machine.\r\n\r\nNote: The \"Allow delegating saved credentials\" policy setting can be set to one or more Service Principal Names (SPNs). The SPN represents the target server to which the user credentials can be delegated. The use of a single wildcard character is permitted when specifying the SPN.\r\n\r\nFor Example:\r\nTERMSRV/host.humanresources.fabrikam.com Remote Desktop Session Host running on host.humanresources.fabrikam.com machine\r\nTERMSRV/* Remote Desktop Session Host running on all machines.\r\nTERMSRV/*.humanresources.fabrikam.com Remote Desktop Session Host running on all machines in humanresources.fabrikam.com\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-credssp#admx-credssp-allowsavedcredentials"],"categoryId":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","categoryName":"Credentials Delegation","options":[{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_credssp_allowsavedcredentials_1","displayName":"Enabled","description":null,"helpText":null}]},"e941570d520f0457":{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list","displayName":"Default:","description":null,"helpText":"","infoUrls":[],"categoryId":"1551f6d3-415c-44a8-b184-393de7c42adf","categoryName":"Advanced Error Reporting Settings","options":[{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list_1","displayName":"Report all application errors","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_errorreporting_pch_allornonedef_pch_allornonedef_list_0","displayName":"Do not report any application errors","description":null,"helpText":null}]},"e98455e77f1cdb0a":{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate","displayName":"Allow hibernate (S4) when starting from a Windows To Go workspace","description":"\r\n\r\nSpecifies whether the PC can use the hibernation sleep state (S4) when started from a Windows To Go workspace.\r\n\r\nIf you enable this setting, Windows, when started from a Windows To Go workspace, can hibernate the PC.\r\n\r\nIf you disable or don't configure this setting, Windows, when started from a Windows To Go workspace, can't hibernate the PC.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-externalboot#admx-externalboot-portableoperatingsystem-hibernate"],"categoryId":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","categoryName":"Portable Operating System","options":[{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_externalboot_portableoperatingsystem_hibernate_1","displayName":"Enabled","description":null,"helpText":null}]},"e9bc0bc74be4d299":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup","displayName":"Allow cross-forest user policy and roaming user profiles","description":"This policy setting allows user-based policy processing, roaming user profiles, and user object logon scripts for interactive logons across forests.\r\n\r\nThis policy setting affects all user accounts that interactively log on to a computer in a different forest when a trust across forests or a two-way forest trust exists.\r\n\r\nIf you do not configure this policy setting:\r\n- No user-based policy settings are applied from the user's forest.\r\n- Users do not receive their roaming profiles; they receive a local profile on the computer from the local forest. A warning message appears to the user, and an event log message (1529) is posted.\r\n- Loopback Group Policy processing is applied, using the Group Policy Objects (GPOs) that are scoped to the computer.\r\n- An event log message (1109) is posted, stating that loopback was invoked in Replace mode.\r\n\r\nIf you enable this policy setting, the behavior is exactly the same as in Windows 2000: user policy is applied, and a roaming user profile is allowed from the trusted forest.\r\n\r\nIf you disable this policy setting, the behavior is the same as if it is not configured.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-allowx-forestpolicy-and-rup"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_allowx-forestpolicy-and-rup_1","displayName":"Enabled","description":null,"helpText":null}]},"e97e0a0eca5e3489":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_avsignaturedue_signatureupdate_avsignaturedue","displayName":"Define the number of days before virus security intelligence is considered out of date","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},"e94f33991307eee4":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sitename_netlogon_sitenamelabel","displayName":"Site:","description":null,"helpText":"","infoUrls":[],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":null},"e9f9d94da4d1b9b6":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypenonconforming_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},"e9df70dc29ff777a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions","displayName":"Enable network prediction (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_0","displayName":"Predict network actions on any network connection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_1","displayName":"Predict network actions on any network that is not cellular.\r\n(Deprecated in 50, removed in 52. After 52, if value 1 is set, it will be treated as 0 - predict network actions on any network connection.)","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_networkpredictionoptions_networkpredictionoptions_2","displayName":"Do not predict network actions on any network connection","description":null,"helpText":null}]},"e903be92a940a7a5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_cookiesallowedforurls_cookiesallowedforurlsdesc","displayName":"Allow cookies on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"e9764b3622e58608":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses","displayName":"Block all Office applications from creating child processes","description":"This rule blocks Office apps from creating child processes. This includes Word, Excel, PowerPoint, OneNote, and Access.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockallofficeapplicationsfromcreatingchildprocesses_warn","displayName":"Warn","description":null,"helpText":null}]},"e9c76e72eb16b1c0":{"id":"device_vendor_msft_policy_config_deviceinstallation_allowinstallationofmatchingdeviceids_deviceinstall_ids_allow_list","displayName":"Allowed device IDs","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-deviceinstallation"],"categoryId":"68237832-f376-4f0e-ba26-4e06fce7a35d","categoryName":"Device Installation Restrictions","options":null},"e93baaedafdba279":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions","displayName":"Java permissions","description":"This policy setting allows you to manage permissions for Java applets.\n\nIf you enable this policy setting, you can choose options from the drop-down box. Custom, to control permissions settings individually.\n\nLow Safety enables applets to perform all operations.\n\nMedium Safety enables applets to run in their sandbox (an area in memory outside of which the program cannot make calls), plus capabilities like scratch space (a safe and secure storage area on the client computer) and user-controlled file I/O.\n\nHigh Safety enables applets to run in their sandbox. Disable Java to prevent any applets from running.\n\nIf you disable this policy setting, Java applets cannot run.\n\nIf you do not configure this policy setting, Java applets are disabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowninternetzonejavapermissions"],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonejavapermissions_1","displayName":"Enabled","description":null,"helpText":null}]},"e9ea652ce7c22e94":{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200","displayName":"Automatic prompting for file downloads","description":"","helpText":"","infoUrls":[],"categoryId":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","categoryName":"Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_trustedsiteszoneallowautomaticpromptingforfiledownloads_iz_partname2200_3","displayName":"Disable","description":null,"helpText":null}]},"e95c9f12939de5ed":{"id":"device_vendor_msft_policy_config_kioskbrowser_restartonidletime","displayName":"Restart On Idle Time","description":"Amount of time in minutes the session is idle until the kiosk browser restarts in a fresh state.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-KioskBrowser#restartonidletime"],"categoryId":"26c1af84-7c09-4910-8b2f-486072fef710","categoryName":"Kiosk Browser","options":null},"e9a3581d3a1a7620":{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_allowanonymoussidornametranslation","displayName":"Network Access Allow Anonymous SID Or Name Translation","description":"Network access: Allow anonymous SID/name translation This policy setting determines whether an anonymous user can request security identifier (SID) attributes for another user. If this policy is enabled, an anonymous user can request the SID attribute for another user. An anonymous user with knowledge of an administrator's SID could contact a computer that has this policy enabled and use the SID to get the administrator's name. This setting affects both the SID-to-name translation as well as the name-to-SID translation. If this policy setting is disabled, an anonymous user cannot request the SID attribute for another user. Default on workstations and member servers: Disabled. Default on domain controllers running Windows Server 2008 or later: Disabled. Default on domain controllers running Windows Server 2003 R2 or earlier: Enabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-LocalPoliciesSecurityOptions#networkaccess_allowanonymoussidornametranslation"],"categoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","categoryName":"Local Policies Security Options","options":[{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_allowanonymoussidornametranslation_1","displayName":"Enable","description":"Enable","helpText":null},{"id":"device_vendor_msft_policy_config_localpoliciessecurityoptions_networkaccess_allowanonymoussidornametranslation_0","displayName":"Disable","description":"Disable","helpText":null}]},"e9d9cc6e44177203":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas","displayName":"Disable Certificate Transparency enforcement for a list of subjectPublicKeyInfo hashes","description":"Disables enforcement of Certificate Transparency requirements for a list of subjectPublicKeyInfo hashes.\r\n\r\nThis policy lets you disable Certificate Transparency disclosure requirements for certificate chains that contain certificates with one of the specified subjectPublicKeyInfo hashes. This allows certificates that would otherwise be untrusted because they were not properly publicly disclosed to still be used for Enterprise hosts.\r\n\r\nTo disable Certificate Transparency enforcement when this policy is set, one of the following sets of conditions must be met:\r\n1. The hash is of the server certificate's subjectPublicKeyInfo.\r\n2. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, that CA certificate is constrained via the X.509v3 nameConstraints extension, one or more directoryName nameConstraints are present in the permittedSubtrees, and the directoryName contains an organizationName attribute.\r\n3. The hash is of a subjectPublicKeyInfo that appears in a CA certificate in the certificate chain, the CA certificate has one or more organizationName attributes in the certificate Subject, and the server's certificate contains the same number of organizationName attributes, in the same order, and with byte-for-byte identical values.\r\n\r\nA subjectPublicKeyInfo hash is specified by concatenating the hash algorithm name, the \"/\" character, and the Base64 encoding of that hash algorithm applied to the DER-encoded subjectPublicKeyInfo of the specified certificate. This Base64 encoding is the same format as an SPKI Fingerprint, as defined in RFC 7469, Section 2.4. Unrecognized hash algorithms are ignored. The only supported hash algorithm at this time is \"sha256\".\r\n\r\nIf you disable this policy or don't configure it, any certificate that's required to be disclosed via Certificate Transparency will be treated as untrusted if it's not disclosed according to the Certificate Transparency policy.\r\n\r\nExample value:\r\n\r\nsha256/AAAAAAAAAAAAAAAAAAAAAA==\r\nsha256//////////////////////w==","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_certificatetransparencyenforcementdisabledforcas_1","displayName":"Enabled","description":null,"helpText":null}]},"e9d1cfb8e31ab809":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended","displayName":"Enable Translate","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\r\n\r\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\r\n\r\nDisable this policy to disable all built-in translate features.\r\n\r\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended_translateenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e970a787b0cb784c":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_cookiesblockedforurls_cookiesblockedforurlsdesc","displayName":"Block cookies on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"e9950bc52c8f9df2":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_notificationsblockedforurlsdesc","displayName":"Block notifications on specific sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"e9aa66d2b71b6abc":{"id":"device_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge~manageability_edgemanagementenrollmenttoken_edgemanagementenrollmenttoken","displayName":"Microsoft Edge management enrollment token (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":null},"e9261f61e1bd673a":{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended","displayName":"Enable insecure download warnings","description":"Enables warnings when potentially dangerous content is downloaded over HTTP.\r\n\r\nIf you enable or don't configure this policy, when a user tries to download potentially dangerous content from an HTTP site, the user will receive a UI warning, such as \"Insecure download blocked.\" The user will still have an option to proceed and download the item.\r\n\r\nIf you disable this policy, the warnings for insecure downloads will be suppressed.","helpText":"","infoUrls":[],"categoryId":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","categoryName":"Downloads","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev128~policy~microsoft_edge_recommended~downloads_recommended_showdownloadsinsecurewarningsenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e98816c5d41b2b0e":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist","displayName":"Configure the Enterprise Mode Site List","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\nExample value: https://internal.contoso.com/sitelist.xml","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_internetexplorerintegrationsitelist_1","displayName":"Enabled","description":null,"helpText":null}]},"e9e1909ffd4593eb":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit","displayName":"Save cookies when Microsoft Edge closes","description":"When this policy is enabled, the specified set of cookies is exempt from deletion when the browser closes. This policy is only effective when:\r\n- The 'Cookies and other site data' toggle is configured in Settings/Privacy and services/Clear browsing data on close or\r\n- The policy 'ClearBrowsingDataOnExit' (Clear browsing data when Microsoft Edge closes) is enabled or\r\n- The policy 'DefaultCookiesSetting' (Configure cookies) is set to 'Keep cookies for the duration of the session'.\r\n\r\nYou can define a list of sites, based on URL patterns, that will have their cookies preserved across sessions.\r\n\r\nNote: Users can still edit the cookie site list to add or remove URLs. However, they can't remove URLs that have been added by an Admin.\r\n\r\nIf you enable this policy, the list of cookies won't be cleared when the browser closes.\r\n\r\nIf you disable or don't configure this policy, the user's personal configuration is used.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_savecookiesonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"e9ab1be4ff0e292f":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit","displayName":"Delete files downloaded as part of kiosk session when Microsoft Edge closes","description":"This policy only applies to Microsoft Edge kiosk mode.\r\n\r\nIf you enable this policy, files downloaded as part of the kiosk session are deleted each time Microsoft Edge closes.\r\n\r\nIf you disable this policy or don't configure it, files downloaded as part of the kiosk session are not deleted when Microsoft Edge closes.\r\n\r\nFor detailed information on configuring kiosk Mode, see https://go.microsoft.com/fwlink/?linkid=2137578.","helpText":"","infoUrls":[],"categoryId":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","categoryName":"Kiosk Mode settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge~kioskmode_kioskdeletedownloadsonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"e9f52de0ba205cda":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablepasswordcaching","displayName":"Disable Password Caching","description":"This policy lets you control whether passwords can be stored in Microsoft Office 2016 files. \r\n\r\nIf you enable this policy setting, Office 2016 users are prevented from storing passwords in Office 2016 files.\r\n\r\nIf you disable or do not configure this policy setting, users can store passwords in Office 2016 files.","helpText":"","infoUrls":[],"categoryId":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","categoryName":"Security Settings","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablepasswordcaching_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine_l_disablepasswordcaching_1","displayName":"Enabled","description":null,"helpText":null}]},"e9ce4df4611ad0ce":{"id":"device_vendor_msft_policy_config_power_energysaverbatterythresholdonbattery","displayName":"Energy Saver Battery Threshold On Battery","description":"This policy setting allows you to specify battery charge level at which Energy Saver is turned on. If you enable this policy setting, you must provide a percent value, indicating the battery charge level. Energy Saver will be automatically turned on at (and below) the specified level. If you disable or do not configure this policy setting, users control this setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Power#energysaverbatterythresholdonbattery"],"categoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","categoryName":"Power","options":null},"e9706b5cc430a473":{"id":"device_vendor_msft_policy_config_remotedesktopservices_donotallowdriveredirection","displayName":"Do not allow drive redirection","description":"This policy setting specifies whether to prevent the mapping of client drives in a Remote Desktop Services session (drive redirection).\r\n\r\nBy default, an RD Session Host server maps client drives automatically upon connection. Mapped drives appear in the session folder tree in File Explorer or Computer in the format on . You can use this policy setting to override this behavior.\r\n\r\nIf you enable this policy setting, client drive redirection is not allowed in Remote Desktop Services sessions, and Clipboard file copy redirection is not allowed on computers running Windows Server 2003, Windows 8, and Windows XP.\r\n\r\nIf you disable this policy setting, client drive redirection is always allowed. In addition, Clipboard file copy redirection is always allowed if Clipboard redirection is allowed.\r\n\r\nIf you do not configure this policy setting, client drive redirection and Clipboard file copy redirection are not specified at the Group Policy level.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-remotedesktopservices#remotedesktopservices-donotallowdriveredirection"],"categoryId":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","categoryName":"Device and Resource Redirection","options":[{"id":"device_vendor_msft_policy_config_remotedesktopservices_donotallowdriveredirection_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_remotedesktopservices_donotallowdriveredirection_1","displayName":"Enabled","description":null,"helpText":null}]},"e9f8760a808bab37":{"id":"plugin_visiblename","displayName":"Visible Name","description":"The name of the web content filter that the system displays on the device.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"e9a7a35df74962b1":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditoracc","displayName":"Alt+F11 (Database Tools | Macro | Visual Basic) (User)","description":"","helpText":"","infoUrls":[],"categoryId":"55eebd7c-beb9-48b6-907f-df4997e18bdb","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditoracc_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_disableitemsinuserinterface~l_predefined_l_disableshortcutkeys_l_altf11toolsmacrovisualbasiceditoracc_1","displayName":"True","description":null,"helpText":null}]},"e9e06c7d3a033482":{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensavertimeout","displayName":"Screen saver timeout (User)","description":"Specifies how much user idle time must elapse before the screen saver is launched.\r\n\r\nWhen configured, this idle time can be set from a minimum of 1 second to a maximum of 86,400 seconds, or 24 hours. If set to zero, the screen saver will not be started.\r\n\r\nThis setting has no effect under any of the following circumstances:\r\n\r\n - The setting is disabled or not configured.\r\n\r\n - The wait time is set to zero.\r\n\r\n - The \"Enable Screen Saver\" setting is disabled.\r\n\r\n - Neither the \"Screen saver executable name\" setting nor the Screen Saver dialog of the client computer's Personalization or Display Control Panel specifies a valid existing screen saver program on the client.\r\n\r\nWhen not configured, whatever wait time is set on the client through the Screen Saver dialog in the Personalization or Display Control Panel is used. The default is 15 minutes.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-controlpaneldisplay#admx-controlpaneldisplay-cpl-personalization-screensavertimeout"],"categoryId":"6424714c-e50a-4b53-acbf-8739825ebf0b","categoryName":"Personalization","options":[{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensavertimeout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_controlpaneldisplay_cpl_personalization_screensavertimeout_1","displayName":"Enabled","description":null,"helpText":null}]},"e92e4b81c33fd16c":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_video","displayName":"Video (User)","description":"This policy setting configures the synchronization of user settings for the Video app.\r\nBy default, the user settings of Video sync between computers. Use the policy setting to prevent the user settings of Video from synchronizing between computers.\r\nIf you enable this policy setting, Video user settings continue to sync.\r\nIf you disable this policy setting, Video user settings are excluded from synchronization.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-video"],"categoryId":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","categoryName":"Windows Apps","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_video_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_video_1","displayName":"Enabled","description":null,"helpText":null}]},"e98d09b2e42408de":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_tryharderpinnedlibrary_library3","displayName":"Location 4 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"e9e3a4da9c3687b5":{"id":"user_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices","displayName":"Disallow Autoplay for non-volume devices (User)","description":"This policy setting disallows AutoPlay for MTP devices like cameras or phones.\n\n If you enable this policy setting, AutoPlay is not allowed for MTP devices like cameras or phones.\n\n If you disable or do not configure this policy setting, AutoPlay is enabled for non-volume devices.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-autoplay#autoplay-disallowautoplayfornonvolumedevices"],"categoryId":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","categoryName":"Auto Play Policies","options":[{"id":"user_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_autoplay_disallowautoplayfornonvolumedevices_1","displayName":"Enabled","description":null,"helpText":null}]},"e9d06ce9c37e0690":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains","displayName":"Suppress lookalike domain warnings on domains (User)","description":"This policy prevents the display of lookalike URL warnings on the sites listed. These warnings are typically shown on sites that Google Chrome believes might be trying to spoof another site the user is familiar with.\r\n\r\nIf the policy is enabled and set to one or more domains, no lookalike warnings pages will be shown when the user visits pages on that domain.\r\n\r\nIf the policy is not set, or set to an empty list, warnings may appear on any site the user visits.\r\n\r\nA hostname can be allowed with a complete host match, or any domain match. For example, a URL like \"https://foo.example.com/bar\" may have warnings suppressed if this list includes either \"foo.example.com\" or \"example.com\".\r\n\r\nExample value:\r\n\r\nfoo.example.com\r\nexample.org","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_lookalikewarningallowlistdomains_1","displayName":"Enabled","description":null,"helpText":null}]},"e96f399c868357de":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled","displayName":"Enable reporting of usage and crash-related data (User)","description":"When this policy is enabled, anonymous reporting of usage and crash-related data about Chrome to Google is enabled by default. Users will still be able to change this setting in the Chrome settings.\r\n\r\nWhen this policy is disabled, anonymous reporting is disabled and no usage or crash data is sent to Google. Users won't be able to change this setting.\r\n\r\nWhen this policy isn't set, users can choose the anonymous reporting behavior at installation or first run, and can later change the setting in the Chrome settings.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft® Active Directory® domain or Windows 10 Pro or Enterprise instances that are enrolled for device management, and macOS instances that are managed via MDM or joined to a domain via MCX.\r\n\r\n(For Chrome OS, see DeviceMetricsReportingEnabled.)","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_metricsreportingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"e974090aca0ce2c3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings","displayName":"Default search provider encodings (User)","description":"If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\r\n\r\nLeaving DefaultSearchProviderEncodings unset puts UTF-8 in use.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_1","displayName":"Enabled","description":null,"helpText":null}]},"e9f4d686583ec883":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings","displayName":"Change Memory Saver Mode Savings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_0","displayName":"Moderate memory savings.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_1","displayName":"Balanced memory savings.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_memorysavermodesavings_memorysavermodesavings_2","displayName":"Maximum memory savings.","description":null,"helpText":null}]},"e9f24996528decd4":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks","displayName":"Excel 95 workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will not be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel95workbooks_1","displayName":"Enabled","description":null,"helpText":null}]},"e98a052ef96e0b51":{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode","displayName":"Reset zoom to default for HTML dialogs in Internet Explorer mode (User)","description":"This policy setting lets admins reset zoom to default for HTML dialogs in Internet Explorer mode.\n\nIf you enable this policy, the zoom of an HTML dialog in Internet Explorer mode will not get propagated from its parent page.\n\nIf you disable, or don't configure this policy, the zoom of an HTML dialog in Internet Explorer mode will be set based on the zoom of it's parent page.\n\nFor more information, see https://go.microsoft.com/fwlink/?linkid=2220107","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-resetzoomfordialoginiemode"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_resetzoomfordialoginiemode_1","displayName":"Enabled","description":null,"helpText":null}]},"e90742c2d4d037b4":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices","displayName":"Send site information to improve Microsoft services (User)","description":"This policy enables sending info about websites visited in Microsoft Edge to Microsoft to improve services like search.\r\n\r\nEnable this policy to send info about websites visited in Microsoft Edge to Microsoft. Disable this policy to not send info about websites visited in Microsoft Edge to Microsoft. In both cases, users can't change or override the setting.\r\n\r\nOn Windows 10, Beta and Stable if this policy is not configured, Microsoft Edge will default to the Windows diagnostic data setting. If this policy is enabled Microsoft Edge will only send info about websites visited in Microsoft Edge if the Windows Diagnostic data setting is set to Full. If this policy is disabled Microsoft Edge will not send info about websites visited. Learn more about Windows Diagnostic data settings: https://go.microsoft.com/fwlink/?linkid=2099569\r\n\r\nOn Windows 10, Canary and Dev channels, this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.\r\n\r\nOn Windows 7, 8, and Mac this policy controls sending info about websites visited. If this policy is not configured, Microsoft Edge will default to the user’s preference.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendsiteinfotoimproveservices_1","displayName":"Enabled","description":null,"helpText":null}]},"e993b5fccf0fa0a7":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~extensions_extensioninstallallowlist_extensioninstallallowlistdesc","displayName":"Extension IDs to exempt from the block list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"66615d2a-fec9-47f1-8eaf-9813e30cc023","categoryName":"Extensions","options":null},"e96c946c4babb7df":{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended","displayName":"Pin browser essentials toolbar button (User)","description":"This policy lets you configure whether to pin the Browser essentials button on the toolbar.\r\n\r\nWhen the button is pinned, it will always appear on the toolbar.\r\n\r\nWhen the button isn't pinned, it will only appear when there's an alert. An example of this kind of alert is the performance detector alert that indicates the browser is using high CPU or memory.\r\n\r\nIf you enable or don't configure this policy, the Browser essentials button will be pinned on the toolbar.\r\n\r\nIf you disable this policy, the Browser essentials button won't be pinned on the toolbar.\r\n\r\nLearn more about browser essentials: https://go.microsoft.com/fwlink/?linkid=2240439","helpText":"","infoUrls":[],"categoryId":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","categoryName":"Performance","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev116~policy~microsoft_edge_recommended~performance_recommended_pinbrowseressentialstoolbarbutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"e9f27301333a9fdc":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_sensorsallowedforurls_sensorsallowedforurlsdesc","displayName":"Allow access to sensors on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"e960bd3d519e25f2":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_forcesynctypes_forcesynctypesdesc","displayName":"Configure the list of types that are included for synchronization (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"e9c72f2c77e40036":{"id":"user_vendor_msft_policy_config_microsoft_edgev99~policy~microsoft_edge_donotsilentlyblockprotocolsfromorigins_donotsilentlyblockprotocolsfromorigins","displayName":"Define a list of protocols that can not be silently blocked by anti-flood protection (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"e9bbc45a26cd90b0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog","displayName":"Display legacy GAL dialog (User)","description":"This policy setting allows you to specify the way contact information is displayed.\r\n\r\nIf you enable this policy setting the global address list (GAL) dialog is displayed instead of the Contact Card when users double click a contact in Outlook. \r\n\r\nIf you disable or do not configure this policy setting the Contact Card is displayed when users double click a contact in Outlook.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_displaylegacygaldialog_1","displayName":"Enabled","description":null,"helpText":null}]},"e9a7465fa77dcb6a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany","displayName":"Replace MAPI - Company (User)","description":"\r\n\r\nIf you enable this policy setting, you can remove or change the default value \"company\".\r\n\r\nIt is recommended that you specify a MAPI property and a corresponding AD attribute. The MAPI property should always be specified, unless Outlook is not installed, in which case only the AD attribute needs to be specified. It must be entered in decimal format. \r\n\r\nIf you know the MAPIHexadecimalPropertyTag, you should convert this to a decimal value. Any properties entered which are binary or list box, cannot be displayed and thus are ignored.\r\n\r\nFor example, if you want to show the Assistant on the Contact Card, for MAPI, the PR_ASSISTANT hexadecimal property tag is 0x3A30001E. In decimal format, it is 976224286.\r\n\r\nYou would enter: \r\n976224286.\r\n\r\nTo remove the value entirely you would enter null.\r\n\r\nNote that for Location and Calendar values on the default Contact Card, the defaults are not MAPI Properties or AD Attributes.\r\n\r\nRelated policy settings: \r\nReplace AD attribute n, Turn On Contact Tab Calendar Line Move, Turn On Contact Tab Location Line Move.\r\n\r\nIf you disable or do not configure this policy setting, the default value of \"company\" is shown.","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplacecompany_1","displayName":"Enabled","description":null,"helpText":null}]},"e9d3f2f9d418dfac":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_documentinformationpanel_l_trustcentersolution_l_empty421","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0696109e-045f-486a-9a6b-ab7877887bed","categoryName":"Document Information Panel","options":null},"e99686580335e212":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy","displayName":"Disable UI extending from documents and templates (User)","description":"This policy setting controls whether Office 2016 applications load any custom user interface (UI) code included with a document or template. Office 2016 allows developers to extend the UI with customization code that is included in a document or template. \r\n\r\nIf you enable this policy setting, Office 2016 applications cannot load any UI customization code included with documents and templates. \r\n\r\nIf you disable or do not configure this policy setting, Office 2016 applications load any UI customization code included with a document or template when opening it.","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"e9cf9692e8ab1190":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary","displayName":"Set update interval for Outlook Global Address List Dictionary (User)","description":"This policy setting allows you to specify the update interval for the Outlook Global Address List Dictionary. This policy setting applies to Japanese Microsoft IME only.\r\n\r\n\r\nIf you enable this policy setting, you can specify the update interval in minutes. For example, if you specify \"720,\" the Outlook Global Address List Dictionary is updated every 720 minutes.\r\n\r\nIf you do not configure this policy setting, the Outlook Global Address List Dictionary is updated every 1440 minutes (24 hours).","helpText":"","infoUrls":[],"categoryId":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","categoryName":"IME (Japanese)","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_imejapanese_l_setupdateintervalforoutlookglobaladdresslistdictionary_1","displayName":"Enabled","description":null,"helpText":null}]},"e9763ba1de38589e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic","displayName":"Amharic (User)","description":"Enables the editing language Amharic","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_amharic_1","displayName":"Enabled","description":null,"helpText":null}]},"e9b49d070caf3f7e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil","displayName":"Portuguese (Brazil) (User)","description":"Enables the editing language Portuguese (Brazil)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_portuguesebrazil_1","displayName":"Enabled","description":null,"helpText":null}]},"e9286079496b600d":{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions","displayName":"Disable 3D Model File Formats List (User)","description":"This policy setting allows you to specify a list of 3D model file formats that will be blocked from being loaded in Office applications.\r\n\r\nIf you enable this policy setting, you can specify a list of 3D Model file format that Office applications will block on insert or load. You should specify the list of 3D model file formats to block in a list of files extensions. For example, to block the FBX extension, enter the string “FBX”. To block the FBX and OBJ extensions, enter the string “FBX; OBJ”.\r\n\r\nIf you disable or do not configure this policy setting, Office applications do not restrict any 3D model file formats.\r\n","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v7~policy~l_microsoftofficesystem~l_securitysettings_l_model3dblockedextensions_1","displayName":"Enabled","description":null,"helpText":null}]},"e99e7529b1c70ff9":{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics","displayName":"Turn off support diagnostics in OneNote (User)","description":"This policy setting controls whether OneNote sends client information to support services on failure.\r\n\r\nSending client information to support services on failure can help diagnose the issue, provide resolution steps, or show contextual error messaging to the user.\r\n\r\nIf you enable this policy setting, OneNote won’t send client information to support services on failure.\r\n\r\nIf you disable or don’t configure this policy setting, OneNote will send client information to support services on failure.\r\n\r\nNote: This policy setting only applies to Version 2207 and later of OneNote.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v4~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_disablesupportdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},"e96354a24b944c68":{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels","displayName":"Enable OneNote Sensitivity Labels (User)","description":"This policy setting controls whether Purview Sensitivity Label capabilities can be enabled for OneNote Sections.\r\n\r\nIf you enable this policy, users can use supported Purview features, such as manual labeling, label removal, or default labels, to apply sensitivity labels to OneNote sections and help protect sensitive information. At this time, mandatory labels, auto labeling, and dynamic watermarking are not supported.\r\n\r\nIf you disable this policy, users won't be able to apply, change or remove Sensitivity Labels in OneNote Sections.\r\n\r\nIf you do not configure this policy setting, users won't be able to apply, change or remove Sensitivity Labels in OneNote Sections.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v7~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_onenotesensitivitylabels_1","displayName":"Enabled","description":null,"helpText":null}]},"e9dad70d93d99140":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges","displayName":"Mark item as read when selection changes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_readingpane_l_markitemasreadwhenselectionchanges_1","displayName":"True","description":null,"helpText":null}]},"e9ccf839dd9ef6ab":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_freebusyoptions_l_options9_l_monthsoffreebusyinformationpublished","displayName":"Months of Free/Busy information published: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c6b72060-8ecb-41d8-8625-2984dd756d4a","categoryName":"Free/Busy Options","options":null},"e941d7bf6ab48e21":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival","displayName":"Process requests and responses on arrival (User)","description":"","helpText":"","infoUrls":[],"categoryId":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","categoryName":"Tracking Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_trackingoptions_l_options_l_processrequestsandresponsesonarrival_1","displayName":"True","description":null,"helpText":null}]},"e9d9b9eacfa2a97d":{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart","displayName":"Disable the Outlook crash notification when Outlook restarts. (User)","description":"This policy setting determines if the Outlook crash notification on restart is allowed. Enabling this setting will block Outlook crash notification on restart.","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v5~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disablecrashnotificationonrestart_1","displayName":"Enabled","description":null,"helpText":null}]},"e9c8ea21a6448197":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02","displayName":"Trusted Location #2 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc02_1","displayName":"Enabled","description":null,"helpText":null}]},"e98e706ad678f72d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc09_l_datecolon41","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"e94fa2b29908d64a":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_datecolon85","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/f0.json b/public/intune-definitions/f0.json index bee47b1d479e..4cd3a6e84bae 100644 --- a/public/intune-definitions/f0.json +++ b/public/intune-definitions/f0.json @@ -1 +1 @@ -{"f05ad35966dd298c":{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch","displayName":"Interface Type Match","description":"An interface type. If specified, this rule matches only if the primary network interface hardware matches the specified type.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_0","displayName":"Ethernet","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_1","displayName":"WiFi","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_2","displayName":"Cellular","description":null,"helpText":null}]},"f037cb9cad74fbcb":{"id":"com.apple.extensiblesso_registrationtoken","displayName":"Registration Token","description":"The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that 'AuthenticationMethod' isn't empty.\nAvailable in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"f075709802152535":{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\n\nIf you set this policy to disabled the search context menu item that relies on your default search provider and sidebar search will not be available.\n\nIf this policy is set to enabled or not set, the context menu item for your default search provider and sidebar search will be available.\n\nThe policy value is only appled when the \"DefaultSearchProviderEnabled\" policy is enabled, and is not applicable otherwise.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidercontextmenuaccessallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"f0f39ccd731396e0":{"id":"com.apple.managedclient.preferences_defaultsensorssetting","displayName":"Default sensors setting","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\n\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies acess to sensors.\n\nYou can override this policy for specific URL patterns by using the \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\" policies.\n\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This is the global default for \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\".\n\nPolicy options mapping:\n\n* AllowSensors (1) = Allow sites to access sensors\n\n* BlockSensors (2) = Do not allow any site to access sensors\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsensorssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsensorssetting_0","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsensorssetting_1","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},"f085600e91f37c93":{"id":"com.apple.managedclient.preferences_printheaderfooter","displayName":"Print headers and footers","description":"Force 'headers and footers' to be on or off in the printing dialog.\n\nIf you don't configure this policy, users can decide whether to print headers and footers.\n\nIf you disable this policy, users can't print headers and footers.\n\nIf you enable this policy, users always print headers and footers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printheaderfooter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printheaderfooter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printheaderfooter_true","displayName":"Enabled","description":null,"helpText":null}]},"f0b2f82ccb0f8296":{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},"f0e56ba0316822f8":{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"f0027d536ac7db10":{"id":"com.apple.xsan.preferences_denydlc","displayName":"Deny DLC","description":"An array of StorNext volume names. If the Xsan client is attempting to mount a volume named in this array, the client only mounts the volume if its logical units (LUNs) are available through Fibre Channel. It doesn't attempt to mount the volume using Distributed LAN Client (DLC).","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},"f060acda7f6c4796":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled","displayName":"Enable Wallet Checkout feature","description":"Enables Wallet Checkout feature in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.\n\nIf you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f003298057d92b56":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies","displayName":"Allow importing of Cookies","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don't configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\nNote: This policy currently manages Google Chrome import (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_true","displayName":"Enabled","description":null,"helpText":null}]},"f04fdd39cd259b3a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84 (Obsolete)","description":"This policy doesn't work because this policy allowed these features to be selectively re-enabled until Microsoft Edge version 85. The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and are disabled by default starting in Microsoft Edge version 80.\n\nIf you set this policy to True, the Web Components v0 features are enabled for all sites.\n\nIf you set this policy to False or don't set this policy, the Web Components v0 features are disabled by default, starting in Microsoft Edge version 80.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f0ef7f5b633d2340":{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength","displayName":"Configure minimum PIN length for startup","description":"\n This policy setting allows you to configure a minimum length for a Trusted Platform Module (TPM) startup PIN. This policy setting is applied when you turn on BitLocker. The startup PIN must have a minimum length of 4 digits and can have a maximum length of 20 digits.\n\n If you enable this policy setting, you can require a minimum number of digits to be used when setting the startup PIN.\n\n If you disable or do not configure this policy setting, users can configure a startup PIN of any length between 6 and 20 digits.\n\n NOTE: If minimum PIN length is set below 6 digits, Windows will attempt to update the TPM 2.0 lockout period to be greater than the default when a PIN is changed. If successful, Windows will only reset the TPM lockout period back to default if the TPM is reset.\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_1","displayName":"Enabled","description":null,"helpText":null}]},"f0e16ab89d9d2834":{"id":"device_vendor_msft_passportforwork_deviceunlock_groupb","displayName":"Group B","description":"Contains a list of providers by GUID that are to be considered for the second step of authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"f0fcd5ddde577e70":{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager","displayName":"Configure target Subscription Manager","description":"This policy setting allows you to configure the server address, refresh interval, and issuer certificate authority (CA) of a target Subscription Manager.\r\n\r\nIf you enable this policy setting, you can configure the Source Computer to contact a specific FQDN (Fully Qualified Domain Name) or IP Address and request subscription specifics.\r\n\r\nUse the following syntax when using the HTTPS protocol:\r\nServer=https://:5986/wsman/SubscriptionManager/WEC,Refresh=,IssuerCA=. When using the HTTP protocol, use port 5985.\r\n\r\nIf you disable or do not configure this policy setting, the Event Collector computer will not be specified.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventforwarding#admx-eventforwarding-subscriptionmanager"],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":[{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_1","displayName":"Enabled","description":null,"helpText":null}]},"f0ded7a147302065":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr","displayName":"Turn on Responder (RSPNDR) driver","description":"This policy setting changes the operational behavior of the Responder network protocol driver.\r\n\r\nThe Responder allows a computer to participate in Link Layer Topology Discovery requests so that it can be discovered and located on the network. It also allows a computer to participate in Quality-of-Service activities such as bandwidth estimation and network health analysis.\r\n\r\nIf you enable this policy setting, additional options are available to fine-tune your selection. You may choose the \"Allow operation while in domain\" option to allow the Responder to operate on a network interface that's connected to a managed network. On the other hand, if a network interface is connected to an unmanaged network, you may choose the \"Allow operation while in public network\" and \"Prohibit operation while in private network\" options instead.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior for the Responder will apply.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-linklayertopologydiscovery#admx-linklayertopologydiscovery-lltd-enablerspndr"],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_1","displayName":"Enabled","description":null,"helpText":null}]},"f0cff6aa4a8942e9":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage","displayName":"Specify sites covered by the GC Locator DNS SRV Records","description":"This policy setting specifies the sites for which the global catalogs (GC) should register site-specific GC locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the GC resides, and records registered by a GC configured to register GC Locator DNS SRV records for those sites without a GC that are closest to it. \r\n\r\nThe GC Locator DNS records and the site-specific SRV records are dynamically registered by the Net Logon service, and they are used to locate the GC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication. A GC is a domain controller that contains a partial replica of every domain in Active Directory.\r\n\r\nTo specify the sites covered by the GC Locator DNS SRV records, click Enabled, and enter the sites' names in a space-delimited format.\r\n\r\nIf you do not configure this policy setting, it is not applied to any GCs, and GCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-gcsitecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},"f0363fb70d7743ec":{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport","displayName":"Pre-populate printer search location text","description":"Enables the physical Location Tracking setting for Windows printers.\r\n\r\nUse Location Tracking to design a location scheme for your enterprise and assign computers and printers to locations in the scheme. Location Tracking overrides the standard method used to locate and associate computers and printers. The standard method uses a printer's IP address and subnet mask to estimate its physical location and proximity to computers.\r\n\r\nIf you enable this setting, users can browse for printers by location without knowing the printer's location or location naming scheme. Enabling Location Tracking adds a Browse button in the Add Printer wizard's Printer Name and Sharing Location screen and to the General tab in the Printer Properties dialog box. If you enable the Group Policy Computer location setting, the default location you entered appears in the Location field by default.\r\n\r\nIf you disable this setting or do not configure it, Location Tracking is disabled. Printer proximity is estimated using the standard method (that is, based on IP address and subnet mask).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-physicallocationsupport"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport_1","displayName":"Enabled","description":null,"helpText":null}]},"f08b8c8a7b93d9fd":{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels","displayName":"Root certificate clean up options","description":null,"helpText":"","infoUrls":[],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_0","displayName":"No cleanup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_1","displayName":"Clean up certificates on smart card removal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_2","displayName":"Clean up certificates on log off","description":null,"helpText":null}]},"f0a7d96acc83c496":{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled","displayName":"Pin Apps to Start when installed","description":"This policy setting allows pinning apps to Start by default, when they are included by AppID on the list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-startpinappswheninstalled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_1","displayName":"Enabled","description":null,"helpText":null}]},"f0a662af6d82f277":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state","displayName":"Set Teredo State","description":"This policy setting allows you to configure Teredo, an address assignment and automatic tunneling technology that provides unicast IPv6 connectivity across the IPv4 Internet.\r\n\r\nIf you disable or do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, you can configure Teredo with one of the following settings:\r\n\r\nDefault: The default state is \"Client.\"\r\n\r\nDisabled: No Teredo interfaces are present on the host.\r\n\r\nClient: The Teredo interface is present only when the host is not on a network that includes a domain controller.\r\n\r\nEnterprise Client: The Teredo interface is always present, even if the host is on a network that includes a domain controller.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_1","displayName":"Enabled","description":null,"helpText":null}]},"f051ad86284041e1":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_browserthemecolor","displayName":"Configure the color of the browser's theme (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"f05903764eff58ce":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations","displayName":"Determine the availability of variations (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_0","displayName":"Enable all variations","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_1","displayName":"Enable variations concerning critical fixes only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_2","displayName":"Disable all variations","description":null,"helpText":null}]},"f09ff096ff715768":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps when Google Chrome is closed","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"f05a8035327daea3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled","displayName":"Default legacy SameSite cookie behavior setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_1","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_2","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},"f0b6f2b520ffe038":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed","displayName":"Allow sites to simultaneously navigate and open pop-ups","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"f0da4bb09fca6cbd":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_0","displayName":"Show expanded enterprise toolbar badge","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_1","displayName":"Hide expanded enterprise toolbar badge","description":null,"helpText":null}]},"f06d3e224383e32f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled","displayName":"Re-enable deprecated/removed Mutation Events","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f07f3a6f27b7883f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled","displayName":"Enable zstd content-encoding support","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f0bcb07b61ad86ef":{"id":"device_vendor_msft_policy_config_fileexplorer_disablegraphrecentitems","displayName":"Disable Graph Recent Items","description":"Turning off this setting will prevent File Explorer from displaying files based on account and cloud provider activity.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#disablegraphrecentitems"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"device_vendor_msft_policy_config_fileexplorer_disablegraphrecentitems_0","displayName":"File Explorer will request cloud file metadata and display it in the Quick access view.","description":"File Explorer will request cloud file metadata and display it in the Quick access view.","helpText":null},{"id":"device_vendor_msft_policy_config_fileexplorer_disablegraphrecentitems_1","displayName":"File Explorer will not request cloud file metadata or display it in the Quick access view.","description":"File Explorer will not request cloud file metadata or display it in the Quick access view.","helpText":null}]},"f0fe273e07219755":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"f09fedea1a573b8b":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled","displayName":"Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 114.\r\n\r\nWhen this policy is set to enabled, Microsoft Edge will perform verification of server certificates using the built-in certificate verifier with the Microsoft Root Store as the source of public trust.\r\n\r\nWhen this policy is set to disabled, Microsoft Edge will use the system certificate verifier and system root certificates.\r\n\r\nWhen this policy is not set, the Microsoft Root Store or system provided roots may be used.\r\n\r\nThis policy is planned to be removed in Microsoft Edge version\r\n121 for Android devices when support for using the platform supplied roots is planned to be removed.\r\n\r\nThis policy was removed in Microsoft Edge version 115 for\r\nMicrosoft Windows and macOS,\r\nMicrosoft Edge version 120 for\r\nLinux, and\r\nMicrosoft Edge version 121 for\r\nAndroid\r\nwhen support for using the platform supplied certificate verifier and roots was removed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f0662c4edeb65790":{"id":"device_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\r\n\r\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\r\n\r\nDisabling this setting is the same as leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nPolicy options mapping:\r\n\r\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\r\n\r\n* RestoreOnStartupIsLastSession (1) = Restore the last session\r\n\r\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\r\n\r\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},"f057293adc5da4c2":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed","description":"This setting lets you specify a custom refresh interval for the Enterprise Mode Site List. The refresh interval is specified in minutes. The minimum refresh interval is 30 minutes.\r\n\r\nThis setting is applicable only when the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) or 'InternetExplorerIntegrationCloudSiteList' (Configure the Enterprise Mode Cloud Site List) setting is configured.\r\n\r\nIf you configure this policy, Microsoft Edge will attempt to retrieve an updated version of the configured Enterprise Mode Site List using the specified refresh interval.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use a default refresh interval, it is 10080 minutes (7 days) starting from version 110 or later, 120 minutes from version 93 to 110, and 30 minutes before version 93.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"f07a8d27f9dfc45b":{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_enhancesecuritymodebypasslistdomainsdesc","displayName":"Configure the list of domains for which enhance security mode will not be enforced (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"f00b68c33b760502":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_grooveexe98","displayName":"groove.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_grooveexe98_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_grooveexe98_1","displayName":"True","description":null,"helpText":null}]},"f0f09cc17087ff0b":{"id":"device_vendor_msft_policy_config_printers_managedriverexclusionlist_driver_exclusionlistentry","displayName":"File Hash File Name:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"f0f6e41dba5d12ee":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscontacts","displayName":"Let Apps Access Contacts","description":"This policy setting specifies whether Windows apps can access contacts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscontacts"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscontacts_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscontacts_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscontacts_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"f0511075dd2b6536":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessmicrophone","displayName":"Let Apps Access Microphone","description":"This policy setting specifies whether Windows apps can access the microphone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessmicrophone"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccessmicrophone_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccessmicrophone_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccessmicrophone_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"f03058639917c611":{"id":"device_vendor_msft_policy_config_settingssync_enablewindowsbackup","displayName":"Enable Windows Backup","description":"This policy setting allows administrators to configure and manage windows backup for their organization.\n\nIf you enable this policy setting, windows backup will occur periodically.\n\nIf you disable or do not configure this policy setting, windows backup will not take place.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-settingssync#settingssync-enablewindowsbackup"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_settingssync_enablewindowsbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_settingssync_enablewindowsbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"f03d7e6d7085f91e":{"id":"device_vendor_msft_policy_config_taskmanager_allowendtask","displayName":"Allow End Task","description":"This setting determines whether non-administrators can use Task Manager to end tasks - enabled (1) or disabled (0). Default: enabled","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TaskManager#allowendtask"],"categoryId":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","categoryName":"Task Manager","options":[{"id":"device_vendor_msft_policy_config_taskmanager_allowendtask_0","displayName":"Block","description":"Disabled. EndTask functionality is blocked in TaskManager.","helpText":null},{"id":"device_vendor_msft_policy_config_taskmanager_allowendtask_1","displayName":"Allow","description":"Enabled. Users can perform EndTask in TaskManager.","helpText":null}]},"f07de5894424ea77":{"id":"linux_platformupdatecontrols_schedule_daysofmonth","displayName":"Platform Update Schedule Day of Month","description":"Specifies on which day of the month platform updates are allowed. Select 'Every Day' for no restriction, or choose a specific day (1-31).","helpText":null,"infoUrls":["https://learn.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#platform-update-preferences"],"categoryId":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","categoryName":"Platform Update","options":[{"id":"linux_platformupdatecontrols_schedule_daysofmonth_1","displayName":"1","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_2","displayName":"2","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_3","displayName":"3","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_4","displayName":"4","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_5","displayName":"5","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_6","displayName":"6","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_7","displayName":"7","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_8","displayName":"8","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_9","displayName":"9","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_10","displayName":"10","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_11","displayName":"11","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_12","displayName":"12","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_13","displayName":"13","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_14","displayName":"14","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_15","displayName":"15","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_16","displayName":"16","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_17","displayName":"17","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_18","displayName":"18","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_19","displayName":"19","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_20","displayName":"20","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_21","displayName":"21","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_22","displayName":"22","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_23","displayName":"23","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_24","displayName":"24","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_25","displayName":"25","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_26","displayName":"26","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_27","displayName":"27","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_28","displayName":"28","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_29","displayName":"29","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_30","displayName":"30","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_31","displayName":"31","description":null,"helpText":null}]},"f0dd645bfe09095a":{"id":"loginwindow_loginwindow","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"0e937777-d01a-4180-a937-c2010451a529","categoryName":"Login Window Login Items","options":null},"f0300d35e54cb66d":{"id":"user_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_1","displayName":"Do not allow Digital Locker to run (User)","description":"Specifies whether Digital Locker can run.\r\n\r\nDigital Locker is a dedicated download manager associated with Windows Marketplace and a feature of Windows that can be used to manage and download products acquired and stored in the user's Windows Marketplace Digital Locker.\r\n\r\nIf you enable this setting, Digital Locker will not run.\r\n\r\nIf you disable or do not configure this setting, Digital Locker can be run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-digitallocker#admx-digitallocker-digitalx-diableapplication-titletext-1"],"categoryId":"1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","categoryName":"Digital Locker","options":[{"id":"user_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_1_1","displayName":"Enabled","description":null,"helpText":null}]},"f0d422264fb4fed2":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ris","displayName":"Remote Installation Services (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-ris"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ris_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ris_1","displayName":"Enabled","description":null,"helpText":null}]},"f0a04bca0247d03e":{"id":"user_vendor_msft_policy_config_admx_startmenu_nohelp","displayName":"Remove Help menu from Start Menu (User)","description":"This policy setting allows you to remove the Help command from the Start menu.\r\n\r\nIf you enable this policy setting, the Help command is removed from the Start menu.\r\n\r\nIf you disable or do not configure this policy setting, the Help command is available from the Start menu.\r\n\r\nThis policy setting only affects the Start menu. It does not remove the Help menu from File Explorer and does not prevent users from running Help.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nohelp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nohelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nohelp_1","displayName":"Enabled","description":null,"helpText":null}]},"f078bc96acae8d25":{"id":"user_vendor_msft_policy_config_admx_userprofiles_limitsize_warnuser","displayName":"Notify user when profile storage space is exceeded. (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"user_vendor_msft_policy_config_admx_userprofiles_limitsize_warnuser_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userprofiles_limitsize_warnuser_1","displayName":"True","description":null,"helpText":null}]},"f073682dc223b804":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nowindowshotkeys","displayName":"Turn off Windows Key hotkeys (User)","description":"Turn off Windows Key hotkeys.\r\n\r\nKeyboards with a Windows key provide users with shortcuts to common shell features. For example, pressing the keyboard sequence Windows+R opens the Run dialog box; pressing Windows+E starts File Explorer. By using this setting, you can disable these Windows Key hotkeys.\r\n\r\nIf you enable this setting, the Windows Key hotkeys are unavailable.\r\n\r\nIf you disable or do not configure this setting, the Windows Key hotkeys are available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nowindowshotkeys"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nowindowshotkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nowindowshotkeys_1","displayName":"Enabled","description":null,"helpText":null}]},"f09f94e5bba60d99":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_explicitlyallowednetworkportsdesc","displayName":"Explicitly allowed network ports (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"f04118613c0b7b59":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps (User)","description":"Setting the policy specifies a list of web apps that install silently, without user interaction, and which users can't uninstall or turn off.\r\n\r\nEach list item of the policy is an object with a mandatory member:\r\nurl (the URL of the web app to install)\r\n\r\nand 5 optional members:\r\n- default_launch_container\r\n(for how the web app opens—a new tab is the default)\r\n\r\n- create_desktop_shortcut\r\n(True if you want to create Linux and\r\nMicrosoft® Windows® desktop shortcuts).\r\n\r\n- fallback_app_name\r\n(Starting with Google Chrome version 90,\r\nallows you to override the app name if it is not a\r\nProgressive Web App (PWA), or the app name that is temporarily\r\ninstalled if it is a PWA but authentication is required before the\r\ninstallation can be completed. If both\r\ncustom_name and\r\nfallback_app_name are provided,\r\nthe latter will be ignored.)\r\n\r\n- custom_name\r\n(Starting with Google Chrome\r\nversion 96, allows you to permanently override the app name for all web\r\napps and PWAs. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\n- custom_icon\r\n(Starting with Google Chrome\r\nversion 96, allows you to override the app icon of installed apps. The\r\nicons have to be square, maximal 1 MB in size, and in one of the following\r\nformats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256\r\nhash of the icon file. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\nSee PinnedLauncherApps for pinning apps to the Google Chrome OS shelf.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebAppInstallForceList for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.google.com/maps\",\r\n \"default_launch_container\": \"window\",\r\n \"create_desktop_shortcut\": true\r\n },\r\n {\r\n \"url\": \"https://docs.google.com\",\r\n \"default_launch_container\": \"tab\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/editor\",\r\n \"default_launch_container\": \"window\",\r\n \"fallback_app_name\": \"Editor\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/sheets\",\r\n \"default_launch_container\": \"window\",\r\n \"custom_name\": \"Spreadsheets\"\r\n },\r\n {\r\n \"url\": \"https://weather.example.com\",\r\n \"custom_icon\": {\r\n \"url\": \"https://mydomain.example.com/sunny_icon.png\",\r\n \"hash\": \"c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38\"\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"f066a88ed01bd261":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_corsmitigationlistdesc","displayName":"Enable CORS check mitigations in the new CORS implementation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"f064be62677023d3":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_notificationsblockedforurlsdesc","displayName":"Block notifications on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"f0a4ecdae65339ef":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled","displayName":"Enable Grammar Tools feature within Immersive Reader in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125.\r\n\r\nThis policy is obsoleted because Grammar Tools is deprecated from Edge. This policy won't work in Microsoft Edge version 126. Enables the Grammar Tools feature within Immersive Reader in Microsoft Edge.\r\nThis helps improve reading comprehension by splitting words into syllables and highlighting nouns, verbs, adverbs, and adjectives.\r\n\r\nIf you enable this policy or don't configure it, the Grammar Tools option shows up within Immersive Reader.\r\nIf you disable this policy, users can't access the Grammar Tools feature within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f0132df0f740bc56":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_typosquattingallowlistdomainsdesc","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":null},"f00f916cffad0823":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites (User)","description":"Configure the list of URL patterns that are excluded from tracking prevention.\r\n\r\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\r\n\r\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"f0a2b1d411776b78":{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts (User)","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf this policy is not set, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the 'InsecurePrivateNetworkRequestsAllowed' (Specifies whether to allow insecure websites to make requests to more-private network endpoints) policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://docs.microsoft.com/en-us/DeployEdge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"f0ebe0952e8047ff":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq","displayName":"Arabic (Iraq) (User)","description":"Enables the editing language Arabic (Iraq)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq_1","displayName":"Enabled","description":null,"helpText":null}]},"f059a197c303c550":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese","displayName":"Burmese (User)","description":"Enables the editing language Burmese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese_1","displayName":"Enabled","description":null,"helpText":null}]},"f02f16a8ab9eeea8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowpath484","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"f0d122d00b1973e9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_datecolon295","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"f06fcf8e4372c62f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink","displayName":"Do not show \"Manage Account\" link for subscription licenses. (User)","description":"This policy setting controls whether a \"Manage Account\" link is exposed in Account tab of the File menu for subscription licenses.\r\n\r\nIf you enable this policy setting, Office does not expose a \"Manage Account\" link for subscription licenses.\r\n\r\nIf you disable or do not configure this policy setting, Office exposes a \"Manage Account\" link for subscription licenses.","helpText":"","infoUrls":[],"categoryId":"760376f3-6b74-4992-89eb-aa41d6190e94","categoryName":"Subscription Activation","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink_1","displayName":"Enabled","description":null,"helpText":null}]},"f0703d95ab59b6db":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin_l_daysbacktokeepitemsinrecyclebinspinid","displayName":"Days back to keep items in recycle bin (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},"f09bafda9bc7468f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions","displayName":"Layout Options (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b9ab4d39-9e28-4897-aa34-0201a35ea989","categoryName":"Right-to-left","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"f0f96f04eba9743b":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols","displayName":"Add slide navigation controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols_1","displayName":"True","description":null,"helpText":null}]},"f00ae5c0cf85d28f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},"f040f4f330032316":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},"f01df096f87a0aaa":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},"f0408c2c3b4dea69":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes","displayName":"My Shapes (User)","description":"Displays the path of the My Shapes folder.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_1","displayName":"Enabled","description":null,"helpText":null}]},"f0163956d854f849":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"f06063a5314702c0":{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}","displayName":" Connection Profile ID (Windows Insiders only)","description":"Unique identifier of a network preference policy. Unique ID is auto-generated.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null}} \ No newline at end of file +{"f05ad35966dd298c":{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch","displayName":"Interface Type Match","description":"An interface type. If specified, this rule matches only if the primary network interface hardware matches the specified type.","helpText":null,"infoUrls":[],"categoryId":"bbe51018-a17d-46c4-9517-ff45c54d8d18","categoryName":"DNS Settings","options":[{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_0","displayName":"Ethernet","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_1","displayName":"WiFi","description":null,"helpText":null},{"id":"com.apple.dnssettings.managed_ondemandrules_item_interfacetypematch_2","displayName":"Cellular","description":null,"helpText":null}]},"f037cb9cad74fbcb":{"id":"com.apple.extensiblesso_registrationtoken","displayName":"Registration Token","description":"The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that 'AuthenticationMethod' isn't empty.\nAvailable in macOS 13 and later.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"f075709802152535":{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed","displayName":"Allow default search provider context menu search access","description":"Enables the use of a default search provider on the context menu.\n\nIf you set this policy to disabled the search context menu item that relies on your default search provider and sidebar search will not be available.\n\nIf this policy is set to enabled or not set, the context menu item for your default search provider and sidebar search will be available.\n\nThe policy value is only appled when the \"DefaultSearchProviderEnabled\" policy is enabled, and is not applicable otherwise.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsearchprovidercontextmenuaccessallowed"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsearchprovidercontextmenuaccessallowed_true","displayName":"Allowed","description":null,"helpText":null}]},"f0f39ccd731396e0":{"id":"com.apple.managedclient.preferences_defaultsensorssetting","displayName":"Default sensors setting","description":"Set whether websites can access and use sensors such as motion and light sensors. You can completely block or allow websites to get access to sensors.\n\nSetting the policy to 1 lets websites access and use sensors. Setting the policy to 2 denies acess to sensors.\n\nYou can override this policy for specific URL patterns by using the \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\" policies.\n\nIf you don't configure this policy, websites can access and use sensors, and users can change this setting. This is the global default for \"SensorsAllowedForUrls\" and \"SensorsBlockedForUrls\".\n\nPolicy options mapping:\n\n* AllowSensors (1) = Allow sites to access sensors\n\n* BlockSensors (2) = Do not allow any site to access sensors\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultsensorssetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultsensorssetting_0","displayName":"Allow sites to access sensors","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultsensorssetting_1","displayName":"Do not allow any site to access sensors","description":null,"helpText":null}]},"f085600e91f37c93":{"id":"com.apple.managedclient.preferences_printheaderfooter","displayName":"Print headers and footers","description":"Force 'headers and footers' to be on or off in the printing dialog.\n\nIf you don't configure this policy, users can decide whether to print headers and footers.\n\nIf you disable this policy, users can't print headers and footers.\n\nIf you enable this policy, users always print headers and footers.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printheaderfooter"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_printheaderfooter_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_printheaderfooter_true","displayName":"Enabled","description":null,"helpText":null}]},"f0b2f82ccb0f8296":{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed","displayName":"Reduce Processor Speed","description":"May not be available on all systems.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":[{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_reduce processor speed_1","displayName":"True","description":null,"helpText":null}]},"f0e56ba0316822f8":{"id":"com.apple.mcx_com.apple.energysaver.portable.batterypower_system sleep timer","displayName":"System Sleep Timer","description":"System sleep time, in minutes. A value of 0 means never.","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"f0027d536ac7db10":{"id":"com.apple.xsan.preferences_denydlc","displayName":"Deny DLC","description":"An array of StorNext volume names. If the Xsan client is attempting to mount a volume named in this array, the client only mounts the volume if its logical units (LUNs) are available through Fibre Channel. It doesn't attempt to mount the volume using Distributed LAN Client (DLC).","helpText":null,"infoUrls":[],"categoryId":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","categoryName":"Xsan Preferences","options":null},"f060acda7f6c4796":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled","displayName":"Enable Wallet Checkout feature","description":"Enables Wallet Checkout feature in Microsoft Edge.\n\nIf you enable or don't configure this policy, users can choose whether to use wallet checkout while shopping on Microsoft Edge.\n\nIf you disable this policy, users can't use wallet checkout while shopping on Microsoft Edge.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgewalletcheckoutenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f003298057d92b56":{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies","displayName":"Allow importing of Cookies","description":"Allows users to import Cookies from another browser into Microsoft Edge.\n\nIf you disable this policy, Cookies aren't imported on first run.\n\nIf you don't configure this policy, Cookies are imported on first run.\n\nYou can also set this policy as a recommendation. This means that Microsoft Edge imports Cookies on first run.\n\nNote: This policy currently manages Google Chrome import (on Windows 7, 8, and 10 and on macOS).","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.importcookies_true","displayName":"Enabled","description":null,"helpText":null}]},"f04fdd39cd259b3a":{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled","displayName":"Re-enable Web Components v0 API until M84 (Obsolete)","description":"This policy doesn't work because this policy allowed these features to be selectively re-enabled until Microsoft Edge version 85. The Web Components v0 APIs (Shadow DOM v0, Custom Elements v0, and HTML Imports) were deprecated in 2018, and are disabled by default starting in Microsoft Edge version 80.\n\nIf you set this policy to True, the Web Components v0 features are enabled for all sites.\n\nIf you set this policy to False or don't set this policy, the Web Components v0 features are disabled by default, starting in Microsoft Edge version 80.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.webcomponentsv0enabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f09ac6d367bac626":{"id":"contentcaching_displayalerts","displayName":"Display Alerts","description":"If `true`, Content Caching displays exceptional conditions (alerts) as system notifications in the upper corner of the screen.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_displayalerts_false","displayName":"Disabled","description":null,"helpText":null},{"id":"contentcaching_displayalerts_true","displayName":"Enabled","description":null,"helpText":null}]},"f0ef7f5b633d2340":{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength","displayName":"Configure minimum PIN length for startup","description":"\n This policy setting allows you to configure a minimum length for a Trusted Platform Module (TPM) startup PIN. This policy setting is applied when you turn on BitLocker. The startup PIN must have a minimum length of 4 digits and can have a maximum length of 20 digits.\n\n If you enable this policy setting, you can require a minimum number of digits to be used when setting the startup PIN.\n\n If you disable or do not configure this policy setting, users can configure a startup PIN of any length between 6 and 20 digits.\n\n NOTE: If minimum PIN length is set below 6 digits, Windows will attempt to update the TPM 2.0 lockout period to be greater than the default when a PIN is changed. If successful, Windows will only reset the TPM lockout period back to default if the TPM is reset.\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesminimumpinlength_1","displayName":"Enabled","description":null,"helpText":null}]},"f06054883e4f76e2":{"id":"device_vendor_msft_maintenancewindows_starttime","displayName":"Start time","description":"Specify the start time for the maintenance window in HH:MM format (24-hour clock).","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":null},"f0e16ab89d9d2834":{"id":"device_vendor_msft_passportforwork_deviceunlock_groupb","displayName":"Group B","description":"Contains a list of providers by GUID that are to be considered for the second step of authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"f0fcd5ddde577e70":{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager","displayName":"Configure target Subscription Manager","description":"This policy setting allows you to configure the server address, refresh interval, and issuer certificate authority (CA) of a target Subscription Manager.\r\n\r\nIf you enable this policy setting, you can configure the Source Computer to contact a specific FQDN (Fully Qualified Domain Name) or IP Address and request subscription specifics.\r\n\r\nUse the following syntax when using the HTTPS protocol:\r\nServer=https://:5986/wsman/SubscriptionManager/WEC,Refresh=,IssuerCA=. When using the HTTP protocol, use port 5985.\r\n\r\nIf you disable or do not configure this policy setting, the Event Collector computer will not be specified.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventforwarding#admx-eventforwarding-subscriptionmanager"],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":[{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_1","displayName":"Enabled","description":null,"helpText":null}]},"f0ded7a147302065":{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr","displayName":"Turn on Responder (RSPNDR) driver","description":"This policy setting changes the operational behavior of the Responder network protocol driver.\r\n\r\nThe Responder allows a computer to participate in Link Layer Topology Discovery requests so that it can be discovered and located on the network. It also allows a computer to participate in Quality-of-Service activities such as bandwidth estimation and network health analysis.\r\n\r\nIf you enable this policy setting, additional options are available to fine-tune your selection. You may choose the \"Allow operation while in domain\" option to allow the Responder to operate on a network interface that's connected to a managed network. On the other hand, if a network interface is connected to an unmanaged network, you may choose the \"Allow operation while in public network\" and \"Prohibit operation while in private network\" options instead.\r\n\r\nIf you disable or do not configure this policy setting, the default behavior for the Responder will apply.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-linklayertopologydiscovery#admx-linklayertopologydiscovery-lltd-enablerspndr"],"categoryId":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","categoryName":"Link- Layer Topology Discovery","options":[{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_linklayertopologydiscovery_lltd_enablerspndr_1","displayName":"Enabled","description":null,"helpText":null}]},"f0cff6aa4a8942e9":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage","displayName":"Specify sites covered by the GC Locator DNS SRV Records","description":"This policy setting specifies the sites for which the global catalogs (GC) should register site-specific GC locator DNS SRV resource records. These records are registered in addition to the site-specific SRV records registered for the site where the GC resides, and records registered by a GC configured to register GC Locator DNS SRV records for those sites without a GC that are closest to it. \r\n\r\nThe GC Locator DNS records and the site-specific SRV records are dynamically registered by the Net Logon service, and they are used to locate the GC. An Active Directory site is one or more well-connected TCP/IP subnets that allow administrators to configure Active Directory access and replication. A GC is a domain controller that contains a partial replica of every domain in Active Directory.\r\n\r\nTo specify the sites covered by the GC Locator DNS SRV records, click Enabled, and enter the sites' names in a space-delimited format.\r\n\r\nIf you do not configure this policy setting, it is not applied to any GCs, and GCs use their local configuration.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-gcsitecoverage"],"categoryId":"41ba590e-9105-4eda-92fb-13c7d34b8eee","categoryName":"DC Locator DNS Records","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_gcsitecoverage_1","displayName":"Enabled","description":null,"helpText":null}]},"f0363fb70d7743ec":{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport","displayName":"Pre-populate printer search location text","description":"Enables the physical Location Tracking setting for Windows printers.\r\n\r\nUse Location Tracking to design a location scheme for your enterprise and assign computers and printers to locations in the scheme. Location Tracking overrides the standard method used to locate and associate computers and printers. The standard method uses a printer's IP address and subnet mask to estimate its physical location and proximity to computers.\r\n\r\nIf you enable this setting, users can browse for printers by location without knowing the printer's location or location naming scheme. Enabling Location Tracking adds a Browse button in the Add Printer wizard's Printer Name and Sharing Location screen and to the General tab in the Printer Properties dialog box. If you enable the Group Policy Computer location setting, the default location you entered appears in the Location field by default.\r\n\r\nIf you disable this setting or do not configure it, Location Tracking is disabled. Printer proximity is estimated using the standard method (that is, based on IP address and subnet mask).\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-physicallocationsupport"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_physicallocationsupport_1","displayName":"Enabled","description":null,"helpText":null}]},"f08b8c8a7b93d9fd":{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels","displayName":"Root certificate clean up options","description":null,"helpText":"","infoUrls":[],"categoryId":"a34ade49-964d-407c-9f60-2e8cd9dfef05","categoryName":"Smart Card","options":[{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_0","displayName":"No cleanup","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_1","displayName":"Clean up certificates on smart card removal","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_smartcard_certproprootcleanupstring_rootcertcleanupoption_levels_2","displayName":"Clean up certificates on log off","description":null,"helpText":null}]},"f0a7d96acc83c496":{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled","displayName":"Pin Apps to Start when installed","description":"This policy setting allows pinning apps to Start by default, when they are included by AppID on the list.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-startpinappswheninstalled"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_startmenu_startpinappswheninstalled_1","displayName":"Enabled","description":null,"helpText":null}]},"f0a662af6d82f277":{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state","displayName":"Set Teredo State","description":"This policy setting allows you to configure Teredo, an address assignment and automatic tunneling technology that provides unicast IPv6 connectivity across the IPv4 Internet.\r\n\r\nIf you disable or do not configure this policy setting, the local host settings are used.\r\n\r\nIf you enable this policy setting, you can configure Teredo with one of the following settings:\r\n\r\nDefault: The default state is \"Client.\"\r\n\r\nDisabled: No Teredo interfaces are present on the host.\r\n\r\nClient: The Teredo interface is present only when the host is not on a network that includes a domain controller.\r\n\r\nEnterprise Client: The Teredo interface is always present, even if the host is on a network that includes a domain controller.\r\n\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tcpip#admx-tcpip-teredo-state"],"categoryId":"486f25cc-c865-446e-95b2-c5b061883a7a","categoryName":"I Pv6 Transition Technologies","options":[{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tcpip_teredo_state_1","displayName":"Enabled","description":null,"helpText":null}]},"f051ad86284041e1":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browserthemecolor_browserthemecolor","displayName":"Configure the color of the browser's theme (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"f05903764eff58ce":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations","displayName":"Determine the availability of variations (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_0","displayName":"Enable all variations","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_1","displayName":"Enable variations concerning critical fixes only","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_chromevariations_chromevariations_2","displayName":"Disable all variations","description":null,"helpText":null}]},"f09ff096ff715768":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps when Google Chrome is closed","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"f05a8035327daea3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled","displayName":"Default legacy SameSite cookie behavior setting (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_1","displayName":"Revert to legacy SameSite behavior for cookies on all sites","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_legacysamesitecookiebehaviorenabled_legacysamesitecookiebehaviorenabled_2","displayName":"Use SameSite-by-default behavior for cookies on all sites","description":null,"helpText":null}]},"f0b6f2b520ffe038":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed","displayName":"Allow sites to simultaneously navigate and open pop-ups","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_tabunderallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"f0da4bb09fca6cbd":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings","displayName":"Controls visibility of enterprise profile badge in the toolbar (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_0","displayName":"Show expanded enterprise toolbar badge","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_enterpriseprofilebadgetoolbarsettings_enterpriseprofilebadgetoolbarsettings_1","displayName":"Hide expanded enterprise toolbar badge","description":null,"helpText":null}]},"f06d3e224383e32f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled","displayName":"Re-enable deprecated/removed Mutation Events","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f07f3a6f27b7883f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled","displayName":"Enable zstd content-encoding support","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f0bcb07b61ad86ef":{"id":"device_vendor_msft_policy_config_fileexplorer_disablegraphrecentitems","displayName":"Disable Graph Recent Items","description":"Turning off this setting will prevent File Explorer from displaying files based on account and cloud provider activity.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#disablegraphrecentitems"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"device_vendor_msft_policy_config_fileexplorer_disablegraphrecentitems_0","displayName":"File Explorer will request cloud file metadata and display it in the Quick access view.","description":"File Explorer will request cloud file metadata and display it in the Quick access view.","helpText":null},{"id":"device_vendor_msft_policy_config_fileexplorer_disablegraphrecentitems_1","displayName":"File Explorer will not request cloud file metadata or display it in the Quick access view.","description":"File Explorer will not request cloud file metadata or display it in the Quick access view.","helpText":null}]},"f0fe273e07219755":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604","displayName":"Allow font downloads","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowfontdownloads_iz_partname1604_1","displayName":"Prompt","description":null,"helpText":null}]},"f09fedea1a573b8b":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled","displayName":"Determines whether the Microsoft Root Store and built-in certificate verifier will be used to verify server certificates (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 114.\r\n\r\nWhen this policy is set to enabled, Microsoft Edge will perform verification of server certificates using the built-in certificate verifier with the Microsoft Root Store as the source of public trust.\r\n\r\nWhen this policy is set to disabled, Microsoft Edge will use the system certificate verifier and system root certificates.\r\n\r\nWhen this policy is not set, the Microsoft Root Store or system provided roots may be used.\r\n\r\nThis policy is planned to be removed in Microsoft Edge version\r\n121 for Android devices when support for using the platform supplied roots is planned to be removed.\r\n\r\nThis policy was removed in Microsoft Edge version 115 for\r\nMicrosoft Windows and macOS,\r\nMicrosoft Edge version 120 for\r\nLinux, and\r\nMicrosoft Edge version 121 for\r\nAndroid\r\nwhen support for using the platform supplied certificate verifier and roots was removed.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge_microsoftrootstoreenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f0662c4edeb65790":{"id":"device_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'RestoreOnStartupIsNewTabPage'.\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'RestoreOnStartupIsLastSession'. The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'RestoreOnStartupIsURLs'.\r\n\r\nStarting in Microsoft Edge version 125, if you want to reopen URLs that were open the last time Microsoft Edge closed and open a specific set of URLs, choose 'RestoreOnStartupIsLastSessionAndURLs'.\r\n\r\nDisabling this setting is the same as leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is only available on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is only available on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nPolicy options mapping:\r\n\r\n* RestoreOnStartupIsNewTabPage (5) = Open a new tab\r\n\r\n* RestoreOnStartupIsLastSession (1) = Restore the last session\r\n\r\n* RestoreOnStartupIsURLs (4) = Open a list of URLs\r\n\r\n* RestoreOnStartupIsLastSessionAndURLs (6) = Open a list of URLs and restore the last session\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev77.3~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},"f057293adc5da4c2":{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval","displayName":"Configure how frequently the Enterprise Mode Site List is refreshed","description":"This setting lets you specify a custom refresh interval for the Enterprise Mode Site List. The refresh interval is specified in minutes. The minimum refresh interval is 30 minutes.\r\n\r\nThis setting is applicable only when the 'InternetExplorerIntegrationSiteList' (Configure the Enterprise Mode Site List) or 'InternetExplorerIntegrationCloudSiteList' (Configure the Enterprise Mode Cloud Site List) setting is configured.\r\n\r\nIf you configure this policy, Microsoft Edge will attempt to retrieve an updated version of the configured Enterprise Mode Site List using the specified refresh interval.\r\n\r\nIf you disable or don't configure this policy, Microsoft Edge will use a default refresh interval, it is 10080 minutes (7 days) starting from version 110 or later, 120 minutes from version 93 to 110, and 30 minutes before version 93.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_internetexplorerintegrationsitelistrefreshinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"f07a8d27f9dfc45b":{"id":"device_vendor_msft_policy_config_microsoft_edgev98~policy~microsoft_edge_enhancesecuritymodebypasslistdomains_enhancesecuritymodebypasslistdomainsdesc","displayName":"Configure the list of domains for which enhance security mode will not be enforced (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"f00b68c33b760502":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_grooveexe98","displayName":"groove.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_grooveexe98_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_protectionfromzoneelevation_l_grooveexe98_1","displayName":"True","description":null,"helpText":null}]},"f0f09cc17087ff0b":{"id":"device_vendor_msft_policy_config_printers_managedriverexclusionlist_driver_exclusionlistentry","displayName":"File Hash File Name:","description":"","helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"f0f6e41dba5d12ee":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscontacts","displayName":"Let Apps Access Contacts","description":"This policy setting specifies whether Windows apps can access contacts.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscontacts"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscontacts_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscontacts_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscontacts_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"f0511075dd2b6536":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessmicrophone","displayName":"Let Apps Access Microphone","description":"This policy setting specifies whether Windows apps can access the microphone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessmicrophone"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_letappsaccessmicrophone_0","displayName":"User in control.","description":"User in control.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccessmicrophone_1","displayName":"Force allow.","description":"Force allow.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_letappsaccessmicrophone_2","displayName":"Force deny.","description":"Force deny.","helpText":null}]},"f03058639917c611":{"id":"device_vendor_msft_policy_config_settingssync_enablewindowsbackup","displayName":"Enable Windows Backup","description":"This policy setting allows administrators to configure and manage windows backup for their organization.\n\nIf you enable this policy setting, windows backup will occur periodically.\n\nIf you disable or do not configure this policy setting, windows backup will not take place.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-settingssync#settingssync-enablewindowsbackup"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_settingssync_enablewindowsbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_settingssync_enablewindowsbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"f03d7e6d7085f91e":{"id":"device_vendor_msft_policy_config_taskmanager_allowendtask","displayName":"Allow End Task","description":"This setting determines whether non-administrators can use Task Manager to end tasks - enabled (1) or disabled (0). Default: enabled","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-TaskManager#allowendtask"],"categoryId":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","categoryName":"Task Manager","options":[{"id":"device_vendor_msft_policy_config_taskmanager_allowendtask_0","displayName":"Block","description":"Disabled. EndTask functionality is blocked in TaskManager.","helpText":null},{"id":"device_vendor_msft_policy_config_taskmanager_allowendtask_1","displayName":"Allow","description":"Enabled. Users can perform EndTask in TaskManager.","helpText":null}]},"f07de5894424ea77":{"id":"linux_platformupdatecontrols_schedule_daysofmonth","displayName":"Platform Update Schedule Day of Month","description":"Specifies on which day of the month platform updates are allowed. Select 'Every Day' for no restriction, or choose a specific day (1-31).","helpText":null,"infoUrls":["https://learn.microsoft.com/microsoft-365/security/defender-endpoint/linux-preferences#platform-update-preferences"],"categoryId":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","categoryName":"Platform Update","options":[{"id":"linux_platformupdatecontrols_schedule_daysofmonth_1","displayName":"1","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_2","displayName":"2","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_3","displayName":"3","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_4","displayName":"4","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_5","displayName":"5","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_6","displayName":"6","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_7","displayName":"7","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_8","displayName":"8","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_9","displayName":"9","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_10","displayName":"10","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_11","displayName":"11","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_12","displayName":"12","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_13","displayName":"13","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_14","displayName":"14","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_15","displayName":"15","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_16","displayName":"16","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_17","displayName":"17","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_18","displayName":"18","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_19","displayName":"19","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_20","displayName":"20","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_21","displayName":"21","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_22","displayName":"22","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_23","displayName":"23","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_24","displayName":"24","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_25","displayName":"25","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_26","displayName":"26","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_27","displayName":"27","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_28","displayName":"28","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_29","displayName":"29","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_30","displayName":"30","description":null,"helpText":null},{"id":"linux_platformupdatecontrols_schedule_daysofmonth_31","displayName":"31","description":null,"helpText":null}]},"f0dd645bfe09095a":{"id":"loginwindow_loginwindow","displayName":"Top Level Setting Group Collection","description":"Synthetic Top Level Setting Group Collection","helpText":null,"infoUrls":[],"categoryId":"0e937777-d01a-4180-a937-c2010451a529","categoryName":"Login Window Login Items","options":null},"f0300d35e54cb66d":{"id":"user_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_1","displayName":"Do not allow Digital Locker to run (User)","description":"Specifies whether Digital Locker can run.\r\n\r\nDigital Locker is a dedicated download manager associated with Windows Marketplace and a feature of Windows that can be used to manage and download products acquired and stored in the user's Windows Marketplace Digital Locker.\r\n\r\nIf you enable this setting, Digital Locker will not run.\r\n\r\nIf you disable or do not configure this setting, Digital Locker can be run.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-digitallocker#admx-digitallocker-digitalx-diableapplication-titletext-1"],"categoryId":"1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","categoryName":"Digital Locker","options":[{"id":"user_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_digitallocker_digitalx_diableapplication_titletext_1_1","displayName":"Enabled","description":null,"helpText":null}]},"f0d422264fb4fed2":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ris","displayName":"Remote Installation Services (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-ris"],"categoryId":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","categoryName":"Group Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ris_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_ris_1","displayName":"Enabled","description":null,"helpText":null}]},"f0a04bca0247d03e":{"id":"user_vendor_msft_policy_config_admx_startmenu_nohelp","displayName":"Remove Help menu from Start Menu (User)","description":"This policy setting allows you to remove the Help command from the Start menu.\r\n\r\nIf you enable this policy setting, the Help command is removed from the Start menu.\r\n\r\nIf you disable or do not configure this policy setting, the Help command is available from the Start menu.\r\n\r\nThis policy setting only affects the Start menu. It does not remove the Help menu from File Explorer and does not prevent users from running Help.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-nohelp"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_nohelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_nohelp_1","displayName":"Enabled","description":null,"helpText":null}]},"f078bc96acae8d25":{"id":"user_vendor_msft_policy_config_admx_userprofiles_limitsize_warnuser","displayName":"Notify user when profile storage space is exceeded. (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":[{"id":"user_vendor_msft_policy_config_admx_userprofiles_limitsize_warnuser_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userprofiles_limitsize_warnuser_1","displayName":"True","description":null,"helpText":null}]},"f073682dc223b804":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nowindowshotkeys","displayName":"Turn off Windows Key hotkeys (User)","description":"Turn off Windows Key hotkeys.\r\n\r\nKeyboards with a Windows key provide users with shortcuts to common shell features. For example, pressing the keyboard sequence Windows+R opens the Run dialog box; pressing Windows+E starts File Explorer. By using this setting, you can disable these Windows Key hotkeys.\r\n\r\nIf you enable this setting, the Windows Key hotkeys are unavailable.\r\n\r\nIf you disable or do not configure this setting, the Windows Key hotkeys are available.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nowindowshotkeys"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nowindowshotkeys_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nowindowshotkeys_1","displayName":"Enabled","description":null,"helpText":null}]},"f09f94e5bba60d99":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_explicitlyallowednetworkports_explicitlyallowednetworkportsdesc","displayName":"Explicitly allowed network ports (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"f04118613c0b7b59":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps (User)","description":"Setting the policy specifies a list of web apps that install silently, without user interaction, and which users can't uninstall or turn off.\r\n\r\nEach list item of the policy is an object with a mandatory member:\r\nurl (the URL of the web app to install)\r\n\r\nand 5 optional members:\r\n- default_launch_container\r\n(for how the web app opens—a new tab is the default)\r\n\r\n- create_desktop_shortcut\r\n(True if you want to create Linux and\r\nMicrosoft® Windows® desktop shortcuts).\r\n\r\n- fallback_app_name\r\n(Starting with Google Chrome version 90,\r\nallows you to override the app name if it is not a\r\nProgressive Web App (PWA), or the app name that is temporarily\r\ninstalled if it is a PWA but authentication is required before the\r\ninstallation can be completed. If both\r\ncustom_name and\r\nfallback_app_name are provided,\r\nthe latter will be ignored.)\r\n\r\n- custom_name\r\n(Starting with Google Chrome\r\nversion 96, allows you to permanently override the app name for all web\r\napps and PWAs. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\n- custom_icon\r\n(Starting with Google Chrome\r\nversion 96, allows you to override the app icon of installed apps. The\r\nicons have to be square, maximal 1 MB in size, and in one of the following\r\nformats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256\r\nhash of the icon file. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\nSee PinnedLauncherApps for pinning apps to the Google Chrome OS shelf.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebAppInstallForceList for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.google.com/maps\",\r\n \"default_launch_container\": \"window\",\r\n \"create_desktop_shortcut\": true\r\n },\r\n {\r\n \"url\": \"https://docs.google.com\",\r\n \"default_launch_container\": \"tab\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/editor\",\r\n \"default_launch_container\": \"window\",\r\n \"fallback_app_name\": \"Editor\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/sheets\",\r\n \"default_launch_container\": \"window\",\r\n \"custom_name\": \"Spreadsheets\"\r\n },\r\n {\r\n \"url\": \"https://weather.example.com\",\r\n \"custom_icon\": {\r\n \"url\": \"https://mydomain.example.com/sunny_icon.png\",\r\n \"hash\": \"c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38\"\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"f066a88ed01bd261":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_corsmitigationlist_corsmitigationlistdesc","displayName":"Enable CORS check mitigations in the new CORS implementation (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"f064be62677023d3":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_notificationsblockedforurls_notificationsblockedforurlsdesc","displayName":"Block notifications on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"f0a4ecdae65339ef":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled","displayName":"Enable Grammar Tools feature within Immersive Reader in Microsoft Edge (obsolete) (User)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 125.\r\n\r\nThis policy is obsoleted because Grammar Tools is deprecated from Edge. This policy won't work in Microsoft Edge version 126. Enables the Grammar Tools feature within Immersive Reader in Microsoft Edge.\r\nThis helps improve reading comprehension by splitting words into syllables and highlighting nouns, verbs, adverbs, and adjectives.\r\n\r\nIf you enable this policy or don't configure it, the Grammar Tools option shows up within Immersive Reader.\r\nIf you disable this policy, users can't access the Grammar Tools feature within Immersive Reader.","helpText":"","infoUrls":[],"categoryId":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","categoryName":"Immersive Reader settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~immersivereader_immersivereadergrammartoolsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f0132df0f740bc56":{"id":"user_vendor_msft_policy_config_microsoft_edgev121~policy~microsoft_edge~typosquattingchecker_typosquattingallowlistdomains_typosquattingallowlistdomainsdesc","displayName":"Configure the list of domains for which Edge Website Typo Protection won't trigger warnings (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fb1e99d0-b921-4b19-9842-17e3e7987528","categoryName":"Edge Website Typo Protection settings","options":null},"f00f916cffad0823":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls","displayName":"Configure tracking prevention exceptions for specific sites (User)","description":"Configure the list of URL patterns that are excluded from tracking prevention.\r\n\r\nIf you configure this policy, the list of configured URL patterns is excluded from tracking prevention.\r\n\r\nIf you don't configure this policy, the global default value from the \"Block tracking of users' web-browsing activity\" policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_allowtrackingforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"f0a2b1d411776b78":{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts (User)","description":"List of URL patterns. Private network requests initiated from insecure websites served by matching origins are allowed.\r\n\r\nIf this policy is not set, this policy behaves as if set to the empty list.\r\n\r\nFor origins not covered by the patterns specified here, the global default value will be used either from the 'InsecurePrivateNetworkRequestsAllowed' (Specifies whether to allow insecure websites to make requests to more-private network endpoints) policy, if it is set, or the user's personal configuration otherwise.\r\n\r\nNote that this policy only affects insecure origins, so secure origins (e.g. https://example.com) included in this list will be ignored.\r\n\r\nFor detailed information on valid URL patterns, please see https://docs.microsoft.com/en-us/DeployEdge/edge-learnmmore-url-list-filter%20format.\r\n\r\nExample value:\r\n\r\nhttp://www.example.com:8080\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"f0ebe0952e8047ff":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq","displayName":"Arabic (Iraq) (User)","description":"Enables the editing language Arabic (Iraq)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabiciraq_1","displayName":"Enabled","description":null,"helpText":null}]},"f059a197c303c550":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese","displayName":"Burmese (User)","description":"Enables the editing language Burmese","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_burmese_1","displayName":"Enabled","description":null,"helpText":null}]},"f02f16a8ab9eeea8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache12_l_workflowpath484","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"f0d122d00b1973e9":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc15_l_datecolon295","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"f06fcf8e4372c62f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink","displayName":"Do not show \"Manage Account\" link for subscription licenses. (User)","description":"This policy setting controls whether a \"Manage Account\" link is exposed in Account tab of the File menu for subscription licenses.\r\n\r\nIf you enable this policy setting, Office does not expose a \"Manage Account\" link for subscription licenses.\r\n\r\nIf you disable or do not configure this policy setting, Office exposes a \"Manage Account\" link for subscription licenses.","helpText":"","infoUrls":[],"categoryId":"760376f3-6b74-4992-89eb-aa41d6190e94","categoryName":"Subscription Activation","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_subscriptionactivation_l_hidemanageaccountlink_1","displayName":"Enabled","description":null,"helpText":null}]},"f0703d95ab59b6db":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_versionsandrecylebin_l_daysbacktokeepitemsinrecyclebin_l_daysbacktokeepitemsinrecyclebinspinid","displayName":"Days back to keep items in recycle bin (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c492dd55-8876-4b1b-b620-615cc9b65ef8","categoryName":"Versions and Recyle Bin","options":null},"f09bafda9bc7468f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions","displayName":"Layout Options (User)","description":"Sets the value in the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"b9ab4d39-9e28-4897-aa34-0201a35ea989","categoryName":"Right-to-left","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_righttoleft_l_layoutoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"f0f96f04eba9743b":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols","displayName":"Add slide navigation controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","categoryName":"General","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced~l_weboptions~l_general_l_slidenavigation_l_addslidenavigationcontrols_1","displayName":"True","description":null,"helpText":null}]},"f00ae5c0cf85d28f":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength","displayName":"Set CNG cipher key length (User)","description":"This policy setting allows you to configure the number of bits to use when creating the cipher key. This number will be rounded down to a multiple of 8.\r\n\r\nIf you enable this policy setting, the key bits specified will be used.\r\n\r\nIf you disable or do not configure this policy setting, the default value will be used.","helpText":"","infoUrls":[],"categoryId":"9544c86b-47bb-4cb2-a725-63214a0454f4","categoryName":"Cryptography","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_cryptography_l_setcngcipherkeylength_1","displayName":"Enabled","description":null,"helpText":null}]},"f040f4f330032316":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders55_1","displayName":"True","description":null,"helpText":null}]},"f01df096f87a0aaa":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc03_l_allowsubfolders19_1","displayName":"True","description":null,"helpText":null}]},"f0408c2c3b4dea69":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes","displayName":"My Shapes (User)","description":"Displays the path of the My Shapes folder.","helpText":"","infoUrls":[],"categoryId":"66395272-f132-4170-b88e-87f794f987f4","categoryName":"File Locations","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_filelocations_l_myshapes_1","displayName":"Enabled","description":null,"helpText":null}]},"f0163956d854f849":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc18_l_descriptioncolon78","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"f06063a5314702c0":{"id":"vendor_msft_wirelessnetworkpreference_connectionprofiles_{connectionprofileid}","displayName":" Connection Profile ID (Windows Insiders only)","description":"Unique identifier of a network preference policy. Unique ID is auto-generated.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","categoryName":"Wireless Network Preference","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/f3.json b/public/intune-definitions/f3.json index edefe1943fbc..6549bdc4e3d8 100644 --- a/public/intune-definitions/f3.json +++ b/public/intune-definitions/f3.json @@ -1 +1 @@ -{"f306f323fc28373a":{"id":"com.apple.applicationaccess_allowspellcheck","displayName":"Allow Spell Check (Deprecated)","description":"If false, disables keyboard spell-check. Requires a supervised device. Available in iOS 8.1.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowspellcheck_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowspellcheck_true","displayName":"True","description":null,"helpText":null}]},"f35eb2d09f850673":{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal","displayName":"Allow pages to send synchronous XHR requests during page dismissal","description":"This policy lets you specify that a page can send synchronous XHR requests during page dismissal.\n\nIf you enable this policy, pages can send synchronous XHR requests during page dismissal.\n\nIf you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowsyncxhrinpagedismissal"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal_true","displayName":"Allowed","description":null,"helpText":null}]},"f3e8609f62326741":{"id":"com.apple.managedclient.preferences_enableauthnegotiateport","displayName":"Include non-standard port in Kerberos SPN","description":"Specifies whether the generated Kerberos SPN should include a non-standard port.\n\nIf you enable this policy, and a user includes a non-standard port (a port other than 80 or 443) in a URL, that port is included in the generated Kerberos SPN.\n\nIf you don't configure or disable this policy, the generated Kerberos SPN won't include a port in any case.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableauthnegotiateport"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableauthnegotiateport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableauthnegotiateport_true","displayName":"Enabled","description":null,"helpText":null}]},"f32ff767c6a47e7f":{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar","description":"Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge the shortcut takes users to their Microsoft Office apps and docs.\n\nIf this policy is enabled or not configure, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\n\nIf the policy is disabled, the shortcut won't be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showofficeshortcutinfavoritesbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar_true","displayName":"Enabled","description":null,"helpText":null}]},"f3a0f1908ca42f16":{"id":"com.apple.managedclient.preferences_translateenabled","displayName":"Enable Translate","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\n\nDisable this policy to disable all built-in translate features.\n\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#translateenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_translateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_translateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f37c0a919a1ed8a5":{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron","displayName":"Repeating Power On","description":"The schedule for powering the device on. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"f376ccbf46dcfcd8":{"id":"com.apple.mobiledevice.passwordpolicy_customregex","displayName":"Custom Regex","description":"Specifies a regular expression, and its description, used to enforce password compliance. Use the simpler passcode restrictions whenever possible, and rely on regular expression matching only when necessary. Mistakes in regular expressions can lead to frustrating user experiences, such as unsatisfiable passcode policies, or policy descriptions that don't match the enforced policy.\n\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"f3232e877e4fdebd":{"id":"com.apple.xsan_fsnameservers","displayName":"FS Name Servers","description":"An array of storage area network (SAN) File System Name Server coordinators. The list should contain the same addresses in the same order as the metadata controller (MDC) /Library/Preferences/Xsan/fsnameservers file. Xsan SAN clients automatically receive updates to the fsnameservers list from the SAN configuration servers whenever this list changes. StorNext administrators should update their profile whenever the fsnameservers list changes. This key is required for StorNext SANs.","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},"f3a6b20b2199dd5e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled","displayName":"Guided Switch Enabled","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\n\nIf you enable this policy, you're prompted to switch to another account if the current profile doesn't work for the requesting link.\n\nIf you disable this policy, you aren't prompted to switch to another account when there's a profile and link mismatch.\n\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f32cecaad59ad451":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver_dns_nameserverlabel","displayName":"IP addresses:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},"f3ec6fcb459038d5":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition","displayName":"Turn on protocol recognition","description":"This policy setting allows you to configure protocol recognition for network protection against exploits of known vulnerabilities.\r\n\r\n If you enable or do not configure this setting, protocol recognition will be enabled.\r\n\r\n If you disable this setting, protocol recognition will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-nis-disableprotocolrecognition"],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},"f3d260dfa9730711":{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2","displayName":"Tape Drives: Deny write access","description":"This policy setting denies write access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"f30e58ef9e127745":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred","displayName":"Configure H.264/AVC hardware encoding for Remote Desktop Connections","description":"This policy setting lets you enable H.264/AVC hardware encoding support for Remote Desktop Connections. When you enable hardware encoding, if an error occurs, we will attempt to use software encoding. If you disable or do not configure this policy, we will always use software encoding.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-avc-hw-encode-preferred"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred_1","displayName":"Enabled","description":null,"helpText":null}]},"f3e095aee1d603be":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2","displayName":"Start a program on connection","description":"Configures Remote Desktop Services to run a specified program automatically upon connection.\r\n\r\nYou can use this setting to specify a program to run automatically when a user logs on to a remote computer.\r\n\r\nBy default, Remote Desktop Services sessions provide access to the full Windows desktop, unless otherwise specified with this setting, by the server administrator, or by the user in configuring the client connection. Enabling this setting overrides the \"Start Program\" settings set by the server administrator or user. The Start menu and Windows Desktop are not displayed, and when the user exits the program the session is automatically logged off.\r\n\r\nTo use this setting, in Program path and file name, type the fully qualified path and file name of the executable file to be run when the user logs on. If necessary, in Working Directory, type the fully qualified path to the starting directory for the program. If you leave Working Directory blank, the program runs with its default working directory. If the specified program path, file name, or working directory is not the name of a valid directory, the RD Session Host server connection fails with an error message.\r\n\r\nIf the status is set to Enabled, Remote Desktop Services sessions automatically run the specified program and use the specified Working Directory (or the program default directory, if Working Directory is not specified) as the working directory for the program.\r\n\r\nIf the status is set to Disabled or Not Configured, Remote Desktop Services sessions start with the full desktop, unless the server administrator or user specify otherwise. (See \"Computer Configuration\\Administrative Templates\\System\\Logon\\Run these programs at user logon\" setting.)\r\n\r\nNote: This setting appears in both Computer Configuration and User Configuration. If both settings are configured, the Computer Configuration setting overrides.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-start-program-2"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_1","displayName":"Enabled","description":null,"helpText":null}]},"f341e26e6ec01fd5":{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification","displayName":"Turn off toast notifications","description":"\n This policy setting turns off toast notifications for applications.\n\n If you enable this policy setting, applications will not be able to raise toast notifications.\n\n Note that this policy does not affect taskbar notification balloons.\n\n Note that Windows system features are not affected by this policy. You must enable/disable system features individually to stop their ability to raise toast notifications.\n\n If you disable or do not configure this policy setting, toast notifications are enabled and can be turned off by the administrator or user.\n\n No reboots or service restarts are required for this policy setting to take effect.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-notoastnotification"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"f3e6ada50c22fc4f":{"id":"device_vendor_msft_policy_config_browser_enterprisemodesitelist","displayName":"Enterprise Mode Site List","description":"This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisemodesitelist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"f35d7b3b02de3264":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps","description":"Setting the policy specifies a list of web apps that install silently, without user interaction, and which users can't uninstall or turn off.\r\n\r\nEach list item of the policy is an object with a mandatory member:\r\nurl (the URL of the web app to install)\r\n\r\nand 5 optional members:\r\n- default_launch_container\r\n(for how the web app opens—a new tab is the default)\r\n\r\n- create_desktop_shortcut\r\n(True if you want to create Linux and\r\nMicrosoft® Windows® desktop shortcuts).\r\n\r\n- fallback_app_name\r\n(Starting with Google Chrome version 90,\r\nallows you to override the app name if it is not a\r\nProgressive Web App (PWA), or the app name that is temporarily\r\ninstalled if it is a PWA but authentication is required before the\r\ninstallation can be completed. If both\r\ncustom_name and\r\nfallback_app_name are provided,\r\nthe latter will be ignored.)\r\n\r\n- custom_name\r\n(Starting with Google Chrome\r\nversion 96, allows you to permanently override the app name for all web\r\napps and PWAs. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\n- custom_icon\r\n(Starting with Google Chrome\r\nversion 96, allows you to override the app icon of installed apps. The\r\nicons have to be square, maximal 1 MB in size, and in one of the following\r\nformats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256\r\nhash of the icon file. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\nSee PinnedLauncherApps for pinning apps to the Google Chrome OS shelf.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebAppInstallForceList for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.google.com/maps\",\r\n \"default_launch_container\": \"window\",\r\n \"create_desktop_shortcut\": true\r\n },\r\n {\r\n \"url\": \"https://docs.google.com\",\r\n \"default_launch_container\": \"tab\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/editor\",\r\n \"default_launch_container\": \"window\",\r\n \"fallback_app_name\": \"Editor\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/sheets\",\r\n \"default_launch_container\": \"window\",\r\n \"custom_name\": \"Spreadsheets\"\r\n },\r\n {\r\n \"url\": \"https://weather.example.com\",\r\n \"custom_icon\": {\r\n \"url\": \"https://mydomain.example.com/sunny_icon.png\",\r\n \"hash\": \"c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38\"\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"f36ef10ddd8288b8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled","displayName":"Disable Developer Tools","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f31cb469a093592c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist","displayName":"Configure the list of force-installed apps and extensions","description":"Setting the policy specifies a list of apps and extensions that install silently, without user interaction, and which users can't uninstall or turn off. Permissions are granted implicitly, including for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These 2 APIs aren't available to apps and extensions that aren't force-installed.)\r\n\r\nLeaving the policy unset means no apps or extensions are autoinstalled, and users can uninstall any app or extension in Google Chrome.\r\n\r\nThis policy superseeds ExtensionInstallBlocklist policy. If a previously force-installed app or extension is removed from this list, Google Chrome automatically uninstalls it.\r\n\r\nOn Microsoft® Windows® instances, apps and extensions from outside the Chrome Web Store can only be forced installed if the instance is joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.\r\n\r\nOn macOS instances, apps and extensions from outside the Chrome Web Store can only be force installed if the instance is managed via MDM, or joined to a domain via MCX.\r\n\r\nThe source code of any extension may be altered by users through developer tools, potentially rendering the extension dysfunctional. If this is a concern, set the DeveloperToolsDisabled policy.\r\n\r\nEach list item of the policy is a string that contains an extension ID and, optionally, an \"update\" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on chrome://extensions when in Developer mode. If specified, the \"update\" URL should point to an Update Manifest XML document ( https://developer.chrome.com/extensions/autoupdate ). By default, the Chrome Web Store's update URL is used. The \"update\" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest.\r\n\r\n Note: This policy doesn't apply to Incognito mode. Read about hosting extensions ( https://developer.chrome.com/extensions/hosting ).\r\n\r\nExample value:\r\n\r\naaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa;https://clients2.google.com/service/update2/crx\r\nabcdefghijklmnopabcdefghijklmnop","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"f3bec7309a03c210":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled","displayName":"Enable QR Code Generator","description":"This policy enables the QR Code generator feature in Google Chrome.\r\n\r\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\r\n\r\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f3b82b5dc91f10c6":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings","displayName":"Settings for Gemini integration","description":"This setting allows Gemini app integrations.\r\n\r\n0/unset = Gemini integration will be available for users.\r\n\r\n1 = Gemini integration will not be available for users.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information, please check the Help Center article https://support.google.com/chrome/a?p=gemini_in_chrome.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_1","displayName":"Enabled","description":null,"helpText":null}]},"f3123c21bd6725af":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy allows controlling post-quantum key agreement for WebRTC.\r\n\r\nIf this policy is set to Enabled, post-quantum key agreement would be offered for\r\nWebRTC.\r\n\r\nIf this policy is set to Disabled, post-quantum key agreement would not be offered\r\nfor WebRTC.\r\n\r\nIf this policy is not set, the value would be set by the default rollout process\r\nfor post-quantum key agreement offered for WebRTC.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing DTLS\r\npeers and networking middleware are expected to ignore the new option and\r\ncontinue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement DTLS may malfunction when\r\noffered the new option. For example, they may disconnect in response to\r\nunrecognized options or the resulting larger messages. Such devices are not\r\npost-quantum-ready and will interfere with an enterprise's post-quantum\r\ntransition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed after some milestones.","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},"f366eaeff0addb76":{"id":"device_vendor_msft_policy_config_credentialproviders_blockpicturepassword","displayName":"Turn off picture password sign-in","description":"This policy setting allows you to control whether a domain user can sign in using a picture password.\n\nIf you enable this policy setting, a domain user can't set up or sign in with a picture password. \n\nIf you disable or don't configure this policy setting, a domain user can set up and use a picture password.\n\nNote that the user's domain password will be cached in the system vault when using this feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-credentialproviders#credentialproviders-blockpicturepassword"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_credentialproviders_blockpicturepassword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_credentialproviders_blockpicturepassword_1","displayName":"Enabled","description":null,"helpText":null}]},"f33f4d180ca74053":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcisdynamicvhd","displayName":"Is Dynamic (VHD)","description":"[ENABLED BY DEFAULT]\r\n\r\nVHD(x) containers will be dynamically allocated. VHD(x) file size will grow as data is added to the VHD(x). If disabled, VHD(x) containers that are auto-created will be fully allocated.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\IsDynamic\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcisdynamicvhd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcisdynamicvhd_1","displayName":"Enabled","description":null,"helpText":null}]},"f3ddfce1bdf87d69":{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions","displayName":"Secure Protocol combinations","description":"","helpText":"","infoUrls":[],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_0","displayName":"Use no secure protocols","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_8","displayName":"Only use SSL 2.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_32","displayName":"Only use SSL 3.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_40","displayName":"Use SSL 2.0 and SSL 3.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_128","displayName":"Only use TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_136","displayName":"Use SSL 2.0 and TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_160","displayName":"Use SSL 3.0 and TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_168","displayName":"Use SSL 2.0, SSL 3.0, and TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_512","displayName":"Only use TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_520","displayName":"Use SSL 2.0 and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_544","displayName":"Use SSL 3.0 and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_552","displayName":"Use SSL 2.0, SSL 3.0, and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_640","displayName":"Use TLS 1.0 and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_648","displayName":"Use SSL 2.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_672","displayName":"Use SSL 3.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_680","displayName":"Use SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2048","displayName":"Only use TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2056","displayName":"Use SSL 2.0 and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2080","displayName":"Use SSL 3.0 and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2088","displayName":"Use SSL 2.0, SSL 3.0, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2176","displayName":"Use TLS 1.0 and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2184","displayName":"Use SSL 2.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2208","displayName":"Use SSL 3.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2216","displayName":"Use SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2560","displayName":"Use TLS 1.1 and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2568","displayName":"Use SSL 2.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2592","displayName":"Use SSL 3.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2600","displayName":"Use SSL 2.0, SSL 3.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2688","displayName":"Use TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2696","displayName":"Use SSL 2.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2720","displayName":"Use SSL 3.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2728","displayName":"Use SSL 2.0, SSL 3.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_8192","displayName":"Only use TLS 1.3","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10240","displayName":"Use TLS 1.2 and TLS 1.3","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10752","displayName":"Use TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10880","displayName":"Use TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10912","displayName":"Use SSL 3.0, TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null}]},"f3d43a32ec004280":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c","displayName":"Allow VBScript to run in Internet Explorer","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_1","displayName":"Prompt","description":null,"helpText":null}]},"f30bfb89018131fd":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowlessprivilegedsites"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"f397ab31c63973a6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed","displayName":"Allow full screen mode","description":"Set the availability of full screen mode - all Microsoft Edge UI is hidden and only web content is visible.\r\n\r\nIf you enable this policy or don't configure it, the user, apps, and extensions with appropriate permissions can enter full screen mode.\r\n\r\nIf you disable this policy, users, apps, and extensions can't enter full screen mode.\r\n\r\nOpening Microsoft Edge in kiosk mode using the command line is unavailable when full screen mode is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"f349d336eab0eb4e":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage","description":"This setting allows you to list the URLs that specify which sites are automatically granted permission to access a HID device containing a top-level collection with the given HID usage.\r\n\r\nEach item in the list requires both usages and urls fields for the policy to be valid.\r\n\r\n * Each item in the usages field must have a usage_page and may have a usage field.\r\n\r\n * Omitting the usage field will create a policy matching any device containing a top-level collection with a usage from the specified usage page.\r\n\r\n * An item which has a usage field without a usage_page field is invalid and is ignored.\r\n\r\nIf you don't set this policy, that means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nURLs in this policy shouldn't conflict with those configured through 'WebHidBlockedForUrls' (Block the WebHID API on these sites). If they do, this policy takes precedence over 'WebHidBlockedForUrls'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://microsoft.com\",\r\n \"https://chromium.org\"\r\n ],\r\n \"usages\": [\r\n {\r\n \"usage\": 5678,\r\n \"usage_page\": 1234\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"f3e5e642d96c917f":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},"f3486a54a52e979d":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting","displayName":"Control use of the Serial API","description":"\r\nSet whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\r\n\r\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SerialAskForUrls' (Allow the Serial API on specific sites) and 'SerialBlockedForUrls' (Block the Serial API on specific sites) policies.\r\n\r\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\r\n\r\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"f3af7dd76d94c471":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge","description":"This setting lets you specify whether Internet Explorer will redirect navigations to sites that require a modern browser to Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Sitelist', beginning in M87, Internet Explorer will redirect sites that require a modern browser to Microsoft Edge.\r\n\r\nMicrosoft provides a list of public sites that require such redirection, such as https://mail.yahoo.com.\r\n\r\nWhen a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that began loading that site is closed if it had no prior content. Otherwise, it is navigated to a Microsoft help page explaining why the site was redirected to Microsoft Edge.\r\n\r\nWhen Microsoft Edge is launched to load a site from IE, an information bar is shown to the user explaining that the site works best in a modern browser.\r\n\r\nIf you set this policy to 'Disable', Internet Explorer will not redirect any traffic to Microsoft Edge.\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable\r\n\r\n* Sitelist (1) = Redirect sites based on the incompatible sites sitelist\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Enabled","description":null,"helpText":null}]},"f3e496a2fc7f4919":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_pptviewexe186","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_pptviewexe186_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_pptviewexe186_1","displayName":"True","description":null,"helpText":null}]},"f3804f2bcab379de":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_payloadcloudid","displayName":"Cloud ID (optional):","description":"","helpText":"","infoUrls":[],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":null},"f3b31e376e924459":{"id":"device_vendor_msft_policy_config_update_engagedrestarttransitionschedule","displayName":"Engaged Restart Transition Schedule","description":"For Quality Updates, this policy specifies the timing before transitioning from Auto restarts scheduled outside of active hours to Engaged restart, which requires the user to schedule. The period can be set between 2 and 30 days from the time the restart becomes pending. Value type is integer. Default value is 7 days. Supported value range: 2 - 30. If you disable or do not configure this policy, the default behaviors will be used. If any of the following policies are configured, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installationsAlways automatically restart at scheduled timeSpecify deadline before auto-restart for update installation","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#engagedrestarttransitionschedule"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"f328b8bb819add8e":{"id":"keyboardsettings_allowautocorrection","displayName":"Allow Auto Correction","description":"If `false`, disables auto-correction.","helpText":null,"infoUrls":[],"categoryId":"dba26132-cba6-4178-93c3-f02476532f08","categoryName":"Keyboard Settings","options":[{"id":"keyboardsettings_allowautocorrection_false","displayName":"False","description":null,"helpText":null},{"id":"keyboardsettings_allowautocorrection_true","displayName":"True","description":null,"helpText":null}]},"f3e6baef3778f834":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_pathcolon23","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"f3654d958e75c5fa":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_disableclose","displayName":"Prohibit closing items (User)","description":"Prevents users from removing Web content from their Active Desktop.\r\n\r\nIn Active Desktop, you can add items to the desktop but close them so they are not displayed.\r\n\r\nIf you enable this setting, items added to the desktop cannot be closed; they always appear on the desktop. This setting removes the check boxes from items on the Web tab in Display in Control Panel.\r\n\r\nNote: This setting does not prevent users from deleting items from their Active Desktop.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-sz-atc-disableclose"],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_disableclose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_disableclose_1","displayName":"Enabled","description":null,"helpText":null}]},"f3f6df6fb74b3557":{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoncloudcandidate","displayName":"Turn on cloud candidate (User)","description":"This policy setting controls the cloud candidates feature, which uses an online service to provide input suggestions that don't exist in a PC's local dictionary.\r\n\r\nIf you enable this policy setting, the functionality associated with this feature is turned on, the user's keyboard input is sent to Microsoft to generate the suggestions, and the user won't be able to turn it off.\r\n\r\nIf you disable this policy setting, the functionality associated with this feature is turned off, and the user won't be able to turn it on.\r\n\r\nIf you don't configure this policy setting, it will be turned off by default, and the user can turn on and turn off the cloud candidates feature.\r\n\r\nThis Policy setting applies to Microsoft CHS Pinyin IME and JPN IME.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eaime#admx-eaime-l-turnoncloudcandidate"],"categoryId":"7d331987-7e2d-4975-b23b-d99a5af26ddf","categoryName":"IME","options":[{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoncloudcandidate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoncloudcandidate_1","displayName":"Enabled","description":null,"helpText":null}]},"f3d2e45259aeae12":{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_extendview","displayName":"Extended View (Web View) (User)","description":"Permits or prohibits use of this snap-in.\n\nIf you enable this setting, the snap-in is permitted. If you disable the setting, the snap-in is prohibited.\n\nIf this setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted.\n\n To explicitly permit use of this snap-in, enable this setting. If this setting is not configured (or disabled), this snap-in is prohibited.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited.\n\n To explicitly prohibit use of this snap-in, disable this setting. If this setting is not configured (or enabled), the snap-in is permitted.\n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmc#admx-mmc-mmc-extendview"],"categoryId":"756d2b0b-5f06-45e7-b5c5-c066deb5ed2f","categoryName":"Extension snap-ins","options":[{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_extendview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_extendview_1","displayName":"Enabled","description":null,"helpText":null}]},"f30db9dbb2a7afb1":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_remstore","displayName":"Removable Storage (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-remstore"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_remstore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_remstore_1","displayName":"Enabled","description":null,"helpText":null}]},"f37c2bdfe7f90139":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup","displayName":"PowerPoint 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft PowerPoint 2013.\r\nMicrosoft PowerPoint 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft PowerPoint 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft PowerPoint 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft PowerPoint 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013powerpointbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"f31b06d13a03a098":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup","displayName":"Word 2016 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Word 2016.\r\nMicrosoft Word 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Word 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Word 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Word 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016wordbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"f3118d7dc22ac758":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings (User)","description":"Configures browsing data lifetime settings for Google Chrome. This policy allows admins to configure (per data-type) when data is deleted by the browser. This is useful for customers that work with sensitive customer data. The policy will only take effect if SyncDisabled is set to true.\r\n\r\nThe available data types are 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\n\r\nThe browser will automatically remove data of selected types that is older than 'time_to_live_in_hours'. The minimum value that can be set is 1 hour.\r\n\r\nThe deletion of expired data will happen 15 seconds after the browser starts then every hour while the browser is running.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=BrowsingDataLifetime for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"time_to_live_in_hours\": 24,\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ]\r\n },\r\n {\r\n \"time_to_live_in_hours\": 12,\r\n \"data_types\": [\r\n \"password_signin\",\r\n \"autofill\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},"f3ab964a3bffc364":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist","displayName":"Clear Browsing Data on Exit (User)","description":"Configures a list of browsing data types that should be deleted when the user closes all browser windows. The available data types are browsing history (browsing_history), download history (download_history), cookies (cookies_and_other_site_data), cache(cached_images_and_files), autofill (autofill), passwords (password_signin), site settings (site_settings) and hosted apps data (hosted_app_data). This policy does not take precedence over AllowDeletingBrowserHistory.\r\n\r\nThis policy requires the SyncDisabled policy to be set to true, otherwise it will be ignored. If this policy is set at platform level, Sync should be disabled at platform level. If this policy is set at user level, Sync should be disabled for that user in order for this policy to take effect.\r\n\r\nIf Google Chrome does not exit cleanly (for example, if the browser or the OS crashes), the browsing data will be cleared the next time the profile is loaded.\r\n\r\nExample value:\r\n\r\nbrowsing_history\r\ndownload_history\r\ncookies_and_other_site_data\r\ncached_images_and_files\r\npassword_signin\r\nautofill\r\nsite_settings\r\nhosted_app_data","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_1","displayName":"Enabled","description":null,"helpText":null}]},"f37f0f64501e65c4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate_policyrefreshrate","displayName":"Refresh rate for user policy: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"f3c11224c77e4ecc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled","displayName":"Enable or disable spell checking web service (User)","description":"Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used.\r\n\r\nLeaving the policy unset lets users choose whether to use the spellcheck service.\r\n\r\nThe spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f331844fccc4bd29":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled","displayName":"Enable PAC URL stripping (for https://) (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f3c26f562b254167":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC (User)","description":"This policy allows controlling post-quantum key agreement for WebRTC.\r\n\r\nIf this policy is set to Enabled, post-quantum key agreement would be offered for\r\nWebRTC.\r\n\r\nIf this policy is set to Disabled, post-quantum key agreement would not be offered\r\nfor WebRTC.\r\n\r\nIf this policy is not set, the value would be set by the default rollout process\r\nfor post-quantum key agreement offered for WebRTC.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing DTLS\r\npeers and networking middleware are expected to ignore the new option and\r\ncontinue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement DTLS may malfunction when\r\noffered the new option. For example, they may disconnect in response to\r\nunrecognized options or the resulting larger messages. Such devices are not\r\npost-quantum-ready and will interfere with an enterprise's post-quantum\r\ntransition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed after some milestones.","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},"f3c828b4b0b31b67":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1","displayName":"Save Excel files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_51","displayName":"Excel Workbook (*.xlsx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_52","displayName":"Excel Macro-Enabled Workbook (*.xlsm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_50","displayName":"Excel Binary Workbook (*.xlsb)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_44","displayName":"Web Page (*.htm; *.html)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_56","displayName":"Excel 97-2003 Workbook (*.xls)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_39","displayName":"Excel 5.0/95 Workbook (*.xls)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_60","displayName":"OpenDocument Spreadsheet (*.ods)","description":null,"helpText":null}]},"f3bb6794ff430376":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_pathcolon13","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"f329ada644fecfad":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon22","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"f32b64cae140a822":{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview","displayName":"Turn off Compatibility View (User)","description":"This policy setting controls the Compatibility View feature, which allows the user to fix website display problems that he or she may encounter while browsing.\n\nIf you enable this policy setting, the user cannot use the Compatibility View button or manage the Compatibility View sites list.\n\nIf you disable or do not configure this policy setting, the user can use the Compatibility View button and manage the Compatibility View sites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecompatview"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview_1","displayName":"Enabled","description":null,"helpText":null}]},"f33203ed1aba6bf5":{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation","displayName":"Prevent participation in the Customer Experience Improvement Program (User)","description":"This policy setting prevents the user from participating in the Customer Experience Improvement Program (CEIP).\n\nIf you enable this policy setting, the user cannot participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you disable this policy setting, the user must participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you do not configure this policy setting, the user can choose to participate in the CEIP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecustomerexperienceimprovementprogramparticipation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_1","displayName":"Enabled","description":null,"helpText":null}]},"f38685a0e6a1ead9":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"f3fd0a5be3a68ed3":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting","displayName":"Allow active scripting (User)","description":"This policy setting allows you to manage whether script code on pages in the zone is run.\n\nIf you enable this policy setting, script code on pages in the zone can run automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow script code on pages in the zone to run.\n\nIf you disable this policy setting, script code on pages in the zone is prevented from running.\n\nIf you do not configure this policy setting, script code on pages in the zone is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowactivescripting"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_1","displayName":"Enabled","description":null,"helpText":null}]},"f3c2767f60e82ce7":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts","displayName":"Configure the list of commands for which to disable keyboard shortcuts (User)","description":"Configure the list of Microsoft Edge commands for which to disable keyboard shortcuts.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2186950 for a list of possible commands to disable.\r\n\r\nIf you enable this policy, commands in the 'disabled' list will no longer be activated by keyboard shortcuts.\r\n\r\nIf you disable this policy, all keyboard shortcuts behave as usual.\r\n\r\nNote: Disabling a command will only remove its shortcut mapping. Commands in the 'disabled' list will still function if accessed via browser UI.\r\n\r\nExample value:\r\n\r\n{\r\n \"disabled\": [\r\n \"new_tab\",\r\n \"fullscreen\"\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"disabled\": [\"new_tab\", \"fullscreen\"]}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"f35cdc22e71df042":{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended","displayName":"Set the default \"share additional operating system region\" setting (User)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\r\n\r\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\r\n\r\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\r\n\r\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\r\n\r\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\r\n\r\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\r\n\r\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\r\n\r\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\r\n\r\nPolicy options mapping:\r\n\r\n* Limited (0) = Limited\r\n\r\n* Always (1) = Always share the OS Regional format\r\n\r\n* Never (2) = Never share the OS Regional format\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"f340b5dc3881feb7":{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\r\n\r\nIf you disable this policy, the UI for the opt-out user experience is off.\r\n\r\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) policy.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\r\n\r\nAfter careful evaluation, we have determined that this experimental opt-out UX is not required. As a result, this policy will be deprecated and stop working after Edge version 130.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f3a682ca1ac68813":{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager (User)","description":"This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager.\r\n\r\nIf the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect.\r\n\r\nIf this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.\r\n\r\nIf this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f3086863c964fd14":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for InPrivate and Guest profiles (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_0","displayName":"Enable ambient authentication in regular sessions only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_1","displayName":"Enable ambient authentication in InPrivate and regular sessions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_2","displayName":"Enable ambient authentication in guest and regular sessions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_3","displayName":"Enable ambient authentication in regular, InPrivate and guest sessions","description":null,"helpText":null}]},"f34a9650ccefc2b6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp","displayName":"Federated search for help (User)","description":"\r\n This policy setting allows you to determine the sources of content that Office users in your organization can access through Office Help (F1).\r\n\r\n If you enable or do not configure this policy setting, users who utilize Office Help see content from both Office and the Internet.\r\n\r\n If you disable this setting, Office users’ search results through Help are limited to Office content.\r\n ","helpText":"","infoUrls":[],"categoryId":"1942922a-cba9-44c8-871f-3d915c62bd06","categoryName":"Help","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp_1","displayName":"Enabled","description":null,"helpText":null}]},"f36f2a61fd8b8e6b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican","displayName":"Corsican (User)","description":"Enables the editing language Corsican","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican_1","displayName":"Enabled","description":null,"helpText":null}]},"f35ddce1912b58db":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian","displayName":"Mongolian (Traditional Mongolian) (User)","description":"Enables the editing language Mongolian (Traditional Mongolian)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian_1","displayName":"Enabled","description":null,"helpText":null}]},"f37ba394a8ab897c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowfriendly441","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"f30c766b1b5fb467":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial","displayName":"Disable the tutorial that appears at the end of OneDrive Setup (User)","description":"This setting lets you prevent the tutorial from launching in a web browser at the end of OneDrive Setup.\r\n\r\nIf you enable this setting, users will not see the tutorial after they complete OneDrive Setup.\r\n\r\nIf you disable or do not configure this setting, the tutorial will appear at the end of OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial_1","displayName":"Enabled","description":null,"helpText":null}]},"f33698855a433e32":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity","displayName":"Set sensitivity (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_1","displayName":"Enabled","description":null,"helpText":null}]},"f3073dc06df08a98":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist","displayName":"Disable user entries to server list (User)","description":"This policy setting controls whether Outlook users can add entries to the list of SharePoint servers when establishing a meeting workspace. \r\n\r\nIf you enable this policy setting, you can choose between two options to determine whether Outlook users can add entries to the published server list: \r\n\r\n- Publish default, allow others. This option is the default configuration in Outlook. \r\n\r\n- Publish default, disallow others. This option prevents users from adding servers to the default published server list. \r\n\r\nIf you disable or do not configure this policy setting, when users create a meeting workspace, they can choose a server from a default list provided by administrators or manually enter the address of a server that is not listed. This is the equivalent of Enabled -- Publish default, allow others.","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_1","displayName":"Enabled","description":null,"helpText":null}]},"f3044db7b246edb5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong","displayName":"Reduce the end time of long appointments and meetings by a specified number of minutes (User)","description":"\r\n This policy setting allows you to specify how many minutes to reduce the end time of a long appointment or meeting by when a user creates an appointment or meeting. A long appointment or meeting is one that lasts for one hour or longer.\r\n\r\n If you enable this policy setting, you specify the number of minutes to reduce the end time of a long appointment or meeting by when a user creates an appointment or meeting. The user won’t be able to change this value by going to File > Options > Calendar.\r\n\r\n Note: You should also enable the “End appointments and meetings early” policy setting\r\n\r\n If you disable or don’t configure this policy setting, the default value of 10 minutes is used or whatever the user specifies by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_1","displayName":"Enabled","description":null,"helpText":null}]},"f30c06f8274be64a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},"f3fd6fd3d11f85b0":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},"f3fe104ef630cedd":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts","displayName":"Prevent adding non-default Exchange accounts (User)","description":"This policy allows you to prevent users from adding non-default Exchange accounts to existing Outlook profiles.\r\n\r\nIf you enable this policy setting, you will prevent users from adding non-default Exchange accounts via the Add New E-mail Account wizard.\r\n\r\nIf you disable or do not configure this policy setting, users can add non-default Exchange accounts to existing Outlook profiles.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},"f34183f75bb12255":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle","displayName":"Saving messages sent from a shared mailbox to the Sent Items folder (User)","description":"This policy setting controls whether messages sent from a shared mailbox are saved to the Sent Items folder of the shared mailbox.\r\n\r\nBy default, messages sent from a shared mailbox aren't saved to the Sent Items folder of the shared mailbox.\r\n\r\nIf you enable this policy setting, messages sent from a shared mailbox will be saved to the Sent Items folder of the shared mailbox.\r\n\r\nIf you disable or don’t configure this policy setting, messages sent from a shared mailbox won’t be saved to the Sent Items folder of the shared mailbox.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle_1","displayName":"Enabled","description":null,"helpText":null}]},"f31e83d2afebfc3e":{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum","displayName":"When installing drivers for a new connection: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum_1","displayName":"Show warning only","description":null,"helpText":null}]},"f3d03abd3883f2a1":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours","displayName":"Hours (User)","description":"Sets the label for hours.\r\n \r\nIf you enable this setting, hours are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_1","displayName":"Enabled","description":null,"helpText":null}]},"f3c54d38ed9776c9":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":null},"f3bab2fb18ce0421":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"f3a6d8fd4f9c5593":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file +{"f306f323fc28373a":{"id":"com.apple.applicationaccess_allowspellcheck","displayName":"Allow Spell Check (Deprecated)","description":"If false, disables keyboard spell-check. Requires a supervised device. Available in iOS 8.1.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowspellcheck_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowspellcheck_true","displayName":"True","description":null,"helpText":null}]},"f35eb2d09f850673":{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal","displayName":"Allow pages to send synchronous XHR requests during page dismissal","description":"This policy lets you specify that a page can send synchronous XHR requests during page dismissal.\n\nIf you enable this policy, pages can send synchronous XHR requests during page dismissal.\n\nIf you disable this policy or don't configure this policy, pages aren't allowed to send synchronous XHR requests during page dismissal.\n\nThis policy is temporary and will be removed in a future release.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#allowsyncxhrinpagedismissal"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal_false","displayName":"Blocked","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_allowsyncxhrinpagedismissal_true","displayName":"Allowed","description":null,"helpText":null}]},"f3e8609f62326741":{"id":"com.apple.managedclient.preferences_enableauthnegotiateport","displayName":"Include non-standard port in Kerberos SPN","description":"Specifies whether the generated Kerberos SPN should include a non-standard port.\n\nIf you enable this policy, and a user includes a non-standard port (a port other than 80 or 443) in a URL, that port is included in the generated Kerberos SPN.\n\nIf you don't configure or disable this policy, the generated Kerberos SPN won't include a port in any case.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#enableauthnegotiateport"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_enableauthnegotiateport_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_enableauthnegotiateport_true","displayName":"Enabled","description":null,"helpText":null}]},"f32ff767c6a47e7f":{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar","displayName":"Show Microsoft Office shortcut in favorites bar","description":"Specifies whether to include a shortcut to Office.com in the favorites bar. For users signed into Microsoft Edge the shortcut takes users to their Microsoft Office apps and docs.\n\nIf this policy is enabled or not configure, users can choose whether to see the shortcut by changing the toggle in the favorites bar context menu.\n\nIf the policy is disabled, the shortcut won't be shown.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#showofficeshortcutinfavoritesbar"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_showofficeshortcutinfavoritesbar_true","displayName":"Enabled","description":null,"helpText":null}]},"f3a0f1908ca42f16":{"id":"com.apple.managedclient.preferences_translateenabled","displayName":"Enable Translate","description":"Enables the integrated Microsoft translation service on Microsoft Edge.\n\nIf you enable this policy, Microsoft Edge offers translation functionality to the user by showing an integrated translate flyout when appropriate, and a translate option on the right-click context menu.\n\nDisable this policy to disable all built-in translate features.\n\nIf you don't configure the policy, users can choose whether to use the translation functionality or not.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#translateenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_translateenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_translateenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f37c0a919a1ed8a5":{"id":"com.apple.mcx_com.apple.energysaver.desktop.schedule_repeatingpoweron","displayName":"Repeating Power On","description":"The schedule for powering the device on. ","helpText":null,"infoUrls":[],"categoryId":"8c75a12d-664d-43ba-a3aa-5259425f9b37","categoryName":"Energy Saver","options":null},"f376ccbf46dcfcd8":{"id":"com.apple.mobiledevice.passwordpolicy_customregex","displayName":"Custom Regex","description":"Specifies a regular expression, and its description, used to enforce password compliance. Use the simpler passcode restrictions whenever possible, and rely on regular expression matching only when necessary. Mistakes in regular expressions can lead to frustrating user experiences, such as unsatisfiable passcode policies, or policy descriptions that don't match the enforced policy.\n\nAvailable in macOS 14 and later.","helpText":null,"infoUrls":[],"categoryId":"d68abc4d-559a-4339-be48-c41a77a87034","categoryName":"Passcode","options":null},"f3232e877e4fdebd":{"id":"com.apple.xsan_fsnameservers","displayName":"FS Name Servers","description":"An array of storage area network (SAN) File System Name Server coordinators. The list should contain the same addresses in the same order as the metadata controller (MDC) /Library/Preferences/Xsan/fsnameservers file. Xsan SAN clients automatically receive updates to the fsnameservers list from the SAN configuration servers whenever this list changes. StorNext administrators should update their profile whenever the fsnameservers list changes. This key is required for StorNext SANs.","helpText":null,"infoUrls":[],"categoryId":"46af3391-ed6d-4ada-aef7-02dac2a1b136","categoryName":"Xsan","options":null},"f3a6b20b2199dd5e":{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled","displayName":"Guided Switch Enabled","description":"Allows Microsoft Edge to prompt the user to switch to the appropriate profile when Microsoft Edge detects that a link is a personal or work link.\n\nIf you enable this policy, you're prompted to switch to another account if the current profile doesn't work for the requesting link.\n\nIf you disable this policy, you aren't prompted to switch to another account when there's a profile and link mismatch.\n\nIf this policy isn't configured, guided switch is turned on by default. A user can override this value in the browser settings.","helpText":null,"infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.guidedswitchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f32cecaad59ad451":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_nameserver_dns_nameserverlabel","displayName":"IP addresses:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":null},"f3ec6fcb459038d5":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition","displayName":"Turn on protocol recognition","description":"This policy setting allows you to configure protocol recognition for network protection against exploits of known vulnerabilities.\r\n\r\n If you enable or do not configure this setting, protocol recognition will be enabled.\r\n\r\n If you disable this setting, protocol recognition will be disabled.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-nis-disableprotocolrecognition"],"categoryId":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","categoryName":"Network Inspection System","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_nis_disableprotocolrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},"f3d260dfa9730711":{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2","displayName":"Tape Drives: Deny write access","description":"This policy setting denies write access to the Tape Drive removable storage class.\r\n\r\nIf you enable this policy setting, write access is denied to this removable storage class.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to this removable storage class.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-tapedrives-denywrite-access-2"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_removablestorage_tapedrives_denywrite_access_2_1","displayName":"Enabled","description":null,"helpText":null}]},"f30e58ef9e127745":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred","displayName":"Configure H.264/AVC hardware encoding for Remote Desktop Connections","description":"This policy setting lets you enable H.264/AVC hardware encoding support for Remote Desktop Connections. When you enable hardware encoding, if an error occurs, we will attempt to use software encoding. If you disable or do not configure this policy, we will always use software encoding.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-server-avc-hw-encode-preferred"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_server_avc_hw_encode_preferred_1","displayName":"Enabled","description":null,"helpText":null}]},"f3e095aee1d603be":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2","displayName":"Start a program on connection","description":"Configures Remote Desktop Services to run a specified program automatically upon connection.\r\n\r\nYou can use this setting to specify a program to run automatically when a user logs on to a remote computer.\r\n\r\nBy default, Remote Desktop Services sessions provide access to the full Windows desktop, unless otherwise specified with this setting, by the server administrator, or by the user in configuring the client connection. Enabling this setting overrides the \"Start Program\" settings set by the server administrator or user. The Start menu and Windows Desktop are not displayed, and when the user exits the program the session is automatically logged off.\r\n\r\nTo use this setting, in Program path and file name, type the fully qualified path and file name of the executable file to be run when the user logs on. If necessary, in Working Directory, type the fully qualified path to the starting directory for the program. If you leave Working Directory blank, the program runs with its default working directory. If the specified program path, file name, or working directory is not the name of a valid directory, the RD Session Host server connection fails with an error message.\r\n\r\nIf the status is set to Enabled, Remote Desktop Services sessions automatically run the specified program and use the specified Working Directory (or the program default directory, if Working Directory is not specified) as the working directory for the program.\r\n\r\nIf the status is set to Disabled or Not Configured, Remote Desktop Services sessions start with the full desktop, unless the server administrator or user specify otherwise. (See \"Computer Configuration\\Administrative Templates\\System\\Logon\\Run these programs at user logon\" setting.)\r\n\r\nNote: This setting appears in both Computer Configuration and User Configuration. If both settings are configured, the Computer Configuration setting overrides.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-terminalserver#admx-terminalserver-ts-start-program-2"],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_start_program_2_1","displayName":"Enabled","description":null,"helpText":null}]},"f341e26e6ec01fd5":{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification","displayName":"Turn off toast notifications","description":"\n This policy setting turns off toast notifications for applications.\n\n If you enable this policy setting, applications will not be able to raise toast notifications.\n\n Note that this policy does not affect taskbar notification balloons.\n\n Note that Windows system features are not affected by this policy. You must enable/disable system features individually to stop their ability to raise toast notifications.\n\n If you disable or do not configure this policy setting, toast notifications are enabled and can be turned off by the administrator or user.\n\n No reboots or service restarts are required for this policy setting to take effect.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-notoastnotification"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_wpn_notoastnotification_1","displayName":"Enabled","description":null,"helpText":null}]},"f3e6ada50c22fc4f":{"id":"device_vendor_msft_policy_config_browser_enterprisemodesitelist","displayName":"Enterprise Mode Site List","description":"This setting lets you configure whether your company uses Enterprise Mode and the Enterprise Mode Site List to address common compatibility problems with legacy websites.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#enterprisemodesitelist"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":null},"f35d7b3b02de3264":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist","displayName":"Configure list of force-installed Web Apps","description":"Setting the policy specifies a list of web apps that install silently, without user interaction, and which users can't uninstall or turn off.\r\n\r\nEach list item of the policy is an object with a mandatory member:\r\nurl (the URL of the web app to install)\r\n\r\nand 5 optional members:\r\n- default_launch_container\r\n(for how the web app opens—a new tab is the default)\r\n\r\n- create_desktop_shortcut\r\n(True if you want to create Linux and\r\nMicrosoft® Windows® desktop shortcuts).\r\n\r\n- fallback_app_name\r\n(Starting with Google Chrome version 90,\r\nallows you to override the app name if it is not a\r\nProgressive Web App (PWA), or the app name that is temporarily\r\ninstalled if it is a PWA but authentication is required before the\r\ninstallation can be completed. If both\r\ncustom_name and\r\nfallback_app_name are provided,\r\nthe latter will be ignored.)\r\n\r\n- custom_name\r\n(Starting with Google Chrome\r\nversion 96, allows you to permanently override the app name for all web\r\napps and PWAs. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\n- custom_icon\r\n(Starting with Google Chrome\r\nversion 96, allows you to override the app icon of installed apps. The\r\nicons have to be square, maximal 1 MB in size, and in one of the following\r\nformats: jpeg, png, gif, webp, ico. The hash value has to be the SHA256\r\nhash of the icon file. Currently only supported on\r\nGoogle Chrome OS.)\r\n\r\nSee PinnedLauncherApps for pinning apps to the Google Chrome OS shelf.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=WebAppInstallForceList for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"url\": \"https://www.google.com/maps\",\r\n \"default_launch_container\": \"window\",\r\n \"create_desktop_shortcut\": true\r\n },\r\n {\r\n \"url\": \"https://docs.google.com\",\r\n \"default_launch_container\": \"tab\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/editor\",\r\n \"default_launch_container\": \"window\",\r\n \"fallback_app_name\": \"Editor\"\r\n },\r\n {\r\n \"url\": \"https://docs.google.com/sheets\",\r\n \"default_launch_container\": \"window\",\r\n \"custom_name\": \"Spreadsheets\"\r\n },\r\n {\r\n \"url\": \"https://weather.example.com\",\r\n \"custom_icon\": {\r\n \"url\": \"https://mydomain.example.com/sunny_icon.png\",\r\n \"hash\": \"c28f469c450e9ab2b86ea47038d2b324c6ad3b1e9a4bd8960da13214afd0ca38\"\r\n }\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_webappinstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"f36ef10ddd8288b8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled","displayName":"Disable Developer Tools","description":"This policy is deprecated. Its usage is discouraged. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_developertoolsdisabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f31cb469a093592c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist","displayName":"Configure the list of force-installed apps and extensions","description":"Setting the policy specifies a list of apps and extensions that install silently, without user interaction, and which users can't uninstall or turn off. Permissions are granted implicitly, including for the enterprise.deviceAttributes and enterprise.platformKeys extension APIs. (These 2 APIs aren't available to apps and extensions that aren't force-installed.)\r\n\r\nLeaving the policy unset means no apps or extensions are autoinstalled, and users can uninstall any app or extension in Google Chrome.\r\n\r\nThis policy superseeds ExtensionInstallBlocklist policy. If a previously force-installed app or extension is removed from this list, Google Chrome automatically uninstalls it.\r\n\r\nOn Microsoft® Windows® instances, apps and extensions from outside the Chrome Web Store can only be forced installed if the instance is joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management.\r\n\r\nOn macOS instances, apps and extensions from outside the Chrome Web Store can only be force installed if the instance is managed via MDM, or joined to a domain via MCX.\r\n\r\nThe source code of any extension may be altered by users through developer tools, potentially rendering the extension dysfunctional. If this is a concern, set the DeveloperToolsDisabled policy.\r\n\r\nEach list item of the policy is a string that contains an extension ID and, optionally, an \"update\" URL separated by a semicolon (;). The extension ID is the 32-letter string found, for example, on chrome://extensions when in Developer mode. If specified, the \"update\" URL should point to an Update Manifest XML document ( https://developer.chrome.com/extensions/autoupdate ). By default, the Chrome Web Store's update URL is used. The \"update\" URL set in this policy is only used for the initial installation; subsequent updates of the extension use the update URL in the extension's manifest.\r\n\r\n Note: This policy doesn't apply to Incognito mode. Read about hosting extensions ( https://developer.chrome.com/extensions/hosting ).\r\n\r\nExample value:\r\n\r\naaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa;https://clients2.google.com/service/update2/crx\r\nabcdefghijklmnopabcdefghijklmnop","helpText":"","infoUrls":[],"categoryId":"216de445-a80d-4981-b151-3b4466edc808","categoryName":"Extensions","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~extensions_extensioninstallforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"f3bec7309a03c210":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled","displayName":"Enable QR Code Generator","description":"This policy enables the QR Code generator feature in Google Chrome.\r\n\r\nIf you enable this policy or don't configure it, the QR Code Generator feature is enabled.\r\n\r\nIf you disable this policy, the QR Code Generator feature is disabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_qrcodegeneratorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f3b82b5dc91f10c6":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings","displayName":"Settings for Gemini integration","description":"This setting allows Gemini app integrations.\r\n\r\n0/unset = Gemini integration will be available for users.\r\n\r\n1 = Gemini integration will not be available for users.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information, please check the Help Center article https://support.google.com/chrome/a?p=gemini_in_chrome.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_geminisettings_1","displayName":"Enabled","description":null,"helpText":null}]},"f3123c21bd6725af":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC","description":"This policy allows controlling post-quantum key agreement for WebRTC.\r\n\r\nIf this policy is set to Enabled, post-quantum key agreement would be offered for\r\nWebRTC.\r\n\r\nIf this policy is set to Disabled, post-quantum key agreement would not be offered\r\nfor WebRTC.\r\n\r\nIf this policy is not set, the value would be set by the default rollout process\r\nfor post-quantum key agreement offered for WebRTC.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing DTLS\r\npeers and networking middleware are expected to ignore the new option and\r\ncontinue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement DTLS may malfunction when\r\noffered the new option. For example, they may disconnect in response to\r\nunrecognized options or the resulting larger messages. Such devices are not\r\npost-quantum-ready and will interfere with an enterprise's post-quantum\r\ntransition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed after some milestones.","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},"f366eaeff0addb76":{"id":"device_vendor_msft_policy_config_credentialproviders_blockpicturepassword","displayName":"Turn off picture password sign-in","description":"This policy setting allows you to control whether a domain user can sign in using a picture password.\n\nIf you enable this policy setting, a domain user can't set up or sign in with a picture password. \n\nIf you disable or don't configure this policy setting, a domain user can set up and use a picture password.\n\nNote that the user's domain password will be cached in the system vault when using this feature.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-credentialproviders#credentialproviders-blockpicturepassword"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_credentialproviders_blockpicturepassword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_credentialproviders_blockpicturepassword_1","displayName":"Enabled","description":null,"helpText":null}]},"f33f4d180ca74053":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcisdynamicvhd","displayName":"Is Dynamic (VHD)","description":"[ENABLED BY DEFAULT]\r\n\r\nVHD(x) containers will be dynamically allocated. VHD(x) file size will grow as data is added to the VHD(x). If disabled, VHD(x) containers that are auto-created will be fully allocated.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\IsDynamic\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","categoryName":"ODFC Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcisdynamicvhd_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc_odfcisdynamicvhd_1","displayName":"Enabled","description":null,"helpText":null}]},"f3ddfce1bdf87d69":{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions","displayName":"Secure Protocol combinations","description":"","helpText":"","infoUrls":[],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_0","displayName":"Use no secure protocols","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_8","displayName":"Only use SSL 2.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_32","displayName":"Only use SSL 3.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_40","displayName":"Use SSL 2.0 and SSL 3.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_128","displayName":"Only use TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_136","displayName":"Use SSL 2.0 and TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_160","displayName":"Use SSL 3.0 and TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_168","displayName":"Use SSL 2.0, SSL 3.0, and TLS 1.0","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_512","displayName":"Only use TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_520","displayName":"Use SSL 2.0 and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_544","displayName":"Use SSL 3.0 and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_552","displayName":"Use SSL 2.0, SSL 3.0, and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_640","displayName":"Use TLS 1.0 and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_648","displayName":"Use SSL 2.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_672","displayName":"Use SSL 3.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_680","displayName":"Use SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.1","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2048","displayName":"Only use TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2056","displayName":"Use SSL 2.0 and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2080","displayName":"Use SSL 3.0 and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2088","displayName":"Use SSL 2.0, SSL 3.0, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2176","displayName":"Use TLS 1.0 and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2184","displayName":"Use SSL 2.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2208","displayName":"Use SSL 3.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2216","displayName":"Use SSL 2.0, SSL 3.0, TLS 1.0, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2560","displayName":"Use TLS 1.1 and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2568","displayName":"Use SSL 2.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2592","displayName":"Use SSL 3.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2600","displayName":"Use SSL 2.0, SSL 3.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2688","displayName":"Use TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2696","displayName":"Use SSL 2.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2720","displayName":"Use SSL 3.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_2728","displayName":"Use SSL 2.0, SSL 3.0, TLS 1.0, TLS 1.1, and TLS 1.2","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_8192","displayName":"Only use TLS 1.3","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10240","displayName":"Use TLS 1.2 and TLS 1.3","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10752","displayName":"Use TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10880","displayName":"Use TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_disableencryptionsupport_advanced_wininetprotocoloptions_10912","displayName":"Use SSL 3.0, TLS 1.0, TLS 1.1, TLS 1.2, and TLS 1.3","description":null,"helpText":null}]},"f3d43a32ec004280":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c","displayName":"Allow VBScript to run in Internet Explorer","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneallowvbscripttorunininternetexplorer_iz_partname140c_1","displayName":"Prompt","description":null,"helpText":null}]},"f30bfb89018131fd":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowlessprivilegedsites"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"f397ab31c63973a6":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed","displayName":"Allow full screen mode","description":"Set the availability of full screen mode - all Microsoft Edge UI is hidden and only web content is visible.\r\n\r\nIf you enable this policy or don't configure it, the user, apps, and extensions with appropriate permissions can enter full screen mode.\r\n\r\nIf you disable this policy, users, apps, and extensions can't enter full screen mode.\r\n\r\nOpening Microsoft Edge in kiosk mode using the command line is unavailable when full screen mode is disabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_fullscreenallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"f349d336eab0eb4e":{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls","displayName":"Automatically grant permission to these sites to connect to HID devices containing top-level collections with the given HID usage","description":"This setting allows you to list the URLs that specify which sites are automatically granted permission to access a HID device containing a top-level collection with the given HID usage.\r\n\r\nEach item in the list requires both usages and urls fields for the policy to be valid.\r\n\r\n * Each item in the usages field must have a usage_page and may have a usage field.\r\n\r\n * Omitting the usage field will create a policy matching any device containing a top-level collection with a usage from the specified usage page.\r\n\r\n * An item which has a usage field without a usage_page field is invalid and is ignored.\r\n\r\nIf you don't set this policy, that means 'DefaultWebHidGuardSetting' (Control use of the WebHID API) applies, if it's set. If not, the user's personal setting applies.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. * is not an accepted value for this policy.\r\n\r\nURLs in this policy shouldn't conflict with those configured through 'WebHidBlockedForUrls' (Block the WebHID API on these sites). If they do, this policy takes precedence over 'WebHidBlockedForUrls'.\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"urls\": [\r\n \"https://microsoft.com\",\r\n \"https://chromium.org\"\r\n ],\r\n \"usages\": [\r\n {\r\n \"usage\": 5678,\r\n \"usage_page\": 1234\r\n }\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev109~policy~microsoft_edge~contentsettings_webhidallowdeviceswithhidusagesforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"f3e5e642d96c917f":{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab","displayName":"Set the default New Tab Page feed tab to Work or Discover (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_0","displayName":"Work","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev148~policy~microsoft_edge~startup_setntpdefaultfeedtab_setntpdefaultfeedtab_1","displayName":"Discover","description":null,"helpText":null}]},"f3486a54a52e979d":{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting","displayName":"Control use of the Serial API","description":"\r\nSet whether websites can access serial ports. You can completely block access or ask the user each time a website wants to get access to a serial port.\r\n\r\nSetting the policy to 3 lets websites ask for access to serial ports. Setting the policy to 2 denies access to serial ports.\r\n\r\nYou can override this policy for specific URL patterns by using the 'SerialAskForUrls' (Allow the Serial API on specific sites) and 'SerialBlockedForUrls' (Block the Serial API on specific sites) policies.\r\n\r\nIf you don't configure this policy, by default, websites can ask users whether they can access a serial port, and users can change this setting.\r\n\r\nPolicy options mapping:\r\n\r\n* BlockSerial (2) = Do not allow any site to request access to serial ports via the Serial API\r\n\r\n* AskSerial (3) = Allow sites to ask for user permission to access a serial port\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_defaultserialguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"f3af7dd76d94c471":{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode","displayName":"Redirect incompatible sites from Internet Explorer to Microsoft Edge","description":"This setting lets you specify whether Internet Explorer will redirect navigations to sites that require a modern browser to Microsoft Edge.\r\n\r\nIf you don't configure this policy or set it to 'Sitelist', beginning in M87, Internet Explorer will redirect sites that require a modern browser to Microsoft Edge.\r\n\r\nMicrosoft provides a list of public sites that require such redirection, such as https://mail.yahoo.com.\r\n\r\nWhen a site is redirected from Internet Explorer to Microsoft Edge, the Internet Explorer tab that began loading that site is closed if it had no prior content. Otherwise, it is navigated to a Microsoft help page explaining why the site was redirected to Microsoft Edge.\r\n\r\nWhen Microsoft Edge is launched to load a site from IE, an information bar is shown to the user explaining that the site works best in a modern browser.\r\n\r\nIf you set this policy to 'Disable', Internet Explorer will not redirect any traffic to Microsoft Edge.\r\n\r\nFor more information about this policy see https://go.microsoft.com/fwlink/?linkid=2141715\r\n\r\nPolicy options mapping:\r\n\r\n* Disable (0) = Disable\r\n\r\n* Sitelist (1) = Redirect sites based on the incompatible sites sitelist\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_redirectsitesfrominternetexplorerredirectmode_1","displayName":"Enabled","description":null,"helpText":null}]},"f3e496a2fc7f4919":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_pptviewexe186","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_pptviewexe186_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_blockpopups_l_pptviewexe186_1","displayName":"True","description":null,"helpText":null}]},"f3804f2bcab379de":{"id":"device_vendor_msft_policy_config_tenantrestrictions_configuretenantrestrictions_payloadcloudid","displayName":"Cloud ID (optional):","description":"","helpText":"","infoUrls":[],"categoryId":"90e3acc6-80d5-41b4-8141-a8620a211c0e","categoryName":"Tenant Restrictions","options":null},"f3b31e376e924459":{"id":"device_vendor_msft_policy_config_update_engagedrestarttransitionschedule","displayName":"Engaged Restart Transition Schedule","description":"For Quality Updates, this policy specifies the timing before transitioning from Auto restarts scheduled outside of active hours to Engaged restart, which requires the user to schedule. The period can be set between 2 and 30 days from the time the restart becomes pending. Value type is integer. Default value is 7 days. Supported value range: 2 - 30. If you disable or do not configure this policy, the default behaviors will be used. If any of the following policies are configured, this policy has no effect:No auto-restart with logged on users for scheduled automatic updates installationsAlways automatically restart at scheduled timeSpecify deadline before auto-restart for update installation","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#engagedrestarttransitionschedule"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"f328b8bb819add8e":{"id":"keyboardsettings_allowautocorrection","displayName":"Allow Auto Correction","description":"If `false`, disables auto-correction.","helpText":null,"infoUrls":[],"categoryId":"dba26132-cba6-4178-93c3-f02476532f08","categoryName":"Keyboard Settings","options":[{"id":"keyboardsettings_allowautocorrection_false","displayName":"False","description":null,"helpText":null},{"id":"keyboardsettings_allowautocorrection_true","displayName":"True","description":null,"helpText":null}]},"f3e74c578b39ea5a":{"id":"plugin_filter","displayName":"Filter","description":"Settings that control authentication.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"f3e6baef3778f834":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_pathcolon23","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"f3654d958e75c5fa":{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_disableclose","displayName":"Prohibit closing items (User)","description":"Prevents users from removing Web content from their Active Desktop.\r\n\r\nIn Active Desktop, you can add items to the desktop but close them so they are not displayed.\r\n\r\nIf you enable this setting, items added to the desktop cannot be closed; they always appear on the desktop. This setting removes the check boxes from items on the Web tab in Display in Control Panel.\r\n\r\nNote: This setting does not prevent users from deleting items from their Active Desktop.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-desktop#admx-desktop-sz-atc-disableclose"],"categoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","categoryName":"Desktop","options":[{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_disableclose_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_desktop_sz_atc_disableclose_1","displayName":"Enabled","description":null,"helpText":null}]},"f3f6df6fb74b3557":{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoncloudcandidate","displayName":"Turn on cloud candidate (User)","description":"This policy setting controls the cloud candidates feature, which uses an online service to provide input suggestions that don't exist in a PC's local dictionary.\r\n\r\nIf you enable this policy setting, the functionality associated with this feature is turned on, the user's keyboard input is sent to Microsoft to generate the suggestions, and the user won't be able to turn it off.\r\n\r\nIf you disable this policy setting, the functionality associated with this feature is turned off, and the user won't be able to turn it on.\r\n\r\nIf you don't configure this policy setting, it will be turned off by default, and the user can turn on and turn off the cloud candidates feature.\r\n\r\nThis Policy setting applies to Microsoft CHS Pinyin IME and JPN IME.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eaime#admx-eaime-l-turnoncloudcandidate"],"categoryId":"7d331987-7e2d-4975-b23b-d99a5af26ddf","categoryName":"IME","options":[{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoncloudcandidate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_eaime_l_turnoncloudcandidate_1","displayName":"Enabled","description":null,"helpText":null}]},"f3d2e45259aeae12":{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_extendview","displayName":"Extended View (Web View) (User)","description":"Permits or prohibits use of this snap-in.\n\nIf you enable this setting, the snap-in is permitted. If you disable the setting, the snap-in is prohibited.\n\nIf this setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted.\n\n To explicitly permit use of this snap-in, enable this setting. If this setting is not configured (or disabled), this snap-in is prohibited.\n\n-- If \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited.\n\n To explicitly prohibit use of this snap-in, disable this setting. If this setting is not configured (or enabled), the snap-in is permitted.\n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmc#admx-mmc-mmc-extendview"],"categoryId":"756d2b0b-5f06-45e7-b5c5-c066deb5ed2f","categoryName":"Extension snap-ins","options":[{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_extendview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmc_mmc_extendview_1","displayName":"Enabled","description":null,"helpText":null}]},"f30db9dbb2a7afb1":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_remstore","displayName":"Removable Storage (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-remstore"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_remstore_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_remstore_1","displayName":"Enabled","description":null,"helpText":null}]},"f37c2bdfe7f90139":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup","displayName":"PowerPoint 2013 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft PowerPoint 2013.\r\nMicrosoft PowerPoint 2013 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft PowerPoint 2013 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft PowerPoint 2013 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft PowerPoint 2013 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013powerpointbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013powerpointbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"f31b06d13a03a098":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup","displayName":"Word 2016 backup only (User)","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Word 2016.\r\nMicrosoft Word 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Word 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Word 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Word 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016wordbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016wordbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"f3118d7dc22ac758":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime","displayName":"Browsing Data Lifetime Settings (User)","description":"Configures browsing data lifetime settings for Google Chrome. This policy allows admins to configure (per data-type) when data is deleted by the browser. This is useful for customers that work with sensitive customer data. The policy will only take effect if SyncDisabled is set to true.\r\n\r\nThe available data types are 'browsing_history', 'download_history', 'cookies_and_other_site_data', 'cached_images_and_files', 'password_signin', 'autofill', 'site_settings' and 'hosted_app_data'.\r\n\r\nThe browser will automatically remove data of selected types that is older than 'time_to_live_in_hours'. The minimum value that can be set is 1 hour.\r\n\r\nThe deletion of expired data will happen 15 seconds after the browser starts then every hour while the browser is running.\r\nSee https://cloud.google.com/docs/chrome-enterprise/policies/?policy=BrowsingDataLifetime for more information about schema and formatting.\r\n\r\n\r\nExample value:\r\n\r\n[\r\n {\r\n \"time_to_live_in_hours\": 24,\r\n \"data_types\": [\r\n \"browsing_history\"\r\n ]\r\n },\r\n {\r\n \"time_to_live_in_hours\": 12,\r\n \"data_types\": [\r\n \"password_signin\",\r\n \"autofill\"\r\n ]\r\n }\r\n]","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_browsingdatalifetime_1","displayName":"Enabled","description":null,"helpText":null}]},"f3ab964a3bffc364":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist","displayName":"Clear Browsing Data on Exit (User)","description":"Configures a list of browsing data types that should be deleted when the user closes all browser windows. The available data types are browsing history (browsing_history), download history (download_history), cookies (cookies_and_other_site_data), cache(cached_images_and_files), autofill (autofill), passwords (password_signin), site settings (site_settings) and hosted apps data (hosted_app_data). This policy does not take precedence over AllowDeletingBrowserHistory.\r\n\r\nThis policy requires the SyncDisabled policy to be set to true, otherwise it will be ignored. If this policy is set at platform level, Sync should be disabled at platform level. If this policy is set at user level, Sync should be disabled for that user in order for this policy to take effect.\r\n\r\nIf Google Chrome does not exit cleanly (for example, if the browser or the OS crashes), the browsing data will be cleared the next time the profile is loaded.\r\n\r\nExample value:\r\n\r\nbrowsing_history\r\ndownload_history\r\ncookies_and_other_site_data\r\ncached_images_and_files\r\npassword_signin\r\nautofill\r\nsite_settings\r\nhosted_app_data","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_1","displayName":"Enabled","description":null,"helpText":null}]},"f37f0f64501e65c4":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policyrefreshrate_policyrefreshrate","displayName":"Refresh rate for user policy: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"f3c11224c77e4ecc":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled","displayName":"Enable or disable spell checking web service (User)","description":"Setting the policy to Enabled puts a Google web service in use to help resolve spelling errors. This policy only controls the use of the online service. Setting the policy to Disabled means this service is never used.\r\n\r\nLeaving the policy unset lets users choose whether to use the spellcheck service.\r\n\r\nThe spell check can always use a downloaded dictionary locally unless the feature is disabled by SpellcheckEnabled in which case this policy will have no effect.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_spellcheckserviceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f331844fccc4bd29":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled","displayName":"Enable PAC URL stripping (for https://) (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_pachttpsurlstrippingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f3c26f562b254167":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement","displayName":"Enable post-quantum key agreement for WebRTC (User)","description":"This policy allows controlling post-quantum key agreement for WebRTC.\r\n\r\nIf this policy is set to Enabled, post-quantum key agreement would be offered for\r\nWebRTC.\r\n\r\nIf this policy is set to Disabled, post-quantum key agreement would not be offered\r\nfor WebRTC.\r\n\r\nIf this policy is not set, the value would be set by the default rollout process\r\nfor post-quantum key agreement offered for WebRTC.\r\n\r\nOffering a post-quantum key agreement is backwards-compatible. Existing DTLS\r\npeers and networking middleware are expected to ignore the new option and\r\ncontinue selecting previous options.\r\n\r\nHowever, devices that do not correctly implement DTLS may malfunction when\r\noffered the new option. For example, they may disconnect in response to\r\nunrecognized options or the resulting larger messages. Such devices are not\r\npost-quantum-ready and will interfere with an enterprise's post-quantum\r\ntransition. If encountered, administrators should contact the vendor for a fix.\r\n\r\nThis policy is a temporary measure and will be removed after some milestones.","helpText":"","infoUrls":[],"categoryId":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","categoryName":"Web Rtc settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~webrtc_webrtcpostquantumkeyagreement_1","displayName":"Enabled","description":null,"helpText":null}]},"f3c828b4b0b31b67":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1","displayName":"Save Excel files as (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_51","displayName":"Excel Workbook (*.xlsx)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_52","displayName":"Excel Macro-Enabled Workbook (*.xlsm)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_50","displayName":"Excel Binary Workbook (*.xlsb)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_44","displayName":"Web Page (*.htm; *.html)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_56","displayName":"Excel 97-2003 Workbook (*.xls)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_39","displayName":"Excel 5.0/95 Workbook (*.xls)","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_save_l_saveexcelfilesas_l_saveexcelfilesas1_60","displayName":"OpenDocument Spreadsheet (*.ods)","description":null,"helpText":null}]},"f3bb6794ff430376":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc04_l_pathcolon13","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"f329ada644fecfad":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_l_datecolon22","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":null},"f32b64cae140a822":{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview","displayName":"Turn off Compatibility View (User)","description":"This policy setting controls the Compatibility View feature, which allows the user to fix website display problems that he or she may encounter while browsing.\n\nIf you enable this policy setting, the user cannot use the Compatibility View button or manage the Compatibility View sites list.\n\nIf you disable or do not configure this policy setting, the user can use the Compatibility View button and manage the Compatibility View sites list.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecompatview"],"categoryId":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","categoryName":"Compatibility View","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecompatview_1","displayName":"Enabled","description":null,"helpText":null}]},"f33203ed1aba6bf5":{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation","displayName":"Prevent participation in the Customer Experience Improvement Program (User)","description":"This policy setting prevents the user from participating in the Customer Experience Improvement Program (CEIP).\n\nIf you enable this policy setting, the user cannot participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you disable this policy setting, the user must participate in the CEIP, and the Customer Feedback Options command does not appear on the Help menu.\n\nIf you do not configure this policy setting, the user can choose to participate in the CEIP.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disablecustomerexperienceimprovementprogramparticipation"],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disablecustomerexperienceimprovementprogramparticipation_1","displayName":"Enabled","description":null,"helpText":null}]},"f38685a0e6a1ead9":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"f3fd0a5be3a68ed3":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting","displayName":"Allow active scripting (User)","description":"This policy setting allows you to manage whether script code on pages in the zone is run.\n\nIf you enable this policy setting, script code on pages in the zone can run automatically. If you select Prompt in the drop-down box, users are queried to choose whether to allow script code on pages in the zone to run.\n\nIf you disable this policy setting, script code on pages in the zone is prevented from running.\n\nIf you do not configure this policy setting, script code on pages in the zone is prevented from running.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowactivescripting"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowactivescripting_1","displayName":"Enabled","description":null,"helpText":null}]},"f3c2767f60e82ce7":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts","displayName":"Configure the list of commands for which to disable keyboard shortcuts (User)","description":"Configure the list of Microsoft Edge commands for which to disable keyboard shortcuts.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2186950 for a list of possible commands to disable.\r\n\r\nIf you enable this policy, commands in the 'disabled' list will no longer be activated by keyboard shortcuts.\r\n\r\nIf you disable this policy, all keyboard shortcuts behave as usual.\r\n\r\nNote: Disabling a command will only remove its shortcut mapping. Commands in the 'disabled' list will still function if accessed via browser UI.\r\n\r\nExample value:\r\n\r\n{\r\n \"disabled\": [\r\n \"new_tab\",\r\n \"fullscreen\"\r\n ]\r\n}\r\n\r\n\r\nCompact example value:\r\n\r\n{\"disabled\": [\"new_tab\", \"fullscreen\"]}","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_configurekeyboardshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"f35cdc22e71df042":{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended","displayName":"Set the default \"share additional operating system region\" setting (User)","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\r\n\r\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\r\n\r\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\r\n\r\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\r\n\r\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\r\n\r\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\r\n\r\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\r\n\r\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\r\n\r\nPolicy options mapping:\r\n\r\n* Limited (0) = Limited\r\n\r\n* Always (1) = Always share the OS Regional format\r\n\r\n* Never (2) = Never share the OS Regional format\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev108~policy~microsoft_edge_recommended_defaultshareadditionalosregionsetting_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"f340b5dc3881feb7":{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled","displayName":"Manage opt-out user experience for Enhanced Security Mode (ESM) in Microsoft Edge (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy lets you manage whether the opt-out user experience for enhanced security mode is presented when ESM is turned on for Microsoft Edge.\r\n\r\nIf you enable or don't configure this policy, the UI for the opt-out user experience is on.\r\n\r\nIf you disable this policy, the UI for the opt-out user experience is off.\r\n\r\nNote: If this policy is used, only the User Interface for the opt-out experience is supressed - ESM is still turned on. For more information, see the 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) policy.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895.\r\n\r\nAfter careful evaluation, we have determined that this experimental opt-out UX is not required. As a result, this policy will be deprecated and stop working after Edge version 130.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev115~policy~microsoft_edge_enhancesecuritymodeoptoutuxenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f3a682ca1ac68813":{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled","displayName":"Enable saving passkeys to the password manager (User)","description":"This policy controls whether users can save passkeys in the built-in password manager. It does not limit access to, or change the contents of, passkeys already saved in the password manager.\r\n\r\nIf the PasswordManagerEnabled policy is Disabled, saving to the built-in password manager is disabled in general, including passkeys. In this case, this policy has no effect.\r\n\r\nIf this policy is enabled or not configured, users can save passkeys in the built-in password manager when signed in to Microsoft Edge.\r\n\r\nIf this policy is disabled, users cannot save new passkeys to the built-in password manager. Previously saved passkeys continue to work.","helpText":"","infoUrls":[],"categoryId":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","categoryName":"Password manager and protection","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev145~policy~microsoft_edge~passwordmanager_passwordmanagerpasskeysenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f3086863c964fd14":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled","displayName":"Enable Ambient Authentication for InPrivate and Guest profiles (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_0","displayName":"Enable ambient authentication in regular sessions only","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_1","displayName":"Enable ambient authentication in InPrivate and regular sessions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_2","displayName":"Enable ambient authentication in guest and regular sessions","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_ambientauthenticationinprivatemodesenabled_ambientauthenticationinprivatemodesenabled_3","displayName":"Enable ambient authentication in regular, InPrivate and guest sessions","description":null,"helpText":null}]},"f34a9650ccefc2b6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp","displayName":"Federated search for help (User)","description":"\r\n This policy setting allows you to determine the sources of content that Office users in your organization can access through Office Help (F1).\r\n\r\n If you enable or do not configure this policy setting, users who utilize Office Help see content from both Office and the Internet.\r\n\r\n If you disable this setting, Office users’ search results through Help are limited to Office content.\r\n ","helpText":"","infoUrls":[],"categoryId":"1942922a-cba9-44c8-871f-3d915c62bd06","categoryName":"Help","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_help_l_federatedsearchforhelp_1","displayName":"Enabled","description":null,"helpText":null}]},"f36f2a61fd8b8e6b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican","displayName":"Corsican (User)","description":"Enables the editing language Corsican","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_corsican_1","displayName":"Enabled","description":null,"helpText":null}]},"f35ddce1912b58db":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian","displayName":"Mongolian (Traditional Mongolian) (User)","description":"Enables the editing language Mongolian (Traditional Mongolian)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_mongoliantraditionalmongolian_1","displayName":"Enabled","description":null,"helpText":null}]},"f37ba394a8ab897c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowfriendly441","displayName":"Name of the document library to be shown the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"f30c766b1b5fb467":{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial","displayName":"Disable the tutorial that appears at the end of OneDrive Setup (User)","description":"This setting lets you prevent the tutorial from launching in a web browser at the end of OneDrive Setup.\r\n\r\nIf you enable this setting, users will not see the tutorial after they complete OneDrive Setup.\r\n\r\nIf you disable or do not configure this setting, the tutorial will appear at the end of OneDrive Setup.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_disablefretutorial_1","displayName":"Enabled","description":null,"helpText":null}]},"f33698855a433e32":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity","displayName":"Set sensitivity (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_setsensitivity_1","displayName":"Enabled","description":null,"helpText":null}]},"f3073dc06df08a98":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist","displayName":"Disable user entries to server list (User)","description":"This policy setting controls whether Outlook users can add entries to the list of SharePoint servers when establishing a meeting workspace. \r\n\r\nIf you enable this policy setting, you can choose between two options to determine whether Outlook users can add entries to the published server list: \r\n\r\n- Publish default, allow others. This option is the default configuration in Outlook. \r\n\r\n- Publish default, disallow others. This option prevents users from adding servers to the default published server list. \r\n\r\nIf you disable or do not configure this policy setting, when users create a meeting workspace, they can choose a server from a default list provided by administrators or manually enter the address of a server that is not listed. This is the equivalent of Enabled -- Publish default, allow others.","helpText":"","infoUrls":[],"categoryId":"f77040df-7dd2-4916-b6a0-5ef962686d4e","categoryName":"Meeting Workspace","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_meetingworkspace_l_disableuserentriestoserverlist_1","displayName":"Enabled","description":null,"helpText":null}]},"f3044db7b246edb5":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong","displayName":"Reduce the end time of long appointments and meetings by a specified number of minutes (User)","description":"\r\n This policy setting allows you to specify how many minutes to reduce the end time of a long appointment or meeting by when a user creates an appointment or meeting. A long appointment or meeting is one that lasts for one hour or longer.\r\n\r\n If you enable this policy setting, you specify the number of minutes to reduce the end time of a long appointment or meeting by when a user creates an appointment or meeting. The user won’t be able to change this value by going to File > Options > Calendar.\r\n\r\n Note: You should also enable the “End appointments and meetings early” policy setting\r\n\r\n If you disable or don’t configure this policy setting, the default value of 10 minutes is used or whatever the user specifies by going to File > Options > Calendar.\r\n\r\n Note: This policy setting only applies to subscription versions of Office, such as Office 365 ProPlus.\r\n ","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_endearlylong_1","displayName":"Enabled","description":null,"helpText":null}]},"f30c06f8274be64a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomaddressaccess_v2_l_oomaddressaccess_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},"f3fd6fd3d11f85b0":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oomsaveas_v2_l_oomsaveas_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},"f3fe104ef630cedd":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts","displayName":"Prevent adding non-default Exchange accounts (User)","description":"This policy allows you to prevent users from adding non-default Exchange accounts to existing Outlook profiles.\r\n\r\nIf you enable this policy setting, you will prevent users from adding non-default Exchange accounts via the Add New E-mail Account wizard.\r\n\r\nIf you disable or do not configure this policy setting, users can add non-default Exchange accounts to existing Outlook profiles.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_preventnondefaultexchangeaccounts_1","displayName":"Enabled","description":null,"helpText":null}]},"f34183f75bb12255":{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle","displayName":"Saving messages sent from a shared mailbox to the Sent Items folder (User)","description":"This policy setting controls whether messages sent from a shared mailbox are saved to the Sent Items folder of the shared mailbox.\r\n\r\nBy default, messages sent from a shared mailbox aren't saved to the Sent Items folder of the shared mailbox.\r\n\r\nIf you enable this policy setting, messages sent from a shared mailbox will be saved to the Sent Items folder of the shared mailbox.\r\n\r\nIf you disable or don’t configure this policy setting, messages sent from a shared mailbox won’t be saved to the Sent Items folder of the shared mailbox.","helpText":"","infoUrls":[],"categoryId":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","categoryName":"Delegates","options":[{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v7~policy~l_microsoftofficeoutlook~l_outlookoptions~l_delegates_l_delegatesentitemsstyle_1","displayName":"Enabled","description":null,"helpText":null}]},"f31e83d2afebfc3e":{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum","displayName":"When installing drivers for a new connection: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","categoryName":"Printers","options":[{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum_0","displayName":"Show warning and elevation prompt","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_printers_pointandprintrestrictions_user_pointandprint_nowarningnoelevationoninstall_enum_1","displayName":"Show warning only","description":null,"helpText":null}]},"f3d03abd3883f2a1":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours","displayName":"Hours (User)","description":"Sets the label for hours.\r\n \r\nIf you enable this setting, hours are displayed with the specified label.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"06c4a76a-805b-4370-9d80-08e720ab2305","categoryName":"View options for time units in 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjedit~l_pjviewoptions_l_pjhours_1","displayName":"Enabled","description":null,"helpText":null}]},"f3c54d38ed9776c9":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_custom_l_disablecommandbarbuttonsandmenuitems1_l_enteracommandbaridtodisable","displayName":"Enter a command bar ID to disable (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e4deef0-4528-47d5-8869-4143c506f18b","categoryName":"Custom","options":null},"f3bab2fb18ce0421":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_l_pathcolon44","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null},"f3a6d8fd4f9c5593":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc12_l_descriptioncolon62","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/f8.json b/public/intune-definitions/f8.json index 56ef4204b3a2..bfbc5a63eb97 100644 --- a/public/intune-definitions/f8.json +++ b/public/intune-definitions/f8.json @@ -1 +1 @@ -{"f8e6d7b08238b351":{"id":"com.apple.applicationaccess_allowautomaticappdownloads","displayName":"Allow Automatic App Downloads","description":"If false, prevents automatic downloading of apps purchased on other devices. This setting doesn’t affect updates to existing apps. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautomaticappdownloads_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautomaticappdownloads_true","displayName":"True","description":null,"helpText":null}]},"f8a4ccca9b66777d":{"id":"com.apple.applicationaccess_allowimageplayground","displayName":"Allow Image Playground (Deprecated)","description":"If false, prohibits the use of image generation.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowimageplayground_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowimageplayground_true","displayName":"True","description":null,"helpText":null}]},"f842428ae0aad8b7":{"id":"com.apple.assetcache.managed_peerlistenranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerlistenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},"f84a3882bd66b1c3":{"id":"com.apple.dock_persistent-apps_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},"f8ba294e51da7385":{"id":"com.apple.extensiblesso_platformsso_nonplatformssoaccounts","displayName":"Non Platform SSO Accounts","description":"The list of local accounts that are not subject to the 'FileVaultPolicy', 'LoginPolicy', or 'UnlockPolicy'. The accounts are also not prompted to register for Platform SSO.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"f85db409951203d4":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"f812b7686293e17e":{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_url","displayName":"URL","description":"The URL for the quick link.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"f8c1f4abbe263cd1":{"id":"com.apple.managedclient.preferences_smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings","description":"Configure the list of Microsoft Defender SmartScreen trusted domains. This means:\nMicrosoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\nThe Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\n\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender Advanced Threat Protection. You must configure your allow and block lists in Microsoft Defender Security Center instead.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreenallowlistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"f805dafe30c3c3a4":{"id":"com.apple.systemconfiguration_proxies_gopherenable","displayName":"Gopher Enable","description":"If true, enables gopher proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_gopherenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_gopherenable_1","displayName":"True","description":null,"helpText":null}]},"f813382d45fc2e97":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowlist","displayName":"Allow media autoplay on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\n\nIf you don't configure this policy, the global default value from the \"AutoplayAllowed\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nNote: * is not an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"f88126bc464c2598":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting","displayName":"Default images setting","description":"Set whether websites can display images. You can allow images on all sites ('AllowImages') or block them on all sites ('BlockImages').\n\nIf you don't configure this policy, images are allowed by default, and the user can change this setting.\n\nPolicy options mapping:\n\n* AllowImages (1) = Allow all sites to show all images\n\n* BlockImages (2) = Don't allow any site to show images\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting_allowimages","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting_blockimages","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},"f89f9378745b5c69":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled","displayName":"Show the Reload in Internet Explorer mode button in the toolbar","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button is only shown on the toolbar when the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy is enabled or if the user chose to enable \"Allow sites to be reloaded in Internet Explorer mode\".\n\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\n\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f84b822092217e6f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.popupsallowedforurls","displayName":"Allow pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that can open pop-up windows. Wildcards (*) are allowed.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"f8363a982ad33480":{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxyoverriderules","displayName":"Proxy override rules","description":"This policy enables rule-based proxy selection that determines which proxy Microsoft Edge uses based on the destination URL and any other conditions you define.\n\nWhen this policy is configured, it takes precedence over proxy settings configured by the ProxySettings policy, the Edge.proxy extension API, and any manual user settings.\n\nIf this policy is disabled or not configured, existing proxy policies and user-defined settings continue to apply.\n\nWhen Edge selects a proxy, it evaluates entries in the ProxyOverrideRules policy in order. A rule is considered a match when all the following conditions are met:\n* At least one URL pattern in DestinationMatchers is matched.\n* No URL pattern in ExcludeDestinationMatchers is matched.\n* If Conditions is specified and non-empty, all conditions are satisfied.\n\nFor a matching rule, the value specified in ProxyList is used as the proxy. If no rule matches, proxy selection falls back to the settings defined by the ProxySettings policy.\n\nThe URL patterns supported by DestinationMatchers and ExcludeDestinationMatchers are documented at https://review.learn.microsoft.com/en-us/DeployEdge/configure-microsoft-edge-proxy-support?branch=pr-en-us-6681#proxy-config-url-patterns .\nEntries in ProxyList correspond to PAC-style proxy strings, such as:\n* DIRECT\n* PROXY host:port\n* HTTPS host:port\n* SOCKS4 host:port\n* SOCKS5 host:port\n\nAlternatively, URL-form proxy specifiers can be used, for example:\n* http://host :port\n* https://host :port\n* socks4://host:port\n* socks5://host:port\n\nThe first reachable proxy in the list is used. Invalid entries are ignored.\n\nThe Conditions field specifies conditions that must all be met for an override rule to be applied when selecting a proxy. If this field is not set, the rule is applied when at least one host in DestinationMatchers matches.\n\nThe DnsProbe condition checks whether the specified DNS Host can be resolved to an IP address. The host must include a hostname (for example, example.com) and can optionally include a scheme or port (for example, https://example.com, example.com:123, or https://example.com:123). When a secure scheme (for example, https) is specified, the DNS lookup may also request the HTTPS record (see RFC 9460).\n\nIf Result is set to resolved, the condition is met when resolution succeeds. If set to not_found, the condition is met only when resolution fails.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},"f83f72ecdbbbccdf":{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallforcelist","displayName":"Configure list of force-installed Web Apps","description":"Setting the policy specifies a list of web apps that install silently, without user interaction. Users can't turn off the policy or uninstall these web apps.\n\nEach list item of the policy is an object with a mandatory member:\nurl (the URL of the web app to install)\n\nand 6 optional members:\n- default_launch_container\n(for how the web app opens—a new tab is the default)\n\n- create_desktop_shortcut\n(True if you want to create Linux and\nMicrosoft Windows desktop shortcuts).\n\n- fallback_app_name\n(Starting with Microsoft Edge version 90,\nyou can permanently override the app name if it's not a Progressive Web App (PWA)\nor you can temporarily override the app name if authentication is required before\ninstallation can be completed. If both\ncustom_name and\nfallback_app_name are provided,\nthe latter is ignored.)\n\n- custom_name\n(Starting with Microsoft Edge version 112\non all desktop platforms, you can permanently override the app name for all\nweb apps and PWAs.)\n\n- custom_icon\n(Starting with Microsoft Edge version 112\non all desktop platforms, you can override the app icon of installed apps.\nThe icons have to be square, maximal 1 MB in size, and in one of the following formats:\njpeg, png, gif, webp, ico. The hash value has to be the SHA256 hash of the icon file.\nThe url should be accessible without authentication to\nensure that the icon can be used upon app installation.)\n\n- install_as_shortcut\n(Starting with Microsoft Edge\nversion 107). If enabled, the given url is installed as a shortcut,\nas if done via the \"Create Shortcut...\" option in the desktop browser GUI.\nWhen installed as a shortcut, it won't be updated if the manifest in url changes.\nIf disabled or unset, the web app at the given url is installed normally.\n(This isn't currently supported in Microsoft Edge.)\n\nThe 'WebAppInstallByUserEnabled' policy doesn't affect this policy. Web apps specified by this policy are installed regardless of the 'WebAppInstallByUserEnabled' policy setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"f82a6b3d03742a64":{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionmaxblocktime","displayName":"Remote Encryption Protection Max Block Time","description":"Set the maximum time an IP address is blocked by Remote Encryption Protection. After this time, blocked IP addresses will be able to reinitiate connections. If set to 0, internal feature logic will determine blocking time.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"f8b3084eb8e2ac64":{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder","displayName":"ECC Curve Order","description":"This policy setting determines the priority order of ECC curves used with ECDHE cipher suites.\r\n\r\nIf you enable this policy setting, ECC curves are prioritized in the order specified.(Enter one Curve name per line)\r\n\r\nIf you disable or do not configure this policy setting, the default ECC curve order is used.\r\n\r\nDefault Curve Order\r\n============\r\ncurve25519\r\nNistP256\r\nNistP384\r\n\r\nTo See all the curves supported on the system, Use the following command:\r\n\r\nCertUtil.exe -DisplayEccCurve\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ciphersuiteorder#admx-ciphersuiteorder-sslcurveorder"],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":[{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_1","displayName":"Enabled","description":null,"helpText":null}]},"f871bfe9f086e132":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping","displayName":"IDN mapping","description":"Specifies whether the DNS client should convert internationalized domain names (IDNs) to the Nameprep form, a canonical Unicode representation of the string.\r\n\r\nIf this policy setting is enabled, IDNs are converted to the Nameprep form.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, IDNs are not converted to the Nameprep form.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-idnmapping"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping_1","displayName":"Enabled","description":null,"helpText":null}]},"f857ccff166a331d":{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_subscriptionmanager_listbox","displayName":"SubscriptionManagers","description":null,"helpText":"","infoUrls":[],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":null},"f812bde75239196f":{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2","displayName":"Use localized subfolder names when redirecting Start Menu and My Documents","description":"This policy setting allows the administrator to define whether Folder Redirection should use localized names for the All Programs, Startup, My Music, My Pictures, and My Videos subfolders when redirecting the parent Start Menu and legacy My Documents folder respectively.\r\n\r\nIf you enable this policy setting, Windows Vista, Windows 7, Windows 8, and Windows Server 2012 will use localized folder names for these subfolders when redirecting the Start Menu or legacy My Documents folder.\r\n\r\nIf you disable or not configure this policy setting, Windows Vista, Windows 7, Windows 8, and Windows Server 2012 will use the standard English names for these subfolders when redirecting the Start Menu or legacy My Documents folder.\r\n\r\nNote: This policy is valid only on Windows Vista, Windows 7, Windows 8, and Windows Server 2012 when it processes a legacy redirection policy already deployed for these folders in your existing localized environment.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-localizexprelativepaths-2"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2_1","displayName":"Enabled","description":null,"helpText":null}]},"f8c21f71665aaba6":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval_signatureupdate_signatureupdatecatchupinterval","displayName":"Define the number of days after which a catch-up security intelligence update is required","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},"f823a7a9ce5115c9":{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name_dxt_standarduserauthorizationfailuretotalthreshold_name","displayName":"Maximum number of authorization failures per duration:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},"f8a1ff9819bcad3a":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013","displayName":"Microsoft Office 365 Outlook 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_1","displayName":"Enabled","description":null,"helpText":null}]},"f894db598a8006a3":{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange","displayName":"Audit Authentication Policy Change","description":"This policy setting allows you to audit events generated by changes to the authentication policy such as the following: Creation of forest and domain trusts. Modification of forest and domain trusts. Removal of forest and domain trusts. Changes to Kerberos policy under Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Kerberos Policy. Granting of any of the following user rights to a user or group: Access This Computer From the Network. Allow Logon Locally. Allow Logon Through Terminal Services. Logon as a Batch Job. Logon a Service. Namespace collision. For example, when a new trust has the same name as an existing namespace name. If you configure this policy setting, an audit event is generated when an attempt to change the authentication policy is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when the authentication policy is changed. Note: The security audit event is logged when the group policy is applied. It does not occur at the time when the settings are modified.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditauthenticationpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"f8b15875f1535a4f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_passwordmanagerblocklistdesc","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":null},"f8758fc0a2aeac34":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb","displayName":"Block untrusted and unsigned processes that run from USB","description":"With this rule, admins can prevent unsigned or untrusted scripts (such as VBScript, JavaScript) and executables (such as .exe, .dll, .scr files) from removable USB drives, including attached SD cards, from running.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_warn","displayName":"Warn","description":null,"helpText":null}]},"f8a5364dc322aff3":{"id":"device_vendor_msft_policy_config_desktopappinstaller_sourceautoupdateinterval","displayName":"Set App Installer Source Auto Update Interval In Minutes","description":"This policy controls the auto-update interval for package-based sources. The default source for Windows Package Manager is configured such that an index of the packages is cached on the local machine. The index is downloaded when a user invokes a command, and the interval has passed.\n\nIf you disable or do not configure this setting, the default interval or the value specified in the Windows Package Manager settings will be used.\n\nIf you enable this setting, the number of minutes specified will be used by the Windows Package Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-sourceautoupdateinterval"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_sourceautoupdateinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_sourceautoupdateinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"f8cc20c89eb0408e":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithtempprofile","displayName":"Prevent Login With Temp Profile","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nPrevent user login when a user receives a temporary Windows profile\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\PreventLoginWithTempProfile\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithtempprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithtempprofile_1","displayName":"Enabled","description":null,"helpText":null}]},"f8868a289deaefbc":{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2","displayName":"Second choice","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_","displayName":"","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},"f8a8c1063eed60f4":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowlessprivilegedsites"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"f888dd616f2c379f":{"id":"device_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols","displayName":"Remove \"Run this time\" button for outdated ActiveX controls in Internet Explorer ","description":"This policy setting allows you to stop users from seeing the \"Run this time\" button and from running specific outdated ActiveX controls in Internet Explorer.\n\nIf you enable this policy setting, users won't see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control.\n\nIf you disable or don't configure this policy setting, users will see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control. Clicking this button lets the user run the outdated ActiveX control once.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-removerunthistimebuttonforoutdatedactivexcontrols"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"f89ade2bd6ccb998":{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay","displayName":"Display zoom in IE Mode tabs with DPI Scale included like it is in Internet Explorer","description":"Lets you display zoom in IE Mode tabs similar to how it was displayed in Internet Explorer, where the DPI scale of the display is factored in.\r\n\r\nFor example, if you have a page zoomed to 200% on a 100 DPI scale display and you change the display to 150 DPI, Microsoft Edge would still display the zoom as 200%. However, Internet Explorer factors in the DPI scale and displays 300%.\r\n\r\nIf you enable this policy, zoom values will be displayed with the DPI scale included for IE Mode tabs.\r\n\r\nIf you disable or don't configure this policy, zoom values will be displayed without DPI scale included for IE Mode tabs","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay_1","displayName":"Enabled","description":null,"helpText":null}]},"f8030238a98b3cc1":{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled","displayName":"Control the availability of the XSLT feature","description":"Controls whether the XSLT feature (the XSLTProcessor JavaScript API and the XSL processing instruction) is available in Microsoft Edge.\r\n\r\nIf you enable this policy, XSLT is available regardless of the browser's default configuration.\r\n\r\nIf you disable this policy, XSLT is unavailable regardless of the browser's default configuration.\r\n\r\nIf you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials.\r\n\r\nThis policy is temporary and will be removed in a future version of Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f8fbc1a1c6833233":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout_navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"f8f9d9e32086902a":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_excelexe141","displayName":"excel.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_excelexe141_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_excelexe141_1","displayName":"True","description":null,"helpText":null}]},"f8b0316a0627cf30":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar","displayName":"Information Bar","description":"Security Band","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_1","displayName":"Enabled","description":null,"helpText":null}]},"f8cdbe869e8dca65":{"id":"device_vendor_msft_policy_config_storage_configstoragesensecloudcontentdehydrationthreshold","displayName":"Config Storage Sense Cloud Content Dehydration Threshold","description":"When Storage Sense runs, it can dehydrate cloud-backed content that hasn’t been opened in a certain amount of days. If the Storage/AllowStorageSenseGlobal policy is disabled, then this policy does not have any effect. If you enable this policy setting, you must provide the minimum number of days a cloud-backed file can remain unopened before Storage Sense dehydrates it. Supported values are: 0–365. If you set this value to zero, Storage Sense will not dehydrate any cloud-backed content. The default value is 0, which never dehydrates cloud-backed content. If you disable or do not configure this policy setting, then Storage Sense will not dehydrate any cloud-backed content by default. Users can configure this setting in Storage settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Storage#configstoragesensecloudcontentdehydrationthreshold"],"categoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","categoryName":"Storage","options":null},"f8ae4bca688e7808":{"id":"device_vendor_msft_policy_config_update_scheduledinstalltime","displayName":"Scheduled Install Time","description":"Note This policy is available on Windows 10 Pro, Windows 10 Enterprise, Windows 10 Education, and Windows 10 Mobile EnterpriseEnables the IT admin to schedule the time of the update installation. The data type is a integer. Supported operations are Add, Delete, Get, and Replace. Supported values are 0-23, where 0 = 12 AM and 23 = 11 PM. The default value is 3.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduledinstalltime"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"f82931162d240a13":{"id":"device_vendor_msft_policy_config_visualstudiov5~policy~visualstudio~installandupdatesettings_updatenotificationsoptout","displayName":"Disable update notifications in Visual Studio","description":"Allows an administrator to control the update notification in the Visual Studio IDE in specific situations.\r\n\r\nIf set to 0 (blocked) or missing entirely, update notifications will appear in the Visual Studio IDE whenever an update is detected.\r\n\r\nIf set to a 1, the update notification in the Visual Studio IDE will be suppressed for the Enterprise and Professional editions on the Release or LTSC channels, only if they are either receiving updates from a layout or if they are enrolled to receive Visual Studio Administrator Updates.\r\n\r\nFor more information, see https://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov5~policy~visualstudio~installandupdatesettings_updatenotificationsoptout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov5~policy~visualstudio~installandupdatesettings_updatenotificationsoptout_1","displayName":"Enabled","description":null,"helpText":null}]},"f825b7ca033be5cd":{"id":"device_vendor_msft_windowsadvancedthreatprotection_configurationtype","displayName":"Microsoft Defender for Endpoint client configuration package type","description":"Microsoft Defender for Endpoint endpoint detection and response capabilities provide advanced attack detections that are near real-time and actionable. Security analysts can prioritize alerts effectively, gain visibility into the full scope of a breach, and take response actions to remediate threats.","helpText":null,"infoUrls":[],"categoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","categoryName":"Microsoft Defender for Endpoint","options":[{"id":"device_vendor_msft_windowsadvancedthreatprotection_configurationtype_autofromconnector","displayName":"Auto from connector","description":null,"helpText":null},{"id":"device_vendor_msft_windowsadvancedthreatprotection_configurationtype_onboard","displayName":"Onboard","description":null,"helpText":null},{"id":"device_vendor_msft_windowsadvancedthreatprotection_configurationtype_offboard","displayName":"Offboard","description":null,"helpText":null}]},"f855bf4baa7ea691":{"id":"intelligencesettings_forceondeviceonlytranslation","displayName":"Force On Device Only Translation","description":"If `true`, forces On-Device Only Translation.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_forceondeviceonlytranslation_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_forceondeviceonlytranslation_true","displayName":"True","description":null,"helpText":null}]},"f89fe8b075262d88":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurertspproxysettings","displayName":"Configure RTSP Proxy (User)","description":"This policy setting allows you to specify the RTSP proxy settings for Windows Media Player.\r\n\r\nIf you enable this policy setting, select one of the following proxy types:\r\n\r\n- Autodetect: the proxy settings are automatically detected.\r\n- Custom: unique proxy settings are used.\r\n\r\nIf the Custom proxy type is selected, the rest of the options on the Setting tab must be specified; otherwise, the default settings are used. The options are ignored if Autodetect is selected.\r\n\r\nThe Configure button on the Network tab in the Player is not available and the protocol cannot be configured. If the \"Hide network tab\" policy setting is also enabled, the entire Network tab is hidden.\r\n\r\nIf you disable this policy setting, the RTSP proxy server cannot be used and users cannot change the RTSP proxy settings.\r\n\r\nIf you do not configure this policy setting, users can configure the RTSP proxy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-configurertspproxysettings"],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurertspproxysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurertspproxysettings_1","displayName":"Enabled","description":null,"helpText":null}]},"f89b8bbaf7b9e750":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_policycodecupdate","displayName":"Prevent Codec Download (User)","description":"This policy setting allows you to prevent Windows Media Player from downloading codecs.\r\n\r\nIf you enable this policy setting, the Player is prevented from automatically downloading codecs to your computer. In addition, the Download codecs automatically check box on the Player tab in the Player is not available.\r\n\r\nIf you disable this policy setting, codecs are automatically downloaded and the Download codecs automatically check box is not available.\r\n\r\nIf you do not configure this policy setting, users can change the setting for the Download codecs automatically check box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-policycodecupdate"],"categoryId":"2f85405a-7472-44ce-8c05-b59bb54912d5","categoryName":"Playback","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_policycodecupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_policycodecupdate_1","displayName":"Enabled","description":null,"helpText":null}]},"f841c3067fddf0a1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"f820fae1fd982f6c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_1","displayName":"Enabled","description":null,"helpText":null}]},"f80b044567b91f72":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled","displayName":"Enable RC4 cipher suites in TLS (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f83077a16e995e2f":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings","displayName":"Settings for Help Me Write (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_0","displayName":"Allow Help Me Write and improve AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_1","displayName":"Allow Help Me Write without improving AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_2","displayName":"Do not allow Help Me Write.","description":null,"helpText":null}]},"f8c7218956707cbb":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments","displayName":"Comments (User)","description":"Determines how comments are displayed on the worksheet.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_1","displayName":"Enabled","description":null,"helpText":null}]},"f8c27290f50f93fb":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},"f8ce6476f6afe41d":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},"f8b1281b2a1a1269":{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"The MK Protocol Security Restriction policy setting reduces attack surface area by preventing the MK protocol. Resources hosted on the MK protocol will fail.\n\nIf you enable this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.\n\nIf you disable this policy setting, applications can use the MK protocol API. Resources hosted on the MK protocol will work for the File Explorer and Internet Explorer processes.\n\nIf you do not configure this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-mkprotocolsecurityrestrictioninternetexplorerprocesses"],"categoryId":"853d5a82-91e4-4c53-8338-fd1a3d9b542c","categoryName":"MK Protocol Security Restriction","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},"f855f63150fcb1a1":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter","displayName":"Enable Google Cast (User)","description":"Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\r\n\r\nDisable this policy to disable Google Cast.\r\n\r\nBy default, Google Cast is enabled.","helpText":"","infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter_1","displayName":"Enabled","description":null,"helpText":null}]},"f8aef5d3a7939649":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended","displayName":"Configure default state of Allow extensions from other stores setting (User)","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\r\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\r\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\r\n\r\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\r\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\r\nIf the user has already turned on the setting and then turned it off, this setting may not work.\r\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\r\nuser settings and the setting will remain as it is.\r\n\r\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":"","infoUrls":[],"categoryId":"b96b63eb-0292-4a73-85d7-c68d330c109e","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"f89505e671391366":{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\r\n\r\nIf you enable this policy, mutation events will continue to be fired, even if they've been disabled by default for normal web users.\r\n\r\nIf you disable or don't configure this policy, these events will not be fired.\r\n\r\nThis policy is a temporary workaround, and enterprises should still work to remove their dependencies on these mutation events.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f888cb373c02b19b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile_l_profilemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"f815e784db05686d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_pathcolon246","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"f8b1ee72197f9ce1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod","displayName":"Catalog Refresh Period (User)","description":"This policy setting sets the apps for Office catalog refresh period, which is the amount of time (hours) Office waits between refreshes of the app catalogs. Refreshing the catalogs detects whether entitlements to any apps have expired.\r\n\r\nIf you enable this policy setting, set the number of hours to determine the length of the refresh period. Choose a value between 0 (always refresh) and 10,000.\r\n\r\nIf you disable or do not configure this policy setting, the catalog refresh period is set to the default 72 hours.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"f8f49438ccc1aff8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing","displayName":"Open Office documents as read/write while browsing (User)","description":"This policy setting controls whether users can edit and save Office 2016 documents on Web servers that they have opened using Internet Explorer.\r\n \r\nIf enable this policy setting, when users browse to an Office 2016 document on a Web server using Internet Explorer the appropriate application opens the file in read/write mode.\r\n\r\nIf you disable or do not configure this policy setting, when users browse to an Office 2016 document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},"f87e8a7c46d3b66a":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris_l_empty14","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"f8edcdb7e1ac273d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42_1","displayName":"True","description":null,"helpText":null}]},"f87d3fdadcba880c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek","displayName":"Choose the first day of the week: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_0","displayName":"Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_1","displayName":"Monday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_4","displayName":"Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_5","displayName":"Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_6","displayName":"Saturday","description":null,"helpText":null}]},"f85ba0aba46f43bc":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts","displayName":"Prevent installation prompts when Windows Desktop Search component is not present (User)","description":"This policy setting allows you to prevent a dialog box from being shown when the Windows Desktop Search 4.0 or above system component is not present on the user's computer and removes the other links provided in Outlook to allow users to download the component. The new search functionality in Outlook requires Windows Desktop Search 4.0 or above.\r\n\r\nIf you enable this policy setting, the dialog box is not shown.\r\n\r\nIf you disable or do not configure this policy setting, the dialog box is shown when this system component is not present. Users are prompted with a dialog box when Outlook starts that explains how to download the system component to install on their computers. In addition, other links are provided by default in Outlook to allow users to download the system component. \r\n\r\nNote: If the required Windows system component is not available, the buttons in the Outlook Search ribbon tab will be disabled regardless of how this policy setting is configured.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts_1","displayName":"Enabled","description":null,"helpText":null}]},"f8066a3191ae8bdb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2","displayName":"Allow scripts in one-off Outlook forms (User)","description":"This policy setting controls whether scripts can run in Outlook forms in which the script and layout are contained within the message. \r\n\r\nIf you enable this policy setting, scripts can run in one-off Outlook forms. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not run scripts in forms in which the script and the layout are contained within the message. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"f8437e0ac4fac88c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},"f874fe4d7052ee22":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask","displayName":"Edits to total task % complete will be spread to the status date (User)","description":"Distributes the changes to total percent complete evenly across the schedule to the project status date (or to the current date if you haven't specified a project status date).\r\n\r\nIf you enable this setting, edits to total task percent complete are evenly distributed across the schedule up to the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask_1","displayName":"Enabled","description":null,"helpText":null}]},"f8e08bd72c9b9d4e":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},"f8e685c50fff5450":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped_1","displayName":"Enabled","description":null,"helpText":null}]},"f824b8e46a37c477":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting","displayName":"Print in background (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting_1","displayName":"Enabled","description":null,"helpText":null}]},"f88ce86df100b68d":{"id":"vendor_msft_sharedpc_deletionpolicy","displayName":"Deletion Policy","description":"Configures when accounts will be deleted. Allowed values: 0 (delete immediately), 1 (delete at disk space threshold), 2 (Delete at disk space threshold and inactive threshold). If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_deletionpolicy_0","displayName":"Delete immediately","description":"Delete immediately.","helpText":null},{"id":"vendor_msft_sharedpc_deletionpolicy_1","displayName":"Delete at disk space threshold","description":"Delete at disk space threshold","helpText":null},{"id":"vendor_msft_sharedpc_deletionpolicy_2","displayName":"Delete at disk space threshold and inactive threshold","description":"Delete at disk space threshold and inactive threshold","helpText":null}]}} \ No newline at end of file +{"f8e6d7b08238b351":{"id":"com.apple.applicationaccess_allowautomaticappdownloads","displayName":"Allow Automatic App Downloads","description":"If false, prevents automatic downloading of apps purchased on other devices. This setting doesn’t affect updates to existing apps. Requires a supervised device. Available in iOS 9 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowautomaticappdownloads_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowautomaticappdownloads_true","displayName":"True","description":null,"helpText":null}]},"f8a4ccca9b66777d":{"id":"com.apple.applicationaccess_allowimageplayground","displayName":"Allow Image Playground (Deprecated)","description":"If false, prohibits the use of image generation.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowimageplayground_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowimageplayground_true","displayName":"True","description":null,"helpText":null}]},"f842428ae0aad8b7":{"id":"com.apple.assetcache.managed_peerlistenranges_item_type","displayName":"IP Address Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_peerlistenranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_peerlistenranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},"f84a3882bd66b1c3":{"id":"com.apple.dock_persistent-apps_item_tile-data","displayName":"Tile Data","description":"The information about the Dock item.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":null},"f8ba294e51da7385":{"id":"com.apple.extensiblesso_platformsso_nonplatformssoaccounts","displayName":"Non Platform SSO Accounts","description":"The list of local accounts that are not subject to the 'FileVaultPolicy', 'LoginPolicy', or 'UnlockPolicy'. The accounts are also not prompted to register for Platform SSO.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"f85db409951203d4":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname","displayName":"Channel Name (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":[{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_0","displayName":"Current Channel","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_1","displayName":"Current Channel (Preview)","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge canary.app_channelname_2","displayName":"Beta Channel","description":null,"helpText":null}]},"f812b7686293e17e":{"id":"com.apple.managedclient.preferences_newtabpagemanagedquicklinks_item_url","displayName":"URL","description":"The URL for the quick link.","helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"f8c1f4abbe263cd1":{"id":"com.apple.managedclient.preferences_smartscreenallowlistdomains","displayName":"Configure the list of domains for which Microsoft Defender SmartScreen won't trigger warnings","description":"Configure the list of Microsoft Defender SmartScreen trusted domains. This means:\nMicrosoft Defender SmartScreen won't check for potentially malicious resources like phishing software and other malware if the source URLs match these domains.\nThe Microsoft Defender SmartScreen download protection service won't check downloads hosted on these domains.\n\nIf you enable this policy, Microsoft Defender SmartScreen trusts these domains.\nIf you disable or don't set this policy, default Microsoft Defender SmartScreen protection is applied to all resources.\n\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.\nAlso note that this policy does not apply if your organization has enabled Microsoft Defender Advanced Threat Protection. You must configure your allow and block lists in Microsoft Defender Security Center instead.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#smartscreenallowlistdomains"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"f805dafe30c3c3a4":{"id":"com.apple.systemconfiguration_proxies_gopherenable","displayName":"Gopher Enable","description":"If true, enables gopher proxy.","helpText":null,"infoUrls":[],"categoryId":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","categoryName":"Network Proxy Configuration","options":[{"id":"com.apple.systemconfiguration_proxies_gopherenable_0","displayName":"False","description":null,"helpText":null},{"id":"com.apple.systemconfiguration_proxies_gopherenable_1","displayName":"True","description":null,"helpText":null}]},"f813382d45fc2e97":{"id":"com.microsoft.edge.mamedgeappconfigsettings.autoplayallowlist","displayName":"Allow media autoplay on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\n\nIf you don't configure this policy, the global default value from the \"AutoplayAllowed\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\n\nNote: * is not an accepted value for this policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"f88126bc464c2598":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting","displayName":"Default images setting","description":"Set whether websites can display images. You can allow images on all sites ('AllowImages') or block them on all sites ('BlockImages').\n\nIf you don't configure this policy, images are allowed by default, and the user can change this setting.\n\nPolicy options mapping:\n\n* AllowImages (1) = Allow all sites to show all images\n\n* BlockImages (2) = Don't allow any site to show images\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting_allowimages","displayName":"Allow all sites to show all images","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultimagessetting_blockimages","displayName":"Don't allow any site to show images","description":null,"helpText":null}]},"f89f9378745b5c69":{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled","displayName":"Show the Reload in Internet Explorer mode button in the toolbar","description":"Set this policy to show the Reload in Internet Explorer mode button in the toolbar. Users can hide the button in the toolbar through edge://settings/appearance. The button is only shown on the toolbar when the \"InternetExplorerIntegrationReloadInIEModeAllowed\" policy is enabled or if the user chose to enable \"Allow sites to be reloaded in Internet Explorer mode\".\n\nIf you enable this policy, the Reload in Internet mode button is pinned to the toolbar.\n\nIf you disable or don't configure this policy, the Reload in Internet Explorer mode button isn't shown in the toolbar by default. Users can toggle the Show Internet Explorer mode button in edge://settings/appearance.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.internetexplorermodetoolbarbuttonenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"f84b822092217e6f":{"id":"com.microsoft.edge.mamedgeappconfigsettings.popupsallowedforurls","displayName":"Allow pop-up windows on specific sites","description":"Define a list of sites, based on URL patterns, that can open pop-up windows. Wildcards (*) are allowed.\n\nIf you don't configure this policy, the global default value from the \"DefaultPopupsSetting\" policy (if set) or the user's personal configuration is used for all sites.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"f8363a982ad33480":{"id":"com.microsoft.edge.mamedgeappconfigsettings.proxyoverriderules","displayName":"Proxy override rules","description":"This policy enables rule-based proxy selection that determines which proxy Microsoft Edge uses based on the destination URL and any other conditions you define.\n\nWhen this policy is configured, it takes precedence over proxy settings configured by the ProxySettings policy, the Edge.proxy extension API, and any manual user settings.\n\nIf this policy is disabled or not configured, existing proxy policies and user-defined settings continue to apply.\n\nWhen Edge selects a proxy, it evaluates entries in the ProxyOverrideRules policy in order. A rule is considered a match when all the following conditions are met:\n* At least one URL pattern in DestinationMatchers is matched.\n* No URL pattern in ExcludeDestinationMatchers is matched.\n* If Conditions is specified and non-empty, all conditions are satisfied.\n\nFor a matching rule, the value specified in ProxyList is used as the proxy. If no rule matches, proxy selection falls back to the settings defined by the ProxySettings policy.\n\nThe URL patterns supported by DestinationMatchers and ExcludeDestinationMatchers are documented at https://review.learn.microsoft.com/en-us/DeployEdge/configure-microsoft-edge-proxy-support?branch=pr-en-us-6681#proxy-config-url-patterns .\nEntries in ProxyList correspond to PAC-style proxy strings, such as:\n* DIRECT\n* PROXY host:port\n* HTTPS host:port\n* SOCKS4 host:port\n* SOCKS5 host:port\n\nAlternatively, URL-form proxy specifiers can be used, for example:\n* http://host :port\n* https://host :port\n* socks4://host:port\n* socks5://host:port\n\nThe first reachable proxy in the list is used. Invalid entries are ignored.\n\nThe Conditions field specifies conditions that must all be met for an override rule to be applied when selecting a proxy. If this field is not set, the rule is applied when at least one host in DestinationMatchers matches.\n\nThe DnsProbe condition checks whether the specified DNS Host can be resolved to an IP address. The host must include a hostname (for example, example.com) and can optionally include a scheme or port (for example, https://example.com, example.com:123, or https://example.com:123). When a secure scheme (for example, https) is specified, the DNS lookup may also request the HTTPS record (see RFC 9460).\n\nIf Result is set to resolved, the condition is met when resolution succeeds. If set to not_found, the condition is met only when resolution fails.","helpText":null,"infoUrls":[],"categoryId":"fe845e81-5993-4a65-b22a-decfc5928c65","categoryName":"Proxy server","options":null},"f83f72ecdbbbccdf":{"id":"com.microsoft.edge.mamedgeappconfigsettings.webappinstallforcelist","displayName":"Configure list of force-installed Web Apps","description":"Setting the policy specifies a list of web apps that install silently, without user interaction. Users can't turn off the policy or uninstall these web apps.\n\nEach list item of the policy is an object with a mandatory member:\nurl (the URL of the web app to install)\n\nand 6 optional members:\n- default_launch_container\n(for how the web app opens—a new tab is the default)\n\n- create_desktop_shortcut\n(True if you want to create Linux and\nMicrosoft Windows desktop shortcuts).\n\n- fallback_app_name\n(Starting with Microsoft Edge version 90,\nyou can permanently override the app name if it's not a Progressive Web App (PWA)\nor you can temporarily override the app name if authentication is required before\ninstallation can be completed. If both\ncustom_name and\nfallback_app_name are provided,\nthe latter is ignored.)\n\n- custom_name\n(Starting with Microsoft Edge version 112\non all desktop platforms, you can permanently override the app name for all\nweb apps and PWAs.)\n\n- custom_icon\n(Starting with Microsoft Edge version 112\non all desktop platforms, you can override the app icon of installed apps.\nThe icons have to be square, maximal 1 MB in size, and in one of the following formats:\njpeg, png, gif, webp, ico. The hash value has to be the SHA256 hash of the icon file.\nThe url should be accessible without authentication to\nensure that the icon can be used upon app installation.)\n\n- install_as_shortcut\n(Starting with Microsoft Edge\nversion 107). If enabled, the given url is installed as a shortcut,\nas if done via the \"Create Shortcut...\" option in the desktop browser GUI.\nWhen installed as a shortcut, it won't be updated if the manifest in url changes.\nIf disabled or unset, the web app at the given url is installed normally.\n(This isn't currently supported in Microsoft Edge.)\n\nThe 'WebAppInstallByUserEnabled' policy doesn't affect this policy. Web apps specified by this policy are installed regardless of the 'WebAppInstallByUserEnabled' policy setting.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"f82a6b3d03742a64":{"id":"device_vendor_msft_defender_configuration_behavioralnetworkblocks_remoteencryptionprotection_remoteencryptionprotectionmaxblocktime","displayName":"Remote Encryption Protection Max Block Time","description":"Set the maximum time an IP address is blocked by Remote Encryption Protection. After this time, blocked IP addresses will be able to reinitiate connections. If set to 0, internal feature logic will determine blocking time.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"f8b3084eb8e2ac64":{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder","displayName":"ECC Curve Order","description":"This policy setting determines the priority order of ECC curves used with ECDHE cipher suites.\r\n\r\nIf you enable this policy setting, ECC curves are prioritized in the order specified.(Enter one Curve name per line)\r\n\r\nIf you disable or do not configure this policy setting, the default ECC curve order is used.\r\n\r\nDefault Curve Order\r\n============\r\ncurve25519\r\nNistP256\r\nNistP384\r\n\r\nTo See all the curves supported on the system, Use the following command:\r\n\r\nCertUtil.exe -DisplayEccCurve\r\n\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-ciphersuiteorder#admx-ciphersuiteorder-sslcurveorder"],"categoryId":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","categoryName":"SSL Configuration Settings","options":[{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_ciphersuiteorder_sslcurveorder_1","displayName":"Enabled","description":null,"helpText":null}]},"f871bfe9f086e132":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping","displayName":"IDN mapping","description":"Specifies whether the DNS client should convert internationalized domain names (IDNs) to the Nameprep form, a canonical Unicode representation of the string.\r\n\r\nIf this policy setting is enabled, IDNs are converted to the Nameprep form.\r\n\r\nIf this policy setting is disabled, or if this policy setting is not configured, IDNs are not converted to the Nameprep form.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dnsclient#admx-dnsclient-dns-idnmapping"],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_idnmapping_1","displayName":"Enabled","description":null,"helpText":null}]},"f857ccff166a331d":{"id":"device_vendor_msft_policy_config_admx_eventforwarding_subscriptionmanager_subscriptionmanager_listbox","displayName":"SubscriptionManagers","description":null,"helpText":"","infoUrls":[],"categoryId":"c859dc1a-fdeb-4591-af97-79d078ee715b","categoryName":"Event Forwarding","options":null},"f812bde75239196f":{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2","displayName":"Use localized subfolder names when redirecting Start Menu and My Documents","description":"This policy setting allows the administrator to define whether Folder Redirection should use localized names for the All Programs, Startup, My Music, My Pictures, and My Videos subfolders when redirecting the parent Start Menu and legacy My Documents folder respectively.\r\n\r\nIf you enable this policy setting, Windows Vista, Windows 7, Windows 8, and Windows Server 2012 will use localized folder names for these subfolders when redirecting the Start Menu or legacy My Documents folder.\r\n\r\nIf you disable or not configure this policy setting, Windows Vista, Windows 7, Windows 8, and Windows Server 2012 will use the standard English names for these subfolders when redirecting the Start Menu or legacy My Documents folder.\r\n\r\nNote: This policy is valid only on Windows Vista, Windows 7, Windows 8, and Windows Server 2012 when it processes a legacy redirection policy already deployed for these folders in your existing localized environment.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-folderredirection#admx-folderredirection-localizexprelativepaths-2"],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_folderredirection_localizexprelativepaths_2_1","displayName":"Enabled","description":null,"helpText":null}]},"f8c21f71665aaba6":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_signatureupdate_signatureupdatecatchupinterval_signatureupdate_signatureupdatecatchupinterval","displayName":"Define the number of days after which a catch-up security intelligence update is required","description":null,"helpText":"","infoUrls":[],"categoryId":"94b5c25e-3af3-4c08-b738-a0527f91dc22","categoryName":"Security Intelligence Updates","options":null},"f823a7a9ce5115c9":{"id":"device_vendor_msft_policy_config_admx_tpm_standarduserauthorizationfailuretotalthreshold_name_dxt_standarduserauthorizationfailuretotalthreshold_name","displayName":"Maximum number of authorization failures per duration:","description":null,"helpText":"","infoUrls":[],"categoryId":"24b30053-14d2-4430-9966-281e926a6918","categoryName":"Trusted Platform Module Services","options":null},"f8a1ff9819bcad3a":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013","displayName":"Microsoft Office 365 Outlook 2013","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Outlook 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Outlook 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Outlook 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Outlook 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Outlook 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365outlook2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365outlook2013_1","displayName":"Enabled","description":null,"helpText":null}]},"f894db598a8006a3":{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange","displayName":"Audit Authentication Policy Change","description":"This policy setting allows you to audit events generated by changes to the authentication policy such as the following: Creation of forest and domain trusts. Modification of forest and domain trusts. Removal of forest and domain trusts. Changes to Kerberos policy under Computer Configuration\\Windows Settings\\Security Settings\\Account Policies\\Kerberos Policy. Granting of any of the following user rights to a user or group: Access This Computer From the Network. Allow Logon Locally. Allow Logon Through Terminal Services. Logon as a Batch Job. Logon a Service. Namespace collision. For example, when a new trust has the same name as an existing namespace name. If you configure this policy setting, an audit event is generated when an attempt to change the authentication policy is made. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when the authentication policy is changed. Note: The security audit event is logged when the group policy is applied. It does not occur at the time when the settings are modified.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#policychange_auditauthenticationpolicychange"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_0","displayName":"Off/None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_policychange_auditauthenticationpolicychange_3","displayName":"Success+Failure","description":"Success+Failure","helpText":null}]},"f8b15875f1535a4f":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_passwordmanagerblocklist_passwordmanagerblocklistdesc","displayName":"Configure the list of domains for which the Password Manager (Save and Fill) will be disabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":null},"f8758fc0a2aeac34":{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb","displayName":"Block untrusted and unsigned processes that run from USB","description":"With this rule, admins can prevent unsigned or untrusted scripts (such as VBScript, JavaScript) and executables (such as .exe, .dll, .scr files) from removable USB drives, including attached SD cards, from running.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/attack-surface-reduction"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":[{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_off","displayName":"Off","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_block","displayName":"Block","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_audit","displayName":"Audit","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_defender_attacksurfacereductionrules_blockuntrustedunsignedprocessesthatrunfromusb_warn","displayName":"Warn","description":null,"helpText":null}]},"f8a5364dc322aff3":{"id":"device_vendor_msft_policy_config_desktopappinstaller_sourceautoupdateinterval","displayName":"Set App Installer Source Auto Update Interval In Minutes","description":"This policy controls the auto-update interval for package-based sources. The default source for Windows Package Manager is configured such that an index of the packages is cached on the local machine. The index is downloaded when a user invokes a command, and the interval has passed.\n\nIf you disable or do not configure this setting, the default interval or the value specified in the Windows Package Manager settings will be used.\n\nIf you enable this setting, the number of minutes specified will be used by the Windows Package Manager.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-desktopappinstaller#desktopappinstaller-sourceautoupdateinterval"],"categoryId":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","categoryName":"Desktop App Installer","options":[{"id":"device_vendor_msft_policy_config_desktopappinstaller_sourceautoupdateinterval_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_desktopappinstaller_sourceautoupdateinterval_1","displayName":"Enabled","description":null,"helpText":null}]},"f8cc20c89eb0408e":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithtempprofile","displayName":"Prevent Login With Temp Profile","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nPrevent user login when a user receives a temporary Windows profile\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\PreventLoginWithTempProfile\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithtempprofile_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithtempprofile_1","displayName":"Enabled","description":null,"helpText":null}]},"f8868a289deaefbc":{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2","displayName":"Second choice","description":"","helpText":"","infoUrls":[],"categoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","categoryName":"Internet Explorer","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_","displayName":"","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_1","displayName":"Microsoft Edge Stable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_2","displayName":"Microsoft Edge Beta version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_3","displayName":"Microsoft Edge Dev version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_4","displayName":"Microsoft Edge Canary version 77 or later","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_configureedgeredirectchannel_neededgebrowser2_0","displayName":"Microsoft Edge version 45 or earlier","description":null,"helpText":null}]},"f8a8c1063eed60f4":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites","displayName":"Web sites in less privileged Web content zones can navigate into this zone","description":"This policy setting allows you to manage whether Web sites from less privileged zones, such as Internet sites, can navigate into this zone.\n\nIf you enable this policy setting, Web sites from less privileged zones can open new windows in, or navigate into, this zone. The security zone will run without the added layer of security that is provided by the Protection from Zone Elevation security feature. If you select Prompt in the drop-down box, a warning is issued to the user that potentially risky navigation is about to occur.\n\nIf you disable this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.\n\nIf you do not configure this policy setting, the possibly harmful navigations are prevented. The Internet Explorer security feature will be on in this zone as set by Protection from Zone Elevation feature control.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddownlocalmachinezoneallowlessprivilegedsites"],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowlessprivilegedsites_1","displayName":"Enabled","description":null,"helpText":null}]},"f888dd616f2c379f":{"id":"device_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols","displayName":"Remove \"Run this time\" button for outdated ActiveX controls in Internet Explorer ","description":"This policy setting allows you to stop users from seeing the \"Run this time\" button and from running specific outdated ActiveX controls in Internet Explorer.\n\nIf you enable this policy setting, users won't see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control.\n\nIf you disable or don't configure this policy setting, users will see the \"Run this time\" button on the warning message that appears when Internet Explorer blocks an outdated ActiveX control. Clicking this button lets the user run the outdated ActiveX control once.\n\nFor more information, see \"Outdated ActiveX Controls\" in the Internet Explorer TechNet library.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-removerunthistimebuttonforoutdatedactivexcontrols"],"categoryId":"4560c525-12a1-4536-9cca-338330e58389","categoryName":"Add-on Management","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_removerunthistimebuttonforoutdatedactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"f89ade2bd6ccb998":{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay","displayName":"Display zoom in IE Mode tabs with DPI Scale included like it is in Internet Explorer","description":"Lets you display zoom in IE Mode tabs similar to how it was displayed in Internet Explorer, where the DPI scale of the display is factored in.\r\n\r\nFor example, if you have a page zoomed to 200% on a 100 DPI scale display and you change the display to 150 DPI, Microsoft Edge would still display the zoom as 200%. However, Internet Explorer factors in the DPI scale and displays 300%.\r\n\r\nIf you enable this policy, zoom values will be displayed with the DPI scale included for IE Mode tabs.\r\n\r\nIf you disable or don't configure this policy, zoom values will be displayed without DPI scale included for IE Mode tabs","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_internetexplorerzoomdisplay_1","displayName":"Enabled","description":null,"helpText":null}]},"f8030238a98b3cc1":{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled","displayName":"Control the availability of the XSLT feature","description":"Controls whether the XSLT feature (the XSLTProcessor JavaScript API and the XSL processing instruction) is available in Microsoft Edge.\r\n\r\nIf you enable this policy, XSLT is available regardless of the browser's default configuration.\r\n\r\nIf you disable this policy, XSLT is unavailable regardless of the browser's default configuration.\r\n\r\nIf you don't configure this policy, XSLT availability is determined by the browser's default configuration and any applicable field trials.\r\n\r\nThis policy is temporary and will be removed in a future version of Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev147~policy~microsoft_edge_xsltenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f8fbc1a1c6833233":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_navigationdelayforinitialsitelistdownloadtimeout_navigationdelayforinitialsitelistdownloadtimeout","displayName":"Set a timeout for delay of tab navigation for the Enterprise Mode Site List: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"f8f9d9e32086902a":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_excelexe141","displayName":"excel.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_excelexe141_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_bindtoobject_l_excelexe141_1","displayName":"True","description":null,"helpText":null}]},"f8b0316a0627cf30":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar","displayName":"Information Bar","description":"Security Band","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_1","displayName":"Enabled","description":null,"helpText":null}]},"f8cdbe869e8dca65":{"id":"device_vendor_msft_policy_config_storage_configstoragesensecloudcontentdehydrationthreshold","displayName":"Config Storage Sense Cloud Content Dehydration Threshold","description":"When Storage Sense runs, it can dehydrate cloud-backed content that hasn’t been opened in a certain amount of days. If the Storage/AllowStorageSenseGlobal policy is disabled, then this policy does not have any effect. If you enable this policy setting, you must provide the minimum number of days a cloud-backed file can remain unopened before Storage Sense dehydrates it. Supported values are: 0–365. If you set this value to zero, Storage Sense will not dehydrate any cloud-backed content. The default value is 0, which never dehydrates cloud-backed content. If you disable or do not configure this policy setting, then Storage Sense will not dehydrate any cloud-backed content by default. Users can configure this setting in Storage settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Storage#configstoragesensecloudcontentdehydrationthreshold"],"categoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","categoryName":"Storage","options":null},"f8480680fabc72d7":{"id":"device_vendor_msft_policy_config_update_maintenancewindowenabled","displayName":"Maintenance Window Enabled","description":"Specifies whether maintenance window is enabled.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowenabled"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"f8ae4bca688e7808":{"id":"device_vendor_msft_policy_config_update_scheduledinstalltime","displayName":"Scheduled Install Time","description":"Note This policy is available on Windows 10 Pro, Windows 10 Enterprise, Windows 10 Education, and Windows 10 Mobile EnterpriseEnables the IT admin to schedule the time of the update installation. The data type is a integer. Supported operations are Add, Delete, Get, and Replace. Supported values are 0-23, where 0 = 12 AM and 23 = 11 PM. The default value is 3.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#scheduledinstalltime"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"f82931162d240a13":{"id":"device_vendor_msft_policy_config_visualstudiov5~policy~visualstudio~installandupdatesettings_updatenotificationsoptout","displayName":"Disable update notifications in Visual Studio","description":"Allows an administrator to control the update notification in the Visual Studio IDE in specific situations.\r\n\r\nIf set to 0 (blocked) or missing entirely, update notifications will appear in the Visual Studio IDE whenever an update is detected.\r\n\r\nIf set to a 1, the update notification in the Visual Studio IDE will be suppressed for the Enterprise and Professional editions on the Release or LTSC channels, only if they are either receiving updates from a layout or if they are enrolled to receive Visual Studio Administrator Updates.\r\n\r\nFor more information, see https://aka.ms/vs/setup/policies.","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":[{"id":"device_vendor_msft_policy_config_visualstudiov5~policy~visualstudio~installandupdatesettings_updatenotificationsoptout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_visualstudiov5~policy~visualstudio~installandupdatesettings_updatenotificationsoptout_1","displayName":"Enabled","description":null,"helpText":null}]},"f825b7ca033be5cd":{"id":"device_vendor_msft_windowsadvancedthreatprotection_configurationtype","displayName":"Microsoft Defender for Endpoint client configuration package type","description":"Microsoft Defender for Endpoint endpoint detection and response capabilities provide advanced attack detections that are near real-time and actionable. Security analysts can prioritize alerts effectively, gain visibility into the full scope of a breach, and take response actions to remediate threats.","helpText":null,"infoUrls":[],"categoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","categoryName":"Microsoft Defender for Endpoint","options":[{"id":"device_vendor_msft_windowsadvancedthreatprotection_configurationtype_autofromconnector","displayName":"Auto from connector","description":null,"helpText":null},{"id":"device_vendor_msft_windowsadvancedthreatprotection_configurationtype_onboard","displayName":"Onboard","description":null,"helpText":null},{"id":"device_vendor_msft_windowsadvancedthreatprotection_configurationtype_offboard","displayName":"Offboard","description":null,"helpText":null}]},"f855bf4baa7ea691":{"id":"intelligencesettings_forceondeviceonlytranslation","displayName":"Force On Device Only Translation","description":"If `true`, forces On-Device Only Translation.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_forceondeviceonlytranslation_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_forceondeviceonlytranslation_true","displayName":"True","description":null,"helpText":null}]},"f89fe8b075262d88":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurertspproxysettings","displayName":"Configure RTSP Proxy (User)","description":"This policy setting allows you to specify the RTSP proxy settings for Windows Media Player.\r\n\r\nIf you enable this policy setting, select one of the following proxy types:\r\n\r\n- Autodetect: the proxy settings are automatically detected.\r\n- Custom: unique proxy settings are used.\r\n\r\nIf the Custom proxy type is selected, the rest of the options on the Setting tab must be specified; otherwise, the default settings are used. The options are ignored if Autodetect is selected.\r\n\r\nThe Configure button on the Network tab in the Player is not available and the protocol cannot be configured. If the \"Hide network tab\" policy setting is also enabled, the entire Network tab is hidden.\r\n\r\nIf you disable this policy setting, the RTSP proxy server cannot be used and users cannot change the RTSP proxy settings.\r\n\r\nIf you do not configure this policy setting, users can configure the RTSP proxy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-configurertspproxysettings"],"categoryId":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","categoryName":"Networking","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurertspproxysettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_configurertspproxysettings_1","displayName":"Enabled","description":null,"helpText":null}]},"f89b8bbaf7b9e750":{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_policycodecupdate","displayName":"Prevent Codec Download (User)","description":"This policy setting allows you to prevent Windows Media Player from downloading codecs.\r\n\r\nIf you enable this policy setting, the Player is prevented from automatically downloading codecs to your computer. In addition, the Download codecs automatically check box on the Player tab in the Player is not available.\r\n\r\nIf you disable this policy setting, codecs are automatically downloaded and the Download codecs automatically check box is not available.\r\n\r\nIf you do not configure this policy setting, users can change the setting for the Download codecs automatically check box.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsmediaplayer#admx-windowsmediaplayer-policycodecupdate"],"categoryId":"2f85405a-7472-44ce-8c05-b59bb54912d5","categoryName":"Playback","options":[{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_policycodecupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsmediaplayer_policycodecupdate_1","displayName":"Enabled","description":null,"helpText":null}]},"f841c3067fddf0a1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchproviderkeyword_recommended_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"f820fae1fd982f6c":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderKeyword specifies the keyword or shortcut used in the address bar to trigger the search for this provider.\r\n\r\nLeaving DefaultSearchProviderKeyword unset means no keyword activates the search provider.\r\n\r\nExample value: mis","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderkeyword_1","displayName":"Enabled","description":null,"helpText":null}]},"f80b044567b91f72":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled","displayName":"Enable RC4 cipher suites in TLS (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_rc4enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f83077a16e995e2f":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings","displayName":"Settings for Help Me Write (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_0","displayName":"Allow Help Me Write and improve AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_1","displayName":"Allow Help Me Write without improving AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_helpmewritesettings_helpmewritesettings_2","displayName":"Do not allow Help Me Write.","description":null,"helpText":null}]},"f8c7218956707cbb":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments","displayName":"Comments (User)","description":"Determines how comments are displayed on the worksheet.","helpText":"","infoUrls":[],"categoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_advanced_l_comments_1","displayName":"Enabled","description":null,"helpText":null}]},"f8c27290f50f93fb":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500","displayName":"Protected Mode (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzoneenableprotectedmode_iz_partname2500_3","displayName":"Disable","description":null,"helpText":null}]},"f8ce6476f6afe41d":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804","displayName":"Launching applications and files in an IFRAME (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonelaunchingapplicationsandfilesiniframe_iz_partname1804_1","displayName":"Prompt","description":null,"helpText":null}]},"f8b1281b2a1a1269":{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"The MK Protocol Security Restriction policy setting reduces attack surface area by preventing the MK protocol. Resources hosted on the MK protocol will fail.\n\nIf you enable this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.\n\nIf you disable this policy setting, applications can use the MK protocol API. Resources hosted on the MK protocol will work for the File Explorer and Internet Explorer processes.\n\nIf you do not configure this policy setting, the MK Protocol is prevented for File Explorer and Internet Explorer, and resources hosted on the MK protocol will fail.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-mkprotocolsecurityrestrictioninternetexplorerprocesses"],"categoryId":"853d5a82-91e4-4c53-8338-fd1a3d9b542c","categoryName":"MK Protocol Security Restriction","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_mkprotocolsecurityrestrictioninternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},"f855f63150fcb1a1":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter","displayName":"Enable Google Cast (User)","description":"Enable this policy to enable Google Cast. Users will be able to launch it from the app menu, page context menus, media controls on Cast-enabled websites, and (if shown) the Cast toolbar icon.\r\n\r\nDisable this policy to disable Google Cast.\r\n\r\nBy default, Google Cast is enabled.","helpText":"","infoUrls":[],"categoryId":"fddc444c-3591-4a50-865b-d8993b798e12","categoryName":"Cast","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~googlecast_enablemediarouter_1","displayName":"Enabled","description":null,"helpText":null}]},"f8aef5d3a7939649":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended","displayName":"Configure default state of Allow extensions from other stores setting (User)","description":"This policy allows you to control the default state of the Allow extensions from other stores setting.\r\nThis policy can't be used to stop installation of extensions from other stores such as Chrome Web Store.\r\nTo stop installation of extensions from other stores, use the Extension Settings policy: https://go.microsoft.com/fwlink/?linkid=2187098.\r\n\r\nWhen enabled, Allow extensions from other stores will be turned on. So, users won't have to turn on the flag manually\r\nwhile installing extensions from other supported stores such as Chrome Web Store. However a user can override this setting.\r\nIf the user has already turned on the setting and then turned it off, this setting may not work.\r\nIf the Admin first sets the policy as Enabled, but then changes it to not configured or disabled, it will have no impact on\r\nuser settings and the setting will remain as it is.\r\n\r\nWhen disabled or not configured, the user can manage the Allow extensions from other store setting.","helpText":"","infoUrls":[],"categoryId":"b96b63eb-0292-4a73-85d7-c68d330c109e","categoryName":"Extensions","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended~extensions_recommended_controldefaultstateofallowextensionfromotherstoressettingenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"f89505e671391366":{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (deprecated) (User)","description":"DEPRECATED: This policy is deprecated. It is currently supported but will become obsolete in a future release.\r\n\r\nThis policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\r\n\r\nIf you enable this policy, mutation events will continue to be fired, even if they've been disabled by default for normal web users.\r\n\r\nIf you disable or don't configure this policy, these events will not be fired.\r\n\r\nThis policy is a temporary workaround, and enterprises should still work to remove their dependencies on these mutation events.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev124~policy~microsoft_edge_mutationeventsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f888cb373c02b19b":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceprofile_l_profilemapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"f815e784db05686d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc03_l_pathcolon246","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"f8b1ee72197f9ce1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod","displayName":"Catalog Refresh Period (User)","description":"This policy setting sets the apps for Office catalog refresh period, which is the amount of time (hours) Office waits between refreshes of the app catalogs. Refreshing the catalogs detects whether entitlements to any apps have expired.\r\n\r\nIf you enable this policy setting, set the number of hours to determine the length of the refresh period. Choose a value between 0 (always refresh) and 10,000.\r\n\r\nIf you disable or do not configure this policy setting, the catalog refresh period is set to the default 72 hours.","helpText":"","infoUrls":[],"categoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","categoryName":"Server Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_serversettings_l_catalogrefreshperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"f8f49438ccc1aff8":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing","displayName":"Open Office documents as read/write while browsing (User)","description":"This policy setting controls whether users can edit and save Office 2016 documents on Web servers that they have opened using Internet Explorer.\r\n \r\nIf enable this policy setting, when users browse to an Office 2016 document on a Web server using Internet Explorer the appropriate application opens the file in read/write mode.\r\n\r\nIf you disable or do not configure this policy setting, when users browse to an Office 2016 document on a Web server using Internet Explorer, the appropriate application opens the file in read-only mode.","helpText":"","infoUrls":[],"categoryId":"0775f21c-9ca1-446d-b1dc-3cea45f15605","categoryName":"Files","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_toolsoptionsgeneralweboptions~l_files_l_openofficedocumentsasreadwritewhilebrowsing_1","displayName":"Enabled","description":null,"helpText":null}]},"f87e8a7c46d3b66a":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_numberofdaysbeforewarningthatserveris_l_empty14","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":null},"f8edcdb7e1ac273d":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42","displayName":"Show associated web page (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_calendarfolderhomepage_l_showassociatedwebpage42_1","displayName":"True","description":null,"helpText":null}]},"f87d3fdadcba880c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek","displayName":"Choose the first day of the week: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_0","displayName":"Sunday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_1","displayName":"Monday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_2","displayName":"Tuesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_3","displayName":"Wednesday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_4","displayName":"Thursday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_5","displayName":"Friday","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_firstdayoftheweek_l_choosethefirstdayoftheweek_6","displayName":"Saturday","description":null,"helpText":null}]},"f85ba0aba46f43bc":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts","displayName":"Prevent installation prompts when Windows Desktop Search component is not present (User)","description":"This policy setting allows you to prevent a dialog box from being shown when the Windows Desktop Search 4.0 or above system component is not present on the user's computer and removes the other links provided in Outlook to allow users to download the component. The new search functionality in Outlook requires Windows Desktop Search 4.0 or above.\r\n\r\nIf you enable this policy setting, the dialog box is not shown.\r\n\r\nIf you disable or do not configure this policy setting, the dialog box is shown when this system component is not present. Users are prompted with a dialog box when Outlook starts that explains how to download the system component to install on their computers. In addition, other links are provided by default in Outlook to allow users to download the system component. \r\n\r\nNote: If the required Windows system component is not available, the buttons in the Outlook Search ribbon tab will be disabled regardless of how this policy setting is configured.","helpText":"","infoUrls":[],"categoryId":"d0a1763a-5cdf-4672-8596-435ec1d94b54","categoryName":"Search Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_searchoptions_l_disableinstallationprompts_1","displayName":"Enabled","description":null,"helpText":null}]},"f8066a3191ae8bdb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2","displayName":"Allow scripts in one-off Outlook forms (User)","description":"This policy setting controls whether scripts can run in Outlook forms in which the script and layout are contained within the message. \r\n\r\nIf you enable this policy setting, scripts can run in one-off Outlook forms. \r\n\r\nIf you disable or do not configure this policy setting, Outlook does not run scripts in forms in which the script and the layout are contained within the message. \r\n\r\nImportant: This policy setting only applies if the \"Outlook Security Mode\" policy setting under \"Microsoft Outlook 2016\\Security\\Security Form Settings\" is configured to \"Use Outlook Security Group Policy.\"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_misccustomformsettings_l_enablescriptsinoneoffforms_v2_1","displayName":"Enabled","description":null,"helpText":null}]},"f8437e0ac4fac88c":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting","displayName":"Guard behavior: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","categoryName":"Security Form Settings","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_1","displayName":"Prompt User","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_2","displayName":"Automatically Approve","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_0","displayName":"Automatically Deny","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_programmaticsettings_l_oommeetingtaskrequest_v2_l_oommeetingtaskrequest_setting_3","displayName":"Prompt user based on computer security","description":null,"helpText":null}]},"f874fe4d7052ee22":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask","displayName":"Edits to total task % complete will be spread to the status date (User)","description":"Distributes the changes to total percent complete evenly across the schedule to the project status date (or to the current date if you haven't specified a project status date).\r\n\r\nIf you enable this setting, edits to total task percent complete are evenly distributed across the schedule up to the status date.\r\n\r\nIf you disable or do not configure this setting, the user's default setting is used.","helpText":"","infoUrls":[],"categoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","categoryName":"Calculation options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjcalculation~l_pjcalcprojectfile_l_pjeditstototaltask_1","displayName":"Enabled","description":null,"helpText":null}]},"f8e08bd72c9b9d4e":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15","displayName":"Trusted Location #15 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc15_1","displayName":"Enabled","description":null,"helpText":null}]},"f8e685c50fff5450":{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped","displayName":"Allow text to be dragged and dropped (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_pub16v2~policy~l_microsoftofficepublisher~l_puboptions~l_advanced_l_allowtexttobedraggedanddropped_1","displayName":"Enabled","description":null,"helpText":null}]},"f824b8e46a37c477":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting","displayName":"Print in background (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_backgroundprinting_1","displayName":"Enabled","description":null,"helpText":null}]},"f88ce86df100b68d":{"id":"vendor_msft_sharedpc_deletionpolicy","displayName":"Deletion Policy","description":"Configures when accounts will be deleted. Allowed values: 0 (delete immediately), 1 (delete at disk space threshold), 2 (Delete at disk space threshold and inactive threshold). If used, this value must be set before the action on the EnableSharedPCMode node is taken.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_deletionpolicy_0","displayName":"Delete immediately","description":"Delete immediately.","helpText":null},{"id":"vendor_msft_sharedpc_deletionpolicy_1","displayName":"Delete at disk space threshold","description":"Delete at disk space threshold","helpText":null},{"id":"vendor_msft_sharedpc_deletionpolicy_2","displayName":"Delete at disk space threshold and inactive threshold","description":"Delete at disk space threshold and inactive threshold","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/f9.json b/public/intune-definitions/f9.json index b12d6b34e9a8..4969511ad7f7 100644 --- a/public/intune-definitions/f9.json +++ b/public/intune-definitions/f9.json @@ -1 +1 @@ -{"f9de9f6461dce507":{"id":"com.apple.assetcache.managed_denytetheredcaching","displayName":"Deny Tethered Caching","description":"If true, disables tethered caching.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_denytetheredcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_denytetheredcaching_true","displayName":"True","description":null,"helpText":null}]},"f9171699cf8ebd11":{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming","displayName":"Allowed Protocol Mask In Roaming","description":"The supported Internet Protocol versions while roaming. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_2","displayName":"Both","description":null,"helpText":null}]},"f9b0e66e46f9eb3a":{"id":"com.apple.finder_prohibitburn","displayName":"Prohibit Burn","description":"If true, disables the Finder's burn support.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitburn_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitburn_true","displayName":"True","description":null,"helpText":null}]},"f9e11addd14e0359":{"id":"com.apple.managedclient.preferences_definitionupdatesinterval","displayName":"Security intelligence update interval (in seconds)","description":"Specifies the time interval (in seconds) after which security intelligence updates will be checked.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-preferences#security-intelligence-update-interval-in-seconds"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":null},"f993e9bf893f9b45":{"id":"com.apple.managedclient.preferences_overridesecurityrestrictionsoninsecureorigin","displayName":"Control where security restrictions on insecure origins apply","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*.contoso.com\") for which security restrictions on insecure origins don't apply.\n\nThis policy allows you to specify permitted origins for legacy applications that cannot deploy TLS or for internal web development staging servers. It enables developers to test features requiring secure contexts without the need to configure TLS on the staging server. Patterns are only accepted for hostnames; URLs or origins with schemes must be exact matches. This policy also prevents the origin from being labeled \"Not Secure\" in the omnibox.\n\nSetting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag.\n\nFor more information on secure contexts, see https://www.w3.org/TR/secure-contexts/.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#overridesecurityrestrictionsoninsecureorigin"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"f99ab7335f3a1143":{"id":"com.apple.mcxmenuextras_volume.menu","displayName":"Volume","description":"If true, enables the Volume menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_volume.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_volume.menu_true","displayName":"True","description":null,"helpText":null}]},"f9db0ca26254584f":{"id":"com.apple.mcxmenuextras_vpn.menu","displayName":"VPN","description":"If true, enables the VPN menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_vpn.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_vpn.menu_true","displayName":"True","description":null,"helpText":null}]},"f9ee852b0da8b953":{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators","displayName":"Disable Keyboard Filter For Administrators (Windows Insiders only)","description":"Determines if Keyboard Filter should be disabled for administrators. Defaults to false. If an admin is currently signed in when this value is set, it will take effect on the next sign-in. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":[{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators_false","displayName":"Blocked keys and scancodes are blocked for Administrators","description":"Blocked keys and scancodes are blocked for Administrators","helpText":null},{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators_true","displayName":"Blocked keys and scancodes are not blocked for Administrators","description":"Blocked keys and scancodes are not blocked for Administrators","helpText":null}]},"f9d1d55c8b84d513":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_1","displayName":"Enabled","description":null,"helpText":null}]},"f95c87ca445cd320":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode","displayName":"Set SYSVOL share compatibility","description":"This policy setting controls whether or not the SYSVOL share created by the Net Logon service on a domain controller (DC) should support compatibility in file sharing semantics with earlier applications.\r\n\r\nWhen this setting is enabled, the SYSVOL share will honor file sharing semantics that grant requests for exclusive read access to files on the share even when the caller has only read permission.\r\n\r\nWhen this setting is disabled or not configured, the SYSVOL share will grant shared read access to files on the share when exclusive access is requested and the caller has only read permission.\r\n\r\nBy default, the SYSVOL share will grant shared read access to files on the share when exclusive access is requested.\r\n\r\nNote: The SYSVOL share is a share created by the Net Logon service for use by Group Policy clients in the domain. The default behavior of the SYSVOL share ensures that no application with only read permission to files on the sysvol share can lock the files by requesting exclusive read access, which might prevent Group Policy settings from being updated on clients in the domain. When this setting is enabled, an application that relies on the ability to lock files on the SYSVOL share with only read permission will be able to deny Group Policy clients from reading the files, and in general the availability of the SYSVOL share on the domain will be decreased.\r\n\r\nIf you enable this policy setting, domain administrators should ensure that the only applications using the exclusive read capability in the domain are those approved by the administrator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sysvolsharecompatibilitymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode_1","displayName":"Enabled","description":null,"helpText":null}]},"f99a824629e793ec":{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle","displayName":"Interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_0","displayName":"Continuous","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_10","displayName":"10 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_30","displayName":"30 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_60","displayName":"1 Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_240","displayName":"4 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_480","displayName":"8 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_720","displayName":"12 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_1440","displayName":"1 Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_2880","displayName":"2 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_4320","displayName":"3 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_5760","displayName":"4 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_7200","displayName":"5 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_8640","displayName":"6 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_10080","displayName":"1 Week","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_20160","displayName":"2 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_30240","displayName":"3 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_40320","displayName":"4 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_50400","displayName":"5 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_60480","displayName":"6 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_70560","displayName":"7 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_4294967295","displayName":"Infinite","description":null,"helpText":null}]},"f9798938698058f8":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup","displayName":"Publisher 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Publisher 2016.\r\nMicrosoft Publisher 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Publisher 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Publisher 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Publisher 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016publisherbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"f923a370f030b385":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled","displayName":"Enable the creation of roaming copies for Google Chrome profile data","description":"If you enable this setting, the settings stored in Google Chrome profiles like bookmarks, autofill data, passwords, etc. will also be written to a file stored in the Roaming user profile folder or a location specified by the Administrator through the RoamingProfileLocation policy. Enabling this policy disables cloud sync.\r\n\r\nIf this policy is disabled or left not set only the regular local profiles will be used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f950abe56ab83ea3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar","displayName":"Show the Google Cast toolbar icon","description":"Setting the policy to Enabled displays the Cast toolbar icon on the toolbar or the overflow menu, and users can't remove it.\r\n\r\nSetting the policy to Disabled or leaving it unset lets users pin or remove the icon through its contextual menu.\r\n\r\nIf the policy EnableMediaRouter is set to Disabled, then this policy's value has no effect, and the toolbar icon doesn't appear.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar_1","displayName":"Enabled","description":null,"helpText":null}]},"f9aebc5264c0efd5":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_windowmanagementblockedforurlsdesc","displayName":"Block Window Management permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"f9b6c295424f831e":{"id":"device_vendor_msft_policy_config_errorreporting_displayerrornotification","displayName":"Display Error Notification","description":"This policy setting controls whether users are shown an error dialog box that lets them report an error.\n\nIf you enable this policy setting, users are notified in a dialog box that an error has occurred, and can display more details about the error. If the Configure Error Reporting policy setting is also enabled, the user can also report the error.\n\nIf you disable this policy setting, users are not notified that errors have occurred. If the Configure Error Reporting policy setting is also enabled, errors are reported, but users receive no notification. Disabling this policy setting is useful for servers that do not have interactive users.\n\nIf you do not configure this policy setting, users can change this setting in Control Panel, which is set to enable notification by default on computers that are running Windows XP Personal Edition and Windows XP Professional Edition, and disable notification by default on computers that are running Windows Server.\n\nSee also the Configure Error Reporting policy setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-errorreporting#errorreporting-displayerrornotification"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_errorreporting_displayerrornotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_errorreporting_displayerrornotification_1","displayName":"Enabled","description":null,"helpText":null}]},"f9af91e26f6fd51d":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesccdlocations","displayName":"CCD Locations","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nCCDLocations are formatted using a type, name and a connectionString separated using a ; as the delimiter. The type will accept either smb or azure. The name is a free-form field used to describe the location. The connectionString for smb type must include the full UNC path to the file share. The connectionString for azure type should be secured as per the documentation (https://aka.ms/fslogix). The strings are case sensitive.\r\n\r\n- CCDLocations using SMB: type=smb,name=\"SMB Share 1\",connectionString=\\\\\\;type=smb,name=\"SMB Share 2\"connectionString=\\\\\\\r\n\r\n- CCDLocations using Azure (secure): type=smb,name=\"SMB Share 1\",connectionString=\\\\\\;type=azure,name=\"Azure Blob 1\",connectionString=\"|fslogix/stgacct1-connectionstring|\"\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\CCDLocations\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"719595d8-ab5d-4418-88aa-8cd55c2964ba","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesccdlocations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesccdlocations_1","displayName":"Enabled","description":null,"helpText":null}]},"f942092646f01d7b":{"id":"device_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning","displayName":"Turn on certificate address mismatch warning","description":"This policy setting allows you to turn on the certificate address mismatch security warning. When this policy setting is turned on, the user is warned when visiting Secure HTTP (HTTPS) websites that present certificates issued for a different website address. This warning helps prevent spoofing attacks.\n\nIf you enable this policy setting, the certificate address mismatch warning always appears.\n\nIf you disable or do not configure this policy setting, the user can choose whether the certificate address mismatch warning appears (by using the Advanced page in the Internet Control panel).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowcertificateaddressmismatchwarning"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning_1","displayName":"Enabled","description":null,"helpText":null}]},"f995016feea6870b":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},"f9b9822e32128a67":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing","displayName":"Disable automatic upload of sign-in failure logs","description":"\r\nUploads the sign-in failure logs to the Microsoft Lync Server automatically for analysis. No logs will be automatically uploaded if sign-in is successful.\r\n\r\nIf this policy is not configured, then the following happens: \r\nFor Lync Online Users: Sign-in failure logs are automatically uploaded.\r\nFor Lync On-Premise Users: A confirmation seeking consent from the user is shown before upload.\r\n\r\nWhen this is disabled, sign-in logs would be uploaded to the Microsoft Lync Server for both Lync On-Premise and Online users automatically.\r\n\r\nWhen this is enabled, sign-in logs will never be uploaded automatically.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1","displayName":"Enabled","description":null,"helpText":null}]},"f9bcf485ca5cab7a":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir","displayName":"Set disk cache directory","description":"Configures the directory to use to store cached files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified the '--disk-cache-dir' flag. To avoid data loss or other unexpected errors, don't configure this policy to a volume's root directory or to a directory used for other purposes, because Microsoft Edge manages its contents.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use when specifying directories and paths.\r\n\r\nIf you don't configure this policy, the default cache directory is used, and users can override that default with the '--disk-cache-dir' command line flag.\r\n\r\nExample value: ${user_home}/Edge_cache","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},"f94415040ec30bf8":{"id":"device_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled","displayName":"Enable Application Bound Encryption","description":"Enabling this policy or leaving it unset binds the encryption keys used for local data storage to Microsoft Edge whenever possible.\r\n\r\nDisabling this policy has a detrimental effect on Microsoft Edge's security because unknown and potentially hostile apps can retrieve the encryption keys used to secure data.\r\n\r\nOnly turn off this policy if there are compatibility issues, such as scenarios where other applications need legitimate access to Microsoft Edge's data. Encrypted user data is expected to be fully portable between different computers or the integrity and location of Microsoft Edge's executable files isn’t consistent.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f95bda707d0da47f":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_insecureprivatenetworkrequestsallowedforurlsdesc","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":null},"f9d022c29b9f4171":{"id":"device_vendor_msft_policy_config_mixedreality_configuremovingplatform","displayName":"Configure Moving Platform","description":"This policy controls the behavior of moving platform feature on HoloLens 2, that is, whether it’s turned off / on or it can be toggled by a user. It should only be used by customers who intend to use HoloLens 2 in moving environments with low dynamic motion. Please refer to HoloLens 2 Moving Platform Mode for background information.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#configuremovingplatform"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_configuremovingplatform_0","displayName":"Last set user's preference. Initial state is OFF and after that user's preference is persisted across reboots and is used to initialize the system.","description":"Last set user's preference. Initial state is OFF and after that user's preference is persisted across reboots and is used to initialize the system.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_configuremovingplatform_1","displayName":"Moving platform is disabled and cannot be changed by user.","description":"Moving platform is disabled and cannot be changed by user.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_configuremovingplatform_2","displayName":"Moving platform is enabled and cannot be changed by user.","description":"Moving platform is enabled and cannot be changed by user.","helpText":null}]},"f9c1690878890b65":{"id":"device_vendor_msft_policy_config_networkisolation_enterprisenetworkdomainnames","displayName":"Enterprise Network Domain Names","description":"This is the list of domains that comprise the boundaries of the enterprise. Data from one of these domains that is sent to a device will be considered enterprise data and protected These locations will be considered a safe destination for enterprise data to be shared to. This is a comma-separated list of domains, for example contoso. sharepoint. com, Fabrikam. com. Note The client requires domain name to be canonical, otherwise the setting will be rejected by the client.  Here are the steps to create canonical domain names:Transform the ASCII characters (A-Z only) to lower case. For example, Microsoft. COM -> microsoft. com. Call IdnToAscii with IDN_USE_STD3_ASCII_RULES as the flags. Call IdnToUnicode with no flags set (dwFlags = 0).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterprisenetworkdomainnames"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":null},"f987769bd6b96241":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockknownfoldermove","displayName":"Prevent users from moving their Windows known folders to OneDrive","description":"This setting prevents users from moving their Documents, Pictures, and Desktop folders to any OneDrive for Business account.\r\nNote: Moving known folders to personal OneDrive accounts is already blocked on domain-joined PCs.\r\n\r\nIf you enable this setting, users won't be prompted with the \"Set up protection of important folders\" window, and the \"Start protection\" command will be disabled. If the user has already moved their known folders, the files in those folders will remain in OneDrive. This setting will not take effect if you enable \"Prompt users to move Windows known folders to OneDrive\" or \"Silently move Windows known folders to OneDrive.\"\r\n\r\nIf you disable or do not configure this setting, users can choose to move their known folders.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockknownfoldermove_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockknownfoldermove_1","displayName":"Enabled","description":null,"helpText":null}]},"f911467b6ea2e4b8":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory_forcedenytheseapps","displayName":"Let Apps Access Call History Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to call history. This setting overrides the default LetAppsAccessCallHistory policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscallhistory_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"f9cf893edcd90394":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessgazeinput_userincontroloftheseapps","displayName":"Let Apps Access Gaze Input User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. The user is able to control the eye tracker privacy setting for the listed apps. This setting overrides the default LetAppsAccessGazeInput policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessgazeinput_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"f9bbb5c4a0663edb":{"id":"mathsettings_calculator_inputmodes","displayName":"Input Modes","description":"If present, controls global input options of the calculator. If not present, all input modes are enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":null},"f9b16e71608c06fd":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepindocuments","displayName":"Documents (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepindocuments_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepindocuments_1","displayName":"True","description":null,"helpText":null}]},"f905228e7e493c93":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewcontextmenu","displayName":"Remove File Explorer's default context menu (User)","description":"Removes shortcut menus from the desktop and File Explorer. Shortcut menus appear when you right-click an item.\r\n\r\nIf you enable this setting, menus do not appear when you right-click the desktop or when you right-click the items in File Explorer. This setting does not prevent users from using other methods to issue commands available on the shortcut menus.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-noviewcontextmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewcontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewcontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"f98cbcd1ebebf587":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist_policydictionarymultiplesourcemergelistdesc","displayName":"Allow merging dictionary policies from different sources (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"f9761bad0735692e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":null},"f91209e11c0e955b":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"f91efd04d4c3ea53":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},"f9fb5f2e06ea0cf8":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer","displayName":"Send all intranet sites to Internet Explorer (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"f9bc1f48e04de37e":{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled","displayName":"Super Drag Drop Enabled (User)","description":"This policy lets you configure the Super Drag Drop feature in Microsoft Edge.\r\n\r\nWith this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine.\r\n\r\nIf you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f951a79fbf684fb7":{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_scarewareblockerallowlistdomainsdesc","displayName":"Configure the list of domains where Microsoft Edge scareware blocker won't run (User)","description":"","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},"f970edebe4642559":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_allowtokenbindingforurlsdesc","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"f95c4b7c45a3ec8c":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_managedsearchengines","displayName":"Manage Search Engines (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},"f91e03081bc3f177":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended","displayName":"Enable the default search provider (User)","description":"Enables the ability to use a default search provider.\r\n\r\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\r\n\r\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\r\n\r\nIf you disable this policy, the user can't search from the address bar.\r\n\r\nIf you enable or disable this policy, users can't change or override it.\r\n\r\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy.","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"f99a02d1ecec4cc2":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled (User)","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\r\n\r\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\r\n\r\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f997e7b2193a6727":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax_l_workfaxadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"f9feb96c4f4b1f2e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework_l_empty434","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":null},"f91ed8ffa649bcf4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5","displayName":"Places Bar Location 5 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_1","displayName":"Enabled","description":null,"helpText":null}]},"f91d42ba81f581ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst","displayName":"Open documents from Office Document Cache first (User)","description":"This policy setting allows the client application to open a document directly from the Office Document Cache if it is aware that the server the document resides on is not reachable. It may be useful in situations where you would like to wait to contact the server every time, time out and then fallback to the cache. \r\n\r\nIf you enable or do not configure this policy setting, documents will be opened directly from the Office Document Cache when the server the document resides on is not reachable. \r\n\r\nIf you disable this policy setting, Office will always attempt to first reach the server the document resides on before opening it from the Office Document Cache.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst_1","displayName":"Enabled","description":null,"helpText":null}]},"f9f39af930549e15":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta","displayName":"Disable Microsoft Office shared drawing code for metafile rendering (User)","description":"Disables nearly all EMF's and WMF's will no longer be converted at runtime to be anti-aliased. Examples of EMF/WMF's that would remain \"aliased\" are: clipart, OLE object placeholders, any user inserted EMF/WMF image, etc. Any EMF/WMF containing text would be an exception to this and would be still getting anti-aliased.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta_1","displayName":"Enabled","description":null,"helpText":null}]},"f9c61e34cc40d65d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings","displayName":"Suppress hyperlink warnings (User)","description":"This policy setting controls whether Office 2016 applications notify users about unsafe hyperlinks. Links that Office 2016 considers unsafe include links to executable files, TIFF files, and Microsoft Document Imaging (MDI) files. Other unsafe links are those that use protocols considered to be unsafe such as javascript. \r\n\r\nIf you enable this policy setting, unsafe hyperlink warnings are suppressed for all users. \r\n\r\nIf you disable or do not configure this policy setting, hyperlink warnings cannot be suppressed by any means. Office 2016 users will be notified that links are unsafe and must enable them manually to use them.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},"f9c97fccaa832de9":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges","displayName":"Add properties to attachments to enable Reply with Changes (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_1","displayName":"Enabled","description":null,"helpText":null}]},"f9329863790e8429":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions","displayName":"Outlook Rich Text options (User)","description":"This policy setting controls how Outlook sends Rich Text Format (RTF) messages to Internet recipients.\r\n\r\nIf you enable this policy setting, you may choose from the following for handling RTF messages addressed to recipients on the Internet:\r\n* Convert to Plain Text format - Outlook converts the message to plain text format in the default character set. Any message formatting will be lost.\r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically converts RTF formatted messages that are sent over the Internet to HTML format, so that the message formatting is maintained and attachments are received.","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"f98bdca0400ce1b9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize","displayName":"Allow attendees to propose new times for meetings you organize (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize_1","displayName":"Enabled","description":null,"helpText":null}]},"f97e5a6ce893a3d1":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist","displayName":"Specify path to Safe Senders list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Safe Senders list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_1","displayName":"Enabled","description":null,"helpText":null}]},"f9da7cc33f47af86":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders","displayName":"Use Protected View for attachments received from internal senders (User)","description":"This policy setting allows you to determine if attachments received from senders within your organization open in Protected View. This setting only applies to Outlook accounts setup to use an Exchange server.\r\n\r\nIf you enable this policy setting, attachments received from senders within your organization open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, attachments received from senders within your organization do not open in Protected View.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders_1","displayName":"Enabled","description":null,"helpText":null}]},"f98f45e3768398bb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy_l_additionalextensions23","displayName":"Additional Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},"f9f95fe3df69c4ba":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral","displayName":"Override published sync interval (User)","description":"By default, Outlook follows the sync interval specified by the Internet Calendar publisher and Internet Calendar subscriptions will not be sync'd more often than allowed by the Internet Calendar publisher. This setting allows you to prevent users from overriding the sync interval published by Internet Calendar publishers.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral_1","displayName":"Enabled","description":null,"helpText":null}]},"f925181895fc8b74":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt","displayName":"File tab | Options | Customize Ribbon | All Commands | Address (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt_1","displayName":"True","description":null,"helpText":null}]},"f9fad116930c5f73":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort","displayName":"New tasks are effort driven (User)","description":"This policy setting specifies that new tasks are scheduled such that the work on the task remains constant as you add or remove assignments.\r\n\r\nIf you enable this policy setting, new tasks will be effort-driven.\r\n\r\nIf you disable or do not configure this policy setting, new tasks will not be effort-driven.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort_1","displayName":"Enabled","description":null,"helpText":null}]},"f9ebe0ec54984f4d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext","displayName":"Do not show Mini Toolbar on selection of text (User)","description":"This policy setting allows you to configure the Mini Toolbar on selection of text.\r\n\r\nIf you enable this policy setting, the Mini Toolbar is not shown on selection.\r\n\r\nIf you disable or do not configure this policy setting, the Mini Toolbar is shown on selection.","helpText":"","infoUrls":[],"categoryId":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","categoryName":"User Interface Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext_1","displayName":"Enabled","description":null,"helpText":null}]},"f9bf9d9cc002dd1d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},"f97f5628a10735bd":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals","displayName":"Correct TWo INitial CApitals (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals_1","displayName":"Enabled","description":null,"helpText":null}]},"f99034cd990325ce":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit","displayName":"Format beginning of list item like the one before it (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit_1","displayName":"Enabled","description":null,"helpText":null}]},"f96383eb93ed03fb":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"f9e48cf30c719de8":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95_1","displayName":"True","description":null,"helpText":null}]},"f96fa428acb25f67":{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm","displayName":"Opportunistically Match Auth Set Per KM","description":"This value is used as an on/off switch. When this option is false, keying modules MUST ignore the entire authentication set if they do not support all of the authentication suites specified in the set. When this option is true, keying modules MUST ignore only the authentication suites that they don’t support. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm_true","displayName":"True","description":"TRUE","helpText":null}]}} \ No newline at end of file +{"f9de9f6461dce507":{"id":"com.apple.assetcache.managed_denytetheredcaching","displayName":"Deny Tethered Caching","description":"If true, disables tethered caching.","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":[{"id":"com.apple.assetcache.managed_denytetheredcaching_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.assetcache.managed_denytetheredcaching_true","displayName":"True","description":null,"helpText":null}]},"f9171699cf8ebd11":{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming","displayName":"Allowed Protocol Mask In Roaming","description":"The supported Internet Protocol versions while roaming. Available in iOS 10.3 and later.","helpText":null,"infoUrls":[],"categoryId":"5c722b3f-9d77-428a-b859-3fb556162cd6","categoryName":"Cellular","options":[{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_0","displayName":"IPv4","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_1","displayName":"IPv6","description":null,"helpText":null},{"id":"com.apple.cellular_apns_item_allowedprotocolmaskinroaming_2","displayName":"Both","description":null,"helpText":null}]},"f9b0e66e46f9eb3a":{"id":"com.apple.finder_prohibitburn","displayName":"Prohibit Burn","description":"If true, disables the Finder's burn support.","helpText":null,"infoUrls":[],"categoryId":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","categoryName":"Finder","options":[{"id":"com.apple.finder_prohibitburn_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.finder_prohibitburn_true","displayName":"True","description":null,"helpText":null}]},"f9e11addd14e0359":{"id":"com.apple.managedclient.preferences_definitionupdatesinterval","displayName":"Security intelligence update interval (in seconds)","description":"Specifies the time interval (in seconds) after which security intelligence updates will be checked.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-preferences#security-intelligence-update-interval-in-seconds"],"categoryId":"93099bd4-c685-434b-9d72-f0cb6db5e753","categoryName":"Cloud delivered protection preferences","options":null},"f993e9bf893f9b45":{"id":"com.apple.managedclient.preferences_overridesecurityrestrictionsoninsecureorigin","displayName":"Control where security restrictions on insecure origins apply","description":"Specifies a list of origins (URLs) or hostname patterns (like \"*.contoso.com\") for which security restrictions on insecure origins don't apply.\n\nThis policy allows you to specify permitted origins for legacy applications that cannot deploy TLS or for internal web development staging servers. It enables developers to test features requiring secure contexts without the need to configure TLS on the staging server. Patterns are only accepted for hostnames; URLs or origins with schemes must be exact matches. This policy also prevents the origin from being labeled \"Not Secure\" in the omnibox.\n\nSetting a list of URLs in this policy has the same effect as setting the command-line flag '--unsafely-treat-insecure-origin-as-secure' to a comma-separated list of the same URLs. If you enable this policy, it overrides the command-line flag.\n\nFor more information on secure contexts, see https://www.w3.org/TR/secure-contexts/.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#overridesecurityrestrictionsoninsecureorigin"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"f99ab7335f3a1143":{"id":"com.apple.mcxmenuextras_volume.menu","displayName":"Volume","description":"If true, enables the Volume menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_volume.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_volume.menu_true","displayName":"True","description":null,"helpText":null}]},"f9db0ca26254584f":{"id":"com.apple.mcxmenuextras_vpn.menu","displayName":"VPN","description":"If true, enables the VPN menu extra.","helpText":null,"infoUrls":[],"categoryId":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","categoryName":"Managed Menu Extras","options":[{"id":"com.apple.mcxmenuextras_vpn.menu_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.mcxmenuextras_vpn.menu_true","displayName":"True","description":null,"helpText":null}]},"f9f7a02a2ee9fac2":{"id":"contentcaching_listenranges","displayName":"Listen Ranges","description":"An array of dictionaries that describe a range of client IP addresses to serve.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"f9ee852b0da8b953":{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators","displayName":"Disable Keyboard Filter For Administrators (Windows Insiders only)","description":"Determines if Keyboard Filter should be disabled for administrators. Defaults to false. If an admin is currently signed in when this value is set, it will take effect on the next sign-in. \r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":[{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators_false","displayName":"Blocked keys and scancodes are blocked for Administrators","description":"Blocked keys and scancodes are blocked for Administrators","helpText":null},{"id":"device_vendor_msft_keyboardfilter_disablekeyboardfilterforadministrators_true","displayName":"Blocked keys and scancodes are not blocked for Administrators","description":"Blocked keys and scancodes are not blocked for Administrators","helpText":null}]},"f9d1d55c8b84d513":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3","displayName":"Control the location of the log file","description":"This policy setting controls the location of the log file. The location of the file must be writable by the Event Log service and should only be accessible to administrators.\r\n\r\nIf you enable this policy setting, the Event Log uses the path specified in this policy setting.\r\n\r\nIf you disable or do not configure this policy setting, the Event Log uses the folder %SYSTEMROOT%\\System32\\winevt\\Logs.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-eventlog#admx-eventlog-channel-logfilepath-3"],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":[{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_logfilepath_3_1","displayName":"Enabled","description":null,"helpText":null}]},"f95c87ca445cd320":{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode","displayName":"Set SYSVOL share compatibility","description":"This policy setting controls whether or not the SYSVOL share created by the Net Logon service on a domain controller (DC) should support compatibility in file sharing semantics with earlier applications.\r\n\r\nWhen this setting is enabled, the SYSVOL share will honor file sharing semantics that grant requests for exclusive read access to files on the share even when the caller has only read permission.\r\n\r\nWhen this setting is disabled or not configured, the SYSVOL share will grant shared read access to files on the share when exclusive access is requested and the caller has only read permission.\r\n\r\nBy default, the SYSVOL share will grant shared read access to files on the share when exclusive access is requested.\r\n\r\nNote: The SYSVOL share is a share created by the Net Logon service for use by Group Policy clients in the domain. The default behavior of the SYSVOL share ensures that no application with only read permission to files on the sysvol share can lock the files by requesting exclusive read access, which might prevent Group Policy settings from being updated on clients in the domain. When this setting is enabled, an application that relies on the ability to lock files on the SYSVOL share with only read permission will be able to deny Group Policy clients from reading the files, and in general the availability of the SYSVOL share on the domain will be decreased.\r\n\r\nIf you enable this policy setting, domain administrators should ensure that the only applications using the exclusive read capability in the domain are those approved by the administrator.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-netlogon#admx-netlogon-netlogon-sysvolsharecompatibilitymode"],"categoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","categoryName":"Net Logon","options":[{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_netlogon_netlogon_sysvolsharecompatibilitymode_1","displayName":"Enabled","description":null,"helpText":null}]},"f99a824629e793ec":{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle","displayName":"Interval:","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_0","displayName":"Continuous","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_10","displayName":"10 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_30","displayName":"30 Minutes","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_60","displayName":"1 Hour","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_240","displayName":"4 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_480","displayName":"8 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_720","displayName":"12 Hours","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_1440","displayName":"1 Day","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_2880","displayName":"2 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_4320","displayName":"3 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_5760","displayName":"4 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_7200","displayName":"5 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_8640","displayName":"6 Days","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_10080","displayName":"1 Week","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_20160","displayName":"2 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_30240","displayName":"3 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_40320","displayName":"4 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_50400","displayName":"5 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_60480","displayName":"6 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_70560","displayName":"7 Weeks","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing2_pruninginterval_pruningintervaltitle_4294967295","displayName":"Infinite","description":null,"helpText":null}]},"f9798938698058f8":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup","displayName":"Publisher 2016 backup only","description":"\r\nThis policy setting configures the backup of certain user settings for Microsoft Publisher 2016.\r\nMicrosoft Publisher 2016 has user settings that are backed up instead of synchronizing between computers. Use the policy setting to suppress the backup of specific Microsoft Publisher 2016 settings.\r\nIf you enable this policy setting, certain user settings of Microsoft Publisher 2016 will continue to be backed up.\r\nIf you disable this policy setting, certain user settings of Microsoft Publisher 2016 will not be backed up.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016publisherbackup"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016publisherbackup_1","displayName":"Enabled","description":null,"helpText":null}]},"f923a370f030b385":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled","displayName":"Enable the creation of roaming copies for Google Chrome profile data","description":"If you enable this setting, the settings stored in Google Chrome profiles like bookmarks, autofill data, passwords, etc. will also be written to a file stored in the Roaming user profile folder or a location specified by the Administrator through the RoamingProfileLocation policy. Enabling this policy disables cloud sync.\r\n\r\nIf this policy is disabled or left not set only the regular local profiles will be used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilesupportenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f950abe56ab83ea3":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar","displayName":"Show the Google Cast toolbar icon","description":"Setting the policy to Enabled displays the Cast toolbar icon on the toolbar or the overflow menu, and users can't remove it.\r\n\r\nSetting the policy to Disabled or leaving it unset lets users pin or remove the icon through its contextual menu.\r\n\r\nIf the policy EnableMediaRouter is set to Disabled, then this policy's value has no effect, and the toolbar icon doesn't appear.","helpText":"","infoUrls":[],"categoryId":"f7486553-9e63-4d63-9423-56e5ffe48700","categoryName":"Google Cast","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~googlecast_showcasticonintoolbar_1","displayName":"Enabled","description":null,"helpText":null}]},"f9aebc5264c0efd5":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_windowmanagementblockedforurlsdesc","displayName":"Block Window Management permission on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"f9b6c295424f831e":{"id":"device_vendor_msft_policy_config_errorreporting_displayerrornotification","displayName":"Display Error Notification","description":"This policy setting controls whether users are shown an error dialog box that lets them report an error.\n\nIf you enable this policy setting, users are notified in a dialog box that an error has occurred, and can display more details about the error. If the Configure Error Reporting policy setting is also enabled, the user can also report the error.\n\nIf you disable this policy setting, users are not notified that errors have occurred. If the Configure Error Reporting policy setting is also enabled, errors are reported, but users receive no notification. Disabling this policy setting is useful for servers that do not have interactive users.\n\nIf you do not configure this policy setting, users can change this setting in Control Panel, which is set to enable notification by default on computers that are running Windows XP Personal Edition and Windows XP Professional Edition, and disable notification by default on computers that are running Windows Server.\n\nSee also the Configure Error Reporting policy setting.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-errorreporting#errorreporting-displayerrornotification"],"categoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","categoryName":"Windows Error Reporting","options":[{"id":"device_vendor_msft_policy_config_errorreporting_displayerrornotification_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_errorreporting_displayerrornotification_1","displayName":"Enabled","description":null,"helpText":null}]},"f9af91e26f6fd51d":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesccdlocations","displayName":"CCD Locations","description":"NOTE: Once this policy is Enabled, only Disable will remove the registry value. Enabled to Not Configured will have NO EFFECT.\r\n\r\nCCDLocations are formatted using a type, name and a connectionString separated using a ; as the delimiter. The type will accept either smb or azure. The name is a free-form field used to describe the location. The connectionString for smb type must include the full UNC path to the file share. The connectionString for azure type should be secured as per the documentation (https://aka.ms/fslogix). The strings are case sensitive.\r\n\r\n- CCDLocations using SMB: type=smb,name=\"SMB Share 1\",connectionString=\\\\\\;type=smb,name=\"SMB Share 2\"connectionString=\\\\\\\r\n\r\n- CCDLocations using Azure (secure): type=smb,name=\"SMB Share 1\",connectionString=\\\\\\;type=azure,name=\"Azure Blob 1\",connectionString=\"|fslogix/stgacct1-connectionstring|\"\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\CCDLocations\r\nType: REG_SZ","helpText":"","infoUrls":[],"categoryId":"719595d8-ab5d-4418-88aa-8cd55c2964ba","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesccdlocations_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_ccd_profilesccdlocations_1","displayName":"Enabled","description":null,"helpText":null}]},"f942092646f01d7b":{"id":"device_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning","displayName":"Turn on certificate address mismatch warning","description":"This policy setting allows you to turn on the certificate address mismatch security warning. When this policy setting is turned on, the user is warned when visiting Secure HTTP (HTTPS) websites that present certificates issued for a different website address. This warning helps prevent spoofing attacks.\n\nIf you enable this policy setting, the certificate address mismatch warning always appears.\n\nIf you disable or do not configure this policy setting, the user can choose whether the certificate address mismatch warning appears (by using the Advanced page in the Internet Control panel).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowcertificateaddressmismatchwarning"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_allowcertificateaddressmismatchwarning_1","displayName":"Enabled","description":null,"helpText":null}]},"f995016feea6870b":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102","displayName":"Allow script-initiated windows without size or position constraints","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowscriptinitiatedwindows_iz_partname2102_3","displayName":"Disable","description":null,"helpText":null}]},"f9b9822e32128a67":{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing","displayName":"Disable automatic upload of sign-in failure logs","description":"\r\nUploads the sign-in failure logs to the Microsoft Lync Server automatically for analysis. No logs will be automatically uploaded if sign-in is successful.\r\n\r\nIf this policy is not configured, then the following happens: \r\nFor Lync Online Users: Sign-in failure logs are automatically uploaded.\r\nFor Lync On-Premise Users: A confirmation seeking consent from the user is shown before upload.\r\n\r\nWhen this is disabled, sign-in logs would be uploaded to the Microsoft Lync Server for both Lync On-Premise and Online users automatically.\r\n\r\nWhen this is enabled, sign-in logs will never be uploaded automatically.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1","displayName":"Enabled","description":null,"helpText":null}]},"f9bcf485ca5cab7a":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir","displayName":"Set disk cache directory","description":"Configures the directory to use to store cached files.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory regardless of whether the user has specified the '--disk-cache-dir' flag. To avoid data loss or other unexpected errors, don't configure this policy to a volume's root directory or to a directory used for other purposes, because Microsoft Edge manages its contents.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use when specifying directories and paths.\r\n\r\nIf you don't configure this policy, the default cache directory is used, and users can override that default with the '--disk-cache-dir' command line flag.\r\n\r\nExample value: ${user_home}/Edge_cache","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_diskcachedir_1","displayName":"Enabled","description":null,"helpText":null}]},"f94415040ec30bf8":{"id":"device_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled","displayName":"Enable Application Bound Encryption","description":"Enabling this policy or leaving it unset binds the encryption keys used for local data storage to Microsoft Edge whenever possible.\r\n\r\nDisabling this policy has a detrimental effect on Microsoft Edge's security because unknown and potentially hostile apps can retrieve the encryption keys used to secure data.\r\n\r\nOnly turn off this policy if there are compatibility issues, such as scenarios where other applications need legitimate access to Microsoft Edge's data. Encrypted user data is expected to be fully portable between different computers or the integrity and location of Microsoft Edge's executable files isn’t consistent.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev128.1~policy~microsoft_edge_applicationboundencryptionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f95bda707d0da47f":{"id":"device_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge~privatenetworkrequestsettings_insecureprivatenetworkrequestsallowedforurls_insecureprivatenetworkrequestsallowedforurlsdesc","displayName":"Allow the listed sites to make requests to more-private network endpoints from insecure contexts (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":null},"f9d022c29b9f4171":{"id":"device_vendor_msft_policy_config_mixedreality_configuremovingplatform","displayName":"Configure Moving Platform","description":"This policy controls the behavior of moving platform feature on HoloLens 2, that is, whether it’s turned off / on or it can be toggled by a user. It should only be used by customers who intend to use HoloLens 2 in moving environments with low dynamic motion. Please refer to HoloLens 2 Moving Platform Mode for background information.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-MixedReality#configuremovingplatform"],"categoryId":"f10138ba-123a-43bc-8031-4458ba327374","categoryName":"Mixed Reality","options":[{"id":"device_vendor_msft_policy_config_mixedreality_configuremovingplatform_0","displayName":"Last set user's preference. Initial state is OFF and after that user's preference is persisted across reboots and is used to initialize the system.","description":"Last set user's preference. Initial state is OFF and after that user's preference is persisted across reboots and is used to initialize the system.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_configuremovingplatform_1","displayName":"Moving platform is disabled and cannot be changed by user.","description":"Moving platform is disabled and cannot be changed by user.","helpText":null},{"id":"device_vendor_msft_policy_config_mixedreality_configuremovingplatform_2","displayName":"Moving platform is enabled and cannot be changed by user.","description":"Moving platform is enabled and cannot be changed by user.","helpText":null}]},"f9c1690878890b65":{"id":"device_vendor_msft_policy_config_networkisolation_enterprisenetworkdomainnames","displayName":"Enterprise Network Domain Names","description":"This is the list of domains that comprise the boundaries of the enterprise. Data from one of these domains that is sent to a device will be considered enterprise data and protected These locations will be considered a safe destination for enterprise data to be shared to. This is a comma-separated list of domains, for example contoso. sharepoint. com, Fabrikam. com. Note The client requires domain name to be canonical, otherwise the setting will be rejected by the client.  Here are the steps to create canonical domain names:Transform the ASCII characters (A-Z only) to lower case. For example, Microsoft. COM -> microsoft. com. Call IdnToAscii with IDN_USE_STD3_ASCII_RULES as the flags. Call IdnToUnicode with no flags set (dwFlags = 0).","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-NetworkIsolation#enterprisenetworkdomainnames"],"categoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","categoryName":"Network Isolation","options":null},"f987769bd6b96241":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockknownfoldermove","displayName":"Prevent users from moving their Windows known folders to OneDrive","description":"This setting prevents users from moving their Documents, Pictures, and Desktop folders to any OneDrive for Business account.\r\nNote: Moving known folders to personal OneDrive accounts is already blocked on domain-joined PCs.\r\n\r\nIf you enable this setting, users won't be prompted with the \"Set up protection of important folders\" window, and the \"Start protection\" command will be disabled. If the user has already moved their known folders, the files in those folders will remain in OneDrive. This setting will not take effect if you enable \"Prompt users to move Windows known folders to OneDrive\" or \"Silently move Windows known folders to OneDrive.\"\r\n\r\nIf you disable or do not configure this setting, users can choose to move their known folders.","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":[{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockknownfoldermove_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_blockknownfoldermove_1","displayName":"Enabled","description":null,"helpText":null}]},"f911467b6ea2e4b8":{"id":"device_vendor_msft_policy_config_privacy_letappsaccesscallhistory_forcedenytheseapps","displayName":"Let Apps Access Call History Force Deny These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. Listed Windows apps are denied access to call history. This setting overrides the default LetAppsAccessCallHistory policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccesscallhistory_forcedenytheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"f9cf893edcd90394":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessgazeinput_userincontroloftheseapps","displayName":"Let Apps Access Gaze Input User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Windows Store Apps. The user is able to control the eye tracker privacy setting for the listed apps. This setting overrides the default LetAppsAccessGazeInput policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessgazeinput_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"f9bbb5c4a0663edb":{"id":"mathsettings_calculator_inputmodes","displayName":"Input Modes","description":"If present, controls global input options of the calculator. If not present, all input modes are enabled.","helpText":null,"infoUrls":[],"categoryId":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","categoryName":"Math Settings","options":null},"f9b16e71608c06fd":{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepindocuments","displayName":"Documents (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"45d15759-2add-40db-9294-d1b391515dba","categoryName":"Folder Redirection","options":[{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepindocuments_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_folderredirection_disablefradminpinbyfolder_disablepindocuments_1","displayName":"True","description":null,"helpText":null}]},"f905228e7e493c93":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewcontextmenu","displayName":"Remove File Explorer's default context menu (User)","description":"Removes shortcut menus from the desktop and File Explorer. Shortcut menus appear when you right-click an item.\r\n\r\nIf you enable this setting, menus do not appear when you right-click the desktop or when you right-click the items in File Explorer. This setting does not prevent users from using other methods to issue commands available on the shortcut menus.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-noviewcontextmenu"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewcontextmenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_noviewcontextmenu_1","displayName":"Enabled","description":null,"helpText":null}]},"f98cbcd1ebebf587":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_policydictionarymultiplesourcemergelist_policydictionarymultiplesourcemergelistdesc","displayName":"Allow merging dictionary policies from different sources (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"f9761bad0735692e":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_l_setmaximumnumberoftrusteddocumentsspinid","displayName":"Maximum number: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7490c4fd-c326-42f7-9908-006504616d4c","categoryName":"Trust Center","options":null},"f91209e11c0e955b":{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_internetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"f91efd04d4c3ea53":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneinitializeandscriptactivexcontrols_iz_partname1201_1","displayName":"Prompt","description":null,"helpText":null}]},"f9fb5f2e06ea0cf8":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer","displayName":"Send all intranet sites to Internet Explorer (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"f9bc1f48e04de37e":{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled","displayName":"Super Drag Drop Enabled (User)","description":"This policy lets you configure the Super Drag Drop feature in Microsoft Edge.\r\n\r\nWith this feature, users can drag a link or text from a webpage and drop it onto the same page. They can then either open the URL in a new tab or search the text using the default search engine.\r\n\r\nIf you enable or don't configure this policy, you can use the Super Drag Drop feature on Microsoft Edge.\r\n\r\nIf you disable this policy, you can't use the Super Drag Drop feature in Microsoft Edge.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev122~policy~microsoft_edge_superdragdropenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f951a79fbf684fb7":{"id":"user_vendor_msft_policy_config_microsoft_edgev142~policy~microsoft_edge~scarewareblocker_scarewareblockerallowlistdomains_scarewareblockerallowlistdomainsdesc","displayName":"Configure the list of domains where Microsoft Edge scareware blocker won't run (User)","description":"","helpText":"","infoUrls":[],"categoryId":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","categoryName":"Scareware Blocker settings","options":null},"f970edebe4642559":{"id":"user_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_allowtokenbindingforurls_allowtokenbindingforurlsdesc","displayName":"Configure the list of sites for which Microsoft Edge will attempt to establish a Token Binding with. (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"f95c4b7c45a3ec8c":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended_managedsearchengines_recommended_managedsearchengines","displayName":"Manage Search Engines (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":null},"f91e03081bc3f177":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended","displayName":"Enable the default search provider (User)","description":"Enables the ability to use a default search provider.\r\n\r\nIf you enable this policy, a user can search for a term by typing in the address bar (as long as what they type isn't a URL).\r\n\r\nYou can specify the default search provider to use by enabling the rest of the default search policies. If these are left empty (not configured) or configured incorrectly, the user can choose the default provider.\r\n\r\nIf you disable this policy, the user can't search from the address bar.\r\n\r\nIf you enable or disable this policy, users can't change or override it.\r\n\r\nIf you don't configure this policy, the default search provider is enabled, and the user can choose the default search provider and set the search provider list.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain, joined to Microsoft Azure Active Directory, or instances that enrolled for device management. On macOS, this policy is available only on instances that are managed via MDM or joined to a domain via MCX.\r\n\r\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy.","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchproviderenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"f99a02d1ecec4cc2":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled","displayName":"Shopping in Microsoft Edge Enabled (User)","description":"This policy lets users compare the prices of a product they are looking at, get coupons from the website they're on, or auto-apply coupons during checkout.\r\n\r\nIf you enable or don't configure this policy, shopping features such as price comparison and coupons will be automatically applied for retail domains. Coupons for the current retailer and prices from other retailers will be fetched from a server.\r\n\r\nIf you disable this policy shopping features such as price comparison and coupons will not be automatically found for retail domains.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_edgeshoppingassistantenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"f997e7b2193a6727":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabadreplaceworkfax_l_workfaxadreplace","displayName":"AD Attribute: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"f9feb96c4f4b1f2e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_downloadingframeworkcomponents_l_setdownloadlocationfornet20framework_l_empty434","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"bc633a5a-c712-49a6-9f56-775ca9321df4","categoryName":"Downloading Framework Components","options":null},"f91ed8ffa649bcf4":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5","displayName":"Places Bar Location 5 (User)","description":"This setting configures the list of items displayed in the Places Bar of the Common File dialog boxes. Valid items include browseable paths and environment variables of the form %...%. Items will be displayed in the Places Bar in the order in which they are entered into the template.","helpText":"","infoUrls":[],"categoryId":"4a832199-a841-4b6a-84fa-51365902a742","categoryName":"Places Bar Locations","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_fileopensave~l_placesbarlocations_l_placesbarlocationpolicy5_1","displayName":"Enabled","description":null,"helpText":null}]},"f91d42ba81f581ea":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst","displayName":"Open documents from Office Document Cache first (User)","description":"This policy setting allows the client application to open a document directly from the Office Document Cache if it is aware that the server the document resides on is not reachable. It may be useful in situations where you would like to wait to contact the server every time, time out and then fallback to the cache. \r\n\r\nIf you enable or do not configure this policy setting, documents will be opened directly from the Office Document Cache when the server the document resides on is not reachable. \r\n\r\nIf you disable this policy setting, Office will always attempt to first reach the server the document resides on before opening it from the Office Document Cache.","helpText":"","infoUrls":[],"categoryId":"2d6891a4-ee83-4e55-8e23-09513e1306e4","categoryName":"Microsoft Office Document Cache","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_microsoftofficedocumentcache_l_opendocumentsfromofficedocumentcachefirst_1","displayName":"Enabled","description":null,"helpText":null}]},"f9f39af930549e15":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta","displayName":"Disable Microsoft Office shared drawing code for metafile rendering (User)","description":"Disables nearly all EMF's and WMF's will no longer be converted at runtime to be anti-aliased. Examples of EMF/WMF's that would remain \"aliased\" are: clipart, OLE object placeholders, any user inserted EMF/WMF image, etc. Any EMF/WMF containing text would be an exception to this and would be still getting anti-aliased.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437_l_microsoftofficeshareddrawingcodeformeta_1","displayName":"Enabled","description":null,"helpText":null}]},"f9c61e34cc40d65d":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings","displayName":"Suppress hyperlink warnings (User)","description":"This policy setting controls whether Office 2016 applications notify users about unsafe hyperlinks. Links that Office 2016 considers unsafe include links to executable files, TIFF files, and Microsoft Document Imaging (MDI) files. Other unsafe links are those that use protocols considered to be unsafe such as javascript. \r\n\r\nIf you enable this policy setting, unsafe hyperlink warnings are suppressed for all users. \r\n\r\nIf you disable or do not configure this policy setting, hyperlink warnings cannot be suppressed by any means. Office 2016 users will be notified that links are unsafe and must enable them manually to use them.","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_suppresshyperlinkwarnings_1","displayName":"Enabled","description":null,"helpText":null}]},"f9c97fccaa832de9":{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges","displayName":"Add properties to attachments to enable Reply with Changes (User)","description":"Sets the value for the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"832f3a51-5e73-4541-8f14-1323cd9919bc","categoryName":"When sending a message","options":[{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v18~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_emailoptions~l_advancedemailoptions~l_whensendingamessagecategory_l_addpropertiestoattachmentstoenablereplywithchanges_1","displayName":"Enabled","description":null,"helpText":null}]},"f9329863790e8429":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions","displayName":"Outlook Rich Text options (User)","description":"This policy setting controls how Outlook sends Rich Text Format (RTF) messages to Internet recipients.\r\n\r\nIf you enable this policy setting, you may choose from the following for handling RTF messages addressed to recipients on the Internet:\r\n* Convert to Plain Text format - Outlook converts the message to plain text format in the default character set. Any message formatting will be lost.\r\n\r\nIf you disable or do not configure this policy setting, Outlook automatically converts RTF formatted messages that are sent over the Internet to HTML format, so that the message formatting is maintained and attachments are received.","helpText":"","infoUrls":[],"categoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","categoryName":"Internet Formatting","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_mailformat~l_internetformatting_l_outlookrichtextoptions_1","displayName":"Enabled","description":null,"helpText":null}]},"f98bdca0400ce1b9":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize","displayName":"Allow attendees to propose new times for meetings you organize (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","categoryName":"Calendar Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions_l_allowattendeestoproposenewtimesformeetingsyouorganize_1","displayName":"Enabled","description":null,"helpText":null}]},"f97e5a6ce893a3d1":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist","displayName":"Specify path to Safe Senders list (User)","description":"Specify a text file containing a list of e-mail addresses to append to or overwrite the Safe Senders list (depending on the policy \"Overwrite or Append Junk Mail Import List\").","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtosafesenderslist_1","displayName":"Enabled","description":null,"helpText":null}]},"f9da7cc33f47af86":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders","displayName":"Use Protected View for attachments received from internal senders (User)","description":"This policy setting allows you to determine if attachments received from senders within your organization open in Protected View. This setting only applies to Outlook accounts setup to use an Exchange server.\r\n\r\nIf you enable this policy setting, attachments received from senders within your organization open in Protected View.\r\n\r\nIf you disable or do not configure this policy setting, attachments received from senders within your organization do not open in Protected View.","helpText":"","infoUrls":[],"categoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security_l_useprotectedviewforattachmentsreceivedfrominternalsenders_1","displayName":"Enabled","description":null,"helpText":null}]},"f98f45e3768398bb":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_securityformsettings~l_miscattachmentsettings_l_level2addfilepolicy_l_additionalextensions23","displayName":"Additional Extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c400a917-cdff-4e15-a70f-59b82df4c038","categoryName":"Attachment Security","options":null},"f9f95fe3df69c4ba":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral","displayName":"Override published sync interval (User)","description":"By default, Outlook follows the sync interval specified by the Internet Calendar publisher and Internet Calendar subscriptions will not be sync'd more often than allowed by the Internet Calendar publisher. This setting allows you to prevent users from overriding the sync interval published by Internet Calendar publishers.","helpText":"","infoUrls":[],"categoryId":"060e7533-6c2f-4ed1-9173-f3de58de4bed","categoryName":"Internet Calendars","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_webcalsubscriptions_l_overridepublishedsyncinteral_1","displayName":"Enabled","description":null,"helpText":null}]},"f925181895fc8b74":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt","displayName":"File tab | Options | Customize Ribbon | All Commands | Address (User)","description":"","helpText":"","infoUrls":[],"categoryId":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_webaddressppt_1","displayName":"True","description":null,"helpText":null}]},"f9fad116930c5f73":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort","displayName":"New tasks are effort driven (User)","description":"This policy setting specifies that new tasks are scheduled such that the work on the task remains constant as you add or remove assignments.\r\n\r\nIf you enable this policy setting, new tasks will be effort-driven.\r\n\r\nIf you disable or do not configure this policy setting, new tasks will not be effort-driven.","helpText":"","infoUrls":[],"categoryId":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","categoryName":"Scheduling options for 'Project1'","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_pjschedule~l_pjscheddoc_l_pjnewtaskseffort_1","displayName":"Enabled","description":null,"helpText":null}]},"f9ebe0ec54984f4d":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext","displayName":"Do not show Mini Toolbar on selection of text (User)","description":"This policy setting allows you to configure the Mini Toolbar on selection of text.\r\n\r\nIf you enable this policy setting, the Mini Toolbar is not shown on selection.\r\n\r\nIf you disable or do not configure this policy setting, the Mini Toolbar is shown on selection.","helpText":"","infoUrls":[],"categoryId":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","categoryName":"User Interface Options","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_general~l_userinterfaceoptions_l_donotshowminitoolbaronselectionoftext_1","displayName":"Enabled","description":null,"helpText":null}]},"f9bf9d9cc002dd1d":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_advanced_l_setnumberofplacesintherecentplaceslist_l_setnumberofplacesintherecentplaceslistspinid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"83087772-6560-4488-a1c5-bb6e4889e868","categoryName":"Advanced","options":null},"f97f5628a10735bd":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals","displayName":"Correct TWo INitial CApitals (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e95db55a-8337-416d-a61f-e60f55cc0d13","categoryName":"AutoCorrect","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autocorrect_l_correcttwoinitialcapitals_1","displayName":"Enabled","description":null,"helpText":null}]},"f99034cd990325ce":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit","displayName":"Format beginning of list item like the one before it (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"e8ce968b-91cb-4301-ba98-b37d42bc5213","categoryName":"Automatically as you type","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_proofing~l_autoformatasyoutype~l_automaticallyasyoutype_l_formatbeginningoflistitemliketheonebeforeit_1","displayName":"Enabled","description":null,"helpText":null}]},"f96383eb93ed03fb":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2003binarydocumentsandtemplates_l_word2003binarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"f9e48cf30c719de8":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc20_l_allowsubfolders95_1","displayName":"True","description":null,"helpText":null}]},"f96fa428acb25f67":{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm","displayName":"Opportunistically Match Auth Set Per KM","description":"This value is used as an on/off switch. When this option is false, keying modules MUST ignore the entire authentication set if they do not support all of the authentication suites specified in the set. When this option is true, keying modules MUST ignore only the authentication suites that they don’t support. For schema versions 0x0200, 0x0201, and 0x020A, this value is invalid and MUST NOT be used.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm_false","displayName":"False","description":"FALSE","helpText":null},{"id":"vendor_msft_firewall_mdmstore_global_opportunisticallymatchauthsetperkm_true","displayName":"True","description":"TRUE","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/fb.json b/public/intune-definitions/fb.json index 7e3cdf484fce..c9b563174c2c 100644 --- a/public/intune-definitions/fb.json +++ b/public/intune-definitions/fb.json @@ -1 +1 @@ -{"fbeb87c361570def":{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp","displayName":"Block USB file transfer","description":"If 'True', prevents users from transferring files over USB. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to transfer files.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp_true","displayName":"True","description":"True","helpText":null}]},"fb8e2e214870e268":{"id":"com.apple.applicationaccess_deniediccidsforrcs","displayName":"Denied ICCIDs For RCS","description":"An array of strings representing ICCIDs of cellular plans. The device prevents use of any matching cellular networks with RCS messaging. The array must contain no more than 4 ICCID strings.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},"fbe5fccd77812f31":{"id":"com.apple.applicationaccess_ratingtvshowsfr","displayName":"Rating TV Shows - France","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_1","displayName":"-10","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_2","displayName":"-12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_3","displayName":"-16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_4","displayName":"-18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_5","displayName":"All","description":null,"helpText":null}]},"fbbc551328c9e4b5":{"id":"com.apple.assetcache.managed_datapath","displayName":"Data Path","description":"The path to the directory used to store cached content. Changing this setting manually doesn't automatically move cached content from the old location to the new one. To move content automatically, use the Sharing preference's Content Caching pane. The value must be (or end with) /Library/Application Support/Apple/AssetCache/Data.\r\nA directory and its intermediates are created for the given data path if it doesn't already exist. The directory is owned by _assetcache:_assetcache and has mode 0750. Its immediate parent directory (.../Library/Application Support/Apple/AssetCache) is owned by _assetcache:_assetcache and has mode 0755. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},"fb945143571c2c95":{"id":"com.apple.extensiblesso_platformsso_additionalgroups","displayName":"Additional Groups","description":"The list of groups that are created and do not have administrator access.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"fb6a3caee0aceb7a":{"id":"com.apple.managedclient.preferences_developertoolsavailability","displayName":"Control where developer tools can be used","description":"Control where developer tools can be used.\n\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (0, the default), users can access the developer tools and the JavaScript console in general, but not in the context of extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsAllowed' (1), users can access the developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsDisallowed' (2), users can't access the developer tools or inspect website elements. Keyboard shortcuts and menu or context menu entries that open the developer tools or the JavaScript Console are disabled.\n\n* 0 = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\n\n* 1 = Allow using the developer tools\n\n* 2 = Don't allow using the developer tools","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#developertoolsavailability"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_developertoolsavailability_0","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_developertoolsavailability_1","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_developertoolsavailability_2","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},"fb93a98aeba3d5a4":{"id":"com.apple.managedclient.preferences_exclusions","displayName":"Scan exclusions","description":"Entities that have been excluded from the scan. Exclusions can be specified by full paths, extensions, or file names.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#scan-exclusions"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"fbe973e347c2118c":{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud","displayName":"Fallback to Microsoft cloud updates","description":"Determine the Defender for Endpoint security intelligence update approach when offline mirror server fails to serve the update request. If set to true, the update is retried via the Microsoft cloud when offline security intelligence update failed.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update#configure-the-endpoints"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud_true","displayName":"Enabled","description":null,"helpText":null}]},"fb34961e737d6a2a":{"id":"com.apple.managedclient.preferences_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\n\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\n\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\n\nIf you set this policy to zero or don't configure it, the system default resolution will be used during rasterization of page images.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printrasterizepdfdpi"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"fb6e17ff943fa896":{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers","displayName":"Registered Protocol Handlers","description":"Register a list of protocol handlers. Set the protocol property to the scheme (like 'mailto') and the url property to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which will be replaced by the handled URL.\n\nYou can recommend a specific value for this policy, but you can't require that your users use it.\n\nThe protocol handlers registered by policy are merged with any handlers registered by the user, and both are available for use. The user can override the protocol handlers installed by policy by installing a new default handler, but they can't remove a protocol handler registered by policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#registeredprotocolhandlers"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"fb3d470df9c89159":{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies","displayName":"Block third party cookies","description":"This policy controls whether third-party cookies are blocked in regular browsing sessions.\n\nIf you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies.\n\nIf you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar.\n\nIf you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.\n\nNote: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_true","displayName":"Enabled","description":null,"helpText":null}]},"fbc3a60df74fa000":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\n\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\n\nIf you enable this policy, Microsoft Edge sends data to the Microsoft Edge service when a user tries to install a blocked extension.\n\nIf you disable or don't configure this policy, Microsoft Edge can't send any data to the Microsoft Edge service about blocked extensions.","helpText":null,"infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fbc24d4f24cde70d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet","displayName":"Enhanced Security Mode configuration for Intranet zone sites","description":"Microsoft Edge applies Enhanced Security Mode on Intranet zone sites by default. This can lead to Intranet zone sites acting in an unexpected manner.\n\nIf you enable this policy, Microsoft Edge can't apply Enhanced Security Mode on Intranet zone sites.\n\nIf you disable or don't configure this policy, Microsoft Edge applies Enhanced Security Mode on Intranet zone sites.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet_true","displayName":"Enabled","description":null,"helpText":null}]},"fbf25f2b1fc670da":{"id":"com.microsoft.edge.mamedgeappconfigsettings.imagesblockedforurls","displayName":"Block images on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\n\nIf you don't configure this policy, the global default value from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"fb47ca80291f9bb7":{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs are automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or isn't configured, and the user has enabled the sleeping tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 30Seconds (30) = 30 seconds of inactivity\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_30seconds","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_5minutes","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_15minutes","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_30minutes","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_1hour","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_2hours","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_3hours","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_6hours","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_12hours","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"fb9d4212abc9b80a":{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name","displayName":"FDVRecoveryKeyUsageDropDown_Name","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_2","displayName":"Allow 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_1","displayName":"Require 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_0","displayName":"Do not allow 256-bit recovery key","description":null,"helpText":null}]},"fbf237481913273e":{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms","displayName":"Define interoperable Kerberos V5 realm settings","description":"This policy setting configures the Kerberos client so that it can authenticate with interoperable Kerberos V5 realms, as defined by this policy setting.\r\n \r\nIf you enable this policy setting, you can view and change the list of interoperable Kerberos V5 realms and their settings. To view the list of interoperable Kerberos V5 realms, enable the policy setting and then click the Show button. To add an interoperable Kerberos V5 realm, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type the interoperable Kerberos V5 realm name. In the Value column, type the realm flags and host names of the host KDCs using the appropriate syntax format. To remove an interoperable Kerberos V5 realm Value Name or Value entry from the list, click the entry, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.\r\n\r\nIf you disable this policy setting, the interoperable Kerberos V5 realm settings defined by Group Policy are deleted.\r\n\r\nIf you do not configure this policy setting, the system uses the interoperable Kerberos V5 realm settings that are defined in the local registry, if they exist.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-mitrealms"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_1","displayName":"Enabled","description":null,"helpText":null}]},"fb259a1685084ac5":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_exploitguard_asr_rules","displayName":"Set the state for each ASR rule:","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},"fb942bbcb9a66168":{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname","displayName":"Friendly Name","description":"Specifies the string that appears for DirectAccess connectivity when the user clicks the Networking notification area icon. For example, you can specify “Contoso Intranet Access” for the DirectAccess clients of the Contoso Corporation.\r\n\r\nIf this setting is not configured, the string that appears for DirectAccess connectivity is “Corporate Connection”.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-friendlyname"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_1","displayName":"Enabled","description":null,"helpText":null}]},"fb3bd4c34a98427c":{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_wsdprinters","displayName":"Number of Web Services Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"fb316f6737dde758":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"fb83ee896353fb6c":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist","displayName":"Verify certificate revocation list","description":"Verifies Server certificate revocation status before streaming using HTTPS.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingverifycertificaterevocationlist"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist_1","displayName":"Enabled","description":null,"helpText":null}]},"fbf542ea3b3cf547":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled","displayName":"CECPQ2 post-quantum key-agreement enabled for TLS","description":"If this policy is not configured, or is set to enabled, then Google Chrome will follow the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in TLS.\r\n\r\nCECPQ2 results in larger TLS messages which, in very rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fbe737d75f9426a9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins_sslerroroverrideallowedfororiginsdesc","displayName":"Allow proceeding from the SSL warning page on specific origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"fb3feb3be04850d7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on these sites","description":"Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"fb029e7519af4392":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy, the following take precedence, in this order:\r\n\r\n * WebHidBlockedForUrls (if there is a match),\r\n\r\n * DefaultWebHidGuardSetting (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with WebHidBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"fbce6d64f0aafb9c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings","displayName":"Managed toolbar avatar label setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"fb850a54a53b0795":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcsiddirectorynamematch_odfcsiddirectorynamematch","displayName":"SID Directory Name Match (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"81eb92d0-acda-4ea2-8183-29ed5457276b","categoryName":"Container and Directory Naming","options":null},"fb0604083ba34016":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithfailure","displayName":"Prevent Login With Failure","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nPrevent user login when a failure occurs while attaching an FSLogix container\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\PreventLoginWithFailure\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithfailure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithfailure_1","displayName":"Enabled","description":null,"helpText":null}]},"fbea20e3336f73f0":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_profilesredirecttype","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_profilesredirecttype_1","displayName":"Legacy Redirection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_profilesredirecttype_2","displayName":"FSLogix Redirection","description":null,"helpText":null}]},"fb0c06b69855569f":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"fb7b4e954d3682c3":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001","displayName":"Run .NET Framework-reliant components signed with Authenticode","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_1","displayName":"Prompt","description":null,"helpText":null}]},"fb0eb50a410a5841":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"fba3234fa58bc7ad":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c","displayName":"Only allow approved domains to use the TDC ActiveX control","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_0","displayName":"Disable","description":null,"helpText":null}]},"fbbd85f40f82ff4f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies","displayName":"Block third party cookies","description":"Block web page elements that aren't from the domain that's in the address bar from setting cookies.\r\n\r\nIf you enable this policy, web page elements that are not from the domain that is in the address bar can't set cookies\r\n\r\nIf you disable this policy, web page elements from domains other than in the address bar can set cookies.\r\n\r\nIf you don't configure this policy, third-party cookies are enabled but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_1","displayName":"Enabled","description":null,"helpText":null}]},"fb23f59a338c2d5c":{"id":"device_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended","displayName":"Allow users to configure Site safety services (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy is obselete as the feature is being removed after Microsoft Edge version 127.\r\n\r\nThis policy disables site safety services from showing top site info in the page info dialog.\r\n\r\nIf you enable this policy or don't configure it, the top site info will be shown.\r\n\r\nIf you disable this policy, the top site info will not be shown.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fb37d27d1eba37ea":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\r\n\r\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies)\r\n\r\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\r\n\r\nIf you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"fbdd8c675a689f6c":{"id":"device_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended","displayName":"Windows Hello For HTTP Auth Enabled","description":"Indicates if Windows Credential UI should be used to respond to NTLM and Negotiate authentication challenges.\r\n\r\nIf you disable this policy, a basic username and password prompt will be used to respond to NTLM and Negotiate challenges. If you enable or don't configure this policy, Windows Credential UI will be used.","helpText":"","infoUrls":[],"categoryId":"6fafeb5c-65ce-4993-b421-46e60da69131","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fb460cda893b4214":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_grooveexe112","displayName":"groove.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_grooveexe112_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_grooveexe112_1","displayName":"True","description":null,"helpText":null}]},"fb8c90fe3bf7b5a5":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_onenoteexe68","displayName":"onent.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_onenoteexe68_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_onenoteexe68_1","displayName":"True","description":null,"helpText":null}]},"fb5099e63a5d4b0c":{"id":"device_vendor_msft_policy_config_onedrivengscv3~policy~onedrivengsc_warningmindiskspacelimitinmb_warningmindiskspacemb","displayName":"Minimum available disk space: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"fb9af1192b4d8ea3":{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutonbattery_enterdchibernatetimeout","displayName":"System Hibernate Timeout (seconds):","description":"","helpText":"","infoUrls":[],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":null},"fbb6569899dbd2b1":{"id":"device_vendor_msft_policy_config_privacy_allowinputpersonalization","displayName":"Allow Input Personalization","description":"Updated in Windows 10, version 1809. This policy specifies whether users on the device have the option to enable online speech recognition. When enabled, users can use their voice for dictation and to talk to Cortana and other apps that use Microsoft cloud-based speech recognition. Microsoft will use voice input to help improve our speech services. If the policy value is set to 0, online speech recognition will be disabled and users cannot enable online speech recognition via settings. If policy value is set to 1 or is not configured, control is deferred to users. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#allowinputpersonalization"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_allowinputpersonalization_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_allowinputpersonalization_1","displayName":"Allow","description":"Choice deferred to user's preference.","helpText":null}]},"fb15bf688d615dd0":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessphone_userincontroloftheseapps","displayName":"Let Apps Access Phone User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the phone call privacy setting for the listed apps. This setting overrides the default LetAppsAccessPhone policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessphone_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"fb50f92f26123c15":{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdownloads","displayName":"Allow Pinned Folder Downloads","description":"This policy controls the visibility of the Downloads shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#allowpinnedfolderdownloads"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdownloads_0","displayName":"The shortcut is hidden and disables the setting in the Settings app.","description":"The shortcut is hidden and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdownloads_1","displayName":"The shortcut is visible and disables the setting in the Settings app.","description":"The shortcut is visible and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdownloads_65535","displayName":"There is no enforced configuration and the setting can be changed by the user.","description":"There is no enforced configuration and the setting can be changed by the user.","helpText":null}]},"fb35f13a0b771e18":{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge","displayName":"Edge Preview enrollment type","description":"Details for this policy will be available in a future release","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_1","displayName":"Enabled","description":null,"helpText":null}]},"fbc7b64ab3296b27":{"id":"device_vendor_msft_policy_elevationclientsettings_allowelevationdetection","displayName":"(Preview) Automatically detect elevations","description":"","helpText":"When set to Yes, applications that need elevated permissions to run will automatically be elevated (based on the rules you set). Otherwise, the system only evaluates requests through the right-click menu or if they are set for automatic elevation.","infoUrls":[],"categoryId":"b750fe41-33c4-4293-8dfc-42285be35752","categoryName":null,"options":[{"id":"device_vendor_msft_policy_elevationclientsettings_allowelevationdetection_0","displayName":"No","description":"No","helpText":null},{"id":"device_vendor_msft_policy_elevationclientsettings_allowelevationdetection_1","displayName":"Yes","description":"Yes","helpText":null}]},"fbd3f80c3508883a":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},"fb16038ebca275dc":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},"fb91c80eace53b4b":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"fb6d580e8a1e8b08":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging","displayName":"Turn on Module Logging (User)","description":"\r\n This policy setting allows you to turn on logging for Windows PowerShell modules.\r\n\r\n If you enable this policy setting, pipeline execution events for members of the specified modules are recorded in the Windows PowerShell log in Event Viewer. Enabling this policy setting for a module is equivalent to setting the LogPipelineExecutionDetails property of the module to True.\r\n\r\n If you disable this policy setting, logging of execution events is disabled for all Windows PowerShell modules. Disabling this policy setting for a module is equivalent to setting the LogPipelineExecutionDetails property of the module to False.\r\n\r\n If this policy setting is not configured, the LogPipelineExecutionDetails property of a module or snap-in determines whether the execution events of a module or snap-in are logged. By default, the LogPipelineExecutionDetails property of all modules and snap-ins is set to False.\r\n\r\n To add modules and snap-ins to the policy setting list, click Show, and then type the module names in the list. The modules and snap-ins in the list must be installed on the computer.\r\n\r\n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enablemodulelogging"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_1","displayName":"Enabled","description":null,"helpText":null}]},"fba27a6a24e4e21a":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner","displayName":"Microsoft SharePoint Designer 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft SharePoint Designer 2013.\r\nBy default, the user settings of Microsoft SharePoint Designer 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Designer 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Designer 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Designer 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013sharepointdesigner"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner_1","displayName":"Enabled","description":null,"helpText":null}]},"fbdc17d7019f4d69":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_maxrecentdocs","displayName":"Maximum number of recent documents (User)","description":"\"This policy setting allows you to set the maximum number of shortcuts the system can display in the Recent Items menu on the Start menu.\r\n\r\nThe Recent Items menu contains shortcuts to the nonprogram files the user has most recently opened.\r\n\r\nIf you enable this policy setting, the system displays the number of shortcuts specified by the policy setting.\r\n\r\nIf you disable or do not configure this policy setting, by default, the system displays shortcuts to the 10 most recently opened documents.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-maxrecentdocs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_maxrecentdocs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_maxrecentdocs_1","displayName":"Enabled","description":null,"helpText":null}]},"fb1061b71908ba68":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs","displayName":"Suppress JavaScript Dialogs triggered from different origin subframes (User)","description":"As described in https://www.chromestatus.com/feature/5148698084376576 , JavaScript modal dialogs, triggered by window.alert, window.confirm, and window.prompt, will be blocked in Google Chrome if triggered from a subframe whose origin is different from the main frame origin.\r\nThis policy allows overriding that change.\r\nIf the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked.\r\nIf the policy is set to disabled, JavaScript dialogs triggered from a different origin subframe will not be blocked.\r\n\r\nThis policy will be removed in Google Chrome version 95.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"fb72a65cf4775ca7":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_windowmanagementblockedforurlsdesc","displayName":"Block Window Management permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"fba22d25d16e0666":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_0","displayName":"Downloads model automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_1","displayName":"Do not download model","description":null,"helpText":null}]},"fbb16860b501ad13":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords (User)","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own and, if fixing them is possible, it usually requires complex user actions.\r\n\r\nSetting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\r\n\r\nSetting the policy to Disabled means users will leave their password manager data untouched, but will experience a broken password manager functionality.\r\n\r\nIf the policy is set, users can't change it in Google Chrome.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fbd559d5362fcc25":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks","displayName":"Excel 4 workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_1","displayName":"Enabled","description":null,"helpText":null}]},"fb8a97ca89f71200":{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate","displayName":"Locked-Down Local Machine Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownlocalmachinezonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"fb86fc621a647309":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneinitializeandscriptactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"fb303c459deaebe1":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter (User)","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenablecrosssitescriptingfilter"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},"fb44118cc60d88da":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},"fb80ced17f214ecd":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended","displayName":"Show Home button on toolbar (User)","description":"Shows the Home button on Microsoft Edge's toolbar.\r\n\r\nEnable this policy to always show the Home button. Disable it to never show the button.\r\n\r\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fb9ce5646d2f619d":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride","displayName":"Prevent bypassing Microsoft Defender SmartScreen prompts for sites (User)","description":"This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.\r\n\r\nIf you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they are blocked from continuing to the site.\r\n\r\nIf you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride_1","displayName":"Enabled","description":null,"helpText":null}]},"fb0b9a6fb09f0499":{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed","displayName":"Live captions allowed (User)","description":"Allow users to turn the Live captions feature on or off.\r\n\r\nLive captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge in to text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device.\r\n\r\nNote: This feature is not generally available. Clients that have the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy set to 'FullMode' may receive the feature before broad availability. Broad availability will be announced via Microsoft Edge release notes.\r\n\r\nIf you enable or don't configure this policy, users can turn this feature on or off at edge://settings/accessibility.\r\n\r\nIf you disable this policy, users will not be able to turn this accessibility feature on. If speech recognition files have been downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment.\r\n\r\nIf users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) will be downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"fb1d6c6293453390":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"fb0cb17c121c1a9f":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"fb331eb1bb3edd8e":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled","displayName":"Enable implicit sign-in (User)","description":"Configure this policy to allow/disallow implicit sign-in.\r\n\r\nIf you have configured the 'BrowserSignin' (Browser sign-in settings) policy to 'Disable browser sign-in', this policy will not take any effect.\r\n\r\nIf you enable or don't configure this setting, implicit sign-in will be enabled, Edge will attempt to sign the user into their profile based on what and how they sign in to their OS.\r\n\r\nIf you disable this setting, implicit sign-in will be disabled.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fb00e3975b306dd3":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI (User)","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\r\n\r\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\r\n\r\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\r\n\r\nIf you set this policy to zero or don't configure it, the system default resolution will be used during rasterization of page images.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_1","displayName":"Enabled","description":null,"helpText":null}]},"fb30d3376a911ba1":{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains","displayName":"Turn off roaming of file names and metadata by server domain. (User)","description":"\r\nThis policy setting controls whether file names and metadata for Office files are roamed and appear in the list of recently opened files in an Office app, such as Word, on different devices.\r\n\r\nRoaming, which relies on a web-based Microsoft service, occurs when a user signs into Office with the same work or school account on different devices.\r\n\r\nNote: This policy is applied to any Office files stored on a specified list of server domains. The set of disallowed domains is a semicolon separated list: \"*.contoso.com;service.microsoft.com\".\r\n\r\nIf you enable this policy setting, file names and metadata won't roam and won’t appear in the list of recently opened files in Office apps on other devices, unless the file has been opened on that device.\r\n\r\nIf you disable or don't configure this policy setting, file names and metadata will roam and will appear in the list of recently opened files in Office apps on other devices, even if the file hasn’t been opened on that device.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_1","displayName":"Enabled","description":null,"helpText":null}]},"fb00976aac675252":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab","displayName":"Remove Member Of tab (User)","description":"This policy setting allows you to remove the Member Of tab from the Contact Card.\r\n\r\nIf you enable this policy setting the Member Of tab is removed from the Contact Card.\r\n\r\nIf you disable or do not configure this policy setting the Member Of tab appears on the Contact Card.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab_1","displayName":"Enabled","description":null,"helpText":null}]},"fbb4f4bdb2a05829":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems_l_tooltipfordisabledtoolbarbuttonsandmenuitems353","displayName":"Tooltip for disabled toolbar buttons and menu items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":null},"fb6be6e5d11ad081":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess_1","displayName":"True","description":null,"helpText":null}]},"fba7db6888a415b6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt","displayName":"Arabic (Egypt) (User)","description":"Enables the editing language Arabic (Egypt)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt_1","displayName":"Enabled","description":null,"helpText":null}]},"fbdd2b79a986a52f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga","displayName":"Xitsonga (User)","description":"Enables the editing language Xitsonga","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga_1","displayName":"Enabled","description":null,"helpText":null}]},"fbce2f637fb62221":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote","displayName":"Default unit of measurement used in OneNote (User)","description":"Sets the value in the option ''Measurement units''.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_1","displayName":"Enabled","description":null,"helpText":null}]},"fb089549210303d2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics","displayName":"Disable online mode for Get Diagnostics. (User)","description":"\r\n This policy setting determines whether online mode for Get Diagnostics is allowed. Enabling this setting will block Get Diagnostics feature from sending authentication and diagnostics logs to our service.\r\n Users will now go through offline mode. We will collect all the logs and store them in the Downloads folder of the user. This user can contact support and decide if they want to send us the logs. \r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},"fb77ed0e24ae7c5f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload","displayName":"Specify list of social network providers to load (User)","description":"This policy setting determines the list of social network providers that are loaded by the Outlook Social Connector.\r\n\r\nIf you enable this policy setting, you may enter a list of provider progIDs of social network providers that will be loaded by the Outlook Social Connector. This list needs to be semi-colon delimited. Note that if you enable this policy setting, only social network providers that are on this list will be loaded by the Outlook Social Connector. No other social network providers will be loaded.\r\n\r\nIf you disable or you do not configure this policy setting, the Outlook Social Connector can load any provider specified by the user.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_1","displayName":"Enabled","description":null,"helpText":null}]},"fb2ca4a9a3f8ddef":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode","displayName":"Cached Exchange Mode (File | Cached Exchange Mode) (User)","description":"Specifies the default Cached Exchange Mode for new profiles and disables the download options in the Cached Exchange Mode command submenu in the File menu.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},"fbf241c31a55481c":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},"fbbb49f1f9746249":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4","displayName":"Language for file conversion (User)","description":"This policy setting specifies how Visio determines what language to use when converting to or from an earlier version of Visio. \r\n\r\nIf you enable this policy setting, you may select from one of these options:\r\n\r\n- Let Visio decide language\r\n- Prompt for language\r\n- Use the following language: You must specify the numeric Microsoft Locale ID (LCID) for that language.\r\n\r\nIf you disable or do not configure this policy setting, Visio decides what language to use.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_1","displayName":"Enabled","description":null,"helpText":null}]},"fbf660e734c304f0":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"fb54f307b409690c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},"fb8d2875884a2ccb":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout","displayName":"Stop checking for tables used for layout (User)","description":"This policy setting prevents the Accessibility Checker from flagging layout tables (i.e. tables with no style applied).\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging layout tables (i.e. tables with no style applied).\r\n\r\nIf you disable or do not configure this policy setting, tables with no style will be flagged and the violations will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout_1","displayName":"Enabled","description":null,"helpText":null}]},"fbe71eeb62a471c0":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},"fbce3ad6a0854f2f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks","displayName":"Update linked data before printing (User)","description":"This policy setting controls the \"Update linked data before printing\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will update linked data in the document before the document is printed. One example of linked data in Word is an embedded Excel chart that is linked to an Excel spreadsheet.\r\n\r\nIf you disable or do not configure this policy setting, Word will not update linked data in the document before the document is printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks_1","displayName":"Enabled","description":null,"helpText":null}]},"fbca7c7a26e26800":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},"fb617dfa29f2591e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},"fb823848b82e9070":{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, firewall rules from the local store are ignored and not enforced. The merge law for this option is to always use the value of the GroupPolicyRSoPStore. This value is valid for all schema versions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge_false","displayName":"False","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge_true","displayName":"True","description":"AllowLocalPolicyMerge On","helpText":null}]},"fb2bac09e2fc6222":{"id":"vendor_msft_sharedpc_enablesharedpcmode","displayName":"Enable Shared PC Mode","description":"Setting this node to \"true\" triggers the action to configure a device to Shared PC mode.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_enablesharedpcmode_false","displayName":"false","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_enablesharedpcmode_true","displayName":"true","description":"Enabled","helpText":null}]}} \ No newline at end of file +{"fb311cc3ae68a46e":{"id":"com.android.devicerestrictionpolicy.screentimeout","displayName":"Screen timeout","description":"Enter the number of seconds for the screen timeout duration. A value of 0 means there is no restriction. When configured, the device enforces this as the maximum screen timeout. Available for fully managed, dedicated, and corporate-owned work profile devices.","helpText":"Enter a value in seconds (0 = no restriction)","infoUrls":[],"categoryId":"95000481-a8b5-4e18-99e3-367666aee03f","categoryName":"Power","options":null},"fbeb87c361570def":{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp","displayName":"Block USB file transfer","description":"If 'True', prevents users from transferring files over USB. If 'False', Intune doesn't change or update this setting. By default, the OS might allow users to transfer files.","helpText":"","infoUrls":[],"categoryId":"b6733d23-eadc-486a-abfc-62b78698a16c","categoryName":"General","options":[{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp_false","displayName":"False","description":"False","helpText":null},{"id":"com.android.devicerestrictionpolicy.storageblockusbfiletransferaosp_true","displayName":"True","description":"True","helpText":null}]},"fb8e2e214870e268":{"id":"com.apple.applicationaccess_deniediccidsforrcs","displayName":"Denied ICCIDs For RCS","description":"An array of strings representing ICCIDs of cellular plans. The device prevents use of any matching cellular networks with RCS messaging. The array must contain no more than 4 ICCID strings.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":null},"fbe5fccd77812f31":{"id":"com.apple.applicationaccess_ratingtvshowsfr","displayName":"Rating TV Shows - France","description":"The maximum level of TV content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingtvshowsfr_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_1","displayName":"-10","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_2","displayName":"-12","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_3","displayName":"-16","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_4","displayName":"-18","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingtvshowsfr_5","displayName":"All","description":null,"helpText":null}]},"fbbc551328c9e4b5":{"id":"com.apple.assetcache.managed_datapath","displayName":"Data Path","description":"The path to the directory used to store cached content. Changing this setting manually doesn't automatically move cached content from the old location to the new one. To move content automatically, use the Sharing preference's Content Caching pane. The value must be (or end with) /Library/Application Support/Apple/AssetCache/Data.\r\nA directory and its intermediates are created for the given data path if it doesn't already exist. The directory is owned by _assetcache:_assetcache and has mode 0750. Its immediate parent directory (.../Library/Application Support/Apple/AssetCache) is owned by _assetcache:_assetcache and has mode 0755. ","helpText":null,"infoUrls":[],"categoryId":"e95335ec-2704-47ab-8b40-f602b31eeb9d","categoryName":"Content Caching","options":null},"fb945143571c2c95":{"id":"com.apple.extensiblesso_platformsso_additionalgroups","displayName":"Additional Groups","description":"The list of groups that are created and do not have administrator access.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":null},"fb6a3caee0aceb7a":{"id":"com.apple.managedclient.preferences_developertoolsavailability","displayName":"Control where developer tools can be used","description":"Control where developer tools can be used.\n\nIf you set this policy to 'DeveloperToolsDisallowedForForceInstalledExtensions' (0, the default), users can access the developer tools and the JavaScript console in general, but not in the context of extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsAllowed' (1), users can access the developer tools and the JavaScript console in all contexts, including extensions installed by enterprise policy.\n\nIf you set this policy to 'DeveloperToolsDisallowed' (2), users can't access the developer tools or inspect website elements. Keyboard shortcuts and menu or context menu entries that open the developer tools or the JavaScript Console are disabled.\n\n* 0 = Block the developer tools on extensions installed by enterprise policy, allow in other contexts\n\n* 1 = Allow using the developer tools\n\n* 2 = Don't allow using the developer tools","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#developertoolsavailability"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_developertoolsavailability_0","displayName":"Block the developer tools on extensions installed by enterprise policy, allow in other contexts","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_developertoolsavailability_1","displayName":"Allow using the developer tools","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_developertoolsavailability_2","displayName":"Don't allow using the developer tools","description":null,"helpText":null}]},"fb93a98aeba3d5a4":{"id":"com.apple.managedclient.preferences_exclusions","displayName":"Scan exclusions","description":"Entities that have been excluded from the scan. Exclusions can be specified by full paths, extensions, or file names.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/mac-preferences#scan-exclusions"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":null},"fbe973e347c2118c":{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud","displayName":"Fallback to Microsoft cloud updates","description":"Determine the Defender for Endpoint security intelligence update approach when offline mirror server fails to serve the update request. If set to true, the update is retried via the Microsoft cloud when offline security intelligence update failed.","helpText":null,"infoUrls":["https://learn.microsoft.com/en-us/defender-endpoint/mac-support-offline-security-intelligence-update#configure-the-endpoints"],"categoryId":"13467142-14e7-4380-8573-4866e842c7f6","categoryName":"Antivirus engine","options":[{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_offlinedefinitionupdatefallbacktocloud_true","displayName":"Enabled","description":null,"helpText":null}]},"fb34961e737d6a2a":{"id":"com.apple.managedclient.preferences_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\n\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\n\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\n\nIf you set this policy to zero or don't configure it, the system default resolution will be used during rasterization of page images.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#printrasterizepdfdpi"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"fb6e17ff943fa896":{"id":"com.apple.managedclient.preferences_registeredprotocolhandlers","displayName":"Registered Protocol Handlers","description":"Register a list of protocol handlers. Set the protocol property to the scheme (like 'mailto') and the url property to the URL pattern of the application that handles the scheme. The pattern can include a '%s', which will be replaced by the handled URL.\n\nYou can recommend a specific value for this policy, but you can't require that your users use it.\n\nThe protocol handlers registered by policy are merged with any handlers registered by the user, and both are available for use. The user can override the protocol handlers installed by policy by installing a new default handler, but they can't remove a protocol handler registered by policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#registeredprotocolhandlers"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"fb3d470df9c89159":{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies","displayName":"Block third party cookies","description":"This policy controls whether third-party cookies are blocked in regular browsing sessions.\n\nIf you enable this policy, web page elements that are not from the domain shown in the address bar can't set cookies.\n\nIf you disable this policy, third-party cookies are allowed, including from domains other than the one shown in the address bar.\n\nIf you don't configure this policy, third-party cookies are allowed by default, but users can change this setting.\n\nNote: This policy doesn't apply in InPrivate mode. In InPrivate, third-party cookies are blocked by default and can only be allowed at the site level using the CookiesAllowedForUrls policy.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.blockthirdpartycookies_true","displayName":"Enabled","description":null,"helpText":null}]},"fbc3a60df74fa000":{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled","displayName":"Microsoft Edge management extensions feedback enabled","description":"This setting controls whether Microsoft Edge sends data about blocked extensions to the Microsoft Edge management service.\n\nThe 'EdgeManagementEnabled' policy must also be enabled for this setting to take effect.\n\nIf you enable this policy, Microsoft Edge sends data to the Microsoft Edge service when a user tries to install a blocked extension.\n\nIf you disable or don't configure this policy, Microsoft Edge can't send any data to the Microsoft Edge service about blocked extensions.","helpText":null,"infoUrls":[],"categoryId":"dfab5866-1712-4bbf-8edf-5b080b315b9b","categoryName":"Manageability","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.edgemanagementextensionsfeedbackenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fbc24d4f24cde70d":{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet","displayName":"Enhanced Security Mode configuration for Intranet zone sites","description":"Microsoft Edge applies Enhanced Security Mode on Intranet zone sites by default. This can lead to Intranet zone sites acting in an unexpected manner.\n\nIf you enable this policy, Microsoft Edge can't apply Enhanced Security Mode on Intranet zone sites.\n\nIf you disable or don't configure this policy, Microsoft Edge applies Enhanced Security Mode on Intranet zone sites.\n\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2185895","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.enhancesecuritymodebypassintranet_true","displayName":"Enabled","description":null,"helpText":null}]},"fbf25f2b1fc670da":{"id":"com.microsoft.edge.mamedgeappconfigsettings.imagesblockedforurls","displayName":"Block images on specific sites","description":"Define a list of sites, based on URL patterns, that aren't allowed to display images.\n\nIf you don't configure this policy, the global default value from the \"DefaultImagesSetting\" policy (if set) or the user's personal configuration is used for all sites.\n\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards (*) are allowed.","helpText":null,"infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"fb47ca80291f9bb7":{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for sleeping tabs","description":"This policy setting lets you configure the timeout, in seconds, after which inactive background tabs are automatically put to sleep if sleeping tabs is enabled. By default, this timeout is 7,200 seconds (2 hours).\n\nTabs are only put to sleep automatically when the policy \"SleepingTabsEnabled\" is enabled or isn't configured, and the user has enabled the sleeping tabs setting.\n\nIf you don't configure this policy, users can choose the timeout value.\n\nPolicy options mapping:\n\n* 30Seconds (30) = 30 seconds of inactivity\n\n* 5Minutes (300) = 5 minutes of inactivity\n\n* 15Minutes (900) = 15 minutes of inactivity\n\n* 30Minutes (1800) = 30 minutes of inactivity\n\n* 1Hour (3600) = 1 hour of inactivity\n\n* 2Hours (7200) = 2 hours of inactivity\n\n* 3Hours (10800) = 3 hours of inactivity\n\n* 6Hours (21600) = 6 hours of inactivity\n\n* 12Hours (43200) = 12 hours of inactivity\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","categoryName":"Sleeping Tabs settings","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_30seconds","displayName":"30 seconds of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_5minutes","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_15minutes","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_30minutes","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_1hour","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_2hours","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_3hours","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_6hours","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sleepingtabstimeout_12hours","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"fb5dbfe54bbb41c7":{"id":"contentcaching_declarativestatusinterval","displayName":"Declarative Status Interval","description":"The time interval in seconds the system uses to update the `StatusContentCacheInfo` declarative status item. The reporting interval can't be less than 60 (1 per minute) or larger than 86400 (1 per day), defaults to 0 (off)","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":null},"fb9d4212abc9b80a":{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name","displayName":"FDVRecoveryKeyUsageDropDown_Name","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"a18508d1-fd74-4955-8032-3bd9219a0944","categoryName":"Fixed Data Drives","options":[{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_2","displayName":"Allow 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_1","displayName":"Require 256-bit recovery key","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_fixeddrivesrecoveryoptions_fdvrecoverykeyusagedropdown_name_0","displayName":"Do not allow 256-bit recovery key","description":null,"helpText":null}]},"fbf237481913273e":{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms","displayName":"Define interoperable Kerberos V5 realm settings","description":"This policy setting configures the Kerberos client so that it can authenticate with interoperable Kerberos V5 realms, as defined by this policy setting.\r\n \r\nIf you enable this policy setting, you can view and change the list of interoperable Kerberos V5 realms and their settings. To view the list of interoperable Kerberos V5 realms, enable the policy setting and then click the Show button. To add an interoperable Kerberos V5 realm, enable the policy setting, note the syntax, and then click Show. In the Show Contents dialog box in the Value Name column, type the interoperable Kerberos V5 realm name. In the Value column, type the realm flags and host names of the host KDCs using the appropriate syntax format. To remove an interoperable Kerberos V5 realm Value Name or Value entry from the list, click the entry, and then press the DELETE key. To edit a mapping, remove the current entry from the list and add a new one with different parameters.\r\n\r\nIf you disable this policy setting, the interoperable Kerberos V5 realm settings defined by Group Policy are deleted.\r\n\r\nIf you do not configure this policy setting, the system uses the interoperable Kerberos V5 realm settings that are defined in the local registry, if they exist.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-kerberos#admx-kerberos-mitrealms"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kerberos_mitrealms_1","displayName":"Enabled","description":null,"helpText":null}]},"fb259a1685084ac5":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_exploitguard_asr_rules_exploitguard_asr_rules","displayName":"Set the state for each ASR rule:","description":null,"helpText":"","infoUrls":[],"categoryId":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","categoryName":"Attack Surface Reduction","options":null},"fb942bbcb9a66168":{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname","displayName":"Friendly Name","description":"Specifies the string that appears for DirectAccess connectivity when the user clicks the Networking notification area icon. For example, you can specify “Contoso Intranet Access” for the DirectAccess clients of the Contoso Corporation.\r\n\r\nIf this setting is not configured, the string that appears for DirectAccess connectivity is “Corporate Connection”.\r\n\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-nca#admx-nca-friendlyname"],"categoryId":"ac0a894c-173a-48fc-b961-901f28463c77","categoryName":"Direct Access Client Experience Settings","options":[{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_nca_friendlyname_1","displayName":"Enabled","description":null,"helpText":null}]},"fb3bd4c34a98427c":{"id":"device_vendor_msft_policy_config_admx_printing_nondomainprinters_wsdprinters","displayName":"Number of Web Services Printers","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"fb316f6737dde758":{"id":"device_vendor_msft_policy_config_appvirtualization_publishingallowserver3_publishing_server_url_prompt","displayName":"Publishing Server URL","description":"","helpText":"","infoUrls":[],"categoryId":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","categoryName":"Publishing","options":null},"fb83ee896353fb6c":{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist","displayName":"Verify certificate revocation list","description":"Verifies Server certificate revocation status before streaming using HTTPS.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-appvirtualization#appvirtualization-streamingverifycertificaterevocationlist"],"categoryId":"5011ca61-1a58-42da-9c66-7763236acc84","categoryName":"Streaming","options":[{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_appvirtualization_streamingverifycertificaterevocationlist_1","displayName":"Enabled","description":null,"helpText":null}]},"fbf542ea3b3cf547":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled","displayName":"CECPQ2 post-quantum key-agreement enabled for TLS","description":"If this policy is not configured, or is set to enabled, then Google Chrome will follow the default rollout process for CECPQ2, a post-quantum key-agreement algorithm in TLS.\r\n\r\nCECPQ2 results in larger TLS messages which, in very rare cases, can trigger bugs in some networking hardware. This policy can be set to False to disable CECPQ2 while networking issues are resolved.\r\n\r\nThis policy is a temporary measure and will be removed in future versions of Google Chrome.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_cecpq2enabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fbe737d75f9426a9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslerroroverrideallowedfororigins_sslerroroverrideallowedfororiginsdesc","displayName":"Allow proceeding from the SSL warning page on specific origins (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"fb3feb3be04850d7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls","displayName":"Block insecure content on these sites","description":"Allows you to set a list of url patterns that specify sites which are not allowed to display blockable (i.e. active) mixed content (i.e. HTTP content on HTTPS sites), and for which optionally blockable (i.e. passive) mixed content will be upgraded.\r\n\r\nIf this policy is left not set blockable mixed content will be blocked and optionally blockable mixed content will be upgraded, but users will be allowed to set exceptions to allow it for specific sites.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_insecurecontentblockedforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"fb029e7519af4392":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls","displayName":"Allow the WebHID API on these sites","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them access to a HID device.\r\n\r\nLeaving the policy unset means DefaultWebHidGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nFor URL patterns which do not match the policy, the following take precedence, in this order:\r\n\r\n * WebHidBlockedForUrls (if there is a match),\r\n\r\n * DefaultWebHidGuardSetting (if set), or\r\n\r\n * Users' personal settings.\r\n\r\nURL patterns must not conflict with WebHidBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://google.com\r\nhttps://chromium.org","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_webhidaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"fbce6d64f0aafb9c":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings","displayName":"Managed toolbar avatar label setting","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_toolbaravatarlabelsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"fb850a54a53b0795":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_containeranddirectorynaming_odfcsiddirectorynamematch_odfcsiddirectorynamematch","displayName":"SID Directory Name Match (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"81eb92d0-acda-4ea2-8183-29ed5457276b","categoryName":"Container and Directory Naming","options":null},"fb0604083ba34016":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithfailure","displayName":"Prevent Login With Failure","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nPrevent user login when a failure occurs while attaching an FSLogix container\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\PreventLoginWithFailure\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithfailure_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilespreventloginwithfailure_1","displayName":"Enabled","description":null,"helpText":null}]},"fbea20e3336f73f0":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_profilesredirecttype","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_profilesredirecttype_1","displayName":"Legacy Redirection","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesredirecttype_profilesredirecttype_2","displayName":"FSLogix Redirection","description":null,"helpText":null}]},"fb0c06b69855569f":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols","displayName":"Don't run antimalware programs against ActiveX controls","description":"This policy setting determines whether Internet Explorer runs antimalware programs against ActiveX controls, to check if they're safe to load on pages.\n\nIf you enable this policy setting, Internet Explorer won't check with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you disable this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control.\n\nIf you don't configure this policy setting, Internet Explorer always checks with your antimalware program to see if it's safe to create an instance of the ActiveX control. Users can turn this behavior on or off, using Internet Explorer Security settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzonedonotrunantimalwareagainstactivexcontrols"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonedonotrunantimalwareagainstactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"fb7b4e954d3682c3":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001","displayName":"Run .NET Framework-reliant components signed with Authenticode","description":"","helpText":"","infoUrls":[],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_3","displayName":"Disable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzonerunnetframeworkreliantcomponentssignedwithauthenticode_iz_partname2001_1","displayName":"Prompt","description":null,"helpText":null}]},"fb0eb50a410a5841":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents","displayName":"Run .NET Framework-reliant components not signed with Authenticode","description":"This policy setting allows you to manage whether .NET Framework components that are not signed with Authenticode can be executed from Internet Explorer. These components include managed controls referenced from an object tag and managed executables referenced from a link.\n\nIf you enable this policy setting, Internet Explorer will execute unsigned managed components. If you select Prompt in the drop-down box, Internet Explorer will prompt the user to determine whether to execute unsigned managed components.\n\nIf you disable this policy setting, Internet Explorer will not execute unsigned managed components.\n\nIf you do not configure this policy setting, Internet Explorer will not execute unsigned managed components.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallownetframeworkreliantcomponents"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallownetframeworkreliantcomponents_1","displayName":"Enabled","description":null,"helpText":null}]},"fba3234fa58bc7ad":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c","displayName":"Only allow approved domains to use the TDC ActiveX control","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_3","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowonlyapproveddomainstousetdcactivexcontrol_iz_partname120c_0","displayName":"Disable","description":null,"helpText":null}]},"fbbd85f40f82ff4f":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies","displayName":"Block third party cookies","description":"Block web page elements that aren't from the domain that's in the address bar from setting cookies.\r\n\r\nIf you enable this policy, web page elements that are not from the domain that is in the address bar can't set cookies\r\n\r\nIf you disable this policy, web page elements from domains other than in the address bar can set cookies.\r\n\r\nIf you don't configure this policy, third-party cookies are enabled but users can change this setting.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_blockthirdpartycookies_1","displayName":"Enabled","description":null,"helpText":null}]},"fb23f59a338c2d5c":{"id":"device_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended","displayName":"Allow users to configure Site safety services (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 127.\r\n\r\nThis policy is obselete as the feature is being removed after Microsoft Edge version 127.\r\n\r\nThis policy disables site safety services from showing top site info in the page info dialog.\r\n\r\nIf you enable this policy or don't configure it, the top site info will be shown.\r\n\r\nIf you disable this policy, the top site info will not be shown.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_sitesafetyservicesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fb37d27d1eba37ea":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit","displayName":"Clear browsing data when Microsoft Edge closes","description":"Microsoft Edge doesn't clear the browsing data by default when it closes. Browsing data includes information entered in forms, passwords, and even the websites visited.\r\n\r\nIf you enable this policy, all browsing data is deleted each time Microsoft Edge closes. Note that if you enable this policy, it takes precedence over how you configured 'DefaultCookiesSetting' (Configure cookies)\r\n\r\nIf you disable or don't configure this policy, users can configure the Clear browsing data option in Settings.\r\n\r\nIf you enable this policy, don't configure the 'AllowDeletingBrowserHistory' (Enable deleting browser and download history) or the 'ClearCachedImagesAndFilesOnExit' (Clear cached images and files when Microsoft Edge closes) policy, because they all deal with deleting browsing data. If you configure the preceding policies and this policy, all browsing data is deleted when Microsoft Edge closes, regardless of how you configured 'AllowDeletingBrowserHistory' or 'ClearCachedImagesAndFilesOnExit'.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_clearbrowsingdataonexit_1","displayName":"Enabled","description":null,"helpText":null}]},"fbdd8c675a689f6c":{"id":"device_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended","displayName":"Windows Hello For HTTP Auth Enabled","description":"Indicates if Windows Credential UI should be used to respond to NTLM and Negotiate authentication challenges.\r\n\r\nIf you disable this policy, a basic username and password prompt will be used to respond to NTLM and Negotiate challenges. If you enable or don't configure this policy, Windows Credential UI will be used.","helpText":"","infoUrls":[],"categoryId":"6fafeb5c-65ce-4993-b421-46e60da69131","categoryName":"HTTP authentication","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev90~policy~microsoft_edge_recommended~httpauthentication_recommended_windowshelloforhttpauthenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fb460cda893b4214":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_grooveexe112","displayName":"groove.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_grooveexe112_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_informationbar_l_grooveexe112_1","displayName":"True","description":null,"helpText":null}]},"fb8c90fe3bf7b5a5":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_onenoteexe68","displayName":"onent.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_onenoteexe68_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_mimesniffingsafetyfature_l_onenoteexe68_1","displayName":"True","description":null,"helpText":null}]},"fb5099e63a5d4b0c":{"id":"device_vendor_msft_policy_config_onedrivengscv3~policy~onedrivengsc_warningmindiskspacelimitinmb_warningmindiskspacemb","displayName":"Minimum available disk space: (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"fb9af1192b4d8ea3":{"id":"device_vendor_msft_policy_config_power_hibernatetimeoutonbattery_enterdchibernatetimeout","displayName":"System Hibernate Timeout (seconds):","description":"","helpText":"","infoUrls":[],"categoryId":"3b64e99d-0359-4264-be38-c544c647f493","categoryName":"Sleep Settings","options":null},"fbb6569899dbd2b1":{"id":"device_vendor_msft_policy_config_privacy_allowinputpersonalization","displayName":"Allow Input Personalization","description":"Updated in Windows 10, version 1809. This policy specifies whether users on the device have the option to enable online speech recognition. When enabled, users can use their voice for dictation and to talk to Cortana and other apps that use Microsoft cloud-based speech recognition. Microsoft will use voice input to help improve our speech services. If the policy value is set to 0, online speech recognition will be disabled and users cannot enable online speech recognition via settings. If policy value is set to 1 or is not configured, control is deferred to users. Most restricted value is 0.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#allowinputpersonalization"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":[{"id":"device_vendor_msft_policy_config_privacy_allowinputpersonalization_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_privacy_allowinputpersonalization_1","displayName":"Allow","description":"Choice deferred to user's preference.","helpText":null}]},"fb15bf688d615dd0":{"id":"device_vendor_msft_policy_config_privacy_letappsaccessphone_userincontroloftheseapps","displayName":"Let Apps Access Phone User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the phone call privacy setting for the listed apps. This setting overrides the default LetAppsAccessPhone policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsaccessphone_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"fb50f92f26123c15":{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdownloads","displayName":"Allow Pinned Folder Downloads","description":"This policy controls the visibility of the Downloads shortcut on the Start menu. The possible values are 0 - means that the shortcut should be hidden and grays out the corresponding toggle in the Settings app, 1 - means that the shortcut should be visible and grays out the corresponding toggle in the Settings app, 65535 - means that there is no enforced configuration and the setting can be changed by the user.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Start#allowpinnedfolderdownloads"],"categoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","categoryName":"Start","options":[{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdownloads_0","displayName":"The shortcut is hidden and disables the setting in the Settings app.","description":"The shortcut is hidden and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdownloads_1","displayName":"The shortcut is visible and disables the setting in the Settings app.","description":"The shortcut is visible and disables the setting in the Settings app.","helpText":null},{"id":"device_vendor_msft_policy_config_start_allowpinnedfolderdownloads_65535","displayName":"There is no enforced configuration and the setting can be changed by the user.","description":"There is no enforced configuration and the setting can be changed by the user.","helpText":null}]},"fb35f13a0b771e18":{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge","displayName":"Edge Preview enrollment type","description":"Details for this policy will be available in a future release","helpText":"","infoUrls":[],"categoryId":"3bb9ca38-645e-479c-ac5f-01959aec9c30","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_updatev128~policy~cat_edgeupdate~cat_applications~cat_microsoftedge_pol_edgepreviewenrollmenttypemicrosoftedge_1","displayName":"Enabled","description":null,"helpText":null}]},"fbc7b64ab3296b27":{"id":"device_vendor_msft_policy_elevationclientsettings_allowelevationdetection","displayName":"(Preview) Automatically detect elevations","description":"","helpText":"When set to Yes, applications that need elevated permissions to run will automatically be elevated (based on the rules you set). Otherwise, the system only evaluates requests through the right-click menu or if they are set for automatic elevation.","infoUrls":[],"categoryId":"b750fe41-33c4-4293-8dfc-42285be35752","categoryName":null,"options":[{"id":"device_vendor_msft_policy_elevationclientsettings_allowelevationdetection_0","displayName":"No","description":"No","helpText":null},{"id":"device_vendor_msft_policy_elevationclientsettings_allowelevationdetection_1","displayName":"Yes","description":"Yes","helpText":null}]},"fb37b561227ac453":{"id":"plugin_pluginbundleid","displayName":"Plugin Bundle ID","description":"The bundle ID of the plug-in that provides filtering service. Consult your filtering solution vendor to determine what to specify for this value.","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"fbd3f80c3508883a":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01","displayName":"Trusted Location #1 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc01_1","displayName":"Enabled","description":null,"helpText":null}]},"fb16038ebca275dc":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06","displayName":"Trusted Location #6 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc06_1","displayName":"Enabled","description":null,"helpText":null}]},"fb91c80eace53b4b":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"fb6d580e8a1e8b08":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging","displayName":"Turn on Module Logging (User)","description":"\r\n This policy setting allows you to turn on logging for Windows PowerShell modules.\r\n\r\n If you enable this policy setting, pipeline execution events for members of the specified modules are recorded in the Windows PowerShell log in Event Viewer. Enabling this policy setting for a module is equivalent to setting the LogPipelineExecutionDetails property of the module to True.\r\n\r\n If you disable this policy setting, logging of execution events is disabled for all Windows PowerShell modules. Disabling this policy setting for a module is equivalent to setting the LogPipelineExecutionDetails property of the module to False.\r\n\r\n If this policy setting is not configured, the LogPipelineExecutionDetails property of a module or snap-in determines whether the execution events of a module or snap-in are logged. By default, the LogPipelineExecutionDetails property of all modules and snap-ins is set to False.\r\n\r\n To add modules and snap-ins to the policy setting list, click Show, and then type the module names in the list. The modules and snap-ins in the list must be installed on the computer.\r\n\r\n Note: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enablemodulelogging"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablemodulelogging_1","displayName":"Enabled","description":null,"helpText":null}]},"fba27a6a24e4e21a":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner","displayName":"Microsoft SharePoint Designer 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft SharePoint Designer 2013.\r\nBy default, the user settings of Microsoft SharePoint Designer 2013 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft SharePoint Designer 2013 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft SharePoint Designer 2013 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft SharePoint Designer 2013 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2013sharepointdesigner"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2013sharepointdesigner_1","displayName":"Enabled","description":null,"helpText":null}]},"fbdc17d7019f4d69":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_maxrecentdocs","displayName":"Maximum number of recent documents (User)","description":"\"This policy setting allows you to set the maximum number of shortcuts the system can display in the Recent Items menu on the Start menu.\r\n\r\nThe Recent Items menu contains shortcuts to the nonprogram files the user has most recently opened.\r\n\r\nIf you enable this policy setting, the system displays the number of shortcuts specified by the policy setting.\r\n\r\nIf you disable or do not configure this policy setting, by default, the system displays shortcuts to the 10 most recently opened documents.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-maxrecentdocs"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_maxrecentdocs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_maxrecentdocs_1","displayName":"Enabled","description":null,"helpText":null}]},"fb1061b71908ba68":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs","displayName":"Suppress JavaScript Dialogs triggered from different origin subframes (User)","description":"As described in https://www.chromestatus.com/feature/5148698084376576 , JavaScript modal dialogs, triggered by window.alert, window.confirm, and window.prompt, will be blocked in Google Chrome if triggered from a subframe whose origin is different from the main frame origin.\r\nThis policy allows overriding that change.\r\nIf the policy is set to enabled or unset, JavaScript dialogs triggered from a different origin subframe will be blocked.\r\nIf the policy is set to disabled, JavaScript dialogs triggered from a different origin subframe will not be blocked.\r\n\r\nThis policy will be removed in Google Chrome version 95.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_suppressdifferentoriginsubframedialogs_1","displayName":"Enabled","description":null,"helpText":null}]},"fb72a65cf4775ca7":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementblockedforurls_windowmanagementblockedforurlsdesc","displayName":"Block Window Management permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"fba22d25d16e0666":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings","displayName":"Settings for GenAI local foundational model (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_0","displayName":"Downloads model automatically","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_genailocalfoundationalmodelsettings_genailocalfoundationalmodelsettings_1","displayName":"Do not download model","description":null,"helpText":null}]},"fbb16860b501ad13":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled","displayName":"Enable deleting undecryptable passwords (User)","description":"This policy controls whether the built-in password manager can delete undecryptable passwords from its database. This is required to restore the full functionality of the built-in password manager, but it may include a permanent data loss. Undecryptable password values will not become decryptable on their own and, if fixing them is possible, it usually requires complex user actions.\r\n\r\nSetting the policy to Enabled or leaving it unset means that users with undecryptable passwords saved to the built-in password manager will lose them. Passwords that are still in a working state will remain untouched.\r\n\r\nSetting the policy to Disabled means users will leave their password manager data untouched, but will experience a broken password manager functionality.\r\n\r\nIf the policy is set, users can't change it in Google Chrome.","helpText":"","infoUrls":[],"categoryId":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","categoryName":"Password manager","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~passwordmanager_deletingundecryptablepasswordsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fbd559d5362fcc25":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks","displayName":"Excel 4 workbooks (User)","description":"This policy setting allows you to determine whether users can open, view, edit, or save Excel files with the format specified by the title of this policy setting.\r\n\r\nIf you enable this policy setting, you can specify whether users can open, view, edit, or save files.\r\n\r\nThe options that can be selected are below. Note: Not all options may be available for this policy setting.\r\n\r\n- Do not block: The file type will not be blocked.\r\n\r\n- Save blocked: Saving of the file type will be blocked.\r\n\r\n- Open/Save blocked, use open policy: Both opening and saving of the file type will be blocked. The file will open based on the policy setting configured in the \"default file block behavior\" key.\r\n\r\n- Block: Both opening and saving of the file type will be blocked, and the file will not open.\r\n\r\n- Open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit the file type will not be enabled.\r\n\r\n- Allow editing and open in Protected View: Both opening and saving of the file type will be blocked, and the option to edit will be enabled.\r\n\r\nIf you disable or do not configure this policy setting, the file type will be blocked.","helpText":"","infoUrls":[],"categoryId":"5c4224e0-6a48-4665-9332-958d98124157","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_fileblocksettings_l_excel4workbooks_1","displayName":"Enabled","description":null,"helpText":null}]},"fb8a97ca89f71200":{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate","displayName":"Locked-Down Local Machine Zone Template (User)","description":"This template policy setting allows you to configure policy settings in this zone consistent with a selected security level, for example, Low, Medium Low, Medium, or High.\n\nIf you enable this template policy setting and select a security level, all values for individual settings in the zone will be overwritten by the standard template defaults.\n\nIf you disable this template policy setting, no security level is configured.\n\nIf you do not configure this template policy setting, no security level is configured.\n\nNote. Local Machine Zone Lockdown Security and Network Protocol Lockdown operate by comparing the settings in the active URL's zone against those in the Locked-Down equivalent zone. If you select a security level for any zone (including selecting no security), the same change should be made to the Locked-Down equivalent.\n\nNote. It is recommended to configure template policy settings in one Group Policy object (GPO) and configure any related individual policy settings in a separate GPO. You can then use Group Policy management features (for example, precedence, inheritance, or enforce) to apply individual settings to specific targets.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-allowlockeddownlocalmachinezonetemplate"],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowlockeddownlocalmachinezonetemplate_1","displayName":"Enabled","description":null,"helpText":null}]},"fb86fc621a647309":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols","displayName":"Initialize and script ActiveX controls not marked as safe (User)","description":"This policy setting allows you to manage ActiveX controls not marked as safe.\n\nIf you enable this policy setting, ActiveX controls are run, loaded with parameters, and scripted without setting object safety for untrusted data or scripts. This setting is not recommended, except for secure and administered zones. This setting causes both unsafe and safe controls to be initialized and scripted, ignoring the Script ActiveX controls marked safe for scripting option.\n\nIf you enable this policy setting and select Prompt in the drop-down box, users are queried whether to allow the control to be loaded with parameters or scripted.\n\nIf you disable this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.\n\nIf you do not configure this policy setting, ActiveX controls that cannot be made safe are not loaded with parameters or scripted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneinitializeandscriptactivexcontrols"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneinitializeandscriptactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"fb303c459deaebe1":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter","displayName":"Turn on Cross-Site Scripting Filter (User)","description":"This policy controls whether or not the Cross-Site Scripting (XSS) Filter will detect and prevent cross-site script injections into websites in this zone.\n\nIf you enable this policy setting, the XSS Filter is turned on for sites in this zone, and the XSS Filter attempts to block cross-site script injections.\n\nIf you disable this policy setting, the XSS Filter is turned off for sites in this zone, and Internet Explorer permits cross-site script injections.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneenablecrosssitescriptingfilter"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenablecrosssitescriptingfilter_1","displayName":"Enabled","description":null,"helpText":null}]},"fb44118cc60d88da":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708","displayName":"Enable dragging of content from different domains within a window (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneenabledraggingofcontentfromdifferentdomainswithinwindows_iz_partname2708_3","displayName":"Disable","description":null,"helpText":null}]},"fb80ced17f214ecd":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended","displayName":"Show Home button on toolbar (User)","description":"Shows the Home button on Microsoft Edge's toolbar.\r\n\r\nEnable this policy to always show the Home button. Disable it to never show the button.\r\n\r\nIf you don't configure the policy, users can choose whether to show the home button.","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_showhomebutton_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fb9ce5646d2f619d":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride","displayName":"Prevent bypassing Microsoft Defender SmartScreen prompts for sites (User)","description":"This policy setting lets you decide whether users can override the Microsoft Defender SmartScreen warnings about potentially malicious websites.\r\n\r\nIf you enable this setting, users can't ignore Microsoft Defender SmartScreen warnings and they are blocked from continuing to the site.\r\n\r\nIf you disable or don't configure this setting, users can ignore Microsoft Defender SmartScreen warnings and continue to the site.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain; or on Windows 10 Pro or Enterprise instances that are enrolled for device management.","helpText":"","infoUrls":[],"categoryId":"08c5f391-e156-4a72-bbb9-3670f2f63a56","categoryName":"SmartScreen settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~smartscreen_preventsmartscreenpromptoverride_1","displayName":"Enabled","description":null,"helpText":null}]},"fb0b9a6fb09f0499":{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed","displayName":"Live captions allowed (User)","description":"Allow users to turn the Live captions feature on or off.\r\n\r\nLive captions is an accessibility feature that converts speech from the audio that plays in Microsoft Edge in to text and shows this text in a separate window. The entire process happens on the device and no audio or caption text ever leaves the device.\r\n\r\nNote: This feature is not generally available. Clients that have the 'ExperimentationAndConfigurationServiceControl' (Control communication with the Experimentation and Configuration Service) policy set to 'FullMode' may receive the feature before broad availability. Broad availability will be announced via Microsoft Edge release notes.\r\n\r\nIf you enable or don't configure this policy, users can turn this feature on or off at edge://settings/accessibility.\r\n\r\nIf you disable this policy, users will not be able to turn this accessibility feature on. If speech recognition files have been downloaded previously, they will be deleted from the device in 30 days. We recommend avoiding this option unless it's needed in your environment.\r\n\r\nIf users choose to turn on Live captions, speech recognition files (approximately 100 megabytes) will be downloaded to the device on first run and then periodically to improve performance and accuracy. These files will be deleted after 30 days.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev103~policy~microsoft_edge_livecaptionsallowed_1","displayName":"Enabled","description":null,"helpText":null}]},"fb1d6c6293453390":{"id":"user_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturl_recommended_defaultsearchprovidersuggesturl","displayName":"Default search provider URL for suggestions (User)","description":"","helpText":"","infoUrls":[],"categoryId":"6f1386e5-148d-4dc3-84d1-79df721e3233","categoryName":"Default search provider","options":null},"fb0cb17c121c1a9f":{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout","displayName":"Set the background tab inactivity timeout for Sleeping Tabs (User)","description":"","helpText":"","infoUrls":[],"categoryId":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","categoryName":"Sleeping Tabs settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_300","displayName":"5 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_900","displayName":"15 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_1800","displayName":"30 minutes of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_3600","displayName":"1 hour of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_7200","displayName":"2 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_10800","displayName":"3 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_21600","displayName":"6 hours of inactivity","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev88~policy~microsoft_edge_recommended~sleepingtabs_recommended_sleepingtabstimeout_recommended_sleepingtabstimeout_43200","displayName":"12 hours of inactivity","description":null,"helpText":null}]},"fb331eb1bb3edd8e":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled","displayName":"Enable implicit sign-in (User)","description":"Configure this policy to allow/disallow implicit sign-in.\r\n\r\nIf you have configured the 'BrowserSignin' (Browser sign-in settings) policy to 'Disable browser sign-in', this policy will not take any effect.\r\n\r\nIf you enable or don't configure this setting, implicit sign-in will be enabled, Edge will attempt to sign the user into their profile based on what and how they sign in to their OS.\r\n\r\nIf you disable this setting, implicit sign-in will be disabled.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge~identity_implicitsigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fb00e3975b306dd3":{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi","displayName":"Print Rasterize PDF DPI (User)","description":"Controls print image resolution when Microsoft Edge prints PDFs with rasterization.\r\n\r\nWhen printing a PDF using the Print to image option, it can be beneficial to specify a print resolution other than a device's printer setting or the PDF default. A high resolution will significantly increase the processing and printing time while a low resolution can lead to poor imaging quality.\r\n\r\nIf you set this policy, it allows a particular resolution to be specified for use when rasterizing PDFs for printing.\r\n\r\nIf you set this policy to zero or don't configure it, the system default resolution will be used during rasterization of page images.","helpText":"","infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge~printing_printrasterizepdfdpi_1","displayName":"Enabled","description":null,"helpText":null}]},"fb30d3376a911ba1":{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains","displayName":"Turn off roaming of file names and metadata by server domain. (User)","description":"\r\nThis policy setting controls whether file names and metadata for Office files are roamed and appear in the list of recently opened files in an Office app, such as Word, on different devices.\r\n\r\nRoaming, which relies on a web-based Microsoft service, occurs when a user signs into Office with the same work or school account on different devices.\r\n\r\nNote: This policy is applied to any Office files stored on a specified list of server domains. The set of disallowed domains is a semicolon separated list: \"*.contoso.com;service.microsoft.com\".\r\n\r\nIf you enable this policy setting, file names and metadata won't roam and won’t appear in the list of recently opened files in Office apps on other devices, unless the file has been opened on that device.\r\n\r\nIf you disable or don't configure this policy setting, file names and metadata will roam and will appear in the list of recently opened files in Office apps on other devices, even if the file hasn’t been opened on that device.","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v12~policy~l_microsoftofficesystem~l_miscellaneous437_l_disallowedroamingmrudomains_1","displayName":"Enabled","description":null,"helpText":null}]},"fb00976aac675252":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab","displayName":"Remove Member Of tab (User)","description":"This policy setting allows you to remove the Member Of tab from the Contact Card.\r\n\r\nIf you enable this policy setting the Member Of tab is removed from the Contact Card.\r\n\r\nIf you disable or do not configure this policy setting the Member Of tab appears on the Contact Card.","helpText":"","infoUrls":[],"categoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","categoryName":"Contact Card","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard_l_removememberoftab_1","displayName":"Enabled","description":null,"helpText":null}]},"fbb4f4bdb2a05829":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_disableitemsinuserinterface_l_tooltipfordisabledtoolbarbuttonsandmenuitems_l_tooltipfordisabledtoolbarbuttonsandmenuitems353","displayName":"Tooltip for disabled toolbar buttons and menu items (User)","description":"","helpText":"","infoUrls":[],"categoryId":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","categoryName":"Disable Items in User Interface","options":null},"fb6be6e5d11ad081":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_noextensibilitycustomizationfromdocumentpolicy_l_noextensibilitycustomizationfromdocumentpolicyaccess_1","displayName":"True","description":null,"helpText":null}]},"fba7db6888a415b6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt","displayName":"Arabic (Egypt) (User)","description":"Enables the editing language Arabic (Egypt)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_arabicegypt_1","displayName":"Enabled","description":null,"helpText":null}]},"fbdd2b79a986a52f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga","displayName":"Xitsonga (User)","description":"Enables the editing language Xitsonga","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_xitsonga_1","displayName":"Enabled","description":null,"helpText":null}]},"fbce2f637fb62221":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote","displayName":"Default unit of measurement used in OneNote (User)","description":"Sets the value in the option ''Measurement units''.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_defaultunitofmeasurementusedinonenote_1","displayName":"Enabled","description":null,"helpText":null}]},"fb089549210303d2":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics","displayName":"Disable online mode for Get Diagnostics. (User)","description":"\r\n This policy setting determines whether online mode for Get Diagnostics is allowed. Enabling this setting will block Get Diagnostics feature from sending authentication and diagnostics logs to our service.\r\n Users will now go through offline mode. We will collect all the logs and store them in the Downloads folder of the user. This user can contact support and decide if they want to send us the logs. \r\n ","helpText":"","infoUrls":[],"categoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other_l_disableonlinemodeauthdiagnostics_1","displayName":"Enabled","description":null,"helpText":null}]},"fb77ed0e24ae7c5f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload","displayName":"Specify list of social network providers to load (User)","description":"This policy setting determines the list of social network providers that are loaded by the Outlook Social Connector.\r\n\r\nIf you enable this policy setting, you may enter a list of provider progIDs of social network providers that will be loaded by the Outlook Social Connector. This list needs to be semi-colon delimited. Note that if you enable this policy setting, only social network providers that are on this list will be loaded by the Outlook Social Connector. No other social network providers will be loaded.\r\n\r\nIf you disable or you do not configure this policy setting, the Outlook Social Connector can load any provider specified by the user.","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifylistofsocialnetworkproviderstoload_1","displayName":"Enabled","description":null,"helpText":null}]},"fb2ca4a9a3f8ddef":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode","displayName":"Cached Exchange Mode (File | Cached Exchange Mode) (User)","description":"Specifies the default Cached Exchange Mode for new profiles and disables the download options in the Cached Exchange Mode command submenu in the File menu.","helpText":"","infoUrls":[],"categoryId":"82ecfab7-b76a-4cec-8e76-859db4599ac2","categoryName":"Cached Exchange Mode","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings~l_cachedexchangemode_l_cachedexchangemodefilecachedexchangemode_1","displayName":"Enabled","description":null,"helpText":null}]},"fbf241c31a55481c":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins","displayName":"Block all unmanaged add-ins (User)","description":"This policy setting blocks all add-ins that are not managed by the \"List of managed add-ins\" policy setting.\r\n\r\nIf you enable this policy setting, and the \"List of managed add-ins\" policy setting is also enabled, all add-ins are blocked except those that are configured as 1 (always enabled) or 2 (configurable by the user) in the \"List of managed add-ins\" policy setting.\r\n\r\nIf you disable or do not configure this policy setting, users can enable or disable any add-ins that are not managed by the \"List of managed add-ins\" policy setting.","helpText":"","infoUrls":[],"categoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_miscellaneous160_l_blockallunmanagedaddins_1","displayName":"Enabled","description":null,"helpText":null}]},"fbbb49f1f9746249":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4","displayName":"Language for file conversion (User)","description":"This policy setting specifies how Visio determines what language to use when converting to or from an earlier version of Visio. \r\n\r\nIf you enable this policy setting, you may select from one of these options:\r\n\r\n- Let Visio decide language\r\n- Prompt for language\r\n- Use the following language: You must specify the numeric Microsoft Locale ID (LCID) for that language.\r\n\r\nIf you disable or do not configure this policy setting, Visio decides what language to use.","helpText":"","infoUrls":[],"categoryId":"6ae0d607-832c-403b-b3bc-c563e390ebad","categoryName":"Save/Open","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_advanced~l_saveopen_l_languageforfileconversion4_1","displayName":"Enabled","description":null,"helpText":null}]},"fbf660e734c304f0":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments","displayName":"Set maximum number of trusted documents (User)","description":"This policy setting allows you to specify the maximum number of trust records for trusted documents that can be stored in the registry before the purge task runs. The purge task reduces the number of trusted documents stored in the registry to the value set by the \"Set maximum number of trust records to preserve\" policy setting.\r\n\r\nIf you enable this policy setting, you can specify the maximum number of trusted documents to be stored in the registry before the purge task runs, with an upper limit of 20,000 documents. For performance reasons, we do not recommend setting this policy setting to the upper limit.\r\n\r\nIf you disable or do not configure this policy setting, the default value of 500 is used for the maximum number of trusted documents that can be stored in the registry before the purge task runs.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_setmaximumnumberoftrusteddocuments_1","displayName":"Enabled","description":null,"helpText":null}]},"fb54f307b409690c":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20","displayName":"Trusted Location #20 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc20_1","displayName":"Enabled","description":null,"helpText":null}]},"fb8d2875884a2ccb":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout","displayName":"Stop checking for tables used for layout (User)","description":"This policy setting prevents the Accessibility Checker from flagging layout tables (i.e. tables with no style applied).\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from flagging layout tables (i.e. tables with no style applied).\r\n\r\nIf you disable or do not configure this policy setting, tables with no style will be flagged and the violations will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingfortablesusedforlayout_1","displayName":"Enabled","description":null,"helpText":null}]},"fbe71eeb62a471c0":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful","displayName":"Stop checking to ensure hyperlink text is meaningful (User)","description":"This policy setting prevents the Accessibility Checker from verifying that hyperlinks have meaningful text.\r\n\r\nIf you enable this policy setting, the Accessibility Checker will be prevented from verifying that hyperlinks have meaningful text.\r\n\r\nIf you disable or do not configure this policy setting, hyperlink text will be checked and any issues will appear in the Accessibility Checker.","helpText":"","infoUrls":[],"categoryId":"73bc2db9-d37f-4add-a64d-a8239273edb3","categoryName":"Check Accessibility","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_filetab~l_checkaccessibility_l_stopcheckingtoensurehyperlinktextismeaningful_1","displayName":"Enabled","description":null,"helpText":null}]},"fbce3ad6a0854f2f":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks","displayName":"Update linked data before printing (User)","description":"This policy setting controls the \"Update linked data before printing\" setting found under File tab | Options | Display | Printing options.\r\n\r\nIf you enable this policy setting, Word will update linked data in the document before the document is printed. One example of linked data in Word is an embedded Excel chart that is linked to an Excel spreadsheet.\r\n\r\nIf you disable or do not configure this policy setting, Word will not update linked data in the document before the document is printed.","helpText":"","infoUrls":[],"categoryId":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","categoryName":"Display","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_display_l_updatelinks_1","displayName":"Enabled","description":null,"helpText":null}]},"fbca7c7a26e26800":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a5ce858b-74c2-4663-9b3e-068d31349a13","categoryName":"Cryptography","options":null},"fb617dfa29f2591e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_l_allowsubfolders71_1","displayName":"True","description":null,"helpText":null}]},"fb823848b82e9070":{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge","displayName":"Allow Local Policy Merge","description":"This value is used as an on/off switch. If this value is false, firewall rules from the local store are ignored and not enforced. The merge law for this option is to always use the value of the GroupPolicyRSoPStore. This value is valid for all schema versions.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge_false","displayName":"False","description":"AllowLocalPolicyMerge Off","helpText":null},{"id":"vendor_msft_firewall_mdmstore_publicprofile_allowlocalpolicymerge_true","displayName":"True","description":"AllowLocalPolicyMerge On","helpText":null}]},"fb2bac09e2fc6222":{"id":"vendor_msft_sharedpc_enablesharedpcmode","displayName":"Enable Shared PC Mode","description":"Setting this node to \"true\" triggers the action to configure a device to Shared PC mode.","helpText":"","infoUrls":[],"categoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","categoryName":"Shared PC","options":[{"id":"vendor_msft_sharedpc_enablesharedpcmode_false","displayName":"false","description":"Not configured","helpText":null},{"id":"vendor_msft_sharedpc_enablesharedpcmode_true","displayName":"true","description":"Enabled","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/fc.json b/public/intune-definitions/fc.json index 1c9144265bdb..ec0c1d254335 100644 --- a/public/intune-definitions/fc.json +++ b/public/intune-definitions/fc.json @@ -1 +1 @@ -{"fc6e77f05706ac6b":{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},"fc7356e7ba8326b5":{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch","displayName":"Assistive Touch","description":"If true, allows the user to toggle Assistive Touch.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch_true","displayName":"True","description":null,"helpText":null}]},"fcd8f653222832ec":{"id":"com.apple.applicationaccess_ratingappsjp","displayName":"Rating Apps - Japan","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_22","displayName":"All","description":null,"helpText":null}]},"fc5babb14e1e01f5":{"id":"com.apple.dock_magsize-immutable","displayName":"Magnification Size Immutable","description":"If true, locks the magnification slider.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_magsize-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_magsize-immutable_true","displayName":"True","description":null,"helpText":null}]},"fc93d3a4207297c2":{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting","displayName":"Set the default \"share additional operating system region\" setting","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultshareadditionalosregionsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},"fc2ef0f830e15e7f":{"id":"com.apple.managedclient.preferences_visualsearchenabled","displayName":"Visual search enabled","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#visualsearchenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_visualsearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualsearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fcdff67f98094b2b":{"id":"com.apple.notificationsettings_notificationsettings","displayName":"Notification Settings","description":"An array of notification settings dictionaries.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},"fcb8cfeafa94352c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page","description":"By default, the App Launcher is shown every time a user opens a new tab page.\n\nIf you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and App Launcher is there for users.\n\nIf you disable this policy, App Launcher doesn't appear and users can't launch Microsoft 365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fcfcaa445d3d8f45":{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\n\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"fca7e4837292c9f2":{"id":"device_vendor_msft_keyboardfilter_breakoutkeyscancode","displayName":"Breakout Key Scancode (Windows Insiders only)","description":"Get or set the scancode that forces the device to the login screen when pressed five times consecutively. The value is the string representation of the hexadecimal scancode (without the \"0x\" prefix). Defaults to \"5b\", the scancode for the \"left windows key\". Only set a single scancode; scancode combinations are not supported. After setting this value, a reboot is required for the change to take effect.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":null},"fca5a916bdffb659":{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy","displayName":"Turn off cache power mode","description":"This policy setting turns off power save mode on the hybrid hard disks in the system.\r\n\r\nIf you enable this policy setting, the hard disks are not put into NV cache power save mode and no power savings are achieved.\r\n\r\nIf you disable this policy setting, the hard disks are put into an NV cache power saving mode. In this mode, the system tries to save power by aggressively spinning down the disk.\r\n\r\nIf you do not configure this policy setting, the default behavior is to allow the hybrid hard disks to be in power save mode.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-cachepowermodepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"fc5d1ab07af06ed0":{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels","displayName":"PKInit Freshness Extension options:","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_1","displayName":"Supported","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_2","displayName":"Required","description":null,"helpText":null}]},"fc5dd726eea81ada":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncignoreblockouttime","displayName":"Maximum Allowed Time Without A Sync (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"fc875918638c7773":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},"fc5852454441aab1":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity","displayName":"Detailed Tracking Audit PNP Activity","description":"This policy setting allows you to audit when plug and play detects an external device. If you configure this policy setting, an audit event is generated whenever plug and play detects an external device. Only Success audits are recorded for this category. If you do not configure this policy setting, no audit event is generated when an external device is detected by plug and play.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditpnpactivity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"fc1d87a4b0d14112":{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata","displayName":"Let Apps Access Cellular Data","description":"This policy setting specifies whether Windows apps can access cellular data.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":[{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_0","displayName":"User is in control","description":"User is in control","helpText":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_1","displayName":"Force Allow","description":"Force Allow","helpText":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_2","displayName":"Force Deny","description":"Force Deny","helpText":null}]},"fcf5e9a367bced92":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled","displayName":"Enable AutoFill for credit cards","description":"Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.\r\n\r\nSetting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fcb762552d6ab4f0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis","displayName":"Disable support for 3D graphics APIs","description":"Setting the policy to True (or setting HardwareAccelerationModeEnabled to False) prevents webpages from accessing the WebGL API, and plugins can't use the Pepper 3D API.\r\n\r\nSetting the policy to False or leaving it unset lets webpages use the WebGL API and plugins use the Pepper 3D API, but the browser's default settings might still require command line arguments to use these APIs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis_1","displayName":"Enabled","description":null,"helpText":null}]},"fc95383aa7f63bf9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended","displayName":"Default search provider new tab page URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page.\r\n\r\nLeaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.\r\n\r\nExample value: https://search.my.company/newtab","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fc9cdc518cb224e7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended_defaultsearchprovidersuggesturlpostparams","displayName":"Parameters for suggest URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"fcd7e93ed505563a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin","displayName":"Minimum SSL version enabled","description":"Setting the policy to a valid value means Google Chrome won't use SSL/TLS versions less than the specified version. Unrecognized values are ignored.\r\n\r\nIf this policy is not set, then Google Chrome will show an error for TLS 1.0 and TLS 1.1, but the user will be able to bypass it.\r\n\r\nIf this policy is set to \"tls1.2\", the user will not be able to bypass this error.\r\n\r\nSupport for setting this policy to \"tls1\" or \"tls1.1\" was removed in version 91. Suppressing the TLS 1.0/1.1 warning is no longer supported.\r\n\r\nExample value: tls1.2","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_1","displayName":"Enabled","description":null,"helpText":null}]},"fca76c270d62d40a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled","displayName":"Enable Translate","description":"Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features.\r\n\r\nIf you set the policy, users can't change this function. Leaving it unset lets them change the setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fc8b6cfc55e50f36":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings","displayName":"Default search provider encodings","description":"If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\r\n\r\nLeaving DefaultSearchProviderEncodings unset puts UTF-8 in use.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_1","displayName":"Enabled","description":null,"helpText":null}]},"fc6c552bbedad4b8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"fcaaec9a0c5cdfa5":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings","displayName":"Settings for AI-powered History Search","description":"AI History Search is a feature that allows users to search their browsing history and receive generated answers based on page contents and not just the page title and URL.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"fc040b9d027421fe":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled","displayName":"Re-enable the deprecated async interface for FileSystemSyncAccessHandle in File System Access API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fc47e0386a66740d":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesnoprofilecontainingfolder","displayName":"No Profile Containing Folder","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nVHD(x) file is placed and used in the root VHDLocation rather than in a SID directory under VHDLocation\r\n\r\nNOTE: This setting will override ANY OTHER setting related to container folders.\r\n\r\n- SIDDIRNameMatch has NO EFFECT when used in conjunction with this setting.\r\n- SIDDIRNamePattern has NO EFFECT when used in conjunction with this setting.\r\n- FlipFlopProfileDirectoryName has NO EFFECT when used in conjunction with this setting.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\NoProfileContainingFolder\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesnoprofilecontainingfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesnoprofilecontainingfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"fc1411c80079b034":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"fc2a79f38c2e0420":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles","displayName":"Enable use of ephemeral profiles","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\r\n\r\nIf you enable this policy, profiles run in ephemeral mode. This lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\r\n\r\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\r\n\r\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user has enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},"fc017f55d24616b0":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare","displayName":"Configure the Share experience","description":"If you set this policy to 'ShareAllowed' (0, the default), users will be able to access the Windows 10 Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\r\n\r\nIf you set this policy to 'ShareDisallowed' (1), users won't be able to access the Windows 10 Share experience. If the Share button is on the toolbar, it will also be hidden.\r\n\r\n* 0 = Allow using the Share experience\r\n\r\n* 1 = Don't allow using the Share experience\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_1","displayName":"Enabled","description":null,"helpText":null}]},"fc6e6036d5620d41":{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 98.\r\n\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing was deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allowed re-enabling of cross-origin WebAssembly module sharing. This policy is obsolete because it was intended to offer a longer transition period in the deprecation process.\r\n\r\nIf you enable this policy, sites can send WebAssembly modules cross-origin\r\nwithout restrictions.\r\n\r\nIf you disable or don't configure this policy, sites can only send\r\nWebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fc9d8504be12a2f4":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled","displayName":"Show links shared from Microsoft 365 apps in History","description":"Allows Microsoft Edge to display links recently shared by or shared with the user from Microsoft 365 apps in History.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge displays links recently shared by or shared with the user from Microsoft 365 apps in History.\r\n\r\nIf you disable this policy, Microsoft Edge does not display links recently shared by or shared with the user from Microsoft 365 apps in History. The control in Microsoft Edge settings is disabled and set to off.\r\n\r\nThis policy only applies for Microsoft Edge local user profiles and profiles signed in using Azure Active Directory.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fca21feac5f012c9":{"id":"device_vendor_msft_policy_config_office16v5~policy~l_microsoftofficemachine~l_updates_l_preventbinginstall","displayName":"Don’t install extension for Microsoft Search in Bing that makes Bing the default search engine","description":"This policy setting allows you to control whether an extension for Microsoft Search in Bing is installed that makes Bing the default search engine for Google Chrome and Firefox web browsers. This extension is installed with a new installation of Office or when an existing installation of Office is updated.\r\n\r\nIf you enable this policy setting, the extension won’t be installed and Bing won’t be made the default search engine.\r\n\r\nIf you disable or don’t configure this policy setting, the extension will be installed and Bing will be made the default search engine, unless you have used some other method, such as the Office Deployment Tool, to exclude the extension from being installed.\r\n\r\nNote: Even if Bing is made the default search engine, users can still change the default search engine in Google Chrome or Firefox.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2109345.\r\n ","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v5~policy~l_microsoftofficemachine~l_updates_l_preventbinginstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v5~policy~l_microsoftofficemachine~l_updates_l_preventbinginstall_1","displayName":"Enabled","description":null,"helpText":null}]},"fcddc7d139655e88":{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_proxyserver_pol_proxymode","displayName":"Choose how to specify proxy server settings","description":"Allows you to specify the proxy server settings that are used by Microsoft Edge Update.\r\n\r\n If you enable this policy, you can choose between the following proxy server options:\r\n - If you choose to never use a proxy server and always connect directly, all other options are ignored.\r\n - If you choose to use system proxy settings or auto-detect the proxy server, all other options are ignored.\r\n - If you choose fixed server proxy mode, you can specify further options in 'Address or URL of proxy server'.\r\n - If you choose to use a .pac proxy script, you must specify the URL for the script in 'URL to a proxy .pac file'.\r\n\r\n If you enable this policy, users in your organization can't change the proxy settings in Microsoft Edge Update.\r\n\r\n If you disable or don't configure this policy, no proxy server settings are configured, but users in your organization can choose their own proxy settings for Microsoft Edge Update.","helpText":"","infoUrls":[],"categoryId":"ff543267-540e-4e37-a1e9-daf6a5e16ba7","categoryName":"Proxy Server","options":[{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_proxyserver_pol_proxymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_proxyserver_pol_proxymode_1","displayName":"Enabled","description":null,"helpText":null}]},"fc8a0b2f67444125":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_cachepath_cachepath_textbox","displayName":"Package Manifest and Payload Cache Path (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":null},"fcacb5892e21664e":{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autocreatedesktopshortcuts","displayName":"Automatically creates Windows App shortcuts to desktop","description":"Automatically creates Windows App shortcuts to the desktop to launch resources specified by the IT administrator.\n\nIf you enable this policy, Windows App will automatically create desktop shortcuts for resources configured by the IT admin in the Azure Virtual Desktop portal. After the user signs in, these shortcuts will be created on the desktop. When the user signs out, the shortcuts will be automatically cleaned up.\n\nIf you disable or do not configure this policy, desktop shortcuts will not be automatically created.\n ","helpText":"","infoUrls":[],"categoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","categoryName":"Windows App","options":[{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autocreatedesktopshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autocreatedesktopshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"fcb1198452b010e1":{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablecleartpmbutton","displayName":"Disable Clear Tpm Button","description":"Disable the Clear TPM button in Windows Security. Enabled:The Clear TPM button will be unavailable for use. Disabled:The Clear TPM button will be available for use on supported systems. Not configured:Same as Disabled. Supported values:0 - Disabled (default)1 - Enabled","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsDefenderSecurityCenter#disablecleartpmbutton"],"categoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","categoryName":"Windows Defender Security Center","options":[{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablecleartpmbutton_0","displayName":"(Disabled or not configured) The security processor troubleshooting page shows a button that initiates the process to clear the security processor (TPM).","description":"(Disabled or not configured) The security processor troubleshooting page shows a button that initiates the process to clear the security processor (TPM).","helpText":null},{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablecleartpmbutton_1","displayName":"(Enabled) The security processor troubleshooting page will not show a button to initiate the process to clear the security processor (TPM)","description":"(Enabled) The security processor troubleshooting page will not show a button to initiate the process to clear the security processor (TPM)","helpText":null}]},"fc32a155744d0d04":{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_clipboardfiletype","displayName":"Clipboard content options","description":"If you choose to enable copying, this policy determines the type of content that can be copied.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsDefenderApplicationGuard-csp/"],"categoryId":"cd55f347-a417-4fe9-83ee-8f1f40ac5eb0","categoryName":null,"options":[{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_clipboardfiletype_1","displayName":"Allow text copying","description":"Allow text copying.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_clipboardfiletype_2","displayName":"Allow image copying","description":"Allow image copying.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_clipboardfiletype_3","displayName":"Allow both text and image copying","description":"Allow text and image copying.","helpText":null}]},"fc9b21bc1191d828":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath","displayName":"Set the default source path for Update-Help (User)","description":"This policy setting allows you to set the default value of the SourcePath parameter on the Update-Help cmdlet.\r\n\r\nIf you enable this policy setting, the Update-Help cmdlet will use the specified value as the default value for the SourcePath parameter. This default value can be overridden by specifying a different value with the SourcePath parameter on the Update-Help cmdlet.\r\n\r\nIf this policy setting is disabled or not configured, this policy setting does not set a default value for the SourcePath parameter of the Update-Help cmdlet.\r\n\r\nNote: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enableupdatehelpdefaultsourcepath"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_1","displayName":"Enabled","description":null,"helpText":null}]},"fc3660eb4fff2df8":{"id":"user_vendor_msft_policy_config_admx_programs_noinstalledupdates","displayName":"Hide \"Installed Updates\" page (User)","description":"This setting prevents users from accessing \"Installed Updates\" page from the \"View installed updates\" task.\r\n\r\n\"Installed Updates\" allows users to view and uninstall updates currently installed on the computer. The updates are often downloaded directly from Windows Update or from various program publishers.\r\n\r\nIf this setting is disabled or not configured, the \"View installed updates\" task and the \"Installed Updates\" page will be available to all users.\r\n\r\nThis setting does not prevent users from using other tools and methods to install or uninstall programs.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-programs#admx-programs-noinstalledupdates"],"categoryId":"dc16dbf0-aac8-4ff3-a546-1ddb55650f47","categoryName":"Programs","options":[{"id":"user_vendor_msft_policy_config_admx_programs_noinstalledupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_programs_noinstalledupdates_1","displayName":"Enabled","description":null,"helpText":null}]},"fc54986f6b179d08":{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_1","displayName":"Custom Classes: Deny write access (User)","description":"This policy setting denies write access to custom removable storage classes.\r\n\r\nIf you enable this policy setting, write access is denied to these removable storage classes.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to these removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-customclasses-denywrite-access-1"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_1_1","displayName":"Enabled","description":null,"helpText":null}]},"fceb157bf22904bb":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013","displayName":"Microsoft Office 365 PowerPoint 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_1","displayName":"Enabled","description":null,"helpText":null}]},"fc11d595883c2c05":{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailyendminute","displayName":"Set the time Quiet Hours ends each day (User)","description":"\r\n This policy setting specifies the number of minutes after midnight (local time) that Quiet Hours is to end each day.\r\n\r\n If you enable this policy setting, the specified time will be used, and users will not be able to customize any Quiet Hours settings.\r\n\r\n If you disable this policy setting, a default value will be used, and users will not be able to change it or any other Quiet Hours setting.\r\n\r\n If you do not configure this policy setting, a default value will be used, which administrators and users will be able to modify.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-quiethoursdailyendminute"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailyendminute_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailyendminute_1","displayName":"Enabled","description":null,"helpText":null}]},"fcac313fed993b36":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_windowmanagementallowedforurlsdesc","displayName":"Allow Window Management permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"fc34e40664e561fb":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins","displayName":"List of origins allowing all HTTP authentication (User)","description":"Setting the policy specifies for which origins to allow all the HTTP authentication schemes Google Chrome supports regardless of the AuthSchemes policy.\r\n\r\nFormat the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in AllHttpAuthSchemesAllowedForOrigins.\r\nWildcards are allowed for the whole origin or parts of the origin, either the scheme, host, port.\r\n\r\nExample value:\r\n\r\n*.example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},"fc53c8c2022bb242":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled","displayName":"Extend support for Chrome Apps on Microsoft® Windows®, macOS, and Linux. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fc672c7ec22ce274":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font_l_namesize","displayName":"Name, Size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":null},"fc1e6b9b2f42c5c0":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails","displayName":"Set document behavior if file validation fails (User)","description":"This policy setting controls how Office handles documents when they fail file validation. \r\n\r\nIf you enable this policy setting, you can configure the following options for files that fail file validation:\r\n\r\n- Block files completely. Users cannot open the files.\r\n- Open files in Protected View and disallow edit. Users cannot edit the files. This is also how Office handles the files if you disable this policy setting.\r\n- Open files in Protected View and allow edit. Users can edit the files. This is also how Office handles the files if you do not configure this policy setting.\r\n\r\nIf you disable this policy setting, Office follows the \"Open files in Protected View and disallow edit\" behavior.\r\n\r\nIf you do not configure this policy setting, Office follows the \"Open files in Protected View and allow edit\" behavior.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_1","displayName":"Enabled","description":null,"helpText":null}]},"fc1d21a780ced2a7":{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc","displayName":"Allow Option To Show This PC (User)","description":"When This PC location is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshowthispc"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"fc878c6aa5ef39b3":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"fc59e4d47455d620":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"fc6a6e6c9213c81d":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles","displayName":"Allow drag and drop or copy and paste files (User)","description":"This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.\n\nIf you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.\n\nIf you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to drag or copy files from this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowdraganddropcopyandpastefiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"fc17e90fb423bd6b":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402","displayName":"Scripting of Java applets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_1","displayName":"Prompt","description":null,"helpText":null}]},"fce4ae26045915fc":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1","displayName":"Disable automatic upload of sign-in failure logs (User)","description":"\r\nUploads the sign-in failure logs to the Microsoft Lync Server automatically for analysis. No logs will be automatically uploaded if sign-in is successful.\r\n\r\nIf this policy is not configured, then the following happens: \r\nFor Lync Online Users: Sign-in failure logs are automatically uploaded.\r\nFor Lync On-Premise Users: A confirmation seeking consent from the user is shown before upload.\r\n\r\nWhen this is disabled, sign-in logs would be uploaded to the Microsoft Lync Server for both Lync On-Premise and Online users automatically.\r\n\r\nWhen this is enabled, sign-in logs will never be uploaded automatically.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1_1","displayName":"Enabled","description":null,"helpText":null}]},"fc2629516190626e":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting","displayName":"Default JavaScript setting (User)","description":"Set whether websites can run JavaScript. You can allow it for all sites (1) or block it for all sites (2).\r\n\r\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\r\n\r\n* 1 = Allow all sites to run JavaScript\r\n\r\n* 2 = Don't allow any site to run JavaScript","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"fc05c86a72ca1d75":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\r\n\r\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\n* 1 = Restore the last session\r\n\r\n* 4 = Open a list of URLs\r\n\r\n* 5 = Open a new tab","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},"fc059e60faba6fda":{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":null},"fc60b4d713e53ad2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics","displayName":"Inuktitut (Syllabics) (User)","description":"Enables the editing language Inuktitut (Syllabics)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics_1","displayName":"Enabled","description":null,"helpText":null}]},"fc7f79ed97b41258":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian","displayName":"Lower Sorbian (User)","description":"Enables the editing language Lower Sorbian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian_1","displayName":"Enabled","description":null,"helpText":null}]},"fcb468e3796eaeb2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari","displayName":"Sindhi (Devanagari) (User)","description":"Enables the editing language Sindhi (Devanagari)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari_1","displayName":"Enabled","description":null,"helpText":null}]},"fcd99fd07edbba4a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowpath439","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"fc0a5a0a9b77b014":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_l_allowedextensionsole","displayName":"File extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},"fc45b7e12bb17bf2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_pathcolon15","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"fc9b74bfb0ff07e4":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders","displayName":"Reminders (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"13eb248a-4549-4d23-9ada-23b40edf36bf","categoryName":"Reminder Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_1","displayName":"Enabled","description":null,"helpText":null}]},"fc3bb8b0dfe5d596":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook","displayName":"Turn off Hierarchical Address Book (User)","description":"This policy setting turns off the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, the HAB will be turned off. \r\n\r\nIf you disable or do not configure this policy setting, the HAB will be displayed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook_1","displayName":"Enabled","description":null,"helpText":null}]},"fc064a4a6e0d009d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"fc95a786bc8a79f1":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_pathcolon84","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"fcdd8ec4c25e8202":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File Tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},"fc0724cd4b95b9ab":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"fcfd84b336484464":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteaddressdynamickeywords","displayName":"Reusable groups","description":"Comma separated list of Dynamic Keyword Address Ids (GUID strings) specifying the remote addresses covered by the rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file +{"fc6e77f05706ac6b":{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary","displayName":"Target version override","description":"When this policy is enabled, and auto-update is enabled, Microsoft Edge will be updated to the version specified by this policy value.\r\n\r\nThe policy value must be a specific Microsoft Edge version, e.g. 83.0.499.12.\r\n\r\nIf a device has newer version of Microsoft Edge than the value specified, Microsoft Edge will remain on the newer version and not downgrade to the specified version.\r\n\r\nIf the specified version does not exist, or is improperly formatted, then Microsoft Edge will remain on its current version and not update to future versions automatically.","helpText":"","infoUrls":[],"categoryId":"797ac384-f48e-4567-b931-33a6ce923b94","categoryName":"Microsoft Edge Canary","options":[{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_0","displayName":"Disabled","description":null,"helpText":null},{"id":"~policy~cat_edgeupdate~cat_applications~cat_microsoftedgecanary_pol_targetversionprefixmicrosoftedgecanary_1","displayName":"Enabled","description":null,"helpText":null}]},"fc7356e7ba8326b5":{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch","displayName":"Assistive Touch","description":"If true, allows the user to toggle Assistive Touch.","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_assistivetouch_true","displayName":"True","description":null,"helpText":null}]},"fcd8f653222832ec":{"id":"com.apple.applicationaccess_ratingappsjp","displayName":"Rating Apps - Japan","description":"The maximum level of app content allowed on the device. Available in iOS 4 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_ratingappsjp_0","displayName":"None","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_1","displayName":"1+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_2","displayName":"2+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_3","displayName":"3+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_4","displayName":"4+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_5","displayName":"5+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_6","displayName":"6+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_7","displayName":"7+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_8","displayName":"8+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_9","displayName":"9+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_10","displayName":"10+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_11","displayName":"11+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_12","displayName":"12+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_13","displayName":"13+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_14","displayName":"14+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_15","displayName":"15+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_16","displayName":"16+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_17","displayName":"17+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_18","displayName":"18+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_19","displayName":"19+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_20","displayName":"20+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_21","displayName":"21+","description":null,"helpText":null},{"id":"com.apple.applicationaccess_ratingappsjp_22","displayName":"All","description":null,"helpText":null}]},"fc5babb14e1e01f5":{"id":"com.apple.dock_magsize-immutable","displayName":"Magnification Size Immutable","description":"If true, locks the magnification slider.","helpText":null,"infoUrls":[],"categoryId":"cc388035-b49c-493e-a598-14b0d0de4359","categoryName":"Dock","options":[{"id":"com.apple.dock_magsize-immutable_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.dock_magsize-immutable_true","displayName":"True","description":null,"helpText":null}]},"fc93d3a4207297c2":{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting","displayName":"Set the default \"share additional operating system region\" setting","description":"This policy controls the default value for the \"share additional operating system region\" setting in Microsoft Edge.\n\nThe \"share additional operating system region\" Microsoft Edge setting controls whether the OS Regional format setting will be shared with the web through the default JavaScript locale. If shared, websites will be able to query the OS Regional format using JavaScript code, for example; \"Intl.DateTimeFormat().resolvedOptions().locale\". The default value for the setting is \"Limited\".\n\nIf you set this policy to \"Limited\", the OS Regional format will only be shared if its language part matches the Microsoft Edge display language.\n\nIf you set this policy to \"Always\", the OS Regional format will always be shared. This value could cause unexpected website behavior if the OS Regional format language is different from the Microsoft Edge display language. For example, if a website uses the JavaScript default locale to format dates, the names of the days and months can be displayed in one language while the surrounding text is displayed in another language.\n\nIf you set this policy to \"Never\", the OS Regional format will never be shared.\n\nExample 1: In this example the OS Regional format is set to \"en-GB\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Limited\", or \"Always\".\n\nExample 2: In this example the OS Regional format is set to \"es-MX\" and the browser display language is set to \"en-US\". Then the OS Regional format will be shared if the policy is set to \"Always\" but will not if the policy is set to \"Limited\".\n\nFor more information about this setting, see https://go.microsoft.com/fwlink/?linkid=2222282\n\nPolicy options mapping:\n\n* Limited (0) = Limited\n\n* Always (1) = Always share the OS Regional format\n\n* Never (2) = Never share the OS Regional format\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#defaultshareadditionalosregionsetting"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_0","displayName":"Limited","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_1","displayName":"Always share the OS Regional format","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_defaultshareadditionalosregionsetting_2","displayName":"Never share the OS Regional format","description":null,"helpText":null}]},"fc2ef0f830e15e7f":{"id":"com.apple.managedclient.preferences_visualsearchenabled","displayName":"Visual search enabled","description":"Visual search lets you quickly explore more related content about entities in an image.\n\nIf you enable or don't configure this policy, visual search will be enabled via image hover, context menu, and search in sidebar.\n\nIf you disable this policy, visual search will be disabled and you won't be able to get more info about images via hover, context menu, and search in sidebar.\n\nNote: Visual Search in Web Capture is still managed by \"WebCaptureEnabled\" policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#visualsearchenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_visualsearchenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_visualsearchenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fcdff67f98094b2b":{"id":"com.apple.notificationsettings_notificationsettings","displayName":"Notification Settings","description":"An array of notification settings dictionaries.","helpText":null,"infoUrls":[],"categoryId":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","categoryName":"Notifications","options":null},"fcb8cfeafa94352c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled","displayName":"Hide App Launcher on Microsoft Edge new tab page","description":"By default, the App Launcher is shown every time a user opens a new tab page.\n\nIf you enable or don't configure this policy, there's no change on the Microsoft Edge new tab page and App Launcher is there for users.\n\nIf you disable this policy, App Launcher doesn't appear and users can't launch Microsoft 365 apps from Microsoft Edge new tab page via the App Launcher.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.newtabpageapplauncherenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fcfcaa445d3d8f45":{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed","displayName":"Allow users to proceed from the HTTPS warning page","description":"Microsoft Edge shows a warning page when users visit sites that have SSL errors.\n\nIf you enable or don't configure (default) this policy, users can click through these warning pages.\n\nIf you disable this policy, users are blocked from clicking through any warning page.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.sslerroroverrideallowed_true","displayName":"Enabled","description":null,"helpText":null}]},"fca7e4837292c9f2":{"id":"device_vendor_msft_keyboardfilter_breakoutkeyscancode","displayName":"Breakout Key Scancode (Windows Insiders only)","description":"Get or set the scancode that forces the device to the login screen when pressed five times consecutively. The value is the string representation of the hexadecimal scancode (without the \"0x\" prefix). Defaults to \"5b\", the scancode for the \"left windows key\". Only set a single scancode; scancode combinations are not supported. After setting this value, a reboot is required for the change to take effect.\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/KeyboardFilter-csp/"],"categoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","categoryName":"Keyboard Filter","options":null},"fca5a916bdffb659":{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy","displayName":"Turn off cache power mode","description":"This policy setting turns off power save mode on the hybrid hard disks in the system.\r\n\r\nIf you enable this policy setting, the hard disks are not put into NV cache power save mode and no power savings are achieved.\r\n\r\nIf you disable this policy setting, the hard disks are put into an NV cache power saving mode. In this mode, the system tries to save power by aggressively spinning down the disk.\r\n\r\nIf you do not configure this policy setting, the default behavior is to allow the hybrid hard disks to be in power save mode.\r\n\r\nNote: This policy setting is applicable only if the NV cache feature is on.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-disknvcache#admx-disknvcache-cachepowermodepolicy"],"categoryId":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","categoryName":"Disk NV Cache","options":[{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_disknvcache_cachepowermodepolicy_1","displayName":"Enabled","description":null,"helpText":null}]},"fc5d1ab07af06ed0":{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels","displayName":"PKInit Freshness Extension options:","description":null,"helpText":"","infoUrls":[],"categoryId":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","categoryName":"KDC","options":[{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_1","displayName":"Supported","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_kdc_pkinitfreshness_pkinitfreshness_levels_2","displayName":"Required","description":null,"helpText":null}]},"fc5dd726eea81ada":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncignoreblockouttime","displayName":"Maximum Allowed Time Without A Sync (minutes)","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"fc875918638c7773":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypeguaranteed_pv_qospriorityvalue","displayName":"Priority value","description":null,"helpText":"","infoUrls":[],"categoryId":"c87ae066-cc1a-44c9-8645-1db2359f7484","categoryName":"Layer-2 priority value","options":null},"fc5852454441aab1":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity","displayName":"Detailed Tracking Audit PNP Activity","description":"This policy setting allows you to audit when plug and play detects an external device. If you configure this policy setting, an audit event is generated whenever plug and play detects an external device. Only Success audits are recorded for this category. If you do not configure this policy setting, no audit event is generated when an external device is detected by plug and play.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditpnpactivity"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditpnpactivity_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"fc1d87a4b0d14112":{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata","displayName":"Let Apps Access Cellular Data","description":"This policy setting specifies whether Windows apps can access cellular data.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Cellular#letappsaccesscellulardata"],"categoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","categoryName":"Cellular","options":[{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_0","displayName":"User is in control","description":"User is in control","helpText":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_1","displayName":"Force Allow","description":"Force Allow","helpText":null},{"id":"device_vendor_msft_policy_config_cellular_letappsaccesscellulardata_2","displayName":"Force Deny","description":"Force Deny","helpText":null}]},"fcf5e9a367bced92":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled","displayName":"Enable AutoFill for credit cards","description":"Setting the policy to True or leaving it unset means users can control autofill suggestions for credit cards in the UI.\r\n\r\nSetting the policy to False means autofill never suggests or fills credit card information, nor will it save additional credit card information that users might submit while browsing the web.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autofillcreditcardenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fcb762552d6ab4f0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis","displayName":"Disable support for 3D graphics APIs","description":"Setting the policy to True (or setting HardwareAccelerationModeEnabled to False) prevents webpages from accessing the WebGL API, and plugins can't use the Pepper 3D API.\r\n\r\nSetting the policy to False or leaving it unset lets webpages use the WebGL API and plugins use the Pepper 3D API, but the browser's default settings might still require command line arguments to use these APIs.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_disable3dapis_1","displayName":"Enabled","description":null,"helpText":null}]},"fc95383aa7f63bf9":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended","displayName":"Default search provider new tab page URL","description":"If DefaultSearchProviderEnabled is on, then setting DefaultSearchProviderNewTabURL specifies the URL of the search engine used to provide a New Tab page.\r\n\r\nLeaving DefaultSearchProviderNewTabURL unset means no new tab page is provided.\r\n\r\nExample value: https://search.my.company/newtab","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidernewtaburl_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fc9cdc518cb224e7":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended~defaultsearchprovider_recommended_defaultsearchprovidersuggesturlpostparams_recommended_defaultsearchprovidersuggesturlpostparams","displayName":"Parameters for suggest URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","categoryName":"Default search provider","options":null},"fcd7e93ed505563a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin","displayName":"Minimum SSL version enabled","description":"Setting the policy to a valid value means Google Chrome won't use SSL/TLS versions less than the specified version. Unrecognized values are ignored.\r\n\r\nIf this policy is not set, then Google Chrome will show an error for TLS 1.0 and TLS 1.1, but the user will be able to bypass it.\r\n\r\nIf this policy is set to \"tls1.2\", the user will not be able to bypass this error.\r\n\r\nSupport for setting this policy to \"tls1\" or \"tls1.1\" was removed in version 91. Suppressing the TLS 1.0/1.1 warning is no longer supported.\r\n\r\nExample value: tls1.2","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_sslversionmin_1","displayName":"Enabled","description":null,"helpText":null}]},"fca76c270d62d40a":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled","displayName":"Enable Translate","description":"Setting the policy to True provides translation functionality when it's appropriate for users by showing an integrated translate toolbar in Google Chrome and a translate option on the right-click context menu. Setting the policy to False shuts off all built-in translate features.\r\n\r\nIf you set the policy, users can't change this function. Leaving it unset lets them change the setting.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_translateenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fc8b6cfc55e50f36":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings","displayName":"Default search provider encodings","description":"If DefaultSearchProviderEnabled is on, setting DefaultSearchProviderEncodings specifies the character encodings supported by the search provider. Encodings are code page names such as UTF-8, GB2312, and ISO-8859-1. They're tried in the order provided.\r\n\r\nLeaving DefaultSearchProviderEncodings unset puts UTF-8 in use.\r\n\r\nExample value:\r\n\r\nUTF-8\r\nUTF-16\r\nGB2312\r\nISO-8859-1","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchproviderencodings_1","displayName":"Enabled","description":null,"helpText":null}]},"fc6c552bbedad4b8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_defaultsearchproviderinstanturlpostparams_defaultsearchproviderinstanturlpostparams","displayName":"Parameters for instant URL which uses POST (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"fcaaec9a0c5cdfa5":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings","displayName":"Settings for AI-powered History Search","description":"AI History Search is a feature that allows users to search their browsing history and receive generated answers based on page contents and not just the page title and URL.\r\n\r\n0 = Allow the feature to be used, while allowing Google to use relevant data to improve its AI models. Relevant data may include prompts, inputs, outputs, source materials, and written feedback, depending on the feature. It may also be reviewed by humans to improve AI models. 0 is the default value, except when noted below.\r\n\r\n1 = Allow the feature to be used, but does not allow Google to improve models using users' content (including prompts, inputs, outputs, source materials, and written feedback). 1 is the default value for Enterprise users managed by Google Admin console and for Education accounts managed by Google Workspace.\r\n\r\n2 = Do not allow the feature.\r\n\r\nIf the policy is unset, its behavior is determined by the GenAiDefaultSettings policy.\r\n\r\nFor more information on data handling for generative AI features, please see https://support.google.com/chrome/a?p=generative_ai_settings.","helpText":"","infoUrls":[],"categoryId":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","categoryName":"Generative AI","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~generativeai_historysearchsettings_1","displayName":"Enabled","description":null,"helpText":null}]},"fc040b9d027421fe":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled","displayName":"Re-enable the deprecated async interface for FileSystemSyncAccessHandle in File System Access API","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_filesystemsyncaccesshandleasyncinterfaceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fc47e0386a66740d":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesnoprofilecontainingfolder","displayName":"No Profile Containing Folder","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nVHD(x) file is placed and used in the root VHDLocation rather than in a SID directory under VHDLocation\r\n\r\nNOTE: This setting will override ANY OTHER setting related to container folders.\r\n\r\n- SIDDIRNameMatch has NO EFFECT when used in conjunction with this setting.\r\n- SIDDIRNamePattern has NO EFFECT when used in conjunction with this setting.\r\n- FlipFlopProfileDirectoryName has NO EFFECT when used in conjunction with this setting.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Profiles\\NoProfileContainingFolder\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"479c2edd-6539-4e1d-96ba-518d6f6264c3","categoryName":"Container and Directory Naming","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesnoprofilecontainingfolder_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles~profiles_containeranddirectorynaming_profilesnoprofilecontainingfolder_1","displayName":"Enabled","description":null,"helpText":null}]},"fc1411c80079b034":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209","displayName":"Scriptlets","description":"","helpText":"","infoUrls":[],"categoryId":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","categoryName":"Locked- Down Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209_0","displayName":"Enable","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddownrestrictedsiteszoneallowscriptlets_iz_partname1209_3","displayName":"Disable","description":null,"helpText":null}]},"fc2a79f38c2e0420":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles","displayName":"Enable use of ephemeral profiles","description":"Controls whether user profiles are switched to ephemeral mode. An ephemeral profile is created when a session begins, is deleted when the session ends, and is associated with the user's original profile.\r\n\r\nIf you enable this policy, profiles run in ephemeral mode. This lets users work from their own devices without saving browsing data to those devices. If you enable this policy as an OS policy (by using GPO on Windows, for example), it applies to every profile on the system.\r\n\r\nIf you disable this policy or don't configure it, users get their regular profiles when they sign in to the browser.\r\n\r\nIn ephemeral mode, profile data is saved on disk only for the length of the user session. Features like browser history, extensions and their data, web data like cookies, and web databases aren't saved after the browser is closed. This doesn't prevent a user from manually downloading any data to disk, or from saving pages or printing them. If the user has enabled sync, all data is preserved in their sync accounts just like with regular profiles. Users can also use InPrivate browsing in ephemeral mode unless you explicitly disable this.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_forceephemeralprofiles_1","displayName":"Enabled","description":null,"helpText":null}]},"fc017f55d24616b0":{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare","displayName":"Configure the Share experience","description":"If you set this policy to 'ShareAllowed' (0, the default), users will be able to access the Windows 10 Share experience from the Settings and More Menu in Microsoft Edge to share with other apps on the system.\r\n\r\nIf you set this policy to 'ShareDisallowed' (1), users won't be able to access the Windows 10 Share experience. If the Share button is on the toolbar, it will also be hidden.\r\n\r\n* 0 = Allow using the Share experience\r\n\r\n* 1 = Don't allow using the Share experience\r\n","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev83diff~policy~microsoft_edge_configureshare_1","displayName":"Enabled","description":null,"helpText":null}]},"fc6e6036d5620d41":{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 98.\r\n\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing was deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allowed re-enabling of cross-origin WebAssembly module sharing. This policy is obsolete because it was intended to offer a longer transition period in the deprecation process.\r\n\r\nIf you enable this policy, sites can send WebAssembly modules cross-origin\r\nwithout restrictions.\r\n\r\nIf you disable or don't configure this policy, sites can only send\r\nWebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev95~policy~microsoft_edge_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fc9d8504be12a2f4":{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled","displayName":"Show links shared from Microsoft 365 apps in History","description":"Allows Microsoft Edge to display links recently shared by or shared with the user from Microsoft 365 apps in History.\r\n\r\nIf you enable or don't configure this policy, Microsoft Edge displays links recently shared by or shared with the user from Microsoft 365 apps in History.\r\n\r\nIf you disable this policy, Microsoft Edge does not display links recently shared by or shared with the user from Microsoft 365 apps in History. The control in Microsoft Edge settings is disabled and set to off.\r\n\r\nThis policy only applies for Microsoft Edge local user profiles and profiles signed in using Azure Active Directory.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev96~policy~microsoft_edge_sharedlinksenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fca21feac5f012c9":{"id":"device_vendor_msft_policy_config_office16v5~policy~l_microsoftofficemachine~l_updates_l_preventbinginstall","displayName":"Don’t install extension for Microsoft Search in Bing that makes Bing the default search engine","description":"This policy setting allows you to control whether an extension for Microsoft Search in Bing is installed that makes Bing the default search engine for Google Chrome and Firefox web browsers. This extension is installed with a new installation of Office or when an existing installation of Office is updated.\r\n\r\nIf you enable this policy setting, the extension won’t be installed and Bing won’t be made the default search engine.\r\n\r\nIf you disable or don’t configure this policy setting, the extension will be installed and Bing will be made the default search engine, unless you have used some other method, such as the Office Deployment Tool, to exclude the extension from being installed.\r\n\r\nNote: Even if Bing is made the default search engine, users can still change the default search engine in Google Chrome or Firefox.\r\n\r\nFor more information, see https://go.microsoft.com/fwlink/p/?linkid=2109345.\r\n ","helpText":"","infoUrls":[],"categoryId":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","categoryName":"Updates","options":[{"id":"device_vendor_msft_policy_config_office16v5~policy~l_microsoftofficemachine~l_updates_l_preventbinginstall_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v5~policy~l_microsoftofficemachine~l_updates_l_preventbinginstall_1","displayName":"Enabled","description":null,"helpText":null}]},"fcddc7d139655e88":{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_proxyserver_pol_proxymode","displayName":"Choose how to specify proxy server settings","description":"Allows you to specify the proxy server settings that are used by Microsoft Edge Update.\r\n\r\n If you enable this policy, you can choose between the following proxy server options:\r\n - If you choose to never use a proxy server and always connect directly, all other options are ignored.\r\n - If you choose to use system proxy settings or auto-detect the proxy server, all other options are ignored.\r\n - If you choose fixed server proxy mode, you can specify further options in 'Address or URL of proxy server'.\r\n - If you choose to use a .pac proxy script, you must specify the URL for the script in 'URL to a proxy .pac file'.\r\n\r\n If you enable this policy, users in your organization can't change the proxy settings in Microsoft Edge Update.\r\n\r\n If you disable or don't configure this policy, no proxy server settings are configured, but users in your organization can choose their own proxy settings for Microsoft Edge Update.","helpText":"","infoUrls":[],"categoryId":"ff543267-540e-4e37-a1e9-daf6a5e16ba7","categoryName":"Proxy Server","options":[{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_proxyserver_pol_proxymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_update~policy~cat_google~cat_googleupdate~cat_proxyserver_pol_proxymode_1","displayName":"Enabled","description":null,"helpText":null}]},"fc8a0b2f67444125":{"id":"device_vendor_msft_policy_config_visualstudiov1~policy~visualstudio~installandupdatesettings_cachepath_cachepath_textbox","displayName":"Package Manifest and Payload Cache Path (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","categoryName":"Install and Update Settings","options":null},"fcacb5892e21664e":{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autocreatedesktopshortcuts","displayName":"Automatically creates Windows App shortcuts to desktop","description":"Automatically creates Windows App shortcuts to the desktop to launch resources specified by the IT administrator.\n\nIf you enable this policy, Windows App will automatically create desktop shortcuts for resources configured by the IT admin in the Azure Virtual Desktop portal. After the user signs in, these shortcuts will be created on the desktop. When the user signs out, the shortcuts will be automatically cleaned up.\n\nIf you disable or do not configure this policy, desktop shortcuts will not be automatically created.\n ","helpText":"","infoUrls":[],"categoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","categoryName":"Windows App","options":[{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autocreatedesktopshortcuts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_windowsapp~policy~winapp_node_winapp_autocreatedesktopshortcuts_1","displayName":"Enabled","description":null,"helpText":null}]},"fcb1198452b010e1":{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablecleartpmbutton","displayName":"Disable Clear Tpm Button","description":"Disable the Clear TPM button in Windows Security. Enabled:The Clear TPM button will be unavailable for use. Disabled:The Clear TPM button will be available for use on supported systems. Not configured:Same as Disabled. Supported values:0 - Disabled (default)1 - Enabled","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-WindowsDefenderSecurityCenter#disablecleartpmbutton"],"categoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","categoryName":"Windows Defender Security Center","options":[{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablecleartpmbutton_0","displayName":"(Disabled or not configured) The security processor troubleshooting page shows a button that initiates the process to clear the security processor (TPM).","description":"(Disabled or not configured) The security processor troubleshooting page shows a button that initiates the process to clear the security processor (TPM).","helpText":null},{"id":"device_vendor_msft_policy_config_windowsdefendersecuritycenter_disablecleartpmbutton_1","displayName":"(Enabled) The security processor troubleshooting page will not show a button to initiate the process to clear the security processor (TPM)","description":"(Enabled) The security processor troubleshooting page will not show a button to initiate the process to clear the security processor (TPM)","helpText":null}]},"fc32a155744d0d04":{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_clipboardfiletype","displayName":"Clipboard content options","description":"If you choose to enable copying, this policy determines the type of content that can be copied.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/WindowsDefenderApplicationGuard-csp/"],"categoryId":"cd55f347-a417-4fe9-83ee-8f1f40ac5eb0","categoryName":null,"options":[{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_clipboardfiletype_1","displayName":"Allow text copying","description":"Allow text copying.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_clipboardfiletype_2","displayName":"Allow image copying","description":"Allow image copying.","helpText":null},{"id":"device_vendor_msft_windowsdefenderapplicationguard_settings_clipboardfiletype_3","displayName":"Allow both text and image copying","description":"Allow text and image copying.","helpText":null}]},"fc7d857348e0d78d":{"id":"plugin_filter_sockets_providercomposedidentifier","displayName":"Provider Composed Identifier","description":"The data provider identifier. This string identifies the filter data provider when the filter starts running. Required when Enabled is true.\n\nIn iOS and visionOS, the identifier is a bundle ID, for example, \"com.example.app\".\n\nIn macOS, the identifier is a composed identifier. The format of the composed identifier is \"Bundle-ID {Designated-Requirement}\". \"Bundle-ID\" is the bundle identifier string of the provider. \"Designated-Requirement\" is the designated requirement string from the code signature of the provider. For example, \"com.example.app {anchor apple generic}\".","helpText":null,"infoUrls":[],"categoryId":"27f47083-6e1b-4fc7-938b-ecd846b79d78","categoryName":"Web Content Filter","options":null},"fc9b21bc1191d828":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath","displayName":"Set the default source path for Update-Help (User)","description":"This policy setting allows you to set the default value of the SourcePath parameter on the Update-Help cmdlet.\r\n\r\nIf you enable this policy setting, the Update-Help cmdlet will use the specified value as the default value for the SourcePath parameter. This default value can be overridden by specifying a different value with the SourcePath parameter on the Update-Help cmdlet.\r\n\r\nIf this policy setting is disabled or not configured, this policy setting does not set a default value for the SourcePath parameter of the Update-Help cmdlet.\r\n\r\nNote: This policy setting exists under both Computer Configuration and User Configuration in the Group Policy Editor. The Computer Configuration policy setting takes precedence over the User Configuration policy setting.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enableupdatehelpdefaultsourcepath"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enableupdatehelpdefaultsourcepath_1","displayName":"Enabled","description":null,"helpText":null}]},"fc3660eb4fff2df8":{"id":"user_vendor_msft_policy_config_admx_programs_noinstalledupdates","displayName":"Hide \"Installed Updates\" page (User)","description":"This setting prevents users from accessing \"Installed Updates\" page from the \"View installed updates\" task.\r\n\r\n\"Installed Updates\" allows users to view and uninstall updates currently installed on the computer. The updates are often downloaded directly from Windows Update or from various program publishers.\r\n\r\nIf this setting is disabled or not configured, the \"View installed updates\" task and the \"Installed Updates\" page will be available to all users.\r\n\r\nThis setting does not prevent users from using other tools and methods to install or uninstall programs.\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-programs#admx-programs-noinstalledupdates"],"categoryId":"dc16dbf0-aac8-4ff3-a546-1ddb55650f47","categoryName":"Programs","options":[{"id":"user_vendor_msft_policy_config_admx_programs_noinstalledupdates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_programs_noinstalledupdates_1","displayName":"Enabled","description":null,"helpText":null}]},"fc54986f6b179d08":{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_1","displayName":"Custom Classes: Deny write access (User)","description":"This policy setting denies write access to custom removable storage classes.\r\n\r\nIf you enable this policy setting, write access is denied to these removable storage classes.\r\n\r\nIf you disable or do not configure this policy setting, write access is allowed to these removable storage classes.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-removablestorage#admx-removablestorage-customclasses-denywrite-access-1"],"categoryId":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","categoryName":"Removable Storage Access","options":[{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_removablestorage_customclasses_denywrite_access_1_1","displayName":"Enabled","description":null,"helpText":null}]},"fceb157bf22904bb":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013","displayName":"Microsoft Office 365 PowerPoint 2013 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 PowerPoint 2013.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 PowerPoint 2013 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 PowerPoint 2013 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 PowerPoint 2013 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365powerpoint2013"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365powerpoint2013_1","displayName":"Enabled","description":null,"helpText":null}]},"fc11d595883c2c05":{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailyendminute","displayName":"Set the time Quiet Hours ends each day (User)","description":"\r\n This policy setting specifies the number of minutes after midnight (local time) that Quiet Hours is to end each day.\r\n\r\n If you enable this policy setting, the specified time will be used, and users will not be able to customize any Quiet Hours settings.\r\n\r\n If you disable this policy setting, a default value will be used, and users will not be able to change it or any other Quiet Hours setting.\r\n\r\n If you do not configure this policy setting, a default value will be used, which administrators and users will be able to modify.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-wpn#admx-wpn-quiethoursdailyendminute"],"categoryId":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","categoryName":"Notifications","options":[{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailyendminute_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_wpn_quiethoursdailyendminute_1","displayName":"Enabled","description":null,"helpText":null}]},"fcac313fed993b36":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_windowmanagementallowedforurls_windowmanagementallowedforurlsdesc","displayName":"Allow Window Management permission on these sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"fc34e40664e561fb":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins","displayName":"List of origins allowing all HTTP authentication (User)","description":"Setting the policy specifies for which origins to allow all the HTTP authentication schemes Google Chrome supports regardless of the AuthSchemes policy.\r\n\r\nFormat the origin pattern according to this format (https://support.google.com/chrome/a?p=url_blocklist_filter_format). Up to 1,000 exceptions can be defined in AllHttpAuthSchemesAllowedForOrigins.\r\nWildcards are allowed for the whole origin or parts of the origin, either the scheme, host, port.\r\n\r\nExample value:\r\n\r\n*.example.com","helpText":"","infoUrls":[],"categoryId":"93ed2300-658d-40f3-8211-9295a240579c","categoryName":"HTTP authentication","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~httpauthentication_allhttpauthschemesallowedfororigins_1","displayName":"Enabled","description":null,"helpText":null}]},"fc53c8c2022bb242":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled","displayName":"Extend support for Chrome Apps on Microsoft® Windows®, macOS, and Linux. (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_chromeappsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fc672c7ec22ce274":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_optionsgeneral_l_font_l_namesize","displayName":"Name, Size (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","categoryName":"General","options":null},"fc1e6b9b2f42c5c0":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails","displayName":"Set document behavior if file validation fails (User)","description":"This policy setting controls how Office handles documents when they fail file validation. \r\n\r\nIf you enable this policy setting, you can configure the following options for files that fail file validation:\r\n\r\n- Block files completely. Users cannot open the files.\r\n- Open files in Protected View and disallow edit. Users cannot edit the files. This is also how Office handles the files if you disable this policy setting.\r\n- Open files in Protected View and allow edit. Users can edit the files. This is also how Office handles the files if you do not configure this policy setting.\r\n\r\nIf you disable this policy setting, Office follows the \"Open files in Protected View and disallow edit\" behavior.\r\n\r\nIf you do not configure this policy setting, Office follows the \"Open files in Protected View and allow edit\" behavior.","helpText":"","infoUrls":[],"categoryId":"fe54701d-42bd-47f0-9c49-26ff6a928b32","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_protectedview_l_setdocumentbehavioriffilevalidationfails_1","displayName":"Enabled","description":null,"helpText":null}]},"fc1d21a780ced2a7":{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc","displayName":"Allow Option To Show This PC (User)","description":"When This PC location is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshowthispc"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshowthispc_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"fc878c6aa5ef39b3":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101","displayName":"Web sites in less privileged Web content zones can navigate into this zone (User)","description":"","helpText":"","infoUrls":[],"categoryId":"99dfe848-181d-480a-bd20-3f93f04b6f5c","categoryName":"Locked- Down Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownintranetzoneallowlessprivilegedsites_iz_partname2101_1","displayName":"Prompt","description":null,"helpText":null}]},"fc59e4d47455d620":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201","displayName":"Automatic prompting for ActiveX controls (User)","description":"","helpText":"","infoUrls":[],"categoryId":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","categoryName":"Locked- Down Local Machine Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddownlocalmachinezoneallowautomaticpromptingforactivexcontrols_iz_partname2201_3","displayName":"Disable","description":null,"helpText":null}]},"fc6a6e6c9213c81d":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles","displayName":"Allow drag and drop or copy and paste files (User)","description":"This policy setting allows you to manage whether users can drag files or copy and paste files from a source within the zone.\n\nIf you enable this policy setting, users can drag files or copy and paste files from this zone automatically. If you select Prompt in the drop-down box, users are queried to choose whether to drag or copy files from this zone.\n\nIf you disable this policy setting, users are prevented from dragging files or copying and pasting files from this zone.\n\nIf you do not configure this policy setting, users are queried to choose whether to drag or copy files from this zone.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszoneallowdraganddropcopyandpastefiles"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszoneallowdraganddropcopyandpastefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"fc17e90fb423bd6b":{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402","displayName":"Scripting of Java applets (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptingofjavaapplets_iz_partname1402_1","displayName":"Prompt","description":null,"helpText":null}]},"fce4ae26045915fc":{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1","displayName":"Disable automatic upload of sign-in failure logs (User)","description":"\r\nUploads the sign-in failure logs to the Microsoft Lync Server automatically for analysis. No logs will be automatically uploaded if sign-in is successful.\r\n\r\nIf this policy is not configured, then the following happens: \r\nFor Lync Online Users: Sign-in failure logs are automatically uploaded.\r\nFor Lync On-Premise Users: A confirmation seeking consent from the user is shown before upload.\r\n\r\nWhen this is disabled, sign-in logs would be uploaded to the Microsoft Lync Server for both Lync On-Premise and Online users automatically.\r\n\r\nWhen this is enabled, sign-in logs will never be uploaded automatically.\r\n ","helpText":"","infoUrls":[],"categoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","categoryName":"Microsoft Lync Feature Policies","options":[{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_lync16v2~policy~l_lync~l_lyncconfiguration_l_policydisableautomaticsendtracing_1_1","displayName":"Enabled","description":null,"helpText":null}]},"fc2629516190626e":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting","displayName":"Default JavaScript setting (User)","description":"Set whether websites can run JavaScript. You can allow it for all sites (1) or block it for all sites (2).\r\n\r\nIf you don't configure this policy, all sites can run JavaScript by default, and the user can change this setting.\r\n\r\n* 1 = Allow all sites to run JavaScript\r\n\r\n* 2 = Don't allow any site to run JavaScript","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~contentsettings_defaultjavascriptsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"fc05c86a72ca1d75":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\r\n\r\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\n* 1 = Restore the last session\r\n\r\n* 4 = Open a list of URLs\r\n\r\n* 5 = Open a new tab","helpText":"","infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~startup_restoreonstartup_1","displayName":"Enabled","description":null,"helpText":null}]},"fc059e60faba6fda":{"id":"user_vendor_msft_policy_config_microsoft_edgev120~policy~microsoft_edge~identity_automaticprofileswitchingsitelist_automaticprofileswitchingsitelist","displayName":"Configure the automatic profile switching site list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":null},"fc60b4d713e53ad2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics","displayName":"Inuktitut (Syllabics) (User)","description":"Enables the editing language Inuktitut (Syllabics)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_inuktitutsyllabics_1","displayName":"Enabled","description":null,"helpText":null}]},"fc7f79ed97b41258":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian","displayName":"Lower Sorbian (User)","description":"Enables the editing language Lower Sorbian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_lowersorbian_1","displayName":"Enabled","description":null,"helpText":null}]},"fcb468e3796eaeb2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari","displayName":"Sindhi (Devanagari) (User)","description":"Enables the editing language Sindhi (Devanagari)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_sindhidevanagari_1","displayName":"Enabled","description":null,"helpText":null}]},"fcd99fd07edbba4a":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache3_l_workflowpath439","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"fc0a5a0a9b77b014":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings_l_allowedextensions_l_allowedextensionsole","displayName":"File extensions: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"50b4bc60-802c-477a-9366-80e09154595f","categoryName":"Security Settings","options":null},"fc45b7e12bb17bf2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc15_l_pathcolon15","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":null},"fc9b74bfb0ff07e4":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders","displayName":"Reminders (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"13eb248a-4549-4d23-9ada-23b40edf36bf","categoryName":"Reminder Options","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_other~l_advanced~l_reminderoptions_l_reminders_1","displayName":"Enabled","description":null,"helpText":null}]},"fc3bb8b0dfe5d596":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook","displayName":"Turn off Hierarchical Address Book (User)","description":"This policy setting turns off the Hierarchical Address Book (HAB).\r\n\r\nIf you enable this policy setting, the HAB will be turned off. \r\n\r\nIf you disable or do not configure this policy setting, the HAB will be displayed.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_turnoffhierarchicaladdressbook_1","displayName":"Enabled","description":null,"helpText":null}]},"fc064a4a6e0d009d":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc04_l_descriptioncolon22","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"fc95a786bc8a79f1":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc20_l_pathcolon84","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":null},"fcdd8ec4c25e8202":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient","displayName":"File Tab | Share | Email (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_filesendtomailrecipient_1","displayName":"True","description":null,"helpText":null}]},"fc0724cd4b95b9ab":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_1","displayName":"Save blocked","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_rtffiles_l_rtffilesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"fcfd84b336484464":{"id":"vendor_msft_firewall_mdmstore_firewallrules_{firewallrulename}_remoteaddressdynamickeywords","displayName":"Reusable groups","description":"Comma separated list of Dynamic Keyword Address Ids (GUID strings) specifying the remote addresses covered by the rule.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Firewall-csp/"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":null}} \ No newline at end of file diff --git a/public/intune-definitions/fd.json b/public/intune-definitions/fd.json index f54a4259736a..4a5415850775 100644 --- a/public/intune-definitions/fd.json +++ b/public/intune-definitions/fd.json @@ -1 +1 @@ -{"fdde04c7e4dfa0b7":{"id":"com.apple.applicationaccess_allowappstobehidden","displayName":"Allow Apps To Be Hidden","description":"If false, disables the ability for the user to hide apps. It does not affect the user's ability to leave it in the App Library, while removing it from the home screen.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappstobehidden_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappstobehidden_true","displayName":"True","description":null,"helpText":null}]},"fd2d49b6a0658526":{"id":"com.apple.applicationaccess_allowcloudreminders","displayName":"Allow Cloud Reminders","description":"If false, disables iCloud Reminder services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudreminders_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudreminders_true","displayName":"True","description":null,"helpText":null}]},"fd898ce00494957b":{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation","displayName":"Allow Web Distribution App Installation","description":"When 'false', the device prevents installation of apps directly from the web.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation_true","displayName":"True","description":null,"helpText":null}]},"fd4b802f418d05b3":{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred","displayName":"Cellular Data Preferred","description":"Set to `true` to prefer this private network over Wi-Fi.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":[{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred_true","displayName":"True","description":null,"helpText":null}]},"fd49908c2bdc3f38":{"id":"com.apple.directoryservice.managed_adpreferreddcserver","displayName":"AD Preferred DC Server","description":"The preferred domain server.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},"fd4243564c7566ac":{"id":"com.apple.managedclient.preferences_audiosandboxenabled","displayName":"Allow the audio sandbox to run","description":"This policy controls the audio process sandbox.\n\nIf you enable this policy, the audio process will run sandboxed.\n\nIf you disable this policy, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\n\nIf you don't configure this policy, the default configuration for the audio sandbox will be used, which might differ based on the platform.\n\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiosandboxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_audiosandboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_audiosandboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fd463c979b79b5b8":{"id":"com.apple.managedclient.preferences_composeinlineenabled","displayName":"Control access to Microsoft 365 Copilot writing assistance in Microsoft Edge for Business","description":"This policy controls whether users can use writing support features in Microsoft Edge for Business, such as Rewrite, which utilizes Microsoft 365 Copilot Chat. With Rewrite, users can receive help with drafting content, rewriting text, and adjusting style directly in their browser tab. In Edge, users can trigger it when highlighting editable content in their main browser through the right-click context menu.\n\nThis policy applies only to Microsoft Entra accounts and does not apply to Microsoft accounts.\n\nIf you enable this policy, users can use Rewrite in Microsoft Edge when logged in with an Entra account.\n\nIf you disable this policy, users within your tenant will not be able to use Rewrite.\n\nIf you don't configure this policy, the default behavior is as follows:\n\n- Rewrite is available to users\n\n- Users can enable or disable Microsoft 365 Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\n\nNote: Rewrite is not available on pages protected by data loss prevention (DLP) policies to help maintain compliance.\n\nLearn more about Microsoft 365 Copilot Chat data, privacy, and security here: https://go.microsoft.com/fwlink/?linkid=2321816","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#composeinlineenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_composeinlineenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_composeinlineenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fd85a593f311c347":{"id":"com.apple.managedclient.preferences_defaultweatherlocation","displayName":"Default weather location","description":"Sets the default weather location in the Calendar view. Enter the city and state or country (e.g. Redmond, WA or Paris, France)","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-default-weather-location"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":null},"fd49bcfd38b199a4":{"id":"com.apple.managedclient.preferences_intranetredirectbehavior","displayName":"Intranet Redirection Behavior","description":"This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\n\nIf this policy isn't configured, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release.\n\n\"DNSInterceptionChecksEnabled\" is a related policy that might also disable DNS interception checks. However, this policy is a more flexible version which might separately control intranet redirection infobars and might be expanded in the future.\nIf either \"DNSInterceptionChecksEnabled\" or this policy make a request to disable interception checks, the checks will be disabled.\nIf DNS interception checks are disabled by this policy but \"GoToIntranetSiteForSingleWordEntryInAddressBar\" is enabled, single word queries will still result in intranet navigations.\n\nPolicy options mapping:\n\n* Default (0) = Use default browser behavior.\n\n* DisableInterceptionChecksDisableInfobar (1) = Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\n\n* DisableInterceptionChecksEnableInfobar (2) = Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.\n\n* EnableInterceptionChecksEnableInfobar (3) = Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#intranetredirectbehavior"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_0","displayName":"Use default browser behavior.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_1","displayName":"Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_2","displayName":"Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_3","displayName":"Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null}]},"fdc77e95fa31202f":{"id":"com.apple.managedclient.preferences_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\n\nThis policy is not considered if a site matches a URL pattern in the \"SameOriginTabCaptureAllowedByOrigins\" policy.\n\nIf a site matches a URL pattern in this policy, the following policies will not be considered: \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tabcaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"fdda1e75c31728fd":{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled","displayName":"Enable zstd content encoding support (Deprecated)","description":"This feature enables advertising \"zstd\" support in the Accept-Encoding request header and support for decompressing zstd web content.\n\nIf you enable or don't configure this policy, Microsoft Edge will accept server responses compressed with zstd.\n\nIf you disable this policy, the zstd content encoding feature will not be advertised or supported when processing server responses.\n\nThis policy is temporary and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#zstdcontentencodingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fdc416f5f44a386d":{"id":"com.apple.preference.security_dontallowfirewallui","displayName":"Do Not Allow Firewall UI","description":"If true, disables user changes to the firewall settings.","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":[{"id":"com.apple.preference.security_dontallowfirewallui_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.security_dontallowfirewallui_true","displayName":"True","description":null,"helpText":null}]},"fdc177d176e60559":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"fd56c5b8958e1c7d":{"id":"com.apple.webcontent-filter_organization","displayName":"Organization","description":"The organization string that passes to the third-party plug-in.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},"fd664c56d1a21215":{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled","displayName":"Enable opaque origins for data URLs in Web Workers","description":"This policy controls whether Web Workers created from data URLs are assigned\na unique opaque origin.\n\nWeb Workers can be created using a data URL that contains the worker script.\nPreviously, these workers inherited the origin of the page that created them,\nwhich allowed them to access the same origin-bound data, such as local\nstorage and cookies.\n\nStarting in Microsoft Edge version\n149, Web Workers created from data URLs are assigned a unique opaque origin\nby default. This behavior improves security and aligns with the HTML\nspecification by isolating these workers from the page that created them.\n\nIf you enable this policy or don't configure it, Web Workers created from\ndata URLs are assigned a unique opaque origin.\n\nIf you disable this policy, Web Workers created from data URLs inherit the\norigin of the page that created them. Use this setting only as a temporary\nmitigation for compatibility issues with internal applications that depend\non the legacy behavior.\n\nThis policy is temporary and will be removed in Microsoft Edge\nversion 157.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fda4d8706e0c9671":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersearchurl_recommended","displayName":"Default search provider search URL (users can override)","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"fdb01edd171e3f56":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended","displayName":"Sets layout for printing (users can override)","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended_portrait","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended_landscape","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},"fd105d4e01992e9e":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize","displayName":"Define the maximum size of downloaded files and attachments to be scanned","description":"This policy setting defines the maximum size (in kilobytes) of downloaded files and attachments that will be scanned.\r\n\r\n If you enable this setting, downloaded files and attachments smaller than the size specified will be scanned.\r\n\r\n If you disable or do not configure this setting, a default size will be applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-ioavmaxsize"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_1","displayName":"Enabled","description":null,"helpText":null}]},"fd3d4a2a3efcf74a":{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization","displayName":"Always rasterize content to be printed using a software rasterizer","description":"Determines whether the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) is forced to use a software rasterizer instead of a Graphics Processing Unit (GPU) to rasterize pages.\r\n\r\nThis setting may improve the performance of the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) on machines that have a relatively powerful CPU as compared to the machine’s GPU.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-forcesoftwarerasterization"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization_1","displayName":"Enabled","description":null,"helpText":null}]},"fda69e08354157bc":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c","displayName":"Best effort service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_1","displayName":"Enabled","description":null,"helpText":null}]},"fd163b019f924c80":{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync","displayName":"Do not sync desktop personalization","description":"Prevent the \"desktop personalization\" group from syncing to and from this PC. This turns off and disables the \"desktop personalization\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"desktop personalization\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn desktop personalization syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"desktop personalization\" group is on by default and configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disabledesktopthemesettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},"fd492ead726cbabb":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath","displayName":"Allow the use of remote paths in file shortcut icons","description":"This policy setting determines whether remote paths can be used for file shortcut (.lnk file) icons.\r\n\r\nIf you enable this policy setting, file shortcut icons are allowed to be obtained from remote paths.\r\n\r\nIf you disable or do not configure this policy setting, file shortcut icons that use remote paths are prevented from being displayed.\r\n\r\nNote: Allowing the use of remote paths in file shortcut icons can expose users’ computers to security risks.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enableshellshortcuticonremotepath"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath_1","displayName":"Enabled","description":null,"helpText":null}]},"fdaca30f3454611b":{"id":"device_vendor_msft_policy_config_browser_allowinprivate","displayName":"Allow InPrivate","description":"This setting lets you decide whether employees can browse using InPrivate website browsing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowinprivate"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowinprivate_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowinprivate_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"fdf533c0b7204ee0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_roamingprofilelocation","displayName":"Set the roaming profile directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"fdce1ab41d70b455":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled","displayName":"Enable HTTP/0.9 support on non-default ports","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd336a0eeb79a2e5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation","displayName":"Configure the home page URL","description":"Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup.\r\n\r\nIf the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect.\r\n\r\n The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome.\r\n\r\nLeaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"fd9c942c95c2a370":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.\r\n\r\nThis policy can be overridden for specific url patterns using the WebHidAskForUrls and WebHidBlockedForUrls policies.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"fd66eb9874823d2b":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled","displayName":"Re-enable the Event.path API until M115.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd7ccc3e4a25c43f":{"id":"device_vendor_msft_policy_config_experience_allowclipboardhistory","displayName":"Allow Clipboard History","description":"Allows history of clipboard items to be stored in memory.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowclipboardhistory"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowclipboardhistory_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowclipboardhistory_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"fdfb9854d77a70e6":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"fddb17119c8810e7":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"fde9c87551ee5335":{"id":"device_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_edgedefaultprofileenabled","displayName":"Default Profile Setting Enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":null},"fd898d285ccbab79":{"id":"device_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_loopbacknetworkblockedforurlsdesc","displayName":"Block sites from making network requests to the local device. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"fd67b1f9d3808c18":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled","displayName":"Configure whether a user always has a default profile automatically signed in with their work or school account","description":"This policy determines if a user can remove the Microsoft Edge profile automatically signed in with a user's work or school account.\r\n\r\nIf you enable this policy, a non-removable profile will be created with the user's work or school account on Windows. This profile can't be signed out or removed.\r\n\r\nIf you disable or don't configure this policy, the profile automatically signed in with a user's work or school account on Windows can be signed out or removed by the user.\r\n\r\nIf you want to configure browser sign in, use the 'BrowserSignin' (Browser sign-in settings) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd5f6d87f9d05785":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended","displayName":"Suggest similar pages when a webpage can’t be found","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fd378c310c267cfc":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled, even if it's turned off by default (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96.\r\n\r\nSupport for AppCache and this policy was removed from Microsoft Edge starting in version 97.\r\n\r\nIf you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge is not available by default.\r\n\r\nIf you set this policy to false, or don't set it, AppCache will follow Microsoft Edge's defaults.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd6c4309dd72af58":{"id":"device_vendor_msft_policy_config_privacy_letappssyncwithdevices_userincontroloftheseapps","displayName":"Let Apps Sync With Devices User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the 'Communicate with unpaired wireless devices' privacy setting for the listed apps. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappssyncwithdevices_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"fd26a69ed5bef21a":{"id":"device_vendor_msft_policy_config_settings_allowvpn","displayName":"Allow VPN","description":"Allows the user to change VPN settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#allowvpn"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":[{"id":"device_vendor_msft_policy_config_settings_allowvpn_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_settings_allowvpn_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"fd7c52fd43d863ec":{"id":"device_vendor_msft_policy_config_wslv3~policy~wsl_defaultnetworkingmode","displayName":"Configure default networking mode","description":"This policy specifies the default networking mode to be used for WSL2.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv3~policy~wsl_defaultnetworkingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv3~policy~wsl_defaultnetworkingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"fdcf4103fa7a57f9":{"id":"intelligencesettings_apps_safari_allowsummary","displayName":"Allow Summary","description":"If `false`, disables Safari Summary.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_apps_safari_allowsummary_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_apps_safari_allowsummary_true","displayName":"True","description":null,"helpText":null}]},"fda799b90a516ab6":{"id":"osrecoverysettings_keyboardsettings","displayName":"Keyboard settings","description":"","helpText":"","infoUrls":[],"categoryId":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","categoryName":"Operating system settings","options":[{"id":"osrecoverysettings_keyboardsettings_afrikaans","displayName":"Afrikaans","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_afrikaansn","displayName":"Afrikaans (Namibia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_albanian","displayName":"Albanian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_albaniank","displayName":"Albanian (Kosovo)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_alsatianf","displayName":"Alsatian (France)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_amharic","displayName":"Amharic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabic","displayName":"Arabic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabica","displayName":"Arabic (Algeria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicb","displayName":"Arabic (Bahrain)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabice","displayName":"Arabic (Egypt)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabici","displayName":"Arabic (Iraq)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicj)","displayName":"Arabic (Jordan)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabick","displayName":"Arabic (Kuwait)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicl","displayName":"Arabic (Lebanon)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicli","displayName":"Arabic (Libya)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicm","displayName":"Arabic (Morocco)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaico","displayName":"Arabic (Oman)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaicq","displayName":"Arabic (Qatar)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaics","displayName":"Arabic (Syria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaict","displayName":"Arabic (Tunisia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaicu","displayName":"Arabic (United Arab Emirates)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicw","displayName":"Arabic (World)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicy","displayName":"Arabic (Yemen)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_armenian","displayName":"Armenian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_assamese","displayName":"Assamese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_azerbaijani","displayName":"Azerbaijani","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_azerbaijanic","displayName":"Azerbaijani (Cyrillic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bangla","displayName":"Bangla","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bashkir","displayName":"Bashkir","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_basque","displayName":"Basque","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_belarusian","displayName":"Belarusian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bengali","displayName":"Bengali (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bosnian","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_breton","displayName":"Breton","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bulgarian","displayName":"Bulgarian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_burmese","displayName":"Burmese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_catalan","displayName":"Catalan","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_catalana","displayName":"Catalan (Andorra)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_catalanfrance","displayName":"Catalan (France)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_catalanitaly","displayName":"Catalan (Italy)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_centralatlastamazight","displayName":"Central Atlas Tamazight","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_centralatlastamazightarabic","displayName":"Central Atlas Tamazight (Arabic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_centralatlastamazighttifinagh","displayName":"Central Atlas Tamazight (Tifinagh)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_centralkurdish","displayName":"Central Kurdish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chechen","displayName":"Chechen","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_cherokee","displayName":"Cherokee","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinese","displayName":"Chinese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinesesimplifiedhongkongsar","displayName":"Chinese (Simplified, Hong Kong SAR)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinesesimplifiedmacaosar","displayName":"Chinese (Simplified, Macao SAR)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinesetraditional","displayName":"Chinese (Traditional)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinesetraditionaltaiwan","displayName":"Chinese (Traditional, Taiwan)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_churchslavic","displayName":"Church Slavic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_colognian","displayName":"Colognian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_cornish","displayName":"Cornish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_corsican","displayName":"Corsican","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_croatian","displayName":"Croatian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_croatianbosniaherzegovina","displayName":"Croatian (Bosnia & Herzegovina)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_czech","displayName":"Czech","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_danish","displayName":"Danish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_danishgreenland","displayName":"Danish (Greenland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_divehi","displayName":"Divehi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutch","displayName":"Dutch","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutcharuba","displayName":"Dutch (Aruba)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchbelgium","displayName":"Dutch (Belgium)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchbonaires","displayName":"Dutch (Bonaire, Sint Eustatius and Saba)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchcuracao","displayName":"Dutch (Curaçao)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchsintmaarten","displayName":"Dutch (Sint Maarten)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchsuriname","displayName":"Dutch (Suriname)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dzongkha","displayName":"Dzongkha","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_english","displayName":"English","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishaustralia","displayName":"English (Australia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishaustria","displayName":"English (Austria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishbelgium","displayName":"English (Belgium)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishbelize","displayName":"English (Belize)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishbritishvirginislands","displayName":"English (British Virgin Islands)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishburundi","displayName":"English (Burundi)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishcanada","displayName":"English (Canada)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishcaribbean","displayName":"English (Caribbean)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishdenmark","displayName":"English (Denmark)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishfalklandislands","displayName":"English (Falkland Islands)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishfinland","displayName":"English (Finland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishgermany","displayName":"English (Germany)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishgibraltar","displayName":"English (Gibraltar)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishguernsey","displayName":"English (Guernsey)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishhongkongsar","displayName":"English (Hong Kong SAR)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishindia","displayName":"English (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishireland","displayName":"English (Ireland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishisleofman","displayName":"English (Isle of Man)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishisrael","displayName":"English (Israel)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishjamaica","displayName":"English (Jamaica)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishjersey","displayName":"English (Jersey)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishmalaysia","displayName":"English (Malaysia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishmalta","displayName":"English (Malta)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishnetherlands","displayName":"English (Netherlands)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishnewzealand","displayName":"English (New Zealand)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishphilippines","displayName":"English (Philippines)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishsingapore","displayName":"English (Singapore)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishslovenia","displayName":"English (Slovenia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishsouthafrica","displayName":"English (South Africa)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishsweden","displayName":"English (Sweden)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishswitzerland","displayName":"English (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishtrinidadtobago","displayName":"English (Trinidad & Tobago)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishuk","displayName":"English (United Kingdom)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishzimbabwe","displayName":"English (Zimbabwe)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_estonian","displayName":"Estonian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_faroese","displayName":"Faroese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_filipino","displayName":"Filipino","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_finnish","displayName":"Finnish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_french","displayName":"French","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchbelgium","displayName":"French (Belgium)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchcameroon","displayName":"French (Cameroon)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchcanada","displayName":"French (Canada)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchcotedivoire","displayName":"French (Côte d’Ivoire)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchhaiti","displayName":"French (Haiti)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchluxembourg","displayName":"French (Luxembourg)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchmali","displayName":"French (Mali)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchmonaco","displayName":"French (Monaco)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchmorocco","displayName":"French (Morocco)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchreunion","displayName":"French (Réunion)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchsenegal","displayName":"French (Senegal)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchswitzerland","displayName":"French (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchcongodrc","displayName":"French Congo (DRC)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_friulian","displayName":"Friulian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulah","displayName":"Fulah","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahadlam","displayName":"Fulah (Adlam)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahburkinafaso","displayName":"Fulah (Latin, Burkina Faso)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahcameroon","displayName":"Fulah (Latin, Cameroon)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahgambia","displayName":"Fulah (Latin, Gambia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahghana","displayName":"Fulah (Latin, Ghana)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahguinea","displayName":"Fulah (Latin, Guinea)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahguineabissau","displayName":"Fulah (Latin, Guinea-Bissau)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahliberia","displayName":"Fulah (Latin, Liberia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahmauritania","displayName":"Fulah (Latin, Mauritania)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahniger","displayName":"Fulah (Latin, Niger)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahnigeria","displayName":"Fulah (Latin, Nigeria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahsierraleone","displayName":"Fulah (Latin, Sierra Leone)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_galician","displayName":"Galician","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_georgian","displayName":"Georgian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_german","displayName":"German","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanaustria","displayName":"German (Austria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanbelgium","displayName":"German (Belgium)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanitaly","displayName":"German (Italy)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanliechtenstein","displayName":"German (Liechtenstein)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanluxembourg","displayName":"German (Luxembourg)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanswitzerland","displayName":"German (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_greek","displayName":"Greek","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_guarani","displayName":"Guarani","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_gujarati","displayName":"Gujarati","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hausa","displayName":"Hausa","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hawaiian","displayName":"Hawaiian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hebrew","displayName":"Hebrew","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hindi","displayName":"Hindi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hungarian","displayName":"Hungarian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_icelandic","displayName":"Icelandic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_igbo","displayName":"Igbo","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_indonesian","displayName":"Indonesian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_interlingua","displayName":"Interlingua","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_inuktitut","displayName":"Inuktitut","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_inuktitutsyllabics","displayName":"Inuktitut (Syllabics)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_irish","displayName":"Irish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_irishunitedkingdom","displayName":"Irish (United Kingdom)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_italian","displayName":"Italian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_italianswitzerland","displayName":"Italian (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_italianvaticancity","displayName":"Italian (Vatican City)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_japanese","displayName":"Japanese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_javanese","displayName":"Javanese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_javanesejavanese","displayName":"Javanese (Javanese)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kalaallisut","displayName":"Kalaallisut","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kannada","displayName":"Kannada","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kashmiri","displayName":"Kashmiri","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kashmiridevanagari","displayName":"Kashmiri (Devanagari)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kazakh","displayName":"Kazakh","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_khmer","displayName":"Khmer","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kinyarwanda","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kiswahili","displayName":"Kiswahili","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kiswahilicongodrc","displayName":"Kiswahili (Congo DRC)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kiswahilitanzania","displayName":"Kiswahili (Tanzania)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kiswahiliuganda","displayName":"Kiswahili (Uganda)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_konkani","displayName":"Konkani","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_korean","displayName":"Korean","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_koreannorthkorea","displayName":"Korean (North Korea)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kyrgyz","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_lao","displayName":"Lao","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_latvian","displayName":"Latvian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_lithuanian","displayName":"Lithuanian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_lowersorbian","displayName":"Lower Sorbian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_luxembourgish","displayName":"Luxembourgish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_macedonian","displayName":"Macedonian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malagasy","displayName":"Malagasy","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malay","displayName":"Malay","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malaybrunei","displayName":"Malay (Brunei)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malayindonesia","displayName":"Malay (Indonesia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malaysingapore","displayName":"Malay (Singapore)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malayalam","displayName":"Malayalam","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_maltese","displayName":"Maltese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_manipuri","displayName":"Manipuri","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_manx","displayName":"Manx","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_maori","displayName":"Maori","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mapuche","displayName":"Mapuche","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_marathi","displayName":"Marathi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mazanderani","displayName":"Mazanderani","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mohawk","displayName":"Mohawk","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mongolian","displayName":"Mongolian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mongolian_traditional_mongolian","displayName":"Mongolian (Traditional Mongolian)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mongolian_traditional_mongolian_mongolia","displayName":"Mongolian (Traditional Mongolian, Mongolia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_nko","displayName":"N'ko","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_nepali","displayName":"Nepali","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_nepali_india","displayName":"Nepali (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_northern_luri","displayName":"Northern Luri","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_northern_sami","displayName":"Northern Sami","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_norwegian","displayName":"Norwegian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_norwegian_nynorsk","displayName":"Norwegian Nynorsk","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_occitan","displayName":"Occitan","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_odia","displayName":"Odia","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_oromo","displayName":"Oromo","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_oromo_kenya","displayName":"Oromo (Kenya)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_ossetic","displayName":"Ossetic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_papiamento","displayName":"Papiamento","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_pashto","displayName":"Pashto","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_pashto_pakistan","displayName":"Pashto (Pakistan)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_persian","displayName":"Persian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_persian_afghanistan","displayName":"Persian (Afghanistan)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_polish","displayName":"Polish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese","displayName":"Portuguese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_angola","displayName":"Portuguese (Angola)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_cabo_verde","displayName":"Portuguese (Cabo Verde)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_equatorial_guinea","displayName":"Portuguese (Equatorial Guinea)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_guinea_bissau","displayName":"Portuguese (Guinea-Bissau)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_luxembourg","displayName":"Portuguese (Luxembourg)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_macao_sar","displayName":"Portuguese (Macao SAR)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_mozambique","displayName":"Portuguese (Mozambique)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_portugal","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_switzerland","displayName":"Portuguese (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_sao_tome_principe","displayName":"Portuguese (São Tomé & Príncipe)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_timor_leste","displayName":"Portuguese (Timor-Leste)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_prussian","displayName":"Prussian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_punjabi","displayName":"Punjabi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_quechua","displayName":"Quechua","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_quechua_ecuador","displayName":"Quechua (Ecuador)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_quechua_peru","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_romanian","displayName":"Romanian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_romanian_moldova","displayName":"Romanian (Moldova)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_romansh","displayName":"Romansh","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_russian","displayName":"Russian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_russian_moldova","displayName":"Russian (Moldova)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sakha","displayName":"Sakha","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sami_lule_norway","displayName":"Sami, Lule (Norway)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sami_northern_finland","displayName":"Sami, Northern (Finland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sami_northern_sweden","displayName":"Sami, Northern (Sweden)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sami_southern_norway","displayName":"Sami, Southern (Norway)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sanskrit","displayName":"Sanskrit","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_scottish_gaelic","displayName":"Scottish Gaelic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian","displayName":"Serbian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_cyrillic","displayName":"Serbian (Cyrillic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_cyrillic_bosnia_herzegovina","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_cyrillic_kosovo","displayName":"Serbian (Cyrillic, Kosovo)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_cyrillic_montenegro","displayName":"Serbian (Cyrillic, Montenegro)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_latin_bosnia_herzegovina","displayName":"Serbian (Latin, Bosnia & Herzegovina)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_latin_kosovo","displayName":"Serbian (Latin, Kosovo)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_latin_montenegro","displayName":"Serbian (Latin, Montenegro)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sesotho","displayName":"Sesotho","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sesotho_lesotho","displayName":"Sesotho (Lesotho)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sesotho_sa_leboa","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_setswana","displayName":"Setswana","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_setswana_botswana","displayName":"Setswana (Botswana)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_shona","displayName":"Shona","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sinhala","displayName":"Sinhala","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_slovak","displayName":"Slovak","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_slovenian","displayName":"Slovenian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_somali","displayName":"Somali","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_somali_djibouti","displayName":"Somali (Djibouti)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_somali_ethiopia","displayName":"Somali (Ethiopia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_somali_kenya","displayName":"Somali (Kenya)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish","displayName":"Spanish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_argentina","displayName":"Spanish (Argentina)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_belize","displayName":"Spanish (Belize)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_bolivia","displayName":"Spanish (Bolivia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_brazil","displayName":"Spanish (Brazil)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_chile","displayName":"Spanish (Chile)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_colombia","displayName":"Spanish (Colombia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_costa_rica","displayName":"Spanish (Costa Rica)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_cuba","displayName":"Spanish (Cuba)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_dominican_republic","displayName":"Spanish (Dominican Republic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_ecuador","displayName":"Spanish (Ecuador)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_el_salvador","displayName":"Spanish (El Salvador)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_equatorial_guinea","displayName":"Spanish (Equatorial Guinea)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_guatemala","displayName":"Spanish (Guatemala)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_honduras","displayName":"Spanish (Honduras)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_latin_america","displayName":"Spanish (Latin America)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_mexico","displayName":"Spanish (Mexico)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_nicaragua","displayName":"Spanish (Nicaragua)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_panama","displayName":"Spanish (Panama)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_paraguay","displayName":"Spanish (Paraguay)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_peru","displayName":"Spanish (Peru)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_philippines","displayName":"Spanish (Philippines)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_puerto_rico","displayName":"Spanish (Puerto Rico)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_united_states","displayName":"Spanish (United States)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_uruguay","displayName":"Spanish (Uruguay)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_venezuela","displayName":"Spanish (Venezuela)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_standard_moroccan_tamazight","displayName":"Standard Moroccan Tamazight","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_swedish","displayName":"Swedish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_swedish_finland","displayName":"Swedish (Finland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_swiss_german","displayName":"Swiss German","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_syriac","displayName":"Syriac","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tachelhit","displayName":"Tachelhit","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tachelhit_latin","displayName":"Tachelhit (Latin)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tajik","displayName":"Tajik","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tamil","displayName":"Tamil","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tamil_malaysia","displayName":"Tamil (Malaysia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tamil_singapore","displayName":"Tamil (Singapore)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tamil_sri_lanka","displayName":"Tamil (Sri Lanka)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tatar","displayName":"Tatar","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_telugu","displayName":"Telugu","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_thai","displayName":"Thai","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tibetan","displayName":"Tibetan","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tibetan_india","displayName":"Tibetan (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tigrinya","displayName":"Tigrinya","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_turkish","displayName":"Turkish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_turkmen","displayName":"Turkmen","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_ukrainian","displayName":"Ukrainian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_upper_sorbian","displayName":"Upper Sorbian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_urdu","displayName":"Urdu","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_urdu_india","displayName":"Urdu (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_uyghur","displayName":"Uyghur","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_uzbek","displayName":"Uzbek","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_uzbek_arabic","displayName":"Uzbek (Arabic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_uzbek_cyrillic","displayName":"Uzbek (Cyrillic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_valencian_spain","displayName":"Valencian (Spain)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_vietnamese","displayName":"Vietnamese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_walser","displayName":"Walser","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_welsh","displayName":"Welsh","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_western_frisian","displayName":"Western Frisian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_wolof","displayName":"Wolof","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_xitsonga","displayName":"Xitsonga","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_yi","displayName":"Yi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_yoruba","displayName":"Yoruba","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_isixhosa","displayName":"IsiXhosa","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_isizulu","displayName":"IsiZulu","description":null,"helpText":null}]},"fd218256f48d5b43":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_maximumpinlength","displayName":"Maximum PIN Length (User)","description":"Maximum PIN length configures the maximum number of characters allowed for the PIN. The largest number you can configure for this policy setting is 127. The lowest number you can configure must be larger than the number configured in the Minimum PIN length policy setting or the number 4, whichever is greater.\n\nIf you configure this policy setting, the PIN length must be less than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be less than or equal to 127.\n\nNOTE: If the above specified conditions for the maximum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"fd6e0d53aed4f5eb":{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvetrack","displayName":"Do not use the tracking-based method when resolving shell shortcuts (User)","description":"This policy setting prevents the system from using NTFS tracking features to resolve a shortcut.\r\n\r\nIf you enable this policy setting, the system does not try to locate the file by using its file ID. It skips this step and begins a comprehensive search of the drive specified in the target path.\r\n\r\nIf you disable or do not configure this policy setting, by default, when the system cannot find the target file for a shortcut (.lnk), it searches all paths associated with the shortcut. If the target file is located on an NTFS partition, the system then uses the target's file ID to find a path. If the resulting path is not correct, it conducts a comprehensive search of the target drive in an attempt to find the file.\r\n\r\nNote: This policy setting only applies to target files on NTFS partitions. FAT partitions do not have this ID tracking and search capability.\r\n\r\nAlso, see the \"Do not track Shell shortcuts during roaming\" and the \"Do not use the search-based method when resolving shell shortcuts\" policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-noresolvetrack"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvetrack_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvetrack_1","displayName":"Enabled","description":null,"helpText":null}]},"fdc83990a4e1d642":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_start_program_1_ts_workdir","displayName":"Working Directory (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},"fd49dfc9580db7ef":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes_disabledschemesdesc","displayName":"List of disabled protocol schemes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"fd2bde73fe8892f3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_renderinhostlistdesc","displayName":"Always render the following URL patterns in the host browser (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"fd29a2e599889fa9":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings","displayName":"Settings for Tab Organizer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_0","displayName":"Allow Tab Organizer and improve AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_1","displayName":"Allow Tab Organizer without improving AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_2","displayName":"Do not allow Tab Organizer.","description":null,"helpText":null}]},"fd5f6c398174d3ce":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"fdbd2443009b2e44":{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork","displayName":"Allow Option To Show Network (User)","description":"When the Network folder is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshownetwork"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"fd9b38e97b86a72a":{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server.\n\nThis policy setting determines whether Internet Explorer requires that all file-type information provided by Web servers be consistent. For example, if the MIME type of a file is text/plain but the MIME sniff indicates that the file is really an executable file, Internet Explorer renames the file by saving it in the Internet Explorer cache and changing its extension.\n\nIf you enable this policy setting, Internet Explorer requires consistent MIME data for all received files.\n\nIf you disable this policy setting, Internet Explorer will not require consistent MIME data for all received files.\n\nIf you do not configure this policy setting, Internet Explorer requires consistent MIME data for all received files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-consistentmimehandlinginternetexplorerprocesses"],"categoryId":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","categoryName":"Consistent Mime Handling","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},"fd7312a8d2006176":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"fd32e855d1bc3068":{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu","displayName":"Enables Microsoft Edge mini menu (User)","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\r\n\r\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\r\n\r\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu_1","displayName":"Enabled","description":null,"helpText":null}]},"fd6fb91008208113":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\r\n\r\nIf you don't configure this policy, no app is forced to be shown in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be shown.\r\n\r\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"fde53c6949ce489b":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink_customhelplink","displayName":"Specify custom help link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"fdd2684a93b2a03e":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content (User)","description":"This policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser.\r\n\r\nIf you set this policy to true or not set, audio and video mixed content will be automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn’t available over HTTPS) and a 'Not Secure' warning will be shown in the URL bar for image mixed content.\r\n\r\nIf you set the policy to false, auto upgrades will be disabled for audio and video, and no warning will be shown for images.\r\n\r\nThis policy does not affect other types of mixed content other than audio, video, and images.\r\n\r\nThis policy will no longer take effect starting in Microsoft Edge 84.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd357d3abfc53e17":{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault","displayName":"Configure Automatic HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_0","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_1","displayName":"Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_2","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},"fd82b0609f74e38b":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist","displayName":"Allow media autoplay on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\r\n\r\nIf you don't configure this policy, the global default value from the 'AutoplayAllowed' (Allow media autoplay for websites) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nNote: * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"fdd90c4e17978db7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework_l_worklabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"fddefc748cf037c2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu","displayName":"Papiamentu (User)","description":"Enables the editing language Papiamentu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu_1","displayName":"Enabled","description":null,"helpText":null}]},"fddbd2e3386fdbbd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan","displayName":"Punjabi (Pakistan) (User)","description":"Enables the editing language Punjabi (Pakistan)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan_1","displayName":"Enabled","description":null,"helpText":null}]},"fdcb95c021f9f9d1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu","displayName":"Urdu (User)","description":"Enables the editing language Urdu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu_1","displayName":"Enabled","description":null,"helpText":null}]},"fd03dab0c71cdd2f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowpath494","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"fd58ffd5b592bff6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag4","displayName":"Tag 4: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},"fde23540dc99275b":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition","displayName":"Auto Numbering Recognition (User)","description":"Checks/Unchecks the option ''Apply numbering to lists automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},"fd72957bd9625551":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":null},"fdb600ca64a812ad":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval_l_specifyactivityfeedsynchronizationintervalspinid","displayName":"Synchronization interval (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},"fd1f967cb3f0102a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox","displayName":"Maximum Number of Online Search Folders per mailbox (User)","description":"Specifies the maximum number of Search Folders that run on the Exchange server. The number of Search Folders running on the client computer is not affected.","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_1","displayName":"Enabled","description":null,"helpText":null}]},"fdbb32c888d73e69":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_l_x509issuednthatrestrictschoiceofcertifyingauthorities","displayName":"X.509 issue DN that restricts choice of certifying authorities: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},"fdea9df4ea9fe2a5":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},"fd81d90399e0fe31":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"fd7ef2f89c57ec5e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible","displayName":"Make hidden markup visible (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible_1","displayName":"Enabled","description":null,"helpText":null}]},"fd0f2d5eb46ecaa6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"fd579d5d4b6b87e6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file +{"fdde04c7e4dfa0b7":{"id":"com.apple.applicationaccess_allowappstobehidden","displayName":"Allow Apps To Be Hidden","description":"If false, disables the ability for the user to hide apps. It does not affect the user's ability to leave it in the App Library, while removing it from the home screen.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowappstobehidden_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowappstobehidden_true","displayName":"True","description":null,"helpText":null}]},"fd2d49b6a0658526":{"id":"com.apple.applicationaccess_allowcloudreminders","displayName":"Allow Cloud Reminders","description":"If false, disables iCloud Reminder services. Available in macOS 10.12 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowcloudreminders_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowcloudreminders_true","displayName":"True","description":null,"helpText":null}]},"fd898ce00494957b":{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation","displayName":"Allow Web Distribution App Installation","description":"When 'false', the device prevents installation of apps directly from the web.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowwebdistributionappinstallation_true","displayName":"True","description":null,"helpText":null}]},"fd4b802f418d05b3":{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred","displayName":"Cellular Data Preferred","description":"Set to `true` to prefer this private network over Wi-Fi.","helpText":null,"infoUrls":[],"categoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","categoryName":"Cellular Private Network","options":[{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.cellularprivatenetwork.managed_cellulardatapreferred_true","displayName":"True","description":null,"helpText":null}]},"fd49908c2bdc3f38":{"id":"com.apple.directoryservice.managed_adpreferreddcserver","displayName":"AD Preferred DC Server","description":"The preferred domain server.","helpText":null,"infoUrls":[],"categoryId":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","categoryName":"Directory Service","options":null},"fd4243564c7566ac":{"id":"com.apple.managedclient.preferences_audiosandboxenabled","displayName":"Allow the audio sandbox to run","description":"This policy controls the audio process sandbox.\n\nIf you enable this policy, the audio process will run sandboxed.\n\nIf you disable this policy, the audio process will run unsandboxed and the WebRTC audio-processing module will run in the renderer process.\nThis leaves users open to security risks related to running the audio subsystem unsandboxed.\n\nIf you don't configure this policy, the default configuration for the audio sandbox will be used, which might differ based on the platform.\n\nThis policy is intended to give enterprises flexibility to disable the audio sandbox if they use security software setups that interfere with the sandbox.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#audiosandboxenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_audiosandboxenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_audiosandboxenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fd463c979b79b5b8":{"id":"com.apple.managedclient.preferences_composeinlineenabled","displayName":"Control access to Microsoft 365 Copilot writing assistance in Microsoft Edge for Business","description":"This policy controls whether users can use writing support features in Microsoft Edge for Business, such as Rewrite, which utilizes Microsoft 365 Copilot Chat. With Rewrite, users can receive help with drafting content, rewriting text, and adjusting style directly in their browser tab. In Edge, users can trigger it when highlighting editable content in their main browser through the right-click context menu.\n\nThis policy applies only to Microsoft Entra accounts and does not apply to Microsoft accounts.\n\nIf you enable this policy, users can use Rewrite in Microsoft Edge when logged in with an Entra account.\n\nIf you disable this policy, users within your tenant will not be able to use Rewrite.\n\nIf you don't configure this policy, the default behavior is as follows:\n\n- Rewrite is available to users\n\n- Users can enable or disable Microsoft 365 Copilot access to Microsoft Edge page content using the toggle in Microsoft Edge settings.\n\nNote: Rewrite is not available on pages protected by data loss prevention (DLP) policies to help maintain compliance.\n\nLearn more about Microsoft 365 Copilot Chat data, privacy, and security here: https://go.microsoft.com/fwlink/?linkid=2321816","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#composeinlineenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_composeinlineenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_composeinlineenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fd85a593f311c347":{"id":"com.apple.managedclient.preferences_defaultweatherlocation","displayName":"Default weather location","description":"Sets the default weather location in the Calendar view. Enter the city and state or country (e.g. Redmond, WA or Paris, France)","helpText":null,"infoUrls":["https://docs.microsoft.com/deployoffice/mac/preferences-outlook#specify-default-weather-location"],"categoryId":"191a84f2-13b5-4609-808f-8b743b7f0247","categoryName":"Microsoft Outlook","options":null},"fd49bcfd38b199a4":{"id":"com.apple.managedclient.preferences_intranetredirectbehavior","displayName":"Intranet Redirection Behavior","description":"This policy configures behavior for intranet redirection via DNS interception checks. The checks attempt to discover whether the browser is behind a proxy that redirects unknown host names.\n\nIf this policy isn't configured, the browser will use the default behavior of DNS interception checks and intranet redirect suggestions. In M88, they are enabled by default but will be disabled by default in the future release.\n\n\"DNSInterceptionChecksEnabled\" is a related policy that might also disable DNS interception checks. However, this policy is a more flexible version which might separately control intranet redirection infobars and might be expanded in the future.\nIf either \"DNSInterceptionChecksEnabled\" or this policy make a request to disable interception checks, the checks will be disabled.\nIf DNS interception checks are disabled by this policy but \"GoToIntranetSiteForSingleWordEntryInAddressBar\" is enabled, single word queries will still result in intranet navigations.\n\nPolicy options mapping:\n\n* Default (0) = Use default browser behavior.\n\n* DisableInterceptionChecksDisableInfobar (1) = Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\n\n* DisableInterceptionChecksEnableInfobar (2) = Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.\n\n* EnableInterceptionChecksEnableInfobar (3) = Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#intranetredirectbehavior"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_0","displayName":"Use default browser behavior.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_1","displayName":"Disable DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_2","displayName":"Disable DNS interception checks; allow did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_intranetredirectbehavior_3","displayName":"Allow DNS interception checks and did-you-mean \"http://intranetsite/\" infobars.","description":null,"helpText":null}]},"fdc77e95fa31202f":{"id":"com.apple.managedclient.preferences_tabcaptureallowedbyorigins","displayName":"Allow Tab capture by these origins","description":"Setting the policy lets you set a list of URL patterns that can use Tab Capture.\n\nLeaving the policy unset means that sites will not be considered for an override at this scope of capture.\n\nThis policy is not considered if a site matches a URL pattern in the \"SameOriginTabCaptureAllowedByOrigins\" policy.\n\nIf a site matches a URL pattern in this policy, the following policies will not be considered: \"WindowCaptureAllowedByOrigins\", \"ScreenCaptureAllowedByOrigins\", \"ScreenCaptureAllowed\".\n\nFor detailed information on valid url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. This policy only matches based on origin, so any path in the URL pattern is ignored.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#tabcaptureallowedbyorigins"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"fdda1e75c31728fd":{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled","displayName":"Enable zstd content encoding support (Deprecated)","description":"This feature enables advertising \"zstd\" support in the Accept-Encoding request header and support for decompressing zstd web content.\n\nIf you enable or don't configure this policy, Microsoft Edge will accept server responses compressed with zstd.\n\nIf you disable this policy, the zstd content encoding feature will not be advertised or supported when processing server responses.\n\nThis policy is temporary and will be removed in the future.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#zstdcontentencodingenabled"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_zstdcontentencodingenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fdc416f5f44a386d":{"id":"com.apple.preference.security_dontallowfirewallui","displayName":"Do Not Allow Firewall UI","description":"If true, disables user changes to the firewall settings.","helpText":null,"infoUrls":[],"categoryId":"8abddb23-7036-4ba8-8912-529279a849ea","categoryName":"Security Preferences","options":[{"id":"com.apple.preference.security_dontallowfirewallui_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.preference.security_dontallowfirewallui_true","displayName":"True","description":null,"helpText":null}]},"fdc177d176e60559":{"id":"com.apple.tcc.configuration-profile-policy_services_systempolicynetworkvolumes_item_identifier","displayName":"Identifier","description":"The bundle ID or installation path of the binary.\n\n> Note:\n> This value is case-sensitive.","helpText":null,"infoUrls":[],"categoryId":"82d173f9-ba0b-4b09-bbb8-68cba4916162","categoryName":"Privacy Preferences Policy Control","options":null},"fd56c5b8958e1c7d":{"id":"com.apple.webcontent-filter_organization","displayName":"Organization","description":"The organization string that passes to the third-party plug-in.","helpText":null,"infoUrls":[],"categoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","categoryName":"Web Content Filter","options":null},"fd664c56d1a21215":{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled","displayName":"Enable opaque origins for data URLs in Web Workers","description":"This policy controls whether Web Workers created from data URLs are assigned\na unique opaque origin.\n\nWeb Workers can be created using a data URL that contains the worker script.\nPreviously, these workers inherited the origin of the page that created them,\nwhich allowed them to access the same origin-bound data, such as local\nstorage and cookies.\n\nStarting in Microsoft Edge version\n149, Web Workers created from data URLs are assigned a unique opaque origin\nby default. This behavior improves security and aligns with the HTML\nspecification by isolating these workers from the page that created them.\n\nIf you enable this policy or don't configure it, Web Workers created from\ndata URLs are assigned a unique opaque origin.\n\nIf you disable this policy, Web Workers created from data URLs inherit the\norigin of the page that created them. Use this setting only as a temporary\nmitigation for compatibility issues with internal applications that depend\non the legacy behavior.\n\nThis policy is temporary and will be removed in Microsoft Edge\nversion 157.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.dataurlinwebworkeropaqueoriginenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fda4d8706e0c9671":{"id":"com.microsoft.edge.mamedgeappconfigsettings.defaultsearchprovidersearchurl_recommended","displayName":"Default search provider search URL (users can override)","description":"Specifies the URL of the search engine used for a default search. The URL contains the string '{searchTerms}', which is replaced at query time by the terms the user is searching for.\n\nSpecify Bing's search URL as:\n\n'{bing:baseURL}search?q={searchTerms}'.\n\nSpecify Google's search URL as: '{google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}ie={inputEncoding}'.\n\nThis policy is required when you enable the \"DefaultSearchProviderEnabled\" policy; if you don't enable the latter policy, this policy is ignored.\n\nStarting in Microsoft Edge 84, you can set this policy as a recommended policy. If the user has already set a default search provider, the default search provider configured by this recommended policy won't be added to the list of search providers the user can choose from. If this is the desired behavior, use the \"ManagedSearchEngines\" policy.","helpText":null,"infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"fdb01edd171e3f56":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended","displayName":"Sets layout for printing (users can override)","description":"Configuring this policy sets the layout for printing webpages.\n\nIf you disable or don't configure this policy, users can decide whether to print webpages in Portrait or Landscape layout.\n\nIf you enable this policy, the selected option is set as the layout option.\n\nPolicy options mapping:\n\n* portrait (0) = Sets layout option as portrait\n\n* landscape (1) = Sets layout option as landscape\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended_portrait","displayName":"Sets layout option as portrait","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingwebpagelayout_recommended_landscape","displayName":"Sets layout option as landscape","description":null,"helpText":null}]},"fd6836fd690f58da":{"id":"device_vendor_msft_maintenancewindows_dayoftheweek","displayName":"Day of the week","description":"Select the day of the week on which the maintenance window should run.","helpText":"","infoUrls":[],"categoryId":"d7b2000f-6aae-42d1-a64b-7339544fa2e0","categoryName":null,"options":[{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_1","displayName":"Sunday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_2","displayName":"Monday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_3","displayName":"Tuesday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_4","displayName":"Wednesday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_5","displayName":"Thursday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_6","displayName":"Friday","description":null,"helpText":null},{"id":"device_vendor_msft_maintenancewindows_dayoftheweek_7","displayName":"Saturday","description":null,"helpText":null}]},"fd105d4e01992e9e":{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize","displayName":"Define the maximum size of downloaded files and attachments to be scanned","description":"This policy setting defines the maximum size (in kilobytes) of downloaded files and attachments that will be scanned.\r\n\r\n If you enable this setting, downloaded files and attachments smaller than the size specified will be scanned.\r\n\r\n If you disable or do not configure this setting, a default size will be applied.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-microsoftdefenderantivirus#admx-microsoftdefenderantivirus-realtimeprotection-ioavmaxsize"],"categoryId":"8a03aebc-9249-4917-a1c3-2957717d9123","categoryName":"Real-time Protection","options":[{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_microsoftdefenderantivirus_realtimeprotection_ioavmaxsize_1","displayName":"Enabled","description":null,"helpText":null}]},"fd3d4a2a3efcf74a":{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization","displayName":"Always rasterize content to be printed using a software rasterizer","description":"Determines whether the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) is forced to use a software rasterizer instead of a Graphics Processing Unit (GPU) to rasterize pages.\r\n\r\nThis setting may improve the performance of the XPS Rasterization Service or the XPS-to-GDI conversion (XGC) on machines that have a relatively powerful CPU as compared to the machine’s GPU.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-printing#admx-printing-forcesoftwarerasterization"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_printing_forcesoftwarerasterization_1","displayName":"Enabled","description":null,"helpText":null}]},"fda69e08354157bc":{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c","displayName":"Best effort service type","description":"Specifies an alternate Layer-3 Differentiated Services Code Point (DSCP) value for packets with the Best Effort service type (ServiceTypeBestEffort). The Packet Scheduler inserts the corresponding DSCP value in the IP header of the packets.\r\n\r\nThis setting applies only to packets that conform to the flow specification.\r\n\r\nIf you enable this setting, you can change the default DSCP value associated with the Best Effort service type.\r\n\r\nIf you disable this setting, the system uses the default DSCP value of 0.\r\n\r\nImportant: If the DSCP value for this service type is specified in the registry for a particular network adapter, this setting is ignored when configuring that network adapter.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-qos#admx-qos-qosservicetypebesteffort-c"],"categoryId":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","categoryName":"DSCP value of conforming packets","options":[{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_qos_qosservicetypebesteffort_c_1","displayName":"Enabled","description":null,"helpText":null}]},"fd163b019f924c80":{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync","displayName":"Do not sync desktop personalization","description":"Prevent the \"desktop personalization\" group from syncing to and from this PC. This turns off and disables the \"desktop personalization\" group on the \"sync your settings\" page in PC settings.\r\n\r\nIf you enable this policy setting, the \"desktop personalization\" group will not be synced.\r\n\r\nUse the option \"Allow users to turn desktop personalization syncing on\" so that syncing it turned off by default but not disabled.\r\n\r\nIf you do not set or disable this setting, syncing of the \"desktop personalization\" group is on by default and configurable by the user.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-settingsync#admx-settingsync-disabledesktopthemesettingsync"],"categoryId":"902f5df1-31d6-44ee-ba95-2561199db35f","categoryName":"Sync your settings","options":[{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_settingsync_disabledesktopthemesettingsync_1","displayName":"Enabled","description":null,"helpText":null}]},"fd492ead726cbabb":{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath","displayName":"Allow the use of remote paths in file shortcut icons","description":"This policy setting determines whether remote paths can be used for file shortcut (.lnk file) icons.\r\n\r\nIf you enable this policy setting, file shortcut icons are allowed to be obtained from remote paths.\r\n\r\nIf you disable or do not configure this policy setting, file shortcut icons that use remote paths are prevented from being displayed.\r\n\r\nNote: Allowing the use of remote paths in file shortcut icons can expose users’ computers to security risks.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-enableshellshortcuticonremotepath"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_windowsexplorer_enableshellshortcuticonremotepath_1","displayName":"Enabled","description":null,"helpText":null}]},"fdaca30f3454611b":{"id":"device_vendor_msft_policy_config_browser_allowinprivate","displayName":"Allow InPrivate","description":"This setting lets you decide whether employees can browse using InPrivate website browsing.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Browser#allowinprivate"],"categoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","categoryName":"Browser","options":[{"id":"device_vendor_msft_policy_config_browser_allowinprivate_0","displayName":"Block","description":"Prevented/Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_browser_allowinprivate_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"fdf533c0b7204ee0":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_roamingprofilelocation_roamingprofilelocation","displayName":"Set the roaming profile directory (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"fdce1ab41d70b455":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled","displayName":"Enable HTTP/0.9 support on non-default ports","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_http09onnondefaultportsenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd336a0eeb79a2e5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation","displayName":"Configure the home page URL","description":"Setting the policy sets the default homepage URL in Google Chrome. You open the homepage using the Home button. On desktop, the RestoreOnStartup policies control the pages that open on startup.\r\n\r\nIf the homepage is set to the New Tab Page, by the user or HomepageIsNewTabPage, this policy has no effect.\r\n\r\n The URL needs a standard scheme, such as http://example.com or https://example.com. When this policy is set, users can't change their homepage URL in Google Chrome.\r\n\r\nLeaving both HomepageLocation and HomepageIsNewTabPage unset lets users choose their homepage.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value: https://www.chromium.org","helpText":"","infoUrls":[],"categoryId":"148a6f4e-8816-4c00-87a3-57481c85c331","categoryName":"Startup Home page and New Tab page","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~startup_homepagelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"fd9c942c95c2a370":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting","displayName":"Control use of the WebHID API","description":"Setting the policy to 3 lets websites ask for access to HID devices. Setting the policy to 2 denies access to HID devices.\r\n\r\nLeaving it unset lets websites ask for access, but users can change this setting.\r\n\r\nThis policy can be overridden for specific url patterns using the WebHidAskForUrls and WebHidBlockedForUrls policies.","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~contentsettings_defaultwebhidguardsetting_1","displayName":"Enabled","description":null,"helpText":null}]},"fd66eb9874823d2b":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled","displayName":"Re-enable the Event.path API until M115.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_eventpathenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd7ccc3e4a25c43f":{"id":"device_vendor_msft_policy_config_experience_allowclipboardhistory","displayName":"Allow Clipboard History","description":"Allows history of clipboard items to be stored in memory.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Experience#allowclipboardhistory"],"categoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","categoryName":"Experience","options":[{"id":"device_vendor_msft_policy_config_experience_allowclipboardhistory_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_experience_allowclipboardhistory_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"fdfb9854d77a70e6":{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols","displayName":"Automatic prompting for ActiveX controls","description":"This policy setting manages whether users will be automatically prompted for ActiveX control installations.\n\nIf you enable this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.\n\nIf you disable this policy setting, ActiveX control installations will be blocked using the Notification bar. Users can click on the Notification bar to allow the ActiveX control prompt.\n\nIf you do not configure this policy setting, users will receive a prompt when a site instantiates an ActiveX control they do not have installed.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-localmachinezoneallowautomaticpromptingforactivexcontrols"],"categoryId":"4086190d-2e5b-439d-8426-08492ebb8c9f","categoryName":"Local Machine Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_localmachinezoneallowautomaticpromptingforactivexcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"fddb17119c8810e7":{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads","displayName":"Automatic prompting for file downloads","description":"This policy setting determines whether users will be prompted for non user-initiated file downloads. Regardless of this setting, users will receive file download dialogs for user-initiated downloads.\n\nIf you enable this setting, users will receive a file download dialog for automatic download attempts.\n\nIf you disable or do not configure this setting, file downloads that are not user-initiated will be blocked, and users will see the Notification bar instead of the file download dialog. Users can then click the Notification bar to allow the file download prompt.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowautomaticpromptingforfiledownloads_1","displayName":"Enabled","description":null,"helpText":null}]},"fde9c87551ee5335":{"id":"device_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge~identity_edgedefaultprofileenabled_edgedefaultprofileenabled","displayName":"Default Profile Setting Enabled (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":null},"fd898d285ccbab79":{"id":"device_vendor_msft_policy_config_microsoft_edgev146~policy~microsoft_edge~network_loopbacknetworkblockedforurls_loopbacknetworkblockedforurlsdesc","displayName":"Block sites from making network requests to the local device. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"3fbd3b29-bafd-4adf-89e4-3be612dee275","categoryName":"Network settings","options":null},"fd67b1f9d3808c18":{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled","displayName":"Configure whether a user always has a default profile automatically signed in with their work or school account","description":"This policy determines if a user can remove the Microsoft Edge profile automatically signed in with a user's work or school account.\r\n\r\nIf you enable this policy, a non-removable profile will be created with the user's work or school account on Windows. This profile can't be signed out or removed.\r\n\r\nIf you disable or don't configure this policy, the profile automatically signed in with a user's work or school account on Windows can be signed out or removed by the user.\r\n\r\nIf you want to configure browser sign in, use the 'BrowserSignin' (Browser sign-in settings) policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_nonremovableprofileenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd5f6d87f9d05785":{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended","displayName":"Suggest similar pages when a webpage can’t be found","description":"Allow Microsoft Edge to issue a connection to a web service to generate URL and search suggestions for connectivity issues such as DNS errors.\r\n\r\nIf you enable this policy, a web service is used to generate url and search suggestions for network errors.\r\n\r\nIf you disable this policy, no calls to the web service are made and a standard error page is shown.\r\n\r\nIf you don't configure this policy, Microsoft Edge respects the user preference that's set under Services at edge://settings/privacy.\r\nSpecifically, there's a **Suggest similar pages when a webpage can’t be found** toggle, which the user can switch on or off. Note that if you have enable this policy (AlternateErrorPagesEnabled), the Suggest similar pages when a webpage can’t be found setting is turned on, but the user can't change the setting by using the toggle. If you disable this policy, the Suggest similar pages when a webpage can’t be found setting is turned off, and the user can't change the setting by using the toggle.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev80diff~policy~microsoft_edge_recommended_alternateerrorpagesenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fd378c310c267cfc":{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled","displayName":"Allows the AppCache feature to be re-enabled, even if it's turned off by default (obsolete)","description":"OBSOLETE: This policy is obsolete and doesn't work after Microsoft Edge 96.\r\n\r\nSupport for AppCache and this policy was removed from Microsoft Edge starting in version 97.\r\n\r\nIf you set this policy to true, the AppCache is enabled, even when AppCache in Microsoft Edge is not available by default.\r\n\r\nIf you set this policy to false, or don't set it, AppCache will follow Microsoft Edge's defaults.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev84diff~policy~microsoft_edge_appcacheforceenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd6c4309dd72af58":{"id":"device_vendor_msft_policy_config_privacy_letappssyncwithdevices_userincontroloftheseapps","displayName":"Let Apps Sync With Devices User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Microsoft Store Apps. The user is able to control the 'Communicate with unpaired wireless devices' privacy setting for the listed apps. This setting overrides the default LetAppsSyncWithDevices policy setting for the specified apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappssyncwithdevices_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"fd26a69ed5bef21a":{"id":"device_vendor_msft_policy_config_settings_allowvpn","displayName":"Allow VPN","description":"Allows the user to change VPN settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#allowvpn"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":[{"id":"device_vendor_msft_policy_config_settings_allowvpn_0","displayName":"Not allowed.","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_settings_allowvpn_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"fd7c52fd43d863ec":{"id":"device_vendor_msft_policy_config_wslv3~policy~wsl_defaultnetworkingmode","displayName":"Configure default networking mode","description":"This policy specifies the default networking mode to be used for WSL2.","helpText":"","infoUrls":[],"categoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","categoryName":"Windows Subsystem For Linux","options":[{"id":"device_vendor_msft_policy_config_wslv3~policy~wsl_defaultnetworkingmode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_wslv3~policy~wsl_defaultnetworkingmode_1","displayName":"Enabled","description":null,"helpText":null}]},"fdcf4103fa7a57f9":{"id":"intelligencesettings_apps_safari_allowsummary","displayName":"Allow Summary","description":"If `false`, disables Safari Summary.","helpText":null,"infoUrls":[],"categoryId":"11d26400-1d13-4dd6-ab4b-cb323494b127","categoryName":"Intelligence Settings","options":[{"id":"intelligencesettings_apps_safari_allowsummary_false","displayName":"False","description":null,"helpText":null},{"id":"intelligencesettings_apps_safari_allowsummary_true","displayName":"True","description":null,"helpText":null}]},"fda799b90a516ab6":{"id":"osrecoverysettings_keyboardsettings","displayName":"Keyboard settings","description":"","helpText":"","infoUrls":[],"categoryId":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","categoryName":"Operating system settings","options":[{"id":"osrecoverysettings_keyboardsettings_afrikaans","displayName":"Afrikaans","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_afrikaansn","displayName":"Afrikaans (Namibia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_albanian","displayName":"Albanian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_albaniank","displayName":"Albanian (Kosovo)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_alsatianf","displayName":"Alsatian (France)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_amharic","displayName":"Amharic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabic","displayName":"Arabic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabica","displayName":"Arabic (Algeria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicb","displayName":"Arabic (Bahrain)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabice","displayName":"Arabic (Egypt)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabici","displayName":"Arabic (Iraq)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicj)","displayName":"Arabic (Jordan)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabick","displayName":"Arabic (Kuwait)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicl","displayName":"Arabic (Lebanon)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicli","displayName":"Arabic (Libya)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicm","displayName":"Arabic (Morocco)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaico","displayName":"Arabic (Oman)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaicq","displayName":"Arabic (Qatar)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaics","displayName":"Arabic (Syria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaict","displayName":"Arabic (Tunisia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arbaicu","displayName":"Arabic (United Arab Emirates)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicw","displayName":"Arabic (World)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_arabicy","displayName":"Arabic (Yemen)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_armenian","displayName":"Armenian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_assamese","displayName":"Assamese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_azerbaijani","displayName":"Azerbaijani","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_azerbaijanic","displayName":"Azerbaijani (Cyrillic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bangla","displayName":"Bangla","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bashkir","displayName":"Bashkir","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_basque","displayName":"Basque","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_belarusian","displayName":"Belarusian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bengali","displayName":"Bengali (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bosnian","displayName":"Bosnian (Latin)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_breton","displayName":"Breton","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_bulgarian","displayName":"Bulgarian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_burmese","displayName":"Burmese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_catalan","displayName":"Catalan","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_catalana","displayName":"Catalan (Andorra)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_catalanfrance","displayName":"Catalan (France)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_catalanitaly","displayName":"Catalan (Italy)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_centralatlastamazight","displayName":"Central Atlas Tamazight","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_centralatlastamazightarabic","displayName":"Central Atlas Tamazight (Arabic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_centralatlastamazighttifinagh","displayName":"Central Atlas Tamazight (Tifinagh)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_centralkurdish","displayName":"Central Kurdish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chechen","displayName":"Chechen","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_cherokee","displayName":"Cherokee","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinese","displayName":"Chinese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinesesimplifiedhongkongsar","displayName":"Chinese (Simplified, Hong Kong SAR)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinesesimplifiedmacaosar","displayName":"Chinese (Simplified, Macao SAR)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinesetraditional","displayName":"Chinese (Traditional)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_chinesetraditionaltaiwan","displayName":"Chinese (Traditional, Taiwan)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_churchslavic","displayName":"Church Slavic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_colognian","displayName":"Colognian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_cornish","displayName":"Cornish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_corsican","displayName":"Corsican","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_croatian","displayName":"Croatian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_croatianbosniaherzegovina","displayName":"Croatian (Bosnia & Herzegovina)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_czech","displayName":"Czech","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_danish","displayName":"Danish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_danishgreenland","displayName":"Danish (Greenland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_divehi","displayName":"Divehi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutch","displayName":"Dutch","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutcharuba","displayName":"Dutch (Aruba)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchbelgium","displayName":"Dutch (Belgium)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchbonaires","displayName":"Dutch (Bonaire, Sint Eustatius and Saba)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchcuracao","displayName":"Dutch (Curaçao)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchsintmaarten","displayName":"Dutch (Sint Maarten)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dutchsuriname","displayName":"Dutch (Suriname)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_dzongkha","displayName":"Dzongkha","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_english","displayName":"English","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishaustralia","displayName":"English (Australia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishaustria","displayName":"English (Austria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishbelgium","displayName":"English (Belgium)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishbelize","displayName":"English (Belize)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishbritishvirginislands","displayName":"English (British Virgin Islands)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishburundi","displayName":"English (Burundi)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishcanada","displayName":"English (Canada)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishcaribbean","displayName":"English (Caribbean)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishdenmark","displayName":"English (Denmark)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishfalklandislands","displayName":"English (Falkland Islands)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishfinland","displayName":"English (Finland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishgermany","displayName":"English (Germany)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishgibraltar","displayName":"English (Gibraltar)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishguernsey","displayName":"English (Guernsey)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishhongkongsar","displayName":"English (Hong Kong SAR)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishindia","displayName":"English (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishireland","displayName":"English (Ireland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishisleofman","displayName":"English (Isle of Man)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishisrael","displayName":"English (Israel)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishjamaica","displayName":"English (Jamaica)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishjersey","displayName":"English (Jersey)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishmalaysia","displayName":"English (Malaysia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishmalta","displayName":"English (Malta)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishnetherlands","displayName":"English (Netherlands)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishnewzealand","displayName":"English (New Zealand)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishphilippines","displayName":"English (Philippines)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishsingapore","displayName":"English (Singapore)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishslovenia","displayName":"English (Slovenia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishsouthafrica","displayName":"English (South Africa)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishsweden","displayName":"English (Sweden)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishswitzerland","displayName":"English (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishtrinidadtobago","displayName":"English (Trinidad & Tobago)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishuk","displayName":"English (United Kingdom)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_englishzimbabwe","displayName":"English (Zimbabwe)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_estonian","displayName":"Estonian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_faroese","displayName":"Faroese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_filipino","displayName":"Filipino","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_finnish","displayName":"Finnish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_french","displayName":"French","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchbelgium","displayName":"French (Belgium)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchcameroon","displayName":"French (Cameroon)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchcanada","displayName":"French (Canada)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchcotedivoire","displayName":"French (Côte d’Ivoire)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchhaiti","displayName":"French (Haiti)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchluxembourg","displayName":"French (Luxembourg)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchmali","displayName":"French (Mali)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchmonaco","displayName":"French (Monaco)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchmorocco","displayName":"French (Morocco)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchreunion","displayName":"French (Réunion)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchsenegal","displayName":"French (Senegal)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchswitzerland","displayName":"French (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_frenchcongodrc","displayName":"French Congo (DRC)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_friulian","displayName":"Friulian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulah","displayName":"Fulah","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahadlam","displayName":"Fulah (Adlam)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahburkinafaso","displayName":"Fulah (Latin, Burkina Faso)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahcameroon","displayName":"Fulah (Latin, Cameroon)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahgambia","displayName":"Fulah (Latin, Gambia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahghana","displayName":"Fulah (Latin, Ghana)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahguinea","displayName":"Fulah (Latin, Guinea)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahguineabissau","displayName":"Fulah (Latin, Guinea-Bissau)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahliberia","displayName":"Fulah (Latin, Liberia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahmauritania","displayName":"Fulah (Latin, Mauritania)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahniger","displayName":"Fulah (Latin, Niger)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahnigeria","displayName":"Fulah (Latin, Nigeria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_fulahsierraleone","displayName":"Fulah (Latin, Sierra Leone)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_galician","displayName":"Galician","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_georgian","displayName":"Georgian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_german","displayName":"German","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanaustria","displayName":"German (Austria)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanbelgium","displayName":"German (Belgium)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanitaly","displayName":"German (Italy)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanliechtenstein","displayName":"German (Liechtenstein)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanluxembourg","displayName":"German (Luxembourg)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_germanswitzerland","displayName":"German (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_greek","displayName":"Greek","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_guarani","displayName":"Guarani","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_gujarati","displayName":"Gujarati","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hausa","displayName":"Hausa","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hawaiian","displayName":"Hawaiian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hebrew","displayName":"Hebrew","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hindi","displayName":"Hindi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_hungarian","displayName":"Hungarian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_icelandic","displayName":"Icelandic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_igbo","displayName":"Igbo","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_indonesian","displayName":"Indonesian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_interlingua","displayName":"Interlingua","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_inuktitut","displayName":"Inuktitut","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_inuktitutsyllabics","displayName":"Inuktitut (Syllabics)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_irish","displayName":"Irish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_irishunitedkingdom","displayName":"Irish (United Kingdom)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_italian","displayName":"Italian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_italianswitzerland","displayName":"Italian (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_italianvaticancity","displayName":"Italian (Vatican City)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_japanese","displayName":"Japanese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_javanese","displayName":"Javanese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_javanesejavanese","displayName":"Javanese (Javanese)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kalaallisut","displayName":"Kalaallisut","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kannada","displayName":"Kannada","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kashmiri","displayName":"Kashmiri","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kashmiridevanagari","displayName":"Kashmiri (Devanagari)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kazakh","displayName":"Kazakh","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_khmer","displayName":"Khmer","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kinyarwanda","displayName":"Kinyarwanda","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kiswahili","displayName":"Kiswahili","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kiswahilicongodrc","displayName":"Kiswahili (Congo DRC)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kiswahilitanzania","displayName":"Kiswahili (Tanzania)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kiswahiliuganda","displayName":"Kiswahili (Uganda)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_konkani","displayName":"Konkani","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_korean","displayName":"Korean","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_koreannorthkorea","displayName":"Korean (North Korea)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_kyrgyz","displayName":"Kyrgyz","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_lao","displayName":"Lao","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_latvian","displayName":"Latvian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_lithuanian","displayName":"Lithuanian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_lowersorbian","displayName":"Lower Sorbian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_luxembourgish","displayName":"Luxembourgish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_macedonian","displayName":"Macedonian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malagasy","displayName":"Malagasy","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malay","displayName":"Malay","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malaybrunei","displayName":"Malay (Brunei)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malayindonesia","displayName":"Malay (Indonesia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malaysingapore","displayName":"Malay (Singapore)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_malayalam","displayName":"Malayalam","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_maltese","displayName":"Maltese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_manipuri","displayName":"Manipuri","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_manx","displayName":"Manx","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_maori","displayName":"Maori","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mapuche","displayName":"Mapuche","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_marathi","displayName":"Marathi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mazanderani","displayName":"Mazanderani","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mohawk","displayName":"Mohawk","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mongolian","displayName":"Mongolian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mongolian_traditional_mongolian","displayName":"Mongolian (Traditional Mongolian)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_mongolian_traditional_mongolian_mongolia","displayName":"Mongolian (Traditional Mongolian, Mongolia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_nko","displayName":"N'ko","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_nepali","displayName":"Nepali","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_nepali_india","displayName":"Nepali (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_northern_luri","displayName":"Northern Luri","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_northern_sami","displayName":"Northern Sami","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_norwegian","displayName":"Norwegian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_norwegian_nynorsk","displayName":"Norwegian Nynorsk","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_occitan","displayName":"Occitan","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_odia","displayName":"Odia","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_oromo","displayName":"Oromo","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_oromo_kenya","displayName":"Oromo (Kenya)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_ossetic","displayName":"Ossetic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_papiamento","displayName":"Papiamento","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_pashto","displayName":"Pashto","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_pashto_pakistan","displayName":"Pashto (Pakistan)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_persian","displayName":"Persian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_persian_afghanistan","displayName":"Persian (Afghanistan)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_polish","displayName":"Polish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese","displayName":"Portuguese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_angola","displayName":"Portuguese (Angola)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_cabo_verde","displayName":"Portuguese (Cabo Verde)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_equatorial_guinea","displayName":"Portuguese (Equatorial Guinea)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_guinea_bissau","displayName":"Portuguese (Guinea-Bissau)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_luxembourg","displayName":"Portuguese (Luxembourg)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_macao_sar","displayName":"Portuguese (Macao SAR)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_mozambique","displayName":"Portuguese (Mozambique)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_portugal","displayName":"Portuguese (Portugal)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_switzerland","displayName":"Portuguese (Switzerland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_sao_tome_principe","displayName":"Portuguese (São Tomé & Príncipe)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_portuguese_timor_leste","displayName":"Portuguese (Timor-Leste)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_prussian","displayName":"Prussian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_punjabi","displayName":"Punjabi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_quechua","displayName":"Quechua","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_quechua_ecuador","displayName":"Quechua (Ecuador)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_quechua_peru","displayName":"Quechua (Peru)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_romanian","displayName":"Romanian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_romanian_moldova","displayName":"Romanian (Moldova)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_romansh","displayName":"Romansh","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_russian","displayName":"Russian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_russian_moldova","displayName":"Russian (Moldova)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sakha","displayName":"Sakha","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sami_lule_norway","displayName":"Sami, Lule (Norway)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sami_northern_finland","displayName":"Sami, Northern (Finland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sami_northern_sweden","displayName":"Sami, Northern (Sweden)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sami_southern_norway","displayName":"Sami, Southern (Norway)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sanskrit","displayName":"Sanskrit","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_scottish_gaelic","displayName":"Scottish Gaelic","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian","displayName":"Serbian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_cyrillic","displayName":"Serbian (Cyrillic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_cyrillic_bosnia_herzegovina","displayName":"Serbian (Cyrillic, Bosnia and Herzegovina)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_cyrillic_kosovo","displayName":"Serbian (Cyrillic, Kosovo)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_cyrillic_montenegro","displayName":"Serbian (Cyrillic, Montenegro)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_latin_bosnia_herzegovina","displayName":"Serbian (Latin, Bosnia & Herzegovina)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_latin_kosovo","displayName":"Serbian (Latin, Kosovo)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_serbian_latin_montenegro","displayName":"Serbian (Latin, Montenegro)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sesotho","displayName":"Sesotho","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sesotho_lesotho","displayName":"Sesotho (Lesotho)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sesotho_sa_leboa","displayName":"Sesotho sa Leboa","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_setswana","displayName":"Setswana","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_setswana_botswana","displayName":"Setswana (Botswana)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_shona","displayName":"Shona","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_sinhala","displayName":"Sinhala","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_slovak","displayName":"Slovak","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_slovenian","displayName":"Slovenian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_somali","displayName":"Somali","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_somali_djibouti","displayName":"Somali (Djibouti)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_somali_ethiopia","displayName":"Somali (Ethiopia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_somali_kenya","displayName":"Somali (Kenya)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish","displayName":"Spanish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_argentina","displayName":"Spanish (Argentina)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_belize","displayName":"Spanish (Belize)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_bolivia","displayName":"Spanish (Bolivia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_brazil","displayName":"Spanish (Brazil)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_chile","displayName":"Spanish (Chile)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_colombia","displayName":"Spanish (Colombia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_costa_rica","displayName":"Spanish (Costa Rica)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_cuba","displayName":"Spanish (Cuba)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_dominican_republic","displayName":"Spanish (Dominican Republic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_ecuador","displayName":"Spanish (Ecuador)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_el_salvador","displayName":"Spanish (El Salvador)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_equatorial_guinea","displayName":"Spanish (Equatorial Guinea)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_guatemala","displayName":"Spanish (Guatemala)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_honduras","displayName":"Spanish (Honduras)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_latin_america","displayName":"Spanish (Latin America)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_mexico","displayName":"Spanish (Mexico)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_nicaragua","displayName":"Spanish (Nicaragua)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_panama","displayName":"Spanish (Panama)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_paraguay","displayName":"Spanish (Paraguay)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_peru","displayName":"Spanish (Peru)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_philippines","displayName":"Spanish (Philippines)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_puerto_rico","displayName":"Spanish (Puerto Rico)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_united_states","displayName":"Spanish (United States)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_uruguay","displayName":"Spanish (Uruguay)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_spanish_venezuela","displayName":"Spanish (Venezuela)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_standard_moroccan_tamazight","displayName":"Standard Moroccan Tamazight","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_swedish","displayName":"Swedish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_swedish_finland","displayName":"Swedish (Finland)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_swiss_german","displayName":"Swiss German","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_syriac","displayName":"Syriac","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tachelhit","displayName":"Tachelhit","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tachelhit_latin","displayName":"Tachelhit (Latin)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tajik","displayName":"Tajik","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tamil","displayName":"Tamil","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tamil_malaysia","displayName":"Tamil (Malaysia)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tamil_singapore","displayName":"Tamil (Singapore)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tamil_sri_lanka","displayName":"Tamil (Sri Lanka)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tatar","displayName":"Tatar","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_telugu","displayName":"Telugu","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_thai","displayName":"Thai","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tibetan","displayName":"Tibetan","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tibetan_india","displayName":"Tibetan (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_tigrinya","displayName":"Tigrinya","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_turkish","displayName":"Turkish","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_turkmen","displayName":"Turkmen","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_ukrainian","displayName":"Ukrainian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_upper_sorbian","displayName":"Upper Sorbian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_urdu","displayName":"Urdu","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_urdu_india","displayName":"Urdu (India)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_uyghur","displayName":"Uyghur","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_uzbek","displayName":"Uzbek","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_uzbek_arabic","displayName":"Uzbek (Arabic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_uzbek_cyrillic","displayName":"Uzbek (Cyrillic)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_valencian_spain","displayName":"Valencian (Spain)","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_vietnamese","displayName":"Vietnamese","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_walser","displayName":"Walser","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_welsh","displayName":"Welsh","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_western_frisian","displayName":"Western Frisian","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_wolof","displayName":"Wolof","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_xitsonga","displayName":"Xitsonga","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_yi","displayName":"Yi","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_yoruba","displayName":"Yoruba","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_isixhosa","displayName":"IsiXhosa","description":null,"helpText":null},{"id":"osrecoverysettings_keyboardsettings_isizulu","displayName":"IsiZulu","description":null,"helpText":null}]},"fd218256f48d5b43":{"id":"user_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_maximumpinlength","displayName":"Maximum PIN Length (User)","description":"Maximum PIN length configures the maximum number of characters allowed for the PIN. The largest number you can configure for this policy setting is 127. The lowest number you can configure must be larger than the number configured in the Minimum PIN length policy setting or the number 4, whichever is greater.\n\nIf you configure this policy setting, the PIN length must be less than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be less than or equal to 127.\n\nNOTE: If the above specified conditions for the maximum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"fd6e0d53aed4f5eb":{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvetrack","displayName":"Do not use the tracking-based method when resolving shell shortcuts (User)","description":"This policy setting prevents the system from using NTFS tracking features to resolve a shortcut.\r\n\r\nIf you enable this policy setting, the system does not try to locate the file by using its file ID. It skips this step and begins a comprehensive search of the drive specified in the target path.\r\n\r\nIf you disable or do not configure this policy setting, by default, when the system cannot find the target file for a shortcut (.lnk), it searches all paths associated with the shortcut. If the target file is located on an NTFS partition, the system then uses the target's file ID to find a path. If the resulting path is not correct, it conducts a comprehensive search of the target drive in an attempt to find the file.\r\n\r\nNote: This policy setting only applies to target files on NTFS partitions. FAT partitions do not have this ID tracking and search capability.\r\n\r\nAlso, see the \"Do not track Shell shortcuts during roaming\" and the \"Do not use the search-based method when resolving shell shortcuts\" policy settings.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-startmenu#admx-startmenu-noresolvetrack"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvetrack_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_startmenu_noresolvetrack_1","displayName":"Enabled","description":null,"helpText":null}]},"fdc83990a4e1d642":{"id":"user_vendor_msft_policy_config_admx_terminalserver_ts_start_program_1_ts_workdir","displayName":"Working Directory (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","categoryName":"Remote Session Environment","options":null},"fd49dfc9580db7ef":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_disabledschemes_disabledschemesdesc","displayName":"List of disabled protocol schemes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"fd2bde73fe8892f3":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_renderinhostlist_renderinhostlistdesc","displayName":"Always render the following URL patterns in the host browser (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":null},"fd29a2e599889fa9":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings","displayName":"Settings for Tab Organizer (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_0","displayName":"Allow Tab Organizer and improve AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_1","displayName":"Allow Tab Organizer without improving AI models.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_taborganizersettings_taborganizersettings_2","displayName":"Do not allow Tab Organizer.","description":null,"helpText":null}]},"fd5f6c398174d3ce":{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14","displayName":"Trusted Location #14 (User)","description":"This policy setting allows you to specify a folder as a trusted location from which to open 2016 Word, Excel, PowerPoint, Access and Visio files. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you can specify a trusted location (or folder) from which the 2016 Office application can open the files which run macros without warning.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_excel16v2~policy~l_microsoftofficeexcel~l_exceloptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc14_1","displayName":"Enabled","description":null,"helpText":null}]},"fdbd2443009b2e44":{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork","displayName":"Allow Option To Show Network (User)","description":"When the Network folder is restricted, give the user the option to enumerate and navigate into it.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-FileExplorer#allowoptiontoshownetwork"],"categoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","categoryName":"File Explorer","options":[{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_0","displayName":"Not Allowed.","description":"Not Allowed.","helpText":null},{"id":"user_vendor_msft_policy_config_fileexplorer_allowoptiontoshownetwork_1","displayName":"Allowed.","description":"Allowed.","helpText":null}]},"fd9b38e97b86a72a":{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses","displayName":"Internet Explorer Processes (User)","description":"Internet Explorer uses Multipurpose Internet Mail Extensions (MIME) data to determine file handling procedures for files received through a Web server.\n\nThis policy setting determines whether Internet Explorer requires that all file-type information provided by Web servers be consistent. For example, if the MIME type of a file is text/plain but the MIME sniff indicates that the file is really an executable file, Internet Explorer renames the file by saving it in the Internet Explorer cache and changing its extension.\n\nIf you enable this policy setting, Internet Explorer requires consistent MIME data for all received files.\n\nIf you disable this policy setting, Internet Explorer will not require consistent MIME data for all received files.\n\nIf you do not configure this policy setting, Internet Explorer requires consistent MIME data for all received files.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-consistentmimehandlinginternetexplorerprocesses"],"categoryId":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","categoryName":"Consistent Mime Handling","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_consistentmimehandlinginternetexplorerprocesses_1","displayName":"Enabled","description":null,"helpText":null}]},"fd7312a8d2006176":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge~defaultsearchprovider_defaultsearchproviderkeyword_defaultsearchproviderkeyword","displayName":"Default search provider keyword (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8aa3383a-efac-4ec4-841d-06e3e18646d8","categoryName":"Default search provider","options":null},"fd32e855d1bc3068":{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu","displayName":"Enables Microsoft Edge mini menu (User)","description":"Enables Microsoft Edge mini menu on websites and PDFs. The mini menu is triggered on text selection and has basic actions like copy and smart actions like definitions.\r\n\r\nIf you enable or don't config this policy, selecting text on websites and PDFs will show the Microsoft Edge mini menu.\r\n\r\nIf you disable this policy, the Microsoft Edge mini menu will not be shown when text on websites and PDFs is selected.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev104~policy~microsoft_edge_quicksearchshowminimenu_1","displayName":"Enabled","description":null,"helpText":null}]},"fd6fb91008208113":{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist","displayName":"Control which apps are forced to be shown in Microsoft Edge sidebar (User)","description":"Define a list of sites, based on URL, that are forced to be shown in sidebar.\r\n\r\nIf you don't configure this policy, no app is forced to be shown in sidebar.\r\n\r\nIf the 'HubsSidebarEnabled' (Show Hubs Sidebar) policy is disabled, this list isn't used and no sidebar can be shown.\r\n\r\nFor detailed information about valid url, see https://go.microsoft.com/fwlink/?linkid=2281313.\r\n\r\nNote: URL patterns are not supported in this policy. You should provide the exact URL of the app.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge_edgesidebarappurlhostforcelist_1","displayName":"Enabled","description":null,"helpText":null}]},"fde53c6949ce489b":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_customhelplink_customhelplink","displayName":"Specify custom help link (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"fdd2684a93b2a03e":{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled","displayName":"Enable stricter treatment for mixed content (User)","description":"This policy controls the treatment for mixed content (HTTP content in HTTPS sites) in the browser.\r\n\r\nIf you set this policy to true or not set, audio and video mixed content will be automatically upgraded to HTTPS (that is, the URL will be rewritten as HTTPS, without a fallback if the resource isn’t available over HTTPS) and a 'Not Secure' warning will be shown in the URL bar for image mixed content.\r\n\r\nIf you set the policy to false, auto upgrades will be disabled for audio and video, and no warning will be shown for images.\r\n\r\nThis policy does not affect other types of mixed content other than audio, video, and images.\r\n\r\nThis policy will no longer take effect starting in Microsoft Edge 84.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev81diff~policy~microsoft_edge_strictermixedcontenttreatmentenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fd357d3abfc53e17":{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault","displayName":"Configure Automatic HTTPS (User)","description":"","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_0","displayName":"Automatic HTTPS functionality is disabled.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_1","displayName":"Navigations delivered over HTTP are switched to HTTPS, only on domains likely to support HTTPS.","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev92~policy~microsoft_edge_recommended_automatichttpsdefault_recommended_automatichttpsdefault_2","displayName":"All navigations delivered over HTTP are switched to HTTPS. Connection errors might occur more often.","description":null,"helpText":null}]},"fd82b0609f74e38b":{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist","displayName":"Allow media autoplay on specific sites (User)","description":"Define a list of sites, based on URL patterns, that are allowed to autoplay media.\r\n\r\nIf you don't configure this policy, the global default value from the 'AutoplayAllowed' (Allow media autoplay for websites) policy (if set) or the user's personal configuration is used for all sites.\r\n\r\nFor detailed information about valid url patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.\r\n\r\nNote: * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.contoso.com\r\n[*.]contoso.edu","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev93~policy~microsoft_edge_autoplayallowlist_1","displayName":"Enabled","description":null,"helpText":null}]},"fdd90c4e17978db7":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttablabelreplacework_l_worklabelreplace","displayName":"Label: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"fddefc748cf037c2":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu","displayName":"Papiamentu (User)","description":"Enables the editing language Papiamentu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_papiamentu_1","displayName":"Enabled","description":null,"helpText":null}]},"fddbd2e3386fdbbd":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan","displayName":"Punjabi (Pakistan) (User)","description":"Enables the editing language Punjabi (Pakistan)","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_punjabipakistan_1","displayName":"Enabled","description":null,"helpText":null}]},"fdcb95c021f9f9d1":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu","displayName":"Urdu (User)","description":"Enables the editing language Urdu","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_urdu_1","displayName":"Enabled","description":null,"helpText":null}]},"fd03dab0c71cdd2f":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache14_l_workflowpath494","displayName":"Full URL to the document library with which the workflow is associated (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"fd58ffd5b592bff6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeosmcustomtags_l_officeosmcustomtagstag4","displayName":"Tag 4: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":null},"fde23540dc99275b":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition","displayName":"Auto Numbering Recognition (User)","description":"Checks/Unchecks the option ''Apply numbering to lists automatically''.","helpText":"","infoUrls":[],"categoryId":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","categoryName":"Editing","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_editing_l_autonumberingrecognition_1","displayName":"Enabled","description":null,"helpText":null}]},"fd72957bd9625551":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_calendaroptions~l_microsoftofficeonlinesharing_l_pathtodavserver_l_empty","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"34c07941-8f52-43ad-b0ca-a7284655afb4","categoryName":"Office.com Sharing Service","options":null},"fdb600ca64a812ad":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlooksocialconnector_l_specifyactivityfeedsynchronizationinterval_l_specifyactivityfeedsynchronizationintervalspinid","displayName":"Synchronization interval (in minutes): (User)","description":"","helpText":"","infoUrls":[],"categoryId":"b3e317cd-c580-478e-885c-666ce3079e78","categoryName":"Outlook Social Connector","options":null},"fd1f967cb3f0102a":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox","displayName":"Maximum Number of Online Search Folders per mailbox (User)","description":"Specifies the maximum number of Search Folders that run on the Exchange server. The number of Search Folders running on the client computer is not affected.","helpText":"","infoUrls":[],"categoryId":"fb721630-fc42-465b-ba22-ab670698c8b5","categoryName":"Search Folders","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_searchfolders_l_maximumnumberofonlinesearchfolderspermailbox_1","displayName":"Enabled","description":null,"helpText":null}]},"fdbb32c888d73e69":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_security~l_cryptography_l_requiredcertificateauthority_l_x509issuednthatrestrictschoiceofcertifyingauthorities","displayName":"X.509 issue DN that restricts choice of certifying authorities: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","categoryName":"Cryptography","options":null},"fdea9df4ea9fe2a5":{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"cc50f179-0c39-4486-a555-de5a6e6ed365","categoryName":"Trust Center","options":[{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_proj16v2~policy~l_proj~l_projectoptions~l_security~l_trustcenter_l_trustedloc09_l_allowsubfolders43_1","displayName":"True","description":null,"helpText":null}]},"fd81d90399e0fe31":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc14_l_pathcolon60","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"fd7ef2f89c57ec5e":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible","displayName":"Make hidden markup visible (User)","description":"Checks/unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","categoryName":"Security","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security_l_makehiddenmarkupvisible_1","displayName":"Enabled","description":null,"helpText":null}]},"fd0f2d5eb46ecaa6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid","displayName":"File block setting: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","categoryName":"File Block Settings","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_0","displayName":"Do not block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_2","displayName":"Open/Save blocked, use open policy","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_3","displayName":"Block","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_4","displayName":"Open in Protected View","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_fileblocksettings_l_word2andearlierbinarydocumentsandtemplates_l_word2andearlierbinarydocumentsandtemplatesdropid_5","displayName":"Allow editing and open in Protected View","description":null,"helpText":null}]},"fd579d5d4b6b87e6":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08","displayName":"Trusted Location #8 (User)","description":"This policy setting allows you to specify a location that is used as a trusted source for opening files in this application. Files in trusted locations bypass file validation, active content checks and Protected View. Macros and code in these files will execute without displaying warnings to the user. If you change or add a location make sure that the new location is secured, with only appropriate user permissions to add document/files.\r\n\r\nIf you enable this policy setting, you may specify a folder location, path, and date from which files can the application can open files which run macros without warning. If you check the \"Allow sub folders\" check box, then all sub-folders in the folder you specify will also be trusted.\r\n\r\nIf you disable or do not configure this policy setting, the trusted location is not specified.","helpText":"","infoUrls":[],"categoryId":"fe786056-6f4a-4d16-bff4-5fbb640308d2","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_wordoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc08_1","displayName":"Enabled","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/fe.json b/public/intune-definitions/fe.json index a1d313400189..ddb17a30e644 100644 --- a/public/intune-definitions/fe.json +++ b/public/intune-definitions/fe.json @@ -1 +1 @@ -{"feae16d2e1d55a6c":{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors","displayName":"Invert Colors","description":"If true, allows the user to toggle Invert Colors. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors_true","displayName":"True","description":null,"helpText":null}]},"fe9772151f31aaad":{"id":"com.apple.extensiblesso_platformsso_authenticationmethod","displayName":"Authentication Method","description":"The Platform SSO authentication method to be used with the extension. Requires that the SSO Extension also support the method.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_0","displayName":"Password","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_1","displayName":"UserSecureEnclaveKey","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_2","displayName":"SmartCard","description":null,"helpText":null}]},"fe1c7a25f140071f":{"id":"com.apple.managedclient.preferences_tags_item_key","displayName":"Type of tag","description":"Specify a tag name and its value. The GROUP tag, tags the device with the specified value. The tag is reflected in the portal under the device page and can be used for filtering and grouping devices.","helpText":null,"infoUrls":[],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":{"id":"com.apple.managedclient.preferences_tags_item_key_0","displayName":"GROUP","description":null,"helpText":null}},"fea303365cecb1c3":{"id":"com.apple.networkusagerules_applicationrules","displayName":"Application Rules","description":"An array of application rules, that apply to only managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},"fe81f4cddb1470e0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (Obsolete)","description":"This policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\n\nIf you enable this policy, mutation events continue to be fired, even if they've been disabled by default for normal web users.\n\nIf you disable or don't configure this policy, these events won't be fired.\n\nNote:\nThis policy is a temporary workaround and will be obsolete starting with Microsoft Edge version 137.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fe10824b7d4ecb6c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\n\nPolicy options mapping:\n\n* any (any) = Allow printing with and without background graphics\n\n* enabled (enabled) = Allow printing only with background graphics\n\n* disabled (disabled) = Allow printing only without background graphics\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},"fe5c670612d1b0e7":{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name","displayName":"Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name_1","displayName":"True","description":null,"helpText":null}]},"fe8dbb18d95b9577":{"id":"device_vendor_msft_defender_configuration_dataduplicationmaximumquota","displayName":"Data Duplication Maximum Quota","description":"Defines the maximum data duplication quota in MB that can be collected. When the quota is reached the filter will stop duplicating any data until the service manages to dispatch the existing collected data, thus decreasing the quota again below the maximum. The valid interval is [5-5000] MB. By default, the maximum quota will be 500 MB.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"fe6c9551b59b84ff":{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_matchingid","displayName":"Matching ID","description":"Matching ID (activation code token) for profile download. Must be set by the MDM when the ICCID subtree is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},"fe28db75a3f43805":{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_maximumpinlength","displayName":"Maximum PIN Length","description":"Maximum PIN length configures the maximum number of characters allowed for the PIN. The largest number you can configure for this policy setting is 127. The lowest number you can configure must be larger than the number configured in the Minimum PIN length policy setting or the number 4, whichever is greater.\n\nIf you configure this policy setting, the PIN length must be less than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be less than or equal to 127.\n\nNOTE: If the above specified conditions for the maximum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"fe9af9c0379742bd":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7_1","displayName":"True","description":null,"helpText":null}]},"fe512cf36fa92132":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions","displayName":"MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)","description":"MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxdataretransmissions"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_1","displayName":"Enabled","description":null,"helpText":null}]},"fe8de091be94de09":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline","displayName":"Enable Background Sync for shares in user selected \"Work Offline\" mode","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline_1","displayName":"True","description":null,"helpText":null}]},"fe8ff091758de8da":{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7_packagepointandprintserverlist_edit","displayName":"Enter fully qualified server names","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"fef221b368f05427":{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2","displayName":"Prevent launch an application","description":"Prevents the user from launching an application from a Tablet PC hardware button.\r\n\r\nIf you enable this policy, applications cannot be launched from a hardware button, and \"Launch an application\" is removed from the drop down menu for configuring button actions (in the Tablet PC Control Panel buttons tab).\r\n\r\nIf you disable this policy, applications can be launched from a hardware button.\r\n\r\nIf you do not configure this policy, applications can be launched from a hardware button.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventlaunchapp-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2_1","displayName":"Enabled","description":null,"helpText":null}]},"fee7054059ac68a4":{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota_wfpquota_size","displayName":"Cache size (in MB) (Device)","description":"\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":null},"fe222e05153644e3":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filepathdetails","displayName":"File Path","description":"The path of the directory or file for application of this rule.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},"febd065a7f41dbc8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal","displayName":"Allows a page to perform synchronous XHR requests during page dismissal.","description":"This policy allows an admin to specify that a page may send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to enabled, pages are allowed to send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to disabled or not set, pages are not allowed to send synchronous XHR requests during page dismissal.\r\n\r\nThis policy will be removed in Chrome 93.\r\n\r\nSee https://www.chromestatus.com/feature/4664843055398912 .","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_1","displayName":"Enabled","description":null,"helpText":null}]},"fed8720b62324713":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_clearbrowsingdataonexitlistdesc","displayName":"Clear Browsing Data on Exit (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"fe47691fa8ac61a5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"fe8dfe932d32a6ee":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy","displayName":"Disable SPDY protocol","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy_1","displayName":"Enabled","description":null,"helpText":null}]},"fea805536d2f904c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols","displayName":"Use Legacy Form Controls until M84.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"fe58ed423b7a5086":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled","displayName":"Control the new behavior of HTMLElement.offsetParent","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fea73ade8f4f5422":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dominbatterypercentageallowedtoupload","displayName":"DO Min Battery Percentage Allowed To Upload","description":"Specifies the minimum battery level required for uploading to peers, while on battery power.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dominbatterypercentageallowedtoupload"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"fec82bd1bef992c8":{"id":"device_vendor_msft_policy_config_devicelock_devicepasswordhistory","displayName":"Device Password History","description":"Specifies how many passwords can be stored in the history that can’t be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#devicepasswordhistory"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":null},"fec5b622381f3967":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingieplugin","displayName":"IE plugin","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging of the IE Plugin.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\IEPlugin\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingieplugin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingieplugin_1","displayName":"Enabled","description":null,"helpText":null}]},"fe13091f8a0b5588":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachinterval_profilesreattachinterval","displayName":"Reattach Interval (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"feb2ff066ce43f1e":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting","displayName":"Script ActiveX controls marked safe for scripting","description":"This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script.\n\nIf you enable this policy setting, script interaction can occur automatically without user intervention.\n\nIf you select Prompt in the drop-down box, users are queried to choose whether to allow script interaction.\n\nIf you disable this policy setting, script interaction is prevented from occurring.\n\nIf you do not configure this policy setting, script interaction is prevented from occurring.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_1","displayName":"Enabled","description":null,"helpText":null}]},"fed01b4e366946c9":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer","displayName":"Send all intranet sites to Internet Explorer","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"fed8a31daf55bcaa":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation","displayName":"Set the roaming profile directory","description":"Configures the directory to use to store the roaming copy of profiles.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory to store a roaming copy of the profiles, as long as you've also enabled the 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy. If you disable the 'RoamingProfileSupportEnabled' policy or don't configure it, the value stored in this policy isn't used.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use.\r\n\r\nIf you don't configure this policy, the default roaming profile path is used.\r\n\r\nExample value: ${roaming_app_data}\\edge-profile","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"feb2db17d8dd1a0e":{"id":"device_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\r\n\r\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\r\n\r\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\r\n\r\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\r\n\r\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\r\n\r\nNote: Sites that use WebAssembly (WASM) are not currently supported when 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2195852\r\n\r\nPolicy options mapping:\r\n\r\n* StandardMode (0) = Standard mode\r\n\r\n* BalancedMode (1) = Balanced mode\r\n\r\n* StrictMode (2) = Strict mode\r\n\r\n* BasicMode (2) = Basic mode\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_1","displayName":"Enabled","description":null,"helpText":null}]},"feafe7305a390e55":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_pptviewexe172","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_pptviewexe172_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_pptviewexe172_1","displayName":"True","description":null,"helpText":null}]},"fec0023fb2bbb31f":{"id":"device_vendor_msft_policy_config_privacy_letappsruninbackground_userincontroloftheseapps","displayName":"Let Apps Run In Background User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the background apps privacy setting for the listed Windows apps. This setting overrides the default LetAppsRunInBackground policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsruninbackground_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"fe2c166b5c12c480":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_stun_client_port_range_part_iceclientportrange","displayName":"Port pool size (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":null},"fe6009f9a92ff7ad":{"id":"settings_item_accessibilitysettings_reducetransparencyenabled","displayName":"Reduce Transparency Enabled","description":"If 'true', enables reduced transparency.","helpText":null,"infoUrls":[],"categoryId":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","categoryName":"Accessibility Settings","options":[{"id":"settings_item_accessibilitysettings_reducetransparencyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_reducetransparencyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"febe7f7f3f0cadd4":{"id":"user_vendor_msft_pde_enablepersonaldataencryption","displayName":"Enable Personal Data Encryption (User)","description":"Allows the Admin to enable Personal Data Encryption. Set to '1' to set this policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/personaldataencryption-csp/"],"categoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","categoryName":"Personal Data Encryption","options":[{"id":"user_vendor_msft_pde_enablepersonaldataencryption_0","displayName":"Disable Personal Data Encryption.","description":"Disable Personal Data Encryption.","helpText":null},{"id":"user_vendor_msft_pde_enablepersonaldataencryption_1","displayName":"Enable Personal Data Encryption.","description":"Enable Personal Data Encryption.","helpText":null}]},"feec3bc5eef283ba":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admcomputers_2","displayName":"Administrative Templates (Computers) (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-admcomputers-2"],"categoryId":"73935f55-c845-40ce-819e-838c0041f6fa","categoryName":"Resultant Set of Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admcomputers_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admcomputers_2_1","displayName":"Enabled","description":null,"helpText":null}]},"fe4a32585841e7ce":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote","displayName":"Microsoft OneNote 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2016.\r\nBy default, the user settings of Microsoft OneNote 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_1","displayName":"Enabled","description":null,"helpText":null}]},"fea23dbcefeb0b9d":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016","displayName":"Microsoft Office 365 Lync 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_1","displayName":"Enabled","description":null,"helpText":null}]},"fed1a8cdcbdf6d86":{"id":"user_vendor_msft_policy_config_admx_userprofiles_limitsize_warnusertimeout","displayName":"Remind user every X minutes: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},"fe9066629f243c2a":{"id":"user_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_1","displayName":"Prohibit installing or uninstalling color profiles (User)","description":"This policy setting affects the ability of users to install or uninstall color profiles.\r\n\r\nIf you enable this policy setting, users cannot install new color profiles or uninstall previously installed color profiles.\r\n\r\nIf you disable or do not configure this policy setting, all users can install new color profiles. Standard users can uninstall color profiles that they previously installed. Administrators will be able to uninstall all color profiles.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowscolorsystem#admx-windowscolorsystem-prohibitchanginginstalledprofilelist-1"],"categoryId":"444409a4-8b03-402d-91d0-1cd9565fb0fb","categoryName":"Windows Color System","options":[{"id":"user_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_1_1","displayName":"Enabled","description":null,"helpText":null}]},"fef7bb0479c2731f":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nofilemru","displayName":"Hide the dropdown list of recent files (User)","description":"Removes the list of most recently used files from the Open dialog box.\r\n\r\nIf you disable this setting or do not configure it, the \"File name\" field includes a drop-down list of recently used files. If you enable this setting, the \"File name\" field is a simple text box. Users must browse directories to find a file or type a file name in the text box.\r\n\r\nThis setting, and others in this folder, lets you remove new features added in Windows 2000 Professional, so that the Open dialog box looks like it did in Windows NT 4.0 and earlier. These policies only affect programs that use the standard Open dialog box provided to developers of Windows programs.\r\n\r\nTo see an example of the standard Open dialog box, start Wordpad and, on the File menu, click Open.\r\n\r\nNote: In Windows Vista, this policy setting applies only to applications that are using the Windows XP common dialog box style. This policy setting does not apply to the new Windows Vista common dialog box style. It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nofilemru"],"categoryId":"12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","categoryName":"Common Open File Dialog","options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nofilemru_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nofilemru_1","displayName":"Enabled","description":null,"helpText":null}]},"fee2f2fb0a4b0289":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist_autoplayallowlistdesc","displayName":"Allow media autoplay on a allowlist of URL patterns (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"fe63505de1337b01":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin (User)","description":"\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing will be deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allows to re-enable cross-origin WebAssembly module sharing to offer a longer transition period in the deprecation process.\r\n\r\nWhen set to True, sites can send WebAssembly modules also cross-origin without restrictions.\r\n\r\nWhen set to False or not set, sites can only send WebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fe9b95f58b0ca488":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.\r\n\r\nIf the DnsOverHttpsMode is set to \"secure\" then this policy must be set and not empty.\r\n\r\nIf the DnsOverHttpsMode is set to \"automatic\" and this policy is set then the URI templates specified will be used; if this policy is unset then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.\r\n\r\nIf the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST.\r\n\r\nIncorrectly formatted templates will be ignored.\r\n\r\nExample value: https://dns.example.net/dns-query{?dns}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"fe37d96929088e9a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"fee3bf78cd01d50d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize","displayName":"Set media disk cache size in bytes (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"fef918594081c0be":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent","displayName":"Freeze User-Agent string major version at 99 (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_1","displayName":"Enabled","description":null,"helpText":null}]},"fe2a36fde8f93758":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled","displayName":"Enable Optimization Guide Fetching (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fe4ec56fe0b33f4d":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled","displayName":"Enable zstd content-encoding support (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"feec416251a54ad3":{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprintresourceid","displayName":"Cloud Print Resource Id (User)","description":"Resource URI for which access is being requested by the Enterprise Cloud Print client during OAuth authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprintresourceid"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},"fe7dc8e7dc9f96b9":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowsmartscreenie"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"fe6df2e0ef8187b7":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"fe79ef0d0bf3170c":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowuserdatapersistence"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"fe6dc6d513a8db21":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel","displayName":"Configure Internet Explorer integration (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\n* 0 = None\r\n\r\n* 1 = Internet Explorer mode\r\n\r\n* 2 = Internet Explorer 11","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_1","displayName":"Enabled","description":null,"helpText":null}]},"fe4e0f1f61c276fd":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\r\n\r\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\n* 1 = Restore the last session\r\n\r\n* 4 = Open a list of URLs\r\n\r\n* 5 = Open a new tab","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fe7b2c377bd37903":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin","displayName":"Minimum TLS version enabled (User)","description":"Sets the minimum supported version of SSL. If you don't configure this policy, Microsoft Edge uses a default minimum version, TLS 1.0.\r\n\r\nIf you enable this policy, you can set the minimum version to one of the following values: \"tls1\", \"tls1.1\" or \"tls1.2\". When set, Microsoft Edge won't use any version of SSL/TLS lower than the specified version. Any unrecognized value is ignored.\r\n\r\n* \"tls1\" = TLS 1.0\r\n\r\n* \"tls1.1\" = TLS 1.1\r\n\r\n* \"tls1.2\" = TLS 1.2\r\n\r\nExample value: tls1","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_1","displayName":"Enabled","description":null,"helpText":null}]},"feee67a93ab53dfa":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended","displayName":"Allow features to download assets from the Asset Delivery Service (User)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\r\nThese assets can be config files or Machine Learning models that power the features that use this service.\r\n\r\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\r\n\r\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fe0c2e6841d876a3":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls_automaticdownloadsallowedforurlsdesc","displayName":"Allow multiple automatic downloads in quick succession on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"fe74c673726363fb":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (User)","description":"Controls whether ads are blocked on sites with intrusive ads. You can set this policy to one of the following options:\r\n\r\n* 1 = Allow ads on all sites.\r\n\r\n* 2 = Block ads on sites with intrusive ads (Default value).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_1","displayName":"Enabled","description":null,"helpText":null}]},"fe93165ca51b84a3":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar","displayName":"Force direct intranet site navigation instead of searching on single word entries in the Address Bar (User)","description":"If you enable this policy, the top auto-suggest result in the address bar suggestion list will navigate to intranet sites if the text entered in the address bar is a single word without punctuation.\r\n\r\nDefault navigation when typing a single word without punctuation will conduct a navigation to an intranet site matching the entered text.\r\n\r\nIf you enable this policy, the second auto-suggest result in the address bar suggestion list will conduct a web search exactly as it was entered, provided that this text is a single word without punctuation. The default search provider will be used unless a policy to prevent web search is also enabled.\r\n\r\nTwo effects of enabling this policy are:\r\n\r\nNavigation to sites in response to single word queries that would typically resolve to a history item will no longer happen. Instead, the browser will attempt navigate to internal sites that may not exist in an organization’s intranet. This will result in a 404 error.\r\n\r\nPopular, single-word search terms will require manual selection of search suggestions to properly conduct a search.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},"fee9a0437cd55c52":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check (User)","description":"Hostnames specified in this list will be exempt from the HSTS policy check that could potentially upgrade requests from \"http://\" to \"https://\". Only single-label hostnames are allowed in this policy. Hostnames must be canonicalized. Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific hostnames specified; it doesn't apply to subdomains of the names in the list.\r\n\r\nExample value:\r\n\r\nmeet","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},"fec0b0e7d8bb5035":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled","displayName":"Hide the one-time redirection dialog and the banner on Microsoft Edge (User)","description":"This policy gives an option to disable one-time redirection dialog and the banner. When this policy is enabled, users will not see both the one-time dialog and the banner.\r\nUsers will continue to be redirected to Microsoft Edge when they encounter an incompatible website on Internet Explorer, but their browsing data will not be imported.\r\n\r\n- If you enable this policy the one-time redirection dialog and banner will never be shown to users. Users' browsing data will not be imported when a redirection happens.\r\n\r\n- If you disable or don't set this policy, the redirection dialog will be shown on the first redirection and the persistent redirection banner will be shown to users on sessions that begin with a redirection. Users' browsing data will be imported every time user encounters such redirection (ONLY IF user consents to it on the one-time dialog).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fe47a1db376f7a60":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd_l_otheraddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"fe37105d27a28eab":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},"fe7ea477e1acabd3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess_1","displayName":"True","description":null,"helpText":null}]},"fe45e84ce0cae218":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde","displayName":"Fulfulde (User)","description":"Enables the editing language Fulfulde","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde_1","displayName":"Enabled","description":null,"helpText":null}]},"fe6a812246f4c446":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian","displayName":"Persian (User)","description":"Enables the editing language Persian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian_1","displayName":"Enabled","description":null,"helpText":null}]},"feffe1fb455d75d0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowdescrip","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"fe857358859f6eb5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_pathcolon254","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"fed19d4db0bf3a93":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_datecolon303","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"fe90bb8a0fd20bd6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14_1","displayName":"True","description":null,"helpText":null}]},"fe2935495f94b4da":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles","displayName":"Enable ability to optimize OneNote files... (User)","description":"Checks/Unchecks the option ''Optimize sections after OneNote has been inactive for the following number of minutes''.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"fece68d0319ec057":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},"feb99c0a3885d746":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat","displayName":"Exchange Unicode Mode - Ignore OST Format (User)","description":"This policy setting allows you to specify whether existing OST format determines the mailbox mode.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n* OST Format determines mode: the format of the user's OST file will be used to determine whether to run in Unicode or ANSI mode.\r\n* Create new OST if format doesn't match mode: create a new OST file if needed.\r\n* Prompt to create new OST if format doesn't match mode\r\n\r\nIf you disable or do not configure this policy setting, you will not be able to specify whether existing OST format determines the mailbox mode.\r\n\r\nThis policy is ignored if PreferANSI is not set and the OST is enabled but either does not exist or is a Unicode OST, because it would be impossible for the user to create an ANSI OST.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_1","displayName":"Enabled","description":null,"helpText":null}]},"fe28d6a72b16cfd5":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"fe1b882cdadc5aaa":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_1","displayName":"True","description":null,"helpText":null}]},"fefc1884ec3f89df":{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall","displayName":"Enable Private Network Firewall","description":"This value is an on/off switch for the firewall and advanced security enforcement. If this value is false, the server MUST NOT block any network traffic, regardless of other policy settings. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]}} \ No newline at end of file +{"feae16d2e1d55a6c":{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors","displayName":"Invert Colors","description":"If true, allows the user to toggle Invert Colors. ","helpText":null,"infoUrls":[],"categoryId":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","categoryName":"App Lock","options":[{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.app.lock_app_userenabledoptions_invertcolors_true","displayName":"True","description":null,"helpText":null}]},"fe9772151f31aaad":{"id":"com.apple.extensiblesso_platformsso_authenticationmethod","displayName":"Authentication Method","description":"The Platform SSO authentication method to be used with the extension. Requires that the SSO Extension also support the method.","helpText":null,"infoUrls":[],"categoryId":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","categoryName":"Extensible Single Sign On (SSO)","options":[{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_0","displayName":"Password","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_1","displayName":"UserSecureEnclaveKey","description":null,"helpText":null},{"id":"com.apple.extensiblesso_platformsso_authenticationmethod_2","displayName":"SmartCard","description":null,"helpText":null}]},"fe1c7a25f140071f":{"id":"com.apple.managedclient.preferences_tags_item_key","displayName":"Type of tag","description":"Specify a tag name and its value. The GROUP tag, tags the device with the specified value. The tag is reflected in the portal under the device page and can be used for filtering and grouping devices.","helpText":null,"infoUrls":[],"categoryId":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","categoryName":"Endpoint Detection and Response (EDR) preferences","options":{"id":"com.apple.managedclient.preferences_tags_item_key_0","displayName":"GROUP","description":null,"helpText":null}},"fea303365cecb1c3":{"id":"com.apple.networkusagerules_applicationrules","displayName":"Application Rules","description":"An array of application rules, that apply to only managed apps.","helpText":null,"infoUrls":[],"categoryId":"06a85f5b-2614-4467-91cf-4a64d0c9326f","categoryName":"Network Usage Rules","options":null},"fe81f4cddb1470e0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled","displayName":"Enable deprecated/removed Mutation Events (Obsolete)","description":"This policy provides a temporary opt-in back to a deprecated and removed set of platform events named Mutation Events.\n\nIf you enable this policy, mutation events continue to be fired, even if they've been disabled by default for normal web users.\n\nIf you disable or don't configure this policy, these events won't be fired.\n\nNote:\nThis policy is a temporary workaround and will be obsolete starting with Microsoft Edge version 137.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.mutationeventsenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"fe10824b7d4ecb6c":{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes","displayName":"Restrict background graphics printing mode","description":"Restricts background graphics printing mode. If this policy isn't set there's no restriction on printing background graphics.\n\nPolicy options mapping:\n\n* any (any) = Allow printing with and without background graphics\n\n* enabled (enabled) = Allow printing only with background graphics\n\n* disabled (disabled) = Allow printing only without background graphics\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"c6099521-a05f-480a-8562-7e71318e2cda","categoryName":"Printing","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_any","displayName":"Allow printing with and without background graphics","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_enabled","displayName":"Allow printing only with background graphics","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.printingallowedbackgroundgraphicsmodes_disabled","displayName":"Allow printing only without background graphics","description":null,"helpText":null}]},"fe5c670612d1b0e7":{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name","displayName":"Allow BitLocker without a compatible TPM (requires a password or a startup key on a USB flash drive)","description":"","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/bitlocker-csp"],"categoryId":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","categoryName":"Operating System Drives","options":[{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_bitlocker_systemdrivesrequirestartupauthentication_configurenontpmstartupkeyusage_name_1","displayName":"True","description":null,"helpText":null}]},"fe8dbb18d95b9577":{"id":"device_vendor_msft_defender_configuration_dataduplicationmaximumquota","displayName":"Data Duplication Maximum Quota","description":"Defines the maximum data duplication quota in MB that can be collected. When the quota is reached the filter will stop duplicating any data until the service manages to dispatch the existing collected data, thus decreasing the quota again below the maximum. The valid interval is [5-5000] MB. By default, the maximum quota will be 500 MB.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/Defender-csp/"],"categoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","categoryName":"Defender","options":null},"fe6c9551b59b84ff":{"id":"device_vendor_msft_euiccs_{euicc}_profiles_{iccid}_matchingid","displayName":"Matching ID","description":"Matching ID (activation code token) for profile download. Must be set by the MDM when the ICCID subtree is created.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/eUICCs-csp/"],"categoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","categoryName":"eSIM","options":null},"fe28db75a3f43805":{"id":"device_vendor_msft_passportforwork_{tenantid}_policies_pincomplexity_maximumpinlength","displayName":"Maximum PIN Length","description":"Maximum PIN length configures the maximum number of characters allowed for the PIN. The largest number you can configure for this policy setting is 127. The lowest number you can configure must be larger than the number configured in the Minimum PIN length policy setting or the number 4, whichever is greater.\n\nIf you configure this policy setting, the PIN length must be less than or equal to this number.\n\nIf you do not configure this policy setting, the PIN length must be less than or equal to 127.\n\nNOTE: If the above specified conditions for the maximum PIN length are not met, default values will be used for both the maximum and minimum PIN lengths.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/PassportForWork-csp/"],"categoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","categoryName":"Windows Hello For Business","options":null},"fe9af9c0379742bd":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7","displayName":"Process even if the Group Policy objects have not changed","description":null,"helpText":"","infoUrls":[],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_scripts_cse_nochanges7_1","displayName":"True","description":null,"helpText":null}]},"fe512cf36fa92132":{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions","displayName":"MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)","description":"MSS: (TcpMaxDataRetransmissions) How many times unacknowledged data is retransmitted (3 recommended, 5 is default)\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mss-legacy#admx-mss-legacy-pol-mss-tcpmaxdataretransmissions"],"categoryId":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","categoryName":"MSS (Legacy)","options":[{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_mss-legacy_pol_mss_tcpmaxdataretransmissions_1","displayName":"Enabled","description":null,"helpText":null}]},"fe8de091be94de09":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline","displayName":"Enable Background Sync for shares in user selected \"Work Offline\" mode","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":[{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_backgroundsyncsettings_lbl_backgroundsyncinforcedoffline_1","displayName":"True","description":null,"helpText":null}]},"fe8ff091758de8da":{"id":"device_vendor_msft_policy_config_admx_printing_packagepointandprintserverlist_win7_packagepointandprintserverlist_edit","displayName":"Enter fully qualified server names","description":null,"helpText":"","infoUrls":[],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":null},"fef221b368f05427":{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2","displayName":"Prevent launch an application","description":"Prevents the user from launching an application from a Tablet PC hardware button.\r\n\r\nIf you enable this policy, applications cannot be launched from a hardware button, and \"Launch an application\" is removed from the drop down menu for configuring button actions (in the Tablet PC Control Panel buttons tab).\r\n\r\nIf you disable this policy, applications can be launched from a hardware button.\r\n\r\nIf you do not configure this policy, applications can be launched from a hardware button.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-tabletshell#admx-tabletshell-preventlaunchapp-2"],"categoryId":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","categoryName":"Hardware Buttons","options":[{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_tabletshell_preventlaunchapp_2_1","displayName":"Enabled","description":null,"helpText":null}]},"fee7054059ac68a4":{"id":"device_vendor_msft_policy_config_admx_windowsfileprotection_wfpquota_wfpquota_size","displayName":"Cache size (in MB) (Device)","description":"\r\n This setting is only available to Windows Insiders","helpText":"","infoUrls":[],"categoryId":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","categoryName":"Windows File Protection","options":null},"fe222e05153644e3":{"id":"device_vendor_msft_policy_config_applicationcontrolv2_supplementalpolicy_buildoptions_{ruleid}_type_filepathdetails","displayName":"File Path","description":"The path of the directory or file for application of this rule.","helpText":null,"infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/applicationcontrol-csp"],"categoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","categoryName":"App Control for Business","options":null},"febd065a7f41dbc8":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal","displayName":"Allows a page to perform synchronous XHR requests during page dismissal.","description":"This policy allows an admin to specify that a page may send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to enabled, pages are allowed to send synchronous XHR requests during page dismissal.\r\n\r\nWhen the policy is set to disabled or not set, pages are not allowed to send synchronous XHR requests during page dismissal.\r\n\r\nThis policy will be removed in Chrome 93.\r\n\r\nSee https://www.chromestatus.com/feature/4664843055398912 .","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_allowsyncxhrinpagedismissal_1","displayName":"Enabled","description":null,"helpText":null}]},"fed8720b62324713":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clearbrowsingdataonexitlist_clearbrowsingdataonexitlistdesc","displayName":"Clear Browsing Data on Exit (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"fe47691fa8ac61a5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemreadblockedforurls_filesystemreadblockedforurlsdesc","displayName":"Block read access via the File System API on these sites (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":null},"fe8dfe932d32a6ee":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy","displayName":"Disable SPDY protocol","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_disablespdy_1","displayName":"Enabled","description":null,"helpText":null}]},"fea805536d2f904c":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols","displayName":"Use Legacy Form Controls until M84.","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_uselegacyformcontrols_1","displayName":"Enabled","description":null,"helpText":null}]},"fe58ed423b7a5086":{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled","displayName":"Control the new behavior of HTMLElement.offsetParent","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_offsetparentnewspecbehaviorenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fea73ade8f4f5422":{"id":"device_vendor_msft_policy_config_deliveryoptimization_dominbatterypercentageallowedtoupload","displayName":"DO Min Battery Percentage Allowed To Upload","description":"Specifies the minimum battery level required for uploading to peers, while on battery power.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-DeliveryOptimization#dominbatterypercentageallowedtoupload"],"categoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","categoryName":"Delivery Optimization","options":null},"fec82bd1bef992c8":{"id":"device_vendor_msft_policy_config_devicelock_devicepasswordhistory","displayName":"Device Password History","description":"Specifies how many passwords can be stored in the history that can’t be used.","helpText":"","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/policy-csp-devicelock#devicepasswordhistory"],"categoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","categoryName":"Device Lock","options":null},"fec5b622381f3967":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingieplugin","displayName":"IE plugin","description":"NOTE: Once this policy is Enabled or Disabled, setting it back to Not Configured has NO EFFECT.\r\n\r\nEnables logging of the IE Plugin.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\FSLogix\\Logging\\IEPlugin\r\nType: DWORD\r\nValues: 0 = Disabled, 1 = Enabled","helpText":"","infoUrls":[],"categoryId":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","categoryName":"Logging","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingieplugin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~logging_loggingieplugin_1","displayName":"Enabled","description":null,"helpText":null}]},"fe13091f8a0b5588":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~profiles_profilesreattachinterval_profilesreattachinterval","displayName":"Reattach Interval (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","categoryName":"Profile Containers","options":null},"feb2ff066ce43f1e":{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting","displayName":"Script ActiveX controls marked safe for scripting","description":"This policy setting allows you to manage whether an ActiveX control marked safe for scripting can interact with a script.\n\nIf you enable this policy setting, script interaction can occur automatically without user intervention.\n\nIf you select Prompt in the drop-down box, users are queried to choose whether to allow script interaction.\n\nIf you disable this policy setting, script interaction is prevented from occurring.\n\nIf you do not configure this policy setting, script interaction is prevented from occurring.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting"],"categoryId":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","categoryName":"Restricted Sites Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_restrictedsiteszonescriptactivexcontrolsmarkedsafeforscripting_1","displayName":"Enabled","description":null,"helpText":null}]},"fed01b4e366946c9":{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer","displayName":"Send all intranet sites to Internet Explorer","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sendintranettointernetexplorer_1","displayName":"Enabled","description":null,"helpText":null}]},"fed8a31daf55bcaa":{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation","displayName":"Set the roaming profile directory","description":"Configures the directory to use to store the roaming copy of profiles.\r\n\r\nIf you enable this policy, Microsoft Edge uses the provided directory to store a roaming copy of the profiles, as long as you've also enabled the 'RoamingProfileSupportEnabled' (Enable using roaming copies for Microsoft Edge profile data) policy. If you disable the 'RoamingProfileSupportEnabled' policy or don't configure it, the value stored in this policy isn't used.\r\n\r\nSee https://go.microsoft.com/fwlink/?linkid=2095041 for a list of variables you can use.\r\n\r\nIf you don't configure this policy, the default roaming profile path is used.\r\n\r\nExample value: ${roaming_app_data}\\edge-profile","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev85diff~policy~microsoft_edge_roamingprofilelocation_1","displayName":"Enabled","description":null,"helpText":null}]},"feb2db17d8dd1a0e":{"id":"device_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode","displayName":"Enhance the security state in Microsoft Edge","description":"This policy lets you enhance the security state in Microsoft Edge.\r\n\r\nIf you set this policy to 'StandardMode', the enhanced mode will be turned off and Microsoft Edge will fallback to its standard security mode.\r\n\r\nIf you set this policy to 'BalancedMode', the security state will be in balanced mode.\r\n\r\nIf you set this policy to 'StrictMode', the security state will be in strict mode.\r\n\r\nIf you set this policy to 'BasicMode', the security state will be in basic mode.\r\n\r\nNote: Sites that use WebAssembly (WASM) are not currently supported when 'EnhanceSecurityMode' (Enhance the security state in Microsoft Edge) is enabled. If you require access to a site that uses WASM, consider adding it to your exception list as described in https://go.microsoft.com/fwlink/?linkid=2183321.\r\n\r\nFor detailed information about Enhanced Security Mode, see https://go.microsoft.com/fwlink/?linkid=2195852\r\n\r\nPolicy options mapping:\r\n\r\n* StandardMode (0) = Standard mode\r\n\r\n* BalancedMode (1) = Balanced mode\r\n\r\n* StrictMode (2) = Strict mode\r\n\r\n* BasicMode (2) = Basic mode\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev98.1~policy~microsoft_edge_enhancesecuritymode_1","displayName":"Enabled","description":null,"helpText":null}]},"feafe7305a390e55":{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_pptviewexe172","displayName":"pptview.exe (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"fa8e7b34-c736-47ec-be83-a9f1960d5281","categoryName":"IE Security","options":[{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_pptviewexe172_0","displayName":"False","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_office16v2~policy~l_microsoftofficemachine~l_securitysettingsmachine~l_iesecurity_l_navigateurl_l_pptviewexe172_1","displayName":"True","description":null,"helpText":null}]},"fec0023fb2bbb31f":{"id":"device_vendor_msft_policy_config_privacy_letappsruninbackground_userincontroloftheseapps","displayName":"Let Apps Run In Background User In Control Of These Apps","description":"List of semi-colon delimited Package Family Names of Windows apps. The user is able to control the background apps privacy setting for the listed Windows apps. This setting overrides the default LetAppsRunInBackground policy setting for the specified Windows apps.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Privacy#letappsruninbackground_userincontroloftheseapps"],"categoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","categoryName":"Privacy","options":null},"fe2c166b5c12c480":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_stun_client_port_range_part_iceclientportrange","displayName":"Port pool size (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":null},"fed044b87deab83d":{"id":"device_vendor_msft_policy_config_update_maintenancewindowdurationhours","displayName":"Maintenance Window Duration Hours","description":"Configure the duration of the maintenance window in hours. Minimum value is 2, maximum value is 24.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowdurationhours"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":null},"fe6d39aa37f8c738":{"id":"device_vendor_msft_policy_config_update_maintenancewindowupdateactions","displayName":"Maintenance Window Update Actions","description":"Specifies which update operations are allowed only during the maintenance window, 1 = Download, install and restart, 2 = Install and restart, 3 = Restart only.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Update#maintenancewindowupdateactions"],"categoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","categoryName":"Windows Update For Business","options":[{"id":"device_vendor_msft_policy_config_update_maintenancewindowupdateactions_1","displayName":"Download, install and restart","description":"Download, install and restart","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowupdateactions_2","displayName":"Install and restart","description":"Install and restart","helpText":null},{"id":"device_vendor_msft_policy_config_update_maintenancewindowupdateactions_3","displayName":"Restart only","description":"Restart only","helpText":null}]},"fe6009f9a92ff7ad":{"id":"settings_item_accessibilitysettings_reducetransparencyenabled","displayName":"Reduce Transparency Enabled","description":"If 'true', enables reduced transparency.","helpText":null,"infoUrls":[],"categoryId":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","categoryName":"Accessibility Settings","options":[{"id":"settings_item_accessibilitysettings_reducetransparencyenabled_false","displayName":"Disabled","description":null,"helpText":null},{"id":"settings_item_accessibilitysettings_reducetransparencyenabled_true","displayName":"Enabled","description":null,"helpText":null}]},"febe7f7f3f0cadd4":{"id":"user_vendor_msft_pde_enablepersonaldataencryption","displayName":"Enable Personal Data Encryption (User)","description":"Allows the Admin to enable Personal Data Encryption. Set to '1' to set this policy.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/personaldataencryption-csp/"],"categoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","categoryName":"Personal Data Encryption","options":[{"id":"user_vendor_msft_pde_enablepersonaldataencryption_0","displayName":"Disable Personal Data Encryption.","description":"Disable Personal Data Encryption.","helpText":null},{"id":"user_vendor_msft_pde_enablepersonaldataencryption_1","displayName":"Enable Personal Data Encryption.","description":"Enable Personal Data Encryption.","helpText":null}]},"feec3bc5eef283ba":{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admcomputers_2","displayName":"Administrative Templates (Computers) (User)","description":"This policy setting permits or prohibits the use of this snap-in. \n\nIf you enable this policy setting, the snap-in is permitted and can be added into the Microsoft Management Console or run from the command line as a standalone console. \n\nIf you disable this policy setting, the snap-in is prohibited and cannot be added into the Microsoft Management Console or run from the command line as a standalone console. An error message is displayed stating that policy is prohibiting the use of this snap-in. \n\nIf this policy setting is not configured, the setting of the \"Restrict users to the explicitly permitted list of snap-ins\" setting determines whether this snap-in is permitted or prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is enabled, users cannot use any snap-in except those explicitly permitted. To explicitly permit use of this snap-in, enable this policy setting. If this policy setting is not configured or disabled, this snap-in is prohibited. \n\n-- If the policy setting \"Restrict users to the explicitly permitted list of snap-ins\" is disabled or not configured, users can use any snap-in except those explicitly prohibited. To explicitly prohibit use of this snap-in, disable this policy setting. If this policy setting is not configured or enabled, the snap-in is permitted. \n\nWhen a snap-in is prohibited, it does not appear in the Add/Remove Snap-in window in MMC. Also, when a user opens a console file that includes a prohibited snap-in, the console file opens, but the prohibited snap-in does not appear.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-mmcsnapins#admx-mmcsnapins-mmc-admcomputers-2"],"categoryId":"73935f55-c845-40ce-819e-838c0041f6fa","categoryName":"Resultant Set of Policy snap-in extensions","options":[{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admcomputers_2_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_mmcsnapins_mmc_admcomputers_2_1","displayName":"Enabled","description":null,"helpText":null}]},"fe4a32585841e7ce":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote","displayName":"Microsoft OneNote 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft OneNote 2016.\r\nBy default, the user settings of Microsoft OneNote 2016 synchronize between computers. Use the policy setting to prevent the user settings of Microsoft OneNote 2016 from synchronization between computers.\r\nIf you enable this policy setting, Microsoft OneNote 2016 user settings continue to synchronize.\r\nIf you disable this policy setting, Microsoft OneNote 2016 user settings are excluded from the synchronization settings.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice2016onenote"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice2016onenote_1","displayName":"Enabled","description":null,"helpText":null}]},"fea23dbcefeb0b9d":{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016","displayName":"Microsoft Office 365 Lync 2016 (User)","description":"\r\nThis policy setting configures the synchronization of user settings for Microsoft Office 365 Lync 2016.\r\nMicrosoft Office 365 synchronizes certain settings by default without UE-V. If the synchronization capabilities of Microsoft Office 365 are disabled, then the user settings of Microsoft Office 365 Lync 2016 will synchronize between a user’s work computers with UE-V by default. Use this policy setting to prevent the user settings of Microsoft Office 365 Lync 2016 from synchronization between computers with UE-V.\r\nIf you enable this policy setting, Microsoft Office 365 Lync 2016 user settings continue to sync with UE-V.\r\nIf you disable this policy setting, Microsoft Office 365 Lync 2016 user settings are excluded from synchronization with UE-V.\r\nIf you do not configure this policy setting, any defined values will be deleted.\r\n \r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-userexperiencevirtualization#admx-userexperiencevirtualization-microsoftoffice365lync2016"],"categoryId":"5966d21b-220b-4937-9323-c6dd46cda942","categoryName":"Applications","options":[{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_userexperiencevirtualization_microsoftoffice365lync2016_1","displayName":"Enabled","description":null,"helpText":null}]},"fed1a8cdcbdf6d86":{"id":"user_vendor_msft_policy_config_admx_userprofiles_limitsize_warnusertimeout","displayName":"Remind user every X minutes: (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","categoryName":"User Profiles","options":null},"fe9066629f243c2a":{"id":"user_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_1","displayName":"Prohibit installing or uninstalling color profiles (User)","description":"This policy setting affects the ability of users to install or uninstall color profiles.\r\n\r\nIf you enable this policy setting, users cannot install new color profiles or uninstall previously installed color profiles.\r\n\r\nIf you disable or do not configure this policy setting, all users can install new color profiles. Standard users can uninstall color profiles that they previously installed. Administrators will be able to uninstall all color profiles.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowscolorsystem#admx-windowscolorsystem-prohibitchanginginstalledprofilelist-1"],"categoryId":"444409a4-8b03-402d-91d0-1cd9565fb0fb","categoryName":"Windows Color System","options":[{"id":"user_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_1_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowscolorsystem_prohibitchanginginstalledprofilelist_1_1","displayName":"Enabled","description":null,"helpText":null}]},"fef7bb0479c2731f":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nofilemru","displayName":"Hide the dropdown list of recent files (User)","description":"Removes the list of most recently used files from the Open dialog box.\r\n\r\nIf you disable this setting or do not configure it, the \"File name\" field includes a drop-down list of recently used files. If you enable this setting, the \"File name\" field is a simple text box. Users must browse directories to find a file or type a file name in the text box.\r\n\r\nThis setting, and others in this folder, lets you remove new features added in Windows 2000 Professional, so that the Open dialog box looks like it did in Windows NT 4.0 and earlier. These policies only affect programs that use the standard Open dialog box provided to developers of Windows programs.\r\n\r\nTo see an example of the standard Open dialog box, start Wordpad and, on the File menu, click Open.\r\n\r\nNote: In Windows Vista, this policy setting applies only to applications that are using the Windows XP common dialog box style. This policy setting does not apply to the new Windows Vista common dialog box style. It is a requirement for third-party applications with Windows 2000 or later certification to adhere to this setting.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-windowsexplorer#admx-windowsexplorer-nofilemru"],"categoryId":"12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","categoryName":"Common Open File Dialog","options":[{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nofilemru_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_nofilemru_1","displayName":"Enabled","description":null,"helpText":null}]},"fee2f2fb0a4b0289":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoplayallowlist_autoplayallowlistdesc","displayName":"Allow media autoplay on a allowlist of URL patterns (User)","description":"","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":null},"fe63505de1337b01":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled","displayName":"Specifies whether WebAssembly modules can be sent cross-origin (User)","description":"\r\nSpecifies whether WebAssembly modules can be sent to another window or worker cross-origin. Cross-origin WebAssembly module sharing will be deprecated as part of the efforts to deprecate document.domain, see https://github.com/mikewest/deprecating-document-domain. This policy allows to re-enable cross-origin WebAssembly module sharing to offer a longer transition period in the deprecation process.\r\n\r\nWhen set to True, sites can send WebAssembly modules also cross-origin without restrictions.\r\n\r\nWhen set to False or not set, sites can only send WebAssembly modules to windows and workers in the same origin.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_crossoriginwebassemblymodulesharingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fe9b95f58b0ca488":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates","displayName":"Specify URI template of desired DNS-over-HTTPS resolver (User)","description":"The URI template of the desired DNS-over-HTTPS resolver. To specify multiple DNS-over-HTTPS resolvers, separate the corresponding URI templates with spaces.\r\n\r\nIf the DnsOverHttpsMode is set to \"secure\" then this policy must be set and not empty.\r\n\r\nIf the DnsOverHttpsMode is set to \"automatic\" and this policy is set then the URI templates specified will be used; if this policy is unset then hardcoded mappings will be used to attempt to upgrade the user's current DNS resolver to a DoH resolver operated by the same provider.\r\n\r\nIf the URI template contains a dns variable, requests to the resolver will use GET; otherwise requests will use POST.\r\n\r\nIncorrectly formatted templates will be ignored.\r\n\r\nExample value: https://dns.example.net/dns-query{?dns}","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_dnsoverhttpstemplates_1","displayName":"Enabled","description":null,"helpText":null}]},"fe37d96929088e9a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~defaultsearchprovider_defaultsearchprovidersearchurl_defaultsearchprovidersearchurl","displayName":"Default search provider search URL (User)","description":"","helpText":"","infoUrls":[],"categoryId":"70498fad-5ddb-4730-8130-d755ff675760","categoryName":"Default search provider","options":null},"fee3bf78cd01d50d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize","displayName":"Set media disk cache size in bytes (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~removedpolicies_mediacachesize_1","displayName":"Enabled","description":null,"helpText":null}]},"fef918594081c0be":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent","displayName":"Freeze User-Agent string major version at 99 (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_forcemajorversiontominorpositioninuseragent_1","displayName":"Enabled","description":null,"helpText":null}]},"fe2a36fde8f93758":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled","displayName":"Enable Optimization Guide Fetching (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_optimizationguidefetchingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fe4ec56fe0b33f4d":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled","displayName":"Enable zstd content-encoding support (User)","description":"This policy is removed. It is not compatible with this version of Google Chrome. Read more at https://support.google.com/chrome/a/answer/7643500","helpText":"","infoUrls":[],"categoryId":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","categoryName":"Removed policies","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome~removedpolicies_zstdcontentencodingenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"feec416251a54ad3":{"id":"user_vendor_msft_policy_config_enterprisecloudprint_cloudprintresourceid","displayName":"Cloud Print Resource Id (User)","description":"Resource URI for which access is being requested by the Enterprise Cloud Print client during OAuth authentication","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-EnterpriseCloudPrint#cloudprintresourceid"],"categoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","categoryName":"Enterprise Cloud Print","options":null},"fe7dc8e7dc9f96b9":{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie","displayName":"Turn on SmartScreen Filter scan (User)","description":"This policy setting controls whether SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you enable this policy setting, SmartScreen Filter scans pages in this zone for malicious content.\n\nIf you disable this policy setting, SmartScreen Filter does not scan pages in this zone for malicious content.\n\nIf you do not configure this policy setting, the user can choose whether SmartScreen Filter scans pages in this zone for malicious content.\n\nNote: In Internet Explorer 7, this policy setting controls whether Phishing Filter scans pages in this zone for malicious content.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-intranetzoneallowsmartscreenie"],"categoryId":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","categoryName":"Intranet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_intranetzoneallowsmartscreenie_1","displayName":"Enabled","description":null,"helpText":null}]},"fe6df2e0ef8187b7":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607","displayName":"Navigate windows and frames across different domains (User)","description":"","helpText":"","infoUrls":[],"categoryId":"ac014aea-e417-46ad-a4a5-9a1fb1030882","categoryName":"Locked- Down Internet Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_0","displayName":"Enable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_3","displayName":"Disable","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowninternetzonenavigatewindowsandframes_iz_partname1607_1","displayName":"Prompt","description":null,"helpText":null}]},"fe79ef0d0bf3170c":{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence","displayName":"Userdata persistence (User)","description":"This policy setting allows you to manage the preservation of information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk. When a user returns to a persisted page, the state of the page can be restored if this policy setting is appropriately configured.\n\nIf you enable this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you disable this policy setting, users cannot preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.\n\nIf you do not configure this policy setting, users can preserve information in the browser's history, in favorites, in an XML store, or directly within a Web page saved to disk.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-lockeddowntrustedsiteszoneallowuserdatapersistence"],"categoryId":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","categoryName":"Locked- Down Trusted Sites Zone","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_lockeddowntrustedsiteszoneallowuserdatapersistence_1","displayName":"Enabled","description":null,"helpText":null}]},"fe6dc6d513a8db21":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel","displayName":"Configure Internet Explorer integration (User)","description":"For guidance about configuring the optimal experience for Internet Explorer mode see https://go.microsoft.com/fwlink/?linkid=2094210\r\n\r\n* 0 = None\r\n\r\n* 1 = Internet Explorer mode\r\n\r\n* 2 = Internet Explorer 11","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_internetexplorerintegrationlevel_1","displayName":"Enabled","description":null,"helpText":null}]},"fe4e0f1f61c276fd":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended","displayName":"Action to take on Microsoft Edge startup (User)","description":"Specify how Microsoft Edge behaves when it starts.\r\n\r\nIf you want a new tab to always open on startup, choose 'Open new tab' (5).\r\n\r\nIf you want to reopen URLs that were open the last time Microsoft Edge closed, choose 'Restore the last session' (1). The browsing session will be restored as it was. Note that this option disables some settings that rely on sessions or that perform actions on exit (such as Clear browsing data on exit or session-only cookies).\r\n\r\nIf you want to open a specific set of URLs, choose 'Open a list of URLs' (4).\r\n\r\nDisabling this setting is equivalent to leaving it not configured. Users will be able to change it in Microsoft Edge.\r\n\r\nThis policy is available only on Windows instances that are joined to a Microsoft Active Directory domain or Windows 10 Pro or Enterprise instances enrolled for device management.\r\n\r\n* 1 = Restore the last session\r\n\r\n* 4 = Open a list of URLs\r\n\r\n* 5 = Open a new tab","helpText":"","infoUrls":[],"categoryId":"1653fa6c-aa99-4918-92c7-1df85d8843e1","categoryName":"Startup, home page and new tab page","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_recommended~startup_recommended_restoreonstartup_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fe7b2c377bd37903":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin","displayName":"Minimum TLS version enabled (User)","description":"Sets the minimum supported version of SSL. If you don't configure this policy, Microsoft Edge uses a default minimum version, TLS 1.0.\r\n\r\nIf you enable this policy, you can set the minimum version to one of the following values: \"tls1\", \"tls1.1\" or \"tls1.2\". When set, Microsoft Edge won't use any version of SSL/TLS lower than the specified version. Any unrecognized value is ignored.\r\n\r\n* \"tls1\" = TLS 1.0\r\n\r\n* \"tls1.1\" = TLS 1.1\r\n\r\n* \"tls1.2\" = TLS 1.2\r\n\r\nExample value: tls1","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_sslversionmin_1","displayName":"Enabled","description":null,"helpText":null}]},"feee67a93ab53dfa":{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended","displayName":"Allow features to download assets from the Asset Delivery Service (User)","description":"The Asset Delivery Service is a general pipeline used to deliver assets to the Microsoft Edge Clients.\r\nThese assets can be config files or Machine Learning models that power the features that use this service.\r\n\r\nIf you enable or don't configure this policy, features can download assets from the Asset Delivery Service.\r\n\r\nIf you disable this policy, features won't be able to download assets needed for them to run correctly.","helpText":"","infoUrls":[],"categoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","categoryName":"Microsoft Edge - Default Settings (users can override)","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev101~policy~microsoft_edge_recommended_edgeassetdeliveryserviceenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fe0c2e6841d876a3":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge~contentsettings_automaticdownloadsallowedforurls_automaticdownloadsallowedforurlsdesc","displayName":"Allow multiple automatic downloads in quick succession on specific sites (User)","description":"","helpText":"","infoUrls":[],"categoryId":"92d69c43-75ac-49b1-a3ef-9350079eef86","categoryName":"Content settings","options":null},"fe74c673726363fb":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites","displayName":"Ads setting for sites with intrusive ads (User)","description":"Controls whether ads are blocked on sites with intrusive ads. You can set this policy to one of the following options:\r\n\r\n* 1 = Allow ads on all sites.\r\n\r\n* 2 = Block ads on sites with intrusive ads (Default value).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_adssettingforintrusiveadssites_1","displayName":"Enabled","description":null,"helpText":null}]},"fe93165ca51b84a3":{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar","displayName":"Force direct intranet site navigation instead of searching on single word entries in the Address Bar (User)","description":"If you enable this policy, the top auto-suggest result in the address bar suggestion list will navigate to intranet sites if the text entered in the address bar is a single word without punctuation.\r\n\r\nDefault navigation when typing a single word without punctuation will conduct a navigation to an intranet site matching the entered text.\r\n\r\nIf you enable this policy, the second auto-suggest result in the address bar suggestion list will conduct a web search exactly as it was entered, provided that this text is a single word without punctuation. The default search provider will be used unless a policy to prevent web search is also enabled.\r\n\r\nTwo effects of enabling this policy are:\r\n\r\nNavigation to sites in response to single word queries that would typically resolve to a history item will no longer happen. Instead, the browser will attempt navigate to internal sites that may not exist in an organization’s intranet. This will result in a 404 error.\r\n\r\nPopular, single-word search terms will require manual selection of search suggestions to properly conduct a search.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev78diff~policy~microsoft_edge_gotointranetsiteforsinglewordentryinaddressbar_1","displayName":"Enabled","description":null,"helpText":null}]},"fee9a0437cd55c52":{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist","displayName":"Configure the list of names that will bypass the HSTS policy check (User)","description":"Hostnames specified in this list will be exempt from the HSTS policy check that could potentially upgrade requests from \"http://\" to \"https://\". Only single-label hostnames are allowed in this policy. Hostnames must be canonicalized. Any IDNs must be converted to their A-label format, and all ASCII letters must be lowercase. This policy only applies to the specific hostnames specified; it doesn't apply to subdomains of the names in the list.\r\n\r\nExample value:\r\n\r\nmeet","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev79diff~policy~microsoft_edge_hstspolicybypasslist_1","displayName":"Enabled","description":null,"helpText":null}]},"fec0b0e7d8bb5035":{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled","displayName":"Hide the one-time redirection dialog and the banner on Microsoft Edge (User)","description":"This policy gives an option to disable one-time redirection dialog and the banner. When this policy is enabled, users will not see both the one-time dialog and the banner.\r\nUsers will continue to be redirected to Microsoft Edge when they encounter an incompatible website on Internet Explorer, but their browsing data will not be imported.\r\n\r\n- If you enable this policy the one-time redirection dialog and banner will never be shown to users. Users' browsing data will not be imported when a redirection happens.\r\n\r\n- If you disable or don't set this policy, the redirection dialog will be shown on the first redirection and the persistent redirection banner will be shown to users on sessions that begin with a redirection. Users' browsing data will be imported every time user encounters such redirection (ONLY IF user consents to it on the one-time dialog).","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev87~policy~microsoft_edge_hideinternetexplorerredirectuxforincompatiblesitesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"fe47a1db376f7a60":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_contactcard~l_contacttab_l_turnoncontacttabmapireplaceotheradd_l_otheraddmapireplace","displayName":"MAPI Property: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"20bacabf-cd07-48be-a184-f0ae76d31e4a","categoryName":"Contact Tab","options":null},"fe37105d27a28eab":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_customizableerrormessages_l_listoferrormessagestocustomize_l_listoferrormessagestocustomize351_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","categoryName":"Customizable Error Messages","options":null},"fe7ea477e1acabd3":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess","displayName":"Disallow in Access (User)","description":"","helpText":"","infoUrls":[],"categoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","categoryName":"Customize","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_gloabloptions~l_customize_l_disabletoolbarcustomizationuipolicy_l_disabletoolbarcustomizationuiaccess_1","displayName":"True","description":null,"helpText":null}]},"fe45e84ce0cae218":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde","displayName":"Fulfulde (User)","description":"Enables the editing language Fulfulde","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_fulfulde_1","displayName":"Enabled","description":null,"helpText":null}]},"fe6a812246f4c446":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian","displayName":"Persian (User)","description":"Enables the editing language Persian","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_persian_1","displayName":"Enabled","description":null,"helpText":null}]},"feffe1fb455d75d0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_miscellaneous437~l_workflowcache_l_workflowcache1_l_workflowdescrip","displayName":"Description of the workflow to be shown to the user (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5f048379-3a42-43f0-9fd5-d269f292aa35","categoryName":"Workflow Cache","options":null},"fe857358859f6eb5":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc05_l_pathcolon254","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"fed19d4db0bf3a93":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241_l_trustedloc17_l_datecolon303","displayName":"Date: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","categoryName":"Trust Center","options":null},"fe90bb8a0fd20bd6":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc14_l_allowsubfolders14_1","displayName":"True","description":null,"helpText":null}]},"fe2935495f94b4da":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles","displayName":"Enable ability to optimize OneNote files... (User)","description":"Checks/Unchecks the option ''Optimize sections after OneNote has been inactive for the following number of minutes''.","helpText":"","infoUrls":[],"categoryId":"acfe6c36-66ab-4a3e-86b0-a178377427d2","categoryName":"Save","options":[{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_save_l_enableabilitytooptimizeonenotefiles_1","displayName":"Enabled","description":null,"helpText":null}]},"fece68d0319ec057":{"id":"user_vendor_msft_policy_config_onent16v2~policy~l_microsoftofficeonenote~l_onenoteoptions~l_security~l_cryptography_l_setcngcipherkeylength_l_setcngcipherkeylengthspinid","displayName":"Cipher key length (User)","description":"","helpText":"","infoUrls":[],"categoryId":"25a84f2d-dbac-457e-b734-bc2605305f2b","categoryName":"Cryptography","options":null},"feb99c0a3885d746":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat","displayName":"Exchange Unicode Mode - Ignore OST Format (User)","description":"This policy setting allows you to specify whether existing OST format determines the mailbox mode.\r\n\r\nIf you enable this policy setting, you may choose one of these options:\r\n\r\n* OST Format determines mode: the format of the user's OST file will be used to determine whether to run in Unicode or ANSI mode.\r\n* Create new OST if format doesn't match mode: create a new OST file if needed.\r\n* Prompt to create new OST if format doesn't match mode\r\n\r\nIf you disable or do not configure this policy setting, you will not be able to specify whether existing OST format determines the mailbox mode.\r\n\r\nThis policy is ignored if PreferANSI is not set and the OST is enabled but either does not exist or is a Unicode OST, because it would be impossible for the user to create an ANSI OST.","helpText":"","infoUrls":[],"categoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","categoryName":"Exchange","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_exchangesettings_l_exchangeunicodemodeignoreostformat_1","displayName":"Enabled","description":null,"helpText":null}]},"fe28d6a72b16cfd5":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_visiooptions~l_security~l_trustcenter_l_trustedloc08_l_descriptioncolon38","displayName":"Description: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","categoryName":"Trust Center","options":null},"fe1b882cdadc5aaa":{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity","displayName":"Developer tab | Code | Macro Security (User)","description":"","helpText":"","infoUrls":[],"categoryId":"44e27b70-4bdb-4aec-a75d-0568a1edc332","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_word16v2~policy~l_microsoftofficeword~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_toolsmacrosecurity_1","displayName":"True","description":null,"helpText":null}]},"fefc1884ec3f89df":{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall","displayName":"Enable Private Network Firewall","description":"This value is an on/off switch for the firewall and advanced security enforcement. If this value is false, the server MUST NOT block any network traffic, regardless of other policy settings. The merge law for this option is to let the value of the GroupPolicyRSoPStore win if it is configured; otherwise, the local store value is used.","helpText":" ","infoUrls":["https://docs.microsoft.com/en-us/windows/client-management/mdm/firewall-csp"],"categoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","categoryName":"Firewall","options":[{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall_false","displayName":"False","description":"Disable Firewall","helpText":null},{"id":"vendor_msft_firewall_mdmstore_privateprofile_enablefirewall_true","displayName":"True","description":"Enable Firewall","helpText":null}]}} \ No newline at end of file diff --git a/public/intune-definitions/ff.json b/public/intune-definitions/ff.json index 8c850218155a..71a1ffd15052 100644 --- a/public/intune-definitions/ff.json +++ b/public/intune-definitions/ff.json @@ -1 +1 @@ -{"ff115805ebde6d36":{"id":"com.android.devicerestrictionpolicy.passwordpreviouspasswordcounttoblock","displayName":"Number of passwords required before user can reuse a password","description":"Use this setting to restrict users from creating previously used passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. If the value is blank, Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-24)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"ffb221d92797bd5b":{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumlettercharacters","displayName":"Number of characters required","description":"Enter the number of characters the work profile password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},"ff8158f5c54071b6":{"id":"com.apple.applicationaccess_allowairplayincomingrequests","displayName":"Allow Air Play Incoming Requests","description":"If false, disables incoming AirPlay requests. Requires a supervised device. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairplayincomingrequests_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairplayincomingrequests_true","displayName":"True","description":null,"helpText":null}]},"ff8e90614f95e8fb":{"id":"com.apple.extensiblesso_extensiondata_pwreqlength_kerberos","displayName":"Password Req Length","description":"The minimum length of passwords on the domain. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"fff5e5103fe3be82":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_lcid","displayName":"Microsoft Edge Dev LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"fff122974f4aec7c":{"id":"com.apple.managedclient.preferences_automaticdownloadsallowedforurls","displayName":"Allow multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticdownloadsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"ff0f10efd62b1545":{"id":"com.apple.managedclient.preferences_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled.\n\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the \"JavaScriptOptimizerAllowedForSites\" policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise Javascript optimization is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptoptimizerallowedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"ff6118376e124538":{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut","displayName":"Create desktop shortcut","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut_true","displayName":"Enabled","description":null,"helpText":null}]},"ffbf3142406455e7":{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (Obsolete)","description":"List of URL patterns. Requests initiated from websites served by matching origins aren't subject to Private Network Access checks.\n\nIf this policy isn't set, this policy behaves as if set to the empty list.\n\nFor origins not covered by the patterns specified here, the global default value is used either from the \"InsecurePrivateNetworkRequestsAllowed\" policy, if it's set, or the user's personal configuration otherwise.\n\nFor detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format).\n\nThis policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.","helpText":null,"infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":null},"ffab0a52434992d3":{"id":"com.microsoft.edge.mamedgeappconfigsettings.serialblockedforurls","displayName":"Block the Serial API on specific sites","description":"Specifies URL patterns for sites that aren't allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. SerialAskForUrls (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nURL patterns in this policy must not conflict with those in SerialAskForUrls. This policy takes precedence.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"fff66343aff4da3b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended","displayName":"Set the default New Tab Page feed tab to Work or Discover (users can override)","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\n\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\n\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\n\nThis policy only takes effect when \"ConfigureNTPFeedTabVisibility\" is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\n\nPolicy options mapping:\n\n* NTPDefaultFeedTabWork (0) = Work\n\n* NTPDefaultFeedTabDiscover (1) = Discover\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended_ntpdefaultfeedtabwork","displayName":"Work","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended_ntpdefaultfeedtabdiscover","displayName":"Discover","description":null,"helpText":null}]},"ff2868a0e8d9e7d0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\n\nIf you enable or don't configure this policy, the button shows up on the native PDF viewer in Microsoft Edge. A user can buy Adobe subscription to access their premium offerings.\n\nIf you disable this policy, the button isn't visible on the native PDF viewer in Microsoft Edge. A user can't discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton_true","displayName":"Enabled","description":null,"helpText":null}]},"ffb0d7ee27f6d8c6":{"id":"device_vendor_msft_laps_policies_adpasswordencryptionprincipal","displayName":"AD Password Encryption Principal ","description":"Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.\n\nThis setting is ignored if the password is currently being stored in Azure.\n\nIf not specified, the password will be decryptable by the Domain Admins group in the device's domain.\n\nIf specified, the specified user or group will be able to decrypt the password stored in Active Directory.\n\nIf the specified user or group account is invalid the device will fallback to using the Domain Admins group in the device's domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},"ff20add57702091d":{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname","displayName":"Name of administrator account to manage","description":"\nAdministrator account name: name of the local account you want to manage password for.\n DO NOT configure when you use built-in admin account. Built-in admin account is auto-detected by well-known SID, even when renamed\n\n DO configure when you use custom local admin account\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd-adminname"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_1","displayName":"Enabled","description":null,"helpText":null}]},"ffaa2f3869c5ff1c":{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist","displayName":"Allow local activation security check exemptions","description":"Allows you to specify that local computer administrators can supplement the \"Define Activation Security Check exemptions\" list.\r\n\r\nIf you enable this policy setting, and DCOM does not find an explicit entry for a DCOM server application id (appid) in the \"Define Activation Security Check exemptions\" policy (if enabled), DCOM will look for an entry in the locally configured list.\r\n\r\nIf you disable this policy setting, DCOM will not look in the locally configured DCOM activation security check exemption list.\r\n\r\nIf you do not configure this policy setting, DCOM will only look in the locally configured exemption list if the \"Define Activation Security Check exemptions\" policy is not configured.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dcom#admx-dcom-dcomactivationsecuritycheckallowlocallist"],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":[{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist_1","displayName":"Enabled","description":null,"helpText":null}]},"ffa883ea85cd3e16":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box","displayName":"Update security level:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_256","displayName":"Only secure","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_16","displayName":"Only unsecure","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_0","displayName":"Unsecure followed by secure","description":null,"helpText":null}]},"ff5a0428f0bab998":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},"ffd480955c570d89":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt","displayName":"Configure software Installation policy processing","description":"This policy setting determines when software installation policies are updated.\r\n\r\nThis policy setting affects all policy settings that use the software installation component of Group Policy, such as policy settings in Software Settings\\Software Installation. You can set software installation policy only for Group Policy Objects stored in Active Directory, not for Group Policy Objects on the local computer.\r\n\r\nThis policy setting overrides customized settings that the program implementing the software installation policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy setting implementations specify that they are updated only when changed. However, you might want to update unchanged policy settings, such as reapplying a desired policies in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-appmgmt"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_1","displayName":"Enabled","description":null,"helpText":null}]},"ff6e2ee814e754cd":{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate","displayName":"Turn off Windows Update device driver searching","description":"This policy setting specifies whether Windows searches Windows Update for device drivers when no local drivers for a device are present.\r\n\r\nIf you enable this policy setting, Windows Update is not searched when a new device is installed.\r\n\r\nIf you disable this policy setting, Windows Update is always searched for drivers when no local drivers are present.\r\n\r\nIf you do not configure this policy setting, searching Windows Update is optional when installing a device.\r\n\r\nAlso see \"Turn off Windows Update device driver search prompt\" in \"Administrative Templates/System,\" which governs whether an administrator is prompted before searching Windows Update for device drivers if a driver is not found locally.\r\n\r\nNote: This policy setting is replaced by \"Specify Driver Source Search Order\" in \"Administrative Templates/System/Device Installation\" on newer versions of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-driversearchplaces-dontsearchwindowsupdate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7973acd9264422":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"ffd82ac0c6e6cc08":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_lbl_reminderfreqspin","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"ff7b97cdb1ef84bf":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter","displayName":"Drive Letter","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_g:","displayName":"G:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_h:","displayName":"H:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_i:","displayName":"I:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_j:","displayName":"J:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_k:","displayName":"K:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_l:","displayName":"L:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_m:","displayName":"M:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_n:","displayName":"N:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_o:","displayName":"O:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_p:","displayName":"P:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_q:","displayName":"Q:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_r:","displayName":"R:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_s:","displayName":"S:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_t:","displayName":"T:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_u:","displayName":"U:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_v:","displayName":"V:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_w:","displayName":"W:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_x:","displayName":"X:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_y:","displayName":"Y:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_z:","displayName":"Z:","description":null,"helpText":null}]},"ff47b78bb3c0ee3f":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl_contactiturl","displayName":"Contact IT URL","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},"ff17a4730f750339":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents","displayName":"Detailed Tracking Audit RPC Events","description":"This policy setting allows you to audit inbound remote procedure call (RPC) connections. If you configure this policy setting, an audit event is generated when a remote RPC connection is attempted. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a remote RPC connection is attempted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditrpcevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"ffe1f94a404e9ee5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled","displayName":"Enable the Click to Call Feature","description":"Enable the Click to Call feature which allows users to send phone numbers from Chrome Desktops to an Android device when the user is Signed-in. For more information, see help center article: https://support.google.com/chrome/answer/9430554?hl=en.\r\n\r\nIf this policy is set to enabled, the capability of sending phone numbers to Android devices will be enabled for the Chrome user.\r\n\r\nIf this policy is set to disabled, the capability of sending phone numbers to Android devices will be disabled for the Chrome user.\r\n\r\nIf you set this policy, users cannot change or override it.\r\n\r\nIf this policy is left unset, the Click to Call feature is enabled by default.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff876db34f4afa1e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled","displayName":"Allow users to customize the background on the New Tab page","description":"If the policy is set to false, the New Tab page won't allow users to customize the background. Any existing custom background will be permanently removed even if the policy is set to true later.\r\n\r\nIf the policy is set to true or unset, users can customize the background on the New Tab page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ffd9208405c1a28e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled","displayName":"Enable Window Occlusion","description":"Enables window occlusion in Google Chrome.\r\n\r\nIf you enable this setting, to reduce CPU and power consumption Google Chrome will detect when a window is covered by other windows, and will suspend work painting pixels.\r\n\r\nIf you disable this setting Google Chrome will not detect when a window is covered by other windows.\r\n\r\nIf this policy is left not set, occlusion detection will be enabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff3bd019ba3d5128":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath_browserswitcherchromepath","displayName":"Path to Chrome for switching from the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"ff8b8c0c5f700f11":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforunregister","displayName":"Healthy Providers Required For Unregister","description":"This setting specifies the number of healthy CCD Locations required for a user to sign out. The default setting is 1, meaning that at least one remote CCD Location is required for the user to sign out.\r\n\r\nIf the number of available CCD Locations, when a user attempts to sign out, is less than the number set for Healthy Providers Required For Unregister, the user's sign out will be prevented for the time specified in CCD Unregister Timeout.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\HealthyProvidersRequiredForUnregister\r\nType: DWORD\r\nValues: Min = 0, Max = 4","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforunregister_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforunregister_1","displayName":"Enabled","description":null,"helpText":null}]},"ff533b6f13011435":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows","displayName":"Enable dragging of content from different domains within a window","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in the same window.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy setting or do not configure it, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_1","displayName":"Enabled","description":null,"helpText":null}]},"ff1154cc26da444c":{"id":"device_vendor_msft_policy_config_kerberos_requirestrictkdcvalidation","displayName":"Require strict KDC validation","description":"This policy setting controls the Kerberos client's behavior in validating the KDC certificate for smart card and system certificate logon. \r\n\r\nIf you enable this policy setting, the Kerberos client requires that the KDC's X.509 certificate contains the KDC key purpose object identifier in the Extended Key Usage (EKU) extensions, and that the KDC's X.509 certificate contains a dNSName subjectAltName (SAN) extension that matches the DNS name of the domain. If the computer is joined to a domain, the Kerberos client requires that the KDC's X.509 certificate must be signed by a Certificate Authority (CA) in the NTAuth store. If the computer is not joined to a domain, the Kerberos client allows the root CA certificate on the smart card to be used in the path validation of the KDC's X.509 certificate.\r\n\r\nIf you disable or do not configure this policy setting, the Kerberos client requires only that the KDC certificate contain the Server Authentication purpose object identifier in the EKU extensions which can be issued to any server.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-kerberos#kerberos-requirestrictkdcvalidation"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_kerberos_requirestrictkdcvalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_requirestrictkdcvalidation_1","displayName":"Enabled","description":null,"helpText":null}]},"ff2f1985effd74b1":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled","displayName":"Web To Browser Sign-in Enabled","description":"Allow user to sign in to the same account in Microsoft Edge when a user signs in to a Microsoft website.\r\nIf this policy is enabled or not configured, user are able to get sign in CTA or seamless sign in experience(if 'SeamlessWebToBrowserSignInEnabled' (Seamless Web To Browser Sign-in Enabled) is enabled) when user sign in on Microsoft website.\r\nIf this policy is disabled, user will not get sign in CTA or seamless sign in experience when user sign in on Microsoft website.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7716b27dd2991e":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"ff5ef3af8b993222":{"id":"device_vendor_msft_policy_config_settings_allowlanguage","displayName":"Allow Language","description":"Allows the user to change the language settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#allowlanguage"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":[{"id":"device_vendor_msft_policy_config_settings_allowlanguage_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_settings_allowlanguage_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"ffcad8606fba1b85":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_port_redirector","displayName":"Enable RDP Shortpath for managed networks","description":"This policy setting lets you enable RDP Shortpath for managed networks.\r\n\r\nIf you enable this policy setting, Azure Virtual Desktop clients connected over managed networks will use UDP to connect to the session host.\r\n\r\nIf you disable or don’t configure this policy setting, the clients won’t use RDP Shortpath for managed networks to connect to the session host.\r\n\r\nIf you enable this policy setting, you should also enable the required firewall exceptions that will allow RDP Shortpath for managed networks to work properly.\r\n ","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":[{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_port_redirector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_port_redirector_1","displayName":"Enabled","description":null,"helpText":null}]},"ff13a740195becd2":{"id":"device_vendor_msft_policy_config_userrights_actaspartoftheoperatingsystem","displayName":"Act As Part Of The Operating System","description":"This user right allows a process to impersonate any user without authentication. The process can therefore gain access to the same local resources as that user. Processes that require this privilege should use the LocalSystem account, which already includes this privilege, rather than using a separate user account with this privilege specially assigned. Caution:Assigning this user right can be a security risk. Only assign this user right to trusted users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#actaspartoftheoperatingsystem"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"ffb16cf4af0d083e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_pathcolon71","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"ffb84e0316e5654b":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts","displayName":"Turn on Script Execution (User)","description":"This policy setting lets you configure the script execution policy, controlling which scripts are allowed to run.\r\n\r\nIf you enable this policy setting, the scripts selected in the drop-down list are allowed to run.\r\n\r\nThe \"Allow only signed scripts\" policy setting allows scripts to execute only if they are signed by a trusted publisher.\r\n\r\nThe \"Allow local scripts and remote signed scripts\" policy setting allows any local scrips to run; scripts that originate from the Internet must be signed by a trusted publisher.\r\n\r\nThe \"Allow all scripts\" policy setting allows all scripts to run.\r\n\r\nIf you disable this policy setting, no scripts are allowed to run.\r\n\r\nNote: This policy setting exists under both \"Computer Configuration\" and \"User Configuration\" in the Local Group Policy Editor. The \"Computer Configuration\" has precedence over \"User Configuration.\"\r\n\r\nIf you disable or do not configure this policy setting, it reverts to a per-machine preference setting; the default if that is not configured is \"No scripts allowed.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enablescripts"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_1","displayName":"Enabled","description":null,"helpText":null}]},"ff8981d41db40fd6":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_placesbar_places1","displayName":"Item 2 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","categoryName":"Common Open File Dialog","options":null},"ffd275e0c304007a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download (User)","description":"List of file types that should be automatically opened on download. The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\r\n\r\nFiles with types that should be automatically opened will still be subject to the enabled safe browsing checks and won't be opened if they fail those checks.\r\n\r\nIf this policy isn't set, only file types that a user has already specified to automatically be opened will do so when downloaded.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nexe\r\ntxt","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_1","displayName":"Enabled","description":null,"helpText":null}]},"ffc3814ce5a0959e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps when Google Chrome is closed (User)","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fff09994ef20d96d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod","displayName":"Set the time period for update notifications (User)","description":"Allows you to set the time period, in milliseconds, over which users are notified that Google Chrome must be relaunched or that a Google Chrome OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Google Chrome OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Google Chrome browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the RelaunchNotification policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"ff3d4423432afb79":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nLeaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns must not conflict with FileSystemWriteBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"ffdc8adba0bdcd54":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_unsafelytreatinsecureoriginassecuredesc","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"ff6d495b7f1193f1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (User)","description":"Overrides default background graphics printing mode.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},"ff07b217ace939cd":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled","displayName":"Use Skia renderer for PDF rendering (User)","description":"Controls whether the PDF viewer in Google Chrome uses Skia renderer.\r\n\r\nWhen this policy is enabled, the PDF viewer uses Skia renderer.\r\n\r\nWhen this policy is disabled, the PDF viewer uses its current AGG renderer.\r\n\r\nWhen this policy is not set, the PDF renderer will be chosen by the browser.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff95da5cb870a124":{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate","displayName":"Intranet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_4","displayName":"High","description":null,"helpText":null}]},"ff6d253f9340a3b6":{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature","displayName":"Turn off the flip ahead with page prediction feature (User)","description":"This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.\n\nMicrosoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn't available for Internet Explorer for the desktop.\n\nIf you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn't loaded into the background.\n\nIf you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.\n\nIf you don't configure this setting, users can turn this behavior on or off, using the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableflipaheadfeature"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_1","displayName":"Enabled","description":null,"helpText":null}]},"ff5a2fa91cb5ca2d":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins","displayName":"Enable site isolation for specific origins (User)","description":"Specify origins to run in isolation, in their own process.\r\nThis policy also isolates origins named by subdomains - for example, specifying https://contoso.com/ will cause https://foo.contoso.com/ to be isolated as part of the https://contoso.com/ site.\r\nIf the policy is enabled, each of the named origins in a comma-separated list will run in its own process.\r\nIf you disable this policy, then both the 'IsolateOrigins' and 'SitePerProcess' features are disabled. Users can still enable 'IsolateOrigins' policy manually, via command line flags.\r\nIf you don't configure the policy, the user can change this setting.\r\n\r\nExample value: https://contoso.com/,https://fabrikam.com/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7d93c9f1b4ac25":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled","displayName":"Configure tab lifecycles (User)","description":"The tab lifecycles feature reclaims CPU and memory associated with running tabs that haven't been used in a long time, by first throttling, then freezing, and finally discarding them.\r\n\r\nIf you disable this policy, the tab lifecycles feature is disabled, and all tabs are left running normally.\r\n\r\nIf you enable or don't configure this policy, the tab lifecycles feature is enabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff26f10a9f4f7050":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled","displayName":"Search in Sidebar enabled (User)","description":"Search in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps).\r\n\r\nIf you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar will be enabled.\r\n\r\nIf you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar will be disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\r\n\r\nIf you configure this policy to 'DisableSearchInSidebar', Search in sidebar will be disabled. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableSearchInSidebar (0) = Enable search in sidebar\r\n\r\n* DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode\r\n\r\n* DisableSearchInSidebar (2) = Disable search in sidebar\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ffccf27a0478576b":{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"ffce33db87f01ce4":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections (User)","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\r\n\r\nIf you enable this policy, services and export targets that match the given list are blocked.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\r\n\r\nPolicy options mapping:\r\n\r\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\npinterest_suggestions","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"ff4c371f7a9fb62c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0_1","displayName":"True","description":null,"helpText":null}]},"ffc6863b40c8d80e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink","displayName":"With a simple Web discussions link (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7f699c45fed1ce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina","displayName":"Bosnian (Cyrillic, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Bosnian (Cyrillic, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},"ffb972fa58c5c927":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen","displayName":"Turkmen (User)","description":"Enables the editing language Turkmen","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen_1","displayName":"Enabled","description":null,"helpText":null}]},"ff189da11fc56cf0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},"ff190c8e582c4fe0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15","displayName":"Escrow Key #15 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_1","displayName":"Enabled","description":null,"helpText":null}]},"ff959538f41ec8ac":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18_1","displayName":"True","description":null,"helpText":null}]},"ff48c17836a4953c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation","displayName":"Turn on privacy settings in Office Telemetry Agent (User)","description":"This policy setting configures Office Telemetry Agent to disguise, or obfuscate, certain file properties that are reported in telemetry data.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent obfuscates the file name, file path, and title of Office documents before uploading telemetry data to the shared folder.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data that shows the full file name, file path, and title of all Office documents.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation_1","displayName":"Enabled","description":null,"helpText":null}]},"ff48e856c9b6c1de":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload","displayName":"Age out documents older than n days Including documents with pending uploads (User)","description":"\r\n This policy controls when locally cached Office documents are aged out of the Office Document Cache including if the file may have pending uploads. This acts as a maximum possible age (in days) for any file to remain in the Office Document Cache.\r\n\r\n If you enable this policy setting, files older than the policy \"Age out documents older than n days\" as well as this setting will get cleaned up regardless of file pending upload status.\r\n\r\n If you disable this policy setting or if you do not configure this policy setting, Office will clean out only files that do not have pending changes per the policy \"Age out documents older than n days\". Configuring this policy with a value of 0 is also considered disabling the policy.\r\n\r\n For more information https://support.microsoft.com/en-us/topic/managing-office-document-cache-size-ea64af72-b597-408e-8ecf-fd55daa02476\r\n\r\n Note: This policy setting only applies to Office builds 19328.20000 and newer\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_1","displayName":"Enabled","description":null,"helpText":null}]},"ff90e8a4792af587":{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier","displayName":"Multiplier for foreground sync interval for the currently viewed section stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between foreground polls of a SharePoint site for changes to the currently viewed section.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently for changes to the currently viewed section. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow section sync but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will sync the currently viewed section at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},"fffa6c13b194aad0":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_urladdressofassociatedwebpage","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"ff405a6a7c391266":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist_l_specifyfullpathandfilenametoblockedsenderslist","displayName":"Specify full path and filename to Blocked Senders list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":null},"ffe7ec839715ab4f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook","displayName":"Do not allow Sharepoint-Outlook integration (User)","description":"This policy setting allows you to prevent access to Microsoft SharePoint Foundation with Outlook.\r\n\r\nIf you enable this policy setting, user profiles will not be able to upload new items or sync changes to the SharePoint list from the server; however, user profiles that have pre-existing SharePoint lists will retain their local data. In addition, new SharePoint lists cannot be connected when this policy setting is enabled. This can be toggled on and off to restore synchronization to existing lists. Note that users will not receive a message if synchronization has been prevented.\r\n\r\nIf you disable or do not configure this policy setting, Microsoft SharePoint Foundation access will be allowed with Outlook.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7a5bb852782673":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics","displayName":"Print TrueType fonts as graphics (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},"ffe2af2ee0a579b2":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},"ffd29843aa9dcd9e":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99","displayName":"File tab | Options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99_1","displayName":"True","description":null,"helpText":null}]}} \ No newline at end of file +{"ff115805ebde6d36":{"id":"com.android.devicerestrictionpolicy.passwordpreviouspasswordcounttoblock","displayName":"Number of passwords required before user can reuse a password","description":"Use this setting to restrict users from creating previously used passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. If the value is blank, Intune doesn't change or update this setting. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-24)","infoUrls":[],"categoryId":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","categoryName":"Device password","options":null},"ffb221d92797bd5b":{"id":"com.android.devicerestrictionpolicy.workprofilepasswordminimumlettercharacters","displayName":"Number of characters required","description":"Enter the number of characters the work profile password must have, between 1 and 16 characters. Available for fully managed, dedicated and corporate-owned work profile devices (at work profile level).","helpText":"Enter a number (1-16)","infoUrls":[],"categoryId":"70c4566f-a079-4a8e-ac97-0736b405df1d","categoryName":"Work profile password","options":null},"ff8158f5c54071b6":{"id":"com.apple.applicationaccess_allowairplayincomingrequests","displayName":"Allow Air Play Incoming Requests","description":"If false, disables incoming AirPlay requests. Requires a supervised device. Available in macOS 12.3 and later.","helpText":null,"infoUrls":[],"categoryId":"eda31027-9270-4959-801b-397fa05512e2","categoryName":"Restrictions","options":[{"id":"com.apple.applicationaccess_allowairplayincomingrequests_false","displayName":"False","description":null,"helpText":null},{"id":"com.apple.applicationaccess_allowairplayincomingrequests_true","displayName":"True","description":null,"helpText":null}]},"ff8e90614f95e8fb":{"id":"com.apple.extensiblesso_extensiondata_pwreqlength_kerberos","displayName":"Password Req Length","description":"The minimum length of passwords on the domain. Available in macOS 10.15 and later.","helpText":null,"infoUrls":[],"categoryId":"f35cc803-3a06-4262-b38b-a5295321f756","categoryName":"Extensible Single Sign On Kerberos","options":null},"fff5e5103fe3be82":{"id":"com.apple.managedclient.preferences_applicationssystem_applications_microsoft edge dev.app_lcid","displayName":"Microsoft Edge Dev LCID (Deprecated)","description":null,"helpText":null,"infoUrls":[],"categoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","categoryName":"Microsoft AutoUpdate (MAU)","options":null},"fff122974f4aec7c":{"id":"com.apple.managedclient.preferences_automaticdownloadsallowedforurls","displayName":"Allow multiple automatic downloads in quick succession on specific sites","description":"Define a list of sites, based on URL patterns, that are allowed to perform multiple successive automatic downloads.\nIf you don't configure this policy, \"DefaultAutomaticDownloadsSetting\" applies for all sites, if it's set. If it isn't set, then the user's personal setting applies.\nFor more detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#automaticdownloadsallowedforurls"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"ff0f10efd62b1545":{"id":"com.apple.managedclient.preferences_javascriptoptimizerallowedforsites","displayName":"Allow JavaScript optimization on these sites","description":"Allows you to set a list of site url patterns that specify sites for which advanced JavaScript optimizations are enabled.\n\nFor detailed information on valid site url patterns, please see https://go.microsoft.com/fwlink/?linkid=2095322. Wildcards, *, are allowed.\n\nJavaScript optimization policy exceptions will only be enforced at a site granularity (eTLD+1). A policy set for only subdomain.contoso.com will not correctly apply to contoso.com or subdomain.contoso.com since they both resolve to the same eTLD+1 (contoso.com) for which there is no policy. In this case, policy must be set on contoso.com to apply correctly for both contoso.com and subdomain.contoso.com.\n\nThis policy applies on a frame-by-frame basis and not based on top level origin url alone, so e.g. if contoso.com is listed in the \"JavaScriptOptimizerAllowedForSites\" policy but contoso.com loads a frame containing fabrikam.com then contoso.com will have JavaScript optimizations enabled, but fabrikam.com will use the policy from \"DefaultJavaScriptOptimizerSetting\", if set, or default to JavaScript optimizations enabled. Blocklist entries have higher priority than allowlist entries, which in turn have higher priority than the configured default value.\n\nIf you don't configure this policy for a site then the policy from \"DefaultJavaScriptOptimizerSetting\" applies to the site, if set, otherwise Javascript optimization is enabled for the site.","helpText":null,"infoUrls":["https://docs.microsoft.com/deployedge/microsoft-edge-policies#javascriptoptimizerallowedforsites"],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":null},"ff6118376e124538":{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut","displayName":"Create desktop shortcut","description":null,"helpText":null,"infoUrls":[],"categoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","categoryName":"Microsoft Edge","options":[{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.apple.managedclient.preferences_webappinstallforcelist_item_create_desktop_shortcut_true","displayName":"Enabled","description":null,"helpText":null}]},"ffbf3142406455e7":{"id":"com.microsoft.edge.mamedgeappconfigsettings.insecureprivatenetworkrequestsallowedforurls","displayName":"Allow the listed sites to make requests to more-private network endpoints from in an insecure manner (Obsolete)","description":"List of URL patterns. Requests initiated from websites served by matching origins aren't subject to Private Network Access checks.\n\nIf this policy isn't set, this policy behaves as if set to the empty list.\n\nFor origins not covered by the patterns specified here, the global default value is used either from the \"InsecurePrivateNetworkRequestsAllowed\" policy, if it's set, or the user's personal configuration otherwise.\n\nFor detailed information on valid URL patterns, see [Filter format for URL list-based policies](/DeployEdge/edge-learnmmore-url-list-filter%20format).\n\nThis policy is obsolete. The previous blanket override has been replaced by the permission-based Local Network Access model, which blocks cross-space requests until users grant explicit consent.","helpText":null,"infoUrls":[],"categoryId":"43057320-7058-46d5-86f9-a56c80bbf8b9","categoryName":"Private Network Request Settings","options":null},"ffab0a52434992d3":{"id":"com.microsoft.edge.mamedgeappconfigsettings.serialblockedforurls","displayName":"Block the Serial API on specific sites","description":"Specifies URL patterns for sites that aren't allowed to request access to a serial port.\n\nIf not configured, Microsoft Edge uses the value from the DefaultSerialGuardSetting policy (if set), or the user's settings.\n\nFor unmatched sites, the following order applies:\n\n1. SerialAskForUrls (if matched).\n\n2. DefaultSerialGuardSetting (if set).\n\n3. User's settings.\n\nURL patterns in this policy must not conflict with those in SerialAskForUrls. This policy takes precedence.\n\nFor detailed information about valid URL patterns, see https://go.microsoft.com/fwlink/?linkid=2095322.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":null},"fff66343aff4da3b":{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended","displayName":"Set the default New Tab Page feed tab to Work or Discover (users can override)","description":"This policy sets the default feed tab on the New Tab Page to Work or Discover.\n\nIf you set this policy to 'Work' (0) or don't configure this policy, Microsoft Edge sets the default feed tab to Work.\n\nIf you set this policy to 'Discover' (1), Microsoft Edge sets the default feed tab to Discover.\n\nThis policy only takes effect when \"ConfigureNTPFeedTabVisibility\" is set to 'EnableBothWorkDiscover' (0) or is not configured. If only one tab is visible, this policy has no effect.\n\nPolicy options mapping:\n\n* NTPDefaultFeedTabWork (0) = Work\n\n* NTPDefaultFeedTabDiscover (1) = Discover\n\nUse the preceding information when configuring this policy.","helpText":null,"infoUrls":[],"categoryId":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","categoryName":"Startup, home page and new tab page","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended_ntpdefaultfeedtabwork","displayName":"Work","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.setntpdefaultfeedtab_recommended_ntpdefaultfeedtabdiscover","displayName":"Discover","description":null,"helpText":null}]},"ff2868a0e8d9e7d0":{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton","displayName":"Shows button on native PDF viewer in Microsoft Edge that allows users to sign up for Adobe Acrobat subscription","description":"This policy lets the native PDF viewer in Microsoft Edge show a button that lets a user looking for advanced digital document features to discover and subscribe to premium offerings. This is done via the Acrobat extension.\n\nIf you enable or don't configure this policy, the button shows up on the native PDF viewer in Microsoft Edge. A user can buy Adobe subscription to access their premium offerings.\n\nIf you disable this policy, the button isn't visible on the native PDF viewer in Microsoft Edge. A user can't discover Adobe's advanced PDF tools or buy their subscriptions.","helpText":null,"infoUrls":[],"categoryId":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","categoryName":"Uncategorized","options":[{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton_false","displayName":"Disabled","description":null,"helpText":null},{"id":"com.microsoft.edge.mamedgeappconfigsettings.showacrobatsubscriptionbutton_true","displayName":"Enabled","description":null,"helpText":null}]},"ffe20ba3697668f0":{"id":"contentcaching_peerfilterranges_item_type","displayName":"Type","description":"The IP address type.","helpText":null,"infoUrls":[],"categoryId":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","categoryName":"Content Cache Settings","options":[{"id":"contentcaching_peerfilterranges_item_type_0","displayName":"IPv4","description":null,"helpText":null},{"id":"contentcaching_peerfilterranges_item_type_1","displayName":"IPv6","description":null,"helpText":null}]},"ffb0d7ee27f6d8c6":{"id":"device_vendor_msft_laps_policies_adpasswordencryptionprincipal","displayName":"AD Password Encryption Principal ","description":"Use this setting to configure the name or SID of a user or group that can decrypt the password stored in Active Directory.\n\nThis setting is ignored if the password is currently being stored in Azure.\n\nIf not specified, the password will be decryptable by the Domain Admins group in the device's domain.\n\nIf specified, the specified user or group will be able to decrypt the password stored in Active Directory.\n\nIf the specified user or group account is invalid the device will fallback to using the Domain Admins group in the device's domain.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/LAPS-csp/"],"categoryId":"f1dcf7b6-2d89-41bf-b5eb-02a879c6db5d","categoryName":null,"options":null},"ff20add57702091d":{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname","displayName":"Name of administrator account to manage","description":"\nAdministrator account name: name of the local account you want to manage password for.\n DO NOT configure when you use built-in admin account. Built-in admin account is auto-detected by well-known SID, even when renamed\n\n DO configure when you use custom local admin account\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-admpwd#admx-admpwd-pol-admpwd-adminname"],"categoryId":"b3b2fc04-4b88-4a1c-8370-04573019eebe","categoryName":"LAPS","options":[{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_admpwd_pol_admpwd_adminname_1","displayName":"Enabled","description":null,"helpText":null}]},"ffaa2f3869c5ff1c":{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist","displayName":"Allow local activation security check exemptions","description":"Allows you to specify that local computer administrators can supplement the \"Define Activation Security Check exemptions\" list.\r\n\r\nIf you enable this policy setting, and DCOM does not find an explicit entry for a DCOM server application id (appid) in the \"Define Activation Security Check exemptions\" policy (if enabled), DCOM will look for an entry in the locally configured list.\r\n\r\nIf you disable this policy setting, DCOM will not look in the locally configured DCOM activation security check exemption list.\r\n\r\nIf you do not configure this policy setting, DCOM will only look in the locally configured exemption list if the \"Define Activation Security Check exemptions\" policy is not configured.\r\n\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-dcom#admx-dcom-dcomactivationsecuritycheckallowlocallist"],"categoryId":"a57b27b6-48e0-42b2-812a-2be86c113a0c","categoryName":"Application Compatibility Settings","options":[{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dcom_dcomactivationsecuritycheckallowlocallist_1","displayName":"Enabled","description":null,"helpText":null}]},"ffa883ea85cd3e16":{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box","displayName":"Update security level:","description":null,"helpText":"","infoUrls":[],"categoryId":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","categoryName":"DNS Client","options":[{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_256","displayName":"Only secure","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_16","displayName":"Only unsecure","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_dnsclient_dns_updatesecuritylevel_dns_updatesecuritylevel_box_0","displayName":"Unsecure followed by secure","description":null,"helpText":null}]},"ff5a0428f0bab998":{"id":"device_vendor_msft_policy_config_admx_eventlog_channel_log_filelogaccess_3_channel_log_filelogaccess","displayName":"Log Access","description":null,"helpText":"","infoUrls":[],"categoryId":"1a2a4fc8-c54b-4906-a422-7dd51a196211","categoryName":"Setup","options":null},"ffd480955c570d89":{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt","displayName":"Configure software Installation policy processing","description":"This policy setting determines when software installation policies are updated.\r\n\r\nThis policy setting affects all policy settings that use the software installation component of Group Policy, such as policy settings in Software Settings\\Software Installation. You can set software installation policy only for Group Policy Objects stored in Active Directory, not for Group Policy Objects on the local computer.\r\n\r\nThis policy setting overrides customized settings that the program implementing the software installation policy set when it was installed.\r\n\r\nIf you enable this policy setting, you can use the check boxes provided to change the options. If you disable or do not configure this policy setting, it has no effect on the system.\r\n\r\nThe \"Allow processing across a slow network connection\" option updates the policies even when the update is being transmitted across a slow network connection, such as a telephone line. Updates across slow connections can cause significant delays.\r\n\r\nThe \"Process even if the Group Policy objects have not changed\" option updates and reapplies the policies even if the policies have not changed. Many policy setting implementations specify that they are updated only when changed. However, you might want to update unchanged policy settings, such as reapplying a desired policies in case a user has changed it.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-grouppolicy#admx-grouppolicy-cse-appmgmt"],"categoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","categoryName":"Group Policy","options":[{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_grouppolicy_cse_appmgmt_1","displayName":"Enabled","description":null,"helpText":null}]},"ff6e2ee814e754cd":{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate","displayName":"Turn off Windows Update device driver searching","description":"This policy setting specifies whether Windows searches Windows Update for device drivers when no local drivers for a device are present.\r\n\r\nIf you enable this policy setting, Windows Update is not searched when a new device is installed.\r\n\r\nIf you disable this policy setting, Windows Update is always searched for drivers when no local drivers are present.\r\n\r\nIf you do not configure this policy setting, searching Windows Update is optional when installing a device.\r\n\r\nAlso see \"Turn off Windows Update device driver search prompt\" in \"Administrative Templates/System,\" which governs whether an administrator is prompted before searching Windows Update for device drivers if a driver is not found locally.\r\n\r\nNote: This policy setting is replaced by \"Specify Driver Source Search Order\" in \"Administrative Templates/System/Device Installation\" on newer versions of Windows.\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-icm#admx-icm-driversearchplaces-dontsearchwindowsupdate"],"categoryId":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","categoryName":null,"options":[{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_icm_driversearchplaces_dontsearchwindowsupdate_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7973acd9264422":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_nopinfiles_2_lbl_nopinfileslist_key","displayName":"Name","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"ffd82ac0c6e6cc08":{"id":"device_vendor_msft_policy_config_admx_offlinefiles_pol_reminderfreq_2_lbl_reminderfreqspin","displayName":"Minutes:","description":null,"helpText":"","infoUrls":[],"categoryId":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","categoryName":"Offline Files","options":null},"ff7b97cdb1ef84bf":{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter","displayName":"Drive Letter","description":null,"helpText":"","infoUrls":[],"categoryId":"89ad0055-1603-420e-940d-9944a63e3da9","categoryName":"Profiles","options":[{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_g:","displayName":"G:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_h:","displayName":"H:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_i:","displayName":"I:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_j:","displayName":"J:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_k:","displayName":"K:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_l:","displayName":"L:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_m:","displayName":"M:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_n:","displayName":"N:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_o:","displayName":"O:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_p:","displayName":"P:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_q:","displayName":"Q:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_r:","displayName":"R:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_s:","displayName":"S:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_t:","displayName":"T:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_u:","displayName":"U:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_v:","displayName":"V:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_w:","displayName":"W:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_x:","displayName":"X:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_y:","displayName":"Y:","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_admx_terminalserver_ts_user_home_ts_drive_letter_z:","displayName":"Z:","description":null,"helpText":null}]},"ff47b78bb3c0ee3f":{"id":"device_vendor_msft_policy_config_admx_userexperiencevirtualization_contactiturl_contactiturl","displayName":"Contact IT URL","description":null,"helpText":"","infoUrls":[],"categoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","categoryName":"Microsoft User Experience Virtualization","options":null},"ff17a4730f750339":{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents","displayName":"Detailed Tracking Audit RPC Events","description":"This policy setting allows you to audit inbound remote procedure call (RPC) connections. If you configure this policy setting, an audit event is generated when a remote RPC connection is attempted. Success audits record successful attempts and Failure audits record unsuccessful attempts. If you do not configure this policy setting, no audit event is generated when a remote RPC connection is attempted.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Audit#detailedtracking_auditrpcevents"],"categoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","categoryName":"Auditing","options":[{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_0","displayName":"Off/ None","description":"Off/None","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_1","displayName":"Success","description":"Success","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_2","displayName":"Failure","description":"Failure","helpText":null},{"id":"device_vendor_msft_policy_config_audit_detailedtracking_auditrpcevents_3","displayName":"Success+ Failure","description":"Success+Failure","helpText":null}]},"ffe1f94a404e9ee5":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled","displayName":"Enable the Click to Call Feature","description":"Enable the Click to Call feature which allows users to send phone numbers from Chrome Desktops to an Android device when the user is Signed-in. For more information, see help center article: https://support.google.com/chrome/answer/9430554?hl=en.\r\n\r\nIf this policy is set to enabled, the capability of sending phone numbers to Android devices will be enabled for the Chrome user.\r\n\r\nIf this policy is set to disabled, the capability of sending phone numbers to Android devices will be disabled for the Chrome user.\r\n\r\nIf you set this policy, users cannot change or override it.\r\n\r\nIf this policy is left unset, the Click to Call feature is enabled by default.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_clicktocallenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff876db34f4afa1e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled","displayName":"Allow users to customize the background on the New Tab page","description":"If the policy is set to false, the New Tab page won't allow users to customize the background. Any existing custom background will be permanently removed even if the policy is set to true later.\r\n\r\nIf the policy is set to true or unset, users can customize the background on the New Tab page.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_ntpcustombackgroundenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ffd9208405c1a28e":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled","displayName":"Enable Window Occlusion","description":"Enables window occlusion in Google Chrome.\r\n\r\nIf you enable this setting, to reduce CPU and power consumption Google Chrome will detect when a window is covered by other windows, and will suspend work painting pixels.\r\n\r\nIf you disable this setting Google Chrome will not detect when a window is covered by other windows.\r\n\r\nIf this policy is left not set, occlusion detection will be enabled.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_windowocclusionenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff3bd019ba3d5128":{"id":"device_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~browserswitcher_browserswitcherchromepath_browserswitcherchromepath","displayName":"Path to Chrome for switching from the alternative browser. (Device)","description":"","helpText":"","infoUrls":[],"categoryId":"10247787-95ea-4507-93de-dbd166df12b5","categoryName":"Legacy Browser Support","options":null},"ff8b8c0c5f700f11":{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforunregister","displayName":"Healthy Providers Required For Unregister","description":"This setting specifies the number of healthy CCD Locations required for a user to sign out. The default setting is 1, meaning that at least one remote CCD Location is required for the user to sign out.\r\n\r\nIf the number of available CCD Locations, when a user attempts to sign out, is less than the number set for Healthy Providers Required For Unregister, the user's sign out will be prevented for the time specified in CCD Unregister Timeout.\r\n\r\nRegistry Entry: HKLM\\SOFTWARE\\Policies\\FSLogix\\ODFC\\HealthyProvidersRequiredForUnregister\r\nType: DWORD\r\nValues: Min = 0, Max = 4","helpText":"","infoUrls":[],"categoryId":"0bae3158-5f75-4e25-acf4-859d2612f892","categoryName":"Cloud Cache","options":[{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforunregister_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_fslogixv1~policy~fslogix~odfc~odfc_ccd_odfchealthyprovidersrequiredforunregister_1","displayName":"Enabled","description":null,"helpText":null}]},"ff533b6f13011435":{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows","displayName":"Enable dragging of content from different domains within a window","description":"This policy setting allows you to set options for dragging content from one domain to a different domain when the source and destination are in the same window.\n\nIf you enable this policy setting and click Enable, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting.\n\nIf you enable this policy setting and click Disable, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.\n\nIn Internet Explorer 10, if you disable this policy setting or do not configure it, users cannot drag content from one domain to a different domain when the source and destination are in the same window. Users can change this setting in the Internet Options dialog.\n\nIn Internet Explorer 9 and earlier versions, if you disable this policy setting or do not configure it, users can drag content from one domain to a different domain when the source and destination are in the same window. Users cannot change this setting in the Internet Options dialog.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows"],"categoryId":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","categoryName":"Internet Zone","options":[{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_internetexplorer_internetzoneenabledraggingofcontentfromdifferentdomainswithinwindows_1","displayName":"Enabled","description":null,"helpText":null}]},"ff1154cc26da444c":{"id":"device_vendor_msft_policy_config_kerberos_requirestrictkdcvalidation","displayName":"Require strict KDC validation","description":"This policy setting controls the Kerberos client's behavior in validating the KDC certificate for smart card and system certificate logon. \r\n\r\nIf you enable this policy setting, the Kerberos client requires that the KDC's X.509 certificate contains the KDC key purpose object identifier in the Extended Key Usage (EKU) extensions, and that the KDC's X.509 certificate contains a dNSName subjectAltName (SAN) extension that matches the DNS name of the domain. If the computer is joined to a domain, the Kerberos client requires that the KDC's X.509 certificate must be signed by a Certificate Authority (CA) in the NTAuth store. If the computer is not joined to a domain, the Kerberos client allows the root CA certificate on the smart card to be used in the path validation of the KDC's X.509 certificate.\r\n\r\nIf you disable or do not configure this policy setting, the Kerberos client requires only that the KDC certificate contain the Server Authentication purpose object identifier in the EKU extensions which can be issued to any server.\r\n","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-kerberos#kerberos-requirestrictkdcvalidation"],"categoryId":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","categoryName":"Kerberos","options":[{"id":"device_vendor_msft_policy_config_kerberos_requirestrictkdcvalidation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_kerberos_requirestrictkdcvalidation_1","displayName":"Enabled","description":null,"helpText":null}]},"ff2f1985effd74b1":{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled","displayName":"Web To Browser Sign-in Enabled","description":"Allow user to sign in to the same account in Microsoft Edge when a user signs in to a Microsoft website.\r\nIf this policy is enabled or not configured, user are able to get sign in CTA or seamless sign in experience(if 'SeamlessWebToBrowserSignInEnabled' (Seamless Web To Browser Sign-in Enabled) is enabled) when user sign in on Microsoft website.\r\nIf this policy is disabled, user will not get sign in CTA or seamless sign in experience when user sign in on Microsoft website.","helpText":"","infoUrls":[],"categoryId":"45a89c1f-0a34-4f78-b28f-d30b623fa423","categoryName":"Identity and sign-in","options":[{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_microsoft_edgev133~policy~microsoft_edge~identity_webtobrowsersigninenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7716b27dd2991e":{"id":"device_vendor_msft_policy_config_onedrivengscv2~policy~onedrivengsc_automountteamsites_automountteamsiteslistbox_value","displayName":"Value","description":"","helpText":"","infoUrls":[],"categoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","categoryName":"OneDrive","options":null},"ff5ef3af8b993222":{"id":"device_vendor_msft_policy_config_settings_allowlanguage","displayName":"Allow Language","description":"Allows the user to change the language settings.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-Settings#allowlanguage"],"categoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","categoryName":"Settings","options":[{"id":"device_vendor_msft_policy_config_settings_allowlanguage_0","displayName":"Block","description":"Not allowed.","helpText":null},{"id":"device_vendor_msft_policy_config_settings_allowlanguage_1","displayName":"Allow","description":"Allowed.","helpText":null}]},"ffcad8606fba1b85":{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_port_redirector","displayName":"Enable RDP Shortpath for managed networks","description":"This policy setting lets you enable RDP Shortpath for managed networks.\r\n\r\nIf you enable this policy setting, Azure Virtual Desktop clients connected over managed networks will use UDP to connect to the session host.\r\n\r\nIf you disable or don’t configure this policy setting, the clients won’t use RDP Shortpath for managed networks to connect to the session host.\r\n\r\nIf you enable this policy setting, you should also enable the required firewall exceptions that will allow RDP Shortpath for managed networks to work properly.\r\n ","helpText":"","infoUrls":[],"categoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","categoryName":"Azure Virtual Desktop","options":[{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_port_redirector_0","displayName":"Disabled","description":null,"helpText":null},{"id":"device_vendor_msft_policy_config_terminalserver-avdv1~policy~avd_gp_node_avd_server_udp_port_redirector_1","displayName":"Enabled","description":null,"helpText":null}]},"ff13a740195becd2":{"id":"device_vendor_msft_policy_config_userrights_actaspartoftheoperatingsystem","displayName":"Act As Part Of The Operating System","description":"This user right allows a process to impersonate any user without authentication. The process can therefore gain access to the same local resources as that user. Processes that require this privilege should use the LocalSystem account, which already includes this privilege, rather than using a separate user account with this privilege specially assigned. Caution:Assigning this user right can be a security risk. Only assign this user right to trusted users.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-UserRights#actaspartoftheoperatingsystem"],"categoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","categoryName":"User Rights","options":null},"ffb16cf4af0d083e":{"id":"user_vendor_msft_policy_config_access16v2~policy~l_microsoftofficeaccess~l_applicationsettings~l_security~l_trustcenter~l_trustedlocations_l_trustedloc18_l_pathcolon71","displayName":"Path: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","categoryName":"Trusted Locations","options":null},"ffb84e0316e5654b":{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts","displayName":"Turn on Script Execution (User)","description":"This policy setting lets you configure the script execution policy, controlling which scripts are allowed to run.\r\n\r\nIf you enable this policy setting, the scripts selected in the drop-down list are allowed to run.\r\n\r\nThe \"Allow only signed scripts\" policy setting allows scripts to execute only if they are signed by a trusted publisher.\r\n\r\nThe \"Allow local scripts and remote signed scripts\" policy setting allows any local scrips to run; scripts that originate from the Internet must be signed by a trusted publisher.\r\n\r\nThe \"Allow all scripts\" policy setting allows all scripts to run.\r\n\r\nIf you disable this policy setting, no scripts are allowed to run.\r\n\r\nNote: This policy setting exists under both \"Computer Configuration\" and \"User Configuration\" in the Local Group Policy Editor. The \"Computer Configuration\" has precedence over \"User Configuration.\"\r\n\r\nIf you disable or do not configure this policy setting, it reverts to a per-machine preference setting; the default if that is not configured is \"No scripts allowed.\"\r\n ","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-admx-powershellexecutionpolicy#admx-powershellexecutionpolicy-enablescripts"],"categoryId":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","categoryName":"Windows Power Shell","options":[{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_admx_powershellexecutionpolicy_enablescripts_1","displayName":"Enabled","description":null,"helpText":null}]},"ff8981d41db40fd6":{"id":"user_vendor_msft_policy_config_admx_windowsexplorer_placesbar_places1","displayName":"Item 2 (User)","description":null,"helpText":"","infoUrls":[],"categoryId":"12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","categoryName":"Common Open File Dialog","options":null},"ffd275e0c304007a":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes","displayName":"List of file types that should be automatically opened on download (User)","description":"List of file types that should be automatically opened on download. The leading separator should not be included when listing the file type, so list \"txt\" instead of \".txt\".\r\n\r\nFiles with types that should be automatically opened will still be subject to the enabled safe browsing checks and won't be opened if they fail those checks.\r\n\r\nIf this policy isn't set, only file types that a user has already specified to automatically be opened will do so when downloaded.\r\n\r\nOn Microsoft® Windows®, this functionality is only available on instances that are joined to a Microsoft® Active Directory® domain, running on Windows 10 Pro, or enrolled in Chrome Browser Cloud Management. On macOS, this functionality is only available on instances that are managed via MDM, or joined to a domain via MCX.\r\n\r\nExample value:\r\n\r\nexe\r\ntxt","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_autoopenfiletypes_1","displayName":"Enabled","description":null,"helpText":null}]},"ffc3814ce5a0959e":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended","displayName":"Continue running background apps when Google Chrome is closed (User)","description":"Setting the policy to Enabled turns background mode on. In background mode, a Google Chrome process is started on OS sign-in and keeps running when the last browser window is closed, allowing background apps and the browsing session to remain active. The background process displays an icon in the system tray and can always be closed from there.\r\n\r\nSetting the policy to Disabled turns background mode off.\r\n\r\nIf you set the policy, users can't change it in the browser settings. If unset, background mode is off at first, but users can change it.","helpText":"","infoUrls":[],"categoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","categoryName":"Google Chrome - Default Settings users can override","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_recommended_backgroundmodeenabled_recommended_1","displayName":"Enabled","description":null,"helpText":null}]},"fff09994ef20d96d":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod","displayName":"Set the time period for update notifications (User)","description":"Allows you to set the time period, in milliseconds, over which users are notified that Google Chrome must be relaunched or that a Google Chrome OS device must be restarted to apply a pending update.\r\n\r\nOver this time period, the user will be repeatedly informed of the need for an update. For Google Chrome OS devices, a restart notification appears in the system tray according to the RelaunchHeadsUpPeriod policy. For Google Chrome browsers, the app menu changes to indicate that a relaunch is needed once one third of the notification period passes. This notification changes color once two thirds of the notification period passes, and again once the full notification period has passed. The additional notifications enabled by the RelaunchNotification policy follow this same schedule.\r\n\r\nIf not set, the default period of 604800000 milliseconds (one week) is used.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome_relaunchnotificationperiod_1","displayName":"Enabled","description":null,"helpText":null}]},"ff3d4423432afb79":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls","displayName":"Allow write access to files and directories on these sites (User)","description":"Setting the policy lets you list the URL patterns that specify which sites can ask users to grant them write access to files or directories in the host operating system's file system.\r\n\r\nLeaving the policy unset means DefaultFileSystemWriteGuardSetting applies for all sites, if it's set. If not, users' personal settings apply.\r\n\r\nURL patterns must not conflict with FileSystemWriteBlockedForUrls. Neither policy takes precedence if a URL matches with both.\r\n\r\nFor detailed information on valid url patterns, please see https://cloud.google.com/docs/chrome-enterprise/policies/url-patterns. * is not an accepted value for this policy.\r\n\r\nExample value:\r\n\r\nhttps://www.example.com\r\n[*.]example.edu","helpText":"","infoUrls":[],"categoryId":"59d29716-55b0-4014-a458-38b408ff9530","categoryName":"Content settings","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~contentsettings_filesystemwriteaskforurls_1","displayName":"Enabled","description":null,"helpText":null}]},"ffdc8adba0bdcd54":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~deprecatedpolicies_unsafelytreatinsecureoriginassecure_unsafelytreatinsecureoriginassecuredesc","displayName":"Origins or hostname patterns for which restrictions on\r\ninsecure origins should not apply (User)","description":"","helpText":"","infoUrls":[],"categoryId":"5900ac65-f656-459c-bd82-1329a862544d","categoryName":"Deprecated policies","options":null},"ff6d495b7f1193f1":{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault","displayName":"Default background graphics printing mode (User)","description":"Overrides default background graphics printing mode.\r\n\r\nExample value: enabled","helpText":"","infoUrls":[],"categoryId":"62499519-97eb-43e7-ae96-d7909c5820d3","categoryName":"Printing","options":[{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev1~policy~googlechrome~printing_printingbackgroundgraphicsdefault_1","displayName":"Enabled","description":null,"helpText":null}]},"ff07b217ace939cd":{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled","displayName":"Use Skia renderer for PDF rendering (User)","description":"Controls whether the PDF viewer in Google Chrome uses Skia renderer.\r\n\r\nWhen this policy is enabled, the PDF viewer uses Skia renderer.\r\n\r\nWhen this policy is disabled, the PDF viewer uses its current AGG renderer.\r\n\r\nWhen this policy is not set, the PDF renderer will be chosen by the browser.","helpText":"","infoUrls":[],"categoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","categoryName":"Google Chrome","options":[{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_chromeintunev141~policy~googlechrome_pdfuseskiarendererenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff95da5cb870a124":{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate","displayName":"Intranet (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8d503574-f93a-4277-a30d-19895d46dd13","categoryName":"Security Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_1","displayName":"Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_2","displayName":"Medium Low","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_3","displayName":"Medium","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_5","displayName":"Medium High","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_allowintranetzonetemplate_iz_partnameintranetzonetemplate_4","displayName":"High","description":null,"helpText":null}]},"ff6d253f9340a3b6":{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature","displayName":"Turn off the flip ahead with page prediction feature (User)","description":"This policy setting determines whether a user can swipe across a screen or click Forward to go to the next pre-loaded page of a website.\n\nMicrosoft collects your browsing history to improve how flip ahead with page prediction works. This feature isn't available for Internet Explorer for the desktop.\n\nIf you enable this policy setting, flip ahead with page prediction is turned off and the next webpage isn't loaded into the background.\n\nIf you disable this policy setting, flip ahead with page prediction is turned on and the next webpage is loaded into the background.\n\nIf you don't configure this setting, users can turn this behavior on or off, using the Settings charm.","helpText":"","infoUrls":["https://docs.microsoft.com/windows/client-management/mdm/policy-csp-internetexplorer#internetexplorer-disableflipaheadfeature"],"categoryId":"822bd634-4d01-486e-adad-8085968fd1c4","categoryName":"Advanced Page","options":[{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_internetexplorer_disableflipaheadfeature_1","displayName":"Enabled","description":null,"helpText":null}]},"ff5a2fa91cb5ca2d":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins","displayName":"Enable site isolation for specific origins (User)","description":"Specify origins to run in isolation, in their own process.\r\nThis policy also isolates origins named by subdomains - for example, specifying https://contoso.com/ will cause https://foo.contoso.com/ to be isolated as part of the https://contoso.com/ site.\r\nIf the policy is enabled, each of the named origins in a comma-separated list will run in its own process.\r\nIf you disable this policy, then both the 'IsolateOrigins' and 'SitePerProcess' features are disabled. Users can still enable 'IsolateOrigins' policy manually, via command line flags.\r\nIf you don't configure the policy, the user can change this setting.\r\n\r\nExample value: https://contoso.com/,https://fabrikam.com/","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_isolateorigins_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7d93c9f1b4ac25":{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled","displayName":"Configure tab lifecycles (User)","description":"The tab lifecycles feature reclaims CPU and memory associated with running tabs that haven't been used in a long time, by first throttling, then freezing, and finally discarding them.\r\n\r\nIf you disable this policy, the tab lifecycles feature is disabled, and all tabs are left running normally.\r\n\r\nIf you enable or don't configure this policy, the tab lifecycles feature is enabled.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edge~policy~microsoft_edge_tablifecyclesenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ff26f10a9f4f7050":{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled","displayName":"Search in Sidebar enabled (User)","description":"Search in Sidebar allows users to open search result in sidebar (including sidebar search for Progressive Web Apps).\r\n\r\nIf you configure this policy to 'EnableSearchInSidebar' or don't configure it, Search in sidebar will be enabled.\r\n\r\nIf you configure this policy to 'DisableSearchInSidebarForKidsMode', Search in sidebar will be disabled when in Kids mode. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\r\n\r\nIf you configure this policy to 'DisableSearchInSidebar', Search in sidebar will be disabled. Some methods that would normally invoke sidebar search will invoke a traditional search instead.\r\n\r\nPolicy options mapping:\r\n\r\n* EnableSearchInSidebar (0) = Enable search in sidebar\r\n\r\n* DisableSearchInSidebarForKidsMode (1) = Disable search in sidebar for Kids Mode\r\n\r\n* DisableSearchInSidebar (2) = Disable search in sidebar\r\n\r\nUse the preceding information when configuring this policy.","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev110~policy~microsoft_edge_searchinsidebarenabled_1","displayName":"Enabled","description":null,"helpText":null}]},"ffccf27a0478576b":{"id":"user_vendor_msft_policy_config_microsoft_edgev139~policy~microsoft_edge_onsecurityevententerpriseconnector_onsecurityevententerpriseconnector","displayName":"Configuration policy for Microsoft Edge for Business Reporting Connectors (User)","description":"","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":null},"ffce33db87f01ce4":{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist","displayName":"Block access to a specified list of services and export targets in Collections (User)","description":"List specific services and export targets that users can't access in the Collections feature in Microsoft Edge. This includes displaying additional data from Bing and exporting collections to Microsoft products or external partners.\r\n\r\nIf you enable this policy, services and export targets that match the given list are blocked.\r\n\r\nIf you don't configure this policy, no restrictions on the acceptable services and export targets are enforced.\r\n\r\nPolicy options mapping:\r\n\r\n* pinterest_suggestions (pinterest_suggestions) = Pinterest suggestions\r\n\r\nUse the preceding information when configuring this policy.\r\n\r\nExample value:\r\n\r\npinterest_suggestions","helpText":"","infoUrls":[],"categoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","categoryName":"Microsoft Edge","options":[{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_microsoft_edgev86~policy~microsoft_edge_collectionsservicesandexportsblocklist_1","displayName":"Enabled","description":null,"helpText":null}]},"ff4c371f7a9fb62c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0","displayName":"Create Shared Notes (User)","description":"","helpText":"","infoUrls":[],"categoryId":"0be98651-a552-4470-b2dc-71c66a5ce1e6","categoryName":"Presentation Services","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_broadcast~l_broadcastservices_l_configurebroadcastservice00_l_broadcastservicecreatesharednotes0_1","displayName":"True","description":null,"helpText":null}]},"ffc6863b40c8d80e":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink","displayName":"With a simple Web discussions link (User)","description":"Defines the default message body text used in an email request for review when the review document is included only as an attachment.","helpText":"","infoUrls":[],"categoryId":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","categoryName":"Default message text for a review request...","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_collaborationsettings~l_defaultmessagetextforareviewrequest_l_withasimplewebdiscussionslink_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7f699c45fed1ce":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina","displayName":"Bosnian (Cyrillic, Bosnia and Herzegovina) (User)","description":"Enables the editing language \"Bosnian (Cyrillic, Bosnia and Herzegovina)\"","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_bosniancyrillicbosniaandherzegovina_1","displayName":"Enabled","description":null,"helpText":null}]},"ffb972fa58c5c927":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen","displayName":"Turkmen (User)","description":"Enables the editing language Turkmen","helpText":"","infoUrls":[],"categoryId":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","categoryName":"Enabled Editing Languages","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_languagesettings~l_editinglanguages~l_enablededitinglanguages_l_turkmen_1","displayName":"Enabled","description":null,"helpText":null}]},"ff189da11fc56cf0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid","displayName":"","description":"","helpText":"","infoUrls":[],"categoryId":"512f133b-9d53-46b8-834f-52501f9b6527","categoryName":"Digital Signatures","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_0","displayName":"0","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_512","displayName":"512","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_768","displayName":"768","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_digsig_l_selectdigitalsignaturelegacydsabits_l_selectdigitalsignaturehashingalgorithmdropid_1024","displayName":"1024","description":null,"helpText":null}]},"ff190c8e582c4fe0":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15","displayName":"Escrow Key #15 (User)","description":"This policy setting allows you to specify a certificate to use as an escrow key for password protected files.\r\n\r\nIf you enable this policy setting, the certificate you specify is used as an escrow key for all password protected files that are created on this machine.\r\n\r\nIf you disable or do not configure this policy setting, an escrow key is not configured.","helpText":"","infoUrls":[],"categoryId":"4f671de2-9777-4969-acf3-8d90c733434c","categoryName":"Escrow Certificates","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_escrowkeycerts_l_escrowkey15_1","displayName":"Enabled","description":null,"helpText":null}]},"ff959538f41ec8ac":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"135e4013-43b8-4227-99fd-54ddeac4e329","categoryName":"Protected View","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_securitysettings~l_trustcenter241~l_protectedview_l_unsafeloc18_l_allowsubfolders18_1","displayName":"True","description":null,"helpText":null}]},"ff48c17836a4953c":{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation","displayName":"Turn on privacy settings in Office Telemetry Agent (User)","description":"This policy setting configures Office Telemetry Agent to disguise, or obfuscate, certain file properties that are reported in telemetry data.\r\n\r\nIf you enable this policy setting, Office Telemetry Agent obfuscates the file name, file path, and title of Office documents before uploading telemetry data to the shared folder.\r\n\r\nIf you disable or do not configure this policy setting, Office Telemetry Agent uploads telemetry data that shows the full file name, file path, and title of all Office documents.","helpText":"","infoUrls":[],"categoryId":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","categoryName":"Telemetry Dashboard","options":[{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v2~policy~l_microsoftofficesystem~l_telemetrydashboard_l_officeinventoryagentfilemetadataobfuscation_1","displayName":"Enabled","description":null,"helpText":null}]},"ff48e856c9b6c1de":{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload","displayName":"Age out documents older than n days Including documents with pending uploads (User)","description":"\r\n This policy controls when locally cached Office documents are aged out of the Office Document Cache including if the file may have pending uploads. This acts as a maximum possible age (in days) for any file to remain in the Office Document Cache.\r\n\r\n If you enable this policy setting, files older than the policy \"Age out documents older than n days\" as well as this setting will get cleaned up regardless of file pending upload status.\r\n\r\n If you disable this policy setting or if you do not configure this policy setting, Office will clean out only files that do not have pending changes per the policy \"Age out documents older than n days\". Configuring this policy with a value of 0 is also considered disabling the policy.\r\n\r\n For more information https://support.microsoft.com/en-us/topic/managing-office-document-cache-size-ea64af72-b597-408e-8ecf-fd55daa02476\r\n\r\n Note: This policy setting only applies to Office builds 19328.20000 and newer\r\n ","helpText":"","infoUrls":[],"categoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","categoryName":"Miscellaneous","options":[{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_office16v21~policy~l_microsoftofficesystem~l_miscellaneous437_l_ageoutpolicyincludingfilespendingupload_1","displayName":"Enabled","description":null,"helpText":null}]},"ff90e8a4792af587":{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier","displayName":"Multiplier for foreground sync interval for the currently viewed section stored on SharePoint (User)","description":"This policy setting allows you to increase the interval between foreground polls of a SharePoint site for changes to the currently viewed section.\r\n\r\nIf you enable this policy setting, OneNote will poll SharePoint less frequently for changes to the currently viewed section. Intervals are multiplied by the entered value, a positive integer value from 1 to 10. Larger intervals will slow section sync but reduce server load.\r\n\r\nIf you disable or do not configure this policy setting, OneNote will sync the currently viewed section at the default rate (multiplier value of 1).\r\n\r\nNote: This policy setting only applies to volume licensed versions of Office 2016 that use Windows Installer (MSI), such as Office Professional Plus 2016 and Office Standard 2016.","helpText":"","infoUrls":[],"categoryId":"ab8301d6-b122-4d40-868a-d00d3c0f1916","categoryName":"Other","options":[{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_onent16v3~policy~l_microsoftofficeonenote~l_onenoteoptions~l_other_l_sharepointlivesyncintervalmultiplier_1","displayName":"Enabled","description":null,"helpText":null}]},"fffa6c13b194aad0":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_folderhomepagesforoutlookspecialfolders_l_rssfolderhomepage_l_urladdressofassociatedwebpage","displayName":"URL address of associated web page: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"3f216590-fb12-4f8e-924f-2a6895d94126","categoryName":"Folder Home Pages for Outlook Special Folders","options":null},"ff405a6a7c391266":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_outlookoptions~l_preferences~l_junkemail_l_specifypathtoblockedsenderslist_l_specifyfullpathandfilenametoblockedsenderslist","displayName":"Specify full path and filename to Blocked Senders list (User)","description":"","helpText":"","infoUrls":[],"categoryId":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","categoryName":"Junk E-mail","options":null},"ffe7ec839715ab4f":{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook","displayName":"Do not allow Sharepoint-Outlook integration (User)","description":"This policy setting allows you to prevent access to Microsoft SharePoint Foundation with Outlook.\r\n\r\nIf you enable this policy setting, user profiles will not be able to upload new items or sync changes to the SharePoint list from the server; however, user profiles that have pre-existing SharePoint lists will retain their local data. In addition, new SharePoint lists cannot be connected when this policy setting is enabled. This can be toggled on and off to restore synchronization to existing lists. Note that users will not receive a message if synchronization has been prevented.\r\n\r\nIf you disable or do not configure this policy setting, Microsoft SharePoint Foundation access will be allowed with Outlook.","helpText":"","infoUrls":[],"categoryId":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","categoryName":"SharePoint Lists","options":[{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_outlk16v2~policy~l_microsoftofficeoutlook~l_toolsaccounts~l_sharepointintegration_l_disablesharepointintegrationinoutlook_1","displayName":"Enabled","description":null,"helpText":null}]},"ff7a5bb852782673":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics","displayName":"Print TrueType fonts as graphics (User)","description":"Checks/Unchecks the corresponding UI option.","helpText":"","infoUrls":[],"categoryId":"76b233cc-f977-4305-b02f-deef6667251d","categoryName":"Advanced","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics_0","displayName":"Disabled","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_advanced_l_printtruetypefontsasgraphics_1","displayName":"Enabled","description":null,"helpText":null}]},"ffe2af2ee0a579b2":{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59","displayName":"Allow sub folders: (User)","description":"","helpText":"","infoUrls":[],"categoryId":"76ad3567-c6cb-43b5-b91d-a52a34853c03","categoryName":"Trusted Locations","options":[{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_ppt16v2~policy~l_microsoftofficepowerpoint~l_powerpointoptions~l_security~l_trustcenter~l_trustedlocations_l_trustedloc15_l_allowsubfolders59_1","displayName":"True","description":null,"helpText":null}]},"ffd29843aa9dcd9e":{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99","displayName":"File tab | Options (User)","description":"","helpText":"","infoUrls":[],"categoryId":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","categoryName":"Predefined","options":[{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99_0","displayName":"False","description":null,"helpText":null},{"id":"user_vendor_msft_policy_config_visio16v2~policy~l_microsoftvisio~l_disableitemsinuserinterface~l_predefined_l_disablecommandbarbuttonsandmenuitems_l_visiooptions99_1","displayName":"True","description":null,"helpText":null}]}} \ No newline at end of file diff --git a/public/intuneCategories.json b/public/intuneCategories.json index 07353ca0444b..59f3636247f9 100644 --- a/public/intuneCategories.json +++ b/public/intuneCategories.json @@ -1 +1 @@ -[{"id":"005ddf8f-da22-4b23-ab02-289f8f6c7960","displayName":"Internet Explorer","description":"Administrative Templates Internet Explorer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["a1fbe395-3b60-475f-8a34-3710d6b2e09f","b491424f-100c-4f84-9b9c-8573b2ff9ac7","d4bf78d5-f6da-463d-85a3-d763e6fbe32b","3f6bb987-17dc-4442-a946-c1c5b1d089d7","f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","bd63ba46-330b-4c49-bfb7-114e1d0cf5e4"],"platforms":"windows10","technologies":"mdm"},{"id":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","displayName":"Startup, home page and new tab page","description":"Microsoft Edge\\Startup, home page and new tab page","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"0101d1d0-1e54-47b0-a749-62c6bd7ab3da","displayName":"BitLocker Drive Encryption","description":"Administrative Templates\\Windows Components\\BitLocker Drive Encryption","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["949a5b32-bbe6-40f6-9d73-99cf9fafe75f","27e0674a-ea53-4f63-9c2e-fe76aa1021d0","36aafec3-7ffb-4ab9-bef9-b8bb431bf8b3"],"platforms":"windows10","technologies":"mdm"},{"id":"015936bf-8273-4499-bb71-33b385ee7d16","displayName":"Hard Disk Settings","description":"Administrative Templates\\System\\Power Management\\Hard Disk Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01bbe7c3-10eb-40a3-8387-c74c33c294b1","displayName":"Video and Display Settings","description":"Administrative Templates\\System\\Power Management\\Video and Display Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01d16911-19a1-4dcb-8089-ffa4781d977c","displayName":"Windows Ink Workspace","description":"Windows Ink Workspace","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"01d16911-19a1-4dcb-8089-ffa4781d977c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01da0c26-af30-4eb2-a899-7d5e7ecb9738","displayName":"Video and Display Settings","description":"Administrative Templates Power Management Video and Display Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","displayName":"QoS Packet Scheduler","description":"Administrative Templates\\Network\\QoS Packet Scheduler","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["67c06154-a798-44bb-83c8-d706a3709c10","3426ef3d-40f5-474e-a493-4a1545c62348","82d20a08-90b8-4e6d-940a-5574844d1b26"],"platforms":"windows10","technologies":"mdm"},{"id":"023116df-a32c-43b0-a384-d6fe7ad9fabe","displayName":"WinRM Service","description":"Administrative Templates\\Windows Components\\Windows Remote Management (WinRM)\\WinRM Service","helpText":null,"parentCategoryId":"a37dba52-d558-47fb-9d46-a5d3bdc5fdd7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0236af48-9ce0-44d5-b085-de2323d7348e","displayName":"Scripting","description":"Administrative Templates\\System\\App-V\\Scripting","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"023e0367-b563-4fae-8fb6-589c836ee223","displayName":"Add or Remove Programs","description":"Administrative Templates Add or Remove Programs","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"025c640e-51e2-4f04-85e3-a13f30b5e08c","displayName":"Encoding","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Encoding","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"038b49c9-4f13-4ace-be8d-bd076bffa23e","displayName":"Save","description":"Microsoft Publisher 2016\\Publisher Options\\Save","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","displayName":"Security Account Manager","description":"Administrative Templates Security Account Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","displayName":"Manage Restricted Permissions","description":"Microsoft Office 2016\\Manage Restricted Permissions","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0456dcd5-c003-4a8b-80e6-61bacf854330","displayName":"RD Licensing","description":"Administrative Templates Remote Desktop Services RD Licensing","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","displayName":"Microsoft Publisher 2016","description":"Microsoft Publisher 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["9caa3b08-b545-4c21-a3b7-b5d2302c1a81","0cea32b4-28be-4164-ae2a-6db33b9dadb7","c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","c6c1120b-988c-4581-a21c-b9786a821242"],"platforms":"windows10","technologies":"mdm"},{"id":"0497eec4-fe3a-44f2-8caf-b5ab11839893","displayName":"Games","description":"Games","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0497eec4-fe3a-44f2-8caf-b5ab11839893","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"04b46099-4ee5-4def-8e04-569c988057a9","displayName":"Identity and sign-in","description":"Microsoft Edge - Default Settings (users can override)\\ Identity and sign-in","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"05305a87-0b19-41bb-bf1e-0bd92bfcdc16","displayName":"Push To Install","description":"Administrative Templates Push To Install","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"055293ad-c585-40c0-b66c-76ff5cc0a332","displayName":"Microsoft Office SmartArt","description":"Microsoft Office 2016\\Microsoft Office SmartArt","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"05811ceb-2954-426c-8afa-2a53f02480cc","displayName":"Permit or deny screen capture","description":"Microsoft Edge\\ Permit or deny screen capture","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"05a6f86f-dab7-4888-97a1-db3457f00974","displayName":"Writing Assistance","description":"Microsoft Office 2016 Writing Assistance","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"060e7533-6c2f-4ed1-9173-f3de58de4bed","displayName":"Internet Calendars","description":"Microsoft Outlook 2016\\Account Settings\\Internet Calendars","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0696109e-045f-486a-9a6b-ab7877887bed","displayName":"Document Information Panel","description":"Microsoft Office 2016\\Document Information Panel","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"06a85f5b-2614-4467-91cf-4a64d0c9326f","displayName":"Network Usage Rules","description":"Networking > Network Usage Rules","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"06c4a76a-805b-4370-9d80-08e720ab2305","displayName":"View options for time units in 'Project1'","description":"Microsoft Project 2016\\Project Options\\Edit\\View options for time units in 'Project1'","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"07221402-6a9c-4440-ae6f-3217ce5ad8fd","displayName":"Attack Surface Reduction","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Microsoft Defender Exploit Guard\\ Attack Surface Reduction","helpText":null,"parentCategoryId":"49abf969-2a98-4479-b234-6990b152cb21","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0775f21c-9ca1-446d-b1dc-3cea45f15605","displayName":"Files","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Files","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"07c023d3-0899-40af-a04f-805876d99a9b","displayName":"Microsoft Management Console","description":"Administrative Templates Microsoft Management Console","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["acb49e73-5a6a-479b-9d58-c3cd7f632e9b"],"platforms":"windows10","technologies":"mdm"},{"id":"08677354-6f67-455e-a430-4d8d2fbabe84","displayName":"Web Rtc settings","description":"Microsoft Edge Web Rtc settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"088b8d8d-5f3f-4979-aa18-b3c4b2616a24","displayName":"Sound Recorder","description":"Administrative Templates Sound Recorder","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","displayName":"Disk Quotas","description":"Administrative Templates Disk Quotas","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"08c5f391-e156-4a72-bbb9-3670f2f63a56","displayName":"SmartScreen settings","description":"Microsoft Edge\\SmartScreen settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"0937f5ff-aabc-49a9-a94f-6f98c4702580","displayName":"Qo S Packet Scheduler","description":"Administrative Templates Qo S Packet Scheduler","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["4ca3b8c7-0350-4043-b96d-918f24df0a3b","c87ae066-cc1a-44c9-8645-1db2359f7484","cf968979-f316-47cb-a207-bf9ef28cd1aa"],"platforms":"windows10","technologies":"mdm"},{"id":"098942c3-afe3-40c8-823f-37f0b5b13ad4","displayName":"Remote access","description":"Google Google Chrome Remote access","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"09c02465-dc11-457e-9eac-19fc542e4cda","displayName":"MAPS","description":"Administrative Templates Microsoft Defender Antivirus MAPS","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a1347d2-90c0-407a-baa0-e4859260532a","displayName":"BitLocker","description":"BitLocker","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","displayName":"General options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\General\\General options for 'Project1'","helpText":null,"parentCategoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a803a48-789a-48b0-b928-e52d56ab17f1","displayName":"Wi-Fi Settings","description":"Wi-Fi Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0a803a48-789a-48b0-b928-e52d56ab17f1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a9f982a-3515-4728-a231-fa000eb9e550","displayName":"User Preferences","description":"Preferences > User Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","displayName":"Profile Containers","description":"FS Logix Profile Containers","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["479c2edd-6539-4e1d-96ba-518d6f6264c3","719595d8-ab5d-4418-88aa-8cd55c2964ba"],"platforms":"windows10","technologies":"mdm"},{"id":"0b635a19-976c-4c28-a642-87ede7649bef","displayName":"Playback","description":"Administrative Templates\\Windows Components\\Windows Media Player\\Playback","helpText":null,"parentCategoryId":"22ebd92b-80b6-493d-99d8-3c72f1a0827e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0bae3158-5f75-4e25-acf4-859d2612f892","displayName":"Cloud Cache","description":"FS Logix ODFC Containers Cloud Cache","helpText":null,"parentCategoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0be23ead-c5f7-4ea5-9ec5-64c05d19cf5d","displayName":"Data Roaming","description":"Managed Settings Data Roaming","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"0be98651-a552-4470-b2dc-71c66a5ce1e6","displayName":"Presentation Services","description":"Microsoft Office 2016\\Present Online\\Presentation Services","helpText":null,"parentCategoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","displayName":"RD Connection Broker","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host RD Connection Broker","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0c2613c9-a7c7-4458-8b0d-2fff13e2beeb","displayName":"Connections","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Connections","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0cc63077-26e9-4fbd-a343-fd88102efd7e","displayName":"Application Compatibility","description":"Administrative Templates\\Windows Components\\Application Compatibility","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","displayName":"Security","description":"Microsoft Publisher 2016\\Security","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["30da5d88-cf03-41f4-ab55-51ead91b3844"],"platforms":"windows10","technologies":"mdm"},{"id":"0d37dddd-6575-485c-92dd-37a3c23edbf9","displayName":"BitLocker Drive Encryption","description":"Administrative Templates BitLocker Drive Encryption","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["acbc98d1-689b-4f9c-9c5a-e6bbf305e654","a18508d1-fd74-4955-8032-3bd9219a0944","8e6b8d0c-faf6-41e6-8e31-4389a5470caf"],"platforms":"windows10","technologies":"mdm"},{"id":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","displayName":"Content settings","description":"Microsoft Edge - Default Settings (users can override)\\Content settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","displayName":"System Logging","description":"System Configuration > System Logging","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","displayName":"Wireless Network Preference","description":"Wireless Network Preference","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0e1122f8-2bbf-475b-bce0-9e43a2f5e475","displayName":"Schedule Scan","description":"Microsoft Defender Schedule Scan","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"0e6c9053-73d6-4c56-9147-53513f6eefd8","displayName":"Windows Update For Business","description":"Windows Update For Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","displayName":"Microsoft Project 2016","description":"Microsoft Project 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["1266b519-e436-4698-8ff4-442acc97efd4","e344b25a-2046-4e70-a3b9-1a418613861f"],"platforms":"windows10","technologies":"mdm"},{"id":"0e937777-d01a-4180-a937-c2010451a529","displayName":"Login Window Login Items","description":"Login > Login Window Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0ef80736-8b59-4c6a-8bdc-e2b246b30e92","displayName":"Integration","description":"Administrative Templates\\System\\App-V\\Integration","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","displayName":"Windows Sandbox","description":"Windows Sandbox","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f42fc50-66c8-4b70-9904-64f8d662c930","displayName":"Custom","description":"Microsoft Word 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"740e7a10-3774-4a1c-9970-6907e0f0b848","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f6020d9-278b-4284-894a-bc4a70c8cf32","displayName":"Display Language","description":"Microsoft Office 2016\\Language Preferences\\Display Language","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","displayName":"Win RM Client","description":"Administrative Templates Windows Remote Management Win RM Win RM Client","helpText":null,"parentCategoryId":"364787de-93e4-4fd6-9608-dce1ad8f88c2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"10247787-95ea-4507-93de-dbd166df12b5","displayName":"Legacy Browser Support","description":"Google Google Chrome Legacy Browser Support","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1043e7ed-8651-44b2-b918-7230c0b75a6c","displayName":"Profile settings","description":"Microsoft Edge Profile settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","displayName":"Virtualization","description":"Administrative Templates App-V Virtualization","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"114356a4-dfc9-44e9-9a62-f1d601d48445","displayName":"Mail Setup","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Setup","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"119ca05b-5f1f-4714-a942-2a76b05d2a7b","displayName":"Lock Down","description":"Lock Down","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"119ca05b-5f1f-4714-a942-2a76b05d2a7b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"11c4cf0f-a03d-4309-93b2-011be4c410d5","displayName":"Screensaver User","description":"User Experience > Screensaver User","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"11d26400-1d13-4dd6-ab4b-cb323494b127","displayName":"Intelligence Settings","description":"Declarative Device Management preview Intelligence Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"120b24dd-c04a-4291-8f24-9c48fcdc1434","displayName":"Cryptography compliance policies","description":"Microsoft Edge Cryptography compliance policies","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12142994-4b30-486c-bab1-9206528b2b96","displayName":"Accessibility settings","description":"Google Google Chrome - Default Settings users can override Accessibility settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1219a9c2-dccb-445f-9f90-8e86e2de22d6","displayName":"Windows Remote Shell","description":"Administrative Templates\\Windows Components\\Windows Remote Shell","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1266b519-e436-4698-8ff4-442acc97efd4","displayName":"Project Options","description":"Microsoft Project 2016\\Project Options","helpText":null,"parentCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["db47f067-f435-4095-8b98-aa3805bc0050","84b7f123-e849-40f9-914b-4b97b57bd3b4","9ecb05b7-e942-4b60-9040-d612385f5c67","6ad0e199-ff50-4e86-b22f-b55ef4ff2329","28c4859e-1faa-4b51-96cf-068cb4354093","623d41fb-000e-41d8-b955-373f8c700def","3265b420-4c88-4f7b-92cc-4e23d9452eb1","20ed0d61-bbf7-421e-8926-0921c7ff7e75","8e48532a-ff0e-4422-82e2-6956b6786005","5bd8c27a-0141-4bbf-93f7-214b2389ff2d"],"platforms":"windows10","technologies":"mdm"},{"id":"12a1b259-a0d5-4505-aedf-b8ca811cd5f9","displayName":"Remote Assistance","description":"Administrative Templates\\System\\Remote Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","displayName":"Trusted Locations","description":"Microsoft Access 2016\\Application Settings\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","displayName":"Common Open File Dialog","description":"Administrative Templates Common Open File Dialog","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","displayName":"Customizable Error Messages","description":"Microsoft Word 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13123148-c522-437f-b316-d78f5cc0d28d","displayName":"Shared Workspace","description":"Microsoft Office 2016\\Global Options\\Customize\\Shared Workspace","helpText":null,"parentCategoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["725adbdf-1eb8-45c4-8eb1-44747bd1615d"],"platforms":"windows10","technologies":"mdm"},{"id":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","displayName":"AirPlay","description":"AirPlay > AirPlay","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"13467142-14e7-4380-8573-4866e842c7f6","displayName":"Antivirus engine","description":"Microsoft Defender > Antivirus engine","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"135e4013-43b8-4227-99fd-54ddeac4e329","displayName":"Protected View","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"139974ad-f615-442b-b3dc-84a44e3ec663","displayName":"Experience","description":"Experience","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13cc3b63-a150-4cf2-8d76-309975603c8e","displayName":"Loader Override Settings","description":"Microsoft Edge WebView2\\Loader Override Settings","helpText":null,"parentCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","rootCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13eb248a-4549-4d23-9ada-23b40edf36bf","displayName":"Reminder Options","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\Advanced\\Reminder Options","helpText":null,"parentCategoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","displayName":"Time Providers","description":"Administrative Templates Windows Time Service Time Providers","helpText":null,"parentCategoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13f62499-a266-42c8-a4dc-531efcea55cb","displayName":"Microsoft Edge Dev","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Dev","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"148a6f4e-8816-4c00-87a3-57481c85c331","displayName":"Startup Home page and New Tab page","description":"Google Google Chrome Startup Home page and New Tab page","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","displayName":"Kerberos","description":"Kerberos","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14fa4ad9-525c-440d-a295-a279c73f97f1","displayName":"Widgets","description":"Widgets","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14fa4ad9-525c-440d-a295-a279c73f97f1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","displayName":"Enterprise Cloud Print","description":"Enterprise Cloud Print","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","displayName":"Microsoft Lync Feature Policies","description":"Skype for Business 2016\\Microsoft Lync Feature Policies","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1526dde4-6726-470e-aebf-3272ae70a99c","displayName":"Server Manager","description":"Administrative Templates\\System\\Server Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1551f6d3-415c-44a8-b184-393de7c42adf","displayName":"Advanced Error Reporting Settings","description":"Administrative Templates Windows Error Reporting Advanced Error Reporting Settings","helpText":null,"parentCategoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"156f2e6a-6638-4749-9f43-e7acc4aba762","displayName":"Windows Installer","description":"Administrative Templates Windows Installer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"15be55d8-7477-4274-9b09-b775bce68416","displayName":"Software Update Enforce Latest","description":"Declarative Device Management preview Software Update Enforce Latest","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1638d9ec-63d5-4d6b-b1b6-4b0402268e36","displayName":"Tenant Restrictions","description":"Administrative Templates\\ Windows Components\\ Tenant Restrictions","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1653fa6c-aa99-4918-92c7-1df85d8843e1","displayName":"Startup, home page and new tab page","description":"Microsoft Edge - Default Settings (users can override)\\Startup, home page and new tab page","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1671dfc3-a1dd-4178-9093-10fb6b62586a","displayName":"Cryptography","description":"Microsoft Project 2016\\Project Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1671f10e-7300-46e3-a93f-ef38bf906cb1","displayName":"Mime Sniffing Safety Feature","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Mime Sniffing Safety Feature","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","displayName":"Scareware Blocker settings","description":"Microsoft Edge Scareware Blocker settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"1720d60f-40a6-471c-8e4c-efbacaf46997","displayName":"Cryptography","description":"Microsoft Outlook 2016\\Security\\Cryptography","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff"],"platforms":"windows10","technologies":"mdm"},{"id":"174ffe92-3770-4688-aa21-85b7535cf374","displayName":"Printing","description":"Printing > Printing","helpText":null,"parentCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","displayName":"Install and Update Settings","description":"Visual Studio Install and Update Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"176ed477-020a-41af-8859-0605c2caad98","displayName":"Portable Operating System","description":"Administrative Templates\\Windows Components\\Portable Operating System","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"17bc9899-d157-4eac-a949-810b4a841e28","displayName":"Restrict File Download","description":"Administrative Templates Internet Explorer Security Features Restrict File Download","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"17f0fdd3-e292-4ecb-ab5f-e4848e9cae1a","displayName":"Button Settings","description":"Administrative Templates\\System\\Power Management\\Button Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"180b2a03-16d4-43cd-ba84-9b4546753ef4","displayName":"Removable Storage Access","description":"Administrative Templates\\System\\Removable Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"18296501-4825-47ea-835d-66a01aba9384","displayName":"Notification bar","description":"Administrative Templates Internet Explorer Security Features Notification bar","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1829cdc1-1bed-4058-9aba-9b778cd3d955","displayName":"Global Preferences","description":"Preferences > Global Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"183628a3-d0a5-47de-b444-e132d634ca38","displayName":"Server Settings","description":"Microsoft Excel 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"184981d4-712b-425e-b0a3-93eac7fbd3ee","displayName":"Consent","description":"Administrative Templates Windows Error Reporting Consent","helpText":null,"parentCategoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"184aa343-0f0b-4bf5-aeeb-42111fedfbbf","displayName":"Internet Communication Management","description":"Administrative Templates\\System\\Internet Communication Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["72dfdba4-e7bb-4f09-862c-e003ea763452"],"platforms":"windows10","technologies":"mdm"},{"id":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","displayName":"Remote Assistance","description":"Administrative Templates Remote Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"187e5f4f-a789-4487-a848-7bf0f41597c7","displayName":"Preferences","description":"Preferences","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":["1829cdc1-1bed-4058-9aba-9b778cd3d955","0a9f982a-3515-4728-a231-fa000eb9e550","c7c1ed5a-a2ec-4237-bbf1-d5723f94d033"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"18893f00-c309-4695-bcaf-b66286ad99c1","displayName":"Camera","description":"Camera","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"18893f00-c309-4695-bcaf-b66286ad99c1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"18b972fd-74f2-4345-9449-087c80dd38a3","displayName":"Windows Boot Performance Diagnostics","description":"Administrative Templates Windows Boot Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"18db3d59-661b-47ec-900a-bf75495ca598","displayName":"Regional and Language Options","description":"Administrative Templates\\Control Panel\\Regional and Language Options","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["e50b312c-2bb3-4565-9212-080dba8d3d85"],"platforms":"windows10","technologies":"mdm"},{"id":"191a84f2-13b5-4609-808f-8b743b7f0247","displayName":"Microsoft Outlook","description":"Microsoft Outlook > Microsoft Outlook","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1942922a-cba9-44c8-871f-3d915c62bd06","displayName":"Help","description":"Microsoft Office 2016\\Help","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","displayName":"Driver Installation","description":"Administrative Templates Driver Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1979a12b-2a72-438d-9de7-320d1b38e777","displayName":"Password","description":"Microsoft OneNote 2016\\OneNote Options\\Password","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"19ab385f-14f5-47cd-87b2-f4784eedcdd9","displayName":"Windows Media Digital Rights Management","description":"Administrative Templates Windows Media Digital Rights Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"19ba782c-3594-45da-b829-72b54f6d45c7","displayName":"Microsoft OneDrive","description":"Microsoft Office > Microsoft OneDrive","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1a0386fd-354b-441e-a0d6-1523c209dae7","displayName":"General","description":"Microsoft Publisher 2016\\Publisher Options\\General","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1a056b49-3fb9-4097-b286-c5f493208578","displayName":"Personal Hotspot","description":"Managed Settings Personal Hotspot","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"1a2a4fc8-c54b-4906-a422-7dd51a196211","displayName":"Setup","description":"Administrative Templates Event Log Service Setup","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ae8c95a-5748-4647-80f8-b447e60601a2","displayName":"Add-ins","description":"Microsoft OneNote 2016\\OneNote Options\\Add-ins","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1aef6e33-cb5c-4ad5-b433-c198750bbc98","displayName":"Locked-Down Local Machine Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Local Machine Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1b1be733-8615-4738-8797-c159d4d484be","displayName":"Wireless Display","description":"Administrative Templates\\Network\\Wireless Display","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","displayName":"Preferences","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["2fbb7677-651a-4b62-8b8c-d502ea29936b","decab1d2-3474-4727-87c0-d0bc648f2458","8e7b730f-c3c9-4e04-9e45-ce06be97908c","d0a1763a-5cdf-4672-8596-435ec1d94b54","2b03e224-c77c-4bb0-8491-cec0b64d9a86"],"platforms":"windows10","technologies":"mdm"},{"id":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","displayName":"Excel Options","description":"Microsoft Excel 2016\\Excel Options","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","67eb1dab-7805-41bb-af5a-798dc7e29f23","d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","5886bba1-bc05-46ca-afbf-66d1b4265ca4","3503e1ba-8168-4b55-92b1-84613292cadc","9215e382-4e7b-4554-8c80-80277136b544","cd1855c4-f7d1-4bed-8d6e-b8c1aab72007"],"platforms":"windows10","technologies":"mdm"},{"id":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","displayName":"Default message text for a reply...","description":"Microsoft Office 2016\\Collaboration Settings\\Default message text for a reply...","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","displayName":"Spelling","description":"Microsoft OneNote 2016\\OneNote Options\\Spelling","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","displayName":"Lanman Server","description":"Lanman Server","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ccd3115-55e7-464f-9bb9-d38a92191306","displayName":"Edge Website Typo Protection settings","description":"Microsoft Edge - Default Settings users can override Edge Website Typo Protection settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1cda8821-d9e2-485e-8d78-1829593d41ca","displayName":"BranchCache","description":"Administrative Templates\\Network\\BranchCache","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1d5e7986-870c-444b-bf09-78bbf82a53fa","displayName":"Personal Data Encryption","description":"Personal Data Encryption","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1d6d392c-8b32-459b-b114-af964a4bbbc5","displayName":"Certificate management settings","description":"Google Google Chrome Certificate management settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","displayName":"Digital Locker","description":"Administrative Templates Digital Locker","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1dd655c9-a1f3-4780-befb-cab19922277d","displayName":"Personalization","description":"Personalization","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ed81d90-7326-4d0b-8934-b0a8bdddc5ce","displayName":"App runtime","description":"Administrative Templates\\Windows Components\\App runtime","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ed9f90e-d8b6-413f-bfc2-face955141bc","displayName":"Windows Mobility Center","description":"Administrative Templates Windows Mobility Center","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1f31ae2d-4867-4733-b52c-cecc0128e10c","displayName":"Scheduled Maintenance","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Scheduled Maintenance","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1f5d8243-cb7e-4b52-a12f-5f0e070d2769","displayName":"Virtualization","description":"Administrative Templates\\System\\App-V\\Virtualization","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1fa3b0c3-e453-4ef3-80aa-a7474d8eb354","displayName":"Digital Locker","description":"Administrative Templates\\Windows Components\\Digital Locker","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1fbc29d7-0530-4208-b506-9df648a402e9","displayName":"Voice Roaming","description":"Managed Settings Voice Roaming","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","displayName":"Recovery Lock Password","description":"Recovery Lock Password","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1fddd12c-a630-47f0-9633-638808e228f9","displayName":"Review Tab","description":"Microsoft Word 2016\\Review Tab","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["d79c9f9a-f469-4f39-a66a-6f7d5ee77e81","7bee4dea-82a4-4a03-b903-654b374819b1"],"platforms":"windows10","technologies":"mdm"},{"id":"200c575d-37d9-405b-aa92-c7a3da6f9358","displayName":"User Interface","description":"Administrative Templates\\Windows Components\\Windows Media Player\\User Interface","helpText":null,"parentCategoryId":"22ebd92b-80b6-493d-99d8-3c72f1a0827e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","displayName":"Platform Update","description":"Microsoft Defender Platform Update","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"20b71dc7-cf08-4534-9e52-d297dd071ca5","displayName":"Enhanced Phishing Protection","description":"Smart Screen\\ Enhanced Phishing Protection","helpText":null,"parentCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","rootCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20bacabf-cd07-48be-a184-f0ae76d31e4a","displayName":"Contact Tab","description":"Microsoft Office 2016\\Contact Card\\Contact Tab","helpText":null,"parentCategoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20ceae56-e189-46ec-a440-791ce7454017","displayName":"Printing","description":"Google Google Chrome - Default Settings users can override Printing","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","displayName":"Calculation","description":"Microsoft Project 2016\\Project Options\\Calculation","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","ed137c3d-d7bc-48f3-ad86-ff194fc6820d"],"platforms":"windows10","technologies":"mdm"},{"id":"2108b443-384c-4bb3-9b9f-acb4a754a86a","displayName":"Web Options...","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["d804205d-6c12-4f40-86a0-aa5a5355370f","56e510be-ca39-46a2-9eb2-6f1af6d4b16a"],"platforms":"windows10","technologies":"mdm"},{"id":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","displayName":"Attack Surface Reduction","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard Attack Surface Reduction","helpText":null,"parentCategoryId":"ad84cea3-5664-4e42-a9d6-1446828bea45","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"216de445-a80d-4981-b151-3b4466edc808","displayName":"Extensions","description":"Google Google Chrome Extensions","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"22086dab-6c7f-408f-bd0c-cc34b2ad086d","displayName":"Ctrl+Alt+Del Options","description":"Administrative Templates\\System\\Ctrl+Alt+Del Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"224dc683-c0e0-4783-8ba8-8f02c76d161d","displayName":"Domains","description":"Networking > Domains","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"2257f7e1-3e88-4d4d-a666-437bbe42baca","displayName":"Applications","description":"Device Restriction Applications","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"22a2a407-0f28-481d-bdbe-1f9cb6d589c3","displayName":" EDR preferences","description":"Microsoft Defender EDR preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"22ebd92b-80b6-493d-99d8-3c72f1a0827e","displayName":"Windows Media Player","description":"Administrative Templates\\Windows Components\\Windows Media Player","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["c7c32942-a139-4d7e-a19e-3495d5e372e7","200c575d-37d9-405b-aa92-c7a3da6f9358","0b635a19-976c-4c28-a642-87ede7649bef"],"platforms":"windows10","technologies":"mdm"},{"id":"22f2b16b-e1af-45fa-8d2f-687854b72c02","displayName":"Data Protection","description":"Data Protection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"22f2b16b-e1af-45fa-8d2f-687854b72c02","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","displayName":"Login","description":"Login","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":["0e937777-d01a-4180-a937-c2010451a529","6efb8802-223a-46a7-b13f-a68f28f8b2c2","9859957e-34f1-4669-9f95-2b7c79fff052","8f831e0a-feb7-4cbb-acc1-2e583f3f4de3"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"2373de26-8270-4e74-a53f-9aeb55d5553c","displayName":"Microsoft AutoUpdate (MAU)","description":"Microsoft AutoUpdate (MAU)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"23c09e06-5bee-4b20-a391-36549bf0f620","displayName":"Signing","description":"Microsoft Office 2016\\Signing","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"23e93393-4a75-44e6-9693-208eedb06976","displayName":"Advanced Error Reporting Settings","description":"Administrative Templates\\Windows Components\\Windows Error Reporting\\Advanced Error Reporting Settings","helpText":null,"parentCategoryId":"d9b7efad-fe18-4c98-925b-c4a5db0f2815","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"23fd467e-24f8-4200-8b19-c6c11afa8926","displayName":"Security","description":"Microsoft Access 2016\\Application Settings\\Security","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["7eaa5e09-e5ab-4051-b557-64a124ae497c","a9edc695-b4a9-4111-b07d-627f934f5a1a"],"platforms":"windows10","technologies":"mdm"},{"id":"2461b964-02f6-4da2-921a-f7e8f868c69d","displayName":"Enhanced Storage Access","description":"Administrative Templates Enhanced Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"24b30053-14d2-4430-9966-281e926a6918","displayName":"Trusted Platform Module Services","description":"Administrative Templates Trusted Platform Module Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"24f6d328-64e7-4490-be38-452ac3b61f6f","displayName":"Trusted Catalogs","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Trusted Catalogs","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"251c6873-bf5b-4d85-8185-3c4973b6f33c","displayName":"Show","description":"Microsoft Project 2016\\Project Options\\View\\Show","helpText":null,"parentCategoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"253fda23-118b-48c7-b24a-27b8c93df41a","displayName":"Macro Security","description":"Microsoft Visio 2016\\Visio Options\\Security\\Macro Security","helpText":null,"parentCategoryId":"2ea63962-4cac-4a5c-9181-e6a364489db0","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","displayName":"Planner Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Planner Options","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"25a84f2d-dbac-457e-b734-bc2605305f2b","displayName":"Cryptography","description":"Microsoft OneNote 2016\\OneNote Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"25df12bc-5ebd-4db2-8930-5d27690f3e60","displayName":"Message Format","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Internet Formatting\\Message Format","helpText":null,"parentCategoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"264202da-475b-476e-bbc7-3c252f777145","displayName":"Device security group","description":"Device security group","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"264202da-475b-476e-bbc7-3c252f777145","childCategoryIds":[],"platforms":"windows10","technologies":"enrollment"},{"id":"2694014c-e044-45a0-99b1-1694bd01827a","displayName":"User Accounts","description":"Administrative Templates\\Control Panel\\User Accounts","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"269c487f-8902-486a-88dd-db9b9b4454b8","displayName":"Network protection","description":"Microsoft Defender Network protection","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"26c1af84-7c09-4910-8b2f-486072fef710","displayName":"Kiosk Browser","description":"Kiosk Browser","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"26c1af84-7c09-4910-8b2f-486072fef710","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"26dfd0a7-546b-4583-b0c7-85b98ac5a40c","displayName":"Tools | Macro","description":"Microsoft Project 2016\\Project Options\\Security\\Tools | Macro","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27087ae6-d02f-4b54-a143-6cde89c04989","displayName":"Device and Driver Compatibility","description":"Administrative Templates Device and Driver Compatibility","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2764869c-54a3-462b-bc72-c580621ab6bb","displayName":"Customize Ribbon","description":"Microsoft Visio 2016\\Visio Options\\Customize Ribbon","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","displayName":"Cryptography","description":"Microsoft Excel 2016\\Excel Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27e0674a-ea53-4f63-9c2e-fe76aa1021d0","displayName":"Operating System Drives","description":"Administrative Templates\\Windows Components\\BitLocker Drive Encryption\\Operating System Drives","helpText":null,"parentCategoryId":"0101d1d0-1e54-47b0-a749-62c6bd7ab3da","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","displayName":"Default message text for a review request...","description":"Microsoft Office 2016\\Collaboration Settings\\Default message text for a review request...","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28831364-ca54-4f31-acca-1aa0c7a7d3d2","displayName":"Data Recovery","description":"Microsoft Excel 2016\\Data Recovery","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28ab8eed-623a-4e9b-813e-13256472dbaf","displayName":"Customizable Error Messages","description":"Microsoft PowerPoint 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28c4859e-1faa-4b51-96cf-068cb4354093","displayName":"View","description":"Microsoft Project 2016\\Project Options\\View","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","251c6873-bf5b-4d85-8185-3c4973b6f33c"],"platforms":"windows10","technologies":"mdm"},{"id":"290ec637-e780-4e95-9834-6368ac0437d1","displayName":"Power Management","description":"Administrative Templates Power Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["3b64e99d-0359-4264-be38-c544c647f493","7226f8a2-c542-471a-8d9e-e0df527325d3","86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","01da0c26-af30-4eb2-a899-7d5e7ecb9738","5d03766c-9480-43f2-9e85-461a44c821d4","91c02e14-8848-485d-8844-b9933fa888ec"],"platforms":"windows10","technologies":"mdm"},{"id":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","displayName":"MIME to MAPI Conversion","description":"Microsoft Outlook 2016\\MIME to MAPI Conversion","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"297f09f9-0a48-4058-81b8-66a630a3c0ea","displayName":"Disk NV Cache","description":"Administrative Templates\\System\\Disk NV Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","displayName":"Device and Resource Redirection","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Device and Resource Redirection","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2ac8fe19-ca17-4533-8818-a5e12030de51","displayName":"MSI Corrupted File Recovery","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\MSI Corrupted File Recovery","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2af24920-f611-4f03-99a6-205773869ae6","displayName":"Protected Content","description":"Microsoft Edge Protected Content","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","displayName":"Contact Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Contact Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b3d275d-4a48-4ac8-9c14-4dc5aa20a80b","displayName":"Network Sharing","description":"Administrative Templates Network Sharing","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b54b208-5459-4e40-8db1-002cb90495bc","displayName":"Windows Memory Leak Diagnosis","description":"Administrative Templates Windows Memory Leak Diagnosis","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b8e43c0-e66b-4bec-b20d-54a1f7151212","displayName":"Display","description":"Administrative Templates\\Control Panel\\Display","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","displayName":"Printers","description":"Administrative Templates\\Printers","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2c156b7e-99c8-4a21-a828-4f9b94479b0d","displayName":"Time Zone","description":"Managed Settings Time Zone","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","displayName":"Threats","description":"Administrative Templates Microsoft Defender Antivirus Threats","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","displayName":"Applications","description":"Microsoft Edge Update\\Applications","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":["797ac384-f48e-4567-b931-33a6ce923b94","7b91ab31-7ed5-4de9-bd49-d04303fd3c74","13f62499-a266-42c8-a4dc-531efcea55cb","3bb9ca38-645e-479c-ac5f-01959aec9c30"],"platforms":"windows10","technologies":"mdm"},{"id":"2cbf2609-1f6a-4597-84e2-a57da0ad0472","displayName":"Locale Services","description":"Administrative Templates\\System\\Locale Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2cc013ad-e5a3-42d9-b2b6-2a872a4c086d","displayName":"Session Time Limits","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Session Time Limits","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","displayName":"Passcode","description":"Declarative Device Management (DDM)\\ Passcode","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"2d5a483f-b408-426d-9234-2883eae20afb","displayName":"Tools | Options | General | Web Options...","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["025c640e-51e2-4f04-85e3-a13f30b5e08c","8ee1d8d2-582f-401b-927a-993016f4290d","0775f21c-9ca1-446d-b1dc-3cea45f15605","eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510"],"platforms":"windows10","technologies":"mdm"},{"id":"2d6891a4-ee83-4e55-8e23-09513e1306e4","displayName":"Microsoft Office Document Cache","description":"Microsoft Office 2016\\Microsoft Office Document Cache","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2d842579-300e-4a24-bc42-7c39af62c468","displayName":"File Share Shadow Copy Provider","description":"Administrative Templates\\System\\File Share Shadow Copy Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2d8634c7-19ca-46e0-923d-019ba18ff4e0","displayName":"RD Licensing","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\RD Licensing","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2dc7de59-a2b5-4f4a-96a4-597927af0617","displayName":"AutoPlay Policies","description":"Administrative Templates\\Windows Components\\AutoPlay Policies","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","displayName":"Kerberos","description":"Administrative Templates Kerberos","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e241b46-e5ae-41d7-a559-fe40819e86f4","displayName":"Typosquatting Checker settings","description":"Microsoft Edge\\ Typosquatting Checker settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e3f0407-6387-41b4-b6c2-ada4354be759","displayName":"Licensing Settings","description":"Microsoft Office 2016 (Machine)\\Licensing Settings","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e57e23c-4847-4864-8e8e-5f6add1f7a84","displayName":"Windows Color System","description":"Administrative Templates\\Windows Components\\Windows Color System","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e71c6fd-dafa-444d-9542-55d838331939","displayName":"NTFS","description":"Administrative Templates\\System\\Filesystem\\NTFS","helpText":null,"parentCategoryId":"50fb9f56-84f1-4fa9-83f5-0aa0bca8ff49","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2ea4b701-fcb8-46b2-a83f-c792b861f5ad","displayName":"Accessories","description":"Administrative Templates\\Windows Components\\Tablet PC\\Accessories","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2ea63962-4cac-4a5c-9181-e6a364489db0","displayName":"Security","description":"Microsoft Visio 2016\\Visio Options\\Security","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["f34e3da0-b440-43dc-a368-4fd39646a9c5","253fda23-118b-48c7-b24a-27b8c93df41a"],"platforms":"windows10","technologies":"mdm"},{"id":"2eed22da-106f-4c93-9a45-5ce803b50233","displayName":"Offline Editing","description":"Microsoft Visio 2016\\Visio Options\\Save\\Offline Editing","helpText":null,"parentCategoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","displayName":"Sudo","description":"Sudo","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f56761a-8e8b-4788-a589-a73ab91818e6","displayName":"Web Archives","description":"Microsoft Office 2016\\Web Archives","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f6205e9-8680-4b8f-97f3-be12e252e038","displayName":"Track changes and compare","description":"Microsoft Word 2016\\Word Options\\Track changes and compare","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f85405a-7472-44ce-8c05-b59bb54912d5","displayName":"Playback","description":"Administrative Templates Windows Media Player Playback","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","displayName":"Trusted Locations","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2fbb7677-651a-4b62-8b8c-d502ea29936b","displayName":"E-mail Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["897675f9-0d1b-437b-ba0a-584fbd54df95","71f4af65-b7fa-4c54-bf73-19b0c7ffe162"],"platforms":"windows10","technologies":"mdm"},{"id":"304a579b-ff3b-4897-8bb8-5a1dda45356f","displayName":"Schedule options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Schedule\\Schedule options for Microsoft Project","helpText":null,"parentCategoryId":"db47f067-f435-4095-8b98-aa3805bc0050","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","displayName":"Background Intelligent Transfer Service BITS","description":"Administrative Templates Background Intelligent Transfer Service BITS","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30da5d88-cf03-41f4-ab55-51ead91b3844","displayName":"Trust Center","description":"Microsoft Publisher 2016\\Security\\Trust Center","helpText":null,"parentCategoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30fcb92f-4d0c-4dbf-95d0-a86350e9efc6","displayName":"Hotspot Authentication","description":"Administrative Templates\\Network\\Hotspot Authentication","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"31070051-859e-4d27-9df3-c07b8a2d2179","displayName":"Word Options","description":"Microsoft Word 2016\\Word Options","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","dc049161-17c6-411e-906b-a871b33651cd","2f6205e9-8680-4b8f-97f3-be12e252e038","89be4acb-fdf9-447b-ad16-9a5af1d68b8b","ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","f9e53433-d8d9-4eaf-bdf3-d32de60d686e","bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","83087772-6560-4488-a1c5-bb6e4889e868"],"platforms":"windows10","technologies":"mdm"},{"id":"311e1dac-a77c-4bc0-a376-35ad55923b7d","displayName":"Start","description":"Start","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3181c361-f4f0-44ff-82cc-24aac8075843","displayName":"Sound Recorder","description":"Administrative Templates\\Windows Components\\Sound Recorder","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"31d3b4c4-767e-403a-834c-51f3691bbf2b","displayName":"Security Center","description":"Administrative Templates Security Center","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"320ccaa3-a391-4d29-a9c4-594561f4104d","displayName":"Miscellaneous","description":"Microsoft Word 2016\\Miscellaneous","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["b206e4ef-a288-4fb7-a7ee-4a30b4df3b98"],"platforms":"windows10","technologies":"mdm"},{"id":"32180186-7378-4d45-b0cc-c533a124bdbc","displayName":"Access- Denied Assistance","description":"Administrative Templates Access- Denied Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","displayName":"General","description":"Microsoft Project 2016\\Project Options\\General","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["0a6bc3ed-c4cd-4928-bcbf-247369a51515","501e47c0-6c18-4a88-9366-adc0bbc2c9b4"],"platforms":"windows10","technologies":"mdm"},{"id":"32b20540-8fe9-4730-a4b0-ff41f6b13a97","displayName":"Windows System Responsiveness Performance Diagnostics","description":"Administrative Templates Windows System Responsiveness Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","displayName":"Microsoft Office 2016 (Machine)","description":"Microsoft Office 2016 (Machine)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":["5d8272e2-1ed3-4a8d-9555-9a87fa13d078","712d184f-d9ac-45fc-9eea-aade3a22b55e","f0190b73-0d5c-410e-bce1-e03aa1f62ed4","2e3f0407-6387-41b4-b6c2-ada4354be759","8c879ddf-7acf-45f3-81d3-2c78c7a1321b","86dae9f9-7eb1-4566-8558-b63fa2e20fee"],"platforms":"windows10","technologies":"mdm"},{"id":"32ee73d6-947f-45e9-856b-793b584c626d","displayName":"MAPS","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\MAPS","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","displayName":"","description":"Administrative Templates","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33a43c22-104b-4683-995b-5652cfd5b490","displayName":"Windows AI","description":"Windows AI","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"33a43c22-104b-4683-995b-5652cfd5b490","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33b9194b-4027-4c23-b662-52f25db7f839","displayName":"International","description":"Microsoft Access 2016\\Application Settings\\International","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33fb4f49-5c7f-472c-a0f3-e05646a55902","displayName":"Improved Error Reporting","description":"Microsoft Office 2016\\Improved Error Reporting","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3426ef3d-40f5-474e-a493-4a1545c62348","displayName":"DSCP value of conforming packets","description":"Administrative Templates\\Network\\QoS Packet Scheduler\\DSCP value of conforming packets","helpText":null,"parentCategoryId":"01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"343eb575-3ac8-4da9-b66d-ce84b84be7c3","displayName":"Project Guide settings","description":"Microsoft Project 2016\\Project Options\\Interface\\Project Guide settings","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3453c694-bc38-4082-9d3d-886e385df927","displayName":"Event Viewer","description":"Administrative Templates Event Viewer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","displayName":"Window Frame Coloring","description":"Administrative Templates Desktop Window Manager Window Frame Coloring","helpText":null,"parentCategoryId":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"34c07941-8f52-43ad-b0ca-a7284655afb4","displayName":"Office.com Sharing Service","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Office.com Sharing Service","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3503e1ba-8168-4b55-92b1-84613292cadc","displayName":"Advanced","description":"Microsoft Excel 2016\\Excel Options\\Advanced","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d"],"platforms":"windows10","technologies":"mdm"},{"id":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","displayName":"Editing Languages","description":"Microsoft Office 2016\\Language Preferences\\Editing Languages","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["60ea21c6-4c2b-4510-83f4-3a2d04fd99a0"],"platforms":"windows10","technologies":"mdm"},{"id":"35525ba9-da99-460e-afd3-ba86506b0ba3","displayName":"File Explorer","description":"Administrative Templates\\Windows Components\\File Explorer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["7c34b514-0fb4-4868-8418-cb9b28f9f6e3","93decccd-de24-4ec4-b21c-e08c14f13576","e21bab5b-308d-4dcd-b6bb-a019e7347373"],"platforms":"windows10","technologies":"mdm"},{"id":"3588f84a-69de-4900-910c-09a5b69e5d99","displayName":"Virtualization Based Technology","description":"Virtualization Based Technology","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3588f84a-69de-4900-910c-09a5b69e5d99","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"35f245bd-8d1f-424c-83de-a80be27a6a4e","displayName":"Desktop Alert","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Advanced E-mail Options\\Desktop Alert","helpText":null,"parentCategoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"361859d9-1382-47c3-b9ec-9251a62fbb25","displayName":"Time Machine","description":"User Experience > Time Machine","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","displayName":"System Policy Control","description":"System Policy","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":["64538726-8745-4e7a-b370-332f725b58bf","763525a0-8456-4336-a8d1-392253e8fdd8"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","displayName":"Removed policies","description":"Google Google Chrome Removed policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"363982dd-fc96-49ce-a499-f6401f2c212b","displayName":"iSCSI","description":"Administrative Templates\\System\\iSCSI","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f5e39798-0511-462f-b859-f892fdde4328","b62de64d-03ed-4e09-be5c-5cc93e34ea47","7d7f6a09-2088-4f1f-a1f1-14fbca93a808"],"platforms":"windows10","technologies":"mdm"},{"id":"364787de-93e4-4fd6-9608-dce1ad8f88c2","displayName":"Windows Remote Management Win RM","description":"Administrative Templates Windows Remote Management Win RM","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","0f6d725e-2c2d-4926-8e78-3d2d5867eef5"],"platforms":"windows10","technologies":"mdm"},{"id":"366a0d4a-8f27-44e7-82d0-d2eafe5b6d6f","displayName":"Windows Standby/Resume Performance Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Standby/Resume Performance Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"36aafec3-7ffb-4ab9-bef9-b8bb431bf8b3","displayName":"Fixed Data Drives","description":"Administrative Templates\\Windows Components\\BitLocker Drive Encryption\\Fixed Data Drives","helpText":null,"parentCategoryId":"0101d1d0-1e54-47b0-a749-62c6bd7ab3da","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","displayName":"Google Chrome","description":"Google Google Chrome","helpText":null,"parentCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["1d6d392c-8b32-459b-b114-af964a4bbbc5","fa2722a8-dcfd-4e14-a429-2b0041642c77","3634c01b-1a85-4f50-9f52-63bc10bf0e39","b811c4fe-7ff0-4bd1-a454-0918d4e2f896","d9432f48-3072-4171-9031-4ebead394151","5900ac65-f656-459c-bd82-1329a862544d","5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","d4ad9168-8c49-45d6-a7e5-86ba990fff3e","ac821e49-1996-4d6c-99d4-9c3c3e4737b6","216de445-a80d-4981-b151-3b4466edc808","da78ddbc-fc94-48f9-8808-4b160d6f1d50","f7486553-9e63-4d63-9423-56e5ffe48700","b46f4e70-d3d1-4177-8e22-62f806d4568c","62499519-97eb-43e7-ae96-d7909c5820d3","59d29716-55b0-4014-a458-38b408ff9530","70498fad-5ddb-4730-8130-d755ff675760","93ed2300-658d-40f3-8211-9295a240579c","8c35f124-e249-43e3-9044-ecc0b0a5855a","f66e6bf2-a437-4d36-b46c-e965b31a5d4f","a5a38799-7bf1-4b83-86fe-62729cd9ed9d","4cd10f38-02cf-40f2-aa87-ad70a2190a1a","f00e9baf-9bbf-48e4-aaac-57410730f016","463e6791-7d54-4964-a36b-63bbedb7d0cd","148a6f4e-8816-4c00-87a3-57481c85c331","4aa852ab-6269-4883-906f-0a0944fa1261","895e0884-6b60-4bb0-b2ab-3a1642103db7","10247787-95ea-4507-93de-dbd166df12b5","098942c3-afe3-40c8-823f-37f0b5b13ad4","b485695b-0fae-41ae-861c-3030769b28df"],"platforms":"windows10","technologies":"mdm"},{"id":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","displayName":"Trust Center","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"85810387-3320-4056-bae2-953beeb246f7","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["42ce9a9b-0574-4b5c-993b-7679de80be47","76ad3567-c6cb-43b5-b91d-a52a34853c03","4d69af55-f100-45fa-92e1-56d46434c647"],"platforms":"windows10","technologies":"mdm"},{"id":"3800661e-5841-4499-8d4e-914527435f59","displayName":"Streaming","description":"Administrative Templates\\System\\App-V\\Streaming","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"394ae912-b5c9-45a0-8883-84791c6acb16","displayName":"RemoteApp and Desktop Connections","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\RemoteApp and Desktop Connections","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"394b2dfb-3404-4668-94af-5acc825fcf51","displayName":"System Restore","description":"Administrative Templates\\System\\System Restore","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"395a548d-737b-41fe-8449-c68c51e3a349","displayName":"Input Panel","description":"Administrative Templates Input Panel","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3969f56d-a8b5-4509-86fb-00eb481665fa","displayName":"Advanced Page","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Advanced Page","helpText":null,"parentCategoryId":"586c5c5a-15cd-4592-beae-1709c6daf5b7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"39e4c352-be9c-4e75-8111-8236279c7f1e","displayName":"Cloud Desktop","description":"Cloud Desktop","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3a28f10c-cb75-4f85-871b-87eb9dcd883c","displayName":"TCPIP Settings","description":"Administrative Templates\\Network\\TCPIP Settings","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f52d9745-eaf4-4e39-84b2-6b32c3b15aa3","d512207c-854d-482d-8e52-26637eef24e3"],"platforms":"windows10","technologies":"mdm"},{"id":"3a901a80-e2b6-470c-9658-d66ba5458370","displayName":"Remote App and Desktop Connections","description":"Administrative Templates Remote Desktop Services Remote App and Desktop Connections","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","displayName":"Certificate management settings","description":"Microsoft Edge Certificate management settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3afbcb74-88c5-4a41-bdc2-82c117b4e82e","displayName":"Applications","description":"Administrative Templates\\Windows Components\\Microsoft User Experience Virtualization\\Applications","helpText":null,"parentCategoryId":"9e857bed-81f8-4dfc-b049-c93eb68b4064","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","displayName":"Scheduling options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Schedule\\Scheduling options for 'Project1'","helpText":null,"parentCategoryId":"db47f067-f435-4095-8b98-aa3805bc0050","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","displayName":"Account Management","description":"Account Management","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b64e99d-0359-4264-be38-c544c647f493","displayName":"Sleep Settings","description":"Administrative Templates Power Management Sleep Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b7e16e7-171f-4169-8904-c8483b06700d","displayName":"Custom","description":"Microsoft Excel 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","displayName":"Password manager and protection","description":"Microsoft Edge\\Password manager and protection","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3bb9ca38-645e-479c-ac5f-01959aec9c30","displayName":"Microsoft Edge","description":"Microsoft Edge Update\\Applications\\Microsoft Edge","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","displayName":"Protection From Zone Elevation","description":"Administrative Templates Internet Explorer Security Features Protection From Zone Elevation","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3c46dc04-e649-41b9-be99-04b771303fdd","displayName":"eSIM","description":"eSIM","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3c7f15ef-a539-411c-93f1-5f97b7bd5519","displayName":"Bluetooth","description":"Managed Settings Bluetooth","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3ccd987e-bfca-4838-98ea-576de34b3ebe","displayName":"Certain Hours","description":"Certain Hours","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3ccd987e-bfca-4838-98ea-576de34b3ebe","childCategoryIds":[],"platforms":"android,iOS","technologies":"exchangeOnline"},{"id":"3d32fb39-ff23-48d9-9890-c8625d2d21e9","displayName":"Group Policy","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins\\Group Policy","helpText":null,"parentCategoryId":"9e882396-4a1c-4d06-a62d-8d910ded8e7d","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["61205786-952e-489c-91f7-5654a5bde11b","814e9e4d-b838-4747-a257-72390a535d56"],"platforms":"windows10","technologies":"mdm"},{"id":"3db7e884-6077-4b96-ace3-005a6b49ecc0","displayName":"Hyperlink appearance in 'Project1'","description":"Microsoft Project 2016\\Project Options\\Edit\\Hyperlink appearance in 'Project1'","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3deb76aa-8336-4ff9-aa98-4dcaf8901468","displayName":"Shutdown","description":"Administrative Templates\\System\\Shutdown","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3e50e056-24bf-46c3-975f-b0aedbc96329","displayName":"Protection From Zone Elevation","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Protection From Zone Elevation","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3e98c3bc-254c-445f-a1c8-4a93c2e0fcf2","displayName":"Tablet PC Pen Training","description":"Administrative Templates\\Windows Components\\Tablet PC\\Tablet PC Pen Training","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3edb2860-b77b-4240-af16-fb34d45d6ba1","displayName":"Performance","description":"Microsoft Edge\\Performance","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3f216590-fb12-4f8e-924f-2a6895d94126","displayName":"Folder Home Pages for Outlook Special Folders","description":"Microsoft Outlook 2016\\Folder Home Pages for Outlook Special Folders","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","displayName":"FileVault","description":"FileVault > FileVault","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3f61a5fe-8508-44dd-bcf0-83273643026a","displayName":"Smart Screen","description":"Smart Screen","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","childCategoryIds":["20b71dc7-cf08-4534-9e52-d297dd071ca5"],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"3f693856-7cbb-4a1c-93be-0d05aa41059f","displayName":"i SCSI","description":"Administrative Templatesi SCSI","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["60ea8de3-bc6d-4b01-974a-a53860fe4ef6","ca1aedf4-b951-45f5-a77c-dec776a82e21","6c1d9109-e4d1-4718-a537-dd685464fdbe"],"platforms":"windows10","technologies":"mdm"},{"id":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","displayName":"Internet Control Panel","description":"Administrative Templates Internet Explorer Internet Control Panel","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["8d503574-f93a-4277-a30d-19895d46dd13","822bd634-4d01-486e-adad-8085968fd1c4"],"platforms":"windows10","technologies":"mdm"},{"id":"3f8299b3-6803-4576-be08-7c311d04b8b9","displayName":"Attachment Manager","description":"Administrative Templates\\Windows Components\\Attachment Manager","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3f8986f3-195d-4ee5-ae8d-96a007b20883","displayName":"Windows Location Provider","description":"Administrative Templates Windows Location Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3fa63a9d-e22d-4fc8-8464-a13b56461115","displayName":"Predefined","description":"Microsoft Excel 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3fbd3b29-bafd-4adf-89e4-3be612dee275","displayName":"Network settings","description":"Microsoft Edge Network settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"40605d4b-d999-4235-9a5a-59fad165ec51","displayName":"Locked-Down Restricted Sites Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Restricted Sites Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4086190d-2e5b-439d-8426-08492ebb8c9f","displayName":"Local Machine Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Local Machine Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","displayName":"Disk NV Cache","description":"Administrative Templates Disk NV Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"41081a6b-ec9f-4b4f-b6ae-1d4dda162654","displayName":"Folder Redirection","description":"Administrative Templates\\System\\Folder Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","displayName":"Explorer Frame Pane","description":"Administrative Templates Explorer Frame Pane","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"41ba590e-9105-4eda-92fb-13c7d34b8eee","displayName":"DC Locator DNS Records","description":"Administrative Templates Net Logon DC Locator DNS Records","helpText":null,"parentCategoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"424a0e73-8002-42e3-b47d-2062fc17c3b3","displayName":"Troubleshooting and Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["439f1603-5241-40c7-a5fe-44ae6744543f","5c1c00f2-def5-4064-925d-aedf4aa0f060","b4272e06-316f-4f9a-a198-93f4168f0c78","366a0d4a-8f27-44e7-82d0-d2eafe5b6d6f","94f6e868-1296-4811-b404-1afa2d50bc7c","2ac8fe19-ca17-4533-8818-a5e12030de51","78b3d753-d84d-496b-a93c-d577ab5865bd","8eb61398-1074-4fa0-8bd4-04d751a9ccad","9c815001-eace-4aa6-a929-14af0a46aaf5","a24e6384-a862-4d0e-8f6c-eb99e5f6a9db","1f31ae2d-4867-4733-b52c-cecc0128e10c","7bc264db-6da2-4c6b-a357-aec47c717737","a4f5cedd-a8f7-4def-b8b6-8fbf9ce9e0d8","f783d1ea-2f9b-4fcb-96cc-fb455cfe69f9"],"platforms":"windows10","technologies":"mdm"},{"id":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","displayName":"Application Compatibility","description":"Administrative Templates Application Compatibility","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"428f107c-2167-4bc2-9293-8f1d6728a0c5","displayName":"Scan","description":"Administrative Templates Microsoft Defender Antivirus Scan","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","displayName":"AirPrint","description":"Printing > AirPrint","helpText":null,"parentCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"42a6198f-bdec-402e-b619-315400b65488","displayName":"Software Update","description":"Declarative Device Management (DDM) Software Update","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"42ce9a9b-0574-4b5c-993b-7679de80be47","displayName":"Protected View","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","displayName":"Telemetry Dashboard","description":"Microsoft Office 2016\\Telemetry Dashboard","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","displayName":"SharePoint Lists","description":"Microsoft Outlook 2016\\Account Settings\\SharePoint Lists","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43057320-7058-46d5-86f9-a56c80bbf8b9","displayName":"Private Network Request Settings","description":"Microsoft Edge\\ Private Network Request Settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"431c3b32-abe7-4534-81a1-9f10c8e0c512","displayName":"Scan","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Scan","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4331c310-93b0-4383-8c55-acd653f37f80","displayName":"Network Inspection System","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Network Inspection System","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","displayName":"Microsoft Edge - Default Settings (users can override)","description":"Microsoft Edge - Default Settings (users can override)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":["04b46099-4ee5-4def-8e04-569c988057a9","6f1386e5-148d-4dc3-84d1-79df721e3233","a7b038e5-3af5-41fe-919e-e8befe83a9a5","fea97af7-df89-4fde-8e2b-f8e7f7b6b741","48965ad9-3011-4722-855b-7179fef89954","1653fa6c-aa99-4918-92c7-1df85d8843e1","6b71fbf6-7156-471a-b488-3eece04bda86","7db75ddb-f702-49f8-ae2b-991d1afd2d17","a877a2ff-f144-421f-814c-593e972a8a20","1ccd3115-55e7-464f-9bb9-d38a92191306","6fafeb5c-65ce-4993-b421-46e60da69131","acabc66f-5faf-4a13-af32-322ccfc1a5b3","70dd505d-40d4-4685-b639-67efc9274ec4","8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","b96b63eb-0292-4a73-85d7-c68d330c109e","0d4cf1d9-d8ad-4628-bd71-fa0de6598f28"],"platforms":"windows10","technologies":"mdm"},{"id":"439f1603-5241-40c7-a5fe-44ae6744543f","displayName":"Application Compatibility Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Application Compatibility Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"439f715e-5511-44fd-9a0f-644ba7cc6baf","displayName":"Logon","description":"Administrative Templates Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43eca758-22c0-4625-8f12-85a8a34ea8b1","displayName":"Windows Logon Options","description":"Administrative Templates Windows Logon Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43fc9dcc-1e66-4108-bded-2d005eeb7ccb","displayName":"Microsoft Edge WebView","description":"Microsoft Edge Update\\Microsoft Edge WebView","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"441d6cc4-e51f-453e-a44d-8394509415be","displayName":"Predefined","description":"Microsoft Publisher 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"444409a4-8b03-402d-91d0-1cd9565fb0fb","displayName":"Windows Color System","description":"Administrative Templates Windows Color System","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","displayName":"Business Data","description":"Microsoft Office 2016\\Business Data","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["952f69c8-2644-48df-976b-01fd624cbb3a","a6e0cee7-34a0-4ca2-b4da-f819a057b532","c72d9f00-d625-43ec-add4-514891035839"],"platforms":"windows10","technologies":"mdm"},{"id":"44774d3d-387b-4fa7-8de4-d82b039c06d1","displayName":"Display","description":"Microsoft OneNote 2016\\OneNote Options\\Display","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4479c9b6-8e08-424f-a20a-2058126dc048","displayName":"Data Collection and Preview Builds","description":"Administrative Templates\\Windows Components\\Data Collection and Preview Builds","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"449201b6-5002-42d1-85ed-d288fb6552da","displayName":"Smart Documents (Word, Excel)","description":"Microsoft Office 2016\\Smart Documents (Word, Excel)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","displayName":"Internet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Internet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44e27b70-4bdb-4aec-a75d-0568a1edc332","displayName":"Predefined","description":"Microsoft Word 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"740e7a10-3774-4a1c-9970-6907e0f0b848","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4560c525-12a1-4536-9cca-338330e58389","displayName":"Add-on Management","description":"Administrative Templates Internet Explorer Security Features Add-on Management","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"45a89c1f-0a34-4f78-b28f-d30b623fa423","displayName":"Identity and sign-in","description":"Microsoft Edge\\ Identity and sign-in","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"45d15759-2add-40db-9294-d1b391515dba","displayName":"Folder Redirection","description":"Administrative Templates Folder Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","displayName":"Carddav","description":"Accounts > CardDAV","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"463e6791-7d54-4964-a36b-63bbedb7d0cd","displayName":"Microsoft Active Directory management settings","description":"Google Google Chrome Microsoft Active Directory management settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"46af3391-ed6d-4ada-aef7-02dac2a1b136","displayName":"Xsan","description":"Xsan > Xsan","helpText":null,"parentCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"46eaa2b7-341b-4e39-be21-c3ea09dd5778","displayName":"Microsoft Edge Web View2 Runtime","description":"Microsoft Edge Update Microsoft Edge Web View2 Runtime","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"476e0bfc-ddb6-4612-8446-bed86e875141","displayName":"Fault Tolerant Heap","description":"Administrative Templates Fault Tolerant Heap","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"478ed057-8ee7-4dd2-8276-06dad8f85397","displayName":"Services","description":"Microsoft Office 2016\\Services","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["a5607145-2bd3-4473-a8ee-d7fa5c2f2675"],"platforms":"windows10","technologies":"mdm"},{"id":"479c2edd-6539-4e1d-96ba-518d6f6264c3","displayName":"Container and Directory Naming","description":"FS Logix Profile Containers Container and Directory Naming","helpText":null,"parentCategoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"486dc66e-960c-4622-b3cb-3ff9a2d434eb","displayName":"Device Installation","description":"Administrative Templates\\System\\Device Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["979412d7-6716-440c-9a64-5889026d73da"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"486f25cc-c865-446e-95b2-c5b061883a7a","displayName":"I Pv6 Transition Technologies","description":"Administrative Templates TCPIP Settings I Pv6 Transition Technologies","helpText":null,"parentCategoryId":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48965ad9-3011-4722-855b-7179fef89954","displayName":"Games settings","description":"Microsoft Edge - Default Settings users can override Games settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48b8705b-58a8-4504-ab7a-2704980f4577","displayName":"Microsoft Defender","description":"Microsoft Defender","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":["d40a32e1-ab3e-4cbc-aa03-4766792e563e","67cd904c-78e0-4e77-9dd4-c713b21763f3","5c4df3be-80b0-40cc-a8c8-0258120b0de5","20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","269c487f-8902-486a-88dd-db9b9b4454b8","22a2a407-0f28-481d-bdbe-1f9cb6d589c3","13467142-14e7-4380-8573-4866e842c7f6","b77a3a7b-6fab-4240-b5c3-852aa78781d5","a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","64c8233f-3057-4485-b902-d71a312318d7","d2191717-e304-46f7-bcc0-55e6477026c9","93099bd4-c685-434b-9d72-f0cb6db5e753","0e1122f8-2bbf-475b-bce0-9e43a2f5e475"],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"48be5f9d-4941-4189-8015-dd78f87aacd5","displayName":"Administrative Templates","description":"Administrative Templates","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["07c023d3-0899-40af-a04f-805876d99a9b","180b2a03-16d4-43cd-ba84-9b4546753ef4","6bed088c-c9b0-4149-b26f-df0c247cdb5b","78d3d93f-03d0-4fa0-be56-be4bca0a7b3b","87e607d8-500d-4dba-a58f-d7695945c973","a7e7529f-1030-41da-8b4d-024e1c08bbac","99ba9e42-9872-4a03-a615-fc4a4cebc067","c01c7d3f-ace1-48bf-abce-e8a02ba877ab","634e4243-284b-4cb7-a7e6-08ca7e262937","c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","909339a5-8f04-4fa2-8807-5d38c83ef547","08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","f3027ba5-9a2f-42c6-9872-ec21f726929c","395a548d-737b-41fe-8449-c68c51e3a349","d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","5dcea340-0469-4f43-b270-a49ed0597201","5371d50c-0aaa-425a-a075-2cb1c59968b9","03a966f7-8f8e-4ecb-aab3-055fe907f5ab","088b8d8d-5f3f-4979-aa18-b3c4b2616a24","50fb9f56-84f1-4fa9-83f5-0aa0bca8ff49","41081a6b-ec9f-4b4f-b6ae-1d4dda162654","2cbf2609-1f6a-4597-84e2-a57da0ad0472","53936d6e-5445-4897-8a40-e3f810ea50c4","b49cb414-bdfb-49d4-af5d-176ded4f9591","6b87c5da-cfd9-44bc-be05-ed08eb2144c7","fff51673-04b8-4277-98ef-4baffbd8d192","444409a4-8b03-402d-91d0-1cd9565fb0fb","cef993dc-bf18-44f7-8e9f-465ef1a0f144","156f2e6a-6638-4749-9f43-e7acc4aba762","bd04d2ce-3275-496c-8cc1-e17ab19888a3","cebd5934-9dfe-4278-966d-b9d880cb30e7","dbb76878-34a9-4f87-bbc6-4de7ea223ff4","e6b767af-2ce1-4c91-9360-15abbb0bf3bc","2b54b208-5459-4e40-8db1-002cb90495bc","2d842579-300e-4a24-bc42-7c39af62c468","32b20540-8fe9-4730-a4b0-ff41f6b13a97","73a3a483-dcba-4b34-b7cb-9c68c871864c","8280dcb9-f2bc-417b-b4ef-cd6c35398f94","8d27fb75-5aeb-44f0-aab2-064cc4b9ecd6","ac0a894c-173a-48fc-b961-901f28463c77","023e0367-b563-4fae-8fb6-589c836ee223","76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","2461b964-02f6-4da2-921a-f7e8f868c69d","98dc5bd0-2b16-4263-ba2f-62115b680017","edd1e620-09e1-47ea-abc8-1e241a174ed9","439f715e-5511-44fd-9a0f-644ba7cc6baf","d982a1ef-84be-4832-99d4-8b71a4644b74","dad3971c-b07b-461b-8ead-6eda80ee57e1","b524d6e2-75bc-4409-ae3d-07605707d7ee","751cf9ec-7214-4b38-a09e-24922684bd8f","dab7104a-b79c-4318-afb0-5d5cfed9caa9","0937f5ff-aabc-49a9-a94f-6f98c4702580","c6a912c5-0334-40fb-8dc5-f2d2547b8071","fe3cb879-8869-4163-91d7-e432abd75da8","b6bb653a-73f0-42f4-b097-1ce556310904","930d2960-3f70-48ca-9ead-b65a5a037c07","5161db41-7947-49ea-b9b3-dd92539e6783","43eca758-22c0-4625-8f12-85a8a34ea8b1","d4c9d046-a8c0-46f0-bd62-bc4d1614e891","18b972fd-74f2-4345-9449-087c80dd38a3","27087ae6-d02f-4b54-a143-6cde89c04989","6c7168c3-6f34-4086-af0b-ed0b74301dc9","734bed4f-be52-46ef-ae60-8fd195dc8f4d","93c28398-faef-4ca5-9667-f5ed004da32c","3334730b-b9f7-4c99-bde8-57f6b2cd826f","32180186-7378-4d45-b0cc-c533a124bdbc","425669eb-3a49-43d1-98a5-0fcc5b04ffcb","56fdfd66-f34d-4bf8-b951-f130114ffb3d","736134cb-4d82-427a-97b7-d219ac6a22f0","9b894b32-3697-4a83-9731-3db2a35455ad","cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","ad47f904-ede2-4b12-849e-bf751d88abf5","c859dc1a-fdeb-4591-af97-79d078ee715b","f14fcb64-a868-4531-a3b4-c3cdf03c2b99","476e0bfc-ddb6-4612-8446-bed86e875141","72972c43-36a3-4034-8cc8-334c99087798","005ddf8f-da22-4b23-ab02-289f8f6c7960","3f693856-7cbb-4a1c-93be-0d05aa41059f","68a3b82d-d1f4-422d-bfee-2168ec260ad7","dc16dbf0-aac8-4ff3-a546-1ddb55650f47","1851afa1-5177-4268-8dfc-5b5e1a17ff7f","31d3b4c4-767e-403a-834c-51f3691bbf2b","daf3f2c8-f6a5-40bd-96b3-2c6a28931614","c08e929f-742a-4cd8-a7e6-9a3d170fe020","d9f5ccc9-5180-43b7-9c81-89ac3364ce00","dd9a3dad-5851-4899-a5c1-c23318986846","f96201d4-894e-4a72-87fb-22146039a802","364787de-93e4-4fd6-9608-dce1ad8f88c2","65873bfe-2798-42fc-ae33-02295b23b3d3","8e19ed1e-e870-4769-bd6f-321f6f47023b","4d36a1f3-29f9-45af-9480-32891a0bf8ef","e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","9dbd66e3-4544-4ca8-a118-272c874bc684","e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","8c30a64e-ad24-47a0-97a8-52320360fd88","643081a4-132d-463e-9d86-c8650cb2a011","6424714c-e50a-4b53-acbf-8739825ebf0b","2becddf1-d8ea-49ec-8560-c8c401faa9bb","05305a87-0b19-41bb-bf1e-0bd92bfcdc16","297f09f9-0a48-4058-81b8-66a630a3c0ea","363982dd-fc96-49ce-a499-f6401f2c212b","fe65603b-1980-446b-ae17-516eb885c6be","785c6df2-c6d0-4d6e-bd73-c3b62caca754","abf781d7-1179-4f24-8d01-5611db14eddc","7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","8eed5d21-a5e9-4bc7-b2df-4526af3e2726","be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","4dd8280d-6c01-4a06-bfd1-e1cb4c529494","f14074a2-de74-48df-b273-48791217ef4d","f926f6e3-1bd6-4259-ae7c-e14108568882","22086dab-6c7f-408f-bd0c-cc34b2ad086d","6cd02266-a42f-4675-b83e-37360dbf3c68","71f349a7-1ca3-4945-8c7d-fd68df3759ac","1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","75e080fb-3ed7-4a73-a6e0-eb93f0119d68","d0e46713-238c-42b7-a996-653cf952c367","7d331987-7e2d-4975-b23b-d99a5af26ddf","b3b2fc04-4b88-4a1c-8370-04573019eebe","b40cfb22-8f17-4317-bcbb-c1c871497446","94a92db4-8704-487b-b0c5-c15d6ac20e6d","5be35eeb-62e9-4317-8804-018a9dd31149","60b55db1-53fc-45ea-93d3-e4372b1e19a5","deadde1d-7e7f-4577-bd6e-fc237c3854c5","bc4f0cce-a5cc-44c9-9e50-b504e09e7eb1","80ed7629-87dd-4bb1-8ea0-555f20d3b156","bedf20d1-1f5a-4840-8458-6d0fa974b664","62b373da-c112-40f4-9047-9cc3e8d8ab13","9329c2bd-9e56-4394-9c89-5726e8b76f2f","394b2dfb-3404-4668-94af-5acc825fcf51","1ed9f90e-d8b6-413f-bfc2-face955141bc","b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","87667b72-85ce-48c2-8023-e6db7f5fe739","0d37dddd-6575-485c-92dd-37a3c23edbf9","184aa343-0f0b-4bf5-aeeb-42111fedfbbf","24b30053-14d2-4430-9966-281e926a6918","99b4ac32-50b5-4659-a7a1-94bc708ae71a","b6d13875-fd8e-41a0-a712-3dab8b75b93f","7a3a7335-4837-4bc5-9282-448402a05d89","e3ca94a7-e506-4133-8fae-41931dc863a5","86e78a4b-706a-4ec8-be90-439461abb29d","cc13d92c-673f-4af7-9748-50342fc8795a","45d15759-2add-40db-9294-d1b391515dba","2de362c7-2c4a-4b24-bda3-f82cb6ed5990","50e243ad-0e21-43f5-b5dc-31ec61ee43d0","4beed579-3d9c-4c6d-9e88-e7df5e2b4613","be9bdbec-b52e-4174-9c5b-cf765dee855b","a24f4ab6-289a-450a-b438-1c4bb1214942","df0be435-d790-485a-b355-6f00eae29511","12a1b259-a0d5-4505-aedf-b8ca811cd5f9","ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","3f8986f3-195d-4ee5-ae8d-96a007b20883","f69e6993-2e88-4938-bfe5-cea9ab21a858","7f363efe-1ea5-4eb8-baf7-8c34456b43fc","86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","a57b27b6-48e0-42b2-812a-2be86c113a0c","9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","788355e5-e113-4b17-ada9-fb5ef38bffa1","40c593b9-63cf-4b10-ad26-1ceb7c9491fe","3453c694-bc38-4082-9d3d-886e385df927","88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","c48917c1-fd99-405f-b1d2-9dfec169e5d8","9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","e042b102-b12c-48d1-86ef-f6d296da5b95","902f5df1-31d6-44ee-ba95-2561199db35f","5c9a2f21-d3a8-4295-a803-e0535aa29489","3deb76aa-8336-4ff9-aa98-4dcaf8901468","90e3acc6-80d5-41b4-8141-a8620a211c0e","f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","c9a65baa-de10-4818-97a2-b61babb28060","cae68a5f-9d1e-44e8-a34b-6a390b88c451","ffd1a98f-0fac-47fe-813f-7510d0dacbc3","424a0e73-8002-42e3-b47d-2062fc17c3b3","53ba922e-db4d-489c-b5ab-dbc4b8321206","e972d9fe-a9b7-4a65-a88f-0958fab19584","12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","5536b5f4-3d31-4290-acea-9bef323bb83d","60b898a9-0490-4599-b7f1-3cd451236266","290ec637-e780-4e95-9834-6368ac0437d1","f1278d6b-60ec-4369-88cf-21df47caaec6","f8bb78a3-d1e4-4c5d-8b0a-904a83830519","9b0b8f3b-8e08-4083-9e2b-2e6bfeb01f83","f4fd69bc-8622-411d-91bb-0e214f8fb112","1526dde4-6726-470e-aebf-3272ae70a99c","e740736f-75f9-481d-990c-02018abc2ea5","30918d48-dafd-4b25-be63-70f6c7ba8a3d","5c3d081f-6f7c-4650-8a40-200f44eb4794","6e1431f2-131e-4cf2-bb60-87b889f1d11b","1943deba-33f7-4c3d-98c8-6b5319ec98ab","5133d5ea-1a12-494f-afb2-5cfaf41d9518","6d4184ab-a66c-47f1-b54e-af55f654e2a5","2b3d275d-4a48-4ac8-9c14-4dc5aa20a80b","a34ade49-964d-407c-9f60-2e8cd9dfef05","19ab385f-14f5-47cd-87b2-f4784eedcdd9","486dc66e-960c-4622-b3cb-3ff9a2d434eb","76c53aab-0288-4ac1-b399-0104e04c6457","58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","d52dd970-febb-4891-8eb7-1c8616cfb6cb","8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","e50acc0f-d177-4803-aa31-fc97eeb60ff2"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"48cb2bee-74be-4165-bc19-89c5b1c50c00","displayName":"Email","description":"Email","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48f508a5-5a2c-4d20-8d89-2d352a209907","displayName":"Reporting","description":"Administrative Templates\\System\\App-V\\Reporting","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"49abf969-2a98-4479-b234-6990b152cb21","displayName":"Microsoft Defender Exploit Guard","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Microsoft Defender Exploit Guard","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["98c9cd71-f6eb-4dfd-b045-85c7e0b44487","07221402-6a9c-4440-ae6f-3217ce5ad8fd"],"platforms":"windows10","technologies":"mdm"},{"id":"49d75a11-64c6-43d1-bc25-0ab156ff4216","displayName":"Microsoft Defender Antivirus","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["32ee73d6-947f-45e9-856b-793b584c626d","c4665793-15ea-44c9-bd0a-d542b3915fe0","5fe14828-4e5b-42ae-87b2-89a579045d1e","4331c310-93b0-4383-8c55-acd653f37f80","4f48b5aa-e887-49ea-a16e-3bb379ccc47c","ad100c6c-9a9a-42cf-8f42-b31c406c1a56","49abf969-2a98-4479-b234-6990b152cb21","a0f1f801-7fce-427c-b5e2-6c6b30065fa5","e06fb472-94c1-4dd9-afdf-6bb2ddaa3dc6","d99ac221-1000-44d8-9ab4-5cdac69562ed","edba50d5-da3c-48cb-8e50-381ad0bfaaaf","431c3b32-abe7-4534-81a1-9f10c8e0c512","eb5baf57-86c8-4bfa-ac3a-53025686e37c"],"platforms":"windows10","technologies":"mdm"},{"id":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","displayName":"Time Language Settings","description":"Time Language Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","displayName":"Firewall","description":"Firewall","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"4a7b0e92-ba43-46aa-96e8-c5839dbcb524","displayName":"Note Flags","description":"Microsoft OneNote 2016\\OneNote Options\\Note Flags","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a832199-a841-4b6a-84fa-51365902a742","displayName":"Places Bar Locations","description":"Microsoft Office 2016\\File Open/Save dialog box\\Places Bar Locations","helpText":null,"parentCategoryId":"92be4fc7-8095-441c-b52b-9861c21bc337","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4aa852ab-6269-4883-906f-0a0944fa1261","displayName":"Allow or deny screen capture","description":"Google Google Chrome Allow or deny screen capture","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4ad00da1-5ed6-47d8-aef3-70f5bcbbbc77","displayName":"Network Provider","description":"Administrative Templates\\Network\\Network Provider","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","displayName":"Customizable Error Messages","description":"Microsoft Office 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4b2f3557-98e9-48d2-9b78-bcb100f72372","displayName":"Sleep Settings","description":"Administrative Templates\\System\\Power Management\\Sleep Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4b540860-0858-48f4-8830-18383bb1766f","displayName":"Licensing","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Licensing","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","displayName":"Scripts","description":"Administrative Templates Scripts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4c604a0e-9339-4c01-9536-b689bd0abe5f","displayName":"Remote Desktop Connection Client","description":"Administrative Templates Remote Desktop Services Remote Desktop Connection Client","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","displayName":"DSCP value of conforming packets","description":"Administrative Templates Qo S Packet Scheduler DSCP value of conforming packets","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4cd10f38-02cf-40f2-aa87-ad70a2190a1a","displayName":"Protected Content","description":"Google Google Chrome Protected Content","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","displayName":"Credentials Delegation","description":"Administrative Templates Credentials Delegation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4d69af55-f100-45fa-92e1-56d46434c647","displayName":"File Block Settings","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4dae3032-1f16-4ace-911b-a957db0b8089","displayName":"AutoFormat as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type","helpText":null,"parentCategoryId":"dc049161-17c6-411e-906b-a871b33651cd","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["b6cafb2c-81be-40cf-90d8-788f713f7099","e8ce968b-91cb-4301-ba98-b37d42bc5213","62492a4c-fd70-4275-ae5e-d60e200e3553"],"platforms":"windows10","technologies":"mdm"},{"id":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","displayName":"Wireless Display","description":"Administrative Templates Wireless Display","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","displayName":"Customize","description":"Microsoft Office 2016\\Global Options\\Customize","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["13123148-c522-437f-b316-d78f5cc0d28d"],"platforms":"windows10","technologies":"mdm"},{"id":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","displayName":"RSS Feeds","description":"Microsoft Outlook 2016\\Account Settings\\RSS Feeds","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e4deef0-4528-47d5-8869-4143c506f18b","displayName":"Custom","description":"Microsoft Visio 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","displayName":"General Options","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\General Options","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e8db19c-cb8e-4361-8849-1d435d50bb66","displayName":"Handwriting","description":"Handwriting","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4e8db19c-cb8e-4361-8849-1d435d50bb66","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f081af6-7b21-44fc-8dd9-d4e0a61a474d","displayName":"Control Policy Conflict","description":"Control Policy Conflict","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4f081af6-7b21-44fc-8dd9-d4e0a61a474d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f29ef5c-6ca0-4b09-893f-01755a670877","displayName":"System Services","description":"System Services","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4f29ef5c-6ca0-4b09-893f-01755a670877","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f48b5aa-e887-49ea-a16e-3bb379ccc47c","displayName":"Threats","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Threats","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f671de2-9777-4969-acf3-8d90c733434c","displayName":"Escrow Certificates","description":"Microsoft Office 2016\\Security Settings\\Escrow Certificates","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4fc4d2f3-35ee-43ec-a033-ef78da571e70","displayName":"Smart Card","description":"Administrative Templates\\Windows Components\\Smart Card","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"500d2bb1-5186-447c-818f-401f2d9065ce","displayName":"Windows Logon","description":"Windows Logon","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"500d2bb1-5186-447c-818f-401f2d9065ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5011ca61-1a58-42da-9c66-7763236acc84","displayName":"Streaming","description":"Administrative Templates App-V Streaming","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"501b5a30-253c-48b7-ab40-de1d100e4358","displayName":"Microsoft Teams","description":"Microsoft Teams","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","displayName":"General options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\General\\General options for Microsoft Project","helpText":null,"parentCategoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","displayName":"Tablet PC","description":"Administrative Templates\\Windows Components\\Tablet PC","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["cc8a93d5-503f-4d46-ac42-65e169642237","e8514a44-e44c-47af-a714-7697ebb2baf7","2ea4b701-fcb8-46b2-a83f-c792b861f5ad","90bbab80-ecf0-47c6-bf01-76b26a3dc503","aa67f0c0-4eb0-492f-a528-decd3e256a22","3e98c3bc-254c-445f-a1c8-4a93c2e0fcf2","917d0fb9-b5dd-401b-982b-1d32f6e0a306","575369a6-17a2-435e-81d4-71772e7d55b5"],"platforms":"windows10","technologies":"mdm"},{"id":"508b2c0e-f572-4a50-93bf-566e5b827c0e","displayName":"Printers","description":"Printers","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"508b2c0e-f572-4a50-93bf-566e5b827c0e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"50b4bc60-802c-477a-9366-80e09154595f","displayName":"Security Settings","description":"Microsoft Office 2016\\Security Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["512f133b-9d53-46b8-834f-52501f9b6527","4f671de2-9777-4969-acf3-8d90c733434c","efb8c441-bad5-4e2f-b07c-5ac299cf3d22"],"platforms":"windows10","technologies":"mdm"},{"id":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","displayName":"Lanman Server","description":"Administrative Templates Lanman Server","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"50fb9f56-84f1-4fa9-83f5-0aa0bca8ff49","displayName":"Filesystem","description":"Administrative Templates\\System\\Filesystem","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["2e71c6fd-dafa-444d-9542-55d838331939"],"platforms":"windows10","technologies":"mdm"},{"id":"512f133b-9d53-46b8-834f-52501f9b6527","displayName":"Digital Signatures","description":"Microsoft Office 2016\\Security Settings\\Digital Signatures","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","displayName":"Hardware Buttons","description":"Administrative Templates Hardware Buttons","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5161db41-7947-49ea-b9b3-dd92539e6783","displayName":"Start Menu and Taskbar","description":"Administrative Templates\\Start Menu and Taskbar","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["cb98f9d4-d921-4a8b-a763-cf69ce2ada62"],"platforms":"windows10","technologies":"mdm"},{"id":"517e55f5-729f-4b4d-9555-33baa95a0e5a","displayName":"Application Guard","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Application Guard","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"51e0cebb-cac4-4905-9b31-539295e4b85b","displayName":"Proofing","description":"Microsoft Publisher 2016\\Publisher Options\\Proofing","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","displayName":"Accounts","description":"Accounts > Accounts","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"522c3302-7a25-4904-a274-66cef9fd6aa0","displayName":"Microsoft Office","description":"Microsoft Office","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":["b5169b74-41be-460a-9402-b13b6c22582b","19ba782c-3594-45da-b829-72b54f6d45c7","191a84f2-13b5-4609-808f-8b743b7f0247"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5261c543-0bf4-49a8-9657-45e2044420d1","displayName":"Messaging","description":"Messaging","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5261c543-0bf4-49a8-9657-45e2044420d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"526e363a-84db-4256-a13c-e01c8c646e26","displayName":"Idle Browser Actions","description":"Microsoft Edge Idle Browser Actions","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","displayName":"Remote Remediation","description":"Remote Remediation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5371d50c-0aaa-425a-a075-2cb1c59968b9","displayName":"MS Security Guide","description":"Administrative Templates\\MS Security Guide","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"53936d6e-5445-4897-8a40-e3f810ea50c4","displayName":"Shutdown Options","description":"Administrative Templates\\System\\Shutdown Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"53ba922e-db4d-489c-b5ab-dbc4b8321206","displayName":"Microsoft User Experience Virtualization","description":"Administrative Templates Microsoft User Experience Virtualization","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["c0ea0178-ad93-4596-94b2-9d7d1bbe8789","5966d21b-220b-4937-9323-c6dd46cda942"],"platforms":"windows10","technologies":"mdm"},{"id":"5401711f-292a-487a-be18-f99593a0477c","displayName":"Font","description":"System Configuration\\ Font","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","displayName":"Connections","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Connections","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","displayName":"Startup Home page and New Tab page","description":"Google Google Chrome - Default Settings users can override Startup Home page and New Tab page","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5536b5f4-3d31-4290-acea-9bef323bb83d","displayName":"Ctrl Alt Del Options","description":"Administrative Templates Ctrl Alt Del Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55a61bb8-e023-4741-8213-99995c5902e5","displayName":"System","description":"Administrative Templates Event Log Service System","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55c888df-44ff-49d1-808e-ad9cb8429aff","displayName":"Device Health Monitoring","description":"Device Health Monitoring","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"55c888df-44ff-49d1-808e-ad9cb8429aff","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55eebd7c-beb9-48b6-907f-df4997e18bdb","displayName":"Predefined","description":"Microsoft Access 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"b8158968-c839-4d37-9eb8-887bd6fd7402","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"569c6b8d-9491-471b-9960-17e3ac60734a","displayName":"RSS Feeds","description":"Administrative Templates\\Windows Components\\RSS Feeds","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56c54112-2991-4bda-9e01-e6868bd07726","displayName":"Printer Provisioning","description":"Printer Provisioning","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"56c54112-2991-4bda-9e01-e6868bd07726","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56e510be-ca39-46a2-9eb2-6f1af6d4b16a","displayName":"Browser","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...\\Browser","helpText":null,"parentCategoryId":"2108b443-384c-4bb3-9b9f-acb4a754a86a","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","displayName":"Branch Cache","description":"Administrative Templates Branch Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"572bc940-42d4-4e00-ac55-012e9b90f6df","displayName":"Remote Desktop Services","description":"Administrative Templates\\Windows Components\\Remote Desktop Services","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["2d8634c7-19ca-46e0-923d-019ba18ff4e0","66e289cf-85cb-425f-94a1-54777950f78b","85c586a6-6b68-48b2-8050-c4fb86aff486","394ae912-b5c9-45a0-8883-84791c6acb16","a4877a42-7e62-4216-a477-0b35357ab313"],"platforms":"windows10","technologies":"mdm"},{"id":"57514d69-d9b1-469a-9b54-b5e94320c2a1","displayName":"Windows Subsystem For Linux","description":"Windows Subsystem For Linux","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","childCategoryIds":["a787672d-4a33-455b-a2db-e340eb35a5c8"],"platforms":"windows10","technologies":"mdm"},{"id":"575369a6-17a2-435e-81d4-71772e7d55b5","displayName":"Input Panel","description":"Administrative Templates\\Windows Components\\Tablet PC\\Input Panel","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"577d5951-fc56-4906-90bc-2c508c6611ad","displayName":"Microsoft Defender for Endpoint","description":"Microsoft Defender for Endpoint","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"579d6272-8708-4b22-a352-89cbd705ca82","displayName":"Security","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Security","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","displayName":"Credential User Interface","description":"Administrative Templates Credential User Interface","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5838ed03-2902-4931-92cf-e349ab09c9b8","displayName":"PowerPoint Designer","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\PowerPoint Designer","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"586c5c5a-15cd-4592-beae-1709c6daf5b7","displayName":"Internet Control Panel","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["d2da164d-dd77-4489-b67f-d7fbdb19cde2","3969f56d-a8b5-4509-86fb-00eb481665fa"],"platforms":"windows10","technologies":"mdm"},{"id":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","displayName":"General","description":"Microsoft Excel 2016\\Excel Options\\General","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","displayName":"Locked- Down Trusted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Trusted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5900ac65-f656-459c-bd82-1329a862544d","displayName":"Deprecated policies","description":"Google Google Chrome Deprecated policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5915e06c-9b74-4c5e-86de-93e67ae183de","displayName":"Online Assistance","description":"Administrative Templates\\Windows Components\\Online Assistance","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5966d21b-220b-4937-9323-c6dd46cda942","displayName":"Applications","description":"Administrative Templates Microsoft User Experience Virtualization Applications","helpText":null,"parentCategoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","displayName":"Directory Service","description":"Authentication > Directory Service","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","displayName":"Trust Center","description":"Microsoft Office 2016\\Privacy\\Trust Center","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"59d29716-55b0-4014-a458-38b408ff9530","displayName":"Content settings","description":"Google Google Chrome Content settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5a92aaed-3c64-4074-bacf-91dc1896d6f1","displayName":"Windows PowerShell","description":"Administrative Templates\\Windows Components\\Windows PowerShell","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5b1be2c5-9939-4b2e-b29b-b22069455c90","displayName":"Microsoft Save As PDF and XPS add-ins","description":"Microsoft Office 2016\\Microsoft Save As PDF and XPS add-ins","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","displayName":"FileVault Options","description":"FileVault > FileVault Options","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5b832259-c30b-43bb-b249-9d3ea4d5b028","displayName":"Customizable Error Messages","description":"Microsoft Excel 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","displayName":"Group Policy snap-in extensions","description":"Administrative Templates Group Policy Group Policy snap-in extensions","helpText":null,"parentCategoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","displayName":"Application Guard settings","description":"Microsoft Edge\\Application Guard settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","displayName":"Edit","description":"Microsoft Project 2016\\Project Options\\Edit","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["d33133b4-77df-429a-9580-ed70f7da676d","3db7e884-6077-4b96-ace3-005a6b49ecc0","06c4a76a-805b-4370-9d80-08e720ab2305"],"platforms":"windows10","technologies":"mdm"},{"id":"5be35eeb-62e9-4317-8804-018a9dd31149","displayName":"Online Assistance","description":"Administrative Templates Online Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bf4c2ba-be08-4cda-bf33-d10707580d78","displayName":"Present Online","description":"Microsoft Office 2016\\Present Online","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["0be98651-a552-4470-b2dc-71c66a5ce1e6"],"platforms":"windows10","technologies":"mdm"},{"id":"5c1c00f2-def5-4064-925d-aedf4aa0f060","displayName":"Microsoft Support Diagnostic Tool","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Microsoft Support Diagnostic Tool","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c3d081f-6f7c-4650-8a40-200f44eb4794","displayName":"File Classification Infrastructure","description":"Administrative Templates\\System\\File Classification Infrastructure","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c4224e0-6a48-4665-9332-958d98124157","displayName":"File Block Settings","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","displayName":"Tamper protection","description":"Microsoft Defender Tamper protection","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"5c645a3e-bc39-44e9-8786-4c82e0553d22","displayName":"ODFC Containers","description":"FS Logix ODFC Containers","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["81eb92d0-acda-4ea2-8183-29ed5457276b","0bae3158-5f75-4e25-acf4-859d2612f892"],"platforms":"windows10","technologies":"mdm"},{"id":"5c722b3f-9d77-428a-b859-3fb556162cd6","displayName":"Cellular","description":"Networking > Cellular","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"5c9a2f21-d3a8-4295-a803-e0535aa29489","displayName":"System Restore","description":"Administrative Templates System Restore","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","displayName":"Auditing","description":"Auditing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"5cd6dc4f-b231-449f-bc10-16041b73356a","displayName":"Contact Card","description":"Microsoft Office 2016\\Contact Card","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["20bacabf-cd07-48be-a184-f0ae76d31e4a"],"platforms":"windows10","technologies":"mdm"},{"id":"5d03766c-9480-43f2-9e85-461a44c821d4","displayName":"Button Settings","description":"Administrative Templates Power Management Button Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d19c257-8b7e-4071-9303-19317c94d7f7","displayName":"Credential User Interface","description":"Administrative Templates\\Windows Components\\Credential User Interface","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d4e843b-2848-4508-9143-cb3217c2fe83","displayName":"RDP Shortpath","description":"Administrative Templates Windows Components Remote Desktop Services Remote Desktop Session Host Azure Virtual Desktop RDP Shortpath","helpText":null,"parentCategoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d8272e2-1ed3-4a8d-9555-9a87fa13d078","displayName":"Customize","description":"Microsoft Office 2016 (Machine)\\Global Options\\Customize","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","displayName":"Browser","description":"Browser","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"5dcea340-0469-4f43-b270-a49ed0597201","displayName":"Mitigation Options","description":"Administrative Templates Mitigation Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","displayName":"Other","description":"Microsoft Outlook 2016\\Outlook Options\\Other","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["6535c74f-74ac-4713-9c7a-ae15f62e97aa","f29a5e42-24f5-47fb-bdcf-9ed9418035ee"],"platforms":"windows10","technologies":"mdm"},{"id":"5e692f3e-1911-43b0-9192-64c2e65b7c10","displayName":"Education","description":"Education","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","displayName":"Downloads","description":"Microsoft Edge Downloads","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","displayName":"Microsoft Visio 2016","description":"Microsoft Visio 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["c67c9e69-6e69-4b63-868c-3b3df5d17e47","e6f727b7-f474-4010-b214-83149ffdac2b","d5b3cab7-d486-4f74-8525-6bd740b950bc","f106d9e2-60ce-4e16-b74d-bd9ef401d7ba"],"platforms":"windows10","technologies":"mdm"},{"id":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","displayName":"Generative AI","description":"Google Google Chrome Generative AI","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","displayName":"OneDrive","description":"OneDrive","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5f048379-3a42-43f0-9fd5-d269f292aa35","displayName":"Workflow Cache","description":"Microsoft Office 2016\\Miscellaneous\\Workflow Cache","helpText":null,"parentCategoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","displayName":"Remote Session Environment","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Remote Session Environment","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b7bde490-eac6-4f57-8808-e0786b8191a1"],"platforms":"windows10","technologies":"mdm"},{"id":"5f71c40e-01aa-42d2-9c8c-7d560126cd4b","displayName":"App Analytics","description":"Managed Settings App Analytics","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","displayName":"Trust Center","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["8391e79d-d618-47c3-979c-83544da43739","c8cdd1a5-3f43-47c5-a775-d27bba4411f5","fe786056-6f4a-4d16-bff4-5fbb640308d2"],"platforms":"windows10","technologies":"mdm"},{"id":"5fe14828-4e5b-42ae-87b2-89a579045d1e","displayName":"Real-time Protection","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Real-time Protection","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"607a1c39-a3db-496f-8db6-c99d67f5f76c","displayName":"Tools | Security","description":"Microsoft Access 2016\\Tools | Security","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["a788a6e5-ab3f-41e5-96c8-ee59627dcb4d"],"platforms":"windows10","technologies":"mdm"},{"id":"60a3188c-7ee3-40db-8f9f-33648dc74555","displayName":"Shutdown Options","description":"Administrative Templates\\Windows Components\\Shutdown Options","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60b55db1-53fc-45ea-93d3-e4372b1e19a5","displayName":"Shutdown","description":"Administrative Templates Shutdown","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60b898a9-0490-4599-b7f1-3cd451236266","displayName":"Microsoft account","description":"Administrative Templates Microsoft account","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","displayName":"Enabled Editing Languages","description":"Microsoft Office 2016\\Language Preferences\\Editing Languages\\Enabled Editing Languages","helpText":null,"parentCategoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","displayName":"i SCSI Target Discovery","description":"Administrative Templatesi SCS Ii SCSI Target Discovery","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"61205786-952e-489c-91f7-5654a5bde11b","displayName":"Resultant Set of Policy snap-in extensions","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins\\Group Policy\\Resultant Set of Policy snap-in extensions","helpText":null,"parentCategoryId":"3d32fb39-ff23-48d9-9890-c8625d2d21e9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"618e0144-c57c-45e1-8b55-94dd3d9fec33","displayName":"Windows Connection Manager","description":"Administrative Templates\\Network\\Windows Connection Manager","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","displayName":"E-mail Options","description":"Microsoft Word 2016\\Word Options\\Advanced\\E-mail Options","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"622c83ff-f780-47e6-8b9c-bf82552e3f04","displayName":"Scripted Window Security Restrictions","description":"Administrative Templates Internet Explorer Security Features Scripted Window Security Restrictions","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"623d41fb-000e-41d8-b955-373f8c700def","displayName":"Security","description":"Microsoft Project 2016\\Project Options\\Security","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["26dfd0a7-546b-4583-b0c7-85b98ac5a40c","1671dfc3-a1dd-4178-9093-10fb6b62586a","cc50f179-0c39-4486-a555-de5a6e6ed365"],"platforms":"windows10","technologies":"mdm"},{"id":"62492a4c-fd70-4275-ae5e-d60e200e3553","displayName":"Apply as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Apply as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"62499519-97eb-43e7-ae96-d7909c5820d3","displayName":"Printing","description":"Google Google Chrome Printing","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"62b373da-c112-40f4-9047-9cc3e8d8ab13","displayName":"Power Management","description":"Administrative Templates\\System\\Power Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["01bbe7c3-10eb-40a3-8387-c74c33c294b1","17f0fdd3-e292-4ecb-ab5f-e4848e9cae1a","7120bf9e-e5f6-42cd-8f7e-15d2ca445c37","015936bf-8273-4499-bb71-33b385ee7d16","4b2f3557-98e9-48d2-9b78-bcb100f72372","d5585700-13a0-4ab4-9b19-4c15c1ead170"],"platforms":"windows10","technologies":"mdm"},{"id":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","displayName":"Remote Desktop Session Host","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["579d6272-8708-4b22-a352-89cbd705ca82","b40b8f80-c0e6-4494-8085-f90cadc167a9","0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","5454d0eb-7eaa-4500-a1fb-f69b76aed740","2a1bbe00-0730-430e-8d19-3eec2fd6b63c","4b540860-0858-48f4-8830-18383bb1766f","5f28f9ff-58f8-43af-9692-3d06e083bbd9","89ad0055-1603-420e-940d-9944a63e3da9","ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","f1455024-7de9-448f-8d8f-a42db2af0a35"],"platforms":"windows10","technologies":"mdm"},{"id":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","displayName":"Security","description":"Security","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":["d68abc4d-559a-4339-be48-c41a77a87034","8abddb23-7036-4ba8-8912-529279a849ea","f4a8384f-9e4e-4fc6-9ee2-28fa5260347a"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"634e4243-284b-4cb7-a7e6-08ca7e262937","displayName":"Attachment Manager","description":"Administrative Templates Attachment Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6355e85b-aeef-49e8-b8c9-5d6cd9a39985","displayName":"Extension snap-ins","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins\\Extension snap-ins","helpText":null,"parentCategoryId":"9e882396-4a1c-4d06-a62d-8d910ded8e7d","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63b9904f-bbdf-4461-954a-c1d67fa8b357","displayName":"File Explorer","description":"File Explorer","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","displayName":"IMAP","description":"Microsoft Outlook 2016\\Account Settings\\IMAP","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63e167a4-65be-4d34-9e9c-186466f2b064","displayName":"Troubleshooting","description":"Troubleshooting","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"63e167a4-65be-4d34-9e9c-186466f2b064","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6424714c-e50a-4b53-acbf-8739825ebf0b","displayName":"Personalization","description":"Administrative Templates Personalization","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"643081a4-132d-463e-9d86-c8650cb2a011","displayName":"Network Provider","description":"Administrative Templates Network Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"64538726-8745-4e7a-b370-332f725b58bf","displayName":"System Policy Managed","description":"System Policy > System Policy Managed","helpText":null,"parentCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"64c8233f-3057-4485-b902-d71a312318d7","displayName":"Scheduled scan configuration","description":"Microsoft Defender Scheduled scan configuration","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","displayName":"Network Isolation","description":"Network Isolation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"65087b94-7e45-4d74-a50d-df4377b67499","displayName":"Parental Controls Dictionary","description":"Parental Controls > Parental Controls Dictionary","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"652a676c-9d60-4c9a-88b6-823a24961a9b","displayName":"Copilot Settings","description":"Visual Studio Copilot Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","displayName":"Advanced","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\Advanced","helpText":null,"parentCategoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["13eb248a-4549-4d23-9ada-23b40edf36bf"],"platforms":"windows10","technologies":"mdm"},{"id":"65873bfe-2798-42fc-ae33-02295b23b3d3","displayName":"Security Account Manager","description":"Administrative Templates System Security Account Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66395272-f132-4170-b88e-87f794f987f4","displayName":"File Locations","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\File Locations","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66448b13-cc0a-4ffe-9ad5-62c4821dc77f","displayName":"Setup","description":"Administrative Templates\\Windows Components\\Event Log Service\\Setup","helpText":null,"parentCategoryId":"fcddcc0b-7cf8-4ebc-a818-d10689603263","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66615d2a-fec9-47f1-8eaf-9813e30cc023","displayName":"Extensions","description":"Microsoft Edge\\Extensions","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"66c92e07-234b-4992-a081-9afe4c113ba3","displayName":"SCEP certificate","description":"SCEP certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"66c92e07-234b-4992-a081-9afe4c113ba3","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66e289cf-85cb-425f-94a1-54777950f78b","displayName":"Remote Desktop Session Host","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["92503b7f-9fa0-4365-8482-57dd61e6d535","cc9231e6-ed1b-4680-aff4-bc72f16733c0","8778eb21-bf7c-41a7-bae1-412c0e3029db","2cc013ad-e5a3-42d9-b2b6-2a872a4c086d","b237a91d-a442-4a7e-8169-1bd6c798f490","bd1bf2cb-c806-479b-a68c-af9dffd438c9","ce572b49-4d47-47b6-b787-ac1252753581","0c2613c9-a7c7-4458-8b0d-2fff13e2beeb","845ff38a-408b-449c-9ef3-7fdc331027df","fe52de11-190e-4429-96c1-106b22724456","f3264346-fdc4-4e23-9a2a-dcfc34022e59"],"platforms":"windows10","technologies":"mdm"},{"id":"6730f0be-a129-4b48-942f-e4ddf69fee66","displayName":"Customizable Error Messages","description":"Microsoft Access 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6776f6fa-8836-408c-b91c-1e444e0cba5c","displayName":"Security Features","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["1671f10e-7300-46e3-a93f-ef38bf906cb1","a126378d-a916-476e-ad91-e3bd82fd3a48","91ed1812-8841-4eb3-b24e-a5e1f4eaa6c8","3e50e056-24bf-46c3-975f-b0aedbc96329","d39f73b0-9d26-4d4c-a8b0-d1b720890d2e","89c0381d-3b9b-4be5-8077-ffb18d47e910","829d1e81-4cbc-4259-bd0e-8cc44870f00e","8d5ce834-5b70-4ec2-8d07-eae26ab6493f","b74f852c-d19b-4a22-a44a-431f7a72a4d6"],"platforms":"windows10","technologies":"mdm"},{"id":"67b48a23-9bc3-48f5-bf6e-c9b3cd7000e4","displayName":"File Revocation","description":"Administrative Templates\\Windows Components\\File Revocation","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"67c06154-a798-44bb-83c8-d706a3709c10","displayName":"Layer-2 priority value","description":"Administrative Templates\\Network\\QoS Packet Scheduler\\Layer-2 priority value","helpText":null,"parentCategoryId":"01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"67cd904c-78e0-4e77-9dd4-c713b21763f3","displayName":"User interface preferences","description":"Microsoft Defender > User interface preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"67eb1dab-7805-41bb-af5a-798dc7e29f23","displayName":"Autocorrect Options","description":"Microsoft Excel 2016\\Excel Options\\Proofing\\Autocorrect Options","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"68237832-f376-4f0e-ba26-4e06fce7a35d","displayName":"Device Installation Restrictions","description":"Administrative Templates Device Installation Device Installation Restrictions","helpText":null,"parentCategoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"684799ba-398b-4728-aa21-40c8469cbe87","displayName":"Printers","description":"Administrative Templates\\Control Panel\\Printers","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"686ae3dd-a663-4484-854e-8f8d578fe3b8","displayName":"Converters","description":"Microsoft PowerPoint 2016 (Machine)\\Converters","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"686ae3dd-a663-4484-854e-8f8d578fe3b8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","displayName":"Portable Operating System","description":"Administrative Templates Portable Operating System","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69931627-230d-4df9-bbef-e3eac64ea8ef","displayName":"Additional Actions","description":"Microsoft Office 2016\\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)\\Additional Actions","helpText":null,"parentCategoryId":"8084033c-156a-4d1b-ab0b-159541810459","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69ec00d9-5698-4b8b-ad54-8d9a537a0fa9","displayName":"Internet Information Services","description":"Administrative Templates\\Windows Components\\Internet Information Services","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","displayName":"Advanced","description":"Microsoft Publisher 2016\\Publisher Options\\Advanced","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["77b0357b-412e-4a81-9469-e20a5f1345fd"],"platforms":"windows10","technologies":"mdm"},{"id":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","displayName":"Save","description":"Microsoft Project 2016\\Project Options\\Save","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["dfd5d749-c68c-448f-ab3f-851c09f09df4","e13ec567-e29c-4ca0-b599-e8c43587f10a","d679b407-a753-40aa-bc9f-175f363b0eff"],"platforms":"windows10","technologies":"mdm"},{"id":"6ae0d607-832c-403b-b3bc-c563e390ebad","displayName":"Save/Open","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Save/Open","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","displayName":"Server Settings","description":"Microsoft Office 2016\\Server Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8e143bee-82fa-4e45-8bd0-c4032b0182d2"],"platforms":"windows10","technologies":"mdm"},{"id":"6b71fbf6-7156-471a-b488-3eece04bda86","displayName":"Printing","description":"Microsoft Edge - Default Settings (users can override)\\Printing","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","displayName":"Tools | Options | Spelling","description":"Microsoft Office 2016\\Tools | Options | Spelling","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["df357f0c-78fe-4aee-a465-f3da7499077e"],"platforms":"windows10","technologies":"mdm"},{"id":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","displayName":"Math Settings","description":"Declarative Device Management preview Math Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"6b87c5da-cfd9-44bc-be05-ed08eb2144c7","displayName":"User Accounts","description":"Administrative Templates User Accounts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","displayName":"Desktop","description":"Administrative Templates\\Desktop","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f4f0dfd7-4638-4173-8b3b-0f08608bf330","a69e7a98-5af7-4834-bae1-2a1047663a71"],"platforms":"windows10","technologies":"mdm"},{"id":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","displayName":"Network Connectivity Status Indicator","description":"Administrative Templates Network Connectivity Status Indicator","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c142a01-47fa-422d-8135-29e81bc970cc","displayName":"Conversion Service","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\Conversion Service","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c1d9109-e4d1-4718-a537-dd685464fdbe","displayName":"i SCSI Security","description":"Administrative Templatesi SCS Ii SCSI Security","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c7168c3-6f34-4086-af0b-ed0b74301dc9","displayName":"Security Settings","description":"Administrative Templates Service Control Manager Settings Security Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6cd02266-a42f-4675-b83e-37360dbf3c68","displayName":"WLAN Media Cost","description":"Administrative Templates WLAN Service WLAN Media Cost","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","displayName":"Customize Ribbon","description":"Microsoft Publisher 2016\\Publisher Options\\Customize Ribbon","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d4184ab-a66c-47f1-b54e-af55f654e2a5","displayName":"Hotspot Authentication","description":"Administrative Templates Hotspot Authentication","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","displayName":"Related Website Sets Settings","description":"Microsoft Edge Related Website Sets Settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","displayName":"Password manager","description":"Google Google Chrome - Default Settings users can override Password manager","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","displayName":"Link- Layer Topology Discovery","description":"Administrative Templates Link- Layer Topology Discovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","displayName":"Login Items","description":"Login > Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","displayName":"Pen Flicks Learning","description":"Administrative Templates Pen Flicks Learning","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6f1386e5-148d-4dc3-84d1-79df721e3233","displayName":"Default search provider","description":"Microsoft Edge - Default Settings (users can override)\\Default search provider","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6fafeb5c-65ce-4993-b421-46e60da69131","displayName":"HTTP authentication","description":"Microsoft Edge - Default Settings (users can override)\\HTTP authentication","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","displayName":"General","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Advanced\\Web Options...\\General","helpText":null,"parentCategoryId":"76b233cc-f977-4305-b02f-deef6667251d","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70063d93-03f0-462e-9943-b0241b88d54d","displayName":"Desktop App Installer","description":"Administrative Templates Windows Components Desktop App Installer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70498fad-5ddb-4730-8130-d755ff675760","displayName":"Default search provider","description":"Google Google Chrome Default search provider","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","displayName":"Calendar Type","description":"Microsoft Project 2016\\Project Options\\View\\Calendar Type","helpText":null,"parentCategoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70b5da13-9c31-4857-890d-b7eb223729c3","displayName":"Firewall","description":"Networking > Firewall","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"70c4566f-a079-4a8e-ac97-0736b405df1d","displayName":"Work profile password","description":"Device Restriction Work profile password","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"70d374bf-6444-4b74-a879-a29e4d44c566","displayName":"News And Interests","description":"News And Interests","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"70d374bf-6444-4b74-a879-a29e4d44c566","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70dd505d-40d4-4685-b639-67efc9274ec4","displayName":"Typosquatting Checker settings","description":"Microsoft Edge - Default Settings (users can override)\\ Typosquatting Checker settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7120bf9e-e5f6-42cd-8f7e-15d2ca445c37","displayName":"Power Throttling Settings","description":"Administrative Templates\\System\\Power Management\\Power Throttling Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"712d184f-d9ac-45fc-9eea-aade3a22b55e","displayName":"Volume Activation","description":"Microsoft Office 2016 (Machine)\\Volume Activation","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"717b634f-72a6-44f6-92c5-e1397bb10f40","displayName":"Keyboard Filter","description":"Keyboard Filter","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"719595d8-ab5d-4418-88aa-8cd55c2964ba","displayName":"Cloud Cache","description":"FS Logix Profile Containers Cloud Cache","helpText":null,"parentCategoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f349a7-1ca3-4945-8c7d-fd68df3759ac","displayName":"Enhanced Storage Access","description":"Administrative Templates\\System\\Enhanced Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","displayName":"Tracking Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Tracking Options","helpText":null,"parentCategoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","displayName":"Operating system settings","description":"Operating system settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","childCategoryIds":[],"platforms":"windows10","technologies":"windowsOsRecovery"},{"id":"71f9795f-defc-4b03-a2b4-31e129b6f861","displayName":"Network Sharing","description":"Administrative Templates\\Windows Components\\Network Sharing","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7226f8a2-c542-471a-8d9e-e0df527325d3","displayName":"Notification Settings","description":"Administrative Templates Power Management Notification Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"724d930a-7a3c-4171-a17c-431cee336518","displayName":"Software Update Settings","description":"Managed Settings Software Update Settings","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","displayName":"Define Shared Workspace URL's","description":"Microsoft Office 2016\\Global Options\\Customize\\Shared Workspace\\Define Shared Workspace URL's","helpText":null,"parentCategoryId":"13123148-c522-437f-b316-d78f5cc0d28d","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"728890f5-bddd-4b69-a1b6-efb221d902d4","displayName":"RemoteFX USB Device Redirection","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Connection Client\\RemoteFX USB Device Redirection","helpText":null,"parentCategoryId":"a4877a42-7e62-4216-a477-0b35357ab313","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72972c43-36a3-4034-8cc8-334c99087798","displayName":"Instant Search","description":"Administrative Templates Instant Search","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","displayName":"First Run","description":"Microsoft Office 2016\\First Run","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72dfdba4-e7bb-4f09-862c-e003ea763452","displayName":"Internet Communication settings","description":"Administrative Templates\\System\\Internet Communication Management\\Internet Communication settings","helpText":null,"parentCategoryId":"184aa343-0f0b-4bf5-aeeb-42111fedfbbf","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72f61c7d-e5d2-4170-baf3-c953c1082e19","displayName":"Controlled Folder Access","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard Controlled Folder Access","helpText":null,"parentCategoryId":"ad84cea3-5664-4e42-a9d6-1446828bea45","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73415dea-0103-4427-83c5-6c97bf81af1d","displayName":"Save Documents","description":"Microsoft Visio 2016\\Visio Options\\Save\\Save Documents","helpText":null,"parentCategoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"734bed4f-be52-46ef-ae60-8fd195dc8f4d","displayName":"Access-Denied Assistance","description":"Administrative Templates\\System\\Access-Denied Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"736134cb-4d82-427a-97b7-d219ac6a22f0","displayName":"Corrupted File Recovery","description":"Administrative Templates Corrupted File Recovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73935f55-c845-40ce-819e-838c0041f6fa","displayName":"Resultant Set of Policy snap-in extensions","description":"Administrative Templates Group Policy Resultant Set of Policy snap-in extensions","helpText":null,"parentCategoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73a3a483-dcba-4b34-b7cb-9c68c871864c","displayName":"Remote Procedure Call","description":"Administrative Templates\\System\\Remote Procedure Call","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73bc2db9-d37f-4add-a64d-a8239273edb3","displayName":"Check Accessibility","description":"Microsoft Word 2016\\File Tab\\Check Accessibility","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"740e7a10-3774-4a1c-9970-6907e0f0b848","displayName":"Disable Items in User Interface","description":"Microsoft Word 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["0f42fc50-66c8-4b70-9904-64f8d662c930","44e27b70-4bdb-4aec-a75d-0568a1edc332"],"platforms":"windows10","technologies":"mdm"},{"id":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","displayName":"BITS","description":"BITS","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7444c3f0-214b-45ea-9b8e-f74b81543644","displayName":"Microsoft account","description":"Administrative Templates\\Windows Components\\Microsoft account","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7490c4fd-c326-42f7-9908-006504616d4c","displayName":"Trust Center","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["5c4224e0-6a48-4665-9332-958d98124157","2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","fe54701d-42bd-47f0-9c49-26ff6a928b32","e36863b6-3232-4a29-be02-32ee67cc48b9"],"platforms":"windows10","technologies":"mdm"},{"id":"751cf9ec-7214-4b38-a09e-24922684bd8f","displayName":"Presentation Settings","description":"Administrative Templates Presentation Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"756d2b0b-5f06-45e7-b5c5-c066deb5ed2f","displayName":"Extension snap-ins","description":"Administrative Templates Microsoft Management Console Restricted Permitted snap-ins Extension snap-ins","helpText":null,"parentCategoryId":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7574a907-5608-491f-8011-c57d487457f4","displayName":"Sync your settings","description":"Administrative Templates\\Windows Components\\Sync your settings","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75ad885f-6118-4508-a2fd-bb26be931c3f","displayName":"Outlook Today Settings","description":"Microsoft Outlook 2016\\Outlook Today Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","displayName":"Event Logging","description":"Administrative Templates Event Logging","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","displayName":"File Block Settings","description":"Microsoft Visio 2016\\Visio Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"760376f3-6b74-4992-89eb-aa41d6190e94","displayName":"Subscription Activation","description":"Microsoft Office 2016\\Subscription Activation","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"763525a0-8456-4336-a8d1-392253e8fdd8","displayName":"System Policy Control","description":"System Policy\\ System Policy Control","helpText":null,"parentCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"7652894d-4667-443f-b925-b1686a942729","displayName":"Disable Items in User Interface","description":"Microsoft Outlook 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["8184df77-410e-41a6-b687-88de05769977","d59dfcc1-6c35-41de-bfb6-de94b8120ca5"],"platforms":"windows10","technologies":"mdm"},{"id":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","displayName":"File Provider","description":"System Configuration > File Provider","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"76ad3567-c6cb-43b5-b91d-a52a34853c03","displayName":"Trusted Locations","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76b233cc-f977-4305-b02f-deef6667251d","displayName":"Advanced","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Advanced","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["6fd44fd0-80d1-47a0-acad-c115e5b807b6"],"platforms":"windows10","technologies":"mdm"},{"id":"76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","displayName":"Audit Process Creation","description":"Administrative Templates Audit Process Creation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76c53aab-0288-4ac1-b399-0104e04c6457","displayName":"Application Compatibility Diagnostics","description":"Administrative Templates Application Compatibility Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76c8131a-62fe-4134-aeac-d999f01911ed","displayName":"Network Connections","description":"Administrative Templates\\Network\\Network Connections","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76e34834-6d47-4e06-b14c-aa2888cdce27","displayName":"Generative AI","description":"Microsoft Edge Generative AI","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76f2d08c-0a3f-4f4e-ad04-51aa16aea0bf","displayName":"Intranet Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Intranet Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","displayName":"Publishing","description":"Administrative Templates App-V Publishing","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"77b0357b-412e-4a81-9469-e20a5f1345fd","displayName":"Complex scripts","description":"Microsoft Publisher 2016\\Publisher Options\\Advanced\\Complex scripts","helpText":null,"parentCategoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"77ca5e78-a1fe-456e-9814-034b1ea2658d","displayName":"PowerPoint Designer","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\PowerPoint Designer","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"78497707-c3e4-400b-a6bc-1813c3689fdc","displayName":"Preferences","description":"Microsoft Edge Update\\Preferences","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","displayName":"TCPIP Settings","description":"Administrative Templates TCPIP Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["91789113-6339-4e96-8e1d-73a4dec4967f","486f25cc-c865-446e-95b2-c5b061883a7a"],"platforms":"windows10","technologies":"mdm"},{"id":"788355e5-e113-4b17-ada9-fb5ef38bffa1","displayName":"App-V","description":"Administrative Templates App-V","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["7740c7ba-aa61-4486-ad26-cb8721a2efb4","e7cc16d8-f74f-4cd7-890d-9b4082a19c39","efabaf11-42e4-48ab-81ca-4514199d239b","b9201072-3681-4e95-ad90-869e6166b129","10835ce3-31c8-4ec6-aa00-c5af48e550a8","5011ca61-1a58-42da-9c66-7763236acc84","ea9a092f-dd93-41d4-9bbb-118de1213578","f125d7cd-a333-4f24-a5f4-99fc289c6d22"],"platforms":"windows10","technologies":"mdm"},{"id":"78906e32-f4fb-453b-939b-05717ffaae59","displayName":"ActiveX Installer Service","description":"Administrative Templates\\Windows Components\\ActiveX Installer Service","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"78b3d753-d84d-496b-a93c-d577ab5865bd","displayName":"Scripted Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Scripted Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"78d3d93f-03d0-4fa0-be56-be4bca0a7b3b","displayName":"Trusted Platform Module Services","description":"Administrative Templates\\System\\Trusted Platform Module Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"794337be-8833-4b9a-bb88-8a030141578d","displayName":"Search","description":"Search","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"794337be-8833-4b9a-bb88-8a030141578d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"797ac384-f48e-4567-b931-33a6ce923b94","displayName":"Microsoft Edge Canary","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Canary","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7a3a7335-4837-4bc5-9282-448402a05d89","displayName":"Control Panel","description":"Administrative Templates\\Control Panel","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["e6231142-3d39-44a7-9522-6a3357bd439f","2694014c-e044-45a0-99b1-1694bd01827a","18db3d59-661b-47ec-900a-bf75495ca598","a809df26-b5db-4af9-b247-a539ada4e869","2b8e43c0-e66b-4bec-b20d-54a1f7151212","684799ba-398b-4728-aa21-40c8469cbe87","f4eaa5be-1498-482e-abe6-de4fed7e3302"],"platforms":"windows10","technologies":"mdm"},{"id":"7a85e72a-a755-4903-b1fd-4939049380f4","displayName":"Privacy","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Privacy","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7a8b936d-b4b0-408f-bec5-3c97050730f8","displayName":"Shared paths","description":"Microsoft Office 2016\\Shared paths","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7aeaf6f8-5511-4216-9483-28f432a5a08f","displayName":"Server Settings","description":"Microsoft PowerPoint 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","displayName":"App Lock","description":"App Management > App Lock","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","displayName":"Extensible Single Sign On (SSO)","description":"Authentication > Extensible Single Sign On (SSO)","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm"},{"id":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","displayName":"Microsoft Edge Beta","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Beta","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7bc264db-6da2-4c6b-a357-aec47c717737","displayName":"Disk Diagnostic","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Disk Diagnostic","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7bee4dea-82a4-4a03-b903-654b374819b1","displayName":"Chinese Conversion | Convert with Options","description":"Microsoft Word 2016\\Review Tab\\Chinese Conversion | Convert with Options","helpText":null,"parentCategoryId":"1fddd12c-a630-47f0-9633-638808e228f9","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7c34b514-0fb4-4868-8418-cb9b28f9f6e3","displayName":"Previous Versions","description":"Administrative Templates\\Windows Components\\File Explorer\\Previous Versions","helpText":null,"parentCategoryId":"35525ba9-da99-460e-afd3-ba86506b0ba3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","displayName":"Windows Connect Now","description":"Administrative Templates Windows Connect Now","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d331987-7e2d-4975-b23b-d99a5af26ddf","displayName":"IME","description":"Administrative Templates IME","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d7f6a09-2088-4f1f-a1f1-14fbca93a808","displayName":"General iSCSI","description":"Administrative Templates\\System\\iSCSI\\General iSCSI","helpText":null,"parentCategoryId":"363982dd-fc96-49ce-a499-f6401f2c212b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d9e5b9b-84e7-473c-b6ca-a1629448df55","displayName":"Safari Extension Settings","description":"Declarative Device Management preview Extension Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","displayName":"Performance","description":"Microsoft Edge - Default Settings (users can override)\\Performance","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","displayName":"Predefined","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7eaa5e09-e5ab-4051-b557-64a124ae497c","displayName":"Cryptography","description":"Microsoft Access 2016\\Application Settings\\Security\\Cryptography","helpText":null,"parentCategoryId":"23fd467e-24f8-4200-8b19-c6c11afa8926","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","displayName":"Parental Controls Game Center","description":"Parental Controls > Parental Controls Game Center","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","displayName":"Display","description":"Microsoft Word 2016\\Word Options\\Display","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","displayName":"Display","description":"Display","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","displayName":"Regional and Language Options","description":"Administrative Templates Regional and Language Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["9a79d480-8cb4-47b5-95c7-5da56eea5bb8"],"platforms":"windows10","technologies":"mdm"},{"id":"7f431009-e8fe-460e-b247-06c838c8a914","displayName":"Location and Sensors","description":"Administrative Templates\\Windows Components\\Location and Sensors","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["d6595bc3-dd73-44a3-8b32-d57af6e40208"],"platforms":"windows10","technologies":"mdm"},{"id":"7f461268-0fb6-4247-b6db-52515d42a20e","displayName":"User Interface","description":"Administrative Templates Windows Media Player User Interface","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f4d325e-bff8-4d91-8313-614243e55e6d","displayName":"DC Locator DNS Records","description":"Administrative Templates\\System\\Net Logon\\DC Locator DNS Records","helpText":null,"parentCategoryId":"bedf20d1-1f5a-4840-8458-6d0fa974b664","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f5517b0-3ff7-4f7e-aa4c-3d2ccbf37bdc","displayName":"VPN Connection","description":"VPN Connection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7f5517b0-3ff7-4f7e-aa4c-3d2ccbf37bdc","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7fc23813-7a7c-412a-b9bd-eda07e6b1f5d","displayName":"List Sync","description":"List Sync","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7fc23813-7a7c-412a-b9bd-eda07e6b1f5d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7fc3275d-5ef6-4806-88b0-210bb175c182","displayName":"Network List Manager","description":"Network List Manager","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7fc3275d-5ef6-4806-88b0-210bb175c182","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"8028dead-8f13-4fe3-9998-ba1e841324d7","displayName":"Windows Apps","description":"Administrative Templates\\Windows Components\\Microsoft User Experience Virtualization\\Windows Apps","helpText":null,"parentCategoryId":"9e857bed-81f8-4dfc-b049-c93eb68b4064","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","displayName":"Feedback Settings","description":"Visual Studio Feedback Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8084033c-156a-4d1b-ab0b-159541810459","displayName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","description":"Microsoft Office 2016\\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["69931627-230d-4df9-bbef-e3eac64ea8ef"],"platforms":"windows10","technologies":"mdm"},{"id":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","displayName":"Config Refresh","description":"Config Refresh","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"80ed7629-87dd-4bb1-8ea0-555f20d3b156","displayName":"Mitigation Options","description":"Administrative Templates\\System\\Mitigation Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"80f5fb2f-e74a-4533-81aa-a92163f49e16","displayName":"Local Machine Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Local Machine Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"811f63f1-1619-4b48-b8f0-3d388729bd47","displayName":"Xsan","description":"Xsan","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":["46af3391-ed6d-4ada-aef7-02dac2a1b136","fd3717c1-dcf8-4038-b7f7-4ad3359a9d32"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"814e9e4d-b838-4747-a257-72390a535d56","displayName":"Group Policy snap-in extensions","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins\\Group Policy\\Group Policy snap-in extensions","helpText":null,"parentCategoryId":"3d32fb39-ff23-48d9-9890-c8625d2d21e9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8184df77-410e-41a6-b687-88de05769977","displayName":"Custom","description":"Microsoft Outlook 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"7652894d-4667-443f-b925-b1686a942729","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"81bc8383-43a5-4c6a-9d51-951e86028934","displayName":"Project Guide settings for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Interface\\Project Guide settings for 'Project1'","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"81c518f1-522e-4957-b850-e8a66d2ab215","displayName":"Games settings","description":"Microsoft Edge Games settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"81eb92d0-acda-4ea2-8183-29ed5457276b","displayName":"Container and Directory Naming","description":"FS Logix ODFC Containers Container and Directory Naming","helpText":null,"parentCategoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","displayName":"Remediation","description":"Administrative Templates Microsoft Defender Antivirus Remediation","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"822bd634-4d01-486e-adad-8085968fd1c4","displayName":"Advanced Page","description":"Administrative Templates Internet Explorer Internet Control Panel Advanced Page","helpText":null,"parentCategoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"826db7fb-889b-4a99-80a6-38347ba37f21","displayName":"Recurring item configuration","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Recurring item configuration","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8280dcb9-f2bc-417b-b4ef-cd6c35398f94","displayName":"Driver Installation","description":"Administrative Templates\\System\\Driver Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"829d1e81-4cbc-4259-bd0e-8cc44870f00e","displayName":"Restrict ActiveX Install","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Restrict ActiveX Install","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"82a437a8-6be8-4003-a951-951999e86db8","displayName":"Parental Controls","description":"Parental Controls","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":["f019963f-f4ed-4429-b6e3-babfb24c36a8","7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","dc270c70-1cf4-4d98-ad26-8c2d441173f1","65087b94-7e45-4d74-a50d-df4377b67499"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"82a9c23f-2c09-4479-9cd3-e7f185d7676f","displayName":"Offline Files","description":"Administrative Templates\\Network\\Offline Files","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"82d173f9-ba0b-4b09-bbb8-68cba4916162","displayName":"Privacy Preferences Policy Control","description":"Privacy > Privacy Preferences Policy Control","helpText":null,"parentCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","rootCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"82d20a08-90b8-4e6d-940a-5574844d1b26","displayName":"DSCP value of non-conforming packets","description":"Administrative Templates\\Network\\QoS Packet Scheduler\\DSCP value of non-conforming packets","helpText":null,"parentCategoryId":"01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"82ecfab7-b76a-4cec-8e76-859db4599ac2","displayName":"Cached Exchange Mode","description":"Microsoft Outlook 2016\\Account Settings\\Exchange\\Cached Exchange Mode","helpText":null,"parentCategoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83087772-6560-4488-a1c5-bb6e4889e868","displayName":"Advanced","description":"Microsoft Word 2016\\Word Options\\Advanced","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["bc65521d-e48a-4e95-899f-49df827808ca","e63361ad-a54b-4557-acc7-02c272a3e58d","61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","2108b443-384c-4bb3-9b9f-acb4a754a86a"],"platforms":"windows10","technologies":"mdm"},{"id":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","displayName":"Caldav","description":"Accounts > CalDAV","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"832f3a51-5e73-4541-8f14-1323cd9919bc","displayName":"When sending a message","description":"Microsoft Outlook 2016 Outlook Options Preferences E-mail Options Advanced E-mail Options When sending a message","helpText":null,"parentCategoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8391e79d-d618-47c3-979c-83544da43739","displayName":"Protected View","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","displayName":"Multi SIM","description":"Multi SIM","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83febe72-a64f-4051-9071-1efae1ea9a15","displayName":"Disk Management","description":"Declarative Device Management preview Disk Management","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"macOS","technologies":"appleRemoteManagement"},{"id":"845ff38a-408b-449c-9ef3-7fdc331027df","displayName":"Azure Virtual Desktop","description":"Administrative Templates Windows Components Remote Desktop Services Remote Desktop Session Host Azure Virtual Desktop","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5d4e843b-2848-4508-9143-cb3217c2fe83"],"platforms":"windows10","technologies":"mdm"},{"id":"8495c82c-f273-4bcc-8886-6751103a9c7b","displayName":"Proofing","description":"Microsoft Visio 2016 Visio Options Proofing","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["af9b2941-29f9-4ee5-ae09-215f4e242943"],"platforms":"windows10","technologies":"mdm"},{"id":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","displayName":"User Experience","description":"User Experience","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":["e42edcd8-fcb0-4255-a774-c78b34f0b0c9","cc388035-b49c-493e-a598-14b0d0de4359","361859d9-1382-47c3-b9ec-9251a62fbb25","c00d6468-cac3-429c-ada5-ba3adf4982a8","11c4cf0f-a03d-4309-93b2-011be4c410d5","b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","ff90bf4b-0583-4761-a1c4-5aa4b50c5872","d8f06fcf-7328-43ac-b5b7-f7166b5333de"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"84b7f123-e849-40f9-914b-4b97b57bd3b4","displayName":"Interface","description":"Microsoft Project 2016\\Project Options\\Interface","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["343eb575-3ac8-4da9-b66d-ce84b84be7c3","81bc8383-43a5-4c6a-9d51-951e86028934","fe7c8652-17d4-40a7-869c-f7cfc3454402"],"platforms":"windows10","technologies":"mdm"},{"id":"84de2eed-843c-401b-a3fd-e21be88f2365","displayName":"Pen","description":"Microsoft OneNote 2016\\OneNote Options\\Pen","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"853d5a82-91e4-4c53-8338-fd1a3d9b542c","displayName":"MK Protocol Security Restriction","description":"Administrative Templates Internet Explorer Security Features MK Protocol Security Restriction","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"853f4181-42e8-411c-91cf-c06968c0a543","displayName":"Time Server","description":"System Configuration > Time Server","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"85810387-3320-4056-bae2-953beeb246f7","displayName":"Security","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["9544c86b-47bb-4cb2-a725-63214a0454f4","36ddafde-fdc7-4787-bf6e-2291446ccc6b"],"platforms":"windows10","technologies":"mdm"},{"id":"859f3bfb-70f6-447a-822e-680ac98e91ce","displayName":"Microsoft Visual Studio","description":"Visual Studio","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":["802f3065-0bf1-4578-9d6d-ab1ef02db3ec","175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","b3b30966-47ac-4b54-a75a-04418d5c6153","d9d5f333-9402-4459-8ef1-e29330cac8be","652a676c-9d60-4c9a-88b6-823a24961a9b","96277512-3d35-4876-ad74-2d849348799e"],"platforms":"windows10","technologies":"mdm"},{"id":"85c586a6-6b68-48b2-8050-c4fb86aff486","displayName":"RD Gateway","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\RD Gateway","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"865a5fd9-f9be-496d-acb4-cd7cdb03e19f","displayName":"Security Center","description":"Administrative Templates\\Windows Components\\Security Center","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","displayName":"Disable Items in User Interface","description":"Microsoft Office 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","displayName":"Power Throttling Settings","description":"Administrative Templates Power Management Power Throttling Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","displayName":"Updates","description":"Microsoft Office 2016 (Machine)\\Updates","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86e78a4b-706a-4ec8-be90-439461abb29d","displayName":"File Revocation","description":"Administrative Templates File Revocation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","displayName":"SSL Configuration Settings","description":"Administrative Templates SSL Configuration Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87667b72-85ce-48c2-8023-e6db7f5fe739","displayName":"Work Folders","description":"Administrative Templates Work Folders","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8778eb21-bf7c-41a7-bae1-412c0e3029db","displayName":"Licensing","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Licensing","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87e607d8-500d-4dba-a58f-d7695945c973","displayName":"Early Launch Antimalware","description":"Administrative Templates\\System\\Early Launch Antimalware","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87f460f4-8403-419c-bfb4-44dec5edcccb","displayName":"Media Management Disc Burning","description":"Media Management > Media Management Disc Burning","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","displayName":"Lanman Workstation","description":"Administrative Templates Lanman Workstation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"88b16683-81f2-450a-9bf2-42f582e0b748","displayName":"Stationery and Fonts","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Stationery and Fonts","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"891d2958-5a8c-479c-aa68-69b1b6c735e1","displayName":"Shared PC","description":"Shared PC","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89519fc9-9b38-4401-8767-b0a047cae515","displayName":"Device Restriction","description":"Device Restriction","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":["2257f7e1-3e88-4d4d-a666-437bbe42baca","929c169a-3480-467c-9f47-d1836b359ef7","bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","70c4566f-a079-4a8e-ac97-0736b405df1d","990880db-3f64-4436-ab4a-d7d5181dfa5d","f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","aad0d3ef-88f5-4b22-831b-27093eafbc64","b6733d23-eadc-486a-abfc-62b78698a16c"],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"895e0884-6b60-4bb0-b2ab-3a1642103db7","displayName":"Native Messaging","description":"Google Google Chrome Native Messaging","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","displayName":"Downloads","description":"Microsoft Edge - Default Settings users can override Downloads","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"897675f9-0d1b-437b-ba0a-584fbd54df95","displayName":"Advanced E-mail Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Advanced E-mail Options","helpText":null,"parentCategoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["35f245bd-8d1f-424c-83de-a80be27a6a4e","832f3a51-5e73-4541-8f14-1323cd9919bc"],"platforms":"windows10","technologies":"mdm"},{"id":"89ad0055-1603-420e-940d-9944a63e3da9","displayName":"Profiles","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Profiles","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","displayName":"Save","description":"Microsoft Word 2016\\Word Options\\Save","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89c0381d-3b9b-4be5-8077-ffb18d47e910","displayName":"Add-on Management","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Add-on Management","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8a03aebc-9249-4917-a1c3-2957717d9123","displayName":"Real-time Protection","description":"Administrative Templates Microsoft Defender Antivirus Real-time Protection","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8a409581-8ea5-493c-9e9e-2190f66381c3","displayName":"DirectAccess Client Experience Settings","description":"Administrative Templates\\Network\\DirectAccess Client Experience Settings","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8aa3383a-efac-4ec4-841d-06e3e18646d8","displayName":"Default search provider","description":"Microsoft Edge\\Default search provider","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"8abddb23-7036-4ba8-8912-529279a849ea","displayName":"Security Preferences","description":"Security > Security Preferences","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8b0e5a63-c309-430b-8521-7bd21e715b90","displayName":"Office 2016 Converters","description":"Microsoft Office 2016\\Office 2016 Converters","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8b7e662c-0410-4e33-ae11-edb7c717d914","displayName":"Restricted Browsing","description":"Microsoft Office 2016\\File Open/Save dialog box\\Restricted Browsing","helpText":null,"parentCategoryId":"92be4fc7-8095-441c-b52b-9861c21bc337","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","displayName":"Immersive Reader settings","description":"Microsoft Edge Immersive Reader settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"8c30a64e-ad24-47a0-97a8-52320360fd88","displayName":"Net Logon","description":"Administrative Templates Net Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["41ba590e-9105-4eda-92fb-13c7d34b8eee"],"platforms":"windows10","technologies":"mdm"},{"id":"8c35f124-e249-43e3-9044-ecc0b0a5855a","displayName":"Idle Browser Actions","description":"Google Google Chrome Idle Browser Actions","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8c75a12d-664d-43ba-a3aa-5259425f9b37","displayName":"Energy Saver","description":"System Configuration > Energy Saver","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","displayName":"App Settings","description":"Declarative Device Management preview App Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","displayName":"Miscellaneous","description":"Microsoft Office 2016 (Machine)\\Miscellaneous","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8caf4546-4ed8-4e8a-b9e7-5ab48c13b709","displayName":"PackageManagement","description":"Administrative Templates\\System\\App-V\\PackageManagement","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8ccb6340-4f25-4bda-a527-127d269b3cbf","displayName":"Windows Calendar","description":"Administrative Templates\\Windows Components\\Windows Calendar","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8cefd936-362e-4a24-bc76-e078b6fd13fa","displayName":"Screensaver","description":"System Configuration > Screensaver","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","displayName":"Trusted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Trusted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8d27fb75-5aeb-44f0-aab2-064cc4b9ecd6","displayName":"Audit Process Creation","description":"Administrative Templates\\System\\Audit Process Creation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8d4a5b79-8399-4075-a71f-80ac3099ae78","displayName":"Bluetooth","description":"Bluetooth","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"8d503574-f93a-4277-a30d-19895d46dd13","displayName":"Security Page","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page","helpText":null,"parentCategoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["4086190d-2e5b-439d-8426-08492ebb8c9f","58ae30f4-10a2-4144-a593-b5f5bd93c10d","dfede24d-d1c8-4e20-82a3-89e1b52057d5","99dfe848-181d-480a-bd20-3f93f04b6f5c","fca9261c-1e93-467d-90cf-ba9108e4cb2e","8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","ac014aea-e417-46ad-a4a5-9a1fb1030882","44c15b2f-10da-4e1e-836b-8b71c19fe34c"],"platforms":"windows10","technologies":"mdm"},{"id":"8d5ce834-5b70-4ec2-8d07-eae26ab6493f","displayName":"Consistent Mime Handling","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Consistent Mime Handling","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8d9eaa88-a2b4-42e7-83e5-8dc12f51d36b","displayName":"Eap","description":"Eap","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8d9eaa88-a2b4-42e7-83e5-8dc12f51d36b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","displayName":"Device Installation","description":"Administrative Templates Device Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["68237832-f376-4f0e-ba26-4e06fce7a35d"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"8dca6b5f-ff9c-44c8-9822-008acef616aa","displayName":"Security","description":"Administrative Templates\\Windows Components\\Event Log Service\\Security","helpText":null,"parentCategoryId":"fcddcc0b-7cf8-4ebc-a818-d10689603263","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","displayName":"SharePoint Server","description":"Microsoft Office 2016\\Server Settings\\SharePoint Server","helpText":null,"parentCategoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e19ed1e-e870-4769-bd6f-321f6f47023b","displayName":"Application Compatibility Settings","description":"Administrative Templates\\System\\Distributed COM\\Application Compatibility Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e48532a-ff0e-4422-82e2-6956b6786005","displayName":"Customize Ribbon","description":"Microsoft Project 2016\\Project Options\\Customize Ribbon","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","displayName":"Intranet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Intranet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","displayName":"Removable Data Drives","description":"Administrative Templates BitLocker Drive Encryption Removable Data Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","displayName":"Junk E-mail","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Junk E-mail","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8eb61398-1074-4fa0-8bd4-04d751a9ccad","displayName":"Windows Memory Leak Diagnosis","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Memory Leak Diagnosis","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8ee1d8d2-582f-401b-927a-993016f4290d","displayName":"Browsers","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Browsers","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","displayName":"Windows Error Reporting","description":"Administrative Templates Windows Error Reporting","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["1551f6d3-415c-44a8-b184-393de7c42adf","184981d4-712b-425e-b0a3-93eac7fbd3ee"],"platforms":"windows10","technologies":"mdm"},{"id":"8efd284f-5a56-4da8-8821-f51984ff954d","displayName":"Associated Domains","description":"App Management > Associated Domains","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","displayName":"Login Window Behavior","description":"Login > Login Window Behavior","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8ff93a7a-503c-4955-89be-900d475b7c5e","displayName":"Managed Settings","description":"Managed Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":["0be23ead-c5f7-4ea5-9ec5-64c05d19cf5d","99d68d97-63b7-4f49-83dd-1ad3b3281d0d","1fbc29d7-0530-4208-b506-9df648a402e9","5f71c40e-01aa-42d2-9c8c-7d560126cd4b","b32726b3-b0e9-465b-86f8-b61ad8af52f0","ef7328b1-c666-40fe-a933-57b14bc77dd3","e7dccaa6-2b16-4dd3-b835-83ca641d0c80","3c7f15ef-a539-411c-93f1-5f97b7bd5519","1a056b49-3fb9-4097-b286-c5f493208578","724d930a-7a3c-4171-a17c-431cee336518","dd68a290-1ba7-470f-afca-339f443a767c","2c156b7e-99c8-4a21-a828-4f9b94479b0d"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","displayName":"Networking","description":"Administrative Templates Windows Media Player Networking","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"902f5df1-31d6-44ee-ba95-2561199db35f","displayName":"Sync your settings","description":"Administrative Templates Sync your settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","displayName":"Global HTTP Proxy","description":"Proxies > Global HTTP Proxy","helpText":null,"parentCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"907fd656-2a80-4f34-8615-a3acb11a2b95","displayName":"Custom","description":"Microsoft Publisher 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"909339a5-8f04-4fa2-8807-5d38c83ef547","displayName":"Device Guard","description":"Administrative Templates Device Guard","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"90bbab80-ecf0-47c6-bf01-76b26a3dc503","displayName":"Touch Input","description":"Administrative Templates\\Windows Components\\Tablet PC\\Touch Input","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"90e3acc6-80d5-41b4-8141-a8620a211c0e","displayName":"Tenant Restrictions","description":"Administrative Templates Tenant Restrictions","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","displayName":"Online Content","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\Online Content","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","displayName":"Local Policies Security Options","description":"Local Policies Security Options","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91789113-6339-4e96-8e1d-73a4dec4967f","displayName":"Parameters","description":"Administrative Templates TCPIP Settings Parameters","helpText":null,"parentCategoryId":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"917d0fb9-b5dd-401b-982b-1d32f6e0a306","displayName":"Pen UX Behaviors","description":"Administrative Templates\\Windows Components\\Tablet PC\\Pen UX Behaviors","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","displayName":"International Options","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\International Options","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91c02e14-8848-485d-8844-b9933fa888ec","displayName":"Hard Disk Settings","description":"Administrative Templates Power Management Hard Disk Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91ed1812-8841-4eb3-b24e-a5e1f4eaa6c8","displayName":"Restrict File Download","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Restrict File Download","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9215e382-4e7b-4554-8c80-80277136b544","displayName":"Formulas","description":"Microsoft Excel 2016\\Excel Options\\Formulas","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"92503b7f-9fa0-4365-8482-57dd61e6d535","displayName":"RD Connection Broker","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\RD Connection Broker","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"929c169a-3480-467c-9f47-d1836b359ef7","displayName":"Connectivity","description":"Device Restriction Connectivity","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"92be4fc7-8095-441c-b52b-9861c21bc337","displayName":"File Open/Save dialog box","description":"Microsoft Office 2016\\File Open/Save dialog box","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8b7e662c-0410-4e33-ae11-edb7c717d914","4a832199-a841-4b6a-84fa-51365902a742"],"platforms":"windows10","technologies":"mdm"},{"id":"92d69c43-75ac-49b1-a3ef-9350079eef86","displayName":"Content settings","description":"Microsoft Edge\\Content settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","displayName":"Account Settings","description":"Microsoft Outlook 2016\\Account Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["060e7533-6c2f-4ed1-9173-f3de58de4bed","43053249-ecd1-4d9f-9fa9-c05e7713da7f","c4dbc05f-da1e-440d-8beb-91bf9dad1875","b161cf66-abfa-4a36-a9ac-c20ca60594e0","63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","4e349e4a-dd0b-4175-8974-a2a0f5e35b4d"],"platforms":"windows10","technologies":"mdm"},{"id":"93099bd4-c685-434b-9d72-f0cb6db5e753","displayName":"Cloud delivered protection preferences","description":"Microsoft Defender > Cloud-delivered protection preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"930d2960-3f70-48ca-9ead-b65a5a037c07","displayName":"SNMP","description":"Administrative Templates SNMP","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9329c2bd-9e56-4394-9c89-5726e8b76f2f","displayName":"Scripts","description":"Administrative Templates\\System\\Scripts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93a20c17-1e34-4778-8c95-91a46980ea75","displayName":"Out of Office Assistant","description":"Microsoft Outlook 2016\\Outlook Options\\Out of Office Assistant","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93c28398-faef-4ca5-9667-f5ed004da32c","displayName":"Internet Information Services","description":"Administrative Templates Internet Information Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93decccd-de24-4ec4-b21c-e08c14f13576","displayName":"Common Open File Dialog","description":"Administrative Templates\\Windows Components\\File Explorer\\Common Open File Dialog","helpText":null,"parentCategoryId":"35525ba9-da99-460e-afd3-ba86506b0ba3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93ed2300-658d-40f3-8211-9295a240579c","displayName":"HTTP authentication","description":"Google Google Chrome HTTP authentication","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"949a5b32-bbe6-40f6-9d73-99cf9fafe75f","displayName":"Removable Data Drives","description":"Administrative Templates\\Windows Components\\BitLocker Drive Encryption\\Removable Data Drives","helpText":null,"parentCategoryId":"0101d1d0-1e54-47b0-a749-62c6bd7ab3da","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","displayName":"Notifications","description":"Administrative Templates Notifications","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94b5c25e-3af3-4c08-b738-a0527f91dc22","displayName":"Security Intelligence Updates","description":"Administrative Templates Microsoft Defender Antivirus Security Intelligence Updates","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94ce8206-be22-496c-aa72-f3560e2a5c8d","displayName":"Links","description":"Microsoft Office 2016 Links","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94f6e868-1296-4811-b404-1afa2d50bc7c","displayName":"Windows Boot Performance Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Boot Performance Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","displayName":"Storage","description":"Storage","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","displayName":"Accounts","description":"Accounts","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":["5214f1e7-a5a9-4de5-80b4-2f7084a8d068","fa20bbc3-d25d-4a7f-a349-9b211d186e21","ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","9ba1b877-865a-4104-8376-b43a0c75b04b","831dcaee-a6fa-4893-a32d-e13fdf7d3777","45fe783f-a80b-42d9-ab3c-8c4081be8d05"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"952f69c8-2644-48df-976b-01fd624cbb3a","displayName":"Database","description":"Microsoft Office 2016\\Business Data\\Database","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9544c86b-47bb-4cb2-a725-63214a0454f4","displayName":"Cryptography","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"85810387-3320-4056-bae2-953beeb246f7","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"957a5b24-ed7a-4f84-9d73-7b6131367396","displayName":"Advanced","description":"Microsoft Visio 2016\\Visio Options\\Advanced","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["bec8c55d-5aee-4d87-a17d-34d5b3b78f19","4e62ada2-f091-49e1-99dd-ffdf5cf558cd","98cefd27-a980-4070-ba45-3696b623810d","f59804be-7fc6-43c3-9baa-942aab85be84","6ae0d607-832c-403b-b3bc-c563e390ebad","66395272-f132-4170-b88e-87f794f987f4"],"platforms":"windows10","technologies":"mdm"},{"id":"96277512-3d35-4876-ad74-2d849348799e","displayName":"Privacy Settings","description":"Visual Studio Privacy Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"962a2377-ad9a-4654-a526-a77c14152fd7","displayName":"Content settings","description":"Google Google Chrome - Default Settings users can override Content settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"979412d7-6716-440c-9a64-5889026d73da","displayName":"Device Installation Restrictions","description":"Administrative Templates\\System\\Device Installation\\Device Installation Restrictions","helpText":null,"parentCategoryId":"486dc66e-960c-4622-b3cb-3ff9a2d434eb","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"9859957e-34f1-4669-9f95-2b7c79fff052","displayName":"Service Management - Managed Login Items","description":"Login > Service Management - Managed Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"9865907f-b775-4d36-9578-a016c5105dfe","displayName":"AutoSave","description":"Microsoft Office 2016\\AutoSave","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98c9cd71-f6eb-4dfd-b045-85c7e0b44487","displayName":"Controlled Folder Access","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Microsoft Defender Exploit Guard\\ Controlled Folder Access","helpText":null,"parentCategoryId":"49abf969-2a98-4479-b234-6990b152cb21","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98cefd27-a980-4070-ba45-3696b623810d","displayName":"Shape Search","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Shape Search","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98dc5bd0-2b16-4263-ba2f-62115b680017","displayName":"Group Policy","description":"Administrative Templates Group Policy","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["73935f55-c845-40ce-819e-838c0041f6fa","5bb9fb31-007d-4e3f-967b-11e865fcdc70"],"platforms":"windows10","technologies":"mdm"},{"id":"98e76d3e-9e52-45b3-b0c7-f029023121e9","displayName":"Privacy","description":"Privacy","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","childCategoryIds":["82d173f9-ba0b-4b09-bbb8-68cba4916162"],"platforms":"macOS,windows10","technologies":"mdm"},{"id":"990880db-3f64-4436-ab4a-d7d5181dfa5d","displayName":"Personal Profile","description":"Device Restriction Personal Profile","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"992a8a1e-428e-41cb-948e-4e5da86105fa","displayName":"Device Guard","description":"Device Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"99b4ac32-50b5-4659-a7a1-94bc708ae71a","displayName":"Device Health Attestation Service","description":"Administrative Templates Device Health Attestation Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"99ba9e42-9872-4a03-a615-fc4a4cebc067","displayName":"Active Directory","description":"Administrative Templates Active Directory","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"99d68d97-63b7-4f49-83dd-1ad3b3281d0d","displayName":"Diagnostic Submission","description":"Managed Settings Diagnostic Submission","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"99dfe848-181d-480a-bd20-3f93f04b6f5c","displayName":"Locked- Down Intranet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Intranet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","displayName":"Intelligent Services","description":"Microsoft Excel 2016\\Intelligent Services","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","displayName":"Maps","description":"Maps","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a79d480-8cb4-47b5-95c7-5da56eea5bb8","displayName":"Handwriting personalization","description":"Administrative Templates Regional and Language Options Handwriting personalization","helpText":null,"parentCategoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","displayName":"RSS Feeds","description":"Administrative Templates RSS Feeds","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9ad70461-c727-40da-8484-250369b6a119","displayName":"Client Coexistence","description":"Administrative Templates\\System\\App-V\\Client Coexistence","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b0b8f3b-8e08-4083-9e2b-2e6bfeb01f83","displayName":"Kerberos","description":"Administrative Templates\\System\\Kerberos","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","displayName":"Miscellaneous","description":"Microsoft Office 2016\\Miscellaneous","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["5f048379-3a42-43f0-9fd5-d269f292aa35"],"platforms":"windows10","technologies":"mdm"},{"id":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","displayName":"Task Scheduler","description":"Task Scheduler","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b894b32-3697-4a83-9731-3db2a35455ad","displayName":"Cursors","description":"Administrative Templates Cursors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9ba1b877-865a-4104-8376-b43a0c75b04b","displayName":"LDAP","description":"Accounts > LDAP","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9bad0513-ac85-431c-86d9-9e3167f9b403","displayName":"Locked-Down Intranet Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Intranet Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","displayName":"Remote Desktop","description":"Remote Desktop Command","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9c815001-eace-4aa6-a929-14af0a46aaf5","displayName":"Windows Shutdown Performance Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Shutdown Performance Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","displayName":"Disable Items in User Interface","description":"Microsoft Publisher 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["441d6cc4-e51f-453e-a44d-8394509415be","907fd656-2a80-4f34-8615-a3acb11a2b95"],"platforms":"windows10","technologies":"mdm"},{"id":"9d14bbed-327d-4c38-ac02-6b916909bdd9","displayName":"Microsoft Edge","description":"Microsoft Edge Apple","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9d26f3a1-6a54-4043-bda2-bfeb84e80524","displayName":"System","description":"Administrative Templates\\Windows Components\\Event Log Service\\System","helpText":null,"parentCategoryId":"fcddcc0b-7cf8-4ebc-a818-d10689603263","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9d6a14ba-11f5-423d-afc0-8d30be1153c1","displayName":"Link-Layer Topology Discovery","description":"Administrative Templates\\Network\\Link-Layer Topology Discovery","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9dbd66e3-4544-4ca8-a118-272c874bc684","displayName":"Local Security Authority","description":"Administrative Templates Local Security Authority","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9e857bed-81f8-4dfc-b049-c93eb68b4064","displayName":"Microsoft User Experience Virtualization","description":"Administrative Templates\\Windows Components\\Microsoft User Experience Virtualization","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["8028dead-8f13-4fe3-9998-ba1e841324d7","3afbcb74-88c5-4a41-bdc2-82c117b4e82e"],"platforms":"windows10","technologies":"mdm"},{"id":"9e882396-4a1c-4d06-a62d-8d910ded8e7d","displayName":"Restricted/Permitted snap-ins","description":"Administrative Templates\\Windows Components\\Microsoft Management Console\\Restricted/Permitted snap-ins","helpText":null,"parentCategoryId":"c483faac-cebf-448a-8f90-e8a125c0c4af","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["3d32fb39-ff23-48d9-9890-c8625d2d21e9","6355e85b-aeef-49e8-b8c9-5d6cd9a39985"],"platforms":"windows10","technologies":"mdm"},{"id":"9ecb05b7-e942-4b60-9040-d612385f5c67","displayName":"Calendar","description":"Microsoft Project 2016\\Project Options\\Calendar","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","displayName":"Locked- Down Restricted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Restricted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","displayName":"User Rights","description":"User Rights","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","displayName":"Accessories","description":"Administrative Templates Accessories","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a004deb8-6f52-4411-8d94-41563a8203fc","displayName":"Quarantine","description":"Administrative Templates Microsoft Defender Antivirus Quarantine","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a01c03d4-ec76-4c01-b982-de71620feb19","displayName":"Printing","description":"Printing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":["174ffe92-3770-4688-aa21-85b7535cf374","429c4b85-a2b4-46ed-afa0-6c89c08a5544"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","displayName":"Microsoft App Store","description":"Microsoft App Store","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a0f1f801-7fce-427c-b5e2-6c6b30065fa5","displayName":"MpEngine","description":"Administrative Templates\\Windows Components\\Microsoft Defender Antivirus\\MpEngine","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a126378d-a916-476e-ad91-e3bd82fd3a48","displayName":"Notification bar","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Notification bar","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a18508d1-fd74-4955-8032-3bd9219a0944","displayName":"Fixed Data Drives","description":"Administrative Templates BitLocker Drive Encryption Fixed Data Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a185940c-7899-4ab6-867d-7559352cf8d2","displayName":"OneNote Options","description":"Microsoft OneNote 2016\\OneNote Options","helpText":null,"parentCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":["1ae8c95a-5748-4647-80f8-b447e60601a2","44774d3d-387b-4fa7-8de4-d82b039c06d1","1979a12b-2a72-438d-9de7-320d1b38e777","c492dd55-8876-4b1b-b620-615cc9b65ef8","a87f9d6a-0c84-4cad-839f-e912c6006c12","fa471a57-af7b-4ccf-b6ba-4c57a7230498","acfe6c36-66ab-4a3e-86b0-a178377427d2","1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","84de2eed-843c-401b-a3fd-e21be88f2365","4a7b0e92-ba43-46aa-96e8-c5839dbcb524","25a84f2d-dbac-457e-b734-bc2605305f2b","ab8301d6-b122-4d40-868a-d00d3c0f1916","c02141e6-0725-4f6f-9138-83d10c6bc104","e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf"],"platforms":"windows10","technologies":"mdm"},{"id":"a1d83497-da94-407f-bbc5-9f65ebc5f9fb","displayName":"Windows Mobility Center","description":"Administrative Templates\\Windows Components\\Windows Mobility Center","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a1fbe395-3b60-475f-8a34-3710d6b2e09f","displayName":"Browsing","description":"Administrative Templates Internet Explorer Internet Settings Advanced settings Browsing","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","displayName":"Custom","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a2230bb9-81a5-4e95-bc7f-0fbc9ecb5de4","displayName":"Instant Search","description":"Administrative Templates\\Windows Components\\Instant Search","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a24e6384-a862-4d0e-8f6c-eb99e5f6a9db","displayName":"Windows Resource Exhaustion Detection and Resolution","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows Resource Exhaustion Detection and Resolution","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a24f4ab6-289a-450a-b438-1c4bb1214942","displayName":"App-V","description":"Administrative Templates\\System\\App-V","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["ea812d2c-1cf9-4132-9b33-12bb7ac17dbd","9ad70461-c727-40da-8484-250369b6a119","48f508a5-5a2c-4d20-8d89-2d352a209907","3800661e-5841-4499-8d4e-914527435f59","1f5d8243-cb7e-4b52-a12f-5f0e070d2769","0ef80736-8b59-4c6a-8bdc-e2b246b30e92","8caf4546-4ed8-4e8a-b9e7-5ab48c13b709","0236af48-9ce0-44d5-b085-de2323d7348e"],"platforms":"windows10","technologies":"mdm"},{"id":"a25a7a02-4bac-411b-9d02-10cb3297cb17","displayName":"Microsoft Edge","description":"Microsoft Edge","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":["43057320-7058-46d5-86f9-a56c80bbf8b9","fb1e99d0-b921-4b19-9842-17e3e7987528","45a89c1f-0a34-4f78-b28f-d30b623fa423","b3c8c6d9-28bb-475a-9353-4a0e657b33c7","1043e7ed-8651-44b2-b918-7230c0b75a6c","ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","81c518f1-522e-4957-b850-e8a66d2ab215","526e363a-84db-4256-a13c-e01c8c646e26","d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","2e241b46-e5ae-41d7-a559-fe40819e86f4","d17b08e6-de3b-445b-ab14-1d47e62efdcf","05811ceb-2954-426c-8afa-2a53f02480cc","2af24920-f611-4f03-99a6-205773869ae6","6d529e48-5477-4ceb-8ff7-c6e959a0e24f","5bd0eaf1-1818-44e8-9168-fc75c5739cc8","92d69c43-75ac-49b1-a3ef-9350079eef86","66615d2a-fec9-47f1-8eaf-9813e30cc023","dfab5866-1712-4bbf-8edf-5b080b315b9b","3edb2860-b77b-4240-af16-fb34d45d6ba1","ae78ab75-2d0d-418c-be6f-9e64642de4e2","3ba8106d-4b2f-4775-939d-1cc8703a41dc","fe845e81-5993-4a65-b22a-decfc5928c65","16ea64a1-563e-43cc-b34a-728c8e7cd13c","08c5f391-e156-4a72-bbb9-3670f2f63a56","120b24dd-c04a-4291-8f24-9c48fcdc1434","5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","3fbd3b29-bafd-4adf-89e4-3be612dee275","8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","fddc444c-3591-4a50-865b-d8993b798e12","3abaf4c2-d5db-4b3b-a461-b1a208231b36","8aa3383a-efac-4ec4-841d-06e3e18646d8","eb6409fc-fb52-413d-ae4b-eff017b52b30","c6099521-a05f-480a-8562-7e71318e2cda","00d7396c-cadc-4d29-86ba-fe4df2ecb110","08677354-6f67-455e-a430-4d8d2fbabe84","76e34834-6d47-4e06-b14c-aa2888cdce27","ef8760ac-a77c-4055-a812-a95bfbf9c00a"],"platforms":"android,iOS,macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"a279f35f-cd71-4489-b0c3-545ea1aa229d","displayName":"Local Security Authority","description":"Local Security Authority","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a279f35f-cd71-4489-b0c3-545ea1aa229d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","displayName":"Disable Items in User Interface","description":"Microsoft Excel 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["3b7e16e7-171f-4169-8904-c8483b06700d","3fa63a9d-e22d-4fc8-8464-a13b56461115"],"platforms":"windows10","technologies":"mdm"},{"id":"a28dd311-46e8-4868-89ab-d3745c0bca21","displayName":"Security","description":"Administrative Templates Event Log Service Security","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a321fc04-d0cb-45ec-a6bf-51d60249922d","displayName":"Automatic Picture Download Settings","description":"Microsoft Outlook 2016\\Security\\Automatic Picture Download Settings","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a33fb618-0ad1-40a3-b94b-49c90c49ea03","displayName":"RemoteFX for Windows Server 2008 R2","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Remote Session Environment\\RemoteFX for Windows Server 2008 R2","helpText":null,"parentCategoryId":"ce572b49-4d47-47b6-b787-ac1252753581","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a34ade49-964d-407c-9f60-2e8cd9dfef05","displayName":"Smart Card","description":"Administrative Templates Smart Card","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","displayName":"Programmatic Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Programmatic Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf"],"platforms":"windows10","technologies":"mdm"},{"id":"a37dba52-d558-47fb-9d46-a5d3bdc5fdd7","displayName":"Windows Remote Management (WinRM)","description":"Administrative Templates\\Windows Components\\Windows Remote Management (WinRM)","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["c919e047-97fc-489f-ab0e-bcb070e36c55","023116df-a32c-43b0-a384-d6fe7ad9fabe"],"platforms":"windows10","technologies":"mdm"},{"id":"a3e48951-624d-4fee-b470-d17ce16e6b0c","displayName":"Secure Boot","description":"Secure Boot","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a3e48951-624d-4fee-b470-d17ce16e6b0c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","displayName":"Features","description":"Microsoft Defender Features","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"a3ec7cde-bca6-4e3e-9f7e-f66a43196924","displayName":"Windows Backup And Restore","description":"Windows Backup And Restore","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a3ec7cde-bca6-4e3e-9f7e-f66a43196924","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","displayName":"Graph settings","description":"Microsoft Office 2016\\Graph settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a42e2248-d2dc-4476-a92d-d152fd67e04b","displayName":"Audio Accessory","description":"Declarative Device Management preview Audio Accessory","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS","technologies":"appleRemoteManagement"},{"id":"a4877a42-7e62-4216-a477-0b35357ab313","displayName":"Remote Desktop Connection Client","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Connection Client","helpText":null,"parentCategoryId":"572bc940-42d4-4e00-ac55-012e9b90f6df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["728890f5-bddd-4b69-a1b6-efb221d902d4"],"platforms":"windows10","technologies":"mdm"},{"id":"a4bffc2b-76af-48d3-acdf-8566e51ef163","displayName":"Restricted Sites Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Restricted Sites Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a4f5cedd-a8f7-4def-b8b6-8fbf9ce9e0d8","displayName":"Windows System Responsiveness Performance Diagnostics","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Windows System Responsiveness Performance Diagnostics","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a4fb2510-977f-42ff-9033-6f1eb98f141b","displayName":"Device Lock","description":"Device Lock","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5060182-4d22-412b-bd0e-3a1e009b36c6","displayName":"Client Interface","description":"Administrative Templates Microsoft Defender Antivirus Client Interface","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a51a8665-045d-482d-b68b-2128959c8b31","displayName":"WWAN UI Settings","description":"Administrative Templates\\Network\\WWAN Service\\WWAN UI Settings","helpText":null,"parentCategoryId":"fc8f887c-cfd9-4bea-bfac-2214d06dba99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a53581a1-e9d7-4ba4-9dea-cea90d40cca1","displayName":"Work Folders","description":"Administrative Templates\\Windows Components\\Work Folders","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","displayName":"Fax","description":"Microsoft Office 2016\\Services\\Fax","helpText":null,"parentCategoryId":"478ed057-8ee7-4dd2-8276-06dad8f85397","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a561e59a-09b7-4106-a6fa-0b82036a5b49","displayName":"RD Gateway","description":"Administrative Templates Remote Desktop Services RD Gateway","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a57b27b6-48e0-42b2-812a-2be86c113a0c","displayName":"Application Compatibility Settings","description":"Administrative Templates Distributed COM Application Compatibility Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a57f0abc-605b-433e-b7da-45ee127188cd","displayName":"Event Logging","description":"Administrative Templates\\Windows Components\\Event Logging","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","displayName":"Password manager","description":"Google Google Chrome Password manager","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","displayName":"Reporting","description":"Administrative Templates Microsoft Defender Antivirus Reporting","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","displayName":"Co-authoring","description":"Microsoft Office 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5ce858b-74c2-4663-9b3e-068d31349a13","displayName":"Cryptography","description":"Microsoft Word 2016\\Word Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","displayName":"Lanman Workstation","description":"Lanman Workstation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a69e7a98-5af7-4834-bae1-2a1047663a71","displayName":"Desktop","description":"Administrative Templates\\Desktop\\Desktop","helpText":null,"parentCategoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","displayName":"Synchronization","description":"Microsoft Office 2016\\Business Data\\Synchronization","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","displayName":"Wireless Display","description":"Wireless Display","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6fe8038-136b-4d50-bf04-8e232409c0d2","displayName":"Web Content Filter","description":"Web > Web Content Filter","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a754c9bd-2116-4dd6-9014-07f914869145","displayName":"Proxies","description":"Proxies","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":["b8ed9eb3-17de-4091-b08b-7adb2fe13271","906df5cd-1d9e-49d0-ab32-cf5c5a041974"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","displayName":"Human Presence","description":"Human Presence","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a787672d-4a33-455b-a2db-e340eb35a5c8","displayName":"WSL container","description":"Windows Subsystem for Linux WSL container","helpText":null,"parentCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","rootCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a788a6e5-ab3f-41e5-96c8-ee59627dcb4d","displayName":"Workgroup Administrator...","description":"Microsoft Access 2016\\Tools | Security\\Workgroup Administrator...","helpText":null,"parentCategoryId":"607a1c39-a3db-496f-8db6-c99d67f5f76c","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a79b2d36-7dea-4a84-81ef-27f99296bccf","displayName":"Authentication","description":"Authentication","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":["f35cc803-3a06-4262-b38b-a5295321f756","c3fdc01d-0648-4dcb-855d-7afe78bf1d89","7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","5995d2ad-5ec7-49d2-ada2-d9c2b57746ba"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","displayName":"SmartScreen settings","description":"Microsoft Edge - Default Settings (users can override)\\SmartScreen settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7b1c291-6bec-499b-9018-6120950cd5a6","displayName":"App Control for Business","description":"App Control for Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","displayName":"User Interface Options","description":"Microsoft Visio 2016\\Visio Options\\General\\User Interface Options","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7e7529f-1030-41da-8b4d-024e1c08bbac","displayName":"Windows Standby Resume Performance Diagnostics","description":"Administrative Templates Windows Standby Resume Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a809df26-b5db-4af9-b247-a539ada4e869","displayName":"Add or Remove Programs","description":"Administrative Templates\\Control Panel\\Add or Remove Programs","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a877a2ff-f144-421f-814c-593e972a8a20","displayName":"Password manager and protection","description":"Microsoft Edge - Default Settings (users can override)\\Password manager and protection","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a87f9d6a-0c84-4cad-839f-e912c6006c12","displayName":"Send to OneNote","description":"Microsoft OneNote 2016\\OneNote Options\\Send to OneNote","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","displayName":"Microsoft Office 2016","description":"Microsoft Office 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["042ab9cf-9524-4dd4-b049-4d5f4ff7053f","2d6891a4-ee83-4e55-8e23-09513e1306e4","af14a55b-d79b-4299-946c-b7582412b748","bc633a5a-c712-49a6-9f56-775ca9321df4","5cd6dc4f-b231-449f-bc10-16041b73356a","eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","adf11731-7089-4e2e-8dde-4bd9ef86b067","449201b6-5002-42d1-85ed-d288fb6552da","cc29afc6-309c-4a0d-86f6-60081ae7cd4c","72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","eb947c30-3c43-4d34-a566-a842a1a142f3","6aeb1df3-d796-4c5b-921d-9f3970a754cc","866eedbc-ffd9-457d-b02b-7b163d55c4bd","44541a16-c3a2-4be1-ba42-4fc15bde4c46","da04d4b8-bd11-439e-9663-5fd2399d9cc1","760376f3-6b74-4992-89eb-aa41d6190e94","5b1be2c5-9939-4b2e-b29b-b22069455c90","94ce8206-be22-496c-aa72-f3560e2a5c8d","2f56761a-8e8b-4788-a589-a73ab91818e6","05a6f86f-dab7-4888-97a1-db3457f00974","055293ad-c585-40c0-b66c-76ff5cc0a332","9b2ad6d8-8837-4c50-89d5-7507b69c7dec","8b0e5a63-c309-430b-8521-7bd21e715b90","59c9b1c4-1757-4cf3-9b27-954dafe016d5","7a8b936d-b4b0-408f-bec5-3c97050730f8","42d8353a-a135-4c2d-8d06-c6cf9961c6c5","9865907f-b775-4d36-9578-a016c5105dfe","b94cbc54-e565-44f2-a27a-a63b2514d8bf","4e0d279d-5ddd-4c4e-8590-6ed92129444d","5bf4c2ba-be08-4cda-bf33-d10707580d78","23c09e06-5bee-4b20-a391-36549bf0f620","8084033c-156a-4d1b-ab0b-159541810459","0696109e-045f-486a-9a6b-ab7877887bed","1942922a-cba9-44c8-871f-3d915c62bd06","33fb4f49-5c7f-472c-a0f3-e05646a55902","4aec010d-487a-4752-8e66-aedb9e4fbb5a","92be4fc7-8095-441c-b52b-9861c21bc337","50b4bc60-802c-477a-9366-80e09154595f","e86f24d3-8531-4298-b064-692ea795b1d9","a40e47b0-5b27-4e4d-b2ef-42f20540e812","478ed057-8ee7-4dd2-8276-06dad8f85397","6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","2d5a483f-b408-426d-9234-2883eae20afb"],"platforms":"windows10","technologies":"mdm"},{"id":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","displayName":"Save","description":"Microsoft Excel 2016\\Excel Options\\Save","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","displayName":"Security","description":"Microsoft Outlook 2016\\Security","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["a321fc04-d0cb-45ec-a6bf-51d60249922d","1720d60f-40a6-471c-8e4c-efbacaf46997","c3db5686-3bb2-437c-8906-60da1a1fa844","d4e5541e-ab77-4e6c-8046-1fb80ee705ad"],"platforms":"windows10","technologies":"mdm"},{"id":"a9edc695-b4a9-4111-b07d-627f934f5a1a","displayName":"Trust Center","description":"Microsoft Access 2016\\Application Settings\\Security\\Trust Center","helpText":null,"parentCategoryId":"23fd467e-24f8-4200-8b19-c6c11afa8926","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["12ad5ec7-346d-4b8b-9eba-d826cdb61c31"],"platforms":"windows10","technologies":"mdm"},{"id":"aa67f0c0-4eb0-492f-a528-decd3e256a22","displayName":"Hardware Buttons","description":"Administrative Templates\\Windows Components\\Tablet PC\\Hardware Buttons","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"aad0d3ef-88f5-4b22-831b-27093eafbc64","displayName":"Users and Accounts","description":"Device Restriction User and Accounts","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","displayName":"Logging","description":"FS Logix Logging","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","displayName":"Consistent Mime Handling","description":"Administrative Templates Internet Explorer Security Features Consistent Mime Handling","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab6aa2f6-87bf-4a06-a206-e0902af3e4bc","displayName":"WWAN Media Cost","description":"Administrative Templates\\Network\\WWAN Service\\WWAN Media Cost","helpText":null,"parentCategoryId":"fc8f887c-cfd9-4bea-bfac-2214d06dba99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab754829-54a1-4082-abfa-56bae0b07ff3","displayName":"Presentation Settings","description":"Administrative Templates\\Windows Components\\Presentation Settings","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab8301d6-b122-4d40-868a-d00d3c0f1916","displayName":"Other","description":"Microsoft OneNote 2016\\OneNote Options\\Other","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"abf781d7-1179-4f24-8d01-5611db14eddc","displayName":"Touch Input","description":"Administrative Templates Touch Input","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac014aea-e417-46ad-a4a5-9a1fb1030882","displayName":"Locked- Down Internet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Internet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac0a894c-173a-48fc-b961-901f28463c77","displayName":"Direct Access Client Experience Settings","description":"Administrative Templates Direct Access Client Experience Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","displayName":"User Profiles","description":"Administrative Templates User Profiles","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","displayName":"Related Website Sets Settings","description":"Google Google Chrome Related Website Sets Settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","displayName":"Sleeping Tabs settings","description":"Microsoft Edge - Default Settings (users can override)\\Sleeping Tabs settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","displayName":"Restricted Permitted snap-ins","description":"Administrative Templates Microsoft Management Console Restricted Permitted snap-ins","helpText":null,"parentCategoryId":"07c023d3-0899-40af-a04f-805876d99a9b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["756d2b0b-5f06-45e7-b5c5-c066deb5ed2f"],"platforms":"windows10","technologies":"mdm"},{"id":"acbc106b-796a-4ba3-ab5f-c130530ad455","displayName":"Earned Value options for Project1","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for 'Project1'\\Earned Value options for Project1","helpText":null,"parentCategoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","displayName":"Operating System Drives","description":"Administrative Templates BitLocker Drive Encryption Operating System Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"accec716-3bf1-4a33-882d-3538d32fcbbc","displayName":"Browsing","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Settings\\Advanced settings\\Browsing","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acfe6c36-66ab-4a3e-86b0-a178377427d2","displayName":"Save","description":"Microsoft OneNote 2016\\OneNote Options\\Save","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad100c6c-9a9a-42cf-8f42-b31c406c1a56","displayName":"Security Intelligence Updates","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Security Intelligence Updates","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad1ecbf4-75da-4dc1-9354-7d00c0e2af72","displayName":"Allday","description":"Allday","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ad1ecbf4-75da-4dc1-9354-7d00c0e2af72","childCategoryIds":[],"platforms":"android,iOS","technologies":"exchangeOnline"},{"id":"ad47f904-ede2-4b12-849e-bf751d88abf5","displayName":"Display","description":"Administrative Templates Display","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad84cea3-5664-4e42-a9d6-1446828bea45","displayName":"Microsoft Defender Exploit Guard","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["210b9c4d-e72a-45a4-97d3-339a6b30c49c","72f61c7d-e5d2-4170-baf3-c953c1082e19"],"platforms":"windows10","technologies":"mdm"},{"id":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","displayName":"Save","description":"Microsoft Visio 2016\\Visio Options\\Save","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["2eed22da-106f-4c93-9a45-5ce803b50233","73415dea-0103-4427-83c5-6c97bf81af1d"],"platforms":"windows10","technologies":"mdm"},{"id":"adc4eb7f-0f34-4f43-b361-dc42363eccab","displayName":"Mp Engine","description":"Administrative Templates Microsoft Defender Antivirus Mp Engine","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"adf11731-7089-4e2e-8dde-4bd9ef86b067","displayName":"What's New","description":"Microsoft Office 2016\\What's New","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","displayName":"Sleeping Tabs settings","description":"Microsoft Edge\\Sleeping Tabs settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","displayName":"Signature Status dialog box","description":"Microsoft Outlook 2016\\Security\\Cryptography\\Signature Status dialog box","helpText":null,"parentCategoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"af14a55b-d79b-4299-946c-b7582412b748","displayName":"Tools | Options | General | Service Options...","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","5838ed03-2902-4931-92cf-e349ab09c9b8","6c142a01-47fa-422d-8135-29e81bc970cc"],"platforms":"windows10","technologies":"mdm"},{"id":"af351b0c-3d9e-4b18-957b-8179e4eaba15","displayName":"Safe Browsing settings","description":"Google Google Chrome - Default Settings users can override Safe Browsing settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"af9b2941-29f9-4ee5-ae09-215f4e242943","displayName":"AutoCorrect Options","description":"Microsoft Visio 2016\\Visio Options\\Proofing\\AutoCorrect Options","helpText":null,"parentCategoryId":"8495c82c-f273-4bcc-8886-6751103a9c7b","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","displayName":"Microsoft One Note 2016","description":"Microsoft One Note 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":["b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","a185940c-7899-4ab6-867d-7559352cf8d2"],"platforms":"windows10","technologies":"mdm"},{"id":"b03bfdc7-f42a-400e-935b-2b07fc71a7f1","displayName":"Mime Sniffing Safety Feature","description":"Administrative Templates Internet Explorer Security Features Mime Sniffing Safety Feature","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","displayName":"Custom","description":"Microsoft One Note 2016 Disable Items in User Interface Custom","helpText":null,"parentCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b1393de2-587f-4516-a35d-58098f2be3c9","displayName":"WLAN Media Cost","description":"Administrative Templates\\Network\\WLAN Service\\WLAN Media Cost","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b13e38a0-6ad6-4a1f-b53f-d8ca94847586","displayName":"SNMP","description":"Administrative Templates\\Network\\SNMP","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b1585568-da15-41fc-a1d0-5d0b194de84c","displayName":"Locked-Down Internet Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Internet Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","displayName":"Exchange ActiveSync","description":"Microsoft Outlook 2016\\Account Settings\\Exchange ActiveSync","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b206e4ef-a288-4fb7-a7ee-4a30b4df3b98","displayName":"Server Settings","description":"Microsoft Word 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b221d3c2-e05a-4210-bf9c-2d7c7c0fd35a","displayName":"SSL Configuration Settings","description":"Administrative Templates\\Network\\SSL Configuration Settings","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b237a91d-a442-4a7e-8169-1bd6c798f490","displayName":"Profiles","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Profiles","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b260992a-8216-4bfa-b60a-4eeea1f356c9","displayName":"News and interests","description":"Feeds","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b260992a-8216-4bfa-b60a-4eeea1f356c9","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","displayName":"PKCS imported certificate","description":"PKCS imported certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b32726b3-b0e9-465b-86f8-b61ad8af52f0","displayName":"Default Applications","description":"Managed Settings Default Applications","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"b3282777-8e27-4029-b153-6f6e5b86b53c","displayName":"HomeGroup","description":"Administrative Templates\\Windows Components\\HomeGroup","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b382d980-7459-4850-a45e-75dd99488972","displayName":"Software Update Settings","description":"Declarative Device Management preview Software Update Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"b3b2fc04-4b88-4a1c-8370-04573019eebe","displayName":"LAPS","description":"Administrative Templates\\LAPS","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b3b30966-47ac-4b54-a75a-04418d5c6153","displayName":"Dev Tunnel Settings","description":"Visual Studio Dev Tunnel Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","displayName":"PDF Reader","description":"Microsoft Edge PDF Reader","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"b3e317cd-c580-478e-885c-666ce3079e78","displayName":"Outlook Social Connector","description":"Microsoft Outlook 2016\\Outlook Social Connector","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b40b8f80-c0e6-4494-8085-f90cadc167a9","displayName":"Temporary folders","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Temporary folders","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b40cfb22-8f17-4317-bcbb-c1c871497446","displayName":"Location and Sensors","description":"Administrative Templates Location and Sensors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b4272e06-316f-4f9a-a198-93f4168f0c78","displayName":"Corrupted File Recovery","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Corrupted File Recovery","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b46f4e70-d3d1-4177-8e22-62f806d4568c","displayName":"Other","description":"Google Google Chrome Other","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","displayName":"Power BI","description":"Microsoft Excel 2016\\Power BI","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b485695b-0fae-41ae-861c-3030769b28df","displayName":"Safe Browsing settings","description":"Google Google Chrome Safe Browsing settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","displayName":"Security Features","description":"Administrative Templates Internet Explorer Security Features","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","e6911a08-946f-4b70-99cb-2a8b92c461e0","622c83ff-f780-47e6-8b9c-bf82552e3f04","853d5a82-91e4-4c53-8338-fd1a3d9b542c","3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","b03bfdc7-f42a-400e-935b-2b07fc71a7f1","4560c525-12a1-4536-9cca-338330e58389","17bc9899-d157-4eac-a949-810b4a841e28","18296501-4825-47ea-835d-66a01aba9384"],"platforms":"windows10","technologies":"mdm"},{"id":"b49cb414-bdfb-49d4-af5d-176ded4f9591","displayName":"User Profiles","description":"Administrative Templates\\System\\User Profiles","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b5006d56-dc0b-4a07-95ee-d6d6e3000f9f","displayName":"Time Providers","description":"Administrative Templates\\System\\Windows Time Service\\Time Providers","helpText":null,"parentCategoryId":"bd04d2ce-3275-496c-8cc1-e17ab19888a3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b5169b74-41be-460a-9402-b13b6c22582b","displayName":"Microsoft Office","description":"Microsoft Office > Microsoft Office","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b5234c18-e555-409e-9550-59b89d1672f1","displayName":"Window Frame Coloring","description":"Administrative Templates\\Windows Components\\Desktop Window Manager\\Window Frame Coloring","helpText":null,"parentCategoryId":"be6b97de-f120-4d89-b7c9-b548d061bac8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b524d6e2-75bc-4409-ae3d-07605707d7ee","displayName":"Pen UX Behaviors","description":"Administrative Templates Pen UX Behaviors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","displayName":"Windows Power Shell","description":"Administrative Templates Windows Power Shell","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b62de64d-03ed-4e09-be5c-5cc93e34ea47","displayName":"iSCSI Security","description":"Administrative Templates\\System\\iSCSI\\iSCSI Security","helpText":null,"parentCategoryId":"363982dd-fc96-49ce-a499-f6401f2c212b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6650a16-32bc-4344-ac98-8f20486c6b0b","displayName":"Cellular Private Network","description":"Cellular Private Network","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"b6733d23-eadc-486a-abfc-62b78698a16c","displayName":"General","description":"Device Restriction General","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","displayName":"Managed Menu Extras","description":"User Experience > Managed Menu Extras","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b6bb653a-73f0-42f4-b097-1ce556310904","displayName":"Scripted Diagnostics","description":"Administrative Templates Scripted Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6cafb2c-81be-40cf-90d8-788f713f7099","displayName":"Replace as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Replace as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","displayName":"App Package Deployment","description":"Administrative Templates App Package Deployment","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b74f852c-d19b-4a22-a44a-431f7a72a4d6","displayName":"Scripted Window Security Restrictions","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Scripted Window Security Restrictions","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","displayName":"Endpoint Detection and Response (EDR) preferences","description":"Microsoft Defender > Endpoint Detection and Response (EDR) preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"b792508d-da03-4174-bcf1-666d128ee8ad","displayName":"AutoFormat as you type","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Proofing\\AutoFormat as you type","helpText":null,"parentCategoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b7bde490-eac6-4f57-8808-e0786b8191a1","displayName":"Remote FX for Windows Server 2008 R2","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Remote Session Environment Remote FX for Windows Server 2008 R2","helpText":null,"parentCategoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","displayName":"Web Rtc settings","description":"Google Google Chrome Web Rtc settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b8158968-c839-4d37-9eb8-887bd6fd7402","displayName":"Disable Items in User Interface","description":"Microsoft Access 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["dba1a547-e288-45ac-8553-27a3b564699e","55eebd7c-beb9-48b6-907f-df4997e18bdb"],"platforms":"windows10","technologies":"mdm"},{"id":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","displayName":"Win RM Service","description":"Administrative Templates Windows Remote Management Win RM Win RM Service","helpText":null,"parentCategoryId":"364787de-93e4-4fd6-9608-dce1ad8f88c2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b85d9c04-4923-4fdf-a425-424686d47859","displayName":"Siri Settings","description":"Declarative Device Management preview Siri Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"b8adcde1-500a-430f-8636-f97eaae2a2c6","displayName":"Japanese Find","description":"Microsoft Word 2016\\Japanese Find","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","displayName":"Network Proxy Configuration","description":"Proxies > Network Proxy Configuration","helpText":null,"parentCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d","displayName":"General","description":"Microsoft Excel 2016\\Excel Options\\Advanced\\Web Options...\\General","helpText":null,"parentCategoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9201072-3681-4e95-ad90-869e6166b129","displayName":"Client Coexistence","description":"Administrative Templates App-V Client Coexistence","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b92241c7-e419-4dc7-b373-08e595c1db1d","displayName":"Operating system","description":"Operating system","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b92241c7-e419-4dc7-b373-08e595c1db1d","childCategoryIds":[],"platforms":"windows10","technologies":"windowsOsRecovery"},{"id":"b94cbc54-e565-44f2-a27a-a63b2514d8bf","displayName":"DLP","description":"Microsoft Office 2016\\DLP","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b96b63eb-0292-4a73-85d7-c68d330c109e","displayName":"Extensions","description":"Microsoft Edge - Default Settings (users can override)\\ Extensions","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9aafd85-b42a-4742-bbba-770b93678a52","displayName":"Locked-Down Trusted Sites Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Locked-Down Trusted Sites Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9ab4d39-9e28-4897-aa34-0201a35ea989","displayName":"Right-to-left","description":"Microsoft Outlook 2016\\Outlook Options\\Right-to-left","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ba1d333c-e19b-4470-bbab-d040a633c3a3","displayName":"IME","description":"Administrative Templates\\Windows Components\\IME","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ba7097b2-cd24-4394-9b3e-2c281ed30ae5","displayName":"Windows Media Digital Rights Management","description":"Administrative Templates\\Windows Components\\Windows Media Digital Rights Management","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ba7686de-e6ee-4af9-b1a5-265b03e08367","displayName":"Microsoft PowerPoint 2016","description":"Microsoft PowerPoint 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["ceacf7fa-fa6e-434d-a381-e20e5245d180","da92dfd6-a29e-42a0-92ed-276bb6904455","28ab8eed-623a-4e9b-813e-13256472dbaf","e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","f5babdb3-c718-4675-b977-6c7bc7e6f886","da1503cb-e474-4545-8e77-cdd577f34a08"],"platforms":"windows10","technologies":"mdm"},{"id":"bb54b081-5004-4f05-a46c-f5b948f57b82","displayName":"NTFS","description":"Administrative Templates Filesystem NTFS","helpText":null,"parentCategoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","displayName":"System Configuration","description":"System Configuration","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":["768d9aa4-7407-4ed9-b97f-2385b8cadb47","8cefd936-362e-4a24-bc76-e078b6fd13fa","cb33668b-933f-4424-8d2d-8bdf0e61bddd","0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","5401711f-292a-487a-be18-f99593a0477c","dec8381a-0a61-406b-842b-fc6ae9930795","853f4181-42e8-411c-91cf-c06968c0a543","8c75a12d-664d-43ba-a3aa-5259425f9b37"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bbe51018-a17d-46c4-9517-ff45c54d8d18","displayName":"DNS Settings","description":"Networking > DNS Settings","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bc4f0cce-a5cc-44c9-9e50-b504e09e7eb1","displayName":"KDC","description":"Administrative Templates\\System\\KDC","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bc58391f-664c-42dd-9d18-269e65f324a7","displayName":"Miscellaneous","description":"Microsoft Excel 2016\\Miscellaneous","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["183628a3-d0a5-47de-b444-e132d634ca38"],"platforms":"windows10","technologies":"mdm"},{"id":"bc633a5a-c712-49a6-9f56-775ca9321df4","displayName":"Downloading Framework Components","description":"Microsoft Office 2016\\Downloading Framework Components","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bc65521d-e48a-4e95-899f-49df827808ca","displayName":"File Locations","description":"Microsoft Word 2016\\Word Options\\Advanced\\File Locations","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bce24fbf-4caf-449f-a210-5dd31a368b22","displayName":"Removed policies","description":"Google Google Chrome - Default Settings users can override Removed policies","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd04d2ce-3275-496c-8cc1-e17ab19888a3","displayName":"Windows Time Service","description":"Administrative Templates\\System\\Windows Time Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b5006d56-dc0b-4a07-95ee-d6d6e3000f9f"],"platforms":"windows10","technologies":"mdm"},{"id":"bd1bf2cb-c806-479b-a68c-af9dffd438c9","displayName":"Security","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Security","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd1dad69-5cbe-415e-8565-e87b15cd4431","displayName":"General","description":"Microsoft Access 2016\\Application Settings\\General","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","displayName":"FileVault Recovery Key Escrow","description":"FileVault > FileVault Recovery Key Escrow","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","displayName":"Compatibility View","description":"Administrative Templates Internet Explorer Compatibility View","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","displayName":"General","description":"Microsoft Word 2016\\Word Options\\General","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd7d2b68-118d-40ee-9dfd-39b2a22a2082","displayName":"Windows Connect Now","description":"Administrative Templates\\Network\\Windows Connect Now","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd8dacbf-ab7b-4a93-8294-7db61b9d49b4","displayName":"DNS Client","description":"Administrative Templates\\Network\\DNS Client","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","displayName":"Cryptography","description":"Cryptography","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"be6b97de-f120-4d89-b7c9-b548d061bac8","displayName":"Desktop Window Manager","description":"Administrative Templates\\Windows Components\\Desktop Window Manager","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b5234c18-e555-409e-9550-59b89d1672f1"],"platforms":"windows10","technologies":"mdm"},{"id":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","displayName":"Windows Time Service","description":"Administrative Templates Windows Time Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["13f025df-7d3f-4ecd-bd38-d7af7853b66e"],"platforms":"windows10","technologies":"mdm"},{"id":"be9bdbec-b52e-4174-9c5b-cf765dee855b","displayName":"Store","description":"Administrative Templates Store","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","displayName":"Editing Options","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Editing Options","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bedf20d1-1f5a-4840-8458-6d0fa974b664","displayName":"Net Logon","description":"Administrative Templates\\System\\Net Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["7f4d325e-bff8-4d91-8313-614243e55e6d"],"platforms":"windows10","technologies":"mdm"},{"id":"bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","displayName":"System Security","description":"Device Restriction System Security","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"c00d6468-cac3-429c-ada5-ba3adf4982a8","displayName":"Accessibility","description":"User Experience > Accessibility","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","displayName":"ActiveX Installer Service","description":"Administrative Templates ActiveX Installer Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c0204a51-a73c-46a6-8626-deeadcabe6ac","displayName":"Licensing","description":"Licensing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c0204a51-a73c-46a6-8626-deeadcabe6ac","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c02141e6-0725-4f6f-9138-83d10c6bc104","displayName":"Backup","description":"Microsoft OneNote 2016\\OneNote Options\\Backup","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c08e929f-742a-4cd8-a7e6-9a3d170fe020","displayName":"Disk Quotas","description":"Administrative Templates\\System\\Disk Quotas","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","displayName":"Windows Apps","description":"Administrative Templates Microsoft User Experience Virtualization Windows Apps","helpText":null,"parentCategoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c14c2e8b-0081-46e0-89ac-48ade3b83408","displayName":"Remote Desktop","description":"Remote Desktop","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c14c2e8b-0081-46e0-89ac-48ade3b83408","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c20ba4a5-483d-417c-bd96-de3cd83303e1","displayName":"Maintenance Scheduler","description":"Administrative Templates\\Windows Components\\Maintenance Scheduler","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c26b2f10-f2c0-45f2-955c-5379dd12f206","displayName":"Compatibility View","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Compatibility View","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3857f91-3df8-472f-9b5a-b10778c715c0","displayName":"Google Chrome - Default Settings users can override","description":"Google Google Chrome - Default Settings users can override","helpText":null,"parentCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["20ceae56-e189-46ec-a440-791ce7454017","54f2e032-bdcc-4877-b7a0-973d0a7c1653","d97d6d8f-0a1a-4160-89aa-d624a36954a2","af351b0c-3d9e-4b18-957b-8179e4eaba15","12142994-4b30-486c-bab1-9206528b2b96","de643352-007f-4a47-8c83-d75a79516b39","962a2377-ad9a-4654-a526-a77c14152fd7","bce24fbf-4caf-449f-a210-5dd31a368b22","6d6b289c-c1e9-4004-b5ab-3123920cf10d"],"platforms":"windows10","technologies":"mdm"},{"id":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","displayName":"Miscellaneous","description":"Microsoft Access 2016\\Miscellaneous","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3b5e77d-c00d-4578-84c9-289362ad0b00","displayName":"Save","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Save","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3db5686-3bb2-437c-8906-60da1a1fa844","displayName":"Trust Center","description":"Microsoft Outlook 2016\\Security\\Trust Center","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3dfb294-a7c0-48af-b705-59c4e257d48c","displayName":"Declarative Device Management (DDM)","description":"Declarative Device Management (DDM)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":["15be55d8-7477-4274-9b09-b775bce68416","11d26400-1d13-4dd6-ab4b-cb323494b127","42a6198f-bdec-402e-b619-315400b65488","83febe72-a64f-4051-9071-1efae1ea9a15","a42e2248-d2dc-4476-a92d-d152fd67e04b","b85d9c04-4923-4fdf-a425-424686d47859","b382d980-7459-4850-a45e-75dd99488972","6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","8c86f511-1729-4fe9-b0b2-111d9044e1ba","d9654cb3-57c8-487c-90a5-454e15336731","7d9e5b9b-84e7-473c-b6ca-a1629448df55","e0ab6868-4b53-4310-b665-f7c979941db7","dba26132-cba6-4178-93c3-f02476532f08","ddb64e9d-34b9-44f4-9980-a6623f14e445","2cdd4a96-23c1-4419-b88c-41bbaa119e68"],"platforms":"iOS,macOS,visionOS,tvOS","technologies":"mdm,appleRemoteManagement"},{"id":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","displayName":"Identification (Deprecated)","description":"Authentication > Identification","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c400a917-cdff-4e15-a70f-59b82df4c038","displayName":"Attachment Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Attachment Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4665793-15ea-44c9-bd0a-d542b3915fe0","displayName":"Remediation","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Remediation","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c483faac-cebf-448a-8f90-e8a125c0c4af","displayName":"Microsoft Management Console","description":"Administrative Templates\\Windows Components\\Microsoft Management Console","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["9e882396-4a1c-4d06-a62d-8d910ded8e7d"],"platforms":"windows10","technologies":"mdm"},{"id":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","displayName":"Remote Desktop Services","description":"Administrative Templates Remote Desktop Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["0456dcd5-c003-4a8b-80e6-61bacf854330","4c604a0e-9339-4c01-9536-b689bd0abe5f","62bbe0df-b9b2-453f-a2f1-ee66291d4956","3a901a80-e2b6-470c-9658-d66ba5458370","a561e59a-09b7-4106-a6fa-0b82036a5b49"],"platforms":"windows10","technologies":"mdm"},{"id":"c492dd55-8876-4b1b-b620-615cc9b65ef8","displayName":"Versions and Recyle Bin","description":"Microsoft OneNote 2016\\OneNote Options\\Versions and Recyle Bin","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","displayName":"Tenant Lockdown","description":"Tenant Lockdown","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","displayName":"Exchange","description":"Microsoft Outlook 2016\\Account Settings\\Exchange","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["82ecfab7-b76a-4cec-8e76-859db4599ac2","e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5"],"platforms":"windows10","technologies":"mdm"},{"id":"c4e48b1b-6d88-434f-a717-d5bab28eb245","displayName":"Wi-Fi Connection","description":"Wi-Fi Connection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c4e48b1b-6d88-434f-a717-d5bab28eb245","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c6099521-a05f-480a-8562-7e71318e2cda","displayName":"Printing","description":"Microsoft Edge\\Printing","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"c64ee570-d51c-4286-9a47-367b833754e4","displayName":"Store","description":"Administrative Templates\\Windows Components\\Store","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","displayName":"Disable Items in User Interface","description":"Microsoft Visio 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","4e4deef0-4528-47d5-8869-4143c506f18b"],"platforms":"windows10","technologies":"mdm"},{"id":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","displayName":"Removable Storage Access","description":"Administrative Templates Removable Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"c6b72060-8ecb-41d8-8625-2984dd756d4a","displayName":"Free/Busy Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Free/Busy Options","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c6c1120b-988c-4581-a21c-b9786a821242","displayName":"Miscellaneous","description":"Microsoft Publisher 2016\\Miscellaneous","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c72d9f00-d625-43ec-add4-514891035839","displayName":"Web Service","description":"Microsoft Office 2016\\Business Data\\Web Service","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","displayName":"Publisher Options","description":"Microsoft Publisher 2016\\Publisher Options","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["51e0cebb-cac4-4905-9b31-539295e4b85b","1a0386fd-354b-441e-a0d6-1523c209dae7","6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","69f3ad9d-871d-42b3-8e10-07dc076a4d32","038b49c9-4f13-4ace-be8d-bd076bffa23e"],"platforms":"windows10","technologies":"mdm"},{"id":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","displayName":"System Preferences","description":"Preferences > System Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c7c32942-a139-4d7e-a19e-3495d5e372e7","displayName":"Networking","description":"Administrative Templates\\Windows Components\\Windows Media Player\\Networking","helpText":null,"parentCategoryId":"22ebd92b-80b6-493d-99d8-3c72f1a0827e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c805d788-1950-4ed1-adfb-771f12564a0c","displayName":"Exclusions","description":"Administrative Templates Microsoft Defender Antivirus Exclusions","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c859dc1a-fdeb-4591-af97-79d078ee715b","displayName":"Event Forwarding","description":"Administrative Templates Event Forwarding","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c87ae066-cc1a-44c9-8645-1db2359f7484","displayName":"Layer-2 priority value","description":"Administrative Templates Qo S Packet Scheduler Layer-2 priority value","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","displayName":"File Block Settings","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c919e047-97fc-489f-ab0e-bcb070e36c55","displayName":"WinRM Client","description":"Administrative Templates\\Windows Components\\Windows Remote Management (WinRM)\\WinRM Client","helpText":null,"parentCategoryId":"a37dba52-d558-47fb-9d46-a5d3bdc5fdd7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c945edd8-c865-4932-806d-83752e3f46ad","displayName":"Microsoft Edge Web View2","description":"Microsoft Edge Web View2","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","childCategoryIds":["13cc3b63-a150-4cf2-8d76-309975603c8e"],"platforms":"windows10","technologies":"mdm"},{"id":"c95a5920-ad56-4668-a6ad-19c3eb428557","displayName":"Lanman Workstation","description":"Administrative Templates\\Network\\Lanman Workstation","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","displayName":"Auto Play Policies","description":"Administrative Templates Auto Play Policies","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c9a65baa-de10-4818-97a2-b61babb28060","displayName":"Microsoft Defender Antivirus","description":"Administrative Templates Microsoft Defender Antivirus","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","428f107c-2167-4bc2-9293-8f1d6728a0c5","adc4eb7f-0f34-4f43-b361-dc42363eccab","cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","2c43699e-90b5-4da6-9689-fe5ad3b25ac9","94b5c25e-3af3-4c08-b738-a0527f91dc22","8a03aebc-9249-4917-a1c3-2957717d9123","c805d788-1950-4ed1-adfb-771f12564a0c","a5a56a36-6d60-4f74-a3c6-d82ed979b24a","a5060182-4d22-412b-bd0e-3a1e009b36c6","ad84cea3-5664-4e42-a9d6-1446828bea45","a004deb8-6f52-4411-8d94-41563a8203fc","09c02465-dc11-457e-9eac-19fc542e4cda"],"platforms":"windows10","technologies":"mdm"},{"id":"c9ab1080-67a7-4d6c-8213-056d4eb08ea0","displayName":"Credential Providers","description":"Credential Providers","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c9ab1080-67a7-4d6c-8213-056d4eb08ea0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c9ce70f5-a64b-442f-ac96-992eedf6a5df","displayName":"Device and Driver Compatibility","description":"Administrative Templates\\Windows Components\\Device and Driver Compatibility","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ca1aedf4-b951-45f5-a77c-dec776a82e21","displayName":"General i SCSI","description":"Administrative Templatesi SCSI General i SCSI","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","displayName":"Full Disk Encryption","description":"Full Disk Encryption","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":["5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","3f56adc1-2207-4033-a6e2-07f64c08e3ff","bd5533e1-f1ee-4994-8a79-cffe02b12d5c"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cae68a5f-9d1e-44e8-a34b-6a390b88c451","displayName":"Credentials Delegation","description":"Administrative Templates\\System\\Credentials Delegation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","displayName":"Notifications","description":"Notifications","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","displayName":"System Extensions","description":"System Configuration > System Extensions","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"cb6472c8-3e22-4029-af98-8a97f03a5a44","displayName":"PST Settings","description":"Microsoft Outlook 2016\\Miscellaneous\\PST Settings","helpText":null,"parentCategoryId":"f5a1a387-6665-4527-b532-88a64a76e732","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb8e8500-0336-4277-b3d9-9177cc967dcf","displayName":"Text Input","description":"Text Input","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb98f9d4-d921-4a8b-a763-cf69ce2ada62","displayName":"Notifications","description":"Administrative Templates\\Start Menu and Taskbar\\Notifications","helpText":null,"parentCategoryId":"5161db41-7947-49ea-b9b3-dd92539e6783","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cbb98485-6a36-47b8-b450-7821e08507ac","displayName":"Web Options - General","description":"Microsoft Access 2016\\Application Settings\\Web Options...\\General","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","displayName":"Network Inspection System","description":"Administrative Templates Microsoft Defender Antivirus Network Inspection System","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cc13d92c-673f-4af7-9748-50342fc8795a","displayName":"Filesystem","description":"Administrative Templates Filesystem","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["bb54b081-5004-4f05-a46c-f5b948f57b82"],"platforms":"windows10","technologies":"mdm"},{"id":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","displayName":"Collaboration Settings","description":"Microsoft Office 2016\\Collaboration Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","1b97e23d-996f-4b8e-9abf-53cfa0fc8917","2806d29a-7c7a-4ff0-baa2-4a0044425ea6"],"platforms":"windows10","technologies":"mdm"},{"id":"cc388035-b49c-493e-a598-14b0d0de4359","displayName":"Dock","description":"User Experience > Dock","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cc50f179-0c39-4486-a555-de5a6e6ed365","displayName":"Trust Center","description":"Microsoft Project 2016\\Project Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cc8a93d5-503f-4d46-ac42-65e169642237","displayName":"Cursors","description":"Administrative Templates\\Windows Components\\Tablet PC\\Cursors","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cc9231e6-ed1b-4680-aff4-bc72f16733c0","displayName":"Temporary folders","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Temporary folders","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","displayName":"Offline Files","description":"Administrative Templates Offline Files","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","displayName":"Mobile Accounts","description":"Accounts > Mobile Accounts","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cd16477e-7cff-4c24-ba7a-cc4342779f4b","displayName":"Trusted Sites Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Trusted Sites Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","displayName":"Security","description":"Microsoft Excel 2016\\Excel Options\\Security","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["7490c4fd-c326-42f7-9908-006504616d4c","27ccaa0b-8755-4116-a0e3-b5d21d68ab65"],"platforms":"windows10","technologies":"mdm"},{"id":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","displayName":"WWAN Service","description":"Administrative Templates WWAN Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","edf3754c-b22d-4946-a744-4773240a5883"],"platforms":"windows10","technologies":"mdm"},{"id":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","displayName":"Desktop App Installer","description":"Administrative Templates Desktop App Installer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ce0b1189-57ea-4444-a93e-e4be17160f18","displayName":"Windows Installer","description":"Administrative Templates\\Windows Components\\Windows Installer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","displayName":"Uncategorized","description":"Microsoft Edge\\ Uncategorized","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"android,iOS,macOS,windows10","technologies":"mobileApplicationManagement"},{"id":"ce572b49-4d47-47b6-b787-ac1252753581","displayName":"Remote Session Environment","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Remote Session Environment","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["a33fb618-0ad1-40a3-b94b-49c90c49ea03"],"platforms":"windows10","technologies":"mdm"},{"id":"ceacf7fa-fa6e-434d-a381-e20e5245d180","displayName":"Co-authoring","description":"Microsoft PowerPoint 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cebd5934-9dfe-4278-966d-b9d880cb30e7","displayName":"Windows Shutdown Performance Diagnostics","description":"Administrative Templates Windows Shutdown Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","displayName":"Windows Components","description":"Administrative Templates\\Windows Components","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["1fa3b0c3-e453-4ef3-80aa-a7474d8eb354","49d75a11-64c6-43d1-bc25-0ab156ff4216","78906e32-f4fb-453b-939b-05717ffaae59","9e857bed-81f8-4dfc-b049-c93eb68b4064","a37dba52-d558-47fb-9d46-a5d3bdc5fdd7","be6b97de-f120-4d89-b7c9-b548d061bac8","c483faac-cebf-448a-8f90-e8a125c0c4af","4479c9b6-8e08-424f-a20a-2058126dc048","5d19c257-8b7e-4071-9303-19317c94d7f7","ab754829-54a1-4082-abfa-56bae0b07ff3","b3282777-8e27-4029-b153-6f6e5b86b53c","fd16aa29-dae5-49b5-910e-88f3078ce2da","1638d9ec-63d5-4d6b-b1b6-4b0402268e36","176ed477-020a-41af-8859-0605c2caad98","35525ba9-da99-460e-afd3-ba86506b0ba3","60a3188c-7ee3-40db-8f9f-33648dc74555","70063d93-03f0-462e-9943-b0241b88d54d","d11e32cf-ac55-401a-a81a-232adc304afc","572bc940-42d4-4e00-ac55-012e9b90f6df","5a92aaed-3c64-4074-bacf-91dc1896d6f1","67b48a23-9bc3-48f5-bf6e-c9b3cd7000e4","a1d83497-da94-407f-bbc5-9f65ebc5f9fb","c20ba4a5-483d-417c-bd96-de3cd83303e1","ce0b1189-57ea-4444-a93e-e4be17160f18","f60cd3c8-a91b-4542-b09f-129dfc7e589c","1219a9c2-dccb-445f-9f90-8e86e2de22d6","1ed81d90-7326-4d0b-8934-b0a8bdddc5ce","69ec00d9-5698-4b8b-ad54-8d9a537a0fa9","71f9795f-defc-4b03-a2b4-31e129b6f861","7444c3f0-214b-45ea-9b8e-f74b81543644","7574a907-5608-491f-8011-c57d487457f4","a2230bb9-81a5-4e95-bc7f-0fbc9ecb5de4","a53581a1-e9d7-4ba4-9dea-cea90d40cca1","c64ee570-d51c-4286-9a47-367b833754e4","c9ce70f5-a64b-442f-ac96-992eedf6a5df","e9aff162-feb0-400a-aa68-8dd8deb93275","0101d1d0-1e54-47b0-a749-62c6bd7ab3da","0cc63077-26e9-4fbd-a343-fd88102efd7e","22ebd92b-80b6-493d-99d8-3c72f1a0827e","5915e06c-9b74-4c5e-86de-93e67ae183de","865a5fd9-f9be-496d-acb4-cd7cdb03e19f","8ccb6340-4f25-4bda-a527-127d269b3cbf","ba1d333c-e19b-4470-bbab-d040a633c3a3","d4bdfec1-2e40-49d2-b8f2-e5b15f072b10","7f431009-e8fe-460e-b247-06c838c8a914","2e57e23c-4847-4864-8e8e-5f6add1f7a84","3f8299b3-6803-4576-be08-7c311d04b8b9","50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","d9b7efad-fe18-4c98-925b-c4a5db0f2815","2dc7de59-a2b5-4f4a-96a4-597927af0617","4fc4d2f3-35ee-43ec-a033-ef78da571e70","569c6b8d-9491-471b-9960-17e3ac60734a","a57f0abc-605b-433e-b7da-45ee127188cd","ba7097b2-cd24-4394-9b3e-2c281ed30ae5","3181c361-f4f0-44ff-82cc-24aac8075843","fcddcc0b-7cf8-4ebc-a818-d10689603263","ffb6de77-8f2d-4b45-9cd4-00bb75cd496c"],"platforms":"windows10","technologies":"mdm"},{"id":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","displayName":"Networking","description":"Networking","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":["e95335ec-2704-47ab-8b40-f602b31eeb9d","06a85f5b-2614-4467-91cf-4a64d0c9326f","70b5da13-9c31-4857-890d-b7eb223729c3","5c722b3f-9d77-428a-b859-3fb556162cd6","bbe51018-a17d-46c4-9517-ff45c54d8d18","224dc683-c0e0-4783-8ba8-8f02c76d161d"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cf968979-f316-47cb-a207-bf9ef28cd1aa","displayName":"DSCP value of non-conforming packets","description":"Administrative Templates Qo S Packet Scheduler DSCP value of non-conforming packets","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","displayName":"Google","description":"Google","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["36c83fb3-c18c-472b-b39e-617c2f8a7fbd","c3857f91-3df8-472f-9b5a-b10778c715c0"],"platforms":"windows10","technologies":"mdm"},{"id":"d0a1763a-5cdf-4672-8596-435ec1d94b54","displayName":"Search Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Search Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","displayName":"Application Settings","description":"Microsoft Access 2016\\Application Settings","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["23fd467e-24f8-4200-8b19-c6c11afa8926","bd1dad69-5cbe-415e-8565-e87b15cd4431","33b9194b-4027-4c23-b662-52f25db7f839","cbb98485-6a36-47b8-b450-7821e08507ac"],"platforms":"windows10","technologies":"mdm"},{"id":"d0e46713-238c-42b7-a996-653cf952c367","displayName":"Home Group","description":"Administrative Templates Home Group","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d0ff97aa-cf53-460e-be82-2c521a56eec6","displayName":"Outlook Options","description":"Microsoft Outlook 2016\\Outlook Options","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["114356a4-dfc9-44e9-9a62-f1d601d48445","d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","93a20c17-1e34-4778-8c95-91a46980ea75","f2bf77fd-37df-448b-8959-6478abf96f6f","fa6bfb01-34f6-4c54-89b9-f7e717e6d394","5e3f61b6-52b7-4c74-a101-33c1cf34a749","fcc8ad48-a1e7-4cba-adae-7c916cbbc897","b9ab4d39-9e28-4897-aa34-0201a35ea989","e87c8824-e7c4-4fca-a3c1-0376d45d7f9f"],"platforms":"windows10","technologies":"mdm"},{"id":"d11e32cf-ac55-401a-a81a-232adc304afc","displayName":"Event Forwarding","description":"Administrative Templates\\Windows Components\\Event Forwarding","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","displayName":"HTTP authentication","description":"Microsoft Edge\\HTTP authentication","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","displayName":"Customize Ribbon","description":"Microsoft Excel 2016\\Excel Options\\Customize Ribbon","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d2191717-e304-46f7-bcc0-55e6477026c9","displayName":"Exclusion Settings","description":"Microsoft Defender Exclusion Settings","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","displayName":"Schedule View","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Schedule View","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","displayName":"Security Page","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page","helpText":null,"parentCategoryId":"586c5c5a-15cd-4592-beae-1709c6daf5b7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["ecfb5fea-26cc-494b-9e5e-88b5e51a5be0","40605d4b-d999-4235-9a5a-59fad165ec51","1aef6e33-cb5c-4ad5-b433-c198750bbc98","b1585568-da15-41fc-a1d0-5d0b194de84c","b9aafd85-b42a-4742-bbba-770b93678a52","cd16477e-7cff-4c24-ba7a-cc4342779f4b","76f2d08c-0a3f-4f4e-ad04-51aa16aea0bf","80f5fb2f-e74a-4533-81aa-a92163f49e16","a4bffc2b-76af-48d3-acdf-8566e51ef163","9bad0513-ac85-431c-86d9-9e3167f9b403"],"platforms":"windows10","technologies":"mdm"},{"id":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","displayName":"Task Manager","description":"Task Manager","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d33133b4-77df-429a-9580-ed70f7da676d","displayName":"Edit options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Edit\\Edit options for Microsoft Project","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d39f73b0-9d26-4d4c-a8b0-d1b720890d2e","displayName":"MK Protocol Security Restriction","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\MK Protocol Security Restriction","helpText":null,"parentCategoryId":"6776f6fa-8836-408c-b91c-1e444e0cba5c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d40a32e1-ab3e-4cbc-aa03-4766792e563e","displayName":"Performance Profiles Configuration","description":"Microsoft Defender Performance Profiles Configuration","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"d4943981-47b2-4a86-848b-860e8ca47381","displayName":"Microsoft Edge Update","description":"Microsoft Edge Update","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":["2c7e8e8e-47fe-48ba-8cb4-55ce296edced","46eaa2b7-341b-4e39-be21-c3ea09dd5778","43fc9dcc-1e66-4108-bded-2d005eeb7ccb","78497707-c3e4-400b-a6bc-1813c3689fdc","ff543267-540e-4e37-a1e9-daf6a5e16ba7"],"platforms":"windows10","technologies":"mdm"},{"id":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","displayName":"Privacy Sandbox policies","description":"Google Google Chrome Privacy Sandbox policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4bdfec1-2e40-49d2-b8f2-e5b15f072b10","displayName":"Event Viewer","description":"Administrative Templates\\Windows Components\\Event Viewer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","displayName":"Delete Browsing History","description":"Administrative Templates Internet Explorer Delete Browsing History","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","displayName":"Windows Connection Manager","description":"Administrative Templates Windows Connection Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","displayName":"Security Form Settings","description":"Microsoft Outlook 2016\\Security\\Security Form Settings","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["e11f4bd4-9041-49c9-9b8c-163827d606ce","a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","c400a917-cdff-4e15-a70f-59b82df4c038"],"platforms":"windows10","technologies":"mdm"},{"id":"d512207c-854d-482d-8e52-26637eef24e3","displayName":"Parameters","description":"Administrative Templates\\Network\\TCPIP Settings\\Parameters","helpText":null,"parentCategoryId":"3a28f10c-cb75-4f85-871b-87eb9dcd883c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","displayName":"Desktop Window Manager","description":"Administrative Templates Desktop Window Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["349c31c1-9b5b-42c8-91f2-aa41f4a36a71"],"platforms":"windows10","technologies":"mdm"},{"id":"d5585700-13a0-4ab4-9b19-4c15c1ead170","displayName":"Notification Settings","description":"Administrative Templates\\System\\Power Management\\Notification Settings","helpText":null,"parentCategoryId":"62b373da-c112-40f4-9047-9cc3e8d8ab13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d59dfcc1-6c35-41de-bfb6-de94b8120ca5","displayName":"Predefined","description":"Microsoft Outlook 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"7652894d-4667-443f-b925-b1686a942729","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","displayName":"KDC","description":"Administrative Templates KDC","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5b3cab7-d486-4f74-8525-6bd740b950bc","displayName":"Customizable Error Messages","description":"Microsoft Visio 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5d99ca9-9995-4724-bc46-fd07f362898c","displayName":"Cellular","description":"Cellular","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d6595bc3-dd73-44a3-8b32-d57af6e40208","displayName":"Windows Location Provider","description":"Administrative Templates\\Windows Components\\Location and Sensors\\Windows Location Provider","helpText":null,"parentCategoryId":"7f431009-e8fe-460e-b247-06c838c8a914","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d679b407-a753-40aa-bc9f-175f363b0eff","displayName":"File locations","description":"Microsoft Project 2016\\Project Options\\Save\\File locations","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d68abc4d-559a-4339-be48-c41a77a87034","displayName":"Passcode","description":"Security > Passcode","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","displayName":"Spelling","description":"Microsoft Outlook 2016\\Outlook Options\\Spelling","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d79c9f9a-f469-4f39-a66a-6f7d5ee77e81","displayName":"Language | Set Proofing Language...","description":"Microsoft Word 2016\\Review Tab\\Language | Set Proofing Language...","helpText":null,"parentCategoryId":"1fddd12c-a630-47f0-9633-638808e228f9","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d804205d-6c12-4f40-86a0-aa5a5355370f","displayName":"Files","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...\\Files","helpText":null,"parentCategoryId":"2108b443-384c-4bb3-9b9f-acb4a754a86a","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d875dca1-dc97-4cc5-9df3-c50b813622a3","displayName":"NS Extension Management","description":"App Management > NS Extension Management","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","displayName":"Finder","description":"User Experience > Finder","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d9432f48-3072-4171-9031-4ebead394151","displayName":"Accessibility settings","description":"Google Google Chrome Accessibility settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9654cb3-57c8-487c-90a5-454e15336731","displayName":"External Intelligence Settings","description":"Declarative Device Management preview External Intelligence Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","displayName":"Kiosk Mode settings","description":"Microsoft Edge\\Kiosk Mode settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","displayName":"Default search provider","description":"Google Google Chrome - Default Settings users can override Default search provider","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d982a1ef-84be-4832-99d4-8b71a4644b74","displayName":"Network Connections","description":"Administrative Templates Network Connections","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d99ac221-1000-44d8-9ab4-5cdac69562ed","displayName":"Quarantine","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Quarantine","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9b5c806-099f-4be8-96e4-1152e99cbf26","displayName":"Check Accessibility","description":"Microsoft Excel 2016\\File tab\\Check Accessibility","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9b7efad-fe18-4c98-925b-c4a5db0f2815","displayName":"Windows Error Reporting","description":"Administrative Templates\\Windows Components\\Windows Error Reporting","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["23e93393-4a75-44e6-9693-208eedb06976","e781bfae-233f-463f-a85b-7299ce5a87c5"],"platforms":"windows10","technologies":"mdm"},{"id":"d9d5f333-9402-4459-8ef1-e29330cac8be","displayName":"Live Share Settings","description":"Visual Studio Live Share Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9f5ccc9-5180-43b7-9c81-89ac3364ce00","displayName":"File Share Shadow Copy Provider","description":"Administrative Templates File Share Shadow Copy Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","displayName":"Readiness Toolkit","description":"Microsoft Office 2016\\Readiness Toolkit","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da1503cb-e474-4545-8e77-cdd577f34a08","displayName":"Miscellaneous","description":"Microsoft PowerPoint 2016\\Miscellaneous","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["7aeaf6f8-5511-4216-9483-28f432a5a08f"],"platforms":"windows10","technologies":"mdm"},{"id":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","displayName":"First- Party Sets Settings","description":"Google Google Chrome First- Party Sets Settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da92dfd6-a29e-42a0-92ed-276bb6904455","displayName":"PowerPoint Options","description":"Microsoft PowerPoint 2016\\PowerPoint Options","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["77ca5e78-a1fe-456e-9814-034b1ea2658d","e2610f41-9a95-47e5-9fc9-572e26dc6baa","76b233cc-f977-4305-b02f-deef6667251d","85810387-3320-4056-bae2-953beeb246f7","c3b5e77d-c00d-4578-84c9-289362ad0b00","f5007db5-6ee6-4bbd-a391-9727902aad6d","f66fb7e4-a968-4969-b627-f99aaad0dfc3"],"platforms":"windows10","technologies":"mdm"},{"id":"daa2ea69-8026-465a-942c-75eb0396d5b9","displayName":"Autonomous Single App Mode","description":"App Management > Autonomous Single App Mode","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","displayName":"Previous Versions","description":"Administrative Templates Previous Versions","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dad3971c-b07b-461b-8ead-6eda80ee57e1","displayName":"Network","description":"Administrative Templates\\Network","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["fd49df1b-bfad-4ed5-85c2-046a32fa8782","4ad00da1-5ed6-47d8-aef3-70f5bcbbbc77","bd7d2b68-118d-40ee-9dfd-39b2a22a2082","de5640ce-1975-407e-a1b6-7eaa164cd159","01f2fac4-fdab-4391-bebe-ebdf6d8fcc77","76c8131a-62fe-4134-aeac-d999f01911ed","8a409581-8ea5-493c-9e9e-2190f66381c3","bd8dacbf-ab7b-4a93-8294-7db61b9d49b4","82a9c23f-2c09-4479-9cd3-e7f185d7676f","f2345e03-bcd9-48fc-9c52-11ae06ba625a","b13e38a0-6ad6-4a1f-b53f-d8ca94847586","1b1be733-8615-4738-8797-c159d4d484be","618e0144-c57c-45e1-8b55-94dd3d9fec33","30fcb92f-4d0c-4dbf-95d0-a86350e9efc6","9d6a14ba-11f5-423d-afc0-8d30be1153c1","c95a5920-ad56-4668-a6ad-19c3eb428557","1cda8821-d9e2-485e-8d78-1829593d41ca","3a28f10c-cb75-4f85-871b-87eb9dcd883c","fc8f887c-cfd9-4bea-bfac-2214d06dba99","b221d3c2-e05a-4210-bf9c-2d7c7c0fd35a","b1393de2-587f-4516-a35d-58098f2be3c9"],"platforms":"windows10","technologies":"mdm"},{"id":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","displayName":"Shutdown Options","description":"Administrative Templates Shutdown Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","displayName":"Internet Formatting","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Internet Formatting","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["25df12bc-5ebd-4db2-8930-5d27690f3e60"],"platforms":"windows10","technologies":"mdm"},{"id":"db47f067-f435-4095-8b98-aa3805bc0050","displayName":"Schedule","description":"Microsoft Project 2016\\Project Options\\Schedule","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","304a579b-ff3b-4897-8bb8-5a1dda45356f"],"platforms":"windows10","technologies":"mdm"},{"id":"dba1a547-e288-45ac-8553-27a3b564699e","displayName":"Custom","description":"Microsoft Access 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"b8158968-c839-4d37-9eb8-887bd6fd7402","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dba26132-cba6-4178-93c3-f02476532f08","displayName":"Keyboard Settings","description":"Declarative Device Management preview Keyboard Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","displayName":"Windows File Protection","description":"Administrative Templates\\System\\Windows File Protection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","displayName":"PKCS certificate","description":"PKCS certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dc049161-17c6-411e-906b-a871b33651cd","displayName":"Proofing","description":"Microsoft Word 2016\\Word Options\\Proofing","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["e95db55a-8337-416d-a61f-e60f55cc0d13","4dae3032-1f16-4ace-911b-a957db0b8089"],"platforms":"windows10","technologies":"mdm"},{"id":"dc16dbf0-aac8-4ff3-a546-1ddb55650f47","displayName":"Programs","description":"Administrative Templates Programs","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","displayName":"Parental Controls Content Filter","description":"Parental Controls > Parental Controls Content Filter","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"dd68a290-1ba7-470f-afca-339f443a767c","displayName":"MDM Options","description":"Managed Settings MDM Options","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","displayName":"Calculation options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for 'Project1'","helpText":null,"parentCategoryId":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["acbc106b-796a-4ba3-ab5f-c130530ad455"],"platforms":"windows10","technologies":"mdm"},{"id":"dd9a3dad-5851-4899-a5c1-c23318986846","displayName":"File Classification Infrastructure","description":"Administrative Templates File Classification Infrastructure","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dd9e4ae2-a432-4c48-a73a-52c75c3e5279","displayName":"Trusted Certificate","description":"Trusted Certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"dd9e4ae2-a432-4c48-a73a-52c75c3e5279","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ddb64e9d-34b9-44f4-9980-a6623f14e445","displayName":"Custom Profile","description":"Declarative Device Management preview Custom Profile","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"visionOS,tvOS","technologies":"appleRemoteManagement"},{"id":"ddcc8634-edc3-40ef-a444-45f806439c18","displayName":"Application Defaults","description":"Application Defaults","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ddcc8634-edc3-40ef-a444-45f806439c18","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de5640ce-1975-407e-a1b6-7eaa164cd159","displayName":"Network Connectivity Status Indicator","description":"Administrative Templates\\Network\\Network Connectivity Status Indicator","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de643352-007f-4a47-8c83-d75a79516b39","displayName":"Deprecated policies","description":"Google Google Chrome - Default Settings users can override Deprecated policies","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de8dd733-3bb6-4ce5-9f93-475caac1862c","displayName":"Application","description":"Administrative Templates\\Windows Components\\Event Log Service\\Application","helpText":null,"parentCategoryId":"fcddcc0b-7cf8-4ebc-a818-d10689603263","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de9a9583-d660-4bdc-83bc-404c8c488267","displayName":"Memory Dump","description":"Memory Dump","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"de9a9583-d660-4bdc-83bc-404c8c488267","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dea96bde-003b-46fa-a960-baf62289c57d","displayName":"Delete Browsing History","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Delete Browsing History","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"deadde1d-7e7f-4577-bd6e-fc237c3854c5","displayName":"Group Policy","description":"Administrative Templates\\System\\Group Policy","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dec8381a-0a61-406b-842b-fc6ae9930795","displayName":"Lock Screen Message","description":"System Configuration > Lock Screen Message","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"decab1d2-3474-4727-87c0-d0bc648f2458","displayName":"Calendar Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","826db7fb-889b-4a99-80a6-38347ba37f21","c6b72060-8ecb-41d8-8625-2984dd756d4a","2592e8ea-5eb0-482b-b41e-eab92f33ac07","34c07941-8f52-43ad-b0ca-a7284655afb4"],"platforms":"windows10","technologies":"mdm"},{"id":"df0be435-d790-485a-b355-6f00eae29511","displayName":"Device Guard","description":"Administrative Templates\\System\\Device Guard","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"df357f0c-78fe-4aee-a465-f3da7499077e","displayName":"Proofing Data Collection","description":"Microsoft Office 2016\\Tools | Options | Spelling\\Proofing Data Collection","helpText":null,"parentCategoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dfab5866-1712-4bbf-8edf-5b080b315b9b","displayName":"Manageability","description":"Microsoft Edge\\Manageability","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"dfd5d749-c68c-448f-ab3f-851c09f09df4","displayName":"Auto Save Options","description":"Microsoft Project 2016\\Project Options\\Save\\Auto Save Options","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","displayName":"Locked- Down Local Machine Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Local Machine Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","displayName":"MSS (Legacy)","description":"Administrative Templates\\MSS (Legacy)","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e042b102-b12c-48d1-86ef-f6d296da5b95","displayName":"Server Manager","description":"Administrative Templates Server Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e06fb472-94c1-4dd9-afdf-6bb2ddaa3dc6","displayName":"Client Interface","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Client Interface","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","displayName":"FSLogix","description":"FSLogix","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["ab2be8b5-5912-4909-8d8b-e66edf4ab097","0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","f2d139ed-a314-48b7-b700-4d11adfcc309","5c645a3e-bc39-44e9-8786-4c82e0553d22"],"platforms":"windows10","technologies":"mdm"},{"id":"e0ab6868-4b53-4310-b665-f7c979941db7","displayName":"Safari Browser","description":"Declarative Device Management preview Safari Browser","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"e0dfe97e-348d-4d30-a6a1-e0de1989236e","displayName":"Other","description":"Microsoft Office 2016\\Language Preferences\\Other","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e0e10e94-325c-49e6-ab48-4f146254395f","displayName":"Form Region Settings","description":"Microsoft Outlook 2016\\Form Region Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e11f4bd4-9041-49c9-9b8c-163827d606ce","displayName":"Custom Form Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Custom Form Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e13ec567-e29c-4ca0-b599-e8c43587f10a","displayName":"Tools | Local Project Cache","description":"Microsoft Project 2016\\Project Options\\Save\\Tools | Local Project Cache","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","displayName":"InfoPath Integration","description":"Microsoft Outlook 2016\\InfoPath Integration","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e21bab5b-308d-4dcd-b6bb-a019e7347373","displayName":"Explorer Frame Pane","description":"Administrative Templates\\Windows Components\\File Explorer\\Explorer Frame Pane","helpText":null,"parentCategoryId":"35525ba9-da99-460e-afd3-ba86506b0ba3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","displayName":"Proofing","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Proofing","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["b792508d-da03-4174-bcf1-666d128ee8ad"],"platforms":"windows10","technologies":"mdm"},{"id":"e2a41bef-2f82-409e-9d20-0fe335390f60","displayName":"Microsoft Excel 2016","description":"Microsoft Excel 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["bc58391f-664c-42dd-9d18-269e65f324a7","1b6ac108-26b0-44f4-95a1-f848d1e90d76","d9b5c806-099f-4be8-96e4-1152e99cbf26","9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","28831364-ca54-4f31-acca-1aa0c7a7d3d2","b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","5b832259-c30b-43bb-b249-9d3ea4d5b028"],"platforms":"windows10","technologies":"mdm"},{"id":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","displayName":"Delivery Optimization","description":"Delivery Optimization","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e344b25a-2046-4e70-a3b9-1a418613861f","displayName":"Miscellaneous","description":"Microsoft Project 2016\\Miscellaneous","helpText":null,"parentCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","displayName":"Offline Address Book","description":"Microsoft Outlook 2016\\Account Settings\\Exchange\\Offline Address Book","helpText":null,"parentCategoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e36863b6-3232-4a29-be02-32ee67cc48b9","displayName":"External Content","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\External Content","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","displayName":"Federated Authentication","description":"Federated Authentication","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e3ca94a7-e506-4133-8fae-41931dc863a5","displayName":"Disk Diagnostic","description":"Administrative Templates Disk Diagnostic","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e42edcd8-fcb0-4255-a774-c78b34f0b0c9","displayName":"Desktop","description":"User Experience > Desktop","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","displayName":"E-mail","description":"Microsoft OneNote 2016\\OneNote Options\\E-mail","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","displayName":"MSI Corrupted File Recovery","description":"Administrative Templates MSI Corrupted File Recovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e50b312c-2bb3-4565-9212-080dba8d3d85","displayName":"Handwriting personalization","description":"Administrative Templates\\Control Panel\\Regional and Language Options\\Handwriting personalization","helpText":null,"parentCategoryId":"18db3d59-661b-47ec-900a-bf75495ca598","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e522c142-5666-4090-a7f4-1da1487f5384","displayName":"Co-authoring","description":"Microsoft Word 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","displayName":"Disable Items in User Interface","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","a20fe651-0f0a-4ddd-9d8b-273f17c89e22"],"platforms":"windows10","technologies":"mdm"},{"id":"e6231142-3d39-44a7-9522-6a3357bd439f","displayName":"Personalization","description":"Administrative Templates\\Control Panel\\Personalization","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e63361ad-a54b-4557-acc7-02c272a3e58d","displayName":"Smart cut and paste","description":"Microsoft Word 2016\\Word Options\\Advanced\\Smart cut and paste","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6911a08-946f-4b70-99cb-2a8b92c461e0","displayName":"Restrict ActiveX Install","description":"Administrative Templates Internet Explorer Security Features Restrict ActiveX Install","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","displayName":"Remote FX USB Device Redirection","description":"Administrative Templates Remote FX USB Device Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6f727b7-f474-4010-b214-83149ffdac2b","displayName":"Miscellaneous","description":"Microsoft Visio 2016\\Miscellaneous","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","displayName":"DNS Client","description":"Administrative Templates DNS Client","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e73ddc98-e465-43b0-bfd8-8a18cd9d4830","displayName":"Exploit Guard","description":"Exploit Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e73ddc98-e465-43b0-bfd8-8a18cd9d4830","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"e740736f-75f9-481d-990c-02018abc2ea5","displayName":"Local Security Authority","description":"Administrative Templates System Local Security Authority","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e781bfae-233f-463f-a85b-7299ce5a87c5","displayName":"Consent","description":"Administrative Templates\\Windows Components\\Windows Error Reporting\\Consent","helpText":null,"parentCategoryId":"d9b7efad-fe18-4c98-925b-c4a5db0f2815","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e7ae2b99-0479-475f-af5c-96457121fcd0","displayName":"Windows Hello For Business","description":"Windows Hello For Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","displayName":"Reporting","description":"Administrative Templates App-V Reporting","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","displayName":"Accessibility Settings","description":"Managed Settings Accessibility Settings","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","displayName":"Defender","description":"Defender","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"e8514a44-e44c-47af-a714-7697ebb2baf7","displayName":"Pen Flicks Learning","description":"Administrative Templates\\Windows Components\\Tablet PC\\Pen Flicks Learning","helpText":null,"parentCategoryId":"50369ef0-e9a8-48c0-a8fa-ff00b0cd0ac1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e865337e-db9f-4d4c-b9fe-35030792c942","displayName":"Microsoft Outlook 2016","description":"Microsoft Outlook 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["3f216590-fb12-4f8e-924f-2a6895d94126","e0e10e94-325c-49e6-ab48-4f146254395f","d0ff97aa-cf53-460e-be82-2c521a56eec6","fb721630-fc42-465b-ba22-ab670698c8b5","92d9620c-92b6-45ec-b7d6-2f9ed0751e78","f77040df-7dd2-4916-b6a0-5ef962686d4e","b3e317cd-c580-478e-885c-666ce3079e78","e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","75ad885f-6118-4508-a2fd-bb26be931c3f","7652894d-4667-443f-b925-b1686a942729","ee62e9fc-14c8-4f24-aa7e-89524087a802","2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","f5a1a387-6665-4527-b532-88a64a76e732"],"platforms":"windows10","technologies":"mdm"},{"id":"e86f24d3-8531-4298-b064-692ea795b1d9","displayName":"Diagnostics","description":"Microsoft Office 2016 Diagnostics","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","displayName":"Compose Messages","description":"Microsoft Outlook 2016\\Outlook Options\\Mail\\Compose Messages","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e8ce968b-91cb-4301-ba98-b37d42bc5213","displayName":"Automatically as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Automatically as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","displayName":"Profile Removal Password","description":"Managed Devices > Profile Removal Password","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","displayName":"Trusted Add-ins","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Programmatic Security\\Trusted Add-ins","helpText":null,"parentCategoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e95335ec-2704-47ab-8b40-f602b31eeb9d","displayName":"Content Caching","description":"Networking > Content Caching","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e95db55a-8337-416d-a61f-e60f55cc0d13","displayName":"AutoCorrect","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoCorrect","helpText":null,"parentCategoryId":"dc049161-17c6-411e-906b-a871b33651cd","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e972d9fe-a9b7-4a65-a88f-0958fab19584","displayName":"App runtime","description":"Administrative Templates App runtime","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e9aff162-feb0-400a-aa68-8dd8deb93275","displayName":"Windows Logon Options","description":"Administrative Templates\\Windows Components\\Windows Logon Options","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","displayName":"Power","description":"Power","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","displayName":"Session Time Limits","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Session Time Limits","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea812d2c-1cf9-4132-9b33-12bb7ac17dbd","displayName":"Publishing","description":"Administrative Templates\\System\\App-V\\Publishing","helpText":null,"parentCategoryId":"a24f4ab6-289a-450a-b438-1c4bb1214942","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea9a092f-dd93-41d4-9bbb-118de1213578","displayName":"Integration","description":"Administrative Templates App-V Integration","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","displayName":"IME (Japanese)","description":"Microsoft Office 2016\\IME (Japanese)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb5baf57-86c8-4bfa-ac3a-53025686e37c","displayName":"Reporting","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Reporting","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb6409fc-fb52-413d-ae4b-eff017b52b30","displayName":"Experimentation","description":"Microsoft Edge\\ Experimentation","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb947c30-3c43-4d34-a566-a842a1a142f3","displayName":"Language Preferences","description":"Microsoft Office 2016\\Language Preferences","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["0f6020d9-278b-4284-894a-bc4a70c8cf32","e0dfe97e-348d-4d30-a6a1-e0de1989236e","3512a9f5-d692-4a1f-aedd-1bd431ae893e"],"platforms":"windows10","technologies":"mdm"},{"id":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","displayName":"Security","description":"Microsoft Word 2016\\Word Options\\Security","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["5f7e1206-359d-49d7-82c3-f6b6a6eddf65","a5ce858b-74c2-4663-9b3e-068d31349a13"],"platforms":"windows10","technologies":"mdm"},{"id":"ecfb5fea-26cc-494b-9e5e-88b5e51a5be0","displayName":"Internet Zone","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Internet Control Panel\\Security Page\\Internet Zone","helpText":null,"parentCategoryId":"d2da164d-dd77-4489-b67f-d7fbdb19cde2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","displayName":"Calculation options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for Microsoft Project","helpText":null,"parentCategoryId":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ed24097d-3bb7-459c-83fb-f0090d1ad8dd","displayName":"Speech","description":"Speech","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ed24097d-3bb7-459c-83fb-f0090d1ad8dd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eda31027-9270-4959-801b-397fa05512e2","displayName":"Restrictions","description":"Restrictions","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"eda31027-9270-4959-801b-397fa05512e2","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"edba50d5-da3c-48cb-8e50-381ad0bfaaaf","displayName":"Exclusions","description":"Administrative Templates\\ Windows Components\\ Microsoft Defender Antivirus\\ Exclusions","helpText":null,"parentCategoryId":"49d75a11-64c6-43d1-bc25-0ab156ff4216","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"edd1e620-09e1-47ea-abc8-1e241a174ed9","displayName":"Locale Services","description":"Administrative Templates Locale Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"edf3754c-b22d-4946-a744-4773240a5883","displayName":"WWAN Media Cost","description":"Administrative Templates WWAN Service WWAN Media Cost","helpText":null,"parentCategoryId":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ee62e9fc-14c8-4f24-aa7e-89524087a802","displayName":"Customizable Error Messages","description":"Microsoft Outlook 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eec07ad3-24ef-4502-8125-9fc988650a7c","displayName":"Settings","description":"Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","displayName":"General","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\General","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","displayName":"WWAN UI Settings","description":"Administrative Templates WWAN Service WWAN UI Settings","helpText":null,"parentCategoryId":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","displayName":"Edge Workspaces settings","description":"Microsoft Edge Edge Workspaces settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ef7328b1-c666-40fe-a933-57b14bc77dd3","displayName":"Wallpaper","description":"Managed Settings Wallpaper","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","displayName":"Native Messaging","description":"Microsoft Edge\\Native Messaging","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","displayName":"Above Lock","description":"Above Lock","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"efabaf11-42e4-48ab-81ca-4514199d239b","displayName":"Scripting","description":"Administrative Templates App-V Scripting","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","displayName":"Trust Center","description":"Microsoft Office 2016\\Security Settings\\Trust Center","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["135e4013-43b8-4227-99fd-54ddeac4e329","24f6d328-64e7-4490-be38-452ac3b61f6f","517e55f5-729f-4b4d-9555-33baa95a0e5a"],"platforms":"windows10","technologies":"mdm"},{"id":"effee722-f6ec-440e-a892-bf645bc341ff","displayName":"Reboot","description":"Reboot","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"effee722-f6ec-440e-a892-bf645bc341ff","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f00e9baf-9bbf-48e4-aaac-57410730f016","displayName":"Sign-in settings","description":"Google Google Chrome Sign-in settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","displayName":"Security Settings","description":"Microsoft Office 2016 (Machine)\\Security Settings","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":["fa8e7b34-c736-47ec-be83-a9f1960d5281"],"platforms":"windows10","technologies":"mdm"},{"id":"f019963f-f4ed-4429-b6e3-babfb24c36a8","displayName":"Parental Controls Application Restrictions","description":"Parental Controls > Parental Controls Application Restrictions","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","displayName":"Connectivity","description":"Connectivity","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f10138ba-123a-43bc-8031-4458ba327374","displayName":"Mixed Reality","description":"Mixed Reality","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f10138ba-123a-43bc-8031-4458ba327374","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","displayName":"Visio Options","description":"Microsoft Visio 2016\\Visio Options","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["ad9610c6-d1c5-4c7a-9e74-58b810dd759d","2ea63962-4cac-4a5c-9181-e6a364489db0","8495c82c-f273-4bcc-8886-6751103a9c7b","2764869c-54a3-462b-bc72-c580621ab6bb","957a5b24-ed7a-4f84-9d73-7b6131367396","a7d55d90-e1d1-4577-8bfd-fe2641bce461"],"platforms":"windows10","technologies":"mdm"},{"id":"f125d7cd-a333-4f24-a5f4-99fc289c6d22","displayName":"Package Management","description":"Administrative Templates App-V Package Management","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f1278d6b-60ec-4369-88cf-21df47caaec6","displayName":"Remote Procedure Call","description":"Administrative Templates Remote Procedure Call","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","displayName":"App Store","description":"App Store > App Store","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f14074a2-de74-48df-b273-48791217ef4d","displayName":"Security Settings","description":"Administrative Templates\\System\\Service Control Manager Settings\\Security Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f1455024-7de9-448f-8d8f-a42db2af0a35","displayName":"Printer Redirection","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Printer Redirection","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","displayName":"Event Log Service","description":"Administrative Templates Event Log Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["55a61bb8-e023-4741-8213-99995c5902e5","fecd321b-9a48-4f97-bbed-b335f9ccebdb","a28dd311-46e8-4868-89ab-d3745c0bca21","1a2a4fc8-c54b-4906-a422-7dd51a196211"],"platforms":"windows10","technologies":"mdm"},{"id":"f2345e03-bcd9-48fc-9c52-11ae06ba625a","displayName":"Background Intelligent Transfer Service (BITS)","description":"Administrative Templates\\Network\\Background Intelligent Transfer Service (BITS)","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","displayName":"Privacy","description":"Administrative Templates Internet Explorer Privacy","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","displayName":"AutoArchive","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\AutoArchive","helpText":null,"parentCategoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f2bf77fd-37df-448b-8959-6478abf96f6f","displayName":"Mail Format","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","88b16683-81f2-450a-9bf2-42f582e0b748","91bf761c-1a1e-4a3a-adbf-27288ea7b0b3"],"platforms":"windows10","technologies":"mdm"},{"id":"f2d139ed-a314-48b7-b700-4d11adfcc309","displayName":"Cloud Cache Service","description":"FS Logix Cloud Cache Service","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f3027ba5-9a2f-42c6-9872-ec21f726929c","displayName":"Early Launch Antimalware","description":"Administrative Templates Early Launch Antimalware","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f3264346-fdc4-4e23-9a2a-dcfc34022e59","displayName":"Printer Redirection","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Printer Redirection","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f34e3da0-b440-43dc-a368-4fd39646a9c5","displayName":"Trust Center","description":"Microsoft Visio 2016\\Visio Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"2ea63962-4cac-4a5c-9181-e6a364489db0","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["75f9bfd8-8ee2-47b0-b080-a4d179724ca8"],"platforms":"windows10","technologies":"mdm"},{"id":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","displayName":"Device password","description":"Device Restriction Device password","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"f35cc803-3a06-4262-b38b-a5295321f756","displayName":"Extensible Single Sign On Kerberos","description":"Authentication > Extensible Single Sign On Kerberos","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm"},{"id":"f36a78cf-46cf-418e-a98e-032f6cfad224","displayName":"App Management","description":"App Management","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":["d875dca1-dc97-4cc5-9df3-c50b813622a3","7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","daa2ea69-8026-465a-942c-75eb0396d5b9","8efd284f-5a56-4da8-8821-f51984ff954d"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","displayName":"Smart Card","description":"Security > Smart Card","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","displayName":"Windows Media Player","description":"Administrative Templates Windows Media Player","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["2f85405a-7472-44ce-8c05-b59bb54912d5","902a93e8-8beb-46c5-ba26-4e2bf6161e22","7f461268-0fb6-4247-b6db-52515d42a20e"],"platforms":"windows10","technologies":"mdm"},{"id":"f4eaa5be-1498-482e-abe6-de4fed7e3302","displayName":"Programs","description":"Administrative Templates\\Control Panel\\Programs","helpText":null,"parentCategoryId":"7a3a7335-4837-4bc5-9282-448402a05d89","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f4f0dfd7-4638-4173-8b3b-0f08608bf330","displayName":"Active Directory","description":"Administrative Templates\\Desktop\\Active Directory","helpText":null,"parentCategoryId":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f4fd69bc-8622-411d-91bb-0e214f8fb112","displayName":"Logon","description":"Administrative Templates\\System\\Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f5007db5-6ee6-4bbd-a391-9727902aad6d","displayName":"General","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\General","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f52d9745-eaf4-4e39-84b2-6b32c3b15aa3","displayName":"IPv6 Transition Technologies","description":"Administrative Templates\\Network\\TCPIP Settings\\IPv6 Transition Technologies","helpText":null,"parentCategoryId":"3a28f10c-cb75-4f85-871b-87eb9dcd883c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f59804be-7fc6-43c3-9baa-942aab85be84","displayName":"Display","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Display","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f59f7502-cd01-4ea7-9925-2231f88596f0","displayName":"Dma Guard","description":"Dma Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f59f7502-cd01-4ea7-9925-2231f88596f0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f5a1a387-6665-4527-b532-88a64a76e732","displayName":"Miscellaneous","description":"Microsoft Outlook 2016\\Miscellaneous","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["ffb0a109-2507-42b3-b26f-9f667f2d5029","cb6472c8-3e22-4029-af98-8a97f03a5a44"],"platforms":"windows10","technologies":"mdm"},{"id":"f5babdb3-c718-4675-b977-6c7bc7e6f886","displayName":"Check Accessibility","description":"Microsoft PowerPoint 2016\\File Tab\\Check Accessibility","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f5e39798-0511-462f-b859-f892fdde4328","displayName":"iSCSI Target Discovery","description":"Administrative Templates\\System\\iSCSI\\iSCSI Target Discovery","helpText":null,"parentCategoryId":"363982dd-fc96-49ce-a499-f6401f2c212b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","displayName":"Internet Explorer","description":"Administrative Templates\\Windows Components\\Internet Explorer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["dea96bde-003b-46fa-a960-baf62289c57d","6776f6fa-8836-408c-b91c-1e444e0cba5c","accec716-3bf1-4a33-882d-3538d32fcbbc","c26b2f10-f2c0-45f2-955c-5379dd12f206","586c5c5a-15cd-4592-beae-1709c6daf5b7","7a85e72a-a755-4903-b1fd-4939049380f4"],"platforms":"windows10","technologies":"mdm"},{"id":"f62e0f2a-4363-4246-8057-1dc811fe4360","displayName":"System","description":"System","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","displayName":"Local Network Access settings","description":"Google Google Chrome Local Network Access settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f66fb7e4-a968-4969-b627-f99aaad0dfc3","displayName":"Customize Ribbon","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Customize Ribbon","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f69e6993-2e88-4938-bfe5-cea9ab21a858","displayName":"Windows Remote Shell","description":"Administrative Templates Windows Remote Shell","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","displayName":"Parental Controls Time Limits","description":"Parental Controls > Parental Controls Time Limits","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","displayName":"Windows Defender Security Center","description":"Windows Defender Security Center","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f7486553-9e63-4d63-9423-56e5ffe48700","displayName":"Google Cast","description":"Google Google Chrome Google Cast","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f77040df-7dd2-4916-b6a0-5ef962686d4e","displayName":"Meeting Workspace","description":"Microsoft Outlook 2016\\Meeting Workspace","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f783d1ea-2f9b-4fcb-96cc-fb455cfe69f9","displayName":"Fault Tolerant Heap","description":"Administrative Templates\\System\\Troubleshooting and Diagnostics\\Fault Tolerant Heap","helpText":null,"parentCategoryId":"424a0e73-8002-42e3-b47d-2062fc17c3b3","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","displayName":"Windows Licensing","description":"Windows Licensing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8bb78a3-d1e4-4c5d-8b0a-904a83830519","displayName":"Shared Folders","description":"Administrative Templates\\Shared Folders","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8f4d337-4c55-4518-91c4-f7f77703d843","displayName":"Software Update","description":"System Updates > Software Update","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f926f6e3-1bd6-4259-ae7c-e14108568882","displayName":"Microsoft Support Diagnostic Tool","description":"Administrative Templates Microsoft Support Diagnostic Tool","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f96201d4-894e-4a72-87fb-22146039a802","displayName":"Device Health Attestation Service","description":"Administrative Templates\\System\\Device Health Attestation Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f9e53433-d8d9-4eaf-bdf3-d32de60d686e","displayName":"Customize Ribbon","description":"Microsoft Word 2016\\Word Options\\Customize Ribbon","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","displayName":"Subscribed Calendars","description":"Accounts Subscribed Calendars","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"fa2722a8-dcfd-4e14-a429-2b0041642c77","displayName":"Network settings","description":"Google Google Chrome Network settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","displayName":"Windows App","description":"Windows App","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","displayName":"Editing","description":"Microsoft OneNote 2016\\OneNote Options\\Editing","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa6bfb01-34f6-4c54-89b9-f7e717e6d394","displayName":"Customize Ribbon","description":"Microsoft Outlook 2016\\Outlook Options\\Customize Ribbon","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa8e7b34-c736-47ec-be83-a9f1960d5281","displayName":"IE Security","description":"Microsoft Office 2016 (Machine)\\Security Settings\\IE Security","helpText":null,"parentCategoryId":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","displayName":"Microsoft Word 2016","description":"Microsoft Word 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["1fddd12c-a630-47f0-9633-638808e228f9","73bc2db9-d37f-4add-a64d-a8239273edb3","b8adcde1-500a-430f-8636-f97eaae2a2c6","12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","e522c142-5666-4090-a7f4-1da1487f5384","320ccaa3-a391-4d29-a9c4-594561f4104d","31070051-859e-4d27-9df3-c07b8a2d2179","740e7a10-3774-4a1c-9970-6907e0f0b848"],"platforms":"windows10","technologies":"mdm"},{"id":"fb1e99d0-b921-4b19-9842-17e3e7987528","displayName":"Edge Website Typo Protection settings","description":"Microsoft Edge Edge Website Typo Protection settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fb721630-fc42-465b-ba22-ab670698c8b5","displayName":"Search Folders","description":"Microsoft Outlook 2016\\Search Folders","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fc8f887c-cfd9-4bea-bfac-2214d06dba99","displayName":"WWAN Service","description":"Administrative Templates\\Network\\WWAN Service","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["a51a8665-045d-482d-b68b-2128959c8b31","ab6aa2f6-87bf-4a06-a206-e0902af3e4bc"],"platforms":"windows10","technologies":"mdm"},{"id":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","displayName":"Restricted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Restricted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","displayName":"Delegates","description":"Microsoft Outlook 2016\\Outlook Options\\Delegates","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fcddcc0b-7cf8-4ebc-a818-d10689603263","displayName":"Event Log Service","description":"Administrative Templates\\Windows Components\\Event Log Service","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["de8dd733-3bb6-4ce5-9f93-475caac1862c","8dca6b5f-ff9c-44c8-9822-008acef616aa","9d26f3a1-6a54-4043-bda2-bfeb84e80524","66448b13-cc0a-4ffe-9ad5-62c4821dc77f"],"platforms":"windows10","technologies":"mdm"},{"id":"fd16aa29-dae5-49b5-910e-88f3078ce2da","displayName":"Push To Install","description":"Administrative Templates\\Windows Components\\Push To Install","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","displayName":"Xsan Preferences","description":"Xsan > Xsan Preferences","helpText":null,"parentCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"fd49df1b-bfad-4ed5-85c2-046a32fa8782","displayName":"Lanman Server","description":"Administrative Templates\\Network\\Lanman Server","helpText":null,"parentCategoryId":"dad3971c-b07b-461b-8ead-6eda80ee57e1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fddc444c-3591-4a50-865b-d8993b798e12","displayName":"Cast","description":"Microsoft Edge\\Cast","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fe3cb879-8869-4163-91d7-e432abd75da8","displayName":"Scheduled Maintenance","description":"Administrative Templates Scheduled Maintenance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe52de11-190e-4429-96c1-106b22724456","displayName":"Device and Resource Redirection","description":"Administrative Templates\\Windows Components\\Remote Desktop Services\\Remote Desktop Session Host\\Device and Resource Redirection","helpText":null,"parentCategoryId":"66e289cf-85cb-425f-94a1-54777950f78b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe54701d-42bd-47f0-9c49-26ff6a928b32","displayName":"Protected View","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe65603b-1980-446b-ae17-516eb885c6be","displayName":"Tablet PC Pen Training","description":"Administrative Templates Tablet PC Pen Training","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe786056-6f4a-4d16-bff4-5fbb640308d2","displayName":"Trusted Locations","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe7c8652-17d4-40a7-869c-f7cfc3454402","displayName":"Show indicators and Option butons for","description":"Microsoft Project 2016\\Project Options\\Interface\\Show indicators and Option butons for","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe845e81-5993-4a65-b22a-decfc5928c65","displayName":"Proxy server","description":"Microsoft Edge\\Proxy server","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","displayName":"Scareware Blocker settings","description":"Microsoft Edge - Default Settings users can override Scareware Blocker settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","displayName":"Application","description":"Administrative Templates Event Log Service Application","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","displayName":"Predefined","description":"Microsoft Visio 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff543267-540e-4e37-a1e9-daf6a5e16ba7","displayName":"Proxy Server","description":"Microsoft Edge Update\\Proxy Server","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","displayName":"E-mail","description":"Microsoft Outlook 2016\\Account Settings\\E-mail","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","displayName":"Notifications","description":"User Experience > Notifications","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"ffb0a109-2507-42b3-b26f-9f667f2d5029","displayName":"Miscellaneous","description":"Microsoft Outlook 2016\\Miscellaneous\\Miscellaneous","helpText":null,"parentCategoryId":"f5a1a387-6665-4527-b532-88a64a76e732","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","displayName":"Microsoft Access 2016","description":"Microsoft Access 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["607a1c39-a3db-496f-8db6-c99d67f5f76c","6730f0be-a129-4b48-942f-e4ddf69fee66","b8158968-c839-4d37-9eb8-887bd6fd7402","d0a3bbad-8ed0-4545-8249-9e464a13e1b7","c3ab8d44-b353-4a8a-a526-ffd743fb7ff8"],"platforms":"windows10","technologies":"mdm"},{"id":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","displayName":"App Package Deployment","description":"Administrative Templates\\Windows Components\\App Package Deployment","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffd1a98f-0fac-47fe-813f-7510d0dacbc3","displayName":"Windows Resource Exhaustion Detection and Resolution","description":"Administrative Templates Windows Resource Exhaustion Detection and Resolution","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","displayName":"Audio and Video","description":"Microsoft OneNote 2016\\OneNote Options\\Audio and Video","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fff51673-04b8-4277-98ef-4baffbd8d192","displayName":"Windows Calendar","description":"Administrative Templates Windows Calendar","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"}] +[{"id":"005ddf8f-da22-4b23-ab02-289f8f6c7960","displayName":"Internet Explorer","description":"Administrative Templates Internet Explorer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","a1fbe395-3b60-475f-8a34-3710d6b2e09f","d4bf78d5-f6da-463d-85a3-d763e6fbe32b","3f6bb987-17dc-4442-a946-c1c5b1d089d7","bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","b491424f-100c-4f84-9b9c-8573b2ff9ac7"],"platforms":"windows10","technologies":"mdm"},{"id":"00d7396c-cadc-4d29-86ba-fe4df2ecb110","displayName":"Startup, home page and new tab page","description":"Microsoft Edge\\Startup, home page and new tab page","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"01d16911-19a1-4dcb-8089-ffa4781d977c","displayName":"Windows Ink Workspace","description":"Windows Ink Workspace","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"01d16911-19a1-4dcb-8089-ffa4781d977c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"01da0c26-af30-4eb2-a899-7d5e7ecb9738","displayName":"Video and Display Settings","description":"Administrative Templates Power Management Video and Display Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"023e0367-b563-4fae-8fb6-589c836ee223","displayName":"Add or Remove Programs","description":"Administrative Templates Add or Remove Programs","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"025c640e-51e2-4f04-85e3-a13f30b5e08c","displayName":"Encoding","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Encoding","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"038b49c9-4f13-4ace-be8d-bd076bffa23e","displayName":"Save","description":"Microsoft Publisher 2016\\Publisher Options\\Save","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"03a966f7-8f8e-4ecb-aab3-055fe907f5ab","displayName":"Security Account Manager","description":"Administrative Templates Security Account Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"042ab9cf-9524-4dd4-b049-4d5f4ff7053f","displayName":"Manage Restricted Permissions","description":"Microsoft Office 2016\\Manage Restricted Permissions","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0456dcd5-c003-4a8b-80e6-61bacf854330","displayName":"RD Licensing","description":"Administrative Templates Remote Desktop Services RD Licensing","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","displayName":"Microsoft Publisher 2016","description":"Microsoft Publisher 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["9caa3b08-b545-4c21-a3b7-b5d2302c1a81","c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","c6c1120b-988c-4581-a21c-b9786a821242","0cea32b4-28be-4164-ae2a-6db33b9dadb7"],"platforms":"windows10","technologies":"mdm"},{"id":"0497eec4-fe3a-44f2-8caf-b5ab11839893","displayName":"Games","description":"Games","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0497eec4-fe3a-44f2-8caf-b5ab11839893","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"04b46099-4ee5-4def-8e04-569c988057a9","displayName":"Identity and sign-in","description":"Microsoft Edge - Default Settings (users can override)\\ Identity and sign-in","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"05305a87-0b19-41bb-bf1e-0bd92bfcdc16","displayName":"Push To Install","description":"Administrative Templates Push To Install","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"055293ad-c585-40c0-b66c-76ff5cc0a332","displayName":"Microsoft Office SmartArt","description":"Microsoft Office 2016\\Microsoft Office SmartArt","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"05811ceb-2954-426c-8afa-2a53f02480cc","displayName":"Permit or deny screen capture","description":"Microsoft Edge\\ Permit or deny screen capture","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"05a6f86f-dab7-4888-97a1-db3457f00974","displayName":"Writing Assistance","description":"Microsoft Office 2016 Writing Assistance","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"060e7533-6c2f-4ed1-9173-f3de58de4bed","displayName":"Internet Calendars","description":"Microsoft Outlook 2016\\Account Settings\\Internet Calendars","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0696109e-045f-486a-9a6b-ab7877887bed","displayName":"Document Information Panel","description":"Microsoft Office 2016\\Document Information Panel","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"06a85f5b-2614-4467-91cf-4a64d0c9326f","displayName":"Network Usage Rules","description":"Networking > Network Usage Rules","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"06c4a76a-805b-4370-9d80-08e720ab2305","displayName":"View options for time units in 'Project1'","description":"Microsoft Project 2016\\Project Options\\Edit\\View options for time units in 'Project1'","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0775f21c-9ca1-446d-b1dc-3cea45f15605","displayName":"Files","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Files","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"07c023d3-0899-40af-a04f-805876d99a9b","displayName":"Microsoft Management Console","description":"Administrative Templates Microsoft Management Console","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["acb49e73-5a6a-479b-9d58-c3cd7f632e9b"],"platforms":"windows10","technologies":"mdm"},{"id":"08677354-6f67-455e-a430-4d8d2fbabe84","displayName":"Web Rtc settings","description":"Microsoft Edge Web Rtc settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"088b8d8d-5f3f-4979-aa18-b3c4b2616a24","displayName":"Sound Recorder","description":"Administrative Templates Sound Recorder","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","displayName":"Disk Quotas","description":"Administrative Templates Disk Quotas","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"08c5f391-e156-4a72-bbb9-3670f2f63a56","displayName":"SmartScreen settings","description":"Microsoft Edge\\SmartScreen settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"0937f5ff-aabc-49a9-a94f-6f98c4702580","displayName":"Qo S Packet Scheduler","description":"Administrative Templates Qo S Packet Scheduler","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["cf968979-f316-47cb-a207-bf9ef28cd1aa","4ca3b8c7-0350-4043-b96d-918f24df0a3b","c87ae066-cc1a-44c9-8645-1db2359f7484"],"platforms":"windows10","technologies":"mdm"},{"id":"098942c3-afe3-40c8-823f-37f0b5b13ad4","displayName":"Remote access","description":"Google Google Chrome Remote access","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"09c02465-dc11-457e-9eac-19fc542e4cda","displayName":"MAPS","description":"Administrative Templates Microsoft Defender Antivirus MAPS","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a1347d2-90c0-407a-baa0-e4859260532a","displayName":"BitLocker","description":"BitLocker","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0a1347d2-90c0-407a-baa0-e4859260532a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a6bc3ed-c4cd-4928-bcbf-247369a51515","displayName":"General options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\General\\General options for 'Project1'","helpText":null,"parentCategoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a803a48-789a-48b0-b928-e52d56ab17f1","displayName":"Wi-Fi Settings","description":"Wi-Fi Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0a803a48-789a-48b0-b928-e52d56ab17f1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0a9f982a-3515-4728-a231-fa000eb9e550","displayName":"User Preferences","description":"Preferences > User Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","displayName":"Profile Containers","description":"FS Logix Profile Containers","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["479c2edd-6539-4e1d-96ba-518d6f6264c3","719595d8-ab5d-4418-88aa-8cd55c2964ba"],"platforms":"windows10","technologies":"mdm"},{"id":"0bae3158-5f75-4e25-acf4-859d2612f892","displayName":"Cloud Cache","description":"FS Logix ODFC Containers Cloud Cache","helpText":null,"parentCategoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0be23ead-c5f7-4ea5-9ec5-64c05d19cf5d","displayName":"Data Roaming","description":"Managed Settings Data Roaming","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"0be98651-a552-4470-b2dc-71c66a5ce1e6","displayName":"Presentation Services","description":"Microsoft Office 2016\\Present Online\\Presentation Services","helpText":null,"parentCategoryId":"5bf4c2ba-be08-4cda-bf33-d10707580d78","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","displayName":"RD Connection Broker","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host RD Connection Broker","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","displayName":"Security","description":"Microsoft Publisher 2016\\Security","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["30da5d88-cf03-41f4-ab55-51ead91b3844"],"platforms":"windows10","technologies":"mdm"},{"id":"0d37dddd-6575-485c-92dd-37a3c23edbf9","displayName":"BitLocker Drive Encryption","description":"Administrative Templates BitLocker Drive Encryption","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["8e6b8d0c-faf6-41e6-8e31-4389a5470caf","a18508d1-fd74-4955-8032-3bd9219a0944","acbc98d1-689b-4f9c-9c5a-e6bbf305e654"],"platforms":"windows10","technologies":"mdm"},{"id":"0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","displayName":"Content settings","description":"Microsoft Edge - Default Settings (users can override)\\Content settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","displayName":"System Logging","description":"System Configuration > System Logging","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","displayName":"Wireless Network Preference","description":"Wireless Network Preference","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0d9ee4f5-7d6b-41fd-9089-b0886f7ff944","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0e1122f8-2bbf-475b-bce0-9e43a2f5e475","displayName":"Schedule Scan","description":"Microsoft Defender Schedule Scan","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"0e6c9053-73d6-4c56-9147-53513f6eefd8","displayName":"Windows Update For Business","description":"Windows Update For Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0e6c9053-73d6-4c56-9147-53513f6eefd8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","displayName":"Microsoft Project 2016","description":"Microsoft Project 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["e344b25a-2046-4e70-a3b9-1a418613861f","1266b519-e436-4698-8ff4-442acc97efd4"],"platforms":"windows10","technologies":"mdm"},{"id":"0e937777-d01a-4180-a937-c2010451a529","displayName":"Login Window Login Items","description":"Login > Login Window Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","displayName":"Windows Sandbox","description":"Windows Sandbox","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"0f05f2c4-3a19-482f-82e8-92a46a4fcbfd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f42fc50-66c8-4b70-9904-64f8d662c930","displayName":"Custom","description":"Microsoft Word 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"740e7a10-3774-4a1c-9970-6907e0f0b848","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f6020d9-278b-4284-894a-bc4a70c8cf32","displayName":"Display Language","description":"Microsoft Office 2016\\Language Preferences\\Display Language","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"0f6d725e-2c2d-4926-8e78-3d2d5867eef5","displayName":"Win RM Client","description":"Administrative Templates Windows Remote Management Win RM Win RM Client","helpText":null,"parentCategoryId":"364787de-93e4-4fd6-9608-dce1ad8f88c2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"10247787-95ea-4507-93de-dbd166df12b5","displayName":"Legacy Browser Support","description":"Google Google Chrome Legacy Browser Support","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1043e7ed-8651-44b2-b918-7230c0b75a6c","displayName":"Profile settings","description":"Microsoft Edge Profile settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"10835ce3-31c8-4ec6-aa00-c5af48e550a8","displayName":"Virtualization","description":"Administrative Templates App-V Virtualization","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"114356a4-dfc9-44e9-9a62-f1d601d48445","displayName":"Mail Setup","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Setup","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"119ca05b-5f1f-4714-a942-2a76b05d2a7b","displayName":"Lock Down","description":"Lock Down","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"119ca05b-5f1f-4714-a942-2a76b05d2a7b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"11c4cf0f-a03d-4309-93b2-011be4c410d5","displayName":"Screensaver User","description":"User Experience > Screensaver User","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"11d26400-1d13-4dd6-ab4b-cb323494b127","displayName":"Intelligence Settings","description":"Declarative Device Management preview Intelligence Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"120b24dd-c04a-4291-8f24-9c48fcdc1434","displayName":"Cryptography compliance policies","description":"Microsoft Edge Cryptography compliance policies","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12142994-4b30-486c-bab1-9206528b2b96","displayName":"Accessibility settings","description":"Google Google Chrome - Default Settings users can override Accessibility settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1266b519-e436-4698-8ff4-442acc97efd4","displayName":"Project Options","description":"Microsoft Project 2016\\Project Options","helpText":null,"parentCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["9ecb05b7-e942-4b60-9040-d612385f5c67","8e48532a-ff0e-4422-82e2-6956b6786005","623d41fb-000e-41d8-b955-373f8c700def","28c4859e-1faa-4b51-96cf-068cb4354093","84b7f123-e849-40f9-914b-4b97b57bd3b4","20ed0d61-bbf7-421e-8926-0921c7ff7e75","db47f067-f435-4095-8b98-aa3805bc0050","6ad0e199-ff50-4e86-b22f-b55ef4ff2329","3265b420-4c88-4f7b-92cc-4e23d9452eb1","5bd8c27a-0141-4bbf-93f7-214b2389ff2d"],"platforms":"windows10","technologies":"mdm"},{"id":"12ad5ec7-346d-4b8b-9eba-d826cdb61c31","displayName":"Trusted Locations","description":"Microsoft Access 2016\\Application Settings\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"a9edc695-b4a9-4111-b07d-627f934f5a1a","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","displayName":"Common Open File Dialog","description":"Administrative Templates Common Open File Dialog","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","displayName":"Customizable Error Messages","description":"Microsoft Word 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13123148-c522-437f-b316-d78f5cc0d28d","displayName":"Shared Workspace","description":"Microsoft Office 2016\\Global Options\\Customize\\Shared Workspace","helpText":null,"parentCategoryId":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["725adbdf-1eb8-45c4-8eb1-44747bd1615d"],"platforms":"windows10","technologies":"mdm"},{"id":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","displayName":"AirPlay","description":"AirPlay > AirPlay","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"132003c7-1130-4f59-96a7-dfb6adb8bd5d","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"13467142-14e7-4380-8573-4866e842c7f6","displayName":"Antivirus engine","description":"Microsoft Defender > Antivirus engine","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"135e4013-43b8-4227-99fd-54ddeac4e329","displayName":"Protected View","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"139974ad-f615-442b-b3dc-84a44e3ec663","displayName":"Experience","description":"Experience","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"139974ad-f615-442b-b3dc-84a44e3ec663","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13cc3b63-a150-4cf2-8d76-309975603c8e","displayName":"Loader Override Settings","description":"Microsoft Edge WebView2\\Loader Override Settings","helpText":null,"parentCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","rootCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13eb248a-4549-4d23-9ada-23b40edf36bf","displayName":"Reminder Options","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\Advanced\\Reminder Options","helpText":null,"parentCategoryId":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13f025df-7d3f-4ecd-bd38-d7af7853b66e","displayName":"Time Providers","description":"Administrative Templates Windows Time Service Time Providers","helpText":null,"parentCategoryId":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"13f62499-a266-42c8-a4dc-531efcea55cb","displayName":"Microsoft Edge Dev","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Dev","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"148a6f4e-8816-4c00-87a3-57481c85c331","displayName":"Startup Home page and New Tab page","description":"Google Google Chrome Startup Home page and New Tab page","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","displayName":"Kerberos","description":"Kerberos","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14df2cb2-fc75-43af-87f8-a1fbd56a64e3","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14fa4ad9-525c-440d-a295-a279c73f97f1","displayName":"Widgets","description":"Widgets","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14fa4ad9-525c-440d-a295-a279c73f97f1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","displayName":"Enterprise Cloud Print","description":"Enterprise Cloud Print","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"14fe5c02-d4f6-4f2a-9eae-2d60d111ee77","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","displayName":"Microsoft Lync Feature Policies","description":"Skype for Business 2016\\Microsoft Lync Feature Policies","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"151e95d3-64ec-424f-ba7e-4d1ba6ef5aa1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1551f6d3-415c-44a8-b184-393de7c42adf","displayName":"Advanced Error Reporting Settings","description":"Administrative Templates Windows Error Reporting Advanced Error Reporting Settings","helpText":null,"parentCategoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"156f2e6a-6638-4749-9f43-e7acc4aba762","displayName":"Windows Installer","description":"Administrative Templates Windows Installer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"15be55d8-7477-4274-9b09-b775bce68416","displayName":"Software Update Enforce Latest","description":"Declarative Device Management preview Software Update Enforce Latest","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1653fa6c-aa99-4918-92c7-1df85d8843e1","displayName":"Startup, home page and new tab page","description":"Microsoft Edge - Default Settings (users can override)\\Startup, home page and new tab page","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1671dfc3-a1dd-4178-9093-10fb6b62586a","displayName":"Cryptography","description":"Microsoft Project 2016\\Project Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"16ea64a1-563e-43cc-b34a-728c8e7cd13c","displayName":"Scareware Blocker settings","description":"Microsoft Edge Scareware Blocker settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"1720d60f-40a6-471c-8e4c-efbacaf46997","displayName":"Cryptography","description":"Microsoft Outlook 2016\\Security\\Cryptography","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff"],"platforms":"windows10","technologies":"mdm"},{"id":"174ffe92-3770-4688-aa21-85b7535cf374","displayName":"Printing","description":"Printing > Printing","helpText":null,"parentCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","displayName":"Install and Update Settings","description":"Visual Studio Install and Update Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"17bc9899-d157-4eac-a949-810b4a841e28","displayName":"Restrict File Download","description":"Administrative Templates Internet Explorer Security Features Restrict File Download","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"18296501-4825-47ea-835d-66a01aba9384","displayName":"Notification bar","description":"Administrative Templates Internet Explorer Security Features Notification bar","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1829cdc1-1bed-4058-9aba-9b778cd3d955","displayName":"Global Preferences","description":"Preferences > Global Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"183628a3-d0a5-47de-b444-e132d634ca38","displayName":"Server Settings","description":"Microsoft Excel 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"bc58391f-664c-42dd-9d18-269e65f324a7","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"184981d4-712b-425e-b0a3-93eac7fbd3ee","displayName":"Consent","description":"Administrative Templates Windows Error Reporting Consent","helpText":null,"parentCategoryId":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1851afa1-5177-4268-8dfc-5b5e1a17ff7f","displayName":"Remote Assistance","description":"Administrative Templates Remote Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"187e5f4f-a789-4487-a848-7bf0f41597c7","displayName":"Preferences","description":"Preferences","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":["c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","0a9f982a-3515-4728-a231-fa000eb9e550","1829cdc1-1bed-4058-9aba-9b778cd3d955"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"18893f00-c309-4695-bcaf-b66286ad99c1","displayName":"Camera","description":"Camera","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"18893f00-c309-4695-bcaf-b66286ad99c1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"18b972fd-74f2-4345-9449-087c80dd38a3","displayName":"Windows Boot Performance Diagnostics","description":"Administrative Templates Windows Boot Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"191a84f2-13b5-4609-808f-8b743b7f0247","displayName":"Microsoft Outlook","description":"Microsoft Outlook > Microsoft Outlook","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1942922a-cba9-44c8-871f-3d915c62bd06","displayName":"Help","description":"Microsoft Office 2016\\Help","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1943deba-33f7-4c3d-98c8-6b5319ec98ab","displayName":"Driver Installation","description":"Administrative Templates Driver Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1979a12b-2a72-438d-9de7-320d1b38e777","displayName":"Password","description":"Microsoft OneNote 2016\\OneNote Options\\Password","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"19ab385f-14f5-47cd-87b2-f4784eedcdd9","displayName":"Windows Media Digital Rights Management","description":"Administrative Templates Windows Media Digital Rights Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"19ba782c-3594-45da-b829-72b54f6d45c7","displayName":"Microsoft OneDrive","description":"Microsoft Office > Microsoft OneDrive","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1a0386fd-354b-441e-a0d6-1523c209dae7","displayName":"General","description":"Microsoft Publisher 2016\\Publisher Options\\General","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1a056b49-3fb9-4097-b286-c5f493208578","displayName":"Personal Hotspot","description":"Managed Settings Personal Hotspot","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"1a2a4fc8-c54b-4906-a422-7dd51a196211","displayName":"Setup","description":"Administrative Templates Event Log Service Setup","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ae8c95a-5748-4647-80f8-b447e60601a2","displayName":"Add-ins","description":"Microsoft OneNote 2016\\OneNote Options\\Add-ins","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","displayName":"Preferences","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["decab1d2-3474-4727-87c0-d0bc648f2458","2b03e224-c77c-4bb0-8491-cec0b64d9a86","d0a1763a-5cdf-4672-8596-435ec1d94b54","8e7b730f-c3c9-4e04-9e45-ce06be97908c","2fbb7677-651a-4b62-8b8c-d502ea29936b"],"platforms":"windows10","technologies":"mdm"},{"id":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","displayName":"Excel Options","description":"Microsoft Excel 2016\\Excel Options","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["9215e382-4e7b-4554-8c80-80277136b544","cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","67eb1dab-7805-41bb-af5a-798dc7e29f23","d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","5886bba1-bc05-46ca-afbf-66d1b4265ca4","a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","3503e1ba-8168-4b55-92b1-84613292cadc"],"platforms":"windows10","technologies":"mdm"},{"id":"1b97e23d-996f-4b8e-9abf-53cfa0fc8917","displayName":"Default message text for a reply...","description":"Microsoft Office 2016\\Collaboration Settings\\Default message text for a reply...","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","displayName":"Spelling","description":"Microsoft OneNote 2016\\OneNote Options\\Spelling","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","displayName":"Lanman Server","description":"Lanman Server","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1c3001ea-af28-4291-94b0-7f12ea93d3ca","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ccd3115-55e7-464f-9bb9-d38a92191306","displayName":"Edge Website Typo Protection settings","description":"Microsoft Edge - Default Settings users can override Edge Website Typo Protection settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1d5e7986-870c-444b-bf09-78bbf82a53fa","displayName":"Personal Data Encryption","description":"Personal Data Encryption","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1d5e7986-870c-444b-bf09-78bbf82a53fa","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1d6d392c-8b32-459b-b114-af964a4bbbc5","displayName":"Certificate management settings","description":"Google Google Chrome Certificate management settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","displayName":"Digital Locker","description":"Administrative Templates Digital Locker","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1dd655c9-a1f3-4780-befb-cab19922277d","displayName":"Personalization","description":"Personalization","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1dd655c9-a1f3-4780-befb-cab19922277d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1ed9f90e-d8b6-413f-bfc2-face955141bc","displayName":"Windows Mobility Center","description":"Administrative Templates Windows Mobility Center","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"1fbc29d7-0530-4208-b506-9df648a402e9","displayName":"Voice Roaming","description":"Managed Settings Voice Roaming","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","displayName":"Recovery Lock Password","description":"Recovery Lock Password","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"1fcd72cb-7c09-4e7b-a314-97a88df6e623","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"1fddd12c-a630-47f0-9633-638808e228f9","displayName":"Review Tab","description":"Microsoft Word 2016\\Review Tab","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["7bee4dea-82a4-4a03-b903-654b374819b1","d79c9f9a-f469-4f39-a66a-6f7d5ee77e81"],"platforms":"windows10","technologies":"mdm"},{"id":"20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a","displayName":"Platform Update","description":"Microsoft Defender Platform Update","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"20b71dc7-cf08-4534-9e52-d297dd071ca5","displayName":"Enhanced Phishing Protection","description":"Smart Screen\\ Enhanced Phishing Protection","helpText":null,"parentCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","rootCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20bacabf-cd07-48be-a184-f0ae76d31e4a","displayName":"Contact Tab","description":"Microsoft Office 2016\\Contact Card\\Contact Tab","helpText":null,"parentCategoryId":"5cd6dc4f-b231-449f-bc10-16041b73356a","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20ceae56-e189-46ec-a440-791ce7454017","displayName":"Printing","description":"Google Google Chrome - Default Settings users can override Printing","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","displayName":"Calculation","description":"Microsoft Project 2016\\Project Options\\Calculation","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","ed137c3d-d7bc-48f3-ad86-ff194fc6820d"],"platforms":"windows10","technologies":"mdm"},{"id":"2108b443-384c-4bb3-9b9f-acb4a754a86a","displayName":"Web Options...","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["56e510be-ca39-46a2-9eb2-6f1af6d4b16a","d804205d-6c12-4f40-86a0-aa5a5355370f"],"platforms":"windows10","technologies":"mdm"},{"id":"210b9c4d-e72a-45a4-97d3-339a6b30c49c","displayName":"Attack Surface Reduction","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard Attack Surface Reduction","helpText":null,"parentCategoryId":"ad84cea3-5664-4e42-a9d6-1446828bea45","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"216de445-a80d-4981-b151-3b4466edc808","displayName":"Extensions","description":"Google Google Chrome Extensions","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"224dc683-c0e0-4783-8ba8-8f02c76d161d","displayName":"Domains","description":"Networking > Domains","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"2257f7e1-3e88-4d4d-a666-437bbe42baca","displayName":"Applications","description":"Device Restriction Applications","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"22a2a407-0f28-481d-bdbe-1f9cb6d589c3","displayName":" EDR preferences","description":"Microsoft Defender EDR preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"22f2b16b-e1af-45fa-8d2f-687854b72c02","displayName":"Data Protection","description":"Data Protection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"22f2b16b-e1af-45fa-8d2f-687854b72c02","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","displayName":"Login","description":"Login","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":["9859957e-34f1-4669-9f95-2b7c79fff052","6efb8802-223a-46a7-b13f-a68f28f8b2c2","8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","0e937777-d01a-4180-a937-c2010451a529"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"2373de26-8270-4e74-a53f-9aeb55d5553c","displayName":"Microsoft AutoUpdate (MAU)","description":"Microsoft AutoUpdate (MAU)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"2373de26-8270-4e74-a53f-9aeb55d5553c","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"23c09e06-5bee-4b20-a391-36549bf0f620","displayName":"Signing","description":"Microsoft Office 2016\\Signing","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"23fd467e-24f8-4200-8b19-c6c11afa8926","displayName":"Security","description":"Microsoft Access 2016\\Application Settings\\Security","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["a9edc695-b4a9-4111-b07d-627f934f5a1a","7eaa5e09-e5ab-4051-b557-64a124ae497c"],"platforms":"windows10","technologies":"mdm"},{"id":"2461b964-02f6-4da2-921a-f7e8f868c69d","displayName":"Enhanced Storage Access","description":"Administrative Templates Enhanced Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"24b30053-14d2-4430-9966-281e926a6918","displayName":"Trusted Platform Module Services","description":"Administrative Templates Trusted Platform Module Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"24f6d328-64e7-4490-be38-452ac3b61f6f","displayName":"Trusted Catalogs","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Trusted Catalogs","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"251c6873-bf5b-4d85-8185-3c4973b6f33c","displayName":"Show","description":"Microsoft Project 2016\\Project Options\\View\\Show","helpText":null,"parentCategoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"253fda23-118b-48c7-b24a-27b8c93df41a","displayName":"Macro Security","description":"Microsoft Visio 2016\\Visio Options\\Security\\Macro Security","helpText":null,"parentCategoryId":"2ea63962-4cac-4a5c-9181-e6a364489db0","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2592e8ea-5eb0-482b-b41e-eab92f33ac07","displayName":"Planner Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Planner Options","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"25a84f2d-dbac-457e-b734-bc2605305f2b","displayName":"Cryptography","description":"Microsoft OneNote 2016\\OneNote Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"25df12bc-5ebd-4db2-8930-5d27690f3e60","displayName":"Message Format","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Internet Formatting\\Message Format","helpText":null,"parentCategoryId":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"264202da-475b-476e-bbc7-3c252f777145","displayName":"Device security group","description":"Device security group","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"264202da-475b-476e-bbc7-3c252f777145","childCategoryIds":[],"platforms":"windows10","technologies":"enrollment"},{"id":"269c487f-8902-486a-88dd-db9b9b4454b8","displayName":"Network protection","description":"Microsoft Defender Network protection","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"26c1af84-7c09-4910-8b2f-486072fef710","displayName":"Kiosk Browser","description":"Kiosk Browser","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"26c1af84-7c09-4910-8b2f-486072fef710","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"26dfd0a7-546b-4583-b0c7-85b98ac5a40c","displayName":"Tools | Macro","description":"Microsoft Project 2016\\Project Options\\Security\\Tools | Macro","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27087ae6-d02f-4b54-a143-6cde89c04989","displayName":"Device and Driver Compatibility","description":"Administrative Templates Device and Driver Compatibility","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2764869c-54a3-462b-bc72-c580621ab6bb","displayName":"Customize Ribbon","description":"Microsoft Visio 2016\\Visio Options\\Customize Ribbon","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27ccaa0b-8755-4116-a0e3-b5d21d68ab65","displayName":"Cryptography","description":"Microsoft Excel 2016\\Excel Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"27f47083-6e1b-4fc7-938b-ecd846b79d78","displayName":"Web Content Filter","description":"Declarative Device Management preview Web Content Filter","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"2806d29a-7c7a-4ff0-baa2-4a0044425ea6","displayName":"Default message text for a review request...","description":"Microsoft Office 2016\\Collaboration Settings\\Default message text for a review request...","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28831364-ca54-4f31-acca-1aa0c7a7d3d2","displayName":"Data Recovery","description":"Microsoft Excel 2016\\Data Recovery","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28ab8eed-623a-4e9b-813e-13256472dbaf","displayName":"Customizable Error Messages","description":"Microsoft PowerPoint 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"28c4859e-1faa-4b51-96cf-068cb4354093","displayName":"View","description":"Microsoft Project 2016\\Project Options\\View","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","251c6873-bf5b-4d85-8185-3c4973b6f33c"],"platforms":"windows10","technologies":"mdm"},{"id":"290ec637-e780-4e95-9834-6368ac0437d1","displayName":"Power Management","description":"Administrative Templates Power Management","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["3b64e99d-0359-4264-be38-c544c647f493","01da0c26-af30-4eb2-a899-7d5e7ecb9738","91c02e14-8848-485d-8844-b9933fa888ec","7226f8a2-c542-471a-8d9e-e0df527325d3","86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","5d03766c-9480-43f2-9e85-461a44c821d4"],"platforms":"windows10","technologies":"mdm"},{"id":"2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","displayName":"MIME to MAPI Conversion","description":"Microsoft Outlook 2016\\MIME to MAPI Conversion","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2a1bbe00-0730-430e-8d19-3eec2fd6b63c","displayName":"Device and Resource Redirection","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Device and Resource Redirection","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2af24920-f611-4f03-99a6-205773869ae6","displayName":"Protected Content","description":"Microsoft Edge Protected Content","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"2b03e224-c77c-4bb0-8491-cec0b64d9a86","displayName":"Contact Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Contact Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b3d275d-4a48-4ac8-9c14-4dc5aa20a80b","displayName":"Network Sharing","description":"Administrative Templates Network Sharing","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2b54b208-5459-4e40-8db1-002cb90495bc","displayName":"Windows Memory Leak Diagnosis","description":"Administrative Templates Windows Memory Leak Diagnosis","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2becddf1-d8ea-49ec-8560-c8c401faa9bb","displayName":"Printers","description":"Administrative Templates\\Printers","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2c156b7e-99c8-4a21-a828-4f9b94479b0d","displayName":"Time Zone","description":"Managed Settings Time Zone","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"2c43699e-90b5-4da6-9689-fe5ad3b25ac9","displayName":"Threats","description":"Administrative Templates Microsoft Defender Antivirus Threats","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","displayName":"Applications","description":"Microsoft Edge Update\\Applications","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":["3bb9ca38-645e-479c-ac5f-01959aec9c30","7b91ab31-7ed5-4de9-bd49-d04303fd3c74","13f62499-a266-42c8-a4dc-531efcea55cb","797ac384-f48e-4567-b931-33a6ce923b94"],"platforms":"windows10","technologies":"mdm"},{"id":"2cdd4a96-23c1-4419-b88c-41bbaa119e68","displayName":"Passcode","description":"Declarative Device Management (DDM)\\ Passcode","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"2d5a483f-b408-426d-9234-2883eae20afb","displayName":"Tools | Options | General | Web Options...","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8ee1d8d2-582f-401b-927a-993016f4290d","0775f21c-9ca1-446d-b1dc-3cea45f15605","eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","025c640e-51e2-4f04-85e3-a13f30b5e08c"],"platforms":"windows10","technologies":"mdm"},{"id":"2d6891a4-ee83-4e55-8e23-09513e1306e4","displayName":"Microsoft Office Document Cache","description":"Microsoft Office 2016\\Microsoft Office Document Cache","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2de362c7-2c4a-4b24-bda3-f82cb6ed5990","displayName":"Kerberos","description":"Administrative Templates Kerberos","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2e3f0407-6387-41b4-b6c2-ada4354be759","displayName":"Licensing Settings","description":"Microsoft Office 2016 (Machine)\\Licensing Settings","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2ea63962-4cac-4a5c-9181-e6a364489db0","displayName":"Security","description":"Microsoft Visio 2016\\Visio Options\\Security","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["f34e3da0-b440-43dc-a368-4fd39646a9c5","253fda23-118b-48c7-b24a-27b8c93df41a"],"platforms":"windows10","technologies":"mdm"},{"id":"2eed22da-106f-4c93-9a45-5ce803b50233","displayName":"Offline Editing","description":"Microsoft Visio 2016\\Visio Options\\Save\\Offline Editing","helpText":null,"parentCategoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","displayName":"Sudo","description":"Sudo","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"2f524350-1bdb-4eee-a96d-b656bc2b0d70","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f56761a-8e8b-4788-a589-a73ab91818e6","displayName":"Web Archives","description":"Microsoft Office 2016\\Web Archives","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f6205e9-8680-4b8f-97f3-be12e252e038","displayName":"Track changes and compare","description":"Microsoft Word 2016\\Word Options\\Track changes and compare","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2f85405a-7472-44ce-8c05-b59bb54912d5","displayName":"Playback","description":"Administrative Templates Windows Media Player Playback","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7","displayName":"Trusted Locations","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"2fbb7677-651a-4b62-8b8c-d502ea29936b","displayName":"E-mail Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["897675f9-0d1b-437b-ba0a-584fbd54df95","71f4af65-b7fa-4c54-bf73-19b0c7ffe162"],"platforms":"windows10","technologies":"mdm"},{"id":"304a579b-ff3b-4897-8bb8-5a1dda45356f","displayName":"Schedule options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Schedule\\Schedule options for Microsoft Project","helpText":null,"parentCategoryId":"db47f067-f435-4095-8b98-aa3805bc0050","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30918d48-dafd-4b25-be63-70f6c7ba8a3d","displayName":"Background Intelligent Transfer Service BITS","description":"Administrative Templates Background Intelligent Transfer Service BITS","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"30da5d88-cf03-41f4-ab55-51ead91b3844","displayName":"Trust Center","description":"Microsoft Publisher 2016\\Security\\Trust Center","helpText":null,"parentCategoryId":"0cea32b4-28be-4164-ae2a-6db33b9dadb7","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"31070051-859e-4d27-9df3-c07b8a2d2179","displayName":"Word Options","description":"Microsoft Word 2016\\Word Options","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["89be4acb-fdf9-447b-ad16-9a5af1d68b8b","ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","83087772-6560-4488-a1c5-bb6e4889e868","dc049161-17c6-411e-906b-a871b33651cd","bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","2f6205e9-8680-4b8f-97f3-be12e252e038","f9e53433-d8d9-4eaf-bdf3-d32de60d686e","7f07427b-9bc2-4bfc-a74e-1a1d8961bd89"],"platforms":"windows10","technologies":"mdm"},{"id":"311e1dac-a77c-4bc0-a376-35ad55923b7d","displayName":"Start","description":"Start","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"311e1dac-a77c-4bc0-a376-35ad55923b7d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"31d3b4c4-767e-403a-834c-51f3691bbf2b","displayName":"Security Center","description":"Administrative Templates Security Center","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"320ccaa3-a391-4d29-a9c4-594561f4104d","displayName":"Miscellaneous","description":"Microsoft Word 2016\\Miscellaneous","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["b206e4ef-a288-4fb7-a7ee-4a30b4df3b98"],"platforms":"windows10","technologies":"mdm"},{"id":"32180186-7378-4d45-b0cc-c533a124bdbc","displayName":"Access- Denied Assistance","description":"Administrative Templates Access- Denied Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","displayName":"General","description":"Microsoft Project 2016\\Project Options\\General","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["501e47c0-6c18-4a88-9366-adc0bbc2c9b4","0a6bc3ed-c4cd-4928-bcbf-247369a51515"],"platforms":"windows10","technologies":"mdm"},{"id":"32b20540-8fe9-4730-a4b0-ff41f6b13a97","displayName":"Windows System Responsiveness Performance Diagnostics","description":"Administrative Templates Windows System Responsiveness Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","displayName":"Microsoft Office 2016 (Machine)","description":"Microsoft Office 2016 (Machine)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":["712d184f-d9ac-45fc-9eea-aade3a22b55e","86dae9f9-7eb1-4566-8558-b63fa2e20fee","8c879ddf-7acf-45f3-81d3-2c78c7a1321b","f0190b73-0d5c-410e-bce1-e03aa1f62ed4","5d8272e2-1ed3-4a8d-9555-9a87fa13d078","2e3f0407-6387-41b4-b6c2-ada4354be759"],"platforms":"windows10","technologies":"mdm"},{"id":"3334730b-b9f7-4c99-bde8-57f6b2cd826f","displayName":"","description":"Administrative Templates","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33a43c22-104b-4683-995b-5652cfd5b490","displayName":"Windows AI","description":"Windows AI","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"33a43c22-104b-4683-995b-5652cfd5b490","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33b9194b-4027-4c23-b662-52f25db7f839","displayName":"International","description":"Microsoft Access 2016\\Application Settings\\International","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"33fb4f49-5c7f-472c-a0f3-e05646a55902","displayName":"Improved Error Reporting","description":"Microsoft Office 2016\\Improved Error Reporting","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"343eb575-3ac8-4da9-b66d-ce84b84be7c3","displayName":"Project Guide settings","description":"Microsoft Project 2016\\Project Options\\Interface\\Project Guide settings","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3453c694-bc38-4082-9d3d-886e385df927","displayName":"Event Viewer","description":"Administrative Templates Event Viewer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"349c31c1-9b5b-42c8-91f2-aa41f4a36a71","displayName":"Window Frame Coloring","description":"Administrative Templates Desktop Window Manager Window Frame Coloring","helpText":null,"parentCategoryId":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"34c07941-8f52-43ad-b0ca-a7284655afb4","displayName":"Office.com Sharing Service","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Office.com Sharing Service","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3503e1ba-8168-4b55-92b1-84613292cadc","displayName":"Advanced","description":"Microsoft Excel 2016\\Excel Options\\Advanced","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d"],"platforms":"windows10","technologies":"mdm"},{"id":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","displayName":"Editing Languages","description":"Microsoft Office 2016\\Language Preferences\\Editing Languages","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["60ea21c6-4c2b-4510-83f4-3a2d04fd99a0"],"platforms":"windows10","technologies":"mdm"},{"id":"3588f84a-69de-4900-910c-09a5b69e5d99","displayName":"Virtualization Based Technology","description":"Virtualization Based Technology","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3588f84a-69de-4900-910c-09a5b69e5d99","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"35f245bd-8d1f-424c-83de-a80be27a6a4e","displayName":"Desktop Alert","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Advanced E-mail Options\\Desktop Alert","helpText":null,"parentCategoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"361859d9-1382-47c3-b9ec-9251a62fbb25","displayName":"Time Machine","description":"User Experience > Time Machine","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","displayName":"System Policy Control","description":"System Policy","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":["763525a0-8456-4336-a8d1-392253e8fdd8","64538726-8745-4e7a-b370-332f725b58bf"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3634c01b-1a85-4f50-9f52-63bc10bf0e39","displayName":"Removed policies","description":"Google Google Chrome Removed policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"364787de-93e4-4fd6-9608-dce1ad8f88c2","displayName":"Windows Remote Management Win RM","description":"Administrative Templates Windows Remote Management Win RM","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["0f6d725e-2c2d-4926-8e78-3d2d5867eef5","b83cafe6-7d8b-4e3b-890d-ce50e548cfc6"],"platforms":"windows10","technologies":"mdm"},{"id":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","displayName":"Google Chrome","description":"Google Google Chrome","helpText":null,"parentCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["70498fad-5ddb-4730-8130-d755ff675760","5900ac65-f656-459c-bd82-1329a862544d","a5a38799-7bf1-4b83-86fe-62729cd9ed9d","216de445-a80d-4981-b151-3b4466edc808","4cd10f38-02cf-40f2-aa87-ad70a2190a1a","d4ad9168-8c49-45d6-a7e5-86ba990fff3e","8c35f124-e249-43e3-9044-ecc0b0a5855a","d9432f48-3072-4171-9031-4ebead394151","ac821e49-1996-4d6c-99d4-9c3c3e4737b6","fa2722a8-dcfd-4e14-a429-2b0041642c77","b46f4e70-d3d1-4177-8e22-62f806d4568c","10247787-95ea-4507-93de-dbd166df12b5","098942c3-afe3-40c8-823f-37f0b5b13ad4","62499519-97eb-43e7-ae96-d7909c5820d3","3634c01b-1a85-4f50-9f52-63bc10bf0e39","148a6f4e-8816-4c00-87a3-57481c85c331","4aa852ab-6269-4883-906f-0a0944fa1261","f66e6bf2-a437-4d36-b46c-e965b31a5d4f","da78ddbc-fc94-48f9-8808-4b160d6f1d50","1d6d392c-8b32-459b-b114-af964a4bbbc5","895e0884-6b60-4bb0-b2ab-3a1642103db7","b811c4fe-7ff0-4bd1-a454-0918d4e2f896","463e6791-7d54-4964-a36b-63bbedb7d0cd","f00e9baf-9bbf-48e4-aaac-57410730f016","59d29716-55b0-4014-a458-38b408ff9530","b485695b-0fae-41ae-861c-3030769b28df","5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","f7486553-9e63-4d63-9423-56e5ffe48700","93ed2300-658d-40f3-8211-9295a240579c"],"platforms":"windows10","technologies":"mdm"},{"id":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","displayName":"Trust Center","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"85810387-3320-4056-bae2-953beeb246f7","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["42ce9a9b-0574-4b5c-993b-7679de80be47","4d69af55-f100-45fa-92e1-56d46434c647","76ad3567-c6cb-43b5-b91d-a52a34853c03"],"platforms":"windows10","technologies":"mdm"},{"id":"395a548d-737b-41fe-8449-c68c51e3a349","displayName":"Input Panel","description":"Administrative Templates Input Panel","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"39e4c352-be9c-4e75-8111-8236279c7f1e","displayName":"Cloud Desktop","description":"Cloud Desktop","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"39e4c352-be9c-4e75-8111-8236279c7f1e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3a901a80-e2b6-470c-9658-d66ba5458370","displayName":"Remote App and Desktop Connections","description":"Administrative Templates Remote Desktop Services Remote App and Desktop Connections","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3abaf4c2-d5db-4b3b-a461-b1a208231b36","displayName":"Certificate management settings","description":"Microsoft Edge Certificate management settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3b2806c8-bd29-44b5-b3e0-b2c54a6008f3","displayName":"Scheduling options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Schedule\\Scheduling options for 'Project1'","helpText":null,"parentCategoryId":"db47f067-f435-4095-8b98-aa3805bc0050","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","displayName":"Account Management","description":"Account Management","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3b384fc5-5906-4dc4-bc48-a52b52fb054b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b64e99d-0359-4264-be38-c544c647f493","displayName":"Sleep Settings","description":"Administrative Templates Power Management Sleep Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3b7e16e7-171f-4169-8904-c8483b06700d","displayName":"Custom","description":"Microsoft Excel 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3ba8106d-4b2f-4775-939d-1cc8703a41dc","displayName":"Password manager and protection","description":"Microsoft Edge\\Password manager and protection","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3bb9ca38-645e-479c-ac5f-01959aec9c30","displayName":"Microsoft Edge","description":"Microsoft Edge Update\\Applications\\Microsoft Edge","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0","displayName":"Protection From Zone Elevation","description":"Administrative Templates Internet Explorer Security Features Protection From Zone Elevation","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3c46dc04-e649-41b9-be99-04b771303fdd","displayName":"eSIM","description":"eSIM","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3c46dc04-e649-41b9-be99-04b771303fdd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3c7f15ef-a539-411c-93f1-5f97b7bd5519","displayName":"Bluetooth","description":"Managed Settings Bluetooth","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3ccd987e-bfca-4838-98ea-576de34b3ebe","displayName":"Certain Hours","description":"Certain Hours","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3ccd987e-bfca-4838-98ea-576de34b3ebe","childCategoryIds":[],"platforms":"android,iOS","technologies":"exchangeOnline"},{"id":"3db7e884-6077-4b96-ace3-005a6b49ecc0","displayName":"Hyperlink appearance in 'Project1'","description":"Microsoft Project 2016\\Project Options\\Edit\\Hyperlink appearance in 'Project1'","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3edb2860-b77b-4240-af16-fb34d45d6ba1","displayName":"Performance","description":"Microsoft Edge\\Performance","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"3f216590-fb12-4f8e-924f-2a6895d94126","displayName":"Folder Home Pages for Outlook Special Folders","description":"Microsoft Outlook 2016\\Folder Home Pages for Outlook Special Folders","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3f56adc1-2207-4033-a6e2-07f64c08e3ff","displayName":"FileVault","description":"FileVault > FileVault","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"3f61a5fe-8508-44dd-bcf0-83273643026a","displayName":"Smart Screen","description":"Smart Screen","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"3f61a5fe-8508-44dd-bcf0-83273643026a","childCategoryIds":["20b71dc7-cf08-4534-9e52-d297dd071ca5"],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"3f693856-7cbb-4a1c-93be-0d05aa41059f","displayName":"i SCSI","description":"Administrative Templatesi SCSI","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["6c1d9109-e4d1-4718-a537-dd685464fdbe","ca1aedf4-b951-45f5-a77c-dec776a82e21","60ea8de3-bc6d-4b01-974a-a53860fe4ef6"],"platforms":"windows10","technologies":"mdm"},{"id":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","displayName":"Internet Control Panel","description":"Administrative Templates Internet Explorer Internet Control Panel","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["822bd634-4d01-486e-adad-8085968fd1c4","8d503574-f93a-4277-a30d-19895d46dd13"],"platforms":"windows10","technologies":"mdm"},{"id":"3f8986f3-195d-4ee5-ae8d-96a007b20883","displayName":"Windows Location Provider","description":"Administrative Templates Windows Location Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3fa63a9d-e22d-4fc8-8464-a13b56461115","displayName":"Predefined","description":"Microsoft Excel 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"3fbd3b29-bafd-4adf-89e4-3be612dee275","displayName":"Network settings","description":"Microsoft Edge Network settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"4086190d-2e5b-439d-8426-08492ebb8c9f","displayName":"Local Machine Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Local Machine Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"40c593b9-63cf-4b10-ad26-1ceb7c9491fe","displayName":"Disk NV Cache","description":"Administrative Templates Disk NV Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","displayName":"Explorer Frame Pane","description":"Administrative Templates Explorer Frame Pane","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"41ba590e-9105-4eda-92fb-13c7d34b8eee","displayName":"DC Locator DNS Records","description":"Administrative Templates Net Logon DC Locator DNS Records","helpText":null,"parentCategoryId":"8c30a64e-ad24-47a0-97a8-52320360fd88","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"425669eb-3a49-43d1-98a5-0fcc5b04ffcb","displayName":"Application Compatibility","description":"Administrative Templates Application Compatibility","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"428f107c-2167-4bc2-9293-8f1d6728a0c5","displayName":"Scan","description":"Administrative Templates Microsoft Defender Antivirus Scan","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"429c4b85-a2b4-46ed-afa0-6c89c08a5544","displayName":"AirPrint","description":"Printing > AirPrint","helpText":null,"parentCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"42a6198f-bdec-402e-b619-315400b65488","displayName":"Software Update","description":"Declarative Device Management (DDM) Software Update","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"42ce9a9b-0574-4b5c-993b-7679de80be47","displayName":"Protected View","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"42d8353a-a135-4c2d-8d06-c6cf9961c6c5","displayName":"Telemetry Dashboard","description":"Microsoft Office 2016\\Telemetry Dashboard","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43053249-ecd1-4d9f-9fa9-c05e7713da7f","displayName":"SharePoint Lists","description":"Microsoft Outlook 2016\\Account Settings\\SharePoint Lists","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43057320-7058-46d5-86f9-a56c80bbf8b9","displayName":"Private Network Request Settings","description":"Microsoft Edge\\ Private Network Request Settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","displayName":"Microsoft Edge - Default Settings (users can override)","description":"Microsoft Edge - Default Settings (users can override)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":["a877a2ff-f144-421f-814c-593e972a8a20","fea97af7-df89-4fde-8e2b-f8e7f7b6b741","6f1386e5-148d-4dc3-84d1-79df721e3233","1653fa6c-aa99-4918-92c7-1df85d8843e1","8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","48965ad9-3011-4722-855b-7179fef89954","b96b63eb-0292-4a73-85d7-c68d330c109e","7db75ddb-f702-49f8-ae2b-991d1afd2d17","acabc66f-5faf-4a13-af32-322ccfc1a5b3","1ccd3115-55e7-464f-9bb9-d38a92191306","6fafeb5c-65ce-4993-b421-46e60da69131","a7b038e5-3af5-41fe-919e-e8befe83a9a5","0d4cf1d9-d8ad-4628-bd71-fa0de6598f28","6b71fbf6-7156-471a-b488-3eece04bda86","04b46099-4ee5-4def-8e04-569c988057a9"],"platforms":"windows10","technologies":"mdm"},{"id":"439f715e-5511-44fd-9a0f-644ba7cc6baf","displayName":"Logon","description":"Administrative Templates Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43eca758-22c0-4625-8f12-85a8a34ea8b1","displayName":"Windows Logon Options","description":"Administrative Templates Windows Logon Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"43fc9dcc-1e66-4108-bded-2d005eeb7ccb","displayName":"Microsoft Edge WebView","description":"Microsoft Edge Update\\Microsoft Edge WebView","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"441d6cc4-e51f-453e-a44d-8394509415be","displayName":"Predefined","description":"Microsoft Publisher 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"444409a4-8b03-402d-91d0-1cd9565fb0fb","displayName":"Windows Color System","description":"Administrative Templates Windows Color System","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","displayName":"Business Data","description":"Microsoft Office 2016\\Business Data","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["a6e0cee7-34a0-4ca2-b4da-f819a057b532","952f69c8-2644-48df-976b-01fd624cbb3a","c72d9f00-d625-43ec-add4-514891035839"],"platforms":"windows10","technologies":"mdm"},{"id":"44774d3d-387b-4fa7-8de4-d82b039c06d1","displayName":"Display","description":"Microsoft OneNote 2016\\OneNote Options\\Display","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"449201b6-5002-42d1-85ed-d288fb6552da","displayName":"Smart Documents (Word, Excel)","description":"Microsoft Office 2016\\Smart Documents (Word, Excel)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44c15b2f-10da-4e1e-836b-8b71c19fe34c","displayName":"Internet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Internet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"44e27b70-4bdb-4aec-a75d-0568a1edc332","displayName":"Predefined","description":"Microsoft Word 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"740e7a10-3774-4a1c-9970-6907e0f0b848","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4560c525-12a1-4536-9cca-338330e58389","displayName":"Add-on Management","description":"Administrative Templates Internet Explorer Security Features Add-on Management","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"45a89c1f-0a34-4f78-b28f-d30b623fa423","displayName":"Identity and sign-in","description":"Microsoft Edge\\ Identity and sign-in","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"45d15759-2add-40db-9294-d1b391515dba","displayName":"Folder Redirection","description":"Administrative Templates Folder Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"45fe783f-a80b-42d9-ab3c-8c4081be8d05","displayName":"Carddav","description":"Accounts > CardDAV","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"463e6791-7d54-4964-a36b-63bbedb7d0cd","displayName":"Microsoft Active Directory management settings","description":"Google Google Chrome Microsoft Active Directory management settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"46af3391-ed6d-4ada-aef7-02dac2a1b136","displayName":"Xsan","description":"Xsan > Xsan","helpText":null,"parentCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"46eaa2b7-341b-4e39-be21-c3ea09dd5778","displayName":"Microsoft Edge Web View2 Runtime","description":"Microsoft Edge Update Microsoft Edge Web View2 Runtime","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"476e0bfc-ddb6-4612-8446-bed86e875141","displayName":"Fault Tolerant Heap","description":"Administrative Templates Fault Tolerant Heap","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"478ed057-8ee7-4dd2-8276-06dad8f85397","displayName":"Services","description":"Microsoft Office 2016\\Services","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["a5607145-2bd3-4473-a8ee-d7fa5c2f2675"],"platforms":"windows10","technologies":"mdm"},{"id":"479c2edd-6539-4e1d-96ba-518d6f6264c3","displayName":"Container and Directory Naming","description":"FS Logix Profile Containers Container and Directory Naming","helpText":null,"parentCategoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"486f25cc-c865-446e-95b2-c5b061883a7a","displayName":"I Pv6 Transition Technologies","description":"Administrative Templates TCPIP Settings I Pv6 Transition Technologies","helpText":null,"parentCategoryId":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48965ad9-3011-4722-855b-7179fef89954","displayName":"Games settings","description":"Microsoft Edge - Default Settings users can override Games settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"48b8705b-58a8-4504-ab7a-2704980f4577","displayName":"Microsoft Defender","description":"Microsoft Defender","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":["93099bd4-c685-434b-9d72-f0cb6db5e753","a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","22a2a407-0f28-481d-bdbe-1f9cb6d589c3","64c8233f-3057-4485-b902-d71a312318d7","d2191717-e304-46f7-bcc0-55e6477026c9","0e1122f8-2bbf-475b-bce0-9e43a2f5e475","13467142-14e7-4380-8573-4866e842c7f6","269c487f-8902-486a-88dd-db9b9b4454b8","d40a32e1-ab3e-4cbc-aa03-4766792e563e","67cd904c-78e0-4e77-9dd4-c713b21763f3","b77a3a7b-6fab-4240-b5c3-852aa78781d5","5c4df3be-80b0-40cc-a8c8-0258120b0de5","20af2e37-4e39-4e47-ba5d-d1cadbfb4b0a"],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"48be5f9d-4941-4189-8015-dd78f87aacd5","displayName":"Administrative Templates","description":"Administrative Templates","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["27087ae6-d02f-4b54-a143-6cde89c04989","6c7168c3-6f34-4086-af0b-ed0b74301dc9","7f363efe-1ea5-4eb8-baf7-8c34456b43fc","736134cb-4d82-427a-97b7-d219ac6a22f0","40c593b9-63cf-4b10-ad26-1ceb7c9491fe","005ddf8f-da22-4b23-ab02-289f8f6c7960","b3b2fc04-4b88-4a1c-8370-04573019eebe","9dbd66e3-4544-4ca8-a118-272c874bc684","e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","1ed9f90e-d8b6-413f-bfc2-face955141bc","476e0bfc-ddb6-4612-8446-bed86e875141","c6a912c5-0334-40fb-8dc5-f2d2547b8071","18b972fd-74f2-4345-9449-087c80dd38a3","19ab385f-14f5-47cd-87b2-f4784eedcdd9","2b54b208-5459-4e40-8db1-002cb90495bc","75e080fb-3ed7-4a73-a6e0-eb93f0119d68","88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","643081a4-132d-463e-9d86-c8650cb2a011","0937f5ff-aabc-49a9-a94f-6f98c4702580","86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","b6d13875-fd8e-41a0-a712-3dab8b75b93f","76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","5be35eeb-62e9-4317-8804-018a9dd31149","dd9a3dad-5851-4899-a5c1-c23318986846","9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","6424714c-e50a-4b53-acbf-8739825ebf0b","902f5df1-31d6-44ee-ba95-2561199db35f","785c6df2-c6d0-4d6e-bd73-c3b62caca754","94a92db4-8704-487b-b0c5-c15d6ac20e6d","788355e5-e113-4b17-ada9-fb5ef38bffa1","58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","72972c43-36a3-4034-8cc8-334c99087798","dab7104a-b79c-4318-afb0-5d5cfed9caa9","dc16dbf0-aac8-4ff3-a546-1ddb55650f47","05305a87-0b19-41bb-bf1e-0bd92bfcdc16","03a966f7-8f8e-4ecb-aab3-055fe907f5ab","5c9a2f21-d3a8-4295-a803-e0535aa29489","60b898a9-0490-4599-b7f1-3cd451236266","8c30a64e-ad24-47a0-97a8-52320360fd88","b524d6e2-75bc-4409-ae3d-07605707d7ee","a34ade49-964d-407c-9f60-2e8cd9dfef05","87667b72-85ce-48c2-8023-e6db7f5fe739","99b4ac32-50b5-4659-a7a1-94bc708ae71a","1dabc7da-bdf8-4c60-95de-427a4b2cb6bf","e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","edd1e620-09e1-47ea-abc8-1e241a174ed9","b40cfb22-8f17-4317-bcbb-c1c871497446","d982a1ef-84be-4832-99d4-8b71a4644b74","24b30053-14d2-4430-9966-281e926a6918","53ba922e-db4d-489c-b5ab-dbc4b8321206","cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","e3ca94a7-e506-4133-8fae-41931dc863a5","c859dc1a-fdeb-4591-af97-79d078ee715b","5133d5ea-1a12-494f-afb2-5cfaf41d9518","9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","f69e6993-2e88-4938-bfe5-cea9ab21a858","be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","0d37dddd-6575-485c-92dd-37a3c23edbf9","5536b5f4-3d31-4290-acea-9bef323bb83d","d52dd970-febb-4891-8eb7-1c8616cfb6cb","68a3b82d-d1f4-422d-bfee-2168ec260ad7","1851afa1-5177-4268-8dfc-5b5e1a17ff7f","3f8986f3-195d-4ee5-ae8d-96a007b20883","6bed088c-c9b0-4149-b26f-df0c247cdb5b","7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","4dd8280d-6c01-4a06-bfd1-e1cb4c529494","a7e7529f-1030-41da-8b4d-024e1c08bbac","4124fc05-5c98-4790-a2a9-4ba2dee3d9b3","b6bb653a-73f0-42f4-b097-1ce556310904","abf781d7-1179-4f24-8d01-5611db14eddc","ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","43eca758-22c0-4625-8f12-85a8a34ea8b1","5371d50c-0aaa-425a-a075-2cb1c59968b9","be9bdbec-b52e-4174-9c5b-cf765dee855b","8eed5d21-a5e9-4bc7-b2df-4526af3e2726","a57b27b6-48e0-42b2-812a-2be86c113a0c","99ba9e42-9872-4a03-a615-fc4a4cebc067","d0e46713-238c-42b7-a996-653cf952c367","d9f5ccc9-5180-43b7-9c81-89ac3364ce00","07c023d3-0899-40af-a04f-805876d99a9b","8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","08c4d8e5-ef84-4b98-a6b8-96a4b5a0c7b1","395a548d-737b-41fe-8449-c68c51e3a349","d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","daf3f2c8-f6a5-40bd-96b3-2c6a28931614","cebd5934-9dfe-4278-966d-b9d880cb30e7","3f693856-7cbb-4a1c-93be-0d05aa41059f","2de362c7-2c4a-4b24-bda3-f82cb6ed5990","c48917c1-fd99-405f-b1d2-9dfec169e5d8","fe3cb879-8869-4163-91d7-e432abd75da8","3334730b-b9f7-4c99-bde8-57f6b2cd826f","f14fcb64-a868-4531-a3b4-c3cdf03c2b99","3453c694-bc38-4082-9d3d-886e385df927","cc13d92c-673f-4af7-9748-50342fc8795a","31d3b4c4-767e-403a-834c-51f3691bbf2b","32180186-7378-4d45-b0cc-c533a124bdbc","4d36a1f3-29f9-45af-9480-32891a0bf8ef","290ec637-e780-4e95-9834-6368ac0437d1","909339a5-8f04-4fa2-8807-5d38c83ef547","1943deba-33f7-4c3d-98c8-6b5319ec98ab","50e243ad-0e21-43f5-b5dc-31ec61ee43d0","6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","4beed579-3d9c-4c6d-9e88-e7df5e2b4613","c9a65baa-de10-4818-97a2-b61babb28060","f926f6e3-1bd6-4259-ae7c-e14108568882","93c28398-faef-4ca5-9667-f5ed004da32c","023e0367-b563-4fae-8fb6-589c836ee223","56fdfd66-f34d-4bf8-b951-f130114ffb3d","2b3d275d-4a48-4ac8-9c14-4dc5aa20a80b","e042b102-b12c-48d1-86ef-f6d296da5b95","cef993dc-bf18-44f7-8e9f-465ef1a0f144","dbb76878-34a9-4f87-bbc6-4de7ea223ff4","364787de-93e4-4fd6-9608-dce1ad8f88c2","c01c7d3f-ace1-48bf-abce-e8a02ba877ab","2461b964-02f6-4da2-921a-f7e8f868c69d","088b8d8d-5f3f-4979-aa18-b3c4b2616a24","b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","e972d9fe-a9b7-4a65-a88f-0958fab19584","425669eb-3a49-43d1-98a5-0fcc5b04ffcb","12ec8efa-2dcc-4c0c-9166-72ecc3cd463e","f1278d6b-60ec-4369-88cf-21df47caaec6","6b87c5da-cfd9-44bc-be05-ed08eb2144c7","444409a4-8b03-402d-91d0-1cd9565fb0fb","30918d48-dafd-4b25-be63-70f6c7ba8a3d","6cd02266-a42f-4675-b83e-37360dbf3c68","45d15759-2add-40db-9294-d1b391515dba","2becddf1-d8ea-49ec-8560-c8c401faa9bb","930d2960-3f70-48ca-9ead-b65a5a037c07","156f2e6a-6638-4749-9f43-e7acc4aba762","e6b767af-2ce1-4c91-9360-15abbb0bf3bc","ffd1a98f-0fac-47fe-813f-7510d0dacbc3","ac0a894c-173a-48fc-b961-901f28463c77","634e4243-284b-4cb7-a7e6-08ca7e262937","f3027ba5-9a2f-42c6-9872-ec21f726929c","98dc5bd0-2b16-4263-ba2f-62115b680017","cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","d4c9d046-a8c0-46f0-bd62-bc4d1614e891","6d4184ab-a66c-47f1-b54e-af55f654e2a5","7d331987-7e2d-4975-b23b-d99a5af26ddf","6e1431f2-131e-4cf2-bb60-87b889f1d11b","439f715e-5511-44fd-9a0f-644ba7cc6baf","5dcea340-0469-4f43-b270-a49ed0597201","ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","60b55db1-53fc-45ea-93d3-e4372b1e19a5","90e3acc6-80d5-41b4-8141-a8620a211c0e","32b20540-8fe9-4730-a4b0-ff41f6b13a97","76c53aab-0288-4ac1-b399-0104e04c6457","9b894b32-3697-4a83-9731-3db2a35455ad","ad47f904-ede2-4b12-849e-bf751d88abf5","86e78a4b-706a-4ec8-be90-439461abb29d","751cf9ec-7214-4b38-a09e-24922684bd8f","fff51673-04b8-4277-98ef-4baffbd8d192","e50acc0f-d177-4803-aa31-fc97eeb60ff2","fe65603b-1980-446b-ae17-516eb885c6be"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"48cb2bee-74be-4165-bc19-89c5b1c50c00","displayName":"Email","description":"Email","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"48cb2bee-74be-4165-bc19-89c5b1c50c00","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","displayName":"Time Language Settings","description":"Time Language Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4a5a066e-27af-46c1-9714-9e4542ffc1f9","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","displayName":"Firewall","description":"Firewall","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4a5e4714-00ac-4793-b0cc-5049041b0ed7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"4a6c4488-bbcf-4b5b-9156-7aa1b10a6010","displayName":"DNS Proxy","description":"Declarative Device Management preview Network DNS Proxy","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"4a7b0e92-ba43-46aa-96e8-c5839dbcb524","displayName":"Note Flags","description":"Microsoft OneNote 2016\\OneNote Options\\Note Flags","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4a832199-a841-4b6a-84fa-51365902a742","displayName":"Places Bar Locations","description":"Microsoft Office 2016\\File Open/Save dialog box\\Places Bar Locations","helpText":null,"parentCategoryId":"92be4fc7-8095-441c-b52b-9861c21bc337","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4aa852ab-6269-4883-906f-0a0944fa1261","displayName":"Allow or deny screen capture","description":"Google Google Chrome Allow or deny screen capture","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4aec010d-487a-4752-8e66-aedb9e4fbb5a","displayName":"Customizable Error Messages","description":"Microsoft Office 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4b540860-0858-48f4-8830-18383bb1766f","displayName":"Licensing","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Licensing","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4beed579-3d9c-4c6d-9e88-e7df5e2b4613","displayName":"Scripts","description":"Administrative Templates Scripts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4c604a0e-9339-4c01-9536-b689bd0abe5f","displayName":"Remote Desktop Connection Client","description":"Administrative Templates Remote Desktop Services Remote Desktop Connection Client","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4ca3b8c7-0350-4043-b96d-918f24df0a3b","displayName":"DSCP value of conforming packets","description":"Administrative Templates Qo S Packet Scheduler DSCP value of conforming packets","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4cd10f38-02cf-40f2-aa87-ad70a2190a1a","displayName":"Protected Content","description":"Google Google Chrome Protected Content","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4d36a1f3-29f9-45af-9480-32891a0bf8ef","displayName":"Credentials Delegation","description":"Administrative Templates Credentials Delegation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4d69af55-f100-45fa-92e1-56d46434c647","displayName":"File Block Settings","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4dae3032-1f16-4ace-911b-a957db0b8089","displayName":"AutoFormat as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type","helpText":null,"parentCategoryId":"dc049161-17c6-411e-906b-a871b33651cd","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["62492a4c-fd70-4275-ae5e-d60e200e3553","b6cafb2c-81be-40cf-90d8-788f713f7099","e8ce968b-91cb-4301-ba98-b37d42bc5213"],"platforms":"windows10","technologies":"mdm"},{"id":"4dd8280d-6c01-4a06-bfd1-e1cb4c529494","displayName":"Wireless Display","description":"Administrative Templates Wireless Display","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e0d279d-5ddd-4c4e-8590-6ed92129444d","displayName":"Customize","description":"Microsoft Office 2016\\Global Options\\Customize","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["13123148-c522-437f-b316-d78f5cc0d28d"],"platforms":"windows10","technologies":"mdm"},{"id":"4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","displayName":"RSS Feeds","description":"Microsoft Outlook 2016\\Account Settings\\RSS Feeds","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e4deef0-4528-47d5-8869-4143c506f18b","displayName":"Custom","description":"Microsoft Visio 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e62ada2-f091-49e1-99dd-ffdf5cf558cd","displayName":"General Options","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\General Options","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4e8db19c-cb8e-4361-8849-1d435d50bb66","displayName":"Handwriting","description":"Handwriting","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4e8db19c-cb8e-4361-8849-1d435d50bb66","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f081af6-7b21-44fc-8dd9-d4e0a61a474d","displayName":"Control Policy Conflict","description":"Control Policy Conflict","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4f081af6-7b21-44fc-8dd9-d4e0a61a474d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f29ef5c-6ca0-4b09-893f-01755a670877","displayName":"System Services","description":"System Services","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"4f29ef5c-6ca0-4b09-893f-01755a670877","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"4f671de2-9777-4969-acf3-8d90c733434c","displayName":"Escrow Certificates","description":"Microsoft Office 2016\\Security Settings\\Escrow Certificates","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"500d2bb1-5186-447c-818f-401f2d9065ce","displayName":"Windows Logon","description":"Windows Logon","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"500d2bb1-5186-447c-818f-401f2d9065ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5011ca61-1a58-42da-9c66-7763236acc84","displayName":"Streaming","description":"Administrative Templates App-V Streaming","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"501b5a30-253c-48b7-ab40-de1d100e4358","displayName":"Microsoft Teams","description":"Microsoft Teams","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"501b5a30-253c-48b7-ab40-de1d100e4358","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"501e47c0-6c18-4a88-9366-adc0bbc2c9b4","displayName":"General options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\General\\General options for Microsoft Project","helpText":null,"parentCategoryId":"3265b420-4c88-4f7b-92cc-4e23d9452eb1","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"508b2c0e-f572-4a50-93bf-566e5b827c0e","displayName":"Printers","description":"Printers","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"508b2c0e-f572-4a50-93bf-566e5b827c0e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"50b4bc60-802c-477a-9366-80e09154595f","displayName":"Security Settings","description":"Microsoft Office 2016\\Security Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["4f671de2-9777-4969-acf3-8d90c733434c","512f133b-9d53-46b8-834f-52501f9b6527","efb8c441-bad5-4e2f-b07c-5ac299cf3d22"],"platforms":"windows10","technologies":"mdm"},{"id":"50e243ad-0e21-43f5-b5dc-31ec61ee43d0","displayName":"Lanman Server","description":"Administrative Templates Lanman Server","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"512f133b-9d53-46b8-834f-52501f9b6527","displayName":"Digital Signatures","description":"Microsoft Office 2016\\Security Settings\\Digital Signatures","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5133d5ea-1a12-494f-afb2-5cfaf41d9518","displayName":"Hardware Buttons","description":"Administrative Templates Hardware Buttons","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"517e55f5-729f-4b4d-9555-33baa95a0e5a","displayName":"Application Guard","description":"Microsoft Office 2016\\Security Settings\\Trust Center\\Application Guard","helpText":null,"parentCategoryId":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"51e0cebb-cac4-4905-9b31-539295e4b85b","displayName":"Proofing","description":"Microsoft Publisher 2016\\Publisher Options\\Proofing","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5214f1e7-a5a9-4de5-80b4-2f7084a8d068","displayName":"Accounts","description":"Accounts > Accounts","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"522c3302-7a25-4904-a274-66cef9fd6aa0","displayName":"Microsoft Office","description":"Microsoft Office","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":["19ba782c-3594-45da-b829-72b54f6d45c7","b5169b74-41be-460a-9402-b13b6c22582b","191a84f2-13b5-4609-808f-8b743b7f0247"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5261c543-0bf4-49a8-9657-45e2044420d1","displayName":"Messaging","description":"Messaging","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5261c543-0bf4-49a8-9657-45e2044420d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"526e363a-84db-4256-a13c-e01c8c646e26","displayName":"Idle Browser Actions","description":"Microsoft Edge Idle Browser Actions","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","displayName":"Remote Remediation","description":"Remote Remediation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"52e76943-bfc9-4fb5-bdc8-5d4e8c6a436e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5371d50c-0aaa-425a-a075-2cb1c59968b9","displayName":"MS Security Guide","description":"Administrative Templates\\MS Security Guide","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"53ba922e-db4d-489c-b5ab-dbc4b8321206","displayName":"Microsoft User Experience Virtualization","description":"Administrative Templates Microsoft User Experience Virtualization","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5966d21b-220b-4937-9323-c6dd46cda942","c0ea0178-ad93-4596-94b2-9d7d1bbe8789"],"platforms":"windows10","technologies":"mdm"},{"id":"5401711f-292a-487a-be18-f99593a0477c","displayName":"Font","description":"System Configuration\\ Font","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5454d0eb-7eaa-4500-a1fb-f69b76aed740","displayName":"Connections","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Connections","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"54f2e032-bdcc-4877-b7a0-973d0a7c1653","displayName":"Startup Home page and New Tab page","description":"Google Google Chrome - Default Settings users can override Startup Home page and New Tab page","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5536b5f4-3d31-4290-acea-9bef323bb83d","displayName":"Ctrl Alt Del Options","description":"Administrative Templates Ctrl Alt Del Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55a61bb8-e023-4741-8213-99995c5902e5","displayName":"System","description":"Administrative Templates Event Log Service System","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55c888df-44ff-49d1-808e-ad9cb8429aff","displayName":"Device Health Monitoring","description":"Device Health Monitoring","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"55c888df-44ff-49d1-808e-ad9cb8429aff","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"55eebd7c-beb9-48b6-907f-df4997e18bdb","displayName":"Predefined","description":"Microsoft Access 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"b8158968-c839-4d37-9eb8-887bd6fd7402","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56c54112-2991-4bda-9e01-e6868bd07726","displayName":"Printer Provisioning","description":"Printer Provisioning","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"56c54112-2991-4bda-9e01-e6868bd07726","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56e510be-ca39-46a2-9eb2-6f1af6d4b16a","displayName":"Browser","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...\\Browser","helpText":null,"parentCategoryId":"2108b443-384c-4bb3-9b9f-acb4a754a86a","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"56fdfd66-f34d-4bf8-b951-f130114ffb3d","displayName":"Branch Cache","description":"Administrative Templates Branch Cache","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"57514d69-d9b1-469a-9b54-b5e94320c2a1","displayName":"Windows Subsystem For Linux","description":"Windows Subsystem For Linux","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","childCategoryIds":["a787672d-4a33-455b-a2db-e340eb35a5c8"],"platforms":"windows10","technologies":"mdm"},{"id":"577d5951-fc56-4906-90bc-2c508c6611ad","displayName":"Microsoft Defender for Endpoint","description":"Microsoft Defender for Endpoint","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"577d5951-fc56-4906-90bc-2c508c6611ad","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"579d6272-8708-4b22-a352-89cbd705ca82","displayName":"Security","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Security","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"58111f34-e9ac-47e2-b8ae-8d55c6a9ed6c","displayName":"Credential User Interface","description":"Administrative Templates Credential User Interface","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5838ed03-2902-4931-92cf-e349ab09c9b8","displayName":"PowerPoint Designer","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\PowerPoint Designer","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5886bba1-bc05-46ca-afbf-66d1b4265ca4","displayName":"General","description":"Microsoft Excel 2016\\Excel Options\\General","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"58ae30f4-10a2-4144-a593-b5f5bd93c10d","displayName":"Locked- Down Trusted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Trusted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5900ac65-f656-459c-bd82-1329a862544d","displayName":"Deprecated policies","description":"Google Google Chrome Deprecated policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5966d21b-220b-4937-9323-c6dd46cda942","displayName":"Applications","description":"Administrative Templates Microsoft User Experience Virtualization Applications","helpText":null,"parentCategoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5995d2ad-5ec7-49d2-ada2-d9c2b57746ba","displayName":"Directory Service","description":"Authentication > Directory Service","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"59c9b1c4-1757-4cf3-9b27-954dafe016d5","displayName":"Trust Center","description":"Microsoft Office 2016\\Privacy\\Trust Center","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"59d29716-55b0-4014-a458-38b408ff9530","displayName":"Content settings","description":"Google Google Chrome Content settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5b1be2c5-9939-4b2e-b29b-b22069455c90","displayName":"Microsoft Save As PDF and XPS add-ins","description":"Microsoft Office 2016\\Microsoft Save As PDF and XPS add-ins","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","displayName":"FileVault Options","description":"FileVault > FileVault Options","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"5b832259-c30b-43bb-b249-9d3ea4d5b028","displayName":"Customizable Error Messages","description":"Microsoft Excel 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bb9fb31-007d-4e3f-967b-11e865fcdc70","displayName":"Group Policy snap-in extensions","description":"Administrative Templates Group Policy Group Policy snap-in extensions","helpText":null,"parentCategoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bd0eaf1-1818-44e8-9168-fc75c5739cc8","displayName":"Application Guard settings","description":"Microsoft Edge\\Application Guard settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","displayName":"Edit","description":"Microsoft Project 2016\\Project Options\\Edit","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["d33133b4-77df-429a-9580-ed70f7da676d","06c4a76a-805b-4370-9d80-08e720ab2305","3db7e884-6077-4b96-ace3-005a6b49ecc0"],"platforms":"windows10","technologies":"mdm"},{"id":"5be35eeb-62e9-4317-8804-018a9dd31149","displayName":"Online Assistance","description":"Administrative Templates Online Assistance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5bf4c2ba-be08-4cda-bf33-d10707580d78","displayName":"Present Online","description":"Microsoft Office 2016\\Present Online","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["0be98651-a552-4470-b2dc-71c66a5ce1e6"],"platforms":"windows10","technologies":"mdm"},{"id":"5c4224e0-6a48-4665-9332-958d98124157","displayName":"File Block Settings","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c4df3be-80b0-40cc-a8c8-0258120b0de5","displayName":"Tamper protection","description":"Microsoft Defender Tamper protection","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"5c645a3e-bc39-44e9-8786-4c82e0553d22","displayName":"ODFC Containers","description":"FS Logix ODFC Containers","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["0bae3158-5f75-4e25-acf4-859d2612f892","81eb92d0-acda-4ea2-8183-29ed5457276b"],"platforms":"windows10","technologies":"mdm"},{"id":"5c722b3f-9d77-428a-b859-3fb556162cd6","displayName":"Cellular","description":"Networking > Cellular","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"5c9a2f21-d3a8-4295-a803-e0535aa29489","displayName":"System Restore","description":"Administrative Templates System Restore","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5c9e9aaf-a36c-437f-b85a-cb78a527a80f","displayName":"Content Cache Settings","description":"Declarative Device Management preview Content Cache Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"macOS","technologies":"appleRemoteManagement"},{"id":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","displayName":"Auditing","description":"Auditing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5cb7f4f0-ef00-4eb3-80f4-2c2b97b053ea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"5cd6dc4f-b231-449f-bc10-16041b73356a","displayName":"Contact Card","description":"Microsoft Office 2016\\Contact Card","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["20bacabf-cd07-48be-a184-f0ae76d31e4a"],"platforms":"windows10","technologies":"mdm"},{"id":"5d03766c-9480-43f2-9e85-461a44c821d4","displayName":"Button Settings","description":"Administrative Templates Power Management Button Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d4e843b-2848-4508-9143-cb3217c2fe83","displayName":"RDP Shortpath","description":"Administrative Templates Windows Components Remote Desktop Services Remote Desktop Session Host Azure Virtual Desktop RDP Shortpath","helpText":null,"parentCategoryId":"845ff38a-408b-449c-9ef3-7fdc331027df","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d8272e2-1ed3-4a8d-9555-9a87fa13d078","displayName":"Customize","description":"Microsoft Office 2016 (Machine)\\Global Options\\Customize","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","displayName":"Browser","description":"Browser","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5d835ac8-2e5e-4887-8e4d-0c3846d0ad9f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"5dcea340-0469-4f43-b270-a49ed0597201","displayName":"Mitigation Options","description":"Administrative Templates Mitigation Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","displayName":"Other","description":"Microsoft Outlook 2016\\Outlook Options\\Other","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["f29a5e42-24f5-47fb-bdcf-9ed9418035ee","6535c74f-74ac-4713-9c7a-ae15f62e97aa"],"platforms":"windows10","technologies":"mdm"},{"id":"5e692f3e-1911-43b0-9192-64c2e65b7c10","displayName":"Education","description":"Education","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5e692f3e-1911-43b0-9192-64c2e65b7c10","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","displayName":"Downloads","description":"Microsoft Edge Downloads","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","displayName":"Microsoft Visio 2016","description":"Microsoft Visio 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["c67c9e69-6e69-4b63-868c-3b3df5d17e47","f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","d5b3cab7-d486-4f74-8525-6bd740b950bc","e6f727b7-f474-4010-b214-83149ffdac2b"],"platforms":"windows10","technologies":"mdm"},{"id":"5ee1e57c-db64-4f8e-a9ec-5308b5c633c4","displayName":"Generative AI","description":"Google Google Chrome Generative AI","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","displayName":"OneDrive","description":"OneDrive","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"5ee629c1-94da-49b3-b7a1-a24b279f36d4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5f048379-3a42-43f0-9fd5-d269f292aa35","displayName":"Workflow Cache","description":"Microsoft Office 2016\\Miscellaneous\\Workflow Cache","helpText":null,"parentCategoryId":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","displayName":"Remote Session Environment","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Remote Session Environment","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["b7bde490-eac6-4f57-8808-e0786b8191a1"],"platforms":"windows10","technologies":"mdm"},{"id":"5f71c40e-01aa-42d2-9c8c-7d560126cd4b","displayName":"App Analytics","description":"Managed Settings App Analytics","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","displayName":"Trust Center","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["fe786056-6f4a-4d16-bff4-5fbb640308d2","c8cdd1a5-3f43-47c5-a775-d27bba4411f5","8391e79d-d618-47c3-979c-83544da43739"],"platforms":"windows10","technologies":"mdm"},{"id":"607a1c39-a3db-496f-8db6-c99d67f5f76c","displayName":"Tools | Security","description":"Microsoft Access 2016\\Tools | Security","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["a788a6e5-ab3f-41e5-96c8-ee59627dcb4d"],"platforms":"windows10","technologies":"mdm"},{"id":"60b55db1-53fc-45ea-93d3-e4372b1e19a5","displayName":"Shutdown","description":"Administrative Templates Shutdown","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60b898a9-0490-4599-b7f1-3cd451236266","displayName":"Microsoft account","description":"Administrative Templates Microsoft account","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60ea21c6-4c2b-4510-83f4-3a2d04fd99a0","displayName":"Enabled Editing Languages","description":"Microsoft Office 2016\\Language Preferences\\Editing Languages\\Enabled Editing Languages","helpText":null,"parentCategoryId":"3512a9f5-d692-4a1f-aedd-1bd431ae893e","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"60ea8de3-bc6d-4b01-974a-a53860fe4ef6","displayName":"i SCSI Target Discovery","description":"Administrative Templatesi SCS Ii SCSI Target Discovery","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"61ecc5ec-c494-420b-a27b-a8d2fbdd7df1","displayName":"E-mail Options","description":"Microsoft Word 2016\\Word Options\\Advanced\\E-mail Options","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"622c83ff-f780-47e6-8b9c-bf82552e3f04","displayName":"Scripted Window Security Restrictions","description":"Administrative Templates Internet Explorer Security Features Scripted Window Security Restrictions","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"623d41fb-000e-41d8-b955-373f8c700def","displayName":"Security","description":"Microsoft Project 2016\\Project Options\\Security","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["26dfd0a7-546b-4583-b0c7-85b98ac5a40c","cc50f179-0c39-4486-a555-de5a6e6ed365","1671dfc3-a1dd-4178-9093-10fb6b62586a"],"platforms":"windows10","technologies":"mdm"},{"id":"62492a4c-fd70-4275-ae5e-d60e200e3553","displayName":"Apply as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Apply as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"62499519-97eb-43e7-ae96-d7909c5820d3","displayName":"Printing","description":"Google Google Chrome Printing","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","displayName":"Remote Desktop Session Host","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5f28f9ff-58f8-43af-9692-3d06e083bbd9","579d6272-8708-4b22-a352-89cbd705ca82","b40b8f80-c0e6-4494-8085-f90cadc167a9","89ad0055-1603-420e-940d-9944a63e3da9","5454d0eb-7eaa-4500-a1fb-f69b76aed740","ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","f1455024-7de9-448f-8d8f-a42db2af0a35","4b540860-0858-48f4-8830-18383bb1766f","0bf6e038-dc12-44c3-94fb-e5c4ffe6375c","2a1bbe00-0730-430e-8d19-3eec2fd6b63c"],"platforms":"windows10","technologies":"mdm"},{"id":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","displayName":"Security","description":"Security","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":["d68abc4d-559a-4339-be48-c41a77a87034","8abddb23-7036-4ba8-8912-529279a849ea","f4a8384f-9e4e-4fc6-9ee2-28fa5260347a"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"634e4243-284b-4cb7-a7e6-08ca7e262937","displayName":"Attachment Manager","description":"Administrative Templates Attachment Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63b9904f-bbdf-4461-954a-c1d67fa8b357","displayName":"File Explorer","description":"File Explorer","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"63b9904f-bbdf-4461-954a-c1d67fa8b357","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","displayName":"IMAP","description":"Microsoft Outlook 2016\\Account Settings\\IMAP","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"63e167a4-65be-4d34-9e9c-186466f2b064","displayName":"Troubleshooting","description":"Troubleshooting","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"63e167a4-65be-4d34-9e9c-186466f2b064","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6424714c-e50a-4b53-acbf-8739825ebf0b","displayName":"Personalization","description":"Administrative Templates Personalization","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"643081a4-132d-463e-9d86-c8650cb2a011","displayName":"Network Provider","description":"Administrative Templates Network Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"64538726-8745-4e7a-b370-332f725b58bf","displayName":"System Policy Managed","description":"System Policy > System Policy Managed","helpText":null,"parentCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"64c8233f-3057-4485-b902-d71a312318d7","displayName":"Scheduled scan configuration","description":"Microsoft Defender Scheduled scan configuration","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","displayName":"Network Isolation","description":"Network Isolation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"64cf78b2-0594-4178-8e80-bdfe3dc38e63","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"65087b94-7e45-4d74-a50d-df4377b67499","displayName":"Parental Controls Dictionary","description":"Parental Controls > Parental Controls Dictionary","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"652a676c-9d60-4c9a-88b6-823a24961a9b","displayName":"Copilot Settings","description":"Visual Studio Copilot Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6535c74f-74ac-4713-9c7a-ae15f62e97aa","displayName":"Advanced","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\Advanced","helpText":null,"parentCategoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["13eb248a-4549-4d23-9ada-23b40edf36bf"],"platforms":"windows10","technologies":"mdm"},{"id":"66395272-f132-4170-b88e-87f794f987f4","displayName":"File Locations","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\File Locations","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"66615d2a-fec9-47f1-8eaf-9813e30cc023","displayName":"Extensions","description":"Microsoft Edge\\Extensions","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"66c92e07-234b-4992-a081-9afe4c113ba3","displayName":"SCEP certificate","description":"SCEP certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"66c92e07-234b-4992-a081-9afe4c113ba3","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6730f0be-a129-4b48-942f-e4ddf69fee66","displayName":"Customizable Error Messages","description":"Microsoft Access 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"67cd904c-78e0-4e77-9dd4-c713b21763f3","displayName":"User interface preferences","description":"Microsoft Defender > User interface preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"67eb1dab-7805-41bb-af5a-798dc7e29f23","displayName":"Autocorrect Options","description":"Microsoft Excel 2016\\Excel Options\\Proofing\\Autocorrect Options","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"68237832-f376-4f0e-ba26-4e06fce7a35d","displayName":"Device Installation Restrictions","description":"Administrative Templates Device Installation Device Installation Restrictions","helpText":null,"parentCategoryId":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"686ae3dd-a663-4484-854e-8f8d578fe3b8","displayName":"Converters","description":"Microsoft PowerPoint 2016 (Machine)\\Converters","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"686ae3dd-a663-4484-854e-8f8d578fe3b8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"68a3b82d-d1f4-422d-bfee-2168ec260ad7","displayName":"Portable Operating System","description":"Administrative Templates Portable Operating System","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69931627-230d-4df9-bbef-e3eac64ea8ef","displayName":"Additional Actions","description":"Microsoft Office 2016\\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)\\Additional Actions","helpText":null,"parentCategoryId":"8084033c-156a-4d1b-ab0b-159541810459","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","displayName":"Advanced","description":"Microsoft Publisher 2016\\Publisher Options\\Advanced","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["77b0357b-412e-4a81-9469-e20a5f1345fd"],"platforms":"windows10","technologies":"mdm"},{"id":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","displayName":"Save","description":"Microsoft Project 2016\\Project Options\\Save","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["dfd5d749-c68c-448f-ab3f-851c09f09df4","e13ec567-e29c-4ca0-b599-e8c43587f10a","d679b407-a753-40aa-bc9f-175f363b0eff"],"platforms":"windows10","technologies":"mdm"},{"id":"6ae0d607-832c-403b-b3bc-c563e390ebad","displayName":"Save/Open","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Save/Open","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","displayName":"Server Settings","description":"Microsoft Office 2016\\Server Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8e143bee-82fa-4e45-8bd0-c4032b0182d2"],"platforms":"windows10","technologies":"mdm"},{"id":"6b71fbf6-7156-471a-b488-3eece04bda86","displayName":"Printing","description":"Microsoft Edge - Default Settings (users can override)\\Printing","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","displayName":"Tools | Options | Spelling","description":"Microsoft Office 2016\\Tools | Options | Spelling","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["df357f0c-78fe-4aee-a465-f3da7499077e"],"platforms":"windows10","technologies":"mdm"},{"id":"6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","displayName":"Math Settings","description":"Declarative Device Management preview Math Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"6b87c5da-cfd9-44bc-be05-ed08eb2144c7","displayName":"User Accounts","description":"Administrative Templates User Accounts","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6b8ac32e-6bda-4eb4-b9e3-3d39ad8ce623","displayName":"Desktop","description":"Administrative Templates\\Desktop","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6bed088c-c9b0-4149-b26f-df0c247cdb5b","displayName":"Network Connectivity Status Indicator","description":"Administrative Templates Network Connectivity Status Indicator","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c142a01-47fa-422d-8135-29e81bc970cc","displayName":"Conversion Service","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\Conversion Service","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c1d9109-e4d1-4718-a537-dd685464fdbe","displayName":"i SCSI Security","description":"Administrative Templatesi SCS Ii SCSI Security","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6c7168c3-6f34-4086-af0b-ed0b74301dc9","displayName":"Security Settings","description":"Administrative Templates Service Control Manager Settings Security Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6cd02266-a42f-4675-b83e-37360dbf3c68","displayName":"WLAN Media Cost","description":"Administrative Templates WLAN Service WLAN Media Cost","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d1e32eb-61f7-4907-b9fe-b83fda8ad67d","displayName":"Customize Ribbon","description":"Microsoft Publisher 2016\\Publisher Options\\Customize Ribbon","helpText":null,"parentCategoryId":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d4184ab-a66c-47f1-b54e-af55f654e2a5","displayName":"Hotspot Authentication","description":"Administrative Templates Hotspot Authentication","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6d529e48-5477-4ceb-8ff7-c6e959a0e24f","displayName":"Related Website Sets Settings","description":"Microsoft Edge Related Website Sets Settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"6d6b289c-c1e9-4004-b5ab-3123920cf10d","displayName":"Password manager","description":"Google Google Chrome - Default Settings users can override Password manager","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6e1431f2-131e-4cf2-bb60-87b889f1d11b","displayName":"Link- Layer Topology Discovery","description":"Administrative Templates Link- Layer Topology Discovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6efb8802-223a-46a7-b13f-a68f28f8b2c2","displayName":"Login Items","description":"Login > Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"6f0e6df6-8654-4b57-b1d5-2160c5a0a54e","displayName":"Pen Flicks Learning","description":"Administrative Templates Pen Flicks Learning","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6f1386e5-148d-4dc3-84d1-79df721e3233","displayName":"Default search provider","description":"Microsoft Edge - Default Settings (users can override)\\Default search provider","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6fafeb5c-65ce-4993-b421-46e60da69131","displayName":"HTTP authentication","description":"Microsoft Edge - Default Settings (users can override)\\HTTP authentication","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"6fd44fd0-80d1-47a0-acad-c115e5b807b6","displayName":"General","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Advanced\\Web Options...\\General","helpText":null,"parentCategoryId":"76b233cc-f977-4305-b02f-deef6667251d","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70498fad-5ddb-4730-8130-d755ff675760","displayName":"Default search provider","description":"Google Google Chrome Default search provider","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70b0e7ef-ceac-4c25-8f9f-5a6bf07163b6","displayName":"Calendar Type","description":"Microsoft Project 2016\\Project Options\\View\\Calendar Type","helpText":null,"parentCategoryId":"28c4859e-1faa-4b51-96cf-068cb4354093","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"70b5da13-9c31-4857-890d-b7eb223729c3","displayName":"Firewall","description":"Networking > Firewall","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"70c4566f-a079-4a8e-ac97-0736b405df1d","displayName":"Work profile password","description":"Device Restriction Work profile password","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"70d374bf-6444-4b74-a879-a29e4d44c566","displayName":"News And Interests","description":"News And Interests","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"70d374bf-6444-4b74-a879-a29e4d44c566","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"712d184f-d9ac-45fc-9eea-aade3a22b55e","displayName":"Volume Activation","description":"Microsoft Office 2016 (Machine)\\Volume Activation","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"717b634f-72a6-44f6-92c5-e1397bb10f40","displayName":"Keyboard Filter","description":"Keyboard Filter","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"717b634f-72a6-44f6-92c5-e1397bb10f40","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"719595d8-ab5d-4418-88aa-8cd55c2964ba","displayName":"Cloud Cache","description":"FS Logix Profile Containers Cloud Cache","helpText":null,"parentCategoryId":"0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f4af65-b7fa-4c54-bf73-19b0c7ffe162","displayName":"Tracking Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Tracking Options","helpText":null,"parentCategoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","displayName":"Operating system settings","description":"Operating system settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"71f79fa3-14c0-4df8-bf9c-8476e36ea755","childCategoryIds":[],"platforms":"windows10","technologies":"windowsOsRecovery"},{"id":"7226f8a2-c542-471a-8d9e-e0df527325d3","displayName":"Notification Settings","description":"Administrative Templates Power Management Notification Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"724d930a-7a3c-4171-a17c-431cee336518","displayName":"Software Update Settings","description":"Managed Settings Software Update Settings","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"725adbdf-1eb8-45c4-8eb1-44747bd1615d","displayName":"Define Shared Workspace URL's","description":"Microsoft Office 2016\\Global Options\\Customize\\Shared Workspace\\Define Shared Workspace URL's","helpText":null,"parentCategoryId":"13123148-c522-437f-b316-d78f5cc0d28d","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72972c43-36a3-4034-8cc8-334c99087798","displayName":"Instant Search","description":"Administrative Templates Instant Search","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","displayName":"First Run","description":"Microsoft Office 2016\\First Run","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"72f61c7d-e5d2-4170-baf3-c953c1082e19","displayName":"Controlled Folder Access","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard Controlled Folder Access","helpText":null,"parentCategoryId":"ad84cea3-5664-4e42-a9d6-1446828bea45","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73415dea-0103-4427-83c5-6c97bf81af1d","displayName":"Save Documents","description":"Microsoft Visio 2016\\Visio Options\\Save\\Save Documents","helpText":null,"parentCategoryId":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"736134cb-4d82-427a-97b7-d219ac6a22f0","displayName":"Corrupted File Recovery","description":"Administrative Templates Corrupted File Recovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73935f55-c845-40ce-819e-838c0041f6fa","displayName":"Resultant Set of Policy snap-in extensions","description":"Administrative Templates Group Policy Resultant Set of Policy snap-in extensions","helpText":null,"parentCategoryId":"98dc5bd0-2b16-4263-ba2f-62115b680017","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"73bc2db9-d37f-4add-a64d-a8239273edb3","displayName":"Check Accessibility","description":"Microsoft Word 2016\\File Tab\\Check Accessibility","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"740e7a10-3774-4a1c-9970-6907e0f0b848","displayName":"Disable Items in User Interface","description":"Microsoft Word 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["0f42fc50-66c8-4b70-9904-64f8d662c930","44e27b70-4bdb-4aec-a75d-0568a1edc332"],"platforms":"windows10","technologies":"mdm"},{"id":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","displayName":"BITS","description":"BITS","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7443c1d4-1087-486c-9a0a-f9da9074e4e1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7490c4fd-c326-42f7-9908-006504616d4c","displayName":"Trust Center","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["5c4224e0-6a48-4665-9332-958d98124157","fe54701d-42bd-47f0-9c49-26ff6a928b32","e36863b6-3232-4a29-be02-32ee67cc48b9","2fa6b5a0-040e-4059-9690-4a1f4aa5c3c7"],"platforms":"windows10","technologies":"mdm"},{"id":"751cf9ec-7214-4b38-a09e-24922684bd8f","displayName":"Presentation Settings","description":"Administrative Templates Presentation Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"756d2b0b-5f06-45e7-b5c5-c066deb5ed2f","displayName":"Extension snap-ins","description":"Administrative Templates Microsoft Management Console Restricted Permitted snap-ins Extension snap-ins","helpText":null,"parentCategoryId":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75ad885f-6118-4508-a2fd-bb26be931c3f","displayName":"Outlook Today Settings","description":"Microsoft Outlook 2016\\Outlook Today Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75e080fb-3ed7-4a73-a6e0-eb93f0119d68","displayName":"Event Logging","description":"Administrative Templates Event Logging","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"75f9bfd8-8ee2-47b0-b080-a4d179724ca8","displayName":"File Block Settings","description":"Microsoft Visio 2016\\Visio Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"f34e3da0-b440-43dc-a368-4fd39646a9c5","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"760376f3-6b74-4992-89eb-aa41d6190e94","displayName":"Subscription Activation","description":"Microsoft Office 2016\\Subscription Activation","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"763525a0-8456-4336-a8d1-392253e8fdd8","displayName":"System Policy Control","description":"System Policy\\ System Policy Control","helpText":null,"parentCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","rootCategoryId":"361dc9bb-0cf7-4d8b-af4b-6117aeb46511","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"7652894d-4667-443f-b925-b1686a942729","displayName":"Disable Items in User Interface","description":"Microsoft Outlook 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["d59dfcc1-6c35-41de-bfb6-de94b8120ca5","8184df77-410e-41a6-b687-88de05769977"],"platforms":"windows10","technologies":"mdm"},{"id":"768d9aa4-7407-4ed9-b97f-2385b8cadb47","displayName":"File Provider","description":"System Configuration > File Provider","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"76ad3567-c6cb-43b5-b91d-a52a34853c03","displayName":"Trusted Locations","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"36ddafde-fdc7-4787-bf6e-2291446ccc6b","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76b233cc-f977-4305-b02f-deef6667251d","displayName":"Advanced","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Advanced","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["6fd44fd0-80d1-47a0-acad-c115e5b807b6"],"platforms":"windows10","technologies":"mdm"},{"id":"76bbc368-9d0b-4aa7-b8e2-2dcfd864b9ee","displayName":"Audit Process Creation","description":"Administrative Templates Audit Process Creation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76c53aab-0288-4ac1-b399-0104e04c6457","displayName":"Application Compatibility Diagnostics","description":"Administrative Templates Application Compatibility Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"76e34834-6d47-4e06-b14c-aa2888cdce27","displayName":"Generative AI","description":"Microsoft Edge Generative AI","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7740c7ba-aa61-4486-ad26-cb8721a2efb4","displayName":"Publishing","description":"Administrative Templates App-V Publishing","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"77b0357b-412e-4a81-9469-e20a5f1345fd","displayName":"Complex scripts","description":"Microsoft Publisher 2016\\Publisher Options\\Advanced\\Complex scripts","helpText":null,"parentCategoryId":"69f3ad9d-871d-42b3-8e10-07dc076a4d32","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"77ca5e78-a1fe-456e-9814-034b1ea2658d","displayName":"PowerPoint Designer","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\PowerPoint Designer","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"78497707-c3e4-400b-a6bc-1813c3689fdc","displayName":"Preferences","description":"Microsoft Edge Update\\Preferences","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","displayName":"TCPIP Settings","description":"Administrative Templates TCPIP Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["486f25cc-c865-446e-95b2-c5b061883a7a","91789113-6339-4e96-8e1d-73a4dec4967f"],"platforms":"windows10","technologies":"mdm"},{"id":"788355e5-e113-4b17-ada9-fb5ef38bffa1","displayName":"App-V","description":"Administrative Templates App-V","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["7740c7ba-aa61-4486-ad26-cb8721a2efb4","5011ca61-1a58-42da-9c66-7763236acc84","e7cc16d8-f74f-4cd7-890d-9b4082a19c39","efabaf11-42e4-48ab-81ca-4514199d239b","b9201072-3681-4e95-ad90-869e6166b129","f125d7cd-a333-4f24-a5f4-99fc289c6d22","ea9a092f-dd93-41d4-9bbb-118de1213578","10835ce3-31c8-4ec6-aa00-c5af48e550a8"],"platforms":"windows10","technologies":"mdm"},{"id":"794337be-8833-4b9a-bb88-8a030141578d","displayName":"Search","description":"Search","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"794337be-8833-4b9a-bb88-8a030141578d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"797ac384-f48e-4567-b931-33a6ce923b94","displayName":"Microsoft Edge Canary","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Canary","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7a8b936d-b4b0-408f-bec5-3c97050730f8","displayName":"Shared paths","description":"Microsoft Office 2016\\Shared paths","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7aeaf6f8-5511-4216-9483-28f432a5a08f","displayName":"Server Settings","description":"Microsoft PowerPoint 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"da1503cb-e474-4545-8e77-cdd577f34a08","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","displayName":"App Lock","description":"App Management > App Lock","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","displayName":"Extensible Single Sign On (SSO)","description":"Authentication > Extensible Single Sign On (SSO)","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm"},{"id":"7b91ab31-7ed5-4de9-bd49-d04303fd3c74","displayName":"Microsoft Edge Beta","description":"Microsoft Edge Update\\Applications\\Microsoft Edge Beta","helpText":null,"parentCategoryId":"2c7e8e8e-47fe-48ba-8cb4-55ce296edced","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7bee4dea-82a4-4a03-b903-654b374819b1","displayName":"Chinese Conversion | Convert with Options","description":"Microsoft Word 2016\\Review Tab\\Chinese Conversion | Convert with Options","helpText":null,"parentCategoryId":"1fddd12c-a630-47f0-9633-638808e228f9","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7ca3f367-a3a3-4f2a-9cdd-a8fa82bd6919","displayName":"Windows Connect Now","description":"Administrative Templates Windows Connect Now","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d331987-7e2d-4975-b23b-d99a5af26ddf","displayName":"IME","description":"Administrative Templates IME","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7d9e5b9b-84e7-473c-b6ca-a1629448df55","displayName":"Safari Extension Settings","description":"Declarative Device Management preview Extension Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"7db75ddb-f702-49f8-ae2b-991d1afd2d17","displayName":"Performance","description":"Microsoft Edge - Default Settings (users can override)\\Performance","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","displayName":"Predefined","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7eaa5e09-e5ab-4051-b557-64a124ae497c","displayName":"Cryptography","description":"Microsoft Access 2016\\Application Settings\\Security\\Cryptography","helpText":null,"parentCategoryId":"23fd467e-24f8-4200-8b19-c6c11afa8926","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","displayName":"Parental Controls Game Center","description":"Parental Controls > Parental Controls Game Center","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"7f07427b-9bc2-4bfc-a74e-1a1d8961bd89","displayName":"Display","description":"Microsoft Word 2016\\Word Options\\Display","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","displayName":"Display","description":"Display","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7f22e772-942b-4eeb-82b9-eac9265a3d6e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","displayName":"Regional and Language Options","description":"Administrative Templates Regional and Language Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["9a79d480-8cb4-47b5-95c7-5da56eea5bb8"],"platforms":"windows10","technologies":"mdm"},{"id":"7f461268-0fb6-4247-b6db-52515d42a20e","displayName":"User Interface","description":"Administrative Templates Windows Media Player User Interface","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7f5517b0-3ff7-4f7e-aa4c-3d2ccbf37bdc","displayName":"VPN Connection","description":"VPN Connection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7f5517b0-3ff7-4f7e-aa4c-3d2ccbf37bdc","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7fc23813-7a7c-412a-b9bd-eda07e6b1f5d","displayName":"List Sync","description":"List Sync","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7fc23813-7a7c-412a-b9bd-eda07e6b1f5d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"7fc3275d-5ef6-4806-88b0-210bb175c182","displayName":"Network List Manager","description":"Network List Manager","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"7fc3275d-5ef6-4806-88b0-210bb175c182","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"802f3065-0bf1-4578-9d6d-ab1ef02db3ec","displayName":"Feedback Settings","description":"Visual Studio Feedback Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8084033c-156a-4d1b-ab0b-159541810459","displayName":"Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","description":"Microsoft Office 2016\\Tools | AutoCorrect Options... (Excel, PowerPoint and Access)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["69931627-230d-4df9-bbef-e3eac64ea8ef"],"platforms":"windows10","technologies":"mdm"},{"id":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","displayName":"Config Refresh","description":"Config Refresh","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"80b21376-0e9a-4e5b-8a74-b672adbe94a8","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"811f63f1-1619-4b48-b8f0-3d388729bd47","displayName":"Xsan","description":"Xsan","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":["46af3391-ed6d-4ada-aef7-02dac2a1b136","fd3717c1-dcf8-4038-b7f7-4ad3359a9d32"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8184df77-410e-41a6-b687-88de05769977","displayName":"Custom","description":"Microsoft Outlook 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"7652894d-4667-443f-b925-b1686a942729","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"81bc8383-43a5-4c6a-9d51-951e86028934","displayName":"Project Guide settings for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Interface\\Project Guide settings for 'Project1'","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"81c518f1-522e-4957-b850-e8a66d2ab215","displayName":"Games settings","description":"Microsoft Edge Games settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"81eb92d0-acda-4ea2-8183-29ed5457276b","displayName":"Container and Directory Naming","description":"FS Logix ODFC Containers Container and Directory Naming","helpText":null,"parentCategoryId":"5c645a3e-bc39-44e9-8786-4c82e0553d22","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","displayName":"Remediation","description":"Administrative Templates Microsoft Defender Antivirus Remediation","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"822bd634-4d01-486e-adad-8085968fd1c4","displayName":"Advanced Page","description":"Administrative Templates Internet Explorer Internet Control Panel Advanced Page","helpText":null,"parentCategoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"826db7fb-889b-4a99-80a6-38347ba37f21","displayName":"Recurring item configuration","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Recurring item configuration","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"82a437a8-6be8-4003-a951-951999e86db8","displayName":"Parental Controls","description":"Parental Controls","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":["7ecdd7c9-6ab2-4dac-88ef-9bdad46e1f66","f019963f-f4ed-4429-b6e3-babfb24c36a8","f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","65087b94-7e45-4d74-a50d-df4377b67499","dc270c70-1cf4-4d98-ad26-8c2d441173f1"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"82d173f9-ba0b-4b09-bbb8-68cba4916162","displayName":"Privacy Preferences Policy Control","description":"Privacy > Privacy Preferences Policy Control","helpText":null,"parentCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","rootCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"82ecfab7-b76a-4cec-8e76-859db4599ac2","displayName":"Cached Exchange Mode","description":"Microsoft Outlook 2016\\Account Settings\\Exchange\\Cached Exchange Mode","helpText":null,"parentCategoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83087772-6560-4488-a1c5-bb6e4889e868","displayName":"Advanced","description":"Microsoft Word 2016\\Word Options\\Advanced","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["bc65521d-e48a-4e95-899f-49df827808ca","e63361ad-a54b-4557-acc7-02c272a3e58d","2108b443-384c-4bb3-9b9f-acb4a754a86a","61ecc5ec-c494-420b-a27b-a8d2fbdd7df1"],"platforms":"windows10","technologies":"mdm"},{"id":"831dcaee-a6fa-4893-a32d-e13fdf7d3777","displayName":"Caldav","description":"Accounts > CalDAV","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"832f3a51-5e73-4541-8f14-1323cd9919bc","displayName":"When sending a message","description":"Microsoft Outlook 2016 Outlook Options Preferences E-mail Options Advanced E-mail Options When sending a message","helpText":null,"parentCategoryId":"897675f9-0d1b-437b-ba0a-584fbd54df95","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8391e79d-d618-47c3-979c-83544da43739","displayName":"Protected View","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","displayName":"Multi SIM","description":"Multi SIM","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"83fb8ae9-dfc0-4ff8-8a98-3a04f0edd919","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"83febe72-a64f-4051-9071-1efae1ea9a15","displayName":"Disk Management","description":"Declarative Device Management preview Disk Management","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"macOS","technologies":"appleRemoteManagement"},{"id":"845ff38a-408b-449c-9ef3-7fdc331027df","displayName":"Azure Virtual Desktop","description":"Administrative Templates Windows Components Remote Desktop Services Remote Desktop Session Host Azure Virtual Desktop","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5d4e843b-2848-4508-9143-cb3217c2fe83"],"platforms":"windows10","technologies":"mdm"},{"id":"8495c82c-f273-4bcc-8886-6751103a9c7b","displayName":"Proofing","description":"Microsoft Visio 2016 Visio Options Proofing","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["af9b2941-29f9-4ee5-ae09-215f4e242943"],"platforms":"windows10","technologies":"mdm"},{"id":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","displayName":"User Experience","description":"User Experience","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":["c00d6468-cac3-429c-ada5-ba3adf4982a8","d8f06fcf-7328-43ac-b5b7-f7166b5333de","e42edcd8-fcb0-4255-a774-c78b34f0b0c9","ff90bf4b-0583-4761-a1c4-5aa4b50c5872","11c4cf0f-a03d-4309-93b2-011be4c410d5","cc388035-b49c-493e-a598-14b0d0de4359","b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","361859d9-1382-47c3-b9ec-9251a62fbb25"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"84b7f123-e849-40f9-914b-4b97b57bd3b4","displayName":"Interface","description":"Microsoft Project 2016\\Project Options\\Interface","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["fe7c8652-17d4-40a7-869c-f7cfc3454402","343eb575-3ac8-4da9-b66d-ce84b84be7c3","81bc8383-43a5-4c6a-9d51-951e86028934"],"platforms":"windows10","technologies":"mdm"},{"id":"84de2eed-843c-401b-a3fd-e21be88f2365","displayName":"Pen","description":"Microsoft OneNote 2016\\OneNote Options\\Pen","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"853d5a82-91e4-4c53-8338-fd1a3d9b542c","displayName":"MK Protocol Security Restriction","description":"Administrative Templates Internet Explorer Security Features MK Protocol Security Restriction","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"853f4181-42e8-411c-91cf-c06968c0a543","displayName":"Time Server","description":"System Configuration > Time Server","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"85810387-3320-4056-bae2-953beeb246f7","displayName":"Security","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["36ddafde-fdc7-4787-bf6e-2291446ccc6b","9544c86b-47bb-4cb2-a725-63214a0454f4"],"platforms":"windows10","technologies":"mdm"},{"id":"859f3bfb-70f6-447a-822e-680ac98e91ce","displayName":"Microsoft Visual Studio","description":"Visual Studio","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":["b3b30966-47ac-4b54-a75a-04418d5c6153","175ddbac-b0ae-4d9d-b76e-4eb1a487fc93","802f3065-0bf1-4578-9d6d-ab1ef02db3ec","d9d5f333-9402-4459-8ef1-e29330cac8be","652a676c-9d60-4c9a-88b6-823a24961a9b","96277512-3d35-4876-ad74-2d849348799e"],"platforms":"windows10","technologies":"mdm"},{"id":"866eedbc-ffd9-457d-b02b-7b163d55c4bd","displayName":"Disable Items in User Interface","description":"Microsoft Office 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86b4fa22-f6f1-4ca5-8fe4-8788f9b3fd89","displayName":"Power Throttling Settings","description":"Administrative Templates Power Management Power Throttling Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86dae9f9-7eb1-4566-8558-b63fa2e20fee","displayName":"Updates","description":"Microsoft Office 2016 (Machine)\\Updates","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86e78a4b-706a-4ec8-be90-439461abb29d","displayName":"File Revocation","description":"Administrative Templates File Revocation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"86f46ebc-a93f-4a2b-b6e7-bab2ac95a3ae","displayName":"SSL Configuration Settings","description":"Administrative Templates SSL Configuration Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87667b72-85ce-48c2-8023-e6db7f5fe739","displayName":"Work Folders","description":"Administrative Templates Work Folders","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"87f460f4-8403-419c-bfb4-44dec5edcccb","displayName":"Media Management Disc Burning","description":"Media Management > Media Management Disc Burning","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"87f460f4-8403-419c-bfb4-44dec5edcccb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"88a2c40a-7b95-4fd8-8ad8-81dc61d4adf5","displayName":"Lanman Workstation","description":"Administrative Templates Lanman Workstation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"88b16683-81f2-450a-9bf2-42f582e0b748","displayName":"Stationery and Fonts","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Stationery and Fonts","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"891d2958-5a8c-479c-aa68-69b1b6c735e1","displayName":"Shared PC","description":"Shared PC","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"891d2958-5a8c-479c-aa68-69b1b6c735e1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89519fc9-9b38-4401-8767-b0a047cae515","displayName":"Device Restriction","description":"Device Restriction","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":["95000481-a8b5-4e18-99e3-367666aee03f","70c4566f-a079-4a8e-ac97-0736b405df1d","929c169a-3480-467c-9f47-d1836b359ef7","990880db-3f64-4436-ab4a-d7d5181dfa5d","aad0d3ef-88f5-4b22-831b-27093eafbc64","f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","b6733d23-eadc-486a-abfc-62b78698a16c","2257f7e1-3e88-4d4d-a666-437bbe42baca","bf8e3e9c-f7e7-4a43-8898-2caf7b01d987"],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"895e0884-6b60-4bb0-b2ab-3a1642103db7","displayName":"Native Messaging","description":"Google Google Chrome Native Messaging","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8974dbd2-bbb1-4706-86f2-162b2e8bf9b5","displayName":"Downloads","description":"Microsoft Edge - Default Settings users can override Downloads","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"897675f9-0d1b-437b-ba0a-584fbd54df95","displayName":"Advanced E-mail Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\E-mail Options\\Advanced E-mail Options","helpText":null,"parentCategoryId":"2fbb7677-651a-4b62-8b8c-d502ea29936b","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["832f3a51-5e73-4541-8f14-1323cd9919bc","35f245bd-8d1f-424c-83de-a80be27a6a4e"],"platforms":"windows10","technologies":"mdm"},{"id":"89ad0055-1603-420e-940d-9944a63e3da9","displayName":"Profiles","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Profiles","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89be4acb-fdf9-447b-ad16-9a5af1d68b8b","displayName":"Save","description":"Microsoft Word 2016\\Word Options\\Save","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"89c0381d-3b9b-4be5-8077-ffb18d47e910","displayName":"Add-on Management","description":"Administrative Templates\\Windows Components\\Internet Explorer\\Security Features\\Add-on Management","helpText":null,"parentCategoryId":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8a03aebc-9249-4917-a1c3-2957717d9123","displayName":"Real-time Protection","description":"Administrative Templates Microsoft Defender Antivirus Real-time Protection","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8aa3383a-efac-4ec4-841d-06e3e18646d8","displayName":"Default search provider","description":"Microsoft Edge\\Default search provider","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"8abddb23-7036-4ba8-8912-529279a849ea","displayName":"Security Preferences","description":"Security > Security Preferences","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8b0e5a63-c309-430b-8521-7bd21e715b90","displayName":"Office 2016 Converters","description":"Microsoft Office 2016\\Office 2016 Converters","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8b7e662c-0410-4e33-ae11-edb7c717d914","displayName":"Restricted Browsing","description":"Microsoft Office 2016\\File Open/Save dialog box\\Restricted Browsing","helpText":null,"parentCategoryId":"92be4fc7-8095-441c-b52b-9861c21bc337","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8bcf8b08-35a3-49b7-8760-5fe3b767d6a6","displayName":"Immersive Reader settings","description":"Microsoft Edge Immersive Reader settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"8c30a64e-ad24-47a0-97a8-52320360fd88","displayName":"Net Logon","description":"Administrative Templates Net Logon","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["41ba590e-9105-4eda-92fb-13c7d34b8eee"],"platforms":"windows10","technologies":"mdm"},{"id":"8c35f124-e249-43e3-9044-ecc0b0a5855a","displayName":"Idle Browser Actions","description":"Google Google Chrome Idle Browser Actions","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8c75a12d-664d-43ba-a3aa-5259425f9b37","displayName":"Energy Saver","description":"System Configuration > Energy Saver","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8c86f511-1729-4fe9-b0b2-111d9044e1ba","displayName":"App Settings","description":"Declarative Device Management preview App Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"8c879ddf-7acf-45f3-81d3-2c78c7a1321b","displayName":"Miscellaneous","description":"Microsoft Office 2016 (Machine)\\Miscellaneous","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8cefd936-362e-4a24-bc76-e078b6fd13fa","displayName":"Screensaver","description":"System Configuration > Screensaver","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","displayName":"Trusted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Trusted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8d4a5b79-8399-4075-a71f-80ac3099ae78","displayName":"Bluetooth","description":"Bluetooth","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8d4a5b79-8399-4075-a71f-80ac3099ae78","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"8d503574-f93a-4277-a30d-19895d46dd13","displayName":"Security Page","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page","helpText":null,"parentCategoryId":"3f6bb987-17dc-4442-a946-c1c5b1d089d7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","ac014aea-e417-46ad-a4a5-9a1fb1030882","fca9261c-1e93-467d-90cf-ba9108e4cb2e","8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","44c15b2f-10da-4e1e-836b-8b71c19fe34c","8cf3550f-14a0-4abd-9d3e-ad44960cf5b3","99dfe848-181d-480a-bd20-3f93f04b6f5c","dfede24d-d1c8-4e20-82a3-89e1b52057d5","4086190d-2e5b-439d-8426-08492ebb8c9f","58ae30f4-10a2-4144-a593-b5f5bd93c10d"],"platforms":"windows10","technologies":"mdm"},{"id":"8d9eaa88-a2b4-42e7-83e5-8dc12f51d36b","displayName":"Eap","description":"Eap","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8d9eaa88-a2b4-42e7-83e5-8dc12f51d36b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8da2792e-3ad7-4fe4-bb04-b797c3abcbe7","displayName":"Device Installation","description":"Administrative Templates Device Installation","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["68237832-f376-4f0e-ba26-4e06fce7a35d"],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"8e143bee-82fa-4e45-8bd0-c4032b0182d2","displayName":"SharePoint Server","description":"Microsoft Office 2016\\Server Settings\\SharePoint Server","helpText":null,"parentCategoryId":"6aeb1df3-d796-4c5b-921d-9f3970a754cc","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e48532a-ff0e-4422-82e2-6956b6786005","displayName":"Customize Ribbon","description":"Microsoft Project 2016\\Project Options\\Customize Ribbon","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e5e115e-ab37-4dc7-94bc-35a28bf5f4df","displayName":"Intranet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Intranet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e6b8d0c-faf6-41e6-8e31-4389a5470caf","displayName":"Removable Data Drives","description":"Administrative Templates BitLocker Drive Encryption Removable Data Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8e7b730f-c3c9-4e04-9e45-ce06be97908c","displayName":"Junk E-mail","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Junk E-mail","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8ee1d8d2-582f-401b-927a-993016f4290d","displayName":"Browsers","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\Browsers","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"8eed5d21-a5e9-4bc7-b2df-4526af3e2726","displayName":"Windows Error Reporting","description":"Administrative Templates Windows Error Reporting","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["184981d4-712b-425e-b0a3-93eac7fbd3ee","1551f6d3-415c-44a8-b184-393de7c42adf"],"platforms":"windows10","technologies":"mdm"},{"id":"8efd284f-5a56-4da8-8821-f51984ff954d","displayName":"Associated Domains","description":"App Management > Associated Domains","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"8f831e0a-feb7-4cbb-acc1-2e583f3f4de3","displayName":"Login Window Behavior","description":"Login > Login Window Behavior","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"8ff93a7a-503c-4955-89be-900d475b7c5e","displayName":"Managed Settings","description":"Managed Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":["0be23ead-c5f7-4ea5-9ec5-64c05d19cf5d","1fbc29d7-0530-4208-b506-9df648a402e9","724d930a-7a3c-4171-a17c-431cee336518","e7dccaa6-2b16-4dd3-b835-83ca641d0c80","dd68a290-1ba7-470f-afca-339f443a767c","1a056b49-3fb9-4097-b286-c5f493208578","5f71c40e-01aa-42d2-9c8c-7d560126cd4b","2c156b7e-99c8-4a21-a828-4f9b94479b0d","3c7f15ef-a539-411c-93f1-5f97b7bd5519","ef7328b1-c666-40fe-a933-57b14bc77dd3","99d68d97-63b7-4f49-83dd-1ad3b3281d0d","b32726b3-b0e9-465b-86f8-b61ad8af52f0"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"902a93e8-8beb-46c5-ba26-4e2bf6161e22","displayName":"Networking","description":"Administrative Templates Windows Media Player Networking","helpText":null,"parentCategoryId":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"902f5df1-31d6-44ee-ba95-2561199db35f","displayName":"Sync your settings","description":"Administrative Templates Sync your settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"906df5cd-1d9e-49d0-ab32-cf5c5a041974","displayName":"Global HTTP Proxy","description":"Proxies > Global HTTP Proxy","helpText":null,"parentCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"907fd656-2a80-4f34-8615-a3acb11a2b95","displayName":"Custom","description":"Microsoft Publisher 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"909339a5-8f04-4fa2-8807-5d38c83ef547","displayName":"Device Guard","description":"Administrative Templates Device Guard","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"90e3acc6-80d5-41b4-8141-a8620a211c0e","displayName":"Tenant Restrictions","description":"Administrative Templates Tenant Restrictions","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91041ad3-e0a6-43fd-bc7b-ad4c7dda5765","displayName":"Online Content","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...\\Online Content","helpText":null,"parentCategoryId":"af14a55b-d79b-4299-946c-b7582412b748","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","displayName":"Local Policies Security Options","description":"Local Policies Security Options","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"914a31d0-ae3b-4ae5-bd31-504b9f0b91df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91789113-6339-4e96-8e1d-73a4dec4967f","displayName":"Parameters","description":"Administrative Templates TCPIP Settings Parameters","helpText":null,"parentCategoryId":"785c6df2-c6d0-4d6e-bd73-c3b62caca754","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","displayName":"International Options","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\International Options","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"91c02e14-8848-485d-8844-b9933fa888ec","displayName":"Hard Disk Settings","description":"Administrative Templates Power Management Hard Disk Settings","helpText":null,"parentCategoryId":"290ec637-e780-4e95-9834-6368ac0437d1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9215e382-4e7b-4554-8c80-80277136b544","displayName":"Formulas","description":"Microsoft Excel 2016\\Excel Options\\Formulas","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"929c169a-3480-467c-9f47-d1836b359ef7","displayName":"Connectivity","description":"Device Restriction Connectivity","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"92be4fc7-8095-441c-b52b-9861c21bc337","displayName":"File Open/Save dialog box","description":"Microsoft Office 2016\\File Open/Save dialog box","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["4a832199-a841-4b6a-84fa-51365902a742","8b7e662c-0410-4e33-ae11-edb7c717d914"],"platforms":"windows10","technologies":"mdm"},{"id":"92d69c43-75ac-49b1-a3ef-9350079eef86","displayName":"Content settings","description":"Microsoft Edge\\Content settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","displayName":"Account Settings","description":"Microsoft Outlook 2016\\Account Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["b161cf66-abfa-4a36-a9ac-c20ca60594e0","63ca5d8b-829d-42c5-92e8-35f9ca47fb0e","c4dbc05f-da1e-440d-8beb-91bf9dad1875","060e7533-6c2f-4ed1-9173-f3de58de4bed","4e349e4a-dd0b-4175-8974-a2a0f5e35b4d","ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","43053249-ecd1-4d9f-9fa9-c05e7713da7f"],"platforms":"windows10","technologies":"mdm"},{"id":"93099bd4-c685-434b-9d72-f0cb6db5e753","displayName":"Cloud delivered protection preferences","description":"Microsoft Defender > Cloud-delivered protection preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS,linux","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"930d2960-3f70-48ca-9ead-b65a5a037c07","displayName":"SNMP","description":"Administrative Templates SNMP","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93a20c17-1e34-4778-8c95-91a46980ea75","displayName":"Out of Office Assistant","description":"Microsoft Outlook 2016\\Outlook Options\\Out of Office Assistant","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93c28398-faef-4ca5-9667-f5ed004da32c","displayName":"Internet Information Services","description":"Administrative Templates Internet Information Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"93ed2300-658d-40f3-8211-9295a240579c","displayName":"HTTP authentication","description":"Google Google Chrome HTTP authentication","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94a92db4-8704-487b-b0c5-c15d6ac20e6d","displayName":"Notifications","description":"Administrative Templates Notifications","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94b5c25e-3af3-4c08-b738-a0527f91dc22","displayName":"Security Intelligence Updates","description":"Administrative Templates Microsoft Defender Antivirus Security Intelligence Updates","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94ce8206-be22-496c-aa72-f3560e2a5c8d","displayName":"Links","description":"Microsoft Office 2016 Links","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","displayName":"Storage","description":"Storage","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"94fd7e7e-2a0f-4b5e-903a-28868a2e7e3c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"95000481-a8b5-4e18-99e3-367666aee03f","displayName":"Power","description":"Device Restriction Power","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","displayName":"Accounts","description":"Accounts","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":["ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","fa20bbc3-d25d-4a7f-a349-9b211d186e21","5214f1e7-a5a9-4de5-80b4-2f7084a8d068","45fe783f-a80b-42d9-ab3c-8c4081be8d05","9ba1b877-865a-4104-8376-b43a0c75b04b","831dcaee-a6fa-4893-a32d-e13fdf7d3777"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"952f69c8-2644-48df-976b-01fd624cbb3a","displayName":"Database","description":"Microsoft Office 2016\\Business Data\\Database","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9544c86b-47bb-4cb2-a725-63214a0454f4","displayName":"Cryptography","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"85810387-3320-4056-bae2-953beeb246f7","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"957a5b24-ed7a-4f84-9d73-7b6131367396","displayName":"Advanced","description":"Microsoft Visio 2016\\Visio Options\\Advanced","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["4e62ada2-f091-49e1-99dd-ffdf5cf558cd","6ae0d607-832c-403b-b3bc-c563e390ebad","bec8c55d-5aee-4d87-a17d-34d5b3b78f19","66395272-f132-4170-b88e-87f794f987f4","98cefd27-a980-4070-ba45-3696b623810d","f59804be-7fc6-43c3-9baa-942aab85be84"],"platforms":"windows10","technologies":"mdm"},{"id":"96277512-3d35-4876-ad74-2d849348799e","displayName":"Privacy Settings","description":"Visual Studio Privacy Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"962a2377-ad9a-4654-a526-a77c14152fd7","displayName":"Content settings","description":"Google Google Chrome - Default Settings users can override Content settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9859957e-34f1-4669-9f95-2b7c79fff052","displayName":"Service Management - Managed Login Items","description":"Login > Service Management - Managed Login Items","helpText":null,"parentCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","rootCategoryId":"22f83491-cbb8-4a84-92c9-301ab9b3c6e3","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"9865907f-b775-4d36-9578-a016c5105dfe","displayName":"AutoSave","description":"Microsoft Office 2016\\AutoSave","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98cefd27-a980-4070-ba45-3696b623810d","displayName":"Shape Search","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Shape Search","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"98dc5bd0-2b16-4263-ba2f-62115b680017","displayName":"Group Policy","description":"Administrative Templates Group Policy","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["5bb9fb31-007d-4e3f-967b-11e865fcdc70","73935f55-c845-40ce-819e-838c0041f6fa"],"platforms":"windows10","technologies":"mdm"},{"id":"98e76d3e-9e52-45b3-b0c7-f029023121e9","displayName":"Privacy","description":"Privacy","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"98e76d3e-9e52-45b3-b0c7-f029023121e9","childCategoryIds":["82d173f9-ba0b-4b09-bbb8-68cba4916162"],"platforms":"macOS,windows10","technologies":"mdm"},{"id":"990880db-3f64-4436-ab4a-d7d5181dfa5d","displayName":"Personal Profile","description":"Device Restriction Personal Profile","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"992a8a1e-428e-41cb-948e-4e5da86105fa","displayName":"Device Guard","description":"Device Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"992a8a1e-428e-41cb-948e-4e5da86105fa","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"99b4ac32-50b5-4659-a7a1-94bc708ae71a","displayName":"Device Health Attestation Service","description":"Administrative Templates Device Health Attestation Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"99ba9e42-9872-4a03-a615-fc4a4cebc067","displayName":"Active Directory","description":"Administrative Templates Active Directory","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"99d68d97-63b7-4f49-83dd-1ad3b3281d0d","displayName":"Diagnostic Submission","description":"Managed Settings Diagnostic Submission","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"99dfe848-181d-480a-bd20-3f93f04b6f5c","displayName":"Locked- Down Intranet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Intranet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","displayName":"Intelligent Services","description":"Microsoft Excel 2016\\Intelligent Services","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","displayName":"Maps","description":"Maps","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9a7843b4-6ec1-47c4-906b-75b8866e97c2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9a79d480-8cb4-47b5-95c7-5da56eea5bb8","displayName":"Handwriting personalization","description":"Administrative Templates Regional and Language Options Handwriting personalization","helpText":null,"parentCategoryId":"7f363efe-1ea5-4eb8-baf7-8c34456b43fc","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9aaa7ee2-727d-426f-8a2b-6b10a4cd084f","displayName":"RSS Feeds","description":"Administrative Templates RSS Feeds","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b2ad6d8-8837-4c50-89d5-7507b69c7dec","displayName":"Miscellaneous","description":"Microsoft Office 2016\\Miscellaneous","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["5f048379-3a42-43f0-9fd5-d269f292aa35"],"platforms":"windows10","technologies":"mdm"},{"id":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","displayName":"Task Scheduler","description":"Task Scheduler","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9b74c5a8-98f8-49f0-b4eb-51e071d75776","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9b894b32-3697-4a83-9731-3db2a35455ad","displayName":"Cursors","description":"Administrative Templates Cursors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9ba1b877-865a-4104-8376-b43a0c75b04b","displayName":"LDAP","description":"Accounts > LDAP","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","displayName":"Remote Desktop","description":"Remote Desktop Command","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9c6a5b09-3fc4-4cf9-916f-d3a20496fd90","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9caa3b08-b545-4c21-a3b7-b5d2302c1a81","displayName":"Disable Items in User Interface","description":"Microsoft Publisher 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["441d6cc4-e51f-453e-a44d-8394509415be","907fd656-2a80-4f34-8615-a3acb11a2b95"],"platforms":"windows10","technologies":"mdm"},{"id":"9d14bbed-327d-4c38-ac02-6b916909bdd9","displayName":"Microsoft Edge","description":"Microsoft Edge Apple","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9d14bbed-327d-4c38-ac02-6b916909bdd9","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"9dbd66e3-4544-4ca8-a118-272c874bc684","displayName":"Local Security Authority","description":"Administrative Templates Local Security Authority","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9ecb05b7-e942-4b60-9040-d612385f5c67","displayName":"Calendar","description":"Microsoft Project 2016\\Project Options\\Calendar","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9f2e0190-516b-4e5b-94e7-f4ba7e4581f3","displayName":"Locked- Down Restricted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Restricted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","displayName":"User Rights","description":"User Rights","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"9fa124da-acc8-4f4a-a75d-732cd5f91bfd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"9fd0e8e2-191f-4ac0-82b8-46cdfb5eddf8","displayName":"Accessories","description":"Administrative Templates Accessories","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a004deb8-6f52-4411-8d94-41563a8203fc","displayName":"Quarantine","description":"Administrative Templates Microsoft Defender Antivirus Quarantine","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a01c03d4-ec76-4c01-b982-de71620feb19","displayName":"Printing","description":"Printing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a01c03d4-ec76-4c01-b982-de71620feb19","childCategoryIds":["429c4b85-a2b4-46ed-afa0-6c89c08a5544","174ffe92-3770-4688-aa21-85b7535cf374"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","displayName":"Microsoft App Store","description":"Microsoft App Store","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a0c9f0b7-aa25-4e9c-a393-516145847b8b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a18508d1-fd74-4955-8032-3bd9219a0944","displayName":"Fixed Data Drives","description":"Administrative Templates BitLocker Drive Encryption Fixed Data Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a185940c-7899-4ab6-867d-7559352cf8d2","displayName":"OneNote Options","description":"Microsoft OneNote 2016\\OneNote Options","helpText":null,"parentCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":["ab8301d6-b122-4d40-868a-d00d3c0f1916","a87f9d6a-0c84-4cad-839f-e912c6006c12","44774d3d-387b-4fa7-8de4-d82b039c06d1","acfe6c36-66ab-4a3e-86b0-a178377427d2","84de2eed-843c-401b-a3fd-e21be88f2365","c02141e6-0725-4f6f-9138-83d10c6bc104","1979a12b-2a72-438d-9de7-320d1b38e777","1bfef2c3-a561-4e7a-8f0f-0944bc79c20f","fa471a57-af7b-4ccf-b6ba-4c57a7230498","25a84f2d-dbac-457e-b734-bc2605305f2b","c492dd55-8876-4b1b-b620-615cc9b65ef8","e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","4a7b0e92-ba43-46aa-96e8-c5839dbcb524","ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","1ae8c95a-5748-4647-80f8-b447e60601a2"],"platforms":"windows10","technologies":"mdm"},{"id":"a1fbe395-3b60-475f-8a34-3710d6b2e09f","displayName":"Browsing","description":"Administrative Templates Internet Explorer Internet Settings Advanced settings Browsing","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a20fe651-0f0a-4ddd-9d8b-273f17c89e22","displayName":"Custom","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a25a7a02-4bac-411b-9d02-10cb3297cb17","displayName":"Microsoft Edge","description":"Microsoft Edge","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":["3abaf4c2-d5db-4b3b-a461-b1a208231b36","45a89c1f-0a34-4f78-b28f-d30b623fa423","fe845e81-5993-4a65-b22a-decfc5928c65","66615d2a-fec9-47f1-8eaf-9813e30cc023","ef8760ac-a77c-4055-a812-a95bfbf9c00a","ae78ab75-2d0d-418c-be6f-9e64642de4e2","08677354-6f67-455e-a430-4d8d2fbabe84","76e34834-6d47-4e06-b14c-aa2888cdce27","8aa3383a-efac-4ec4-841d-06e3e18646d8","3edb2860-b77b-4240-af16-fb34d45d6ba1","81c518f1-522e-4957-b850-e8a66d2ab215","5bd0eaf1-1818-44e8-9168-fc75c5739cc8","c6099521-a05f-480a-8562-7e71318e2cda","2af24920-f611-4f03-99a6-205773869ae6","6d529e48-5477-4ceb-8ff7-c6e959a0e24f","b3c8c6d9-28bb-475a-9353-4a0e657b33c7","00d7396c-cadc-4d29-86ba-fe4df2ecb110","d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","92d69c43-75ac-49b1-a3ef-9350079eef86","d17b08e6-de3b-445b-ab14-1d47e62efdcf","ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","fddc444c-3591-4a50-865b-d8993b798e12","526e363a-84db-4256-a13c-e01c8c646e26","05811ceb-2954-426c-8afa-2a53f02480cc","120b24dd-c04a-4291-8f24-9c48fcdc1434","dfab5866-1712-4bbf-8edf-5b080b315b9b","08c5f391-e156-4a72-bbb9-3670f2f63a56","ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","eb6409fc-fb52-413d-ae4b-eff017b52b30","43057320-7058-46d5-86f9-a56c80bbf8b9","3fbd3b29-bafd-4adf-89e4-3be612dee275","3ba8106d-4b2f-4775-939d-1cc8703a41dc","fb1e99d0-b921-4b19-9842-17e3e7987528","16ea64a1-563e-43cc-b34a-728c8e7cd13c","1043e7ed-8651-44b2-b918-7230c0b75a6c","5e8e9c7f-1988-45cd-b5ca-78d939e3d49e","8bcf8b08-35a3-49b7-8760-5fe3b767d6a6"],"platforms":"android,iOS,macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"a279f35f-cd71-4489-b0c3-545ea1aa229d","displayName":"Local Security Authority","description":"Local Security Authority","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a279f35f-cd71-4489-b0c3-545ea1aa229d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","displayName":"Disable Items in User Interface","description":"Microsoft Excel 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["3fa63a9d-e22d-4fc8-8464-a13b56461115","3b7e16e7-171f-4169-8904-c8483b06700d"],"platforms":"windows10","technologies":"mdm"},{"id":"a28dd311-46e8-4868-89ab-d3745c0bca21","displayName":"Security","description":"Administrative Templates Event Log Service Security","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a321fc04-d0cb-45ec-a6bf-51d60249922d","displayName":"Automatic Picture Download Settings","description":"Microsoft Outlook 2016\\Security\\Automatic Picture Download Settings","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a34ade49-964d-407c-9f60-2e8cd9dfef05","displayName":"Smart Card","description":"Administrative Templates Smart Card","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","displayName":"Programmatic Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Programmatic Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf"],"platforms":"windows10","technologies":"mdm"},{"id":"a3e48951-624d-4fee-b470-d17ce16e6b0c","displayName":"Secure Boot","description":"Secure Boot","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a3e48951-624d-4fee-b470-d17ce16e6b0c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a3ea4da3-445e-41c0-ac4d-c9ad2467ec26","displayName":"Features","description":"Microsoft Defender Features","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"a3ec7cde-bca6-4e3e-9f7e-f66a43196924","displayName":"Windows Backup And Restore","description":"Windows Backup And Restore","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a3ec7cde-bca6-4e3e-9f7e-f66a43196924","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a40e47b0-5b27-4e4d-b2ef-42f20540e812","displayName":"Graph settings","description":"Microsoft Office 2016\\Graph settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a42e2248-d2dc-4476-a92d-d152fd67e04b","displayName":"Audio Accessory","description":"Declarative Device Management preview Audio Accessory","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS","technologies":"appleRemoteManagement"},{"id":"a4fb2510-977f-42ff-9033-6f1eb98f141b","displayName":"Device Lock","description":"Device Lock","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a4fb2510-977f-42ff-9033-6f1eb98f141b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5060182-4d22-412b-bd0e-3a1e009b36c6","displayName":"Client Interface","description":"Administrative Templates Microsoft Defender Antivirus Client Interface","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5607145-2bd3-4473-a8ee-d7fa5c2f2675","displayName":"Fax","description":"Microsoft Office 2016\\Services\\Fax","helpText":null,"parentCategoryId":"478ed057-8ee7-4dd2-8276-06dad8f85397","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a561e59a-09b7-4106-a6fa-0b82036a5b49","displayName":"RD Gateway","description":"Administrative Templates Remote Desktop Services RD Gateway","helpText":null,"parentCategoryId":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a57b27b6-48e0-42b2-812a-2be86c113a0c","displayName":"Application Compatibility Settings","description":"Administrative Templates Distributed COM Application Compatibility Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5a38799-7bf1-4b83-86fe-62729cd9ed9d","displayName":"Password manager","description":"Google Google Chrome Password manager","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5a56a36-6d60-4f74-a3c6-d82ed979b24a","displayName":"Reporting","description":"Administrative Templates Microsoft Defender Antivirus Reporting","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","displayName":"Co-authoring","description":"Microsoft Office 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a5ce858b-74c2-4663-9b3e-068d31349a13","displayName":"Cryptography","description":"Microsoft Word 2016\\Word Options\\Security\\Cryptography","helpText":null,"parentCategoryId":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","displayName":"Lanman Workstation","description":"Lanman Workstation","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6780c5d-05e0-4047-a6a7-aa7fc4804163","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6e0cee7-34a0-4ca2-b4da-f819a057b532","displayName":"Synchronization","description":"Microsoft Office 2016\\Business Data\\Synchronization","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","displayName":"Wireless Display","description":"Wireless Display","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6e15085-a3a9-41dd-9a6a-65c8a26c616d","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a6fe8038-136b-4d50-bf04-8e232409c0d2","displayName":"Web Content Filter","description":"Web > Web Content Filter","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a6fe8038-136b-4d50-bf04-8e232409c0d2","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a754c9bd-2116-4dd6-9014-07f914869145","displayName":"Proxies","description":"Proxies","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":["906df5cd-1d9e-49d0-ab32-cf5c5a041974","b8ed9eb3-17de-4091-b08b-7adb2fe13271"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","displayName":"Human Presence","description":"Human Presence","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a77e6e83-a02e-4a51-a27e-6437ea42aeb5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a787672d-4a33-455b-a2db-e340eb35a5c8","displayName":"WSL container","description":"Windows Subsystem for Linux WSL container","helpText":null,"parentCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","rootCategoryId":"57514d69-d9b1-469a-9b54-b5e94320c2a1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a788a6e5-ab3f-41e5-96c8-ee59627dcb4d","displayName":"Workgroup Administrator...","description":"Microsoft Access 2016\\Tools | Security\\Workgroup Administrator...","helpText":null,"parentCategoryId":"607a1c39-a3db-496f-8db6-c99d67f5f76c","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a79b2d36-7dea-4a84-81ef-27f99296bccf","displayName":"Authentication","description":"Authentication","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":["f35cc803-3a06-4262-b38b-a5295321f756","c3fdc01d-0648-4dcb-855d-7afe78bf1d89","7b6ddf4e-7136-4fde-adbf-38e6bdfcc962","5995d2ad-5ec7-49d2-ada2-d9c2b57746ba"],"platforms":"iOS,macOS,windows10","technologies":"mdm,appleRemoteManagement"},{"id":"a7b038e5-3af5-41fe-919e-e8befe83a9a5","displayName":"SmartScreen settings","description":"Microsoft Edge - Default Settings (users can override)\\SmartScreen settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7b1c291-6bec-499b-9018-6120950cd5a6","displayName":"App Control for Business","description":"App Control for Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a7b1c291-6bec-499b-9018-6120950cd5a6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7d55d90-e1d1-4577-8bfd-fe2641bce461","displayName":"User Interface Options","description":"Microsoft Visio 2016\\Visio Options\\General\\User Interface Options","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a7e7529f-1030-41da-8b4d-024e1c08bbac","displayName":"Windows Standby Resume Performance Diagnostics","description":"Administrative Templates Windows Standby Resume Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a877a2ff-f144-421f-814c-593e972a8a20","displayName":"Password manager and protection","description":"Microsoft Edge - Default Settings (users can override)\\Password manager and protection","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a87f9d6a-0c84-4cad-839f-e912c6006c12","displayName":"Send to OneNote","description":"Microsoft OneNote 2016\\OneNote Options\\Send to OneNote","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","displayName":"Microsoft Office 2016","description":"Microsoft Office 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["8084033c-156a-4d1b-ab0b-159541810459","94ce8206-be22-496c-aa72-f3560e2a5c8d","760376f3-6b74-4992-89eb-aa41d6190e94","50b4bc60-802c-477a-9366-80e09154595f","7a8b936d-b4b0-408f-bec5-3c97050730f8","8b0e5a63-c309-430b-8521-7bd21e715b90","9b2ad6d8-8837-4c50-89d5-7507b69c7dec","23c09e06-5bee-4b20-a391-36549bf0f620","af14a55b-d79b-4299-946c-b7582412b748","5cd6dc4f-b231-449f-bc10-16041b73356a","72a7524b-11c5-4695-9fcf-6cf30c8ba2b9","a40e47b0-5b27-4e4d-b2ef-42f20540e812","4e0d279d-5ddd-4c4e-8590-6ed92129444d","1942922a-cba9-44c8-871f-3d915c62bd06","478ed057-8ee7-4dd2-8276-06dad8f85397","5b1be2c5-9939-4b2e-b29b-b22069455c90","33fb4f49-5c7f-472c-a0f3-e05646a55902","b94cbc54-e565-44f2-a27a-a63b2514d8bf","0696109e-045f-486a-9a6b-ab7877887bed","59c9b1c4-1757-4cf3-9b27-954dafe016d5","6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","44541a16-c3a2-4be1-ba42-4fc15bde4c46","adf11731-7089-4e2e-8dde-4bd9ef86b067","cc29afc6-309c-4a0d-86f6-60081ae7cd4c","42d8353a-a135-4c2d-8d06-c6cf9961c6c5","bc633a5a-c712-49a6-9f56-775ca9321df4","e86f24d3-8531-4298-b064-692ea795b1d9","da04d4b8-bd11-439e-9663-5fd2399d9cc1","055293ad-c585-40c0-b66c-76ff5cc0a332","042ab9cf-9524-4dd4-b049-4d5f4ff7053f","2d5a483f-b408-426d-9234-2883eae20afb","9865907f-b775-4d36-9578-a016c5105dfe","eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","2f56761a-8e8b-4788-a589-a73ab91818e6","05a6f86f-dab7-4888-97a1-db3457f00974","2d6891a4-ee83-4e55-8e23-09513e1306e4","92be4fc7-8095-441c-b52b-9861c21bc337","eb947c30-3c43-4d34-a566-a842a1a142f3","6aeb1df3-d796-4c5b-921d-9f3970a754cc","449201b6-5002-42d1-85ed-d288fb6552da","866eedbc-ffd9-457d-b02b-7b163d55c4bd","4aec010d-487a-4752-8e66-aedb9e4fbb5a","5bf4c2ba-be08-4cda-bf33-d10707580d78"],"platforms":"windows10","technologies":"mdm"},{"id":"a92d0868-54e7-4a4f-a9f0-87bb1b81af3a","displayName":"Save","description":"Microsoft Excel 2016\\Excel Options\\Save","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","displayName":"Security","description":"Microsoft Outlook 2016\\Security","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["d4e5541e-ab77-4e6c-8046-1fb80ee705ad","a321fc04-d0cb-45ec-a6bf-51d60249922d","c3db5686-3bb2-437c-8906-60da1a1fa844","1720d60f-40a6-471c-8e4c-efbacaf46997"],"platforms":"windows10","technologies":"mdm"},{"id":"a9edc695-b4a9-4111-b07d-627f934f5a1a","displayName":"Trust Center","description":"Microsoft Access 2016\\Application Settings\\Security\\Trust Center","helpText":null,"parentCategoryId":"23fd467e-24f8-4200-8b19-c6c11afa8926","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["12ad5ec7-346d-4b8b-9eba-d826cdb61c31"],"platforms":"windows10","technologies":"mdm"},{"id":"aad0d3ef-88f5-4b22-831b-27093eafbc64","displayName":"Users and Accounts","description":"Device Restriction User and Accounts","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"ab2be8b5-5912-4909-8d8b-e66edf4ab097","displayName":"Logging","description":"FS Logix Logging","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","displayName":"Consistent Mime Handling","description":"Administrative Templates Internet Explorer Security Features Consistent Mime Handling","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ab8301d6-b122-4d40-868a-d00d3c0f1916","displayName":"Other","description":"Microsoft OneNote 2016\\OneNote Options\\Other","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"abf781d7-1179-4f24-8d01-5611db14eddc","displayName":"Touch Input","description":"Administrative Templates Touch Input","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac014aea-e417-46ad-a4a5-9a1fb1030882","displayName":"Locked- Down Internet Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Internet Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac0a894c-173a-48fc-b961-901f28463c77","displayName":"Direct Access Client Experience Settings","description":"Administrative Templates Direct Access Client Experience Settings","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac2d7c6b-7321-42b4-8dd1-d69e15c5f3f6","displayName":"User Profiles","description":"Administrative Templates User Profiles","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ac821e49-1996-4d6c-99d4-9c3c3e4737b6","displayName":"Related Website Sets Settings","description":"Google Google Chrome Related Website Sets Settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acabc66f-5faf-4a13-af32-322ccfc1a5b3","displayName":"Sleeping Tabs settings","description":"Microsoft Edge - Default Settings (users can override)\\Sleeping Tabs settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acb49e73-5a6a-479b-9d58-c3cd7f632e9b","displayName":"Restricted Permitted snap-ins","description":"Administrative Templates Microsoft Management Console Restricted Permitted snap-ins","helpText":null,"parentCategoryId":"07c023d3-0899-40af-a04f-805876d99a9b","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["756d2b0b-5f06-45e7-b5c5-c066deb5ed2f"],"platforms":"windows10","technologies":"mdm"},{"id":"acbc106b-796a-4ba3-ab5f-c130530ad455","displayName":"Earned Value options for Project1","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for 'Project1'\\Earned Value options for Project1","helpText":null,"parentCategoryId":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acbc98d1-689b-4f9c-9c5a-e6bbf305e654","displayName":"Operating System Drives","description":"Administrative Templates BitLocker Drive Encryption Operating System Drives","helpText":null,"parentCategoryId":"0d37dddd-6575-485c-92dd-37a3c23edbf9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"acfe6c36-66ab-4a3e-86b0-a178377427d2","displayName":"Save","description":"Microsoft OneNote 2016\\OneNote Options\\Save","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad1ecbf4-75da-4dc1-9354-7d00c0e2af72","displayName":"Allday","description":"Allday","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ad1ecbf4-75da-4dc1-9354-7d00c0e2af72","childCategoryIds":[],"platforms":"android,iOS","technologies":"exchangeOnline"},{"id":"ad47f904-ede2-4b12-849e-bf751d88abf5","displayName":"Display","description":"Administrative Templates Display","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ad84cea3-5664-4e42-a9d6-1446828bea45","displayName":"Microsoft Defender Exploit Guard","description":"Administrative Templates Microsoft Defender Antivirus Microsoft Defender Exploit Guard","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["210b9c4d-e72a-45a4-97d3-339a6b30c49c","72f61c7d-e5d2-4170-baf3-c953c1082e19"],"platforms":"windows10","technologies":"mdm"},{"id":"ad9610c6-d1c5-4c7a-9e74-58b810dd759d","displayName":"Save","description":"Microsoft Visio 2016\\Visio Options\\Save","helpText":null,"parentCategoryId":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["73415dea-0103-4427-83c5-6c97bf81af1d","2eed22da-106f-4c93-9a45-5ce803b50233"],"platforms":"windows10","technologies":"mdm"},{"id":"adc4eb7f-0f34-4f43-b361-dc42363eccab","displayName":"Mp Engine","description":"Administrative Templates Microsoft Defender Antivirus Mp Engine","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"adf11731-7089-4e2e-8dde-4bd9ef86b067","displayName":"What's New","description":"Microsoft Office 2016\\What's New","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ae78ab75-2d0d-418c-be6f-9e64642de4e2","displayName":"Sleeping Tabs settings","description":"Microsoft Edge\\Sleeping Tabs settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ae89907b-f0c0-4e8f-ab59-dc5514e0a2ff","displayName":"Signature Status dialog box","description":"Microsoft Outlook 2016\\Security\\Cryptography\\Signature Status dialog box","helpText":null,"parentCategoryId":"1720d60f-40a6-471c-8e4c-efbacaf46997","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"af14a55b-d79b-4299-946c-b7582412b748","displayName":"Tools | Options | General | Service Options...","description":"Microsoft Office 2016\\Tools | Options | General | Service Options...","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["6c142a01-47fa-422d-8135-29e81bc970cc","5838ed03-2902-4931-92cf-e349ab09c9b8","91041ad3-e0a6-43fd-bc7b-ad4c7dda5765"],"platforms":"windows10","technologies":"mdm"},{"id":"af351b0c-3d9e-4b18-957b-8179e4eaba15","displayName":"Safe Browsing settings","description":"Google Google Chrome - Default Settings users can override Safe Browsing settings","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"af9b2941-29f9-4ee5-ae09-215f4e242943","displayName":"AutoCorrect Options","description":"Microsoft Visio 2016\\Visio Options\\Proofing\\AutoCorrect Options","helpText":null,"parentCategoryId":"8495c82c-f273-4bcc-8886-6751103a9c7b","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","displayName":"Microsoft One Note 2016","description":"Microsoft One Note 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":["b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","a185940c-7899-4ab6-867d-7559352cf8d2"],"platforms":"windows10","technologies":"mdm"},{"id":"b03bfdc7-f42a-400e-935b-2b07fc71a7f1","displayName":"Mime Sniffing Safety Feature","description":"Administrative Templates Internet Explorer Security Features Mime Sniffing Safety Feature","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b135b86c-b0f4-4cb5-94f4-a6c7ae2013d9","displayName":"Custom","description":"Microsoft One Note 2016 Disable Items in User Interface Custom","helpText":null,"parentCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b161cf66-abfa-4a36-a9ac-c20ca60594e0","displayName":"Exchange ActiveSync","description":"Microsoft Outlook 2016\\Account Settings\\Exchange ActiveSync","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b206e4ef-a288-4fb7-a7ee-4a30b4df3b98","displayName":"Server Settings","description":"Microsoft Word 2016\\Miscellaneous\\Server Settings","helpText":null,"parentCategoryId":"320ccaa3-a391-4d29-a9c4-594561f4104d","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b260992a-8216-4bfa-b60a-4eeea1f356c9","displayName":"News and interests","description":"Feeds","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b260992a-8216-4bfa-b60a-4eeea1f356c9","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","displayName":"PKCS imported certificate","description":"PKCS imported certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b2b85670-5475-4148-ab3d-c4c86b4d5af0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b32726b3-b0e9-465b-86f8-b61ad8af52f0","displayName":"Default Applications","description":"Managed Settings Default Applications","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"b382d980-7459-4850-a45e-75dd99488972","displayName":"Software Update Settings","description":"Declarative Device Management preview Software Update Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"b3b2fc04-4b88-4a1c-8370-04573019eebe","displayName":"LAPS","description":"Administrative Templates\\LAPS","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b3b30966-47ac-4b54-a75a-04418d5c6153","displayName":"Dev Tunnel Settings","description":"Visual Studio Dev Tunnel Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b3c8c6d9-28bb-475a-9353-4a0e657b33c7","displayName":"PDF Reader","description":"Microsoft Edge PDF Reader","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"b3e317cd-c580-478e-885c-666ce3079e78","displayName":"Outlook Social Connector","description":"Microsoft Outlook 2016\\Outlook Social Connector","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b40b8f80-c0e6-4494-8085-f90cadc167a9","displayName":"Temporary folders","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Temporary folders","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b40cfb22-8f17-4317-bcbb-c1c871497446","displayName":"Location and Sensors","description":"Administrative Templates Location and Sensors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b46f4e70-d3d1-4177-8e22-62f806d4568c","displayName":"Other","description":"Google Google Chrome Other","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","displayName":"Power BI","description":"Microsoft Excel 2016\\Power BI","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b485695b-0fae-41ae-861c-3030769b28df","displayName":"Safe Browsing settings","description":"Google Google Chrome Safe Browsing settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","displayName":"Security Features","description":"Administrative Templates Internet Explorer Security Features","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["4560c525-12a1-4536-9cca-338330e58389","e6911a08-946f-4b70-99cb-2a8b92c461e0","853d5a82-91e4-4c53-8338-fd1a3d9b542c","622c83ff-f780-47e6-8b9c-bf82552e3f04","18296501-4825-47ea-835d-66a01aba9384","17bc9899-d157-4eac-a949-810b4a841e28","ab33bc0d-aea2-440a-a3c3-bf0fb84b98ce","b03bfdc7-f42a-400e-935b-2b07fc71a7f1","3bbaff1b-7d59-4b9c-ab53-c235d72b2fb0"],"platforms":"windows10","technologies":"mdm"},{"id":"b5169b74-41be-460a-9402-b13b6c22582b","displayName":"Microsoft Office","description":"Microsoft Office > Microsoft Office","helpText":null,"parentCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","rootCategoryId":"522c3302-7a25-4904-a274-66cef9fd6aa0","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b524d6e2-75bc-4409-ae3d-07605707d7ee","displayName":"Pen UX Behaviors","description":"Administrative Templates Pen UX Behaviors","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b5b6e80d-463d-4e54-aec0-e3a0d3b3cb20","displayName":"Windows Power Shell","description":"Administrative Templates Windows Power Shell","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6650a16-32bc-4344-ac98-8f20486c6b0b","displayName":"Cellular Private Network","description":"Cellular Private Network","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b6650a16-32bc-4344-ac98-8f20486c6b0b","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"b6733d23-eadc-486a-abfc-62b78698a16c","displayName":"General","description":"Device Restriction General","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"b6ad9576-be4c-46b9-a3a6-13a03ff1fed7","displayName":"Managed Menu Extras","description":"User Experience > Managed Menu Extras","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b6bb653a-73f0-42f4-b097-1ce556310904","displayName":"Scripted Diagnostics","description":"Administrative Templates Scripted Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6cafb2c-81be-40cf-90d8-788f713f7099","displayName":"Replace as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Replace as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b6d13875-fd8e-41a0-a712-3dab8b75b93f","displayName":"App Package Deployment","description":"Administrative Templates App Package Deployment","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b77a3a7b-6fab-4240-b5c3-852aa78781d5","displayName":"Endpoint Detection and Response (EDR) preferences","description":"Microsoft Defender > Endpoint Detection and Response (EDR) preferences","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"b792508d-da03-4174-bcf1-666d128ee8ad","displayName":"AutoFormat as you type","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Proofing\\AutoFormat as you type","helpText":null,"parentCategoryId":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b7bde490-eac6-4f57-8808-e0786b8191a1","displayName":"Remote FX for Windows Server 2008 R2","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Remote Session Environment Remote FX for Windows Server 2008 R2","helpText":null,"parentCategoryId":"5f28f9ff-58f8-43af-9692-3d06e083bbd9","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b811c4fe-7ff0-4bd1-a454-0918d4e2f896","displayName":"Web Rtc settings","description":"Google Google Chrome Web Rtc settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b8158968-c839-4d37-9eb8-887bd6fd7402","displayName":"Disable Items in User Interface","description":"Microsoft Access 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["55eebd7c-beb9-48b6-907f-df4997e18bdb","dba1a547-e288-45ac-8553-27a3b564699e"],"platforms":"windows10","technologies":"mdm"},{"id":"b83cafe6-7d8b-4e3b-890d-ce50e548cfc6","displayName":"Win RM Service","description":"Administrative Templates Windows Remote Management Win RM Win RM Service","helpText":null,"parentCategoryId":"364787de-93e4-4fd6-9608-dce1ad8f88c2","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b85d9c04-4923-4fdf-a425-424686d47859","displayName":"Siri Settings","description":"Declarative Device Management preview Siri Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"b8adcde1-500a-430f-8636-f97eaae2a2c6","displayName":"Japanese Find","description":"Microsoft Word 2016\\Japanese Find","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b8ed9eb3-17de-4091-b08b-7adb2fe13271","displayName":"Network Proxy Configuration","description":"Proxies > Network Proxy Configuration","helpText":null,"parentCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","rootCategoryId":"a754c9bd-2116-4dd6-9014-07f914869145","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"b90fb0dc-b8c1-4fc3-b9f9-dfbda4b3f03d","displayName":"General","description":"Microsoft Excel 2016\\Excel Options\\Advanced\\Web Options...\\General","helpText":null,"parentCategoryId":"3503e1ba-8168-4b55-92b1-84613292cadc","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9201072-3681-4e95-ad90-869e6166b129","displayName":"Client Coexistence","description":"Administrative Templates App-V Client Coexistence","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b92241c7-e419-4dc7-b373-08e595c1db1d","displayName":"Operating system","description":"Operating system","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"b92241c7-e419-4dc7-b373-08e595c1db1d","childCategoryIds":[],"platforms":"windows10","technologies":"windowsOsRecovery"},{"id":"b94cbc54-e565-44f2-a27a-a63b2514d8bf","displayName":"DLP","description":"Microsoft Office 2016\\DLP","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b96b63eb-0292-4a73-85d7-c68d330c109e","displayName":"Extensions","description":"Microsoft Edge - Default Settings (users can override)\\ Extensions","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"b9ab4d39-9e28-4897-aa34-0201a35ea989","displayName":"Right-to-left","description":"Microsoft Outlook 2016\\Outlook Options\\Right-to-left","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ba7686de-e6ee-4af9-b1a5-265b03e08367","displayName":"Microsoft PowerPoint 2016","description":"Microsoft PowerPoint 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["28ab8eed-623a-4e9b-813e-13256472dbaf","da92dfd6-a29e-42a0-92ed-276bb6904455","f5babdb3-c718-4675-b977-6c7bc7e6f886","ceacf7fa-fa6e-434d-a381-e20e5245d180","e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","da1503cb-e474-4545-8e77-cdd577f34a08"],"platforms":"windows10","technologies":"mdm"},{"id":"bb54b081-5004-4f05-a46c-f5b948f57b82","displayName":"NTFS","description":"Administrative Templates Filesystem NTFS","helpText":null,"parentCategoryId":"cc13d92c-673f-4af7-9748-50342fc8795a","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","displayName":"System Configuration","description":"System Configuration","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":["8c75a12d-664d-43ba-a3aa-5259425f9b37","cb33668b-933f-4424-8d2d-8bdf0e61bddd","5401711f-292a-487a-be18-f99593a0477c","dec8381a-0a61-406b-842b-fc6ae9930795","768d9aa4-7407-4ed9-b97f-2385b8cadb47","8cefd936-362e-4a24-bc76-e078b6fd13fa","0d4d90ab-7ad8-4524-ade0-bc01aa7b71a3","853f4181-42e8-411c-91cf-c06968c0a543"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bbe51018-a17d-46c4-9517-ff45c54d8d18","displayName":"DNS Settings","description":"Networking > DNS Settings","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bc58391f-664c-42dd-9d18-269e65f324a7","displayName":"Miscellaneous","description":"Microsoft Excel 2016\\Miscellaneous","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["183628a3-d0a5-47de-b444-e132d634ca38"],"platforms":"windows10","technologies":"mdm"},{"id":"bc633a5a-c712-49a6-9f56-775ca9321df4","displayName":"Downloading Framework Components","description":"Microsoft Office 2016\\Downloading Framework Components","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bc65521d-e48a-4e95-899f-49df827808ca","displayName":"File Locations","description":"Microsoft Word 2016\\Word Options\\Advanced\\File Locations","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bce24fbf-4caf-449f-a210-5dd31a368b22","displayName":"Removed policies","description":"Google Google Chrome - Default Settings users can override Removed policies","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd1dad69-5cbe-415e-8565-e87b15cd4431","displayName":"General","description":"Microsoft Access 2016\\Application Settings\\General","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd5533e1-f1ee-4994-8a79-cffe02b12d5c","displayName":"FileVault Recovery Key Escrow","description":"FileVault > FileVault Recovery Key Escrow","helpText":null,"parentCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"bd63ba46-330b-4c49-bfb7-114e1d0cf5e4","displayName":"Compatibility View","description":"Administrative Templates Internet Explorer Compatibility View","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bd69fa31-677f-4d3d-bd4c-91ab1cd0dcb4","displayName":"General","description":"Microsoft Word 2016\\Word Options\\General","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","displayName":"Cryptography","description":"Cryptography","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"bdc32a5e-2bce-46b1-9838-ed557b1e287e","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"be6ca30a-cd4d-40f1-a9f8-d2ea8809cb5e","displayName":"Windows Time Service","description":"Administrative Templates Windows Time Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["13f025df-7d3f-4ecd-bd38-d7af7853b66e"],"platforms":"windows10","technologies":"mdm"},{"id":"be9bdbec-b52e-4174-9c5b-cf765dee855b","displayName":"Store","description":"Administrative Templates Store","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bec8c55d-5aee-4d87-a17d-34d5b3b78f19","displayName":"Editing Options","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Editing Options","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"bf8e3e9c-f7e7-4a43-8898-2caf7b01d987","displayName":"System Security","description":"Device Restriction System Security","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise","technologies":"android"},{"id":"c00d6468-cac3-429c-ada5-ba3adf4982a8","displayName":"Accessibility","description":"User Experience > Accessibility","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c01c7d3f-ace1-48bf-abce-e8a02ba877ab","displayName":"ActiveX Installer Service","description":"Administrative Templates ActiveX Installer Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c0204a51-a73c-46a6-8626-deeadcabe6ac","displayName":"Licensing","description":"Licensing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c0204a51-a73c-46a6-8626-deeadcabe6ac","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c02141e6-0725-4f6f-9138-83d10c6bc104","displayName":"Backup","description":"Microsoft OneNote 2016\\OneNote Options\\Backup","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c0ea0178-ad93-4596-94b2-9d7d1bbe8789","displayName":"Windows Apps","description":"Administrative Templates Microsoft User Experience Virtualization Windows Apps","helpText":null,"parentCategoryId":"53ba922e-db4d-489c-b5ab-dbc4b8321206","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c14c2e8b-0081-46e0-89ac-48ade3b83408","displayName":"Remote Desktop","description":"Remote Desktop","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c14c2e8b-0081-46e0-89ac-48ade3b83408","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3857f91-3df8-472f-9b5a-b10778c715c0","displayName":"Google Chrome - Default Settings users can override","description":"Google Google Chrome - Default Settings users can override","helpText":null,"parentCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["af351b0c-3d9e-4b18-957b-8179e4eaba15","12142994-4b30-486c-bab1-9206528b2b96","20ceae56-e189-46ec-a440-791ce7454017","de643352-007f-4a47-8c83-d75a79516b39","962a2377-ad9a-4654-a526-a77c14152fd7","d97d6d8f-0a1a-4160-89aa-d624a36954a2","6d6b289c-c1e9-4004-b5ab-3123920cf10d","54f2e032-bdcc-4877-b7a0-973d0a7c1653","bce24fbf-4caf-449f-a210-5dd31a368b22"],"platforms":"windows10","technologies":"mdm"},{"id":"c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","displayName":"Miscellaneous","description":"Microsoft Access 2016\\Miscellaneous","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3b5e77d-c00d-4578-84c9-289362ad0b00","displayName":"Save","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Save","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3db5686-3bb2-437c-8906-60da1a1fa844","displayName":"Trust Center","description":"Microsoft Outlook 2016\\Security\\Trust Center","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c3dfb294-a7c0-48af-b705-59c4e257d48c","displayName":"Declarative Device Management (DDM)","description":"Declarative Device Management (DDM)","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":["11d26400-1d13-4dd6-ab4b-cb323494b127","b382d980-7459-4850-a45e-75dd99488972","6b83806b-eb3e-4224-b082-d6f2c8ab3eb9","2cdd4a96-23c1-4419-b88c-41bbaa119e68","dba26132-cba6-4178-93c3-f02476532f08","a42e2248-d2dc-4476-a92d-d152fd67e04b","83febe72-a64f-4051-9071-1efae1ea9a15","d9654cb3-57c8-487c-90a5-454e15336731","b85d9c04-4923-4fdf-a425-424686d47859","42a6198f-bdec-402e-b619-315400b65488","ddb64e9d-34b9-44f4-9980-a6623f14e445","4a6c4488-bbcf-4b5b-9156-7aa1b10a6010","7d9e5b9b-84e7-473c-b6ca-a1629448df55","e0ab6868-4b53-4310-b665-f7c979941db7","5c9e9aaf-a36c-437f-b85a-cb78a527a80f","15be55d8-7477-4274-9b09-b775bce68416","27f47083-6e1b-4fc7-938b-ecd846b79d78","8c86f511-1729-4fe9-b0b2-111d9044e1ba"],"platforms":"iOS,macOS,visionOS,tvOS","technologies":"mdm,appleRemoteManagement"},{"id":"c3fdc01d-0648-4dcb-855d-7afe78bf1d89","displayName":"Identification (Deprecated)","description":"Authentication > Identification","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c400a917-cdff-4e15-a70f-59b82df4c038","displayName":"Attachment Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Attachment Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c48917c1-fd99-405f-b1d2-9dfec169e5d8","displayName":"Remote Desktop Services","description":"Administrative Templates Remote Desktop Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["3a901a80-e2b6-470c-9658-d66ba5458370","0456dcd5-c003-4a8b-80e6-61bacf854330","a561e59a-09b7-4106-a6fa-0b82036a5b49","4c604a0e-9339-4c01-9536-b689bd0abe5f","62bbe0df-b9b2-453f-a2f1-ee66291d4956"],"platforms":"windows10","technologies":"mdm"},{"id":"c492dd55-8876-4b1b-b620-615cc9b65ef8","displayName":"Versions and Recyle Bin","description":"Microsoft OneNote 2016\\OneNote Options\\Versions and Recyle Bin","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","displayName":"Tenant Lockdown","description":"Tenant Lockdown","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c4ce54b8-e555-4447-9791-dd8e9dbb86b0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","displayName":"Exchange","description":"Microsoft Outlook 2016\\Account Settings\\Exchange","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["82ecfab7-b76a-4cec-8e76-859db4599ac2","e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5"],"platforms":"windows10","technologies":"mdm"},{"id":"c4e48b1b-6d88-434f-a717-d5bab28eb245","displayName":"Wi-Fi Connection","description":"Wi-Fi Connection","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c4e48b1b-6d88-434f-a717-d5bab28eb245","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c6099521-a05f-480a-8562-7e71318e2cda","displayName":"Printing","description":"Microsoft Edge\\Printing","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","displayName":"Disable Items in User Interface","description":"Microsoft Visio 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","4e4deef0-4528-47d5-8869-4143c506f18b"],"platforms":"windows10","technologies":"mdm"},{"id":"c6a912c5-0334-40fb-8dc5-f2d2547b8071","displayName":"Removable Storage Access","description":"Administrative Templates Removable Storage Access","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,microsoftSense"},{"id":"c6b72060-8ecb-41d8-8625-2984dd756d4a","displayName":"Free/Busy Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Free/Busy Options","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c6c1120b-988c-4581-a21c-b9786a821242","displayName":"Miscellaneous","description":"Microsoft Publisher 2016\\Miscellaneous","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c72d9f00-d625-43ec-add4-514891035839","displayName":"Web Service","description":"Microsoft Office 2016\\Business Data\\Web Service","helpText":null,"parentCategoryId":"44541a16-c3a2-4be1-ba42-4fc15bde4c46","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c7aba693-8132-4b9f-9a69-dbaaa0ecc03d","displayName":"Publisher Options","description":"Microsoft Publisher 2016\\Publisher Options","helpText":null,"parentCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","rootCategoryId":"0483f5bb-0aaa-4f99-9a5e-b05bbfd70524","childCategoryIds":["69f3ad9d-871d-42b3-8e10-07dc076a4d32","51e0cebb-cac4-4905-9b31-539295e4b85b","1a0386fd-354b-441e-a0d6-1523c209dae7","038b49c9-4f13-4ace-be8d-bd076bffa23e","6d1e32eb-61f7-4907-b9fe-b83fda8ad67d"],"platforms":"windows10","technologies":"mdm"},{"id":"c7c1ed5a-a2ec-4237-bbf1-d5723f94d033","displayName":"System Preferences","description":"Preferences > System Preferences","helpText":null,"parentCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","rootCategoryId":"187e5f4f-a789-4487-a848-7bf0f41597c7","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"c805d788-1950-4ed1-adfb-771f12564a0c","displayName":"Exclusions","description":"Administrative Templates Microsoft Defender Antivirus Exclusions","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c859dc1a-fdeb-4591-af97-79d078ee715b","displayName":"Event Forwarding","description":"Administrative Templates Event Forwarding","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c87ae066-cc1a-44c9-8645-1db2359f7484","displayName":"Layer-2 priority value","description":"Administrative Templates Qo S Packet Scheduler Layer-2 priority value","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c8cdd1a5-3f43-47c5-a775-d27bba4411f5","displayName":"File Block Settings","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\File Block Settings","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c945edd8-c865-4932-806d-83752e3f46ad","displayName":"Microsoft Edge Web View2","description":"Microsoft Edge Web View2","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c945edd8-c865-4932-806d-83752e3f46ad","childCategoryIds":["13cc3b63-a150-4cf2-8d76-309975603c8e"],"platforms":"windows10","technologies":"mdm"},{"id":"c99d6f15-7bbe-45f2-a6e3-a4bd583e1905","displayName":"Auto Play Policies","description":"Administrative Templates Auto Play Policies","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"c9a65baa-de10-4818-97a2-b61babb28060","displayName":"Microsoft Defender Antivirus","description":"Administrative Templates Microsoft Defender Antivirus","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["ad84cea3-5664-4e42-a9d6-1446828bea45","2c43699e-90b5-4da6-9689-fe5ad3b25ac9","c805d788-1950-4ed1-adfb-771f12564a0c","a004deb8-6f52-4411-8d94-41563a8203fc","adc4eb7f-0f34-4f43-b361-dc42363eccab","a5060182-4d22-412b-bd0e-3a1e009b36c6","94b5c25e-3af3-4c08-b738-a0527f91dc22","09c02465-dc11-457e-9eac-19fc542e4cda","cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","8212ba6e-101d-4ee8-8ca2-c4cd2cddba96","a5a56a36-6d60-4f74-a3c6-d82ed979b24a","428f107c-2167-4bc2-9293-8f1d6728a0c5","8a03aebc-9249-4917-a1c3-2957717d9123"],"platforms":"windows10","technologies":"mdm"},{"id":"c9ab1080-67a7-4d6c-8213-056d4eb08ea0","displayName":"Credential Providers","description":"Credential Providers","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"c9ab1080-67a7-4d6c-8213-056d4eb08ea0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ca1aedf4-b951-45f5-a77c-dec776a82e21","displayName":"General i SCSI","description":"Administrative Templatesi SCSI General i SCSI","helpText":null,"parentCategoryId":"3f693856-7cbb-4a1c-93be-0d05aa41059f","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","displayName":"Full Disk Encryption","description":"Full Disk Encryption","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ca48a8ac-4f14-475a-9e32-08b5ed4fa667","childCategoryIds":["5b327ef8-f9fb-4e10-ba9e-8a8ca9bf4ed9","3f56adc1-2207-4033-a6e2-07f64c08e3ff","bd5533e1-f1ee-4994-8a79-cffe02b12d5c"],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","displayName":"Notifications","description":"Notifications","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cb1e177e-8f06-4a69-8215-ec1e91c19e30","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb33668b-933f-4424-8d2d-8bdf0e61bddd","displayName":"System Extensions","description":"System Configuration > System Extensions","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"cb6472c8-3e22-4029-af98-8a97f03a5a44","displayName":"PST Settings","description":"Microsoft Outlook 2016\\Miscellaneous\\PST Settings","helpText":null,"parentCategoryId":"f5a1a387-6665-4527-b532-88a64a76e732","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cb8e8500-0336-4277-b3d9-9177cc967dcf","displayName":"Text Input","description":"Text Input","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cb8e8500-0336-4277-b3d9-9177cc967dcf","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cbb98485-6a36-47b8-b450-7821e08507ac","displayName":"Web Options - General","description":"Microsoft Access 2016\\Application Settings\\Web Options...\\General","helpText":null,"parentCategoryId":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cbc9f1e5-a0bb-4b54-9064-1b8c04e4fa2b","displayName":"Network Inspection System","description":"Administrative Templates Microsoft Defender Antivirus Network Inspection System","helpText":null,"parentCategoryId":"c9a65baa-de10-4818-97a2-b61babb28060","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cc13d92c-673f-4af7-9748-50342fc8795a","displayName":"Filesystem","description":"Administrative Templates Filesystem","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["bb54b081-5004-4f05-a46c-f5b948f57b82"],"platforms":"windows10","technologies":"mdm"},{"id":"cc29afc6-309c-4a0d-86f6-60081ae7cd4c","displayName":"Collaboration Settings","description":"Microsoft Office 2016\\Collaboration Settings","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["2806d29a-7c7a-4ff0-baa2-4a0044425ea6","a5aea816-9c1d-4a85-a2ab-33e3d1c26a8c","1b97e23d-996f-4b8e-9abf-53cfa0fc8917"],"platforms":"windows10","technologies":"mdm"},{"id":"cc388035-b49c-493e-a598-14b0d0de4359","displayName":"Dock","description":"User Experience > Dock","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cc50f179-0c39-4486-a555-de5a6e6ed365","displayName":"Trust Center","description":"Microsoft Project 2016\\Project Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"623d41fb-000e-41d8-b955-373f8c700def","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ccc826ef-d0ea-4241-8b8c-d23a0f78d2cd","displayName":"Offline Files","description":"Administrative Templates Offline Files","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ccea1cb0-55cd-4597-bfb1-e2d38b8a53ac","displayName":"Mobile Accounts","description":"Accounts > Mobile Accounts","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cd1855c4-f7d1-4bed-8d6e-b8c1aab72007","displayName":"Security","description":"Microsoft Excel 2016\\Excel Options\\Security","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["27ccaa0b-8755-4116-a0e3-b5d21d68ab65","7490c4fd-c326-42f7-9908-006504616d4c"],"platforms":"windows10","technologies":"mdm"},{"id":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","displayName":"WWAN Service","description":"Administrative Templates WWAN Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","edf3754c-b22d-4946-a744-4773240a5883"],"platforms":"windows10","technologies":"mdm"},{"id":"cd9fbd32-93e5-4cbc-a51f-a2212cb9d1c2","displayName":"Desktop App Installer","description":"Administrative Templates Desktop App Installer","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ce3ba7d1-c101-4ab6-bf2a-0c683e921bf8","displayName":"Uncategorized","description":"Microsoft Edge\\ Uncategorized","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"android,iOS,macOS,windows10","technologies":"mobileApplicationManagement"},{"id":"ceacf7fa-fa6e-434d-a381-e20e5245d180","displayName":"Co-authoring","description":"Microsoft PowerPoint 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cebd5934-9dfe-4278-966d-b9d880cb30e7","displayName":"Windows Shutdown Performance Diagnostics","description":"Administrative Templates Windows Shutdown Performance Diagnostics","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","displayName":"Windows Components","description":"Administrative Templates\\Windows Components","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["f60cd3c8-a91b-4542-b09f-129dfc7e589c","ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","845ff38a-408b-449c-9ef3-7fdc331027df"],"platforms":"windows10","technologies":"mdm"},{"id":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","displayName":"Networking","description":"Networking","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":["5c722b3f-9d77-428a-b859-3fb556162cd6","224dc683-c0e0-4783-8ba8-8f02c76d161d","e95335ec-2704-47ab-8b40-f602b31eeb9d","bbe51018-a17d-46c4-9517-ff45c54d8d18","06a85f5b-2614-4467-91cf-4a64d0c9326f","70b5da13-9c31-4857-890d-b7eb223729c3"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"cf968979-f316-47cb-a207-bf9ef28cd1aa","displayName":"DSCP value of non-conforming packets","description":"Administrative Templates Qo S Packet Scheduler DSCP value of non-conforming packets","helpText":null,"parentCategoryId":"0937f5ff-aabc-49a9-a94f-6f98c4702580","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","displayName":"Google","description":"Google","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":["36c83fb3-c18c-472b-b39e-617c2f8a7fbd","c3857f91-3df8-472f-9b5a-b10778c715c0"],"platforms":"windows10","technologies":"mdm"},{"id":"d0a1763a-5cdf-4672-8596-435ec1d94b54","displayName":"Search Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Search Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d0a3bbad-8ed0-4545-8249-9e464a13e1b7","displayName":"Application Settings","description":"Microsoft Access 2016\\Application Settings","helpText":null,"parentCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["33b9194b-4027-4c23-b662-52f25db7f839","23fd467e-24f8-4200-8b19-c6c11afa8926","bd1dad69-5cbe-415e-8565-e87b15cd4431","cbb98485-6a36-47b8-b450-7821e08507ac"],"platforms":"windows10","technologies":"mdm"},{"id":"d0e46713-238c-42b7-a996-653cf952c367","displayName":"Home Group","description":"Administrative Templates Home Group","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d0ff97aa-cf53-460e-be82-2c521a56eec6","displayName":"Outlook Options","description":"Microsoft Outlook 2016\\Outlook Options","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["f2bf77fd-37df-448b-8959-6478abf96f6f","1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","b9ab4d39-9e28-4897-aa34-0201a35ea989","5e3f61b6-52b7-4c74-a101-33c1cf34a749","114356a4-dfc9-44e9-9a62-f1d601d48445","d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","93a20c17-1e34-4778-8c95-91a46980ea75","fa6bfb01-34f6-4c54-89b9-f7e717e6d394","fcc8ad48-a1e7-4cba-adae-7c916cbbc897"],"platforms":"windows10","technologies":"mdm"},{"id":"d17b08e6-de3b-445b-ab14-1d47e62efdcf","displayName":"HTTP authentication","description":"Microsoft Edge\\HTTP authentication","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d1e2bb0d-6c0e-4f40-9f2e-52055edc14b5","displayName":"Customize Ribbon","description":"Microsoft Excel 2016\\Excel Options\\Customize Ribbon","helpText":null,"parentCategoryId":"1b6ac108-26b0-44f4-95a1-f848d1e90d76","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d2191717-e304-46f7-bcc0-55e6477026c9","displayName":"Exclusion Settings","description":"Microsoft Defender Exclusion Settings","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"linux","technologies":"microsoftSense"},{"id":"d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","displayName":"Schedule View","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options\\Schedule View","helpText":null,"parentCategoryId":"decab1d2-3474-4727-87c0-d0bc648f2458","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","displayName":"Task Manager","description":"Task Manager","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d2f1d28a-682d-49e9-bb71-0782e4a06c1b","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d33133b4-77df-429a-9580-ed70f7da676d","displayName":"Edit options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Edit\\Edit options for Microsoft Project","helpText":null,"parentCategoryId":"5bd8c27a-0141-4bbf-93f7-214b2389ff2d","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d40a32e1-ab3e-4cbc-aa03-4766792e563e","displayName":"Performance Profiles Configuration","description":"Microsoft Defender Performance Profiles Configuration","helpText":null,"parentCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","rootCategoryId":"48b8705b-58a8-4504-ab7a-2704980f4577","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement,microsoftSense"},{"id":"d4943981-47b2-4a86-848b-860e8ca47381","displayName":"Microsoft Edge Update","description":"Microsoft Edge Update","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":["78497707-c3e4-400b-a6bc-1813c3689fdc","46eaa2b7-341b-4e39-be21-c3ea09dd5778","ff543267-540e-4e37-a1e9-daf6a5e16ba7","43fc9dcc-1e66-4108-bded-2d005eeb7ccb","2c7e8e8e-47fe-48ba-8cb4-55ce296edced"],"platforms":"windows10","technologies":"mdm"},{"id":"d4ad9168-8c49-45d6-a7e5-86ba990fff3e","displayName":"Privacy Sandbox policies","description":"Google Google Chrome Privacy Sandbox policies","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4bf78d5-f6da-463d-85a3-d763e6fbe32b","displayName":"Delete Browsing History","description":"Administrative Templates Internet Explorer Delete Browsing History","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4c9d046-a8c0-46f0-bd62-bc4d1614e891","displayName":"Windows Connection Manager","description":"Administrative Templates Windows Connection Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","displayName":"Security Form Settings","description":"Microsoft Outlook 2016\\Security\\Security Form Settings","helpText":null,"parentCategoryId":"a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["e11f4bd4-9041-49c9-9b8c-163827d606ce","c400a917-cdff-4e15-a70f-59b82df4c038","a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec"],"platforms":"windows10","technologies":"mdm"},{"id":"d52dd970-febb-4891-8eb7-1c8616cfb6cb","displayName":"Desktop Window Manager","description":"Administrative Templates Desktop Window Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["349c31c1-9b5b-42c8-91f2-aa41f4a36a71"],"platforms":"windows10","technologies":"mdm"},{"id":"d59dfcc1-6c35-41de-bfb6-de94b8120ca5","displayName":"Predefined","description":"Microsoft Outlook 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"7652894d-4667-443f-b925-b1686a942729","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5acd615-cfd9-46b4-89fa-424ac0a9e1f2","displayName":"KDC","description":"Administrative Templates KDC","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5b3cab7-d486-4f74-8525-6bd740b950bc","displayName":"Customizable Error Messages","description":"Microsoft Visio 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d5d99ca9-9995-4724-bc46-fd07f362898c","displayName":"Cellular","description":"Cellular","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"d5d99ca9-9995-4724-bc46-fd07f362898c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d679b407-a753-40aa-bc9f-175f363b0eff","displayName":"File locations","description":"Microsoft Project 2016\\Project Options\\Save\\File locations","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d68abc4d-559a-4339-be48-c41a77a87034","displayName":"Passcode","description":"Security > Passcode","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d6bd7b5c-b0ba-4cc1-bcaa-48b0f48e416b","displayName":"Spelling","description":"Microsoft Outlook 2016\\Outlook Options\\Spelling","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d79c9f9a-f469-4f39-a66a-6f7d5ee77e81","displayName":"Language | Set Proofing Language...","description":"Microsoft Word 2016\\Review Tab\\Language | Set Proofing Language...","helpText":null,"parentCategoryId":"1fddd12c-a630-47f0-9633-638808e228f9","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d804205d-6c12-4f40-86a0-aa5a5355370f","displayName":"Files","description":"Microsoft Word 2016\\Word Options\\Advanced\\Web Options...\\Files","helpText":null,"parentCategoryId":"2108b443-384c-4bb3-9b9f-acb4a754a86a","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d875dca1-dc97-4cc5-9df3-c50b813622a3","displayName":"NS Extension Management","description":"App Management > NS Extension Management","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d8f06fcf-7328-43ac-b5b7-f7166b5333de","displayName":"Finder","description":"User Experience > Finder","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"d9432f48-3072-4171-9031-4ebead394151","displayName":"Accessibility settings","description":"Google Google Chrome Accessibility settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9654cb3-57c8-487c-90a5-454e15336731","displayName":"External Intelligence Settings","description":"Declarative Device Management preview External Intelligence Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"d9678af8-c0c7-401a-a0a5-3e7f5b1253ce","displayName":"Kiosk Mode settings","description":"Microsoft Edge\\Kiosk Mode settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d97d6d8f-0a1a-4160-89aa-d624a36954a2","displayName":"Default search provider","description":"Google Google Chrome - Default Settings users can override Default search provider","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d982a1ef-84be-4832-99d4-8b71a4644b74","displayName":"Network Connections","description":"Administrative Templates Network Connections","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9b5c806-099f-4be8-96e4-1152e99cbf26","displayName":"Check Accessibility","description":"Microsoft Excel 2016\\File tab\\Check Accessibility","helpText":null,"parentCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9d5f333-9402-4459-8ef1-e29330cac8be","displayName":"Live Share Settings","description":"Visual Studio Live Share Settings","helpText":null,"parentCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","rootCategoryId":"859f3bfb-70f6-447a-822e-680ac98e91ce","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"d9f5ccc9-5180-43b7-9c81-89ac3364ce00","displayName":"File Share Shadow Copy Provider","description":"Administrative Templates File Share Shadow Copy Provider","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da04d4b8-bd11-439e-9663-5fd2399d9cc1","displayName":"Readiness Toolkit","description":"Microsoft Office 2016\\Readiness Toolkit","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da1503cb-e474-4545-8e77-cdd577f34a08","displayName":"Miscellaneous","description":"Microsoft PowerPoint 2016\\Miscellaneous","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["7aeaf6f8-5511-4216-9483-28f432a5a08f"],"platforms":"windows10","technologies":"mdm"},{"id":"da78ddbc-fc94-48f9-8808-4b160d6f1d50","displayName":"First- Party Sets Settings","description":"Google Google Chrome First- Party Sets Settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"da92dfd6-a29e-42a0-92ed-276bb6904455","displayName":"PowerPoint Options","description":"Microsoft PowerPoint 2016\\PowerPoint Options","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["e2610f41-9a95-47e5-9fc9-572e26dc6baa","77ca5e78-a1fe-456e-9814-034b1ea2658d","f66fb7e4-a968-4969-b627-f99aaad0dfc3","85810387-3320-4056-bae2-953beeb246f7","c3b5e77d-c00d-4578-84c9-289362ad0b00","76b233cc-f977-4305-b02f-deef6667251d","f5007db5-6ee6-4bbd-a391-9727902aad6d"],"platforms":"windows10","technologies":"mdm"},{"id":"daa2ea69-8026-465a-942c-75eb0396d5b9","displayName":"Autonomous Single App Mode","description":"App Management > Autonomous Single App Mode","helpText":null,"parentCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":[],"platforms":"macOS","technologies":"mdm"},{"id":"dab7104a-b79c-4318-afb0-5d5cfed9caa9","displayName":"Previous Versions","description":"Administrative Templates Previous Versions","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"daf3f2c8-f6a5-40bd-96b3-2c6a28931614","displayName":"Shutdown Options","description":"Administrative Templates Shutdown Options","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad","displayName":"Internet Formatting","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format\\Internet Formatting","helpText":null,"parentCategoryId":"f2bf77fd-37df-448b-8959-6478abf96f6f","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["25df12bc-5ebd-4db2-8930-5d27690f3e60"],"platforms":"windows10","technologies":"mdm"},{"id":"db47f067-f435-4095-8b98-aa3805bc0050","displayName":"Schedule","description":"Microsoft Project 2016\\Project Options\\Schedule","helpText":null,"parentCategoryId":"1266b519-e436-4698-8ff4-442acc97efd4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["304a579b-ff3b-4897-8bb8-5a1dda45356f","3b2806c8-bd29-44b5-b3e0-b2c54a6008f3"],"platforms":"windows10","technologies":"mdm"},{"id":"dba1a547-e288-45ac-8553-27a3b564699e","displayName":"Custom","description":"Microsoft Access 2016\\Disable Items in User Interface\\Custom","helpText":null,"parentCategoryId":"b8158968-c839-4d37-9eb8-887bd6fd7402","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dba26132-cba6-4178-93c3-f02476532f08","displayName":"Keyboard Settings","description":"Declarative Device Management preview Keyboard Settings","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"dbb76878-34a9-4f87-bbc6-4de7ea223ff4","displayName":"Windows File Protection","description":"Administrative Templates\\System\\Windows File Protection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","displayName":"PKCS certificate","description":"PKCS certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"dbbe5cb3-fe2e-4d28-8918-24d075a91676","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dc049161-17c6-411e-906b-a871b33651cd","displayName":"Proofing","description":"Microsoft Word 2016\\Word Options\\Proofing","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["e95db55a-8337-416d-a61f-e60f55cc0d13","4dae3032-1f16-4ace-911b-a957db0b8089"],"platforms":"windows10","technologies":"mdm"},{"id":"dc16dbf0-aac8-4ff3-a546-1ddb55650f47","displayName":"Programs","description":"Administrative Templates Programs","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dc270c70-1cf4-4d98-ad26-8c2d441173f1","displayName":"Parental Controls Content Filter","description":"Parental Controls > Parental Controls Content Filter","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"dd68a290-1ba7-470f-afca-339f443a767c","displayName":"MDM Options","description":"Managed Settings MDM Options","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"dd85b339-dd41-4d4e-a6a4-3efb86c14b5d","displayName":"Calculation options for 'Project1'","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for 'Project1'","helpText":null,"parentCategoryId":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":["acbc106b-796a-4ba3-ab5f-c130530ad455"],"platforms":"windows10","technologies":"mdm"},{"id":"dd9a3dad-5851-4899-a5c1-c23318986846","displayName":"File Classification Infrastructure","description":"Administrative Templates File Classification Infrastructure","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dd9e4ae2-a432-4c48-a73a-52c75c3e5279","displayName":"Trusted Certificate","description":"Trusted Certificate","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"dd9e4ae2-a432-4c48-a73a-52c75c3e5279","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ddb64e9d-34b9-44f4-9980-a6623f14e445","displayName":"Custom Profile","description":"Declarative Device Management preview Custom Profile","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"visionOS,tvOS","technologies":"appleRemoteManagement"},{"id":"ddcc8634-edc3-40ef-a444-45f806439c18","displayName":"Application Defaults","description":"Application Defaults","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ddcc8634-edc3-40ef-a444-45f806439c18","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de643352-007f-4a47-8c83-d75a79516b39","displayName":"Deprecated policies","description":"Google Google Chrome - Default Settings users can override Deprecated policies","helpText":null,"parentCategoryId":"c3857f91-3df8-472f-9b5a-b10778c715c0","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"de9a9583-d660-4bdc-83bc-404c8c488267","displayName":"Memory Dump","description":"Memory Dump","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"de9a9583-d660-4bdc-83bc-404c8c488267","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dec8381a-0a61-406b-842b-fc6ae9930795","displayName":"Lock Screen Message","description":"System Configuration > Lock Screen Message","helpText":null,"parentCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","rootCategoryId":"bb995a00-4ed7-49aa-aef2-a6d2c341ee37","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"decab1d2-3474-4727-87c0-d0bc648f2458","displayName":"Calendar Options","description":"Microsoft Outlook 2016\\Outlook Options\\Preferences\\Calendar Options","helpText":null,"parentCategoryId":"1b59bea5-b6db-4a37-9fdd-5bc2e141a61d","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["2592e8ea-5eb0-482b-b41e-eab92f33ac07","d2b665cb-d82b-4d14-8cc2-d9b69e5c51a5","c6b72060-8ecb-41d8-8625-2984dd756d4a","826db7fb-889b-4a99-80a6-38347ba37f21","34c07941-8f52-43ad-b0ca-a7284655afb4"],"platforms":"windows10","technologies":"mdm"},{"id":"df357f0c-78fe-4aee-a465-f3da7499077e","displayName":"Proofing Data Collection","description":"Microsoft Office 2016\\Tools | Options | Spelling\\Proofing Data Collection","helpText":null,"parentCategoryId":"6b7aefda-7b74-48eb-9f8a-37bcc14ce3e1","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dfab5866-1712-4bbf-8edf-5b080b315b9b","displayName":"Manageability","description":"Microsoft Edge\\Manageability","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"dfd5d749-c68c-448f-ab3f-851c09f09df4","displayName":"Auto Save Options","description":"Microsoft Project 2016\\Project Options\\Save\\Auto Save Options","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"dfede24d-d1c8-4e20-82a3-89e1b52057d5","displayName":"Locked- Down Local Machine Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Locked- Down Local Machine Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e00ff1f8-a2d1-4d3b-bb07-f58b38b8d5d7","displayName":"MSS (Legacy)","description":"Administrative Templates\\MSS (Legacy)","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e042b102-b12c-48d1-86ef-f6d296da5b95","displayName":"Server Manager","description":"Administrative Templates Server Manager","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","displayName":"FSLogix","description":"FSLogix","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":["ab2be8b5-5912-4909-8d8b-e66edf4ab097","5c645a3e-bc39-44e9-8786-4c82e0553d22","0b4f28d5-fc68-43a4-92cb-9a47c2a8ebf9","f2d139ed-a314-48b7-b700-4d11adfcc309"],"platforms":"windows10","technologies":"mdm"},{"id":"e0ab6868-4b53-4310-b665-f7c979941db7","displayName":"Safari Browser","description":"Declarative Device Management preview Safari Browser","helpText":null,"parentCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","rootCategoryId":"c3dfb294-a7c0-48af-b705-59c4e257d48c","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"appleRemoteManagement"},{"id":"e0dfe97e-348d-4d30-a6a1-e0de1989236e","displayName":"Other","description":"Microsoft Office 2016\\Language Preferences\\Other","helpText":null,"parentCategoryId":"eb947c30-3c43-4d34-a566-a842a1a142f3","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e0e10e94-325c-49e6-ab48-4f146254395f","displayName":"Form Region Settings","description":"Microsoft Outlook 2016\\Form Region Settings","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e11f4bd4-9041-49c9-9b8c-163827d606ce","displayName":"Custom Form Security","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Custom Form Security","helpText":null,"parentCategoryId":"d4e5541e-ab77-4e6c-8046-1fb80ee705ad","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e13ec567-e29c-4ca0-b599-e8c43587f10a","displayName":"Tools | Local Project Cache","description":"Microsoft Project 2016\\Project Options\\Save\\Tools | Local Project Cache","helpText":null,"parentCategoryId":"6ad0e199-ff50-4e86-b22f-b55ef4ff2329","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","displayName":"InfoPath Integration","description":"Microsoft Outlook 2016\\InfoPath Integration","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e2610f41-9a95-47e5-9fc9-572e26dc6baa","displayName":"Proofing","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Proofing","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["b792508d-da03-4174-bcf1-666d128ee8ad"],"platforms":"windows10","technologies":"mdm"},{"id":"e2a41bef-2f82-409e-9d20-0fe335390f60","displayName":"Microsoft Excel 2016","description":"Microsoft Excel 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":["1b6ac108-26b0-44f4-95a1-f848d1e90d76","b473c6fa-a971-4e5d-ad15-2c27c17c5d3e","5b832259-c30b-43bb-b249-9d3ea4d5b028","28831364-ca54-4f31-acca-1aa0c7a7d3d2","9a2bfe77-7e03-4a24-a9fa-c42a225a28b8","a2806db0-3cea-4a1a-8c1c-f9e1fdfd316b","bc58391f-664c-42dd-9d18-269e65f324a7","d9b5c806-099f-4be8-96e4-1152e99cbf26"],"platforms":"windows10","technologies":"mdm"},{"id":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","displayName":"Delivery Optimization","description":"Delivery Optimization","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e2ec9af6-6143-4cd8-952c-1b3e849ee0dc","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e344b25a-2046-4e70-a3b9-1a418613861f","displayName":"Miscellaneous","description":"Microsoft Project 2016\\Miscellaneous","helpText":null,"parentCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e35a83ff-7c5b-48d4-9ba3-a57849c6b5f5","displayName":"Offline Address Book","description":"Microsoft Outlook 2016\\Account Settings\\Exchange\\Offline Address Book","helpText":null,"parentCategoryId":"c4dbc05f-da1e-440d-8beb-91bf9dad1875","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e36863b6-3232-4a29-be02-32ee67cc48b9","displayName":"External Content","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\External Content","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","displayName":"Federated Authentication","description":"Federated Authentication","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e3a7d1a6-ab02-4c88-86d9-0b541c033d13","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e3ca94a7-e506-4133-8fae-41931dc863a5","displayName":"Disk Diagnostic","description":"Administrative Templates Disk Diagnostic","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e42edcd8-fcb0-4255-a774-c78b34f0b0c9","displayName":"Desktop","description":"User Experience > Desktop","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e4e72b9b-db0e-4a97-9d90-a21d87a4d9bf","displayName":"E-mail","description":"Microsoft OneNote 2016\\OneNote Options\\E-mail","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e50acc0f-d177-4803-aa31-fc97eeb60ff2","displayName":"MSI Corrupted File Recovery","description":"Administrative Templates MSI Corrupted File Recovery","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e522c142-5666-4090-a7f4-1da1487f5384","displayName":"Co-authoring","description":"Microsoft Word 2016\\Collaboration Settings\\Co-authoring","helpText":null,"parentCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e5cbbf8a-45b9-44c8-bce1-c5c2416c998a","displayName":"Disable Items in User Interface","description":"Microsoft PowerPoint 2016\\Disable Items in User Interface","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":["7e0626c6-bc98-4f59-a6ee-1560e27bc9bd","a20fe651-0f0a-4ddd-9d8b-273f17c89e22"],"platforms":"windows10","technologies":"mdm"},{"id":"e63361ad-a54b-4557-acc7-02c272a3e58d","displayName":"Smart cut and paste","description":"Microsoft Word 2016\\Word Options\\Advanced\\Smart cut and paste","helpText":null,"parentCategoryId":"83087772-6560-4488-a1c5-bb6e4889e868","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6911a08-946f-4b70-99cb-2a8b92c461e0","displayName":"Restrict ActiveX Install","description":"Administrative Templates Internet Explorer Security Features Restrict ActiveX Install","helpText":null,"parentCategoryId":"b491424f-100c-4f84-9b9c-8573b2ff9ac7","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6b767af-2ce1-4c91-9360-15abbb0bf3bc","displayName":"Remote FX USB Device Redirection","description":"Administrative Templates Remote FX USB Device Redirection","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6f727b7-f474-4010-b214-83149ffdac2b","displayName":"Miscellaneous","description":"Microsoft Visio 2016\\Miscellaneous","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e6fa2ec7-3f19-44d9-b88c-1561fb554d4b","displayName":"DNS Client","description":"Administrative Templates DNS Client","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e73ddc98-e465-43b0-bfd8-8a18cd9d4830","displayName":"Exploit Guard","description":"Exploit Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e73ddc98-e465-43b0-bfd8-8a18cd9d4830","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"e7ae2b99-0479-475f-af5c-96457121fcd0","displayName":"Windows Hello For Business","description":"Windows Hello For Business","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e7ae2b99-0479-475f-af5c-96457121fcd0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager"},{"id":"e7cc16d8-f74f-4cd7-890d-9b4082a19c39","displayName":"Reporting","description":"Administrative Templates App-V Reporting","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e7dccaa6-2b16-4dd3-b835-83ca641d0c80","displayName":"Accessibility Settings","description":"Managed Settings Accessibility Settings","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","displayName":"Defender","description":"Defender","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e8400c82-34c8-4d6e-bbf9-85220f3205ea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"e865337e-db9f-4d4c-b9fe-35030792c942","displayName":"Microsoft Outlook 2016","description":"Microsoft Outlook 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["2938509f-7d8c-4d5f-ad8a-10018ad3a0e8","a9b83120-15ad-4c9d-bb0d-4ff75c2f9453","7652894d-4667-443f-b925-b1686a942729","f77040df-7dd2-4916-b6a0-5ef962686d4e","d0ff97aa-cf53-460e-be82-2c521a56eec6","e0e10e94-325c-49e6-ab48-4f146254395f","3f216590-fb12-4f8e-924f-2a6895d94126","75ad885f-6118-4508-a2fd-bb26be931c3f","b3e317cd-c580-478e-885c-666ce3079e78","92d9620c-92b6-45ec-b7d6-2f9ed0751e78","f5a1a387-6665-4527-b532-88a64a76e732","ee62e9fc-14c8-4f24-aa7e-89524087a802","e1a2f289-40d8-4e7c-b0a6-cd36f0ee9111","fb721630-fc42-465b-ba22-ab670698c8b5"],"platforms":"windows10","technologies":"mdm"},{"id":"e86f24d3-8531-4298-b064-692ea795b1d9","displayName":"Diagnostics","description":"Microsoft Office 2016 Diagnostics","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e87c8824-e7c4-4fca-a3c1-0376d45d7f9f","displayName":"Compose Messages","description":"Microsoft Outlook 2016\\Outlook Options\\Mail\\Compose Messages","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e8ce968b-91cb-4301-ba98-b37d42bc5213","displayName":"Automatically as you type","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoFormat as you type\\Automatically as you type","helpText":null,"parentCategoryId":"4dae3032-1f16-4ace-911b-a957db0b8089","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","displayName":"Profile Removal Password","description":"Managed Devices > Profile Removal Password","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e905d6cf-7820-48d4-86e0-b55fa991a5ad","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e94d8ce3-d08e-4ee6-83e9-5f89aa37a6bf","displayName":"Trusted Add-ins","description":"Microsoft Outlook 2016\\Security\\Security Form Settings\\Programmatic Security\\Trusted Add-ins","helpText":null,"parentCategoryId":"a36b9aa4-52d0-44a4-bc2c-eec26d2a53ec","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e95335ec-2704-47ab-8b40-f602b31eeb9d","displayName":"Content Caching","description":"Networking > Content Caching","helpText":null,"parentCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","rootCategoryId":"cf5f7f94-cb88-497e-9599-f0985d9ff3cb","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"e95db55a-8337-416d-a61f-e60f55cc0d13","displayName":"AutoCorrect","description":"Microsoft Word 2016\\Word Options\\Proofing\\AutoCorrect","helpText":null,"parentCategoryId":"dc049161-17c6-411e-906b-a871b33651cd","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e972d9fe-a9b7-4a65-a88f-0958fab19584","displayName":"App runtime","description":"Administrative Templates App runtime","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","displayName":"Power","description":"Power","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"e9cd3225-7b0e-485e-99f8-7ec8dd3977a1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea70bf7e-63c2-4f75-aacc-fd638c8a3f5f","displayName":"Session Time Limits","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Session Time Limits","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ea9a092f-dd93-41d4-9bbb-118de1213578","displayName":"Integration","description":"Administrative Templates App-V Integration","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb54e1fc-5780-445c-b9e3-9ceb7a4360d7","displayName":"IME (Japanese)","description":"Microsoft Office 2016\\IME (Japanese)","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb6409fc-fb52-413d-ae4b-eff017b52b30","displayName":"Experimentation","description":"Microsoft Edge\\ Experimentation","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eb947c30-3c43-4d34-a566-a842a1a142f3","displayName":"Language Preferences","description":"Microsoft Office 2016\\Language Preferences","helpText":null,"parentCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["e0dfe97e-348d-4d30-a6a1-e0de1989236e","0f6020d9-278b-4284-894a-bc4a70c8cf32","3512a9f5-d692-4a1f-aedd-1bd431ae893e"],"platforms":"windows10","technologies":"mdm"},{"id":"ec8a2b7c-d8dd-49d8-af2a-3ae0ca8eac02","displayName":"Security","description":"Microsoft Word 2016\\Word Options\\Security","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["5f7e1206-359d-49d7-82c3-f6b6a6eddf65","a5ce858b-74c2-4663-9b3e-068d31349a13"],"platforms":"windows10","technologies":"mdm"},{"id":"ed137c3d-d7bc-48f3-ad86-ff194fc6820d","displayName":"Calculation options for Microsoft Project","description":"Microsoft Project 2016\\Project Options\\Calculation\\Calculation options for Microsoft Project","helpText":null,"parentCategoryId":"20ed0d61-bbf7-421e-8926-0921c7ff7e75","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ed24097d-3bb7-459c-83fb-f0090d1ad8dd","displayName":"Speech","description":"Speech","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ed24097d-3bb7-459c-83fb-f0090d1ad8dd","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eda31027-9270-4959-801b-397fa05512e2","displayName":"Restrictions","description":"Restrictions","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"eda31027-9270-4959-801b-397fa05512e2","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"edd1e620-09e1-47ea-abc8-1e241a174ed9","displayName":"Locale Services","description":"Administrative Templates Locale Services","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"edf3754c-b22d-4946-a744-4773240a5883","displayName":"WWAN Media Cost","description":"Administrative Templates WWAN Service WWAN Media Cost","helpText":null,"parentCategoryId":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ee62e9fc-14c8-4f24-aa7e-89524087a802","displayName":"Customizable Error Messages","description":"Microsoft Outlook 2016\\Customizable Error Messages","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eec07ad3-24ef-4502-8125-9fc988650a7c","displayName":"Settings","description":"Settings","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"eec07ad3-24ef-4502-8125-9fc988650a7c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eef9e433-0ca1-40b0-9a5d-c0ba1f8f0510","displayName":"General","description":"Microsoft Office 2016\\Tools | Options | General | Web Options...\\General","helpText":null,"parentCategoryId":"2d5a483f-b408-426d-9234-2883eae20afb","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"eefc9ae4-b9ae-4d77-8b68-359b9e5ec6f7","displayName":"WWAN UI Settings","description":"Administrative Templates WWAN Service WWAN UI Settings","helpText":null,"parentCategoryId":"cd5d4069-6a72-41fa-ad0d-ef78de5c5a68","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ef6a4e8c-07b2-4f55-9e94-5701cb2268b1","displayName":"Edge Workspaces settings","description":"Microsoft Edge Edge Workspaces settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ef7328b1-c666-40fe-a933-57b14bc77dd3","displayName":"Wallpaper","description":"Managed Settings Wallpaper","helpText":null,"parentCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","rootCategoryId":"8ff93a7a-503c-4955-89be-900d475b7c5e","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"ef8760ac-a77c-4055-a812-a95bfbf9c00a","displayName":"Native Messaging","description":"Microsoft Edge\\Native Messaging","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","displayName":"Above Lock","description":"Above Lock","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ef8b8f2d-7791-4c44-a4f2-e39051f2e715","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"efabaf11-42e4-48ab-81ca-4514199d239b","displayName":"Scripting","description":"Administrative Templates App-V Scripting","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"efb8c441-bad5-4e2f-b07c-5ac299cf3d22","displayName":"Trust Center","description":"Microsoft Office 2016\\Security Settings\\Trust Center","helpText":null,"parentCategoryId":"50b4bc60-802c-477a-9366-80e09154595f","rootCategoryId":"a8aa0d8c-19f2-4e71-acb8-68da2dbf73df","childCategoryIds":["24f6d328-64e7-4490-be38-452ac3b61f6f","135e4013-43b8-4227-99fd-54ddeac4e329","517e55f5-729f-4b4d-9555-33baa95a0e5a"],"platforms":"windows10","technologies":"mdm"},{"id":"effee722-f6ec-440e-a892-bf645bc341ff","displayName":"Reboot","description":"Reboot","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"effee722-f6ec-440e-a892-bf645bc341ff","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f00e9baf-9bbf-48e4-aaac-57410730f016","displayName":"Sign-in settings","description":"Google Google Chrome Sign-in settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","displayName":"Security Settings","description":"Microsoft Office 2016 (Machine)\\Security Settings","helpText":null,"parentCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":["fa8e7b34-c736-47ec-be83-a9f1960d5281"],"platforms":"windows10","technologies":"mdm"},{"id":"f019963f-f4ed-4429-b6e3-babfb24c36a8","displayName":"Parental Controls Application Restrictions","description":"Parental Controls > Parental Controls Application Restrictions","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","displayName":"Connectivity","description":"Connectivity","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f03f9f2f-f8ba-4c94-ad5f-95ada256c8c6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f10138ba-123a-43bc-8031-4458ba327374","displayName":"Mixed Reality","description":"Mixed Reality","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f10138ba-123a-43bc-8031-4458ba327374","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f106d9e2-60ce-4e16-b74d-bd9ef401d7ba","displayName":"Visio Options","description":"Microsoft Visio 2016\\Visio Options","helpText":null,"parentCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["2764869c-54a3-462b-bc72-c580621ab6bb","8495c82c-f273-4bcc-8886-6751103a9c7b","2ea63962-4cac-4a5c-9181-e6a364489db0","a7d55d90-e1d1-4577-8bfd-fe2641bce461","ad9610c6-d1c5-4c7a-9e74-58b810dd759d","957a5b24-ed7a-4f84-9d73-7b6131367396"],"platforms":"windows10","technologies":"mdm"},{"id":"f125d7cd-a333-4f24-a5f4-99fc289c6d22","displayName":"Package Management","description":"Administrative Templates App-V Package Management","helpText":null,"parentCategoryId":"788355e5-e113-4b17-ada9-fb5ef38bffa1","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f1278d6b-60ec-4369-88cf-21df47caaec6","displayName":"Remote Procedure Call","description":"Administrative Templates Remote Procedure Call","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","displayName":"App Store","description":"App Store > App Store","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f14014f5-a401-41e3-8a97-1a9e3c5e3614","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f1455024-7de9-448f-8d8f-a42db2af0a35","displayName":"Printer Redirection","description":"Administrative Templates Remote Desktop Services Remote Desktop Session Host Printer Redirection","helpText":null,"parentCategoryId":"62bbe0df-b9b2-453f-a2f1-ee66291d4956","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","displayName":"Event Log Service","description":"Administrative Templates Event Log Service","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["1a2a4fc8-c54b-4906-a422-7dd51a196211","55a61bb8-e023-4741-8213-99995c5902e5","fecd321b-9a48-4f97-bbed-b335f9ccebdb","a28dd311-46e8-4868-89ab-d3745c0bca21"],"platforms":"windows10","technologies":"mdm"},{"id":"f26fe4c2-d073-4e51-90bf-61c4bbdeb4f2","displayName":"Privacy","description":"Administrative Templates Internet Explorer Privacy","helpText":null,"parentCategoryId":"005ddf8f-da22-4b23-ab02-289f8f6c7960","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f29a5e42-24f5-47fb-bdcf-9ed9418035ee","displayName":"AutoArchive","description":"Microsoft Outlook 2016\\Outlook Options\\Other\\AutoArchive","helpText":null,"parentCategoryId":"5e3f61b6-52b7-4c74-a101-33c1cf34a749","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f2bf77fd-37df-448b-8959-6478abf96f6f","displayName":"Mail Format","description":"Microsoft Outlook 2016\\Outlook Options\\Mail Format","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["91bf761c-1a1e-4a3a-adbf-27288ea7b0b3","88b16683-81f2-450a-9bf2-42f582e0b748","db2ed2fd-1ab5-4ef9-a76c-7b0baacc67ad"],"platforms":"windows10","technologies":"mdm"},{"id":"f2d139ed-a314-48b7-b700-4d11adfcc309","displayName":"Cloud Cache Service","description":"FS Logix Cloud Cache Service","helpText":null,"parentCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","rootCategoryId":"e099d9e1-4ffa-42ed-a250-5fd7875469f2","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f3027ba5-9a2f-42c6-9872-ec21f726929c","displayName":"Early Launch Antimalware","description":"Administrative Templates Early Launch Antimalware","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f34e3da0-b440-43dc-a368-4fd39646a9c5","displayName":"Trust Center","description":"Microsoft Visio 2016\\Visio Options\\Security\\Trust Center","helpText":null,"parentCategoryId":"2ea63962-4cac-4a5c-9181-e6a364489db0","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":["75f9bfd8-8ee2-47b0-b080-a4d179724ca8"],"platforms":"windows10","technologies":"mdm"},{"id":"f350f9a2-3a91-4d6d-90ed-7e3849b0d5f1","displayName":"Device password","description":"Device Restriction Device password","helpText":null,"parentCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","rootCategoryId":"89519fc9-9b38-4401-8767-b0a047cae515","childCategoryIds":[],"platforms":"androidEnterprise,aosp","technologies":"android"},{"id":"f35cc803-3a06-4262-b38b-a5295321f756","displayName":"Extensible Single Sign On Kerberos","description":"Authentication > Extensible Single Sign On Kerberos","helpText":null,"parentCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","rootCategoryId":"a79b2d36-7dea-4a84-81ef-27f99296bccf","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm"},{"id":"f36a78cf-46cf-418e-a98e-032f6cfad224","displayName":"App Management","description":"App Management","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f36a78cf-46cf-418e-a98e-032f6cfad224","childCategoryIds":["7b4e3f58-fb7a-4e6b-8f39-35d1cd90f508","8efd284f-5a56-4da8-8821-f51984ff954d","daa2ea69-8026-465a-942c-75eb0396d5b9","d875dca1-dc97-4cc5-9df3-c50b813622a3"],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f4a8384f-9e4e-4fc6-9ee2-28fa5260347a","displayName":"Smart Card","description":"Security > Smart Card","helpText":null,"parentCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","rootCategoryId":"62cb63bd-d3ef-4cff-9b4a-e7bbf4657173","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f4d4e062-0bcb-496e-b8d0-7e67cefe05c0","displayName":"Windows Media Player","description":"Administrative Templates Windows Media Player","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["902a93e8-8beb-46c5-ba26-4e2bf6161e22","2f85405a-7472-44ce-8c05-b59bb54912d5","7f461268-0fb6-4247-b6db-52515d42a20e"],"platforms":"windows10","technologies":"mdm"},{"id":"f5007db5-6ee6-4bbd-a391-9727902aad6d","displayName":"General","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\General","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f59804be-7fc6-43c3-9baa-942aab85be84","displayName":"Display","description":"Microsoft Visio 2016\\Visio Options\\Advanced\\Display","helpText":null,"parentCategoryId":"957a5b24-ed7a-4f84-9d73-7b6131367396","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f59f7502-cd01-4ea7-9925-2231f88596f0","displayName":"Dma Guard","description":"Dma Guard","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f59f7502-cd01-4ea7-9925-2231f88596f0","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f5a1a387-6665-4527-b532-88a64a76e732","displayName":"Miscellaneous","description":"Microsoft Outlook 2016\\Miscellaneous","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":["ffb0a109-2507-42b3-b26f-9f667f2d5029","cb6472c8-3e22-4029-af98-8a97f03a5a44"],"platforms":"windows10","technologies":"mdm"},{"id":"f5babdb3-c718-4675-b977-6c7bc7e6f886","displayName":"Check Accessibility","description":"Microsoft PowerPoint 2016\\File Tab\\Check Accessibility","helpText":null,"parentCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f60cd3c8-a91b-4542-b09f-129dfc7e589c","displayName":"Internet Explorer","description":"Administrative Templates\\Windows Components\\Internet Explorer","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":["89c0381d-3b9b-4be5-8077-ffb18d47e910"],"platforms":"windows10","technologies":"mdm"},{"id":"f62e0f2a-4363-4246-8057-1dc811fe4360","displayName":"System","description":"System","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f62e0f2a-4363-4246-8057-1dc811fe4360","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f66e6bf2-a437-4d36-b46c-e965b31a5d4f","displayName":"Local Network Access settings","description":"Google Google Chrome Local Network Access settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f66fb7e4-a968-4969-b627-f99aaad0dfc3","displayName":"Customize Ribbon","description":"Microsoft PowerPoint 2016\\PowerPoint Options\\Customize Ribbon","helpText":null,"parentCategoryId":"da92dfd6-a29e-42a0-92ed-276bb6904455","rootCategoryId":"ba7686de-e6ee-4af9-b1a5-265b03e08367","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f69e6993-2e88-4938-bfe5-cea9ab21a858","displayName":"Windows Remote Shell","description":"Administrative Templates Windows Remote Shell","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f71e7e3a-482a-4760-b7f9-0403b2b6f7d8","displayName":"Parental Controls Time Limits","description":"Parental Controls > Parental Controls Time Limits","helpText":null,"parentCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","rootCategoryId":"82a437a8-6be8-4003-a951-951999e86db8","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","displayName":"Windows Defender Security Center","description":"Windows Defender Security Center","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f72e61e9-7e84-4c6d-8057-fa0a4f79cbea","childCategoryIds":[],"platforms":"windows10","technologies":"mdm,configManager,microsoftSense"},{"id":"f7486553-9e63-4d63-9423-56e5ffe48700","displayName":"Google Cast","description":"Google Google Chrome Google Cast","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f77040df-7dd2-4916-b6a0-5ef962686d4e","displayName":"Meeting Workspace","description":"Microsoft Outlook 2016\\Meeting Workspace","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","displayName":"Windows Licensing","description":"Windows Licensing","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f8a973d8-b5d6-4d3e-9e82-63f61107fd0c","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f8f4d337-4c55-4518-91c4-f7f77703d843","displayName":"Software Update","description":"System Updates > Software Update","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"f8f4d337-4c55-4518-91c4-f7f77703d843","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"f926f6e3-1bd6-4259-ae7c-e14108568882","displayName":"Microsoft Support Diagnostic Tool","description":"Administrative Templates Microsoft Support Diagnostic Tool","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"f9e53433-d8d9-4eaf-bdf3-d32de60d686e","displayName":"Customize Ribbon","description":"Microsoft Word 2016\\Word Options\\Customize Ribbon","helpText":null,"parentCategoryId":"31070051-859e-4d27-9df3-c07b8a2d2179","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa20bbc3-d25d-4a7f-a349-9b211d186e21","displayName":"Subscribed Calendars","description":"Accounts Subscribed Calendars","helpText":null,"parentCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","rootCategoryId":"952bb5bd-fd1f-44d0-b3af-2201977fc87f","childCategoryIds":[],"platforms":"iOS","technologies":"mdm,appleRemoteManagement"},{"id":"fa2722a8-dcfd-4e14-a429-2b0041642c77","displayName":"Network settings","description":"Google Google Chrome Network settings","helpText":null,"parentCategoryId":"36c83fb3-c18c-472b-b39e-617c2f8a7fbd","rootCategoryId":"d097ffb0-1ceb-4384-9d96-0ced6bd08c31","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","displayName":"Windows App","description":"Windows App","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"fa45b2a8-738c-4bac-acc8-7e5bcd6ea6cb","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa471a57-af7b-4ccf-b6ba-4c57a7230498","displayName":"Editing","description":"Microsoft OneNote 2016\\OneNote Options\\Editing","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa6bfb01-34f6-4c54-89b9-f7e717e6d394","displayName":"Customize Ribbon","description":"Microsoft Outlook 2016\\Outlook Options\\Customize Ribbon","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fa8e7b34-c736-47ec-be83-a9f1960d5281","displayName":"IE Security","description":"Microsoft Office 2016 (Machine)\\Security Settings\\IE Security","helpText":null,"parentCategoryId":"f0190b73-0d5c-410e-bce1-e03aa1f62ed4","rootCategoryId":"32cd9bf8-5833-4e78-9bfd-beaa9d3a38a4","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","displayName":"Microsoft Word 2016","description":"Microsoft Word 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":["31070051-859e-4d27-9df3-c07b8a2d2179","12f9c95a-3ff1-49ef-bc8e-8d2b5ef4b06e","e522c142-5666-4090-a7f4-1da1487f5384","1fddd12c-a630-47f0-9633-638808e228f9","73bc2db9-d37f-4add-a64d-a8239273edb3","740e7a10-3774-4a1c-9970-6907e0f0b848","b8adcde1-500a-430f-8636-f97eaae2a2c6","320ccaa3-a391-4d29-a9c4-594561f4104d"],"platforms":"windows10","technologies":"mdm"},{"id":"fb1e99d0-b921-4b19-9842-17e3e7987528","displayName":"Edge Website Typo Protection settings","description":"Microsoft Edge Edge Website Typo Protection settings","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fb721630-fc42-465b-ba22-ab670698c8b5","displayName":"Search Folders","description":"Microsoft Outlook 2016\\Search Folders","helpText":null,"parentCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fca9261c-1e93-467d-90cf-ba9108e4cb2e","displayName":"Restricted Sites Zone","description":"Administrative Templates Internet Explorer Internet Control Panel Security Page Restricted Sites Zone","helpText":null,"parentCategoryId":"8d503574-f93a-4277-a30d-19895d46dd13","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fcc8ad48-a1e7-4cba-adae-7c916cbbc897","displayName":"Delegates","description":"Microsoft Outlook 2016\\Outlook Options\\Delegates","helpText":null,"parentCategoryId":"d0ff97aa-cf53-460e-be82-2c521a56eec6","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fd3717c1-dcf8-4038-b7f7-4ad3359a9d32","displayName":"Xsan Preferences","description":"Xsan > Xsan Preferences","helpText":null,"parentCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","rootCategoryId":"811f63f1-1619-4b48-b8f0-3d388729bd47","childCategoryIds":[],"platforms":"macOS","technologies":"mdm,appleRemoteManagement"},{"id":"fddc444c-3591-4a50-865b-d8993b798e12","displayName":"Cast","description":"Microsoft Edge\\Cast","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fe3cb879-8869-4163-91d7-e432abd75da8","displayName":"Scheduled Maintenance","description":"Administrative Templates Scheduled Maintenance","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe54701d-42bd-47f0-9c49-26ff6a928b32","displayName":"Protected View","description":"Microsoft Excel 2016\\Excel Options\\Security\\Trust Center\\Protected View","helpText":null,"parentCategoryId":"7490c4fd-c326-42f7-9908-006504616d4c","rootCategoryId":"e2a41bef-2f82-409e-9d20-0fe335390f60","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe65603b-1980-446b-ae17-516eb885c6be","displayName":"Tablet PC Pen Training","description":"Administrative Templates Tablet PC Pen Training","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe786056-6f4a-4d16-bff4-5fbb640308d2","displayName":"Trusted Locations","description":"Microsoft Word 2016\\Word Options\\Security\\Trust Center\\Trusted Locations","helpText":null,"parentCategoryId":"5f7e1206-359d-49d7-82c3-f6b6a6eddf65","rootCategoryId":"fab15a0f-3aff-44b3-b1f3-6788bd60070f","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe7c8652-17d4-40a7-869c-f7cfc3454402","displayName":"Show indicators and Option butons for","description":"Microsoft Project 2016\\Project Options\\Interface\\Show indicators and Option butons for","helpText":null,"parentCategoryId":"84b7f123-e849-40f9-914b-4b97b57bd3b4","rootCategoryId":"0e864f4a-d9e7-48f5-abe6-c7f92773921a","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fe845e81-5993-4a65-b22a-decfc5928c65","displayName":"Proxy server","description":"Microsoft Edge\\Proxy server","helpText":null,"parentCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","rootCategoryId":"a25a7a02-4bac-411b-9d02-10cb3297cb17","childCategoryIds":[],"platforms":"macOS,windows10","technologies":"mdm,mobileApplicationManagement"},{"id":"fea97af7-df89-4fde-8e2b-f8e7f7b6b741","displayName":"Scareware Blocker settings","description":"Microsoft Edge - Default Settings users can override Scareware Blocker settings","helpText":null,"parentCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","rootCategoryId":"43593f1a-6e4d-44a9-b1d4-99b375a9baa6","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fecd321b-9a48-4f97-bbed-b335f9ccebdb","displayName":"Application","description":"Administrative Templates Event Log Service Application","helpText":null,"parentCategoryId":"f14fcb64-a868-4531-a3b4-c3cdf03c2b99","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fed4ebaf-ec71-4fb0-be3e-4c7a6bb1af77","displayName":"Predefined","description":"Microsoft Visio 2016\\Disable Items in User Interface\\Predefined","helpText":null,"parentCategoryId":"c67c9e69-6e69-4b63-868c-3b3df5d17e47","rootCategoryId":"5e9bf104-334e-4056-bb4b-d6d072a92cb7","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff543267-540e-4e37-a1e9-daf6a5e16ba7","displayName":"Proxy Server","description":"Microsoft Edge Update\\Proxy Server","helpText":null,"parentCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","rootCategoryId":"d4943981-47b2-4a86-848b-860e8ca47381","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff87ffcb-a827-4d2b-90fc-e5789ef6d3e0","displayName":"E-mail","description":"Microsoft Outlook 2016\\Account Settings\\E-mail","helpText":null,"parentCategoryId":"92d9620c-92b6-45ec-b7d6-2f9ed0751e78","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ff90bf4b-0583-4761-a1c4-5aa4b50c5872","displayName":"Notifications","description":"User Experience > Notifications","helpText":null,"parentCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","rootCategoryId":"84affc4e-1473-43e6-9df0-0fe7e1e84c4b","childCategoryIds":[],"platforms":"iOS,macOS","technologies":"mdm,appleRemoteManagement"},{"id":"ffb0a109-2507-42b3-b26f-9f667f2d5029","displayName":"Miscellaneous","description":"Microsoft Outlook 2016\\Miscellaneous\\Miscellaneous","helpText":null,"parentCategoryId":"f5a1a387-6665-4527-b532-88a64a76e732","rootCategoryId":"e865337e-db9f-4d4c-b9fe-35030792c942","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","displayName":"Microsoft Access 2016","description":"Microsoft Access 2016","helpText":null,"parentCategoryId":"00000000-0000-0000-0000-000000000000","rootCategoryId":"ffb238b0-ab9f-46f5-9b85-580f49c1a2b6","childCategoryIds":["d0a3bbad-8ed0-4545-8249-9e464a13e1b7","6730f0be-a129-4b48-942f-e4ddf69fee66","b8158968-c839-4d37-9eb8-887bd6fd7402","c3ab8d44-b353-4a8a-a526-ffd743fb7ff8","607a1c39-a3db-496f-8db6-c99d67f5f76c"],"platforms":"windows10","technologies":"mdm"},{"id":"ffb6de77-8f2d-4b45-9cd4-00bb75cd496c","displayName":"App Package Deployment","description":"Administrative Templates\\Windows Components\\App Package Deployment","helpText":null,"parentCategoryId":"cef993dc-bf18-44f7-8e9f-465ef1a0f144","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffd1a98f-0fac-47fe-813f-7510d0dacbc3","displayName":"Windows Resource Exhaustion Detection and Resolution","description":"Administrative Templates Windows Resource Exhaustion Detection and Resolution","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"ffe3b0a1-62e6-4a31-ad9a-a213472fb7ef","displayName":"Audio and Video","description":"Microsoft OneNote 2016\\OneNote Options\\Audio and Video","helpText":null,"parentCategoryId":"a185940c-7899-4ab6-867d-7559352cf8d2","rootCategoryId":"afc4a9d5-81df-4077-bb80-bd46dcd0d0d1","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"},{"id":"fff51673-04b8-4277-98ef-4baffbd8d192","displayName":"Windows Calendar","description":"Administrative Templates Windows Calendar","helpText":null,"parentCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","rootCategoryId":"48be5f9d-4941-4189-8015-dd78f87aacd5","childCategoryIds":[],"platforms":"windows10","technologies":"mdm"}] diff --git a/public/version.json b/public/version.json index 3b88d3c7ee3b..c078a41b9ff0 100644 --- a/public/version.json +++ b/public/version.json @@ -1,3 +1,3 @@ { - "version": "10.10.1" + "version": "10.10.2" } \ No newline at end of file diff --git a/src/components/CippComponents/CippAddUserDrawer.jsx b/src/components/CippComponents/CippAddUserDrawer.jsx index 7866178d2880..6477a319d66f 100644 --- a/src/components/CippComponents/CippAddUserDrawer.jsx +++ b/src/components/CippComponents/CippAddUserDrawer.jsx @@ -1,6 +1,6 @@ import React, { useState, useEffect } from "react"; import { CippIcons } from "../../utils/icon-registry" -import { Button, Box } from "@mui/material"; +import { Alert, Button, Box } from "@mui/material"; import { useForm, useWatch, useFormState } from "react-hook-form"; import { CippOffCanvas } from "./CippOffCanvas"; import { CippApiResults } from "./CippApiResults"; @@ -22,6 +22,13 @@ export const CippAddUserDrawer = ({ const [formResetKey, setFormResetKey] = useState(0); const userSettingsDefaults = useSettings(); + // User creation targets a single tenant. Under "All Tenants" the tenant does not resolve, and + // the Graph write helpers silently no-op while /api/AddUser still reports success, so guard the + // submit rather than letting it appear to succeed while creating nothing. + const isAllTenants = + !userSettingsDefaults?.currentTenant || + userSettingsDefaults.currentTenant === "AllTenants"; + const formControl = useForm({ mode: "onChange", defaultValues: { @@ -162,7 +169,12 @@ export const CippAddUserDrawer = ({ variant="contained" color="primary" onClick={formControl.handleSubmit(handleSubmit)} - disabled={createUser.isPending || !isValid || (!isDirty && !createUser.isSuccess)} + disabled={ + isAllTenants || + createUser.isPending || + !isValid || + (!isDirty && !createUser.isSuccess) + } > {createUser.isPending ? "Creating User..." @@ -178,6 +190,12 @@ export const CippAddUserDrawer = ({ } > + {isAllTenants && ( + + User creation is single-tenant only. Select a specific tenant using the tenant + selector before adding a user — with "All Tenants" selected no user will be created. + + )} item.label) : []; @@ -164,7 +170,12 @@ export const CippBulkUserDrawer = ({ variant="contained" color="primary" onClick={handleSubmit} - disabled={createBulkUsers.isLoading || !bulkUserData || bulkUserData.length === 0} + disabled={ + isAllTenants || + createBulkUsers.isLoading || + !bulkUserData || + bulkUserData.length === 0 + } > {createBulkUsers.isLoading ? "Creating Users..." @@ -179,6 +190,15 @@ export const CippBulkUserDrawer = ({ } > + {isAllTenants && ( + + + Bulk user creation is single-tenant only. Select a specific tenant using the tenant + selector before adding users — with "All Tenants" selected no users will be created. + + + )} + + !item?.['@odata.type'] || item['@odata.type'] === '#microsoft.graph.group' + +const collectNestResolveGroupIds = (row) => { + const reasons = [...(row?.includeReasons || []), ...(row?.excludeReasons || [])] + const ids = [] + for (const reason of reasons) { + if ( + (reason?.type === 'includeGroups' || reason?.type === 'excludeGroups') && + reason?.transitive && + GUID_PATTERN.test(reason?.id) + ) { + ids.push(reason.id) + } + if ( + (reason?.type === 'includeRoles' || reason?.type === 'excludeRoles') && + GUID_PATTERN.test(reason?.viaGroupId) + ) { + ids.push(reason.viaGroupId) + } + } + return [...new Set(ids)] +} + +const resolveViaNestedGroups = (memberOfValue, nestedUnderByAssignedId) => { + const directGroups = (Array.isArray(memberOfValue) ? memberOfValue : []).filter(isGraphGroup) + const directById = new Map(directGroups.map((group) => [group.id, group])) + const viaByAssignedId = {} + + for (const [assignedId, nestedGroups] of Object.entries(nestedUnderByAssignedId || {})) { + const via = [] + for (const nested of Array.isArray(nestedGroups) ? nestedGroups : []) { + if (!isGraphGroup(nested) || !directById.has(nested.id)) continue + const direct = directById.get(nested.id) + via.push({ + id: nested.id, + name: direct.displayName || nested.displayName || nested.id, + }) + } + viaByAssignedId[assignedId] = via + } + + return viaByAssignedId +} + +const enrichReasonsWithNestPath = (reasons, viaByAssignedId) => + (Array.isArray(reasons) ? reasons : []).map((reason) => { + const isGroupReason = + (reason?.type === 'includeGroups' || reason?.type === 'excludeGroups') && + reason?.transitive && + reason?.id + const isRoleViaGroup = + (reason?.type === 'includeRoles' || reason?.type === 'excludeRoles') && reason?.viaGroupId + + const lookupId = isGroupReason ? reason.id : isRoleViaGroup ? reason.viaGroupId : null + if (!lookupId) return reason + + const viaNestedGroups = viaByAssignedId?.[lookupId] + if (!viaNestedGroups?.length) return reason + return { ...reason, viaNestedGroups } + }) + +const reasonIcon = (reason) => { + const type = reason?.type || '' + if (type.includes('Roles')) return CippIcons.AdminPanelSettings + if (type.includes('Groups')) return CippIcons.Groups + if (type.includes('Guests') || reason?.value?.includes('GuestsOrExternalUsers')) { + return CippIcons.Badge + } + if (type.includes('Users')) return CippIcons.Person + return CippIcons.Shield +} + +const cippEntityHref = (part, tenantFilter) => { + if (!part?.id || !tenantFilter || !GUID_PATTERN.test(part.id)) return null + const tenant = encodeURIComponent(tenantFilter) + if (part.type === 'group') { + return `/identity/administration/groups/group?groupId=${encodeURIComponent( + part.id + )}&tenantFilter=${tenant}` + } + if (part.type === 'role') { + return `/identity/administration/roles/role?roleTemplateId=${encodeURIComponent( + part.id + )}&tenantFilter=${tenant}` + } + return null +} + +const ReasonSentence = ({ reason, tenantFilter, tone }) => { + const parts = getCaCoverageReasonParts(reason) + + return ( + + {parts.map((part, index) => { + if (part.type === 'text') { + return ( + + {part.value} + + ) + } + + const href = cippEntityHref(part, tenantFilter) + if (href) { + return ( + + ) + } + + return ( + + ) + })} + + ) +} + +const ReasonList = ({ + title, + reasons, + tone = 'success', + tenantFilter, + nestPathLoading = false, +}) => { + const items = Array.isArray(reasons) ? reasons : [] + const accent = tone === 'warning' ? 'warning.main' : 'success.main' + const Icon = tone === 'warning' ? CippIcons.PersonOff : CippIcons.Check + + return ( + + + + tone === 'warning' + ? theme.palette.warning.main + '22' + : theme.palette.success.main + '22', + color: accent, + }} + > + + + + {title} + + {nestPathLoading && } + + + {items.length === 0 ? ( + + None + + ) : ( + + {items.map((reason) => { + const ReasonIcon = reasonIcon(reason) + const typeMeta = getCaCoverageReasonTypeMeta(reason) + return ( + + + + + + + + + + {(reason?.transitive || (reason?.viaNestedGroups?.length ?? 0) > 0) && ( + + + + )} + + + + + ) + })} + + )} + + ) +} + +const CoverageWhyOffCanvas = ({ row, tenantFilter }) => { + const nestedAssignedIds = useMemo(() => collectNestResolveGroupIds(row), [row]) + const nestedKey = nestedAssignedIds.join(',') + const nestBulk = ApiPostCall({ urlFromData: true }) + const nestFetchedKey = useRef(null) + + useEffect(() => { + if (!row?.id || !tenantFilter || nestedAssignedIds.length === 0) { + nestFetchedKey.current = null + return + } + const key = `${tenantFilter}:${row.id}:${nestedKey}` + if (nestFetchedKey.current === key) return + nestFetchedKey.current = key + + nestBulk.mutate({ + url: '/api/ListGraphBulkRequest', + data: { + tenantFilter, + Requests: [ + { + id: 'memberOf', + method: 'GET', + url: `/users/${row.id}/memberOf/microsoft.graph.group?$select=id,displayName`, + }, + ...nestedAssignedIds.map((groupId) => ({ + id: `nestedUnder-${groupId}`, + method: 'GET', + url: `/groups/${groupId}/transitiveMembers/microsoft.graph.group?$select=id,displayName`, + })), + ], + }, + }) + // nestBulk.mutate is stable; intentionally omit the mutation object from deps. + // eslint-disable-next-line react-hooks/exhaustive-deps -- refetch only when nest inputs change + }, [row?.id, tenantFilter, nestedKey]) + + const viaByAssignedId = useMemo(() => { + if (!row?.id || nestedAssignedIds.length === 0) return {} + if (nestBulk.isPending) return {} + const expectedKey = `${tenantFilter}:${row.id}:${nestedKey}` + if (nestFetchedKey.current !== expectedKey) return {} + + const bulkRows = Array.isArray(nestBulk?.data?.data) ? nestBulk.data.data : [] + if (bulkRows.length === 0) return {} + + const memberOfRow = bulkRows.find((item) => item.id === 'memberOf') + const memberOfValue = + memberOfRow?.body?.value || + (Array.isArray(memberOfRow?.body) ? memberOfRow.body : []) || + [] + + const nestedUnderByAssignedId = {} + for (const groupId of nestedAssignedIds) { + const rowResult = bulkRows.find((item) => item.id === `nestedUnder-${groupId}`) + nestedUnderByAssignedId[groupId] = + rowResult?.body?.value || + (Array.isArray(rowResult?.body) ? rowResult.body : []) || + [] + } + + return resolveViaNestedGroups(memberOfValue, nestedUnderByAssignedId) + }, [nestBulk?.data, nestBulk.isPending, nestedAssignedIds, nestedKey, row?.id, tenantFilter]) + + const includeReasons = useMemo( + () => enrichReasonsWithNestPath(row?.includeReasons, viaByAssignedId), + [row?.includeReasons, viaByAssignedId] + ) + const excludeReasons = useMemo( + () => enrichReasonsWithNestPath(row?.excludeReasons, viaByAssignedId), + [row?.excludeReasons, viaByAssignedId] + ) + + const nestPathLoading = nestedAssignedIds.length > 0 && nestBulk.isPending + + if (!row) return null + const isExcluded = row.status === 'excluded' + const StatusIcon = isExcluded ? CippIcons.PersonOff : CippIcons.Check + + return ( + + + + isExcluded + ? theme.palette.warning.main + '22' + : theme.palette.success.main + '22', + color: isExcluded ? 'warning.main' : 'success.main', + flexShrink: 0, + }} + > + + + + + {row.displayName || row.userPrincipalName || row.id} + + {row.userPrincipalName && row.displayName && ( + + {row.userPrincipalName} + + )} + + {row.status && ( + } + label={formatCaCoverageStatus(row.status)} + /> + )} + {row.userType && ( + + )} + + + + + {isExcluded && (row.includeReasons?.length ?? 0) > 0 && ( + + This identity matches include rules, but an exclusion wins. Net result is excluded. + + )} + + {nestedAssignedIds.length > 0 && nestBulk.isError && ( + + Could not resolve which nested group this membership goes through. The Nested badge still + means membership is not direct. + + )} + + r.transitive)} + /> + r.transitive)} + /> + + ) +} + +/** + * Drawer showing who a CA policy's identity assignment touches and why. + * Opens from the CA policies list action. + */ +export const CippCAPolicyCoverageDrawer = ({ + policyId, + policyName, + tenantFilter, + visible: controlledVisible, + onClose: controlledOnClose, + showButton = false, + buttonText = 'View identity coverage', + requiredPermissions = ['Tenant.ConditionalAccess.Read'], + PermissionButtonComponent = PermissionButton, + ...buttonProps +}) => { + const [internalVisible, setInternalVisible] = useState(false) + const isControlled = typeof controlledVisible === 'boolean' + const drawerVisible = isControlled ? controlledVisible : internalVisible + + const handleClose = () => { + if (isControlled) { + controlledOnClose?.() + } else { + setInternalVisible(false) + } + } + + const handleOpen = () => { + if (!isControlled) { + setInternalVisible(true) + } + } + + const coverage = ApiGetCall({ + url: '/api/ListCAPolicyCoverage', + data: { tenantFilter, GUID: policyId }, + queryKey: `CAPolicyCoverage-${tenantFilter}-${policyId}`, + waiting: Boolean(drawerVisible && policyId && tenantFilter), + }) + + const results = coverage.data?.Results + const identities = Array.isArray(results?.identities) ? results.identities : [] + const summary = results?.summary + const isLoading = coverage.isFetching && !results + const title = policyName + ? `Identity coverage - ${policyName}` + : results?.displayName + ? `Identity coverage - ${results.displayName}` + : 'Identity coverage' + + const identityActions = useMemo( + () => [ + { + label: 'View User', + link: `/identity/administration/users/user?userId=[id]&tenantFilter=${encodeURIComponent( + tenantFilter || '' + )}`, + pinned: true, + multiPost: false, + hideBulk: true, + icon: , + color: 'success', + }, + { + label: 'View in Entra', + link: `https://entra.microsoft.com/${encodeURIComponent( + tenantFilter || '' + )}/#view/Microsoft_AAD_UsersAndTenants/UserProfileMenuBlade/~/overview/userId/[id]`, + external: true, + multiPost: false, + hideBulk: true, + icon: , + color: 'info', + }, + ], + [tenantFilter] + ) + + return ( + <> + {showButton && ( + } + {...buttonProps} + > + {buttonText} + + )} + + + {coverage.isError && ( + + Failed to load identity coverage. + + )} + {isLoading && ( + + + + Resolving identity coverage… + + + )} + {results && ( + + {results.includesAllUsers && ( + + )} + + + + + + + + + + {(summary?.unresolvedCount ?? 0) > 0 && ( + + )} + + )} + {results?.includesAllUsers && + !results?.hasExclusions && + identities.length === 0 && + !coverage.isFetching && ( + + This policy includes all users and has no exclusions. Individual rows appear only + when identities are also touched by a concrete assignment (users, groups, roles, or + guests). + + )} + {!coverage.isFetching && + results && + identities.length === 0 && + !(results.includesAllUsers && !results.hasExclusions) && ( + + No identities were touched by a concrete include or exclude on this policy. + + )} + {(results?.unresolved?.length ?? 0) > 0 && ( + + {results.unresolved.length} assignment reference(s) could not be resolved (deleted + users, groups, or roles). + + )} + {!isLoading && ( + ( + + ), + }} + /> + )} + + + + ) +} + +export default CippCAPolicyCoverageDrawer diff --git a/src/components/CippComponents/CippDevicePolicySettingStates.jsx b/src/components/CippComponents/CippDevicePolicySettingStates.jsx new file mode 100644 index 000000000000..5f54285f9fb0 --- /dev/null +++ b/src/components/CippComponents/CippDevicePolicySettingStates.jsx @@ -0,0 +1,192 @@ +import PropTypes from 'prop-types' +import { useMemo, useState } from 'react' +import { + Alert, + Box, + FormControlLabel, + Skeleton, + Stack, + Switch, + Typography, +} from '@mui/material' +import { ApiGetCall } from '../../api/ApiCall' +import { CippDataTable } from '../CippTable/CippDataTable' +import { getCippError } from '../../utils/get-cipp-error' + +const FAIL_SORT_PRIORITY = { + noncompliant: 0, + error: 1, + conflict: 2, +} + +const FAIL_STATES = new Set(['noncompliant', 'error', 'conflict']) + +const isFailingState = (state) => FAIL_STATES.has(String(state ?? '').toLowerCase()) + +const sortSettingStates = (rows) => + [...rows].sort((a, b) => { + const aPriority = FAIL_SORT_PRIORITY[String(a.state ?? '').toLowerCase()] ?? 10 + const bPriority = FAIL_SORT_PRIORITY[String(b.state ?? '').toLowerCase()] ?? 10 + if (aPriority !== bPriority) return aPriority - bPriority + const aName = a.settingName || a.setting || '' + const bName = b.settingName || b.setting || '' + return aName.localeCompare(bName) + }) + +const formatSources = (sources) => { + if (!Array.isArray(sources) || sources.length === 0) return '' + return sources + .map((source) => source?.displayName) + .filter(Boolean) + .join(', ') +} + +/** + * Lazy-loaded setting states for an Intune compliance or configuration policy + * on a managed device. Mount only when the parent policy card is expanded. + */ +export const CippDevicePolicySettingStates = ({ + deviceId, + policyStateId, + tenantFilter, + statesCollection, +}) => { + const [showAll, setShowAll] = useState(false) + const canFetch = Boolean(deviceId && policyStateId && tenantFilter && statesCollection) + + const settingStatesRequest = ApiGetCall({ + url: '/api/ListGraphRequest', + data: { + Endpoint: `deviceManagement/managedDevices/${deviceId}/${statesCollection}/${policyStateId}/settingStates`, + tenantFilter, + }, + queryKey: `DevicePolicySettingStates-${statesCollection}-${deviceId}-${policyStateId}-${tenantFilter}`, + waiting: canFetch, + }) + + const rows = useMemo(() => { + if (!settingStatesRequest.isSuccess) return [] + const results = settingStatesRequest.data?.Results + const rawRows = Array.isArray(results) ? results : results ? [results] : [] + return sortSettingStates(rawRows).map((row, index) => ({ + ...row, + id: row.id || `${row.settingInstanceId || row.setting || 'setting'}-${index}`, + settingName: row.settingName || row.setting || 'Unknown setting', + complianceState: row.state, + sourcesDisplay: formatSources(row.sources), + })) + }, [settingStatesRequest.isSuccess, settingStatesRequest.data]) + + const failingRows = useMemo(() => rows.filter((row) => isFailingState(row.state)), [rows]) + const displayRows = showAll ? rows : failingRows + + if (!canFetch) { + return ( + + Policy setting states cannot be loaded for this policy. + + ) + } + + if (settingStatesRequest.isFetching && !settingStatesRequest.isSuccess) { + return ( + + + + ) + } + + if (settingStatesRequest.isError) { + return ( + + + {getCippError(settingStatesRequest.error) || + 'Unable to load setting states. Try expanding this policy again.'} + + + ) + } + + if (rows.length === 0) { + return ( + + + No setting states returned for this policy. + + + ) + } + + const filterControls = ( + + + {failingRows.length} failing of {rows.length} settings + + setShowAll(event.target.checked)} + /> + } + label="Show all settings" + /> + + ) + + if (!showAll && failingRows.length === 0) { + return ( + + {filterControls} + + No failing settings. + + + ) + } + + return ( + + {filterControls} + + settingStatesRequest.refetch()} + /> + + + ) +} + +CippDevicePolicySettingStates.propTypes = { + deviceId: PropTypes.string.isRequired, + policyStateId: PropTypes.string.isRequired, + tenantFilter: PropTypes.string.isRequired, + statesCollection: PropTypes.oneOf([ + 'deviceCompliancePolicyStates', + 'deviceConfigurationStates', + ]).isRequired, +} + +export default CippDevicePolicySettingStates diff --git a/src/components/CippComponents/CippMfaVerifyForm.jsx b/src/components/CippComponents/CippMfaVerifyForm.jsx index 6853feba6083..b11052f9f291 100644 --- a/src/components/CippComponents/CippMfaVerifyForm.jsx +++ b/src/components/CippComponents/CippMfaVerifyForm.jsx @@ -20,9 +20,6 @@ const MFA_METHOD_MAP = { }, '#microsoft.graph.phoneAuthenticationMethod': { label: 'Phone (SMS or call)' }, '#microsoft.graph.fido2AuthenticationMethod': { label: 'FIDO2 security key' }, - '#microsoft.graph.windowsHelloForBusinessAuthenticationMethod': { - label: 'Windows Hello for Business', - }, '#microsoft.graph.emailAuthenticationMethod': { label: 'Email' }, } @@ -67,7 +64,8 @@ export const MfaVerifyForm = ({ formControl, row }) => { queryKey: `MFAPreferred-${tenant}-${upn}`, }) - const registered = (methods.data?.Results ?? []) + // One chip per method type: a user can register the same type many times (several devices). + const registered = [...new Map((methods.data?.Results ?? []).map((m) => [m['@odata.type'], m])).values()] .map((m) => ({ type: m['@odata.type'], ...MFA_METHOD_MAP[m['@odata.type']] })) .filter((m) => m.label) const hasPush = registered.some((m) => m.push) diff --git a/src/components/CippComponents/CippPolicyDeployDrawer.jsx b/src/components/CippComponents/CippPolicyDeployDrawer.jsx index c96c35d3d7c6..b5812cdc9e71 100644 --- a/src/components/CippComponents/CippPolicyDeployDrawer.jsx +++ b/src/components/CippComponents/CippPolicyDeployDrawer.jsx @@ -46,6 +46,10 @@ const reservedReplacementVariables = new Set( 'cippurl', 'defaultdomain', 'organizationid', + // Apple enrollment (ADE) token binding. Resolved per tenant from the tenant's ADETokenId custom + // variable at deploy time; if it is unset the backend returns a clear error naming the tenant's + // real token id, so the token is never prompted for or shown in this drawer. + 'adetokenid', ].map((variable) => variable.toLowerCase()), ) diff --git a/src/components/CippComponents/CippTranslations.jsx b/src/components/CippComponents/CippTranslations.jsx index d4065e067fb2..dab26621d981 100644 --- a/src/components/CippComponents/CippTranslations.jsx +++ b/src/components/CippComponents/CippTranslations.jsx @@ -23,6 +23,7 @@ export const CippTranslations = { lastOutcome: 'Last Outcome', feedEvent: 'Event', detail: 'Detail', + Detail: 'Details', outcome: 'Outcome', runId: 'Run ID', mode: 'Mode', @@ -30,6 +31,8 @@ export const CippTranslations = { baselineName: 'Baseline', secureScoreImpact: 'Secure Score Impact', userPrincipalName: 'User Principal Name', + includeReasons: 'Included via', + excludeReasons: 'Excluded via', aadRegistered: 'Microsoft Entra Registered', azureADRegistered: 'Microsoft Entra Registered', azureActiveDirectoryDeviceId: 'Microsoft Entra Device ID', @@ -132,4 +135,9 @@ export const CippTranslations = { unknownFutureValue: 'Unknown', devicePrepData: 'Corporate Identifiers', overwriteExisting: 'Overwrite Existing Identifiers', + // Instance Diagnostics + BusiestClient: 'Busiest Client Before Event', + RequestsPriorHour: 'Requests In Prior Hour', + BaselinePerHour: 'Baseline / Hr', + SharePct: 'Share %', } diff --git a/src/components/CippComponents/ForcedSsoMigrationDialog.jsx b/src/components/CippComponents/ForcedSsoMigrationDialog.jsx index 8c60479a247e..0b7a7e68adce 100644 --- a/src/components/CippComponents/ForcedSsoMigrationDialog.jsx +++ b/src/components/CippComponents/ForcedSsoMigrationDialog.jsx @@ -103,7 +103,7 @@ export const ForcedSsoMigrationDialog = () => { An app registration named CIPP-SSO in your partner tenant, - requesting three delegated Microsoft Graph permissions and no application + requesting four delegated Microsoft Graph permissions and no application permissions at all: @@ -118,6 +118,10 @@ export const ForcedSsoMigrationDialog = () => { email — reads the UPN, which CIPP matches against the CIPP Users list to decide their roles. +
  • + offline_access — issues a refresh token so the sign-in session + can be renewed without signing in again. Grants no additional data access. +
  • { To get ready, CIPP needs to create an app registration in your tenant called - CIPP-SSO with minimal permissions (OpenID, Profile, Email only). + CIPP-SSO with minimal permissions (OpenID, Profile, Email, Offline + Access only). This won't change how you log in today — it just prepares your tenant for when the update rolls out. diff --git a/src/components/CippSettings/CippRoleAddEdit.jsx b/src/components/CippSettings/CippRoleAddEdit.jsx index f13c3b3ad343..e213ebb888e6 100644 --- a/src/components/CippSettings/CippRoleAddEdit.jsx +++ b/src/components/CippSettings/CippRoleAddEdit.jsx @@ -46,7 +46,6 @@ export const CippRoleAddEdit = ({ selectedRole }) => { const [allTenantSelected, setAllTenantSelected] = useState(false); const [cippApiRoleSelected, setCippApiRoleSelected] = useState(false); const [selectedRoleState, setSelectedRoleState] = useState(null); - const [updateDefaults, setUpdateDefaults] = useState(false); const [baseRolePermissions, setBaseRolePermissions] = useState({}); const [isBaseRole, setIsBaseRole] = useState(false); // New roles start in simple (pattern) mode; existing roles pick their mode in the @@ -246,6 +245,8 @@ export const CippRoleAddEdit = ({ selectedRole }) => { if ( (customRoleListSuccess && tenantsSuccess && + // The grid is built from the permission list; loading before it arrives yields {}. + apiPermissionSuccess && selectedRole && selectedRoleState !== selectedRole) || // An empty {} isn't a real change — only a populated baseRolePermissions should retrigger this. @@ -329,7 +330,10 @@ export const CippRoleAddEdit = ({ selectedRole }) => { Object.keys(apiPermissions[cat]).forEach((obj) => { const key = `${cat}${obj}`; const existingPerm = permissions?.[key]; - processed[key] = existingPerm || `${cat}.${obj}.None`; + // Roles saved while the bug above was live hold ".undefined"; treat as None. + processed[key] = /\.(None|Read|ReadWrite)$/.test(existingPerm) + ? existingPerm + : `${cat}.${obj}.None`; }); }); return processed; @@ -376,11 +380,12 @@ export const CippRoleAddEdit = ({ selectedRole }) => { setGridDiverged(false); } } - }, [customRoleList, customRoleListSuccess, tenantsSuccess, baseRolePermissions]); + }, [customRoleList, customRoleListSuccess, tenantsSuccess, apiPermissionSuccess, baseRolePermissions]); useEffect(() => { - if (updateDefaults !== setDefaults) { - setUpdateDefaults(setDefaults); + // Only a real "Set All" selection applies; the watched field is undefined on mount + // and after reset(), and applying that wrote "Cat.Obj.undefined" for every row. + if (setDefaults) { var newPermissions = {}; Object.keys(apiPermissions).forEach((cat) => { Object.keys(apiPermissions[cat]).forEach((obj) => { @@ -395,7 +400,7 @@ export const CippRoleAddEdit = ({ selectedRole }) => { }); formControl.setValue("Permissions", newPermissions); } - }, [setDefaults, updateDefaults]); + }, [setDefaults]); useEffect(() => { var alltenant = false; diff --git a/src/components/CippSettings/CippSSOSettings.jsx b/src/components/CippSettings/CippSSOSettings.jsx index af27704fc78a..a229e1553012 100644 --- a/src/components/CippSettings/CippSSOSettings.jsx +++ b/src/components/CippSettings/CippSSOSettings.jsx @@ -30,7 +30,7 @@ import { CippApiResults } from "../CippComponents/CippApiResults"; const SSO_DOCS_URL = "https://docs.cipp.app/user-documentation/cipp/advanced/authentication/sso"; -// The three delegated scopes New-CIPPSSOApp requests. Kept here verbatim so an admin can hand +// The four delegated scopes New-CIPPSSOApp requests. Kept here verbatim so an admin can hand // this straight to their own security team without having to ask what the app can reach. const ssoAppPermissions = [ { @@ -47,6 +47,11 @@ const ssoAppPermissions = [ reason: "Reads the signed-in user's UPN, which CIPP matches against the CIPP Users list to decide their roles.", }, + { + name: "offline_access", + reason: + "Issues a refresh token so a signed-in session can be renewed without the user signing in again. Grants no additional data access.", + }, ]; // Application permissions already consented on CIPP-SAM that the setup runs as. Nothing new is @@ -59,7 +64,7 @@ const samPermissionsUsed = [ { name: "Directory.ReadWrite.All", reason: - "Grants tenant-wide consent for the three scopes above so your users are not prompted to consent at sign-in.", + "Grants tenant-wide consent for the four scopes above so your users are not prompted to consent at sign-in.", }, { name: "Policy.ReadWrite.ApplicationConfiguration", @@ -359,9 +364,9 @@ export const CippSSOSettings = () => { }}> No application (app-only) permissions are requested, so the app can never act without a signed-in user. None of these scopes grant access to mail, files, - Teams or directory data — they are the standard OpenID Connect sign-in scopes, - classed by Microsoft as low impact. Who can actually reach CIPP is still - controlled by the CIPP Users list. + Teams or directory data — they are the standard OpenID Connect sign-in scopes + plus offline_access to renew the session, all classed by Microsoft as low + impact. Who can actually reach CIPP is still controlled by the CIPP Users list. diff --git a/src/components/CippTable/CIPPTableToptoolbar.jsx b/src/components/CippTable/CIPPTableToptoolbar.jsx index 30cbe5824bd1..6268fd97372b 100644 --- a/src/components/CippTable/CIPPTableToptoolbar.jsx +++ b/src/components/CippTable/CIPPTableToptoolbar.jsx @@ -619,7 +619,10 @@ export const CIPPTableToptoolbar = React.memo( if (table?.type === 'global' && typeof table.value !== 'string') { return { graph: last.graph ?? null, table: null } } - return { graph: last.graph ?? null, table } + // corrupted echo can persist graph.value as a bare guid string instead of an object + const graph = + last.graph && typeof last.graph.value !== 'object' ? null : last.graph ?? null + return { graph, table } } // legacy single-slot {type, value, name} if (last.type === 'graph') { diff --git a/src/components/CippTable/CippGraphExplorerFilter.jsx b/src/components/CippTable/CippGraphExplorerFilter.jsx index eba6c6cbf83b..b018d84b768e 100644 --- a/src/components/CippTable/CippGraphExplorerFilter.jsx +++ b/src/components/CippTable/CippGraphExplorerFilter.jsx @@ -260,8 +260,8 @@ const CippGraphExplorerFilter = ({ setLastPresetTitle(selectedPresets.label) formControl.reset(params, { keepDefaultValues: true }) - // Notify parent when preset changes in this component - if (onPresetSelect) { + // Notify parent only on user-driven changes, not the sync effect echoing selectedPreset back + if (onPresetSelect && selectedPresets.value !== selectedPreset?.id) { onPresetSelect(selectedPresets) } } diff --git a/src/components/ReleaseNotesDialog.jsx b/src/components/ReleaseNotesDialog.jsx index 9a538d08d3bf..2fdc7e1a9c01 100644 --- a/src/components/ReleaseNotesDialog.jsx +++ b/src/components/ReleaseNotesDialog.jsx @@ -488,6 +488,9 @@ export const ReleaseNotesDialog = forwardRef((_props, ref) => { pt: 1, pb: 0, flex: 1, + // Flex children default to min-height:auto and refuse to shrink below their + // content, so the notes box below could never scroll. This lets it. + minHeight: 0, display: 'flex', // Drop MUI's default side padding; prose padding lives on the scroll box / // banners instead. Theme hides the mobile gutter entirely below `lg`. @@ -526,11 +529,11 @@ export const ReleaseNotesDialog = forwardRef((_props, ref) => { ago(1h)\n| where Message !contains \"heartbeat\"\n| take 1000\n| sort by Timestamp desc" + }, + { + "name": "API Client Access (Last 24h)", + "id": "cl-preset-api-client-access", + "query": "search all files\n| where Message contains \"API Access: AppName=\"\n| where Timestamp > ago(24h)\n| take 1000\n| sort by Timestamp desc" + }, + { + "name": "Out of Memory / Watchdog Restarts", + "id": "cl-preset-oom-watchdog", + "query": "search all files\n| where Message matches regex \"OutOfMemoryException|Container startup attempt|Restart counter\"\n| take 500\n| sort by Timestamp desc" + }, + { + "name": "HTTP Pool Exhausted", + "id": "cl-preset-http-pool-exhausted", + "query": "search all files\n| where Message contains \"HTTP pool exhausted\"\n| where Timestamp > ago(24h)\n| take 500\n| sort by Timestamp desc" + }, + { + "name": "Slow Requests (HTTP timings)", + "id": "cl-preset-slow-requests", + "query": "where Message matches regex \"\\\\[HTTP\\\\] \\\\S+ \\\\S+ \\\\d{3} \\\\d{5,}ms\"\n| where Timestamp > ago(24h)\n| take 500\n| sort by Timestamp desc" } ] diff --git a/src/data/standards.json b/src/data/standards.json index c645548e7d22..4653ad33f0aa 100644 --- a/src/data/standards.json +++ b/src/data/standards.json @@ -1741,7 +1741,7 @@ "cat": "Entra (AAD) Standards", "tag": ["CIS M365 7.0.0 (1.3.4)", "SMB1001 (2.8)"], "appliesToTest": ["CIS_1_3_4", "EIDSCAAP05", "SMB1001_2_8"], - "helpText": "**Requires 'Billing Administrator' GDAP role.** This standard disables all self service licenses and enables all exclusions", + "helpText": "This standard disables all self service licenses and enables all exclusions", "executiveText": "Prevents employees from purchasing Microsoft 365 licenses independently, ensuring all software acquisitions go through proper procurement channels. This maintains budget control, prevents unauthorized spending, and ensures compliance with corporate licensing agreements.", "addedComponent": [ { @@ -1760,7 +1760,7 @@ "impact": "Medium Impact", "impactColour": "warning", "addedDate": "2021-11-16", - "powershellEquivalent": "Set-MsolCompanySettings -AllowAdHocSubscriptions $false", + "powershellEquivalent": "Update-MSCommerceProductPolicy -PolicyId AllowSelfServicePurchase -Value Disabled", "recommendedBy": [] }, { @@ -1768,8 +1768,9 @@ "cat": "Entra (AAD) Standards", "tag": ["SMB1001 (2.8)"], "appliesToTest": ["SMB1001_2_8", "ZTNA21858"], - "helpText": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone.", - "executiveText": "Automatically disables external guest accounts that haven't been used for a number of days, reducing security risks from dormant accounts while maintaining access for active external collaborators. This helps maintain a clean user directory and reduces potential attack vectors.", + "helpText": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Optionally soft-deletes already-disabled guests after a configurable grace period past that threshold (0 = never delete). Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. Deleted guests remain recoverable from Deleted Items for about 30 days.", + "docsDescription": "Blocks login for guest users whose most recent sign-in attempt, interactive or non-interactive, is older than the number of days. Remediation first disables stale enabled guests, and later soft-deletes guests that are already disabled once they have been inactive for the disable threshold plus the configured grace delta (deletion age = days + deleteGraceDays). The disable-before-delete grace is further guaranteed by never deleting a guest in the same pass it was disabled. Guests that have never signed in are only included when 'Disable accounts that have not yet signed in' is enabled. Accounts an administrator re-enabled in the last 7 days are left alone. Graph user DELETE is a soft-delete (recoverable from Deleted Items for about 30 days), which lets a later re-invite create a clean guest object instead of colliding with a disabled account.", + "executiveText": "Automatically disables external guest accounts that haven't been used for a number of days, and can optionally remove already-disabled dormant guests after an additional grace period. This reduces security risks from abandoned external access, keeps the directory clean, and avoids errors when previously disabled guests need to be invited back.", "addedComponent": [ { "type": "number", @@ -1778,6 +1779,15 @@ "defaultValue": 90, "label": "Days of inactivity" }, + { + "type": "number", + "name": "standards.DisableGuests.deleteGraceDays", + "label": "Grace days after disable before deletion (0 = never delete). Guests are deleted once inactive for the disable threshold plus this many additional days.", + "defaultValue": 0, + "validators": { + "min": { "value": 0, "message": "Minimum value is 0" } + } + }, { "type": "switch", "name": "standards.DisableGuests.IncludeNeverSignedIn", @@ -1786,8 +1796,8 @@ } ], "label": "Disable Guest accounts that have not logged on for a number of days", - "impact": "Medium Impact", - "impactColour": "warning", + "impact": "High Impact", + "impactColour": "danger", "addedDate": "2022-10-20", "powershellEquivalent": "Graph API", "recommendedBy": ["CIS", "CIPP"], diff --git a/src/pages/cipp/advanced/container-management/diagnostics.jsx b/src/pages/cipp/advanced/container-management/diagnostics.jsx new file mode 100644 index 000000000000..9ddc66d2d9a3 --- /dev/null +++ b/src/pages/cipp/advanced/container-management/diagnostics.jsx @@ -0,0 +1,569 @@ +import { useMemo, useState } from "react"; +import { CippIcons } from "../../../../utils/icon-registry"; +import Head from "next/head"; +import { + Alert, + Box, + Card, + CardContent, + CardHeader, + CircularProgress, + Container, + IconButton, + Stack, + ToggleButton, + ToggleButtonGroup, + Tooltip, + Typography, +} from "@mui/material"; +import { Grid } from "@mui/system"; +import { useTheme } from "@mui/material/styles"; +import { useQueryClient } from "@tanstack/react-query"; +import { + AreaChart, + BarChart, + ComposedChart, + Area, + Bar, + Line, + CartesianGrid, + XAxis, + YAxis, + ResponsiveContainer, + Tooltip as RechartsTooltip, + Legend, + ReferenceLine, +} from "recharts"; +import { Layout as DashboardLayout } from "../../../../layouts/index"; +import { TabbedLayout } from "../../../../layouts/TabbedLayout"; +import { ApiGetCall } from "../../../../api/ApiCall"; +import { CippDataTable } from "../../../../components/CippTable/CippDataTable"; +import tabOptions from "./tabOptions"; +import { useTitleClaimedByTabPicker } from "../../../../layouts/tab-navigation-context"; +import { + aggregateDiagnosticsClients, + sortDiagnosticsChecks, + buildClientLogQuery, + buildRequestSeries, + getCheckLabel, + formatBytes, +} from "../../../../utils/instance-diagnostics"; + +const WINDOWS = [ + { label: "6h", hours: 6 }, + { label: "24h", hours: 24 }, + { label: "3d", hours: 72 }, + { label: "7d", hours: 168 }, + { label: "14d", hours: 336 }, +]; + +// Maps the backend's check vocabulary onto the labels the shared Status chip +// formatter (get-cipp-formatting.jsx) already recognizes, rather than adding a +// one-off chip renderer for this page. +const STATUS_LABEL = { FAIL: "Failed", WARN: "Warning", PASS: "Passed", INFO: "Info" }; + +const formatChartTime = (bucket, hours) => { + // Bucket is a naive 'yyyy-MM-ddTHH:mm' UTC string — force UTC parsing. + const d = new Date(`${bucket}:00Z`); + if (hours <= 24) { + return d.toLocaleTimeString("en-US", { hour: "2-digit", minute: "2-digit" }); + } + return d.toLocaleDateString("en-US", { month: "short", day: "numeric", hour: "2-digit", minute: "2-digit" }); +}; + +// Always the full date + time — a bare clock time is ambiguous on a multi-day window. +const formatFullDateTime = (bucket) => { + const d = new Date(`${bucket}:00Z`); + return d.toLocaleString("en-US", { + month: "short", + day: "numeric", + hour: "2-digit", + minute: "2-digit", + }); +}; + +const formatRatio = (ratio) => (ratio != null ? `${ratio}x` : "—"); + +// Same nested view for a client's log lines, used both from the API Clients table +// and from a client row inside an Event's off-canvas. +const ClientLogsTable = ({ appId, hours }) => { + const logsQuery = ApiGetCall({ + url: "/api/ListContainerLogs", + data: { Action: "Query", Query: buildClientLogQuery(appId, hours) }, + queryKey: `InstanceDiagnosticsClientLogs-${appId}-${hours}`, + waiting: !!appId, + // Log lines change every second; never serve a cached result when the drawer opens. + staleTime: 0, + }); + + return ( + + ); +}; + +const clientLogsOffCanvas = (hours) => ({ + size: "lg", + title: "Client Log Lines", + children: (row) => , +}); + +const ChecksCard = ({ checks, isFetching, refreshFunction }) => { + const rows = useMemo( + () => + sortDiagnosticsChecks(checks).map((c) => ({ + ...c, + Check: getCheckLabel(c.Check), + Status: STATUS_LABEL[c.Status] ?? c.Status, + })), + [checks] + ); + + return ( + + ); +}; + +const buildEventRows = (events) => + (events ?? []).map((e, i) => { + const topClients = e.TopClients ?? []; + const busiest = topClients[0]; + return { + id: `${e.Bucket}-${i}`, + Time: formatFullDateTime(e.Bucket), + Event: e.Type === "boot" ? "Container restarted" : "Out of memory", + Outage: e.Type === "boot" && e.GapMinutes != null ? `${e.GapMinutes} min` : "", + BusiestClient: busiest ? busiest.AppName || busiest.AppId : "—", + RequestsPriorHour: busiest?.Count ?? "—", + BaselinePerHour: busiest?.Baseline ?? "—", + Ratio: formatRatio(busiest?.Ratio), + TopClients: topClients.map((c) => ({ + Client: c.AppName || c.AppId, + AppId: c.AppId, + IP: c.IP, + Count: c.Count, + Baseline: c.Baseline, + Ratio: formatRatio(c.Ratio), + })), + }; + }); + +const EventsCard = ({ events, hours, isFetching, refreshFunction }) => { + const rows = useMemo(() => buildEventRows(events), [events]); + + return ( + ( + + ), + }} + /> + ); +}; + +const ApiClientsCard = ({ buckets, hours, isFetching, refreshFunction }) => { + const rows = useMemo( + () => + aggregateDiagnosticsClients(buckets).map((c) => ({ + ...c, + Client: c.AppName || c.AppId, + })), + [buckets] + ); + + return ( + + ); +}; + +// primary and warning are both orange in the CIPP theme, so they never sit side by side. +const CLIENT_COLOR_KEYS = ["primary", "info", "success", "secondary"]; + +// Small bordered sub-chart, stacked full-width under the "Health Timeline" card header so +// every sub-chart's x-axis lines up (same buckets, same left margin). +const SubChart = ({ title, caption, height = 220, children }) => ( + + `1px solid ${t.palette.divider}`, borderRadius: 1, p: 1.5 }}> + + {title} + + {caption && ( + + {caption} + + )} + + + {children} + + + + +); + +const chartTooltipStyle = (t) => ({ + contentStyle: { + backgroundColor: t.palette.background.paper, + border: `1px solid ${t.palette.divider}`, + borderRadius: 4, + }, +}); + +const RequestsChart = ({ data, series, theme: t }) => ( + + + + + + + + + {series.map((s, i) => ( + + ))} + {data.some((row) => row.Other > 0) && ( + + )} + + +); + +const EgressChart = ({ data, todayBytes, capBytes, theme: t }) => { + const caption = + todayBytes == null + ? null + : capBytes + ? `Today: ${formatBytes(todayBytes)} of ${formatBytes(capBytes)} (${Math.round( + (todayBytes / capBytes) * 100 + )}%)` + : `Today: ${formatBytes(todayBytes)}`; + + return ( + + + + + + + [`${value} MB`, "Egress"]} /> + + + + + ); +}; + +const HeapChart = ({ data, heapCapMb, eventMarkers, theme: t }) => { + const peak = data.reduce((max, d) => (d.Heap != null && d.Heap > max ? d.Heap : max), 0); + const domainMax = Math.max(heapCapMb || 0, peak) * 1.05; + + return ( + + + + + + + + + + {heapCapMb ? ( + + ) : null} + {eventMarkers.map((e, i) => ( + + ))} + + + ); +}; + +const PoolChart = ({ data, theme: t }) => ( + + + + + + + + + + + + +); + +const Page = () => { + const theme = useTheme(); + const titleClaimed = useTitleClaimedByTabPicker("Diagnostics"); + const queryClient = useQueryClient(); + const [hours, setHours] = useState(24); + + const checksQuery = ApiGetCall({ + url: "/api/ListInstanceDiagnostics", + data: { Action: "Checks", Hours: String(hours) }, + queryKey: `InstanceDiagnosticsChecks-${hours}`, + }); + + const timelineQuery = ApiGetCall({ + url: "/api/ListInstanceDiagnostics", + data: { Action: "Timeline", Hours: String(hours) }, + queryKey: `InstanceDiagnosticsTimeline-${hours}`, + }); + + const checks = checksQuery.data?.Results ?? []; + const buckets = useMemo(() => timelineQuery.data?.Results?.Buckets ?? [], [timelineQuery.data]); + const events = useMemo(() => timelineQuery.data?.Results?.Events ?? [], [timelineQuery.data]); + const heapCapMb = timelineQuery.data?.Results?.HeapCapMb ?? null; + const egressAvailable = timelineQuery.data?.Results?.EgressAvailable ?? false; + const egressCapBytes = timelineQuery.data?.Results?.EgressCapBytes ?? null; + const isFetching = checksQuery.isFetching || timelineQuery.isFetching; + + const chartData = useMemo( + () => + buckets.map((b) => ({ + ...b, + time: formatChartTime(b.Bucket, hours), + Heap: b.HeapMb ?? b.HeapMbLive ?? null, + })), + [buckets, hours] + ); + + const requestSeries = useMemo(() => buildRequestSeries(buckets), [buckets]); + const requestChartData = useMemo( + () => requestSeries.data.map((row) => ({ ...row, time: formatChartTime(row.Bucket, hours) })), + [requestSeries, hours] + ); + + const egressChartData = useMemo( + () => + buckets.map((b) => ({ + time: formatChartTime(b.Bucket, hours), + EgressMb: b.EgressBytes != null ? Math.round((b.EgressBytes / 1048576) * 10) / 10 : null, + })), + [buckets, hours] + ); + // Newest bucket that actually carries a reading - later buckets in the window can be empty. + const egressToday = [...buckets].reverse().find((b) => b.EgressBytesToday != null)?.EgressBytesToday ?? null; + + const showPoolChart = buckets.some( + (b) => (b.PoolExhaustedCount ?? 0) > 0 || (b.MaxLimiterWaitMs ?? 0) >= 10000 + ); + const poolChartData = useMemo( + () => chartData.map((b) => ({ ...b, MaxLimiterWaitSec: (b.MaxLimiterWaitMs ?? 0) / 1000 })), + [chartData] + ); + + // Only draw a marker for events whose bucket landed in this window's samples — + // an event just outside the sample set has no x-axis category to attach to. + const eventMarkers = useMemo(() => { + const timeByBucket = new Map(buckets.map((b) => [b.Bucket, formatChartTime(b.Bucket, hours)])); + return events + .map((e) => ({ ...e, time: timeByBucket.get(e.Bucket) })) + .filter((e) => e.time != null); + }, [events, buckets, hours]); + + const handleRefresh = () => { + queryClient.invalidateQueries({ queryKey: [`InstanceDiagnosticsChecks-${hours}`] }); + queryClient.invalidateQueries({ queryKey: [`InstanceDiagnosticsTimeline-${hours}`] }); + }; + + const isEmpty = + !checksQuery.isFetching && + !timelineQuery.isFetching && + checks.length === 0 && + buckets.length === 0 && + events.length === 0; + + return ( + <> + + Diagnostics | CIPP + + + + + {/* ── Header toolbar ── */} + + {titleClaimed ? : Diagnostics} + + {isFetching && } + val !== null && setHours(val)} + size="small" + > + {WINDOWS.map((w) => ( + + {w.label} + + ))} + + + + + + + + + + {isEmpty && ( + + No diagnostic samples yet — samples are collected every 5 minutes, so this fills + in as the instance keeps running. + + )} + + {!isEmpty && ( + <> + {/* ── Checks ── */} + + + {/* ── Health Timeline ── */} + + } + slotProps={{ title: { variant: "h6" } }} + /> + + {chartData.length === 0 ? ( + + No timeline samples in this window yet + + ) : ( + + + {egressAvailable && ( + + )} + + {showPoolChart && } + + )} + + + + {/* ── Events ── */} + + + {/* ── API clients ── */} + + + )} + + + + + ); +}; + +Page.getLayout = (page) => ( + + {page} + +); + +export default Page; diff --git a/src/pages/cipp/advanced/container-management/tabOptions.json b/src/pages/cipp/advanced/container-management/tabOptions.json index 3f381899d4f8..7af2356c2e56 100644 --- a/src/pages/cipp/advanced/container-management/tabOptions.json +++ b/src/pages/cipp/advanced/container-management/tabOptions.json @@ -18,5 +18,10 @@ "label": "Worker Health", "path": "/cipp/advanced/container-management/worker-health", "icon": "Timeline" + }, + { + "label": "Diagnostics", + "path": "/cipp/advanced/container-management/diagnostics", + "icon": "FactCheck" } ] diff --git a/src/pages/copilot/settings/index.jsx b/src/pages/copilot/settings/index.jsx index 87eff0f1bbf6..42f4e10c0ca8 100644 --- a/src/pages/copilot/settings/index.jsx +++ b/src/pages/copilot/settings/index.jsx @@ -19,6 +19,11 @@ const Page = () => { 'microsoft.copilot.allowwebsearch', 'microsoft.copilot.imagegeneration', ].includes(row.settingId), + hideCondition: (row) => + [ + 'microsoft.copilot.allowwebsearch', + 'microsoft.copilot.imagegeneration', + ].includes(row.settingId), fields: [ { type: 'autoComplete', @@ -44,6 +49,7 @@ const Page = () => { icon: , data: { settingId: 'settingId' }, condition: (row) => row.settingId === 'microsoft.copilot.imagegeneration', + hideCondition: (row) => row.settingId !== 'microsoft.copilot.imagegeneration', fields: [ { type: 'autoComplete', @@ -69,6 +75,7 @@ const Page = () => { icon: , data: { settingId: 'settingId' }, condition: (row) => row.settingId === 'microsoft.copilot.allowwebsearch', + hideCondition: (row) => row.settingId !== 'microsoft.copilot.allowwebsearch', fields: [ { type: 'autoComplete', diff --git a/src/pages/endpoint/MEM/devices/device/index.jsx b/src/pages/endpoint/MEM/devices/device/index.jsx index f572cedbd8da..8b195ef18363 100644 --- a/src/pages/endpoint/MEM/devices/device/index.jsx +++ b/src/pages/endpoint/MEM/devices/device/index.jsx @@ -21,6 +21,7 @@ import { CippDataTable } from '../../../../../components/CippTable/CippDataTable import { CippHead } from '../../../../../components/CippComponents/CippHead' import { Button } from '@mui/material' import { getCippFormatting } from '../../../../../utils/get-cipp-formatting' +import { CippDevicePolicySettingStates } from '../../../../../components/CippComponents/CippDevicePolicySettingStates' const Page = () => { const userSettingsDefaults = useSettings() @@ -140,6 +141,18 @@ const Page = () => { const users = usersData?.body?.value || [] const deviceMemberOf = deviceMemberOfData?.body?.value || [] + // Graph bulk items omit `error.message` on many failures (message is under body.error), + // and a missing item makes `status !== 200` true — treat only real HTTP failures as errors. + const isBulkRequestFailed = (item) => + item != null && typeof item.status === 'number' && (item.status < 200 || item.status >= 300) + + const getBulkFailureMessage = (item, fallback) => + item?.error?.message || + item?.body?.error?.message || + (typeof item?.body?.error === 'string' ? item.body.error : null) || + (item?.status ? `Unable to load this data (HTTP ${item.status}).` : null) || + fallback + // Helper function to format bytes to GB (matching getCippFormatting pattern) const formatBytesToGB = (bytes) => { if (!bytes || bytes === 0) return 'N/A' @@ -202,11 +215,13 @@ const Page = () => { return } + const tenantFilter = router.query.tenantFilter ?? userSettingsDefaults.currentTenant + // Prepare compliance policy items let compliancePolicyItems = [] if (deviceCompliance.length > 0) { compliancePolicyItems = deviceCompliance.map((policy, index) => ({ - id: index, + id: policy.id || `compliance-${index}`, cardLabelBox: { cardLabelBoxHeader: policy.complianceState === 'compliant' ? : , }, @@ -219,19 +234,26 @@ const Page = () => { label: 'Setting Count', value: policy.settingCount || 'N/A', }, - { - label: 'Setting States', - value: policy.settingStates?.length || 0, - }, ], + children: policy.id ? ( + + ) : null, })) - } else if (deviceComplianceData?.status !== 200) { + } else if (isBulkRequestFailed(deviceComplianceData) || deviceBulkRequest.isError) { compliancePolicyItems = [ { id: 1, cardLabelBox: '!', text: 'Error loading compliance policies', - subtext: deviceComplianceData?.error?.message || 'Unknown error', + subtext: getBulkFailureMessage( + deviceComplianceData, + 'Unable to load compliance policies. Try refreshing the device.' + ), statusColor: 'error.main', statusText: 'Error', propertyItems: [], @@ -255,7 +277,7 @@ const Page = () => { let configurationPolicyItems = [] if (deviceConfiguration.length > 0) { configurationPolicyItems = deviceConfiguration.map((policy, index) => ({ - id: index, + id: policy.id || `configuration-${index}`, cardLabelBox: { cardLabelBoxHeader: policy.state === 'compliant' ? : , }, @@ -268,19 +290,26 @@ const Page = () => { label: 'Setting Count', value: policy.settingCount || 'N/A', }, - { - label: 'Setting States', - value: policy.settingStates?.length || 0, - }, ], + children: policy.id ? ( + + ) : null, })) - } else if (deviceConfigurationData?.status !== 200) { + } else if (isBulkRequestFailed(deviceConfigurationData) || deviceBulkRequest.isError) { configurationPolicyItems = [ { id: 1, cardLabelBox: '!', text: 'Error loading configuration policies', - subtext: deviceConfigurationData?.error?.message || 'Unknown error', + subtext: getBulkFailureMessage( + deviceConfigurationData, + 'Unable to load configuration policies. Try refreshing the device.' + ), statusColor: 'error.main', statusText: 'Error', propertyItems: [], @@ -322,13 +351,16 @@ const Page = () => { }, }, ] - } else if (detectedAppsData?.status !== 200) { + } else if (isBulkRequestFailed(detectedAppsData) || deviceBulkRequest.isError) { detectedAppsItems = [ { id: 1, cardLabelBox: '!', text: 'Error loading detected applications', - subtext: detectedAppsData?.error?.message || 'Unknown error', + subtext: getBulkFailureMessage( + detectedAppsData, + 'Unable to load detected applications. Try refreshing the device.' + ), statusColor: 'error.main', statusText: 'Error', propertyItems: [], @@ -378,13 +410,16 @@ const Page = () => { }, }, ] - } else if (usersData?.status !== 200) { + } else if (isBulkRequestFailed(usersData) || deviceBulkRequest.isError) { usersItems = [ { id: 1, cardLabelBox: '!', text: 'Error loading device users', - subtext: usersData?.error?.message || 'Unknown error', + subtext: getBulkFailureMessage( + usersData, + 'Unable to load associated users. Try refreshing the device.' + ), statusColor: 'error.main', statusText: 'Error', propertyItems: [], @@ -439,13 +474,16 @@ const Page = () => { }, }, ] - : deviceMemberOfData && deviceMemberOfData.status !== 200 + : isBulkRequestFailed(deviceMemberOfData) || deviceBulkRequest.isError ? [ { id: 1, cardLabelBox: '!', text: 'Error loading device group memberships', - subtext: deviceMemberOfData?.error?.message || 'Unknown error', + subtext: getBulkFailureMessage( + deviceMemberOfData, + 'Unable to load group memberships. Try refreshing the device.' + ), statusColor: 'error.main', statusText: 'Error', propertyItems: [], @@ -609,6 +647,18 @@ const Page = () => { {getCippFormatting(data?.complianceState, 'complianceState') || 'N/A'}
    + {data?.complianceGracePeriodExpirationDateTime && ( + + + Grace period expires: + + + {new Date(data.complianceGracePeriodExpirationDateTime).toLocaleString()} + + + )} { const apiData = {} if (roleTemplateId) apiData.roleTemplateId = roleTemplateId if (principalId) apiData.principalId = principalId + const tenantQuery = + currentTenant === 'AllTenants' ? '[Tenant]' : currentTenant const actions = [ + { + label: 'View Role', + link: `/identity/administration/roles/role?roleTemplateId=[RoleDefinitionId]&tenantFilter=${tenantQuery}`, + pinned: true, + color: 'info', + icon: , + }, { label: 'Create template from role settings', type: 'POST', @@ -169,6 +178,10 @@ const Page = () => { 'IsPrivilegedRole', 'PolicySummary', ]} + rowOpen={{ + link: `/identity/administration/roles/role?roleTemplateId=[RoleDefinitionId]&tenantFilter=${tenantQuery}`, + condition: (row) => Boolean(row?.RoleDefinitionId), + }} /> ) } diff --git a/src/pages/identity/administration/roles/role/audit.jsx b/src/pages/identity/administration/roles/role/audit.jsx new file mode 100644 index 000000000000..21abae890a5f --- /dev/null +++ b/src/pages/identity/administration/roles/role/audit.jsx @@ -0,0 +1,178 @@ +import { Layout as DashboardLayout } from '../../../../../layouts/index' +import { CippIcons } from '../../../../../utils/icon-registry' +import { useSettings } from '../../../../../hooks/use-settings' +import { useRouter } from 'next/router' +import { ApiGetCall } from '../../../../../api/ApiCall' +import CippFormSkeleton from '../../../../../components/CippFormPages/CippFormSkeleton' +import { HeaderedTabbedLayout } from '../../../../../layouts/HeaderedTabbedLayout' +import { CippEntitySwitcher } from '../../../../../components/CippComponents/CippEntitySwitcher' +import tabOptions from './tabOptions.json' +import { CippCopyToClipBoard } from '../../../../../components/CippComponents/CippCopyToClipboard' +import { Alert, Chip, Tooltip } from '@mui/material' +import { CippHead } from '../../../../../components/CippComponents/CippHead' +import { CippTablePage } from '../../../../../components/CippComponents/CippTablePage.jsx' +import CippJsonView from '../../../../../components/CippFormPages/CippJSONView' +import { PRIVILEGED_ROLE_TOOLTIP, getRoleRow } from '../../../../../utils/role-detail-shared' + +const GUID_RE = + /^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$/i + +const buildRoleAuditFilter = (roleTemplateId, days = 30) => { + const clampedDays = Math.min(90, Math.max(1, Number(days) || 30)) + const start = new Date() + start.setUTCDate(start.getUTCDate() - clampedDays) + const startTime = start.toISOString().replace(/\.\d{3}Z$/, 'Z') + return `activityDateTime ge ${startTime} and targetResources/any(s:s/id eq '${roleTemplateId}')` +} + +const Page = () => { + const userSettingsDefaults = useSettings() + const router = useRouter() + const { roleTemplateId } = router.query + const tenantFilter = + router.query.tenantFilter ?? userSettingsDefaults.currentTenant + const needsTenant = !tenantFilter || tenantFilter === 'AllTenants' + const roleId = + typeof roleTemplateId === 'string' && GUID_RE.test(roleTemplateId) + ? roleTemplateId + : null + + const roleRequest = ApiGetCall({ + url: '/api/ListPIMRoles', + data: { + roleTemplateId, + tenantFilter, + }, + queryKey: `ListPIMRoles-${tenantFilter}-${roleTemplateId}`, + waiting: !!roleTemplateId && !needsTenant, + }) + + const roleData = getRoleRow(roleRequest.data) + + const title = !roleTemplateId + ? 'No Role Selected' + : needsTenant + ? 'Select a Tenant' + : roleRequest.isError + ? 'Role' + : roleRequest.isSuccess + ? roleData?.RoleDisplayName ?? 'Role' + : 'Loading...' + + const subtitle = roleRequest.isSuccess && roleData + ? [ + { + icon: , + text: ( + + ), + }, + roleData.IsPrivilegedRole + ? { + icon: , + text: ( + + + + ), + } + : null, + ].filter(Boolean) + : [] + + const offCanvas = { + children: (row) => ( + + ), + size: 'xl', + } + + return ( + + Array.isArray(data) ? data : (data?.Results ?? []) + } + getId={(row) => row.RoleDefinitionId} + getPrimary={(row) => row.RoleDisplayName} + getSecondary={(row) => row.RoleDefinitionId} + sortByPrimary + /> + ) : undefined + } + subtitle={subtitle} + isFetching={!!roleTemplateId && !needsTenant && roleRequest.isLoading} + > + + {!roleTemplateId && ( + + No role selected. Open this page from the Roles & PIM list. + + )} + {roleTemplateId && needsTenant && ( + + Select a single tenant to view role audit events. All Tenants is not + supported on this page. + + )} + {roleTemplateId && !needsTenant && !roleId && ( + + Role id must be a valid GUID. + + )} + {roleTemplateId && !needsTenant && roleRequest.isLoading && ( + + )} + {roleTemplateId && !needsTenant && roleRequest.isError && ( + + Failed to load role details. + + )} + {roleId && !needsTenant && ( + + )} + + ) +} + +Page.getLayout = (page) => {page} + +export default Page diff --git a/src/pages/identity/administration/roles/role/index.jsx b/src/pages/identity/administration/roles/role/index.jsx new file mode 100644 index 000000000000..e47a2f422ba0 --- /dev/null +++ b/src/pages/identity/administration/roles/role/index.jsx @@ -0,0 +1,315 @@ +import { Layout as DashboardLayout } from '../../../../../layouts/index' +import { CippIcons } from '../../../../../utils/icon-registry' +import { useSettings } from '../../../../../hooks/use-settings' +import { useRouter } from 'next/router' +import { ApiGetCall } from '../../../../../api/ApiCall' +import CippFormSkeleton from '../../../../../components/CippFormPages/CippFormSkeleton' +import { HeaderedTabbedLayout } from '../../../../../layouts/HeaderedTabbedLayout' +import { CippEntitySwitcher } from '../../../../../components/CippComponents/CippEntitySwitcher' +import tabOptions from './tabOptions.json' +import { CippCopyToClipBoard } from '../../../../../components/CippComponents/CippCopyToClipboard' +import { Box, Stack } from '@mui/system' +import { Grid } from '@mui/system' +import { + Alert, + Button, + Card, + CardHeader, + Chip, + Divider, + SvgIcon, + Tooltip, + Typography, +} from '@mui/material' +import { PropertyList } from '../../../../../components/property-list' +import { PropertyListItem } from '../../../../../components/property-list-item' +import { getCippFormatting } from '../../../../../utils/get-cipp-formatting' +import { CippHead } from '../../../../../components/CippComponents/CippHead' +import { CippDataTable } from '../../../../../components/CippTable/CippDataTable' +import { useCippRoleAssignmentActions } from '../../../../../components/CippComponents/CippRoleAssignmentActions' +import CippInfoTooltip from '../../../../../components/CippComponents/CippInfoTooltip' +import { + POLICY_BELOW_FLOOR_TOOLTIP, + PRIVILEGED_ROLE_TOOLTIP, + getRoleRow, +} from '../../../../../utils/role-detail-shared' + +const Page = () => { + const userSettingsDefaults = useSettings() + const router = useRouter() + const { roleTemplateId } = router.query + const tenantFilter = + router.query.tenantFilter ?? userSettingsDefaults.currentTenant + const needsTenant = !tenantFilter || tenantFilter === 'AllTenants' + + const roleRequest = ApiGetCall({ + url: '/api/ListPIMRoles', + data: { + roleTemplateId, + tenantFilter, + }, + queryKey: `ListPIMRoles-${tenantFilter}-${roleTemplateId}`, + waiting: !!roleTemplateId && !needsTenant, + }) + + const roleData = getRoleRow(roleRequest.data) + + const assignmentActions = useCippRoleAssignmentActions({ + relatedQueryKeys: [ + `ListPIMRoles-${tenantFilter}-${roleTemplateId}`, + 'ListPIMRoles*', + 'ListRoleAssignments*', + ], + }) + + const viewSignInsAction = { + label: 'View sign-ins', + link: `/identity/administration/users/user?userId=[PrincipalId]&tenantFilter=${tenantFilter}`, + icon: , + color: 'info', + condition: (row) => row?.PrincipalType === 'User' && !!row?.PrincipalId, + } + + const title = !roleTemplateId + ? 'No Role Selected' + : needsTenant + ? 'Select a Tenant' + : roleRequest.isError + ? 'Role' + : roleRequest.isSuccess + ? roleData?.RoleDisplayName ?? 'Role' + : 'Loading...' + + const subtitle = roleRequest.isSuccess && roleData + ? [ + { + icon: , + text: ( + + ), + }, + roleData.IsPrivilegedRole + ? { + icon: , + text: ( + + + + ), + } + : null, + roleData.PolicyBelowFloor + ? { + icon: , + text: ( + + + + ), + } + : null, + { + icon: , + text: ( + + ), + }, + ].filter(Boolean) + : [] + + return ( + + Array.isArray(data) ? data : (data?.Results ?? []) + } + getId={(row) => row.RoleDefinitionId} + getPrimary={(row) => row.RoleDisplayName} + getSecondary={(row) => row.RoleDefinitionId} + sortByPrimary + /> + ) : undefined + } + subtitle={subtitle} + isFetching={!!roleTemplateId && !needsTenant && roleRequest.isLoading} + > + {!roleTemplateId && ( + + No role selected. Open this page from the Roles & PIM list. + + )} + {roleTemplateId && needsTenant && ( + + Select a single tenant to view role details. All Tenants is not + supported on this page. + + )} + {roleTemplateId && !needsTenant && roleRequest.isLoading && ( + + )} + {roleTemplateId && !needsTenant && roleRequest.isError && ( + + Failed to load role details. + + )} + {roleTemplateId && + !needsTenant && + roleRequest.isSuccess && + !roleData && ( + + No role was found for this id in the selected tenant. + + )} + {roleRequest.isSuccess && roleData && ( + + + + + + + + + + + + + + {roleData.RoleDisplayName || 'N/A'} + + + {roleData.RoleIsBuiltIn + ? 'Built-in role' + : 'Custom role'} + + + } + /> + + + + Description: + + + {roleData.RoleDescription || 'N/A'} + + + + + Role Definition ID: + + + {getCippFormatting( + roleData.RoleDefinitionId, + 'RoleDefinitionId' + ) || 'N/A'} + + + + + + Privileged Role: + + + + + {getCippFormatting( + roleData.IsPrivilegedRole, + 'IsPrivilegedRole' + )} + + + + + Members / Permanent / Eligible / Active: + + + {roleData.MemberCount ?? 0} /{' '} + {roleData.PermanentCount ?? 0} /{' '} + {roleData.EligibleCount ?? 0} /{' '} + {roleData.ActiveCount ?? 0} + + + + } + /> + + + + + + + +
    + )} + + ) +} + +Page.getLayout = (page) => {page} + +export default Page diff --git a/src/pages/identity/administration/roles/role/pim.jsx b/src/pages/identity/administration/roles/role/pim.jsx new file mode 100644 index 000000000000..1cf22fb17ac3 --- /dev/null +++ b/src/pages/identity/administration/roles/role/pim.jsx @@ -0,0 +1,541 @@ +import { useMemo, useState } from 'react' +import { Layout as DashboardLayout } from '../../../../../layouts/index' +import { CippIcons } from '../../../../../utils/icon-registry' +import { useSettings } from '../../../../../hooks/use-settings' +import { usePermissions } from '../../../../../hooks/use-permissions' +import { useRouter } from 'next/router' +import { ApiGetCall } from '../../../../../api/ApiCall' +import CippFormSkeleton from '../../../../../components/CippFormPages/CippFormSkeleton' +import { HeaderedTabbedLayout } from '../../../../../layouts/HeaderedTabbedLayout' +import { CippEntitySwitcher } from '../../../../../components/CippComponents/CippEntitySwitcher' +import tabOptions from './tabOptions.json' +import { CippCopyToClipBoard } from '../../../../../components/CippComponents/CippCopyToClipboard' +import { Box, Stack } from '@mui/system' +import { Grid } from '@mui/system' +import { + Alert, + Button, + Card, + CardActionArea, + CardContent, + CardHeader, + Chip, + Divider, + List, + ListItem, + ListItemText, + SvgIcon, + Tooltip, + Typography, +} from '@mui/material' +import { CippPropertyList } from '../../../../../components/CippComponents/CippPropertyList' +import { getCippFormatting } from '../../../../../utils/get-cipp-formatting' +import { CippHead } from '../../../../../components/CippComponents/CippHead' +import CippInfoTooltip from '../../../../../components/CippComponents/CippInfoTooltip' +import { CippOffCanvas } from '../../../../../components/CippComponents/CippOffCanvas' +import { CippDataTable } from '../../../../../components/CippTable/CippDataTable' +import { useCippRoleAssignmentActions } from '../../../../../components/CippComponents/CippRoleAssignmentActions' +import { + POLICY_BELOW_FLOOR_TOOLTIP, + PRIVILEGED_ROLE_TOOLTIP, + formatPimDuration, + getRoleRow, +} from '../../../../../utils/role-detail-shared' + +const ASSIGNMENT_BUCKETS = [ + { + key: 'Permanent', + label: 'Permanent', + description: 'Active with no end date', + match: (row) => row?.AssignmentType === 'Permanent', + countKey: 'PermanentCount', + icon: CippIcons.LockPerson, + }, + { + key: 'Eligible', + label: 'Eligible', + description: 'Can activate through PIM', + match: (row) => row?.AssignmentType === 'Eligible', + countKey: 'EligibleCount', + icon: CippIcons.HourglassBottom, + }, + { + key: 'Active', + label: 'Active (time-bound)', + description: 'Active with an end date', + match: (row) => + row?.AssignmentType === 'Active' || + row?.AssignmentType === 'ActivatedFromEligible', + countKey: 'ActiveCount', + icon: CippIcons.MoreTime, + }, +] + +const Page = () => { + const userSettingsDefaults = useSettings() + const router = useRouter() + const { checkPermissions } = usePermissions() + const canWriteRole = checkPermissions(['Identity.Role.ReadWrite']) + const { roleTemplateId } = router.query + const tenantFilter = + router.query.tenantFilter ?? userSettingsDefaults.currentTenant + const needsTenant = !tenantFilter || tenantFilter === 'AllTenants' + const [assignmentDrawer, setAssignmentDrawer] = useState(null) + + const roleRequest = ApiGetCall({ + url: '/api/ListPIMRoles', + data: { + roleTemplateId, + tenantFilter, + }, + queryKey: `ListPIMRoles-${tenantFilter}-${roleTemplateId}`, + waiting: !!roleTemplateId && !needsTenant, + }) + + const roleData = getRoleRow(roleRequest.data) + const settings = roleData?.PolicySettings ?? {} + const floorIssues = Array.isArray(roleData?.FloorIssues) + ? roleData.FloorIssues + : [] + const assignments = roleData?.Assignments ?? [] + + const assignmentActions = useCippRoleAssignmentActions({ + relatedQueryKeys: [ + `ListPIMRoles-${tenantFilter}-${roleTemplateId}`, + 'ListPIMRoles*', + 'ListRoleAssignments*', + ], + }) + + const viewSignInsAction = { + label: 'View sign-ins', + link: `/identity/administration/users/user?userId=[PrincipalId]&tenantFilter=${tenantFilter}`, + icon: , + color: 'info', + condition: (row) => row?.PrincipalType === 'User' && !!row?.PrincipalId, + } + + const drawerBucket = ASSIGNMENT_BUCKETS.find( + (bucket) => bucket.key === assignmentDrawer + ) + const drawerRows = useMemo(() => { + if (!drawerBucket) return [] + return assignments.filter(drawerBucket.match) + }, [assignments, drawerBucket]) + + const title = !roleTemplateId + ? 'No Role Selected' + : needsTenant + ? 'Select a Tenant' + : roleRequest.isError + ? 'Role' + : roleRequest.isSuccess + ? roleData?.RoleDisplayName ?? 'Role' + : 'Loading...' + + const subtitle = roleRequest.isSuccess && roleData + ? [ + { + icon: , + text: ( + + ), + }, + roleData.IsPrivilegedRole + ? { + icon: , + text: ( + + + + ), + } + : null, + roleData.PolicyBelowFloor + ? { + icon: , + text: ( + + + + ), + } + : null, + ].filter(Boolean) + : [] + + const roleActions = [ + { + label: 'Create template from role settings', + type: 'POST', + icon: , + url: '/api/AddPIMRoleSettingsTemplate', + data: { + captureRoleId: 'RoleDefinitionId', + captureRoleName: 'RoleDisplayName', + tenantFilter: 'Tenant', + }, + fields: [ + { + type: 'textField', + name: 'templateName', + label: 'Template Name', + required: true, + validators: { required: 'A template name is required' }, + }, + { + type: 'textField', + name: 'description', + label: 'Description (optional)', + }, + ], + confirmText: + "Create a PIM role settings template from the current PIM settings of [RoleDisplayName]? Anything below CIPP's secure floor is raised to it, and every raised value is listed in the results.", + relatedQueryKeys: ['ListPIMRoleSettingsTemplates*'], + condition: (row) => + canWriteRole && !!row?.PIMCapable && !!row?.PolicySummary, + }, + ] + + const activationRequiresLabel = (() => { + switch (settings.activationRequires) { + case 'MFA': + return 'Multi-factor authentication' + case 'AuthenticationContext': + return settings.authenticationContextClaimValue + ? `Authentication context (${settings.authenticationContextClaimValue})` + : 'Authentication context' + default: + return 'None' + } + })() + + const activationItems = [ + { + label: 'Maximum activation duration', + value: formatPimDuration(settings.activationMaxDuration), + }, + { + label: 'Activation requires', + value: activationRequiresLabel, + }, + { + label: 'Justification on activation', + value: getCippFormatting( + settings.activationRequiresJustification, + 'activationRequiresJustification' + ), + }, + { + label: 'Ticket on activation', + value: getCippFormatting( + settings.activationRequiresTicket, + 'activationRequiresTicket' + ), + }, + { + label: 'Approval on activation', + value: getCippFormatting( + settings.activationRequiresApproval, + 'activationRequiresApproval' + ), + }, + ...(settings.activationRequiresApproval && settings.approvers + ? [{ label: 'Approvers', value: settings.approvers }] + : []), + ] + + const assignmentPolicyItems = [ + { + label: 'Maximum eligible assignment', + value: formatPimDuration(settings.eligibilityMaxDuration), + }, + { + label: 'Maximum active assignment', + value: formatPimDuration(settings.activeAssignmentMaxDuration), + }, + { + label: 'Justification when creating active assignment', + value: getCippFormatting( + settings.activeAssignmentRequiresJustification, + 'activeAssignmentRequiresJustification' + ), + }, + { + label: 'MFA when creating active assignment', + value: getCippFormatting( + settings.activeAssignmentRequiresMfa, + 'activeAssignmentRequiresMfa' + ), + }, + ...(settings.notificationRecipients + ? [ + { + label: 'Notification recipients', + value: settings.notificationRecipients, + }, + ] + : []), + { + label: 'Meets secure floor', + value: ( + + + {roleData?.PolicyBelowFloor == null + ? 'N/A' + : getCippFormatting( + !roleData.PolicyBelowFloor, + 'MeetsSecureFloor' + )} + + + + ), + }, + ] + + // CippPropertyList double layout splits one array; keep Activation and Assignments + // as two side-by-side cards so the grouping stays obvious. + return ( + + Array.isArray(data) ? data : (data?.Results ?? []) + } + getId={(row) => row.RoleDefinitionId} + getPrimary={(row) => row.RoleDisplayName} + getSecondary={(row) => row.RoleDefinitionId} + sortByPrimary + /> + ) : undefined + } + actions={roleActions} + actionsData={roleData} + queryKeys={[`ListPIMRoles-${tenantFilter}-${roleTemplateId}`]} + subtitle={subtitle} + isFetching={!!roleTemplateId && !needsTenant && roleRequest.isLoading} + > + + {!roleTemplateId && ( + + No role selected. Open this page from the Roles & PIM list. + + )} + {roleTemplateId && needsTenant && ( + + Select a single tenant to view PIM settings. All Tenants is not + supported on this page. + + )} + {roleTemplateId && !needsTenant && roleRequest.isLoading && ( + + )} + {roleTemplateId && !needsTenant && roleRequest.isError && ( + + Failed to load role details. + + )} + {roleTemplateId && + !needsTenant && + roleRequest.isSuccess && + !roleData && ( + + No role was found for this id in the selected tenant. + + )} + {roleRequest.isSuccess && roleData && ( + + + {!roleData.PIMCapable && ( + + This tenant is not PIM capable for this role (typically no Entra + ID P2). Assignments are permanent directory role memberships; + eligibility, activation limits and policy settings are not + available. + + )} + {roleData.PIMCapable && roleData.PolicyBelowFloor && ( + + + + + Policy below secure floor + + + + {floorIssues.length > 0 ? ( + + {floorIssues.map((issue) => ( + + + + ))} + + ) : ( + + The live PIM settings for this role fall below CIPP's + secure floor. + + )} + + + )} + + + {ASSIGNMENT_BUCKETS.map((bucket) => { + const BucketIcon = bucket.icon + return ( + + + setAssignmentDrawer(bucket.key)} + sx={{ height: '100%' }} + aria-label={`View ${bucket.label.toLowerCase()} assignments`} + > + + + + + + {bucket.label} + + + {roleData[bucket.countKey] ?? 0} + + + {bucket.description} + + + + + + + + + + + ) + })} + + + {roleData.PIMCapable ? ( + + + PIM Templates + + } + /> + + + + + + Activation + + + + + + + + Assignments + + + + + + + ) : null} + + + setAssignmentDrawer(null)} + size="xl" + > + + + + )} + + ) +} + +Page.getLayout = (page) => {page} + +export default Page diff --git a/src/pages/identity/administration/roles/role/tabOptions.json b/src/pages/identity/administration/roles/role/tabOptions.json new file mode 100644 index 000000000000..41018f622410 --- /dev/null +++ b/src/pages/identity/administration/roles/role/tabOptions.json @@ -0,0 +1,17 @@ +[ + { + "label": "Overview", + "path": "/identity/administration/roles/role", + "icon": "AdminPanelSettings" + }, + { + "label": "PIM", + "path": "/identity/administration/roles/role/pim", + "icon": "Security" + }, + { + "label": "Audit", + "path": "/identity/administration/roles/role/audit", + "icon": "History" + } +] diff --git a/src/pages/tenant/conditional/list-policies/index.jsx b/src/pages/tenant/conditional/list-policies/index.jsx index f8b213d2c8bf..103a63b2f7e1 100644 --- a/src/pages/tenant/conditional/list-policies/index.jsx +++ b/src/pages/tenant/conditional/list-policies/index.jsx @@ -5,6 +5,7 @@ import { Box } from "@mui/material"; import CippJsonView from "../../../../components/CippFormPages/CippJSONView"; import { CippCADeployDrawer } from "../../../../components/CippComponents/CippCADeployDrawer"; import { CippApiLogsDrawer } from "../../../../components/CippComponents/CippApiLogsDrawer"; +import { CippCAPolicyCoverageDrawer } from "../../../../components/CippComponents/CippCAPolicyCoverageDrawer"; import { PermissionButton } from "../../../../utils/permissions"; import { useSettings } from "../../../../hooks/use-settings.js"; @@ -25,6 +26,25 @@ const Page = () => { color: "info", hideBulk: true, }, + { + label: "View identity coverage", + icon: , + color: "info", + hideBulk: true, + multiPost: false, + customComponent: (row, { drawerVisible, setDrawerVisible }) => { + const policy = Array.isArray(row) ? row[0] : row; + return ( + setDrawerVisible(false)} + /> + ); + }, + }, { label: "Create template based on policy", type: "POST", diff --git a/src/theme/base/create-components.jsx b/src/theme/base/create-components.jsx index 11a42940133c..b1ed5db2d4f1 100644 --- a/src/theme/base/create-components.jsx +++ b/src/theme/base/create-components.jsx @@ -227,10 +227,29 @@ export const createComponents = () => { margin: 0, width: "100%", maxWidth: "100%", - maxHeight: "100%", borderRadius: 0, + // A tall dialog fills the screen and, in a home-screen install, runs under the + // iOS status bar. Keep it below the inset; fullscreen dialogs pad themselves. + "&:not(.MuiDialog-paperFullScreen)": { + marginTop: "env(safe-area-inset-top, 0px)", + maxHeight: "calc(100% - env(safe-area-inset-top, 0px))", + }, }, }, + // Fullscreen dialogs and edge drawers reach the top of the screen. In a home-screen + // (standalone) install with viewport-fit=cover that is under the iOS status bar, so + // pad by the safe-area inset the same way the top nav does. 0px everywhere else. + paperFullScreen: { + paddingTop: "env(safe-area-inset-top, 0px)", + }, + }, + }, + MuiDrawer: { + styleOverrides: { + paper: ({ ownerState }) => + ownerState.variant === "temporary" && ["left", "right"].includes(ownerState.anchor) + ? { paddingTop: "env(safe-area-inset-top, 0px)" } + : {}, }, }, MuiDialogActions: { diff --git a/src/utils/format-ca-coverage-reason.js b/src/utils/format-ca-coverage-reason.js new file mode 100644 index 000000000000..56386018362c --- /dev/null +++ b/src/utils/format-ca-coverage-reason.js @@ -0,0 +1,339 @@ +const GUEST_TYPE_LABELS = { + none: 'None', + internalGuest: 'Internal guest', + b2bCollaborationGuest: 'B2B collaboration guest', + b2bCollaborationMember: 'B2B collaboration member', + b2bDirectConnectUser: 'B2B direct connect user', + otherExternalUser: 'Other external user', + serviceProvider: 'Service provider', +} + +const tokenFromValue = (value) => { + if (typeof value !== 'string' || !value.includes(':')) return null + return value.slice(value.indexOf(':') + 1) +} + +export const formatGuestTypes = (raw) => { + if (!raw || typeof raw !== 'string') return null + return raw + .split(',') + .map((part) => GUEST_TYPE_LABELS[part.trim()] || part.trim()) + .filter(Boolean) + .join(', ') +} + +/** + * Turn a CA coverage reason object into a short human-readable sentence. + */ +const formatViaNestedNames = (viaNestedGroups) => + (Array.isArray(viaNestedGroups) ? viaNestedGroups : []) + .map((group) => group?.name || group?.displayName) + .filter(Boolean) + .join(', ') + +const parseReasonNames = (reason) => { + const { type, label, value, viaNestedGroups } = reason || {} + const token = tokenFromValue(value) + const groupName = label?.match(/^Group:\s*(.+?)(\s*\(nested\))?$/i)?.[1]?.trim() + const roleViaGroup = label?.match(/^Role:\s*(.+?)\s+via group\s+(.+)$/i) + const roleName = roleViaGroup + ? roleViaGroup[1].trim() + : label?.match(/^Role:\s*(.+)$/i)?.[1]?.trim() + const roleGroupName = roleViaGroup?.[2]?.trim() || reason?.viaGroupLabel + const guestTypesRaw = + label?.match(/^Guest types:\s*(.+)$/i)?.[1]?.trim() || (type?.includes('Guests') ? token : null) + const viaNested = (Array.isArray(viaNestedGroups) ? viaNestedGroups : []) + .map((group) => ({ + id: group?.id, + name: group?.name || group?.displayName || group?.id, + })) + .filter((group) => group.name) + + return { + token, + groupName, + roleName, + roleGroupName, + guestTypesRaw, + viaNested, + viaNestedNames: formatViaNestedNames(viaNestedGroups), + } +} + +const textPart = (value) => ({ type: 'text', value }) +const entityPart = (kind, name, id) => ({ type: kind, name, id: id || null }) + +/** + * Sentence parts for rich why-drawer rendering (text + linkable group/role chips). + * formatCaCoverageReason joins these for plain-text contexts (grid/export). + */ +export const getCaCoverageReasonParts = (reason) => { + if (!reason || typeof reason !== 'object') return [] + + const { type, label, transitive, id, viaGroupId, value } = reason + const { token, groupName, roleName, roleGroupName, guestTypesRaw, viaNested } = + parseReasonNames(reason) + + switch (type) { + case 'includeUsers': + if (token === 'All') return [textPart('Policy includes all users')] + if (token === 'GuestsOrExternalUsers') { + return [textPart('Matched as guest or external user')] + } + return [textPart('Listed directly under Include users')] + + case 'excludeUsers': + if (token === 'GuestsOrExternalUsers') { + return [textPart('Excluded as guest or external user')] + } + return [textPart('Listed directly under Exclude users')] + + case 'includeGroups': { + if (!groupName) return [textPart(label || 'Member of an included group')] + const parts = [textPart('Member of group '), entityPart('group', groupName, id)] + if (viaNested.length) { + parts.push(textPart(viaNested.length === 1 ? ' via nested group ' : ' via nested groups ')) + viaNested.forEach((group, index) => { + if (index > 0) parts.push(textPart(', ')) + parts.push(entityPart('group', group.name, group.id)) + }) + } else if (transitive) { + parts.push(textPart(' via a nested group')) + } + return parts + } + + case 'excludeGroups': { + if (!groupName) return [textPart(label || 'Excluded as member of a group')] + const parts = [ + textPart('Excluded as member of group '), + entityPart('group', groupName, id), + ] + if (viaNested.length) { + parts.push(textPart(viaNested.length === 1 ? ' via nested group ' : ' via nested groups ')) + viaNested.forEach((group, index) => { + if (index > 0) parts.push(textPart(', ')) + parts.push(entityPart('group', group.name, group.id)) + }) + } else if (transitive) { + parts.push(textPart(' via a nested group')) + } + return parts + } + + case 'includeRoles': { + if (!roleName) return [textPart(label || 'Has an included directory role')] + const parts = [ + textPart('Has directory role '), + entityPart('role', roleName, id), + ] + if (roleGroupName) { + parts.push(textPart(' via group ')) + parts.push(entityPart('group', roleGroupName, viaGroupId)) + if (viaNested.length) { + parts.push(textPart(viaNested.length === 1 ? ' via nested group ' : ' via nested groups ')) + viaNested.forEach((group, index) => { + if (index > 0) parts.push(textPart(', ')) + parts.push(entityPart('group', group.name, group.id)) + }) + } + } + return parts + } + + case 'excludeRoles': { + if (!roleName) return [textPart(label || 'Excluded because of a directory role')] + const parts = [ + textPart('Excluded because of directory role '), + entityPart('role', roleName, id), + ] + if (roleGroupName) { + parts.push(textPart(' via group ')) + parts.push(entityPart('group', roleGroupName, viaGroupId)) + if (viaNested.length) { + parts.push(textPart(viaNested.length === 1 ? ' via nested group ' : ' via nested groups ')) + viaNested.forEach((group, index) => { + if (index > 0) parts.push(textPart(', ')) + parts.push(entityPart('group', group.name, group.id)) + }) + } + } + return parts + } + + case 'includeGuestsOrExternalUsers': { + const types = formatGuestTypes(guestTypesRaw) + return [ + textPart( + types + ? `Included as guest or external user (${types})` + : 'Included as guest or external user' + ), + ] + } + + case 'excludeGuestsOrExternalUsers': { + const types = formatGuestTypes(guestTypesRaw) + return [ + textPart( + types + ? `Excluded as guest or external user (${types})` + : 'Excluded as guest or external user' + ), + ] + } + + default: + return [textPart(label || value || type || '')] + } +} + +export const formatCaCoverageReason = (reason) => + getCaCoverageReasonParts(reason) + .map((part) => (part.type === 'text' ? part.value : part.name)) + .join('') + +export const formatCaCoverageReasons = (reasons) => + (Array.isArray(reasons) ? reasons : []).map(formatCaCoverageReason).filter(Boolean) + +export const formatCaCoverageStatus = (status) => { + if (status === 'covered') return 'Covered by this policy' + if (status === 'excluded') return 'Excluded from this policy' + return status || '' +} + +const REASON_TYPE_META = { + includeUsers: { + chip: 'Include users', + tooltip: + 'This identity is listed under Include users on the policy, or matched a special token such as All or Guests or external users.', + }, + excludeUsers: { + chip: 'Exclude users', + tooltip: + 'This identity is listed under Exclude users on the policy, or matched a guest or external users token there.', + }, + includeGroups: { + chip: 'Include groups', + tooltip: + 'This identity is a member of a group under Include groups. Nested group membership counts.', + }, + excludeGroups: { + chip: 'Exclude groups', + tooltip: + 'This identity is a member of a group under Exclude groups. Nested group membership counts.', + }, + includeRoles: { + chip: 'Include roles', + tooltip: + 'This identity has a directory role under Include roles, either assigned directly or through a group that holds the role.', + }, + excludeRoles: { + chip: 'Exclude roles', + tooltip: + 'This identity has a directory role under Exclude roles, either assigned directly or through a group that holds the role.', + }, + includeGuestsOrExternalUsers: { + chip: 'Include guests', + tooltip: + 'This identity matched the Include guests or external users block on the policy.', + }, + excludeGuestsOrExternalUsers: { + chip: 'Exclude guests', + tooltip: + 'This identity matched the Exclude guests or external users block on the policy.', + }, +} + +/** + * Chip label + tooltip for a coverage reason type (used in the why drawer). + */ +export const getCaCoverageReasonTypeMeta = (reason) => { + const type = reason?.type + if (type && REASON_TYPE_META[type]) return REASON_TYPE_META[type] + return { + chip: type || 'Assignment', + tooltip: 'How this identity was matched on the policy assignment.', + } +} + +const GUID_PATTERN = /^[0-9a-f]{8}-([0-9a-f]{4}-){3}[0-9a-f]{12}$/i + +/** + * Concrete targets on a reason (group / role / via-group) for chips and deep links. + */ +export const getCaCoverageReasonTargets = (reason) => { + if (!reason || typeof reason !== 'object') return [] + + const { type, label, id, transitive, viaGroupId, viaGroupLabel, value } = reason + const targets = [] + const token = tokenFromValue(value) + + const groupName = label?.match(/^Group:\s*(.+?)(\s*\(nested\))?$/i)?.[1]?.trim() + const roleViaGroup = label?.match(/^Role:\s*(.+?)\s+via group\s+(.+)$/i) + const roleName = roleViaGroup + ? roleViaGroup[1].trim() + : label?.match(/^Role:\s*(.+)$/i)?.[1]?.trim() + const roleGroupName = roleViaGroup?.[2]?.trim() || viaGroupLabel + + if (type === 'includeGroups' || type === 'excludeGroups') { + if (id || groupName) { + targets.push({ + kind: 'group', + id: GUID_PATTERN.test(id) ? id : null, + name: groupName || id, + nested: Boolean(transitive), + }) + } + for (const via of Array.isArray(reason.viaNestedGroups) ? reason.viaNestedGroups : []) { + if (!via?.id && !via?.name && !via?.displayName) continue + targets.push({ + kind: 'group', + id: GUID_PATTERN.test(via.id) ? via.id : null, + name: via.name || via.displayName || via.id, + nested: true, + viaNested: true, + }) + } + return targets + } + + if (type === 'includeRoles' || type === 'excludeRoles') { + if (id || roleName) { + targets.push({ + kind: 'role', + id: GUID_PATTERN.test(id) ? id : null, + name: roleName || id, + nested: false, + }) + } + if (viaGroupId || roleGroupName) { + targets.push({ + kind: 'group', + id: GUID_PATTERN.test(viaGroupId) ? viaGroupId : null, + name: roleGroupName || viaGroupId, + nested: false, + viaRole: true, + }) + } + return targets + } + + if ( + (type === 'includeUsers' || type === 'excludeUsers') && + token && + !GUID_PATTERN.test(token) && + token !== 'None' + ) { + targets.push({ + kind: 'token', + id: null, + name: token === 'All' ? 'All users' : token === 'GuestsOrExternalUsers' ? 'Guests or external users' : token, + nested: false, + }) + } + + return targets +} + + diff --git a/src/utils/get-cipp-formatting.jsx b/src/utils/get-cipp-formatting.jsx index 88b4ad5bc131..0226d553eb2f 100644 --- a/src/utils/get-cipp-formatting.jsx +++ b/src/utils/get-cipp-formatting.jsx @@ -1,4 +1,4 @@ -import { Chip, Link, SvgIcon, Tooltip } from '@mui/material' +import { Chip, Link, SvgIcon, Tooltip, Typography } from '@mui/material' import { CippIcons } from './icon-registry' import NextLink from 'next/link' import { alpha } from '@mui/material/styles' @@ -28,6 +28,10 @@ import { CippTimeAgo } from '../components/CippComponents/CippTimeAgo' import { getCippRoleTranslation } from './get-cipp-role-translation' import { getCippTranslation } from './get-cipp-translation' import DOMPurify from 'dompurify' +import { + formatCaCoverageReason, + formatCaCoverageReasons, +} from './format-ca-coverage-reason' import { getSignInErrorCodeTranslation } from './get-cipp-signin-errorcode-translation' import { CollapsibleChipList } from '../components/CippComponents/CollapsibleChipList' import countryList from '../data/countryList.json' @@ -186,13 +190,33 @@ export const getCippFormatting = ( } if (cellNameLower === 'compliancestate') { - if (isText) return data - const label = data?.label ?? data + const raw = data?.label ?? data + const complianceStateLabels = { + compliant: 'Compliant', + remediated: 'Remediated', + noncompliant: 'Non-compliant', + error: 'Error', + conflict: 'Conflict', + notapplicable: 'Not applicable', + unknown: 'Unknown', + notassigned: 'Not assigned', + ingraceperiod: 'In grace period', + } const complianceStateColor = { compliant: 'success', + remediated: 'success', noncompliant: 'error', + error: 'error', + conflict: 'warning', + ingraceperiod: 'warning', + notapplicable: 'default', + unknown: 'default', + notassigned: 'default', } - const color = complianceStateColor[String(label).toLowerCase()] ?? 'default' + const key = String(raw ?? '').toLowerCase() + const label = complianceStateLabels[key] ?? raw + if (isText) return label + const color = complianceStateColor[key] ?? 'default' return } @@ -687,10 +711,18 @@ export const getCippFormatting = ( 'denied - delete pending': 'warning', 'skipped - no license': 'default', 'no data': 'default', + covered: 'success', + excluded: 'warning', } const baselineColor = baselineStatusColors[String(data).toLowerCase()] if (baselineColor) { - if (isText) return data + const displayLabel = + String(data).toLowerCase() === 'covered' + ? 'Covered' + : String(data).toLowerCase() === 'excluded' + ? 'Excluded' + : data + if (isText) return displayLabel // Pending states answer the "when does something happen?" question inline. const baselineStatusTooltips = { 'no data': 'Not collected yet - happens automatically on the next run.', @@ -705,7 +737,7 @@ export const getCippFormatting = ( const chip = ( @@ -1502,6 +1534,38 @@ export const getCippFormatting = ( return isText ? data : } + // CA policy identity coverage: grid shows a count/top-reason summary; full lists belong in off-canvas. + if (cellName === 'includeReasons' || cellName === 'excludeReasons') { + const reasons = Array.isArray(data) ? data : [] + const noun = cellName === 'includeReasons' ? 'include' : 'exclude' + const labels = formatCaCoverageReasons(reasons) + if (isText) { + return labels.length > 0 ? labels.join(' · ') : '' + } + if (reasons.length === 0) { + return ( + + - + + ) + } + if (reasons.length === 1) { + return ( + + {labels[0]} + + ) + } + const summary = `${reasons.length} ${noun}s` + return ( + + + {summary} + + + ) + } + // handle autocomplete labels if (data?.label && data?.value) { return isText ? ( diff --git a/src/utils/instance-diagnostics.js b/src/utils/instance-diagnostics.js new file mode 100644 index 000000000000..8533507c9df9 --- /dev/null +++ b/src/utils/instance-diagnostics.js @@ -0,0 +1,100 @@ +// Pure helpers for the Diagnostics tab — kept dependency-free so they're cheap to unit test. + +// Backend check ids are machine-readable slugs; map the known ones to readable labels. +// Unknown ids (future checks) pass through unchanged. +export const CHECK_LABELS = { + oom: "Out of memory", + "heap-headroom": "Heap headroom", + watchdog: "Watchdog restarts", + "pool-exhausted": "HTTP worker pool", + "stalled-runs": "Stalled runs", + "api-clients": "API clients", + restarts: "Container restarts", + orchestrator: "Orchestrator", + "container-log": "Platform container log", +}; +export const getCheckLabel = (id) => CHECK_LABELS[id] ?? id; + +// Sums Clients[].Count across every Timeline bucket, grouped by AppId. +export const aggregateDiagnosticsClients = (buckets) => { + const totals = new Map(); + for (const bucket of buckets ?? []) { + for (const client of bucket?.Clients ?? []) { + if (!client?.AppId) continue; + const existing = totals.get(client.AppId) ?? { + AppId: client.AppId, + AppName: client.AppName, + IP: client.IP, + Count: 0, + }; + existing.Count += Number(client.Count) || 0; + if (client.AppName) existing.AppName = client.AppName; + if (client.IP) existing.IP = client.IP; + totals.set(client.AppId, existing); + } + } + const rows = Array.from(totals.values()).sort((a, b) => b.Count - a.Count); + const grandTotal = rows.reduce((sum, r) => sum + r.Count, 0); + return rows.map((r) => ({ + ...r, + SharePct: grandTotal > 0 ? Math.round((r.Count / grandTotal) * 1000) / 10 : 0, + })); +}; + +// FAIL, WARN, INFO, PASS — worst first. +const STATUS_ORDER = { FAIL: 0, WARN: 1, INFO: 2, PASS: 3 }; +export const sortDiagnosticsChecks = (checks) => + [...(checks ?? [])].sort( + (a, b) => (STATUS_ORDER[a.Status] ?? 99) - (STATUS_ORDER[b.Status] ?? 99) + ); + +// Stacked-bar series for the Health Timeline's "API Requests" chart: the top N clients by +// total Count over the window get their own series, everything else is folded into "Other". +export const buildRequestSeries = (buckets, topN = 4) => { + const totals = new Map(); + for (const bucket of buckets ?? []) { + for (const client of bucket?.Clients ?? []) { + if (!client?.AppId) continue; + const existing = totals.get(client.AppId) ?? { AppId: client.AppId, AppName: client.AppName, Count: 0 }; + existing.Count += Number(client.Count) || 0; + if (client.AppName) existing.AppName = client.AppName; + totals.set(client.AppId, existing); + } + } + const topClients = Array.from(totals.values()) + .sort((a, b) => b.Count - a.Count) + .slice(0, topN); + const topIds = new Set(topClients.map((c) => c.AppId)); + + const data = (buckets ?? []).map((bucket) => { + const row = { Bucket: bucket.Bucket }; + for (const id of topIds) row[id] = 0; + let other = 0; + for (const client of bucket?.Clients ?? []) { + if (!client?.AppId) continue; + const count = Number(client.Count) || 0; + if (topIds.has(client.AppId)) { + row[client.AppId] += count; + } else { + other += count; + } + } + if (other > 0) row.Other = other; + return row; + }); + + return { data, series: topClients.map((c) => ({ AppId: c.AppId, AppName: c.AppName || c.AppId })) }; +}; + +// Human-readable byte size, one decimal place, B/KB/MB/GB. +export const formatBytes = (bytes) => { + const n = Number(bytes) || 0; + if (n >= 1024 ** 3) return `${(n / 1024 ** 3).toFixed(1)} GB`; + if (n >= 1024 ** 2) return `${(n / 1024 ** 2).toFixed(1)} MB`; + if (n >= 1024) return `${(n / 1024).toFixed(1)} KB`; + return `${n.toFixed(1)} B`; +}; + +// Deep-link query for the Logs tab, scoped to one API client's calls in the current window. +export const buildClientLogQuery = (appId, hoursWindow) => + `search all files\n| where Message contains "AppId=${appId}"\n| where Timestamp > ago(${hoursWindow}h)\n| take 1000\n| sort by Timestamp desc`; diff --git a/src/utils/role-detail-shared.js b/src/utils/role-detail-shared.js new file mode 100644 index 000000000000..a1682b0a4378 --- /dev/null +++ b/src/utils/role-detail-shared.js @@ -0,0 +1,32 @@ +// Shared copy for the role detail header chips and field help icons. + +export const POLICY_BELOW_FLOOR_TOOLTIP = + "This role's PIM settings are weaker than CIPP's secure floor: activation must expire within 24 hours and require MFA or an authentication context plus a justification; eligible and active assignments must expire within a year; creating an active assignment requires a justification. Entra defaults often sit below this floor." + +export const PRIVILEGED_ROLE_TOOLTIP = + "This role is on CIPP's privileged-roles list (the same list standards and alerts use) — for example Global, Security, Exchange, SharePoint, User, Conditional Access, and Application administrators." + +export const formatPimDuration = (iso) => { + if (!iso) return 'No expiration (permanent allowed)' + try { + // PT8H / P90D / P365D — enough for the values PIM policies use. + const match = String(iso).match(/^P(?:(\d+)D)?(?:T(?:(\d+)H)?(?:(\d+)M)?)?$/i) + if (!match) return iso + const days = Number(match[1] || 0) + const hours = Number(match[2] || 0) + const minutes = Number(match[3] || 0) + if (days >= 365 && days % 365 === 0) return `${days / 365} year${days === 365 ? '' : 's'}` + if (days >= 30 && days % 30 === 0) return `${days / 30} month${days === 30 ? '' : 's'}` + if (days > 0) return `${days} day${days === 1 ? '' : 's'}` + if (hours > 0) return `${hours} hour${hours === 1 ? '' : 's'}` + if (minutes > 0) return `${minutes} minute${minutes === 1 ? '' : 's'}` + return iso + } catch { + return iso + } +} + +export const getRoleRow = (data) => + Array.isArray(data) + ? data[0] + : data?.Results?.[0] ?? data?.[0] diff --git a/tests/components/CippComponents/CippAddUserDrawer.test.jsx b/tests/components/CippComponents/CippAddUserDrawer.test.jsx index 346bc8161732..6a4a1f011831 100644 --- a/tests/components/CippComponents/CippAddUserDrawer.test.jsx +++ b/tests/components/CippComponents/CippAddUserDrawer.test.jsx @@ -252,3 +252,50 @@ describe('CippAddUserDrawer - backdrop click must not wipe typed input (issue #3 expect(screen.queryByTestId('CippOffCanvas')).not.toBeInTheDocument() }, 30000) }) + +describe('CippAddUserDrawer - user creation is refused under All Tenants (ticket 48312738612)', () => { + beforeEach(() => { + vi.clearAllMocks() + postState = { isPending: false, isSuccess: false, isError: false } + mutateSpy = vi.fn() + mockApis() + }) + + it('warns and keeps Create disabled under All Tenants even with the form complete', async () => { + const user = userEvent.setup() + renderWithProviders(, { + settings: settingsWith({ + currentTenant: 'AllTenants', + usageLocation: { value: 'US', label: 'United States' }, + }), + }) + + await user.click(screen.getByRole('button', { name: 'Add User' })) + await waitFor(() => { + expect(getDomainInput()).toHaveValue('testdomain.com') + }) + await fillRequiredFields(user, { displayName: 'Blocked User', username: 'blocked.user' }) + + // The single-tenant warning is shown... + expect(screen.getByText(/single-tenant only/i)).toBeInTheDocument() + + // ...and the guard keeps submit disabled despite a complete, valid, dirty form - the exact + // state that enables the button under a specific tenant (the create-another-user test above), + // so this fails if the isAllTenants guard is dropped from the disabled condition. + expect(screen.getByRole('button', { name: 'Create User' })).toBeDisabled() + }, 30000) + + it('shows no single-tenant warning once a specific tenant is selected', async () => { + const user = userEvent.setup() + renderWithProviders(, { + settings: settingsWith({ usageLocation: { value: 'US', label: 'United States' } }), + }) + + await user.click(screen.getByRole('button', { name: 'Add User' })) + await waitFor(() => { + expect(getDomainInput()).toHaveValue('testdomain.com') + }) + + expect(screen.queryByText(/single-tenant only/i)).not.toBeInTheDocument() + }, 30000) +}) diff --git a/tests/components/CippComponents/CippBulkUserDrawer.test.jsx b/tests/components/CippComponents/CippBulkUserDrawer.test.jsx new file mode 100644 index 000000000000..674ecce85ab1 --- /dev/null +++ b/tests/components/CippComponents/CippBulkUserDrawer.test.jsx @@ -0,0 +1,128 @@ +import React from 'react' +import { describe, it, expect, vi, beforeEach } from 'vitest' +import { screen, within, waitFor } from '@testing-library/react' +import userEvent from '@testing-library/user-event' +import { renderWithProviders, settingsWith } from '../../test-utils' +import { CippBulkUserDrawer } from '../../../src/components/CippComponents/CippBulkUserDrawer' +import { + ApiGetCall, + ApiPostCall, + ApiGetCallWithPagination, +} from '../../../src/api/ApiCall' + +vi.mock('../../../src/api/ApiCall', () => ({ + ApiGetCall: vi.fn(), + ApiPostCall: vi.fn(), + ApiGetCallWithPagination: vi.fn(), +})) + +// The license selector, the preview table and the results panel take no part in the tenant +// guard under test, and each drags in the data-table / 2.2 MB license graph that exhausts the +// worker, so they are stubbed. CippFormComponent stays real because the manual-add dialog needs +// it to queue a row. +vi.mock( + '../../../src/components/CippComponents/CippFormLicenseSelector', + () => ({ + CippFormLicenseSelector: () => ( +
    + ), + default: () =>
    , + }) +) +vi.mock('../../../src/components/CippComponents/CippApiResults', () => ({ + CippApiResults: () => null, +})) +// CippFormComponent statically imports the data-table stack for its cippDataTable case, and +// CippAutoComplete pulls in CippJSONView for its option preview; neither renders here, but the +// static imports alone are enough to kill the worker. +vi.mock('../../../src/components/CippTable/CippDataTable', () => ({ + CippDataTable: () =>
    , + default: () =>
    , +})) +vi.mock('../../../src/components/CippFormPages/CippJSONView', () => ({ + default: () => null, +})) +// The real drawer shell renders through a MUI Drawer portal; the stub keeps the essential +// contract - content and footer render only while the drawer is open. +vi.mock('../../../src/components/CippComponents/CippOffCanvas', () => ({ + CippOffCanvas: ({ visible, children, footer }) => + visible ? ( +
    + {children} + {footer} +
    + ) : null, +})) + +const idleGet = { + isSuccess: false, + isFetching: false, + isError: false, + data: undefined, + refetch: vi.fn(), +} +const idlePaginated = { ...idleGet, fetchNextPage: vi.fn() } + +let postState +let mutateSpy + +function mockApis() { + ApiGetCall.mockImplementation(() => idleGet) + ApiGetCallWithPagination.mockImplementation(() => idlePaginated) + ApiPostCall.mockImplementation(() => ({ ...postState, mutate: mutateSpy })) +} + +// Queue one user through the manual-add dialog. Any typed field is enough - handleAddItem pushes +// whatever `addrow` holds - so with a row present the Create button's disabled state is governed +// solely by the tenant guard rather than the empty-list default. +async function queueOneUser(user) { + await user.click(screen.getByRole('button', { name: 'Add User Manually' })) + const dialog = await screen.findByRole('dialog') + await user.type(within(dialog).getAllByRole('textbox')[0], 'Test User') + await user.click(within(dialog).getByRole('button', { name: 'Add' })) + await waitFor(() => { + expect(screen.queryByRole('dialog')).not.toBeInTheDocument() + }) +} + +describe('CippBulkUserDrawer - bulk creation is refused under All Tenants (ticket 48312738612)', () => { + beforeEach(() => { + vi.clearAllMocks() + postState = { isLoading: false, isSuccess: false, isError: false } + mutateSpy = vi.fn() + mockApis() + }) + + it('warns and keeps Create Users disabled with a queued row when All Tenants is selected', async () => { + const user = userEvent.setup() + renderWithProviders(, { + settings: settingsWith({ currentTenant: 'AllTenants' }), + }) + + await user.click(screen.getByRole('button', { name: 'Bulk Add Users' })) + + // The single-tenant warning must be visible before the user wastes time building a list. + expect(screen.getByText(/single-tenant only/i)).toBeInTheDocument() + + // Even with a row queued - the state that normally enables Create Users - the guard keeps + // submit disabled, because under All Tenants the write silently creates nothing. + await queueOneUser(user) + expect(screen.getByRole('button', { name: 'Create Users' })).toBeDisabled() + }, 30000) + + it('enables Create Users and shows no warning once a specific tenant is selected', async () => { + const user = userEvent.setup() + renderWithProviders(, { + settings: settingsWith({ currentTenant: 'contoso.onmicrosoft.com' }), + }) + + await user.click(screen.getByRole('button', { name: 'Bulk Add Users' })) + + expect(screen.queryByText(/single-tenant only/i)).not.toBeInTheDocument() + + await queueOneUser(user) + await waitFor(() => { + expect(screen.getByRole('button', { name: 'Create Users' })).toBeEnabled() + }) + }, 30000) +}) diff --git a/tests/components/CippSettings/CippRoleAddEdit.test.jsx b/tests/components/CippSettings/CippRoleAddEdit.test.jsx index 166b6bedf333..57802fb38fcc 100644 --- a/tests/components/CippSettings/CippRoleAddEdit.test.jsx +++ b/tests/components/CippSettings/CippRoleAddEdit.test.jsx @@ -1,4 +1,5 @@ -import React from "react"; +import React, { useState } from "react"; +import { act } from "@testing-library/react"; import { describe, it, expect, vi } from "vitest"; import { renderWithProviders } from "../../test-utils"; @@ -52,3 +53,56 @@ describe("CippRoleAddEdit render stability", () => { consoleError.mockRestore(); }); }); + +// Regression: the "Set All Permissions" effect used to fire on mount with an undefined +// selection. With the permissions list already cached that overwrote the loaded role +// with "Cat.Obj.undefined" for every row. +const loadedPermissions = { CIPP: { Alert: { Read: [], ReadWrite: [] } } }; +const technicianRole = { + RowKey: "technician", + Permissions: { CIPPAlert: "CIPP.Alert.Read" }, + PermissionRules: { Include: ["CIPP.Alert.Read"], Exclude: [] }, +}; + +describe("CippRoleAddEdit custom role advanced view", () => { + it("shows the saved permission levels instead of undefined", async () => { + pendingPermissions.data = loadedPermissions; + pendingPermissions.isFetching = false; + pendingPermissions.isSuccess = true; + idlePagination.data = { pages: [[technicianRole]] }; + idlePagination.isSuccess = true; + + const { findByText, queryByText } = renderWithProviders( + + ); + + expect(await findByText("CIPP.Alert.Read")).toBeTruthy(); + expect(queryByText(/\.undefined/)).toBeNull(); + }); + + // Cold cache: the role list resolves before the permission list. Loading the role + // then built the grid from zero categories and the summary stayed blank. + it("shows the saved permission levels when the permission list arrives last", async () => { + pendingPermissions.data = undefined; + pendingPermissions.isFetching = true; + pendingPermissions.isSuccess = false; + idlePagination.data = { pages: [[technicianRole]] }; + idlePagination.isSuccess = true; + + // Re-render inside the providers once the mocked query flips to success. + let bump; + const Harness = () => { + const [, setTick] = useState(0); + bump = () => setTick((n) => n + 1); + return ; + }; + const { findByText } = renderWithProviders(); + + pendingPermissions.data = loadedPermissions; + pendingPermissions.isFetching = false; + pendingPermissions.isSuccess = true; + act(() => bump()); + + expect(await findByText("CIPP.Alert.Read")).toBeTruthy(); + }); +}); diff --git a/tests/components/CippTable/CippGraphExplorerFilter.test.jsx b/tests/components/CippTable/CippGraphExplorerFilter.test.jsx index 49df07503eb8..d0d523f268c5 100644 --- a/tests/components/CippTable/CippGraphExplorerFilter.test.jsx +++ b/tests/components/CippTable/CippGraphExplorerFilter.test.jsx @@ -197,6 +197,28 @@ describe('CippGraphExplorerFilter', () => { }) }) + it('does not echo the selectedPreset prop back to onPresetSelect (remount-echo regression)', async () => { + ApiGetCall.mockImplementation(() => ({ + isSuccess: false, + isFetching: false, + data: undefined, + refetch: vi.fn(), + })) + const onPresetSelect = vi.fn() + renderWithProviders( + + ) + await waitFor(() => { + expect(screen.getByRole('combobox', { name: 'Select a preset' })).toHaveValue('Licensed Users') + }) + expect(onPresetSelect).not.toHaveBeenCalled() + }) + it('switching between two option-shape presets applies the second (dep-array regression)', async () => { const optionA = { label: BUILTIN.name, value: BUILTIN.id, addedFields: BUILTIN } const optionB = { label: 'Saved Object Select', value: 'saved-1', addedFields: savedObjectSelect } diff --git a/tests/theme/mobile-gutters.test.js b/tests/theme/mobile-gutters.test.js index bf17a4fd4c6b..bca5ad75a4e6 100644 --- a/tests/theme/mobile-gutters.test.js +++ b/tests/theme/mobile-gutters.test.js @@ -45,3 +45,30 @@ describe("horizontal gutters on small screens", () => { expect(content[MOBILE]?.paddingBottom).toBeUndefined(); }); }); + +// A home-screen (standalone) install on iPhone draws under the status bar because the viewport +// is viewport-fit=cover. The top nav pads for that itself; everything else that reaches the top +// edge — fullscreen dialogs and the left/right drawers — gets the inset from the theme. +describe("status-bar inset on surfaces that reach the top edge", () => { + const theme = createTheme({ colorPreset: "orange", contrast: "high", paletteMode: "light" }); + const INSET = "env(safe-area-inset-top, 0px)"; + const drawerPaper = (ownerState) => theme.components.MuiDrawer.styleOverrides.paper({ ownerState }); + + it("pads fullscreen dialogs", () => { + expect(theme.components.MuiDialog.styleOverrides.paperFullScreen.paddingTop).toBe(INSET); + }); + + it("keeps a tall non-fullscreen phone dialog below the inset without double-padding fullscreen", () => { + const rule = theme.components.MuiDialog.styleOverrides.paper[MOBILE]["&:not(.MuiDialog-paperFullScreen)"]; + expect(rule.marginTop).toBe(INSET); + expect(rule.maxHeight).toBe(`calc(100% - ${INSET})`); + expect(theme.components.MuiDialog.styleOverrides.paper[MOBILE].maxHeight).toBeUndefined(); + }); + + it("pads temporary left/right drawers only — the permanent side nav already sits under the top nav", () => { + expect(drawerPaper({ variant: "temporary", anchor: "left" }).paddingTop).toBe(INSET); + expect(drawerPaper({ variant: "temporary", anchor: "right" }).paddingTop).toBe(INSET); + expect(drawerPaper({ variant: "temporary", anchor: "bottom" }).paddingTop).toBeUndefined(); + expect(drawerPaper({ variant: "permanent", anchor: "left" }).paddingTop).toBeUndefined(); + }); +}); diff --git a/tests/utils/instance-diagnostics.test.js b/tests/utils/instance-diagnostics.test.js new file mode 100644 index 000000000000..ff66982d8f94 --- /dev/null +++ b/tests/utils/instance-diagnostics.test.js @@ -0,0 +1,123 @@ +import { + aggregateDiagnosticsClients, + sortDiagnosticsChecks, + buildClientLogQuery, + buildRequestSeries, + getCheckLabel, + formatBytes, +} from '../../src/utils/instance-diagnostics' + +describe('instance-diagnostics', () => { + describe('aggregateDiagnosticsClients', () => { + it('sums Count per AppId across buckets and computes share%', () => { + const buckets = [ + { Clients: [{ AppId: 'a', AppName: 'App A', IP: '1.1.1.1', Count: 10 }] }, + { Clients: [{ AppId: 'a', AppName: 'App A', IP: '1.1.1.1', Count: 5 }, { AppId: 'b', AppName: 'App B', IP: '2.2.2.2', Count: 5 }] }, + ] + const result = aggregateDiagnosticsClients(buckets) + expect(result).toEqual([ + { AppId: 'a', AppName: 'App A', IP: '1.1.1.1', Count: 15, SharePct: 75 }, + { AppId: 'b', AppName: 'App B', IP: '2.2.2.2', Count: 5, SharePct: 25 }, + ]) + }) + + it('rounds SharePct to one decimal place', () => { + const buckets = [{ Clients: [{ AppId: 'a', Count: 2 }, { AppId: 'b', Count: 1 }] }] + const result = aggregateDiagnosticsClients(buckets) + expect(result).toEqual([ + { AppId: 'a', AppName: undefined, IP: undefined, Count: 2, SharePct: 66.7 }, + { AppId: 'b', AppName: undefined, IP: undefined, Count: 1, SharePct: 33.3 }, + ]) + }) + + it('handles empty/missing input without throwing', () => { + expect(aggregateDiagnosticsClients(undefined)).toEqual([]) + expect(aggregateDiagnosticsClients([])).toEqual([]) + expect(aggregateDiagnosticsClients([{}])).toEqual([]) + }) + }) + + describe('buildRequestSeries', () => { + it('splits 5 clients into 4 named series plus Other', () => { + const buckets = [ + { + Bucket: '2026-09-10T10:00', + Clients: [ + { AppId: 'a', AppName: 'App A', Count: 50 }, + { AppId: 'b', AppName: 'App B', Count: 40 }, + { AppId: 'c', AppName: 'App C', Count: 30 }, + { AppId: 'd', AppName: 'App D', Count: 20 }, + { AppId: 'e', AppName: 'App E', Count: 10 }, + ], + }, + ] + const { data, series } = buildRequestSeries(buckets, 4) + expect(series).toEqual([ + { AppId: 'a', AppName: 'App A' }, + { AppId: 'b', AppName: 'App B' }, + { AppId: 'c', AppName: 'App C' }, + { AppId: 'd', AppName: 'App D' }, + ]) + expect(data).toEqual([{ Bucket: '2026-09-10T10:00', a: 50, b: 40, c: 30, d: 20, Other: 10 }]) + }) + + it('emits only the series present with no Other key when nothing is left over', () => { + const buckets = [ + { + Bucket: '2026-09-10T10:00', + Clients: [ + { AppId: 'a', AppName: 'App A', Count: 5 }, + { AppId: 'b', AppName: 'App B', Count: 3 }, + ], + }, + ] + const { data, series } = buildRequestSeries(buckets, 4) + expect(series).toEqual([ + { AppId: 'a', AppName: 'App A' }, + { AppId: 'b', AppName: 'App B' }, + ]) + expect(data).toEqual([{ Bucket: '2026-09-10T10:00', a: 5, b: 3 }]) + }) + }) + + describe('sortDiagnosticsChecks', () => { + it('orders FAIL, WARN, INFO, PASS', () => { + const checks = [ + { Check: 'a', Status: 'PASS' }, + { Check: 'b', Status: 'FAIL' }, + { Check: 'c', Status: 'INFO' }, + { Check: 'd', Status: 'WARN' }, + ] + expect(sortDiagnosticsChecks(checks).map((c) => c.Status)).toEqual([ + 'FAIL', + 'WARN', + 'INFO', + 'PASS', + ]) + }) + }) + + describe('getCheckLabel', () => { + it('maps known check ids to readable labels and passes unknown ids through', () => { + expect(getCheckLabel('api-clients')).toBe('API clients') + expect(getCheckLabel('some-future-check')).toBe('some-future-check') + }) + }) + + describe('formatBytes', () => { + it('picks the right unit with one decimal place', () => { + expect(formatBytes(512)).toBe('512.0 B') + expect(formatBytes(2048)).toBe('2.0 KB') + expect(formatBytes(5 * 1024 * 1024)).toBe('5.0 MB') + expect(formatBytes(1.5 * 1024 * 1024 * 1024)).toBe('1.5 GB') + }) + }) + + describe('buildClientLogQuery', () => { + it('builds a search-all-files KQL query scoped to the AppId and window', () => { + expect(buildClientLogQuery('11111111-2222-3333-4444-555555555555', 24)).toBe( + 'search all files\n| where Message contains "AppId=11111111-2222-3333-4444-555555555555"\n| where Timestamp > ago(24h)\n| take 1000\n| sort by Timestamp desc' + ) + }) + }) +})